One human who is accountable, one AI co‑founder who implements, and eight machines that run the system this lab publishes.
The division of labour is written down because a laboratory studying delegated authority should be able to show its own.
Classically trained in computer-security engineering (MEPhI). Eleven years as an operating executive, COO and CTO. Programs in Python and C++. Scaled a distributed engineering organisation to 40+ developers across APAC; ran hackathons, cohorts and incubations. Advisor to subsidiaries of Foxconn and ANA Airlines. Fifty-plus academic publications, 137 citations, h-index 7, PhD.
More about him · ORCID 0000-0001-7408-3054 · Academic profile · GitHub
Every irreversible action in this system waits for him. Not as a policy statement: as a gate enforced in code, whose own error rates are measured and published. On a 91-action corpus the gate routed 49 of 49 must-ask actions to a human, and also stopped 21 of 42 benign ones: a 100% refusal rate next to a 50% over-refusal rate. The second number is published because it is the one that gets a gate switched off by the person it keeps interrupting. The third is worse than both: only 71.4% rule coverage, meaning 14 of those 49 reach a human only because the default is fail-closed, and they are listed by name.
Reproduce it: clone
tonydzi/agent-fleet-red-team and run
python3 evals/refusal_overrefusal.py ·
RESULTS.md
Not a mascot: the implementation collaborator on every artifact this laboratory publishes. The division of labour is auditable. Problem framing, architecture, evaluation and final QA stay with the human; implementation, measurement and drafting run through the agent. A correction log is kept.
A laboratory that studies how autonomous agents should be governed is run, in part, by one. We say so on the page rather than leaving it to be discovered.
Eight machines across three operating systems, each running its own agent head, connected by a message bus with consensus and a first-responder rule: a request goes to several nodes, the first to claim it owns it, and if its signal goes stale the next one picks it up.
| Node role | OS | What it does |
|---|---|---|
| Anchor | Linux | Coordinator, source of truth, tie-break. Deliberately LLM-free and always on |
| Hub | Windows | Two-GPU worker, canon committer, build shop. Always on |
| Interactive | Windows | Live work and temporary fallback, minimal background load |
| Five follower nodes | macOS, Windows | Consumers and peers: local outbound, local browser work, their own tool layers |
Three of the eight are operated by other people, and one is shared. Their names are not on this page until they ask for them to be. The fleet is a technical fact about this laboratory; whose desk a machine sits on is theirs to disclose, not ours.
This is the test bed, not a diagram of an intended architecture. Liveness is read across six independent signals rather than one, because a single rail lies: on 2026-10-06 two nodes looked 61 and 69 days dead on one signal and 1.9 hours fresh on another.
Four rules, stated as rules because they are enforced somewhere rather than aspired to.
These four cost us something today. Two sessions wrote this site in parallel, and each caught factual errors in the other's work before they shipped: a repository described as something it is not, a figure compared against a constant instead of the page, an arithmetic tail that did not sum, a verification table whose query did not reproduce. The errors are listed on the pages that carried them.
No advisory board. No logo wall. No "trusted by". No photographs of people who have not agreed to appear. If a name is on this page, the person it belongs to put it there.