#AIDoneRight

Artificial intelligence, with a human answering for it.

AI Done Right is an open standard for using AI with a clear purpose, a named person responsible for it, and proof that anyone outside the company can check. It was written for everyone who has good reasons to worry about AI, and wants more than promises.

PDF · 59 pages · EnglishVersion 2.0, “The Verifiable Edition” · Issued 13 August 2026 · Proposed for public review

If you are worried about AI

You are paying attention.

Skepticism about AI is not ignorance. It is a reasonable response to what people have seen. AI Done Right starts from the same evidence the skeptics do, and turns it into rules.

39%
of Americans say AI does more harm than good, up from 31%.Polling published July 2026
27%
express at least some trust in businesses to use AI responsibly.Same polling, down from 31%
84%
of CIOs had no formal process to check whether their AI is accurate.Gartner, October 2025
1,800+
court cases worldwide involved AI-invented legal citations.Academic tracker, August 2026

Figures as cited in AI Done Right v2.0, Part One, with the attributions it gives.

The idea in one sentence

A principle you cannot evidence is a preference.

The first version of AI Done Right, in 2025, was a pledge: a list of good intentions. Pledges cannot be checked, so they cannot be failed.

Version 2.0 keeps every one of those commitments and attaches to each one a document that proves it: who is responsible, what the AI may do, where it came from, what it keeps, and how it is stopped. The moral content has not changed. What is new is that someone outside the company can check.

Start with your concern

What worries you most?

Pick a concern to see which parts of the standard answer it.

  1. 01Accountability

    Human accountability

    What it means for peopleEvery AI system has one named person who answers for it, and who has the authority to switch it off.

    In the standard’s wordsNo AI system is ever in charge. There is always a clearly identified human, team or institution responsible for outcomes, decisions and harms.
  2. 02Accountability

    Declared purpose and value

    What it means for peopleBefore it is built, the company writes down what the AI is for, what it must never be used for, and what result would make it switch it off.

    In the standard’s wordsWe do not ship because we can. We ship when we understand why we should, and we say in advance what the system is not for.
  3. 03Accountability

    Human dignity and fair impact

    What it means for peopleNo pretending to be human, no manipulative designs, testing for unfair results across groups, and a real person to appeal to when a decision affects you.

    In the standard’s wordsIf a shortcut is unethical, it is not a shortcut. It is a liability.
  4. 04Accountability

    Inventory and bill of materials

    What it means for peopleThe company keeps a complete list of every AI system it runs and what each one is made of. Nothing reaches customers without being on the list.

    In the standard’s wordsWe cannot govern what we have not enumerated.
  5. 05Provenance

    Data provenance and rights

    What it means for peopleYour data is not used to train AI without your separate, written permission, and the company knows where its models came from.

    In the standard’s wordsWe do not use data we do not have the right to use, and we do not make our customers’ data into someone else’s model.
  6. 06Provenance

    Custody, retention and records

    What it means for peopleThe company knows exactly what the AI keeps, for how long and who can read it, instead of leaving it to a vendor’s default setting.

    In the standard’s wordsPrompts and outputs are records. We decide before anyone demands them.
  7. 07Provenance

    Supply chain

    What it means for peopleEvery outside company that touches your data through the AI is named, bound by contract and checked, not just “improving their services”.

    In the standard’s wordsThe obligations we accept, we impose.
  8. 08Control

    Bounded agency

    What it means for peopleAI cannot send, delete, pay, publish or change anything important without a human approving it, and there is a tested way to stop it.

    In the standard’s wordsAn AI system may act only within limits a human set in advance, and it can always be stopped. Capability is not permission.
  9. 09Control

    Security by design

    What it means for peopleSystems are built assuming the AI can be tricked, so that when it is, nothing important breaks.

    In the standard’s wordsSecurity is part of safety.
  10. 10Control

    Cost containment

    What it means for peopleAutomatic limits stop runaway AI costs and loops before anyone has to notice them.

    In the standard’s wordsAn AI system that can spend without limit is an availability risk and a financial one.
  11. 11Trust

    Transparency and disclosure

    What it means for peopleYou are told when you are dealing with AI, AI-generated media is marked, and limitations are disclosed up front.

