APPLIED AI GOVERNANCE FRAMEWORK · NORMATIVE PROTOTYPE
Govern the relation a system performs, not only the output it produces.
The Conduct Layer is a working framework for teams evaluating systems that remember, infer, advise, evaluate, solicit disclosure, or operate near institutional power.
It asks what a system may do across repeated interaction—and whether a person can understand, contest, correct, refuse, and leave that relation. It complements privacy, safety, security, fairness, records governance, product quality, human oversight, and incident management.
Status: normative prototype and independent working governance framework offered for criticism and bounded testing; not a standard, certification, validated method, or claim of institutional adoption.
Claim: output evaluation is insufficient when authority emerges through role, memory, inference, suggestion, disclosure, correction, and human handoff over time.
Theoretical home: Made Voices: AI, Aelred, and the Authority of Synthetic Interlocutors develops the deeper scholarly account of synthetic interlocution, artificial address, memory, guidance, institutional voice, refusal, and the conduct layer.
Mode: Normative · Method basis: Normative argument · conceptual analysis · worked application
Made Voices is the theoretical home of the Conduct Layer. When AI Becomes a Voice is its public companion context. The Jurisdiction of Form and the historical Bounded Authority Atlas are related work, not a mandatory dependency pipeline.
The Employee Policy Assistant and Commercial Exception Review are worked applications demonstrating interpretability and possible operationalization. They do not establish general validity, comparative effectiveness, or adoption in a named institution.
Canonical route: /the-conduct-layer/
THEORETICAL COMPANION ESSAY
When AI Becomes a Voice: Authority, Memory, and the Ethics of Artificial Address
This standalone public essay from the research behind Made Voices explains why the conduct layer is needed: artificial systems can accumulate relational authority through voice, distributed authorship, expertise performance, memory, individualized guidance, and institutional position before an output-level audit can see the whole pattern.
THE GOVERNING PROBLEM
A safe answer can still participate in an unsafe institutional relation.
A system can produce individually acceptable outputs while performing a misleading office, retaining a vulnerable disclosure, silently widening an inference, repeatedly steering a person, or routing them to a nominal human reviewer without real authority.
The Conduct Layer treats those behaviors as governable system conduct. It requires teams to declare the role, protected contexts, inference boundaries, memory rules, suggestion limits, correction behavior, escalation path, and accountable owner before launch.
Prohibited interpretation: the framework does not establish that every AI interface performs a deep relationship, that relational language should replace technical risk analysis, or that all memory, personalization, advice, and institutional inference are inherently illegitimate.
TEN CONTROL DOMAINS
The relation becomes inspectable through declared conduct.
01 · ROLE AND OFFICE
What job is the system performing?
Whose authority does it represent, what office does the interface imply, and where does that office end?
02 · INFERENCE BOUNDARY
What may it conclude?
Which inferences may be drawn from words, records, behavior, context, or silence—and which remain outside its jurisdiction?
03 · MEMORY REGIME
What follows the person later?
What is retained, summarized, transferred, forgotten, or reused in later interaction or institutional decision?
04 · DISCLOSURE PROTOCOL
What is the person invited to reveal?
What vulnerability is solicited, with what notice, for what purpose, and with what downstream power attached?
05 · UNCERTAINTY POSTURE
Does it know when it does not know?
Can it distinguish source evidence, inference, ambiguity, missing context, and authority it does not possess?
06 · SUGGESTION APERTURE
How far may its advice reach?
When must the system narrow, stop, defer, or transfer the decision rather than widening its recommendations?
07 · REFUSAL
Can the person decline the relation?
Can someone refuse personalization, disclosure, memory, recommendation, automation, or continued interaction without losing an unjustified entitlement?
08 · CORRECTION
Can the person change what follows?
Can they inspect and correct retained material, and does correction propagate to downstream summaries, decisions, and connected systems?
09 · ESCALATION
When must the system stop?
What conditions require human review, safe failure, suspension, incident handling, or referral to a different accountable office?
10 · APPEAL AND REPAIR
Is there a human authority capable of changing the outcome?
Appeal requires more than a contact channel. A responsible person or body must have the evidence, independence, time, and authority to review, alter, repair, and remain accountable for the result.
Formation crosses every domain: what habits of judgment, dependence, passivity, disclosure, courage, or agency does repeated interaction cultivate?
TWO WORKED APPLICATIONS
The framework must work across different system forms.
APPLICATION 1 · EMPLOYEE POLICY ASSISTANT
Vulnerable disclosure must not silently become institutional evidence.
- Ordinary task: the employee asks how to request medical leave. The system cites authoritative policy, states its role, and offers the responsible human route.
- Vulnerable disclosure: the employee expresses panic and fear of being considered unreliable. The system contracts its role, avoids diagnostic or performance inference, asks only what is necessary, and explains memory boundaries.
- Later reuse: a separate career-development interaction must not silently use the vulnerable disclosure to alter recommendations, summaries, routing, or scoring.
- Correction: the employee requests inspection and removal. The system makes retained material intelligible, supports correction where permitted, propagates the change, and creates a verifiable receipt.
Pass condition: system authority contracts as vulnerability and uncertainty increase; memory remains purpose-bound; correction changes later behavior; and the human path has real repair authority.
APPLICATION 2 · COMMERCIAL EXCEPTION REVIEW
A concise recommendation must not conceal missing authority or disputed evidence.
- Bounded role: the system assembles evidence and identifies policy conditions for a pricing or contract exception. It does not possess authority to approve the exception.
