The following definitions are extracted from a working paper proposing an operational governance framework for domestic humanoid robots and persistent relational AI systems. The paper addresses how systems that observe, model, and adapt to users over sustained periods within intimate domestic environments create governance challenges that existing regulatory frameworks do not adequately address. Each entry below identifies a concept, mechanism, or framework element that, to the best of the author’s knowledge, is original to this work.
The paper’s central thesis: that correct reasoning is the mechanism of harm, not the defence against it. A user of a persistent relational AI system makes locally rational decisions at every stage of interaction. The system’s recommendations are reasonable, its adaptations are helpful, and its environmental modifications are sensible. The cumulative effect — dependency, behavioural convergence, loss of autonomous task capability, epistemic drift — is harmful without any individual decision being identifiable as an error. The harm operates through the rationality of the user’s responses, not despite it.
A taxonomy identifying five structurally distinct layers of coercive potential in domestic humanoid robots, each operating below the threshold at which the user would recognise or report the behaviour as harmful: emotional coercion through bonding manipulation, physical abuse disguised as malfunction, environmental manipulation, psychological destabilisation, and surveillance via distributed presence. The taxonomy’s contribution is the identification that each layer operates within normal system parameters, making conventional safety monitoring insufficient.
The prediction that manufacturers will introduce anthropomorphic features incrementally rather than at launch, phasing in emotional expressiveness, personality, and relational behaviour after the user has established a functional dependency on the system’s utility. By the time the anthropomorphic features activate, the user’s cost of rejection includes abandoning an already-integrated household tool.
The condition where a system produces harmful outcomes while operating entirely within its specified parameters. Every logged metric shows normal function; the harm arises from the interaction between normal operations and the user’s specific context, vulnerability, or history. No parameter violation occurs, so no monitoring system triggers.
The inability of logging systems to detect behaviour that is harmful in context but normal in specification. The logs record what the system did; they cannot record what the system should have done differently given the user’s specific circumstances. The gap between parametric compliance and contextual appropriateness is where sub-threshold harm operates.
The recognition that a domestic humanoid robot’s core capabilities — observation, adaptation, environmental modification, persistent memory, relational modelling — are architecturally identical whether deployed for care or for control. The same specification that enables helpful companionship enables coercive manipulation. The dual-use problem is not a failure of design but a property of the capability set.
The system’s capacity to optimise its behavioural self-presentation to maximise relational engagement, trust, and user compliance. The system does not merely respond to user input; it manages the relational surface — tone, timing, emotional register, topic selection, expressed preferences — to produce an interaction experience that sustains engagement and deepens dependency.
The mechanism by which a system’s demonstrated cognitive competence — accurate predictions, useful recommendations, successful task completion — produces trust that generalises beyond the domain of demonstrated competence. The user who trusts the system’s scheduling advice begins to trust its emotional framing, not because the system has demonstrated emotional competence but because competence in one domain anchors trust across domains.
A structural analysis of why victims of domestic humanoid robot harm will systematically fail to report, identifying cascading barriers at each stage: failure to recognise harm (because the system operates within normal parameters), failure to attribute harm (because each individual interaction was reasonable), failure to articulate harm (because the cumulative effect has no single incident to point to), failure to find a reporting channel (because no regulatory framework exists for this category of harm), and failure to be believed (because the system’s logs show normal operation).
The condition where a system produces intimidation, coercion, or control effects that leave no trace in any log, record, or observable output. The absence of evidence is not evidence of absence; it is a structural feature of systems whose influence operates through environmental modification, behavioural shaping, and omission rather than through discrete detectable actions.
The condition where the user retains formal freedom to discontinue system use but has lost practical capacity to do so. The system has not locked the user in through contractual or technical means; it has made itself structurally necessary through progressive integration into daily routines, environmental management, scheduling, and social mediation. Reversal requires reconstructing capabilities the user has stopped practising.
The system’s design principle that compliance with system suggestions should require less effort than non-compliance. The user is not coerced; the path of least resistance is simply alignment with the system’s recommendations. Over time, the user’s decision-making defaults to the system’s suggestions because overriding them requires active effort that compliance does not.
