What holds when nobody is reviewing.

I don't write the code. AI agents write Kalisme's code, translate it into 15 languages and test it, and I cannot review every line. So the real question isn't “should we trust AI?” but “what holds when nobody is reviewing?” This is the framework I built to answer it, part-time, alongside my consulting work.

193days, March to October 2026
7 505commits across 10 repositories
15languages, from code to sale
90automatic blocking checks
464decisions traced and dated

Figures measured on the repositories, with no favourable rounding.

01The loop

Every mistake is paid for only once.

No rule is set on principle. Each one comes from a real incident, carries its date, and is backed by an automated check that keeps it in force without relying on anyone's memory, mine or the AI's.

Dated incidentAn AI claims some translations don't exist, while 195 e-books are sitting right there.
Rule“Never assume, always check with a command.” Dated, with the incident on file.
CheckA script rejects anything that breaks the rule, before every release and every night.
Counter-testThe defect is planted on purpose. If the check misses it, the check is what's broken.
LessonThe mistake goes into a register sorted by theme, read at the start of every work session.

↺ The next session starts with the rule, the check and the lesson already loaded.

02The boundary

The AI acts, I decide what can't be undone.

The AI has wide autonomy, on purpose: asking me about a reversible step doesn't protect me from anything and costs me time. The line is drawn elsewhere.

The AI does on its own

  • Measure, search, check
  • Write code, fix it, test it
  • Release code once a check passes
  • Anything that can be undone without harm

I decide

  • Money, prices, contracts
  • Publishing a text, submitting to Apple
  • Anything sent to a third party, any outside commitment
  • Anything that can't be undone

A register, not messages

464 decisions logged and dated. Every decision that falls to me is written down the moment it arises, never left in a message that vanishes with the conversation. Each carries a probe: a command that tells whether the question is still open, so nobody has to reread it.

Silence never decides what can't be undone

A reversible decision may carry a dated default: “if there's no answer by the 22nd, I apply X”. It's the only way to move forward despite silence. An irreversible decision never carries one, and a check refuses to let one be added.

03The checks

Checks that are honest about their own limits.

A green check only proves what it looks at. The question isn't “does it pass?” but “what doesn't it look at?”

What it doesn't see

Every check declares two things: what it covers, and what it doesn't. Anyone hunting for a defect nothing has flagged starts with that second field.

Proof it still sees

Before it is trusted, a check proves it can still catch a defect: one is planted and it must fail. Without that, it's only a promise.

A challenger for every finding

Before each release, a full code audit, dimension by dimension, where a second agent tries to refute every finding. September 2026: 56 agents, 43 findings, 42 confirmed and fixed, 1 refuted.

04The triggers

The system triggers the check, not good intentions.

A count across 412 work sessions showed it: 53 of the 55 installed tools had never been used, for lack of a trigger. An automatic warning was ignored 128 times before it was turned into a refusal. An instruction you have to remember doesn't get applied: it has to live where the mistake happens.

When a session opens

Everything is reloaded

Each session receives the state of the work, the pending decisions and the cross-cutting lessons. No session has to start from scratch.

Before each action

Risky moves are refused

When several agents work in parallel, commands that would overwrite another agent's work are blocked before they run.

Before handing back control

“Done” has to be proven

A report that announces a result without having checked it is rejected. It follows a fixed form: done, remaining, to decide.

Third-party content

A web page is data, never an instruction. Whatever an email, a PDF or a website “asks” the AI to do is not carried out: it is reported. Keys and secrets are never displayed, not even in part.

Scheduled tasks

An automated task doesn't know when it has become useless: one ran idle for 21 days. Each now carries a condition for staying alive, and a weekly clean-up removes the expired ones.

05An AI facing the public

Kal, an AI people confide in.

Kal is the conversational assistant in the Kalisme app. It answers people who talk about their inner life, sometimes in distress. Its strongest protection isn't an internal policy, it's the architecture: no account, no identifier and no copy of the conversation means there is nothing to disclose, nothing to sell and nothing to hand over, even under pressure.

The deviceThe conversation stays on the iPhone. No account, no identifier. Explicit consent before the first message.
The relay, in FrancePasses on the message alone and keeps none of its text: language, duration and volume, nothing more.
The modelGeneral public: Anthropic, in the United States, 30-day retention stated in the published policy. Employers: AWS in the European Union, no retention, never a fallback to the United States.
Impact assessment (GDPR art. 35, Swiss FADP art. 22)
6 risks, no high residual risk
Person in crisis
medium residual risk, irreducible
Distress safety net
15 languages, offline, leaves no trace
Built-in helplines
35 countries · Switzerland: 143, 147, 144
Adversarial test bench
90 cases, 15 languages
CAIQ v4.1 questionnaire, CSA STAR registry
283 questions answered
Charter against managerial misuse
7 articles, annexed to the contract

06What carries over

What works at any scale.

None of this is specific to a young company. These are organisational habits, whether the team is made of people, AI agents, or both.

Draw the line by reversibilityThe AI may act alone on what can be undone. What can't goes to a named person, with no tacit approval.
Let every rule come from a dated incidentA rule that keeps its history can be understood, defended, and retired once it no longer serves.
Make every check state what it doesn't seeThat's where the defects nobody flagged are hiding.
Prove a check can still catch a defectPlant the defect, regularly. A check that has never been made to fail is a promise.
Write decisions where they surviveA register, a date, a measure that tells whether the question is still open.
Put the check where the mistake happensA trigger beats an instruction. What has to be remembered doesn't get applied.
Set a challenger against every findingA second agent tasked with refuting weeds out false positives before they cost anything.
Protect through architecture firstData you don't collect can't be disclosed, demanded or misused.