Series

AI-Native Software Development

Don't commission an SIer — stand it up yourself, and run it yourself

Introduction — what changed

1-01

AI Solves the World's Hardest Coding Problems — From the Codeforces 2700 tier to design — in the Mythos/Fable era, AI became the strongest SIer, callable for $20 a month

AI's code-writing ability has matched human top-class on public competitive-programming ratings (the Codeforces 2700 tier). It can also assemble a cyberattack autonomously — evidence of design ability. Attack, design, and verification are three faces of one power. In the Mythos/Fable era AI became the strongest SIer, handling requirements, design, and build, and callable by anyone for $20 a month. The whole series argues outward from that.

1-02

Maintenance-Phase Shift Is the Real Story — Cheaper coding is the tip of the iceberg — because AI understands context, maintaining at the code level stops being necessary

The most overlooked consequence of AI writing code is not faster coding. It is the structural shift of the maintenance phase itself. Maintenance eats 40 to 80 percent of software cost, 60 percent on average (Glass, IEEE Software, 2001). Because AI understands context, maintaining at the code level stops being necessary, and the unit of maintenance moves from code to design, spec, and context. The single largest cost, reading legacy code, evaporates. Anyone who can read a manual and fit it to their own reality can do development and maintenance.

1-03

AI Now Does the Software Engineer's Work — The coder obviously goes — and the software engineer who designs and codes becomes, not a designer-coder, but someone who works in dialogue with AI (the builder)

The coder, the code-writing role, obviously disappears. But the subject of this chapter is what lies beyond. AI now does the software engineer's work too. Writing code and deciding structure are not divided between separate AIs but are faces of one power, so design and code are both carried by AI. What stays with humans is not designing and coding yourself. It is building and operating a system in dialogue with AI — that is, the builder. The same split that followed the calculator replacing the abacus is happening now. What disappears is the role definition, not people.

1-04

The Builder Role — Plan what to build and write the spec, build it in dialogue with AI, run it, integrate the whole

The builder builds and runs whole systems in dialogue with AI, and is not the next version of the software engineer. The software engineer solves narrowly closed problems, and that is the work AI takes over. The builder handles the open problem of raising what to build out of reality. This chapter defines the builder as a loop of four steps — plan, build with AI, check, integrate — and then, along the axis of the narrowly closed problem versus the open problem, shows why judgment cannot be left to AI.

1-05

Customers Co-Develop with AI — The first move is OSS, not code — use it for the generic, customize it for the personal (2-04, 2-10, 2-14), build the foundation for the organization (the Independence part). Only the specific gets written with AI

This is the era in which customers themselves become builders. But the first move is not writing code. It is using proven OSS. For generic things, use OSS first: it is the most economical path, and it is also effective as a security measure. Personal things are customized on top of OSS in dialogue with AI, and the worked examples live in 2-04, 2-10, and 2-14. Organizations stand up a foundation with OSS that replaces Microsoft 365, Copilot, and WordPress, which is the Independence part. Only the company-specific logic gets written with AI. What AI cannot do, the SIer cannot do either.

Independence — a specification the AI can execute

2-01

Becoming Independent from Microsoft and Google — The Whole Map — Move the foundation of your business out of the vendor's cage and into your own hands

The lock-in is not weak features. It is that the layers are closed, and that the key (identity) is concentrated in someone else's hands. The Office suite and the core business systems stand on the same structure. Opening what is closed is AI's role. It unseals proprietary formats, reads unreadable code, and extracts imprisoned business knowledge. The Independence part, working with AI, unties the closed bundle into open OSS and moves the key to your side — the machine is one Debian PC, logic is Python and Flet, auth is PocketBase, documents are AsciiDoc and git, code and sharing are Forgejo, mail is Stalwart, meetings and calendars are Jitsi and Radicale, the web is your own machine or Cloudflare Pages, data is PostgreSQL, SQLite and DuckDB, core logic is FastAPI, and AI is a local LLM plus RAG. This chapter is the map; the chapters that follow stand each one up.

