The registry.
How a way of working is held. One entry is one named person and one family of machine, built only from sessions that person consented to. Entries are held and addressed by name, one runs at a time, and nothing in the registry is ever fitted together with anything else.
One entry. One name. One family of machine.
An entry is the unit the whole chain is built on. Everything downstream โ the release, the count, the attribution, the withdrawal โ addresses an entry, and addresses it by name.
An entry holds one person's way of running one family of machine. It is built from that person's own sessions and from nothing else. No entry draws on a second person's work. No entry is topped up from a pool of material gathered elsewhere. A session that did not pass admission is not in the entry, and there is no route by which it can be added afterwards: consent is read at the moment of recording, and a permission given later does not reach back over a recording already made.
The entry carries the name the licence runs under. That name is not a label on the outside of the object. It is the address. It is how the entry is found, how it is selected, how the hours it runs are counted, and how it is ended. A licensee asks for an entry by name. A machine is told which name it is running before it runs anything. The count line comes back under the same name, and so does the money.
The person's paper is with Even Steven, who holds the corpus and holds their consent. Tacit Source is the commercial licensor of Even Steven skills: we hold a licence from Even Steven and we market under it. We never contract with the person in the seat, and nothing on this page changes on our say-so.
- Scope
- One person's way of running one family of machine.
- Source
- That person's own sessions, admitted one at a time.Nothing is admitted silently and nothing retrospectively.
- Address
- The name the licence runs under.The same name at selection, at the count and at the payment.
- Selection
- By name, before the work starts. One entry runs at a time.
- End
- On the person's own word, to Even Steven, needing nobody's agreement.
Licensed together is not held together.
Several entries can be licensed under one paper. Nothing about that paper changes what the entries are.
A set is a shelf, not a stew. Each member stays separately named, separately selectable, separately counted and separately endable. Licensing several entries together never merges them, no entry is trained on another, and there is no object anywhere in the registry that is an average of two people's work. A machine holding three licensed entries holds three entries.
This is why one person ending theirs does not disturb the others. That member stops. The rest of the shelf carries on under its own names, at its own count, on the same paper. A licensee loses a name, not an agreement, and the withdrawal is never a breach by us and never a failure of supply.
Selected one at a time
A machine runs one named entry, chosen deliberately before the work starts. There is no default and no last-used. A machine carrying yesterday's choice forward would be running on nobody's authority.
Counted one at a time
Each member is metered by the machine-hour that member runs, separately from every other member. The hour that is invoiced and the hour that is paid are the same signed row.
Ended one at a time
Consent is four separate permissions, each given on its own and each ended on its own. An entry ends when the person says so, free, effective on receipt.
Side by side, and nothing in between.
The dashed rules below carry as much of the argument as the arrow does. What is not joined is what makes the rest of this site enforceable.
Fig. 1 โ Entries held side by side. Dashed rules are boundaries nothing crosses; the dark entry has been withdrawn.
A name is an address, not a credit line.
Attribution that cannot be resolved back to a separately addressable object is decoration. In the registry, the name is the thing the machine is pointed at.
Separability is not a feature. It is the condition.
This is the part of the architecture that everything else rests on, and it is worth setting out in the order the argument actually runs.
First: a per-person count and a per-person withdrawal are honourable exactly where each person's contribution stays a separately addressable thing. If an hour can be resolved to one entry, it can be counted for one person and paid to one person. If an entry can be lifted out whole, a withdrawal is an operation somebody other than us can carry out and check. Both promises are the same promise wearing different clothes, and both are promises about addressing.
Second: fit contributions together into one set of model weights and both of them go. Checking afterwards, from the delivered artefact, that one person's influence was removed is not a hard engineering problem waiting on a better method. It is formally unavailable.
We cannot prove unlearning by showing that the parameters of the unlearned model are obtained without training on the unlearned data.
Thudi, Jia, Shumailov and Papernot ยท On the Necessity of Auditable Algorithmic Definitions for Machine Unlearning ยท USENIX Security 2022
The same paper states the point from the other side: unlearning "can only be defined at the level of the algorithms used for learning and unlearning, and not by reasoning over the model parameters they output." The restatement is ours to make and we make it plainly. Unlearning is not a property of a model. It is a property of a history, and histories are attested, not measured. Any offer to inspect a delivered model and confirm from it that one person is gone is offering something that cannot exist.
Three claims sit close together here and they are not the same claim. Blurring them is the easiest way to be knocked down by a counterparty's counsel, so the registry keeps them apart.
| The question | Where it stands | What the registry does |
|---|---|---|
| Verifying, from a delivered model's parameters, that one person's influence was removed | A formal result. It cannot be done. It is formally unavailable from the model itself. | Nothing is held as one set of fitted weights, so the question is never reached. |
| Removing a person's influence from a large generative model by approximate unlearning | Not achieved. No published method has survived an adversarial evaluation. That is evidence, not impossibility. | An entry is lifted out whole. There is nothing to approximate. |
| Exact unlearning at generative scale | Absent. No published construction exists at that scale. | Entries are held at the scale where removal is an ordinary operation on an addressable object. |
| Recalling weights that have been published openly | No mechanism exists, and for weights published openly none can. | The registry never publishes weights. |
| Rebuilding from scratch without a person's material | Always correct, and always available, at a price. | Separability keeps that price small enough that the honest answer is the one we can afford. |
A right to withdraw can be honoured today โ in a database, in a retrieval index, in a small model, and in anything kept separately addressable. It cannot be honoured, in any way a second party can check, in a large generative model trained the ordinary way.
Third, and this is the conclusion the first two were for: separability is not a feature of the registry. It is the condition on which every other promise on this site can be kept โ the count, the attribution, the withdrawal, the deletion. Take it away and each of them becomes a statement about our intentions. Keep it and each of them becomes something a second party can check at source.
The registry never publishes weights.
Nothing recalls what has been published. Once weights are in other hands there is no mechanism that reaches them, and for weights published openly there can be none โ not a licence term, not a takedown, not a later change of mind. A withdrawal that cannot reach every copy is not a withdrawal. It is a notice.
So the registry does not publish weights. Not as a release, not as a research artefact, not to a licensee, not to us. What crosses to a machine is a release, which is a different object built for a different purpose: it carries a digest of what went into it and never the contents, and it carries nothing identifying the person beyond the name the licence runs under.
The same discipline governs what an entry is used for. A record of a person working is personal information because that person is identifiable in it, and it is held on that footing throughout. It is never supplied to assess the person โ not to an insurer, not to an employer, not to anyone else, and not to us for that purpose either.
When a person ends an entry, the timing is exact and neither we nor a licensee can extend it. It stops for new work at once; a job already underway finishes. No new job starts under it from the day the withdrawal arrives, and the job underway runs to its end because stopping a machine mid-pass is its own hazard. That is the one delay in it. The whole sequence is set out on the withdrawal page.
A person who ends an entry is told both: the out-of-service date, the day it stops being choosable, and the true date, the day the last copy is gone, backups included. The shorter is never allowed to stand in for the longer.
Working out whether a named entry can carry your job?
Tell us the work and the family of machine, and whether an entry can carry it.
