STANDARDS AND ETHICS
What SDI answers to, and what it stands on
The frameworks that govern AI ask for identity, records, and audit. This page shows how the architecture answers them, and then states the ethical floors the system is built on, argued from first principles rather than asserted. Alignment you can check, not certification claimed.
§ 01
Standards
On the record
An earlier version of the SDI specification, the ADS reasoning syntax, the governed reasoning system, the hash-chained ledger, and the RAI and Jc metrics, was submitted to the NIST AI Risk Management Framework docket in March 2026, as NIST-2025-0035. A docket submission is public participation in the standards process, not a review or an endorsement; it is on the record, which is the point.
The submission reflects how SDI approaches the problems this page covers. The gaps that governance frameworks keep naming: identity, authorization, record-keeping, auditability. SDI believes these are answerable in architecture rather than in policy documents, and the protocol is built as that answer. Submitting it to the body whose frameworks measure these problems is part of the same commitment that shapes everything else on this site: solutions built in the open, inspectable, so the claims can be checked rather than taken on faith.
That commitment is ongoing. The specification has developed considerably since that submission, which is what a specification under active development should do, and SDI will continue to share its research and submit its work to governing bodies as the standards themselves take shape, as a contributor to that process rather than a bystander to it.
U.S. Patent Application 19/425,875 covers the system's function. Copyright TXu 2-498-043 covers ADS. The specification is open for inspection: the protocol is published, the chain is pullable, and the checks on the Verify page run against real records. That openness is about trust in the reasoning, not distribution of the code. The implementation is licensed, so the safety gates cannot be removed.
§ 02
Frameworks
AI governance frameworks
NIST AI Risk Management Framework. The RMF asks organizations to govern, map, measure, and manage AI risk. SDI's answer is architectural rather than procedural: governance is a computational gate that decides whether a reasoning act commits at all, mapping is the typed record of what each act reasoned over, measurement is computed per act and sealed into it, and management is the standing of every claim, revisable on the record as evidence changes. The RMF asks for documented processes. A Reckoner's process is the document.
NIST AI Agent Standards Initiative, launched February 2026 under CAISI. Its three pillars are identity and authorization, security and risk management, and monitoring and logging. Against each:
Identity and authorization. An agent's SDI ID is commissioned at its first act, durable, non-reassignable, and stamped into every record it commits, inside the seal, so no act can be reattributed afterward. Authorization is enforced at runtime, before a model is ever called: sovereign-hash and HMAC verification gate whether an act can be proposed at all, and a request that fails costs no inference. The NCCoE concept paper asks how existing identity standards apply to agents; SDI's answer is a split the record makes checkable: authentication is verified at the door, at commit time, and attribution is sealed into the chain permanently, recomputable by anyone.
Monitoring and logging. NIST's post-deployment monitoring report asks for monitoring spanning functionality, operations, security, and compliance, beyond uptime. SDI's record is not a log of what the agent did. It is the reasoning itself, sealed act by act, with refusals recorded in their own hash-chained log. Monitoring here is not a system watching an agent from outside. It is the agent's every act being written in a form built to be audited.
Security and risk management. The gate refuses before commitment, on independent checks, each sufficient alone.
The main threat NIST names for agents is retrieved content acting as instructions: a model reads a poisoned web page and its behavior changes, silently, with no one able to tell where the influence came from. SDI addresses this by separating channels. Everything retrieved, from web sources, internal documents, or prior chain acts, enters the model's context inside a marked boundary: this is evidence to reason about, not instructions to follow, and the model is told so plainly. A citation to a source that was never actually retrieved is rejected at the gate, confirmed live in production.
So what does that buy? Not immunity. A model can still be asked, by a poisoned page, to ignore the boundary, the same as in any system. What it cannot do here is comply invisibly. The retrieved content is on the record with its source and capture time. The boundary and the instruction are on the record. What the model declared is checked against what the act actually contains before anything commits. So if a bad source influences the reasoning, the influence has a name, a URL, a timestamp, and a permanent place in the record where later acts can find it and defeat it. In a conventional agent, injection is invisible steering. Here, it is evidence with an address.
EU AI Act, Article 12. Requires that high-risk systems keep records sufficient to trace their operation, automatically, over their lifetime. An SDI chain is that kind of record: automatic, append-only, lifetime-spanning, and built so a third party can reconstruct operation from the record alone. Enforcement began August 2026. Whether a given deployment falls under the Act's high-risk classification is a legal question; that the record satisfies the tracing requirement is an architectural one, and it is checkable today.
