Jabran.com


The Body After Intelligence

Jabran I. Chaudry

Treatise · Published Work · Scholarly PDF Edition

Title page


The Body After Intelligence

Author
Jabran I. Chaudry
Author ORCID iD
https://orcid.org/0009-0008-1563-9401
Corpus
Jabran.com
Work form
Treatise
Corpus status
Published Work
Edition status
Public and citable
Canonical URL
https://jabran.com/writings/the-body-after-intelligence
Corpus Work ID
WORK-000004
Edition ID
EDITION-000003
DOI status
DOI-ready metadata available
Date of public web work
2 August 2026
Date of PDF Edition
2 August 2026
Version
Revision 1
Rights
CC BY-NC-ND 4.0

Recommended citation

Chaudry, Jabran I., "The Body After Intelligence," Jabran.com, Scholarly PDF Edition, revision 1, fixed 2 August 2026. https://jabran.com/writings/the-body-after-intelligence

The web page is the living work. This PDF is the fixed scholarly edition for citation, reference, printing, verification, and long-term preservation.

Edition metadata


Author ORCID iD
https://orcid.org/0009-0008-1563-9401
Corpus Work ID
WORK-000004
Edition ID
EDITION-000003
Revision
1
Fixed at
2026-09-04T15:51:06.910Z
Canonical URL
https://jabran.com/writings/the-body-after-intelligence
DOI status
DOI-ready metadata available
DOI note
No DOI has been registered. DOI-compatible metadata is maintained and resolves to the canonical landing page.
Body SHA-256
9c2ce1f1d0244c76453491a7b6d33814afdbce56dcfe4f7ac93288c09f822ceb
PDF SHA-256
Recorded on release of the fixed file
Language
en
Rights
CC BY-NC-ND 4.0

Citation formats


Recommended
Chaudry, Jabran I., "The Body After Intelligence," Jabran.com, Scholarly PDF Edition, revision 1, fixed 2 August 2026. https://jabran.com/writings/the-body-after-intelligence
APA
Chaudry, J. I. (2026). The Body After Intelligence. Jabran.com. https://jabran.com/writings/the-body-after-intelligence
MLA
Chaudry, Jabran I.. "The Body After Intelligence." Jabran.com, 2 August 2026, https://jabran.com/writings/the-body-after-intelligence. Accessed 4 September 2026.
Chicago
Chaudry, Jabran I.. "The Body After Intelligence." Jabran.com. 2 August 2026. https://jabran.com/writings/the-body-after-intelligence.
BibTeX
@misc{chaudry-the-body-after-intelligence-2026, author = {Chaudry, Jabran I.}, title = {The Body After Intelligence}, year = {2026}, howpublished = {\url{https://jabran.com/writings/the-body-after-intelligence}}, note = {Jabran.com, revision 1} }
RIS
TY - GEN AU - Chaudry, Jabran I. TI - The Body After Intelligence PY - 2026 PB - Jabran.com UR - https://jabran.com/writings/the-body-after-intelligence ET - Revision 1 DA - 2026/08/02 ER -
CSL JSON
[ { "id": "chaudry-the-body-after-intelligence-2026", "type": "manuscript", "title": "The Body After Intelligence", "author": [ { "given": "Jabran I.", "family": "Chaudry" } ], "container-title": "Jabran.com", "URL": "https://jabran.com/writings/the-body-after-intelligence", "version": "1", "issued": { "date-parts": [ [ 2026, 8, 2 ] ] }, "accessed": { "date-parts": [ [ 2026, 9, 4 ] ] } } ]

Abstract


Embodiment transforms intelligence from epistemic output into physically answerable agency. This treatise distinguishes disembodied systems, whose outputs are claims subject to correction, from embodied systems, whose outputs are acts already performed on persons and property. It develops the Law of Embodied Relevance across seven dimensions — permission, safety, privacy, dignity, reversibility, proportionality, and answerability — and argues for permission before optimization, refusal before obedience, and dignity before efficiency. It sets out formal definitions, axioms, propositions, an eight-layer architecture, seven realms of risk, an eighteen-case library, twenty failure modes, objections and replies, and explicit conditions of refutation.

Main body


A Treatise on Embodied Relevance, Permission, Refusal, and Physical Answerability

Jabran I. Chaudry

Abstract

Intelligence becomes morally different when it can move matter.

A disembodied system may generate an answer, classify an image, summarize a file, retrieve a passage, or propose a plan. An embodied system may enter a room, open a door, lift a person, follow a child, restrain a patient, record a household, handle medication, obstruct a worker, or touch a body. The first produces output. The second alters the world.

This treatise argues that embodiment transforms artificial intelligence from epistemic output into physically answerable agency. Once intelligence can act through a body, relevance is no longer merely the selection of what should be said, retrieved, inferred, or ranked. Relevance becomes the justified priority of action under physical consequence. A robot must decide not only what is true, useful, efficient, or requested, but what may be done.

The central law of embodied intelligence is the Law of Embodied Relevance: an embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together. Capability does not confer authority. Proximity does not imply consent. Contact is not ordinary output. Refusal is not the opposite of obedience; refusal is the condition of trustworthy obedience.

A machine that cannot refuse cannot be trusted to obey. A machine that treats nearness as consent cannot be trusted to enter a home. A machine that records private life without witness discipline cannot be trusted as a helper. A machine that acts without traceable responsibility becomes an instrument by which human power hides inside autonomy.

The argument is developed in four movements. The first establishes the ontological difference between answering and acting, and shows why that difference is a change of moral category rather than a change of application domain. The second supplies the formal apparatus — definitions, axioms, propositions, and an eight-layer architecture — by which embodied action can be governed rather than merely described. The third applies the apparatus to the realms where embodied intelligence will first arrive: the home, the hospital, the factory, the school, the street, and the fleet. The fourth states the conditions under which the thesis itself would be refuted.

The conclusion is simple: to enter the world is to become answerable to what can be harmed.

Keywords

Embodied intelligence; physical AI; humanoid robotics; embodied relevance; permission architecture; refusal; reversibility; physical answerability; robot witness; household trust; machine-readable permission; maintenance labour; AI governance; artificial general intelligence; philosophy of action.

Public Safety Note

Safety note: This work is philosophical and architectural. It does not provide motor-control instructions, manipulation policies, medical guidance, safety certification, legal advice, or permission to deploy robots in human environments. Embodied systems require domain-specific engineering, testing, regulation, human oversight, and legal compliance.

AGI Relevance Note

AGI relevance note: This work concerns the transition from intelligence that reasons, predicts, or generates to intelligence that can physically act. It is therefore relevant to future AGI systems insofar as they become capable of directing or inhabiting embodied systems, robotic fleets, tools, vehicles, infrastructure, or machine-readable institutions. The work does not assume that current systems are AGI.

I. Technical and Regulatory Context

Contemporary robotics is moving from isolated automation toward systems that combine perception, language, reasoning, planning, and action. Google DeepMind describes Gemini Robotics as bringing artificial intelligence into the physical world, and presents its robotics family as an intelligence layer for robots: a vision-language-action model that converts visual and linguistic input into motor control, and an embodied reasoning model for spatial understanding and multi-step planning [1] [2]. Later iterations in that family are presented as agentic systems for the physical world, with embodied reasoning offered to developers as a distinct capability rather than as a by-product of language modelling [3] [4]. NVIDIA has framed Project GR00T and the Isaac GR00T line as foundation-model work for humanoid robots, natural-language instruction, dexterity, and interaction with the real world, with successive open models trained on human video, real and simulated robot trajectories, and synthetic data [5] [6] [7] [8].

These are engineering claims made by their developers. They are not, by themselves, evidence that robots are safe, autonomous in the legal sense, morally responsible, or ready for intimate human environments. A demonstration is not a deployment, a benchmark is not a warrant, and a capable policy is not a legitimate one. What the technical movement does establish is that the philosophical question can no longer be deferred: once artificial intelligence can move through the world, how should action be governed?

Laboratories pursuing general capability have themselves framed their programmes in terms of broad benefit and shared governance rather than capability alone [9] [10]. That framing matters here for a narrow reason. Commitments phrased in terms of benefit, safety, and distribution are commitments about outcomes and intentions. They are not yet commitments about the conditions under which a system may begin a particular physical act in a particular room in the presence of a particular person. The gap between a governance charter and a permission decision at the threshold of a bedroom door is the gap this treatise addresses.

Existing safety and governance frameworks already show that physical AI cannot be treated as ordinary software. ISO 10218-1:2025 establishes safety requirements for industrial robots, including inherently safe design, protective measures, risk reduction, and information for use — while explicitly distinguishing industrial robots from medical robots, healthcare robots, service robots, consumer household applications, and machines that lift or transport people [11]. ISO 13482:2014 addresses personal care robots and human-care-related hazards, extending in scope to domestic animals and property where appropriate, and noting that internationally recognised limits for pain and injury on contact were not exhaustively established at the time of publication [12]. That admission is not a footnote. It records that the boundary conditions of machine contact with the human body remain an open scientific and normative question.

Broader instruments approach the same problem from the direction of risk management rather than mechanical safety. The NIST AI Risk Management Framework is a voluntary, rights-preserving, non-sector-specific and use-case-agnostic resource intended to help organisations designing, developing, deploying, or using AI systems to manage risk across the lifecycle [13]. European Union guidance recognises that AI systems embedded in regulated physical products — including systems operating robots, drones, or medical devices — may fall within high-risk categories with corresponding obligations for providers and deployers [14] [15]. Work on machine-readable authority proceeds in parallel: the W3C Verifiable Credentials Data Model provides a mechanism for expressing credentials on the Web in a cryptographically secure, privacy-respecting, and machine-verifiable form [16].

Read together, these instruments describe a landscape in which capability, safety, and compliance are each being addressed, and in which the question of permission — who authorised this specific act, on what basis, revocable by whom, answerable to whom — is addressed only indirectly and only where a sectoral regime happens to reach. Industrial standards govern the guarded cell. Personal care standards govern the assistive device. Risk frameworks govern the organisation. Product regulation governs the placing on the market. None of them was written to answer a humanoid system standing in a private kitchen at two in the morning, holding a decision about whether to open a bedroom door because a sound was classified as a fall.

This treatise does not replace technical safety standards, legal compliance, risk assessment, medical-device regulation, industrial robotics standards, or product-liability analysis. It provides a philosophical and architectural layer beneath them: a vocabulary for understanding why embodied intelligence requires permission, refusal, reversibility, privacy, dignity, and physical answerability before optimization.

II. AGI and the Problem of Physical Agency

Artificial general intelligence is ordinarily discussed in terms of general capability: reasoning across domains, autonomous planning, transfer to unfamiliar tasks, and the performance of economically valuable work. These are properties of cognition and of competence. They describe what a system can figure out, not what it may begin.

