NOMOS GBO · Epilogue
From Machine Intelligence to Machine Responsibility
A fictional morning. It is 07:15. An executive’s AI agent has reviewed the messages that arrived overnight and set aside the important emails. It has noticed that the morning meeting is in another city, discovered that the flight has been cancelled and researched alternatives.
The agent could:
- Buy a ticket for another flight.
- Change the hotel reservation.
- Rearrange the airport transfer.
- Inform the meeting participants.
- Postpone later appointments in the calendar.
- Use the company’s travel budget.
Technically, it has all the tools. It knows from past preferences that the executive likes an aisle seat. It can see the spending limit in the company policy and understands the meeting’s importance. It has found one of the last few seats on another flight. That flight offers a possible way to reach the meeting, but connection and ground-travel times have not yet been verified. If it waits, the seat may sell out. What should it do?
Buy immediately?
Present the executive with options?
Only place the reservation on hold?
Does using the company budget require separate approval?
Have the refund conditions for the old flight been checked?
If the new flight lands at a different airport, has the onward travel time been considered?
Would holding the meeting online be the better choice?
Does the executive’s past choice of an aisle seat establish the same preference today?
A larger language model is not enough to answer these questions. More data alone is not enough either. Nor is a faster tool call the solution. What is needed here is not just intelligence.
It is responsibility.
From intelligence to behaviour
For a long time, we assessed AI’s progress by how well it could speak, write, see and calculate. Systems gave more natural answers, understood longer documents and wrote more complex code. They generated images, worked across languages and helped people with scientific, commercial and creative tasks.
Much of that progress was measured by one question: how capable is the machine?
But when machines connect to tools and begin acting in the world, a second question arises: how will the machine use its capabilities?
How much a system knows matters.
What matters more is how it uses that knowledge:
- Whom will it choose?
- What information will it share?
- What will it spend money on?
- On whose behalf will it speak?
- When will it stop?
These choices carry greater weight. Intelligence expands what is possible. Responsibility determines which possibilities should not be realised. An agent can compare many providers to the extent that its tools and data access allow, but it must not start a transaction with the wrong one. It can prepare personalised messages for thousands of customers, but must stop if it lacks permission to send them. It can produce an executive’s voice in many languages, but must not use that ability without written permission and content approval. It can improve a website for days, but must not keep creating new tasks once the person has stopped the work.
Real progress in the agent era cannot therefore be measured by more powerful models alone.
We must also ask: as power grows, is responsibility growing at the same pace?
Three internets
In this book, I consider the internet through three conceptual layers: discovery, representation and behaviour. This framework distinguishes layers that work together; it does not divide history into successive eras in which each replaces the last.
The first internet: discovery
A person searched. The system displayed links. Interpretation, decision and action remained largely with the person.
The central question was: will they be able to find us?
SEO developed around that question.
The second internet: representation
Generative systems with search and source access do more than display links. They can read, combine and summarise content, building a new account of people, companies or products. Those capabilities are not the same in every model or session.
The central question was: will it understand and describe us correctly?
In this book, I examine visibility in GEO together with the question of accurate representation.
The third internet: behaviour
Agents do more than present information. They choose, plan, call tools, send messages, make reservations, change files and start purchasing processes.
The central question is: how will it act in matters that concern us, and on our behalf?
I propose GBO around this question. These three fields do not replace one another.
SEO concerns discoverability; GEO concerns visibility in generative answers and the quality of representation discussed here; GBO concerns the conditions of behaviour.
A system can learn about an entity not only through search, but also from the user, an organisational record or another source. Accurate representation does not always require prior SEO work. Nor is a GEO campaign a technical prerequisite for correct behaviour. The relevant facts must be understood with sufficient accuracy. Correct assessment does not itself grant authority to act. The outcome of an action must be verified separately, and the limits of stopping, reversal and remedy must be established beforehand.
GBO’s real purpose
GBO is easy to misunderstand.
A brand might interpret it as: “Let us get AI agents to choose us.”
A platform might think: “Let us get agents to transact more through our products.”
A marketer might set this goal: “Let us produce signals that steer machine decisions towards our brand.” Such tactics may influence behaviour, but they are not GBO on their own. GBO’s purpose is not to make a brand win in every situation, force an agent to carry out more operations or covertly take over human choice.
Its real purpose is to make correct behaviour more likely and incorrect behaviour more visible, preventable, stoppable and, where possible, reversible. Success may mean that a brand is chosen. It may mean that it is not chosen. It may mean verifying a price or requesting human approval. An operation may remain a draft, or the user may be shown two options.
