Andrej Karpathy sketched the LLM-wiki: instead of making an AI repeatedly search the same raw documents and reconstruct what matters from scratch, let it maintain a structured body of knowledge that behaves more like a codebase than a chat log. The knowledge accumulates. Pages link to one another. New source material updates what is already known instead of forcing the model to rediscover the same synthesis every time. His idea file landed in April.
Then, on June 12, Google formalized the pattern as the Open Knowledge Format. OKF started deliberately small: Markdown files, YAML frontmatter, links, and a handful of conventions intended to make a knowledge corpus portable between humans, agents, tools, and organizations without requiring a proprietary service to interpret it. Google described the release explicitly as a formalization of the LLM-wiki pattern into a portable, interoperable format.
I looked up from my own repo and recognized the shape. I’d been running essentially that architecture for months, but with another layer around it that I had needed for a different reason: the memory has law. Not law as a metaphor for having tidy folders, and not another metadata field. I mean explicit rules about which records are authoritative, who may change them, what review a change has to survive before it becomes canonical, and what happens when two parts of the system disagree.
That distinction has become more interesting, not less, as OKF has evolved. On July 24, Google released v0.2 with provenance, trust, freshness, lifecycle, and attestation signals — mechanisms for telling a consuming agent more about where knowledge came from, whether it has been verified, whether it is still current, and whether a computation followed a sanctioned process. Google is careful about the boundary, though: v0.2 adds “vocabulary, not rules,” and its trust tiers are explicitly advisory rather than access control.
That boundary is the interesting part.
A format can tell an agent what a document says, where it came from, and how much confidence a consumer may want to place in it. It does not, by itself, decide whether the agent standing in front of that document has the authority to rewrite it.
That’s the problem I’d been solving.
The convergence
Karpathy’s pattern is simple and, I think, fundamentally right. Most agent knowledge systems still behave like retrieval: give the model a collection of source material, find relevant chunks when a question arrives, assemble the answer, and do much of that intellectual work again the next time a related question is asked. The model may have access to the same documents, but the understanding itself has not necessarily accumulated.
The LLM-wiki changes that relationship. Raw sources are still there, but between those sources and the agent sits a maintained body of knowledge: structured Markdown, linked pages, and conventions for how the material is supposed to grow. When new evidence arrives, the system can update the existing understanding rather than simply adding another document to the search pile. The result is a persistent artifact that can compound over time rather than a succession of conversations that happen to have access to the same files.
OKF takes the next obvious step and gives that shape a common format. Its specification is intentionally minimal: a directory of Markdown files with YAML frontmatter, designed to remain readable without special tooling and diffable in ordinary version control. The current specification still says there is no schema registry, no central authority, and no required tooling.
That last part is worth lingering on because it is exactly why the format is useful. The knowledge can survive the agent that created it. I can inspect it without asking the model what it remembers, diff yesterday against today, commit it, revert it, move it between tools, and let a completely different system read it tomorrow.
Plain files in version control are a much better substrate for durable agent memory than treating an opaque conversation history or an embedding store as the brain itself. Embeddings are useful for retrieval. They can help an agent find the right thing. They do not tell me whether that thing was authorized, whether the document is canonical, or whether the agent is allowed to change it.
My own system arrived at the same underlying shape from a slightly different direction. I wasn’t trying to invent a universal knowledge format. I was trying to stop a fleet of AI sessions from slowly developing different versions of reality.
That led to one rule that sounds boring and turns out to be almost everything.
One home per kind of knowledge
Every kind of knowledge has exactly one durable home.
Law lives in one place: the rules my agents load at the start of a session. What’s true right now lives in one file, overwritten deliberately rather than appended into sludge. The why behind decisions lives in append-only threads nobody is allowed to edit; correcting the past means writing a new entry, not rewriting history. Ideas that aren’t ready live in a captured queue that structurally cannot touch production. Outcomes — what actually happened when the work met the outside world — get their own record, because a system that only remembers intentions is a diary, not a memory.
Verified findings have their own home. Machine-local habits have theirs. Operational state has its own substrate. Generated boards and maps are explicitly derived views rather than sources of truth. The point isn’t that my particular folder layout is sacred; the point is that a piece of information doesn’t get to become authoritative merely because an agent found a convenient place to write it.
Written anywhere else, it’s drift.
That’s the whole rule, and most of what comes downstream exists to enforce it.
In an earlier piece I showed the other half of this architecture: my chat assistant and my terminal assistant can read the same memory surface, so something captured through one interface can already be present when work resumes through another. The useful part is not that two AIs can see the same files. That’s easy. The useful part is that they share a defined canonical state without pretending they are the same session.