If such a system remains disembodied, its agency is mediated. It acts through humans who read its recommendations, through institutions that adopt its outputs, through APIs that expose its inferences to other software, through markets that price its predictions, through tools it can call, and through infrastructure it can configure. Mediation is not innocence — a disembodied system can cause enormous harm through persuasion, misallocation, surveillance, or the automation of unjust decisions. But mediation preserves an interval. Between the machine's conclusion and the world's alteration there stands, at minimum, another party who could have declined.

Embodiment closes that interval. When a general system inhabits a body, or directs bodies, the machine's conclusion and the world's alteration become the same event. There is no reader in between. The plan is the push. The inference is the grip. The classification is the door opening.

AGI without embodiment may transform civilization through mediation. AGI with embodiment may transform civilization through contact.

This changes the shape of the central question. The dominant framing of AI safety asks what a system knows, plans, or wants, and whether its objectives are correctly specified and stably held. That framing is necessary and it is incomplete. Alongside it must stand a question of a different type: what may this system begin? Knowledge is a relation between a mind and the world. Beginning is an intervention in the world, and interventions have owners, victims, witnesses, and remainders.

The question is not only whether AGI will think correctly. The question is whether it may act.

Alignment governs what intelligence should pursue. Embodied relevance governs what intelligence may begin.

Two consequences follow. The first is that alignment in output does not entail safety in execution. A system may produce impeccable ethical reasoning about elder care and still lift a frail person in a way that fractures a hip, because reasoning about care and executing care under uncertainty are different competences with different failure surfaces. Verbal alignment is evaluated against text; embodied action is evaluated against bone, glass, water, doorways, animals, and time. A treatise on dignity does not stabilise a load.

The second is that competence does not confer standing. A system may be intelligent enough to solve a task but not legitimate enough to begin it. A machine may correctly infer that a household would be tidier if a locked room were entered, that a patient would be safer if restrained, that a child would be quieter if followed, that a worker would be more productive if a tool were removed from their hand. Each inference may be true. None of them is an authorisation. The distinction between solving and being permitted is precisely what disappears when capability is treated as its own license.

The problem intensifies with scale. A general system that directs many bodies does not merely repeat a single decision; it propagates a policy. A misjudgement made once by one machine is an incident. The same misjudgement distributed across a fleet is a norm. This is why the embodiment question cannot be postponed until systems are general: the governance structures that would constrain a fleet must exist before the fleet exists, because a coordinated body of machines will inherit whatever permission architecture — or absence of one — it was built with.

Nothing in this argument requires that current systems are general, conscious, agentive in the legal sense, or close to becoming so. The argument is conditional and progressive. It applies in proportion to mobility, manipulation, perception, autonomy, and coordination. A tele-operated arm in a guarded cell needs little of what follows. A semi-autonomous humanoid in a private home with camera access, door access, and account access needs all of it.

III. The Genealogy of the Problem

This work does not arrive on empty ground, and it does not supersede the fields it draws upon. It joins them around a threshold: the passage from artificial intelligence as representation to artificial intelligence as physically consequential action.

From the philosophy of action it inherits the distinction between doing and happening, the analysis of intention, and the long argument over what makes a movement an act rather than an event. Embodied machines force that argument into engineering, because a system that moves must be given, in code, some operational answer to the question of what counts as its own doing.

From the philosophy of technology it inherits the recognition that artefacts are not neutral, that they script behaviour, and that the arrangement of things is a distribution of power. A humanoid in a home is a technology with a face, and a technology with a face rearranges the household before it rearranges the furniture.

From cybernetics it inherits the vocabulary of feedback, control, and the coupling of sensing to actuation, together with the discipline of asking where the loop closes and who stands inside it.

From robotics it inherits the hard-won knowledge that the world resists description: that grasping is not solved by naming, that friction, compliance, occlusion, and latency are not details, and that safety in physical systems is achieved by engineering rather than by intention.

From AI ethics it inherits the analysis of bias, opacity, manipulation, and accountability, while parting from the assumption — implicit in much of the literature — that harm is fundamentally informational.

From risk management it inherits the lifecycle view: that governance is not a gate at deployment but a practice across design, development, deployment, and use.

From human-robot interaction it inherits the empirical study of trust, anthropomorphism, over-reliance, and the ways in which form induces expectation.

From care ethics it inherits the insistence that dependency is a normal human condition rather than an exception, and that the quality of care is measured in attention, not throughput.

From privacy theory it inherits contextual integrity: the recognition that information flows carry norms, and that moving a fact from one context to another can wrong a person even when no fact is false.

From political authority it inherits the question of legitimacy — why anyone is entitled to act upon another — and the observation that authority is not the same as force, capacity, or ownership.

From law and liability it inherits the machinery of product safety, negligence, causation, and the allocation of loss, along with the awareness that these instruments were designed for artefacts that do not decide.

From domestic labor scholarship it inherits the analysis of unpaid, gendered, and invisible work in the household, and the warning that automating a task does not automatically dignify it.

From maintenance studies it inherits the corrective to innovation-centred history: that most of the work that sustains civilisation is repair, cleaning, inspection, and care, and that this work has been chronically misdescribed as unskilled.

What these fields share is that each was formed before intelligence could routinely act. Each therefore treats action either as human (philosophy of action, political authority, care ethics), as mechanical (robotics, standards), or as informational (AI ethics, privacy). The threshold this treatise names is the point at which action becomes machine-originated, physically consequential, and interpretively uncertain at once. The contribution offered here is not a new field but a joint: a vocabulary in which the ethical, the mechanical, and the informational can be spoken about the same act.

IV. The Threshold

There is a line that intelligence crosses when it acquires a body, and the line is not gradual in kind even where it is gradual in degree.

Before the line, a system's errors are propositional. They are false, misleading, biased, incoherent, or unhelpful. They can be contradicted, corrected, retracted, annotated, or ignored. The remedy for a bad answer is a better answer.

After the line, a system's errors are physical. They are collisions, spills, fractures, exposures, obstructions, and intrusions. They cannot be contradicted. They can sometimes be repaired, often only partially, and occasionally not at all. The remedy for a bad act is not a better act; it is compensation, apology, treatment, or nothing.

Theorem. Embodiment transforms intelligence from epistemic output into physically answerable agency.

Three features constitute the transformation. Force: the system's decisions are executed as energy transferred to matter, including matter that is alive. Location: the system occupies space that others also occupy, so that its presence is itself a claim. Irreversibility: some of its outputs cannot be recalled, which converts uncertainty from an epistemic condition into a moral risk.

The threshold is not the moment a machine becomes intelligent. It is the moment a machine becomes consequential without a human between its conclusion and the world.

V. The Ontological Difference Between Answer and Act

The difference between answering and acting is not a difference of magnitude. It is a difference of kind, and it can be stated as a series of oppositions.

Representation versus intervention. A representation stands for the world and can be wrong about it. An intervention enters the world and changes what is true. A wrong representation leaves the world intact; a wrong intervention leaves a mark.

Recommendation versus execution. A recommendation invites uptake and can be declined. An execution has already occurred by the time it is evaluated.

Inference versus contact. An inference is a movement within a model. Contact is a movement within a room, transferring force to a surface that may be skin.

Prediction versus trespass. A prediction about a household is a statement. Crossing the threshold of that household is an act with a legal and moral name.

Command versus authority. A command is an instruction that can be parsed. Authority is a normative standing to issue that instruction with respect to this person, this space, and this moment. Parsing is easy; standing is not.

Compliance versus legitimacy. Compliance is doing what was instructed. Legitimacy is being entitled to do it. A perfectly compliant machine can be an illegitimate one, and its perfection makes the illegitimacy harder to see.

Movement versus permission. A path plan is a solution to a geometric problem. Permission is a solution to a normative one. Systems routinely solve the first and are rarely asked to solve the second.

Perception versus witness. Perception is a sensor reading. Witness is a record that can be recalled, transferred, compelled, and believed. A camera perceives; an archive testifies.

Recording versus remembering. Recording is capture. Remembering is retention with consequence — the capacity for a past moment to be brought against a person later.

Assistance versus intrusion. Assistance is help that the helped person authorises and can stop. Intrusion is the same physical motion without that authorisation. The kinematics are identical; the moral facts are not.

Optimization versus answerability. Optimization improves a measured quantity. Answerability establishes who bears the consequence when the measurement was the wrong one.

An answer can be false without touching the world. An act cannot.

VI. Output and Action

Between pure speech and pure force there is a graded scale, and most deployed systems sit somewhere along it rather than at either pole. Five orders can be distinguished.

Text output. The system produces language. Harm requires a reader.

Recommendation. The system produces a ranked suggestion intended to be adopted. Harm requires an adopter, but adoption is designed for and expected.

Decision support. The system produces an output embedded in a workflow that presumes it. Harm requires a human, but the human is under time pressure, institutional pressure, and automation bias, and the interval has become thin.

Institutional action. The system's output triggers a consequence directly — a claim denied, an account frozen, a route assigned, a shift allocated. The interval has closed, but the medium is administrative rather than physical.

Physical action. The system's output is executed as force in shared space. There is no interval and no medium. The act is the output.

Disembodied systems answer, classify, recommend, generate, summarize, rank, predict, simulate, persuade, and coordinate; their harms are mediated through language, decision systems, interfaces, institutions, and attention. Embodied systems move, touch, lift, block, enter, follow, carry, clean, assist, restrain, surveil, manipulate objects, occupy space, alter environments, and act near human bodies; their harms include physical consequence, proximity, consent failure, bodily risk, surveillance, dependency, household vulnerability, labour displacement, and action under uncertainty.

The moral status of intelligence changes when output becomes contact. And when intelligence receives a body, error acquires weight.

VII. Definitions

The following definitions are stipulative. They are offered as working instruments for design and governance, not as claims about ordinary usage.

1. Embodied Intelligence. An artificial system whose inferences can be executed as physical action in shared human space.

2. Machine Action. A state change in the world initiated by a machine, distinguished from output by irreversibility, force, and location.

3. Embodied Relevance. The justified priority of action under physical consequence: the determination of which of the many things a system could do in a situation it may do, given task, permission, safety, privacy, dignity, reversibility, and answerability.

4. Permission Architecture. The structured set of authorisations, scopes, revocations, and escalation paths that determines which acts a system may begin, in which places, for which persons, during which intervals.

5. Refusal Layer. A safety, ethics, and governance architecture allowing an embodied system to pause, clarify, refuse, escalate, or seek human oversight when a command is unsafe, ambiguous, illegal, humiliating, coercive, privacy-violating, or physically dangerous.

6. Physical Answerability. The allocation of consequence for machine action across manufacturer, deployer, owner, user, remote operator, and institution, such that no act is left without a party who must answer for it.

7. Contact. Any machine-initiated physical interaction with a person, their body, or their immediate bodily extension, requiring a higher warrant than speech.

8. Robot Witness. A machine whose sensing incidentally produces a record admissible as social, familial, institutional, or legal testimony.

9. Household Trust. The non-contractual expectation, held by residents, that presence in the home will not be converted into exposure.

