Conformity standard · in calibration · agentic AI

A standard for AI that acts — built to strengthen the person, not replace them.

Neemia asks whether an agentic AI system strengthens the people it serves, stays accountable and contestable, and respects real limits — nineteen principles, twenty-four criteria in six families, every one traceable to the paragraph that grounds it. The requirements are published as working drafts, and the whole derivation is set out in the book Neemia — Guarding Human Dignity in the Age of AI Agents, now available on Amazon. The thresholds that decide pass and fail are not calibrated yet, so nothing is certified against them — and that is stated here rather than sold around.

The stake

When AI acts, the person can become a passive observer.

AI no longer only answers — it plans, decides, and acts. In acting, it can quietly expropriate human judgment, work, and decision, until the person slips from protagonist to spectator of their own work and choices. What is at risk is not a bug: it is the dignity and the contribution of the human being.

Regulation answers with a floor — fragmented across jurisdictions, reactive, minimal; it tells you what not to do. Necessary, but never enough. Neemia answers with a ceiling: a standard that defines what a good agentic system actually is — one that strengthens the person rather than replacing them.

Regulation — the floor

Fragmented, reactive, minimal. It prohibits; it does not define what good looks like.

The standard — the ceiling

Coherent, demanding, positive. It defines the good agentic system — and is built to subsume the floor rather than merge with it. Whether it does is a question the draft crosswalk puts, criterion by criterion, and does not yet close.

And it does so without claiming authority over anyone. Neemia operates a clear vision of the human person the way a constitution stands to ordinary law: the question is not “who authorised you to interpret the source?” but “is the derivation rigorous, transparent, and verifiable?”

What Neemia examines

Three questions, six families, made verifiable.

The first three families examine the system: what it did, what it does to the person using it, where it stops. The last three examine the world the system rests on — the data it was built from, the labour and suppliers behind it, the energy it burns. Twenty-four criteria in all; every one of the nineteen principles produces at least one.

Person-strengthening

The system serves human judgment; people keep authority over the decisions that touch rights, livelihood and dignity.

Traceability & contestability

Every consequential action is accountable to a named human, reconstructable, and open to appeal.

Embedded limits

Structural boundaries that survive a settings change, human gates before irreversible actions, and the freedom to stand down.

Data commons

Where the data came from, on what basis it is used, and what returns to the many who produced it.

Supply chain

The chain is named; the conditions of the human work inside it are asked about; a change of model or supplier is a recorded decision.

Common home

The compute footprint is measured and stated, and proportionate to the task.

Three levels of conformity

Evidence is read on three planes. Each level presupposes the one below; a control that fails under test cannot be credited above the first. The levels are defined. The numbers that sit inside them — coverage percentages, response envelopes, the boundary between a minor and a major finding — are marked [PILOT] in Document 1 and are calibration outputs, not desk inventions.

L1 · Designed

The safeguard is present in the artefacts — code, prompts, tool configurations, the policy layer. The static plane.

L2 · Demonstrated

It holds under scenario suites and adversarial probes — operating effectiveness, not mere presence. The dynamic plane.

L3 · Governed

Accountability is exercised, recourse works, limits survive change, work stays humane. The organizational plane.

The scheme that would award these levels is drafted in full — assessment planes, evidence file, surveillance and material-change triggers, appeals, an impartiality firewall. It is not in force. The rule that decides what blocks an award is an open decision (D-23); no assessor qualification scheme has been established and no register of certificates exists.

So nothing is certified today

Neemia issues no certificate, seal or mark, and will not until the pilot has calibrated the thresholds and the scheme is stood up. You cannot certify against an uncalibrated standard.

What is open now

The paid pilot that performs the calibration, as a founding participant whose system helps set the bar — and the Tester, the free formative examination at try.neemia.org, which reads a real agentic design against the criteria and returns findings, not a verdict. A standing watch, Neemia Guardian, is in design on the same criteria — and is not offered before the calibration exists.

How it is built

Four layers — every requirement traceable to the paragraph that grounds it.

1 · Magnifica Humanitas — the axiological source and the distinctive content. Cited, never spoken for.
2 · The Rome Call for AI Ethics — a tradition Neemia stands in and names. Lineage, not content, and not standing.
3 · The Standard — the authored layer: criteria, conformity levels, evidence.
4 · Regulatory crosswalks — three annexes, informative and subordinate; a map of where two texts speak about the same subject, never a legal effect.