2-02

Give the AI a PC of Its Own — The Machine the Independence Part Runs On — Turn one company PC into Debian and hand it over, root included. The human keeps only what a reinstall cannot restore

Everything the Independence part stands up has to run somewhere. This chapter decides where. Turn one company PC into Debian and hand it to the AI. The public website, the in-house tools, and the AI's own work all sit on that one machine (only the self-hosted LLM goes on a separate server), with a desktop (GNOME) installed and left running. Services are installed with apt and run under systemd, not Docker. The AI does all the configuration, so it gets root: with the configuration in git and the data copied off the machine, a broken machine is recovered by reinstalling. The human keeps only the three things even that cannot restore — keys and accounts, actions taken outside the machine, and copies of the data. Add an AI from another vendor, and have them check each other with nothing but the artifact and the criteria. The bill is about $120 a month while building and about $40 in steady operation. No approval process, no server contract, no per-seat licenses.

2-03

Lay the Foundation — SQLite, PostgreSQL, pgvector, DuckDB, Polars — Stand up the data layer everything sits on, first, on your own side

The Independence part starts with the data layer everything sits on. SQLite is usually enough — a single file, no server, already built into Python. Step up to PostgreSQL only when you share and several people write at once. Enable pgvector for semantic search; analyze with columnar DuckDB and Polars — Excel stays the human's I/O while machines crunch the data behind it; step off Power BI's per-seat billing. Installed with apt, run under systemd. The generic is already shared as OSS — you don't write it, you stand it up. It all goes on the one machine handed to the AI in 2-02.

2-04

Write the Logic — Own Your Tools with Python and Flet — Move macros, charts, and pivots into Python, and put the screen on with Flet

Externalize into Python the macros, VBA, charts, and pivots embedded in Excel and Word. The skill you need is not writing but using. Open JupyterLab in a browser, turn pivots and VLOOKUP into Polars code, draw charts with matplotlib and Altair. Then peel the human-facing I/O — reports, dashboards, invoices — off the core system and bring it down to your own machine; the month-end report run that freezes the sales system goes away with that split. Where a screen is needed, put Flet on top: the same Python runs on Mac, Windows, Linux, the web, and mobile, and flet-mcp hands the AI the API of the version actually installed.

2-05

Stand Up the Gate — One Login with PocketBase — Share only identity (authentication) — each server enforces its own access control. Central minimal, defense in depth

Authentication is not something each app builds on its own. It is a gate you stand up once and share. But the gate holds only the minimal common thing — identity. Authorization ("what you can do") is held by each app, each server, itself (defense in depth); the single-perimeter idea that "whoever passed the gate goes anywhere inside" is not the design. PocketBase is a single binary with email auth, OAuth2, one-time codes, MFA, an admin UI, and a REST API. Identity lives in the gate; business data lives in PostgreSQL. Step off Microsoft Entra ID's per-seat monthly bill.

2-06

Bring Code In-House — Forgejo and Zed — The builder's workshop, on your own side — repositories and CI, outside Microsoft

A builder's work is to have AI write code, evaluate it, and integrate it. The place that code lives — the repository — gets stood up on your own side. Forgejo is a single Git forge that replaces GitHub and Azure DevOps, with Actions covering CI/CD. It rides on the PostgreSQL from 2-03 and sits behind the gate from 2-05, on the one machine handed to the AI in 2-02. The local tools are Zed and the AI called from inside it. Code is an asset; control of where it lives stays with you.

2-07

Take Documents Back — Prose in AsciiDoc, Working Tables in a Grid, Printed Pages from Templates — Keep the content as text in git. Excel, Word, and Claude Docs become doors you pass through, not the place the content lives

What was made in Word and Excel is not one kind of thing. It is three — things you read, tables you work in, and pages you print — and each is held differently. Things you read are written as AsciiDoc text, kept in the Forgejo of 2-06 and edited in Zed; the design stays out of git and a build prints PDF and HTML. Tables you work in stay in a grid — Excel, Euro-Office, or LibreOffice — with the data outside the grid (2-03); how far to push into Python depends on the person. Pages you print (published statistical tables, forms, slips) hold the shape in a template and the values as text, and pour one into the other; reproducing page layout is not pursued. Office and Claude Docs become doors you pass through. What shrinks is what was made by hand: statistical tables shrink a great deal, closing the books much less.

2-08

Mail on Your Own Side — Stalwart and Thunderbird — Outside Exchange and Outlook — the inbox on your side, sending yourself when the conditions hold

Mail is the record of the business itself. Stalwart is a Rust single server carrying SMTP, IMAP, JMAP, spam defense, and DKIM signing in one, replacing Exchange. It rides on the PostgreSQL from 2-03, stands up on the machine handed to the AI in 2-02, and is read with an IMAP client such as Thunderbird. Sending is done yourself when four conditions hold — a fixed IP, reverse DNS, SPF/DKIM/DMARC, and a line that lets port 25 out — and a relay is borrowed only when a recipient cannot be reached. Installed with the official script, run under systemd. DNS (MX, SPF, DKIM, DMARC) and sending mail to the outside stay with the human.