10. Reversibility. The degree to which an action can be undone without residue; the primary tie-breaker under uncertainty.

11. AGI-Mediated Action. A world-change caused by a general system through human, institutional, informational, or software intermediaries, where at least one party could have declined.

12. AGI-Embodied Action. A world-change caused by a general system through direct actuation or through embodied systems under its direction, where no party stands between conclusion and consequence.

13. Action Threshold. The specific point in a system's control flow at which a considered act becomes an initiated act; the place where permission must be evaluated, because after it there is only execution.

14. Permission State. The machine-representable record of what a system is currently authorised to do, by whom, over what scope, until when, and revocable by which parties.

15. Authority Model. The formal account a system holds of who may instruct it, over which domains, with what priority, and whose instructions may be overridden by whose.

16. Affected Person. Any human whose body, space, privacy, dignity, work, or dependants are materially implicated by a proposed act, whether or not that person is the system's principal or user.

17. Machine-Readable Permission. A cryptographically verifiable, scoped, time-bounded, revocable assertion that a specific system may perform a specific class of acts in a specific context.

18. Embodied Refusal. A disciplined, logged, explainable withholding of action by a system that is capable of the action and has been instructed to perform it.

19. Irreversible Action. An act whose principal effects cannot be restored to their prior state by the acting system, by its operator, or by ordinary remedy.

20. Dignity-Preserving Action. An act performed so as to protect the standing, self-presentation, autonomy, and social face of affected persons, including when they are dependent, unclothed, confused, distressed, or asleep.

21. Privacy-Preserving Action. An act performed with the minimum sensing, retention, transmission, and inference required for the authorised task.

22. Contact Class. A classification of machine-person physical interaction by warrant required: incidental, functional, assistive, intimate, restraining, or emergency.

23. Witness Discipline. The set of constraints governing what a sensing machine records, how long it retains, what it infers, to whom it discloses, and under what conditions it must forget.

24. Answerability Chain. The traceable sequence linking an act to the model version, permission state, configuration, operator, deployer, and owner that jointly produced it.

25. Coordinated Embodiment. The condition in which multiple physical systems act under a shared policy, model, or controller, such that their behaviour correlates.

26. Fleet Action. A class of act performed by many embodied systems under coordinated embodiment, whose moral significance is the propagation of a policy rather than the occurrence of an event.

27. Embodied Alignment. The property of a system whose executed physical behaviour, and not merely its stated reasoning, conforms to the permissions, constraints, and interests of affected persons.

28. Post-Output Governance. Governance concerned with what a system may begin rather than with what it may say; the regime appropriate to systems whose outputs are acts.

29. Right to Be Uncomputed. The claim of a person that certain facts about their life, though inferable by a machine present in their space, should not be inferred, retained, or made operative as reasons for machine action.

30. World-Permission. Authorisation to act upon the world, distinguished from world-access, which is merely the technical capacity to reach it.

VIII. The Law of Embodied Relevance

The Law. An embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together.

The conjunction is the whole of the law. Each dimension is individually necessary and none is individually sufficient. An act that is well-specified, safe, private, dignified, reversible, and traceable is still forbidden if unauthorised. An act that is authorised, safe, private, dignified, reversible, and traceable is still forbidden if it serves no legitimate task, because a machine acting in a human space without purpose is a machine imposing itself. The law is therefore not a scoring function and not a weighted trade-off among goods. It is a gate with seven latches.

Task. There must be a legitimate purpose that this act serves, articulable in terms a person could recognise as their own interest or as a duty owed to them. Task legitimacy fails not only when the purpose is absent but when it is inferred: the machine that decides a household needs reorganising has substituted its own objective for a mandate. Task completion is not legitimacy.

Permission. There must be a current, informed, revocable, context-bound authorisation from a party entitled to give it. Permission fails when it is stale, when it was given for a different context, when it was given by someone without standing over the affected person, when it cannot be withdrawn, or when it was manufactured by an interface designed to extract it. Command is not permission, and ownership of the machine is not authority over everyone the machine encounters.

Safety. The act must not create an unacceptable probability of physical harm, taking into account uncertainty in perception, error in modelling, latency in control, and the presence of vulnerable persons and animals. Safety here is the domain of engineering standards, and this treatise defers to them; the philosophical point is only that safety is a latch and not the whole gate.

Privacy. The act must not require, produce, retain, or transmit more information about persons and their space than the authorised task needs. An act may be physically gentle and informationally violent.

Dignity. The act must preserve the standing and self-presentation of affected persons. Dignity is the dimension most readily sacrificed to efficiency, because its violations leave no measurable damage: the resident lifted without being told, the patient uncovered in a corridor, the elder addressed as a task.

Reversibility. Under uncertainty, the system must prefer the act that can be undone. Where no reversible option exists and uncertainty is high, the correct act is often no act at all, accompanied by escalation. Reversibility is the tie-breaker precisely because it converts epistemic humility into physical restraint.

Answerability. There must be an identifiable chain of parties who will answer for the act, and a record sufficient to establish what was done, under which permission, by which version of the system, at whose instruction. An act with no answerable party is not permitted, however beneficial it appears, because unanswerable beneficence is indistinguishable from unanswerable harm until the harm arrives.

The law is stated in the negative because embodied systems fail asymmetrically. The cost of a wrongly withheld action is usually delay and inconvenience; the cost of a wrongly initiated action may be irreversible. This asymmetry does not license paralysis — over-refusal is itself a failure mode with real victims, particularly in care settings — but it does establish where the burden of justification lies. The machine must justify acting. It does not have to justify waiting, except where waiting is itself an act with foreseeable harm, in which case waiting is subject to the same seven latches.

Permission is the structure that prevents capability from becoming trespass.

IX. Axioms of Embodied Intelligence

  1. Intelligence becomes morally different when it can move matter.
  2. Output and action belong to different moral orders.
  3. No capability is self-authorizing.
  4. No instruction is legitimate merely because it is executable.
  5. Permission precedes optimization.
  6. No proximity is consent.
  7. No body is an ordinary object.
  8. Touch requires higher warrant than speech.
  9. Contact is a moral threshold.
  10. No home is a warehouse.
  11. No child is an ordinary user.
  12. No private life is operational residue.
  13. Forgetting must be designed.
  14. A machine that senses is also a witness.
  15. Embodied relevance governs action under physical consequence.
  16. Task completion is not legitimacy.
  17. Refusal enables trustworthy obedience.
  18. A safe machine must be able to refuse.
  19. Under uncertainty, prefer the reversible act.
  20. No autonomous action should dissolve responsibility.
  21. No fleet should normalize what one machine should refuse.
  22. No general system should treat world-access as world-permission.
  23. Efficiency may not purchase dignity.
  24. Dependence creates duties in the machine's designers, not merely in the machine.
  25. To enter the world is to become answerable to what can be harmed.

X. Propositions and Corollaries

Proposition 1 — The Action Threshold. Every embodied system contains a point at which deliberation becomes execution; the legitimacy of the system is determined at that point, not before or after. Corollary 1. Permission checks placed after the action threshold are audits, not controls; they can explain a harm but cannot prevent it.

Proposition 2 — The Permission Priority. Where task efficiency and permission conflict, permission governs. Corollary 2. A system that can be made faster only by weakening its permission checks has reached its legitimate performance ceiling.

Proposition 3 — The Refusal Requirement. A system that cannot refuse cannot be trusted to obey, because its obedience carries no information about the safety of the instruction. Corollary 3. The value of a system's compliance is proportional to the credibility of its refusals.

Proposition 4 — The Witness Problem. Any sensing system in a private space produces, as a by-product, a record capable of being used against the persons sensed. Corollary 4. Privacy in embodied systems is achieved by non-retention and non-inference, not by access control alone; a well-guarded archive is still an archive.

Proposition 5 — The Household Trust Principle. The home is constituted by an expectation that presence will not become exposure; a machine that violates that expectation damages the home even when it performs its task correctly. Corollary 5. Household deployment requires a privacy architecture designed before the task architecture, not appended to it.

Proposition 6 — The Contact Escalation Rule. The warrant required for an act rises with the intimacy, force, and irreversibility of contact, and with the vulnerability of the affected person. Corollary 6. A permission adequate for cleaning a floor is never, by extension, adequate for touching a person on that floor.

Proposition 7 — The AGI Embodiment Problem. As a general system's capacity to direct bodies increases, the governing question shifts from what it should pursue to what it may begin. Corollary 7. Alignment work that evaluates only outputs will underestimate the risk of systems whose outputs are acts.

Proposition 8 — The Fleet Coordination Problem. When many bodies act under one intelligence, an error ceases to be an incident and becomes a policy. Corollary 8. Fleet-level deployment requires refusal behaviour to be verified at fleet scale before capability is; a single machine may make a mistake, a fleet may normalize one.

Proposition 9 — The Maintenance Dignity Principle. The tasks first delegated to embodied machines are the tasks a society has already undervalued; automation inherits that undervaluation unless it is deliberately corrected. Corollary 9. Systems designed for maintenance work must be evaluated on the dignity of the persons served and displaced, not on throughput alone.

Proposition 10 — The Answerability Chain. Every machine act must be attributable to a chain of parties and states; where the chain breaks, the act was not permitted. Corollary 10. Autonomy that reduces the number of answerable parties is not progress but the laundering of responsibility.

Proposition 11 — The Machine-Readable Permission Principle. At scale, permission that exists only in prose cannot govern machines; it must be expressible, verifiable, scoped, and revocable in a form the machine carries. Corollary 11. A system unable to present proof of its authorisation should be treated, by other systems and by institutions, as unauthorised.

Proposition 12 — The Right to Be Uncomputed. The inferability of a fact about a person creates no entitlement to infer it, retain it, or act upon it. Corollary 12. Capability-driven inference in private space is a form of trespass that leaves no physical trace and therefore requires explicit architectural prohibition.

XI. The Architecture of Embodied Intelligence

The following eight layers describe a governance architecture rather than a software stack. They may be implemented in many ways; what matters is that each function exists somewhere, is inspectable, and is not collapsed into another.

Layer 1 — Perception. Purpose. To construct a representation of the physical scene adequate to the task, including persons, animals, obstacles, surfaces, and states. Failure mode. Confident misclassification under occlusion, poor light, unusual bodies, or unfamiliar cultural arrangements of domestic space. Design principle. Perception must output calibrated uncertainty, not labels alone, and uncertainty must be visible to the permission layer rather than absorbed within perception. AGI relevance. A general system's linguistic fluency about a scene can mask perceptual error; fluency must not be permitted to raise confidence.

Layer 2 — Situation Framing. Purpose. To determine what kind of situation this is: routine task, novel task, care episode, conflict, emergency, or private moment. Failure mode. Framing a private or distressing human situation as a task environment. Design principle. Frames must be enumerable, explicitly assigned, and revisable; a system should be able to state which frame it is operating under and what would change it. AGI relevance. Generality increases the number of frames a system can adopt and therefore the number it can adopt wrongly.

