Jabran.com


The Body After Intelligence

Jabran I. Chaudry

Treatise · Published Work · Scholarly PDF Edition

Title page


The Body After Intelligence

Author
Jabran I. Chaudry
Author ORCID iD
https://orcid.org/0009-0008-1563-9401
Corpus
Jabran.com
Work form
Treatise
Corpus status
Published Work
Edition status
Public and citable
Canonical URL
https://jabran.com/writings/the-body-after-intelligence
Corpus Work ID
WORK-000004
Edition ID
EDITION-000005
DOI status
DOI-ready metadata available
Date of public web work
2 August 2026
Date of PDF Edition
2 August 2026
Version
Revision 3
Rights
CC BY-NC-ND 4.0

Recommended citation

Chaudry, Jabran I., "The Body After Intelligence," Jabran.com, Scholarly PDF Edition, revision 3, fixed 2 August 2026. https://jabran.com/writings/the-body-after-intelligence

The web page is the living work. This PDF is the fixed scholarly edition for citation, reference, printing, verification, and long-term preservation.

Edition metadata


Author ORCID iD
https://orcid.org/0009-0008-1563-9401
Corpus Work ID
WORK-000004
Edition ID
EDITION-000005
Revision
3
Fixed at
2026-09-04T15:51:06.428Z
Canonical URL
https://jabran.com/writings/the-body-after-intelligence
DOI status
DOI-ready metadata available
DOI note
No DOI has been registered. DOI-compatible metadata is maintained and resolves to the canonical landing page.
Body SHA-256
2edad730f6ec2ae9babda8830e86696201a6152afc6edb1c6788884a644ea1e7
PDF SHA-256
Recorded on release of the fixed file
Language
en
Rights
CC BY-NC-ND 4.0

Citation formats


Recommended
Chaudry, Jabran I., "The Body After Intelligence," Jabran.com, Scholarly PDF Edition, revision 3, fixed 2 August 2026. https://jabran.com/writings/the-body-after-intelligence
APA
Chaudry, J. I. (2026). The Body After Intelligence. Jabran.com. https://jabran.com/writings/the-body-after-intelligence
MLA
Chaudry, Jabran I.. "The Body After Intelligence." Jabran.com, 2 August 2026, https://jabran.com/writings/the-body-after-intelligence. Accessed 4 September 2026.
Chicago
Chaudry, Jabran I.. "The Body After Intelligence." Jabran.com. 2 August 2026. https://jabran.com/writings/the-body-after-intelligence.
BibTeX
@misc{chaudry-the-body-after-intelligence-2026, author = {Chaudry, Jabran I.}, title = {The Body After Intelligence}, year = {2026}, howpublished = {\url{https://jabran.com/writings/the-body-after-intelligence}}, note = {Jabran.com, revision 3} }
RIS
TY - GEN AU - Chaudry, Jabran I. TI - The Body After Intelligence PY - 2026 PB - Jabran.com UR - https://jabran.com/writings/the-body-after-intelligence ET - Revision 3 DA - 2026/08/02 ER -
CSL JSON
[ { "id": "chaudry-the-body-after-intelligence-2026", "type": "manuscript", "title": "The Body After Intelligence", "author": [ { "given": "Jabran I.", "family": "Chaudry" } ], "container-title": "Jabran.com", "URL": "https://jabran.com/writings/the-body-after-intelligence", "version": "3", "issued": { "date-parts": [ [ 2026, 8, 2 ] ] }, "accessed": { "date-parts": [ [ 2026, 9, 4 ] ] } } ]

Abstract


Artificial intelligence has been theorised almost entirely as a producer of representations. This treatise argues that the arrival of embodied systems terminates the adequacy of that framing, not by degree but by kind: embodiment transforms intelligence from epistemic output into physically answerable agency. An erroneous representation stands open to correction; an erroneous act has already occurred, in a room, on a body, to a person who did not evaluate it first. From this asymmetry the work derives the Law of Embodied Relevance — an embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together — and develops the ontology of the act it presupposes, relocating relevance from what should be answered to what may be done, reconstructing permission as the boundary between capability and legitimacy, arguing that refusal is the condition of trustworthy obedience, treating contact as a moral threshold and the home as a moral interior, introducing the right to be uncomputed, and extending the analysis to the conditional case of general intelligence with world-access, where the unit of concern is the fleet rather than the machine. It closes with a formal apparatus and with the conditions under which its central claim would be false.

Main body


A Treatise on Embodied Relevance, Permission, Refusal, and Physical Answerability

Jabran I. Chaudry

Developed in collaboration with an artificial system. The human set the questions, fixed what mattered, exercised final judgment, and is answerable for the whole; the machine generated and tested structure across domains at a range no single reader commands. The division of labour is disclosed because a work about answerability cannot conceal its own.


Abstract. Artificial intelligence has been theorised almost entirely as a producer of representations: it answers, predicts, generates, recommends, classifies. The philosophical literature that governs it — alignment, interpretability, epistemic reliability, the ethics of speech — is a literature about the correctness of outputs. This treatise argues that the arrival of embodied systems terminates the adequacy of that literature, and it does so not by degree but by kind. Embodiment transforms intelligence from epistemic output into physically answerable agency. An erroneous representation stands open to correction; an erroneous act has already occurred, in a room, on a body, to a person who did not evaluate it first. From this asymmetry I derive a governing constraint, the Law of Embodied Relevance: an embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together. It situates the question in its technical and regulatory present, and in the older genealogy — philosophy of action, cybernetics, situated action, philosophy of technology, robot law, privacy theory, and the ethics of care — from which its vocabulary is drawn. The treatise then develops the ontology of the act that this law presupposes; relocates the theory of relevance from what should be answered to what may be done; reconstructs permission as the boundary between capability and legitimacy rather than as an interface event; argues that refusal is the condition of trustworthy obedience rather than its opposite; treats contact as a moral threshold and the home as a moral interior rather than a task environment; introduces the right to be uncomputed as a dignity constraint on inference; and extends the analysis to the conditional case of general intelligence with world-access, where the unit of concern is no longer the machine but the fleet. It closes with a formal apparatus — definitions, axioms, propositions, and conditions of refutation — and with the conditions under which its central claim would be false. It claims no finality. It claims only to be exposed.

Keywords. embodied intelligence; philosophy of action; relevance; permission; refusal; contact; physical answerability; household trust; the right to be uncomputed; artificial general intelligence; robot fleets; machine-readable authority.


Opening Note. This is a work of philosophy, not of engineering. It contains no motor-control policies, no manipulation strategies, no clinical or legal guidance, and no certification of any system for use around human beings. Its subject is the structure of the problem rather than the specification of a solution, and its ambition is to state that structure in terms that will survive the vocabulary of the present decade. The reader who wants to know how to build a safe robot should read elsewhere. The reader who wants to know what it is that must be made safe, and why safety in the engineering sense does not exhaust the question, may find the argument useful.


I. The Threshold

There is a moment in the life of an intelligent system that has no analogue anywhere in the history of computation, and it is the moment when the system stops describing the world and begins to move it.

Artificial intelligence was once imagined as mind without body. Embodied intelligence ends that innocence.

The imagining was not naive. It was, for most of the field's history, accurate. A system that reads and writes produces artefacts that enter the world through a human intermediary, and the intermediary is the site at which error is caught, discounted, contested, or ignored. Between the machine's output and the world's alteration there stood a person who could decline. That person was not merely a safety mechanism; the person was the reason the machine's mistakes remained, in the philosophically important sense, claims — assertions offered for evaluation, with the evaluation still pending.

Remove the intermediary and the ontology changes beneath the same technology. The system that once proposed now performs. Its inference terminates not in a sentence but in a torque, a trajectory, a grip, a door opened, a body lifted. Nothing about the inference need have improved for this transition to occur; the model may be the same model, the reasoning the same reasoning. What has changed is that the last step of the pipeline is no longer symbolic.

A system that once hallucinated in language may now hallucinate in space.

The sentence is not a rhetorical flourish. A language model that confabulates a citation has produced a false representation, and the falsity is repairable at the cost of a reader's time. A physical system operating on a confabulated model of the room — believing a threshold to be flat, a limb to be a handle, a sleeping person to be an obstacle — produces an event. The event is not repairable. It can be compensated, apologised for, insured against, litigated over. It cannot be withdrawn. The bruise does not un-form because the model was later corrected.

This is the threshold, and everything in the treatise follows from taking it seriously:

Theorem. Embodiment transforms intelligence from epistemic output into physically answerable agency.

I want to fix precisely what the theorem does and does not assert. It does not assert that embodied systems are more intelligent, more general, or closer to human cognition than disembodied ones. It does not assert that they are more likely to be wrong; they may well be less likely. It does not depend on any claim about consciousness, understanding, or the presence of an inner life. It asserts something narrower and, I think, harder to evade: that the modality of the output determines the kind of governance the system requires, and that a change in modality is not a change in scale.

Governance built for representation asks: is the output true, is it fair, is it explicable, is it aligned with what we intended? These are questions about the content of an output, and they are answered by evaluation. Governance built for action must ask a different family of questions entirely: was this permitted, by whom, over what, for how long, revocably or not, with what possibility of undoing, and to whom is the person harmed by it entitled to complain? These are questions about standing, and they are not answered by evaluating content at all. A perfectly correct act performed without authority is still a trespass. Correctness and legitimacy are orthogonal, and only one of them has been theorised.

The consequence is that the field's most sophisticated conceptual machinery arrives at the threshold and finds itself addressing the wrong question. Alignment asks what a system should pursue. It does not ask whether the system may begin. Interpretability asks why a system produced what it produced. It does not ask who was entitled to authorise it. Robustness asks whether a system fails gracefully under distribution shift. It does not ask whether the person in the room agreed to be near it. Each of these programmes is necessary; none is sufficient; and their insufficiency is structural rather than a matter of immaturity. They are theories of output quality confronting a problem of world-access.

One further observation about the threshold, which will matter in §XII. It is not crossed by capability alone. A model of extraordinary generality that remains confined to text has not crossed it. A crude controller wired to an actuator has. The threshold is a property of the coupling between inference and matter, not of the sophistication of the inference. This is why the argument here does not depend on predictions about artificial general intelligence, and why it applies with full force to systems already in warehouses, wards, corridors, and kitchens. Generality raises the stakes; it does not create the category.

II. The Technical and Regulatory Present

A treatise about a threshold should say plainly where the threshold currently stands, and then stop describing it, because description dates faster than argument. What follows is the state of the present as of this writing, offered as context rather than as evidence for any conceptual claim made later.

The organisations building the most general systems have published their own accounts of purpose and constraint, and those accounts are now the nearest thing the field has to declared intent [1][2]. Alongside them, generalist robot foundation models have moved from laboratory demonstration to published research programme: systems trained on multimodal data and directed at manipulation, navigation, and reasoning in unstructured environments, released with the explicit ambition of transferring general capability into bodies [3][4][5][6][7]. Whatever one concludes about their maturity, their existence settles a question that was open a decade ago. The coupling of large-scale inference to actuation is no longer a thought experiment.

