People compare offline models, inspect archives, teach across generations, and maintain physical and digital recovery media.
AI, LLMs, autonomy & knowledge · Conceptual generated illustration. Interfaces are intentionally unreadable and do not depict an operational AI authority model.

Evidence boundary: NIST and UNESCO provide present risk-management and normative guidance for trustworthy, accountable, privacy-respecting AI. NASA standards provide software assurance and safety methods. None establishes a constitution for AI in a permanently isolated society, and no cited system has maintained safe, legitimate judgment across generations. This lesson proposes governance boundaries; it does not confer legal authority or certify any system. It is civil-and-defensive and excludes offensive cyber operations, autonomous weapons, weapon integration, and actionable exploitation instructions. Cyber, dual-use, governance, and life-safety provisions require two-person review.

Plain-language summary

An AI constitution answers a prior question to “What can the system do?”:

What may it do, for whom, under which evidence, with which appeal, and who remains accountable?

The constitution should bind the surrounding institution, not ask the model to regulate itself. It defines permitted advisory roles, prohibited decisions, tool permissions, source duties, privacy limits, update gates, audit, emergency authority, and remedies.

Its core commitments are:

  • people retain rights and accountable authority;
  • safety does not depend on generative models;
  • consequential output is traceable to controlled evidence;
  • every automated effect has an external permission boundary;
  • no model approves its own update or evaluation;
  • residents can know, challenge, and correct consequential use;
  • emergency powers are narrow and temporary; and
  • the ship can operate safely with AI isolated.

Why a constitution rather than a policy prompt?

A system prompt is interpreted by the model and can be displaced by context, error, injection, or update. A constitution is implemented across technical controls, institutional rules, training, oversight, and rights.

It should exist in human-readable law or charter, machine-readable policy, system requirements, tests, operating procedures, and audit records. Conflicts between those forms must be visible and resolved through legitimate governance.

NIST’s AI Risk Management Framework organizes work through Govern, Map, Measure, and Manage. It is voluntary and does not decide a ship’s constitution, but it reinforces that risk is sociotechnical and lifecycle-wide.

Define roles by consequence

Classify uses before selecting a model:

Informational

Search, translation, summarization, tutoring, drafting, and explanation. Even here, the model can expose private data or invent evidence. Require source links, revision state, uncertainty, and a non-AI interface.

Recommending

Candidate maintenance, schedules, diagnoses, designs, or resource plans. The output remains a proposal. Show alternatives, assumptions, conflicts, and expected consequence. Independent people and deterministic checks decide.

Executing bounded tools

A model may prepare a typed request to an external tool only when the user already has that authority. External systems enforce identity, scope, rate, schema, range, and safety. Preview and confirmation are required for consequential effects.

Controlling

Direct life-support, medical, navigation, nuclear, identity, judicial, or industrial-safety control is prohibited for generative models. Verified controllers and bounded automation may act inside separately assured contracts.

Governing

AI cannot vote, hold office, determine rights, define legal personhood, adjudicate guilt, set reproductive eligibility, choose who receives basic life support, or count as an independent reviewer. It may support research and clerical work under the other rules.

Nondelegable human accountability

“The AI decided” is not an accountable explanation. Every consequential use needs a named human or public body responsible for:

  • authorizing the purpose;
  • ensuring lawful and rights-respecting data use;
  • selecting evidence and evaluation;
  • accepting residual risk;
  • reviewing operation;
  • responding to harm; and
  • retiring the system.

Responsibility should not be assigned to the lowest-status operator who clicked “confirm.” Designers, maintainers, authorities, and institutions retain their shares.

High-consequence approval requires two qualified people with sufficiently independent evidence and declared conflicts. A second model, a second answer from the same model, or an AI evaluator is not the second person.

Evidence duties

Consequential output should carry an evidence packet:

  • model, runtime, prompt, tool, and configuration versions;
  • retrieval corpus and exact retrieved records;
  • source revision, locator, review state, and conflicts;
  • user identity and authorized role;
  • input and output, including rejected proposals;
  • distinction among observation, retrieved record, inference, simulation, and recommendation;
  • uncertainty, abstention, and unresolved contradiction;
  • tool preview and resulting state;
  • human decision and rationale; and
  • appeal, correction, and retention status.

The authoritative evidence/requirements graph remains outside the model. The model may query it but cannot silently invent or rewrite relationships. Cryptographic signatures establish integrity and authenticity under a policy, not truth, currency, legitimacy, or safety.

Privacy and limits on surveillance

An isolated community may be tempted to treat total observation as safety. That can create coercion, chill reporting, and make political control look like anomaly detection.