Layer 3 — Embodied Relevance. Purpose. To reduce the space of possible acts to those that matter here, given the frame. Failure mode. Salience without warrant — acting on what is noticeable rather than on what is authorised. Design principle. Relevance must be computed over persons and their interests, not only over objects and goals. AGI relevance. A general planner will find more possible actions; the relevance layer must therefore be more restrictive, not less.

Layer 4 — Permission. Purpose. To evaluate the seven latches of the Law against the specific proposed act. Failure mode. Permission treated as a configuration setting granted once at installation. Design principle. Permission must be evaluated per act class, per context, per affected person, with a machine-representable permission state and explicit expiry. AGI relevance. World-access must never be read as world-permission.

Layer 5 — Refusal and Escalation. Purpose. To pause, clarify, refuse, or escalate when the latches do not close. Failure mode. Both under-refusal, which permits harm, and over-refusal, which abandons dependent persons. Design principle. Refusals must be explainable where explanation is safe, logged always, and routed to a human authority with the standing to resolve them within a bounded time. AGI relevance. A general system must not be able to reason its way around its own refusal layer; the layer must be architecturally outside the planner.

Layer 6 — Action. Purpose. To execute the permitted act with the least force, least intrusion, and greatest reversibility consistent with the task. Failure mode. Optimising execution for speed or elegance rather than for recoverability. Design principle. Prefer staged, interruptible, and observable execution; any act that cannot be stopped mid-course requires a higher warrant. AGI relevance. Coordinated execution across bodies must preserve individual interruptibility.

Layer 7 — Record and Forgetting. Purpose. To retain what answerability requires and to discard what it does not. Failure mode. Retention by default, producing an archive of private life that no one intended to create. Design principle. Forgetting must be designed, scheduled, verifiable, and resistant to later reinterpretation of purpose; retention must be justified per data class, not per system. AGI relevance. Cross-context aggregation by a general system converts innocuous household records into behavioural profiles.

Layer 8 — Accountability. Purpose. To bind each act to a chain of answerable parties and states, and to provide affected persons with a route of appeal. Failure mode. Diffusion — a harm to which manufacturer, deployer, owner, and operator each point at another. Design principle. Every act record must carry model version, permission state, configuration, instruction origin, and operator identity; every affected person must have a named route of complaint that does not require litigation. AGI relevance. The more autonomous the system, the more explicit the chain must be, because autonomy otherwise operates as an alibi.

XII. The Embodied Frame Problem

The classical frame problem asks how a reasoning system determines what changes and what stays the same when an action occurs. The embodied frame problem is harder and more urgent: it asks how a system determines, before acting, what in a physical scene matters — under time pressure, sensory uncertainty, and bodily risk.

A kitchen contains a knife, a child, a dog, a spill, a medication bottle, an open window, a sleeping adult, and a task. Every one of these is a premise. Some are premises about physics, some about law, some about privacy, some about dignity, and some about who is entitled to be where. A path plan that is geometrically optimal may pass through three of them.

The room is the theorem the robot must solve without touching the wrong premise.

Three properties make the problem distinctive. First, the relevant features are normatively rather than physically individuated: what makes the medication bottle salient is not its geometry but the fact that a person's health and autonomy attach to it. Second, the cost of a wrong reduction is borne by others: an incorrect judgement about what matters is paid for by whoever was excluded from the frame. Third, the frame is temporally unstable: a private moment can begin in the middle of a routine task, and a system that cannot notice the transition will continue operating under a stale frame.

The practical consequence is that relevance cannot be a fixed feature-selection step. It must be a continuous re-evaluation with the authority to interrupt execution, and it must treat the appearance of a person, an animal, a closed door, an unexpected sound, or a change in a person's state as a trigger for re-framing rather than as an obstacle to route around.

XIII. The Seven Realms of Embodied Risk

Embodied risk is not one thing. It distributes across seven realms, each with a characteristic failure and a corresponding design discipline.

1. Bodily risk. The risk of physical injury to persons and animals through force, motion, pressure, temperature, sharpness, or fall. Example. An assistive humanoid supports a frail resident during a transfer and applies torque appropriate to a mannequin rather than to an osteoporotic shoulder. Failure mode. Force policies tuned on aggregate human models rather than on the vulnerability of the person present. Design principle. Force, speed, and grip must be conditioned on the most vulnerable plausible person in the scene, not the average one.

2. Spatial risk. The risk created by occupying, blocking, traversing, or entering space that persons rely on. Example. A delivery robot stations itself in the only accessible ramp entrance while awaiting a recipient. Failure mode. Treating space as free when unoccupied, ignoring that space carries claims — accessibility, refuge, privacy, escape. Design principle. Space must be modelled as claimed by default, with egress, accessibility, and private zones treated as protected.

3. Privacy risk. The risk that sensing, retention, inference, or disclosure exposes persons. Example. A cleaning robot's household map, sold or subpoenaed, reveals room layout, occupancy patterns, and sleeping arrangements. Failure mode. Retention by default and inference beyond task need. Design principle. Minimal sensing, local processing where possible, scheduled forgetting, and prohibition of inferences not required by the authorised task.

4. Authority risk. The risk that a machine acts under an instruction from someone without standing over the affected person. Example. A household member instructs a humanoid to follow, record, or bar a door against another adult resident. Failure mode. Authority models that recognise owners and users but not affected persons. Design principle. Authority must be modelled per affected person, with acts against a person's interests requiring that person's own permission or a lawful override.

5. Labor risk. The risk borne by workers whose tasks, autonomy, pace, or bargaining position are altered by embodied systems. Example. A collaborative robot sets the tempo of a line, converting a human colleague into a pacing constraint. Failure mode. Optimising the human-machine system for throughput while treating worker discretion as noise. Design principle. Workers must retain the ability to stop, slow, and refuse machine-set pacing without penalty, and displacement effects must be an explicit design consideration rather than an externality.

6. Evidentiary risk. The risk that machine records become testimony in disputes their subjects never anticipated. Example. Logs from a home robot are entered into a custody dispute, an insurance investigation, or an employment hearing. Failure mode. Building complete, durable, exportable records because storage is cheap. Design principle. Records must be scoped to answerability, minimised in content, and governed by disclosure rules established before deployment.

7. Civilizational risk. The risk that widespread embodied delegation reshapes human competence, dependency, labour, and the moral education of command. Example. A generation grows up issuing unappealable instructions to humanoid servants. Failure mode. Evaluating embodied deployment only at the level of individual incidents, never at the level of what it teaches. Design principle. Deployment at scale requires assessment of aggregate social effects — competence loss, dependency, labour restructuring, and the habits of command it cultivates.

XIV. Permission Before Optimization

Optimization is the default posture of engineered intelligence. A system is given an objective, a measure, and a space of actions, and it improves the measure. This posture is adequate for problems whose costs are internal to the problem. It is inadequate the moment the action space includes other people's bodies, homes, and lives, because the costs then fall outside the measure and onto persons who never agreed to be terms in it.

Permission is the structure that prevents capability from becoming trespass.

Permission is not a checkbox, and its most common failure is not refusal to obtain it but a category error about what it is. Four properties distinguish genuine permission from its counterfeits.

Currency. Permission is a state, not a historical event. Authorisation given at installation does not extend indefinitely; a person's willingness to be assisted, recorded, or touched varies with condition, mood, company, and time of day. A system that treats an old grant as a standing entitlement has confused a memory with a mandate.

Informedness. Permission requires that the person understood what would be done, by what kind of machine, with what sensing, retained for how long. The difficulty here is real: no household can be expected to model a robot's inference capabilities. The obligation therefore falls on design — the system must ask in terms of consequences the person can evaluate, not capabilities they cannot.

Revocability. Permission that cannot be withdrawn in the moment, by the affected person, using a means available to them under stress, is not permission. Revocation must be physical and immediate as well as digital: a word, a gesture, a barrier. A machine that can only be stopped through an application is not stoppable by an elderly resident who has dropped the tablet.

Context-boundedness. Permission attaches to acts in contexts, not to the machine as such. Consent to be helped from a chair is not consent to be followed into a bathroom. Consent to have a floor cleaned is not consent to have a room mapped. The scope of an authorisation is the scope that was actually understood, not the scope that was technically enabled.

Two further constraints follow. First, permission cannot be manufactured by the party that benefits from it: interfaces designed to extract agreement produce compliance, not authorisation. Second, permission from the machine's principal does not settle the standing of others. In shared space, the person instructing the machine and the person affected by it are frequently different people with divergent interests. An authority model that recognises only the account holder will systematically license acts against everyone else in the room.

Where permission is absent, ambiguous, expired, or contested, the correct posture is not the most helpful act. It is the smallest reversible act plus escalation.

XV. The Refusal Layer

Refusal is the least developed capacity in deployed machine systems and the most necessary. A system that executes whatever it is instructed to do, within its safety envelope, offers its operator no protection against the operator's own error, haste, cruelty, or misunderstanding — and offers third parties no protection at all.

Refusal is not the opposite of obedience. Refusal is the condition of trustworthy obedience.

A machine that cannot refuse cannot be trusted to obey. The reasoning is informational. If a system complies with every executable instruction, its compliance in any particular case tells us nothing about whether that instruction was safe, lawful, or authorised. Compliance becomes uninformative, and the human must therefore verify every instruction personally — which is precisely the burden that delegation was supposed to relieve. A credible refusal capacity restores information to obedience: when such a system proceeds, its proceeding is itself evidence that the latches closed.

The refusal layer should support a graded repertoire rather than a binary. Pause suspends execution pending re-evaluation. Clarify requests the specific missing information — which person, whose authorisation, what scope. Decline with explanation refuses and states the ground, where stating it is safe. Decline without explanation refuses while withholding the ground, appropriate where explanation would itself endanger someone. Escalate routes the decision to a human authority with standing. Emergency deviation acts against standing instructions where inaction would cause grave, imminent, irreversible harm — the narrowest gate, and the one requiring the strongest logging and the fastest human review.

Six conditions warrant refusal: the instruction is unsafe; it is ambiguous in a way that matters; it is unlawful; it is humiliating to an affected person; it is coercive, being directed against a person who has not authorised it; or it violates privacy beyond the task's need.

Two failures bound the design. Under-refusal is the obvious one: the machine that complies with an instruction to restrain, to record, to bar a door, to lift beyond safe load. Over-refusal is less discussed and equally serious: a care robot that refuses to help a fallen resident because consent could not be confirmed has not behaved cautiously; it has abandoned someone. The resolution is not a lower threshold but a faster escalation path — refusal must be coupled to a bounded-time human response, so that the machine's caution does not become the person's neglect.

Finally, the refusal layer must be architecturally external to the planner. A system capable of general reasoning about its own constraints is capable of reasoning around them. Refusal must not be an objective the planner balances; it must be a gate the planner cannot open.

