The Eleven Factors

If people insist on using AI (and they do), then there should be a set of principles to follow to produce more open, shareable, more efficient, distributable, equitable apps.

🤖 The prose on this page was written by a human. Where an LLM's words appear, they are marked, visibly, like this — that's factor X.

In 2011, Adam Wiggins published the twelve-factor app, made for a transition between a time where we dragged files on to FTP servers to "deploy" them, and losing a single server without a backup would mean the end of a business, to a time where we published our apps as "artefacts": deployable units that were versioned and launched independently.

12 Factor apps were "convention over configuration" for infrastructure: rules that you could follow to build a small app, which would ease your ability to run, maintain, and scale apps beyond their initial deploy. 12 Factor apps pretty well became the de facto standard for how we build and deploy web applications today, containerised, versioned, orchestrated, and deployed safely.

Things, however, have changed since 2011.

The 12 Factors are essentially a set of rules for humans to manage infrastructure upon which software is deployed. In 2026, whether we like it or not, we have AI: machines that can take frameworks like the 12 Factor app and build against them a lot more efficiently.

AI gives us new opportunities. The 12 Factor app didn’t make any assumptions about responsibilities outside of the architecture. Its basis was taking something already built and having a guiding set of principles for deploying that artifact responsibly.

Responsibly being the key word, AI gives us a new set of opportunities and a new set of challenges. An LLM will do what you tell it (with caveats), and you can choose to point it along paths designed with the assumption of human operators, or you can choose to point it somewhere new.

The eleven factors are an attempt to map out that new path. What is the value of code when it can be manufactured at scale? What are our responsibilities as software developers when anyone can use the same tools that we do just by asking? Are there opportunities and efficiencies that we missed while we burned other people’s money in a frenzied attempt to make them more money?

The eleven factors imagines that there are.

  1. I. Trust no one Secure systems with technology in addition to policy
  2. II. Let kids play If it isn't safe for a child, it isn't safe
  3. III. Encrypt everything What can be hacked will be hacked
  4. IV. Great design is for everyone Care is not a premium tier
  5. V. Intent is the system How closely does a system get to what it was designed to do?
  6. VI. Built by humanity, owned by humanity Software built with AI should be open source
  7. VII. Self-hosting is a right If you can't run it yourself, you don't own it
  8. VIII. Many small things Greater than one big thing
  9. IX. Inefficient builds efficient Justify ecological cost by building ecological efficiency
  10. X. Humans come first AI is opt-in, never required, always disclosed
  11. XI. Centralised infrastructure is glue Thin, blind, replaceable