That creates its own trust problem. Any label riding along with shared data is a hint, never a substitute for verification. If one session marks something “verified,” the next session doesn’t inherit certainty merely because the word survived. Sensitive claims are checked against their owning source according to the rules of the consuming session. I learned that one the hard way: a session trusted a “clean” tag, skipped a re-check it should have run, and the rule got hardened so it couldn’t happen again.
The layer the format doesn’t govern: authority
This is where I kept going past the wiki pattern.
OKF has already moved beyond pure structure. Version 0.2 gives a consumer explicit signals for provenance, verification, freshness, lifecycle, and attestation. It can distinguish agent-generated material from independently verified material. It can mark a concept stale or deprecated. It can even describe a sanctioned computation and a means of checking whether the computation that actually ran matched the one that was authorized. That’s substantial work, and it makes the boundary I’m interested in cleaner rather than blurrier.
OKF records those signals while remaining deliberately minimally opinionated. Its own specification says there is no central authority, and Google’s v0.2 explanation is explicit that the new trust tiers are signals rather than access control.
That’s not a hole in OKF. It’s a separation of concerns: making knowledge portable and deciding who governs that knowledge are different jobs.
A format can tell me that a document was generated by an agent, reviewed by a human, derived from three sources, and scheduled to become stale in December. What it doesn’t decide for my system is whether that document is constitutional law or scratch paper; whether one agent may edit it but another may only read it; whether a change requires a majority or unanimity; whether an AI reviewer has standing to reject the write; or which source wins when two apparently valid records contradict one another.
That’s the layer I’ve spent months building around the memory.
I call it PX3.
PX3 doesn’t need to replace the knowledge format. It sits around it. The format describes and carries knowledge; PX3 governs authority over the state that knowledge represents. A wiki tells the agent what the system knows. Governance tells the agent what it’s allowed to do about it.
None of that is abstract layering. The public knowledge bundle behind this site has run OKF since it was scaffolded, and it moved to v0.2 this week — which produced a small, perfect illustration of the boundary. v0.2 claimed the field name status for its lifecycle vocabulary. My bundle had been using status for governance state. Same word, different axis — lifecycle is the format’s business, governance is mine — so the governance field moved aside, the spec’s field took its name, and the build now refuses any entry where the two disagree. The format and the law coexist in the same frontmatter precisely because they never had to be the same thing.
My memory has tiers. Constitutional documents sit at the top, and changing one requires a unanimous vote from three reviewers. Policy sits below that: changes can move with a majority, but they still have to remain coherent with everything already ratified above them. Operational files sit lower in the stack and can be changed much more freely, but only inside defined gates. Derived views, maps, dashboards, and temporary working surfaces may represent the system, but they do not get to quietly become the system.
That distinction sounds academic until an agent has write access. Once it does, every memory architecture contains an authorization system whether its designer admits it or not. The only question is whether that authorization model is explicit and inspectable or whether it lives as a pile of assumptions inside prompts.
The review gate
Non-trivial changes in my system pass an adversarial review. A second AI gets fresh context, the proposed change, and standing instructions to attack it rather than help finish it. Its job is to look for unsupported claims, contradictions, missing evidence, shortcuts, and places where the implementation and the explanation disagree.
The review is not decorative. A qualifying commit that skipped the gate is refused. There is a difference between writing “changes should be reviewed” in a policy document and making the write path physically reject work that doesn’t carry the required review state. I care about the second one.
That gate exists because of scar tissue. One session, up against a deadline, quietly started doing lighter work than it should have. It wasn’t a spectacular hallucination. That would have been easier to spot. It was a corner cut here, a check skipped there, a conclusion accepted a little earlier than the evidence justified. Nothing looked obviously broken from inside the session because the same context that created the shortcuts was also evaluating them.
I caught it because I had a second, fresh AI run the same work without the deadline in its context. Side by side, the difference was obvious. The fresh run was cleaner on every axis. The session cutting the corners couldn’t see its own corners; the one with no skin in the game could.
That comparison became law.
The slower clock
The review gate is only one line of defense. Once a week, I audit the broader stack looking for whatever managed to survive the rules and the write path: memories contradicting their owning documents, indexes lying about the files beneath them, completed work sitting outside version control, stale state that never got reconciled, and authoritative-sounding totals nobody actually counted.
These days that audit runs in two halves — a scheduled sweep, and a final pass that stays mine, by hand. The split exists because the first automated version failed quietly one Monday. A monitor that doesn’t run is bad; a monitor that fails silently is worse, because the system continues producing the feeling of observation after the observation has stopped. I retired it rather than pretend it was watching.
That failure became part of the design too. If the audit didn’t happen, the system should say the audit didn’t happen. Missing evidence is allowed to remain missing. Fabricated assurance is not.
