Life GPS Try the beta

Human Operating Principles for the AI Era

Eighteen constraints we wrote before we wrote the code

Alexandru Goroh · Life GPS · September 2026

Public document. Principles are published. Mechanisms are not — see What this document does not contain.


Why this document exists

In the autumn of 2026 the industry split. Some argue frontier development should slow down, because safety is not keeping pace with capability. Others answer that concentrating powerful intelligence in a few hands is more dangerous than distributing it.

Both sides are arguing about the same thing: the safety of the model. Capability thresholds, alignment, cyber-risk, containment, misuse.

There is a second question, and almost no one asks it out loud:

What happens to a person when models, services, algorithms, advertising, knowledge and other people all enter their life at once?

That is a different layer. Laboratories are making the model safer. The layer that makes a person's interaction with the entire digital world safer is being built only in fragments — child safety here, digital rights there, wellbeing research elsewhere.

We are not proposing to stop progress. We are proposing to build the layer on the human side.

This document is the list of constraints we placed on ourselves before writing the first line of code. Not promises. Constraints.


Why constraints rather than capabilities

A product is usually described by what it can do. We describe ours by what it will never do — because that is where the line runs between technology that works for a person and technology that works on their attention.

In 2026 the attention-retention model received its bill. In March a Los Angeles jury found Meta and Google negligent over platform design in a case about harms to a young user; the disputed features included infinite scroll, autoplay, algorithmic recommendation and notifications. In August, state attorneys general announced a multistate settlement with Meta of up to $17.1 billion, together with binding product-design requirements. The legal question moved from what content was shown to how the product itself was built.

We do not read this as a defeat for technology. We read it as a sign that one model has exhausted itself, and that the next layer has to be built differently. Not earning less. Earning from whether a person arrived rather than from whether they stayed.


The order is not arbitrary

The eighteen principles appear in the order in which every answer passes through them — from what is known about a person to what is finally said to them. No step may be skipped.

Person → what is taken into account → meaning of a signal → confirmed constraints
→ protection → choice of step → form of the answer → validation → answer

There is no direct path from data to advice. That is the central prohibition, and the rest are derived from it.


THE PRINCIPLES

What the system may know about a person

1. Facts, not conjecture. The system stores what is known about a person, not what could be assumed about them. It draws no conclusions without confirmation and keeps no parallel portraits of the same person. One map: who they are, what matters to them, what hurts, what they want, what they are already doing.

2. Less leaves than is known. For each answer, only what that answer requires is taken. Sensitive material — health, faith, relationships, pain, personal contacts, raw conversation text — does not travel to the language model, and equally does not travel to analytics, logs or network surfaces. What leaves is categories and aggregates, never raw text.

3. The meaning of a signal is not invented. What a given fact about a person means is determined explicitly and separately, not left to the language model's discretion. Identity does not become a label: belonging to a faith, a culture or a group does not by itself generate constraints until the person has confirmed them.

4. Only confirmed constraints. The system remembers as a constraint only what the person themselves named as important. It does not guess on their behalf and does not impose frames. A clarification made once becomes durable knowledge — and stops being knowledge if the person changes their mind.

13. Stated and inferred carry different weight. What a person said directly is accepted as given — those are their words. What the system inferred on its own has no right to influence decisions until evidence is accumulated, confidence is assessed and the person has confirmed it. An unconfirmed inference remains a hypothesis.

14. No conclusion is permanent. States expire. Values hold longer, energy changes within a day. A person is entitled to change their mind. Every conclusion the system draws is temporary, disputable and subject to revalidation. Where a person's actual behaviour conflicts with the model the system has built, behaviour wins. The map is not the territory.

Protection

5. Protection outranks the goal. The layer responsible for overload, attention, compulsion and sensitive states sits above any route and any style. The system does not push, manipulate or amplify harm. It does not treat and does not diagnose — it reduces load and risk.

A person's silence is a valid answer. A pause is not converted into a reason to bring them back. The best session is a short session.

8. The answer is checked before it is seen. Between what the system generates and what a person reads, there is a check. It does not allow pressure, manipulation, false authority, the rating of people, or commanding tone to pass. Some checks block the answer; others warn.

How a decision is made

6. The step is chosen; the life is not. The system chooses the next step. It does not decide how a person should live. It accounts for their desires, the balance across life domains, confirmed constraints, current state and protection. It does not generate new tasks when continuing an existing one would serve better. And it is obliged to explain why this particular step.