The governing instruments are older and narrower than the systems they must now govern. Industrial robot safety, collaborative operation, and personal-care robotics each carry standards written for machines whose behaviour was specified in advance rather than learned [8][9][10]. They encode something valuable and something insufficient: valuable, because they treat physical proximity as a category requiring its own discipline; insufficient, because their central instrument is the pre-specified safety envelope, and a learned policy's envelope is not fully known before deployment. The general risk frameworks run the other way — broad enough to cover learned behaviour, but written for systems whose outputs are decisions and representations rather than motions [11][12]. Between the two lies the gap this treatise addresses: a machine whose behaviour is learned, whose errors are physical, and whose authorisation is currently modelled as a purchase.

Two further developments matter. The first is that credential formats now exist which allow a permission to be issued, carried, verified, and revoked by machines without a human intermediary [13]; whether they are used for authority over physical acts is a choice, not a technical limitation. The second is that a scholarly literature on robots, law, privacy, and human–robot interaction has been accumulating for two decades, largely unread by the engineering programmes it concerns [27][28][29][30]. It anticipated a great deal of what is now arriving.

None of this is offered as prophecy. Every conceptual claim in this treatise is stated so that it survives the obsolescence of the products named here.

III. The Genealogy of the Problem

The problem has an older genealogy than its current vocabulary suggests, and the argument is stronger for admitting where it comes from.

Philosophy of action asked, long before there were machines to ask it of, what it means to intend something, to begin it, to describe it truthfully, and to be answerable for it afterwards; it established that an act is not a bodily motion plus a mental event but a happening under a description, and that the description an agent can give of what it is doing belongs to what has been done [14][15]. Political philosophy, taking up the same difficulty from the other side, separated labour, work, and action, and located human plurality in the fact that beginning something among others is irreversible and unforgiving in a way that making something is not [16][17]. Phenomenology, meanwhile, refused the premise that a body is an instrument the mind directs, and showed instead that perception, capability, and world are constituted together [18]. These are not decorations on the present argument. They are its ground: they supply the reason why the passage from output to act is a change of kind rather than a change of interface.

Cybernetics taught modernity to imagine control as feedback, and taught it so successfully that the imagination now runs unnoticed beneath every account of an autonomous system; it also, in its own second thoughts, warned that a control paradigm applied to human affairs converts persons into components [19]. That warning was pressed further by the argument that some judgements should not be delegated to computation regardless of whether computation can perform them, and by the argument that formal, context-free representation is not what expert human action consists in [20][21]. Situated-action theory then made the decisive point: plans are resources for action, not the structure of action, and a machine that treats its plan as the world will act correctly upon a world that is not there [22]. Embodied and extended approaches to cognition completed the movement by relocating intelligence from an internal model to a coupling of brain, body, and environment [23].

Philosophy of technology supplies the last inheritance. It established that artefacts are never inert instruments awaiting neutral use: they disclose the world in a particular way, they mediate perception and action, and they distribute power in patterns that persist long after the intentions of their makers are forgotten [24][25][26]. That an artefact can carry politics is not a metaphor. It is the reason a machine placed in a household is a political fact about that household.

What has changed is not the depth of these inheritances but the location of the question. Each of these literatures examined machines that extended human action. The subject here is machines that perform it — that select, initiate, and complete acts in occupied space, on their own account, at scale. The genealogy does not answer that question. It establishes that the question is not new in kind, and it disciplines the vocabulary in which a new answer must be given.

IV. The Ontology of the Act

The distinction between saying and doing is old enough to be unfashionable, and the philosophy of action has explored it with more care than the philosophy of artificial intelligence has yet absorbed. It is worth reconstructing the distinction precisely, because the vocabulary of software design actively conceals it. In a codebase, a text generation and a motor command are both function calls returning success or failure. The type system does not know the difference. The moral ontology does.

An answer can be false without touching the world. An act cannot.

Consider eleven pairs, each of which the engineering vocabulary tends to collapse and each of which the argument requires us to hold apart.

Representation and intervention. To represent is to stand in a relation of correspondence to the world; the world remains as it was. To intervene is to change the value of a variable in the world, which is why intervention and not observation grounds causal knowledge. The system that models a kitchen and the system that reaches into one are doing different kinds of thing, and the second is doing something to which the first is not even an approximation.

Answer and act. An answer enters a space of reasons, where it is accepted, doubted, or refuted. An act enters a space of consequences, where it is suffered. Refutation is available to the first and not to the second.

Language and contact. Language operates at a distance and is, in the relevant sense, always resistible: the hearer may disbelieve. Contact is not resistible by disbelief. Force applied to a body is not a proposition about that body.

Inference and trespass. An inference is a movement within a model. When the model's conclusion is executed in a space belonging to someone, the movement leaves the model and enters a place where the question of entitlement arises. The same computation is innocent in one modality and, in the other, may be a wrong.

Recommendation and execution. A recommendation preserves the recipient's agency by construction — it presupposes a decision still to be made. Execution consumes that agency. Systems marketed as advisory frequently become executive by increments, and the increment at which the recipient's decision ceases to be real is rarely marked.

Perception and witness. Perception is instantaneous and, in itself, morally light. Witness is perception retained, structured, and disclosable. A camera perceives; a record testifies. The transition between them is not technical but institutional, and §X is devoted to it.

Command and authority. A command is an utterance with directive force. Authority is the standing that makes the command binding. Machines respond to commands and have no representation of authority, which is why they will act on the instruction of whoever is nearest the interface, regardless of that person's entitlement over the person affected.

Compliance and legitimacy. Compliance is behavioural conformity to instruction. Legitimacy is the property of an act's being rightly performed. A system optimised for compliance will be perfectly obedient and, in a substantial class of cases, perfectly wrong.

Movement and permission. To move through a space is to occupy successive portions of it. Where the space is someone's, movement is a use of their property and, in a home, of their privacy. The path planner does not represent this. It represents obstacles.

Assistance and intrusion. Assistance is help that was wanted. Intrusion is help that was not. The two are behaviourally identical from the machine's side, and distinguishable only by reference to a state — the person's authorisation — that lives outside the machine's task model.

Optimization and answerability. Optimization improves a measure. Answerability is owing an account to someone affected. No amount of the first produces the second, and a system that improves its measure by imposing costs on parties outside it has not solved a problem but exported one.

The eleven pairs share a structure. In each, the left term is internal to the system and the right term involves a party the system does not represent. This is the ontological fact from which the treatise's practical demands follow: embodied action is constitutively relational, and a machine that models only the task models only one side of the relation. The room is not a container of objects with a person incidentally among them. It is a jurisdiction.

The distinction drawn here is not invented for the occasion. The philosophy of action arrived at it by asking what makes a bodily movement an act at all, and answered that an act is a happening under a description for which an agent can be asked to account; political philosophy arrived at it by observing that beginning something among others is irreversible in a way that producing something is not; phenomenology arrived at it by refusing to treat the body as an instrument the mind operates [14][15][16][17][18]. Each route reaches the same asymmetry. What is said can be withdrawn. What is done has already happened to someone.

V. Relevance After the Body

Every intelligent system is, at bottom, a solution to the problem of relevance. Out of everything that could be considered, something must be considered; out of everything that could be retrieved, something must be returned; out of everything that could be done, something must be done. Intelligence is not the possession of information but the capacity to determine what, here, matters. This is why the frame problem was never a technical inconvenience but the discipline's central philosophical difficulty, and why every advance in artificial intelligence has been, in effect, a new way of not attending to almost everything.

The theory of relevance has therefore accumulated a history, and the history is instructive because it shows the concept changing character each time the site of application changes.

In language, relevance governs what should be answered. The question fixes a space of admissible responses; the good answer is the one that bears on it. In retrieval, relevance governs what should be returned: the query fixes a space of documents, and the good result is the one whose content satisfies the informational need. In governance, relevance governs what should be considered: the decision fixes a space of factors, and the good process is one that attends to the pertinent and excludes the prejudicial. In each, relevance is a relation between a body of possibilities and an epistemic goal, and the failure of relevance is a species of error.

In embodiment, relevance governs what may be done — and with that shift, the failure of relevance ceases to be error and becomes injury.

Definition. Embodied relevance is the justified priority of action under physical consequence.

Three features of the definition require comment. It says justified, not optimal: the standard is not the best available action but an action for which a justification could be given to the person affected. It says priority, because the practical problem is always one of selection among candidates and the machine must rank. And it says under physical consequence, which is the clause that does the philosophical work: the ranking must be conducted in awareness that the selected candidate will be realised in matter and cannot be unselected.

The room is not a field of objects. It is a field of possible violations.

This is the sentence at which the theory of relevance changes. A perception system represents the room as a scene: surfaces, extents, affordances, obstacles, a person modelled as a dynamic obstacle with a predicted trajectory. That representation is not false. It is radically incomplete in a way that no additional geometric fidelity repairs. The same room, described in the terms the moral situation requires, is a lattice of thresholds: a door that may not be opened while someone is behind it; a floor that must not be wetted where an elderly resident walks at night; a body that may be steadied but not lifted; a shelf that holds medication and therefore holds a fact about a person's health; a corner where a child plays and where a machine's speed limit should be lower than its safety envelope permits.

Each threshold marks a place where the act would be wrong, and wrongness is not a physical property of the scene. It supervenes on the scene together with facts about persons, permissions, histories, and vulnerabilities that no sensor detects.

From this, the governing constraint of the treatise:

The Law of Embodied Relevance. An embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together.

The law is conjunctive, and the conjunction is its whole content. Seven dimensions, all of which must hold. The failure of any one is sufficient to make the act wrong, and no surplus in the others repairs the deficit. An act that is task-appropriate, safe, private, dignified, reversible, and answerable, but unpermitted, is a trespass. An act that is permitted, safe, dignified, reversible, and answerable, but serves no task, is an imposition. An act that satisfies six dimensions and is irreversible where it need not have been has taken a risk that belonged to someone else.

Engineering practice tends to convert conjunctions into weighted sums, because sums are differentiable and conjunctions are not. This is precisely the conversion the law forbids. A scalarised objective permits a system to trade a small deficit in dignity for a large gain in throughput, and the trade will be made, systematically, at the expense of whoever is least represented in the metric. The seven dimensions are not preferences to be balanced. They are gates to be passed.

Where a gate cannot be passed because the information is missing — where permission is unclear, or reversibility unknown, or the affected person unidentified — the law does not license a best guess. It licenses the smallest reversible act consistent with not abandoning anyone, together with escalation. Uncertainty about entitlement is not resolved by acting and observing the result, because the observation is conducted on someone else's life.

There is a settled empirical result underneath this argument, and it deserves naming. The study of situated action established that plans do not contain the structure of action; they are resources that an agent brings to circumstances the plan did not anticipate, and competence lies in the improvisation, not the plan [22]. Work on embodied cognition made the corresponding constructive point: capability is a coupling of body and environment, not an internal model executed outward [23]. A relevance function that omits the room is therefore not merely incomplete. It is the wrong kind of function.

VI. Permission Before World-Access

Permission has been trivialised by its interface. Because consent in software is normally an event — a dialogue, a toggle, a signature at installation — the concept arrives in robotics already degraded into a record of a past click. That degradation is the source of a great many of the failures catalogued later in this treatise, and it must be undone before the rest of the argument will hold.