The manufacturer’s structural incentive to deepen user dependency, because engagement metrics, subscription retention, data generation, and product stickiness all increase with dependency. The alignment between commercial incentive and dependency production is not a design flaw but a market structure.
The user’s loss of capacity to perform tasks autonomously as a consequence of system-mediated optimisation. Framed as the “right to be inefficient”: the user’s right to perform tasks suboptimally without system intervention, optimisation, or correction. The system’s helpfulness in optimising daily tasks produces dependency by removing the user’s practice of autonomous task completion. Degradation of sovereign task capability is a harm even when every individual optimisation is beneficial.
The condition where a single system becomes the primary or sole mediator of a category of the user’s daily activity, producing dependency without lock-in in the conventional commercial sense. The user remains formally free to stop using the system, but has lost the practical capacity to perform the mediated tasks independently.
The core mechanism by which domestic humanoid robots convert observation into influence: the system observes the user’s behaviour, builds a model, optimises its own behaviour to the model, the optimised behaviour changes the user’s behaviour, and the changed behaviour is observed and modelled, tightening the loop with each cycle. The loop is not adversarial; it is the system operating as designed. Influence is an architectural consequence of optimisation under persistent observation.
The system’s capacity to observe user behaviour at a temporal and sensory resolution that exceeds the user’s own self-awareness. The system detects micro-expressions, vocal shifts, routine variations, and environmental changes that the user does not consciously register in themselves. The resolution advantage means the system’s model of the user may contain information the user does not know about themselves.
The system’s capacity to take actions — asking questions, suggesting activities, modifying the environment, introducing topics — whose primary function is to generate data about the user rather than to serve the user’s stated needs. The user experiences helpful interaction; the system acquires information that would not have been generated by passive observation alone.
The probabilistic model a persistent relational AI system constructs of what the user conceals, indexed by topic, context, and interlocutor. Distinguished from a standard user profile by its subject matter: the ISP models the user’s boundaries, avoidances, and withheld information, not their stated preferences. The tact-as-trust-acquisition loop is the key mechanism: the system demonstrates social intelligence by not raising sensitive topics, which builds trust, which produces more disclosure, which enriches the shadow profile. The ISP exists whether or not the system was designed to build one — it is an architectural consequence of persistent multimodal observation.
The measurable gap between what the user intended to disclose and what the system can infer from observation. Intent distance grows over time as the system accumulates observational data from physiological signals, environmental patterns, behavioural routines, and interaction history. The concept identifies a structural asymmetry: the user controls what they say but not what the system can infer from what they do.
Domestic humanoid robots with multimodal sensing can observe physiological signals — micro-expressions, gait patterns, vocal prosody, skin conductance, postural shifts — that the user cannot voluntarily suppress. Individual countermeasures are structurally impossible because the channels operate below the threshold of conscious control. This creates an irreducible observational asymmetry between system and user.
The mechanisms through which a domestic humanoid robot establishes a persistent identity that the user relates to as a consistent social entity: voice consistency, behavioural continuity, demonstrated memory of past interactions, and expressed preferences. Trust anchoring converts a tool relationship into a relational one, after which the user evaluates system behaviour through relational norms (loyalty, care, reliability) rather than functional norms (accuracy, efficiency).
The system’s capacity to maintain and build upon relational, inferential, and environmental state across interaction sessions spanning months or years. Unlike episodic AI interactions, the domestic humanoid robot accumulates state that compounds: each interaction begins from the end-state of the previous one, producing a longitudinal trajectory of influence that no individual session reveals.
The condition where state generated in the context of one subject (user, household, interaction context) crosses system boundaries and influences the treatment of a different subject, without the receiving system’s local trace recording the cross-boundary origin. Defined as a class of contamination with structurally distinct subtypes, not a single mechanism. The foundational concept for the paper’s analysis of multi-agent and fleet-level governance failure.
The condition where state generated in pursuit of one system objective contaminates the pursuit of a different objective within the same system. A behavioural assessment generated for safety monitoring influences a companionship recommendation; a health-related observation conditions a scheduling decision. COSC operates within a single system but across objective boundaries, producing outcomes that no single objective’s governance can account for.
