← Language From First Principles

The Personal AI

Compose representation, attention, preference and state into one inspectable personal interface layer.

Eight chapters built the parts: explicit policy, the type demolition, conditional learning, durable policy, temporary overlays, authorised friction, portable protection, visible model. This chapter earns the name they compose into — by composition, adding no new capability:

A Personal AI is not a profile that knows the user. It is a policy-constrained mediation runtime that can act differently for the user while keeping authority, inference, provenance, and correction distinct.

The architecture, visible early and complete:

PART II RadarDecision (what / how much / when)
        ↓
USER AUTHORITY (communication policy, boundaries, friction)
  + LEARNED EVIDENCE (preference evidence, model beliefs)
  + CURRENT CONTEXT (declared mode, observable constraints)
        ↓
POLICY COMPILER (scope, precedence, confidence,
                 preservation, accessibility)
        ↓
EFFECTIVE INTERACTION POLICY (representation, ordering,
  evidence visibility, interaction structure, friction,
  service enforcement)
        ↓
VIEW / ACTION + WHY TRACE + ENFORCEMENT RECEIPT + CORRECTION PATH

Five namespaces flow through the compiler and must never merge into confidence-weighted sludge, now stated with their authority content: USER-AUTHORED AUTHORITY (what the user explicitly permits), LEARNED CONDITIONAL EVIDENCE (observations supporting scoped policy), INFERRED PERSONAL STATE (uncertain model propositions), TEMPORARY CONTEXT (declared/observable session state), EXTERNAL CAPABILITY/SERVICE STATE (what other systems can actually enforce) — crossed by the independent axis of DATA-USE AUTHORITY (which information operations are permitted), which belongs with authority, never folded into the learned/inferred namespaces. Their separation is the integration result — a dossier with no boundaries is less aligned, not more, and the chapter rejects the equation outright: more history plus larger context plus better model does not equal Personal AI. (PASS D consistency note: LEARNED/INFERRED entries carry DataUseAuthority lineage — purpose, scope, retention, allowed reuse — per Chapters 23–28; TEMPORARY entries expire without residue per Chapter 25; the compiler honours safe-default behaviour wherever personal state is absent or uninspected.) The definition the architecture supports:

An inspectable mediation system whose behaviour is conditioned by user-owned policies, contextual evidence and revisable personal-model state, preserving the distinction between authorised and inferred.

Two invariants govern composition. Inference may propose behaviour; only authorised policy establishes authority — observations update evidence, inferences update beliefs, and neither grants blocking authority, sharing permission, persistence of temporary state, or widened scope. Confidence never converts to consent: a 0.99 inferred preference remains an inference, gated exactly like a 0.51 one where authority is concerned. Architecturally the compiler is now two compilers in series: a PERSONALISATION COMPILER (what behaviour would fit this user/task/context?) whose output passes an AUTHORITY COMPILER (which inputs and operations are permitted? preservation/accessibility first, then data-use authority, then action/speech/boundary authority) before any effective behaviour executes — so the system can know something about the user and still be forbidden to use it. Alongside the personalised path runs a peer GENERIC SAFE PATH: personalisation disabled, evidence unavailable, authority missing, or inference too weak all route to generic bounded behaviour as a first-class mode, never a failure state.

Emergent failures: the integration dividend

Components correct alone fail together, and the chapter’s new work is exhibiting the combinations: durable source-first against QUICK SCAN resolving to short conclusion with visible source affordance rather than either winning; learned concision against qualification-sensitive material where preservation wins without deleting the preference; present-tense override defeating FOCUS blocking locally; incapable services yielding UNSUPPORTED instead of theatre; and the diagnostic prize — a vanished prerequisite traced through the why-chain to the belief (false-known X) rather than the brevity preference, a failure only integration can expose. EXP-29 stresses the cumulative stack (A generic through H full runtime with precedence, provenance separation, traces, receipts, locality) across frozen information-world cases with planted model errors and the hostile battery: the obedient mistake (harmful explicit preference honoured with trade-off exposed), the confident false belief, the week-of-mobile-scanning contamination test, service betrayal after API change, unauthorised helpful overreach, cascading-correction locality, control abandonment (no settings visits — system stays bounded), accurate-preference/unauthorised-inference splits, temporary-state persistence attempts, valid-adaptation/wrong-cognitive-claim separations (faster completion never labelled better learning), composed-privilege exposures, revocation-after-derivation accounting, third-party-information containment, and the generic escape hatch — turn all personalisation off must yield a coherent non-personalised path, or user control is theatre. Scored in five unmerged families (task/utility; management burden — separate, because theoretical control without usable non-administration is not control; agency/authority; epistemic integrity; privacy/scope) with non-monotonic trade-offs kept as results, never averaged into a Personal-AI score.

