← AI-Native Office
Transmit
The AI-Native Office normative requirements, v0.5.1

Normative requirements

The normative requirements of the AI-Native Office specification, stated as numbered RFC 2119 clauses, with three conformance classes an implementation may claim against.

Clauses
64
Absolute
55
Recommended
8
Optional
1
Chapters
10

Interpretation of requirement levels

The key words below are to be interpreted as described in IETF RFC 2119. They appear in capitals wherever they carry normative force, and only there.

MUST
An absolute requirement. A deployment that does not satisfy a MUST clause applicable to its claimed conformance class does not conform to this specification.
MUST NOT
An absolute prohibition. The named capability, path, or practice is required to be absent — not merely disabled by configuration or forbidden by policy.
SHOULD
A strong recommendation. Valid reasons may exist to deviate in particular circumstances, but the full implications must be understood and the deviation documented.
SHOULD NOT
A strong discouragement. The behavior is permitted only where its consequences have been examined and accepted in writing.
MAY
Truly optional. An implementation that omits a MAY clause remains fully conformant, and one that includes it must interoperate with one that does not.

Conformance classes

A conformance claim is meaningless unless it is scoped. Each class below is a distinct, mutually exclusive claim about what a deployment actually does — and, just as importantly, what it does not.

Class A — Sovereign Ambient Enclave

57 applicable · 49 absolute

The complete architecture. Tenant-owned inference hardware inside an acoustically engineered enclave, with continuous ambient ingestion, physical identity enforcement, and no egress path for inference payloads.

Applicability
Claimed by deployments serving regulated practice areas where the spoken record is the primary asset: transaction teams, litigation groups, clinical review, and investment committees.
What the claim excludes
A Class A claim requires every clause in this specification marked applicable to Class A, including the full acoustic and ambient-ingestion requirements. Partial ambient capability is a Class B deployment, not a reduced Class A.

Class B — Sovereign Compute Enclave

47 applicable · 41 absolute

Tenant-owned inference hardware inside a declared demarcation boundary with no egress path, but without continuous ambient sensory ingestion. Input arrives through conventional interfaces.

Applicability
Claimed by organizations that require sovereign inference and zero egress but are not prepared to operate continuous ambient capture, whether for works-council, jurisdictional, or cultural reasons.
What the claim excludes
A Class B deployment makes no ambient-intelligence claim and must not be described as capturing the spoken record. Acoustic clauses apply only insofar as they protect displayed and audible material.

Class C — AI-Ready Shell

12 applicable · 12 absolute

Building infrastructure prepared to host a Class A or Class B enclave — power, cooling, structural, and pathway capacity verified — with no tenant compute installed and no inference occurring.

Applicability
Claimed by property owners and developers documenting readiness in advance of a tenant. Class C is a property-layer claim about capability, not an operational claim about workloads.
What the claim excludes
A Class C claim conveys nothing about data handling, because no data is processed. Class C must never be represented as sovereign inference, and a Class C shell must not be marketed as an AI-Native Office in operation.

1Conformance & Terminology

How a claim of conformance is made, scoped, and withdrawn. These clauses govern the use of the specification itself rather than the architecture it describes.

ANO-1.1MUSTClass A, B, C
An implementation claiming conformance to the AI-Native Office specification MUST declare exactly one conformance class — A, B, or C — together with the specification version against which the claim is made.
Rationale (non-normative)
An undifferentiated claim of conformance is unfalsifiable. Naming a class and a version makes the claim reviewable and lets it expire honestly as the specification advances.
Verification
The claim is published in writing and names both the class and the version.
ANO-1.2MUSTClass A, B, C
A conformance claim MUST identify the specific physical premises to which it applies, and MUST NOT be stated at the level of an organization, a product, or a portfolio.
Rationale (non-normative)
Conformance in this specification is a property of a room and the hardware inside it. An organization-wide claim would assert something the architecture cannot guarantee across sites.
ANO-1.3MUST NOTClass A, B, C
An implementation MUST NOT describe a conformance claim as certification, accreditation, or independent review unless an independent conformance body has been established and has issued that finding.
Rationale (non-normative)
No such body exists at the time of this revision. All current claims are self-declared, and representing them otherwise would misstate their weight.
ANO-1.4MUSTClass A, B, C
The keywords MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY in the AI-Native Office specification MUST be interpreted as described in RFC 2119.
ANO-1.5MUSTClass A, B, C
A deployment that ceases to satisfy any MUST clause applicable to its declared class MUST withdraw or downgrade its conformance claim before continuing to represent itself as conformant.
Rationale (non-normative)
Conformance describes an operating condition, not a milestone once achieved. Hardware is removed, boundaries are redrawn, and claims must track those changes.

2The Demarcation Boundary

Every other requirement in this specification is evaluated against a boundary. These clauses require that the boundary be declared explicitly, enumerated exhaustively, and kept inspectable.

