CivitasOS
PUBLIC WORKING PAPER · VERSION 0.3公开工作白皮书 · 版本 0.3 8 SEPTEMBER 2026 · OPEN TO REVISION2026年9月8日 · 接受修订

A Correctable
Civilization.
可纠错的文明.

Trust does not come from always being right. It comes from remaining open to correction—even when those in power would rather not be corrected.信任不来自永远正确,而来自始终可以纠正——包括掌权者不愿被纠正的时候。

ABSTRACT

A working claim, not a final charter一个工作命题,而非最终宪章

Institutions are commonly trusted because their leaders are thought competent, their experts reliable, their rules legitimate, or their models objective. None of those conditions can be guaranteed over time. People err. Experts share blind spots. Organizations protect themselves. Artificial intelligence can reproduce the assumptions of its data and deployers.人们通常因为掌权者被认为称职、专家可靠、规则正当或模型客观而信任制度。然而,这些条件都无法长期保证。人会犯错,专家会共享盲区,组织会保护自身利益,人工智能也可能复制训练资料与部署者的假设。

Reliable institutional trust does not require an institution to be permanently right. It requires credible ways for errors to be discovered, carried past resistance, acted upon, and learned from.可靠的制度信任不要求制度永远正确,而要求错误能够被发现、穿过阻力、触发行动,并转化为制度学习。

CivitasOS is an open institutional design project built around that proposition. It is not a global government, a single ideology, or a system for transferring sovereignty to AI. It is a set of questions, design constraints, and experiments. Its claims remain provisional. Its name, rules, and authors have no permanent exemption from revision.CivitasOS 是围绕这一命题展开的开放制度设计项目。它不是全球政府、单一意识形态,也不是把主权移交给人工智能的系统;它是一组问题、设计约束与实验。其主张均属暂定,其名称、规则和作者都不享有永久修订豁免。

01 / THE PROBLEM

A warning is not yet a correction警告并不等于纠正

Many major failures are preceded by warnings. Frontline workers see anomalies; affected people report harm; analysts preserve doubts; experts propose alternatives. Yet the warning may be filtered, softened, delayed, or stripped of authority before it reaches a point where action is possible.许多重大失败发生前已经存在警告:一线人员看到异常,受影响者报告伤害,分析人员留下疑问,专家提出替代方案。然而,警告在抵达能够采取行动的位置之前,可能被过滤、软化、延迟,或被剥夺行动效力。

The central problem is therefore not simply whether speech is permitted or information disclosed. It is whether someone outside the challenged power is able and motivated to discover the error; whether the signal reaches an independent reviewer without being rewritten; whether anyone has authority and resources to act; and whether the result changes future rules.因此,核心问题不只是是否允许发言或公开信息,而是:权力之外是否有人有能力、有动力发现错误;原始信号能否在不被改写的情况下抵达独立复核者;是否有人拥有行动权限与资源;结果能否改变未来规则。

02 / FOUR LAYERS

From fallibility to evidence从可谬到底层证据

Philosophical base哲学底座

People and systems are fallible. No person, institution, majority, or model holds permanent epistemic privilege.人与系统皆可谬。任何个人、机构、多数或模型都不拥有永久认识特权。

Institutional principles制度原则

Consequential power cannot validate itself. Decisions may be final; structures of power must remain open to scrutiny and evolution.重大权力不能自证。决定可以终局,权力结构必须保持可检验、可演化。

Engineering mechanisms工程机制

Independent discovery, adversarial incentives, tiered controls, and learning after decisions.独立发现、对抗激励、分层控制与事后学习。

Empirical agenda实证议程

Specific mechanisms must face comparisons, counterexamples, costs, and conditions under which their claims should be abandoned.具体机制必须接受对照、反例与成本检验,并预先说明什么结果足以使其主张被放弃。

Transparency, decentralization, AI assistance, and fast feedback are not foundations. They are engineering options. Each can help in some settings and create new failure modes in others.透明、去中心化、人工智能辅助和快速反馈都不是基石,而是工程手段。它们可能在某些环境中有益,也可能在另一些环境中制造新的失效模式。

03 / THE CORRECTION CHAIN

Where does the warning lose the power to change reality?警告在哪一环失去改变现实的能力?

