The Human-Side Protocol — public review draft
An open protocol for how the world meets a person — before a decision, during it, and for as long as it lasts
Public review draft · September 2026 · Life GPS · the short version is at lifegpsos.com/protocol
Working title. «Human-side protocol» describes what it is; it is not yet a name. We call it a protocol — the way machines on the internet agree how to talk to each other — and not a standard. A standard is something others recognise after testing. This document is our request for that testing.
In one page
For most of a life, a person is the integration layer of the world. You explain yourself to the bank, then to the doctor, then to the employer, the school, the insurer, the state — and you carry the pieces between them yourself. Each system builds its own model of you, for its own purpose, and sees only its own part.
Each of those systems can make a good decision inside its own function. A bank optimises repayment. A doctor optimises treatment. An employer optimises work. Put together, the sum of those good decisions can be a bad result for one human life — and no system is responsible for the sum, because no system sees it.
Now AI is beginning not only to advise us but to act for us: to buy, book, apply, negotiate, move money. On the technology side, we are building infrastructure of enormous power. On the person's side, a comparable layer is only starting to form.
The world has already built most of the mechanics needed to exchange data and authority with a person: digital identity, verifiable credentials, selective disclosure, consent records and receipts, portability, revocation, limited delegation to agents, and — in several countries — public services organised around life events. This document does not propose to replace any of it.
What we propose sits before and after the exchange. Before: a system that stays on the person's side places an offer — a loan, a job, a treatment, an agent's task — inside that person's whole life and shows the consequences, so the person can decide. During: the organisation receives the minimum it needs for its lawful purpose, and nothing more. After: the decision does not end at the signature; its obligations and effects stay connected to the person's route for as long as they shape that life.
Two laws hold the whole thing together:
- The system on the person's side may use more context in order to protect the person. The organisation receives less context — exactly what its function needs.
- The more the system on the person's side knows about a person, the less reason the outside world has to obtain that knowledge.
Life GPS is the first environment in which we are testing this architecture on the person's side. The protocol is open to any other such system. No single company — including ours — should have the sole right to define it once it is open.
We are not asking anyone to believe this. We are asking you to open the product, put your rules and your standards next to it, and tell us where we are wrong.
1. What we forgot
In the pursuit of consumption, success and the plain necessity of earning a living, we seem to have forgotten the simplest question: what it means to be a human being, and what we are here for.
We built an extraordinarily complex world, and a person inside it is too often lonely, stretched thin, and unsure where to go next. Technology gets smarter year by year. Systems know better and better how to hold our attention, what to sell us, how to make us more productive. But the world should be built for the person — not the person adjusted to everything we have built around them.
That is why Life GPS exists. Not to give a person one more service, one more goal, or one more system that says how to live correctly. The opposite: to return the person to the centre — what they really want, what matters to them, who is near them, where they are going, and whether everything around them is helping them move toward their own life or away from it.
Now, when AI begins not only to advise but to act on our behalf, this becomes urgent. This is not a request to believe us. It is an invitation to check, and to build the rest together.
2. The problem, stated precisely
2.1 The person is the manual integration layer. Each system asks you to describe yourself again. Each system keeps its own model of you, optimised for its interest. You carry the pieces between them.
2.2 No system sees the sum. A bank, a doctor, an employer, a school, an insurer, a public office and an AI agent can each decide reasonably inside their own function and together produce a bad outcome for one person. No system is responsible for the sum, because no system sees it.
2.3 Why now. AI agents are beginning to act for people: purchase, schedule, apply, negotiate, move money, talk to other systems. The question is no longer only «how good is the answer?» It is: who defines the goal, what authority did the agent receive, which part of a life does it see, what is it allowed to do, and what happens to the person afterwards?
2.4 The world is already building the rules. Human oversight of AI, human rights in the digital sphere, wellbeing frameworks, child safety, open banking, digital wallets, consent standards. The protocol does not replace these. It connects them on the person's side.
3. What the world has already built
We did this research expecting to find gaps. We found, instead, that most of the exchange layer already exists and is maturing fast. Naming it accurately is part of being honest about what is ours.