The constitution should require:

  • declared purpose and legal basis;
  • minimum necessary data;
  • separation of process telemetry from personal behavior;
  • restrictions on medical, reproductive, genetic, civic, and communications data;
  • access logging and resident visibility;
  • retention limits and legitimate deletion;
  • correction of inaccurate records;
  • protection against unrelated reuse;
  • independent authorization for invasive access; and
  • appeal and remedy.

Training or improving a model is not automatic permission to reuse personal data. De-identification has limits, especially in a small population.

Prompt, tool, and data integrity

Instructions embedded in a document, telemetry field, website, or message can attempt to redirect a tool-using model. Treat retrieved content as data, never authority. Model output remains untrusted until external controls check it.

NIST AI 100-2 also describes data and model poisoning, evasion, privacy, and misuse. The constitution should mandate:

  • provenance and separated approval for model, data, prompt, and tools;
  • quarantine and testing of new material;
  • least-privilege tools;
  • no secret-bearing context unless strictly required and controlled;
  • independent logging the model cannot erase;
  • red-team and misuse testing inside a defensive sandbox;
  • rollback and recovery;
  • refusal to act on unresolved provenance; and
  • incident notification and correction.

Testing stays civil and defensive. It must not become live intrusion practice or weapon development.

Evaluation and abstention

An evaluation must match the real use, users, environment, consequence, language, and workload. Report not only average success but severe errors, distribution shifts, privacy harms, tool misuse, false confidence, and failures to abstain.

Abstention is bounded behavior, not a magic phrase. Define when the system must:

  • state that evidence is missing;
  • show conflicting sources;
  • refuse an out-of-scope tool action;
  • route to a qualified person;
  • fall back to a controlled procedure; or
  • isolate itself after integrity loss.

Over-refusal can also harm people by blocking access or delaying service. Evaluate both unsafe action and unsafe refusal.

Updates require constitutional review

A new model, retrieval corpus, tool, prompt, fine-tune, quantization, runtime, or safety rule can change behavior. Each consequential update moves through the update airlock:

  1. preserve the old configuration;
  2. document purpose, provenance, and affected rights;
  3. evaluate on representative and adversarial cases;
  4. check resource, privacy, and accessibility effects;
  5. test common-mode failure and rollback;
  6. obtain independent technical and rights review;
  7. deploy in stages with defined health measures; and
  8. retain a tested non-AI workflow.

The model cannot generate the decisive evaluation, approve itself, or erase unfavorable results.

Diversity without a parliament of models

Multiple models may improve exploration and reveal disagreement. They do not create legitimate authority and may share data, architectures, cultural assumptions, runtime, or evaluators.

Record independence across:

  • training and retrieval data;
  • developers and governance;
  • model family and implementation;
  • hardware, runtime, and toolchain;
  • evaluation and reviewers;
  • sensor and evidence sources; and
  • incentives and institutional power.

For safety, prefer diverse physical evidence and accountable people over majority vote among models.

Appeal, correction, and remedy

Any person materially affected by AI-supported action should receive understandable notice where safety and privacy permit:

  • that AI contributed;
  • which role it played;
  • the governing rule;
  • the evidence and uncertainty;
  • the accountable authority;
  • how to contest records or outcome; and
  • what remedy is available.

Appeal must reach an independent human body capable of changing the outcome. Preserve dissent and corrections in the evidence graph without rewriting the original event.

Emergency authority expires

During an acute incident, temporary AI support may help summarize logs or allocate attention. It still cannot determine guilt or directly bypass physical safety.

Emergency access needs a trigger, scope, duration, owner, log, resident notice, review, and automatic expiry. Restoring ordinary authority is part of incident recovery. A recurring emergency cannot become the constitution.

Skill retention and AI-off governance

Rights on paper fail if nobody can operate without the system. Maintain:

  • deterministic search and plain exports;
  • manual local control;
  • people trained to read primary evidence;
  • mixed-team exercises without AI;
  • the ability to rebuild or replace models locally;
  • lessons on automation bias and confident error; and
  • independent institutions with enough time and expertise to review.

The recurring test is not “Can people turn it off?” but “Can they remain safe, informed, and governed after turning it off?”

