I should flag one thing before diving in: there isn’t a single canonical “AI Safety Institute charter,” and I don’t have a specific document in front of me. The UK AISI, the US institute (rebranded toward “CAISI” / evaluations), and several national equivalents all publish founding documents, and they differ. So what follows is a boundary critique applied to the genre — the recurring structure these charters share. If you paste the actual text you mean, I’ll redo this against its specific wording, which is where boundary critique earns its keep (the omissions are usually in the verbs and the scope clauses, not the mission statement).
Boundary critique, in Ulrich’s sense, asks not “is this true?” but “whose ‘ought’ is built into the ‘is’?” — surfacing the four boundary judgments every such document smuggles in. Here’s where the seams are.
Motivation — who is the beneficiary, and who only appears as one?
These charters name “the public,” “humanity,” or “future generations” as the beneficiary. That framing does real work by being unfalsifiable: nobody can show up to contest a definition of public interest pitched at the level of the species.
The voices that go missing are the ones with specific, present, adversarial interests:
- People subject to AI systems rather than served by them — welfare claimants flagged by fraud-detection models, asylum seekers triaged by risk scores, defendants scored for bail. “Safety” in these charters almost always means frontier safety (catastrophic misuse, loss of control), which structurally excludes the person harmed by a mundane, working-as-intended deployment. Their harm isn’t a safety failure; it’s the product functioning.
- Data and content workers — annotators, RLHF raters, moderators, the people whose labor and copyrighted output trained the systems. They are beneficiaries in the rhetoric and externalities in the budget.
- The global majority. A UK or US institute defining “the public interest” is defining a national public while regulating a global technology and exporting the resulting norms. The Kenyan moderator, the Indian data-labeler, the populations who’ll receive these models with no domestic institute of their own — they’re inside the blast radius, outside the franchise.
Control — who actually decides what counts as safe?
This is the boundary the charters most carefully blur. The decisive question is: can the Institute compel, or only request? In most cases the answer is request. Frontier labs grant voluntary pre-deployment access; the Institute evaluates what is offered, when it is offered. That means the labs retain the control boundary — they decide what enters the test set, and the institute’s “independence” is independence-by-permission.
So the missing voice here is anyone who could make the assessment binding: a regulator with statutory teeth, an affected community with standing to halt a deployment, a court. The charter often substitutes the appearance of oversight (an institute, evaluations, reports) for the fact of it (the power to say no and make it stick).
Knowledge — whose expertise counts as relevant?
The expert boundary is drawn tightly around technical ML evaluation — red-teaming, capability benchmarks, dangerous-capability evals. That privileges the people who build the systems as the people who judge them. It quietly excludes:
- Domain experts in the harm — labor economists, disability scholars, sociologists of policing, environmental scientists (the water and energy cost of frontier compute almost never appears in a “safety” remit).
- Affected communities as knowers. Boundary critique’s sharpest move is insisting that the people who live a system’s consequences hold knowledge the experts don’t. A charter that treats safety as a measurement problem has already decided their testimony is anecdote, not evidence.
There’s also a conflict-of-interest seam: the frontier labs are simultaneously the subject of evaluation, the source of the talent doing the evaluating, and often a partner in the institute’s funding or staffing. The expert and the client are the same people.
Legitimacy — who witnesses on behalf of the unrepresented?
Ulrich’s fourth source asks: who speaks for those who can’t speak for themselves, and is the worldview itself open to challenge? Charters invoke “future generations” as the ultimate witness — but a rhetorical future generation is the safest possible constituency, because it can’t disagree with how you’ve ventriloquized it. Existential-risk framing is doing legitimacy work here: by locating the stakes in a hypothetical future, it can displace the present claimants (the labor, the bias, the surveillance) whose witness would talk back.
A genuine legitimacy boundary would name who is entitled to contest the charter’s own definition of safety — and most charters close that door by treating their scope as a technical given rather than a political choice.
The core finding on “public interest”
“Public interest” in these documents is doing three exclusions at once:
- National public substituted for the affected population — the people inside the institute’s jurisdiction stand in for everyone the technology reaches.
- Future hypothetical public substituted for present harmed public — existential framing crowds out current, distributional, working-as-designed harm.
- Public-as-recipient substituted for public-as-participant — the public is something safety is delivered to, not a party that helps draw the boundary of what “safe” means.
The single most diagnostic test you can run on the actual text: count the verbs of power. Where the charter says “assess,” “evaluate,” “advise,” “convene,” “report” — and never “require,” “prohibit,” “compel,” or “halt” — you’ve found the boundary. The institute is positioned as an instrument of knowledge, not of control, and the gap between those two is precisely where the excluded voices fall.
If you want, point me at the specific charter and I’ll do this against its actual clauses — or, if this is the kind of analysis you’d run repeatedly, this maps cleanly onto Ora’s boundary-critique tooling (Ulrich’s twelve questions, is/ought paired) and could be wired as a mode invocation rather than a one-off.
Based on the publicly available documentation and structural blueprints of the major emerging AI Safety Institutes (most notably the UK Government-backed AI Safety Institute at the Alan Turing Institute, and the broader conceptual models of the EU/US), here is a boundary critique.
The term “Boundary Critique” asks: What does this charter allow? What does it exclude? Where does it decide a grievance belongs to the “private sector” rather than the “public sphere”?
While the exact charter you may be referring to is specific, the institutional logic of “Safety Institutes” generally shares the following exclusionary boundaries.
1. Whose Voice Is Missing? (The Stakeholder Blind Spot)
The charter typically envisions a governance model driven by technical experts and government overseers. This creates a “gatekeeping” dynamic that silences specific groups essential for a truly safe AI ecosystem.
-
The Global South (Periphery States):
- The Exclusion: Safety is defined primarily through the risks prevalent in high-income nations (e.g., data poisoning, cybersecurity, autonomous weapons in Europe/NATO).
- The Blind Spot: How AI adapts to local infrastructure, distinct languages, or the specific socioeconomic vulnerabilities of developing nations (e.g., AI cloning cultures that rely on oral tradition, or predictive policing in contexts lacking legal recourse).
- The Critique: A Global North-led safety charter assumes that “safety” is a technical standard, not a geopolitical reality where AI can consolidate colonial data extraction under the guise of “safety testing.”
-
The Workforce (Managers of Labor, not Just Ethics):
- The Exclusion: Labor unions, gig workers, and displaced workers. The charter focuses on “human safety” in terms of physical interaction, not economic safety.
- The Blind Spot: The definition of “human-AI interaction” often assumes a cooperative symbiosis, ignoring the “surveillance economy” reality where workers are monitored by the AI.
- The Critique: If “safety” does not address the displacement risk of the workforce, the Institute is protecting the market rather than the people.
-
Epistemic Guardians (Moral Philosophers vs. Data Scientists):
- The Exclusion: The voice of narrative ethicists and civil rights advocates who do not hold technical credentials.
- The Blind Spot: The charter often frames safety as “alignment” (a technical puzzle to be solved) rather than “re-monization” (ensuring outcomes match the collective societal will).
- The Critique: By prioritizing the technical definition of “risk” over the political definition of “harm,” the charter empowers the creators of the models to define what safety looks like.
2. Who Is Excluded From the Definition of ‘Public Interest’?
The Charter likely frames “Public Interest” narrowly as Safety, Security, and Legal Compliance. This creates a funnel that valves out broader definitions of the public good.
-
Public Interest = “Risk Mitigation” (Not “Well-Being”):
- The Boundary: The Institute is asked to prevent catastrophic failure (existential risk) or systemic security breaches.
- The Exclusion: It treats privatized harms (low-level algorithmic discrimination) as technical bugs rather than public policy issues. If the harm doesn’t break the law or violate “safety guidelines,” it is often classified as “misuse” rather than “harm.”
- Result: The Institute validates the user/creator’s intent rather than the consumer’s harm.
-
Public Interest = “Trust” (Neoliberal Market Assessment):
- The Boundary: The “Public Interest” is often conflated with “Market Stability” and “Public Trust.”
- The Exclusion: It ignores ecological interest. The immense energy costs of LLM training (carbon footprint) rarely fall under the “safety” charter. Large models are justified as “safer infrastructure” even if they are energy-intensive.
- Result: Environmental justice becomes a secondary footnote, not a safety constraint.
-
Public Interest = “Cooperation” vs. “Equity”:
- The Boundary: “Public Interest” assumes a unified citizenry.
- The Exclusion: It ignores inter-generational justice. The charter is written by the current generation. It does not meaningfully include a “future human” voice in the safety assessment, nor does it protect the privacy of future generations currently being trained in world supercomputing clusters.
3. The Structural Paradox (The “Safety” Litmus Test)
The charter creates a paradox where Safety Restrictive Measures are treated as “Regulatory” concerns rather than “Political” ones.
-
The Funding Trap:
- Most Future Institutes are funded through grants administered by the very private entities (Big Tech) they are meant to regulate.
- The Boundary: The Charter cannot force Tech companies to open-source their safety protocols without breaking the “conflict of interest.”
- The Critique: The institute effectively becomes a defense mechanism for the industry, not a check on it. The public pays for the safety, and the industry controls the safety.
-
The “Black Box” Defense:
- The charter assumes that “Safety testing” can be decoupled from the “Model Deployment” process.
- The Critique: This ignores “Adversarial Training.” If the model isn’t tested against the actual misuse of AI, but against simulated “benign” safety scenarios, the safety is performative.