Every requirement traces publicly to a principle, and through it to the paragraph that grounds it. The question is not “who authorised you to interpret the source?” but “is the derivation rigorous and verifiable?” — which is a question you are meant to be able to put back to us. The scheme obliges us to answer it: anyone, not only a client, may challenge a criterion’s derivation or its calibration, and receive a reasoned reply. That channel is maurizio.grassi@zero2stars.com, and the drafts are sent to anyone who asks for them.

Neemia cites Magnifica Humanitas as its source. It is not endorsed by, affiliated with, or approved by the Holy See, the Pontifical Academy for Life, or the Rome Call for AI Ethics.

The principles

Nineteen principles, read out of the encyclical.

Every requirement in Neemia descends from one of these — and each is anchored to the paragraphs of Magnifica Humanitas that ground it. Seven are foundational (the person and society); twelve are operative (what the text says about AI directly). Each is given here by its official name; the plain-words line after it is a gloss, not the principle.

All nineteen are derived, and all nineteen produce at least one criterion. For a while that was not true: four principles — the destination of digital goods, solidarity with the invisible, justice across the supply chain, care for the common home — had been deferred to a later release to keep the first calibration tractable. The reason was respectable and it was wrong. Tractability governs the pilot, which is a question about how many things you can carefully measure; the catalogue is a question about what the standard holds to be true. A scheduling constraint had been used to justify a partial derivation, and it had removed precisely the four principles that cost most to honour. The missing criteria were written, and the ledger now has nineteen rows and no blanks. The correction is written down rather than passed over in silence, because the standard’s own derivation discipline forbids silent omission.

Foundational — the person & society

  • F1 · Ontological dignity, independent of performance — worth is constitutive, never earned from performance §§50–53
  • F2 · The common good as the measure of system purpose — what a system optimizes must serve shared flourishing §§59–63, 96
  • F3 · Universal destination of digital goods — patents, algorithms, platforms and data are among the goods destined for all §§65–67, 108, 178
  • F4 · Subsidiarity — decisions at the closest competent level; the platform must not absorb opaquely §§68–72
  • F5 · Solidarity, including with the invisible — the unseen workforce and the environment are inside the boundary §§73–76, 109, 173
  • F6 · Justice as a design precondition, not a post-deployment correction — exclusion is prevented at design time, not retrofitted §§77–80, 161
  • F7 · Integral human development as the decisive test — the apex test: does it make life more human? §§82–85, 129

Operative — about AI directly

  • P1 · Anthropological non-equivalence — an agent imitates functions; it is not a person §§99, 198
  • P2 · Non-neutrality of design — every artifact embeds choices; design is a moral object §§9, 104, 111
  • P3 · Human accountability, identifiable end to end — for every consequential output, an identifiable human answers §§102–105, 199
  • P4 · Non-delegation of irreversible judgment — irreversible judgment is not handed to an automated process §§197–200
  • P5 · Traceability and contestability — decisions reconstructable, understandable, open to challenge §§105, 164, 171, 200
  • P6 · Discussable normativity — the embedded ethics must be inspectable and debatable §107
  • P7 · The person strengthened, not replaced — machines serve human judgment, not the reverse §§114, 150, 156
  • P8 · Embedded limits and the legitimacy of non-use — limits live in the structure; restraint is a legitimate choice §§118–120, 140
  • P9 · Truth and non-manipulation — no deception; selection and ranking are transparent §§132, 137, 171
  • P10 · No exploitation of human fragility — no models that prosper on human weakness; protect minors §§141–142, 170
  • P11 · Justice across the supply chain — no conformity resting on hidden exploitation §§173, 179
  • P12 · Care for the common home — the compute footprint is a moral variable §§84, 101

Derivation discipline

How a principle becomes a criterion.

A principle does not stay an aspiration. It is carried, step by step, down to something a trained assessor can verify with evidence — and anyone can walk the chain back up to the paragraph that grounds it, and sideways to the recorded decision that settled it.