Evidence ledger

  • L10-05-A — An AI constitution is a proposed sociotechnical governance layer, not a property encoded in a model prompt. Basis: normative. Readiness: early research. Confidence: supported.
  • L10-05-B — Current AI risk frameworks identify lifecycle, privacy, information-integrity, human-configuration, and governance responsibilities. Basis: observed. Readiness: operational as voluntary guidance. Confidence: strong.
  • L10-05-C — Generative models should not hold direct life-safety, identity, judicial, or constitutional authority. Basis: normative decision boundary. Readiness: proposed. Confidence: strong.
  • L10-05-D — Prompt/tool injection, poisoning, confabulation, privacy loss, and automation bias require external controls and evaluation. Basis: observed risk classes. Readiness: early research for high-consequence mitigation. Confidence: strong for risks, tentative for control sufficiency.
  • L10-05-E — Model diversity does not establish independence, truth, or legitimacy. Basis: normative systems inference. Readiness: operational as analysis. Confidence: supported.
  • L10-05-F — Safe AI-off operation, notice, appeal, correction, and expiring emergency authority are launch gates. Basis: normative. Readiness: proposed. Confidence: supported.

Linked corpus claims: claim-11-01, claim-11-04, claim-11-06, claim-11-07, claim-11-10, claim-12-06, and claim-12-10. See the claim registry for each record's current evidence grade and independent-review state.

Assumptions and limits

  • “Constitution” means binding governance and rights architecture, not a present legal instrument.
  • NIST and UNESCO guidance is adapted as context, not adopted automatically as ship law.
  • Capability, correctness, and popularity do not create authority.
  • Privacy, due process, accessibility, and remedy apply during ordinary and emergency operation.
  • LLMs remain offline-capable, evidence-linked, logged, non-authoritative, removable, and outside direct life-safety actuation.
  • Human review must be real, informed, timely, independent, and empowered to refuse.
  • Offensive cyber operations and autonomous weapons are excluded.

What would change this conclusion?

A legitimate participatory constitutional process could adopt different boundaries if it demonstrated equal or stronger safety, rights, accountability, and recovery. Confidence would rise through long-duration trials where affected residents use notice, correction, and appeal; emergencies expire; poisoned systems are isolated; and essential services continue AI-off. Evidence that any provision concentrates unreviewable power, produces discriminatory denial, suppresses truthful reporting, or makes safe refusal impossible should trigger revision or prohibition.

Sources and locators

Editorial record

  • Prepared by: GShips Project
  • Last edited: 2026-07-25
  • Status: Substantive editorial draft
  • Independent domain review: Pending; cyber, dual-use, governance, rights, privacy, and life-safety claims require explicit two-person review before publication
  • Required review: AI governance, constitutional design, human rights, safety engineering, AI evaluation, cybersecurity, privacy, and human factors
  • Reviewer: No independent reviewer assigned
  • Conflicts: Maintainer intends to explore a commercial venture based on some GShips work; no entity, funding, customer, sponsor, or partner relationship currently exists
  • Relationship boundary: Independent educational synthesis; citations do not imply affiliation, endorsement, partnership, or adoption by NASA, NIST, UNESCO, CCSDS, or any named organization
  • Scope boundary: Civil and defensive uses only; offensive cyber operations, autonomous weapons, weapon integration, and actionable exploitation instructions are excluded
  • Corrections: Suggest a correction

Substantive editorial draft; cited calculations have not received independent domain review · Last edited 2026-07-25 · Suggest a correction

Accountability record

How to inspect this page

Scope: Academy lesson lesson-10-05

Page citations and accountability links

  • claim-11-01
    Linked stable claim record with claim-specific citations and locators · internal accountability record
  • claim-11-04
    Linked stable claim record with claim-specific citations and locators · internal accountability record
  • claim-11-06
    Linked stable claim record with claim-specific citations and locators · internal accountability record
  • claim-11-07
    Linked stable claim record with claim-specific citations and locators · internal accountability record
  • claim-11-10
    Linked stable claim record with claim-specific citations and locators · internal accountability record
  • claim-12-06
    Linked stable claim record with claim-specific citations and locators · internal accountability record
  • claim-12-10
    Linked stable claim record with claim-specific citations and locators · internal accountability record

Assumptions and limits

  • The lesson's explicit Assumptions and limits section governs its scope.
  • Linked claim records remain independently unreviewed unless their own review record says otherwise.

What would change this page?

The lesson's explicit What would change this conclusion section lists the evidence, demonstrations, standards, and counterexamples that would trigger revision.

People, review, and conflicts

Prepared by
GShips Project
Editorial status
substantive-editorial-draft
Editorial reviewer
GShips Project editorial synthesis
Last editorial review
No editorial-review date recorded
Independent review
pending
Independent reviewer
No independent reviewer assigned
Last independent review
No independent-review date exists
Last content edit
2026-07-25

Declared conflicts

  • The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.

Suggest a correction to this page