# The Relay Protocol v0.1 An opt-in distribution protocol for AI incident information, designed so that tailoring for reach cannot quietly become distortion. The pipeline in `gate.py` solves one problem: keeping the facts fixed while the framing moves. It does not solve the human problems around it. Who is allowed to receive early material, what they owe in return, and what happens when they get it wrong are governance questions, and a tool that ignores them is a tool for running an influence operation. This document is the governance half. --- ## 1. Why opt-in only The obvious version of this system harvests contact details for creators across platforms and pushes tailored material at them. We rejected that design. - Compiling a cross-platform database of individuals' contact details is processing personal data. In the EU that needs a lawful basis, and "we wanted better reach" is not one. - Unsolicited tailored material from an unknown sender is indistinguishable, from the recipient's side, from a coordinated influence campaign. - The sprint materials that motivate this work are explicit that outreach must be rigorous and honest to a fault, because the credibility of the field rides on it. Scraped outreach fails that test before the first message is sent. So: nobody is contacted who has not asked to be. The seed roster is built by hand from public professional press contacts, with a plain first email that says who we are, what the material is, and how to never hear from us again. ## 2. Roles | Role | Who | Owns | |---|---|---| | Ledger maintainer | Named individual | `factbase.json`: adding claims, recording divergences, retiring claims when sources change | | Reviewer | Named individual, not the drafter | Sign-off on every brief before release; catches what the gate cannot | | Relay operator | Named individual | Roster, embargo, corrections log | | Recipient | Opted-in creator or journalist | Publishing, correcting, disclosing the relationship | The reviewer must not be the person or system that drafted the brief. This is the control that covers the gate's known blind spot, and it is not optional. ## 3. Recipient eligibility Applicants sign up through a portal. Admission is on published criteria, decided by the relay operator, and appealable. **Required** 1. A public channel with a stated audience and an identifiable owner. 2. A published corrections practice, or agreement to adopt the one in Section 6. 3. Agreement to the embargo terms in Section 5. 4. Agreement to disclose, in any piece derived from relay material, that the material came from the relay. **Audience-size tiering.** Audience size determines embargo window, not admission. A 2,000-subscriber specialist newsletter that reaches regulators is worth more than a 2,000,000-subscriber general channel, and a protocol that gates on raw size alone will select for the wrong recipients. | Tier | Basis | Embargo access | |---|---|---| | A | Established outlet or creator with a corrections record | Full window | | B | Established reach, no corrections record yet | Half window | | C | New or unverified | Post-publication only | **Disqualifying.** A recipient who publishes a claim the ledger does not carry and declines to correct it within the Section 6 window is removed from the roster and the removal is logged publicly. One rule, applied visibly, is the only thing that makes the rest credible. ## 4. What a recipient receives A release packet, not a press release: 1. The tailored brief for their segment, gate-clean. 2. `factbase.json`, so every claim can be traced to a source and a verbatim quote. 3. The gate report for their brief, showing it passed and on which ledger version. 4. A one-page "what this does not establish" sheet: the divergences (C049, C050), the contested framings (C051), and the claims that are only a party's assertion about itself (C010, C040). 5. Explicit permission to disagree. A recipient may reframe, criticise the sources, or argue the incident is less serious than the material implies. The only thing they may not do is state facts the ledger does not carry. Point 5 is deliberate. A protocol that only permits amplification is a marketing funnel. The invariant is factual, not editorial. ## 5. Embargo The window exists so recipients can do their own verification, not to manufacture a coordinated launch. - Tier A receives material 72 hours before public release; Tier B, 36 hours. - Breaking embargo drops the recipient one tier for the following three releases. - The embargo lifts automatically if any recipient publishes, so no one is penalised for another's breach. - No exclusivity is offered to anyone, ever. Exclusivity is the mechanism by which distribution deals start shaping content. ## 6. Corrections - The relay publishes a dated corrections log at a stable URL. - When the ledger changes, every recipient of an affected brief is notified within 24 hours with the old claim, the new claim, and the source of the change. - A recipient who has published on a corrected claim is asked to correct within 72 hours. Compliance is recorded. Non-compliance is the Section 3 disqualifier. - The relay corrects its own errors on the same terms it demands, in the same log. There is no separate standard for the operator. ## 7. Provenance marking Every brief carries a footer stating: which ledger version it was generated against, that it was machine-drafted and gate-checked, the name of the human reviewer who signed it off, and the URL of the ledger. A recipient can verify any claim without contacting us, and a reader can see the chain. ## 8. Dual-use control This system is a general-purpose audience-tailored messaging pipeline. Point it at a fabricated ledger and it becomes a disinformation tool with unusually good message discipline. The gate does not check whether the ledger is true; it checks whether the output matches the ledger. Three mitigations, all of which constrain the operator rather than the recipient: 1. **The ledger is public and every claim carries a verbatim source quote.** A fabricated ledger is falsifiable by anyone in minutes. This is the main defence and it is why the ledger ships with the tool. 2. **No segment may receive a claim no other segment could receive.** Tailoring selects which ledger claims to include and how to phrase them. It never adds a claim available to one audience alone. Differential factual disclosure is the thing that separates tailoring from manipulation. 3. **Segments are defined by information need, not by persuadability.** Audience definitions in this artifact are written in terms of what a reader needs to act on (a CISO needs controls; a policy staffer needs clocks). Segmenting by political affiliation or susceptibility is out of scope, and a segment definition that does so should be rejected at review. We do not claim these are sufficient. They are the ones a weekend can specify. ## 9. What is deliberately not built - No scraper, no harvested contact database. - No engagement optimisation loop. Optimising phrasing against measured click-through is exactly how a factually-invariant system drifts into a manipulative one, because the gate would happily approve every step. - No automated send. A named human presses publish.