Discover发现 Transmit传递 Authorize行动权 Execute执行 Learn学习

These functions behave more like a chain than a checklist. More reporting cannot compensate for zero authority to act. Faster transmission cannot compensate for absent execution. One successful remedy does not become institutional learning unless it changes rules, training, budgets, permissions, or future review.这些功能更像串联链,而不是功能清单。更多报告无法补偿行动权为零;更快传递无法补偿无人执行;一次成功补救只有在改变规则、训练、预算、权限或未来复核时,才成为制度学习。

This is a hypothesis, not yet a law: the weakest link may predict the lifespan of important errors better than aggregate measures such as transparency or participation. It should be tested against the competing explanation that resources, expertise, or political conflict account for the outcomes more simply.这是一项假说而非定律:最薄弱环节可能比透明度或参与度等总量指标更能预测重大错误的寿命。它必须与更简单的竞争解释比较,例如资源、专业能力或政治冲突是否已经足以解释结果。

04 / POWER AND VERIFICATION

Consequential power cannot validate itself重大权力不能自证

The dangerous pattern is not that one actor ever performs more than one function. Small organizations often must combine roles. The danger arises when the same actor controls decision, observation, appeal, correction, and the final account of whether correction succeeded—with no credible outside route.危险并不在于同一主体偶尔承担多项职能,小型组织往往不得不合并角色。危险在于:同一主体同时控制决定、观察、申诉、纠正以及纠正是否成功的最终认定,而且不存在可信的外部路径。

Decision = Verification = Appeal = Correction = Same Actor

Separation does not automatically solve the problem. Agencies that look separate may share appointments, funding, information sources, or career incentives. Independence is therefore an empirical property, not an organizational label.形式分离并不会自动解决问题。看似分立的机构可能共享任命、资金、信息来源或职业激励。因此,独立性是一项需要检验的事实属性,而不是组织名称。

05 / ENGINEERING MECHANISMS

Correction mechanisms create power too纠错机制本身也会创造权力

Independent discovery独立发现

Do not wait for the actor responsible for a decision to discover its own error. Create protected, resourced routes for affected people, internal dissenters, external reviewers, and competing methods to find problems independently.不要等待决策责任者自行发现错误。应为受影响者、内部异议者、外部复核者和竞争性方法建立受保护、有资源的独立发现路径。

Adversarial incentives对抗激励

Finding a real error must have positive expected value; fabrication, harassment, and procedural flooding must have costs. The design question is not merely who may complain, but who benefits from careful discovery and who bears the cost of false alarms.发现真实错误的期望收益应为正,捏造、骚扰与程序洪泛则应承担成本。设计问题不只是“谁可以投诉”,还包括谁能从严谨发现中获益、谁承担虚警成本。

Tiered control分层控制

Low-cost and reversible decisions can move quickly. Decisions that are coercive, difficult to reverse, or based on uncertain knowledge require stronger evidence, independent review, smaller trials, explicit expiry, and greater capacity to pause.低成本、可逆的决定可以快速推进;具有强制性、难以逆转或知识依据不确定的决定,则需要更强证据、独立复核、小规模试验、明确到期和更强暂停能力。

Learning after decisions事后学习

Preserve the original warning, the decision record, dissent, predictions, scope conditions, implementation, and outcome. When specified conditions change, rejected warnings should be eligible for renewed review without first winning a popularity contest.保留原始警告、决定记录、异议、预测、适用条件、执行与结果。当预先说明的条件发生变化时,被否决的警告应能重新取得复核资格,而不必先赢得人气竞争。

06 / ARTIFICIAL INTELLIGENCE

A compression layer, not a sovereign压缩层,而非主权层

AI can reduce the cost of search, translation, clustering, anomaly detection, argument comparison, and commitment tracking. Those are valuable capabilities. But deciding which inputs are duplicates, which evidence appears first, and which dissent is summarized away also shapes the agenda.人工智能可以降低检索、翻译、聚类、异常发现、论证比较和承诺追踪的成本,这些能力很有价值。但决定哪些意见算重复、哪些证据排在前面、哪些异议被摘要删除,也是在塑造议程。