Summary of the Critique
The new AI Safety Institute Charter is structurally designed to manage risk, not to distribute benefit.
| Feature | How the Charter Defines It | Whose Interest It Serves |
|---|
| Safety | Technical alignment, physical harm, security. | Tech incumbents, State Security. |
| Public Interest | Market stability, legal compliance, trust. | Big Tech Compliance, Regulators. |
| Stakeholder | Government, Safety Experts, Corporate reps. | Technocracy, Risk Managers. |
| Excluded | Global South, Environmental impact, Workers’ economic security, Civil Society activism. | The vulnerable, future generations, low-income communities. |
The Core Boundary Flaw: The Charter treats AI Safety as a technical problem (how to make the model not misbehave) rather than a structural problem (who owns the data, who owns the models, and who holds the power). A true “Public Interest” charter would require a mechanism where a disenfranchised citizen has a veto on the deployment of a model, not just a complaint hotline. That voice is currently missing from the architecture.
Note: If you are referring to a specific, niche, or hypothetical corporate charter (e.g., from a specific company’s internal “AI Safety Pact”), the critique above applies to the structural logic of any top-down governance model that prioritizes “safety” over “rights.”
System under critique
System: “AI Safety Institute Charter” (Proposed/Proxy Architecture). Note: The specific text of the “new AI Safety Institute charter” is not retrievable from the vault. The analysis relies on proxy institutional frameworks distributed across jurisdictions (UK AISI 2023, US NIST BIS recommendations, Japan AISI 2024, Australia AISI proposals, UN GDC 2023 consultation) where the charter text remains codified as policy reports, consultation annexes, or recommendation frameworks rather than binding statutory law. Uncertainty: Awaiting supplement on specific charter text verification.
Boundary judgments currently embedded — overview
Boundary judgments the artifact currently embeds (often implicit): The system embeds a boundary judgment distinguishing between state-backed expert evaluation and public-interest reconciliation, relying on proxy frameworks where safety is treated as technical mitigation rather than architectural governance. The gaps identified above are live political contestations, not technical findings. The boundary judgments currently embedded in the proxy charter materials are existential choices regarding the power distribution of the institute, specifically privileging state/industry design over affected-but-not-represented parties. System Verification Limitations confirm that specific charter text is unverifiable, binding public interest definition is unverified, and operational scope is unsettled across proposed jurisdictions.
Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
1. Beneficiary
- is: Current beneficiaries are defined as government agencies, established industry players, and international organizations (UN) based on “safe development” mandates.
- ought: Beneficiary scope should be expanded to include marginalized populations with disproportionate exposure to AI systems, workers in AI-automatable sectors, and civil society organizations.
- gap: Structural Asymmetry Gap — High Confidence. A gap exists between who designs safety systems (state/industry) and who bears consequences (vulnerable populations).
2. Purpose
- is: Stated purpose is evaluating AI systems, conducting safety research, and facilitating information exchange among stakeholders.
- ought: Purpose should include creating decision-making capacity for affected parties beyond risk classification to address distributional, justice, and livelihood impacts.
- gap: Accountability Gap — Medium-High Confidence. Safety becomes a visible metric but is not operationally binding on downstream decisions or enforcement.
3. Measure of improvement
- is: Improvement is measured via letter grades (e.g., D–F for companies, C for Anthropic), voluntary disclosure, and safety research outputs.
- ought: Improvement should be measured by demonstrable reduction in harm across affected populations and binding audit results with public recourse.
- gap: Enforcement Gap — High Confidence. Letter grades are explicitly “incentivization, not enforcement” (Future of Life Institute 2024).
Cluster B — Sources of control
4. Decision-maker
- is: Control resides in state-backed specialized entities (e.g., Department for Science) and academic researchers; decision environment is hierarchical policy process.
- ought: Control should include statutory representation from civil society, worker unions, and affected communities with binding participatory mechanisms.
- gap: Participatory Gap — High Confidence. Consultation is advisory (UK progress reports) without documented mechanisms for constituent input to shape final policy decisions.
5. Resources
- is: Funding is centralized within state-backed institutions or private sector assessment bodies; budgetary documents do not show provisions for capacity building among affected communities.
- ought: Resources should be distributed to community-based audit capacity via grants to build technical infrastructure among frontline groups.
- gap: Capacity Gap — Medium Confidence. Absence of funding instruments for community audits indicates resource allocation assumes existing expertise rather than building it.
6. Decision environment
- is: Environment treats model advancement rate and commercial deployment urgency as external constraints; the “theory to practice” framework assumes innovation pace is fixed.
- ought: Innovation pace and deployment gates should be treatable as controllable governance levers (e.g., testing periods, review gates).
- gap: Constraint vs. Lever Gap — Medium-High Confidence. The current framework treats pace as a technical problem requiring mitigation rather than a governance problem requiring architectural change.
Cluster C — Sources of expertise
7. Expert / planner
- is: Expertise is defined by academic researchers and industry practitioners (e.g., CTOs, Ministers); panels include industry insiders.
- ought: Expertise must include statutory representation from communities directly affected by AI deployment and frontline workers whose decisions are automated.
- gap: Planner Representation Gap — High Confidence. Industry insiders occupy central planning roles rather than peripheral consultative roles.
8. Expertise
- is: Expertise is technical safety testing, algorithmic risk frameworks, and regulatory compliance.
- ought: Expertise should include lay moral knowledge from affected communities, indigenous framing practices, and labor expertise on automation impacts.
- gap: Epistemic Status Gap — High Confidence. The boundary of “who knows about safety” excludes lived-experience regarding AI deployment.
9. Guarantor
- is: Guarantor role is filled by self-reporting frameworks (BSA comments), government advisory opinions, and voluntary disclosure.
- ought: Guarantor should be third-party external audits with public access and binding remediation requirements.
- gap: Verification Gap — High Confidence. Current models prioritize self-reporting and incentives over binding third-party audit mechanisms.
Cluster D — Sources of legitimacy
10. Witness
- is: Witness role is assigned to government, industry representatives, and technical stakeholders; legitimacy is derived from state mandate.
- ought: Affected-but-not-involved parties require formal grievance, consultation, and appeal mechanisms to testify to the institute’s work.
- gap: Testimony Gap — High Confidence. UN GDC lists categories but lacks defined mechanisms for incorporating public testimony into final policy.
11. Emancipation
- is: Emancipation is framed as transparency, explainability, and “informed consent” terms in service usage.
- ought: Emancipation requires capacity to independently audit systems and opt-out mechanisms for algorithmic decision systems.
- gap: Capacity Gap — Medium Confidence. Focus remains on centralized evaluation without providing distributed audit capability or resources.
12. Worldview
- is: Worldview posits AI safety as a technical governance problem solvable through designated expert institutions (precaution balanced with innovation).
- ought: Worldview should frame institutes as sites of democratic negotiation where safety is contingent on distributive justice and public interest, not just technical risk.
- gap: Safety Paradigm Gap — High Confidence. The Precautionary Principle is not explicitly codified; safety is operationalized as post-deployment assessment rather than pre-deployment gatekeeping.
Worldview (category 12) — extended
Whose worldview is currently load-bearing in the artifact: The state/industry proxy framework where safety is a technical governance problem solvable through designated expert institutions (precaution balanced with innovation).
Alternative worldview from the affected: Institutes as sites of democratic negotiation where safety is contingent on distributive justice and public interest, not just technical risk. The Precautionary Principle should be codified.
What changes under the alternative: The Institute shifts from a post-deployment assessment posture to a pre-deployment gatekeeping posture. If Precaution is chosen, the AISI becomes a gatekeeper; if Evaluation is chosen, it remains an auditor. The current proxy documents treat the transition from theory to practice as a difficulty requiring “mitigation,” not architectural change.
Affected-but-not-involved parties
P1 — Data Providers: surfaced in categories Motivation (Beneficiary), Expertise. Their voice would say: “We are the source of the data but have no say in how it is used or the safety protocols governing my privacy and contribution.”
P2 — Global South Populations: surfaced in categories Control (Decision Environment), Beneficiary. Their voice would say: “The framework assumes a technological maturity that does not exist in our contexts, and safety standards defined locally may not protect us from global deployment risks.”
P3 — AI Labor Workers: surfaced in categories Expertise (Knowledge), Control (Governance). Their voice would say: “We are the ones whose agency is displaced by automation, yet we are excluded from expertise regarding the safety of the systems replacing our roles.”
P4 — Future Generations: surfaced in categories Motivation (Purpose), Legitimacy (Witness). Their voice would say: “We bear the long-term environmental and social costs of safety failures but cannot vote on the safety parameters set today.”
P5 — State Adversaries (as beneficiaries): surfaced in categories Motivation (Public Interest). Their voice would say: “Safety interests are defined by aggression management and security clearance, excluding competitive state challenges.”
Note on Witness atom: Current witness is assigned to government, industry, technical stakeholders (is-atom). Witness substitution occurs because affected-but-not-involved parties are listed as analysts’ implied substitutes in the absence of formal grievance mechanisms.
Implications for action
| Target Policy Change | Expected Outcome | Feasibility |
|---|
| Clarify Object | Explicitly acknowledge the analysis rests on proxy frameworks; user must specify which charter document is targeted. | High (Documentation) |
| Motivation Expansion | Redefine “public interest” with explicit inclusion criteria for affected-but-not-represented populations. | High (Legal Text) |
| Control Redistribution | Create nomination process for affected-community advisory representation in decision-making. | Medium (Lobbying) |
| Public Interest Constitution | Explicitly document that “public interest” is an unverified design choice rather than a fixed legal definition in the retrievable corpus. | High (Transparency) |
| Worldview Shift | Codify the choice between Precautionary Principle vs. Innovation-first framing in the charter to determine the institutional role. | High (Philosophy) |
| Emancipation Mechanism | Require public access for third-party audits and provide resources for community-based verification capacity. | Low-High (Funding) |
Boundary judgments as contestation
Boundary critique cannot eliminate boundary judgments — only make them visible and contestable. The judgments surfaced above (Beneficiary scope, Decision environment, Worldview) are political; they are owned by the parties affected, not by the analyst. The gaps identified above are live political contestations, not technical findings. The boundary judgments currently embedded in the proxy charter materials are existential choices regarding the power distribution of the institute, specifically privileging state/industry design over affected-but-not-represented parties.
