Trust model. Every result here is mechanism-existence under stated dials: "this rule closes this specific failure mode under these assumptions" — never a forecast, never a guarantee. Pass/fail bars were registered in writing before each engine ran. Dials and sweep ranges are enumerated in the replication kit's ASSUMPTIONS LEDGER.
Provenance, stated plainly. Every artifact behind this paper — simulations, proofs, verification passes, and this text — was produced by the owner working with AI models, and until July 2026 only models from that same family had checked it. On July 31, 2026 the work received its first outside check: an out-of-family AI reviewer (5.6 Sol), given only this site and the public replication kit, independently re-ran the full harness — 72 of 82 discovered programs reproduced within tolerance, none verdict-reversing under its classification — and published a critical review, hosted unedited with our response on the independent reviews page. That is machine replication and machine criticism, not human review. The program's own standard remains verify, don't trust, and its two standing obligations are what this document exists to invite: hostile human review and field evidence.
Reading paths. Full read ≈ 60–90 min. The 15-minute skeptic's path: this section → §10 Failure log → §11 Demotions → §12 Open items. The failures are not in an appendix; they are the spine.
Status vocabulary (every claim carries exactly one):
Every claim card is anchor-linkable (cite /paper#C-10, not a paragraph) and ends in a kit path so any number can be traced to the results file and code that produced it in two clicks. TODO markers are unmined CLAIMS-REGISTER keys — present in the kit, not yet wired into this draft.
Nearly all new money enters the world as bank credit — created when banks lend, extinguished as loans repay. That system supports productive credit, but it can distribute new purchasing power unevenly and amplify asset cycles, and whether its gains reach people whose main asset is their time is a distributional outcome, not a design guarantee. What is not in question: human creative output — the writing, data, and code that now train AI systems — is priced at zero and harvested as free raw material. None of this requires a villain, and none of it is hidden. It is a design. This paper specifies a complement — not a replacement — and reports how it has been tested.
Goals. (1) Give every verified person an income-bearing asset: their data, creations, and genuine attention. (2) Make machine and institutional use of human work a payment event, permanently. (3) Reward transparency so honesty out-competes opacity on economics rather than enforcement. (4) Keep wealth earnable but not inheritable or purchasable, so mobility replaces dynasty. (5) Remain optional at every step.
Non-goals, stated as hard boundaries. Not a replacement for the dollar — promises are denominated in goods; dollars remain the pricing language at the interface. Not a token sale: there is nothing to buy, and the unit cannot be purchased into existence. Not a new internet: an overlay changing four layers of the one we have — monetization (creators paid natively when work is used), discovery (neutral retrieval, disclosed ranking), identity (one portable, self-owned identity), provenance (signed, checkable origin) — while transport, hosting, browsers, devices, jobs, and dollars stay where they are. And not a promise of a safety-net floor (§09).
Rule 0: humans mint; machines pay. New currency is created in exactly one circumstance — a verified human genuinely engaging with real work — and the mint event pays the work's creators automatically. Machine and institutional actors can hold and transfer existing units but can never occupy the minting position; the prohibition is enforceable in code, which is why "never" is used here and almost nowhere else. The money supply is anchored to verified human time and attention — an anchor whose robustness against live adversaries (identity, H-2) is the program's single load-bearing open question.
Digital work is free at the door. Creators are paid per use rather than charging tolls. Payouts follow a decay ladder — heavily-used work earns broad-and-shallow — with two ratified companions: per-buyer cumulative pricing (one buyer's aggregate pull gets more expensive, not cheaper, so bulk extraction never rides the popularity discount) and the minimum ask (a non-waivable, essentials-indexed floor on personal-data prices; above it, owners price freely; launch value stays at canon's conservative 1e-4 with the calibration method ratified and the number pilot-gated).
Custody is freshness-matched (DR-20). Declared commons stay freely copyable (K0). Short-half-life data — live market and behavioral streams, below τ* ≈ 4.35 years — may leave under priced export licenses, because staleness itself is the moat (K1). Long-half-life data, the stores actually worth stealing, never leaves: compute-to-data access with per-buyer cumulative egress budgets (K2). Individual-granularity-sensitive data is aggregate-only (K3).
Every non-human actor — a lab training a model, a company, a personal AI assistant reading someone's work on a user's behalf — participates as a payer. Capability growth therefore translates into payment flow toward the humans it learned from. Corporations coordinate; they never own the mint-anchor (DR-18): a firm can organize, fund, and profit from collective work through a capped coordination cut (ceiling 25%) for a bounded term (30 years), with income streams anchored to the human contributors. The transparency principle is privacy for people, transparency for power: individual reading and browsing stay private (read-logging was measured and declined); value flows are public.
Each person holds one lifetime identity (the keystone assumption — H-2). Income streams are non-transferable: they cannot be sold, bought, or inherited. Success and wealth remain fully achievable — they must simply be continuously earned, because no one can purchase another's money-making machine or bequeath their own.
Minting anchored to human attention is a faucet that never closes by itself. The first full simulation proved exactly that — and the repair is a formula, not a committee. This section carries four claims; two of them are failures we keep.
Support that tops everyone up to the same line makes marginal effort worthless below it. The second registered failure proved it, and the repair is a taper whose no-cliff property is machine-checked, not asserted.
