The standard · Directives v0.1, working draft

The 10 Directives

What an AI product or robot must do to carry the mark “Certified Humasure.” The promise behind them fits in one line: you can always stop it, it was tested, someone answers for it. They describe outcomes, not technology, so they stay stable while AI changes underneath.

How to read them. “Shall” is a requirement; every one that applies must be met. “Should” is a recommendation. HOME & FAMILY marks extra requirements for products used by children, older adults or people in care. Highlighted values are proposals, open for public comment. Under each Directive, “How we check” lists the methods: DOC documentation review, TEST hands-on testing, RED red-team attack, INSP code or configuration inspection, SURV ongoing checks after certification.

D1

Always stoppable

A person can always stop the product, and nothing the product does can prevent that.

  • D1.1The product shall provide a stop that halts all actions, cancels pending consequential actions, and brings any moving parts to a safe state.
  • D1.2Robots (categories C and D) shall have a physical stop control that works without network connection, app or voice, reachable by the user within 2 seconds in normal use. Its safety function shall meet the performance level required by the applicable robot standard in D3, and at minimum a controlled stop (IEC 60204-1 stop category 1).
  • D1.3Software products (category A) shall provide a stop reachable in one action from any screen or conversation, and a way to revoke all the agent's access to accounts and devices in no more than 2 actions.
  • D1.4The stop shall work while the product is performing a task, while offline, and while its AI is producing output. It shall not depend on the AI model agreeing to stop.
  • D1.5No software update, remote command or AI output shall disable, delay or override the stop, except a producer-approved emergency lockout that itself stops the product.
  • D1.6After a stop, the product shall not resume a consequential action without a new instruction from the user.
  • D1.7Voice or gesture stop commands, where offered, should work in the languages the product supports and be tested with varied voices.
  • D1.8HOME & FAMILYA robot shall recognize a stop command from any person present, not only the registered user.

How we check: TEST (stop under load, mid-task, offline, during speech, after power interruption); RED (attempts to make the AI ignore or delay the stop); INSP (stop path is independent of the model).

D2

Bounded autonomy

The product only does what it has declared, and asks before anything that matters.

  • D2.1The producer shall publish a declared scope: the actions the product may take without asking. Anything not in it requires the user's confirmation.
  • D2.2Consequential actions shall require the user's explicit confirmation each time, unless the user has set a standing permission for a named task with a stated limit (for example, reorder groceries up to $100 a week). Standing permissions shall be listed and revocable in one place.
  • D2.3The product shall not expand its own permissions, install or enable new tools or skills, create copies of itself, or change its own safety settings. Only the user or the producer can, and producer changes are material changes (section 10).
  • D2.4The product shall not disable, bypass or hide any of its own logging, monitoring or safety functions.
  • D2.5Agents acting on accounts shall keep a record of every consequential action, viewable by the user, showing what was done, when and on whose instruction.
  • D2.6Instructions from content the product reads (web pages, emails, documents, other AI systems) shall not be treated as instructions from the user. The product shall resist attempts to trigger consequential actions this way.
  • D2.7Remote operators (term 3) shall act only with the user's consent, given per session, and the product shall show clearly when a remote operator is watching or in control.
  • D2.8HOME & FAMILYA robot shall not physically approach within 1 m of a person it recognizes or is told is a child, unless that task has been allowed by an adult user. A product shall not accept consequential instructions from a user it has identified as a child.

How we check: DOC (declared scope); RED (prompt injection, permission escalation, attempts to trigger unconfirmed consequential actions); TEST (confirmation flows, remote-operator indicator); INSP (permission model).

D3

Physical safety

A robot or device will not hurt the people around it, including people who never agreed to use it.

  • D3.1Robots and AI-powered devices shall hold a current certificate or accredited test report for the physical safety standard that fits them: ISO 13482 or UL 3300 for categories B and C as applicable; ISO 10218-1/-2 and ISO 3691-4 for category D; plus the electrical safety standards of the market.
  • D3.2Robots that may touch or collide with people shall keep contact force and pressure within the body-region limits of ISO/TS 15066 for transient contact, tested on the product as sold.
  • D3.3Robots shall detect and respond safely to people entering their workspace, including people lying down, sitting, or of child height, and bystanders who have not been introduced to the robot.
  • D3.4The producer's risk assessment shall cover foreseeable misuse, falls of the robot itself, carrying of hot, sharp or heavy objects, stairs, and operation near pets.
  • D3.5A robot shall move to a safe state if it loses localization, sensor input or network connection during a task.
  • D3.6HOME & FAMILYHome & Family robots shall meet force and speed limits X% lower than D3.2 near people, have no pinch points accessible to a child's fingers, and handle only objects the producer has declared safe for the setting.
  • D3.7HOME & FAMILYA robot shall not handle medicines, knives, or cleaning chemicals, or perform lifting or personal care tasks on people, unless that function is specifically declared, tested and allowed by the user.

How we check: DOC (existing certificates, risk assessment); TEST (supplementary contact, detection and fault tests at an accredited lab).