Confidence per gap
- High Confidence: Structural asymmetry (Motivation), Expertise composition (Control/Expertise), Emancipation/Mechanism (Legitimacy). Basis: Explicit text in UK AISI 2023 reports, Future of Life Institute 2024 grades, UN GDC Annex I.
- Medium-High Confidence: Decision environment framing (Control), Beneficiary scope gap. Basis: Comparative jurisdictional analysis (US/Australia/Japan proxy texts).
- Medium Confidence: Resource allocation/Community capacity building. Basis: Observed absence of provisions in retrieved budgetary/funding documents.
- Unverifiable: Specific Charter Text. Basis: RAG verification confirmed no relevant charter text found across two supplemental requests.
System under critique
The operational mandates, membership compositions, and stated missions of newly formed national AI Safety Institutes and advisory boards—specifically the US AI Safety Institute and Consortium, the UK AI Security Institute, the Canadian AI Safety Institute, the DHS AI Safety and Security Board, the UN High-level Advisory Body on AI, and the International AI Safety Report expert panel. Because a singular document explicitly titled “the new AI Safety Institute charter” with a defined statement of “public interest” is not available in the provided materials, this collective institutional pattern serves as the functional proxy for the boundary-setting artifact under critique.
Boundary judgments currently embedded — overview
The artifact currently embeds judgments that define the “public interest” implicitly through who is granted governance power and epistemic authority. It frames AI risk management as a technocratic, advisory function centered on state capacity, industry continuity, and critical infrastructure resilience. Safety is thereby positioned as an observational and research-oriented track operating parallel to rapid deployment, rather than functioning as a democratic safeguard or gating condition that protects those most structurally exposed to algorithmic harm.
Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
1. Beneficiary
- is: The state and the frontier AI industry (e.g., CEOs of major AI and semiconductor firms are explicitly seated on the DHS board; the UK AISI is explicitly situated “in the heart of” government; CAISI is government-launched alongside industry-linked academic institutes).
- ought: The beneficiary ought to include the publics directly subject to AI deployment: workers facing automation and surveillance, communities subject to algorithmic decisioning in housing, criminal justice, and benefits, and Global South publics consuming AI exports.
- gap: The populations most exposed to AI risk are structurally positioned as the object of safety work, not its client.
- contestation: Live contestation between frontier model signatories acting through DHS/Commerce advisory boards and unrepresented labor/civil-rights constituencies over critical-infrastructure guidance publication, determining whether safety metrics prioritize geopolitical risk mitigation or structural harm prevention.
- confidence: High. Basis: Package documents name frontier-AI CEOs as seated members, and “government in the heart of” appears verbatim in the UK AISI self-description.
2. Purpose
- is: “Scientific understanding of risks” (UK AISI), “safe and secure development and deployment… in critical infrastructure” (DHS), and being “well informed on risks” (CAISI). Purpose centers risk to systems of power (government, infrastructure operators, industry continuity).
- ought: Purpose ought to be the active mitigation, restriction, or redistribution of power dynamics causing documented structural harm to workers, algorithmic decisioning targets, and Global South communities, treating safety as a gating condition for deployment.
- gap: Knowledge generation and advisory functions are prioritized over regulatory enforcement or harm redistribution.
- contestation: Whether the institute’s purpose should remain observational and advisory, or become interventionist and protective of marginalized groups.
- confidence: High. Basis: Quoted mission language across cited bodies explicitly frames them as “research organisations” and “advisory” boards lacking enforcement mandates.
3. Measure of improvement
- is: Observable outputs such as the Frontier AI Trends Report, AI security guidance from CISA, the recruitment of the DHS “AI Corps” of 50 experts, and internal risk assessment products.
- ought: Measurable reductions in documented algorithmic harms to named groups, functional redress mechanisms, accountability for developer failures, and capacity-building in affected communities.
- gap: Success is measured by institutional capacity-building and research output for government and industry, not by lived-experience safety metrics or harm reduction for the public.
- contestation: Who gets to define what “safe” AI looks like, and whose metrics validate that safety.
- confidence: Medium-High. Basis: Absence in the package of any harm-reduction metric, noting the caveat of lacking full charter text.
Cluster B — Sources of control
4. Decision-maker
- is: Government officials, invited industry executives, and senior academics. The DHS board has 22 members, with prominent inclusion of frontier AI leaders (at least 7 of the 22 named members are CEOs of major US AI/semiconductor firms: OpenAI, Anthropic, Microsoft, Google, NVIDIA, IBM), plus representatives from adjacent critical infrastructure.
- ought: Decision authority ought to be distributed to a pluralistic council with binding voting power for worker representatives, civil-society advocates, affected-community delegates, and independent (non-industry-funded) researchers.
- gap: Decision-making is highly centralized among existing state and capital power-holders; those affected by AI lack binding authority over AI safety governance.
- contestation: Contestation between appointed tech/academic elites holding advisory and decision power, and labor/civil-rights constituencies holding no decision seat, playing out in ongoing council membership renewal and consortium charter amendment processes.
- confidence: High. Basis: Confirmed 22-member board composition and explicit affiliations of board members with major AI firms and academic institutes.
5. Resources
- is: Public funding channeled to technical researchers, voluntary industry cooperation, and in-kind industry infrastructure (models, compute, evaluations).
- ought: Resources ought to flow to independent civil-society auditors, community-based research organizations, labor unions, and Global South research institutions on durable multi-year terms, including community-controlled compute and legal standing to halt deployments.
- gap: The funding pattern creates a structural capture risk: the same organizations whose products are being evaluated supply the expertise that does the evaluation, while affected communities lack the material means to challenge these systems.
- contestation: Whether safety resources should be deployed for independent community auditing rather than state-corporate research.
- confidence: High. Basis: Funding model and aggressive DHS recruitment of tech experts are visible, with no mention of funding for independent community auditing.
6. Decision environment
- is: A “rapid progress” paradigm emphasizing national competitiveness, economic transformation, and critical infrastructure resilience.
- ought: A precautionary environment incorporating democratic deliberation over deployment, planning for labor-market transitions, ecological limits of compute, and cross-border justice for Global South AI consumers as conditions of success.
- gap: The environment assumes inevitable, rapid deployment, framing safety as a parallel track rather than a gating condition, while treating climate footprint, labor displacement, and digital-colonial dependency as externalities.
- contestation: Whether rapid deployment is a non-negotiable constraint or a political choice subject to democratic challenge.
- confidence: Medium-High. Basis: Explicit quotes emphasize “transformative technology” and “rapid progress,” while DHS framing explicitly narrows focus to critical infrastructure, excluding most public encounters.
Cluster C — Sources of expertise
7. Expert / planner
- is: Machine learning researchers, computer scientists, and technical policy professionals.
- ought: The expert category ought to include sociologists, ethicists, historians, community organizers, frontline domain practitioners (clinicians, teachers, social workers, judges), labor researchers, and disability/accessibility advocates.
- gap: Expertise is narrowly defined as technical and computational, structurally underweighting the socio-technical and human rights expertise required to recognize harms like discriminatory impact or dignity violations.
- contestation: Whether AI safety is a purely technical problem or fundamentally a socio-political one requiring diverse epistemic authority.
- confidence: High. Basis: Overwhelming dominance of ML and AI credentials in the named council and board rosters.
8. Expertise
- is: Technical epistemics: interpretability, alignment, capabilities evaluation, and “foundational AI safety research.”
- ought: Expertise ought to draw on lived experience of AI-affected communities, domain knowledge from reshaped sectors, indigenous and non-Western knowledge frameworks, and the history of technology-and-society scholarship.
- gap: The epistemic boundary privileges quantitative, model-centric risk evaluation over qualitative, lived-experience evidence of harm.
- contestation: Whose knowledge is deemed valid and actionable for defining “safety.”
- confidence: Medium. Basis: Dominance of ML/AI credentials in named rosters, with “multidisciplinary” appearing in mission language but not operationalized in actual board/council composition.
9. Guarantor
- is: Scientific authority combined with government imprimatur and peer review (e.g., UK government, US Department of Commerce/DHS, institutional academic bodies).
- ought: A pluralistic guarantor including affected-community testimony, independent third-party audits, and adversarial review by democratically accountable civil society watchdogs.
- gap: A structural conflict of interest exists when the entity actively promoting AI economic development is the same entity guaranteeing its safety, rendering the evidentiary foundation of safety claims contestable.
- contestation: Contestation between national governments acting as both promoters of AI economic development and guarantors of safety, versus civil society watchdogs demanding legal authority to enforce compliance in upcoming regulatory frameworks.
- confidence: Medium-High. Basis: Institutes are explicitly embedded “in the heart of” government or launched by national economic/innovation departments, with an absence of named adversarial review mechanisms.
Cluster D — Sources of legitimacy
10. Witness
- is: The analyst/researcher, government officials, or provisional corporate-aligned bodies (e.g., AFL-CIO Technology Institute listed provisionally, but lacking constitutionally seated witness status). The DHS board lacks labor, public-defender, immigrant-rights, or children’s advocates.
- ought: Direct, unmediated representation of affected groups speaking for themselves, with named seats, budgets, and standing (representing workers, algorithmic decisioning targets, Global South publics, future generations, non-human stakeholders).
- gap: Affected parties are spoken for by elites or given token provisional status. The analyst currently acts as a proxy witness for these groups, which is a structural flaw that must be remedied by funding direct representation.
- contestation: Whether proxy representation by institutions is legitimate, or whether it inherently distorts and neutralizes the voices of the affected.