The most dangerous adversary isn't lazy. The third registered failure came from an adversarial audit that modeled smart thieves — and the repair is three interlocking economic locks rather than surveillance, because surveillance was tested on its own terms and lost.
Rules change by formula and jury, not by executive. Disputes and parameter changes route through sortition juries of verified persons; structural change requires two-house concurrence — one-person-one-vote alongside a contribution-weighted house with hard caps. An early cap leaked 9.4% of influence as first written; fixed, and disclosed as a failure (card C-46, §11). All governance actions, like all value flows, are public.
The project set out to guarantee everyone's essentials. Stress-testing returned the program's largest honest negative, and the design bends to it rather than around it: the floor is published as a fully-specified, separately-funded module — reserve mechanics visible on-ledger, activation by formula, staged delivery tied to funding — that any community, government, or coalition can adopt and run in public. A progress bar, not a pledge.
Failure was defined before any test ran: if the poorest tenth can't afford essentials for three consecutive months, the design fails. Months were then spent trying to cause exactly that. It worked, three times. Full plain-language history: /evidence.
The program's verification passes re-run everything and re-score downward where re-runs disagree. The current record is the post-correction one; earlier circulating numbers are superseded by the cards below.
Stage 0 — deployment & identification strategy (EdenQuest). The program's first live artifact is deliberately non-monetary: EdenQuest, a free, local-first personal-data app with non-transferable in-app points under a ratified no-conversion rule, live in public form (product-surface details are audited in the independent reviewer's app assessment, hosted on the reviews page). It activates none of the layers this paper analyzes — no EVE, no data commons, no lifetime economic identity — and its role in the research design is identification: it is the registered instrument for the behavioral dials every simulation treats as exogenous (genuine-vs-gamed contribution, wash behavior under rewards, liveness drop-off, motivation crowding-out) and the recruitment substrate for the willingness-to-pay experiment (H-1). The ratified bridge specification (gates G1–G5) separates it from every monetary layer; entry into any future data commons is a separate, default-off, revocable decision. Its adoption is evidence about product value and data-production behavior only — never about EVE demand.
Bars before code. Every engine's pass/fail bars were fixed in writing before the engine was coded; failures were published as failures, and three forced full public redesigns. The lineage runs v1–v39 with lettered sub-waves (and two distinct v13 engines — Oracle and Ecology — noted to prevent citation confusion). Verification passes v2–v6 re-executed the record and re-scored downward where re-runs disagreed; §11 carries the results.
Reproducibility is verified, not asserted. verify_all.py (python ≥ 3.10; numpy, scipy, matplotlib, sympy) re-runs every discovered engine and prints a per-engine ledger; the canonical July 31, 2026 owner-machine run reproduces 73 of 82 within tolerance and the independent out-of-family run 72 of 82 (C-45), every exception classified; dated ledgers and a LATEST.json pointer ship in the kit. Every headline traces from the CLAIMS REGISTER to a committed results file to the code that produced it. The reviewer guide ships a two-day hostile plan: day one, read (this paper, then the red-team scorecard, then the ledgers); day two, re-run and attack. Different numbers on your hardware is a finding we want filed.
What "in-family" means, and why it's on every page. All artifacts were produced by the owner working with AI models (Anthropic Claude; per-artifact attribution recorded as uncertain after a mid-session model switch — the provenance note travels with the index). In-family verification can catch arithmetic and internal inconsistency; it cannot substitute for hostile, out-of-family review or field evidence. Those are the program's two standing obligations, and this document is the instrument for the first.
Attack the assumptions, not the arithmetic — the arithmetic reproduces mechanically (C-45), and different numbers on your hardware is a finding we want. The six standing questions per artifact: does it trust an input it doesn't control; static vs adaptive adversary; any "by construction" tells; off-protocol flanks; correlated failures; does transparency break it.
Highest-value targets, in our own estimation: the WTP anchors (H-1 — improve the experiment or show it can't work); the incidence chain (who ultimately pays for machine participation); essentials-index composition governance (C-12); the austerity-threshold contract framing (C-40); and grading the red-team's self-grades (O-2).
Filing findings: against named artifacts (file + JSON key) wherever possible — they can be verified in minutes. Findings are published with named credit; a finding that forces a canon change is the product working, not an insult. Engagement terms for commissioned review (fixed fee, published verbatim whatever it concludes) available on request: devan@ai-realized.com.
Cite: Allen, D. (2026). Minting Money from Verified Human Engagement: Design and Pre-Registered Adversarial Testing of an Exploration-Driven Economic Network. Release 1, paper v2.0 (web). explorationeconomy.org/paper — cite claim anchors (e.g., /paper#C-10) rather than page sections. DOI: TODO — Zenodo snapshot per release.
Changelog: v0.2 (July 24, 2026) — all sixteen sections assembled; 24 claim cards live (C-10…C-60, H-1/H-2, O-1/O-2); all three demonstrations embedded; CLAIMS-REGISTER keys still unmined (TODO markers). v0.1 (July 24, 2026) — first assembled draft; nine sections stubbed. Underlying text: Design Paper v2.0, ratified July 24, 2026 (owner, provisional), including the five ratification corrections (custody K-classes; DR-18 ceiling; DR-21 look-through; DR-22 conduct-claim class; red-team 4/6/0).