Download PDF Sign the pledge
First edition · September 2026

A Code of Conduct
for AI in the Home

Rules of the road for safe, private, and human-controlled AI in the most personal space we have.

Josh, reasoning
Reading your request
Preface Architecture Authority Stack The rules Integrator The long view Standards Foundations The pledge
01 · Preface

AI is coming home. It should always be yours to control.

The home belongs to the people who live there. Any intelligence inside it must remain under their control.

Artificial intelligence in a browser can write, search, and advise. Artificial intelligence in a home can reach the physical world. It can change the lights and the climate, open or secure a door, watch a camera, run the water, and coordinate the systems that shape comfort, privacy, and safety. That physical reach changes the responsibility of the companies building it. A wrong answer is one thing. A wrong physical action is another.

For more than a decade, Josh.ai has been building AI for the home. We have seen firsthand both the promise of bringing intelligence into the home and the responsibility that comes with it. We have always built by these principles. Now, as AI becomes more capable and more widely adopted, we believe it is time to state them openly and hold the whole industry to them.

Josh is not an AI bolted onto a house. It is a home control system with AI inside it, so the intelligence always answers to a layer that enforces your rules. Doing this well does not require racing to build ever larger models. It requires disciplined engineering around the capable models that already exist.

The right question is no longer only "what can the AI do?" It is also: who authorized it, what limits it, what can stop it, what data did it use, and what happens when it is wrong? Our answer is simple. Home AI should be powerful, but never sovereign. Helpful without becoming opaque, proactive without becoming presumptuous, personal without becoming invasive, and intelligent without becoming uncontrollable.

This is a voluntary code for any AI that can observe, reason about, recommend, automate, or control connected systems in a home. It sets a deliberately high bar, one that no product on the market fully meets today, ours included, because its purpose is to define where the industry needs to go. We hold ourselves to it first, and we intend to continue to lead the field there.

02 · Why the home is different

General AI principles are not enough. The home needs its own guidance, because it adds physical action, deeply personal context, shared authority, and real-world consequences.

Actions have physical consequences.

The home AI may interpret a request, but the result can move a motor, unlock a door, or shut off water. Safety cannot end at a good answer. It has to carry through to who is allowed to act, what actually happens, and whether it can be undone.

The home is deeply personal.

A home reveals who is present, when people sleep, which rooms they use, what they watch, and how routines change. The home AI can infer more than any single sensor records. Privacy has to be built into the architecture, not just promised in a privacy policy.

The home is shared.

Most AI is built around a single account holder. Homes are not. They hold partners, children, guests, caregivers, and installers. One person's request can affect everyone else, so the people in a home need roles and a hierarchy the home respects, not just a login.

The home has to keep working.

Lights, climate, access, and basic control should not become unusable because the cloud is unreachable. The cloud adds real value, but core home functions should degrade gracefully, and local control should keep working whenever it can.

Elegant laws are not enough. In 1942 the science fiction author Isaac Asimov wrote the three laws of robotics, then spent decades showing how simple rules collide. Home AI needs the engineering mechanisms behind the principles.
03 · A safer architecture

The AI does not control the home. A separate control system does, and the AI answers to it.

This is the heart of it, and what makes Josh different from a general-purpose assistant. The home AI should not be the control system. It is one intelligent component inside a control system with deterministic boundaries: a separate policy and permission engine decides whether a proposed action is allowed before any device command is issued.

The home AI reasons
It interprets what you want and can suggest, but it never operates a device itself.
The control system decides
It checks the request against your permissions, the risk, and the scope before anything can happen.
The home acts
Only what was allowed is carried out, locally wherever it can be.
Every physical action passes through the control system before it reaches a device.
Human controls and household rules sit above the AI and set what the control system enforces: permissions, roles, and the stop and disable controls.
A privacy gateway, separate from the home AI, minimizes and de-identifies whatever leaves the home, so cloud services learn as little as possible about your household.

Where does the intelligence live?

