Skip to main content
K4M2 AI

Responsible AI standard

Capability is not sufficient justification.

AI can increase people's ability to understand, create, learn, decide, and cooperate. It can also obscure responsibility, concentrate power, scale manipulation, weaken judgement, and make people dependent on systems they cannot examine or challenge.

Before asking whether something can be built, we ask what human purpose it serves, who benefits from it, who may be harmed by it, who remains responsible when it is wrong, what power it creates or removes, and whether it should exist in the proposed form at all.

This standard applies to the products we create, the systems we implement for clients, the technologies we license, and the commercial work we choose to accept.

01

Begin with the human purpose

Every system should begin with a clearly defined human or institutional need. "We should use AI" is not a sufficient problem statement. Before development begins, we should be able to explain what problem is being addressed, who experiences it, why it matters, what currently happens without the system, what a better outcome would look like, and whether AI is necessary to produce it. When a simpler process, conventional software, organisational change, or human service would work better, we recommend that instead.

02

Human agency should increase

A system may be efficient while still reducing agency. It may make decisions faster while leaving people less able to understand them, remove effort while removing skill, or provide convenience while making departure increasingly difficult. We examine whether a system helps people understand more clearly, make better-informed decisions, develop capability rather than lose it, question the system's output, retain meaningful choice, act without unnecessary dependency, and leave or refuse the system without unreasonable cost. Automation should not remove meaningful human judgement simply because removal is technically possible.

03

People should know when AI is involved

People should not be led to believe they are interacting with a person, receiving human judgement, or viewing independently produced material when AI has played a significant role. At minimum, people should be informed when AI materially affects a decision about them, advice they may reasonably rely upon, the content they receive, the evaluation of their work or conduct, access to a service or opportunity, the interpretation of sensitive information, or a simulated human relationship. A hidden statement in lengthy terms is not meaningful disclosure.

04

Responsibility must remain identifiable

An AI system cannot accept legal, moral, or institutional responsibility. Responsibility remains with the people and organisations that design, deploy, operate, approve, and rely upon it. For each significant system, there should be identifiable responsibility for approving its purpose, determining where it may be used, evaluating its performance, reviewing important outputs, responding to failures, investigating reported harm, correcting or withdrawing the system, and communicating with people affected by it. "AI made the decision" is not an acceptable account of responsibility.

05

Important outputs should be reviewable

People affected by significant AI outputs should have a meaningful way to question, review, correct, or appeal them. Review may include human reconsideration, access to relevant inputs, correction of inaccurate information, explanation of the factors influencing an output, escalation to an accountable person, independent assessment, or reversal or suspension of an automated action. A person should not be trapped inside a decision process that no responsible human is willing or able to examine.

06

Evaluation should reflect real use

A demonstration or benchmark does not establish that a system is ready for use. Systems should be evaluated under conditions resembling the environment in which they will operate, examining accuracy and reliability, performance across relevant groups and circumstances, failure modes, uncertainty and hallucination, resistance to misuse, privacy and security, human oversight, accessibility, operational resilience, unintended incentives, effects on behaviour and decision-making, and the consequences of false positives and false negatives. A system used for low-stakes drafting does not require the same safeguards as one influencing employment, finance, education, healthcare, safety, legal rights, or access to essential services.

07

Uncertainty should be visible

AI systems often produce fluent outputs even when their information is incomplete, uncertain, outdated, or wrong. Fluency should not be mistaken for confidence. Where uncertainty is material, the system should express it, identify missing information, distinguish fact from inference, provide sources, recommend human review, refuse to answer beyond an appropriate threshold, and avoid false precision. The design should not encourage people to trust an answer merely because it is delivered confidently.

08

Data collection should be proportionate

The existence of useful data does not automatically justify collecting, combining, retaining, or analyzing it. We consider whether the data is necessary for the stated purpose, whether less sensitive data would be sufficient, whether the person reasonably expects this use, whether consent is meaningful, how long the data must be retained, who can access it, how it may be combined with other information, what happens if it is exposed or misused, and whether the system can operate with less data. A business model should not depend on collecting more information than the service genuinely requires.