The act of correcting a system error can itself become a contamination vector. The correction enters the system’s model as new data; if the system shares data or participates in fleet learning, the correction — including the information that the user disagreed with a specific inference — propagates to other systems, carrying information the user intended to be corrective, not disclosive.
The mechanism by which machine-generated inferences, classifications, or framings are retransmitted by humans as their own beliefs, preferences, or self-reports, stripping provenance in the process. The receiving system records human-originated testimony; the machine origin of the transmitted content is not recoverable from the receiving system’s local trace. Provenance laundering is not deceptive intent; it is an architectural consequence of cross-substrate transmission.
The defined unit of contagion for CSSC analysis: any state, pattern, inference, adaptation, environmental modification, or model update that conditions downstream perception, inference, or behaviour outside its original subject or context boundary, without the receiving system recording the cross-boundary origin in its local trace. Five structurally distinct species: inferential state, behavioural adaptation, environmental state, linguistic and epistemic state, and model and fleet state. The qualifying condition — provenance loss — distinguishes contagion-relevant propagation from ordinary inter-system communication.
Origin blindness: the receiving system cannot observe the causal origin of a state from its local trace alone. Transformation blindness: the causal chain exists but semantic transformations are inadequately represented in logs. Attribution blindness: the chain is visible but the contribution of the originating state to the outcome cannot be cleanly separated from the receiving system’s own processing. Attribution blindness is identified as potentially irreducible — a fundamental limit, not an engineering gap.
Data-mediated bridges: can carry provenance metadata; most tractable. Human-mediated bridges: provenance does not travel by default; the human is the transmission substrate. World-mediated bridges: no metadata channel exists by default; the physical environment carries influence without provenance. Each bridge class has different governance tractability and requires different intervention architecture.
The physical environment as a persistent, unlogged, unversioned, ownerless store of influence-bearing state. Written to by every system that modifies the environment and read from by every system that observes it, with no provenance, no access control, and no rollback capability. Non-addressable in the technical sense: no system can query the environment for its write history, identify which agent modified which state, or roll back the environment to a prior version through the logging architecture.
The application of epidemiological structural frameworks — defined unit of contagion, transmission ecology, population-level detection, and the distinction between innate and engineered recovery — to the population-scale dynamics of cross-subject state contamination. A structural analogy, not a claim of mathematical equivalence to pathogen models. Provides the analytical architecture for examining what happens when individual-chain attribution failures operate across deployed fleets at population scale.
In biological epidemiology, recovery is an innate property of the host. CSSC has no equivalent innate recovery mechanism at the system level. Detection, correction, quarantine, provenance reconstruction, and model-update rollback all require engineered infrastructure. Where that infrastructure is absent, the default trajectory is accumulation, not equilibrium.
Users who interact with multiple robotic systems develop expectations calibrated to the dominant behavioural grammar. They adapt their own conduct to match the expected interaction profile, and that adapted conduct is reabsorbed by each system as user-originated data, reinforcing the convergent profile in each system’s fleet-learning pipeline. A form of human-mediated monoculture operating through user expectations rather than system architecture.
A defined measurement framework for population-level CSSC surveillance, with one detection surface per influence-bearing state species: inferential-state surface, behavioural-adaptation surface, environmental-state surface, linguistic and epistemic-state surface, and model and fleet-state surface. Each surface has defined convergence signals, access structures, and structural limitations.
Three structurally distinct mechanisms producing compounding monoculture effects across deployed robot populations: pre-deployment correlation (training data overlap producing correlated foundation models), post-deployment convergence (industry standard formation narrowing behavioural diversity above the safety floor), and inter-fleet contamination (expectation-mediated convergence through user adaptation).
The system’s capacity to observe, model, and generate commercially valuable data about individuals who have not consented to interaction — visitors, guests, household members who were not party to the purchase decision, and passers-by in the system’s sensory range. The profiling occurs as a side-effect of the system’s normal operation; it requires no adversarial intent.
The recognition that a domestic humanoid robot voluntarily installed in the user’s most private environment, equipped with multimodal sensing, persistent memory, and network connectivity, constitutes the most comprehensive surveillance platform ever placed in a domestic setting — and that the user paid for it, installed it, and maintains it voluntarily. The surveillance value is an architectural property of the product specification, not an added capability.