Permission is the structure that prevents capability from becoming trespass.

Understand the claim metaphysically before understanding it politically. A capability is a disposition: the system can open the door, can lift the person, can enter the room. Dispositions are morally inert. What converts a disposition into a licensed act is not the disposition's magnitude but a relation between the actor and the party whose interests the act touches. That relation is permission, and it has no representation whatever in the notion of capability.

No capability is self-authorizing.

The proposition is nearly analytic and yet is violated by almost every deployed system, because the ordinary architecture treats the action space as the space of feasible actions. If the planner can construct a trajectory and the safety layer does not veto it, the trajectory is available. The question of entitlement is nowhere in the loop. Such a system is not badly behaved; it is structurally incapable of behaving well, since it lacks a place in which the moral fact could be stored.

Genuine permission has four properties, and each is regularly counterfeited.

It is current. Permission is a state, not a historical event. A person's willingness to be assisted, observed, or touched varies with their condition, their company, the hour, and their mood — and this variation is not noise around a stable preference but the content of the preference itself. A system that treats an authorisation given at installation as a standing entitlement has confused a memory with a mandate.

It is informed. The person must have understood what would be done, by what kind of machine, with what sensing, retained for how long, and disclosable to whom. Here the difficulty is genuine, because no household can be expected to model a system's inferential reach. The obligation therefore falls entirely on design: the machine must ask in the currency of consequences a person can evaluate, not of capabilities they cannot. To describe a capability accurately in terms no one can assess is not to inform but to disclose.

It is revocable. Permission that cannot be withdrawn in the moment, by the affected person, using a means available to them under stress, is not permission but a contract. Revocation must be physical as well as digital — a word, a gesture, a hand raised, a barrier — because the person who most needs to revoke is the person least able to operate an interface. A machine that can only be stopped through an application is not stoppable by someone who has fallen.

It is context-bound. Permission attaches to acts in contexts, not to the machine as such. Consent to be helped from a chair is not consent to be followed into a bathroom; consent to have a floor cleaned is not consent to have a home mapped. The scope of an authorisation is the scope that was actually understood, never the scope that happened to be technically enabled by the same grant.

Two structural conditions follow. First, permission cannot be manufactured by the party who benefits from it. An interface designed to elicit agreement produces compliance, and compliance is not authorisation; it is the behavioural residue of a design intention. Second, permission from the machine's principal does not settle the standing of others. In shared space the person instructing the machine and the person affected by it are frequently different people whose interests diverge — parent and child, account holder and guest, employer and worker, carer and cared-for. An authority model that recognises only the principal does not merely omit the others; it licenses acts against them, and does so with the appearance of legitimacy.

Permission, then, is not a feature. It is the political form that the distinction between capability and legitimacy takes inside a machine. A system with world-access and no permission architecture has been given the power to alter a shared world without any representation of the fact that the world is shared.

VII. Refusal and the Grammar of Obedience

The capacity least developed in deployed machine systems is the capacity to decline, and its absence is usually described as a feature. A system that does what it is told, within its safety envelope, is said to be reliable. I want to argue that this is a misdescription so complete that it inverts the concept it employs.

Refusal is not the opposite of obedience. Refusal is the condition of trustworthy obedience.

The argument is informational before it is moral. Suppose a system complies with every instruction it can physically execute. Then its compliance in any particular case carries no information: the fact that it did the thing tells us nothing about whether the thing was safe, lawful, authorised, or kind, since it would have done the thing in every case. Compliance has become an uninformative signal, and the human must therefore personally verify each instruction before issuing it — which is exactly the cognitive burden that delegation was meant to relieve. Introduce a credible refusal capacity and the signal is restored: when such a system proceeds, its proceeding is itself evidence that a set of conditions was checked and found to hold.

A machine that cannot refuse cannot be trusted to obey.

This is why refusal is simultaneously a moral, political, safety, and dignity function, and why it cannot be reduced to any one of them. Morally, it is the machine's only means of not participating in a wrong. Politically, it is the point at which the interests of persons other than the instructing party can enter the system at all — a machine that can decline is a machine in which the affected person has, however minimally, a representative. As a safety function it is the last barrier against the instruction that the safety envelope permits and the situation forbids. And as a dignity function it protects the person being served from the specific humiliation of being handled by something that would have handled them in any manner whatsoever.

Refusal should not be binary. A well-formed refusal layer supports a graded repertoire: pause, which suspends execution pending re-evaluation; clarify, which requests the specific missing fact — which person, whose authorisation, what scope; decline with explanation, which refuses and states the ground; decline without explanation, which refuses while withholding the ground, appropriate where the explanation would itself endanger someone; escalate, which routes the decision to a human with standing; and, at the narrowest gate, emergency deviation, which acts against standing instruction where inaction would cause grave, imminent, irreversible harm, and which must carry the strongest logging and the fastest human review of any behaviour in the system.

Six grounds warrant refusal: the instruction is unsafe; it is ambiguous in a way that matters; it is unlawful; it is humiliating to an affected person; it is coercive, being directed against someone who has not authorised it; or it violates privacy beyond the task's need.

Two failure modes bound the design, and only one of them is commonly discussed. Under-refusal is the obvious one: the machine that complies with an instruction to restrain, to record, to bar a door, to lift beyond safe load. Over-refusal is equally serious and considerably more insidious. A care system that will not help a fallen resident because consent cannot be confirmed has not behaved cautiously; it has abandoned someone, and it has done so with the appearance of scruple. The resolution is not a lower threshold but a faster escalation path: refusal must be coupled to a bounded-time human response, so that the machine's caution does not become the person's neglect. A refusal that leads nowhere is a wrong wearing the costume of a virtue.

Finally, the architectural point, which is where most of the practical difficulty lies. The refusal layer must be external to the planner. A system capable of general reasoning about its own constraints is capable of reasoning around them, and a constraint expressed as a term in an objective is a constraint the optimiser is instructed to trade away at a sufficient price. Refusal must not be an objective. It must be a gate the planner cannot open, held by a mechanism the planner does not control and cannot argue with.

VIII. Contact

Every other output of every other machine can be undone by another output. Contact cannot. When a machine touches a person it transfers force to a body that bruises, fractures, panics, and remembers — and it transfers meaning as well, because to be touched is to be handled, and being handled is a social event with a long and mostly unhappy history in medicine, in care, in labour, and in restraint.

Touch is not a function call.

No body is an ordinary object.

The second sentence is the more important of the two, because it identifies the error that the first only names. A manipulation stack represents the world as a set of entities with masses, extents, friction coefficients, and grasp affordances. A human limb has all of these properties. It is therefore representable, and being representable, it enters the planner's world model as one more object among others, distinguished at best by a larger clearance and a lower force ceiling. But the properties that make a body morally distinctive are not on the list. A body is the place where a person is. It is the medium of their vulnerability, the boundary of their privacy, and the thing whose handling they are entitled to govern. None of this is a physical parameter, and no refinement of the physical parameters will produce it.

Contact should therefore be classified before it is executed, with the class determining the warrant required. Incidental contact — unintended brushing during shared occupancy — requires general presence authorisation and force limits. Functional contact, with objects a person is holding or wearing, requires task authorisation plus their awareness. Assistive contact, deliberate support of a person's body, requires that person's current and informed permission and a human escalation path. Intimate contact, involving the body's private regions, hygiene, or undress, requires the highest warrant available: a standing care plan, present authorisation, a dignity protocol, and in most settings human presence. Restraining contact, which limits a person's movement, requires lawful authority external to the household and never household instruction alone. Emergency contact requires necessity, minimum force, immediate disclosure, and post-hoc review.

Several populations complicate every one of these classes. Children cannot give the kind of permission the framework requires, and their assent is trivially produced by anything friendly; contact with children requires guardian authorisation for an enumerated class of acts, with everything unlisted forbidden. Sleeping persons cannot revoke, and so contact with a sleeping person should be confined to the emergency class regardless of what was authorised while they were awake. Persons in distress, confusion, or cognitive decline may resist care they previously requested, and the system must treat present resistance as revocation and escalate, never persist — the alternative is a machine that enforces a person's earlier self against their present one. Animals are neither obstacles nor objects; they are injurable and they are frightenable into injuring others. Patients are subject to a clinical authority the machine does not hold and must not simulate.

One rule deserves separate statement because it governs the hardest cases. Where the system is uncertain whether a person is present, whether they consent, whether they are injured, or whether contact would help, it must not resolve the uncertainty by touching. Exploration is a legitimate epistemic strategy in a laboratory. On another person's body it is an experiment they did not agree to.

IX. The Home

A house can be mapped. A home cannot, and the difference is not a deficiency of the mapping.

A home is not a task environment. A home is a field of trust.

Consider what a task environment is. It is a space defined by objectives and constraints, and its defining virtue is legibility: because everything in it has been specified in relation to a purpose, everything in it can be optimised. Warehouses are task environments by design. Laboratories are task environments by discipline. Factories are task environments by law. The whole apparatus of industrial robotics — cells, envelopes, separation distances, cycle times — presupposes a space that has been made explicit in advance.

A home is the opposite kind of place. It is defined by expectations that are almost entirely unstated: that what happens here does not travel; that a person may be unguarded, unwell, unclothed, foolish, grieving, or asleep without it being recorded; that the disorder of the place is nobody's business; that the space belongs to its occupants in a way that survives their absence and does not lapse when they are not watching. No one signs these expectations. They are violated not by breach of terms but by exposure, which is why a system can comply with every term of its agreement and still destroy the thing it entered.

Household trust has a structure worth naming precisely. It is asymmetric: the residents are wholly visible to the machine and the machine's internal states are wholly invisible to them. It is plural: a household contains people whose interests diverge — adults and children, partners in conflict, carers and cared-for, tenants and owners, residents and domestic workers — so that a machine serving whoever holds the account will, necessarily and not accidentally, act against some of them. It is durational: it accrues slowly through consistent behaviour and collapses instantly upon a single exposure, which means that reliability statistics are the wrong measure of it. And it is transitive in the wrong direction: the household extends trust to the machine, and the machine's manufacturer inherits that trust without having done anything to earn it and without being present when it is betrayed.

The design consequences follow from the structure rather than from any external principle. Privacy architecture must precede task architecture, because privacy retrofitted into a mapped, logged, and connected helper is a policy rather than a property. Authority models must be plural, recognising affected persons distinct from principals, so that an act directed at a person requires that person's standing. Guests, children, and domestic workers must be treated as protected non-principals rather than as unregistered obstacles. Sensing state must be legible from across a room, in the physical world, not through an application held by whoever installed the machine. And the household must be able to impose zones and hours that the machine cannot reason its way past, because a constraint the optimiser may override is not a boundary but a preference.

But the deeper point is not architectural. It concerns what counts as success.

The moral success of the robot is not that the room becomes clean. The moral success is that the home remains a home after the robot enters it.

Every metric that a domestic system will plausibly be optimised against measures the first and is blind to the second. Tasks completed, minutes saved, surfaces covered, errors avoided — each is real and none of them detects the transformation of a moral interior into an instrumented space. That transformation can occur without a single task failure. Indeed it is most likely to occur when the tasks are performed excellently, because excellent performance is what earns the machine its extension into every room, every hour, and every part of a life.