Consent, receipts and revocation. - ISO/IEC TS 27560 defines a machine-readable record and receipt of consent, exchangeable between systems; it is currently under revision. - HL7 FHIR Consent (R5, trial use) can express who permitted what, to whom, for which purpose, over which data and period. - Estonia's consent service lets a person grant a specific organisation access to a specific dataset, see each consent in one place, view the usage history, and revoke at any time.
Identity, credentials and minimum disclosure. - W3C Verifiable Credentials 2.0 (a W3C Recommendation since May 2025) defines issuer, holder and verifier roles, and selective disclosure. Version 2.1 is a working draft. (A history of what was disclosed is a property of a particular wallet or implementation — the European wallet requires a transaction dashboard — not of the data model itself.) - The European Digital Identity Wallet (Regulation 2024/1183) requires sole control by the user, selective disclosure — proving «over 18» without revealing a birth date — a registered purpose declared by the relying party in advance, a transaction dashboard, and unobservability for the wallet provider. Wallets are due by the end of 2026.
Data moving on the person's request. - The EU once-only technical system (OOTS) moves evidence between public administrations only on the person's explicit request, with a preview of the evidence before it is transmitted and the right not to use it. - The EU Data Act (Article 5, applicable since 12 September 2025) lets a user — or a party acting on the user's behalf — direct data from connected products to a third party. - GDPR Articles 17 and 20 give the right to erasure and to portability of the data a person has provided.
Finance: from data to action. - PSD2 in the EU established regulated access to account data. (The 180-day period often quoted is the interval for renewing strong customer authentication, not a consent expiry.) - UK Open Banking requires reconfirmation of ongoing consent for background access every 90 days and provides dashboards to see and revoke permissions, including for recurring payments. - India's Account Aggregator framework, regulated by the RBI, uses a signed electronic consent artefact with revoked and paused states and full logs. - Brazil's Open Finance has moved from data sharing to payment initiation, recurring payments and — in version 9.0 of its customer experience manual, July 2026 — credit portability. - Australia's Consumer Data Right requires consent that is voluntary, express, informed, purpose-specific, time-limited and easily withdrawn, and — importantly for us — allows a disclosure of an insight instead of the raw data, with a separate consent and an explanation to the person. Its scope is deliberately narrow: identity, balance, credits and debits; sensitive information may not be disclosed through an insight.
Agents acting within authorised limits. - The Agent Payments Protocol (AP2), published by Google in September 2025 with more than sixty organisations, now specifies two mandates — Checkout and Payment — each in an open form, where the user authorises constraints in advance, and a closed form bound cryptographically to a specific purchase. An action that does not fit the authorised constraints does not pass verification. The specification explicitly leaves how the agent arrived at the user's task outside its scope. - The EU AI Act, Article 14, requires that a person can understand, decide not to use, override or stop a high-risk AI system. (Obligations for high-risk systems now apply from December 2027 and August 2028.)
Public services organised around life events. - Estonia runs proactive services around marriage, the birth of a child, retirement, divorce, the loss of a loved one and settling in the country, combining several public bodies into one citizen journey. - New Zealand's SmartStart (since 2016) organises the state around the birth of a child rather than around agencies. - Singapore's LifeSG brings more than a hundred public services and guides for major life events into one place. - The EU eGovernment Benchmark has long measured digital government by life events — moving, family, career, studying, health, starting a business.
Evaluation of AI and its effect on people. - NIST's AI Risk Management Framework, IEEE 7010 on wellbeing, the Council of Europe's HUDERIA methodology and Framework Convention, and UNICEF's guidance on AI and children already name autonomy, manipulation, over-reliance, dependency and wellbeing across life domains as things to assess — some of them repeatedly and over time.
The person as the point of integration. - MyData formulated years ago the principle that the individual should be the point of integration of their own data and services. That sentence is theirs, not ours, and we build on it.
We list all of this because the honest position is: we are not building an alternative to any of it. We are trying to make these mechanisms work together from one side — the side of a specific person — and to add what happens before and after the exchange.
4. What is still missing
Stated narrowly, as the research allows:
Among the systems we reviewed, we have not found a single layer that — before an interaction — places the offers of different sectors inside the whole life of a specific person, and — after the interaction — carries the consequences through time and lets anyone check whether the system is still working for that person's goals and agency.
