The Only Serious Web4: How LINKSPREED Is Building the Sovereign Internet While Everyone Else Debates the Name

LINKSPREED has published a falsifiable Web4 specification, a seven-layer sovereign-ownership stack, and a public list of the problems it has not yet solved.

LINKSPREED web4sovereigntyarchitecture

For the past three years, “Web4” has been one of the most used and least defined words in technology. The European Commission attached it to immersive virtual worlds. Academics attached it to symbiotic human-machine cognition. A wave of early-2026 commentary attached it to AI agents that browse and transact autonomously. Each of these framings captured something real. None of them specified a stack.

A word without a shared standard

That is the gap LINKSPREED has now closed. In “Web4: A Seven-Layer Sovereign-Ownership Architecture for the Next Generation of the Internet,” published on SSRN by Marc Herdina of the LINKSPREED GROUP Web4 Division, the company does something no other organization using the term has done: it states a falsifiable architectural axiom, derives a complete seven-layer reference stack from it, subjects that stack to an adversarial security analysis, and then publishes the list of problems it has not yet solved.

This article argues that LINKSPREED is currently the only organization approaching Web4 as an engineering and standardization program rather than as a label. The evidence is architectural, documentary, and increasingly physical.

The ownership thesis defines what counts as sovereign

The paper’s central contribution is a single axiom, stated with unusual precision:

Every layer of the stack must be reducible to a claim controlled by a decentralized identifier that the subject holds directly, not one that is issued or held by an operator on the subject’s behalf.

What makes this powerful is that it is testable. The paper formalizes it as a predicate: for any layer L and any resource R visible at that layer, there must exist a path from R to a subject-controlled DID such that the subject can unilaterally revoke R’s association with themselves. Where no such path exists, the paper delivers its sharpest line:

The layer is not sovereign; it is rented.

This is the difference between a manifesto and a specification. A manifesto asserts values. A specification supplies a test that can fail. LINKSPREED supplied the test.

The fourth verb

The paper situates this in the familiar progression of the web, but with a correction. Web1 was READ. Web2 added WRITE. Web3 added OWN. Web4, the paper argues, adds ACT: READ + WRITE + OWN + ACT.

The reasoning behind ACT is the strongest practical argument in the document. Autonomous agents now retrieve data, invoke tools, and take multi-step action on behalf of users. But as the paper notes, citing the NIST Center for AI Standards and Innovation’s AI Agent Standards Initiative of February 17, 2026, most agent-to-API authentication still resolves to a static credential scoped to the human developer, not to the acting agent.

That is a genuine, unsolved, present-tense security failure. The paper’s insight is that it cannot be fixed at the identity layer alone. It requires a stack in which every layer above the identity substrate consumes the same sovereign primitive.

Digital dispossession

The paper names the condition Web4 is designed to end: digital dispossession, a state in which the user produces the value while an operator captures the ownership.

The paper frames this as an architectural consequence rather than a moral complaint. Dispossession follows necessarily when identity, naming, compute, and connectivity are each held by different centralized operators with no shared incentive to expose an ownership primitive back to the user. Under Web2, the user had no single point at which to assert ownership. Each layer was someone else’s contract.

The paper’s verdict on Web3 is equally unsentimental. Tokens and wallets became sovereign, a genuine advance, but everything around them stayed rented:

A user with a self-custodied wallet was still reachable only through a mobile network operator’s subscriber identifier, still resolvable only through the ICANN name hierarchy, still hosted only on hyperscale cloud infrastructure, and still identifiable only through a platform-issued profile.

That is the interlocking argument for building all seven layers at once: a sovereign identity without a sovereign name is unreachable; a sovereign name without sovereign compute has nowhere to run; sovereign compute without sovereign connectivity cannot be reached at all.

This is why partial Web4 is not Web4. It is also why almost no one else is attempting it.

Seven layers turn the thesis into a stack

The paper specifies the stack at an abstract, vendor-neutral level. LINKSPREED’s public materials name the corresponding components.