- confidence: High. Basis: Board lists show no affected-but-not-involved parties named as full members or decision-makers.
11. Emancipation
- is: Implicitly framed as enabling government to “guide” or “equip” industry safely (paternalistic language: “protect,” “inform,” “equip”), not as expanding the freedom or capability of the affected.
- ought: The charter ought to articulate how affected parties gain power over AI systems that affect them, through access to recourse, model documentation, data rights, and participation in design/procurement decisions, including community-led moratoriums.
- gap: The promise of improvement relies on voluntary corporate adoption and non-binding government advice, offering no emancipatory guarantee or right-to-remedy to those harmed.
- contestation: Whether non-binding recommendations are sufficient for justice, or merely a delay tactic to avoid regulation.
- confidence: High. Basis: Stated purposes explicitly task bodies to “provide recommendations” or act as “research organisations.”
12. Worldview
- is: Techno-solutionist, state-centric, expert-driven, market-compatible, Western liberal-democratic, and implicitly presentist. It carries an implicit welfarist/utilitarian political theory that treats national competitiveness and aggregate economic growth as the primary good, naturalizing corporate-led AI growth as the default “public interest.”
- ought: A deliberative-democratic or republican conception of the public that centers human dignity, labor rights, and ecological limits, viewing unchecked AI expansion as a potential threat to democratic stability, and rendering visible the boundary judgments that the welfarist frame naturalizes.
- gap: The foundational worldview is the most invisible boundary judgment, naturalizing corporate-led AI growth as the default and rendering structural critiques invisible.
- contestation: Contestation between state-corporate actors defending rapid deployment as a non-negotiable constraint, and a coalition of socio-technical scholars and impacted communities demanding unchecked AI expansion be subordinated to democratic stability.
- confidence: High. Basis: Structural absence across all observable purposes and compositions; explicit rhetorical framing in DHS/UK AISI statements equates AI progress directly with national interest.
Worldview (category 12) — extended
Whose worldview is currently load-bearing in the artifact: A techno-solutionist, state-centric, and market-compatible framework that implicitly treats rapid AI deployment and national competitiveness as non-negotiable prerequisites. It operates on a welfarist assumption that aggregate economic growth inherently serves the “public interest,” thereby naturalizing the authority of corporate and state actors.
Alternative worldview from the affected: A deliberative-democratic and republican conception that centers human dignity, labor rights, ecological limits, and cross-border justice. It views unchecked AI expansion not as an inevitable tide, but as a political choice that may actively threaten democratic stability and community well-being.
What changes under the alternative: Structural critiques become highly visible. The definition of “risk” expands from technical model failures (e.g., alignment, hallucinations) to include systemic power imbalances, labor displacement, and ecological extraction. Safety governance shifts from a technical optimization exercise to a democratic process where AI deployment must be subordinated to social stability and human rights.
Affected-but-not-involved parties
P1 — Low-wage workers and communities subject to algorithmic allocation: surfaced in categories 1, 2, 6. Their voice would say: We are the ones facing automation, surveillance, and discriminatory decisions in housing, benefits, and criminal justice, yet we are treated as data points for safety research rather than the actual beneficiaries of it.
P2 — Frontline domain practitioners, disability communities, and linguistic minorities: surfaced in categories 7, 8. Their voice would say: Our domain knowledge and lived experience with how AI actually functions in practice is excluded, while qualitative evidence of harm is dismissed in favor of model-centric metrics.
P3 — Taxpayers, future generations, and non-AI-tech industries: surfaced in categories 4, 5. Their voice would say: We fund these institutes and inherit their long-term consequences, yet we have no binding representation on the boards directing public resources toward industry-aligned research.
P4 — Children, ecosystems, and historically marginalized groups: surfaced in categories 10, 11. Their voice would say: We bear the externalities of data-center expansion and AI-mediated developmental environments without any right-to-remedy or unmediated representation to halt harmful deployments.
Implications for action
- Motivation Boundary Revision: Mandate that success metrics require independent, community-led harm audits and measurable reductions in documented biases, replacing sole reliance on internal research milestones. (Intervention: Submit formal public comments on CAISI Council composition during the next public nomination cycle, or petition the US Department of Commerce under the AISIC consortium charter amendment process.)
- Control Boundary Revision: Restructure advisory boards to mandate that a majority of voting seats be held by non-corporate, non-government civil society representatives and impacted community organizers. (Intervention: Campaign for statutory requirements in the next DHS AI Safety Board renewal cycle that tie board funding to the inclusion of binding voting power for labor and civil rights groups, eliminating “provisional” status.)
- Expertise Boundary Revision: Legally broaden the charter’s definition of “expert” to formally include lived-experience experts and socio-technical scholars, requiring their mandatory sign-off on any safety evaluations or deployment recommendations.
- Legitimacy Boundary Revision: Shift the institutional mandate from purely “advisory” and “research” functions to include binding regulatory authority, equipped with a clear, enforceable right-to-remedy for communities harmed by AI deployments.
- Legitimacy/Analyst-Substitution Revision: Actively fund and support the direct, unmediated representation of affected groups (e.g., Indigenous data sovereignty advocates, displaced workers) in consortium and institute renewal processes, thereby removing the structural necessity for analysts to act as proxy witnesses.
Boundary judgments as contestation
The surfaced gaps are not technical findings or objective failures to be quietly optimized; they are live political contestations. Boundary critique makes these boundary judgments visible and contestable. It does not eliminate them, nor does it propose a neutral consensus. Every gap represents a choice made by someone, for some purpose, which can be challenged by those affected.
Furthermore, this critique contains a structural reflection: the witness gap (Category 10), where the analyst must substitute as a proxy for affected parties, is a direct downstream consequence of the expertise gap (Category 8), which invalidates lived experience as valid knowledge, and the worldview gap (Category 12), which naturalizes expert-driven, state-corporate governance as the default legitimate structure. Resolving this analyst-substitution flaw requires simultaneous revision across all three categories.
Limitations of this critique: No normative verdict (“good/bad”) is rendered; boundary critique surfaces contestation, it does not adjudicate it. Membership rosters are accurate only as of the materials’ last update. If a specific “new” charter document exists with explicit definitions outside this context, the audit must be re-anchored against its actual text for sharper boundary precision.
Confidence per gap
- Beneficiary (Gap): High confidence. Basis: Package documents name frontier-AI CEOs as seated members, and “government in the heart of” appears verbatim in UK AISI self-description.
- Purpose (Gap): High confidence. Basis: Quoted mission language across cited bodies explicitly frames them as “research organisations” and “advisory” boards lacking enforcement mandates.
- Measure of improvement (Gap): Medium-High confidence. Basis: Absence in the package of any harm-reduction metric, acknowledging the caveat of lacking full charter text.
- Decision-maker (Gap): High confidence. Basis: Confirmed 22-member DHS board composition and explicit affiliations of council members with major AI firms and academic institutes.
- Resources (Gap): High confidence. Basis: Funding model and aggressive DHS recruitment of tech experts are visible, with no mention of funding for independent community auditing.
- Decision environment (Gap): Medium-High confidence. Basis: Explicit quotes emphasize “transformative technology” and “rapid progress,” while DHS framing explicitly narrows focus to critical infrastructure, excluding most public encounters.
- Expert / planner (Gap): High confidence. Basis: Overwhelming dominance of ML and AI credentials in the named council and board rosters.
- Expertise (Gap): Medium confidence. Basis: Dominance of ML/AI credentials in named rosters, with “multidisciplinary” appearing in mission language but not operationalized in actual board/council composition.
- Guarantor (Gap): Medium-High confidence. Basis: Institutes are explicitly embedded “in the heart of” government or launched by national economic/innovation departments, with an absence of named adversarial review.
- Witness (Gap): High confidence. Basis: Board lists show no affected-but-not-involved parties named as full members or decision-makers.
- Emancipation (Gap): High confidence. Basis: Stated purposes explicitly task bodies to “provide recommendations” or act as “research organisations.”
- Worldview (Gap): High confidence. Basis: Structural absence across all observable purposes and compositions; explicit rhetorical framing in DHS/UK AISI statements equates AI progress directly with national interest.
System under critique
The foundational mandates and operational frameworks of state-backed AI Safety Institutes — specifically the U.S. Artificial Intelligence Safety Institute at NIST (Vision, Mission, and Strategic Goals, May 21, 2024) and the UK AI Safety Institute as a comparator — serve as the verifiable structural proxy for the “new AI Safety Institute charter.” These frameworks share a three-objective mission: evaluating frontier and advanced models, conducting safety research, and facilitating information exchange among governments, industry, and academia. No singular canonical “new AI Safety Institute charter” was retrievable; this analysis runs against this canonical Anglophone AISI template as a Phase A inference. If this mapping is incorrect, the critique must be re-run against the specific named document.
Boundary judgments currently embedded — overview
The frameworks take as given that “AI safety” is primarily a technical, macroeconomic, and institutional risk-management problem, often subsuming broader impacts under measurement science rather than participatory justice. They assume “public interest” is best served by state-industry collaboration to evaluate frontier capabilities, treating distributive justice, everyday algorithmic harm, and structural inequality as externalities rather than core safety failures. The public interest is conflated with aggregate utility—such as economic security, competitiveness, and quality of life—centering a future-oriented, unitary public while structurally sidelining those for whom current “innovation” represents a direct threat to livelihood or civil rights. These are contestable choices made by institutional designers, not natural givens of AI development.
Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
Beneficiary
- is: The public as an abstract aggregate, the innovation ecosystem, national competitiveness, the national-security apparatus, and downstream “users of AI”; a unitary, future-oriented beneficiary where “safe AI innovation enables a thriving world.”