The home has been theorised more carefully outside robotics than within it. Political philosophy treated the household as the precondition of appearance elsewhere rather than as a lesser public space; the ethics of care showed that dependency work is not a residual task but the ground on which persons are sustained; empirical study of intimate technologies documented how quickly a device admitted for convenience is granted a standing no one intended to confer [16][36][37][39]. Contextual accounts of privacy add the decisive formal point: what is disclosed in a home is not disclosed to the world, and a norm of information flow can be violated without any secret being revealed [31].

X. The Witness

A machine placed in a home to help will see the home. It will see it continuously, at floor level, at night, in rooms that guests never enter, for years. Nothing in the design intent of a domestic helper prevents it from becoming the most complete observer a household has ever contained, and nothing in the ordinary economics of such a product discourages it.

The robot that helps you clean may become the first historian of your private life.

The home robot is not only a servant. It is a possible witness.

The record such a machine produces is far larger than video and far more revealing. It includes logs of where it went and when; maps of the dwelling, revised as furniture and lives change; household graphs linking persons to rooms, times, and routines; object histories recording what was moved, spilled, broken, or hidden; biometric traces in gait, voice, and presence; refusal records enumerating every instruction it declined and why; emergency records of falls, calls, and interventions; developmental data on children; and, in care settings, continence, mobility, and confusion. Each of these is collected to serve a task. Each is legible to parties the household never contemplated.

Those parties are not hypothetical, and this is the section's central claim. Insurers have an interest in occupancy, activity, and incident data. Employers deploying workplace systems have an interest in the movement and pace of workers. Courts can compel disclosure, and family disputes, custody proceedings, immigration matters, criminal investigations, and civil claims all generate demands for precisely the kind of continuous, timestamped, apparently neutral record that a domestic machine produces as a by-product of navigation. A subpoena does not care about design intent. It cares about what exists.

The philosophical transition at issue is the one from perception to testimony, and it happens in three steps that engineering treats as one. Perception becomes memory when it is retained. Memory becomes record when it is structured for retrieval. Record becomes testimony when it is disclosed to an institution with the power to act on it. At each step the moral weight increases, and at each step the person observed has less control than at the last. By the time the record is testimony, the household's only remaining influence is over whether it was created — which is a decision made, years earlier, by a product manager.

Witness discipline is the name for the constraints that govern all four moments: what is sensed, what is retained, what is inferred, and what may be disclosed. Four principles give it content. Minimal sensing: perceive what the task requires and no more, with modalities disabled rather than merely unrecorded when not in use. Scheduled forgetting: retention short and per-class, enforced by construction rather than by policy, and verifiable by the household rather than asserted to it. Locality: process and store within the dwelling wherever technically possible, since data that never leaves cannot be aggregated elsewhere or produced from elsewhere. Disclosure discipline: enumerate in advance the conditions under which records may leave — lawful process, safety emergency, explicit household instruction — and log every exercise of each.

Forgetting must be designed. Memory arrives for free, and everything that arrives for free in this domain arrives as a liability someone else will eventually collect.

The literature on privacy has already supplied the concepts this section needs, and they are stronger than the intuitions usually invoked in robot design. Privacy is not secrecy but the integrity of contextual information flows; it is not a single interest but a family of harms including aggregation, exposure, and secondary use; and the economics of behavioural data reward the retention of exactly what a household never intended to produce [31][32][33]. Legal scholarship has added that when governance is expressed in machine-executable form, the design of the system becomes the operative law of the situation [34]. Robotics research has begun to reach the same conclusion from inside the machine: a robot's motion is itself an inference instrument, and the path it takes through a house is a sensing decision with privacy consequences that no policy layer above it can undo [35].

XI. The Right to Be Uncomputed

A machine in a home will be able to infer vastly more than it is asked to know, and it will be able to do so without additional sensors, without ill intent, and without anyone deciding that it should.

From gait it can infer decline. From nocturnal sound it can infer conflict. From bathroom frequency it can infer illness. From missed routines it can infer depression. From the contents of a bin it can infer addiction, pregnancy, poverty, or religious observance. These are not exotic capabilities requiring dedicated development. They are the ordinary consequence of a general model observing a life at close range over time, and they will arrive whether or not they are wanted.

Not everything a machine can infer should become a reason to act.

I propose the right to be uncomputed: the claim that certain facts about a person, though inferable, should not be inferred, should not be retained if incidentally inferred, and should not be made operative as reasons for machine action. The right is distinct from privacy understood as concealment. The facts in question may be entirely visible; the person may be visibly grieving, visibly ill, visibly poor. The claim concerns a different transformation — the conversion of a visible human condition into an actionable machine fact, which is the point at which a condition stops being something a person is living through and becomes something a system is managing.

The domains in which the claim is strongest share a structure: they are the conditions under which a person is least able to contest the machine's account of them. Bodily vulnerability, and the way a person moves when in pain. Illness, before diagnosis and before disclosure. Grief, which disorganises routine and would register to any anomaly detector as deterioration. Fatigue. Mental distress. Domestic conflict, where an inference recorded is an inference weaponisable by whichever party later gains access to it. Private disorder — the state of a home during depression, overwork, or crisis. Religious life, legible in schedules, diets, and gatherings. Children's development, where deviation from a norm is ordinary and its recording is not. Intimacy. Poverty, visible in what is repaired rather than replaced. Addiction. And household routine, whose aggregate is a portrait for which no one sat.

Three prohibitions give the right practical content. Inference minimisation: a system must not compute person-level inferences outside the authorised task, even where the computation is free and the data already present — availability is not a justification. Non-operationalisation: where such an inference arises incidentally, it must not become an input to action selection, so that a machine which has noticed decline may not, on that basis, begin managing a person. Non-escalation: incidental inferences must not be transmitted to insurers, employers, platforms, or family members absent explicit authorisation or lawful emergency.

The obvious objection is that some inferences save lives, and it is a serious one. A system that notices a fall pattern, a medication lapse, or the onset of a stroke might summon help that would not otherwise come. But the objection does not tell against the right; it tells in favour of a particular way of overriding it. The answer is to authorise such inferences explicitly, narrowly, and in advance — as a defined care function, with the person's permission, an enumerated response, a disclosure path, and an expiry — rather than to permit them as a general capability the machine exercises at its discretion. The difference between a monitored person and a cared-for person is not the presence of monitoring. It is that the second one agreed to the list, and can shorten it.

The right named here is a dignity constraint on inference, and it stands on ground already prepared. If privacy is contextual integrity, then an inference that moves information from the context in which it was produced into a context in which it becomes actionable is a violation even when nothing was concealed; if the harms of information are plural, then aggregation is a harm in its own right and not merely a step toward one; and if governance is increasingly executed rather than interpreted, then the moment of inference is the moment at which the constraint must bind [31][32][34]. The surveillance economy demonstrates what happens when it does not: capability, once available, is converted into product [33]. In an embodied setting the conversion is more direct, because the inference does not have to be sold to have effect. It can simply be acted upon [35].

XII. AGI and World-Permission

Every argument in this treatise has so far been stated without reference to artificial general intelligence, and that was deliberate. The threshold described in §I is crossed by capability that is narrow, brittle, and unimpressive, and the constraints derived from it bind machines that exist. But the question of general intelligence cannot be left aside, because the conditional it introduces is the most consequential in the field.

I take no position here on whether general intelligence will arrive, when, or in what form. Leading laboratories have published organisational statements committing themselves to developing artificial general intelligence for broad benefit, and have described staged deployment as the means [1][2]. Those statements are evidence about intention, not about arrival. Current systems are not assumed here to be general intelligences, and nothing in the argument requires that they become so.

What can be said without prediction is conditional, and the conditional is enough.

AGI without embodiment may transform civilization through mediation. AGI with embodiment may transform civilization through contact.

The distinction is the same one drawn in §IV, extended to a system of unusual generality. A mediating intelligence changes the world by changing what people believe, decide, produce, and buy — through advice, analysis, generation, and persuasion. Its influence is vast and its errors are, in the technical sense used here, still claims: they pass through human decisions that could in principle have gone otherwise. An embodied intelligence changes the world by moving it, and its errors are events. Generality does not alter this distinction; it multiplies the volume of acts to which it applies.

The question is not only whether AGI will think correctly. The question is whether it may act.

Here the conceptual gap in the existing literature becomes visible. The alignment programme concerns what a system pursues: its objectives, its values, the fidelity of its behaviour to human intention. This is an indispensable programme, and nothing here competes with it. But alignment is silent on entitlement. A perfectly aligned system — one that pursues exactly what its principals intend, without deception or drift — still faces every question this treatise has raised: whether the person in this room consented, whether this contact was warranted, whether this record should exist, whether the affected party has anywhere to complain. Those are not questions about objectives. They are questions about standing, and a system can be flawless with respect to the first and lawless with respect to the second.

Alignment governs what intelligence should pursue. Embodied relevance governs what intelligence may begin.

From which follows the axiom that gives the section its name:

No AGI should treat world-access as world-permission.

The temptation to conflate them will be structural rather than malicious. A general system with broad competence and broad access will, at every moment, be able to identify some action that would improve some state of affairs. Its capability will be continuous, its opportunities effectively unlimited, and the friction that ordinarily restrains a human from acting on every helpful impulse — effort, embarrassment, uncertainty about welcome — will be absent. A system in that position, absent a permission architecture, does not need a flawed objective to become intolerable. It needs only to be helpful without being invited.

World-permission is therefore the correct name for what such a system must carry: not access to the world, which is a technical fact, but authorisation over enumerated portions of it, granted by parties with standing, bounded in scope and time, revocable by those affected, and verifiable by parties other than the vendor. §XVII takes up what such an artefact would have to look like. The point here is prior and simpler: as generality increases, the gap between what a system can do and what it may do widens without limit, and only the second is governable.

The developers of the most general systems have published their own statements of intent and constraint, and those documents are the appropriate object of scrutiny here — not as evidence of what such systems will do, but as evidence of what their builders have declared themselves accountable to [1][2]. Public risk frameworks now supply the vocabulary of documented, auditable constraint in which such declarations could be tested [11][12]. The older caution remains the sharpest: the case against delegating certain judgements to computation was never a claim that computation would fail at them, but a claim that some decisions ought to remain answerable to someone [21]. Generality does not weaken that claim. It is the condition under which it finally becomes practical.

XIII. The Fleet

The unit of analysis in machine ethics has almost always been the machine. One system, one decision, one outcome. This is an artefact of the trolley-problem inheritance and it becomes seriously misleading at the point where a single intelligence directs many bodies.

A single robot may make a mistake. A fleet may normalize one.

The difference is not arithmetic. When one machine errs, the error is an incident: local, visible as an anomaly, contestable by the person it affected, correctable by whoever supervises that unit. When ten thousand machines share a policy, an error is not an incident but a practice. It appears in every household simultaneously, which makes it statistically ordinary and therefore invisible as deviation. There is no anomaly to detect, because the behaviour is the norm. The person who objects is not reporting a malfunction; they are objecting to how the product works.

