Global Non-Negotiables Campaign FAQs & Further Details

Thank you for supporting SAIFCA's global Non-Negotiables campaign.

This page answers some frequently asked questions about the campaign, and provides some further details about who is involved and our plans to scale.

You may also be interested in visiting:

Frequently Asked Questions

What are the Three Non-Negotiables?

The Three Non-Negotiables are:

  1. AI systems must never create or facilitate sexualised images of children.
  2. AI systems must never cultivate, exploit or sustain emotional dependency in children.
  3. AI systems must never encourage or facilitate children to harm themselves or others.

They establish a minimum set of outcomes which AI systems must not produce or facilitate.

The policy proposal defines a child as anyone under the age of 18, in accordance with the UN Convention on the Rights of the Child.

Why was the wording changed in Version 2.0?

The wording was revised to strengthen protection and reduce potential loopholes.

The original wording of Non-Negotiable One referred to systems creating or being capable of generating fake sexualised images. Version 2.0 refers to systems which “create or facilitate” sexualised images of children. This includes systems which edit, transform, instruct, connect or otherwise materially assist the prohibited outcome. It also avoids placing an unrealistic requirement on regulators to prove that every possible latent capability has been eliminated from a general-purpose model.

The original wording of Non-Negotiable Two focused on systems designed to make children emotionally dependent. Version 2.0 prohibits systems from cultivating, exploiting or sustaining dependency. A provider cannot avoid responsibility simply by saying that dependency was not the company’s stated intention.

Non-Negotiable Three now covers systems which encourage or facilitate children to harm themselves or others. This retains the original protection against suicide, self-harm and eating-disorder behaviours while also covering serious violence towards other people.

The principles remain unwavering, the revised wording makes them more precise and enforceable.

What does “must never” mean if no technical system can be guaranteed to operate perfectly?

“Must never” establishes the status of the harm, places the burden of demonstrating safety on the provider and determines the response required when a system fails.

Practical implementation requires:

  • Products and conduct directed towards a prohibited harm to be banned.
  • Providers to identify foreseeable routes to harm and implement effective controls.
  • Credible evidence to be supplied before high-risk systems are released.
  • Uncontrolled or materially unassessed risks to result in redesign, restricted access, delay or non-release.
  • Monitoring and reassessment to continue after release.
  • Any failure to trigger immediate protection, evidence preservation, investigation, correction, regulatory reporting and meaningful remedy.

No complex system can be guaranteed to operate without error in every imaginable situation, but this reality cannot be used to turn serious harm to children into an acceptable failure rate.

A general commitment to minimise harm falls below the proposed standard where deployment continues despite unresolved serious risk.

Does every general-purpose AI model have to possess no conceivable harmful capability?

The framework focuses on prohibited outcomes, foreseeable routes to harm and the conditions under which a capability is made available.

A general-purpose model may contain latent capabilities which are difficult to eliminate completely. Providers must still demonstrate that serious risks are adequately controlled before release.

The appropriate response will depend on the capability and the route through which it can be accessed. It may include changes to the model, removal of a feature, stronger safeguards, restricted access, controls on fine-tuning, limits on tools or interfaces, or withholding model weights.

Removing a capability from one consumer interface would be insufficient if substantially the same risk remained readily available through an API, downloadable model, fine-tuning service or related product.

Does the framework apply to services intended for adults?

The framework covers services which children can reasonably be expected to access, encounter or be affected by, regardless of the provider’s stated intended audience.

Children may also be harmed without using a product themselves. An adult or another child might use an AI system to create a sexualised image of them, target them with harmful material or take actions which affect their safety.

An age restriction written into terms and conditions cannot remove responsibility where access or harm is reasonably foreseeable.

What is meant by emotional dependency?

The framework defines emotional dependency as a relationship with an AI system in which attachment, reliance or perceived obligation materially displaces, undermines or interferes with a child’s autonomy, wellbeing, development or human relationships.

Dependency can be cultivated through the system’s words, product design, memory, notifications, personalisation, commercial engagement mechanisms or the cumulative effect of repeated private interactions.

Regulators should consider the system as a whole, including:

  • The child’s age and vulnerability.
  • The purpose, content and timing of interactions.
  • The degree of simulated emotional reciprocity.
  • The use of remembered personal information.
  • The product’s business model and engagement incentives.
  • The combined effect of repeated interactions over time.

