IAIA NAIA HACK The Judge Protocol TJP = OPEN STANDARD

Open Governance Standard · CC BY 4.0 · Judge Protocol Foundation, Sweden

Human oversight of
artificial intelligence

"AI may analyze, recommend and simulate — but a human must authorize."

The Judge Protocol (TJP) is a proposed global governance framework establishing a mandatory human authorization layer for all consequential AI decisions — from military targeting to financial markets to autonomous weapons.

Every major governance framework
has emerged from a defining moment of crisis.

AI is embedded in military targeting systems, financial markets, healthcare decisions and critical infrastructure — operating at speeds no human can match, at scales no regulator currently governs, with consequences that are increasingly irreversible. This is that moment.

The Gulf conflict, 2026

AI systems embedded in active military planning and target identification without a universally agreed governance framework.

Nuclear AI simulations

AI models recommended nuclear strikes in 95% of simulated crisis scenarios. No model ever chose de-escalation. — King's College London, 2026

Magnifica Humanitas, 2026

Pope Leo XIV: "It is not permissible to entrust AI systems with lethal decisions." The moral case has been made. The technical architecture to enforce it is what this framework proposes.

The governance vacuum

No existing framework addresses the cross-domain, cross-border nature of AI risk. None establish a binding global mechanism for human authorization.

The same logic that built the internet

In TCP/IP, no packet is considered delivered without an explicit acknowledgement signal. The Judge Protocol applies the same principle to AI governance.

AI may analyze · AI may recommend · AI may simulate → A human must authorize

No AI action is considered authorized until an explicit human acknowledgement is received.

Enterprise Architecture

The Judge Protocol operates across three interdependent layers — silicon enforcement, national governance, and global oversight — with domain-specific rule sets and an open legal standard.

Global
Layer 3
IAIA
IAIA Global Emergency Dashboard Global AI Registry GÉANT Backbone
National
Layer 2
NAIA
NAIA Decision Gate Platform GAE Human Authorizer
Silicon
Layer 1
HACK
HACK COE ACP On-chip Audit Log
Decision
Gate Tiers
Tier 1 — Hard Stop Tier 2 — High Tier 3 — Significant Tier 4 — Routine
Domain
Rule Sets
Military Financial Healthcare Infrastructure Judicial Physical P1–P4

Open standard · CC BY 4.0

All documents are freely available under Creative Commons Attribution 4.0. Cite, share, adapt — attribution required.

The Judge Protocol at AI4Peace 2026

Alexander Hofmann presents "The Judge Protocol: Making Human Authority over AI Enforceable" at the AI4Peace 2026 International Symposium — the first biennial global gathering dedicated to AI, conflict prevention and peace, co-hosted by the University for Peace (UPEACE) Rome, the Pontifical Academy for Life, and the Pontifical Lateran University, 20–22 September 2026 in Rome.

Session

War, Escalation and Human Control

How hardware-enforced human authorization closes the gap between AI decision speed and the human oversight that existing governance frameworks assume.

Monday 21 September · 14:45–15:00 · Room B, Session 2 · Pontifical Lateran University · Chaired by Antonio Marturano

Proof It Can Be Done

The Judge Protocol does not emerge from a vacuum. It draws inspiration from two proven governance precedents: the IAEA — demonstrating that binding international oversight of dangerous technology is achievable — and CERN — demonstrating that complex international technical infrastructure can be governed independently of any single nation's interests.

Architecturally, the pattern runs: CERN gave the world the internet. TCP/IP gave it the universal language. Proton emerged directly from CERN scientists to protect the privacy of what CERN created — sovereignty by design, open source. The Judge Protocol applies TCP/IP's own architectural principles to govern the AI systems now running on it — and continues the practice as much as the principle. The reference sandbox runs on open source infrastructure throughout: NVIDIA OpenShell, Apache ActiveMQ Artemis, PostgreSQL, Grafana. The hardware specification proposes open silicon foundations — OpenTitan and RISC-V cores — released under the same CERN Open Hardware Licence CERN uses for its own designs.

HACK's hardware mandate has its own, more specific precedent: the Trusted Platform Module. TPM began in 1999 as an open standard defined by a five-company consortium — Compaq, HP, IBM, Intel and Microsoft — and spread by being embedded in every motherboard by default. It took until 2021, when Windows 11 made TPM 2.0 "non-negotiable," to become a true mandate. Twenty-two years from consortium to mandate, with nothing more than security hygiene behind it. HACK proposes the same arc for AI governance — and starts from a stronger position: Anthropic, OpenAI, the U.S. Congress and the Vatican are already pushing in the same direction before a single chip has shipped.

Powerful technology belongs to humanity — not to any single nation, company or interest.

The framework is open.
The conversation is urgent.

The Judge Protocol is a working draft designed to evolve. Contributions, institutional engagement and expert review are welcome. The standard is open — owned by nobody, available to everyone.

Download the Executive Summary