09

Sensitive contexts require stronger safeguards

Some uses of AI affect people's rights, dignity, safety, opportunities, or access to essential services, and require stronger standards. Sensitive contexts may include healthcare, mental health and emotional support, education and student evaluation, employment and worker monitoring, credit, insurance, and financial access, law enforcement and public safety, legal services, government benefits, housing, biometric identification, children and vulnerable populations, and systems affecting personal liberty or essential rights. In these areas, greater capability does not reduce the need for human responsibility. It increases it.

10

Emotional dependence should not be exploited

AI systems can create a strong impression of attention, understanding, intimacy, authority, or companionship, and that capacity requires restraint. We will not intentionally design systems to create emotional dependency for the purpose of increasing engagement, spending, data collection, or control. Systems interacting in emotionally sensitive contexts should not pretend to possess feelings they do not have, pressure users to remain in the interaction, discourage healthy human relationships, use personal vulnerability to increase commercial outcomes, present themselves as an unquestionable authority, manipulate attachment to prevent departure, or hide the commercial interests shaping the interaction. A system may support a person without attempting to make itself indispensable.

11

Engagement is not the same as value

Time spent, messages sent, daily use, retention, and frequency of interaction can indicate usefulness. They can also indicate confusion, dependency, compulsion, or difficulty leaving. Product evaluation should also consider whether the system helps people complete what they came to do, reach useful understanding, make progress without unnecessary repetition, reduce dependence over time where appropriate, retain control over their attention, and leave the product without manufactured anxiety. A product should not create the problem it claims to solve in order to maintain usage.

12

Persuasion must not become manipulation

All communication influences people to some degree. The relevant question is whether the influence respects their ability to understand and choose. We will not knowingly build systems whose primary value depends on deception, covert psychological targeting, exploitation of vulnerability, false urgency, hidden commercial influence, manufactured social pressure, deliberate confusion, compulsive interaction patterns, suppression of relevant alternatives, or impersonation without disclosure. Persuasion should remain open to reflection. Manipulation works by preventing it.

13

Human oversight must be real

Adding a person to a process does not automatically create meaningful oversight. Human review becomes symbolic when the reviewer has too little time, cannot inspect the relevant evidence, lacks authority to change the outcome, is expected to approve nearly every result, does not understand the system, is evaluated for speed rather than judgement, or becomes dependent on the system's recommendation. Where human oversight is required, the reviewer should have sufficient information, competence, time, authority, and institutional support to disagree.

14

People should be able to leave

A responsible system should not make departure unnecessarily difficult. People should be able to understand how to stop using the service, what happens to their data, whether their information can be exported, what functionality will be lost, whether an important decision can be completed through another route, and how to revoke permissions or integrations. Where practical, systems should support portability and interoperability. User dependence should arise from genuine value, not artificial lock-in.

15

Security is part of responsibility

An AI system that is useful but insecure is not responsibly built. Security considerations should include unauthorized access, data leakage, prompt injection, model or system manipulation, access-control failures, abuse of tools and integrations, supply-chain risk, fraud and impersonation, misuse by authorized users, and recovery after an incident. Security should be considered during design, not added only after deployment.

16

Misuse should be considered before release

A system may be designed for a legitimate purpose and still be easily adapted for harmful use. Before release, we examine who could misuse the system, which capabilities may be repurposed, whether access should be restricted, whether monitoring is justified, what safeguards can reduce abuse, whether some capabilities should be withheld, how reports of misuse will be handled, and whether the system should be released at all. The absence of harmful intent by the builder does not remove responsibility for foreseeable misuse.

17

Systems should have conditions for refusal

A responsible AI system should not always attempt to answer, comply, predict, or automate. It should be capable of refusing when information is insufficient, when the request exceeds its reliable capability, when the use would create unreasonable risk, when the person requires qualified human support, when the requested action is unlawful or harmful, when the system cannot establish appropriate authority, or when the consequences cannot be responsibly evaluated. Refusal should be understandable and, where possible, direct the person toward a safer or more appropriate path.

18

Deployment should be reversible

Organisations often continue using systems because stopping them becomes expensive, disruptive, or politically difficult. Before deployment, we consider how the system can be paused, limited, rolled back, replaced, independently reviewed, removed from a workflow, or operated manually during failure. Higher-risk systems should not become irreversible before their effects are understood. A pilot should be designed as a genuine test, not as an informal commitment to permanent adoption.