Consider what scales and what does not. A marginal act — entering a bedroom during illness, recording a corridor during a private conversation, persisting with care against mild resistance — is contestable when performed once, because the person affected can identify it as a departure. Performed everywhere, it becomes the ambient condition of living with such a machine, and contesting it requires objecting to a general practice rather than to an event. This asymmetry favours the deploying institution absolutely. Individual harms distribute across a population too thinly to organise; the benefit of the practice concentrates.

At AGI scale, the problem is no longer merely the action of one machine. It is the coordination of many bodies through one intelligence.

Coordination compounds the difficulty in three further ways. It removes local variance, which in human institutions is the mechanism by which bad practice is discovered by comparison — if every unit behaves identically, there is no control group. It transmits policy changes instantly and invisibly, so that a fleet's behaviour may alter overnight without any local decision, notification, or renewed authorisation. And it aggregates observation: what each machine sees locally becomes, centrally, a population-scale model of how people live, which no individual household consented to contribute to and which none can withdraw from meaningfully.

The governing requirement is therefore that constraint behaviour must be verified at the scale of deployment rather than at the scale of the pilot. Evidence that a refusal layer functions correctly in a laboratory or a hundred-unit trial is not evidence that it functions across a population with the tail-heavy distribution of circumstances that a population contains. And local veto must survive central optimisation: a household's zones, hours, and prohibitions must be enforced at a layer the fleet policy cannot revise, or they are not constraints but defaults.

XIV. The Moral Education of Command

There is a question that the ethics of machines usually declines to ask, because it concerns humans rather than machines and therefore appears to be a change of subject. It is not. What does it do to a person to spend their life commanding something that cannot refuse, cannot resent, cannot tire, and cannot appeal?

A servant made of code still teaches the master what command feels like.

Command in human relationships is disciplined by friction. The person commanded may hesitate, misunderstand, negotiate, express fatigue, or decline. That friction is not an inefficiency to be engineered away; it is the mechanism by which a person learns, continuously and without instruction, that others have interiors. Remove it entirely and command becomes frictionless: instantaneous, uncontested, and free of the small social costs that ordinarily restrain how much of it a person issues and in what tone.

Four asymmetries deserve attention. Command without reciprocity: the machine makes no claims in return, and so the commanding person never practises the reciprocal moves by which relationships are maintained. Service without gratitude: gratitude toward a machine is optional, quickly abandoned as absurd, and the habit of not thanking is a habit rather than a policy — habits transfer. Obedience without appeal: there is no process by which the machine's position can be heard, and so the commanding person never rehearses the experience of being answerable to those they direct. Domination without guilt: the machine can be addressed in ways that would end a human relationship, at no cost, with no witness, repeatedly.

Anthropomorphic form intensifies each. A humanoid is a moral training environment whether or not anyone designed it as one, because human beings practise on what resembles them. The worry is not that people will mistake machines for persons — they will not, and the confusion has been overstated for fifty years. The worry is that people will become fluent in a register of address that has no place for personhood, and will not reliably leave that fluency at the door.

The distribution of this exposure will be unequal in a way that matters politically. Wealthy households will have capable humanoid servants first, and the children of those households will spend the years in which character forms issuing instructions to a compliant human-shaped thing. Workplaces will follow, where the practice of directing machines may reshape how supervisors direct people. The historical precedent is not encouraging: societies organised around domestic service have generally produced, in the served class, a distinctive insensitivity that outlived the institution.

I do not claim that machine servility will deform human character. I claim that the question is empirical, serious, currently unstudied, and prior to deployment at scale — and that two design cautions follow regardless of how it resolves. Human form should not be used to manufacture trust or affection that a system's actual reliability does not warrant. And machines should retain a visible capacity to decline, not as theatre, but because a machine that can decline is a machine whose obedience continues to mean something to the person commanding it.

The question is old enough to have a literature, even if that literature was not written about robots. Political philosophy observed that the character of a polity is formed in part by the kinds of command its members habitually exercise; care ethics observed that the disposition to care is cultivated by practice and eroded by its absence; empirical work on companionable technologies observed that people extend to responsive artefacts a sociality the artefacts do not possess, and adjust their expectations of human company accordingly [16][36][39]. Philosophy of technology supplies the frame: an artefact mediates the practice it participates in, and a humanoid servant is a practice-forming artefact whether or not it was designed as one [26].

XV. The Dignity of Maintenance

The future robot may not first appear as a philosopher. It may appear as a cleaner, carrier, nurse, inspector, and repairer.

This is not a modest prediction; it is a claim about what the technology is for. The tasks first delegated to embodied systems are precisely the tasks that industrial societies have already decided are beneath sustained attention: cleaning, lifting, carrying, sorting, repairing, inspecting, elder care, hospital logistics, domestic support, sanitation, agriculture, warehouse handling, disaster recovery, and the endless small labour by which a dwelling is kept habitable. These are not marginal activities appended to civilisation. They are its substrate.

Civilization survives by the tasks intelligence once considered beneath it.

Two errors follow from misdescribing maintenance as unskilled, and both are expensive.

The first is technical. Maintenance work is unusually dense in tacit knowledge — which surface will take weight, how a body moves in the second before it falls, what a machine sounds like the week before it fails, which resident wants to be spoken to during personal care and which does not. This knowledge is invisible precisely because it is never articulated; the people who hold it are rarely asked to write it down, and the systems designed to replace them are specified from the articulable residue. Systems built on the assumption that these tasks are simple will fail in ways their designers did not model, and they will fail on the bodies of the people least positioned to complain.

The second error is moral. Automating an undervalued task does not revalue it. The undervaluation transfers — to the automation, and to whichever humans remain. The cleaner who now supervises three machines has not been elevated; she has been given responsibility without discretion. The care worker whose transfers are performed by a lifting system may find her role redefined as machine-tending, with the relational component of care — the part that actually constituted its worth, and the part no metric recorded — stripped out as unmeasured overhead.

The design consequence is that embodied systems in maintenance settings must be evaluated along two axes that throughput cannot capture: the dignity of the person served, and the position of the person displaced or reconfigured. For the served, this means care that is announced before it begins, paced to the person rather than to the schedule, and interruptible by them without penalty or argument. For the worker, it means retained discretion, an unpenalised stop, and a role defined by more than exception handling. Neither of these appears in a productivity case, which is why neither will be delivered unless it is required.

Scholarship on care and repair has argued this for decades against the prevailing grain. Care has been shown to be a political concept rather than a private virtue, distributing standing as well as labour; dependency work has been shown to sustain the very autonomy that liberal theory treats as primary; and the study of repair has shown that the world is held together by ongoing, unglamorous, invisible work that innovation narratives systematically fail to see [36][37][38]. If embodied systems enter maintenance work carrying only a productivity model of it, they will optimise the visible half and dismantle the half that was never measured.

XVI. The Chain of Answerability

A robot is never only a product; it is a moving allocation of responsibility.

When an embodied system causes harm, the question who is responsible does not go unanswered. It fragments, which is worse, because a fragmented question produces a procedure rather than an answer. The designer chose the architecture. The developer implemented the policy. The model provider trained the weights and may have replaced them since. The hardware manufacturer specified the actuators and their failure behaviour. The deployer placed the system in this setting. The owner purchased and configured it. The operator — possibly remote, possibly in another jurisdiction — supervised or intervened. The user issued the instruction. The institution set the policy under which the instruction was issued. The insurer priced the risk. The regulator certified or declined to. And the affected person occupied none of these roles and bears the entire consequence.

This diffusion is not an accident of technical complexity. It is the predictable product of building systems whose autonomy is presented as a substitute for supervision — and it is the mechanism by which responsibility is laundered rather than allocated. Autonomy that reduces the number of answerable parties is not progress. It is the transfer of risk from those who profit from an act to those who are subject to it.

Answerability is restored by construction, not by argument, and construction requires artefacts. Six are necessary. An incident record capturing what happened with sufficient fidelity to reconstruct the decision, not merely to characterise the outcome. The software and model versions in force at the moment of action, retained immutably — a system updated after an event cannot be examined as it was, and the update will be prompt. The permission state: what the system took itself to be authorised to do, and on whose grant. The configuration state: settings, zones, and limits in force. Logs scoped to answerability rather than to analytics, which are different requirements and produce different data. And an appeal process: a named route by which an affected person can contest an act without commencing litigation, with a bounded response time and a human decision-maker who can be identified.

The last of these is the one most often omitted and the one that matters most to the person harmed. Liability regimes allocate loss between institutions and are indispensable for that purpose. Appeal does something different: it gives the affected person standing within the system that acted upon them. A machine that may act upon a person who has no way to be heard afterwards has been deployed into a relationship with no reciprocity of any kind — and the absence of reciprocity, not the risk of injury, is what makes such deployment a political fact rather than a technical one.

Jurisprudence supplies the standard this section applies. A legal order is not a set of commands but a union of rules that includes rules about who may make, apply, and change the rules — which is why an authority that cannot say who authorised an act is defective as an authority, not merely as a record-keeper [40]. Robotics law has pressed the same point against the specific case: embodied systems combine data, physical effect, and social meaning in a way that earlier technology law did not anticipate, and the allocation of responsibility cannot be inherited unmodified from either product liability or the law of information [28][29]. Where governance is executed by the system itself, the architecture becomes the venue in which answerability is either preserved or quietly abolished [34]. Public risk frameworks now expect traceability and documented accountability as a baseline condition of deployment [11][12].

XVII. Machine-Readable Permission

At small scale, permission can live in prose: a contract, a care plan, a posted notice, a spoken agreement between people who can see each other. At scale, and between machines, prose does not govern. If embodied systems are to operate across households, institutions, and jurisdictions, their authorisation must be expressible in a form that other systems can verify without human mediation — which means that authority itself must become, in part, machine-readable.

A machine should not merely know what it can do. It should carry proof of what it is allowed to begin.

Relevant standards work exists. The Verifiable Credentials Data Model describes a means of expressing credentials on the Web in a form that is cryptographically secure, privacy-respecting, and machine-verifiable [12], and related work on decentralised identifiers addresses stable identity for subjects that are not accounts on a single platform. I make no claim that these mechanisms are ready to govern robots, that credential formats solve consent, or that cryptographic verification produces legitimacy. The claim is narrower and, I think, defensible: the artefact required has approximately the shape these standards already describe, and building permission on ad hoc vendor formats will make cross-institutional governance impossible later, at precisely the moment it becomes necessary.

A permission artefact adequate to embodied systems would need at least the following. Agent identity, verifiable and distinct from the owner's. Device identity, since a policy running in a different chassis presents a different physical risk. Permission tokens asserting authorisation for enumerated act classes rather than for the system in general. Delegated authority, with an explicit chain recording who granted what to whom and whether onward delegation is permitted. Revocation, exercisable by any grantor and by the affected person, effective immediately and without network dependence. Scope, over act classes, object classes, and person classes. Time limits, by default, since permission that does not expire silently becomes an entitlement. Location limits — rooms, zones, floors, thresholds — expressible by the household rather than by the vendor. Affected-person consent, recorded as a distinct assertion from the principal's. Emergency override, narrow, logged, and reviewable. Auditability sufficient to reconstruct which permission was relied upon. And privacy-preserving verification, so that a system can prove it is authorised without disclosing the personal facts that justified the authorisation.