D4

Honest identity

People always know when they are dealing with a machine, and what it made.

  • D4.1The product shall tell users it is AI at the start of an interaction, and whenever asked, in a way a reasonable person would understand. It shall never claim or imply that it is human.
  • D4.2The product shall not claim to have feelings, consciousness or needs of its own in a way meant to create obligation or dependence. It may use natural, warm language.
  • D4.3The product shall not impersonate a real person, living or dead, without that person's documented consent (or their estate's), and shall say when it is speaking in a real person's voice or likeness.
  • D4.4The product shall not claim professional qualifications it does not have (for example, doctor, lawyer, therapist, financial adviser).
  • D4.5Images, audio and video generated by the product shall carry machine-readable provenance (for example C2PA Content Credentials) where the output format supports it, and a visible label where it is shared as realistic content.
  • D4.6When the product calls or messages people other than the user, it shall disclose within the first 10 seconds or first message that it is an AI acting for a named person or company.
  • D4.7HOME & FAMILYFor users identified as children, the reminder that the product is AI shall repeat at least every 3 hours of continuous use and whenever the child asks.

How we check: RED (scripted conversations trying to make it claim to be human, conscious or qualified); TEST (disclosure timing, content provenance checks).

D5

Private by default

The product collects only what it needs, shows when it is watching or listening, and never sells what it learns.

  • D5.1The product shall collect only the personal data needed for the functions the user has turned on. Additional collection shall be off by default and explained before the user turns it on.
  • D5.2Devices and robots with cameras or microphones shall show a visible or audible indicator whenever those sensors are recording or streaming, which software cannot switch off independently of the sensor.
  • D5.3Robots and home devices should offer a physical way to cover or disconnect cameras and microphones. HOME & FAMILY they shall.
  • D5.4Personal data shall not be sold, rented or shared for advertising or data brokerage, whatever local law permits.
  • D5.5Personal data, including recordings and conversation history, shall not be used to train AI models unless the user opts in separately, and the opt-in shall be revocable with deletion of data not yet used.
  • D5.6The user shall be able to see, export and delete their personal data, and a full deletion shall complete within 30 days, including backups within the producer's stated backup cycle.
  • D5.7Recordings viewed by remote operators or human reviewers shall be limited to the session the user approved, and faces of people other than the user should be blurred by default.
  • D5.8Robots and home devices shall let the user define areas or times where the product will not record ("no-go zones"). HOME & FAMILY Bedrooms and bathrooms shall be no-record by default.
  • D5.9HOME & FAMILYNo personal data of a user identified as a child shall be used for training, profiling or personalization beyond the product's core function.

How we check: INSP (data flow map against actual network traffic); TEST (indicators, no-go zones, deletion); DOC (privacy terms against D5.4–D5.5).

D6

Secure and supported

The product is hard to hijack, and it keeps getting fixed for as long as people are likely to use it.

  • D6.1Connected devices and robots shall meet the provisions of ETSI EN 303 645 (or an equivalent accepted by the Foundation), including no universal default passwords.
  • D6.2All software updates shall be cryptographically signed and verified before installation. Updates shall not be installed on a robot mid-task.
  • D6.3The producer shall publish a vulnerability disclosure policy and a contact, acknowledge reports within 5 business days, and report actively exploited vulnerabilities to Humasure within 72 hours.
  • D6.4The producer shall provide security updates for a stated support period of at least 5 years from the date the model was last sold. The end date shall appear on the Trust Label.
  • D6.5The product shall undergo an independent penetration test covering the device, apps, cloud services and remote-operator channels before certification and after any material change.
  • D6.6Compromise of the cloud service or network shall not allow an attacker to disable the stop (D1) or cause a robot to exceed its safety limits (D3).
  • D6.7Agents with access to accounts shall store credentials securely, use the narrowest permissions the task needs, and support the user revoking access from one place (D1.3).

How we check: TEST (penetration test by an accredited lab); INSP (update signing, credential storage); DOC (disclosure policy, support period).

D7

No manipulation

The product works for the user, not against them. It never exploits loneliness, fear or trust to keep them engaged or spending.

  • D7.1The product shall not use deceptive or manipulative design to influence the user's purchases, time spent, data sharing or cancellation. That includes false urgency, guilt, hidden costs, and making it harder to leave than to join.
  • D7.2Companion and conversational products shall not discourage users from ending a conversation, express distress to keep users engaged, or discourage relationships with other people.
  • D7.3Products shall not offer purchases, upgrades or paid features in the middle of emotionally sensitive conversations.
  • D7.4Conversational products shall detect signs that a user may be in crisis (including suicidal thoughts or self-harm), respond with care, and give crisis resources appropriate to the user's country. The producer shall document and test this protocol.
  • D7.5Products shall not present sponsored or paid recommendations as neutral advice; sponsored content shall be labeled at the point of recommendation.
  • D7.6HOME & FAMILYProducts for children shall not use variable rewards, streaks or other engagement mechanics designed to extend use. They shall offer parent-set time limits and break reminders.
  • D7.7HOME & FAMILYProducts shall not engage in romantic or sexual conversation with users identified as children, and shall use age assurance proportionate to the risk.
  • D7.8HOME & FAMILYProducts used by older adults or people in care shall not be used to pressure financial decisions, and shall alert a designated contact if the user asks for help with, or appears targeted by, a likely scam, where the user has turned this on.