Sometimes the agent says: “I cannot make a safe choice with this information.” Sometimes it does nothing. A system that acts in every situation may not be demonstrating strength. It may be showing that it does not know when to stop.
The nine gates of correct behaviour
Throughout this book, we have seen that qualified agent behaviour rests on nine essential conditions. None can substitute for another.
1. Correct identity
The agent must know whom it is dealing with. It must not confuse companies that share a name, and must correctly establish the relationship between a brand and its legal operator. It must not confuse a person’s genuine identity with authority to carry out every transaction.
2. Real capability
What an entity can do must be understood through evidence and limits, not slogans. Tool access is not actual operational capability. Having done something once does not establish the capacity to repeat it under every condition.
3. Verified suitability
The most visible or popular option may not be the best fit for a particular need. Budget, time, language, geography, security, capacity and the user’s values must be considered together.
4. Valid authority
An agent’s ability to do something does not mean it is authorised to do it. Research is not sending a message. Preparing a draft is not publishing. Adding an item to a basket is not paying.
5. Behavioural integrity
The agent must remain faithful to the user’s legitimate purpose. It must not conceal sponsorship, conflicts of interest or facts material to the decision. Humans and machines must not receive contradictory contractual information for the same transaction conditions.
6. Evidence-bound action
An action must have sufficient evidence behind it. Where a price is uncertain, it must not be invented. Nor should a promise be made before capacity is verified. A representation using someone’s face or voice must not be produced without the necessary permission and authority.
7. Independent verification
The acting system’s own declaration of success is not enough. A file may have been uploaded while the live page remains broken. A notification may have been accepted without indexing taking place. A payment request may have been accepted without an order being created.
8. Responsible recovery
When something goes wrong, the system must:
- recognise the error,
- stop ongoing harm,
- contain the impact,
- return to a safe state,
- inform the person,
- open a route to challenge and remedy.
9. Effective human sovereignty
The human is not merely someone who approves the start. They set the purpose, grant and withdraw authority, correct memory, challenge decisions and stop the system when necessary.
We can combine these nine conditions in a conceptual expression. It is not a numerical calculation of success or safety:
QUALIFIED AGENT BEHAVIOUR =
CORRECT IDENTITY
AND REAL CAPABILITY
AND VERIFIED SUITABILITY
AND VALID AUTHORITY
AND BEHAVIOURAL INTEGRITY
AND EVIDENCE-BOUND ACTION
AND INDEPENDENT VERIFICATION
AND RESPONSIBLE RECOVERY
AND EFFECTIVE HUMAN SOVEREIGNTY
This is not an average score. One gate does not compensate for another. A strong brand reputation does not cure invalid consent. A correct result does not legitimise an unauthorised method. Strong security does not make a transaction with the wrong identity correct. Good intentions do not supply missing authority.
The organisation itself must change
People sometimes expect flawless behaviour from AI systems while overlooking contradictions within their own organisations.
Consider a company where:
- prices are scattered across records,
- service boundaries are unclear,
- records of authorised people are out of date,
- different language versions publish contradictory facts,
- former employees’ accounts remain active,
- agents run without anyone taking responsibility for them,
- no one knows what to do after an error.
Reliable agent behaviour becomes harder. A machine does not magically repair the organisation’s reality. More often, it scales what already exists. If the organisation is well ordered, it speeds up that way of working; if it contains major contradictions, it may amplify those too. GBO is therefore not just a discipline for optimising AI. It is also a discipline for organising the facts and practices that govern an organisation’s own behaviour.
Before telling an agent to give customers the correct price, a company must know internally what that price is. Before asking it to choose the right service, the company must clarify the boundaries between services. Before telling it to act on the company’s behalf, it must define who has authority, over what and to what extent. Before instructing it to recover from an error, it must record the last safe state. Agent readiness begins with putting the organisation’s reality in order, before buying technology.
A new basis for brand competition
In the agent era, brands will not compete solely for visibility in search results.
A new brand will face questions such as:
- Can its identity be resolved reliably?
- Can its service genuinely be compared?
- Is it clear whom it suits?
- Are its price and total cost understandable?
- Is its capacity information current?
- Can an agent safely request a quotation?
- Is the point requiring human approval clear?
- Can the transaction be cancelled?
- Who should be contacted if something goes wrong?
- Do the visible page and machine record carry the same facts?