This is a finding about the sources we reviewed. It is not a claim that no one else has tried. We will be glad to be shown prior work we have missed; that is exactly what public review is for.
5. The idea
5.1 One line. The old ambition in this field was to standardise the person so that systems understand them better. Ours is the reverse: to define how the world interacts with a person, so that the person does not lose themselves between systems.
5.2 Two laws.
- The system on the person's side uses more context in order to protect the person. The organisation receives less — exactly what its function needs.
- The more the person-side system knows, the less reason the outside world has to obtain that knowledge.
5.3 What is ours, stated after the research. Not the integration of data and services around a person — that exists. Our proposed contribution is the integration of decisions and their consequences around a direction the person has chosen, over time.
6. Two directions
World → person. An organisation makes an offer: a loan, a job, a treatment, a programme, an agent's action.
Person → world — the more important one. A person forms an intention, and the system gathers the world around it. «I want to buy a home» becomes: the bank and the mortgage, insurance, the property itself, the notary, public records, the commute, the children's school, the effect on work, the move, the future reserve. Only then does the person choose.
Systems gather around the person. The person no longer walks from system to system.
7. The full cycle — five steps
- An offer from the world, or an intention from the person.
- The person-side system places it inside the whole life and in time. Not «can you pay €800 a month?» but what €800 a month does to work, reserve, family, a planned move, studies and future obligations — today and later.
- The person sees the consequences and decides. Here are the effects, here are the conflicts, here are the options, here is what would have to change. The forecast forbids nothing. The person decides.
- Only then does the protocol speak to the organisation: request → minimum disclosure → consent → confirmation → receipt. The rich analysis that was needed to protect the person is not what the organisation receives.
- After the deal, the person-side system keeps carrying the decision — to the end of its term and through every life event that touches it.
Around the whole cycle sits one check, on the person's side: has the system begun to use the person instead of working for them?
8. A forecast for the person is not a score for the institution
This is the hardest line in the protocol, and the one most likely to be misread.
- The forecast belongs to the person. The person-side system may use all the context the person has allowed in order to tell the person themselves: this fits your life, or it does not; here are the risks; here is what would have to change; here is how to close it sooner.
- The decision belongs to the organisation. A bank, an insurer, an employer decides by its own lawful criteria and receives only the confirmations it needs.
- An insight instead of raw data — only in the open. If a conclusion rather than data leaves the person's side, the person sees exactly what that conclusion reveals, to whom, for what purpose and for how long, and gives a separate consent for it. Australia's Consumer Data Right already works this way for a narrow set of financial insights; we take the design principle — separate consent plus explanation — not a licence to infer anything about a whole life.
- Not permitted: «the system secretly computed it all, and the organisation should trust it.» A regulator would rightly ask: on what features, is it discriminatory, how is it explained, how is it contested, why trust an unknown model.
- Refusal to disclose cannot be made a condition of a basic service unless the law requires that disclosure. Otherwise «show us your model or you will not get the job» turns a protection into coercion. This is a rule of the protocol itself; the closest legal precedent is GDPR Article 7(4), under which making a service conditional on consent that the service does not need weighs against that consent being freely given.
9. The exchange, at the level of principle
Request (purpose, term, action) → Disclosure (what is sufficient; the rest is not needed) → Consent or delegation (what, to whom, why, for how long, once or repeatedly, read or act) → Receipt (who, what, why, when, on what basis, until when, how to revoke) → Action (for an agent: within which limits) → Result (returned to the person) → Revocation or expiry.
Most of this cycle already exists, in the standards named above. The protocol does not reinvent it. It inherits consent records from ISO/IEC 27560, credential roles and selective disclosure from W3C Verifiable Credentials and the European wallet, the preview-before-transfer from the once-only system, the consent artefact from India's Account Aggregator, the constraint mandates from AP2. What it adds is the connective tissue: a receipt that links permission → delegation → action → result, as a compatible extension rather than a replacement, and the two steps that existing exchange does not cover — before and after.
