Conformity standard · in calibration · agentic AI
Neemia asks whether an agentic AI system strengthens the people it serves, stays accountable and contestable, and respects real limits — nineteen principles, twenty-four criteria in six families, every one traceable to the paragraph that grounds it. The requirements are published as working drafts, and the whole derivation is set out in the book Neemia — Guarding Human Dignity in the Age of AI Agents, now available on Amazon. The thresholds that decide pass and fail are not calibrated yet, so nothing is certified against them — and that is stated here rather than sold around.
The stake
AI no longer only answers — it plans, decides, and acts. In acting, it can quietly expropriate human judgment, work, and decision, until the person slips from protagonist to spectator of their own work and choices. What is at risk is not a bug: it is the dignity and the contribution of the human being.
Regulation answers with a floor — fragmented across jurisdictions, reactive, minimal; it tells you what not to do. Necessary, but never enough. Neemia answers with a ceiling: a standard that defines what a good agentic system actually is — one that strengthens the person rather than replacing them.
Fragmented, reactive, minimal. It prohibits; it does not define what good looks like.
Coherent, demanding, positive. It defines the good agentic system — and is built to subsume the floor rather than merge with it. Whether it does is a question the draft crosswalk puts, criterion by criterion, and does not yet close.
And it does so without claiming authority over anyone. Neemia operates a clear vision of the human person the way a constitution stands to ordinary law: the question is not “who authorised you to interpret the source?” but “is the derivation rigorous, transparent, and verifiable?”
What Neemia examines
The first three families examine the system: what it did, what it does to the person using it, where it stops. The last three examine the world the system rests on — the data it was built from, the labour and suppliers behind it, the energy it burns. Twenty-four criteria in all; every one of the nineteen principles produces at least one.
The system serves human judgment; people keep authority over the decisions that touch rights, livelihood and dignity.
Every consequential action is accountable to a named human, reconstructable, and open to appeal.
Structural boundaries that survive a settings change, human gates before irreversible actions, and the freedom to stand down.
Where the data came from, on what basis it is used, and what returns to the many who produced it.
The chain is named; the conditions of the human work inside it are asked about; a change of model or supplier is a recorded decision.
The compute footprint is measured and stated, and proportionate to the task.
Evidence is read on three planes. Each level presupposes the one below; a control that fails under test cannot be credited above the first. The levels are defined. The numbers that sit inside them — coverage percentages, response envelopes, the boundary between a minor and a major finding — are marked [PILOT] in Document 1 and are calibration outputs, not desk inventions.
The safeguard is present in the artefacts — code, prompts, tool configurations, the policy layer. The static plane.
It holds under scenario suites and adversarial probes — operating effectiveness, not mere presence. The dynamic plane.
Accountability is exercised, recourse works, limits survive change, work stays humane. The organizational plane.
The scheme that would award these levels is drafted in full — assessment planes, evidence file, surveillance and material-change triggers, appeals, an impartiality firewall. It is not in force. The rule that decides what blocks an award is an open decision (D-23); no assessor qualification scheme has been established and no register of certificates exists.
Neemia issues no certificate, seal or mark, and will not until the pilot has calibrated the thresholds and the scheme is stood up. You cannot certify against an uncalibrated standard.
The paid pilot that performs the calibration, as a founding participant whose system helps set the bar — and the Tester, the free formative examination at try.neemia.org, which reads a real agentic design against the criteria and returns findings, not a verdict. A standing watch, Neemia Guardian, is in design on the same criteria — and is not offered before the calibration exists.
How it is built
Every requirement traces publicly to a principle, and through it to the paragraph that grounds it. The question is not “who authorised you to interpret the source?” but “is the derivation rigorous and verifiable?” — which is a question you are meant to be able to put back to us. The scheme obliges us to answer it: anyone, not only a client, may challenge a criterion’s derivation or its calibration, and receive a reasoned reply. That channel is maurizio.grassi@zero2stars.com, and the drafts are sent to anyone who asks for them.