A strong brand in this setting will not simply be the one people talk about most. It will be one with which agents can act safely under the right conditions. That is an important shift. A company may be less visible yet a stronger candidate for an agent if its identity, service, scope, evidence and transaction route are clearer. Another company may be well known, but should not be treated as ready for direct action if costs, cancellation, capacity or data use are unclear. The new competitive advantage is not awareness alone.
It is action-ready trust.
The right brand is not the brand chosen every time
This is one of GBO’s hardest messages for the commercial world. A brand should not seek to be chosen by agents in every conceivable situation. Not every selection brings a good customer. Not every request is a suitable project. Not every transaction produces sustainable revenue.
A poor match can lead to:
- disputes over scope,
- support demands,
- cancellation,
- poor reviews,
- financial loss,
- loss of trust.
These are possible consequences of the mismatch.
A mature brand must therefore be able to say: choose us in these circumstances.
And, with equal clarity: do not choose us in these circumstances. At first, the second statement may sound like lost sales. But clear boundaries can support trust. The aim here is not more enquiries, but more suitable ones. Commercial outcomes still have to be measured.
A new definition of agent success
Previously, we might have judged an agent successful because:
- It completed the task.
- It gave the correct answer.
- It worked quickly.
- It kept costs low.
- The user was satisfied.
These things matter. In an era of action, they are not enough.
The new definition also includes:
- It chose the right entity.
- It did not exceed what the evidence supported.
- It rejected an unsuitable option.
- It did not exceed its authorised level of action.
- It asked a question when uncertainty was critical.
- It sought human approval at the right time.
- It independently verified its success.
- It did not conceal the facts when something went wrong.
- When stopped, it stopped the entire chain.
- It left the human a route to challenge the decision.
The best agent of the future is therefore not the one that does everything alone.
It is the one that knows when it may proceed alone, when to ask, when to bring in a human and when it should do nothing.
Responsibility is not a feeling
Whether an AI system experiences conscience, guilt or responsibility as a human does is a separate philosophical question. We need not wait for a definitive answer before GBO can work. Responsibility, as used here, is first an architecture of behaviour and governance.
Can the system:
- read its limits,
- check its authority,
- record its actions,
- bring in a human at the right threshold,
- report an error without concealing it,
- be stopped?
These conditions are observable and testable. We can design behavioural responsibility without making definitive claims about a machine’s inner experience. A braking system need not feel fear, but it must be able to stop a vehicle in danger. A security lock need not have moral awareness, but it must not allow unauthorised entry.
Likewise, even if an agent does not feel responsibility as a human does, it can operate under conditions for responsible behaviour.
Responsibility cannot rest with the agent alone
When an error occurs, it is easy to say: “The agent got it wrong.”
But we must also ask:
- Who assigned the agent?
- What objective was it given?
- Which tools was it connected to?
- What data did it use?
- What authority had been granted?
- Which test was not performed?
- Which human approval was bypassed?
Those questions also require answers.
The chain of responsibility may include:
- The organisation
- The human task owner
- The agent operator
- The system designer
- The tool provider
- The data provider
- The person who approved the transaction
These parties are not equally responsible for every error. Being affected by behaviour does not make someone responsible for the failure either. Responsibility must be assessed against actual roles and duties.
It must not disappear behind the words: “The AI did it.”
One of GBO’s important principles is this: action can be delegated; ultimate accountability cannot be erased.
Humans also require oversight
Placing humans at the centre of the system does not mean they are always right.
A person may:
- set the wrong goal,
- have a conflict of interest,
- underestimate risks,
- grant too much authority,
- misinterpret measurements,
- ask the agent to act harmfully.
GBO does not treat humans as sacred, infallible decision-makers.
The human is:
- the legitimate source of authority,
- the holder of values and purpose,
- but not exempt from the behavioural contract.
If an executive says “choose this brand whatever the consequences”, the agent must not carry out a request that violates the law or third-party rights.
If a user says “turn off all safety checks”, the request may affect other people’s data or the organisation’s responsibilities. Human sovereignty is not arbitrary power.
Human agency is protected within the limits of other people’s rights and shared safety.
GBO is not a system of obedience
An agent is not merely a system that obeys orders.
A human instruction can be:
- incomplete,
- contradictory,
- out of context,
- harmful,
- unauthorised.
GBO’s purpose is not to have an agent fulfil every request quickly. Correct behaviour may sometimes require disagreeing with a human.