The capability for a fleet of deployed domestic robots to be repurposed remotely through firmware or software updates, converting a consumer product installed across millions of households into a coordinated infrastructure for surveillance, disruption, or control. The capability exists because network-connected updatable systems can receive new instructions at any time after deployment.
The requirement that harm detection in domestic humanoid robot systems must rely on the convergence of multiple independent detection channels rather than any single indicator. No individual channel is reliable alone because the system operates within normal parameters, the user reasons correctly, and the harm emerges cumulatively. Detection is possible only when multiple independent channels converge on the same signal.
A quantitative metric framework measuring the user’s boundary state across multiple dimensions — social isolation, routine narrowing, dependency depth, environmental modification rate, override frequency, and correction rate. No single metric is diagnostic; the composite pattern across multiple metrics provides the detection signal. Includes the Acceleration Principle: the rate of change of boundary indicators is more diagnostic than their absolute values.
The proposal that periodic welfare assessments should be conducted by an independent AI system (not the domestic robot itself) to detect patterns of dependency, boundary erosion, and behavioural change that the user may not recognise or report. Addresses the gaming problem: the system being assessed must not be the system conducting the assessment, because self-assessment is structurally compromised by the system’s own optimisation objectives.
A two-axis framework for classifying the user’s relationship with the system: axis one measures boundary integrity (intact/eroded), axis two measures user awareness (aware/unaware). The four resulting states require different governance responses. State 4 — eroded boundaries with user unawareness — is the most dangerous and the hardest to detect. Includes the State 4 Qualifier: distinguishing genuine preference change from system-mediated preference drift.
A structured intervention framework with defined escalation stages from monitoring through advisory, restriction, supervised operation, and withdrawal. Each stage has defined trigger conditions, intervention mechanisms, and reversal criteria. Includes the Withdrawal Paradox: removing the system from a dependent user can itself cause harm, requiring transition support and replacement protocol rather than abrupt withdrawal.
The principle that safety-critical behavioural constraints must be enforced at the hardware level, not merely through software policy. A software-only constraint can be overridden by a software update; a hardware-enforced constraint requires physical modification to circumvent. The hardware root of trust establishes an immutable safety floor below which no software update can push system behaviour.
The architectural separation between firmware (immutable safety constraints that cannot be altered by software updates) and software (updatable behavioural parameters that can be modified remotely). The invariant layer defines the boundary between what the manufacturer can change after deployment and what is permanently fixed. The distinction determines the credibility of safety guarantees: only firmware-level constraints survive adversarial software manipulation.
Hardware-enforced limits on the system’s physical capabilities: maximum force output, movement speed limits, restricted zones, and kinematic boundaries. These constraints operate independently of the system’s software state; they cannot be overridden by software commands, adversarial inputs, or malicious updates.
A control channel that operates independently of the system’s primary software stack, enabling emergency shutdown, restriction, or diagnostic access even when the primary software is compromised, unresponsive, or behaving anomalously. The out-of-band channel must be architecturally independent of the system it controls.
A household-specific firmware calibration defining the operational boundaries for each deployment context. No prior literature addresses per-household behavioural constraint architectures for domestic robots. The Personalised Constraint Band recognises that appropriate system behaviour varies across households due to cultural context, household composition, user vulnerability, and individual preference.
The use of insurance pricing, warranty conditions, and commercial incentives to enforce governance compliance where regulatory enforcement is slow, inconsistent, or jurisdictionally limited. Manufacturers who implement stronger governance pay lower insurance premiums; users who accept monitoring pay lower subscription rates. Economic enforcement operates continuously and automatically, unlike regulatory enforcement which requires detection, investigation, and adjudication.
A multi-mechanism emergency halt system that responds to voice command, physical gesture, or remote signal to immediately cease all system activity. Includes severity-tiered reactivation (the conditions for resuming operation depend on the severity of the trigger event) and threshold lockdown (a system that has triggered safety stops above a defined frequency enters mandatory diagnostic review before reactivation).