The horizon at the edge: intention is not permission

One emerging frontier belongs here precisely because it sharpens the architecture rather than extending it. Wandelt et al. (Nature Human Behaviour 2024, verified: two implanted participants, SMG arrays, six words plus two pseudowords, offline 55%/24% and online 79%/23% against 12.5% chance, authors explicit that internal-speech decoding remains sparse and far from general thought decoding) and Kunz et al. (Cell 2025, verified via PMC: four motor-cortex participants, real-time self-paced inner-speech decoding including 125k-vocabulary operation, free-form aspects decodable in counting tasks, a motor-intent dimension separating attempted from inner speech, imagery-silenced training plus an unlocking keyword at 98.75% detection) jointly establish something remarkable and narrow: constrained attempted and internal speech signals can be decoded under implants — while complete intelligible free-form thought transfer is undemonstrated and generalisation uncertain. The 2025 streaming brain-to-voice neuroprostheses (reported, not independently verified here) restore intended speech for paralysis — communication repair, not thought access. The chapter’s horizon thesis, and the book’s reason for carrying it:

As the interface moves closer to intention, the boundary between internal state and communicative act becomes more important, not less: representation ≠ intention to communicate ≠ permission to transmit.

Intention gating, scope, privacy, and explicit authority become first-class communication-system problems — the Kunz keyword-unlock is Chapter-26-style friction at the neural edge. “AI will soon read our thoughts” is refused outright; constrained decodability with gated authority is claimed instead. Then BCI is left behind — a horizon survived, not a foundation used.

What this chapter earned

The Personal AI as runtime, not dossier: authority, evidence, context, and pipeline composed through an explicit compiler with namespace separation, dual invariants, emergent-failure diagnostics, five-family scoring, hostile battery including the generic escape hatch, and a BCI horizon that reinforces rather than relaxes the architecture. Revised verdict: a Personal AI is not merely a policy-constrained mediation runtime but one whose personalisation is conditional on both evidential support and operation-specific authority, and whose safe behaviour never depends on continuous user supervision. Part III’s mechanisms now act as one inspectable system — which raises the question Part III cannot answer: how far can adaptation go before the distinction between system and person itself is tested?

A personal AI that adapts communication raises a new question: can a bounded model predict or act on the person’s behalf?

References

  • Wandelt, S.K. et al. (2024). Nat. Hum. Behav. 8:1136–1149. DOI 10.1038/s41562-024-01867-y. Verified (abstract + biblio): 2 participants, SMG, 6 words + 2 pseudowords, 55%/24% offline, 79%/23% online, chance 12.5%, sparse-decoding caveat.
  • Kunz, E.M. et al. (2025). Cell 188:4658–4673. PMC12360486. Verified in depth: 4 participants, motor cortex, real-time inner-speech decoding, 125k vocab, free-form counting aspects, motor-intent dimension, imagery-silenced training, 98.75% keyword unlock.
  • 2025 streaming brain-to-voice neuroprostheses (Nature, s41586-025-09127-3): reported, not verified here; cited as communication-repair context only.
  • Ch 21–28 mechanisms: composed, not re-argued.

Proposed experiment EXP-29: Personal AI stress test

Status: PROPOSED. Per the design above (A–H cumulative, frozen cases + planted errors, extended hostile battery incl. generic escape, five-family scoring, non-monotonic trade-offs kept).