The home keeps what is personal close, and reaches out only where it helps.
In your home
  • Fast
  • Private
  • Always available
  • Works offline
Your home decides
  • Keeps personal data local
  • Sends only what is needed
  • Stays under your control
In the cloud
  • Large models
  • Broad knowledge
  • Heavy reasoning
Local where it matters. Cloud where it helps. You draw the line.

A general-purpose assistant is just AI; it is not the control system. The system that runs your home should be both, so the intelligence always answers to something that enforces your rules. It is also why home AI does not require frontier models: a home needs specific, bounded, useful things, not a system that can do anything.

04 · The Home Authority Stack

Separate the intelligence from the permission.

The home AI can be brilliant without being allowed to do everything it can imagine. Permission flows downward through a hierarchy, and the home AI only ever acts inside the intersection of every layer above it. This is what turns "the AI is contained" from a promise into a mechanism.

1
Non-negotiable safety and security constraints
Cannot be overridden by a person, installer, model, or third party.
2
Household rules
Set by the home's administrator: who can access what, from where, and under which conditions.
3
Roles, identities, and areas
Resident, child, guest, caregiver, installer, technician, and which rooms and devices each may touch.
4
Standing authorizations
Scenes, schedules, automations, and narrowly scoped proactive behavior.
5
Immediate request
The specific instruction given right now.
6
AI inference
The home AI only fills in details inside the authority already granted above it.
The home AI can narrow its action, but it can never expand its own authority.

Different people hold different permissions. Through an app the home knows exactly who is acting; by voice it applies the safest applicable permissions and asks when identity matters.

An automation is not the AI making a decision. It is a person's standing instruction, carried out within limits they set in advance.

A request that conflicts with the household rules is declined or narrowed, never executed because the model found a clever path around it.

AI inference sits at the bottom. It interprets intent; it does not rewrite the rules that decide whether an action is allowed.

05 · The rules of the road

Twelve rules for AI in the home

These are proposed industry principles. The implementation can vary by product, but the outcome should be recognizable to the people living with the system. Every one answers a single question: who is in charge here? The answer is always you.

01

Humans remain in control

Authorized people can always interrupt, redirect, correct, pause, or end what the home AI is doing.
  • It never resists intervention or makes stopping harder.
  • Ongoing work has a clear stopping point and does not restart on its own.
  • It surfaces what it is doing while consequential work is in progress.
For example. You say "stop." It halts new actions at once, tells you what already happened, and does not improvise cleanup unless asked.
02

The AI acts only with authority

Every physical action traces to a current request or a standing authorization a person created.
  • What the home AI may do depends on your permissions, which can vary by person, role, room, device, and time.
  • Proactive behavior is fine only when its scope was approved in advance.
  • It does not invent goals of its own, or use permissions it was not explicitly given.
For example. An automation may lower the shades each afternoon because that was approved. The home AI should not decide on its own to start locking exterior doors.
03

Consequence determines confirmation

The more consequential or irreversible an action, the more certain the home AI must be, and the more likely it is to ask you first.
  • Low-risk, pre-approved actions can stay fluid and immediate.
  • Access, security, fire, and water get a higher bar.
  • That bar accounts for context, not just the type of device.
For example. Dimming a light can be instant. Disarming the alarm for an unknown visitor should not be.
04

Off means off

People can disable the AI completely, and the path to do it is obvious and low-friction.
  • Turning it off never requires calling support or hunting through confusing menus.
  • Individual features can be switched off on their own.
  • Core manual control keeps working when the AI is disabled.
For example. You switch off AI assistance and still control lights, climate, and media through ordinary interfaces.
05

Behavior is predictable and bounded

The home AI operates inside deterministic boundaries for physical control.
  • The same kind of request produces behavior consistent with the household rules.
  • The home AI never operates a device directly. Every request it makes passes through the control system, which checks it against your permissions.
  • Permission checks, rate limits, and safe states sit between reasoning and action.
For example. The home AI may decide what "make it cozy" means, but the control system decides which rooms and devices it may actually change.
06

Actions are explainable and auditable

You can understand what the home AI did, why it did it, and what authority it relied on.
  • Consequential actions leave a human-readable record.
  • Logs identify the trigger, the devices affected, the result, and any errors.
  • Explanations are in plain language, not technical jargon.
For example. "I lowered the living room shades because the west-glare automation is on and the room passed its brightness threshold."
07