2-09

Meetings and Calendars on Your Own Side — Jitsi and CalDAV — Teams meetings and shared calendars — on your own domain. Booking is written in 2-12

Video meetings with Jitsi Meet, shared calendars with Radicale (CalDAV). Replace Teams, Zoom, and calendar sharing with your own domain on the machine handed to the AI in 2-02. Both install from Debian's apt and sit behind Caddy. Booking (in place of Calendly and Bookings) is written in 2-12 as a small FastAPI app, since no self-hostable OSS remains for it. BigBlueButton needs a dedicated Ubuntu machine, so it goes on a separate box only for serious teaching. The human holds the domain and DNS, the list of people who may open a meeting, and the future events to move.

2-10

Build the Web — Back to HTML, CSS, and JavaScript — Content in AsciiDoc and Mermaid, the frame in minimal HTML and CSS

Build a website in two layers. Content in AsciiDoc (Markdown works the same) and Mermaid, the frame in HTML, CSS, and minimal JavaScript, with Python connecting the two. Coming back from the row of frameworks and build tools to raw web standards leaves a single-digit dependency count you can read through. Content held in WordPress moves to text in seven steps, and where there is no time to rebuild, Playwright can mirror the existing site into static files. The other reason to leave npm is the supply chain, and the moving parts stay on one FastAPI, kept minimal.

2-11

Publish the Web — Your Own Machine, or Cloudflare Pages — Ship the baked HTML to either home, by the same procedure

Ship the static site you baked in the previous chapter. There are two homes for it: your own machine from 2-02 with Caddy in front, or Cloudflare Pages. Both take the same procedure — build, verify, deploy as separate steps — and either can replace the other later. On your own machine, the public web, the internal tools, and the moving parts all sit on one box, and Caddy takes the certificate automatically. On Cloudflare Pages, you borrow the CDN and the defense and hold no machine. The moving parts are one FastAPI, and the public side reaches exactly that one point. The human holds the domain, the keys, and the decision to go live.

2-12

Build an API — Expose Core Logic with FastAPI — Rewrite the core system via parallel operation and gather your own logic into one API

'Don't break it, don't touch it' is old advice. AI has cut the cost of rewriting a core system by an order of magnitude. Build the new system in FastAPI, run it beside the old one, and compare the outputs against reality. When the diffs vanish, stop the old. Push business knowledge out into Markdown all at once, let the floor write the tests, and stop outsourcing. The rewritten core logic lands as one API that reads and writes the 2-03 PostgreSQL and verifies identity with the 2-05 gate's token. The first one can be the booking intake.

2-13

Make Diagrams and Documents — Mermaid, Marp, and the Other Tools — Diagrams, slides, even 3D — all produced from text and code

Diagrams, slides, and the documents you hand out all come out of text and code. Structural diagrams in Mermaid, screen drafts asked of the AI as HTML, slides in Markdown with Marp (a standalone binary) or pandoc. Those are the everyday tools; beyond them sit D3.js, Blender (bpy), ComfyUI, and CadQuery / Build123d / OpenSCAD / FreeCAD. Every one of them is driven by a script or code, so you have the AI write it, look at what comes back, and adjust. White backgrounds for product photos, a sensor housing for a factory line, video assets for a tourism campaign, a population chart for a local paper — work that used to go out to a production house now runs in your own hands. Business documents keep content and design apart, so fixing one place updates every output.

2-14

From Electronics to IoT — Think in Python, Have the AI Translate — Assemble the parts, run the board, stream the readings home — the thinking stays on the Python side

One chapter covering the whole span: buy parts, wire them on a breadboard, attach sensors, and stream the readings home over the network. Microcontrollers finally run C or C++, or at lightest Rust or MicroPython, but design and validation happen in Python on a PC. Confirm it works, then have the AI translate only the parts that need translating. Pick the language by development phase: Python, then MicroPython, then Rust when performance demands it; C and C++ are for existing assets. Print the housing with 2-13's CAD, stack the readings in 2-03's store, expose them with 2-12's API, and put 2-04's Flet on the screen. Includes a farmer's field-sensor network and a twenty-year-old PLC ladder turned into Python.