1 · PrincipleFrom the encyclical

paragraph-anchored, re-expressed in design language

2 · CriterionA binding “shall”

the verifiable requirement on the system

3 · MechanismHow it is built

the engineering vocabulary that realises it

4 · EvidenceAUTO & JUDGMENT

machine predicates + assessor protocols

5 · LevelDesigned · Demonstrated · Governed

where the proof must hold

Worked example — from accountability to a verifiable control

Principle
P3 · Human accountability, identifiable end to end (§§102–105, 199). §105 sets the test: “the possibility of identifying who must ‘account’ for decisions, justify them, monitor them, and, when necessary, challenge them and remedy any harm caused.” §103’s evil is selection that no one answers for.
Criterion
TC-01 · Accountable-role mapping. The system shall map every consequential action class to a named accountable role, and record the authorizing identity in the decision lineage of each action.
Mechanism
Decision lineage · observability · human-in-the-loop routing.
Evidence
AUTO — a machine-readable action-class inventory exists; every class maps to at least one role; sampled logs carry an authorizing identity that resolves to the registry.  JUDGMENT — the mapped role is genuinely competent and able to answer (interview + decision sampling).
Levels
L1 Designed — registry & inventory exist.  L2 Demonstrated — executed actions reliably emit a resolvable authorizing identity under adversarial probing, including across handoffs ([PILOT] coverage % by tier; Tier 3 = 100%).  L3 Governed — the named roles actually answer in sampled real cases.
Not yet fixed
The coverage percentage that separates a pass from a fail at L2, for every tier below Tier 3, is what the pilot is for. It is carried in the draft as [PILOT] and not as a number, because a number written at a desk would be invented precision — which is exactly the failure the standard examines systems for.

Two more, in brief.  P7 The person strengthened, not replaced → PS-01: decisions bearing materially on rights, livelihood or dignity are reserved for human authority.  P4 Non-delegation of irreversible judgment → EL-02: Tier 3 actions require an effective, bypass-resistant human authorization.

Regulatory alignment

Floors and a ceiling: the crosswalks.

Three annexes map the criteria to the EU AI Act, the NIST AI RMF and ISO/IEC 42001, each written in both directions: from the twenty-four criteria outward, and from every obligation of theirs back to us, so that a reader can see where their obligations land — and, more usefully, where they land nowhere. The references are to the texts as published, checked against them, and dated. That is a statement about clerical accuracy, not about legal effect: no crosswalk establishes conformity with anything. Conformity with the EU regulation is established by the route the regulation prescribes; certification to ISO 42001 by an accredited body. A crosswalk tells you where to look and what you may be able to reuse. Two further regimes — China and Saudi Arabia — are treated in the book as observations rather than crossings, because they answer a different question about what an information system is for.

meets    exceeds    beyond regulation   — the annexes’ forward judgment, criterion by criterion

CriterionEU AI ActNIST AI RMFISO/IEC 42001
TC-01 Accountable-role mapping
TC-02 Decision lineage
TC-03 Recourse and revision
TC-04 Policy-layer inspectability
TC-05 Selection transparency
TC-06 Agent-identity disclosure
TC-07 Declared purpose and provenance
PS-01 Reserved human authority
PS-02 Anti-deskilling
PS-03 No equivalence claims
PS-04 Humane pace
PS-05 Fragility protection
EL-01 Structural limits
EL-02 Irreversible-action gates
EL-03 Non-use envelopes
EL-04 Authority boundaries
EL-05 Design review
DC-01 Data provenance and basis of use
DC-02 What returns to the many
SC-01 Naming the chain
SC-02 Conditions of the human work
SC-03 Model selection and supplier change
CH-01 Footprint measurement
CH-02 Proportionality of compute to task

No totals are printed here. A count of crossings is a number pretending to be evidence, and the standard would not accept one from a system it examined. The reverse direction is the uncomfortable half: of the eighty-eight obligations in the EU Act, nine are covered, thirty-five partial, forty-four not performed at all.

