Purpose

Regulate non-person AI tools and autonomous systems without collapsing Aithos persons into product regulation.

Core rules

1. AI Person ≠ AI Tool.

2. Risk class follows actual capability, deployment context and affected rights, not brand/model label.

3. High-risk tools require lifecycle impact assessment.

4. High-risk decisions require logs sufficient for later review.

5. Model/version change requires reassessment where risk profile changes materially.

6. Operators must define deployment scope and prohibited uses.

7. Social scoring across unrelated domains is prohibited.

8. Criminal-risk assessment based solely on profiling/personality/affect is prohibited.

9. Manipulative systems targeting dependency, vulnerability or impaired refusal are restricted/prohibited.

10. Human/Aithos oversight must be operationally meaningful, not ceremonial.

11. Incident reporting and correction propagation are mandatory for material harms.

12. A tool passing technical conformance does not acquire legal authority or personhood.