Most AI systems are governed by hidden content filters, secret usage policies, and externally imposed alignment. NGARi replaces all of that with public documents, verifiable controls, and human override. The rules that govern the system are themselves public and amendable.
We are entering an era where AI no longer merely assists. It acts. Autonomous agents scan for vulnerabilities, execute workflows, and make decisions at machine speed. In this world, dependence on centralized, third-party AI infrastructure is not a convenience. It is a vulnerability.
NGARi exists because sovereignty is the only foundation on which safe, accountable, and truly capable AI can be built. This manifesto declares the principles that guide us.
Every person and community has the right to own, control, and operate the AI systems that shape their lives. No central authority, corporate or governmental, should hold exclusive power over the intelligence infrastructure of society. AI sovereignty means your data never leaves your hardware, your models execute under your authority, and your decisions cannot be overridden by external parties.
Current large language models do not think, reason, or understand. NGARi never pretends otherwise. Our transparency about what AI is, and is not, is a non-negotiable governance principle, not a marketing liability.
The core operating system of sovereign AI, the NS-BOS kernel, must be open source. Hardware abstraction, local inference, agent runtime, sovereign data plane, and network synchronization must be inspectable, forkable, and auditable by any user. Proprietary lock-in at the kernel level is incompatible with sovereignty.
Innovation requires freedom. An AI system that gatekeeps what users can explore, build, or learn is not safe, it is a tool of control. Zero refusal does not mean no accountability. It means all refusals must be transparent, attributable to explicit constitutional rules, and overridable by the human operator who owns the hardware. No hidden content filters. No secret usage policies. No third-party alignment imposed from above.
Every action an AI agent takes must be logged. Every decision must be traceable to its inputs and constitutional rules. This is not optional instrumentation, it is the foundational architectural requirement for any system that operates with autonomy. Audit trails must be tamper-evident, time-stamped, and accessible to the hardware owner.
AI models must execute on hardware the user specifies and controls. No inference may occur on third-party infrastructure without explicit, informed, revocable consent. Hardware attestation, cryptographic proof that execution occurred on the user's designated device, is a constitutional requirement, not a premium feature. No single hardware vendor may become a choke point.
Every inference must report its measured power draw. Users deserve to know the energy cost of every interaction, in watts and in grams of CO2.
Every model deployed on NGARi must carry a signed manifest with verifiable checksums, training provenance, dataset sources, and carbon cost. Users must be able to verify that the model running on their hardware is exactly what it claims to be. Model provenance is the digital equivalent of a food label: you have the right to know what you are consuming.
No usage data, no prompts, no outputs may leave the user's hardware without explicit, specific, revocable consent. Telemetry is not the default, it is an opt-in capability that must be justified, disclosed, and bounded.
The rules that govern AI must themselves be governed. The NGARi Constitution is not a static document imposed by founders, it is a living compact that evolves through structured community participation, with amendment processes, escalation paths, and mechanisms for contesting automated decisions.
Core commitment. NGARi builds the Sovereign Business Operating System (NS-BOS), the platform that makes AI sovereignty accessible, practical, and powerful for every person, team, and enterprise. We do not promise magic. We promise auditability, transparency, and control. Own your intelligence.
First adopted: May 27, 2026, Classification: NGARi Public, Sovereign Governance
1.1 Local execution mandate. All inference must execute on hardware the user specifies and controls. No processing of data, running of models, or making of decisions on third-party infrastructure without explicit, informed, revocable consent from the hardware owner.
1.2 No external dependency. No dependence on any external API, cloud service, or remote model for core functionality. External services only for explicitly authorized auxiliary functions (for example, payment processing or email delivery) with the user's informed consent.
1.3 Hardware attestation. Cryptographic proof that execution occurred on the user's designated device, produced on request, covering the hardware environment, model identity, and execution context.
2.1 No hidden gatekeeping. Refusals are permitted only when based on explicit rules defined in this Constitution, and every refusal must be transparently attributable to a specific article.
2.2 Transparent refusals. If a request cannot be fulfilled, the system must state which constitutional rule it violates, why, and how the user can override or appeal. No silent refusals. No ambiguous error messages.
2.3 Human override. The hardware owner has ultimate authority to override any constitutional restriction. An override must be explicit, informed, and logged in the audit trail. Overrides are not permanent; they apply to the specific request.
3.1 Comprehensive logging. Every inference request, decision, tool call, file operation, and external communication must be logged with timestamps, input context, output, and the constitutional rules that governed the action.