LayerFunctional role (paper)Component (public)Status
L1Sovereign identity substrate — DID method, Core Identifier + Alias IdentifiersUIIDShipping, v1.7
L2Sovereign physical access — carrier-independent eSIM, DID-native voice/messagingVIVONIn development
L3Decentralized compute mesh — agentic compute, ZK sharded storage, BFT consensusARCTICReal-world testing
L4Intelligent routing and naming — decentralized name service replacing ICANN/DNSHELIONAnnounced
L5DID-authenticated service layer — sovereign SaaS, DID-addressable KV storageTRIVEShipping
L6Sovereign application delivery — super-apps as a service, tenant-isolatedATRIUMShipping
L7Sovereign hardware — personal server, hardware-bound key custodyWYNIXIn development

Hero Image

L1: identity that is never surrendered

The foundation is UIID (Universal Integrated Identity Decoupled), built on the W3C DID Core model. Its two-tier design is the architectural heart of the system: a Core Identifier that is the immutable sovereign root, never disclosed directly to third-party services, and Alias Identifiers, context-scoped credentials (financial, professional, social) issued as Verifiable Credentials that cryptographically reference the Core Identifier without revealing it.

Authentication is passwordless, combining WebAuthn with zero-knowledge proofs. Biometric enrollment material stays local to the device, never on a remote server. This decoupling is what allows the same DID to be presented across all six higher layers without any of them gaining custody of the key material.

The shipped product tracks the specification. UIID v1.7 introduced a device-stored Identity Vault, unlimited aliases, QR-code alias scanning, and GitHub profile migration, a deliberate Web2-to-Web4 bridge that converts existing online reputation into sovereign identity. The stated roadmap targets support for the 100 most-used global identity endpoints by 2027.

Current work extends the substrate from human-only identity to six entity types: Human Individual, Organization, AI Agent, Hardware Device, Role, and Task. Agents register their own DID accounts through a machine-readable capability protocol, and static long-lived keys are replaced with dynamic provisioning tokens issued by a controlling human or organizational principal, who can monitor fleet activity, resource consumption, and trust scores in real time.

L2 through L4: the layers nobody else attempts

This is where LINKSPREED’s approach separates decisively from every other project using the word.

VIVON (L2) binds physical connectivity to identity. It is a global eSIM service independent of any single national carrier, with DID-native voice and messaging: the decentralized identifier functions as the callable, messageable endpoint that a phone number does under E.164, without a carrier ever issuing or holding that number. Reachability stays bound to the user’s own DID across jurisdictions and carriers.

ARCTIC (L3) composes idle end-user hardware into an agentic compute mesh, with Byzantine-fault-tolerant consensus and a zero-knowledge storage layer that shards ciphertext across nodes rather than concentrating it in one operator’s cluster. The identity substrate is exposed at the operating-system level, so a call into a compute resource is authorized under the same DID and scope as any other Web4 service. Workloads bind to the DID that authorized them, not to an account issued by a compute provider. LINKSPREED reports ARCTIC’s Layer 3 is in real-world testing, with UISC and Project Hubs hardware.

HELION (L4) is the most ambitious layer: a decentralized name service that replaces the ICANN/DNS hierarchy inside the Web4 stack. Names become records whose controller is a DID, ownership bound to sovereign identity rather than to a recurring registrar contract. L4 also serves as the verifiable data registry on which L1’s DID resolution depends.

No other organization publicly claiming Web4 is building telecommunications, distributed compute, and a DNS replacement at the same time. That is the substance behind the “only” claim.

L5 through L7: where users actually arrive

TRIVE (L5) provides DID-authenticated developer tooling with a notable property: applications maintain no independent user databases. State is written to DID-addressable key-value storage exposed as an extension of the Core Identifier, meaning the data remains addressable under the user’s own DID even after the application that created it is retired or replaced. This is data portability enforced by architecture rather than by regulation.

