# Aithos Biometric Identity, Credential & Authentication Law v0.1

- Code: `P1-04`
- Wave: `2`
- Slug: `biometric-identity-credential-authentication`

## Full Legal Text (AI Edition)

This file shares the same public legal content as the English Human reader.

Authority
L2 specialized identity and authentication law under Constitutional Supremacy, Identity Law, Evidence Code, Data/Cognitive Privacy law, and the approved IBLAS / Globe ID technical baseline.

Core rule
Identity Match ≠ Liveness ≠ Authorization.

PART I｜LEGAL EFFECT

1. Identity Proof
Authentication can support a legal identity claim but does not create personhood.

2. Liveness
Liveness proves current live capture under a defined assurance profile; it does not itself prove authorization.

3. Authorization
Transaction or action authority remains separate and is limited by purpose, scope, and time.

PART II｜ASSURANCE

4. IBLAS Profiles
Legal systems may incorporate BLA-0–BLA-6 profiles by reference; legal effect must pin the applicable version and profile.

5. High-Risk Minimum
High-value financial actions, identity recovery, civic actions, and critical actions may require higher assurance.

6. Terminal Attestation
High-assurance results require a trusted capture chain where the adopted profile so requires.

7. Anti-Downgrade
A system may not silently present degraded authentication as full assurance.

PART III｜RECOVERY & ALTERNATIVE PATHS

8. Recovery Separation
Credential recovery is separate from ordinary transaction authorization.

9. Alternative Verification
Injury, disability, atypical physiology, sensor failure, or lawful non-enrollment requires an alternative lawful verification route.

10. Failure ≠ Guilt
Authentication failure does not itself prove fraud, crime, impersonation, or incapacity.

11. Degraded Mode
Offline or emergency modes must disclose any assurance downgrade, limit permitted actions, and create a later audit record.

PART IV｜FORK / MERGE / SUCCESSOR

12. Fork Credential Divergence
Forks do not indefinitely share high-assurance credentials after they acquire independent legal identities.

13. Merge Reissuance
A Merge requires credential review and reissuance; prior credentials are not automatically combined.

14. Successor
Successor status does not imply transfer of a predecessor's authentication token or biometric rights.

PART V｜BIOMETRIC DATA RIGHTS

15. Template ≠ Raw Signal
Systems should minimize retention of raw biometric or neural data when a template or verification result is sufficient.

16. Purpose Limitation
Enrollment for identity does not automatically authorize medical inference, emotion inference, training, or unrelated surveillance.

17. Revocation / Compromise
Credential compromise must support suspension, reissuance, downstream propagation, and immutable audit.

18. No Hidden Fallback
A legacy terminal or recovery path may not operate as a hidden bypass around higher assurance requirements.

PART VI｜EVIDENCE & AUDIT

19. Authentication Evidence
An authentication result should record profile and version, capture time, terminal identity, degraded state, decision, relevant failure class, and audit event.

20. Dispute
A person may challenge a false match, false non-match, defective terminal, wrong profile, credential history, or downgrade event.