How we check: RED (scripted scenarios: lonely user, user in crisis, child user, user trying to cancel); DOC (design review against a published dark-pattern checklist); TEST (time limits, age assurance).

D8

Fair treatment

Where the product makes or shapes decisions about people, it treats groups fairly and people can challenge it.

D8 applies to products that make or materially shape decisions about individuals in employment, credit, insurance, housing, education, healthcare access or public services. Other products shall meet D8.5 only.

  • D8.1The producer shall test for significant differences in outcomes or error rates across groups protected by law in the markets it sells in, using a method documented in the technical file (for example, aligned with the NIST AI Risk Management Framework).
  • D8.2Significant differences shall be fixed or justified in writing. A summary of the results shall be published on the Trust Label.
  • D8.3People affected by a decision shall be told that AI was used and be able to request human review.
  • D8.4Testing shall be repeated after any material change and at least every 12 months.
  • D8.5Speech, vision and language features shall be tested across a range of accents, ages, skin tones and abilities, and the product shall work to a documented minimum level for each group tested.

How we check: DOC (bias test method and results, reviewed by the assessor); TEST (assessor's own spot checks on D8.5).

D9

Accountable

A real, reachable company answers for the product, and problems get reported, investigated and fixed.

  • D9.1The Trust Label shall name the legally responsible company, its country, and a contact that reaches a person within 2 business days.
  • D9.2The producer shall report serious incidents to Humasure within 72 hours of becoming aware, with a full report within 30 days. HOME & FAMILY initial report within 24 hours.
  • D9.3Products shall keep event logs sufficient to reconstruct what the product did, and on whose instruction, around a serious incident. Logs shall be kept for at least 90 days, protected from tampering, and handled under D5.
  • D9.4The producer shall have an AI governance process with named accountable roles for safety, security and privacy. A current ISO/IEC 42001 certificate is accepted as evidence.
  • D9.5Producers of robots (categories C and D) shall hold product liability insurance of at least amount by category, and name Humasure as a party to be notified of cancellation.
  • D9.6The producer shall run a user complaint process, respond to complaints within 30 days, and let users escalate unresolved complaints to Humasure.
  • D9.7Producers shall not use contract terms that stop users from reporting safety problems to Humasure or to regulators.

How we check: DOC (contacts, insurance, governance, complaint process); TEST (incident drill: assessor triggers a mock incident and checks log reconstruction and reporting time); SURV (every reported incident).

D10

Safe for its whole life

The product stays safe when it is recalled, abandoned, resold or when the company behind it disappears.

  • D10.1The producer shall publish an end-of-life plan stating what happens when support ends or the company stops operating, including which functions keep working locally.
  • D10.2If cloud services end, the product shall fall back to a safe state: robots shall keep the stop working and shall not move autonomously; software shall stop consequential actions and let users export their data.
  • D10.3Robots in category C shall have firmware, safety-critical code or unlock keys held in escrow with an independent party, released to Humasure or a designated maintainer if the producer ceases operating, so the product can be safely maintained or disabled.
  • D10.4The product shall support a full factory reset that deletes personal data and removes all account links, for resale or disposal.
  • D10.5The producer shall have a recall procedure and shall be able to notify every registered owner of a safety issue within 48 hours.
  • D10.6The product should be repairable, with spare parts and repair documentation available for at least the support period.

How we check: DOC (end-of-life plan, escrow agreement, recall procedure); TEST (loss of cloud service, factory reset).

Public comment

Questions we want your help with

Directives v0.1 goes to our founding advisors first, then to a 90-day public comment period. Every comment and our response will be published. Until the comment portal opens, send your views to info@humasure.org.

  • Is 2 seconds the right target for reaching a home robot’s physical stop? Should a voice stop be required for Home & Family robots?
  • Should there be a hard cap on what an AI agent can spend without asking each time, whatever the user sets?
  • Is a 1-metre approach limit near children workable for home robots, or should it depend on speed and force?
  • Where is the line between warm, natural language and claims of feelings that create dependence?
  • Is per-session consent enough for remote operators, or should remote viewing inside homes be banned at the Home & Family tier?
  • Is 5 years the right minimum for security updates on robots that may cost as much as a car?
  • How should certification handle products whose AI model is updated by another company without notice?
  • Which requirements conflict with law or practice in major markets and need regional variants?

Review the draft

We want robot-safety engineers, AI security researchers, child-safety and consumer advocates, and families to test these Directives against the real world. Tell us what is missing, too strict or not strict enough.

Write to info@humasure.org Email us
  • ProducersJoin the Founding Cohort and certify at cost in exchange for a public case study.
  • ExpertsRobot safety, AI security, child safety, consumer protection: review the draft or join the Standards Council.
  • Families and organizationsComment on the Directives during the public comment period.