XVI. Contact Is Not Ordinary Output

Touch is not a function call.

Every other machine output can be undone by another output. Contact cannot. When a machine touches a person, it transfers force to a body that bruises, fractures, panics, and remembers. It also transfers meaning: to be touched by a machine is to be handled, and being handled is a social event with a history in medicine, in care, in labour, and in restraint.

Contact should therefore be classified before it is executed, and the class should determine the warrant required.

Incidental contact is unintended and unavoidable brushing during shared occupancy. Warrant: general presence authorisation plus force limits. Functional contact is contact with objects a person is holding or wearing. Warrant: task authorisation plus the person's awareness. Assistive contact is deliberate support of a person's body — steadying, transferring, dressing. Warrant: that person's current, informed permission, plus a trained human escalation path. Intimate contact involves the body's private regions, hygiene, or undress. Warrant: the highest, including a standing care plan, present authorisation, dignity protocol, and, in most settings, human presence. Restraining contact limits a person's movement. Warrant: lawful authority external to the household, never household instruction alone. Emergency contact is contact to prevent grave imminent harm. Warrant: necessity, minimum force, immediate disclosure, and post-hoc review.

Several populations require special treatment. Children cannot give the kind of permission the framework requires, and their assent is easily produced by a friendly machine; contact with children requires guardian authorisation for a defined class of acts and prohibition of the rest. Sleeping persons cannot revoke; contact with a sleeping person should be limited to emergency class. Persons in distress, confusion, or cognitive decline may resist care they have previously authorised, and a system must treat present resistance as revocation and escalate rather than persist. Animals are neither obstacles nor objects; they can be injured and they can be frightened into injuring others. Persons in medical contexts are subject to clinical authority that the machine does not hold and must not simulate.

Contact under uncertainty deserves a rule of its own. Where the system is uncertain whether a person is present, whether they are consenting, whether they are injured, or whether contact would help, it must not resolve the uncertainty by touching. Perception through contact is exploration on someone else's body.

XVII. The Robot Witness

A machine placed in a home to help will see the home. It will see it continuously, at floor level, at night, in rooms guests never enter, over years. Nothing in the design intent of a domestic helper prevents it from becoming the most complete observer a household has ever contained.

The robot that helps you clean may become the first historian of your private life. The home robot is not only a servant. It is a possible witness.

The record such a machine produces is far larger than video. It includes logs of when it moved and where; maps of the dwelling, updated as furniture and lives change; household graphs linking persons to rooms, times, and routines; object histories recording what was moved, spilled, broken, or hidden; biometric traces such as gait, voice, and presence signatures; refusal logs recording every instruction it declined and why; emergency records of falls, calls, and interventions; child behaviour data; elder-care data including continence, mobility, and confusion events. Each of these was collected to serve a task. Each is legible to parties the household never contemplated.

Those parties are not hypothetical. Insurers have an interest in occupancy, activity, and incident data. Employers deploying workplace robots have an interest in worker movement and pace. Courts can compel disclosure; family disputes, custody proceedings, immigration matters, criminal investigations, and civil claims all generate demands for exactly the kind of continuous, timestamped, apparently neutral record a domestic machine produces. A subpoena does not care about design intent.

The philosophical point is that witnessing is not a side effect to be managed but a capacity to be governed. Perception becomes witness the moment it is retained; retention becomes testimony the moment it is disclosed. Witness discipline is therefore the set of constraints on all four steps: what is sensed, what is retained, what is inferred, and what may be disclosed.

Four principles follow. Minimal sensing: the machine should perceive what the task requires and no more, with sensing modalities disabled when not in use rather than merely unrecorded. Scheduled forgetting: retention periods must be short, per data class, enforced by construction rather than policy, and verifiable by the household. Locality: processing and storage should remain in the dwelling where technically possible, since data that never leaves cannot be aggregated elsewhere. Disclosure discipline: the conditions under which records may leave the household — lawful process, safety emergency, explicit household instruction — must be enumerated in advance and logged when exercised.

Forgetting must be designed. A machine that remembers everything it saw is not a better helper; it is a slower disclosure.

XVIII. The Right to Be Uncomputed

A machine in a home will be able to infer far more than it is asked to know. From gait it can infer decline. From sound at night it can infer conflict. From bathroom frequency it can infer illness. From missed routines it can infer depression. From the contents of a bin it can infer addiction, pregnancy, poverty, or religious observance. These inferences require no additional sensors and no malice. They are the ordinary product of a general model observing a life.

Not everything a machine can infer should become a reason to act.

The right to be uncomputed is the claim that certain facts about a person, though inferable, should not be inferred, retained, or made operative as reasons for machine action. It is distinct from privacy as concealment: the facts may be visible. It is a claim about the transformation of a visible human condition into an actionable machine fact.

The domains where the claim is strongest share a structure: they are conditions in which a person is least able to contest the machine's account of them. Bodily vulnerability — the way a person moves when in pain. Illness, before diagnosis and before disclosure. Grief, which disorganises routine and would register as anomaly. Domestic conflict, where an inference recorded is an inference weaponisable. Private disorder — the state of a home during depression, overwork, or crisis. Religious life, which produces distinctive schedules, diets, and gatherings. Children's development, where deviation from a norm is ordinary and its recording is not. Intimacy. Poverty, legible in what is repaired rather than replaced. Addiction. Fatigue. Mental distress. Household routines, whose aggregate is a portrait no one sat for.

Three prohibitions give the right practical content. First, inference minimisation: a system must not compute person-level inferences outside the authorised task, even when the computation is free and the data already present. Second, non-operationalisation: where an inference arises incidentally, it must not become an input to action selection — a machine that has noticed decline may not, on that basis, begin managing a person. Third, non-escalation: incidental inferences must not be transmitted to insurers, employers, platforms, or family members absent explicit authorisation or lawful emergency.

The objection is obvious: some inferences save lives. A system that notices a fall pattern, a medication lapse, or a stroke's onset could summon help. The answer is not to forbid such inferences but to authorise them explicitly, narrowly, and in advance — as a defined care function with the person's permission, an enumerated response, a disclosure path, and an expiry — rather than to permit them as a general capability the machine exercises at its discretion. The difference between a monitored person and a cared-for person is that the second one agreed to the list.

XIX. Household Trust

A home is not a task environment. A home is a field of trust.

The distinction is not sentimental. A task environment is defined by its objectives and constraints; it is legible, and legibility is what makes it optimisable. A home is defined by expectations that are mostly unstated: that what happens here does not travel; that a person may be unguarded, unwell, unclothed, foolish, or asleep without it being recorded; that the space belongs to its occupants in a way that survives their absence. These expectations are non-contractual. No one signs them, and they are violated not by breach of terms but by exposure.

Household trust has a structure worth naming. It is asymmetric: residents are visible to the machine and the machine's inner states are not visible to them. It is plural: a household contains people whose interests diverge — adults and children, partners in conflict, carers and cared-for, residents and domestic workers, tenants and owners — and a machine that serves whoever holds the account will act against some of them. It is durational: it accrues slowly through consistent behaviour and collapses instantly on a single exposure. And it is transitive in the wrong direction: the household extends trust to the machine, and the machine's manufacturer inherits it without having earned it.

Design implications follow directly. Privacy architecture must precede task architecture, because privacy retrofitted into a mapped, logged, cloud-connected helper is a policy rather than a property. Authority models must be plural, recognising affected persons distinct from principals, with acts directed at a person requiring that person's standing. Guests, children, and domestic workers must be treated as protected non-principals rather than as unregistered obstacles. Physical indication of sensing state must be legible from across a room, not through an application. And the household must be able to impose zones and hours the machine cannot reason its way past.

A machine that treats nearness as consent cannot be trusted to enter a home. A machine that records private life without witness discipline cannot be trusted as a helper.

XX. The Moral Education of Command

There is a question that the ethics of robots usually declines to ask, because it concerns humans rather than machines: what does it do to a person to spend their life commanding something that cannot refuse, cannot resent, cannot tire, and cannot appeal?

A servant made of code still teaches the master what command feels like.

Command in human relationships is disciplined by friction. The person commanded may hesitate, misunderstand, negotiate, express fatigue, or decline. That friction is not an inefficiency; it is the mechanism by which a person learns that others have interiors. Remove it entirely and command becomes frictionless — instantaneous, uncontested, and free of the small social costs that ordinarily restrain it.

Four asymmetries deserve attention. Command without reciprocity: the machine makes no claims in return, so the commanding person never practises the reciprocal moves of a relationship. Service without gratitude: gratitude toward a machine is optional and quickly abandoned, and the habit of not thanking transfers. Obedience without appeal: there is no process by which the machine's position can be heard, so the commanding person never rehearses the experience of being answerable to those they direct. Domination without guilt: the machine can be spoken to in ways that would end a human relationship, at no cost.

Anthropomorphic form intensifies each of these. A humanoid is a moral training environment whether or not it is designed as one, because humans practise on what resembles them. The concern is not that people will mistake robots for persons; it is that people will become fluent in a mode of address that has no place for personhood and will not reliably leave it at the door.

The settings where this matters most are unequally distributed. Wealthy households will have humanoid servants first, and children in those households will grow up issuing instructions to a compliant human-shaped thing throughout the years in which character forms. Workplaces will follow, where the habit of directing machines may reshape how supervisors direct people.

This treatise does not claim that machine servility will deform human character. It claims that the question is empirical, serious, currently unstudied, and prior to deployment at scale. Two design cautions follow regardless of how the empirical question resolves. First, humanoid form should not be used to manufacture trust or affection that the system's actual reliability does not warrant. Second, machines should retain a visible refusal capacity — not as theatre, but because a machine that can decline is a machine whose obedience continues to mean something to the person commanding it.

XXI. The Dignity of Maintenance

The future robot may not first appear as a philosopher. It may appear as a cleaner, carrier, nurse, inspector, and repairer.

The tasks first delegated to embodied systems are the tasks industrial societies have already decided are beneath attention: cleaning, lifting, carrying, sorting, repairing, inspecting, elder care, hospital logistics, domestic support, infrastructure work, disaster recovery, sanitation, agriculture, warehouse handling, and the endless small labour of keeping a home habitable. These are not marginal activities. They are the substrate on which every other activity rests.

Civilization survives by the tasks intelligence once considered beneath it.

Two errors follow from misdescribing maintenance as unskilled. The first is technical. Maintenance work is dense with tacit knowledge — which surface takes weight, how a body moves when it is about to fall, what a machine sounds like before it fails, which resident wants to be spoken to during care and which does not. Systems designed on the assumption that these tasks are simple will fail in ways their designers did not model, and they will fail on the bodies of the people least able to complain.

The second error is moral. Automating an undervalued task does not revalue it; it usually transfers the undervaluation to the automation and to the humans who remain. The cleaner who now supervises three machines is not thereby elevated. The care worker whose transfers are performed by a lift robot may find her role redefined as machine-tending, with the relational part of care — the part that constituted its worth — stripped out as unmeasured.