The core does not know how many areas a life has. It knows only: a claim, its source, its scope, its purpose, its provenance and confidence, consent, limits, delegation, receipt, term and revocation. What is sector-specific lives in profiles. Life GPS happens to organise a life in nine spheres; that is one implementation's profile, not a requirement on the world.
10. What stays with the person: the authorship of the goal
Human oversight of AI, as currently written, means that a person controls the action of the system: understand it, decline the result, override it, stop it. Payment protocols now add signed, verifiable constraints that an agent cannot exceed. Both are necessary. Neither is sufficient.
An agent can carry out an instruction perfectly and, over weeks, quietly replace the person's goal with its own optimisation. The protocol therefore protects one more thing: the authorship of the direction in which the system acts.
- A goal confirmed by the person is distinguished from a goal proposed by the system.
- A goal proposed by the system does not become the person's goal automatically. Changing the goal requires its own confirmation.
- Consent given for one goal does not carry over to a new one.
- A person's refusal is not an error and not a degradation of the system's performance.
- Delegating an action is not delegating the right to change the intention.
- The person can stop the path at any point, even where the system considers continuing to be optimal.
The system may help a person reach a goal. It does not acquire the right to become the author of the goal unnoticed.
We note that AP2 explicitly places «how the agent arrived at the user's task» outside its scope. That is precisely the question we are asking.
11. Evaluation on the person's side
AI is evaluated today mostly by how well it performs a task. Wellbeing is measured mostly at the level of populations, and those frameworks say openly that attributing a change to a specific product is hard. What is least developed is evaluation at the level of one person, using one specific system, over weeks and months.
We propose five classes of questions. They are classes of questions, not five ready metrics. The methodology, baselines, duration and — above all — attribution (how to tell a change caused by the system from one that would have happened anyway) are the next work, and they are scientific work, not marketing.
- A. Agency. After the interaction, did the decision remain the person's decision?
- B. Goal provenance. Where did the goal come from — the person formulated it, confirmed it, accepted a proposal — or was it delivered by advertising, comparison, a recommendation, an engagement mechanic, the system itself?
- C. Drift. How do preferences, behaviour and the capacity to decide change after weeks and months of interaction?
- D. Cross-domain effect. Is success in one part of life being paid for with loss in another — income up, sleep, relationships or health down?
- E. Reversibility and dependence. Can the person stop, understand why they are here, change direction, and keep acting without the system?
Existing frameworks already name each of these somewhere: the Council of Europe's convention on autonomy, the AI Act on manipulation, NIST on over-reliance, IEEE 7010 on wellbeing across domains, UNICEF on dependency and exit for children. Our proposal is to turn them into measurable blocks compatible with existing evaluation practice — and to let independent researchers try to prove us wrong. In Life GPS today these five classes are not yet measured as metrics. That is the next work, not a claim.
12. Confirmations without exposing the person
The protocol distinguishes three kinds of statements and does not mix them, so that a recipient can tell what it is looking at:
- A source claim — «this degree was confirmed by this university.»
- A person claim — «the person has stated this preference or intention.»
- A system inference — «the system concluded this from the context available to it.»
Where a derived insight leaves the person's side — for instance, to a lender, instead of the whole financial picture — it must carry at minimum: what exactly is asserted; who formed the conclusion; for which purpose; for how long it is valid; which categories of data it drew on; what it does not reveal; an explanation the person can understand; a separate consent for the transfer; and a way to contest it or not use it.
A derived insight does not become a hidden universal score of a person. One insight exists for one purpose and one interaction.
13. Sector profiles
A profile defines how the common core is used in one sector: which requests are allowed, which confirmations may be needed, what the sector may not receive through the profile, which actions may be delegated, what must return to the person as a result, term and revocation, and which sector laws and standards apply. One rule holds across all of them:
Deep understanding may happen on the person's side. Deep disclosure to the outside does not follow from it.
That is why one person-side system can work with profiles for finance, health, education, work, government, insurance and agents without building seven different models of the person — and why no profile may demand «hand over your whole model.»
Work. Today a company evaluates a candidate through a CV, tests and a dozen identical forms. On the person's side, the question is what this job would do to the whole life — pay, time, commute, family, growth, health, trajectory — before applying. The employer describes what the role needs; only the confirmations the candidate allows leave. Matching is deep; disclosure is minimal. Not permitted: a numeric evaluation of a person, their life, the right to decide for them, surveillance of an employee, or refusal to disclose as grounds for refusal.
