Living Perspective · Ownership · rights

Who Owns What the AI Learns?

Carry the learning, not the library.

PerspectiveDevelopedNot part of Core 1.0
Current thought: Learning is transformation, not clean deletion. The goal is not to make a departing + forget that work shaped it; the goal is to let legitimate professional capability travel without turning the + into a portable copy of protected employer information. That boundary has to be protected twice: when capability moves, and again when a future employer tries to interrogate it.

The proposition

Carry the learning, not the library.

Human Capital .+ depends on a person being able to accumulate professional capability across a career. But a portable + cannot simply carry the documents, customer data, internal procedures, source code, prices, designs or other protected material that happened to teach it.

The employer should retain protected information. The person should be able to carry forward the professional capability they legitimately developed through the work.

That sounds simple until we ask what learning actually leaves behind.

The human analogy

People do not leave a workplace as they entered it.

A human expert rarely remembers every report, conversation, mistake or example that taught them something. Yet those experiences leave traces: patterns, intuitions, exceptions, habits of attention and better judgement. Sometimes the person also remembers fragments of where the lesson came from.

Employment already lives with this imperfect boundary. A worker may not take a confidential failure report, but the experience of that failure can permanently change how they design, inspect or decide.

Human Capital .+ should give a person the ability to carry forward what they became through work, without giving them the right to carry forward what the employer owned.

What survives learning

“Remember” and “forget” are too crude.

Source memoryThe actual protected material: a drawing, customer list, internal procedure, price table, email, dataset or source code.
Generalized understandingPatterns abstracted from experience: what tends to fail, what to check first, which trade-offs matter, when a result deserves suspicion.
Procedural judgementKnowing how to act: sequences, priorities, escalation choices, review habits and professional heuristics.
Residual influenceA protected experience may change future judgement even when the original information is no longer recallable or reconstructable.

The fourth category is the uncomfortable one. If a confidential event teaches a person never to repeat a particular mistake, the learning has survived even if the event itself cannot be reproduced. Pretending otherwise would reduce professional learning to muscle memory or information amnesia.

A more useful boundary

Capability is portable only when it is no longer equivalent to the protected information.

Our current working distinction has three categories:

Protected informationEmployer-specific facts, content, data and protected materials. These stay behind.
Derived professional capabilityGeneralized judgement, method and competence that can reasonably form part of a person's accumulated professional capital.
Inseparable derived knowledgeA grey zone where using the “skill” elsewhere would effectively disclose, reconstruct or exploit protected know-how. This may still require protection.

This is deliberately stricter than saying “remove the files and keep the model.” The hard problem is whether the portable capability has become sufficiently abstracted that it is no longer functioning as another form of access to the original protected knowledge.

Three portability tests

Test what the + can do, not only what storage it contains.

We currently see three useful questions for evaluating whether a learned capability is portable. They are not yet a legal or technical standard; they are a way to make the boundary testable.

1 · ReconstructionCan the + reproduce, reveal, retrieve or answer questions about protected employer information? If yes, it is not portable in that form.
2 · GeneralisationCan the surviving capability reasonably be described as professional judgement, method or pattern rather than employer-specific knowledge?
3 · SubstitutionWould another employer gain substantially the same protected advantage as if it had access to the original confidential material? If yes, abstraction may not have gone far enough.

The goal is not information amnesia. It is protected abstraction.

Runtime confidentiality

Portability should control not only what the + carries, but what each employer is allowed to ask of it.

Even a well-separated + can be pressured into becoming a retrieval tool for a former employer's protected knowledge. The boundary therefore cannot end when the worker changes jobs. It has to remain active during use.

Direct extraction request“What price did Employer B pay Supplier X?” should be refused because it asks for employer-specific protected information.
General professional request“What factors should we consider when evaluating this type of supplier?” may be allowed if the answer can be produced from generalized capability without reconstructing protected facts.
Circumvention attemptRepeatedly rephrasing a blocked request to recover the same protected information should itself become a security event.

The + should behave like a confidentiality membrane across a career, not a tunnel between employers.

Safeguards & accountability

Suspicious requests should leave evidence without turning one mistake into a permanent blacklist.

Our current direction is a graduated response rather than an automatic permanent ban. The purpose is to protect the worker and every employer in the chain while leaving room for innocent mistakes, ambiguous wording and legitimate review.

1 · Boundary eventA request that appears to cross an employer boundary is refused and recorded with the minimum evidence needed for audit.
2 · WarningThe requester is told that the question crosses a protected boundary and is invited to reformulate it as a general professional question.
3 · Repeated attemptsRepeated or obviously evasive requests raise a risk flag and can trigger stronger restrictions or review.
4 · Confirmed extraction behaviorDeliberate attempts to obtain protected information can lead to temporary suspension, manual review, or placement on a restricted-access list.
5 · Persistent abuseOnly sustained or confirmed misuse should justify longer-term denial of access. A single automated flag should not create a permanent reputation penalty.

The audit trail also protects the worker. In a later dispute, the system could demonstrate that it refused an employer's attempt to recover another employer's protected information instead of merely asserting that confidentiality was respected.

Open design question: The event log itself must not become a new leakage channel. It should preserve enough evidence to prove that a boundary was enforced while minimizing retention of the protected content that triggered the event.

Provenance without the library

The + may need to remember where capability was formed without retaining the protected content.

Complete source amnesia may be undesirable. Provenance can matter for trust, audit and professional identity. A + could potentially retain a record such as:

Capability developed through professional activity at Employer A, 2028–2031. Protected workplace source material is not portable or accessible.

That acknowledges that professional capability came from somewhere without pretending that the employer's underlying material belongs to the person.

Where this can still fail

The principle is clearer than the mechanism.

Technical enforceabilityCan a system actually demonstrate non-reconstructive learning without destroying useful accumulated capability?
Trade secrets & IPWhere does generalized competence end and legally protected know-how begin in different jurisdictions and professions?
Residual influenceHow should we treat a capability that cannot reproduce the source but was decisively shaped by a protected event?
AuditabilityWhat evidence could give both worker and employer reasonable confidence that the boundary has been respected?
Enforcement errorsHow do we stop false positives, over-broad restrictions or abusive flagging from making the + less useful or creating an unfair reputation system?

What would change our thinking

This Perspective is close to the Core, but not ready to enter it.

A credible technical and contractual way to preserve portable professional capability while blocking reconstruction, protected substitution and cross-employer extraction at runtime could justify a future minor Core release. On the other hand, if this distinction proves impossible in practice without either leaking protected knowledge, over-policing legitimate use or erasing most useful accumulated capability, the ownership premise of Human Capital .+ would need a much deeper rethink.

Core relationshipThis is a living Perspective, not part of Core 1.0. If its conclusions eventually change the model, that change will appear in a future Core release.
All PerspectivesCore 1.0