Who holds the whole person when every institution holds only a part?
In short
States and UN bodies are responsible for the person as a whole. Agencies and foundations hold one part of a life each: the child, the worker, the patient, the woman, the older person. Independent institutes measure and defend. Standards groups and open-source projects are giving agents identity, delegated authority, loyalty tests and conformance suites. Every one of these is a real piece of the person's side of AI, built by serious people. What we have not found is the place where the pieces meet for one person — the side that stays theirs when the agent, the service and the area of life change. This page maps who holds which piece and how we connect to each. It is drawn from a single registry and grows as we check.
We are not writing this to say we are ahead. We are far enough to show a working construction and early enough not to pretend one small company should define the rules for everyone. If you are on this map and we have described you wrongly, or you should be here and are not, write to hello@lifegpsos.com and we will correct it.
1 · HUMANITY — who is formally responsible for the person as a whole
How we connect. We bring the person's side as evidence and use cases to the tables where states already meet — consultations, focus groups, written submissions — and ask one question: who holds the whole person when every mandate holds a part?
| Who | What they do, in their words | The question it answers | What stays open for the person | What we bring |
|---|---|---|---|---|
| UN Global Dialogue on AI Governance every country at the table entry: consultations · partnerships hub · mailing list | the UN platform where all governments and stakeholders convene on AI governance; established by the General Assembly under the Global Digital Compact; first session Geneva, July 2026; next New York, 3–4 May 2027; themes include human rights, transparency, accountability and human oversight | how states cooperate on governing AI | governance of systems does not by itself give one person a side that follows them across systems | written submissions and consultations; the person's side as a use case for the human-oversight theme |
| UNESCO Recommendation on the Ethics of AI entry: Observatory · Member State channels | the first global standard on AI ethics, adopted by 193 Member States in 2021: human rights and human dignity, human oversight and determination, policy areas from gender to data; a Global AI Ethics and Governance Observatory | what AI must respect — across societies | a norm for systems, not a mechanism one person carries between them | our constraints written before the code map onto its principles; we offer a working example for the Observatory |
| Council of Europe Framework Convention on AI entry: CDNET · HUDERIA · Conference of the Parties | the first legally binding international treaty on AI, human rights, democracy and the rule of law (opened 5 September 2024; the EU is a party): human dignity and individual autonomy, remedies and safeguards for affected persons, risk and impact assessment | what states must guarantee to people affected by AI | remedies after the fact; not a side that acts for the person before and during | CDNET and HUDERIA as places to bring the person-side model; Czechia is a member state |
| Ofcom Online Safety Act, UK entry: consultation webform | consultation on user empowerment tools and identity verification duties for the largest services (closes 2 October 2026) | what a user can switch off inside one service | a side that travels between services, so the burden of protection does not sit on the person alone | a consultation response with the person's side as a working alternative |
2 · HUMAN LIFE — who is responsible for one part of a life
How we connect. To each mandate-holder: your part of the person is real. We bring a working construction where that part meets the others — and ask you to test whether the person's interest survives the crossing between your domain and the next.