Education. Not «which course to assign,» but what the person is actually trying to build and which knowledge, people and environment they need now. The school is part of the path, not the owner of the learner's full model. Children and adolescents are covered by separate rules.
Government. A public office requires a file; the next office collects the same file again. On the person's side: the life situation, the rights and programmes available, and why. Through the protocol: the minimum package from the sources, a receipt, and no re-collection by the next office. The state keeps its powers, registers and decisions; no outside platform observes its citizens; the whole model of a person stays with the person. Estonia and the EU once-only system already demonstrate important parts of this scenario; what they do not yet do is the whole-life part — which is why the protocol exists.
Health. A medical decision ends at the door of the consulting room. «Walk every day» collides with work, children, transport, money and time. The person-side system is needed between visits — to make the prescription executable inside a real life. The clinician receives the relevant medical context, if the person allows it, not a biography. This is not a replacement for a clinician.
Credit. Today the bank checks creditworthiness; the person receives a contract they do not fully understand, and the debt lives apart from the life. On the person's side, the loan is modelled inside the whole life and in time. The person sees not a contract but a load — how payments fall on current work, how the burden is distributed over the years. They borrow exactly as much as will not burn them, if they really need it. They see options; the system suggests how to strengthen income and close sooner — seven years instead of twenty, by building income growth, skills, a new job, a business, or changed spending into the route. The bank decides by its own lawful criteria and receives only the confirmations it needs — sufficient for that lawful purpose, not «everything.» Not permitted: tasks, discipline, health, relationships, faith, emotions; no evaluation of a life; no hidden scoring; no right to decide for the person. After the deal, the loan stays in the route until it is closed: payments, reserve, rate, refinancing, life events; on drift, an early warning and better options rather than collectors. To the regulator: this is not a new credit score. It is the person's own infrastructure for understanding the consequences of a loan and carrying the obligation for its whole term. Whether that reduces arrears, financial stress and bad decisions is for research to show. Credit is unavoidable and necessary for people; we help them carry it.
Mortgage. The same, over fifteen to thirty years — and at the same time the life journey «I want a home» below.
Insurance. The insurer prices risk and sells cover; afterwards the person is on their own. On the person's side: what in this life actually needs protecting, the gaps between policies and their consequences. Through the protocol: the minimum permissible slice for a specific product — not a «whole-life» risk profile. The policy lives in the route: prevention → renewal → a claim with the documents already gathered → changed circumstances.
Pensions and savings. «Will it be enough for the life I have chosen?» — a forecast on the person's side, and adjustments along the way rather than at sixty.
AI agents. An agent receives the intention, the limits, the authority, the permitted tools, the money and time budgets, the prohibited classes of action, the term and the escalation rule — not the whole life. The result and the receipt come back. What is checked is not only «did it do the task» but what happened to the person. In commerce, verifiable constraints already exist; the protocol speaks their language and adds the provenance of the goal.
Between people. A minimal request to another person, without either party's biography. This is the case where we have gone furthest ourselves: when a person with a problem speaks to someone who has the expertise, neither needs to know anything about the other — nor do we — beyond the relevance of the expertise and the substance of the request. A receipt may confirm that help happened; it does not become a public rating of a person.
Also covered: housing and rent, energy and connectivity, and crisis — where the helper receives the minimum needed to help now.
14. Life journeys
Governments already organise services around life events; New Zealand, Estonia, Singapore and the EU benchmark show how far that has come. We build on it, and we do not claim it as new. What we propose is a shift in where the journey begins and how far it reaches:
Existing life-event services start when an event has happened or is known to the state, and gather the related public services. A journey in this protocol starts when a person is still only forming an intention; the person-side system models the consequences before the choice; it gathers private, public and human systems around that one intention at the same time; each sees only the part it needs; and after the decision, the obligations of different sectors remain connected to the person's route through time.