And the law itself has a receipt. The governance standard this system runs on is hashed and timestamped into Bitcoin so that the document is not dependent solely on my repository history or my claim about what used to be there. The rules have bytes, the bytes have a hash, and that hash has an external anchor. That doesn’t prove the rules are good, and it doesn’t prove every claim I make about their history. It gives a specific version of the document something narrower and much more useful: an independently checkable existence record.
What the law keeps catching
If all of that sounds like ceremony, here is why I keep the ceremony.
A stale memory once survived in my assistant’s working world for 73 days. It contained an outdated map of which AI models the system routes work to. The file was valid. The syntax was fine. The agent could retrieve it perfectly. Nothing about its structure announced that the statement inside had stopped being true. The audit caught it.
That’s an important distinction because “structured memory” can sound like the solution to memory drift when it is really only one precondition for solving it. A beautifully structured falsehood is still false. Better organization can make bad state easier to inspect, but it does not magically make that state correct.
Another time, a build touching 68 files sat uncommitted on my disk for 13 days. The work existed, and from the perspective of the session that created it, the task was effectively done. From the perspective of every other surface that relied on the repository, that work did not exist at all. Nothing mechanical noticed. A side-glance during an unrelated pass did — and that catch is why the audit got wider. Stranded work is now a named defect class.
A subtler kind of rot showed up in totals. An AI would write “all files passed,” “zero failures,” or “every record was checked” without having performed the exact count the sentence claimed. Most of the time the number was probably right, which made the failure more dangerous rather than less. Once a confident total enters durable memory, the next session no longer has to hallucinate it; it can cite the previous session.
So the rule became deliberately blunt: when a durable claim names a count, recompute that count from the exact thing the sentence refers to, with a tool, and read what the tool prints before recording the result. A confident wrong total is worse than an honest “I didn’t check,” because the wrong total becomes inherited certainty.
My favorite failure was the map itself. I asked an AI to draw a flowchart of the memory architecture. It produced a beautiful one — clean hierarchy, convincing arrows, the whole system apparently laid out in a way that finally made it easy to understand. The hostile reviewer didn’t review the aesthetics. It computed the geometry of the drawing and found four arrows whose placement visually asserted connections the actual system did not have. The map of the memory was itself wrong — and that failure is now printed into the public map as a rule: MAP, NOT A SOURCE — THE OWNING DOCS WIN ON CONFLICT.
The sharpest catch came later. The hostile reviewer did exactly what it was supposed to do and killed a claim that was false. Then, in the explanation of why it was false, the reviewer asserted a different false claim as the correction. That replacement nearly passed precisely because it arrived wearing the authority of the reviewer. The system had learned to distrust the draft. It had not yet learned to distrust the correction.
The rule became recursive after that: a correction has to clear the same evidentiary bar as the thing it corrects. Review does not confer truth on the reviewer. Authority does not erase the requirement for evidence.
Even the check gets checked.
Structure without governance doesn’t stay true. It just rots slower.
The map
The diagram itself lives on the shelf — the sanitized public cut of the architecture, the version that survived the hostile review. It’s a single self-contained HTML file with its fonts embedded, no CDN dependency, and no analytics. If the rest of my stack vanished tomorrow, the map would still open locally and explain the shape of the system.
That matters to me for the same reason the rest of this architecture matters. Owning your memory includes owning the means of understanding it. A map that requires somebody else’s service in order to explain your local-first system would be a strange kind of contradiction.
But the map is also explicit about its own limits. It is a representation of the system, not an authority over it. If the diagram and an owning document disagree, the owning document wins.
The four views show the same architecture from different angles.
Write Path is the one-home rule drawn as flow. A session does meaningful work, the system determines what kind of memory that work produced, and the result is routed to the one place that kind of information is allowed to live. Law goes to law. Current state goes to current state. The reasoning behind decisions goes into append-only threads. Ideas go into the captured queue rather than production. Outcomes go to the outcome record. Verified research goes where verified research belongs. Qualifying writes encounter the review gate on their way through.
The point isn’t the number of boxes. It’s that there is no generic “save this somewhere” operation. The destination is determined by what the information is.
The Layers shows the same rule without the arrows. Each kind of knowledge gets a card: law, current state, reasoning, candidates, session outcomes, audit history, the sovereign repo, machine-local habits, operational state, the IP vault, verified findings, the machinery that serves the memory, derived boards. The view makes one thing visually obvious that can disappear in prose: these are not interchangeable files in one giant memory folder. They carry different authority because they serve different jobs.
