Over the last few days, I’ve been working on an AI safety framework for my own work.
It began as an attempt to gather the many dimensions of AI safety into one place: governance, privacy, security, accessibility, testing, human oversight, incident response, worker protection, and the safe retirement of systems that have reached the end of their useful lives.
The framework draws primarily from the NIST AI Risk Management Framework, its Generative AI Profile, and ISO/IEC 42001, the international standard for organizational AI management systems. It also incorporates principles from the EU AI Act, which establishes legal obligations based on the risks associated with different AI systems.
AI does not exist separately from software, data, or the people expected to use it. For that reason, I have also drawn from the NIST Cybersecurity Framework 2.0, the NIST Secure Software Development Framework, the NIST Privacy Framework, the Web Content Accessibility Guidelines, and OWASP’s security guidance for large language model applications.
This is not a new official standard, and it is not intended to replace any of those sources. It is a practical synthesis: a way of organizing the questions I believe teams should answer from the moment an AI system is proposed through its development, deployment, operation, and eventual retirement.
It is also deliberately a living framework. No checklist can anticipate every product, population, jurisdiction, or emerging harm. Safety has to be managed continuously as models, data, integrations, users, and circumstances change.
But as I worked through the framework, one question kept pulling everything else into focus:
Who, exactly, are we trying to keep safe?
The person at the screen is only the beginning
The obvious answer is the user.
When we picture AI safety, we tend to picture someone sitting in front of a screen. Will the chatbot give them a dangerous answer? Will the assistant expose their private information? Will an agent send a message, spend money, or delete something without meaningful authorization?
These are important questions. But the person at the interface is only one point in a much larger human system.
There is also the applicant being ranked by an algorithm, the artist whose work entered a training set, the moderator filtering disturbing material, the employee working under automated surveillance, and the stranger harmed by a deepfake they never consented to and may never see.
A person can be affected by an AI system without purchasing it, operating it, understanding it, or even knowing it exists.
Those people do not stand in the same relationship to the technology. They do not face the same risks, possess the same information, or have the same ability to walk away. Treating all of them as “users” conceals the differences that matter most.
I have come to think of people as occupying five broad positions around an AI system:
The user interacts with it.
The subject is evaluated, ranked, monitored, or acted upon by it.
The source provides the data, identity, behavior, or creative work from which it learns.
The worker builds, trains, moderates, operates, supports, or works under it.
The public lives with consequences that extend beyond the product and its customers.
These are not five fixed types of people. They are positions, and one person may occupy several at once.
An employee might use an AI assistant while also being evaluated by an automated performance system. Their communications may become a source of training or monitoring data. Their job may change because of the technology. Outside work, they remain a member of the public exposed to AI-generated fraud, misinformation, and systemic failures.
Where someone stands matters. But position alone does not tell us enough.
Position, proximity, and power
I want to examine each of these relationships through three questions.
Position: How does this person relate to the system?
Are they using it, being judged by it, supplying its data, performing the labor behind it, or encountering its wider effects?
Proximity: How directly and quickly can its consequences reach them?
An incorrect restaurant recommendation and an incorrect medical recommendation may emerge from similar technical behavior, but they do not create the same exposure. Neither do a private drafting error and an automated action executed across thousands of accounts.
Power: Can the person understand, refuse, correct, appeal, or escape what the system does?
Power may be the most important of the three. The same error means something very different to a customer who can close an app than to an applicant who is silently rejected, a worker who cannot refuse workplace surveillance, or a patient who has no alternative source of care.
This is also why vulnerability should not be treated as a separate category of person. Vulnerability can emerge within any of the five positions. Age, disability, language, literacy, crisis, economic dependence, and institutional authority can all change someone’s exposure and their ability to respond.
A person does not need to be inherently vulnerable to be placed in a vulnerable position.
A human map of AI safety
This series will explore AI safety from each of these five positions.
The first piece will consider the user and ask whether interacting with an AI system amounts to meaningful understanding or control.
The second will examine the subject: the person who is screened, scored, monitored, or judged by a system they may never see.
The third will focus on the source and the continuing obligations organizations acquire when human lives and creative work become data.
The fourth will turn to the worker and the labor, surveillance, responsibility, and displacement hidden behind the language of automation.
The final piece will consider the public: people and communities exposed to consequences despite never choosing to participate.
The framework will remain underneath the series. Its provisions on governance, privacy, security, fairness, accessibility, testing, monitoring, redress, vendor risk, and retirement provide the practical tools. The NTIA’s work on independent AI accountability, the FTC’s guidance on manipulative interface design, and UNICEF’s guidance on AI and children help extend those tools into questions of organizational power, consumer autonomy, and child-specific protection.
But instead of approaching all of this from the perspective of the organization, the series will ask what safety means from the position of the people the organization is responsible for protecting.
What can they see?
What can they lose?
What choices do they genuinely possess?
What can they do when the system is wrong?
AI safety cannot be judged only from the seat of the customer the product was built to serve. It must also be judged from the positions of those the system observes, evaluates, learns from, relies upon, and places at risk.
Before we ask whether an AI system is safe, we need to ask:
Where are people standing when it reaches them?
Anthralytic is a social impact strategy studio helping mission-driven organizations hone their social transformation through digital tools, including AI, safely.