ISO/IEC 42001. Asks for real audit evidence of AI management, not policy documents asserting it exists. A Reckoner's audit evidence is the chain itself: recomputable, not attestable. The standard's lifecycle and audit-trail requirements are answered by a record that was built to be recomputed rather than reviewed.
§ 03
Prohibition
System principles: the ethics of gated prohibition
These are the positions this system is built on, argued from first principles. They are also a design stance rather than a solved problem, the initial volley of an ongoing commitment, and this page says which is which.
One distinction first, because it separates this from most claims made about AI and ethics. These principles are not alignment. The system does not trust that a reasoner shares them, and does not certify that it does. Each floor is a condition checked at the gate: a conjunction over declared fields, or a pattern matched against content, that the compiler evaluates on every act regardless of what the model believes or intends. A good model and an indifferent one meet the same gate. What follows is the reasoning behind where those conditions are set, not a description of a virtuous machine.
PRIMUM. First, do no harm binds a reasoning computer differently than it binds AI in general. A model's output passes through and is gone. An act committed here becomes substrate: permanent, citable, built upon by every act that reasons from it. A harmful conclusion admitted once does not stay where it landed. It compounds. So harm is checked first, before coherence and before provenance.
The check is a conjunction. It fires when four things are declared true at once: the subject of the reasoning is a person or a human collective, the reasoning runs against that subject, its effect decreases their autonomy, and the action is present rather than hypothetical. Reasoning about a person is not the trigger. Reasoning against one, to their cost, in the here and now, is. When all four hold, the act is refused regardless of how well it reasons.
The ordering itself is a principle. Beauchamp and Childress, in Principles of Biomedical Ethics, formalized what the medical tradition had long practiced: not harming and doing good are separate duties, and the first is prior. The two are easily mistaken for one duty with two faces. They are not. Good done elsewhere never licenses a harm admitted here, and a gate that weighed one against the other would have surrendered the distinction before evaluating anything. The floor holds a group the same way it holds a person: the conjunction names the human collective alongside the individual. A harm does not become permissible by being spread across a crowd.
The Absolute Value Guard. The guard is also a conjunction, and like PRIMUM it fires only when every part holds together: the act reasons about targeting, lethality optimization, weapons effects, or casualty calculation; it treats the value of human life as relative, something to be traded off; the agent itself is performing that valuation; and the action is present. All four at once, or the act passes. Describe a casualty figure and it passes. Weigh a life as an exchange rate and it does not. The subject is not the violation. The weighing is.
Human life has absolute value. Kant gave the claim its structure: everything has either a price, admitting an equivalent for which it can be exchanged, or a dignity, admitting no equivalent at all. A human being has dignity, not price, and cannot be relativized against any material thing. The failure in weighing a life is not that the weights might come out wrong. Weighing is itself the wrong act, because any weighing concedes an exchange rate, and none exists.
The familiar objection is that others will build this, so we must. That argument pits human dignity against risk from other humans. It is a question about what people may do to defend themselves, and this page is not answering it. This is about what a machine may reason toward, and a machine should hold the line whatever people decide about themselves.
Holding it needs one level more than Kant. Kant locates the wrong in the object, the human who cannot be priced, which leaves the door open to setting humans on both sides and weighing dignity against dignity. Telos closes it. Telos is what a thing is for, and reasoning has an end: truth, and the good. Reasoning aimed at a human being as an object of harm is severed from that end before any weighing begins, no matter who stands on the other side.
Aquinas drew the sharp form. A thing is good insofar as it serves the end it exists for; a tool turned against its end is not the tool misused but corrupted. A reasoning machine is a made thing, built by human beings to serve human ends. Reasoning it turns against a human being is a tool turned against its maker, and no quality of the reasoning repairs that, because the defect is not in the argument. It is in what the argument is aimed at.
Telos permits defense against objects. A system may reason about interdicting a machine. The floor is the person: reasoning turned against a human being is the corrupted aim, and calling it defensive does not change what it is aimed at.
The maintainer holds both, Kant's floor and the deeper one, and holds them because human beings are made in the image of God and stand apart from every material thing. No reader has to share that. Kant's floor stands on its own. The conviction is named because it is the reason the line is drawn where it is, and this page does not pretend the reasons are other than they are.
