PARTNERS
Rules of the road for safe, private, and human-controlled AI in the most personal space we have.
Artificial intelligence in a browser can write, search, and advise. Artificial intelligence in a home can reach the physical world. It can change the lights and the climate, open or secure a door, watch a camera, run the water, and coordinate the systems that shape comfort, privacy, and safety. That physical reach changes the responsibility of the companies building it. A wrong answer is one thing. A wrong physical action is another.
For more than a decade, Josh.ai has been building AI for the home. We have seen firsthand both the promise of bringing intelligence into the home and the responsibility that comes with it. We have always built by these principles. Now, as AI becomes more capable and more widely adopted, we believe it is time to state them openly and hold the whole industry to them.
Josh is not an AI bolted onto a house. It is a home control system with AI inside it, so the intelligence always answers to a layer that enforces your rules. Doing this well does not require racing to build ever larger models. It requires disciplined engineering around the capable models that already exist.
The right question is no longer only "what can the AI do?" It is also: who authorized it, what limits it, what can stop it, what data did it use, and what happens when it is wrong? Our answer is simple. Home AI should be powerful, but never sovereign. Helpful without becoming opaque, proactive without becoming presumptuous, personal without becoming invasive, and intelligent without becoming uncontrollable.
This is a voluntary code for any AI that can observe, reason about, recommend, automate, or control connected systems in a home. It sets a deliberately high bar, one that no product on the market fully meets today, ours included, because its purpose is to define where the industry needs to go. We hold ourselves to it first, and we intend to continue to lead the field there.
General AI principles are not enough. The home needs its own guidance, because it adds physical action, deeply personal context, shared authority, and real-world consequences.
The home AI may interpret a request, but the result can move a motor, unlock a door, or shut off water. Safety cannot end at a good answer. It has to carry through to who is allowed to act, what actually happens, and whether it can be undone.
A home reveals who is present, when people sleep, which rooms they use, what they watch, and how routines change. The home AI can infer more than any single sensor records. Privacy has to be built into the architecture, not just promised in a privacy policy.
Most AI is built around a single account holder. Homes are not. They hold partners, children, guests, caregivers, and installers. One person's request can affect everyone else, so the people in a home need roles and a hierarchy the home respects, not just a login.
Lights, climate, access, and basic control should not become unusable because the cloud is unreachable. The cloud adds real value, but core home functions should degrade gracefully, and local control should keep working whenever it can.
This is the heart of it, and what makes Josh different from a general-purpose assistant. The home AI should not be the control system. It is one intelligent component inside a control system with deterministic boundaries: a separate policy and permission engine decides whether a proposed action is allowed before any device command is issued.
A general-purpose assistant is just AI; it is not the control system. The system that runs your home should be both, so the intelligence always answers to something that enforces your rules. It is also why home AI does not require frontier models: a home needs specific, bounded, useful things, not a system that can do anything.
These are proposed industry principles. The implementation can vary by product, but the outcome should be recognizable to the people living with the system. Every one answers a single question: who is in charge here? The answer is always you.
What the code looks like in the moments that matter.
First, the control system checks whether the home AI is even allowed to operate the fireplace. If it is, the home AI still treats fire as high-impact: it confirms the request comes from an authorized person before anything lights, and it will not start it on a guess.
Lights, climate, and your scenes keep working locally. The home AI tells you what needs the cloud and carries on with everything that does not.
The cameras are yours. A guest can play music and adjust the lights they were given, but the guest role does not include watching the house.
It warms the lights and lowers the shades in the rooms it is allowed to touch, then tells you exactly what it changed. It might ask before turning on anything that carries more risk, but it will not do something that consequential on its own.
It halts new actions at once, reports what already happened, and does not pick the routine back up on its own.
Nothing grants itself access after setup. The request waits for an owner to approve a specific, limited scope, or to decline it.
A modern home is not a single device. It is an ecosystem: lights, climate, locks, cameras, audio, networks, and now AI, all expected to work together safely. Getting that ecosystem to actually meet a standard like this one is real work, and much of it, secure configuration, sensible roles and permissions, no default passwords, local-first device choices, and graceful fallback, is exactly the kind of thing a trained professional does well.
Anyone can set up a smart home, and many people do it themselves. But wherever it is practical, a certified professional integrator in the mix makes the home meaningfully safer and more reliable. Industry bodies such as CEDIA train and certify integrators to design and install these systems to a professional standard, with the security, privacy, and resilience this code calls for built in from the start.
Because keeping a home secure is ongoing work, you should be able to delegate limited administrative access, including the ability to approve multi-factor or remote access, to a trusted, certified integrator. That access is granted for a set time, scoped to what is needed, and fully auditable, so expert help never means handing over permanent control of your home.
