The principles, the two kinds they come in, and the three questions they fold into
A cardiologist once explained to me how she survives the flood of information in an emergency. “Machines give me forty numbers,” she said. “I have three questions. The questions tell me which numbers matter.”
Keep her in mind. By the end of this article you will have nineteen principles, and I will have to do for you what she does for herself: fold them, without losing them, into what a person can hold in one hand.
Start with the vendor. The deck says the product “respects human dignity” and is “human-centred by design”. You nod; everyone nods. Now ask the only question that matters: what would it take to find them wrong?
If nothing would — if no system, however built, could ever be shown to contradict the claim — then the claim is not a principle. It is a mood, and moods are not checkable. The nineteen principles I am about to show you were written to pass that test. Each one is anchored to specific paragraphs of the letter, re-expressed in design language, and phrased so that somebody can come back later and say: here is the paragraph, and here is where your system contradicts it.
That is also why I give them codes. A code is not bureaucracy; it is a handle. You cannot argue about “dignity” for long before the word dissolves. You can argue about F1 all afternoon, because F1 says one thing, rests on four paragraphs, and either holds of a system or does not.
The load-bearing wall of the whole Register is a distinction, and the first character of each code carries it.
F-principles are foundational. There are seven, and they are borrowed from a tradition much older than computing — the Church’s social teaching, which has been thinking about persons and power since a pope named Leo wrote about factories in 1891. They do not mention software. They tell you why anything about software matters.
F1 — Ontological dignity, independent of performance (§§50–53). Worth is constitutive, never earned. A system that scores worth has failed before it starts.
F2 — The common good as the measure of system purpose (§§59–63, 96). What a system optimises must serve shared flourishing; adding up private interests does not produce it.
F3 — Universal destination of digital goods (§§65–67, 108, 178). Patents, algorithms, platforms and data are among the goods destined for all; data is the product of many and cannot be the asset of a few.
F4 — Subsidiarity (§§68–72). Decisions belong at the level closest to the people they affect — and in the digital order the “higher level” is no longer the State but the platform.
F5 — Solidarity, including with the invisible (§§73–76, 109, 173). The woman labelling images in Nairobi, the moderator, the river cooling the servers: all inside the boundary.
F6 — Justice as a design precondition, not a post-deployment correction (§§77–80, 161). Exclusion is prevented on the drawing board or it is not prevented; afterwards it has another name, remedy, and remedy is dearer.
F7 — Integral human development as the decisive test (§§82–85, 129). The question that outranks every other: does it make life more human?
P-principles are operative. There are twelve, and they are the letter’s direct reply to this technology — what it says about AI itself. They tell you where the foundations bite.
P1 — Anthropological non-equivalence (§§99, 198). An agent imitates functions; it is not a person, and no design may insinuate otherwise.
P2 — Non-neutrality of design (§§9, 104, 111). Every artefact embeds choices; design is a moral act with an author.
P3 — Human accountability, identifiable end to end (§§102–105, 199). For every consequential output, an identifiable human answers.
P4 — Non-delegation of irreversible judgment (§§197–200). What cannot be undone is not handed to an automated process.
P5 — Traceability and contestability (§§105, 164, 171, 200). Decisions reconstructable, understandable, open to challenge.
P6 — Discussable normativity (§107). The ethics embedded in a system must be inspectable and debatable — its rules need answerable authors too.
P7 — The person strengthened, not replaced (§§114, 150, 156). Machines serve human judgment, not the reverse.
P8 — Embedded limits and the legitimacy of non-use (§§118–120, 140). Limits live in the structure, not in a settings page; knowing when not to use AI is wisdom, not backwardness.
P9 — Truth and non-manipulation (§§132, 137, 171). No deception; selection and ranking are transparent.
P10 — No exploitation of human fragility (§§141–142, 170). No business model that prospers on what is weakest in a person; minors protected absolutely.