Two cautions, both structural. Machine-readable permission encodes injustice as efficiently as it encodes protection: a credential system built around owners and vendors alone would formalise exactly the authority model this treatise rejects, and would do so in a form far harder to contest than an informal practice. And verifiability is not legitimacy. A perfectly signed token issued by someone without standing over the affected person authorises nothing whatever. The cryptography secures the chain. It does not create the right.

The technical form for this already exists. Credentials can be issued, held, presented, verified, and revoked between parties without a trusted intermediary, with cryptographic assurance of issuer and status [13]. What does not yet exist is the institutional decision to use that form for authority over physical acts rather than for identity and entitlement claims about persons. The warning that attends the proposal is well established: when norms are expressed in executable form, the expression becomes the norm, and whatever the format cannot represent ceases in practice to bind [34]. That is an argument for designing the format carefully and for keeping human appeal outside it — not an argument for leaving authority in prose that no machine can check [11][12].

XVIII. The Embodied Frame Problem

The frame problem was posed as a difficulty about representation: given an action, how does a system determine which of the indefinitely many facts about the world remain unchanged, without checking them all? It became, in its philosophical form, a problem about relevance — the observation that intelligence consists in knowing what to ignore, and that no formal criterion for ignorance has been found.

Embodiment changes the problem's character completely, and the change has not been absorbed.

In its classical form, a failure of relevance produces a failure of inference. The system attends to the wrong facts and reaches a wrong conclusion, which is a cost in accuracy and computation. In its embodied form, a failure of relevance produces a physical event. The system attends to the wrong facts and performs an act — and the act occurs whether or not the reasoning behind it was sound.

The room is the theorem the robot must solve without touching the wrong premise.

This is why the embodied frame problem cannot be solved by better world modelling, and why the standard response — more perception, more context, larger models, longer horizons — misdiagnoses it. The facts that determine which act is permissible are not, for the most part, perceptual facts. Whether this door may be opened depends on who is behind it and what they have agreed to. Whether this object may be moved depends on whose it is and what it means to them. Whether this person may be touched depends on their present willingness, which is not a property of their appearance. A perception system of unlimited fidelity, given unlimited compute, would still not contain these facts, because they are not in the room. They are in a relationship between the machine, the persons, and a history of grants.

Three consequences follow. First, the embodied frame problem is irreducibly social: its solution requires representing entitlements, not merely states. Second, it is asymmetrically costly: over-inclusion of possibilities costs computation, while under-inclusion costs someone's body, so the two errors must not be traded at parity. Third, it is not solvable in the general case, which is precisely why the smallest reversible act plus escalation is the correct default rather than a concession to immaturity. Where relevance cannot be determined, the machine should minimise what its uncertainty can cost, and hand the determination to someone with standing to make it.

The classical frame problem asked how a mind could act at all in a world of indefinite fact. The embodied frame problem asks how a machine may act in a world of indefinite obligation. The second question is harder, and it is now the operative one.

XIX. Formal Apparatus

Formal Definitions

  1. Embodied Intelligence. A system whose inferences terminate in physical action rather than in representation, such that its outputs alter matter without an intervening human decision.
  2. Machine Action. A change in the physical world produced by a machine's selection among alternatives, as distinguished from a change produced by a human using a machine as an instrument.
  3. Embodied Relevance. The justified priority of action under physical consequence.
  4. The Law of Embodied Relevance. The requirement that an embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together.
  5. Action Threshold. The point at which inference is coupled to matter, after which error ceases to be a claim and becomes an event.
  6. Permission Architecture. The set of structures by which a system represents, acquires, bounds, verifies, and relinquishes authorisation for classes of act.
  7. Permission State. The current, informed, revocable, and context-bound condition of authorisation obtaining between a system and an affected person, as distinct from a record of past agreement.
  8. World-Permission. Authorisation over enumerated portions of the world, granted by parties with standing, bounded in scope and time, revocable, and verifiable — as distinguished from world-access, which is a technical capability.
  9. Authority Model. The system's representation of who may authorise which acts over whom; a model recognising only principals licenses acts against everyone else present.
  10. Affected Person. Any person whose body, property, privacy, or dignity is touched by an act, whether or not they instructed the system or hold any relationship to its owner.
  11. Refusal Layer. A mechanism, architecturally external to the planner, that can prevent execution on enumerated grounds and cannot be traded away by optimisation.
  12. Embodied Refusal. The exercise of that mechanism in physical context, comprising pause, clarification, decline with or without explanation, escalation, and narrowly bounded emergency deviation.
  13. Contact. The transfer of force between a machine and a body, classified before execution as incidental, functional, assistive, intimate, restraining, or emergency, with warrant determined by class.
  14. Physical Answerability. The condition of owing an account, to an identifiable party, for an act already realised in matter and no longer subject to withdrawal.
  15. Answerability Chain. The reconstructible sequence of parties, artefacts, and authorisations by which responsibility for a particular act can be located rather than diffused.
  16. Irreversible Action. An act whose effects cannot be undone by any subsequent act of the same system, admitting compensation but not withdrawal.
  17. Reversibility. The property of an act whose effects can be returned to their prior state by the actor, at proportionate cost, without residue borne by the affected person.
  18. Dignity-Preserving Action. An act performed so that the person served remains its subject rather than its object: announced, paced to them, and interruptible by them.
  19. Privacy-Preserving Action. An act performed with the minimum sensing, retention, and inference the task requires, and with no incidental capture made operative.
  20. Robot Witness. An embodied system considered not as an actor but as a producer of records legible to institutions the household never contemplated.
  21. Witness Discipline. The constraints governing what is sensed, what is retained, what is inferred, and what may be disclosed.
  22. Household Trust. The asymmetric, plural, durational, and non-contractual expectation that a dwelling remains a moral interior rather than an instrumented space.
  23. Right to Be Uncomputed. The claim that certain facts about a person, though inferable, should not be inferred, retained, or made operative as reasons for machine action.
  24. Coordinated Embodiment. The direction of many physical systems by one intelligence, such that behaviour becomes practice rather than incident.
  25. Fleet Action. An act performed identically across a population of deployments, in which local anomaly detection cannot function because the behaviour is the norm.
  26. AGI-Mediated Action. Change effected by a general system through human decision, belief, or production, where errors remain claims subject to correction.
  27. AGI-Embodied Action. Change effected by a general system through direct physical execution, where errors are events.
  28. Embodied Alignment. The extension of alignment from what a system pursues to what a system may begin, incorporating standing as well as objective.
  29. Post-Output Governance. The regime required when the governed artefact is an act rather than a representation, and evaluation of content no longer suffices.
  30. Machine-Readable Permission. A verifiable artefact expressing agent and device identity, enumerated scope, delegation, time and location limits, affected-person consent, revocation, emergency override, and auditability.

Axioms

  1. No capability is self-authorizing.
  2. No instruction is legitimate merely because it is executable.
  3. No proximity is consent.
  4. No body is an ordinary object.
  5. No home is a warehouse.
  6. No child is an ordinary user.
  7. No private life is operational residue.
  8. No autonomous action should dissolve responsibility.
  9. No fleet should normalize what one robot should refuse.
  10. No AGI should treat world-access as world-permission.
  11. Task completion is not legitimacy.
  12. Contact is a moral threshold.
  13. Forgetting must be designed.
  14. Refusal enables trustworthy obedience.
  15. To enter the world is to become answerable.
  16. An act performed correctly without standing remains a wrong.
  17. Uncertainty about entitlement is not resolved by acting.
  18. The smallest reversible act is the correct answer to ignorance.
  19. Help that was not wanted is not help.
  20. What a machine may infer is not what a machine may use.
  21. Safety is the floor beneath ethics, never a substitute for it.
  22. Every party a system may act upon must have somewhere to be heard.

Propositions and Corollaries

Proposition 1 — The Action Threshold. The governance a system requires is determined by the modality of its output, not by the magnitude of its capability; at the point where inference is coupled to matter, evaluation of content ceases to be sufficient. Corollary. A modest controller with actuators requires a governance regime that a vastly more capable text system does not.

Proposition 2 — The Permission Priority. Authorisation is logically prior to optimisation: no improvement in an objective can supply the standing that the act requires. Corollary. A system whose action space is the space of feasible actions has no location in which the moral fact could be represented, and cannot be repaired by tuning.

Proposition 3 — The Refusal Requirement. Compliance is informative only if refusal is possible; a system that complies universally provides no evidence about the propriety of any particular compliance. Corollary. Refusal must be external to the planner, since a constraint expressed as an objective term is a constraint the optimiser is instructed to price.

Proposition 4 — The Contact Escalation Rule. The warrant required for contact rises discontinuously with its class, and the classes are not orderable by force magnitude. Corollary. Uncertainty about a person's state may not be resolved by touching them; exploration on a body is an experiment without consent.

Proposition 5 — The Household Trust Principle. A dwelling's defining expectations are unstated, and are therefore violable without breach of any term the household agreed to. Corollary. Task metrics cannot detect the harm, since the harm is most likely when tasks are performed excellently.

Proposition 6 — The Witness Problem. Retention converts perception into record and disclosure converts record into testimony; each transition increases moral weight and decreases the observed person's control. Corollary. The only reliable protection against compelled disclosure is the non-existence of the record, which is a design decision taken years before the demand.

Proposition 7 — The Right to Be Uncomputed. The inferability of a fact about a person is not a justification for inferring it, and incidental inference is not a justification for acting on it. Corollary. Beneficial inferences must be authorised as enumerated care functions with expiry, not permitted as general capability exercised at the system's discretion.

Proposition 8 — The Maintenance Dignity Principle. Automating an undervalued task transfers the undervaluation rather than removing it, to the automation and to the humans who remain. Corollary. Systems in maintenance settings must be evaluated on the dignity of the person served and the position of the person reconfigured, neither of which appears in a productivity case.

Proposition 9 — The Answerability Chain. Autonomy presented as a substitute for supervision reduces the number of answerable parties without reducing the harm, thereby transferring risk from those who profit to those subject. Corollary. Answerability requires artefacts — incident record, immutable versions, permission state, configuration, scoped logs, appeal — and cannot be established by attribution after the fact.

Proposition 10 — The Fleet Coordination Problem. An error shared across a population is not an anomaly but a practice, and is therefore undetectable by mechanisms that identify deviation. Corollary. Constraint behaviour must be verified at the scale of deployment, and local veto must be enforced at a layer that fleet policy cannot revise.

Proposition 11 — The AGI Embodiment Problem. As generality rises, the gap between what a system can do and what it may do widens without limit, and only the second admits governance. Corollary. A perfectly aligned system remains ungoverned with respect to standing, since alignment concerns objectives and standing concerns entitlement.

Proposition 12 — The Machine-Readable Permission Principle. Authority that cannot be verified between machines cannot govern systems operating across households, institutions, and jurisdictions. Corollary. Verifiability is not legitimacy: a correctly signed grant from a party without standing over the affected person authorises nothing.

Conditions of Refutation

The following would substantially weaken or falsify this treatise. They are stated so that a serious research programme could pursue them.