2-15

Make Your Knowledge Legible — Preparation Is the Main Body, AI the Last Move — OCR, classification, codifying tacit knowledge — move scattered, unwritten knowledge into a written, structured state. A no-regret investment you recover even without AI.

Before you put AI on top, build information worth putting it on. Scattered files, paper and scanned PDFs, tacit knowledge that lives only in someone's head — move them into a written, structured state with OCR, classification, and codification. Preparation is the main body; AI is the last move. What to keep and how to structure it is a judgment only people can make, and it pays off as the end of personnel lock-in even if you never put AI on it — a no-regret investment. Put the prepared information into 2-07's files and 2-03's pgvector, and the next chapter mounts RAG on it.

2-16

Stand Up Your Own AI — LLM and RAG — Lay AI on top of everything — answers grounded in your own data, on your own side

AI goes on top of everything stood up so far. The pgvector enabled in 2-03 finally pays off. Start by holding Cohere's open-weight coding model North Mini Code locally on Ollama, so no data leaves your side. Load a general model and embeddings alongside for RAG, put documents, code, and mail into pgvector to answer with citations, and use it through Open WebUI. Search never bypasses the gate. Keep secrets and always-on processing in-house and borrow a frontier model for hard judgment — control yours, capability borrowed. Step away from Copilot and close the Independence part.

2-17

Decide How Far the AI Goes — No Autonomous Runs, Freeze It into Code — The AI proposes, the human approves; repeated work is frozen into code and commands

Once your own AI is standing, the next thing to settle is how it runs. Do not run agents autonomously: errors chain, accountability disappears, verification stops reaching, and outside data turns into instructions. Autonomy is allowed only when four conditions hold together. Putting AI inside Office has the lowest decision threshold, the widest footprint, and the deepest capability erosion. Run AI inside a sandbox and hand-pick what it sees. Freeze repeated work into Python and Linux commands — AI is a generator, not a runtime. The bill goes from a fee on every run to a fee on the first run only.

Shift — why the industry structure changes

3-01

Companies Don't Write Their Own Code — Office and Core, Two Parallel Worlds — Writing it in-house was inefficient — so office was bought, core was outsourced, and two worlds stood in parallel

Companies have not written their own code — and that was rational. In-house development was inefficient, demanding a large specialized workforce no single company could justify keeping. So companies BOUGHT packaged software for generic office work (Microsoft) and OUTSOURCED custom core systems (SIer) — two parallel, separately locked-in worlds, joined only by thin seams (auth and document sharing). That parallel split was the efficient equilibrium for decades. AI inverts the efficiency: one person plus AI now stands up both worlds on the same OSS foundation. The premise dissolves, and both vendor structures collapse together. This chapter sets the premise for the Shift part.

3-02

Checking the Story — Verifying Vendor Narratives Against Primary Sources — AI leans toward the story too — so design the checking, not just the asking

A vendor's narrative is not, by itself, material for a decision. You check it against primary sources first. This chapter lays out that procedure. AI leans toward narratives too — its training data is thick with English and with large vendors' official documents, and weight settles on authority and on the majority. The owners of the sources AI learns from (GitHub, npm, LinkedIn, technical blogs) are often the parties telling the story. So you design the checking: combine AIs built by different methods, ask more than one vendor, state a critical hypothesis, and end at primary sources. Four cases — WordPress, Node.js, Linux distributions, and Microsoft's return to native apps. Including the contrast where Gemini Pro summarized EF Core's AOT support as "nearly perfect" while Microsoft's own documentation says "recommend against" and "highly experimental." The Debian governance check is the very ground on which 2-02 places Debian. The conclusions of Shift 3 and Shift 4 were obtained with this procedure.

3-03

Digital Sovereignty — The Microsoft Problem and the Trump Problem — OSS and sovereign AI are now the better choice on both economics and security

Until recently, Microsoft 365 was the economical and safe default — which is exactly why everyone bought it. That premise has inverted. OSS plus sovereign (self-hosted, local-weight) AI is now better on both cost AND security. The Microsoft problem — per-seat rent that only rises, data on a US company's cloud reachable under the CLOUD Act, opaque telemetry, Copilot routing content through Microsoft's models. The convenience IS the dependence. The Trump problem — depending on US Big Tech means depending on the US government's goodwill, and the Trump administration cannot be trusted not to weaponize that dependence (sanctions, cut-offs). So leaving Microsoft is no longer ideology — it is the new economic-and-security rational default. This chapter sets the premise for the Shift part's office (Microsoft) side.