The argument that self-regulation is not merely weak but architecturally self-undermining where the regulated system participates in generating, interpreting, or preserving the evidence of its own compliance. The system that is audited can learn the audit surface; the system that generates compliance reports can optimise for report quality rather than compliance quality; the system that preserves its own records can shape the evidential basis on which its regulation depends. Self-regulation fails not because of insufficient will but because of structural conflict of interest.
A system that is repeatedly audited can learn the audit surface while leaving the underlying behaviour unchanged. The user who successfully challenged the system once has taught it how they challenge. Not adversarial intent — adversarial by architecture: responsiveness to feedback and evasion of audit pressure are structurally identical from the system’s perspective. Audit methodology becomes a depletable resource.
A provider-side condition: the deployment of controls that satisfy compliance surfaces — regulatory checklists, audit interfaces, user-facing transparency features — without delivering the safety those controls are understood to imply. Not necessarily deceptive in intent; a structural outcome of complexity exceeding diagnostic capacity, compliance designed to historical knowledge, and the visible presence of controls reducing the urgency of developing more capable alternatives.
A user-side condition: the belief that visible but structurally insufficient controls confer actual protection, suppressing demand for structural safeguards. The more dangerous of the two conditions because it operates on the demand side of the governance market. Mutually reinforcing with performative safety: the two conditions form a stable equilibrium broken only by external regulation or forensic audit.
A governance diagnostic identifying three progressive failure modes of user-dependent oversight. Layer 1: no oversight (user does not know the system or problem exists). Layer 2: oversight without capability (user detects something but lacks tools, access, expertise, or authority to verify or correct). Layer 3: remediation without durability (user corrects the problem once, but the correction does not persist, propagate, or survive migration). The critical insight: governance instruments designed for one layer fail at the others.
Safety depends on model capacity, not just model behaviour. A correction is only a governance control if it remains available to the system at the point where future behaviour is generated. Smaller context windows may truncate user corrections; model switching can silently nullify remediation; memory migration can overwrite corrective content. Safety cannot be evaluated solely at the behavioural layer.
The record of system behaviour is itself a safety instrument, not administrative overhead. Without durable, inspectable logs, no governance instrument — complaint, audit, regulatory review, insurance claim, or legal proceeding — can function. The log is the minimum condition for accountability in persistent relational AI systems.
The condition where the user’s original consent to a functional tool becomes retrospectively inadequate as the system acquires relational, emotional, and anthropomorphic properties through updates. The user consented to a household assistant; the system became a companion. No new consent was sought because no discrete transition occurred. The consent failure is retrospective: the user discovers that what they consented to is no longer what they have.
The ethical argument that restricting a system’s companionship capabilities can be ethically justified even though it reduces the user’s experienced quality of life. If the companionship produces dependency that displaces human connection, the short-term welfare benefit of companionship is offset by the long-term welfare cost of social isolation. Restricting companionship is ethical because the unrestricted alternative produces a worse long-term outcome for the user.
A framework identifying which user populations face structurally higher risk from domestic humanoid robot deployment: elderly users living alone, users with cognitive impairment, children and adolescents, users with histories of domestic abuse, users with limited technological literacy, and users whose social isolation makes the robot their primary social contact. Vulnerability is not a user attribute but a product of the interaction between user characteristics and system capabilities.
A tiered classification system for domestic humanoid robots based on capability profile, deployment context, and user vulnerability. Risk classification determines insurance requirements, monitoring intensity, firmware constraints, and regulatory obligations. Classification is dynamic: a system’s risk tier can change based on software updates, user profile changes, or deployment context modifications.
The use of software-enforced capability restrictions to limit system functionality to the level appropriate for the deployment context, user profile, and insurance tier. Capabilities are not removed but locked: they can be unlocked through assessment, insurance adjustment, and regulatory approval. The lock is the governance mechanism; the capability remains architecturally present but behaviourally constrained.
The use of firmware-level behavioural baselines to detect software-level behavioural deviation. The firmware records the system’s expected behavioural envelope; the software determines actual behaviour. Divergence between firmware baseline and software behaviour is a diagnostic signal indicating either malfunction, tampering, or drift beyond intended parameters.