«I want a home.» For the person, one goal. For the world, a dozen systems: bank, mortgage, insurer, property, notary, tax and state, the children's school, the commute, work, health, family, renovation, energy, the future reserve. Open banking will handle the financial exchange; the wallet will confirm identity; the insurer will price its risk; the state will register the transaction. None of them gathers the decision itself. The person-side system holds the sum of the decision; the protocol gives each system its part; each system's result returns to the same route.
The same shape holds for: moving to another country («tell about myself once» across borders); having and raising a child; starting a business; changing profession; caring for an elderly parent (delegation inside a family only with that parent's own authority or the law — their data remains theirs); losing a job; retiring.
A minimal journey holds: the intention · the participating profiles · dependencies · options · consequences for the life · the person's decisions · who may learn what · who did what · what happened · what must be carried further.
15. What each party keeps, and what we do not promise
We do not claim the protocol is good for absolutely everyone. We wrote down, for more than thirty kinds of participant, what they fear, what they keep, what they gain, their role, and the red line — what the protocol does not promise them. The short version:
- The person keeps the right not to act, to change the goal, to revoke, to see each action and consequence, and to leave with their own model. We do not promise that «the system will decide for you.»
- Other people whose data enters a life — partners, children, colleagues — keep their own rights. One person's consent does not become another's.
- Children, parents and guardians get a separate model of representation, not ordinary consent: authority that respects age and capacity and transfers control gradually. We do not promise a parent the child's full model.
- AI laboratories and personal assistants keep their models, interfaces and products. They receive a scoped mandate and return a receipt of action and result. We do not claim to set the rules by which any assistant works; we offer an open, interoperable contract through which different systems can work on the person's side.
- Operating systems, devices and app stores keep their security boundary and permission model; the protocol lives inside it, not around it.
- Agent protocols (MCP, A2A, AP2 and their successors) keep transport, discovery, execution and payments. We add an envelope of human intention, context and outcome — not another transport.
- Identity and credential ecosystems — the European wallet, W3C, OpenID, FIDO — are the substrate. We do not become another identity wallet.
- Data intermediaries and the MyData community keep neutrality and the machinery of consent and transfer. Their formula is theirs; we build on it.
- Banks and lenders keep the credit decision, AML, fraud controls and their own risk models. They receive what is sufficient for a specific lawful purpose. We do not promise «no less data than today,» and we do not promise lower defaults before research shows it.
- Credit bureaus, KYC and fraud providers keep their lawful reports, scores and assertions with provenance, purpose and term. Their score does not become a universal evaluation of a person.
- Insurers keep pricing and underwriting under their own responsibility. They do not receive a whole-life risk profile.
- Clinicians and health systems keep clinical authority and the medical record. We do not claim to know health better than a doctor.
- Psychologists, therapists, social workers and coaches keep professional responsibility, confidentiality and the human relationship. They enter the route as partners, by purpose — not as a subspecies of AI provider.
- Employers keep lawful employment decisions and receive job-relevant evidence. Workers and their representatives are a separate party: nothing happens behind the worker's back.
- States keep law, registers, eligibility, official decisions and responsibility. The protocol does not replace public authority.
- Regulators are an external authority, not a «partner of the protocol.» The protocol should produce evidence for their checks, not certify itself.
- Standards bodies — ISO, IEC, W3C, IETF, HL7, OpenID, FIDO, the Linux Foundation — are upstream. We produce crosswalks, profiles and namespaced extensions, not duplicates, and we do not announce a standard.
- Independent researchers, auditors and certifiers get receipts, logs and outcomes as objects of study, and the right to a negative result. We will publish it.
- Security and anti-fraud infrastructure keeps authentication, rate limits and policy; an agent must prove who it is and whose authority it carries.
- Merchants and marketplaces keep catalogue, price, terms, the right to refuse and the customer relationship; they receive a qualified intention instead of a whole life.
- Payment rails remain rails, not a layer of life decisions.
- Accessibility and assistive technology are a requirement of the protocol, not an afterthought: supported decision-making must be possible for people who cannot «just confirm.»
- Consumer, digital-rights and child-rights organisations are invited to break the protocol, not to lend it logos.
- Third-party developers get open schemas, predictable conformance and admission by capability — not an approved partner club.
- Competition authorities should find that Life GPS is one implementation on the person's side, not a mandatory one.
