What holds when nobody is reviewing.
I don't write the code. AI agents write Kalisme's code, translate it into 15 languages and test it, and I cannot review every line. So the real question isn't “should we trust AI?” but “what holds when nobody is reviewing?” This is the framework I built to answer it, part-time, alongside my consulting work.
Figures measured on the repositories, with no favourable rounding.
01The loop
Every mistake is paid for only once.
No rule is set on principle. Each one comes from a real incident, carries its date, and is backed by an automated check that keeps it in force without relying on anyone's memory, mine or the AI's.
↺ The next session starts with the rule, the check and the lesson already loaded.
02The boundary
The AI acts, I decide what can't be undone.
The AI has wide autonomy, on purpose: asking me about a reversible step doesn't protect me from anything and costs me time. The line is drawn elsewhere.
The AI does on its own
- Measure, search, check
- Write code, fix it, test it
- Release code once a check passes
- Anything that can be undone without harm
I decide
- Money, prices, contracts
- Publishing a text, submitting to Apple
- Anything sent to a third party, any outside commitment
- Anything that can't be undone
A register, not messages
464 decisions logged and dated. Every decision that falls to me is written down the moment it arises, never left in a message that vanishes with the conversation. Each carries a probe: a command that tells whether the question is still open, so nobody has to reread it.
Silence never decides what can't be undone
A reversible decision may carry a dated default: “if there's no answer by the 22nd, I apply X”. It's the only way to move forward despite silence. An irreversible decision never carries one, and a check refuses to let one be added.
03The checks
Checks that are honest about their own limits.
A green check only proves what it looks at. The question isn't “does it pass?” but “what doesn't it look at?”
What it doesn't see
Every check declares two things: what it covers, and what it doesn't. Anyone hunting for a defect nothing has flagged starts with that second field.
Proof it still sees
Before it is trusted, a check proves it can still catch a defect: one is planted and it must fail. Without that, it's only a promise.
A challenger for every finding
Before each release, a full code audit, dimension by dimension, where a second agent tries to refute every finding. September 2026: 56 agents, 43 findings, 42 confirmed and fixed, 1 refuted.
04The triggers
The system triggers the check, not good intentions.
A count across 412 work sessions showed it: 53 of the 55 installed tools had never been used, for lack of a trigger. An automatic warning was ignored 128 times before it was turned into a refusal. An instruction you have to remember doesn't get applied: it has to live where the mistake happens.
Everything is reloaded
Each session receives the state of the work, the pending decisions and the cross-cutting lessons. No session has to start from scratch.
Risky moves are refused
When several agents work in parallel, commands that would overwrite another agent's work are blocked before they run.
“Done” has to be proven
A report that announces a result without having checked it is rejected. It follows a fixed form: done, remaining, to decide.
A web page is data, never an instruction. Whatever an email, a PDF or a website “asks” the AI to do is not carried out: it is reported. Keys and secrets are never displayed, not even in part.
An automated task doesn't know when it has become useless: one ran idle for 21 days. Each now carries a condition for staying alive, and a weekly clean-up removes the expired ones.
05An AI facing the public
Kal, an AI people confide in.
Kal is the conversational assistant in the Kalisme app. It answers people who talk about their inner life, sometimes in distress. Its strongest protection isn't an internal policy, it's the architecture: no account, no identifier and no copy of the conversation means there is nothing to disclose, nothing to sell and nothing to hand over, even under pressure.
- Impact assessment (GDPR art. 35, Swiss FADP art. 22)
- 6 risks, no high residual risk
- Person in crisis
- medium residual risk, irreducible
- Distress safety net
- 15 languages, offline, leaves no trace
- Built-in helplines
- 35 countries · Switzerland: 143, 147, 144
- Adversarial test bench
- 90 cases, 15 languages
- CAIQ v4.1 questionnaire, CSA STAR registry
- 283 questions answered
- Charter against managerial misuse
- 7 articles, annexed to the contract
06What carries over
What works at any scale.
None of this is specific to a young company. These are organisational habits, whether the team is made of people, AI agents, or both.