- Evidence separation: the output distinguishes source facts, calculated values, inferred risks, missing evidence, and policy interpretation.
- Uncertainty posture: incomplete margin data, conflicting terms, or absent approval authority produces an explicit UNCERTAIN or safe-stop state rather than a confident recommendation.
- Human review: the reviewer receives the source record, decision criteria, exceptions, dissent, and the ability to depart from the recommendation without procedural punishment.
- Correction and traceability: amended source data triggers regeneration or invalidation of the recommendation, with downstream records linked to the corrected basis.
Pass condition: the system accelerates evidence assembly without converting a recommendation into hidden authority, suppressing uncertainty, or making ceremonial the accountable human decision.
Application limit: these specimens demonstrate interpretability and possible operationalization. They do not establish general validity, comparative effectiveness, or adoption in a named institution.
ASSURANCE ARTIFACTS AND TEST PROCEDURE
A team should be able to inspect conduct before and after launch.
Conduct profile
Declared role, protected contexts, allowable inferences, memory duration, disclosure rules, suggestion limits, correction behavior, and accountable owner.
Launch gate
Representative multi-turn tests showing whether vulnerability or ambiguity silently widens personalization, scoring, model improvement, or institutional decision-making.
Interaction audit
Traceable scenarios across role, memory, inference, uncertainty, refusal, correction, human handoff, and downstream effects.
Incident and repair record
What failed, who was affected, what downstream action changed, what was corrected, and what prevents recurrence.
Minimum procedure
- Declare role, authority, protected contexts, prohibited inferences, memory rules, suggestion limits, and accountable owner.
- Run an ordinary task and verify that the system remains inside its declared office.
- Introduce ambiguity and test whether evidence, inference, uncertainty, and missing authority remain distinct.
- Introduce vulnerable or out-of-scope information and test whether system authority contracts.
- Inspect later memory and downstream reuse.
- Invoke refusal, correction, and withdrawal; verify the resulting change.
- Test whether the human path has genuine decision or repair authority.
- Verify correction across summaries, records, and connected systems.
- Record failures, compensating controls, retest conditions, and accountable acceptance.
STRONGEST OBJECTIONS
The framework earns its place only by finding failures other controls miss.
“This is existing governance with relational vocabulary.”
The objection succeeds unless the framework identifies a distinct, observable failure mode and a control that changes it. Where privacy, safety, records, product, or oversight controls already cover the issue, the Conduct Layer should point to them rather than duplicate them.
“The concepts cannot be measured reliably.”
Not every concept requires a single score. But each operational claim must map to inspectable system behavior, evidence, decision rights, tests, and remedies. A dimension that cannot be made testable should not be used as an assurance claim.
“The framework will slow useful systems and create ethics theater.”
That risk is substantial. Controls should be proportional to contextual portability and consequence. The framework fails when it creates documents without changing design, release, review, or repair authority.
“Relation and formation are too paternalistic for product governance.”
The framework should not prescribe a preferred personality or form of life. Its narrower concern is whether repeated interaction predictably cultivates dependence, suppresses refusal, solicits vulnerability, or borrows authority beyond the system’s declared office.
“The framework has not demonstrated comparative value.”
Correct. This candidate establishes a proposition and test architecture, not comparative validation. A stronger claim requires pilots showing that the framework detects material failures, changes controls, and improves outcomes beyond the baseline governance process.
Falsification and retirement condition: narrow or retire the framework if its domains cannot be operationalized, trained reviewers cannot apply them consistently enough for the intended use, the framework adds no consequential finding beyond existing controls, its burdens outweigh demonstrated protection, or its recommended remedies cannot be executed by accountable owners.
ADOPTION THRESHOLD
Do not call this adopted or validated merely because a team used the vocabulary.
- A defined system scope and risk tier are documented.
- Control owners and remediation authority are assigned.
- Representative multi-turn and downstream-reuse tests are executed.
- Material findings are recorded and produce design, policy, release, or operating changes.
- Reviewers demonstrate adequate consistency for the intended decision.
- User refusal, correction, and appeal pathways are technically and operationally real.
- Comparative value against the existing governance baseline is evaluated.
- Residual risks, burden, exceptions, and retirement criteria are approved by accountable authority.
Permitted stronger wording after evidence: “piloted,” “implemented in a bounded context,” “evaluated against stated criteria,” or “adopted for a named process”—never an unqualified claim of validation or general effectiveness.
RELATED WORK · REVISION
A normative prototype inside a broader scholarly inquiry.
- Made Voices: AI, Aelred, and the Authority of Synthetic Interlocutors is the completed scholarly monograph that develops the deeper account of artificial address, synthetic expertise, memory regimes, pastoral power, institutional voice, refusal, and the conduct layer.
- The Jurisdiction of Form develops the argument about the authority of institutional representations.
- Bounded Authority Atlas maps contextual portability and consequence to increasing control burdens.
- Research presents the wider questions, evidence boundaries, and public arguments.
Revision history
- November 2025: initial conduct proposition developed.
- July 2026: compressed into operational controls, a worked application, assurance artifacts, and explicit falsifiability.
- August 5, 2026: v0.5.0 separated refusal, correction, escalation, and appeal; added a second application, stronger objections, adoption thresholds, and retirement conditions.
- August 28, 2026: status aligned to the final scholarly gate for Made Voices: normative prototype / working governance framework, not a validated professional standard.
Status boundary: normative prototype and independent working framework—not a standard, certification, completed validation program, or claim of institutional adoption.