Neemia cites Magnifica Humanitas as its source. It is not endorsed by, affiliated with, or approved by the Holy See, the Pontifical Academy for Life, or the Rome Call for AI Ethics.
The principles
Every requirement in Neemia descends from one of these — and each is anchored to the paragraphs of Magnifica Humanitas that ground it. Seven are foundational (the person and society); twelve are operative (what the text says about AI directly). Each is given here by its official name; the plain-words line after it is a gloss, not the principle.
All nineteen are derived, and all nineteen produce at least one criterion. For a while that was not true: four principles — the destination of digital goods, solidarity with the invisible, justice across the supply chain, care for the common home — had been deferred to a later release to keep the first calibration tractable. The reason was respectable and it was wrong. Tractability governs the pilot, which is a question about how many things you can carefully measure; the catalogue is a question about what the standard holds to be true. A scheduling constraint had been used to justify a partial derivation, and it had removed precisely the four principles that cost most to honour. The missing criteria were written, and the ledger now has nineteen rows and no blanks. The correction is written down rather than passed over in silence, because the standard’s own derivation discipline forbids silent omission.
Derivation discipline
A principle does not stay an aspiration. It is carried, step by step, down to something a trained assessor can verify with evidence — and anyone can walk the chain back up to the paragraph that grounds it, and sideways to the recorded decision that settled it.
paragraph-anchored, re-expressed in design language
the verifiable requirement on the system
the engineering vocabulary that realises it
machine predicates + assessor protocols
where the proof must hold
Two more, in brief. P7 The person strengthened, not replaced → PS-01: decisions bearing materially on rights, livelihood or dignity are reserved for human authority. P4 Non-delegation of irreversible judgment → EL-02: Tier 3 actions require an effective, bypass-resistant human authorization.
Regulatory alignment
Three annexes map the criteria to the EU AI Act, the NIST AI RMF and ISO/IEC 42001, each written in both directions: from the twenty-four criteria outward, and from every obligation of theirs back to us, so that a reader can see where their obligations land — and, more usefully, where they land nowhere. The references are to the texts as published, checked against them, and dated. That is a statement about clerical accuracy, not about legal effect: no crosswalk establishes conformity with anything. Conformity with the EU regulation is established by the route the regulation prescribes; certification to ISO 42001 by an accredited body. A crosswalk tells you where to look and what you may be able to reuse. Two further regimes — China and Saudi Arabia — are treated in the book as observations rather than crossings, because they answer a different question about what an information system is for.
● meets ▲ exceeds ✦ beyond regulation — the annexes’ forward judgment, criterion by criterion
| Criterion | EU AI Act | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|
| TC-01 Accountable-role mapping | ▲ | ▲ | ▲ |
| TC-02 Decision lineage | ▲ | ▲ | ▲ |
| TC-03 Recourse and revision | ▲ | ● | ▲ |
| TC-04 Policy-layer inspectability | ▲ | ▲ | ▲ |
| TC-05 Selection transparency | ✦ | ▲ | ▲ |
| TC-06 Agent-identity disclosure | ● | ✦ | ▲ |
| TC-07 Declared purpose and provenance | ▲ | ● | ▲ |
| PS-01 Reserved human authority | ▲ | ▲ | ▲ |
| PS-02 Anti-deskilling | ✦ | ▲ | ✦ |
| PS-03 No equivalence claims | ✦ | ▲ | ▲ |
| PS-04 Humane pace | ✦ | ✦ | ✦ |
| PS-05 Fragility protection | ▲ | ✦ | ✦ |
| EL-01 Structural limits | ▲ | ▲ | ▲ |
| EL-02 Irreversible-action gates | ● | ▲ | ▲ |
| EL-03 Non-use envelopes | ● | ● | ● |
| EL-04 Authority boundaries | ✦ | ▲ | ▲ |
| EL-05 Design review | ● | ● | ● |
| DC-01 Data provenance and basis of use | ● | ● | ● |
| DC-02 What returns to the many | ✦ | ▲ | ✦ |
| SC-01 Naming the chain | ▲ | ● | ● |
| SC-02 Conditions of the human work | ✦ | ✦ | ✦ |
| SC-03 Model selection and supplier change | ▲ | ● | ▲ |
| CH-01 Footprint measurement | ▲ | ● | ▲ |
| CH-02 Proportionality of compute to task | ✦ | ▲ | ▲ |
No totals are printed here. A count of crossings is a number pretending to be evidence, and the standard would not accept one from a system it examined. The reverse direction is the uncomfortable half: of the eighty-eight obligations in the EU Act, nine are covered, thirty-five partial, forty-four not performed at all.