    In the standard’s wordsAI should not be an inscrutable box that people are asked to simply trust.
  12. 12Trust

    Evaluation and monitoring

    What it means for peopleAccuracy is measured on a schedule after launch, and facts, figures and citations are checked by a person before they reach you.

    In the standard’s wordsPowerful models are not a substitute for engineering rigour. Deployment is the beginning of responsibility.
  13. 13Trust

    Independent assurance

    What it means for peopleThe evidence is kept, and shown to people who do not work for the company.

    In the standard’s wordsWe are prepared to be checked. Conformity that only we can verify is not conformity; it is confidence.

The pledge

What the people behind a labelled system publicly affirm.

AI Done Right asks for responsibility, not perfection. It is the promise that behind every system bearing this label there are humans who care enough to stand in front of it.

  1. We know exactly what this AI is for, what it must never be used for, and who is accountable for it by name.
  2. We know where its models came from, what they were trained on, and on what legal basis, and our customers’ data is not in them.
  3. We know every system it can reach and every action it can take, because we enumerated them, and it cannot take a consequential action without a human.
  4. We can stop it, we have tested that we can stop it, and we know how long that takes.
  5. We know what it retains, for how long, who can read it, and how we produce it when it is demanded.
  6. We measure whether it is still correct, we record what we measure, and we have agreed in advance what result would make us switch it off.
  7. We tell people they are talking to it, we mark what it generates, and we do not hide behind a disclaimer.
  8. We have written down what we cannot yet do, with a date.
  9. And we have shown all of this to someone who does not work for us.

The red lines

Any one of these means no #AIDoneRight label.

However good everything else is.

  • Training on customer data without separate, express permission.
  • An AI that can take an irreversible or public action without a human approving it.
  • No tested way to stop the system.
  • Claiming a certification the organisation does not hold.
  • Presenting an AI as a human being, or as an actor separate from the company.
  • Knowing a system treats a protected group unfairly, and doing nothing.
  • Not knowing how long the system keeps what people type into it.

Honesty over perfection

The standard rewards telling the truth about gaps.

Each commitment is rated on four levels. The label requires at least Level 2 everywhere, and Level 3 on the four that matter most. Most organisations will not qualify on day one, and the standard says the right answer is to publish the gap rather than pretend.

  1. L3GovernedEnforced by a technical control, checked automatically and reviewed independently.
  2. L2ManagedDocumented and applied consistently, but relying on people following the process.
  3. L1DocumentedA policy exists, but it is applied unevenly and proof is rebuilt on demand.
  4. L0Ad hocNo stated position. The answer would come from memory.
An organisation that marks itself down in two places and up in ten is believed. An organisation that marks itself Low everywhere is re-examined.

For journalists

The facts, in one place.

What it is
An open, voluntary standard for human-accountable AI in digital products and platforms, with 13 Articles, a four-level conformance ladder and a public label.
Who wrote it
Nicolas Genest, founder and CEO of CodeBoxx Technology Corporation.
Version and status
Version 2.0, “The Verifiable Edition”, issued 13 August 2026 as a draft for review. It supersedes Version 1.0 (2025).
Who it is for
Any organisation that builds or uses AI affecting people, and the AI agents that now write software on their behalf.
How it relates to the law
It is not a law and not a certification. It maps onto ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act and the OWASP threat lists, and explicitly forbids presenting that mapping as certification.
Cost to use
Free to read, adopt and turn into company policy.
Hashtag
#AIDoneRight

Media inquiries[email protected]

Adopt it

Ninety days from good intentions to proof.

The standard ends with a practical plan for any organisation starting from zero.

  1. Days 1–15

    Find out what is true

    List every AI system actually in use, what each keeps and for how long, and every credential it holds.

  2. Days 16–45

    Close the gaps that cannot wait

    Write and test the off switch, require human approval for risky actions, and name an owner for every system.

  3. Days 46–75

    Build the evidence habit

    Measure accuracy, list every outside provider, and run a first test of how the AI can be tricked.

  4. Days 76–90

    Make it checkable

    Rate yourself honestly on all 13 commitments, and have someone independent challenge the ratings.

#AIDoneRight

Hold AI to a standard. Start with this one.

Read it, use it, argue with it. Version 2.0 is proposed for public review because a standard for accountability should itself be accountable.

Download AI Done Right v2.0PDF · 59 pages · English