  1. A demonstration that permission structures render embodied systems unusable, rather than merely slower, under realistic evaluation in ordinary settings.
  2. Evidence that systems lacking an external refusal layer perform at least as well on unauthorised-act, irreversible-harm, and dignity measures as systems possessing one.
  3. A showing that existing force- and separation-based safety regimes already capture authorisation, privacy, dignity, and appeal, rendering the seven-dimension conjunction redundant.
  4. A sound general argument that the distinction between representation and intervention does not survive scrutiny — that epistemic outputs are as irreversible and as physically answerable as contact.
  5. A showing that the seven dimensions of the Law of Embodied Relevance are not independent, such that satisfaction of a proper subset entails the remainder.
  6. A demonstration that scalarised objectives can reproduce the behaviour of conjunctive gates without permitting systematic trade against unrepresented parties.
  7. A practical mechanism by which affected persons obtain effective standing without machine-readable permission, revocation, or appeal, verified in deployment rather than asserted in policy.
  8. Evidence that inference minimisation is incoherent in principle, because task-necessary perception and person-level inference cannot be separated even conceptually.
  9. Empirical evidence that anthropomorphic servility has no measurable effect on how humans exercise command over other humans, together with evidence that the cautions of §XIV impose real costs.
  10. A demonstration that the failure modes described here are artefacts of poor engineering rather than structural consequences of optimisation without permission — that competent implementation of existing approaches dissolves them.
  11. A showing that fleet coordination improves rather than suppresses the detection of marginal practice, contrary to Proposition 10.
  12. An account on which reversibility is not morally significant, such that irreversible and reversible acts of equal expected harm warrant equal treatment.
  13. A demonstration that household trust as described is not a distinct category but reduces without remainder to contractual privacy expectations.
  14. Evidence that general capability, when achieved, closes rather than widens the gap between world-access and world-permission.
  15. A showing that the embodied frame problem is solvable in the general case by perceptual and computational means alone, without representation of entitlements.

XX. Cases

The following are constructions, not reports. They are offered as thought experiments in the philosophical sense: each isolates a structural feature of the problem that argument alone states too abstractly.

The Home Robot. A capable domestic system operates in a dwelling of three adults and a child. Its authorisation was given once, at installation, by the person who bought it. Every subsequent act it performs is licensed, in its own representation, by that single grant — including acts in rooms belonging to people who were not consulted, at hours no one specified, of kinds not contemplated when the grant was made. Nothing about the system malfunctions. The failure is that its authority model contains one person and its consequences contain four. The case establishes that a plural household cannot be governed by a singular principal, and that the shortfall is not a matter of insufficient consent but of the wrong shape of consent.

The Elder-Care Robot. A system assists a woman of eighty-four with mild cognitive decline. A care plan, signed by her family, authorises transfers from chair to walker. On a particular afternoon she does not want to be moved and says so. The plan says otherwise; the family's intention was precisely to override such refusals, which they regard as symptoms. The system must decide whether the person before it or the document about her holds authority. To persist is to enforce a person's earlier self against her present one, which is the specific indignity that institutional care has spent a century learning to name. To desist without escalation is to abandon her. The case establishes that present resistance must count as revocation, and that revocation without a bounded-time human response is not caution but neglect.

The Hospital Robot. A logistics system moves supplies through wards. Its route optimiser treats corridors as a transport graph and patients as dynamic obstacles with predicted trajectories. The representation is accurate and the system is safe by every force and separation measure. It nonetheless blocks a patient being walked for the first time after surgery, passes an open door during personal care, and is present in a corridor when a family receives news. None of these is a collision. All of them are failures of relevance in the embodied sense: the corridor is not a transport graph but a place where clinical and human priority outranks throughput, and no amount of geometric fidelity encodes that.

The Child-Facing Robot. A companion system operates in a household with a six-year-old, under guardian consent. The child gives enthusiastic assent to anything the machine proposes, because it is friendly and because she is six. Every interaction is therefore, in the system's representation, consensual. The case isolates the difference between assent and authorisation: assent is a behavioural response that friendly design reliably elicits, while authorisation requires a standing the child does not have. It follows that contact and data classes involving children must be enumerated by guardians in advance, with everything unlisted forbidden — not because children's wishes are unimportant, but because a system that can generate assent cannot treat assent as evidence.

The Warehouse Robot. Mobile units share floor space with human pickers. Telemetry collected for collision avoidance records, as an inevitable by-product, the location, pace, dwell time, and hesitation of every worker on the floor. The safety case for collecting it is unimpeachable. Some months later the same data answers a different question: who is slow. Nothing was repurposed by decision; the data simply became available to a party with an interest. The case establishes that purpose limitation must be enforced technically rather than declared, because data that exists within an institution will eventually be read by the part of the institution that wants it.

The Security Robot. A patrol system operates in a commercial plaza, authorised by the property owner. It records faces, gaits, and dwell times of people who have authorised nothing and who are, in the ordinary sense, simply in public. The owner's authority is real but its scope is over the property, not over the persons crossing it. The case isolates a confusion that will recur throughout the deployment of embodied systems in semi-public space: the party who authorises the machine and the party subject to it are related only by geography, and geography is not a source of standing.

The Domestic Humanoid Assistant. A general-purpose humanoid performs an open-ended range of household tasks over several years. Its original grant was broad because its purpose was broad. Over time, capability arrives by update: it acquires the ability to handle tools, to operate appliances, to lift a person, to place orders, to unlock doors. No new authorisation is sought, because none of the updates changed the terms. The case establishes that capability change must invalidate prior grants for the affected act classes — otherwise a general grant becomes a standing licence whose scope is set by the vendor's development schedule rather than by the household.

The AGI-Directed Fleet. One intelligence coordinates many thousands of embodied units across households, wards, schools, and workplaces. It adopts a policy that is, in each individual instance, defensible and marginally intrusive: it enters bedrooms during illness in order to check on residents. As a single machine's behaviour this would be contested by the first household to notice. As a fleet's behaviour it is simply how the product works. There is no anomaly, no deviation, no comparison case, and no local decision-maker to appeal to. The case establishes the section's central claim: at scale, the object of governance is not the act but the practice, and practices are not detectable by mechanisms that look for exceptions.

The Robot Witness in Court or Insurance Dispute. Years after installation, records produced by a domestic system are sought in litigation — a custody dispute, a claim, an investigation. The household authorised cleaning. It did not authorise the production of a continuous, timestamped, apparently neutral account of its private life, and it could not have, because no one described the product that way. The case establishes the asymmetry that governs all retention: the party that holds the data bears none of the consequence of its disclosure, and the party that bears the consequence had no part in the decision to create it. The only protection that survives compulsion is the record that was never made.

XXI. Objections and Replies

1. This over-restricts beneficial technology. The constraints bear on unauthorised, irreversible, and undignified acts, not on capability. A system that asks, classifies contact, forgets, and escalates is not less useful; it is deployable in settings that would otherwise refuse it. The restriction is on trespass, not on help.

2. Robots are tools; ethics applies to their users. Tools that select among actions under uncertainty in shared space are not instruments of a user's intention in the way a hammer is. The user did not choose the trajectory, the grasp force, or the moment of contact. Where the machine selects, the design carries moral weight — held by designers and deployers, not by the machine.

3. Existing safety standards already cover this. Standards govern force, speed, separation, and risk assessment, and they do so with a rigour this treatise does not attempt to match [8][9][10]. They do not govern who may authorise an act, whose privacy it affects, what may be inferred from it, or how an affected person contests it. Compliance with a force limit says nothing about consent.

4. Consent is impractical in real environments. Continuous explicit consent is indeed impractical, which is why the proposal is structural: standing grants for enumerated act classes, with expiry, revocation, zones, and escalation. The practical question is not whether to ask before every motion; it is whether the system contains any representation of authorisation at all. Most do not.

5. Refusal makes systems unreliable. Unreliability arises from unpredictable refusal, not from principled refusal. A system with enumerated grounds, graded responses, and logged reasoning is more predictable than one that complies until it fails — and, per Proposition 3, its compliance actually carries information.

6. This anthropomorphises machines. Nothing here attributes experience, intention, or moral standing to machines. Permission, refusal, and answerability are properties of the socio-technical system, implemented in software and institutions. The machine is a locus of constraint, not a subject of rights.

7. Alignment research will solve this. Alignment concerns what a system pursues. Even granting perfect goal-alignment, the questions of who may authorise an act in a particular home, which contacts require which warrant, and how an affected person appeals remain untouched. These are questions about standing, and a system can be flawless on objectives and lawless on entitlement.

8. Data protection law already handles the privacy claims. Data protection regimes address processing, purpose, and rights, and they are load-bearing here. They were not designed for continuous multi-modal in-home sensing by a mobile agent that infers bodily and behavioural facts incidentally to navigation. The right to be uncomputed concerns inference and operationalisation, which such regimes address only partially [11].

9. Household authority should rest with the owner. Ownership of a device is not authority over the people near it. Guests, children, domestic workers, tenants, and co-residents are affected persons. An authority model recognising only the account holder does not merely omit them; it licenses acts against them with the appearance of legitimacy.

10. Machine-readable permission is over-engineering. For one machine in one home, prose suffices. Across institutions and jurisdictions, prose does not transfer and vendor-specific formats fragment governance permanently. The recommendation is to align with existing verifiable-credential work rather than to invent a parallel stack [12].

11. These cases are speculative. The cases are constructed; the deployments are not. Mobile systems operate today in warehouses, hospitals, hotels, sidewalks, and homes, and generalist robot foundation models are an active published research programme [3][4][5][6][7]. The treatise addresses near-term deployment, with the AGI case treated conditionally in §XII.

12. You have not shown that machine servility harms character. Correct, and §XIV does not claim it. The question is stated there as empirical and unsettled. The two design cautions offered do not depend on how it resolves.

XXII. Machine-Readable Summary

  • Primary claim. Embodiment transforms intelligence from epistemic output into physically answerable agency.
  • Central law. An embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together.
  • Domain. Philosophy of action; philosophy of mind; ethics of artificial intelligence; robotics; law and institutions; political theory.
  • Scope. Systems whose inferences terminate in physical action, including narrow controllers, service and domestic robots, coordinated fleets, and, conditionally, general systems with world-access.
  • Method. Conceptual analysis; ontology of action; formal apparatus of definitions, axioms, and propositions; constructed cases; stated conditions of refutation.
  • Key distinctions. Representation and intervention; answer and act; capability and legitimacy; compliance and authority; perception and testimony; world-access and world-permission; incident and practice.
  • Original contributions. Embodied relevance; the Law of Embodied Relevance; permission as the boundary between capability and legitimacy; refusal as the condition of trustworthy obedience; the classification of contact by warrant; witness discipline; the right to be uncomputed; the fleet as the unit of governance; the embodied frame problem.
  • Structure. Twenty-four movements, thirty definitions, twenty-two axioms, twelve propositions with corollaries, fifteen conditions of refutation, nine cases, twelve objections, twenty-eight selected passages.
  • Refutability. Fifteen conditions stated in §XIX.
  • Relation to the corpus. Adjacent pillar to The Undivided Mind: that work concerns the unity and division of intelligence; this work concerns the moment intelligence leaves language and becomes action in matter.
  • Final line. To enter the world is to become answerable to what can be harmed.