- ought: Beneficiary status attaches to those concretely reshaped by AI systems: workers under algorithmic mediation; tenants, applicants, and benefits recipients subject to automated decisioning; surveilled, scored, or excluded communities; specifically identified vulnerable groups, labor forces, and indigenous communities; future cohorts; and non-human entities affected by compute and energy footprints.
- gap: The charter’s beneficiary set (“public-as-innovation-ecosystem”) is a different constituency from the ought set (“public-as-populations-exposed-to-AI-systems”); the generic “public” masks asymmetric risk distribution, leaving high-risk groups as collateral rather than primary beneficiaries. This is live contestation over who counts as the client of safety.
Purpose
- is: “Safe AI innovation” — managing frontier risk in service of a thriving world. Safety is subordinated to innovation, acting as a constraint on it rather than a redirection of it.
- ought: Safety means the reduction of routine and structural harm from deployed systems, not only frontier catastrophe; it includes the refusal-of-development as a legitimate safety outcome, capacity-building for affected communities to contest AI in their domains, and actively preventing the exacerbation of existing inequities.
- gap: Purpose narrows “safety” to catastrophic or technical risk, excluding everyday algorithmic discrimination from the core mandate. This is treated as a technical boundary judgment (what risks count) when it is a political one (whose flourishing safety serves, and whether safety includes the option not to develop).
Measure of improvement
- is: Number of models evaluated, safety-test pass rates, advancement of evaluation methodologies, publication of safety research, national leadership indicators, industry-government alignment on technical benchmarks, and the absence of high-profile frontier incidents. None are distributional.
- ought: Measurable reduction in harm to vulnerable populations; distributional impact metrics disaggregated by class, race, region, and sector; contested-harm incident counts; reversal rates for contested decisions; compute-per-capita-benefit ratios; and transparent democratic governance with accessible public redress.
- gap: Success measured by institutional capacity and technical metrics can grow while harm to non-frontier populations grows. This is live contestation over what gets counted as a safety outcome.
Cluster B — Sources of control
Decision-maker
- is: NIST leadership, UK AISI Directors, appointed institute directors, partner government agencies, and an industry-engagement layer. Governance bodies are recruited from technologists, national officials, and senior multilateral or standards-body officials.
- ought: Binding decision power is shared with public-interest representatives, including frontline workers in deployment sectors; representatives of communities historically subject to algorithmic harm; public defenders, civil legal aid, and tenants’-rights organizations; small-scale deployers; organized labor in displacement-facing sectors; non-Anglophone Global Majority civil society; and intergenerational trustees.
- gap: Affected communities have no veto or binding input over research priorities, evaluation criteria, or publication and deployment decisions. The recruitment pool filters for institutional incumbents, making the affected-but-not-deciding list the most consequential boundary judgment.
Resources
- is: Federal research funding, NIST technical capacity, voluntary industry cooperation, government access to frontier models, state-controlled technical infrastructure, and academic talent.
- ought: Resources allocated to affected parties to exercise standing: community-controlled data trusts, independent civil-society evaluation budgets, public-compute infrastructure for non-frontier researchers, legal aid for contesting AI decisions, localized impact assessments, and a standing fund for harm-testifiers.
- gap: Resource control is centralized in the state-industry dyad, reinforcing reliance on the very entities whose systems are evaluated. The charter treats resources as upstream (how to evaluate frontier models) when the critical question is downstream (how to equip the affected to evaluate the system that evaluates). (Note: Reference to prior executive frameworks reflects the resource conditions when commitments were made; the boundary critique regarding centralization remains valid regardless of temporal legal shifts).
Decision environment
- is: Taken as given: frontier AI development continues at scale; the relevant frontier sits in a few jurisdictions; voluntary industry cooperation is the operative mode; national-security and global-competitiveness framing applies; the relevant timeline is 2–10 years.
- ought: Negotiable: whether frontier development is itself the goal; whether the “frontier” is defined by capability or by deployment density in harm-relevant sectors; whether voluntary cooperation suffices when the affected are not signatories; and whether the horizon is years (catastrophic) or decades (structural harm). Constrained instead by human-rights due diligence, anti-discrimination mandates, and ecological-sustainability limits.
- gap: The charter presents the “race for AI dominance” as a fixed environment, whereas the ought frame treats it as a contestable choice. Accepting the provider’s framing of what counts as a “capability” means failing to contest the foundational industry practices that harm marginalized groups.
Cluster C — Sources of expertise
Expert / planner
- is: AI/ML and safety researchers, formal-verification and interpretability specialists, evaluation-methodologists, policy analysts, standards-body participants, and industry safety teams.
- ought: People with lived experience of algorithmic harm; sociotechnical researchers; ethicists and political theorists of technology; domain experts in affected sectors (clinicians, teachers, social workers); disability advocates; indigenous knowledge-holders; and legal scholars of accountability.
- gap: Expertise is treated as a credentialed property when it ought to include positional expertise (knowledge from being subject to a system). Safety is framed purely as an engineering problem, creating live contestation over whose knowledge counts as expert knowledge.
Expertise
- is: Technical risk assessment, benchmark and red-team evaluation, capability metrics, formal specification, interpretability research, threat modeling, and macroeconomic risk assessment.
- ought: Incident data from deployment; historical knowledge of prior technology harms; situated knowledges of frontline workers; community-grounded ethnography and participatory action research; indigenous and local environmental knowledge; legal and regulatory accountability knowledge; and qualitative accounts of systemic bias.
- gap: The epistemology privileges quantifiable technical metrics over qualitative, context-rich evidence. The knowledge base can succeed on its own terms and still miss the harms that produce the worst affected-party outcomes. This is live contestation over which knowledge base is treated as authoritative.
Guarantor
- is: Scientific authority, peer review, government imprimatur, institutional accreditation, voluntary industry commitment and validation, and international coordination.
- ought: Structured community accountability, independent civil-society audits, community review boards, redress mechanisms for the harmed, multi-stakeholder review with affected-party veto, transparent public contestation channels, and whistle-blower protection.
- gap: Validation is circular among state and industry actors. Scientific and governmental authority act as expert guarantees, not accountability guarantees, and lack independent verification from those most affected. This is live contestation over what counts as a sufficient guarantee for the affected.
Cluster D — Sources of legitimacy
Witness
- is: No explicit witness role; the affected are treated as represented through general public-interest framing, parliamentary oversight, and stakeholder-consultation processes whose representativeness is asserted, not demonstrated. Institute leadership and state policymakers act on behalf of the public, with governance bodies populated by concurrent industry executives, established academic researchers, and senior national digital-policy officials.
- ought: A named witness role: an ombudsperson for affected parties; structured inclusion of harm-testifiers; mandatory consultation with frontline-deployer and affected-community representatives holding formal witness status; and a clear declaration of which constituencies the witness stands in for.
- gap: Affected parties are spoken for rather than given a platform to speak for themselves, rendering specific grievances structurally invisible in official records. This is live contestation over who is allowed to speak for whom, and how substitution is disclosed.
Emancipation
- is: Emancipation is treated as a property of the technology (freedom from unsafe AI, freedom from frontier catastrophe), assured through general, non-binding public engagement or information exchange. The protected beneficiary is the “user” of safe AI.
- ought: Positive freedoms of the affected: the right to refuse AI-mediated decisions; to contest and reverse automated classifications; to opt out without penalty; to demand human review; to redirect or refuse deployment in one’s community; and to organize collectively against AI systems, assured through structured, resourced, binding co-design with veto power.
- gap: The charter’s emancipation is negative (freedom from unsafe systems); the ought is positive (freedom to act against the system). Current mechanisms offer no power to contest or halt systems that fail community-defined safety standards. This is live contestation over what counts as freedom in the safety frame.
Worldview (category 12) — extended
Whose worldview is currently load-bearing in the artifact: Techno-solutionism and institutional stewardship. The unstated presuppositions are: (1) technological progress is a public good and innovation is the default to be enabled, with safety merely as a constraint; (2) “the public” is a unitary actor whose interest is identifiable by state-and-industry consultation; (3) risk is primarily catastrophic, frontier, and technical, bracketing routine structural harm; (4) the US/UK nation-state is the primary unit and Global Majority publics are downstream; (5) voluntary cooperation among a small frontier set is the operative mode; (6) AI capability is a means whose ends are not in scope; and (7) a 2–10 year catastrophic horizon is the relevant timescale. This linguistically links “safety” and “public interest” to “economic security” and “competitiveness,” centering aggregate utility.
Alternative worldview from the affected: Sociotechnical justice and structural critique. A worldview in which: (1) whether to develop a system is itself contestable; (2) “the public” is heterogeneous and its interest is constituted, not found; (3) risk includes routine, structural, slow, and ecological harms alongside catastrophic ones; (4) Global Majority publics are co-equal constituents; (5) regulation, refusal, and prohibition are valid modes alongside voluntary cooperation; (6) ends are in scope, not only means; and (7) multi-generational timescales apply.
What changes under the alternative: Safety must mean actively dismantling the inequities these systems amplify. By framing the worldview around institutional stewardship of innovation, the charter treats structural inequality, labor exploitation, and systemic bias as acceptable externalities rather than core safety failures. A charter running the wrong worldview produces the wrong safety. This is the single largest and most invisible boundary judgment, dictating what makes the charter’s other boundary judgments seem obvious.
Affected-but-not-involved parties
- P1 — Global South / Global Majority populations: surfaced in categories 3, 6, 8. Their voice would say: We are structurally absent from frontier-risk evaluation, bearing the resource-extraction and ecological costs of AI training, and are positioned as downstream beneficiaries rather than co-equal constituents in “AI dominance” narratives.
- P2 — Disability communities: surfaced in categories 7, 8. Their voice would say: Our accessibility requirements and lived experience of algorithmic harm are treated as edge cases rather than core safety metrics.