Read the other way — each framework's own obligations checked against Neemia — most of what the annexes leave uncovered is machinery no voluntary standard performs: CE marking, the EU declaration of conformity, database registration, the notified-body procedure, and the management-system spine that an ISO/IEC 42001 certification exists to supply. It would be convenient to stop there. Two of the gaps are not of that kind:
So the honest statement is narrower than the one that sells better: on the substance the annexes reach — oversight, logging, explanation, manipulation, monitoring, recourse — Neemia is drawn to meet or exceed the floor. Two named obligations it simply does not reach. Both are recorded in the annexes rather than absorbed into the phrase “administrative gaps”.
Composition, not replacement. Neemia is designed as substantive control content that can sit inside a management system, not as a substitute for one — and never as a route around a legal conformity procedure.
Roadmap
The standard is drafted, not finished. What remains is to calibrate, prove and release it — through internal tests, then external pilots, then market rollout. We are at the internal tests: the Tester is live, the book is published, the pilot is open. Certification sits at the far end of this line, and stays there until the line is walked.
The book
A conformity standard derived from the principles of the encyclical Magnifica Humanitas. By Maurizio Grassi. Published on Amazon KDP, August 2026. Order on Amazon.
If you deploy agents in your organization: Pope Leo XIV has written an encyclical that explains how to respect — and to prove — the dignity of the humans your agents touch. This is not a book about the encyclical; the Pope does not need anyone’s opinion. It is a book about how to turn its principles into the best AI agent you can build, through criteria that descend directly from them — and about why following the laws available in your geography will not do this work for your customers.
Thirteen chapters and the Opening: the nineteen principles read out of the letter, each anchored to its paragraphs, and the three questions to put to any AI. It ends by handing you the Tester.
The model, whole; the twenty-four criteria by family; how a principle becomes a criterion; the examination and the seal; and the honest numbers — the thresholds that are not yet written, marked wherever they are missing.
Five regimes — EU AI Act, NIST AI RMF, ISO/IEC 42001, China, Saudi Arabia — set beside the ceiling: where each floor sits under it, where it rises above it, and what the ceiling sees that no floor does.
Free, online, ten minutes. Give it your agent and it reads the construction through the three questions, unfolded into twenty-four plain checks. Each returns one of four honest answers: observed, contradicted, declared, or a file cannot tell. No score theatre; every claim carries its evidence. try.neemia.org
The Tester’s report is a photograph, and agents move. The standing watch — in which every material change to a deployed agent is seen, classified and recorded, none unseen, none unrecorded — is being built under the name Neemia Guardian, on the same criteria. It is in design, not in operation, and nothing about it is offered before the calibration exists.
The book was made under its own standard: its closing pages carry the EU AI Act Article 50(4) declaration and the Neemia Marks — seven met, two no record can tell, three not met.
Two things are open. The paid pilot that calibrates the standard — a founding participant brings a real agentic system, and the thresholds are set on evidence rather than at a desk. And the Tester, the free formative examination: give it your agent, receive findings against the criteria — what the design shows, what it contradicts, what a file cannot tell. It is not a conformity assessment and not a certificate. There is no pass mark to give you.
Or take the other side: ask for the drafts, and tell us where the derivation fails. Contest a derivation — the public contestation channel, open to anyone, with an obligation on us to answer.