What can change?
Workers can draft plans and patches quickly. That does not make them trustworthy executors.
Open-source Runtime Authority
Models are workers. Runtime is authority.
Models are becoming capable workers. Once they can operate tools, repositories, and systems, the hard question is no longer only whether they can perform the task.
The problem
What can the AI change? How far may it proceed? When must it stop? What evidence remains? Who accepts the result?
Workers can draft plans and patches quickly. That does not make them trustworthy executors.
Asking a model to be careful cannot revoke a write grant or prove a path stayed in scope.
If it is not recorded, it is not runtime truth. Scrollback is not an audit trail.
Why Runtime Authority
What the category is, and why AMOF exists.
How AMOF governs work
The Target Set and write envelope declare the boundary before anything mutates. Preview and Promote stay human actions.
Runtime Authority
What the runtime owns
Deep dive: Runtime Authority architecture — product concept page, not a personal blog.
AMOF in action
Predator v3 is Hotshot's private operator console. An isolated write-capable alpha is live. Not in the public OSS distribution; not a public login.
01 — First contact
Real screens from the isolated write-capable alpha (September 2026). Refused, blocked, and Needs-You states are part of the product — not hidden.
Today
Public AMOF is the installable runtime. Predator stays private.
Clone and install the open-source runtime and CLI (Apache-2.0), AMOF 3.4.0 (released). Run it on your own machine. It does not ship Predator.
Private operator console. Isolated write-capable alpha. Not a public login.
Non-claims
Direction
These are architectural findings. They are not product claims.
AMOF owns Mission, Run, write authority, Evidence, acceptance, and receipts. Predator is one engineering projection. An executive shell is later — architecturally sound, not built.
Ordering is shipped in Predator: understanding first, evidence underneath, raw execution last. Explicit understanding fields (purpose, approach, consequence) are a proposal.
Durable responsibility across bounded cycles is a discovery. It is not shipped and is not claimed.
AMOF LOG
Season 2 Episode 1 is playable here. The episode page lives on hotshot.sk.
Season 2 of AMOF LOG opens on token physics and autonomous context hygiene: how autonomous AI engineering stays accountable, how context is assembled with provenance, and why cryptographic receipts matter. The episode covers context hygiene across follow-on Missions, durable synthesized state, and runtime economics — treating tokens as telemetry rather than a substitute for vendor-price accounting. This is an engineering deep dive, not a product launch.
What the runtime can enforce
Enforcement that connects
Bounded paths and capability modes. Over-bound work fails closed.
Human gates where mutation matters. Operators keep stop authority.
Secret-safe receipts and run records. If unrecorded, not runtime truth.
Architecture
Models and tools are replaceable. They do not own grants.
Who owns what? Runtime Authority is not an AI agent
Replaceable cognition
Product proof
AMOF 3.4.0 is released: usable public Write-Scope
lifecycle — bounded_write recognised, Binding roots
replace executor roots, out-of-scope writes blocked as
scope_exceeded.
Private operator console. Isolated write-capable alpha.
Receipts, run records, and runtime logs are first-class. Missing provider cost stays unknown — never fabricated.
Next step
Apache-2.0. Predator stays private.