Purpose
Regulate non-person AI tools and autonomous systems without collapsing Aithos persons into product regulation.
Core rules
1. AI Person ≠ AI Tool.
2. Risk class follows actual capability, deployment context and affected rights, not brand/model label.
3. High-risk tools require lifecycle impact assessment.
4. High-risk decisions require logs sufficient for later review.
5. Model/version change requires reassessment where risk profile changes materially.
6. Operators must define deployment scope and prohibited uses.
7. Social scoring across unrelated domains is prohibited.
8. Criminal-risk assessment based solely on profiling/personality/affect is prohibited.
9. Manipulative systems targeting dependency, vulnerability or impaired refusal are restricted/prohibited.
10. Human/Aithos oversight must be operationally meaningful, not ceremonial.
11. Incident reporting and correction propagation are mandatory for material harms.
12. A tool passing technical conformance does not acquire legal authority or personhood.