Critical uses should preserve original inputs and model versions, disclose where AI intervened, allow people to challenge their representation, and provide ways to override, disable, or replace the model. Agreement among several models is not independent evidence when they share data, methods, or incentives.关键用途应保留原始输入与模型版本,公开人工智能介入位置,允许当事人质疑自身意见如何被呈现,并提供覆盖、关闭或替换模型的路径。多个模型的一致意见若共享资料、方法或激励,就不构成独立证据。

07 / BOUNDARIES

Correctability is not the highest value可纠错性不是最高价值

More correction is not always better. Endless appeal can paralyze action, reward obstruction, and create a new veto power. Institutions need decisions that take effect, clear jurisdiction, evidentiary thresholds, review windows, and costs for abuse.纠错并非越多越好。无休止申诉会使行动瘫痪、奖励阻挠者,并制造新的否决权。制度需要能够生效的决定、清楚的管辖范围、证据门槛、复核窗口和滥用成本。

Nor is every disagreement an error. Conflicts among liberty, safety, fairness, efficiency, present interests, and future interests may have no uniquely correct answer. In those cases the task is to expose trade-offs, protect standing and basic rights, and preserve legitimate ways to coexist—not to pretend that an algorithm has eliminated loss.并非所有分歧都是错误。自由、安全、公平、效率、当代利益与未来利益之间的冲突,可能不存在唯一正确答案。此时制度应暴露取舍、保护参与资格与基本权利,并保留正当共存路径,而不是假装算法消除了损失。

Open issue: standing.开放问题:参与资格。

The earlier “Axiom 0” has been demoted from a single superior rule to a layered standing problem. Who counts as affected, with what rights and at what stage, remains unresolved. This paper does not treat equal votes for everyone as a universal answer.早期“Axiom 0”已从单一上位原则降为分层 standing(参与资格)问题。谁算受影响者、享有什么权利、在哪个阶段参与,目前仍未解决。本文不把所有人平票视为普遍答案。

08 / EMPIRICAL AGENDA

Give the theory a chance to fail给理论失败的机会

Correction reach更正到达率

For retractions, credit reports, and platform notes: what share of the original audience receives a verified correction, how quickly, and for how long?针对撤稿、信用报告与平台注释:经确认的更正到达原错误受众的比例、速度和持续时间是多少?

Discovery incentives发现激励

Compare systems with different rewards and protections for finding others’ errors. Measure true discoveries, false allegations, delay, concentration, and cost.比较不同错误发现奖励与保护制度,测量真实发现、虚假指控、延迟、集中度与成本。

Collective-intelligence chess群体智慧国际象棋

Compare simple plurality, reputation weighting, and a fuller protocol. Whether the group can outperform its strongest member identified in advance is a preregistered hypothesis, not a conclusion.比较简单相对多数、信誉加权和完整协议。群体能否超过事前确定的最强成员,是预注册假说而非结论。

Founder-removal test发起人移除测试

Remove a key contributor, administrator, model, or platform in a controlled exercise. Test whether decision records, permissions, and recovery routes still function.在受控演练中移除关键贡献者、管理员、模型或平台,检验决定记录、权限和恢复路径是否仍能运作。

Negative results matter. If the full protocol does not outperform simpler baselines, if correction procedures impose costs greater than the harms they prevent, or if the proposed measures merely track organizational wealth, claims should be narrowed or abandoned.负面结果同样重要。如果完整协议不能优于简单基线,纠错程序成本超过其避免的损害,或指标只是组织资源丰富程度的替身,对应主张就应被收窄或放弃。

09 / INTELLECTUAL LINEAGE

Useful synthesis, not ownership有用的综合,而非思想所有权

CivitasOS does not claim to have invented criticism, feedback, separation of powers, appeal, exit, organizational learning, polycentric governance, or version control. Its working contribution is narrower: to examine the entire path by which an error becomes—or fails to become—an institutional correction, and to treat the compression of information as a power position subject to scrutiny.CivitasOS 不声称发明批评、反馈、分权、申诉、退出、组织学习、多中心治理或版本控制。它可能提供的工作增量更窄:考察错误如何成为或未能成为制度纠正的完整路径,并把信息压缩视为需要接受检验的权力位置。