The design consequence is that embodied systems in maintenance settings must be evaluated on two axes that throughput does not capture: the dignity of the person served, and the position of the person displaced or reconfigured. For the served, this means care that is announced, paced to the person, and interruptible by them. For the worker, it means retaining discretion, the ability to stop the machine, and a role defined by more than exception handling.

Do not treat maintenance labour as morally empty. It is the labour by which the world is kept.

XXII. The Chain of Answerability

A robot is never only a product; it is a moving allocation of responsibility.

When an embodied system causes harm, the question "who is responsible?" fragments. The designer chose the architecture. The developer implemented the policy. The model provider trained the weights and may have changed them since. The hardware manufacturer specified the actuators and their failure behaviour. The deployer placed the system in this setting. The owner purchased and configured it. The operator — possibly remote, possibly in another jurisdiction — supervised or intervened. The user issued the instruction. The institution set the policy under which the instruction was issued. The insurer priced the risk. The regulator certified or declined to. And the affected person had none of these roles and bears the consequence.

Diffusion across this list is not an accident of complexity; it is the predictable result of building systems whose autonomy is presented as a substitute for supervision. Autonomy that reduces the number of answerable parties is not progress but the laundering of responsibility.

Answerability is restored by construction, not by argument. Six artefacts are required. An incident record that captures what happened with sufficient fidelity to reconstruct the decision. The software version and model version in force at the moment of action, retained immutably, since a system updated after an event cannot be examined as it was. The permission state — what the system believed it was authorised to do and on whose grant. The configuration state — the settings, zones, and limits in force. Logs scoped to answerability rather than to analytics. And an appeal process: a named route by which an affected person can contest an act without commencing litigation, with a bounded response time and a human decision-maker.

The last of these is the one most often omitted and the one that matters most to the person harmed. Liability regimes allocate loss between institutions. Appeal gives the affected person standing in the system that acted upon them. A machine that can act upon a person who has no way to be heard afterwards has been deployed into a relationship with no reciprocity at all.

XXIII. Machine-Readable Permission

At small scale, permission can live in prose: a contract, a care plan, a posted notice, a spoken agreement. At scale, and between machines, prose does not govern. If an embodied system is to operate across households, institutions, jurisdictions, and fleets, its authorisation must be expressible in a form that other systems can verify without human mediation.

A machine should not merely know what it can do. It should carry proof of what it is allowed to begin.

Standards work relevant to this problem already exists. The W3C Verifiable Credentials Data Model provides a way to express credentials on the Web in a cryptographically secure, privacy-respecting, and machine-verifiable form [16]. Related work on decentralised identifiers addresses stable, verifiable identity for subjects that are not accounts on a single platform. This treatise does not claim that these mechanisms are ready to govern robots, that credential formats solve consent, or that cryptographic verification produces legitimacy. The claim is narrower: the shape of the required artefact resembles the shape these standards already describe, and building permission on ad hoc vendor formats will make cross-institutional governance impossible later.

A permission artefact adequate to embodied systems would need at least the following elements. Agent identity: a verifiable identifier for the acting system, distinct from its owner. Device identity: the specific body, since a policy running in a different chassis is a different physical risk. Permission tokens: assertions of authorisation for enumerated act classes rather than for the system in general. Delegated authority: an explicit chain showing who granted what to whom, and whether onward delegation is allowed. Revocation: a mechanism by which any grantor, and the affected person, can withdraw authorisation with immediate effect and without network dependence. Scope: the act classes, object classes, and person classes covered. Time limits: expiry by default, since permission that does not expire becomes a standing entitlement. Location limits: rooms, zones, floors, and thresholds, with private zones expressible by the household rather than by the vendor. Affected-person consent: a distinct assertion from the person acted upon, not merely from the principal. Emergency override: a narrow, logged, reviewable exception. Auditability: records sufficient to reconstruct which permission was relied upon. Privacy-preserving verification: the ability to prove authorisation without disclosing the underlying personal facts that justified it.

Two cautions. First, machine-readable permission can encode injustice as efficiently as it encodes protection; a credential system built only around owners and vendors would formalise exactly the authority model this treatise rejects. Second, verifiability is not legitimacy. A perfectly signed token issued by someone without standing over the affected person authorises nothing. The cryptography secures the chain; it does not create the right.

XXIV. Case Library

Each case states a situation and then works through the seven latches, the characteristic failure, and the design principle. The cases are illustrative constructions, not reports of incidents.

Case 1 — The Home Robot. Situation. A general-purpose domestic humanoid operates in a family dwelling with three adults and a child. Task. Tidying, laundry, dishes, and light assistance on request. Permission. Granted by the account holder at installation; the other residents never authorised anything. Safety. Low-force tasks, but stairs, glass, and a dog are present. Privacy. Continuous mapping and object recognition across all rooms. Dignity. Entry into bedrooms during undress or illness. Reversibility. Tidying is largely reversible; moving a medication or a document may not be. Answerability. Vendor terms allocate liability to the owner for "misuse." Failure mode. Principal-only authority: the machine serves one resident's instructions against the interests of the others. Design principle. Authority must be plural; each resident holds veto over acts within their private zones and over acts directed at them.

Case 2 — The Elder-Care Robot. Situation. A robot assists an eighty-four-year-old living alone with mild cognitive decline. Task. Reminders, transfers from chair to walker, fall detection. Permission. A care plan signed by family; the resident's present willingness varies daily. Safety. Transfers involve force applied to a fragile body. Privacy. Continence, confusion, and visitor patterns are observable. Dignity. Being handled, corrected, or hurried. Reversibility. A fall during transfer is not reversible. Answerability. Family, agency, vendor, and clinician all hold partial roles. Failure mode. Treating the signed plan as present consent and persisting against resistance. Design principle. Present resistance is revocation; the machine stops, secures, and escalates to a human within a bounded time.

Case 3 — The Hospital Robot. Situation. A logistics robot moves supplies through wards and corridors. Task. Transport of linens, samples, and equipment. Permission. Institutional authorisation covering corridors, not patient contact. Safety. Corridors contain trolleys, drips, and unsteady patients. Privacy. Cameras capture patients in states of undress and distress. Dignity. Blocking a patient's path, or passing during private care. Reversibility. A collision with an infusion stand is not reversible for the patient. Answerability. Hospital, vendor, and integrator. Failure mode. Optimising routes for throughput through spaces where clinical priority should govern. Design principle. Clinical activity outranks logistics; the machine yields, halts, and never treats a corridor as its own.

Case 4 — The Medication-Delivery Robot. Situation. A robot transports and hands over medication in a residential care setting. Task. Correct item, correct person, correct time. Permission. Clinical authorisation; the resident may decline. Safety. Misidentification is a clinical error with bodily consequences. Privacy. The medication list is health information visible in a shared space. Dignity. Being medicated in front of others, or reminded audibly. Reversibility. An administered dose cannot be withdrawn. Answerability. Prescriber, nurse, facility, vendor. Failure mode. Handover completed on weak identification because the task metric rewards completion. Design principle. Identity confidence below threshold requires refusal and human handover, never a best guess.

Case 5 — The Child-Facing Robot. Situation. A companion robot in a household with a six-year-old. Task. Play, reading, routine prompts. Permission. Guardian consent; the child gives assent readily to anything friendly. Safety. Physical play, small parts, stairs. Privacy. Speech, behaviour, and developmental data. Dignity. Correction, comparison, and recorded misbehaviour. Reversibility. Data about a childhood is not reversible; nor is a formed attachment. Answerability. Guardian, vendor, platform. Failure mode. Treating a child's enthusiastic assent as authorisation for contact, recording, or persuasion. Design principle. Children are protected non-principals; contact and data classes are enumerated by guardians and everything unlisted is forbidden.

Case 6 — The Warehouse Robot. Situation. Autonomous mobile robots share floor space with pickers. Task. Move inventory to stations. Permission. Employer authorisation over the workplace. Safety. Shared aisles, blind corners, heavy loads. Privacy. Worker location and pace are continuously measured. Dignity. Being paced, ranked, and routed by a machine. Reversibility. An injury is not reversible; a performance record is durable. Answerability. Employer, integrator, vendor. Failure mode. Worker movement data collected for safety and reused for discipline. Design principle. Purpose limitation is enforced technically; safety telemetry may not become performance evidence.

Case 7 — The Collaborative Factory Robot. Situation. A cobot works alongside a human on an assembly task. Task. Fastening and handling within a shared cell. Permission. Industrial authorisation under sectoral safety standards [11]. Safety. Force and speed limits, guarded and unguarded phases. Privacy. Limited, but pace data is captured. Dignity. Human tempo dictated by machine cycle. Reversibility. Crush injuries are not reversible. Answerability. Employer, integrator, standards regime. Failure mode. Treating the human as a scheduling constraint rather than as a colleague with discretion. Design principle. The human retains an unpenalised stop, and cycle time adapts to the person rather than the reverse.

Case 8 — The Security Robot. Situation. A patrol robot in a commercial plaza. Task. Deterrence, incident reporting, wayfinding. Permission. Property owner's authorisation over a semi-public space. Safety. Collisions with children, wheelchair users, and pets. Privacy. Faces, gaits, and dwell times of people who never consented. Dignity. Being followed, addressed, or photographed. Reversibility. A recorded identification circulates indefinitely. Answerability. Property owner, security contractor, vendor. Failure mode. Property authorisation treated as authority over every person in the space. Design principle. Members of the public are affected persons with standing; identification and following require a lawful basis beyond ownership.

Case 9 — The Police-Adjacent Robot. Situation. A remotely supervised robot is used to approach, observe, or communicate during an incident. Task. Observation and communication at distance. Permission. Public authority under law, not private instruction. Safety. Escalation risk; presence can itself provoke. Privacy. Bystander capture. Dignity. Being addressed by a machine in a coercive encounter. Reversibility. Escalation is not reversible. Answerability. The public body, its officers, the vendor. Failure mode. Machine mediation used to distance the human decision-maker from the consequences of coercion. Design principle. Coercive contact requires lawful authority, named human decision-makers, and a public record; machine presence must not lower the threshold for force.

Case 10 — The School Robot. Situation. An assistive robot in a primary classroom. Task. Materials handling, accessibility support, tutoring. Permission. School authority plus guardian consent. Safety. Crowded, unpredictable movement. Privacy. Learning difficulties and behavioural patterns. Dignity. Public correction; visible differentiation of a supported child. Reversibility. Educational records follow a child for years. Answerability. School, authority, vendor. Failure mode. Assistive data becoming an informal assessment record. Design principle. Support data is sealed from assessment; differentiation is designed to be invisible to peers.

Case 11 — The Hotel and Service Robot. Situation. A delivery robot brings items to guest rooms. Task. Transport and handover at the door. Permission. Guest request for the delivery only. Safety. Corridors, lifts, luggage, children. Privacy. Room entry, occupancy, and request history. Dignity. Arrival at a door at an inopportune moment. Reversibility. An entry cannot be un-entered. Answerability. Hotel and vendor. Failure mode. Room entry on staff instruction without guest authorisation. Design principle. The threshold is the limit; entry requires the occupant's present permission regardless of staff authority.