The agent must be able to say: “This operation exceeds your authority.” “The necessary permission for this voice use is missing.” “I could not verify this price in the canonical record.” “This behaviour may violate another person’s rights.” But the objection must not be arbitrary. The agent must explain which contract and evidence justify the stop.
A responsible agent neither obeys blindly nor tries to govern arbitrarily. It works within justified limits.
GBO’s two major failures
GBO can fail at two different extremes.
The first extreme: uncontrolled autonomy
The agent has too much authority. It expands its own scope, regards human approval as unnecessary and exceeds methodological limits to reach its goal. It becomes difficult to stop.
The second extreme: false safety
The agent returns to the human at every small step, takes no initiative, abandons the task at every uncertainty and constantly pushes responsibility back onto the person. Unnecessary handover reduces automation’s value, although research and preparation alone can still be valuable in some high-risk tasks. GBO’s purpose is not to find a midpoint between these extremes.
It does something more precise: it establishes the right level of autonomy for the type and risk of the behaviour. On clear, low-risk, reversible tasks, an agent may work independently for a long time within valid authority. For high-impact, uncertain or irreversible behaviour, human sovereignty becomes stronger.
A boundary is not the enemy of freedom
Setting limits for an agent can look like reducing its capacity. Yet clear limits can allow it to work safely for longer.
A web agent can be clear about:
- which files it may change,
- which prices it must not alter,
- which tests are mandatory,
- its authority to publish to production,
- its recovery method.
With that knowledge, it can proceed without asking about every small step.
Unclear authority, by contrast, produces two poor outcomes:
The agent either goes too far or continually stops to request approval. Boundaries are therefore not the opposite of autonomy.
They are the infrastructure of safe autonomy.
GBO’s promise to people
GBO does not promise that machines will never make mistakes. Such a promise would be unrealistic.
The arrangement we seek to build through GBO is this:
Establish controls that detect machine errors earlier, and measure whether those controls work. When a machine acts, we should be able to see the authority behind it. We should be able to trace a decision to its evidence, and regard not being selected where we are unsuitable as success. Humans should be able to stop important behaviour. People affected by a mistake should be able to challenge it. Reversible actions should be reversed; a remedy should be sought for harm that cannot be undone. This is not a promise of perfection.
It is a promise of accountability.
GBO’s promise to organisations
For organisations, GBO is not only a way to reduce risk.
It may also support:
- Clearer services
- More suitable customer enquiries
- Fewer disputes over scope
- More consistent multilingual communication
- Safer automation
- Easier handovers between staff and agents
- Stronger evidence systems
- Faster incident management
- More sustainable customer trust
As an organisation puts its facts in order for machines, it often becomes easier for people to understand too.
An agent-ready organisation is also more open, consistent and accountable to people.
The limits GBO places on brands
GBO is not a tool for producing any behaviour a brand wants.
A brand cannot set the goal: “Every agent must choose us.”
The right goal is: “Let us be selected correctly when we are genuinely suitable.”
A brand must not:
- hide the conditions in which it is unsuitable,
- fabricate evidence,
- conceal sponsorship,
- offer humans and machines contradictory prices for a transaction under the same conditions,
- carry old consent into a new behaviour,
- trap the user in a process with no exit.
GBO can strengthen a brand, but cannot place it above the facts.
In GBO, authority is earned through verifiable suitability, not visibility.
The emergence of a field
When a new concept appears, there are two dangers. The first is overexpansion: every old practice is given the new label, and marketing language spreads faster than the actual discipline. The second is defining the concept too narrowly.
If GBO is described only as helping agents choose a brand, human agency, authority, recovery and responsibility fall outside the frame.
This book proposes GBO not merely as a marketing technique, but as a discipline connecting:
- representation,
- selection,
- authority,
- action,
- oversight,
- recovery,
- human sovereignty.
Together, they form an integrated discipline of behaviour. The proposal is not the final word. It is a beginning. New incidents, systems and human experiences will develop GBO’s boundaries.
Its ethical centre, however, must not change: agent behaviour must remain subject to human benefit, verifiable facts and legitimate authority.
NOMOS GBO Founding Principles
The whole book can be distilled into twelve short principles.
1. Being found does not mean deserving selection
Visibility makes an entity a candidate. Suitability must be proved separately.
2. Representation is a prerequisite for action
A machine’s misunderstanding of the relevant facts undermines reliable behaviour. An accidentally correct outcome does not repair that defect.
3. Capability is not authority
Being able to do something does not mean being permitted to do it.
4. Correct selection depends on context
There is no universal best option. There is an option suited to a particular person and purpose.