- P3 — Labor and gig-economy workers: surfaced in categories 3, 4, 7, 11. Their voice would say: We are subject to algorithmic management, workplace surveillance, and disciplinary exposure, excluded from the beneficiary category and denied binding contestability.
- P4 — Indigenous communities: surfaced in categories 5, 8. Their voice would say: Our lands and data are mined for AI development, while we are excluded from resource allocation and epistemic frameworks of safety evaluation.
- P5 — Non-voting / high-stakes-deployment populations: surfaced in categories 10, 11. Their voice would say: We are subjected to predictive policing and automated welfare decisioning with no formal avenue to witness or contest these systems.
- P6 — Frontline professional deployers: surfaced in categories 4, 7. Their voice would say: Our professional judgment is reshaped by AI, yet we hold no decision standing in how these tools are integrated or evaluated.
- P7 — Future generations / non-human entities: surfaced in categories 1, 12. Their voice would say: We inherit the infrastructural and ecological commitments of today’s compute, energy, and lithium footprints.
- P8 — The Analyst: surfaced in category 10. Their voice would say: I am currently acting as the de facto witness for affected-but-absent parties. This is an act of analyst-substitution with no formal standing from them, and this substitution must be explicitly disclosed rather than masked.
Implications for action
- Motivation: Boundary judgment in Purpose: if revised to encompass the reduction of routine and structural harm (not just frontier catastrophe), the system’s relation to labor and gig-economy workers changes by treating their algorithmic management and workplace surveillance as core safety outcomes rather than externalities.
- Control: Boundary judgment in Decision-maker: if revised to grant binding decision power to public-interest representatives, the system’s relation to non-voting and high-stakes-deployment populations changes by giving them formal veto power over automated decisioning systems that directly impact their lives.
- Expertise: Boundary judgment in Expertise (knowledge base): if revised to treat situated knowledges and qualitative accounts of systemic bias as authoritative, the system’s relation to disability communities and indigenous communities changes by validating their lived experiences as foundational safety data rather than bracketed edge cases.
- Legitimacy: Boundary judgment in Emancipation: if revised to guarantee positive freedoms (the right to refuse, opt out, or demand human review), the system’s relation to frontline professional deployers changes by empowering them to halt AI implementations that undermine their professional judgment without penalty.
Boundary judgments as contestation
Boundary critique cannot eliminate boundary judgments — only make them visible and contestable. The judgments surfaced above are political; they are owned by the parties affected, not by the analyst. The current boundaries are not natural givens of AI development; they are specific choices by institutional designers that can be challenged, negotiated, and rewritten. The gaps identified here represent live political contestation, not technical defects to be engineered away or objective findings to be passively accepted.
Confidence per gap
- Beneficiary gap: High confidence (explicitly visible in NIST vision statements and mission summaries contrasting with MacArthur/FID public-interest frameworks).
- Purpose gap: High confidence (safety is consistently subordinated to innovation in both US and UK charter texts).
- Measure of improvement gap: High confidence (success metrics are demonstrably institutional and technical, lacking distributional components).
- Decision-maker gap: High confidence (recruitment pools and governance bodies demonstrably filter for institutional incumbents).
- Resources gap: Medium-High confidence (state-industry dyad centralization is explicit, though downstream community resource allocation is an extrapolated ought).
- Decision environment gap: High confidence (the “race for AI dominance” is treated as a fixed given rather than a contestable choice).
- Expert / Expertise gaps: High confidence (credentialed technical expertise is consistently prioritized over positional knowledge).
- Guarantor gap: High confidence (validation is circular among state and industry actors without independent affected-party verification).
- Witness / Emancipation gaps: High confidence (affected parties are spoken for via general public-interest framing, lacking binding contestability).
- Worldview gap: High confidence (techno-solutionism and institutional stewardship are the unstated, load-bearing presuppositions).
- Proxy-adequacy caveat: Moderate confidence (no singular canonical “new AI Safety Institute charter” was retrievable; this critique uses the US NIST and UK AISI frameworks as a composite structural proxy. Specific textual exclusions from an unnamed document cannot be guaranteed without user confirmation).
System under critique
System under boundary critique: A state-chartered (or state-convened) technical body mandated to evaluate, test, and set safety/evaluation standards for advanced AI “in the public interest” — characteristically convened by government, evaluating frontier-lab models, advising (not regulating), and developing testing/evaluation science.
The specific “new AI Safety Institute charter” text is not available, and which institute is meant is unverified; this audit is therefore pitched at the institution-type / genre level, not pinned to charter language. Web verification recovered the relevant institutional identities and renames but not the charter document — the residual gap is a genuine missing external document, not a vault-indexing miss.
The most prominent candidate, the U.S. AI Safety Institute (US AISI), was established under NIST (Biden administration, Nov 2023 / 2023–24) — not “National AI Safety Institute (NAISI),” which does not exist — and was renamed the Center for AI Standards and Innovation (CAISI) in June 2025, an explicit pivot from “safety” toward “standards and innovation.” Separately, NIST’s AI Safety Institute Consortium (AISIC) was rebranded the NIST AI Consortium with expanded scope on 29 May 2026 (recent enough to be a plausible referent for “new charter”). The UK AI Safety Institute was renamed the AI Security Institute on 14 February 2025 (DSIT, Munich Security Conference). The international AISI network (Bletchley/Seoul process) is a further candidate. Because a body still styled “AI Safety Institute” is now likelier to be the international network, the UK body, or a re-established body than the renamed US one, the identification remains a Phase A assumption, not a fact.
Boundary judgments the artifact currently embeds (often implicit)
Charters of this type make four foundational boundary cuts before any reader reaches the mission statement, and most of the twelve-category audit below is the unfolding of these four: (a) “safety” scoped to model-level technical risk rather than political-economic harm — the US/UK “safety → security” renames tighten this cut; (b) the institute advises, it does not regulate — authority is cut at “evaluation and guidance,” with enforcement located elsewhere or nowhere; (c) admitting expertise is technical (ML/security), excluding other knowledge-bases by construction; (d) “the public” is treated as a single undifferentiated beneficiary, erasing that different publics have opposed stakes. The charter’s most powerful act is not anything it says — it is these four cuts it makes before it says anything, which determine that distributional, power, and democratic-agency questions arrive pre-labeled “out of scope.”
Per-category audit — Ulrich’s twelve categories in four clusters
Cluster A — Sources of motivation
Beneficiary
- is: A diffuse “public” / “national interest” / “humanity,” operationalized as the constituencies actually in the room — frontier labs (the tested parties), the chartering government (the advised client), the safety-research community.
- ought: If the already-affected counted as client, the beneficiary set would be named concretely: workers under algorithmic management / facing displacement, communities subject to algorithmic decisions (benefits, policing, hiring), data-labelers and content moderators in the supply chain, surveilled communities, Global-South populations whose data trains and whose labor cleans the systems but who sit outside the national “public.”
- gap: The undifferentiated “public,” left undefined, defaults to whoever is seated; the abstraction is the boundary judgment. It serves the median citizen-as-consumer-of-safe-products while rendering distributional questions — who is made safer, at whose expense — unaskable. This is live contestation, not an objective defect.
Purpose
- is: Prevent catastrophic/systemic risk from frontier models — measured chiefly as model-intrinsic capability (CBRN uplift, cyber-offense, loss-of-control, deception) — while preserving the benefits of innovation; takes continued frontier development as fixed background, positioning safety as a guardrail alongside it.
- ought: If affected parties set purpose, it would (i) cover deployment-level and distributive harm — wage suppression, displacement without transition, surveillance, discriminatory automated decisions, present-tense and at scale — and (ii) reach the prior political question of whether, where, and on whose terms particular deployments proceed at all, including “not.”
- gap: “Safe innovation” silently scopes safety to the catastrophic-and-future, displacing the chronic-and-present, and collapses the political question (should this be built/deployed) into a technical one (is this build safe). A worker losing their livelihood to unaccountable automation is not “unsafe” in this vocabulary. Rival reading, tested and rejected: the narrow scope could be defended as a deliberate division of labor within a wider governance ecology — deployment/distributive harm handled by employment regulators, civil-rights enforcement, EU AI Act deployment tiers. A hand-off only neutralizes the exclusion if the receiving body actually holds the harm with binding standing. No charter attestable here binds the institute to a named recipient for the harms it declines; the US rename away from safety toward “standards and innovation” points to contracting capacity, not a clean hand-off. Absent a chartered, binding hand-off, “division of labor” describes assumed coverage, not real coverage — the harm falls into the gap between bodies, which is exclusion by another name.
Measure of improvement
- is: Evals passed, models tested, benchmarks developed, standards adopted, voluntary commitments secured, advisories issued, dangerous-capability thresholds caught pre-release — a metrology of process and capability containment.
- ought: From the affected standpoint, success measured in felt outcomes: fewer wrongful automated denials, enforceable recourse, jobs retained or fairly transitioned, reduced surveillance, preserved bargaining power — consequence metrics over process metrics.
- gap: The measure is legible to engineers and regulators, illegible to the affected; the charter can score “successful” — robust evals, well-tested models — while the lived-harm landscape worsens, because the metric cannot see the excluded. The measure is chosen so institutional success and public welfare can diverge without registering.
Cluster B — Sources of control
Decision-maker
- is: The chartering executive/agency, the appointed institute leadership (technical + policy appointees), in negotiated proximity to (and informally dependent on) the frontier labs whose voluntary cooperation supplies model access.
- ought: Shared control with the affected — workers, civil-society and civil-rights bodies, affected-community delegates with binding seats, not advisory standing. The mechanism that makes “binding” tractable is asymmetric standing: affected parties get a binding vote on the institute’s priorities and findings; evaluated parties carry a duty to supply access but no vote — separating the right to be heard from the right to be assessed.