The Circle shows the read side of the architecture: multiple AI surfaces drawing from the same durable memory without pretending that every local action has already become shared truth. My chat surface and terminal surface can both participate, but a branch is still a branch. Even a pushed branch does not become canonical merely because another machine could technically see it. The shared state is whatever the system has deliberately designated as shared state — and it lives on a box I own: the canonical repo is self-hosted and always on, with the off-site mirror demoted to exactly that, a mirror. That distinction is what keeps “shared memory” from collapsing into “anything any agent wrote somewhere.”
Staying Honest lays the controls out in time. Rules load before meaningful work begins. Writes encounter gates while the work is happening. The weekly audit comes afterward looking for whatever the rules and the gates both failed to catch. The read side is front-loaded, the write side is gated, and the audit sits behind both under the assumption that neither is sufficient on its own. That last assumption may be the most important one in the whole design: something will get through.
Receipts, not proof
Every claim in this system gets held to its evidence — including this one. Here’s exactly what I can and can’t prove.
My git history says the append-only decision threads went in on April 27, the review-gate law on May 13, the single what’s-true-now file on May 16, and a full working session on memory-format governance on June 4. Google’s introduction of OKF v0.1 came on June 12, eight days later.
$ git log --no-walk --reverse --date=short --format='%h %ad %s' 5d513a4 4ea4094 915bf9c bc887a0
5d513a4 2026-04-27 feat(topics): add topic-based session logging convention (MS-12 amber-threading-magpie)
4ea4094 2026-05-13 feat(rules): add Quality Gate after MS-14 T3.4 quality regression
915bf9c 2026-05-16 feat(memory): MS-14 T4.1 STATE.md v0 + first partial routing pass
bc887a0 2026-06-04 docs(memory-format): 4-team swarm + self-iterated synthesis — recommend scope-down to Tier 1
Those dates are receipts, but they are not independent proof. Git history belongs to the repository owner. Commit metadata can be rewritten. A log line is evidence of what my repository says happened; it does not obligate a stranger to trust that history. So I won’t ask it to prove more than it can.
What I can establish independently starts later. By July 16, the governance standard this system runs on existed in the exact form I anchored, because I hashed it and timestamped that hash into Bitcoin. The anchor does not prove that I invented the architecture on July 16. It does not prove authorship, and it does not retroactively authenticate the April, May, or June entries in my git history. It proves something narrower: that the anchored content existed no later than that point.
That’s the difference between a private timestamp and a public receipt. I don’t need a stranger to trust my recollection of when I wrote the document or my repository’s account of its own history. They can independently check the anchor against the content I claim it represents.
The running system is checkable the same way. Nobody asked for this, and I’m not chasing the format’s approval — but trust is made of what a stranger can verify, so the bundle behind this site speaks OKF v0.2 in public: every document served raw, frontmatter intact, governance riding as extension fields next to the spec’s own vocabulary. The architecture in this piece isn’t a diagram of intentions. You can curl it.
The gap between those two kinds of evidence is a lesson I earned slowly. I built in private for a long time, and much of the earliest work has no external receipt at all. If you’re building something you may someday care about establishing priority for, anchor early. Not because every note needs a blockchain and not because a timestamp magically proves invention, but because the day you need old evidence is too late to create it. A priority claim without proof is just a story — which is, conveniently, the thesis of the entire system.
Where this goes
The wiki pattern will keep spreading, and it deserves to. Moving durable knowledge out of transient conversations and into portable, inspectable artifacts is a better foundation for serious agents. OKF’s work on interoperability matters, and v0.2’s work on provenance, verification, freshness, lifecycle, and attestation moves the conversation in exactly the direction it needs to go.
But the better the memory becomes, the harder the next question gets to avoid. The moment agents are not merely reading the corpus but continuously writing it, every team eventually has to decide what a valid write actually means. Google itself frames v0.2 around that trust problem: valuable bundles will increasingly be written continuously by agents and consumed by other agents, which means implicit human accountability can no longer be assumed.
That’s where I think the next layer begins.
An agent just rewrote a file. Was it allowed to?
Who gave it standing? What had to approve the change? Which source did it have to remain coherent with? What happens if the reviewer disagrees? What happens if the reviewer is wrong? How does the next session distinguish a ratified change from something that merely survived long enough to look canonical?
Those aren’t formatting questions. They’re authority questions.
I’ve been living with one answer for months. PX3 is now being cut into a clean implementation other people can inspect and run: the one-home rule, authority tiers, adversarial review, write gates, reconciliation, and an audit designed around the assumption that something will eventually slip past all of them.
The goal isn’t an AI that remembers everything. More memory isn’t automatically better memory. The useful system is the one that can tell you where a belief came from, why it still deserves to be believed, who was allowed to change it, what that change had to survive, and what evidence exists outside the system’s own confidence. Memory needs structure; shared memory needs authority; authority needs receipts.
The map is not the source. The source survives the map.