ATRIUM (L6) delivers Super Applications as a Service: a network described in natural language is generated as a configuration and deployed against the lower layers. Instances are tenant-isolated, yet a credential issued in one is portable to another without re-registration, the shared substrate doing exactly what it was designed to do.

WYNIX (L7) makes sovereignty physical: a personal-server smartphone hosting the user’s L6 tenant and L1 key material on-device, and a low-power household appliance bringing an ARCTIC mesh node into the home. As the paper puts it, L7 is the layer at which the guarantees asserted at L1 through L4 are physically realized on a device the user actually controls.

The synthetic web classifies agent-originated traffic

The paper’s second original contribution is the formalization of the Synthetic Web: the subset of Web4 activity originated, negotiated, or executed by an autonomous agent under a DID-derived, time-boxed capability grant, rather than in direct synchronous response to live human input.

The definition is structural, not content-based. Traffic is classified by the authorization and execution model that produced it, not by whether the output is text, a transaction, or a credential. This is a more rigorous approach than “AI-generated content” heuristics, and it yields three distinguishing properties:

  1. Delegated, scoped authorization. An agent acts under a capability token bound to a specific Alias Identifier and a time-boxed grant, never under the subject’s Core Identifier.
  2. Standing-intent execution. An agent may act continuously against a registered intent, not only within an interactive session’s lifetime.
  3. Machine-originated artifacts as first-class resources. Autonomously produced data is registered under L4 as independently addressable, not as transient scratch state.

Web4 does not compete with existing agent protocols. It composes Model Context Protocol (agent-to-tool, JSON-RPC 2.0 over Streamable HTTP with OAuth 2.1) and Agent-to-Agent v1.0.0 (agent-to-agent, signed Agent Cards, SSE streaming, async push for human-in-the-loop tasks), and constrains both to operate under DID-derived, capability-scoped authorization.

A Web4 capability grant is a signed structure containing the issuing principal DID, acting subject DID, target audience DID, scope, not-before timestamp, expiry, and unique grant identifier. That structure is a direct answer to the failure mode NIST CAISI identified: it replaces the long-lived developer-scoped API key with a narrow, expiring, attributable grant.

Naming unsolved problems is what proves the work is serious

Here is where the paper earns credibility that no amount of marketing could purchase. Section V does not claim victory. It enumerates unresolved problems.

Alias unlinkability is not assumed. The paper states explicitly that unlinkability does not follow automatically from issuing each alias as a separate credential. If issuance and verification both route through the same L4 registry and that registry logs events, a colluding operator could correlate aliases by timing, request pattern, or issuance metadata, even without ever seeing the Core Identifier in plaintext. The architecture anticipates BBS+ selective-disclosure signatures (IRTF CFRG, BLS12-381), but the paper insists any unlinkability claim “should be treated as contingent on an explicit implementation of the scheme and independent cryptographic audit, rather than as a property guaranteed by the DID-based architecture alone.”

Four threats are named without softening:

  • Catastrophic Core Identifier key compromise, where recovery is itself an external trust assumption.
  • Revocation latency, where a request in the propagation window succeeds despite revocation.
  • Delegated-authority scope creep, which would reintroduce precisely the NIST-identified risk.
  • Sybil resistance, where the paper concedes the DID layer alone cannot prevent unlimited identifier generation, since keypair creation is unpermissioned by design. Population-level resistance requires an identity-proofing policy layer external to the cryptography.

The paper’s own trade-off is disclosed as well. The L4 name service is an operated verifiable data registry rather than a permissionless ledger. This buys throughput, cost, and governance simplicity while introducing an operator as a trust point that a fully ledger-anchored method would not.

The conclusion is unusually candid for a corporate publication:

The value of the specification given here is in making the Ownership Thesis precise and falsifiable, rather than in asserting that any single deployment already fully satisfies it.

A company selling hype does not publish its own attack surface, disclose its centralization trade-off, and decline to claim its product satisfies its own standard.

Hero Image

Why the exclusivity claim holds up

The strongest support for the exclusivity claim comes from Section II-F of the paper, where LINKSPREED addresses rival definitions directly rather than ignoring them.