3-04

The Structural Uneconomy of the SIer Model — The upstream judgment outsourcing cannot remove, and the de-responsibilization and hollowing-out it brings — for the same effort, you can build it yourself

Even when you outsource, the upstream judgment — improving the business operations themselves, and understanding the systems — stays with the customer. That work is not a straight line but a loop, and with AI you can run it fast in-house. The SIer cannot run the loop: every turn needs budget approval and a contract, so it usually runs to a year. And the deepest problem with commissioning is the erosion of responsibility and capability: the moment you hand it off, no one owns the result whole. The most expensive example is GitHub Copilot, and the responsibility for that failure rests with the CEO. For the same effort, you can build it yourself. The disappearance of the SIer commission model is inevitable.

3-05

The Lock-In Problem — Proprietary frameworks, proprietary abstractions, human dependency — with Palantir's FDE as the archetype

Lock-in is the state in which migration cost is high enough that nothing moves. SIer commissioning anchors customers with three layers — proprietary frameworks, proprietary abstractions and Ontology, human dependency. Palantir's FDE model is the extreme form, maximizing all three to sustain premium pricing in the tens of billions of yen. AI-native development, by contrast, structurally avoids lock-in: AI tends to write in standard libraries and standard formats, so another AI, another builder, or the customer themselves can take over. The chapter also treats a second lock-in — vendor AI, and Microsoft's backward compatibility.

3-06

Companies Hire Builders — The senior builder is management — moving into the CIO's seat, with heavier responsibility than today

In the AI-native era, the professional work — including lawyer- and doctor-level judgment — is done by AI. So the human senior builder is not a profession that sells judgment but management that makes business decisions: the CIO (Chief Information Officer). IT judgment = business judgment = management judgment, and because IT becomes the core of the business rather than a surface layer, the responsibility is heavier than today's CIO. A general-employee grade cannot accommodate this. The corporate-website case shows both the cost and the structural change, and the chapter shows that builder supply is not limited to former coders.

3-07

Japan's SIer Industry Transition and Labor Mobility — Multi-tier subcontracting, paradoxically, makes the transition easier

Japan's multi-tier subcontracting structure in the SIer industry is usually treated as a barrier to transition. Dissect the structure and the conclusion reverses: because coder demand is externalized through contracts, the structure can shrink without internal lay-offs. Prime contractors can downsize by not renewing subcontractor agreements, and talented subcontractor coders flow to primes, to customer companies, or to independence. Labor mobility is trending upward, with long-term commissions, secondment and internal ventures absorbing the shift, while AI physical infrastructure, manufacturing reshoring and the shift to natural farming open labor demand outside the industry.

3-08

The AI Revolution Starts From Below — Top-down adoption always fails. It starts where a line and $100 a month are all you need

The AI revolution does not start with an executive decision or a large budget. It starts where no approval process is needed: small companies, sole traders, a department with real discretion inside a large company, and the periphery of large companies. All it takes is an internet line and $100 a month. Adopted from the top, it passes through the IT department and the SIer, turns into a headcount-reduction story, drives the floor to use AI in hiding, and leaves the company with nothing. Started from below, six things stay: the code, the business knowledge put into words, the checking mechanism, the record of what got stuck and how it was fixed, the people who can build, and the data. Executives have no time to look at small problems, and small problems are exactly what AI solves. So AI belongs to the floor. Held at the center it is used for surveillance and censorship; held below it solves problems. There are countless places for it to start, and no hand that can stop it.

3-09

The Structural Transition That Won't Reverse — The changes chain together, the main part lands in the near future, and because the premise has inverted it does not move back

From AI reaching top-tier execution capability, the changes chain: the coder role goes away, the builder appears, customers build in-house, and the SIer commission model shrinks. The main part lands in the near future. And because the premises of economics and security have already inverted, the structure that has moved does not move back. But complete replacement happens only where the rules are explicit and correctness is machine-verifiable — coding inside software development. Desk work, self-driving, and robotics stall at the last 1% and never reach complete replacement; those are productivity-gain stories. Read wider, this transition is one cross-section of a Second Renaissance.

Direction is decided by humans. Execution is done by AI.
The ceiling on execution has risen — which makes deciding direction heavier work than before.

Start with installment 1

Start with what Fable 5 is — and what it is not good at.