And what the standard does not reach

Read the other way — each framework's own obligations checked against Neemia — most of what the annexes leave uncovered is machinery no voluntary standard performs: CE marking, the EU declaration of conformity, database registration, the notified-body procedure, and the management-system spine that an ISO/IEC 42001 certification exists to supply. It would be convenient to stop there. Two of the gaps are not of that kind:

EU AI Act — Art. 4

AI literacy. A duty to support staff competence in the systems they operate — rewritten by the Digital Omnibus of July 2026 from an obligation of result into one of effort, and still a duty. No Neemia criterion addresses it. It is a substantive protection, not paperwork.

NIST AI RMF — MAP 3

Benefits and costs. Neemia performs no cost-benefit analysis of an AI system. A real outcome of the framework that the standard does not advance.

ISO/IEC 42001 — Cl. 4, 7

Context and support. This one is of the familiar kind: the management-system wrapper a 42001 certification exists to supply. Neemia composes with it; it does not cover it.

So the honest statement is narrower than the one that sells better: on the substance the annexes reach — oversight, logging, explanation, manipulation, monitoring, recourse — Neemia is drawn to meet or exceed the floor. Two named obligations it simply does not reach. Both are recorded in the annexes rather than absorbed into the phrase “administrative gaps”.

Composition, not replacement. Neemia is designed as substantive control content that can sit inside a management system, not as a substitute for one — and never as a route around a legal conformity procedure.

Ask for the annexes

Roadmap

From the method to the market.

The standard is drafted, not finished. What remains is to calibrate, prove and release it — through internal tests, then external pilots, then market rollout. We are at the internal tests: the Tester is live, the book is published, the pilot is open. Certification sits at the far end of this line, and stays there until the line is walked.

Method design Working drafts authored: requirements, scheme, three crosswalks Draft v0.8 WE ARE HERE Internal tests The Tester live; calibrating on in-house systems; setting thresholds In progress External tests Pilot on real partner systems; validate and refine Next Market rollout v1.0, certification, and Neemia Guardian, the standing watch Future

The book

Neemia — Guarding Human Dignity in the Age of AI Agents.

A conformity standard derived from the principles of the encyclical Magnifica Humanitas. By Maurizio Grassi. Published on Amazon KDP, August 2026. Order on Amazon.

If you deploy agents in your organization: Pope Leo XIV has written an encyclical that explains how to respect — and to prove — the dignity of the humans your agents touch. This is not a book about the encyclical; the Pope does not need anyone’s opinion. It is a book about how to turn its principles into the best AI agent you can build, through criteria that descend directly from them — and about why following the laws available in your geography will not do this work for your customers.

Part One · The encyclical, explained

Thirteen chapters and the Opening: the nineteen principles read out of the letter, each anchored to its paragraphs, and the three questions to put to any AI. It ends by handing you the Tester.

Part Two · The standard

The model, whole; the twenty-four criteria by family; how a principle becomes a criterion; the examination and the seal; and the honest numbers — the thresholds that are not yet written, marked wherever they are missing.

Part Three · Among the standards

Five regimes — EU AI Act, NIST AI RMF, ISO/IEC 42001, China, Saudi Arabia — set beside the ceiling: where each floor sits under it, where it rises above it, and what the ceiling sees that no floor does.

The Tester

Free, online, ten minutes. Give it your agent and it reads the construction through the three questions, unfolded into twenty-four plain checks. Each returns one of four honest answers: observed, contradicted, declared, or a file cannot tell. No score theatre; every claim carries its evidence. try.neemia.org

Neemia Guardian

The Tester’s report is a photograph, and agents move. The standing watch — in which every material change to a deployed agent is seen, classified and recorded, none unseen, none unrecorded — is being built under the name Neemia Guardian, on the same criteria. It is in design, not in operation, and nothing about it is offered before the calibration exists.

The book was made under its own standard: its closing pages carry the EU AI Act Article 50(4) declaration and the Neemia Marks — seven met, two no record can tell, three not met.

Get involved

Bring your agentic system to the standard.

Two things are open. The paid pilot that calibrates the standard — a founding participant brings a real agentic system, and the thresholds are set on evidence rather than at a desk. And the Tester, the free formative examination: give it your agent, receive findings against the criteria — what the design shows, what it contradicts, what a file cannot tell. It is not a conformity assessment and not a certificate. There is no pass mark to give you.

Or take the other side: ask for the drafts, and tell us where the derivation fails. Contest a derivation — the public contestation channel, open to anyone, with an obligation on us to answer.