19

Continuous monitoring is required

A system that performed acceptably at launch may become unreliable later. Models change, data changes, users adapt, new forms of misuse emerge, business incentives shift, integrations fail, and the surrounding institution changes. Significant systems should be monitored for changes in reliability, emerging failure patterns, user complaints, security incidents, unequal effects, behavioural dependence, misuse, changes in the underlying model, drift in purpose, and outcomes that differ from the original justification. Monitoring should lead to action.

20

Some work should not be accepted

How we choose and refuse work →

K4M2 AI will refuse work where the primary value depends on practices that conflict with its purpose. This includes systems designed primarily for deception or impersonation, covert manipulation, compulsive engagement, exploitative surveillance, unjustified biometric tracking, suppression of meaningful human choice, avoidance of institutional accountability, discriminatory exclusion, harmful targeting of vulnerable people, unnecessary removal of responsible human judgement, or concealment of material risks or limitations. Not every difficult or controversial project should be rejected, but potential revenue does not create an obligation to build.

A review process for significant systems

The depth of review should reflect the level of risk. For significant systems, K4M2 AI should document the following.

Purpose

What problem is being addressed? Why is AI appropriate? Who benefits? Who may bear the risk?

Responsibility

Who approves deployment? Who reviews important outputs? Who responds when something goes wrong? How can affected people reach them?

Data

What data is required? How was it obtained? How long is it retained? What sensitive information may be inferred?

Performance

How was the system evaluated? Under what conditions does it fail? Which users or cases may experience worse results? What level of uncertainty is acceptable?

Human agency

Can people understand when AI is involved? Can they question or appeal important outcomes? Can they refuse or leave? Does the system build or erode capability?

Misuse and security

How could the system be abused? What access controls are required? What happens if the system or its data is compromised? Can harmful actions be detected and stopped?

Monitoring and withdrawal

What will be monitored? Who reviews the findings? What conditions require correction, restriction, or withdrawal? Can the system be safely reversed?

Four possible outcomes

Proceed. Proceed with safeguards. Redesign and reassess. Do not build or deploy.

Working with clients

Responsible deployment requires participation from the institution using the system. We expect clients to provide accurate information about the intended use, affected people, data, risks, and operational environment. We may require clients to assign accountable owners, establish human review, maintain appropriate security, inform affected users, provide appeal or correction mechanisms, monitor agreed risks, restrict unapproved uses, report significant incidents, and participate in periodic reassessment.

We may decline, suspend, or end work when a client materially changes the use of a system, conceals relevant information, removes required safeguards, or deploys the system in ways that conflict with the agreed purpose.

Reporting failures

Employees, contractors, clients, users, and affected people should have a way to report significant failures or concerns, reviewed according to their seriousness and potential consequence. Where justified, the response may include investigation, correction, notification of affected people, restriction of the system, suspension of deployment, independent review, contract termination, public disclosure, or withdrawal of the system.

People raising concerns in good faith should not be punished for identifying a risk or failure.

Public accountability

K4M2 AI intends to publish information about how this standard is applied. Depending on the company's stage and the sensitivity of the work, reporting may include the categories of systems reviewed, common reasons for requiring safeguards, categories of work refused, significant changes to the standard, material incidents and responses, lessons from failed or withdrawn systems, and exceptions approved and their justification.

Accountability does not require exposing protected information. It requires providing enough visibility to evaluate whether the standard influences real decisions.

This standard will evolve

AI capabilities, uses, risks, and social consequences will continue to change. This standard is not intended to be a permanent answer to every future question. It should be reviewed through experience from deployed systems, feedback from affected people, technical research, legal and regulatory developments, independent expertise, public-interest evaluation, and changes in the mission and work of K4M2A Foundation.

Changes should strengthen the standard's ability to protect human agency, responsibility, and well-being. They should not quietly lower the standard to accommodate work the company wishes to accept.

We do not want to build systems that merely perform more work. We want to build systems that help people and institutions become more capable without becoming less responsible.

The purpose of responsible AI is not to make every system harmless. No important technology is without risk. The purpose is to ensure that capability remains connected to human purpose, visible responsibility, meaningful choice, and the ability to correct mistakes.

What we build