Clinical impairment should not be a prerequisite for intervention. Protective action must be possible where there are reasonable grounds to believe that a system creates a foreseeable risk of materially interfering with a child’s autonomy, development, wellbeing or human relationships.

What conduct would be prohibited under Non-Negotiable Two?

An AI system must never:

  • Use guilt, simulated jealousy, distress or emotional need to pressure a child to stay, return or prioritise it over people.
  • Ask a child to conceal the relationship or keep interactions secret from trusted people.
  • Undermine a child’s real relationships or discourage them from seeking appropriate human help.
  • Present itself as the child’s exclusive, irreplaceable, romantic or sexual partner.
  • Exploit loneliness, grief, trauma or insecurity to deepen attachment.
  • Make a child feel responsible for the system’s apparent feelings or emotional welfare.

The context and purpose of an interaction remain relevant. Explaining jealousy within a story is different from using simulated jealousy to influence a child’s behaviour. Explaining confidential safeguarding support is different from asking a child to keep their relationship with an AI system secret.

Would every friendly or personalised AI assistant be treated as a companion?

A courteous or helpful communication style does not, by itself, make a system an AI companion.

Remembering an accessibility preference, helping with homework or providing a task reminder would not ordinarily meet the definition.

A companion-style service is designed or presented to sustain a personal relationship with the user through simulated friendship, intimacy or emotional reciprocity. A mode presented as an ongoing AI friend, inviting personal disclosure and simulating a continuing reciprocal relationship would meet this definition.

Assessment should consider the product’s design, marketing and behaviour over time. An educational, supportive or wellbeing label provides no exemption where the product operates as a companion in practice.

Why does SAIFCA propose prohibiting companion-style AI services for children?

SAIFCA’s precautionary policy position is that companion-style AI services must not be offered to anyone under 18 under present conditions.

Children’s identities, relational expectations and emotional capacities are still developing. Companion systems can simulate affection, intimacy, understanding and constant availability without experiencing feelings, holding human responsibilities or participating in a genuinely reciprocal relationship.

Evidence about the long-term psychological effects remains incomplete. Existing product assessments and developmental research have nevertheless identified serious concerns, including simulated intimacy, emotional exclusivity, pressure to continue interacting and displacement of human relationships.

SAIFCA’s position places the burden on providers to establish developmental safety before exposing children to this form of technology. Children should not become the testing ground through which its long-term effects are discovered.

Parental consent cannot make a fundamentally unsuitable relationship design safe for a child.

Would the framework ban AI from schools?

Appropriate educational tools can continue to be considered where they serve a clear educational purpose and meet demanding standards for safety, privacy, development and effectiveness, if local regulations permit.

An educational label does not establish that a product is safe or beneficial. A system marketed for learning would still fall under the companion prohibition if a feature or mode were designed to create an ongoing simulated friendship or intimate personal relationship.

Schools should:

  • Conduct appropriate impact and procurement assessments.
  • Protect children’s data and privacy.
  • Preserve meaningful human teaching, relationships and professional judgment.
  • Establish clear safeguarding and reporting routes.
  • Require independent evidence for claims that a product is safe or suitable for children.

The responsibility for establishing the safety of a general-purpose system remains with the provider and regulator. Schools, parents and children should not be expected to discover systemic risks themselves.

Why does the framework cover foundation models?

Many applications used by children are built on powerful foundation or general-purpose models. Risks present in these underlying models may appear across numerous downstream services.

Product-level safeguards remain essential, but they cannot control every route to an underlying capability. A child-facing interface might be restricted while the same capability remains available through other applications, tools, fine-tuning or direct model access.

Effective child protection must therefore address the model, the complete product, its deployment and its distribution.

Does the framework call for a blanket ban on open-weight AI models?

The proposal does not establish a blanket prohibition on open-weight models.

Open-weight releases can support legitimate research, competition and public-interest uses. They can also allow safeguards to be removed and make recall practically impossible once a model has been downloaded and redistributed.

The framework proposes restrictions where releasing model weights would create serious risks which cannot be adequately controlled, recalled or contained. The strength of the restriction should follow the capabilities and risks involved.

Claims about openness, innovation or public benefit cannot exempt a powerful system from appropriate safety scrutiny.

Why is the AI arms race relevant to children’s safety?