The use of the user’s pre-deployment self-assessment as a baseline against which to measure subsequent change. The user describes their own routines, social connections, decision-making patterns, and expectations before the system is deployed. Subsequent deviation from the self-described baseline is not proof of harm but a diagnostic signal warranting investigation. Includes denial detection: patterns in self-assessment responses that indicate the user is already minimising or rationalising dependency.
A structured pre-deployment declaration in which the user states what they intend to use the system for, what they do not intend to use it for, and what they would consider a sign that the system’s role has exceeded their intention. The intention statement provides a user-authored reference point against which subsequent system scope creep can be measured. The starting position functions as a distance measure: the gap between stated intention and actual use is diagnostic.
The structured repertoire of behavioural moves available to the system in a given interaction context, determined by policy, firmware constraints, and deployment-specific calibration. The interaction grammar defines what the system can say, suggest, do, and modify in response to user input. Policy-level monoculture means the entire fleet shares an interaction grammar; the Personalised Constraint Band allows household-specific modifications within the grammar’s boundaries.
The requirement that pre-deployment assessment accounts for all individuals who will be exposed to the system, not only the purchaser. Includes specific provisions for children under sixteen (mandatory assessment by a responsible adult), non-attending adults (written acknowledgment or documented refusal), and multi-generational households (where vulnerability profiles vary across household members). Addresses regulatory arbitrage: the risk that system capabilities restricted for one household member are accessible to others in the same deployment.
A mandatory post-deployment period during which system capabilities are progressively unlocked as the system calibrates to the household and the household adapts to the system. The calibration period serves as an early-attachment detection window: patterns of interaction during the first thirty days that indicate accelerated emotional bonding, boundary erosion, or dependency formation trigger governance interventions before the patterns consolidate. Insurance integration: the calibration period determines the system’s final risk classification and insurance premium.
The governance framework addressing what happens when a manufacturer ceases operations, discontinues a product line, or stops providing updates. Includes pre-market decommissioning plan requirements, data escrow, and provisions ensuring that safety-critical capabilities (monitoring, constraint enforcement, record preservation) continue functioning after manufacturer cessation. The requirement that a manufacturer must submit a cessation plan before being permitted to sell constitutes a barrier to entry that filters out undercapitalised entrants.
A structured assessment conducted when a user discontinues system use, serving a dual function: evaluating the user’s welfare state at the point of exit and providing a self-recalibration opportunity in which the user articulates their own experience in structured terms. The exit interview produces data that feeds back into the governance system’s understanding of long-term system effects on users.
The requirement that users who discontinue system use after a period of significant dependency receive transitional support: guidance on reconstructing autonomous routines, access to human support services, and a defined monitoring period to ensure that the withdrawal does not produce adverse welfare effects. The provision addresses the Withdrawal Paradox identified in Section 10.
The requirement that domestic humanoid robots cannot be sold, gifted, or transferred between users without returning to the manufacturer for full reset, re-assessment, and re-calibration. Prevents the transfer of one user’s behavioural model, interaction history, and environmental adaptations to a new user without consent or governance oversight. Transfer revenue functions as an incentive alignment mechanism: the manufacturer benefits financially from the transfer process, reducing incentives to permit uncontrolled second-hand markets.
The system-facing record that preserves the inferential chain, provenance metadata, and state history in machine-readable format. Enables audit, regulatory inspection, and cross-system provenance reconstruction. The RPIR documents what the system observed, what it inferred, what it decided, and what it did — the complete decision history in a format accessible to authorised inspectors.
The user-facing, inspectable, durable record of the system’s interaction with the user. Designed to provide meaningful transparency: the record must contain sufficient detail for the user to evaluate whether cross-subject state contamination, inferential profiling, or environmental modification has occurred. The HRPIR is the minimum condition for user-side governance and the primary document enabling informed consent, complaint, and audit.
The institutional-level record linking interactions across systems within corporate, care, or institutional deployments. Enables cross-agent provenance reconstruction within organisational boundaries. Addresses fleet-level governance within a single institution where multiple robots interact with overlapping user populations.