| Who | What they do, in their words | The question it answers | What stays open for the person | What we bring |
|---|---|---|---|---|
| UNICEF Child-centric AI entry: Digital Impact · D-CRIA toolkit | child-centric AI: five principles — developmental appropriateness, privacy by default, genuine transparency, inclusion, and agency: encourage healthy independence rather than emotional dependency; child rights impact assessments for business | what AI owes a child | the child's best interests between school, AI companion, family, health, money and attention — not inside one product | the child and guardian as one of our 26 protected areas; a joint scenario on best interests across domains |
| 5Rights Foundation Children & AI Design Code entry: compliance programme · research centre | children's rights translated into design requirements: the Children & AI Design Code, research on persuasive design, the Digital Futures for Children centre with LSE; multilateral work with the AU and the UN Committee on the Rights of the Child | how products must be designed for children by default | design duties on each product; a side of the child that persists across products | our constraints (no feed, no streaks, no attention optimisation) against their Code; a scenario for the Digital Futures centre |
| UN Women digital public infrastructure for women entry: publications · programmes | gender-inclusive digital public infrastructure across the whole life cycle — from birth registration to support in older years — digital ID, payments and data exchange; violence and AI; economic empowerment | how public digital infrastructure serves women's lives | infrastructure per service; the woman's own side that stays hers between services and decades | Women's World in the product and the person's side as the life-cycle layer their DPI work describes |
| WHO AI for health entry: Global Initiative on AI for Health — ai@who.int | governance, guidance and standards for responsible AI in health; the Global Initiative on AI for Health with ITU and WIPO; ethics guidance on large multimodal models; responsible AI for mental health and wellbeing | how AI may be used for health | health optimised alone; who resolves the conflict between health, money and work for one person | health as one of the 12 life areas the person's side has to protect; a scenario for the Global Initiative |
| ILO human-centred AI in the world of work entry: publications · G7 Employment Working Group | with the OECD and the G7: a compendium of best practices for a human-centred adoption of safe, secure and trustworthy AI in the world of work; workers, skills and transitions | what AI owes the worker | the worker is protected; the same person's health, family and money sit outside the mandate | work as one life area among twelve; a scenario where the work agent and the rest of the life conflict |
3 · GUARDIANS — independent advocates, researchers, civil society
How we connect. Measure it, break it, compare it. We publish the gaps and the statuses; you publish what we missed.
| Who | What they do, in their words | The question it answers | What stays open for the person | What we bring |
|---|---|---|---|---|
| Project Liberty Institute pro-human AI ecosystem entry: Alliance · Institute | an independent 501(c)(3) founded by Frank McCourt: open infrastructure that puts people in control of their data and identity (DSNP), policy frameworks (the Digital Choice Act enacted in Utah and South Dakota), and research proving pro-human AI can be commercially competitive; the Project Liberty Alliance | how an open, pro-human AI ecosystem gets built and funded | protocols for data and social identity; a persistent side of the person that decides across domains and executors | the person's side as a layer above data portability; the Alliance as a network, not a letter |
| Partnership on AI companies · civil society · academia entry: partnership · programmes | a 501(c)(3) convening companies, civil society and academia; programmes on AI and human connection, labour and the economy, safety, policy; recommendations to the UN Global Dialogue; real-time failure detection in agents | what industry and civil society can agree on | guidelines for developers; the person's own side is not their object | the AI and Human Connection programme; our failure classes as input to agent failure detection |
4 · PIECES — who is already building the technical layers
How we connect. Your piece plus a persistent person's side. We join the working groups, contribute use cases and requirements, and offer the product as a test environment.
| Who | What they do, in their words | The question it answers | What stays open for the person | What we bring |
|---|---|---|---|---|
| ITU-T FG-TIDA Trust and Identity for Humans and Agentic AI entry: free ITU account · mailing list | trust management and interoperable digital identity for humans and for agentic AI: use cases, delegation artefacts, trust lifecycle, human oversight; under ITU-T Study Group 17 | whether, and under what conditions, an entity should be trusted to act | the side of the person that stays the same between agents and after an authorised action | a use case with candidate requirements for deliverable 4.1; participation in the preparatory e-meetings |
| W3C Agent Identity Registry Protocol CG entry: W3C account · CLA | verifiable agent identity bound to a controlling organisation, authorisation scope, credentials, revocation; integration profiles with MCP, A2A, OAuth/OIDC, SPIFFE | who the agent is, who controls it, what scope it carries | an authorisation scope derived from the person's side, not only from the organisation that controls the agent | join the group; comment on scope derivation |