The worry is that AI could eventually improve itself faster than anyone can track, growing beyond meaningful human oversight, the idea sometimes called the singularity. We take that concern seriously. Rather than try to predict whether it happens, we have designed the home so that it does not change who is in control: the architecture in this document holds regardless. However capable the model becomes, it still answers to the same control system, the same permission layers, the same off switch. Capability can grow. Authority does not have to grow with it.
The home is a good place to hold that line, because a home does not need a system that can do anything. It needs one that does specific, bounded, useful things. Every rule here keeps capability and authority apart. A more powerful model is still only a smarter voice at the bottom of the Home Authority Stack. It may reason better than we can. It cannot grant itself more of your home.
Capability must never quietly become control. The off switch stays physical and absolute. Core functions keep working locally, without the cloud, so the home can always fall back to human hands. Permissions never expand on their own. And the control system that decides what may actually happen stays simple, inspectable, and separate from the intelligence it governs. However clever the reasoning becomes, the checkpoint it must pass through does not move.
The other half is protecting the safety rules themselves, the limits that keep the home AI in check. They should be held apart from the model, so that neither an intruder nor the system itself can weaken them, switch them off, or rewrite the rules that keep it accountable. An AI that can edit its own limits is not contained, however well it behaves. Its boundaries should be as hard to move as the walls of the house.
Eventually this will not be a job for industry alone. As these systems grow more capable, we believe government policy will become essential, and that AI in the home deserves the same seriousness we give to building codes and electrical standards. We offer this code as a starting framework, and we are glad to work with policymakers, researchers, and our peers to shape what comes next. Getting this right matters more than getting the credit.
We publish this to set the standard for AI in the home, and to build it with the people who share the responsibility. We want the platform makers, device manufacturers, integrators, security researchers, and homeowners to adopt it, strengthen it, and hold themselves to it. Regulation is coming to AI. Self-regulation is the industry's chance to get ahead of it with rules that actually fit how homes work.
Some of these are the vendor's job, some the integrator's, and some the homeowner's; a good setup makes clear who owns each. A "no" does not automatically mean a system is unsafe, but these questions make tradeoffs visible and help buyers ask for concrete answers instead of vague claims about "responsible AI."
This is the standard we hold ourselves to, and the one we believe every company building AI for the home should meet. We are convening the people who can sharpen it and carry it forward. If you build for the home, add your name, or help shape where it goes next, we would like to hear from you.
Josh.ai has spent more than a decade building AI for the home, and we intend to continue to lead how it is done safely. This code brings the rigor of the field's most serious work on AI safety, ethics, and device security into the one environment none of it was written for: the place you live, where AI has context, authority, and a path to the physical world.
The thinking runs deep, from Isaac Asimov's early insistence that a machine stay subordinate to the people it serves, to today's governance frameworks. Principles alone were never enough. Asimov spent decades showing how simple rules collide, which is exactly why this document pairs its rules with real mechanisms. For anyone who wants to go further, these are the foundations worth reading.
The founding intuition in popular form: machines must be subordinate to human safety and human command, in that order.
Build privacy in as the default rather than bolting it on. Foundational to keeping the most sensitive context closest to home.
Twenty-three principles from a landmark gathering of AI researchers, covering safety, transparency, human control, and shared benefit.
An advocacy voice pressing the industry to put human wellbeing first and to confront the risks of persuasive and autonomous AI.
Human-centered values, transparency, robustness, and accountability, adopted across many governments.
A global framework centered on human rights, oversight, and proportionality.
Training a model to follow an explicit written constitution: an early example of governing behavior with a public set of principles.
A practical vocabulary for trustworthy AI: valid, safe, secure, accountable, explainable, and privacy-enhanced.
Cybersecurity baselines for connected devices: secure updates, access control, no default passwords, secure by default.
The first broad law to tier AI by risk and require human oversight, transparency, and off-ramps for high-stakes uses.
A public specification of how a model should behave: a direct peer to codes like this one, written for general assistants.
Centers meaningful human control, and that models should not resist interruption, correction, or shutdown. We build on it, for the home.
We believe every company building AI for the home should commit to these principles. The home belongs to the people who live there, and the intelligence inside it must always answer to them. If your company builds AI that can observe, reason about, or act inside a residence, add your name.
A public commitment to work toward the rules of the road for AI in the home. Signatures are reviewed before they appear.
For researchers and practitioners in AI safety, security, privacy, and the connected home who want to help shape future versions.
Your company here. Signatures open now.
Josh.ai has published A Code of Conduct for AI in the Home: twelve principles for keeping AI in the home safe, private, and under human control. Journalists are welcome to read it, quote it, and get in touch.