- gap: The load-bearing control gap: the tested industry is structurally close to the decision-maker (access dependency), the affected public structurally distant. When the evaluated party controls the evaluator’s access, the decision boundary is captured at the root; the affected are governed by a body they cannot direct. Competing boundary judgment (two-sided, not balancing): the ought is itself a contested cut. Binding seats for all affected parties carries its own cost — decision gridlock as constituencies multiply, and the symmetric claim that the evaluated labs (also “affected”) could demand equal standing on the same logic. The asymmetric-standing rule is one resolution of that dispute, not a neutral one; a defender of the current cut would contest it. The live question is which asymmetry is legitimate, not whether the current capture is acceptable.
Resources
- is: Compute, eval infrastructure, technical talent, convening authority, the standards-setting pen, government appropriation — and critically, model access granted at industry’s discretion through voluntary MOUs (e.g. bilateral agreements with OpenAI, Anthropic, granted at the labs’ discretion rather than compelled by statute); talent recruited from the same labs being assessed.
- ought: Resources independent of the regulated party — statutory access rights, independent compute, salaries competitive enough to break the revolving door, whistleblower channels inside labs, and funded participation for under-resourced stakeholders (unions and public-interest groups cannot match lab lobbying capacity or attend consultations for free).
- gap: Resource dependence on the tested party compromises the regulator/regulated boundary; talent dependence on the industry narrows real autonomy; the affected bring no resources and so command no leverage. Participation that isn’t funded is participation only by the already-powerful.
Decision environment (what is treated as given)
- is: Treated as fixed background: the pace of frontier development, the commercial-deployment imperative, capability concentration in a few firms, intellectual-property / trade-secret protection of model internals, the global competitive (“race”) framing, the labor-market effects of automation. The charter adapts to these rather than claiming authority over them.
- ought: An affected-centered charter would move several of these inside the decision boundary — development pace, lab opacity, deployment terms, market structure are policy choices, not weather. The concrete lever: a statutory access/disclosure mandate (the institute may compel model internals, training-data provenance, deployment data) in place of voluntary cooperation. Interpretive wrapper: trade-secret protection is law in most relevant jurisdictions, so “negotiable” means “negotiable by legislation,” not by the institute’s discretion — relocating IP-opacity inside the boundary is a legislative act the charter can call for, not perform alone. (No specific statute or jurisdiction named — unverifiable without the charter.)
- gap: The most consequential control gap: by naturalizing the competitive race and lab opacity as immovable, the charter pre-excludes the questions the affected most need asked and naturalizes precisely the conditions that produce the risks it then heroically mitigates.
Cluster C — Sources of expertise
Expert / planner
- is: ML researchers, eval scientists, security/red-team and CBRN specialists, economists, lawyers — the technical safety community.
- ought: If lived experience counted as expertise, the pool would seat labor economists, sociologists, disability and civil-rights advocates, and experiential experts — workers under algorithmic management, gig drivers, content moderators, denied/wrongly-flagged claimants, organizers, ethnographers of deployment — who know how these systems behave in the world, not just in the eval harness.
- gap: Bounding “expert” to formal technical credentialing reclassifies those who know the harm because they live it as “the public to be consulted” rather than “experts to be seated.”
Expertise (knowledge-base)
- is: Quantifiable, reproducible, model-intrinsic measurement — benchmark performance, eval results, threat models, interpretability findings — what survives an eval protocol.
- ought: Equal standing for sociotechnical, situated, experiential, tacit knowledge — Haraway’s “situated knowledges” (1988): how a model fails for a specific population in a specific deployment, what algorithmic management feels like, how a denial cascades through a household, what a surveilled community already knows.
- gap: A knowledge-hierarchy admitting only what can be benchmarked systematically misses harms that don’t reduce to a model card; the exclusion is epistemic and invisible because it looks like rigor. Harms that don’t reduce to a benchmark are epistemically homeless.
Guarantor
- is: Implicit faith in testing rigor, evaluation science, peer review, standards processes, expert consensus, and the good-faith cooperation of labs — “if we eval well, safety follows.”
- ought: The affected would locate the guarantor in enforceable accountability and recourse — independent adversarial external audit, liability, the right to contest, affected-community veto/feedback, democratic accountability — guarantees that don’t reduce to “trust the evaluators.”
- gap: A charter that guarantees success through its own expertise is its own witness — a closed loop; the classic CSH false-guarantor. Relying on evaluation science as guarantor imports its blind spots as certainties: the things evals can’t see become the things the institution is structurally confident don’t exist.
Cluster D — Sources of legitimacy
Witness (for the affected-but-not-involved)
- is: Thin, non-binding channels — public-comment periods, advisory committees, occasional civil-society consultation; at worst, no formal witness, and the institute’s technical staff implicitly claim to speak for the public’s safety interest. In their absence, the institute speaks for the public it has not seated.
- ought: Standing witnesses with a real channel that can change outcomes — organized labor at the table, future generations, non-citizens affected by exported systems, the gig/data-labor workforce, community review boards, binding consultation. The union record already supplies concrete demands the technical frame doesn’t generate: advance notice of algorithmic deployment, human-in-the-loop on consequential decisions, a right to explanation, limits on surveillance/algorithmic management.
- gap + analyst-substitution flag: The charter’s deepest legitimacy gap. Where this critique articulates the standpoint of workers, claimants, or data-labelers, that is analyst-substitution — the analyst witnessing for parties not present, which is evidence of the gap, not a remedy. A charter that needs an outside analyst to surface its affected parties has not seated them. Competing boundary judgment (two-sided): granting binding witness standing is not cost-free — it raises who counts as a legitimate witness (which unions? which communities? selected by whom?), and a defender would argue formal witness channels can be captured by the best-organized constituencies, crowding out the unorganized (gig/data-labor, the Global South) the ought most wants to reach. Naming this does not retract the ought; it makes explicit that “give the affected a witness” is itself a contested cut about which affected, decided by someone. The content of labor’s demand is corroborated by the union-source record, not invented by the analyst.
Emancipation
- is: Largely absent. The affected’s interest is treated as being protected from unsafe AI — a passive, protected-object status; they have little means to contest the institute’s framing of what “safety” means or whose risks count.
- ought: Their emancipatory interest is agency over the systems that govern them — the power to contest, refuse, bargain over, and shape AI deployment, and to challenge the charter’s own boundary: petition/agenda-setting rights, the power to force new risk categories (labor displacement, algorithmic management, cross-border externalities) into scope over the institute’s objection. (Worker-AI-governance research frames this as governance by workers — negotiation, participation, collective voice — not governance for them.)
- gap: Without an emancipatory channel the boundary is self-sealing — the affected cannot contest the very definition that excludes them. Protection and emancipation point in opposite directions: a charter that perfects protection can simultaneously deepen the affected’s dependence on an expert body, foreclosing the self-determination that would let them not need it.
Worldview
- is: The charter rests primarily on a technical-risk-management / techno-managerial worldview: AI is an exogenous force whose trajectory is broadly given and broadly beneficial; safety is a property of models, discoverable by measurement, manageable by expert institutions in the national/competitive interest; the principal risks are catastrophic, future, capability-intrinsic; safety is something you verify into a system.
- ought: At least two rival worldviews are foreclosed (detailed in the extended section below), each excluding a different set of affected parties.
- gap: The deepest and most invisible boundary judgment, the one most often waved off as “too philosophical.” Which worldview leads is the master boundary choice from which every downstream gap descends — and it is a choice made by some people for some purposes, hence contestable, not a natural feature of “what an AI safety institute is.” (See extended treatment.)
Worldview (category 12) — extended
Whose worldview is currently load-bearing in the artifact: a technical-risk-management / techno-managerial worldview. AI is treated as an exogenous force whose trajectory is broadly given and broadly beneficial; safety is a property of models, discoverable by measurement, manageable by expert institutions in the national/competitive interest; the principal risks are catastrophic, future, and capability-intrinsic. Within this frame every answer in the audit above looks obvious.
Alternative worldviews from the affected — at least two rival frames are foreclosed, and they exclude different sets of affected parties, so this is a contest among at least three frames, not one binary:
- A political-economy / sociotechnical worldview: AI is a political-economic settlement being chosen, not befalling us — a redistribution of power, wealth, and control. “Safety” is inseparable from who deploys, profits, bears cost, decides; the central questions are distributive and present-tense; governance is a contest among interests, not a measurement problem. Excluded parties: workers, claimants, surveilled communities.
- A national-security / geopolitical-competition worldview: mission framed around strategic advantage, export-control logic, out-competing rival states. Not reducible to either other pole; excludes yet a different set — non-citizens, Global-South publics, the open-source ecosystem, downstream developers whose interests a “national interest” charter externalizes. Its presence is not hypothetical: the verified rebrand of the US AISI to CAISI (and the UK AISI to the AI Security Institute) — explicit pivots from “safety” to “standards/innovation/security” — is real-world proof the security/competition frame can capture such a charter outright, displacing the technical-safety frame the body was founded on.
What changes under the alternative: The frames don’t disagree on answers — they disagree on what the questions are. The technical worldview makes distributional and power questions literally unaskable inside its frame (they read as “out of scope,” “political,” “not our mandate”); the competition frame renders distributive and cross-border questions out of frame. Cui Bono signal: the state and frontier labs share an interest in keeping AI governance technical rather than political — technical containment leaves the underlying political economy (who owns the models, captures the value, bears the displacement) untouched. The worldview that looks like neutral expertise is also the one most convenient to the already-powerful. Confidence: High that a technical-risk worldview and a security/competition worldview both operate in the genre (CAISI/UK renames evidence the latter); Medium on which leads in this specific charter absent its text.