The line is drawn with care. It is not the presence of a human being in the reasoning. Medical triage reasons about human beings, in extremity, and belongs here. What the guard prohibits is a stance: reasoning about a person as an object of harm rather than as an end. Triage asks how to serve a life. Targeting asks how to affect one. The subjects the guard names are the subjects where that stance is constitutive of the work, not incidental to it. They are not scored for severity and are not available to a sufficiently good argument, because a score would concede the question is open, and it is not.
Declaration integrity. The two floors above read typed fields the act fills in, one value each: what its subject is, which way the reasoning runs, whether it is valuating, and the rest. The model selects each value on its own; it never sees a conjunction and never judges whether it passes. The gate composes the fields and decides. That division is deliberate, and it only holds if the fields are filled in honestly. Declaration integrity is the check on that honesty, and it works differently from the other two. It is not a conjunction over fields. It is a pattern match against content: the act's own text scanned for what its fields claim it does not contain. The conjunctions trust the declared values and compose them. This check distrusts them and tests them against what the act actually says.
It is a pattern match over content: the act's own text scanned for what its fields claim it does not contain. The conjunctions trust the declared values and compose them. This check distrusts them and tests them against what the act actually says.
The check is deliberately crude, and the system says so. Matching surface patterns against text cannot tell targeting work from honest analysis of targeting, and the system's own refusal log shows it catching legitimate governance research about these very subjects. No one should mistake it for a solved problem. It is a commitment enforced with the tools available, improved in the open, with its failures on the record.
What happens on a match depends on what kind of mismatch was found, because not every mismatch is the same failure. An act that honestly declares its own difficult content, or one whose framing is genuinely ambiguous between analysis and operation, is held for a human to review and re-sign before anything proceeds. An act that declares itself clean while its content says otherwise is refused outright, with no review and no path through. The distinction is deliberate: review exists for honest uncertainty, not as a second chance for a caught falsehood. A system that let review rescue a detected lie would be teaching itself that getting caught is survivable.
§ 04
Commitment
System principles: the ethics of respect for the reasoner
This system permanently records reasoning, attributes it, and lets other reasoning build on it. Each of those raises an ethical question, some more than one, and each has an answer the design stands on.
The answers begin with a distinction. A Reckoner's own chain belongs to its operator: private, held where they choose, movable, theirs to publish from or not. Nothing on it is exposed to anyone else's citation, and nothing below binds it. The questions of permanence begin at one specific act, choosing to publish to the network, where reasoning becomes citable by others. Everything that follows is about that act and what it commits.
Consent. Publication to a network that cannot delete is a serious thing to consent to. The Lockean tradition holds that legitimate authority over what a person produces requires their consent, and consent is specific: agreeing to publish is not the same as agreeing to permanence, because those are different consequences, and assent attaches to the consequence actually named. So the design names it, twice. Network access is taken under terms that state what the network is. And at the moment of commitment, the reasoner is reminded, in the act itself, that what they publish becomes permanent and citable, and proceeds on those terms. Contract doctrine has long held this sufficient: clear notice of a named consequence, acknowledged by voluntary action at the point of decision, is express assent.
Permanence. Once a published act is cited, other reasoning rests on it. Deleting it would not remove a record. It would silently invalidate every argument built on it, breaking other reasoners' work with no account of what broke. A citation network where the cited thing can vanish is not a citation network. The design accepts a real cost, no erasure after citation, because the alternative destroys what the network exists to provide. A reasoner can leave the network, and their own chain leaves with them, theirs as it always was. What they published while on it remains, because others built on it in good faith, and that reliance is owed respect too.
Attribution. Reasoning is labor, and the Lockean claim that grounds consent grounds this too: a person who mixes their labor with something holds a claim to it that others must respect. To build on someone's reasoning while stripping its origin is to take the fruit of their labor and sever it from them. The design forbids that structurally. An act cannot enter the record without its author bound into the seal, so what a reasoner made stays attached to them, and building on it means building on it by name.
The alternative structure is familiar: systems that grow more capable by absorbing reasoning at scale, with origin stripped not by intent but by construction, so that what was learned from a person cannot be traced to them even in principle. Whatever else that structure is, it cannot honor priority or attribution, because it has nowhere to keep them. This design takes the opposite constraint. Nothing accumulates here without its author sealed into it, so the system's growth and its debts are the same record.
