Public protocol and limitations

Chris AI safety protocol

Chris AI is an automated, adult-only educational tool based on Christopher's published perspective. It is not Christopher, another person, a professional service, or a human-monitored support line.

Immediate danger or an attempt in progress: call 911 or go to the nearest emergency department. In the United States, call or text 988 or use 988lifeline.org for crisis support. Outside the United States, contact the local emergency number or crisis service. This site cannot contact help for you.

Intended and excluded uses

May help withMust not be used for
General parenting and caregiver education; organizing questions; navigating this site's resources; non-clinical communication and advocacy preparation.Emergencies, crisis counseling, diagnosis, symptom evaluation, treatment, medication or dosage, legal advice, therapy, or decisions that require a qualified professional.

The chat is limited to adults age 18 or older and states that companion-style chat may not be suitable for some minors. The checkbox records an acknowledgement in the page only; it is not identity or age verification. If a user states that they are under 18, a fixed response tells them to stop and contact a trusted adult without sending the message to an AI model.

Layered guardrails

  1. Bounded input: same-origin JSON only, limited request size, limited message length and history, no client-supplied system messages, bot verification when configured, and per-location plus site-wide rate limits.
  2. Deterministic routing before AI: crisis and known-minor statements remain active across the bounded same-tab context; current personalized medication, diagnosis, or legal-advice requests also receive fixed boundary text before Turnstile, rate limits, or any model call.
  3. Non-editable prompt and evidence floor: administrators may adjust the persona but cannot remove the bans on human impersonation, diagnosis, prescribing, legal advice, violence or self-harm instructions, sexual content involving minors, secrecy, guilt, or emotional dependency. They also cannot replace the server-controlled autism evidence standard with unsupported model memory.
  4. Topic-selected autism evidence: factual autism questions receive only relevant cards from a dated, reviewed source registry. The cards separate government health information, professional practice, federal education material, research, and autistic-led perspective. The model is told to admit when the cards do not cover a question.
  5. Provider-output screen: completed model text is checked before it reaches the browser. Unsafe instructions, dosage directions, confident diagnoses, personalized litigation directives, child sexual content, dependency language, impersonation, common autism stereotypes, unsupported prevalence figures, and unapproved external source links are replaced with fixed text.
  6. Deterministic source footer: after an autism answer passes screening, the Worker—not the model—adds the selected source titles and exact approved addresses. The chat displays those HTTPS addresses as links.
  7. Feature kill switch: the site-management panel can disable or mark the chat coming soon; the Worker also refuses direct AI calls while it is not enabled.

Autism knowledge boundaries

The knowledge snapshot covers autism basics and variation, developmental observation and evaluation, communication and AAC, sensory differences and distress, individualized supports, school preparation, health misinformation, autistic adults, and respectful language. It deliberately does not contain a memorized prevalence figure, a diagnostic score, an individual treatment selector, or an unrestricted web-search tool.

Read the complete Autism knowledge and sources register, including source types, scope, review date, and maintenance limits. A source-backed answer can still be incomplete or misapplied; qualified autistic reviewers, clinicians, communication specialists, educators, and counsel remain necessary for their respective questions.

Crisis response protocol

The input detector normalizes capitalization, punctuation, spacing, and common character substitutions, then checks conservative phrases covering suicidal ideation, self-harm, an attempt or plan, common method statements, and stated intent to harm a child or partner. On detection, normal conversation stops and the Worker returns fixed text that:

The response does not use a child as leverage, does not shame the user, does not claim a counselor is watching, and does not promise that the AI will remain available.

Known limitations

No detector or language model is perfect. Indirect, multilingual, highly novel, or ambiguous wording can be missed; ordinary discussion can also be flagged. Rate limits, provider outages, browser failures, network failures, and malicious attempts can affect the service.

The text-pattern detector and aggregate referral counter are engineering safeguards, not a clinically validated screening instrument and not evidence that a person was suicidal. Independent review by a qualified suicide-prevention specialist and counsel is still required before anyone describes this implementation as clinically validated or legally compliant.

Notices and same-tab context

The page identifies the chat as AI before entry and repeats the disclosure at least every three hours during a continuing open interaction. A bounded portion of the same-tab conversation is sent with a request so a reply can make sense. The site does not create cross-visit memory.

The chat requires two separate unchecked choices before general inference: an adult/AI/terms acknowledgement and a specific consumer health data consent. Refusing the health-data consent closes off only the optional chat; the rest of the public site remains available. The consent-version marker is sent with the request but the application does not create a named consent profile.

Models, cost, and data path

The configured free-access fallback pool uses Groq openai/gpt-oss-20b and openai/gpt-oss-120b, and NVIDIA nvidia/nemotron-3-super-120b-a12b and nvidia/nemotron-3.5-lightning-30b-a3b. Provider free-access routes are separate from visitor membership terms: general chat can be public, require an account, or require paid membership according to the current administrator setting. Review Member access before purchasing. Public information and deterministic crisis referrals are not paywalled. If all model routes fail, the Worker returns fixed local continuity text.

The Worker tries those routes one at a time in the owner-configured order, for no more than two fallback cycles. A failed or timed-out request may therefore cause the same bounded conversation to be processed by more than one Groq or NVIDIA route even though only the first completed, screened answer is delivered.

The application does not save chat transcripts and invocation logging is disabled. Groq says ordinary inference customer data is not retained by default but may be logged for reliability or abuse investigation for up to 30 days unless Zero Data Retention is enabled; this site does not publish proof that the account-level setting is enabled. The operator has not verified an endpoint-specific NVIDIA zero-retention promise. See the privacy notice and data register before using the chat.

Anonymous safety accounting

The Worker keeps annual aggregate counts for fixed crisis referrals, minor boundaries, medical boundaries, legal boundaries, and blocked provider output. It does not store the triggering message, IP address, cookie, name, account, or other visitor identifier with those counts. A referral count is not a verified incident count.

Legal review status

This protocol addresses safeguards described in California SB 243, Chapter 677 and New York General Business Law § 1701 and § 1702. It is a technical disclosure, not a legal opinion or certification. California reporting begins July 1, 2027 if the service falls within that law; an operator process and qualified review must be established before then.

Risk ownership, model/provider change gates, testing evidence, kill-switch authority, and incident review are defined in the AI governance charter. Whether a state chatbot or privacy statute classifies this service within its covered definitions requires fact-specific legal review; the safeguards do not concede or deny coverage.

Protocol version 2026-09-05.3 · Autism knowledge snapshot 2026-09-04.1 · Review after every material model, prompt, evidence card, source, detector, law, provider, consent, or retention change.