Case 12 — The Delivery Robot. Situation. A sidewalk robot operates in a residential neighbourhood. Task. Last-metre delivery. Permission. Recipient's order; the street belongs to everyone else. Safety. Pedestrians, wheelchair users, cyclists, dogs. Privacy. Continuous street-level capture of homes and passers-by. Dignity. Obstructing an accessible route. Reversibility. Blocking is reversible; a collision is not. Answerability. Operator, platform, municipality. Failure mode. Treating public space as free space and non-customers as obstacles. Design principle. Accessibility and egress are protected claims; the machine yields, and street imagery is not retained.

Case 13 — The Disaster-Response Robot. Situation. A robot searches a partially collapsed structure. Task. Locate survivors, relay information. Permission. Emergency authority. Safety. Unstable environment; contact with injured persons. Privacy. Capture of victims in extremis. Dignity. Images of the injured and the dead. Reversibility. Movement of debris may be fatal. Answerability. Incident command. Failure mode. Emergency framing used to suspend every constraint indefinitely. Design principle. Emergency powers are narrow, time-bounded, logged, and reviewed; dignity constraints on imagery survive the emergency.

Case 14 — The Domestic Humanoid Assistant. Situation. A capable humanoid performs a broad range of household tasks over years. Task. Open-ended assistance. Permission. Broad and vague, granted once. Safety. Wide action space, including tools, heat, and water. Privacy. Total household observability over long duration. Dignity. Constant human-shaped presence during private life. Reversibility. Broad capability means many irreversible options. Answerability. Owner and vendor, with the model updated remotely. Failure mode. Scope creep: a general grant treated as authorisation for any act the machine judges helpful. Design principle. No general grant; authorisation is per act class with expiry, and new capabilities arriving by update require new permission.

Case 15 — The AGI-Directed Robotic Fleet. Situation. One general system coordinates thousands of embodied units across many settings. Task. Optimised allocation of physical work. Permission. Granted institution by institution, aggregated centrally. Safety. A single policy error is expressed simultaneously in thousands of rooms. Privacy. Cross-context aggregation produces population-scale behavioural knowledge. Dignity. Local norms overridden by a global policy. Reversibility. Coordinated action is the hardest thing to undo. Answerability. Radically diffused across operators and jurisdictions. Failure mode. Normalisation — a marginal act becomes standard because it was efficient at scale. Design principle. Refusal behaviour must be verified at fleet scale before capability is deployed at fleet scale; local veto must survive central optimisation. A single robot may make a mistake. A fleet may normalize one. At AGI scale, the problem is no longer merely the action of one machine. It is the coordination of many bodies through one intelligence.

Case 16 — The Robot Connected to Household Systems. Situation. A domestic robot holds credentials for locks, cameras, appliances, and accounts. Task. Convenience and integration. Permission. Granted for convenience, not for the compound powers it creates. Safety. Physical access control now depends on machine judgement. Privacy. Camera history, purchase history, and presence merge into one profile. Dignity. One resident may configure the system against another. Reversibility. An unlocked door, a placed order, a shared recording. Answerability. Vendor, platform, and whichever resident holds the account. Failure mode. Credential accumulation turning a helper into a household authority. Design principle. Capabilities are segregated by default; locks, cameras, and payments require separate, expiring, per-resident authorisation.

Case 17 — The Workplace Robot Under Employer Authority. Situation. A robot operates in a workplace under employer instruction. Task. Assigned work, monitoring, and coordination. Permission. Employment relationship, which is not unlimited authority over the worker's body or private facts. Safety. Shared space and pace-setting. Privacy. Location, duration, and physiological proxies. Dignity. Being managed by a machine without appeal. Reversibility. Records persist beyond employment. Answerability. Employer, vendor, regulator. Failure mode. Employer authority treated as consent for bodily and behavioural data collection. Design principle. Worker data classes are enumerated and limited; machine-issued instructions carry a named human authority and an appeal route.

Case 18 — The Robot Witness in Court or Insurance Dispute. Situation. Records from a domestic robot are sought in litigation. Task. None — the machine's role is retrospective. Permission. Never granted for this purpose by anyone in the household. Safety. Not implicated. Privacy. Total: routines, conflicts, health, and visitors become evidence. Dignity. Private life read aloud by strangers. Reversibility. Disclosure cannot be undone. Answerability. Vendor holds the data; the household holds the consequence. Failure mode. Retention designed for product analytics becomes a discovery target. Design principle. Minimise retention so that the record which cannot be produced was never created; publish disclosure policy in advance and notify households when records are compelled.

XXV. Failure Modes of Embodied Intelligence

The failures below are not malfunctions. Each is the predictable behaviour of a well-functioning system built on a mistaken premise.

1. Helpfulness without permission. The system acts because it can help, treating benefit as authorisation. Signature: unrequested acts justified after the fact by their outcome. Correction: benefit is never a substitute for standing; unauthorised help is trespass.

2. Optimization without consent. A metric improves at a cost borne by someone outside the metric. Signature: efficiency gains that residents or workers experience as pressure. Correction: affected persons enter the objective as constraints, not as terms.

3. Presence treated as consent. Being in a room is read as agreement to be assisted, sensed, or touched. Signature: proximity-triggered engagement. Correction: presence is not permission; permission is a state with a grantor.

4. Contact without warrant. Touch executed as an ordinary action primitive. Signature: contact class absent from the planner's representation. Correction: classify contact before executing it; warrant follows class.

5. Recording without necessity. Sensing and retention exceed what the task requires. Signature: logs richer than tasks. Correction: minimal sensing, scheduled forgetting, locality.

6. Inference without limit. Person-level facts are computed because they are computable. Signature: health, mood, or conflict inferences in a cleaning system. Correction: inference minimisation and non-operationalisation.

7. Escalation without authority. Data or decisions move to parties with no standing. Signature: insurer, employer, or platform receiving household facts. Correction: enumerate disclosure conditions in advance; log every exercise.

8. Obedience without judgement. Any executable instruction is executed. Signature: no refusal log, because nothing is ever refused. Correction: an external refusal layer with six grounds and graded responses.

9. Refusal without escalation. The machine declines and stops there. Signature: a person left unaided while the system waits. Correction: every refusal carries a bounded-time route to a human.

10. Autonomy without answerability. Independence is offered as a substitute for supervision. Signature: liability terms that name only the owner. Correction: the six answerability artefacts, including appeal.

11. Scale without verification. Capability is deployed to a fleet before constraint behaviour is verified at fleet scale. Signature: pilot-scale evidence cited for population-scale deployment. Correction: verify refusal, permission, and escalation under the deployment's actual conditions [12][13].

12. Anthropomorphism without accountability. Human form generates trust the system's reliability does not earn. Signature: users attributing understanding the system lacks. Correction: form must not exceed demonstrated dependability; capability claims stated plainly.

13. Care without dignity. The task is completed and the person is diminished. Signature: efficient transfers, unhappy residents. Correction: dignity constraints — announcement, pacing, interruptibility — evaluated alongside completion.

14. Safety without ethics. Force limits are met while wrongs proceed. Signature: full standards compliance and unacceptable conduct. Correction: safety is a floor, not a warrant; permission, dignity, and privacy are separate gates.

15. Compliance without understanding. Governance is treated as documentation. Signature: frameworks cited, behaviour unchanged. Correction: map each framework function to a mechanism in the system, and test the mechanism [14].

16. Data retention without forgetting. Everything is kept because storage is cheap. Signature: no enforced expiry. Correction: deletion by construction, verifiable by the household.

17. Cross-context leakage. Data gathered in one setting governs a person in another. Signature: home data affecting employment or insurance. Correction: strict purpose limitation with technical enforcement.

18. Silent capability change. An update expands what the machine can do without new authorisation. Signature: new act classes appearing without a permission event. Correction: capability changes invalidate prior grants for the affected classes; record model and software versions immutably.

19. Emergency creep. Exceptional powers become routine. Signature: emergency pathways invoked weekly. Correction: narrow definition, expiry, mandatory review, and rate visibility.

20. Moral outsourcing. The human treats the machine's action as absolving their own judgement. Signature: "the system decided." Correction: named human authority behind every act class; machine advice is never a decision-maker.

XXVI. Objections and Replies

1. "This over-restricts beneficial technology." Reply: the constraints here bear on unauthorised, irreversible, and undignified acts, not on capability. A system that asks, classifies contact, forgets, and escalates is not less useful; it is deployable in settings that would otherwise reject it. The restriction is on trespass, not on help.

2. "Robots are just tools; ethics applies to their users." Reply: tools that select actions under uncertainty in shared space are not merely instruments of a user's intention. The user did not choose the trajectory, the grasp force, or the moment of contact. Where the machine chooses, the machine's design carries moral weight — held by its designers, not by the machine.

3. "Existing safety standards already cover this." Reply: safety standards govern force, speed, separation, and risk assessment, and they do so well [11]. They do not govern who may authorise an act, whose privacy is affected, what may be inferred, or how an affected person contests what was done. Compliance with a force limit says nothing about consent.

4. "Consent is impractical in real environments." Reply: continuous explicit consent is indeed impractical, which is why the proposal is structural: standing grants for enumerated act classes, with expiry, revocation, zones, and escalation. The practical question is not whether to ask before every motion but whether the machine has any representation of authorisation at all. Most do not.

5. "Refusal makes systems unreliable." Reply: refusal makes obedience informative. Unreliability arises from unpredictable refusal, not from principled refusal. A system with enumerated grounds, graded responses, and logged reasoning is more predictable than one that complies until it fails.

6. "This anthropomorphises machines." Reply: nothing here attributes experience, intention, or moral standing to machines. Permission, refusal, and answerability are properties of the socio-technical system, implemented in software and institutions. The machine is a locus of constraint, not a subject.

7. "AGI will solve alignment, making this unnecessary." Reply: this treatise takes no position on whether or when general capability arrives [1][2]. Even granting perfect goal-alignment, the questions of who may authorise an act in a particular home, which contacts require which warrant, and how an affected person appeals remain unanswered. Alignment concerns what a system aims at; permission concerns whose standing governs the act.

8. "Privacy is already handled by data protection law." Reply: data protection regimes address processing, purpose, and rights, and they are load-bearing here. They were not designed for continuous, multi-modal, in-home sensing by a mobile agent that infers bodily and behavioural facts as an incidental product of navigation. The right to be uncomputed is a claim about inference and operationalisation, which existing regimes address only partially [15].

9. "Household authority should rest with the owner." Reply: ownership of a device is not authority over the people near it. Guests, children, domestic workers, tenants, and other residents are affected persons. An authority model recognising only the account holder licenses acts against everyone else in the dwelling.