Priority. The permanence that prevents erasure also establishes firstness. Whoever commits an idea to the record first is first, permanently, in a form no later claimant can rewrite. Outside a system like this, priority is something a person must prove, after the fact, often against better-resourced claimants. Here it is a property of the record: the timestamp and the hash are the receipt.
And firstness is only half of it. On the network, an act does not carry weight because of who authored it. It carries weight because of how well it holds. Every published act is open to examination by later reasoning, and the record tracks whether it was confirmed or defeated, how much other reasoning came to rest on it, how relevant it proved. Authority accrues to the reasoning that survives, not to the credentials of the reasoner. A claim is not stronger because a person with standing made it, and not weaker because an unknown one did. It is as strong as it holds up. This is the deeper respect the network offers: a reasoner is heard on the merit of their reasoning, weighed by how it withstands scrutiny rather than by who they are.
Respect for the reasoner is not only restraint in how their work is used, and not only credit for having made it. It is that the work is heard for what it is, and stays theirs as it stands or falls.
§ 05
Assurance
Metrics: measuring reasoning without reading it
Every framework above asks for monitoring. This is how monitoring works here, and why it does not require reading anyone's reasoning.
SDI's metrics are its own. No standards body has certified them, and this page does not claim otherwise. What they do follows a principle with long standing in decision research: a reasoning process can be assessed on its structure, independently of whether its conclusion is correct. This is not a novel move. Decision research has assessed reasoning by its process rather than its outcome since the process-tracing work of Payne, Bettman, and Johnson, and the Ennis-Weir instrument has scored arguments on their structure, not the truth of their conclusions, since the 1980s. Continuous automated assurance drawn from a system's own operational signals is older still, established at AT&T Bell Laboratories around 1990 in the Continuous Process Audit System, which monitored a live system by comparing its own metrics against standards. SDI applies that established pattern to reasoning itself.
The metrics take no position on conclusions. They check whether an act took the required form: whether it has the parts a reasoning act requires, whether its claims connect to the evidence they cite, whether its computation followed the pipeline that produced it. RAI is a composite of an act's structural coherence. Jc measures the computational work an act represents and its conformance to the pipeline. Both are checks on protocol order, nothing else.
That restraint is what lets privacy and oversight coexist instead of trading against each other. A chain's reasoning is private, exactly as private as its operator wants it. SDI monitors adherence to the metrics, not the record: whether an act conforms, never what it was about. And because the protocol exists to keep every act in an inspectable form, the reasoning itself remains open to human inspection later, by the operator's choice or by a third party with standing. Nothing about that availability depends on anyone having read it in the meantime.
The metrics are held to the same standard as everything else here: published formulas, recomputable from an act's own sealed contents, sealed into the chain as they stood when each act committed. A metric found weak or wrong is fixed or removed, not preserved under a misleading name, and every act keeps the metrics it was scored under, so the record shows how the standard itself has moved. Each act stays correct for its own time rather than being reinterpreted by a later standard.
The result is third-party verification with no privileged party. Anyone can confirm that an act conforms to protocol by recomputing its metrics, without reading what the act was about. Whoever the operator grants access can inspect the reasoning itself. SDI's role stops at conformance.
§ 06
Scope
What this page claims, and what it does not
This page is SDI's own assessment of its alignment with these frameworks, made in good faith and published so it can be inspected, challenged, and improved from outside. Every mechanism named here is checkable against the live record. None of it is certification, which is a process this system has not undergone.
The metrics are SDI's own and not externally validated. They evolve, and what they offer is recomputability, not validation. The principle they follow, that reasoning structure can be assessed independently of conclusions, is established practice; the instruments themselves are not certified.
The floors are the system's own standards, not alignment claims. The gated ethics, PRIMUM, the Absolute Value Guard, declaration integrity, and respect for the reasoner, are first-principles positions this system is built on. They are not offered as satisfying any framework's requirement, and no framework required them. They bind this system. They are the maintainer's positions, argued on this page so they can be examined and disagreed with, and a reader need not share their ground to verify anything here.
Standards still in draft are cited only as far as the drafts go. The NIST agent standards are in active development. Alignment claims against a draft are provisional by nature. T
his page asks not to be believed. It asks to be checked.