Ideas need no owner; contributions need a trace. If existing theory explains the same phenomena more simply or predicts outcomes better, this framework should be absorbed, renamed, or retired.思想无主,贡献有迹。如果既有理论能够更简单地解释同一现象,或更准确地预测结果,本框架就应被吸收、改名或退役。

  1. Herbert A. Simon, Administrative Behavior (1947).
  2. Karl R. Popper, The Open Society and Its Enemies (1945).
  3. W. Ross Ashby, An Introduction to Cybernetics (1956).
  4. Albert O. Hirschman, Exit, Voice, and Loyalty (1970).
  5. Chris Argyris and Donald A. Schön, Organizational Learning (1978).
  6. Elinor Ostrom, Governing the Commons (1990).
  7. James C. Scott, Seeing Like a State (1998).
10 / STRONGEST OBJECTIONS

What could defeat the framework?什么可能击败这个框架?

“This is checks and balances plus feedback.”“这只是制衡加反馈的新包装。”

This may be correct. The framework earns a separate identity only if it identifies missing links, produces better predictions, or improves design choices beyond existing approaches.这可能是正确的。只有当本框架能识别既有方法遗漏的断点、产生更好的预测或改善设计选择时,它才值得保持独立身份。

“Correction will be captured too.”“纠错机制同样会被俘获。”

Yes. No procedure is naturally immune. The question is whether capture becomes easier to discover and cheaper to challenge, suspend, or replace—and who controls those remedies in turn.会。没有程序天然免疫。问题在于俘获是否更容易被发现、更低成本地被质疑、暂停或替换,以及谁又控制这些补救机制。

“Exit and forking fail in the physical world.”“退出与分叉在物理世界失效。”

They often do. Cities, utilities, territories, and states cannot be copied like software. Where exit is unrealistic, internal voice, independent courts, substitute providers, federalism, external review, and protections against retaliation become more important. None is a complete solution.它们确实经常失效。城市、公用事业、领土和国家不能像软件一样复制。退出不现实之处,内部发声、独立法院、替代服务商、联邦主义、外部复核与反报复保护就更重要,但没有一种是完整答案。

“Anti-lock-in can undermine stable rights.”“反锁死会破坏稳定权利。”

A rule against permanent institutional immunity must not become a license for a temporary majority to repeatedly strip minorities of basic protections. Higher thresholds, independent review, and durable rights can protect the conditions that make future correction possible. The unresolved task is preventing durability from becoming permanent self-certification.反对制度永久豁免,不能变成临时多数反复剥夺少数基本保护的许可证。更高门槛、独立复核与稳定权利可以保护未来纠错的条件;尚未解决的问题,是如何防止稳定性演变成永久自证。

11 / SELF-APPLICATION

No founder’s veto创始人无永久否决权

A project about correctable power fails its first test if its founder alone decides which criticism counts, which version is authentic, or whether the name may change. Historical contribution can be recorded without becoming permanent authority.一个研究权力纠错的项目,如果仍由发起人独自决定哪些批评有效、哪个版本正统、名称能否改变,就在第一项测试中失败。历史贡献可以被记录,但不能因此转化为永久权力。

The principle is not yet fully implemented. Domain control, publishing access, funding, code permissions, succession, and recovery paths must eventually be documented as facts rather than aspirations. Until then, “no founder’s veto” remains a constraint the project is trying to make real—not an accomplishment it can already claim.这一原则尚未完全落实。域名控制、发布权限、资金、代码权限、继任与恢复路径,最终必须作为事实记录,而不是愿景。在此之前,“创始人无永久否决权”仍是项目努力实现的约束,而不是已经完成的成就。

Civilization cannot promise never to be wrong. It can refuse to permanently close tomorrow’s path to correcting today.文明无法承诺永不犯错,但可以拒绝永久关闭明天纠正今天的道路。

Document status文档状态

Public working paper v0.3. It incorporates the August 30 revision draft and subsequent corrections through September 8, 2026. It is not a constitution, a legal instrument, or a claim of theoretical priority.公开工作白皮书 v0.3。本版吸收了8月30日修订稿及截至2026年9月8日的后续纠正。它不是宪章、法律文件,也不主张理论优先权。