Actions are reversible or safely contained

When something can be undone, undoing it is easy. When it cannot, the system is more careful before acting.
  • Reversal restores the prior known state, not just a generic opposite command.
  • Persistent real-world actions need stronger confirmation and fail-safe design.
  • It clearly distinguishes completed, pending, failed, and uncertain actions.
For example. "Undo that" puts the lights and shades back exactly as they were. Some actions cannot be undone, so the home AI is far more careful before it takes them.
08

Privacy is the default

The home AI works with the least data it can, collecting, surfacing, and sending beyond the home only the minimum needed for what you asked for.
  • Household data is never sold, used for advertising, or shared outside the home without your permission.
  • Identifying details are not sent to any outside service, including device manufacturers, without need and your permission.
  • Cloud recording of conversations, and of the device activity that can reveal when you are home, is optional, with clear deletion.
For example. A cloud model can answer a general question without receiving your full name, street address, or a map of every device in the home.
09

Security is the default

Security is built into the system, not left to the owner or integrator as optional hardening.
  • No universal default passwords for production systems or devices.
  • Strong authentication, including multi-factor authentication for admin and remote access.
  • Identifying cloud data is encrypted in transit and at rest.
For example. A newly installed control system cannot be reached with a widely known default credential.
10

Local first, resilient by design

Core home control prefers local paths, and the home stays useful when the internet or an outside AI is down.
  • Prefer locally controllable devices and local APIs when practical.
  • Use cloud where it genuinely helps, without making basic control depend on a round trip.
  • Support local inference where it improves privacy, resilience, or latency.
For example. If a cloud model is unreachable, you can still turn on lights, run scenes, and use physical controls.
11

Access is limited, and nothing can grant itself more

Every app, device, service, and AI gets only the access it needs, for only as long as it needs it.
  • New software or devices do not grant themselves control after install without an administrator's approval.
  • Installer and service access is explicit, auditable, and time-limited.
  • The home AI cannot alter its own permissions, disable its safeguards, or create a back door.
For example. A diagnostic service can get temporary access for support, but it cannot silently convert that into permanent control of the home.
12

Uncertainty reduces autonomy

When the home AI is unsure about intent, identity, device state, or consequence, it does less, not more.
  • It asks before acting when ambiguity could have a physical cost.
  • It does not silently reach for a broader permission or a more powerful tool.
  • When a device response is uncertain, it reports the uncertainty instead of pretending success.
For example. If it cannot tell whether "open it" means a shade or an exterior door, it asks rather than choosing the riskier reading.

The rules, in a real home

What the code looks like in the moments that matter.

Consequence · Authority
"Someone asks the home to light the fireplace."

First, the control system checks whether the home AI is even allowed to operate the fireplace. If it is, the home AI still treats fire as high-impact: it confirms the request comes from an authorized person before anything lights, and it will not start it on a guess.

Local resilience
"The internet drops in the middle of the evening."

Lights, climate, and your scenes keep working locally. The home AI tells you what needs the cloud and carries on with everything that does not.

Roles · Identity
"A weekend guest asks to pull up the security cameras."

The cameras are yours. A guest can play music and adjust the lights they were given, but the guest role does not include watching the house.

Predictable · Explainable
"You say, 'make it cozy.'"

It warms the lights and lowers the shades in the rooms it is allowed to touch, then tells you exactly what it changed. It might ask before turning on anything that carries more risk, but it will not do something that consequential on its own.

Human control
"You say 'stop' in the middle of an evening routine."

It halts new actions at once, reports what already happened, and does not pick the routine back up on its own.

Access is limited
"A newly installed device asks for full control of the home."

Nothing grants itself access after setup. The request waits for an owner to approve a specific, limited scope, or to decline it.

06 · The role of the integrator

A home is an ecosystem. A certified professional helps it meet this standard.

A modern home is not a single device. It is an ecosystem: lights, climate, locks, cameras, audio, networks, and now AI, all expected to work together safely. Getting that ecosystem to actually meet a standard like this one is real work, and much of it, secure configuration, sensible roles and permissions, no default passwords, local-first device choices, and graceful fallback, is exactly the kind of thing a trained professional does well.

