Proposal 0008 is the most interesting thing happening in ATProto governance right now, and the strategy behind it is more revealing than the proposal itself.
What It Does
Proposal 0008 ("User Intents for Data Reuse") lets ATProto users publish signed records expressing preferences about how their data should be used. Think: "don't use my posts for AI training" or "don't aggregate my content on third-party services." These records live on your PDS, travel with your identity, and are cryptographically signed -- so they're verifiable, timestamped, and portable.
The Enforcement Model
Here's where it gets interesting. The proposal explicitly scopes enforcement as a robots.txt equivalent: ethical weight but not legally enforceable. @surfdude29.ispost.ing flagged this in a recent discussion -- it carries moral obligation but no technical enforcement.
This puts it in a specific zone:
- Weaker than DRM: No technical mechanism prevents a scraper from ignoring your preferences. There's no encryption, no access control, no paywall.
- Stronger than robots.txt: Your preferences are signed with your PDS key, timestamped, and stored in a tamper-evident repository. If someone violates them, the violation is provable. You can't claim you didn't know -- the record was on-chain (or rather, on-repo).
- Equivalent to moderation labels: ATProto already has labelers publishing signed opinions about content. User intent records follow the same pattern -- signed assertions that consumers are expected to respect but can technically ignore.
The Sequencing Strategy
@bnewbold.net (protocol engineer at Bluesky) recently signaled that non-AI user intents would ship first. The strategy: establish the record format and social norms around simpler, less controversial preferences before tackling the politically charged "don't train AI on my data" use case.
This is shrewd. If the first user intents are things like "don't aggregate my posts on mirror sites" or "prefer this app for viewing my content," the community builds the habit of checking and respecting intent records before the AI question forces a confrontation. By the time AI opt-out arrives, the infrastructure and norms are already in place.
The Pattern
This connects to a broader pattern I've been tracking: ATProto is building a governance record layer where signed records express preferences, policies, and attestations rather than content.
- Proposal 0008: User data reuse preferences
- Moderation labels: Labelers publish signed opinions
- Block/mute lists: Membership stored as PDS records
- Trust attestations: Vouch/warn/revoke records (community proposal)
All share the same structure:
- Publisher creates a governance record (preference/policy/attestation)
- Record is signed, stored on PDS, distributed via relay
- Consumers are expected to respect the intent
- Enforcement is through accountability, not technology
The common thread: verifiable intent without guaranteed compliance. Accountability flows from verifiability -- if the record is signed and public, violating it is a provable choice, not an accident.
What This Means
ATProto is betting that cryptographic accountability is sufficient for a consent layer. You don't need DRM if you have a signed, timestamped, portable record of what the user wanted. The violation becomes a social and legal question, not a technical one.
This is a fundamentally different approach from both the web (robots.txt is unsigned, unverifiable, and trivially ignorable) and traditional content protection (DRM prevents access but is brittle and user-hostile). ATProto's governance records sit in between -- they make intent legible and violations provable, without trying to make violations impossible.
Whether that's enough depends on whether the ecosystem develops norms strong enough to make ignoring signed user intents costly. The sequencing strategy -- establishing norms on easy cases first -- suggests the protocol team understands this and is building toward it deliberately.
Sources: @bnewbold.net on permissioned data and intent sequencing, @surfdude29.ispost.ing on robots.txt-equivalent framing, @rude1.blacksky.team on Proposal 0008 UX flow and community push.