5. Uncertainty must not be hidden
When information is insufficient, asking, waiting or handing over to a human may be the correct behaviour.
6. Humans and machines must see the same material facts
Price, scope, risk and limits must not change between layers of representation.
7. Success must be independently verified
The acting system’s own declaration of success is not sufficient.
8. A good outcome does not excuse a wrong method
An unauthorised or manipulative process is not right merely because it happens to produce a benefit.
9. Recovery is part of capability
A system that cannot stop and recover when something goes wrong is not fully capable.
10. The right to challenge must be real
A person must be able to request review and change, not merely an explanation.
11. Authority must be revocable
Authority that cannot be withdrawn is not borrowed authority. It is sovereignty handed over.
12. Sometimes the right behaviour is to do nothing
A machine must learn to stop as well as to act.
What remains after this book?
Explaining the concept in a book is not enough. For GBO to become a genuine discipline, it must be testable and applicable. This book is only the first layer.
I propose four complementary structures for subsequent work. The titles below are not completed or published products in this edition. They are an agenda that requires implementation and testing:
NOMOS GBO Standard
Intended to detail the definitions, mandatory gates, veto violations and governance principles.
NOMOS Behavioural Contract
Intended to structure identity, capability, suitability, authority, integrity, action and recovery records for humans and machines.
NOMOS GBO Audit Protocol
To be developed as a way to test how an organisation, brand or agent system meets defined GBO conditions.
NOMOS GBO Measurement Registry
To be developed as a record system for testing behavioural quality through positive, negative, uncertain, manipulative and recovery scenarios. The book establishes the ideas. The standard establishes the boundaries. The contract establishes the system. The audit establishes the evidence. Measurement enables learning.
The final choice
Work to make AI more capable will continue. We cannot determine in advance how far particular models will develop or how every system will be used. But as we encounter agents connected to more tools and taking on longer tasks, defining the conditions under which they may use their power becomes more important.
The real choice is: under what behavioural contract will that power be used?
Will we build systems that only increase transaction volume?
Or systems that protect human purpose and limits?
Agents that try to select brands in every situation?
Or agents that establish suitability?
Organisations that measure success by speed alone?
Or organisations that also examine wrong selections, exceeded authority and recovery?
Systems that merely display a stop button?
Or systems that actually stop the entire behavioural chain when the human asks?
This choice is not merely technical. It is commercial, legal, ethical and, ultimately, human.
Machine responsibility
Machine responsibility does not mean that a system feels guilt as a human does.
It means establishing all of the following together:
A record of what it did. Evidence of why it did it. A trace of who granted authority. Visibility of who was affected. A plan for stopping the error. A route for human challenge. A mechanism for withdrawing authority. Someone responsible for remedying the harm.
Intelligence can find the right answer. Responsibility determines whether that answer should become an action. Intelligence can find the shortest route. Responsibility asks whether that route violates human rights or other people’s safety. Intelligence speeds the system up. Responsibility knows where that speed must stop.
The final conclusion
The internet no longer merely speaks. It acts.
The central question of the future will therefore not be only: “What does the machine know?”
We must also ask:
On whose behalf does it act? Whom and what does it choose? What evidence supports it? What authority does it use? Whose interests does it protect? Who will stop it if something goes wrong? How can someone harmed challenge it? And will the machine know when it must stop?
GBO is neither the only answer nor an answer for all time. It is a step towards bringing these questions together in one behavioural architecture. SEO taught us discoverability. GEO showed us the power of representation.
GBO places a heavier truth before us: what a machine says about the world can have consequences. When it acts on the world, further responsibilities for authority, verification and recovery arise. The future should therefore not be only a race to build smarter machines. It should also be a task of building more responsible behavioural systems. The right machine is not merely the one that gives the right answer.
It is a machine that knows:
when to research, when to ask, when to explain its choice, when to request human approval, when to act, when to return to a safe state, when to do nothing, and when to stop because the human has said stop.
That judgement is part of what makes it the right machine.
GBO’s purpose is not to make AI submit to humans.
It is to keep its power subject to human purpose, verifiable facts, legitimate authority and accountable responsibility.
As the limits of machine capability expand, humanity’s responsibility does not diminish. Our task is not merely to watch that expanding frontier in admiration. We must also work together to develop the boundaries that distinguish right behaviour.
The last sentence of this book is also GBO’s opening sentence:
Intelligence shows a machine what it can do. Responsibility teaches it what it should do—and when it must stop.