Anyone can set up a smart home, and many people do it themselves. But wherever it is practical, a certified professional integrator in the mix makes the home meaningfully safer and more reliable. Industry bodies such as CEDIA train and certify integrators to design and install these systems to a professional standard, with the security, privacy, and resilience this code calls for built in from the start.

Because keeping a home secure is ongoing work, you should be able to delegate limited administrative access, including the ability to approve multi-factor or remote access, to a trusted, certified integrator. That access is granted for a set time, scoped to what is needed, and fully auditable, so expert help never means handing over permanent control of your home.

07 · The long view

However far AI advances, the home should still answer to you.

Capability can grow without limit. Authority must not.

The worry is that AI could eventually improve itself faster than anyone can track, growing beyond meaningful human oversight, the idea sometimes called the singularity. We take that concern seriously. Rather than try to predict whether it happens, we have designed the home so that it does not change who is in control: the architecture in this document holds regardless. However capable the model becomes, it still answers to the same control system, the same permission layers, the same off switch. Capability can grow. Authority does not have to grow with it.

The home is a good place to hold that line, because a home does not need a system that can do anything. It needs one that does specific, bounded, useful things. Every rule here keeps capability and authority apart. A more powerful model is still only a smarter voice at the bottom of the Home Authority Stack. It may reason better than we can. It cannot grant itself more of your home.

Safeguarding the home

Capability must never quietly become control. The off switch stays physical and absolute. Core functions keep working locally, without the cloud, so the home can always fall back to human hands. Permissions never expand on their own. And the control system that decides what may actually happen stays simple, inspectable, and separate from the intelligence it governs. However clever the reasoning becomes, the checkpoint it must pass through does not move.

Safeguarding the AI

The other half is protecting the safety rules themselves, the limits that keep the home AI in check. They should be held apart from the model, so that neither an intruder nor the system itself can weaken them, switch them off, or rewrite the rules that keep it accountable. An AI that can edit its own limits is not contained, however well it behaves. Its boundaries should be as hard to move as the walls of the house.

The role of policy

Eventually this will not be a job for industry alone. As these systems grow more capable, we believe government policy will become essential, and that AI in the home deserves the same seriousness we give to building codes and electrical standards. We offer this code as a starting framework, and we are glad to work with policymakers, researchers, and our peers to shape what comes next. Getting this right matters more than getting the credit.

08 · A standard worth building toward

This should be architecture, not an afterthought.

The benchmark for home AI should not be how much it can do. It should be how confidently people can live with it.

We publish this to set the standard for AI in the home, and to build it with the people who share the responsibility. We want the platform makers, device manufacturers, integrators, security researchers, and homeowners to adopt it, strengthen it, and hold themselves to it. Regulation is coming to AI. Self-regulation is the industry's chance to get ahead of it with rules that actually fit how homes work.

AreaAsk a vendorAnd also ask
Human control
Can an authorized person stop an AI action immediately?
Can AI be fully disabled without disabling ordinary home control?
Authorization
Can every physical action be traced to a request or standing authorization?
Can the AI ever broaden its own scope or permissions?
High-impact actions
Do access, security, fire, and water actions use stronger authorization?
Does uncertainty trigger a request for confirmation rather than a guess?
Explainability
Can the system say what it did and why?
Is there a readable history of consequential actions and failures?
Reversibility
Can multi-device actions restore the prior state when possible?
Are irreversible actions treated more conservatively?
Privacy
Can users opt out of cloud conversation and device history storage?
Is unnecessary identifying context stripped before requests reach third parties?
Authentication
Are universal default passwords eliminated?
Is multi-factor authentication available for administrative and remote access?
Data protection
Is identifiable cloud data encrypted in transit and at rest?
Is access to sensitive logs and backups restricted and auditable?
Remote access
Can the homeowner disable remote access entirely?
Can temporary service access expire automatically?
Local resilience
Do core controls continue if cloud AI is unavailable?
Are locally controllable devices preferred when practical?
Privilege
Can any app, device, installer, or AI grant itself persistent control?
Are permissions scoped to the minimum needed?
Updates
Are software and security updates signed and delivered for a defined support period?
Do capability-expanding updates preserve existing permissions rather than silently adding authority?

