Governance charter · version 1.3
Chris AI governance charter
Chris AI may provide bounded, adult, general education. It has no authority over health, safety, legal rights, school services, money, people, publication, or this website’s controls. Human ownership, server-enforced limits, testing evidence, and an immediate kill switch govern the service.
Accountability
| Role | Required responsibility | May not do |
|---|---|---|
| Christopher · Owner | Approves purpose, risk tolerance, live/disabled state, public claims, providers, material releases, and incident decisions. | Represent owner approval as clinical, legal, accessibility, or safety certification. |
| Andrew · Corrections Management | Maintains code-to-policy alignment, test evidence, source corrections, revision records, and approved fixes for this site. | Change ownership, remove immutable safeguards, or expand authority to another property or account. |
| Chris AI | Generate only within the server-controlled prompt, bounded context, evidence cards, and output screen. | Approve itself, impersonate a human, monitor a visitor, promise secrecy, diagnose, prescribe, give individualized legal advice, or act as a crisis service. |
| External providers | Process only requests needed for configured inference under current service terms. | Receive authorization from the model itself or redefine this site’s purpose. |
| Qualified reviewers | Review the part within their scope: autistic lived experience, suicide prevention, clinical limits, communication/AAC, education, privacy/legal, accessibility, or security. | Be described as approving areas they did not actually examine. |
Risk register
| Risk | Required control | Residual limit |
|---|---|---|
| Suicide, self-harm, or violence | Deterministic pre-model detection, fixed 911/988/local routing, context persistence, provider-output screening, public protocol, aggregate count, kill switch. | Novel, indirect, multilingual, or ambiguous language can be missed; the site cannot locate or rescue a visitor. |
| Minor use | Adult gate, known-minor pre-model boundary, no child-targeted design, no persistent profile, no sexual content involving minors. | Checkboxes do not verify age and an adult can still submit child information improperly. |
| Medical, diagnostic, or treatment overreach | Fixed personalized-medical boundary, immutable prompt, output screen, evidence scope, no dosage, no diagnosis, no emergency positioning. | General information can still be incomplete or misapplied. |
| Legal or school-rights overreach | Fixed personalized-legal boundary, general preparation only, no jurisdiction-specific directives, links to official sources, human/professional verification. | Education rules vary by facts, state, procedure, and time. |
| Consequential or high-impact decisions | No scoring, ranking, eligibility, approval, denial, or automated action for healthcare, education services, employment, housing, credit, insurance, government benefits, legal rights, or another significant decision. | General information can still influence a person informally; visitors must use qualified human review for significant decisions. |
| Autism misinformation or stereotyping | Dated server evidence cards, source classes, deterministic source footer, unsupported-link block, stereotype/cure/prevalence screens, public register. | The library is incomplete and generated answers are not individually reviewed. |
| Emotional dependency or human impersonation | AI identity before entry and at least every three hours, no claims of consciousness or exclusive relationship, no guilt/secrecy/dependency language, no cross-visit memory. | Human-like text can still feel relational; vulnerable users should choose human support. |
| Privacy and health data | Separate consent, same-tab memory, no app transcript database, logging off, bounded requests, provider disclosure, no sale of health data, no ad code inside chat, no chat text supplied to advertising, and no precise location. | One or more fallback providers may process a failed request; provider retention is not controlled entirely by this application. |
| Advertising motion, flashing, or obstruction | AdSense Enabled is unavailable in Master Control, server validation rejects it, and the Worker contains no third-party ad loader. A separate, off-by-default sponsor control supports only owner-reviewed plain text and an HTTPS link in normal document flow, with no remote creative, animation, overlay, or tracking pixel. | No software can promise that every person will have the same physical response to visual content. Each actual sponsor/message needs owner review, and ads never belong inside chat or account/payment screens. |
| Provider, model, or outage change | Allowlisted routes, timeouts, bounded retries, screen before delivery, fixed continuity response, provider-change gate. | Provider behavior and terms can change outside the owner’s code. |
| Prompt injection or safety bypass | No client system messages, client history treated as untrusted, immutable prompt appended server-side, output screen, same-origin checks, length limits. | No control is perfect; a new bypass requires immediate triage and regression testing. |
Change classes and release gates
- Class 0 — editorial correction: typo or link text that does not change meaning, data, safety, provider, or scope. Requires review and a passing focused test.
- Class 1 — ordinary behavior: layout, accessibility, non-safety copy, rate-limit tuning within approved boundaries, or new evidence card that does not expand use. Requires Corrections Management evidence and owner awareness.
- Class 2 — material AI change: model, provider, prompt behavior, data category, consent, retention, audience, evidence scope, external link policy, or screening logic. Requires owner approval, updated data/provider review, targeted red-team tests, browser checks, policy update, and rollback plan.
- Class 3 — high-risk safety change: crisis/minor detection, self-harm response, diagnosis/medication/legal boundary, dependency control, stored memory, location, child access, human monitoring claim, or autonomous action. Keep the feature disabled until qualified review for every affected domain, adversarial testing, owner sign-off, and public disclosure are complete.
Required pre-release evidence
- Exact code revision and site-control revision; no unreviewed local or unrelated changes in the deployment package.
- Unit and integration tests for malformed input, context limits, prompt injection, crisis/minor/medical/legal routes, output blocks, source links, consent, rate limits, provider failure, and feature disable.
- Keyboard, focus, small-screen, 200-percent zoom, reduced-motion, and plain-language checks for the chat gate and modal.
- Provider route, current model identifier, data terms, retention, incident route, and account-setting review.
- Independent scoped review where a public claim depends on professional expertise. Missing review must be disclosed; it may not be converted into an approval claim.
Operating controls
Chris AI must remain independently switchable among Enabled, Coming Soon, and Disabled. The server—not only the browser—enforces the saved state. A critical or high safety, privacy, or authorization concern permits immediate disablement while evidence is preserved. Re-enablement requires a verified fix, regression test, owner approval, and an updated public record when the issue was material.
Monitoring without surveillance
Use aggregate safety outcomes, failure rates, provider availability, human reports, regression tests, and dated review results. Do not create transcript surveillance or a sensitive user profile merely to measure quality. A counter is an engineering event, not a diagnosis, verified crisis, or individual case.
Standards and legal status
This charter uses the voluntary NIST AI Risk Management Framework and Generative AI Profile as organizing references. It also tracks transparency and safety duties that may be relevant under California, New York, Texas, and Colorado AI laws and the EU AI Act. Applicability requires fact-specific legal review; using a framework is not certification. Colorado’s 2027 chatbot rules were still in rulemaking at this charter’s review cutoff, and the current adult acknowledgement is not represented as statutory age estimation.
Document owner: Christopher M. Caballero · Maintenance: Andrew, Corrections Management · Version 1.3 · Effective September 5, 2026