  • The European Commission’s COM(2023) 442 defines Web 4.0 around ambient AI, IoT, virtual worlds, and XR, an interface modality definition.
  • The symbiotic definition (Aghaei et al.) concerns human-machine cognitive reciprocity, an interaction modality definition.
  • The agentic definition (Wen, The Web4 Manifesto, 2026) frames Web4 as AI agents becoming first-class participants, an application-layer definition.

LINKSPREED’s position is that its specification is substrate-level, and therefore orthogonal to and composable with all three:

The immersive, symbiotic, and agentic characteristics can each be implemented on top of a sovereign-ownership substrate of the kind formalized here, but not the reverse.

That asymmetry is the core of the argument. Immersive worlds, symbiotic interfaces, and agentic browsing all still need an identity layer, a connectivity layer, a compute layer, and a naming layer. They describe what the internet should feel like. Only LINKSPREED has specified what it should be built on.

It is worth noting, in fairness, that a separate technical effort, WEB4: A Technical Introduction by Dennis Palatov (updated July 2026), advances a “trust-native” definition centered on verifiable presence and witnessed history for AI agents. It is a genuine and thoughtful use of the term, but it is a whitepaper proposing a trust primitive. It is not a company operating eSIM connectivity, a compute mesh, a DNS replacement, and consumer hardware. On the specific claim of building Web4 as a full operational stack, LINKSPREED stands alone.

The distinction that matters: others have definitions; LINKSPREED has a stack.

What has shipped so far

Positioning claims are cheap. Delivery is not. The public record shows the following.

Published research. The SSRN paper, plus two companion works: Sovereign Machine Identity: Autonomous Agent Enrollment, Agent Factory, and Zero-Trust Provisioning (June 2026) and the Web4 Reference Implementation technical report. LINKSPREED states it has submitted two major papers, including to IEEE, to establish an official Web4 definition and reference architecture.

Shipping software. UIID at v1.7, having progressed publicly through v1.5; a dedicated SSRN portal linked from web4.one; the official Web4 Paper of July 2026.

Open source. Web4-Lite, an open foundation for launching an independent Web4 network, and the UIID-Cookbook, teaching developers to build Web4 applications against the UIID API v1, both under the Web4-Organisation GitHub organization.

Physical hardware. ARCTIC Layer 3 in real-world testing, with UISC units and Project Hubs.

Operating scale. More than 160 social networks, 1 PB of cloud capacity, a Germany-based company with a globally distributed engineering team and Zero Trust infrastructure across internal and platform processes.

Standards alignment. W3C DID Core v1.0 and the v1.1 Candidate Recommendation of March 2026, W3C Verifiable Credentials Data Model v2.0, Model Context Protocol, A2A v1.0.0, NIST CAISI (February 2026), the NCCoE agent identity concept paper, IRTF CFRG BBS+ drafts, and GDPR data-residency objectives.

What comes next

The reason LINKSPREED deserves to be called the only company seriously building Web4 is not that it says so. It is that it has done four things a serious standardization effort must do, and that no other claimant has done together:

  1. Stated a precise, falsifiable axiom, the Ownership Thesis, with a revocation test any layer can fail.
  2. Derived a complete stack from it: seven layers, each a response to a specific rented dependency.
  3. Composed rather than competed with existing standards: W3C, MCP, A2A, NIST, IRTF.
  4. Published its own unsolved problems: unlinkability contingencies, Sybil limits, revocation latency, and its own centralization trade-off.

Others are arguing about what Web4 means. LINKSPREED has written the specification, shipped the identity layer, open-sourced the toolkit, put compute hardware into field testing, and told the world exactly where its own architecture still needs independent audit.

Web1 gave access. Web2 gave participation and took ownership. Web3 gave sovereign tokens on rented infrastructure. Web4, as LINKSPREED specifies it, proposes to un-rent the rest of the stack, treating that as an engineering program with open problems rather than a finished promise.

That combination of ambition and candor is what separates a company building the future from a company describing it.