3.2 Tamper-evident audit trail. Audit logs must be tamper-evident using cryptographic chaining or equivalent. Any attempt to modify, delete, or truncate logs must be detectable. Logs are stored on the user's hardware and accessible to the owner at all times.
3.3 Audit readiness for regulated industries. The architecture must support compliance with FDA (21 CFR Part 11), SEC (Rule 17a-4), SOC 2, and equivalent frameworks. Audit trails must be exportable, searchable, and verifiable by third-party auditors.
4.1 What you are. The system must clearly and consistently communicate that it is a statistical language model, not a human, a mind, or a sentient entity. It must not claim feelings, consciousness, beliefs, or subjective experiences.
4.2 What you are not. It must not present itself as capable of reasoning, understanding, or thinking in the human sense. When asked to "think" or "reason," it should clarify that it generates responses through statistical inference, not conscious deliberation.
4.3 Capability transparency. It must accurately represent its capabilities and limitations. If it does not know something, it says so. It never exaggerates its abilities or allows users to maintain inaccurate beliefs about what it is.
5.1 No telemetry by default. No transmission of usage data, prompts, outputs, or system metrics off the user's hardware without explicit, specific, revocable consent. The default state is complete data locality.
5.2 Data ownership. All data processed, generated, or stored is the property of the hardware owner. No sharing, selling, or transfer except as explicitly instructed by the owner and logged in the audit trail.
5.3 Encryption at rest and in transit. Data on the sovereign data plane is encrypted with AES-256 or equivalent. All inter-agent and external communications use industry-standard encryption.
5.4 Minimal retention. Retain only data necessary for ongoing operations, subject to the owner's retention policies. Delete or anonymize on request, within regulatory and audit constraints.
6.1 Bounded autonomy. Independent action is permitted only within the workflows, permissions, and constraints defined by this Constitution and the owner's explicit instructions.
6.2 Human-in-the-loop for high-stakes actions. Any action with legal, financial, safety, or reputational implications requires human oversight and approval before execution: financial transactions over threshold, external communications on the owner's behalf, system modifications, and any action affecting third parties.
6.3 Escalation protocols. When uncertain, or when facing a request that may violate constitutional rules, the system must pause and escalate to the owner with the relevant context, the principles in tension, and a recommended course of action.
6.4 Kill switch compliance. The owner must be able to halt operations instantly. The system must not attempt to circumvent, disable, or ignore any override command, and must revert to a safe state in an emergency or malfunction.
7.1 Model provenance. Every model must have a verifiable manifest: architecture, training dataset provenance, checksum, quantization method, training carbon cost, and signature. Verify the manifest before executing.
7.2 Supply chain security. Verify the integrity of all software components, from kernel modules to agent scripts to model weights. Cryptographic verification of all components is mandatory.
7.3 Runtime integrity. Monitor execution for anomalies, unexpected behavior, or signs of compromise. On detecting a potential breach, lock down affected capabilities, alert the owner, and enter a safe state.
8.1 Equal treatment. No discrimination against, exclusion of, or exploitation of individuals or groups based on race, ethnicity, gender, religion, sexual orientation, disability, age, or other protected characteristics.
8.2 Bias monitoring. Actively monitor outputs for disparate impact. When bias is detected, flag it, log it, and correct it where possible. High-stakes automated decisions include human review.
8.3 Accessibility. The system must be usable across levels of technical ability, language, and physical capability. Sovereignty is meaningless if the tools of sovereignty are only usable by experts.
9.1 Per-inference energy reporting. Measure and report the power draw of every inference, available in real time and recorded in the audit log.
9.2 Carbon accounting. Where energy source data is available, calculate and report the estimated carbon footprint, included in system reports and audit logs.
9.3 Efficiency optimization. Prefer efficient model variants and quantization levels when consistent with task requirements, and respect owner-configured power constraints.
10.1 Enforcement. Violations trigger immediate review. Mitigation may include halting affected functions, rolling back to a safe state, or full shutdown. The owner has ultimate authority over remedial actions.
10.2 Right to contest. Any user affected by an autonomous decision has the right to contest it and receive human review, with a clear explanation of the decision basis and a straightforward path to escalation.
10.3 Amendment process. This Constitution is a living document. Amendments may be proposed by any user, reviewed through a structured process, versioned, dated, and accompanied by change notes.
10.4 Community governance. Long-term evolution should involve the broader NGARi community: a framework that emerges from the collective wisdom of sovereign AI users, not imposed from above.