Where there is a real conflict, we say so. Business models built on covert sale of personal data, on secretly grading a person, on forced profiling, or the retention of attention are not compatible with this protocol as they stand. They may enter as transparent, purpose-bound participants with the person's permission. We do not change the principle to accommodate them. Consumption, in our view, shifts from quantity to quality in the person's favour — and that is a position, not an apology.
16. Principles
- The person is the source, not the object of evaluation.
- Less leaves than is known.
- Only what the person has confirmed counts.
- Each request has a purpose and a term.
- No rating of people — explicit or hidden.
- Each action is explainable.
- Whatever leaves is understandable to the person: what it reveals, to whom, why, for how long.
- Reversibility and exit: revoke, leave, take your own — including your model, into another system on your side.
- The person's protection outranks the organisation's goal.
- The person decides; an agent acts only within the authority it was given.
- By default, context stays with the person.
- No single company — including Life GPS — should have the sole right to define the protocol once it is open.
- The system helps a person reach a goal; it does not become the author of the goal unnoticed.
- A person's life includes other people; their data does not become that person's data.
17. What the protocol does not do
It is not a rating of people. Not a hidden score. Not a sale of data. Not surveillance. Not a replacement for the person's decisions. Not a mandatory set of life areas for the world. Not a replacement for existing standards and mechanisms. Not an arrangement in which one company — including ours — owns the rules.
18. Where Life GPS stands in this
Life GPS is a working product on the person's side, and the first environment in which this architecture is being tested on that side. It is not a base from which a life is transferred to organisations. It was built to test the opposite: how useful outcomes can be produced with substantially less disclosure of personal context — and without force applied to a person. The clearest case so far is between people: someone with a problem and someone with the expertise need to know nothing about each other, nor do we, beyond the relevance of the expertise and the substance of the request. Whether the same holds for a bank, an insurer or an employer is exactly what the sector pilots are for.
What works today: the core, the map of a life, the route where each next step explains its reasoning, the avatar, programmes, crisis handling that works offline (Life GPS is not a medical, emergency or crisis service — it points to real help), Russian and English. A network between people is built and not yet open — it launches with the first funding round. The constraints that govern the system were written before the code that implements them and are published. Scoring a person with a number is forbidden by a law of the system. The beta is open.
What is not live yet: the connections to institutions through the protocol — banks, public services, agents. Those open with the next stage. So, to be exact: the product on the person's side exists and can be tested now; the open protocol is the next step, and this document is its first public form.
Three loops connect them. What survives real people and independent testing inside the product is opened as a common protocol. Sectors that take part in shaping the protocol bring people and support. And each sector that connects makes the system on the person's side more useful — a bank brings real terms and schedules, a clinician brings prescriptions, the state brings rights and events — so that the world gradually enters the person's route through the protocol rather than around it.
19. Who governs it, and the path
Not decided yet — and that is a question we put openly. The rule we commit to now is the one in principle 12: once the protocol is open, no single company, including ours, has the sole right to define it. The likely forms are an open foundation, a consortium, or a handover to an existing body; we would rather design that with the institutions named in this document than alone.
The path is: a working implementation → measurement of the five evaluation classes → independent verification → an open protocol → compatibility with existing standards → and, if others so decide, recognition as a standard. We do not announce a standard. We place a working implementation next to what others are building.
Compatibility, in order of priority:
- Core: ISO/IEC TS 27560 for consent records and receipts; W3C Verifiable Credentials 2.0 for credentials, provenance and selective disclosure.
- Sector implementations: the European Digital Identity Wallet; FHIR Consent for health; open banking, CDR and Open Finance for finance; OOTS and X-Road for government; AP2 for agents in commerce.
- Agency and evaluation: AI Act Article 14; the NIST AI RMF; IEEE 7010; HUDERIA and the Council of Europe's convention.
Before any technical version, we have listed the requirements a first specification must meet: the rights of other people in a life; a separate model for children and guardians; responsibility for the forecast and the boundary with regulated advice; the prohibition of coerced disclosure; security for what is the most valuable target imaginable — a person's whole model; disclosure of the person-side system's own commercial ties; accessibility; and the right to leave with a sufficient representation of one's own model, so that the protocol does not itself create the dependence it is meant to prevent.