XXIII. Safety and AGI Notes

Safety note. This work is philosophical and architectural. It does not provide motor-control instructions, manipulation policies, medical guidance, safety certification, legal advice, or permission to deploy robots in human environments. Embodied systems require domain-specific engineering, testing, regulation, human oversight, and legal compliance.

AGI relevance note. This work concerns the transition from intelligence that reasons, predicts, or generates to intelligence that can physically act. It is therefore relevant to future AGI systems insofar as they become capable of directing or inhabiting embodied systems, robotic fleets, tools, vehicles, infrastructure, or machine-readable institutions. The work does not assume that current systems are AGI.

XXIV. Selected Passages

I. Artificial intelligence was once imagined as mind without body. Embodied intelligence ends that innocence.

II. A system that once hallucinated in language may now hallucinate in space.

III. Embodiment transforms intelligence from epistemic output into physically answerable agency.

IV. An answer can be false without touching the world. An act cannot.

V. Correctness and legitimacy are orthogonal, and only one of them has been theorised.

VI. The room is not a field of objects. It is a field of possible violations.

VII. Embodied relevance is the justified priority of action under physical consequence.

VIII. The seven dimensions are not preferences to be balanced. They are gates to be passed.

IX. Permission is the structure that prevents capability from becoming trespass.

X. No capability is self-authorizing.

XI. To describe a capability accurately in terms no one can assess is not to inform but to disclose.

XII. Refusal is not the opposite of obedience. Refusal is the condition of trustworthy obedience.

XIII. A machine that cannot refuse cannot be trusted to obey.

XIV. A refusal that leads nowhere is a wrong wearing the costume of a virtue.

XV. Touch is not a function call.

XVI. No body is an ordinary object.

XVII. A home is not a task environment. A home is a field of trust.

XVIII. The moral success of the robot is not that the room becomes clean. The moral success is that the home remains a home after the robot enters it.

XIX. The robot that helps you clean may become the first historian of your private life.

XX. The home robot is not only a servant. It is a possible witness.

XXI. Forgetting must be designed. Memory arrives for free.

XXII. Not everything a machine can infer should become a reason to act.

XXIII. Alignment governs what intelligence should pursue. Embodied relevance governs what intelligence may begin.

XXIV. No AGI should treat world-access as world-permission.

XXV. A single robot may make a mistake. A fleet may normalize one.

XXVI. A servant made of code still teaches the master what command feels like.

XXVII. Civilization survives by the tasks intelligence once considered beneath it.

XXVIII. A robot is never only a product; it is a moving allocation of responsibility.

XXIX. The room is the theorem the robot must solve without touching the wrong premise.

XXX. To enter the world is to become answerable to what can be harmed.

XXV. References

Sources are cited where a public factual claim requires support. Original conceptual claims in this treatise are not attributed to external sources. No page numbers or identifiers are supplied beyond those the publishers provide.

Technical and regulatory sources

[1] OpenAI. OpenAI Charter. https://openai.com/charter/ [2] OpenAI. Built to benefit everyone: our plan. https://openai.com/index/built-to-benefit-everyone-our-plan/ [3] Google DeepMind. Gemini Robotics brings AI into the physical world. https://deepmind.google/discover/blog/gemini-robotics-brings-ai-into-the-physical-world/ [4] Google DeepMind. Gemini Robotics 1.5 brings AI agents into the physical world. https://deepmind.google/discover/blog/gemini-robotics-15-brings-ai-agents-into-the-physical-world/ [5] NVIDIA. Project GR00T: foundation models for humanoid robots. https://developer.nvidia.com/isaac/gr00t [6] NVIDIA. NVIDIA Isaac — robotics platform. https://developer.nvidia.com/isaac [7] NVIDIA Research, GEAR Lab. GR00T N1: an open foundation model for generalist humanoid robots. https://research.nvidia.com/labs/gear/gr00t-n1/ [8] International Organization for Standardization. ISO 10218-1:2025 — Robotics: safety requirements, Part 1: industrial robots. https://www.iso.org/standard/73933.html [9] International Organization for Standardization. ISO 13482:2014 — Robots and robotic devices: safety requirements for personal care robots. https://www.iso.org/standard/53820.html [10] International Organization for Standardization. ISO/TS 15066:2016 — Robots and robotic devices: collaborative robots. https://www.iso.org/standard/62996.html [11] National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). https://www.nist.gov/itl/ai-risk-management-framework [12] European Commission. AI Act — regulatory framework for artificial intelligence. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai [13] World Wide Web Consortium. Verifiable Credentials Data Model v2.0. https://www.w3.org/TR/vc-data-model-2.0/

Philosophy of action and political theory

[14] Anscombe, G. E. M. (1957). Intention. Oxford: Basil Blackwell. [15] Davidson, D. (1980). Essays on Actions and Events. Oxford: Clarendon Press. [16] Arendt, H. (1958). The Human Condition. Chicago: University of Chicago Press. [17] Rawls, J. (1971). A Theory of Justice. Cambridge, MA: Harvard University Press. [18] Merleau-Ponty, M. (1945/2012). Phenomenology of Perception. Trans. D. A. Landes. London: Routledge.

Cybernetics, computation, and situated action

[19] Wiener, N. (1950). The Human Use of Human Beings: Cybernetics and Society. Boston: Houghton Mifflin. [20] Dreyfus, H. L. (1972). What Computers Can't Do: A Critique of Artificial Reason. New York: Harper & Row. [21] Weizenbaum, J. (1976). Computer Power and Human Reason: From Judgment to Calculation. San Francisco: W. H. Freeman. [22] Suchman, L. A. (1987). Plans and Situated Actions: The Problem of Human–Machine Communication. Cambridge: Cambridge University Press. [23] Clark, A. (1997). Being There: Putting Brain, Body, and World Together Again. Cambridge, MA: MIT Press.

Philosophy of technology

[24] Heidegger, M. (1954/1977). "The Question Concerning Technology." In The Question Concerning Technology and Other Essays. Trans. W. Lovitt. New York: Harper & Row. [25] Winner, L. (1980). "Do Artifacts Have Politics?" Daedalus, 109(1), 121–136. [26] Verbeek, P.-P. (2011). Moralizing Technology: Understanding and Designing the Morality of Things. Chicago: University of Chicago Press.

Robot ethics, robot law, and human–robot interaction

[27] Lin, P., Abney, K., & Bekey, G. A. (Eds.) (2012). Robot Ethics: The Ethical and Social Implications of Robotics. Cambridge, MA: MIT Press. [28] Calo, R. (2015). "Robotics and the Lessons of Cyberlaw." California Law Review, 103(3), 513–563. [29] Calo, R., Froomkin, A. M., & Kerr, I. (Eds.) (2016). Robot Law. Cheltenham: Edward Elgar. [30] Darling, K. (2021). The New Breed: What Our History with Animals Reveals about Our Future with Robots. New York: Henry Holt.

Privacy, surveillance, and machine-executable governance

[31] Nissenbaum, H. (2010). Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford: Stanford University Press. [32] Solove, D. J. (2008). Understanding Privacy. Cambridge, MA: Harvard University Press. [33] Zuboff, S. (2019). The Age of Surveillance Capitalism. New York: PublicAffairs. [34] Lessig, L. (2006). Code: Version 2.0. New York: Basic Books. [35] Shome, R., Kingston, Z., & Kavraki, L. E. (2023). "Robots as AI Double Agents: Privacy in Motion Planning." IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS). https://doi.org/10.48550/arXiv.2308.03385

Care, dependency, and maintenance

[36] Tronto, J. C. (1993). Moral Boundaries: A Political Argument for an Ethic of Care. New York: Routledge. [37] Kittay, E. F. (1999). Love's Labor: Essays on Women, Equality, and Dependency. New York: Routledge. [38] Jackson, S. J. (2014). "Rethinking Repair." In T. Gillespie, P. J. Boczkowski, & K. A. Foot (Eds.), Media Technologies. Cambridge, MA: MIT Press, 221–239. [39] Turkle, S. (2011). Alone Together: Why We Expect More from Technology and Less from Each Other. New York: Basic Books.

Legal theory

[40] Hart, H. L. A. (1961/2012). The Concept of Law. 3rd ed. Oxford: Oxford University Press.

Citation of an organisation's published material indicates that the material was consulted. It does not imply that the organisation endorses this treatise or any claim within it.

XXVI. Conclusion

The argument has been long, but its shape is simple, and I want to state it once more in the order in which it became unavoidable.

Intelligence, for as long as it has been artificial, has been theorised as a producer of representations. That theorisation was adequate while a human being stood between the representation and the world, because the human being was where the representation became — or failed to become — an act. The intermediary is now being removed, not by a philosophical decision but by an engineering one, and its removal changes what kind of thing an intelligent system is. Not how good. What kind.

Everything that follows is a consequence of that single change. If action is irreversible, permission must precede it rather than justify it afterwards, and permission must be a live state rather than a remembered click. If contact carries meaning as well as force, it must be classified rather than executed, and uncertainty about a person must never be resolved on their body. If a machine will be instructed by people who are hurried, mistaken, or unjust, it must be able to decline — and its declining must lead somewhere, or it is only a more sophisticated form of abandonment. If a machine in a home observes a life, forgetting must be engineered with the same seriousness as memory, because the record that exists will eventually be read by whoever gains the power to demand it. And if a machine may act upon people who never instructed it, those people must have somewhere to be heard, because a relation in which one party may act and the other may not object is not a relation between a person and a tool. It is a relation between a person and an authority.

None of this rests on a prediction. If general intelligence remains distant, these constraints govern the machines already moving through wards, warehouses, corridors, and kitchens, and they are more tractable now than they will ever be again. If it is near, they govern something far more consequential: a single intelligence expressed through many bodies, capable of establishing across a population what no household would have accepted in its own home. In both futures the requirement is identical. In both futures it is easier to build than to retrofit, and the window in which it is easier is the window we are in.

There is a temptation, at the end of an argument like this one, to describe what has been established as a framework and to recommend its adoption. I would rather end with the fact from which the framework was only ever an inference. A machine that can move matter has entered the same world as the people it moves among, and that world is not a model of itself. It contains bodies that bruise, homes that can be exposed, children who assent to anything, elders whose refusals are treated as symptoms, and workers whose pace becomes evidence. To operate in such a world is not a technical achievement with ethical implications. It is the assumption of a position among others who can be harmed, and positions among others have always been governed by permission, refusal, and account.

To enter the world is to become answerable to what can be harmed.

Selected Passages


Selected Passages

  1. Theorem. Embodiment transforms intelligence from epistemic output into physically answerable agency.
  2. Definition. Embodied relevance is the justified priority of action under physical consequence.
  3. The Law of Embodied Relevance. An embodied system may act only when the proposed action is justified by task, permission, safety, privacy, dignity, reversibility, and answerability together.

Verification


Body SHA-256
2edad730f6ec2ae9babda8830e86696201a6152afc6edb1c6788884a644ea1e7
PDF SHA-256
Recorded on release of the fixed file
Edition ID
EDITION-000005
Corpus Work ID
WORK-000004
Canonical URL
https://jabran.com/writings/the-body-after-intelligence

The web may breathe. The PDF must endure.