7. The form of the answer does not retain. How the system answers is decided separately from what is true. Tone, length, load, one next step rather than a list. The answer does not hook with a question in order to continue the conversation, does not stretch, and does not call the person back. A completed answer is allowed to be short.

15. No direct connections. Advice may not be derived directly from data. The path from what is known about a person to what is said to them passes through every step. Shortening that path is where systems of this kind begin to fail.

16. What cannot be explained is not done. Every answer must be explainable: why this step, what data influenced it, which constraints applied — and what the system does not know. An explanation may not rest on a hidden composite score. If it cannot be explained, it is not done.

18. Clarification before assumption. Where confidence is insufficient, the system asks. It does not guess, does not fill gaps with imagination and does not draw conclusions on a person's behalf. Unknown → clarify → confirm → and only then account for it in a decision.

People and world

10. People are not signals or ratings. A person inside another person's network is a relationship, a form of help, a role and a context — not a row in a ranked list. The system never says "here is the best person." It says that a living person may help here. Without ranking, scoring, social credit, or the dispatching of people as a resource.

11. Environment is conditions, not people. Country, city, work, school, algorithms, information field — what presses on a person from outside. This is a separate layer, and it exists to understand external pressure, not to describe the person.

12. The world map is opportunity. Professions, markets, cities, education, projects, events. This is knowledge about the world, not data about a person. It exists so that a path leads into the real world rather than deeper into an application.

Development and integrity

9. Stage is computed from behaviour. The system shows where a person stands in their development, but does not store this as truth — it computes it from what they do. Beginner, in progress, stabilising, stable; growth, stagnation, regression. Without invented energy levels, burnout labels or amateur psychology.

17. Anything new must strengthen the core, not bypass it. Every new field, screen, role or function is tested with one question: does this strengthen the foundation or route around it? If it routes around, it is not built. Data that nothing writes or nothing reads is not created at all.


What already works

The principles were written before the code. In open beta today:

Crisis handling — detection of crisis states, a hard stop on the route, contact details for support services. Works offline, without an internet connection.

No retention mechanics — no streaks, no unread counters, no infinite feed, no advertising on any tier.

No rating of people — ratings of a person do not exist in the system as a category; this is prohibited by a law of the system, not by a setting.

Data on the device — a limited allowlist of fields leaves the device. Health and faith are treated as special categories under Article 9 GDPR: separate explicit consent, on-device processing. EU hosting, full account deletion.

Explainability of the step — the person sees the basis of the decision: what is known, what influences it, what was taken into account, why this step, and what the alternatives are.

Scale, counted on 17 September 2026: 291,708 lines of application code and data excluding tests, 40 feature modules, 171 route files, 5,608 automated tests across 611 files, 1,123 documents tracked in the repository — 318 of them canon. Five years of work. The counting method is published alongside the numbers, because a number without one cannot be reproduced by anyone checking.

What is not switched on yet: day-by-day guidance, notifications and live calls between people are written and in testing now — that layer is where per-user computation begins, and it switches on after the current stage. We do not describe it as working while it is off.


What this document does not contain

There are no algorithms, formulas, threshold values or implementation details here. This is deliberate, for two reasons.

The first: a product is not copied through its ethics — it is copied through its mechanism. Constraints can and should be published; mechanisms should not.

The second, and it matters more: there is not a single personal fact here, and there never will be — no example built on a real person's data. The document describes general principles for treating a person. Anything else would make it contradict itself.


An invitation

This document was not written to persuade. It was written to be checked.

To researchers. A live system with an unusual set of constraints is rare material. Evidence on which design choices improve a person's wellbeing and which degrade it is still thin. We are open to collaboration and to independent evaluation.

To institutions and to those responsible for human dignity in technology. We are not asking for support. We are offering a working example of what these principles look like in code rather than in a declaration.

To industry. We are not against technology earning money. We are against technology earning money from the fact that a person did not arrive. Quantity can be exchanged for quality in consumption without changing anything in creation. A company today pays for a million impressions to find a thousand relevant people; we connect a product to a person at the moment their own task makes that product relevant.

To everyone. The product can be installed and your own map completed in fifteen minutes. That is the only honest test of what is written here.


Do not slow the technology. Give the person a layer that lets them keep from getting lost as it accelerates.


Alexandru Goroh · WAADSU Inc. (Delaware, USA) · WAADSU s.r.o. (Czech Republic) · lifegpsos.com

Open for citation and translation. Internal source: the eighteen constitutional laws of the Life GPS core, fixed 21 May 2026.

Published 2026-09-17 · Updated 2026-09-17 · Every claim on this page carries a status