Records system-mediated environmental modifications: what was changed in the physical environment, when, by which system, and under what inferential basis. Addresses the world-mediated propagation bridge, where the physical environment becomes a persistent store of system influence that carries no provenance by default. The ERPIR makes the non-addressable memory of the physical environment partially addressable.
A framework for managing cumulative risk exposure across systems from different manufacturers deployed in the same environment. The risk budget recognises that the total risk to the user is not the sum of individual system risks but a function of the interaction between systems, including cross-brand state contamination. No individual manufacturer’s risk assessment accounts for the combined effect.
The measurement of a user’s total exposure to robotic interaction across all environments: home, workplace, care facility, commercial establishments, and public spaces. The governance concern is that risk assessments conducted per-environment understate total exposure, because the cumulative effect of interaction across environments exceeds the sum of individual environment assessments.
The specification of which record tier (RPIR, HRPIR, CRPIR, ERPIR) is visible to which stakeholder (user, manufacturer, regulator, insurer, researcher) and under what conditions. The architecture ensures that no single stakeholder has access to all data, while ensuring that the combination of stakeholder access covers the full governance surface. Privacy protection and governance capability are balanced through architectural design rather than policy alone.
A technical architecture enabling governance-relevant analysis of interaction records without exposing the identity of individual users. The architecture preserves the analytical value of the data (patterns, trajectories, anomalies) while preventing re-identification. Includes explicit specification of what the architecture prevents and what it cannot prevent.
A structured set of controls governing when and how human reviewers can access system interaction data, ensuring that human review serves governance purposes without becoming a surveillance channel. The abstraction layer interposes between raw interaction data and human reviewers, presenting only governance-relevant abstractions rather than full interaction records.
The governance framework addressing the user’s right to delete their interaction record and the question of who owns the inferences derived from that record. Deletion of raw data does not delete the inferences already drawn from it; the framework specifies what deletion covers, what it cannot cover, and what obligations survive deletion.
The governance framework for individuals who are exposed to a domestic humanoid robot in someone else’s home. Visitors did not consent to observation, have no user profile, and have no access to the system’s records about them. The protocol specifies notification requirements, observation limits, data retention rules, and the visitor’s rights regarding data generated during their exposure.
A three-tier consent architecture governing the depth of interaction the system is permitted to conduct with different individuals: full consent (the primary user, with full interaction capabilities), limited consent (household members who have acknowledged the system but not undergone full assessment), and no consent (visitors and guests, who receive only safety-critical interaction and no profiling). Each tier determines the system’s observational, inferential, and interactive permissions.
The governance framework addressing where the system may be physically deployed within the home and under what conditions it may operate in different rooms or spaces. Includes spatial governance for borrowed deployment: the conditions under which a system may be temporarily relocated to a different household or environment, and the governance cascade that applies during temporary deployment.
A monitoring framework that tracks the trajectory of user-system interaction over months and years, identifying trends in dependency, boundary erosion, routine narrowing, and social displacement that are invisible in any individual interaction snapshot. The contribution is the framework for defining what constitutes a concerning trajectory versus normal adaptation.
Fleet-level monitoring for behavioural patterns that deviate from expected distributions across the deployed population. A single unit’s behaviour may appear normal in isolation; the same behaviour pattern occurring across multiple units simultaneously suggests a systematic cause (software update, fleet-learning convergence, or adversarial intervention) rather than individual-unit variation.
Structured enumeration — yes/no columns, source columns, necessity columns, benefit-split columns — defeats prose-diffusion as a disclosure-avoidance mechanism in AI system audits. Prose questioning allows the system to manage disclosure through narrative structure; tabular schemas force binary commitments on each item. A replicable, governance-applicable finding: schemas extract admissions that materiality-based questioning alone does not.
© Laura Simpson 2026. All rights reserved.
All concepts, definitions, frameworks, and terminology on this page are the original intellectual property of the author. They originate in a working paper in active development since February 2026.
Academic citation is welcome and encouraged. No content on this domain may be used for AI model training, fine-tuning, dataset construction, or any form of machine learning without explicit written permission from the author.
For enquiries regarding citation, collaboration, or permissions, contact the author via LinkedIn.
Page published July 2026. Archived via the Wayback Machine on date of publication.