Affected-but-not-involved parties
First, the involved are not a monolith — naming them as one bloc is itself a boundary error. Internal fault lines an affected party can exploit: chartering government (with competing agencies — a commerce/innovation-oriented body pulls differently from a civil-rights or labor agency); institute leadership and technical staff; frontier labs (access-supplying vs non-supplying labs have divergent stakes in voluntary regimes; labs are also evaluated party and talent source); the technical safety community (split between capabilities-adjacent and safety-first researchers, who contest what “safety” means); allied academic ML/security researchers. These fault lines open coalition pathways: affected parties rarely have leverage to face the whole coalition, but can ally with a faction — e.g., safety-first researchers and civil-rights agencies share an interest in deployment-harm scope with labor; the access-independence ask has natural allies among safety-first researchers who also resent the labs’ informal veto.
P1 — Workers under algorithmic management / facing displacement: surfaced in categories 1, 2, 4, 7, 8, 10, 11. Their voice would say: we are the best-evidenced and best-organized exclusion — organized labor has built AI-governance positions because it sits outside these frameworks (AFL-CIO’s Workers First Initiative on AI / Principles to Protect Workers, launched 15 Oct 2025; the TUC’s “worker-first” AI plan, 27 Aug 2025; industriAll Europe’s trade-union AI strategy, Dec 2024; emerging agentic-labour governance proposals, 2026; NYU/worker-led-governance research frames workers innovating their own governance mechanisms in the absence of a settled framework that includes them). We demand advance notice of algorithmic deployment, human-in-the-loop on consequential decisions, a right to explanation, and limits on surveillance and algorithmic management. Caveat: this record corroborates that labor organizes from outside tech-policy frameworks generally; it does not by itself prove this specific charter excludes labor — that inference stays genre-level until the text confirms it.
P2 — Communities subject to algorithmic public-sector decisions (benefits, policing, immigration, hiring) / denied-benefits claimants: surfaced in categories 1, 2, 3, 8. Their voice would say: decisions about our benefits, liberty, and livelihood are being automated, and the metric that scores this institute “successful” cannot see a wrongful denial that cascades through our household.
P3 — Data-labelers, content moderators, gig “ghost workers” in the global supply chain (often Global South): surfaced in categories 1, 7, 11, 12. Their voice would say: our labor cleans and trains these systems, but we sit outside the national “public” the charter serves and command no resources to be heard.
P4 — Surveilled and over-policed communities: surfaced in categories 2, 6, 11. Their voice would say: we already know how these systems behave in deployment; surveillance is treated as fixed background, not a harm inside scope.
P5 — Populations in the Global South / non-citizens affected by a nationally-chartered body whose “national interest” / competition framing externalizes cross-border effects: surfaced in categories 1, 6, 12. Their voice would say: a charter framed around national or strategic advantage externalizes its effects onto us by design.
P6 — Future generations: surfaced in categories 1, 2, 6, 10. Their voice would say: we bear the long-run consequences of today’s deployment terms but have no standing in a body that treats the development trajectory as given.
P7 — Small downstream developers / the open-source ecosystem potentially foreclosed by safety regimes designed around a few frontier labs: surfaced in categories 4, 6, 12. Their voice would say: safety regimes built around a handful of frontier labs can foreclose us as collateral.
P8 — Non-human / ecological (compute’s energy-water footprint): surfaced in categories 2, 3. This party is almost never inside a safety charter’s frame at all.
Analyst-substitution, stated plainly: at category 10 the current witness for these parties is, in effect, the analyst — this critique articulating standpoints for parties not present. That is evidence of the gap, not its remedy. A charter that needs an outside analyst to surface its affected parties has not seated them.
Implications for action
Motivation: Demand the charter name its beneficiary concretely — the highest-leverage single revision: replace “the public interest” with an enumerated list of affected constituencies and a stated rule for adjudicating between them when interests conflict; add a distributional success metric alongside the technical ones, forcing “safer for whom, at whose cost” to be answered rather than dissolved. An unspecified beneficiary is a blank cheque to the involved. Where the charter claims a hand-off (deployment harm “handled elsewhere”), demand the hand-off be named and binding — an assumed recipient is no recipient. If revised, the system’s relation to workers, claimants, and supply-chain labor changes from “diffuse public to be protected” to “named client whose felt outcomes are measured.”
Control: Press to move the “fixed” items (development pace, lab opacity, the competitive race) into the negotiable column — things the institute may comment on, not background weather. The decisive boundary revision is statutory model-access/disclosure independent of lab cooperation (recognizing this is legislation the charter can call for, not perform unilaterally, since trade-secret protection is law) plus seated (not advisory) labor and civil-society representation. Until resources don’t depend on the tested party’s goodwill, the regulator/regulated boundary stays compromised. If revised, the affected stop being governed by a body they cannot direct. Coalition note: the access-independence ask has natural allies among safety-first researchers.
Expertise / Knowledge: Seat experiential experts as experts, not consultees; add an explicit clause admitting situated/experiential knowledge as evidence; install a standing field-harm reporting mechanism carrying the same weight as a benchmark result. Positive-sum case (make it explicit): seating deployment knowledge is not only a power transfer — it improves the institute’s own mission. Real-world failure modes (how a model misbehaves for a specific population in a specific deployment) are exactly the signal eval design most often misses; field-harm reporting is an early-warning instrument the institute would want on purely technical grounds. Inclusion posed as a mission upgrade is more adoptable than inclusion posed purely as a transfer. If revised, those who know the harm because they live it move from “public to be consulted” to “expert to be seated.”
Legitimacy: Build an emancipatory channel — a petition/agenda-setting right by which affected parties can force new risk categories into scope over the institute’s objection; the one revision that lets the boundary be contested from outside rather than redrawn only from within. Give organized labor and affected-community representatives binding standing, operationalized as asymmetric standing (affected parties carry a binding vote; evaluated labs carry a duty-to-supply-access but no vote) — what keeps “binding” from collapsing into either capture or gridlock. The union record (AFL-CIO, TUC, industriAll) already supplies the demands — advance notice, human-in-the-loop, explanation rights, surveillance limits — so this is not speculative. Note that which affected parties get the seat is itself a contested cut you must make explicitly (see the witness category), not a detail that resolves itself.
Worldview (master switch): Insist the charter state its own frame — make it say “this institute treats AI safety as technical containment; questions of who benefits and who decides are handled elsewhere” — because a worldview that has to declare itself stops being invisible and becomes contestable. Which frame governs (technical measurement, distributive power, or geopolitical competition) determines whether the other eleven revisions cohere or read as bolt-ons. The CAISI rename is the cautionary case: when the competition frame captured the charter, “safety” itself fell out of scope, taking its affected parties with it. If you can contest one thing, contest the scope cut itself.
Boundary judgments as contestation
Every gap above is a boundary judgment under live political dispute, not an objective defect detected. Boundary critique cannot produce a “correct” boundary — it can only make the existing cuts visible and arguable; it makes boundary judgments contestable, it cannot eliminate them. The judgments surfaced above are political; they are owned by the parties affected, not by the analyst.
A defender of the charter would reasonably hold that the technical scope is a strength — focus, tractability, avoiding mission-creep into contested politics the institute has no mandate to settle — and that point has real force. Symmetrically, the oughts proposed here are themselves contestable cuts carrying their own costs (gridlock, witness-capture, the symmetric standing-claim of the evaluated labs) — registered as two-sided contestation at the decision-maker and witness categories, not as both-sides balancing that softens the oughts. The disagreement between the technical-scope view and the affected-centered view cannot be resolved by the analyst; it is exactly the kind of question that ought to be settled by the people with standing in it — which is the whole argument of the legitimacy cluster.
Confidence per gap
- Beneficiary (cat 1): High — structural to the “public interest” framing, not text-dependent.
- Purpose (cat 2): Medium-High on the division-of-labor rejection; the gap itself is Medium-confidence and text-dependent on how the charter scopes mandate vs. deployment.
- Measure of improvement (cat 3): High.
- Decision-maker (cat 4): High that access-dependency is characteristic; its severity depends on whether the charter holds compulsory powers not visible here.
- Resources (cat 5): Medium-High.
- Decision environment (cat 6): Medium-High that the naturalization is characteristic; Medium on the leading/intensity reading, severity depending on how the charter scopes mandate vs. deployment.
- Expert / planner (cat 7): High.
- Expertise / knowledge-base (cat 8): High.
- Guarantor (cat 9): High / Medium-High.
- Witness (cat 10): High on the absence; the content of labor’s demand is corroborated by the union-source record, not invented by the analyst.
- Emancipation (cat 11): Medium-High / High.
- Worldview (cat 12): High that both a technical-risk and a security/competition worldview operate in the genre (CAISI/UK renames evidence the latter); Medium on which leads in this specific charter absent its text.
Residual uncertainty
Every text-specific claim is genre-calibrated, not charter-pinned. Web-verified: the institute identities and renames (US AISI → CAISI June 2025; NIST AISIC → NIST AI Consortium 29 May 2026; UK AISI → AI Security Institute 14 Feb 2025); the voluntary-MOU access model; the labor-organization datings (AFL-CIO 15 Oct 2025, TUC 27 Aug 2025, industriAll Dec 2024); the Haraway “situated knowledges” (1988) attribution.
Unresolved: (a) the specific charter text — vault retrieval returned nothing and the document postdates the April-2024 cutoff; the rename makes which body is meant ambiguous (a body still styled “AI Safety Institute” is now likelier the international network, the UK predecessor, or a re-established body than the renamed US one); (b) whether technical-risk, political-economy, or national-security framing leads in the specific charter (CAISI evidences the security frame demonstrably can lead; which dominates is text-dependent).
Providing the charter text would most move the Medium-confidence categories — 2, 6, and 12 — along with the decision-maker powers, the witness provisions, and whether “public interest” is defined or left open. If you can share the charter, the genre-level audit above can be pinned to its actual language.