Research · Tag · Earned Autonomy

Posts tagged earned autonomy.

10 entries · sorted: recency← All research
EARNED-AUTONOMY
2026-07-28

Beyond Zero answers what the machine decides. It does not answer who said it could.

Google's Beyond Zero moves the trust boundary from the application to the individual action and puts a reasoning layer in the access path. The objection that landed on Hacker News, that a non-deterministic evaluator does not belong there, is aimed one layer too low. The gap is not determinism. It is legitimacy: nothing establishes that a given system has the standing to act in your environment, against your traffic, under your conditions. Vendor-asserted accuracy is not evidence.

Simon Morley
Read →5 min read
SUBSTRATE
2026-04-26

Introducing Substrate: An Open Format for Validator Threat Intelligence

Validator threat intelligence has no shared format. We're publishing a bundle spec, a ten-family taxonomy, and seeding a 1,092-bundle corpus to fix that.

Simon
Read →7 min read
SUI
2026-03-13

What We Found Scanning the Sui Validator Network

We scanned 138 Sui validators across 20 countries using kernel-level temporal fingerprinting. 41% have SSH exposed, 57 run unexpected internet-facing services, and 9 confirmed CVEs sit on 4 hosts, including 2 critical at CVSS 9.8. Here is what we found and why it matters for DeFi.

Simon
Read →6 min read
OPEN-SOURCE
2026-02-26

Open-Sourcing Our Autonomous Defence Arsenal: Here's What's Inside

We're open-sourcing the tooling behind NullRabbit's autonomous kernel-level network defence: the scanning, intelligence, observation, and adversarial validation layers that feed our enforcement pipeline. Six tools, MIT licensed, with more coming.

Simon
Read →5 min read
EARNED-AUTONOMY
2026-02-13

Why Autonomous Enforcement Must Earn Authority

The technology to defend networks autonomously exists. The legitimacy to deploy it does not. Introducing earned autonomy: a governance framework where defensive authority is demonstrated before granted, scoped per abuse class, and continuously re-earned or revoked.

NullRabbit Research
Read →9 min read
EARNED-AUTONOMY
2026-02-05

Building the Jig (Again): Claiming the Time Dimension

Inline defence without understanding is guesswork. Before machines act, they need evidence. Why we're open-sourcing our scanning system, building jigs instead of shortcuts, and claiming time as a first-class signal in infrastructure security.

NullRabbit Research
Read →4 min read
EARNED-AUTONOMY
2026-01-28

Earned Autonomy: The Paper

Machines attack at machine speed. Humans defend at human speed. The technology to close this gap exists - the governance doesn't. A framework for when machines should be permitted to act without human approval.

NullRabbit Research
Read →2 min read
EARNED-AUTONOMY
2026-01-21

Validating Inline Enforcement with XDP: IBSR and the Path to Earned Autonomy

Inline enforcement operates at machine speed, but trust cannot. IBSR is a validation step: using XDP to observe real traffic, simulate enforcement, and generate evidence before any blocking is enabled.

NullRabbit Research
Read →4 min read
EARNED-AUTONOMY
2026-01-16

Earned Autonomy: A Governance Framework for Autonomous Network Defence

Autonomous mitigations already act at machine speed - but we still have no legitimate framework for granting them authority over novel threats.

NullRabbit Research
Read →2 min read
EARNED-AUTONOMY
2026-01-13

On Earned Autonomy: When Should Machines Defend Networks Without Asking?

Machines attack at machine speed. Humans defend at human speed. We propose a governance framework for closing that gap, not through blind trust but through demonstrated competence.

NullRabbit Research
Read →4 min read