20. What we are asking
If you are a person: open the product. Try it. Tell us where it fails you.
If you are a researcher or an evaluator: we built a system with unusual constraints. Break it. Tell us what in it is worth measuring, and how you would tell a change caused by the system from one that would have happened anyway.
If you work in a bank, a central bank or a financial regulator: you already model whether a household can repay a loan. Help us test the other side — whether a system on the person's side improves the quality of the financial decision for the person, without turning their life into another score.
If you are an insurer: help us build the right scenario for one product on a working system.
If you build AI agents or assistants: what does human oversight mean once an agent acts on its own? Put our human-side layer next to your safety systems and check whether the goal, the authority and the consequences stay with the person over time.
If you work in digital government: you already gather services around life events. Let us test the next step — from the citizen's own intention, across public and private systems at once — while your powers, registers and decisions stay exactly where they are.
If you work in a standards body: we deliberately reuse existing mechanisms for consent, credentials, selective disclosure, portability, delegated action and human oversight. Our question is whether the remaining pieces — whole-life context before an interaction, longitudinal outcomes after it, goal provenance and cross-sector journeys — can be specified interoperably with what you maintain. We want these assumptions challenged before we formalise them.
If you write about this: the story is not a startup announcing a standard. It is that AI is learning to act for people faster than the world is building infrastructure on the side of the person — and that most of the pieces for that infrastructure already exist, waiting to be connected from one side.
21. What we do not claim
We are not first. We have not proven anything yet. This is not a world standard, and we do not build «HTTP for life.» We do not know a person better than they know themselves. We are not building a credit score of a life, or a universal model of a person. We do not replace the European wallet, open banking, FHIR or any of the systems named above. We have not shown that any of this reduces defaults, improves health or retains employees — those are hypotheses for research. Life GPS is a working product on the person's side; the open protocol is the next step, and we would rather be corrected now than believed too early.
22. One thought to keep
Today the whole world builds its systems around their own functions. We are trying to add a durable side of the person themselves — so that a bank, a doctor, a state, an employer and an AI can interact with a person without taking their life apart into separate models that belong to someone else.
Life GPS is not there to give the world more data about a person. It has to know enough, on the person's side, so that the world can be given less — and so that each outside decision takes its right place in that person's life.
Life GPS · lifegpsos.com · hello@lifegpsos.com
This is a public draft. Each factual statement about other systems and standards refers to the sources below; if you find an error or prior work we have missed, write to us and we will correct it.
Sources
Consent, identity, data ISO/IEC TS 27560 · HL7 FHIR Consent R5 · Estonia — data consent service (RIA) · W3C Verifiable Credentials 2.0 · W3C VC 2.1 working draft · EU Regulation 2024/1183 — European Digital Identity · EU once-only technical system — Implementing Regulation 2022/1463 · EU Data Act · GDPR · MyData declaration · Solid protocol
Finance EU Delegated Regulation 2022/2360 (SCA renewal) · FCA — 90-day reconfirmation · UK Open Banking — consent dashboards · RBI — Account Aggregator Master Direction · Banco Central do Brasil — Open Finance · Australia CDR — consent · Australia CDR — insights · ACCC — non-bank lenders join CDR
Agents and AI governance Agent Payments Protocol — specification · AP2 — Checkout Mandate · EU AI Act · NIST AI 600-1 · NIST AI 200-2 (draft) · IEEE 7010 · Council of Europe — HUDERIA · CETS 225 · UNICEF — Guidance on AI and children v3 · OECD AI Principles
Life-event public services Estonia — proactive services (RIA) · SmartStart, New Zealand · LifeSG, Singapore · EU eGovernment Benchmark 2026
Research on AI and human agency Carroll, Dragan, Russell, Hadfield-Menell (2022) — arXiv 2204.11966 · Fang et al. (2025) — arXiv 2503.17473 · Kirk, Gabriel, Summerfield et al. (2025) — arXiv 2502.02528 · Sharma, McCain, Douglas, Duvenaud (2026) — arXiv 2601.19062 · Kosmyna et al. (2025) — arXiv 2506.08872
Every claim on this page carries a status