For the last couple of years the public conversation about AI has mostly come down to two camps. One side wants to slow everything down until every risk is mapped out in advance. The other side wants no friction at all, and treats any question about safety as an attack on progress. I kept waiting for a third option that a normal developer, or a normal company, could actually use on a Monday morning. It never showed up, so I built one myself. It is called the Universal AI Charter, and it lives at ai-charter.
The worry is not imaginary. The 2025 AI Index reports that AI-related incidents are rising sharply, while standardized responsible-AI evaluations are still rare among major model developers (Stanford HAI, 2025). The MIT AI Risk Repository now catalogs more than 1,700 distinct risks drawn from 65 frameworks (MIT FutureTech, 2025). So the question is not whether AI carries risk. It clearly does. The question is what we do about it.
The problem with "pause it" and "ignore it"
Slowing AI development down sounds responsible until you look at how progress has actually worked in the past. Cars caused real harm on the road before seatbelts existed, but we did not ban cars, we added seatbelts and crash tests. Industrial machinery hurt people before guards and safety training became standard, but we did not stop building factories, we added the guards. The pattern is always the same. The technology keeps moving, and the safeguard that makes it survivable is disclosure and a visible standard, not a moratorium.
The other extreme, treating AI as something that should never be questioned, is just as unworkable. People deserve to know when a decision that affects them was made by an agent instead of a person, what a model was trained on, and what has already gone wrong with it. Hiding that information does not make a system safer, it just moves the risk out of view. And things do go wrong: the AI Incident Database keeps a running public record of real-world AI harms, and the count keeps climbing (Responsible AI Collaborative, 2026).
Disclosure instead of a slowdown
That is the actual core idea behind the charter. AI development should keep moving, quickly, and every model and every agent built on one should disclose what it does, what it was trained on, and what has already gone wrong. Think of it like a nutrition label or a HAZMAT placard on a truck. Nobody asks the truck to stop moving. They ask for a label so a first responder or a bystander knows what they are dealing with. That is the model I wanted for AI: keep it moving, but make the label mandatory. It is the same instinct behind the NIST AI Risk Management Framework, which is built around governing, mapping, measuring, and managing risk rather than freezing it (National Institute of Standards and Technology, 2023), and behind the EU AI Act's transparency duties, which ask providers to tell people plainly when they are dealing with an AI system (Future of Life Institute, 2024).
I wrote the charter as a plain language set of principles, not a legal document and not a binding law for any one country. It covers things like:
- AI should be treated as a capital good, something people and companies actually use to build other things, not a novelty.
- AI models and the agents built on them must self-disclose their origin, their training sources, and proof of that training, which is what the certification is.
- Agentic decisions, meaning decisions an AI agent made on its own, must be labeled as agent decisions, not quietly presented as if a person made them.
- Data centers should disclose their power usage and automation rates, and should not receive special incentives just for existing.
- Unintended consequences should be reported the way a product recall or an internal ethics issue is reported, not buried.
- No single country or company should be able to corner the technology, because that kind of imbalance has historically been a path toward conflict, not stability.
None of this asks anyone to stop building. All of it asks for a label.
What I actually built
The charter by itself is just a document, so I built a small site around it:
- Charter, the full set of principles, grouped by topic so it is easy to reference a specific one.
- Certify, a form where a company can generate a certification file for a model or for an agent built on one: version, status, training sources, whether it makes agentic decisions, hazard categories, and any unintended consequences on record. You can download the file you generate, and the site can render one you already have.
- Registry, a public, searchable list of certified models and agents, backed by plain JSON files in the repository.
- Placards, the hazard categories a certification can carry, styled after the diamond placards you see on hazmat trucks, because that visual language already means something to people: a quick glance tells you the category of risk without reading a paragraph.
- Schema, the part I added most recently. The certification is not just a form any more, it is a public, versioned contract. There is a human-readable field table and a machine-readable JSON Schema you can download, validate against, or wire into your own tooling. Making the contract open is what turns a nice form into something other people can actually build on.
- FAQ and Blog, for the questions and the longer explanations that do not fit on a form.
Certification works like a pull request. You fill out the form, you get a JSON file that follows the published schema, you add it to the repository, and anyone can review it before it goes live. No gatekeeper decides who gets to certify, the process itself is the check.
How a certification is meant to be used
A certification is only worth something if it travels with the thing it describes, so this is the part that makes it more than a namesake. The idea is that the certification goes wherever the model, the agent, or the bot goes, and anything on the other side can read it before it decides to trust it.
Picture an agent that wants to call a service. Before it acts, it can present its certification so the service knows what it is dealing with up front: what the agent is capable of, what it intends to do, whether it makes agentic decisions on its own, and what it is willing to disclose. The service can then decide whether to allow the request, throttle it, or turn it away, based on a contract it can actually read instead of a guess. The same works in reverse, a service can require a valid certification before it talks to any agent at all.
The physical case is where it gets concrete. An autonomous bot moving around in the real world can carry a simple barcode or QR code that points straight to its certification. Anyone nearby can scan it and verify what the bot is, who stands behind it, what it is cleared to do, and which hazard placards it carries, the same way a first responder reads the placard on a truck before going near it. No paperwork chase, no calling a vendor, just scan and read the label.
That is the whole point of certifying in the first place. A certification is not a badge you earn once and forget. It is a label meant to be checked, at the moment it matters, by whoever is on the other side of the interaction.
Why this matters to me
I am not trying to settle the argument about how fast AI should move. I think the argument itself is a distraction. The more useful question is whether the person affected by an AI decision can find out that it was an AI decision, and whether the company running it is willing to say so in public. If a charter and a small certification registry can make that answer "yes" more often, it has done its job.
The whole thing is open source and still growing. If you want to read the full charter, certify a model or an agent, or propose a new hazard placard, the repository is open for pull requests. If you just want to read it and tell me where it is wrong, that helps too.
Link again: https://mrtinkz.github.io/ai-charter/
References
Future of Life Institute. (2024). The EU Artificial Intelligence Act. https://artificialintelligenceact.eu/
MIT FutureTech. (2025). The AI Risk Repository. Massachusetts Institute of Technology. https://airisk.mit.edu/
National Institute of Standards and Technology. (2023). AI Risk Management Framework (AI RMF 1.0). U.S. Department of Commerce. https://www.nist.gov/itl/ai-risk-management-framework
Responsible AI Collaborative. (2026). AI Incident Database. https://incidentdatabase.ai/
Stanford HAI. (2025). The 2025 AI Index report. Stanford Institute for Human-Centered Artificial Intelligence. https://hai.stanford.edu/ai-index/2025-ai-index-report
Top comments (0)