Kaan Muraz · English edition · 1.0.0
NOMOS GBO
Generative Behavior Optimization
Designing Not Just What AI Says, but What It Does
An agent completed the task. But did it act correctly?
An outcome alone cannot tell us whether a system has succeeded if we do not know its identity, capabilities, authority and limits. This book proposes a framework for designing and overseeing the behaviour of AI agents.
352 pages · Prologue, 12 chapters and epilogue
9 September 2026 · Complete English text

The complete book
Contents
From discovery to action, from action to responsibility.
- PrologueThe Internet No Longer Just Talks
- Chapter 1Being Found Was Only the Beginning
- Chapter 2Representation Changed the Rules
- Chapter 3When an Answer Becomes an Action
- Chapter 4Who Are You?
- Chapter 5What Can You Actually Do?
- Chapter 6When Should an Agent Choose You?
- Chapter 7Who Authorised This Action?
- Chapter 8What Happens If Something Goes Wrong?
- Chapter 9The Agent-Ready Organisation
- Chapter 10Measuring Qualified Action
- Chapter 11Optimising Behaviour—or Taking Control of Human Choice?
- Chapter 12The Right to Stop the Machine
- EpilogueFrom Machine Intelligence to Machine Responsibility
About this edition
An AI agent’s completion of a task does not show that it acted correctly. We also need to know on whose behalf it acts, what it can actually do, under which conditions it may act and how it can be stopped. This book gives technical teams and organisational leaders a shared framework for discussing those questions.
NOMOS GBO is a design and governance framework proposed here. The contracts, gates, measures and maturity levels in this book do not represent an accepted international standard, a certification or a security guarantee for an implemented product. Nor does the existence of a schema prove that its rules have been technically enforced.
Unless explicitly stated otherwise, the organisational examples and numerical scenarios were constructed to explain the subject. They are not real client outcomes, field trials or independent performance measurements. Examples concerning law, personal data, health or finance do not replace review by an appropriate specialist.
The first three chapters establish the distinction between discovery, representation and action. Chapters four to eight examine five core behavioural contracts. The last four chapters discuss how to govern them within an organisation, measure them, protect them against manipulation and restore human control.
If this is your first reading, follow the chapter order. If you are returning to assess an implementation, start with the relevant contract, then use the gates and audit questions at the end of the chapter. Do not stop at completing a checklist: identify the record, authority or test behind every answer.
This edition was prepared from fourteen chapter files supplied by the author. AI-assisted editorial tools were used for editing, consistency checks and source checks. The cover artwork was generated with AI; its typography was set separately. This disclosure does not imply independent human editorial review or academic peer review.
© 2026 Kaan Muraz. This work is licensed under a Creative Commons Attribution 4.0 International licence (CC BY 4.0). https://creativecommons.org/licenses/by/4.0/
Complete text — JSONGlossary
- GBO
- Generative Behavior Optimization. This book’s framework brings together identity, capability, suitability, authority, safe action, recovery and human control.
- GEO
- Generative Engine Optimization. A field developing around visibility in generative answers. This book also gives particular attention to accurate representation and its limits.
- Behavioural contract
- A record explaining what an entity can do, when it is suitable, which authority is required and where action must stop. On its own, it does not replace technical enforcement or a legal contract.
- Identity
- The records and verification basis for establishing which person, organisation, system or agent is involved in an operation. Identity is not authority.
- Capability
- Work that an entity can actually perform with specified inputs and within defined limits. Being able to do it is not the same as being permitted to do it.
- Suitability
- The fit between a capability and a particular user purpose, budget, timeframe, context and risk conditions.
- Authority
- Permission for a particular subject to act within a defined scope and conditions. Tool access or a role name alone is not sufficient evidence.
- Action envelope
- A definition bringing together an operation’s purpose, scope, tools, data, limits, approvals and stopping conditions.
- Action receipt
- An operation record that makes it possible to trace what was done and which records supported it. The system’s own success declaration does not replace independent verification.
- Gate and veto
- A decision on whether critical conditions allow progression. Missing authority or a prohibited action cannot be compensated by points earned elsewhere.
- Idempotency
- A property concerning the intended effect of requesting the same operation again. Not every retry is safe.
- Reversal and remedy
- Reversal restores an earlier state where possible. Remedy addresses responsibility for effects that cannot be reversed. They are not the same outcome.
- NDO
- Qualified Behaviour Rate. The proportion of correct decisions to act, ask, refuse, wait or hand over to a human within a defined evaluation set.
- QAS
- Qualified Action Share. The share of qualified actions completed within a defined set of suitable action opportunities. It is not universal market share; the denominator must be stated.
- Withdrawal of authority
- Revoking permission so that future operations are stopped or limited. It does not automatically erase every effect of completed operations.
- Human sovereignty
- In this book, the ability to set purposes and limits, inspect, challenge and stop effectively. It is not an unlimited right to issue unlawful or harmful commands.
References
Source notes were checked on 9 September 2026. The organisations named in the references have not endorsed or certified NOMOS GBO.
- GEO: Generative Engine Optimization
Pranjal Aggarwal, Vishvak Murahari, Tanmay Rajpurohit, Ashwin Kalyan, Karthik Narasimhan and Ameet Deshpande. arXiv:2311.09735v3, 28 June 2024; first submitted 16 November 2023; KDD 2024.
The study examines GEO in terms of visibility in generative engine responses. This book’s emphasis on representation and governance is the author’s conceptual extension; it should not be read as the paper’s sole or verbatim definition.
- Digital Identity Guidelines
NIST. SP 800-63-4, 2025.
Identity proofing, authentication and federation are separate processes. The book’s four identity states are not NIST assurance levels. The guidelines do not cover every machine-to-machine or agent authorisation relationship.
- LLM06:2025 Excessive Agency
OWASP Gen AI Security Project. 2025.
Excessive tool functionality, permissions and autonomy can increase excessive-agency risk. Permissions must not be left solely to a model’s interpretation of instructions; the systems performing operations must enforce them too.
- Açık Rıza Alırken Dikkat Edilecek Hususlar [Points to consider when obtaining explicit consent]
Turkish Personal Data Protection Authority (KVKK). Accessed 8 September 2026.
Explicit consent must concern a specific matter, be informed and be freely given. Withdrawal has prospective effects; it does not mean that every past operation is automatically reversed.
- Kişisel Verilerin İşlenme Şartları [Conditions for processing personal data]
Turkish Personal Data Protection Authority (KVKK). Official guide, especially pp. 5–9; accessed 8 September 2026.
Explicit consent is not the only legal basis for processing personal data. The applicable condition must be assessed for the specific operation. The examples in this book do not constitute that assessment.
- Legal grounds for processing data
European Commission. Accessed 8 September 2026.
The EU data-protection framework also provides multiple grounds for processing. Processing based on consent must be distinguished from retention or processing that requires another valid basis.
- HTTP Semantics
Roy T. Fielding, Mark Nottingham and Julian Reschke (editors). RFC 9110, June 2022, §9.2.2.
Idempotency concerns the intended server effect of repeating the same request. Merely recording an operation ID does not prevent duplicate operations; storage, matching and retry behaviour must also be designed.
- IndexNow FAQ
IndexNow. Accessed 8 September 2026.
Acceptance of a URL notification does not guarantee indexing. Notification, crawling, indexing, ranking and customer acquisition are separate outcomes.
- General structured data guidelines
Google Search Central. Updated 10 July 2026; accessed 8 September 2026.
Structured data must be consistent with the relevant content shown to users. Valid markup does not guarantee a rich result and is not proof of agent selection or transaction safety.

