Thesis

Each of us wears many hats, and our growth compounds because of it.

Our AI should keep them straight, and help that growth compound exponentially as well.

AI is a fundamental paradigm change, and new platforms need new principles. The internet and mobile each got theirs; the web’s founders wrote down a few simple ones, open, decentralized, yours, and the web grew up around them. AI arrives as all three at once: a new place (where the work now happens), a new platform (what software is built on), and a new interface (how people and machines work together).

These principles matter more as compute accelerates. Models improve faster every cycle, are beginning to improve themselves, and quantum computing is reshaping the hardware underneath. The faster models get, the more harm a single careless inference can do, and the higher the cost. The faster a system can move, the further it can take you off course when pointed the wrong way, and small mistakes compound quickly.

This is what we build for.

1. Built the way humans work

Humans work in context, sometimes with hard boundaries between them. We struggle with it even among people, keeping a confidence, not letting one relationship color another, and we’re now asking machines to do it at far greater speed, with none of the instinct: a model that can draft your board memo can also leak it into your next client call.

This matters even more in the highest-stakes fields, healthcare, legal and safety, financial advisory, where the whole value of the work is the boundary, and the organizations with the most to gain are the least able to adopt AI today.

The same context that must stay sealed is also where learning accumulates — every case a clinician closes, every matter a lawyer sees — so the boundary and the compounding are two sides of one system. That is the pair mnemur is built for: a trust layer and a learning layer.

The World Economic Forum and Kearney read it the same way: their “AI-First Operating System” blueprint names the same trap, that organizations adopt AI faster than they redesign how they work, and argues the missing piece isn’t a better model, it’s contextual workflows. Sierra, Bret Taylor’s AI-agent company, hit the same wall running its own operation: “the bottleneck has moved to context: what’s specific to your company, your workflows, your history.” Even the teams building the agents find that context, not model IQ, is the constraint.

2. Own your AI

Each of us should own our own AI, our knowledge, and our learning, and be able to compound it over time: the craft a person builds and the standards an organization sets, portable to any model. Your AI’s “constitution” (the rules that make it yours) should not be trapped in one vendor’s memory.

That ownership lives in two stores:

Both are plain, portable documents, so neither is surrendered to whichever model runs today. Where a person works inside an organization, the org’s overlay governs the org’s work while the personal constitution and learning stay the person’s; the rules keep your AI safe to trust, the learning makes it worth keeping.

What is actually worth owning is not the transcript; it’s a “constitution”: what your AI must never do, what it may decide alone, how it handles your health and your money, when it discloses that AI was involved, which model may see which data, and how it writes as you. In practice that spans several core domains, the same shape whether the owner is a person or an organization:

  1. Values & laws: the non-negotiables, and the priority order that never inverts.
  2. Operating rules: the autonomy envelope for what the AI may decide alone versus what waits for a human (safety-critical lines, like clinical care, live here as hard floors: it advises, never decides).
  3. Financial policy: what it may decide about money, and what always waits for a human.
  4. Disclosure: when AI involvement is named.
  5. Model choice & costs: which model tier runs which work, and what data may reach it.
  6. Data provenance: what feeds the AI, and at what trust.
  7. Communication style: how it writes when it writes as you.

The full detail, and how mnemur stores and enforces each, lives in the documentation.

3. Trusted, but verified

Guardrails should be inspectable, because trust you can’t examine is just branding. Every governed call is logged to a tamper-evident record (the automatic record-keeping the EU AI Act’s Article 12 will require of high-risk systems from August 2026), and the source code for the key components will be accessible, so the parts that enforce safety can be verified, not just promised. And because those pieces belong to you, you can host mnemur wherever makes sense: your own cloud, your infrastructure, or ours.

Verification is becoming the scarce resource: models make output nearly free; knowing it’s right is what still costs (Dan Shipper’s AI paradox). Rules as plain text are advisory; enforcement makes them reliable, in two layers: a gateway that governs what information flows (contexts sealed by subject, deny rules and budgets before a call leaves, the audit behind it; working code, running our own practice daily) and a loop runtime, the independent verifier we’re building now, that governs how the agent behaves.

Enforcement means more than segregation; it owns the two ends of a task: pre-decomposition, breaking an ask into checkable steps before execution, and post-verification, checking the outcome after, by an independent agent that is never the one that did the work. Attestation tools can prove a record wasn’t tampered with; none of them re-execute the work to check it honored the policy and the boundary. The audit receipts are being aligned with OVERT, an emerging open standard for verification receipts, adopted, not rivaled.

4. Organizations set their own policies

How tightly boundaries are drawn should be a choice, and that choice belongs to the organization, not to us. The same system is designed to run across a range of postures, and each organization picks where it sits and moves as its needs change.

These are some of the choices that matter most:

  1. How strictly the boundaries are enforced: from sampled spot-checks up to policy on every call, human sign-off on sensitive actions, and egress that is locked down.
  2. Speed of deployment: a lighter posture ships faster and suits lower-stakes work, while a stricter one trades some of that speed for tighter assurance where the work demands it.
  3. Portability: a person can carry and export the AI they’ve built (the personal store above), while the organization keeps its own standards in the organizational store. Personal AI stays with the person; org AI stays with the org.

None of this is fixed at the factory: enforcement level, portability, and speed are all set, and changed, at the org level.

Early access

Get early access and shape the product.

Opens your mail app, pre-filled. Nothing is sent until you hit send.