| IETF WIMSE workload identity entry: mailing list | workload identity in multi-system environments; personal identities are explicitly out of the charter | how workloads identify each other | the person is outside the charter | read the AI identity management draft before commenting; a separate Internet-Draft if the person's side does not fit |
| OpenID AIIM Community Group AI identity management entry: participation agreement · mailing list | use cases, agent identity assertion, tokens between agents, discovery and governance; organising principle: empowerment through consent | which identity standards agents should use | consent is not the same as interest; who holds the person's goals and limits when the agent changes | a use case for the Use-cases and Threat Modelling subgroups |
| DIF Trusted AI Agents WG delegated authority entry: Contributor membership | an interoperable stack for trustworthy AI agents: identity, authority and governance; reports on delegated authority, its threat model and its governance; a Delegated Authority task force | what authority a person delegated, and how it is governed | what remains acceptable for the person after delegation, across the rest of their life | Contributor membership (free); a use case for the Delegated Authority task force |
| Loyal Agents Stanford DEL + Consumer Reports entry: loyalagents.org | agents loyal by design: duty of care and duty of loyalty, agent ratings and loyalty tests in sandboxes, the Human Context Protocol, a revocable model of delegated authority and authentication | does the agent act loyally, in the consumer's best interest | an agent can be loyal to its task and authorised, and the combined result can still be wrong for the person's life as a whole | our whole-person failure cases as input to their evaluations; the person's side above loyalty |
| W3C Agent Conformance & Benchmarking CG entry: W3C account · CLA | reproducible conformance suites with adversarial fixtures; crosswalks to OWASP, NIST, ISO/IEC 42001 and the EU AI Act | does the agent meet published requirements, reproducibly | a test that the agent did not leave the person's mandate | propose a person-side conformance profile as a work item |
| Solid / Inrupt — Charlie Sir Tim Berners-Lee entry: release partners | a personal AI agent on the person's side: collects and connects their information, picks the AI for each task, disguises personal details before they reach an external model; released through partner organisations | what may be known about the person, what leaves | what is still acceptable for this person's life once the data question is answered well | their data side, our authority and arbitration side — an interface conversation |
| LifeOS Daniel Miessler · open source entry: GitHub | an open-source life operating system that captures who you are, what you care about and where you are going, and moves you from current to ideal state; memory, skills, a digital assistant identity, security gates | what the person wants and remembers, for their own AI | an independent boundary that decides, per interaction, what any executor may know, do or spend — outside the executor | an open-source neighbour: compare theses; the person's side as a boundary any harness can call |
| Human Context Protocol Loyal Agents entry: reference implementation | a protocol connecting LLM clients and memory managers so a person's context is portable | how the person's context travels between AI clients | context that travels is not yet a side that decides | portable context plus a decision boundary |
| AP2 agent payments protocol entry: specification | signed mandates, verifiable checkout, receipts back to the person | is this payment what was mandated | does the mandate still fit the person's life now | the mandate is theirs; the arbitration above it is ours |
22 organisations shown — each read by us from its own pages, most recently on 2026-09-28. 40 more we have read about but not yet verified ourselves; they are counted, not shown, and appear as we check. · Corrections: hello@lifegpsos.com
The question underneath
Every layer above answers a real question: whether the agent may be trusted, who controls it, what authority was delegated, whether it acts loyally, what may be known about the person, what a user can switch off. Put together, they answer "may the agent do this?" They do not answer "should this still happen for this person, given the rest of their life?" — the child's school agent, the parent's finance agent and the family's health service are each authorised, each loyal, and the combined result can still be wrong for that family. That second question is what the security model exists for, and what the protocol puts up for review.
What we are asking each of you
States and UN bodies — take the person's side as a use case in your consultations; we will bring evidence, not slogans. Mandate-holders for one part of a life — test whether the person's interest survives the crossing from your domain to the next. Guardians and researchers — measure it, break it, compare it; the scope is on /security. Builders of the pieces — bring your piece; the interface is the protocol, and the product is a test environment. People — check that this side stays yours.
What takes a large organisation years of approvals between departments, an independent side can build and publish in months — and test with you now. That is what we are offering, not a finished answer.
Sources
Every organisation on this map is described from its own pages, read by us on the date shown in the registry; the picture and the tables are generated from that one registry, so a correction changes both at once. Our own claims carry their status on the security model. Corrections: hello@lifegpsos.com.
Every claim on this page carries a status