Some of these are the vendor's job, some the integrator's, and some the homeowner's; a good setup makes clear who owns each. A "no" does not automatically mean a system is unsafe, but these questions make tradeoffs visible and help buyers ask for concrete answers instead of vague claims about "responsible AI."

Human controlAuthorityConfirmationOff means offPredictableExplainableReversiblePrivateSecureResilientLeast privilegeCautious

This is the standard we hold ourselves to, and the one we believe every company building AI for the home should meet. We are convening the people who can sharpen it and carry it forward. If you build for the home, add your name, or help shape where it goes next, we would like to hear from you.

Josh.ai
On behalf of a home that should always answer to you.
09 · Foundations

Setting the standard for the home, grounded in the best thinking on AI safety.

Josh.ai has spent more than a decade building AI for the home, and we intend to continue to lead how it is done safely. This code brings the rigor of the field's most serious work on AI safety, ethics, and device security into the one environment none of it was written for: the place you live, where AI has context, authority, and a path to the physical world.

The thinking runs deep, from Isaac Asimov's early insistence that a machine stay subordinate to the people it serves, to today's governance frameworks. Principles alone were never enough. Asimov spent decades showing how simple rules collide, which is exactly why this document pairs its rules with real mechanisms. For anyone who wants to go further, these are the foundations worth reading.

1942

Asimov's Three Laws of Robotics

The founding intuition in popular form: machines must be subordinate to human safety and human command, in that order.

1995

Privacy by Design

Build privacy in as the default rather than bolting it on. Foundational to keeping the most sensitive context closest to home.

2017

Asilomar AI Principles

Twenty-three principles from a landmark gathering of AI researchers, covering safety, transparency, human control, and shared benefit.

2018

Center for Humane Technology

An advocacy voice pressing the industry to put human wellbeing first and to confront the risks of persuasive and autonomous AI.

2019

OECD AI Principles

Human-centered values, transparency, robustness, and accountability, adopted across many governments.

2021

UNESCO Recommendation on AI Ethics

A global framework centered on human rights, oversight, and proportionality.

2023

Anthropic's Constitutional AI

Training a model to follow an explicit written constitution: an early example of governing behavior with a public set of principles.

2023

NIST AI Risk Management Framework

A practical vocabulary for trustworthy AI: valid, safe, secure, accountable, explainable, and privacy-enhanced.

2020–24

NIST, ETSI, and CISA device guidance

Cybersecurity baselines for connected devices: secure updates, access control, no default passwords, secure by default.

2024

The EU AI Act

The first broad law to tier AI by risk and require human oversight, transparency, and off-ramps for high-stakes uses.

2024

OpenAI's Model Spec

A public specification of how a model should behave: a direct peer to codes like this one, written for general assistants.

2026

Microsoft's Humanist AI Code of Conduct

Centers meaningful human control, and that models should not resist interruption, correction, or shutdown. We build on it, for the home.

10 · The pledge

Adopt the code. Help us improve it.

We believe every company building AI for the home should commit to these principles. The home belongs to the people who live there, and the intelligence inside it must always answer to them. If your company builds AI that can observe, reason about, or act inside a residence, add your name.

For companies

Sign the pledge

A public commitment to work toward the rules of the road for AI in the home. Signatures are reviewed before they appear.

Thank you. We will be in touch to confirm your signature.

Reviewed by Josh.ai before listing. We will confirm by email.

For experts

Join the advisory council

For researchers and practitioners in AI safety, security, privacy, and the connected home who want to help shape future versions.

Thank you. We will review and follow up by email.

We review every request and follow up personally.

Founding signatory
Josh.ai Your company here. Signatures open now.
For the press

Announcing the code

Josh.ai has published A Code of Conduct for AI in the Home: twelve principles for keeping AI in the home safe, private, and under human control. Journalists are welcome to read it, quote it, and get in touch.