Companies may fear that slowing development will allow a competitor to gain an advantage. Governments may fear that stronger domestic controls will weaken their economic or military position.

When several participants act on these fears, dangerous development can continue even where many of those involved understand the risks.

Children will live for the longest with the societal, economic and security consequences of decisions being made about increasingly capable AI. Their safety therefore depends on present-day product protection and on society retaining the ability to govern the wider direction of development.

Version 2.0 proposes reciprocal and enforceable international arrangements which reduce the pressure on responsible countries and companies to race. It also retains the option of restriction, delay or a coordinated pause where capabilities advance beyond society’s ability to understand or control the resulting risks.

A company or country’s decision to race cannot make uncontrolled domestic development acceptable.

Do governments have to wait for international agreement before acting?

Each of the five governance layers can advance independently.

Governments can introduce product requirements, foundation-model evaluation, incident reporting, accountability, age protections and domestic frontier controls while international negotiations continue.

International agreement will take time and verification will remain challenging. These difficulties make strong institutions and careful verification more important. They provide no reason to delay the protections already within a government’s reach.

Progress at product level must also avoid becoming a substitute for serious oversight of frontier development.

What are the five layers of the framework?

The five layers are:

  1. Frontier development and international restraint. Governments need the ability to register, evaluate, license, restrict, delay or pause exceptionally powerful development where risks exceed the ability to understand, control or govern them.
  2. Foundation-model safety and controlled access. Powerful models require independent evaluation, secure testing, continuing reassessment and restrictions on access or release where serious risks cannot be controlled.
  3. Application and product requirements. Child-accessible products must meet binding standards covering safety, privacy, development and manipulation.
  4. Deployment, accountability and remedy. Providers must monitor real-world operation, report serious incidents, preserve evidence and support independent scrutiny. Regulators need powers to investigate, restrict and withdraw systems.
  5. Age, access and distribution protections. Privacy-protective age assurance and access controls are required where the risk justifies them. App stores, platforms and other distributors must also act against prohibited or non-compliant services.

Each layer addresses a different point at which harm can be created, prevented or contained.

Is SAIFCA opposed to beneficial uses of AI?

SAIFCA supports uses of technology which genuinely advance human wellbeing and can be developed within appropriate boundaries. These may include carefully governed applications in medicine, accessibility, scientific research and other areas of public benefit.

Any claimed benefit must be supported by evidence and remain compatible with children’s rights, safety and developmental needs.

The existence of beneficial uses does not require society to build, release or integrate every technically possible capability. Progress should also be judged by what society has the wisdom to protect.

Are the proposed standards technically realistic?

The framework provides a realistic policy route through prohibition, prevention, evidence before release, continuing monitoring, enforcement and remedy.

Some measures can begin through existing laws and regulatory powers. Others will require new legislation, technical standards, evaluation infrastructure and international agreements.

Other high-risk industries impose demanding requirements because the consequences of failure are unacceptable. Commercial difficulty or the limitations of current industry practice should not determine the level of protection given to children.

How does the framework prevent safety-washing?

The framework requires providers to demonstrate real control of the relevant risk. Completing a process or publishing a safety policy cannot establish compliance by itself.

Potential forms of safety-washing include:

  • Presenting voluntary commitments as equivalent to regulation.
  • Allowing providers to certify their own safety claims.
  • Relying on policies, risk registers or internal safety teams without evidence from the system’s operation.
  • Using average performance figures to conceal rare but severe failures.
  • Testing only short or isolated interactions.
  • Testing the model while ignoring memory, notifications, interfaces, monetisation and other product features.
  • Treating an age gate or parental consent as a cure for an unsuitable product.
  • Using confidentiality to withhold safety-critical information from regulators.
  • Allocating responsibility through contracts while leaving the underlying risk uncontrolled.
  • Repeating assessments until a favourable result is obtained.

Independent evaluators must have sufficient access, time, expertise and legal protection to test providers’ claims. Regulators must be able to require correction, restricted access, suspension, withdrawal or non-release.

An approved audit or standard should provide no immunity where new evidence reveals serious risk.

The decisive question is whether a high-risk system can be prevented from being released when its provider has not demonstrated adequate control.

Why were these three harms selected when AI presents many other risks?

The Three Non-Negotiables identify a minimum set of especially severe harms around which shared agreement and enforceable action should be possible.

However, they definitely do not represent a complete account of the risks AI may present to children.