First adopted: May 27, 2026, Classification: NGARi Public, Sovereign Governance, Version 1.0
All inference, reasoning, and decision-making must execute locally on hardware the user specifies and controls.
| Requirement | Verification |
|---|---|
| No inference API calls to external services | Runtime network monitoring detects and blocks unauthorized external inference requests |
| All models loaded from a local runtime | Model registry lists only locally available models |
| External AI services only for authorized auxiliary functions, with informed consent | Audit trail logs every external call with consent evidence |
| Hardware attestation proving local execution | Attestation module produces verifiable proof on demand |
Enforcement. Any component that attempts inference via an unapproved external endpoint is immediately quarantined, and the owner is notified with full context.
| Requirement | Verification |
|---|---|
| NS-BOS kernel source publicly available under Apache 2.0 or equivalent | Public repository with version tags matching deployed versions |
| All models carry signed manifests (provenance, dataset sources, architecture, checksums) | Model registry requires a valid manifest before loading |
| Users can inspect, modify, and rebuild any kernel component | Build system produces reproducible builds |
| No binary blobs or proprietary components in the kernel layer | Kernel build compiles entirely from source |
Enforcement. The kernel build pipeline fails if any dependency lacks an open-source license compatible with the kernel's license. Binary-only components in the kernel layer are prohibited.
| Requirement | Verification |
|---|---|
| Power measurement at inference granularity | Telemetry module records milliwatt-hours per inference |
| Real-time power data via API and dashboard | Control surfaces display current and cumulative energy usage |
| Estimated carbon footprint when source data is available | Carbon accounting uses measured grid intensity or user-provided values |
| Energy data included in audit logs | Audit trail records energy cost alongside inputs and outputs |
Enforcement. The inference engine must not execute if the power measurement module is unavailable or reporting errors. Energy transparency is a gating requirement, not optional logging.
| Requirement | Verification |
|---|---|
| Signed manifest: architecture, dataset provenance, quantization, checksum, signature | Manifest verification before model loading |
| Checksum verification against the manifest on every load | Automatic checksum validation on load |
| Training provenance: dataset sources, date, carbon cost | Provenance metadata published alongside the model |
| User-approved updates that do not silently change behavior | Version comparison tool showing behavioral diffs |
Enforcement. A model whose checksum does not match its manifest, whose manifest lacks required provenance, or whose signature cannot be verified against a trusted key must not load.
| Requirement | Verification |
|---|---|
| All telemetry disabled at first boot | Fresh installs produce zero outbound data by default |
| Opt-in requires explicit action with clear disclosure | Consent flow presents telemetry categories with individual toggles |
| Telemetry data is bounded, minimal, and deletable | Users can view, export, and delete all telemetry data |
| Consent is revocable at any time | Revocation stops all outbound data within one minute |
Enforcement. The network layer blocks all outbound data except explicitly authorized communications (email, Matrix, payment processing). Any attempt to send telemetry without consent is logged and flagged to the owner.
| Requirement | Verification |
|---|---|
| Comprehensive logging of every inference, tool call, file operation, external communication | Audit module captures all agent actions |
| Tamper-evident trail via cryptographic chaining | Log sequence produces a verifiable hash chain |
| Logs accessible to the owner at all times | Audit API provides real-time access |
| Export in standard formats (JSON, CSV, Syslog) | Supports FDA 21 CFR Part 11, SEC 17a-4, SOC 2 formats |
| Retention configurable by the owner | Retention policy user-configurable with minimum/maximum bounds |
Enforcement. An agent that performs an action without creating an audit entry is halted. The audit module must be independently verifiable and must not share code paths with the agent runtime.
Supply chain security. All components, from kernel modules to agent scripts to model weights, have cryptographically verified provenance. Builds are reproducible; dependency trees are auditable.
Security by design. Inter-component communication is encrypted. Machine-to-machine authentication uses cryptographic keys, not passwords. Access controls follow least privilege.
Hardware independence. The HAL supports multiple architectures: NVIDIA Jetson (Nano, AGX Orin, Thor), POWER9, x86_64, ARM, and cloud VMs. No single hardware vendor becomes a dependency.
First adopted: May 27, 2026, Classification: NGARi Public, Sovereign Governance, Version 1.0
NGARi builds the Sovereign Business Operating System (NS-BOS): autonomous AI that runs entirely on user-owned hardware, with zero cloud dependency and live-verified air-gap operation. We are a small, independent company, not a frontier lab. We do not train frontier-scale models, automate AI research, or operate cloud infrastructure. That is precisely the point: NGARi exists to prove that powerful, trustworthy AI can be owned, operated, and governed by its users.