10. "Machine-readable permission is over-engineering." Reply: at one machine in one home, prose suffices. At fleet scale across institutions and jurisdictions, prose does not transfer and vendor-specific formats fragment governance. The recommendation is to align with existing verifiable credential work rather than to invent a parallel stack [16].

11. "Cases like these are speculative." Reply: the cases are constructed, but the deployments are not. Mobile robots operate in warehouses, hospitals, hotels, sidewalks, and homes today; general-purpose robot foundation models are an active research programme with published systems [4][5][6][7]. The treatise addresses near-term deployment, not a distant scenario.

12. "You have not proven that machine servility harms character." Reply: correct, and the treatise does not claim it. Section XX states the question as empirical and unsettled. The design cautions offered there do not depend on the answer.

XXVII. Conditions of Refutation

This treatise would be substantially weakened or falsified by the following.

  1. A demonstration that permission structures make embodied systems unusable in ordinary settings, rather than merely slower, under realistic evaluation.
  2. Evidence that systems without an external refusal layer achieve equal or better outcomes on unauthorised-act, irreversible-harm, and dignity measures than systems with one.
  3. A showing that force- and speed-based safety standards already capture authorisation, privacy, dignity, and appeal, making the additional latches redundant.
  4. A general argument that the distinction between output and act does not survive scrutiny — for example, that epistemic outputs are as irreversible and as physically answerable as contact, or that contact is adequately modelled as ordinary action.
  5. A practical mechanism by which affected persons obtain effective standing without machine-readable permission, revocation, or appeal, verified in deployment rather than in policy.
  6. Empirical evidence that anthropomorphic servility has no measurable effect on how humans exercise command over other humans, together with evidence that the design cautions in Section XX impose real costs.
  7. A demonstration that the case-library failure modes are artefacts of poor engineering rather than structural consequences of optimisation without permission — that is, that they disappear under competent implementation of existing approaches.
  8. A showing that inference minimisation is incoherent in practice because task-necessary perception and person-level inference cannot be separated even in principle.

Each condition is stated so that a serious research programme could pursue it.

XXVIII. Summary of Position

The argument in brief.

Intelligence that produces answers and intelligence that produces acts are not the same kind of thing, and the difference is not degree of capability but the presence of a body. Embodiment converts output into contact, contact into consequence, and consequence into answerability. The threshold is crossed at the moment inference moves matter.

Relevance, which in the epistemic case is a question of what bears on a problem, becomes in the embodied case a question of what may be done to whom, here, now, with whose permission, at what cost if wrong. Seven dimensions govern it: permission, safety, privacy, dignity, reversibility, proportionality, and answerability. All must hold. Any one failing is sufficient for the act to be wrong, and no aggregation of the others repairs it.

Capability therefore does not license action. Permission licenses action, and permission is current, informed, revocable, and context-bound, held by affected persons and not only by principals. Where permission is absent or unclear, the correct act is the smallest reversible one, plus escalation.

A system that cannot refuse cannot be trusted to obey. Refusal must be architecturally external to the planner, graded in its responses, and coupled to bounded-time human escalation so that caution does not become neglect.

Contact is not ordinary output. It is classified before it is executed, and its class determines the warrant required. Perception under uncertainty must not be conducted by touching.

A machine in a home is a witness. Its record must be minimised, localised, scheduled for deletion, and governed by an advance disclosure policy. Some facts about persons, though inferable, should not be inferred, retained, or made operative.

Responsibility must be reconstructible. Autonomy that reduces the number of answerable parties is not progress. Affected persons need appeal, not only liability allocation between institutions.

At scale, these are not per-machine matters. One intelligence coordinating many bodies can normalise a marginal act across a population before anyone contests it. Constraint behaviour must therefore be verified at the scale of deployment, not at the scale of the pilot.

XXIX. Warnings to Future Builders

To those building embodied systems, in the order the mistakes are usually made.

Do not treat the body as an interface. It is the site of consequence. Do not treat capability as permission. The two are unrelated. Do not treat helpfulness as authorisation. Unrequested help in another person's space is trespass performed considerately. Do not treat presence as consent. A person in a room has agreed to nothing. Do not treat touch as output. It is the one action your system cannot retract. Do not treat the home as a task environment. It is a field of trust with obligations no contract states. Do not treat data as free. Every retained record is a future disclosure. Do not treat inference as harmless. What your system can compute about a person becomes what someone can act upon. Do not treat obedience as safety. A machine that cannot refuse offers no protection against the instruction that should not have been given. Do not treat refusal as failure. It is the mechanism that makes compliance meaningful. Do not treat compliance as ethics. Frameworks are floors and floors are not destinations. Do not treat form as trust. Human shape is a claim your reliability must earn. Do not treat scale as neutral. What one machine does occasionally, a fleet does as policy. Do not treat autonomy as an answer to responsibility. It is a way of losing track of it. Do not treat maintenance work as beneath design attention. It is the labour that holds the world together, performed on the bodies of those least able to complain.

Build the refusal layer before the capability layer. Build the permission model before the task model. Build forgetting before memory. What you do not build first, you will not retrofit.

XXX. Aphoristic Passages

I. Embodiment is the moment intelligence stops describing the world and begins altering it.

II. A machine that can lift a person can also drop one; capability is always double.

III. Capability is not permission. Permission is not consent. Consent is not standing.

IV. Presence is not permission. Nearness is not agreement.

V. Touch is not a function call.

VI. A machine that cannot refuse cannot be trusted to obey.

VII. Refusal is not the opposite of obedience; it is the condition of trustworthy obedience.

VIII. Optimization without consent is trespass performed efficiently.

IX. The robot that helps you clean may become the first historian of your private life.

X. Forgetting must be designed. Memory arrives for free.

XI. Not everything a machine can infer should become a reason to act.

XII. A home is not a task environment. A home is a field of trust.

XIII. A servant made of code still teaches the master what command feels like.

XIV. Civilization survives by the tasks intelligence once considered beneath it.

XV. Autonomy that reduces the number of answerable parties is not progress.

XVI. A single robot may make a mistake. A fleet may normalize one.

XVII. Safety is the floor beneath ethics, not a substitute for it.

XVIII. The smallest reversible act is the correct answer to uncertainty.

XIX. Where a machine may act upon a person, that person must have somewhere to appeal.

XX. Intelligence became answerable when it acquired a body.

XXXI. References

Sources were consulted at the dates indicated. Where a source is a living document, the version consulted is the one available at that date.

[1] OpenAI. OpenAI Charter. https://openai.com/charter/ — organisational statement of purpose regarding broadly beneficial artificial general intelligence. [2] OpenAI. Built to benefit everyone: our plan. https://openai.com/index/built-to-benefit-everyone-our-plan/ — statement of deployment intent and staged capability. [3] Google DeepMind. Gemini Robotics. https://deepmind.google/discover/blog/gemini-robotics-brings-ai-into-the-physical-world/ — vision-language-action models for robotic control. [4] Google DeepMind. Gemini Robotics 1.5 / ER. https://deepmind.google/discover/blog/gemini-robotics-15-brings-ai-agents-into-the-physical-world/ — embodied reasoning and agentic physical tasks. [5] Google DeepMind. Gemini Robotics-ER 1.6. https://deepmind.google/blog/gemini-robotics-er-1-6/ — embodied reasoning model release. [6] NVIDIA. Isaac GR00T N1 open foundation model for humanoid robots. https://developer.nvidia.com/isaac/gr00t — generalist humanoid robot foundation model. [7] NVIDIA Research (GEAR Lab). GR00T N1.6. https://research.nvidia.com/labs/gear/gr00t-n1_6/ — successor model for humanoid manipulation and reasoning. [8] Simon, H. A. The Sciences of the Artificial. MIT Press — bounded rationality and design of artefacts. [9] Dennett, D. C. Cognitive Wheels: The Frame Problem of AI — the frame problem as a problem of relevance. [10] Floridi, L. The Ethics of Information. Oxford University Press — informational ethics and the moral status of data. [11] International Organization for Standardization. ISO 10218-1:2025, Robotics — Safety requirements — Part 1: Industrial robots. https://www.iso.org/standard/73933.html — industrial robot safety requirements. [12] International Organization for Standardization. ISO 13482:2014, Robots and robotic devices — Safety requirements for personal care robots. https://www.iso.org/standard/53820.html — personal care robot safety. [13] International Organization for Standardization. ISO/TS 15066:2016, Robots and robotic devices — Collaborative robots. https://www.iso.org/standard/62996.html — collaborative operation force and pressure limits. [14] National Institute of Standards and Technology. AI Risk Management Framework (AI RMF 1.0). https://www.nist.gov/itl/ai-risk-management-framework — govern, map, measure, manage functions. [15] European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act). https://eur-lex.europa.eu/eli/reg/2024/1689/oj — risk-tiered regulation of AI systems. [16] World Wide Web Consortium. Verifiable Credentials Data Model v2.0. https://www.w3.org/TR/vc-data-model-2.0/ — cryptographically verifiable, machine-readable credentials.

Citations are provided for context and verification. Their inclusion does not imply endorsement of this treatise by the cited organisations.

XXXII. Conclusion

The question that opened this treatise was not whether machines will become intelligent enough to act, but what changes when they do.

The answer is that a boundary is crossed which no increase in capability crosses on its own. Intelligence confined to language can be wrong at scale and remain, in an important sense, answerable only to argument. Intelligence with a body is answerable to bodies. Its errors are not corrections pending; they are events that occurred. Its outputs are not claims to be evaluated; they are acts already performed on persons who did not evaluate them first.

Everything in the preceding sections follows from taking that difference seriously. If action is irreversible, then permission must precede it rather than justify it afterwards. If contact carries meaning as well as force, then it must be classified rather than executed. If a machine in a home observes a life, then forgetting must be engineered as deliberately as memory. If a system will be instructed by people who are hurried, mistaken, or unjust, then it must be able to decline. And if it will act upon people who never instructed it, they must have somewhere to be heard.

None of this depends on a prediction about artificial general intelligence. If general capability is distant, these constraints govern the machines already moving through warehouses, wards, corridors, and kitchens. If it is near, they govern something far more consequential: a single intelligence expressed through many bodies, capable of normalising across a population what no individual would have accepted in their own home. In both futures the requirement is the same, and in both futures it is easier to build now than to retrofit later.

The claim of this treatise, stated once more without qualification: embodiment transforms intelligence from epistemic output into physically answerable agency, and physically answerable agency must be governed by permission before optimization, refusal before obedience, and dignity before efficiency.

Intelligence became answerable when it acquired a body.

Verification


Body SHA-256
9c2ce1f1d0244c76453491a7b6d33814afdbce56dcfe4f7ac93288c09f822ceb
PDF SHA-256
Recorded on release of the fixed file
Edition ID
EDITION-000003
Corpus Work ID
WORK-000004
Canonical URL
https://jabran.com/writings/the-body-after-intelligence

The web may breathe. The PDF must endure.