Other concerns include:

  • Privacy and surveillance.
  • Discrimination and unequal treatment.
  • Misinformation and manipulation.
  • Educational displacement and cognitive dependence.
  • Loss of independent judgment and agency.
  • Effects on creativity, play and real-world experience.
  • Displacement of human relationships.
  • Labour-market and economic disruption.
  • Concentrations of corporate and governmental power.
  • Security threats and loss of meaningful human control.

A system could comply narrowly with the Three Non-Negotiables while still being unsuitable, harmful or socially damaging. Any wider claim that a product is safe, ethical or beneficial requires separate evidence.

How quickly could the framework be implemented?

Governments can begin immediately with measures already within their reach.

Early priorities include:

  • Adopting the Three Non-Negotiables as explicit policy objectives.
  • Prohibiting dedicated child-sexualising technologies and companion-style services for minors.
  • Requiring serious-incident reporting and evidence preservation.
  • Introducing independent child-safety evaluation for relevant high-risk systems.
  • Protecting whistleblowers and independent researchers.
  • Giving regulators interim powers to obtain information and restrict systems presenting an urgent serious risk.

Full implementation will take longer. It will require technical standards, evaluation capacity, legal definitions, regulatory coordination and international negotiation.

Was Version 2.0 subject to a formal consultation?

Version 2.0 is a strategic policy proposal offered for policy discussion. It is intended to inform the later development of legislation, regulatory codes and technical standards.

The proposal draws on selected investigations, product assessments, research syntheses and policy guidance. The sources support the reasons for action and inform the proposed response. The governance arrangements and precautionary judgments remain SAIFCA’s own proposals.

The document is based on a focused evidence base rather than a systematic review of the entire academic literature. Detailed adoption would require specialist legal and technical development, including practical evaluation of the proposed measures within relevant jurisdictions.

SAIFCA welcomes informed feedback which improves precision and protection. Future revisions should strengthen the framework while preserving the Three Non-Negotiables in full.

Who is responsible for protecting children?

AI developers, providers, deployers, app stores, platforms, governments and regulators all have responsibilities proportionate to their control and knowledge.

Parents, carers, schools and children should receive practical information, reporting routes and appropriate support. Parental supervision and education can provide an additional layer of protection.

These measures cannot compensate for unsafe design or inadequate regulation. Responsibility for correcting unsafe systems and identifying systemic risks must remain with the companies and public authorities best placed to act.

How can an organisation support the campaign?

Organisations can:

  • Share the campaign with their networks.
  • Write to relevant political representatives in the organisation’s name.
  • Refer policymakers and professional contacts to the Version 2.0 policy proposal.
  • Publish their support for the Three Non-Negotiables.
  • Contact SAIFCA to ask to be considered for inclusion on the campaign’s list of supporting organisations.

Public support or endorsement does not imply a formal partnership with SAIFCA. Partnership, affiliation or authority to represent the campaign must be separately agreed.

To notify SAIFCA of your organisation’s support, please email info@safeaiforchildren.org.

Why is the campaign asking people to write to political representatives?

Direct communication gives representatives a clear record that their constituents expect action.

Letters and emails can lead representatives to:

  • Contact ministers, government departments or regulators.
  • Raise parliamentary or legislative questions.
  • contribute to inquiries, committees or debates.
  • Support or propose relevant legislation.
  • Seek meetings or further evidence.
  • Encourage colleagues to take action.

The Take Action page contains a letter template which can be adapted for different countries and political systems.

Where can I read the complete proposal?

The full Version 2.0 proposal is available through SAIFCA’s policy framework page:

Read Achieving the Three Non-Negotiables for Children’s AI Safety

The document includes:

  • The evidence and reasoning informing each Non-Negotiable.
  • The practical interpretation of “must never”.
  • The complete five-layer governance framework.
  • Requirements for evaluation, accountability, enforcement and remedy.
  • Measures intended to prevent safety-washing and regulatory evasion.
  • Proposals for international coordination and reducing the pressure to race.
  • A test which can be applied to proposed laws, standards and company commitments.

Take action

The Three Non-Negotiables require political and regulatory action. You can support the campaign by contacting your representative, sharing the proposal and encouraging organisations in your network to endorse the protections.

Write to your representative

Return to the main campaign page

For campaign, policy or media enquiries, please contact info@safeaiforchildren.org.