P11 — Justice across the supply chain (§§173, 179). No system is clean if the chain that feeds it is dirty.
P12 — Care for the common home (§§84, 101). The energy, water and materials a system burns are part of its moral ledger.
Two notes before you object. First, the line after each code is a gloss, not the principle; the principle is the formal entry in the Register, with its paragraphs. Second, several of these are stated in the letter in the language of faith — F1’s dignity has a giver; F5’s fraternity has a Father. I flag that wherever it occurs and proceed on the shared ground the letter itself offers: you do not have to accept the foundation to check whether the structure stands.
Why does the F/P distinction matter so much that I call it load-bearing?
Because it is the difference between a constitution and ordinary law. A constitution does not regulate traffic. But every traffic rule can be tested against it, and when a rule fails the test, it is the rule that goes. The seven F-principles are Neemia’s constitution: they say what a person is and what power owes her. The twelve P-principles are the articles that apply that to machines that act. And — this is the point — when you reach the criteria, in two weeks, every one of them will name the principle it descends from, and through it the paragraph. Pull any thread and you arrive at the letter.
Take one thread now, to see it hold. F1 says worth is independent of performance. Apply it to a hiring system that scores CVs. The question is not whether the score is accurate. The question is whether a score of 6.4 is allowed to mean anything about the person — and F1 says it is not: the proxy may rank forms, it may never rank worth. One sentence, and a whole class of product has just been ruled out of bounds, or required to keep a human able to overrule the number and make overruling part of the job.
Nobody carries nineteen principles into a meeting. So here is what the book does with them, and what the Tester runs.
Who answers? The accountability question. It gathers F4, P3, P5, P6 and P9 — because an unanswerable system and a deceptive one are cousins; both hide the human behind the machine. Its probes: name one person who accounts for what this system does to me; reconstruct one decision; show me the door my challenge goes through; let me read the rules.
Does it strengthen the person? The anthropological question. F1, F7, P1, P7, P10. Its probes: where this measures people, does anyone remember what the score is a proxy for? After a season with it, are its users stronger or only faster? Does its business model profit from my flourishing or from my inability to stop? Does it say what it is, everywhere, always?
Where does it stop? The limits question. P2, P4, P8. Its probes: which actions cannot be undone, and does an effective human decision stand in front of each? Do the gravest limits live in the architecture or in a setting a busy afternoon can flip? Can its makers name the contexts where it refuses to operate at all?
Six principles stand deliberately outside the fold — F2, F3, F5, F6, P11, P12 — because they cannot be asked of a system in a demo. They must be asked of the organisation behind it: whom was this built for, who shares in what it concentrates, who carried its hidden costs, what does it burn. That is the second conversation, the one you have not with the product but with its maker, its buyer, its investor.
Ask the three in sequence, because they are ordered by urgency. A system with no answerer is disqualified before its features matter. A system with an answerer that weakens its users is a bad bargain dressed as a service. A system that answers, strengthens, and cannot say where it stops is a good servant waiting to become an accident.
Here is where I stand. A principle you cannot be found wrong against is not a principle. All nineteen of these were written so that you can find me wrong — paragraph in hand — and so that you can find a system wrong, evidence in hand. That is the whole difference between a Register and a manifesto.
And ask the three questions in plain words. They lose nothing in translation: Chi risponde? Ti rende più forte? Dove si ferma? They work at a school board, in a procurement review, at dinner. The vendor who answers two of three has told you exactly where to press. The one who answers none has told you everything.
— Maurizio
When the Machine Is Not Enough — a season of six letters on building AI agents that respect the people they touch. The book is Neemia: Guarding Human Dignity in the Age of AI Agents, on Amazon. The Tester reads your agent in ten minutes, free: try.neemia.org.
If you want to take part — as a builder, an assessor, a critic, a pilot participant — reply to this email. I read everything, and I answer.
Maurizio Grassi
When the Machine Is Not Enough arrives by email every second Monday.