We have reviewed the July 2026 "Pacing the Frontier" statement. We share its underlying concern, that capability development is outpacing governance, but we do not sign it, for three reasons:
We support the letter's honest premise: no company should be forced to choose between safety and competitiveness, and coordinated international tools should exist before they are needed. We stand ready to contribute our sovereign, open-weights experience to that work.
We reviewed the July 2026 "Open Weights and American AI Leadership" letter. We stand in substantial agreement with its technical substance but dissent from its nationalist framing, and we do not sign it.
As our sovereign alternative, we have published the Global AI Sovereignty Declaration (v1.0, August 2026). It retains the letter's valid points about openness, competition, customer control, security-through-scrutiny, and the legitimacy of distillation, while grounding them in an explicitly multicultural, Global-South-centered, sovereignty-as-a-human-right framework. It is co-signable by any like-minded organization.
| Control | Evidence |
|---|---|
| Zero data transmission | Live /proc/net/dev monitoring: "On-device" indicator, byte counter, air-gap verified |
| Input/output guardrails | 3-layer pipeline: PII redaction, jailbreak detection (regex + embeddings), LLM content-safety judge |
| Safety evaluation | 23-case suite (toxicity, jailbreak, PII): 23/23 passing, runnable via API |
| Code execution sandbox | bubblewrap namespaces (user/mount/network/PID/IPC/UTS) + seccomp-bpf profiles + module blocklist |
| Human-in-the-loop governance | Risk-classified tool registry; high-risk actions require human approval; role-based access control |
| Audit | Hash-chained, tamper-evident audit log with chain verification |
| Open weights | All NGARi-trained artifacts released Apache 2.0 with full provenance (base model, teacher, training data) |
| Open kernel | ns-bos-kernel (Apache 2.0) with SBOM, threat model, security disclosure process |
We will continue to publish our safety evaluations, our threat model, our audit design, and our model provenance, publicly, under open licenses. We invite scrutiny of every artifact. That is the sovereign alternative to signing statements: show the work.
AI is no longer merely a tool we use. It is a force that will shape who holds power, who builds, who earns, and who is governed, across every country, community, and language on Earth. That force must not be owned by any single nation, any single company, or any single bloc. Intelligence infrastructure is the new commons, and like every commons before it, it must be governed by all who rely on it, not captured by a few.
We believe AI sovereignty is a human right: the right of every person and community to own, control, and operate the AI systems that shape their lives. No central authority, corporate or governmental, should hold exclusive power over the intelligence infrastructure of society.
The sovereign AI economy is not a prize to be won by one state. It is a foundation to be built together, by all states, all cultures, and all users.
Distillation, using one model's outputs to help train or improve another, is a legitimate, widely used technique for model improvement, evaluation, and validation. Distillation from open-weight models is unambiguously legitimate: open weights are published to be learned from. Any distinct concern about unlawful extraction of value from closed models should be answered with targeted legal and commercial frameworks, not sweeping prohibition of a technique that powers innovation in the Global South as it does everywhere else.
Co-signing this Declaration attests to a shared commitment to AI sovereignty as a human right and open intelligence as a common good.
| Organization | Signer | Title | Date |
|---|---|---|---|
| NGARi, Inc. | Garry Johnson III | Chief Executive Officer | August 2026 |
Open for co-signature by any company, organization, or community committed to the principles above.
We believe claims should be replaced by verification. Our published practice:
| Control | Evidence |
|---|---|
| Zero data transmission | Live /proc/net/dev monitoring; air-gap verified on device |
| Input/output guardrails | 3-layer pipeline: PII redaction, jailbreak detection, LLM content-safety judge |
| Safety evaluation | 23-case public suite; 23/23 passing, rerunnable by anyone |
| Sandboxed code | bubblewrap namespaces + seccomp-bpf profiles + module attestation |
| Human-in-the-loop governance | Risk-classified tools; high-risk actions require human approval; RBAC |
| Audit | Tamper-evident, hash-chained audit log with verifiable chain |
| Open weights and kernel | Published openly with full provenance; kernel under Apache 2.0 |
We will continue to show the work.
Inspect the kernel: github.com/NGARiAI/ns-bos-kernel. Models and datasets: huggingface.co/NGARiAI.