Formalizes Cryptographic Isolation and the Zero-Trust Moat

ANO-2.1MUSTClass A, B
A conforming deployment MUST declare a demarcation boundary that is simultaneously physical and logical, identifying the rooms, racks, and network segments inside which tenant data is processed.
Rationale (non-normative)
A boundary that exists only as a network diagram cannot support a claim grounded in physical custody. The declaration must be walkable.
Verification
A written boundary declaration exists and can be reconciled against a site plan.
ANO-2.2MUSTClass A, B
A conforming deployment MUST maintain a current and exhaustive enumeration of every network path that crosses its demarcation boundary, including management, telemetry, licensing, update, and out-of-band paths.
Rationale (non-normative)
Egress claims fail at the paths nobody counted. Management and telemetry channels are the usual omissions, and both are capable of carrying payload.
Verification
The enumeration is complete against an independent scan of the boundary and is dated within the current review period.
ANO-2.3MUSTClass A, B
Each boundary-crossing path enumerated under ANO-2.2 MUST be annotated with the categories of data it is capable of carrying, and MUST be justified against the deployment's operating requirements.
ANO-2.4MUST NOTClass A, B
A conforming deployment MUST NOT rely on a boundary whose enforcement depends on a control plane operated outside that boundary.
Rationale (non-normative)
A boundary policed from outside is a boundary held at another party's discretion, which is the dependency this specification exists to remove.
ANO-2.5SHOULDClass A, B
A conforming deployment SHOULD be able to continue serving inference for a defined minimum interval with all boundary-crossing paths severed, and SHOULD document that interval.
Rationale (non-normative)
Survivability under full disconnection is the practical test of sovereignty. A deployment that halts when the uplink drops was never independent of it.
ANO-2.6MUSTClass C
A Class C shell MUST declare the boundary a future enclave is intended to occupy, and MUST state plainly that no demarcation boundary is presently in force because no tenant compute is installed.

3Data Movement & Egress

The zero-egress property, stated as a prohibition on paths rather than a preference for behavior. A control that could be reconfigured to permit egress does not satisfy this chapter.

Formalizes The Cloud Egress Trap

ANO-3.1MUST NOTClass A, B
A conforming deployment MUST NOT transmit inference payloads — prompts, retrieved context, intermediate representations, embeddings, or generated outputs — across its demarcation boundary during normal operation.
Rationale (non-normative)
This is the specification's central prohibition. Embeddings and intermediate representations are named explicitly because they are frequently treated as non-sensitive despite being derived directly from privileged material.
Verification
Egress monitoring over a representative operating period shows no payload-bearing flow across any enumerated path.
ANO-3.2MUSTClass A, B
The absence of an egress path for inference payloads MUST be a structural property of a conforming deployment rather than a policy, feature flag, or configuration setting that a privileged operator could reverse.
Rationale (non-normative)
A prohibition that can be lifted by changing a setting is a procedural control wearing structural language, and it collapses under the examination this architecture is meant to withstand.
ANO-3.3MUST NOTClass A, B
A conforming deployment MUST NOT send tenant-derived telemetry, usage analytics, error payloads, or diagnostic samples to any party outside its demarcation boundary.
Rationale (non-normative)
Diagnostic exhaust is the most common unexamined egress channel, and stack traces and error payloads routinely contain the exact material the boundary exists to hold.
ANO-3.4MAYClass A, B
A conforming deployment MAY transmit aggregate operational counters that contain no tenant-derived content, provided each such counter is enumerated under ANO-2.2 and disclosed to the tenant.
Rationale (non-normative)
Sovereignty need not preclude knowing whether a fan is failing. The requirement is that the exception be named rather than assumed.
ANO-3.5MUSTClass A, B
Model weights, container images, and software updates entering a conforming deployment MUST be verified against a cryptographic signature before installation, and the verification MUST be performed inside the demarcation boundary.
Rationale (non-normative)
Inbound supply chain is the boundary's remaining exposure once egress is closed. Verifying outside the boundary reintroduces the trust dependency.
ANO-3.6SHOULD NOTClass A, B
A conforming deployment SHOULD NOT depend on an external service for any function on the critical path of inference, including authentication, license validation, model retrieval, or rate authorization.

4Compute & Siting

Where inference executes, on whose hardware, and under what failure and dependency conditions. These clauses establish that sovereignty is a property of physical custody.

Formalizes How It Works

ANO-4.1MUSTClass A, B
Inference in a conforming deployment MUST execute on accelerator hardware physically located inside the declared demarcation boundary.
Verification
Hardware inventory reconciles to the boundary declaration and to physical inspection.
ANO-4.2MUSTClass A, B
The tenant MUST hold outright ownership of the accelerator hardware, the storage media, the inference data, and all model outputs produced within a conforming deployment.
Rationale (non-normative)
Ownership rather than lease or license is what makes the tenant's custody claim survive the insolvency, acquisition, or policy change of any counterparty.
ANO-4.3MUST NOTClass A, B
A conforming deployment MUST NOT route any portion of an inference request to a model endpoint hosted outside its demarcation boundary, including for overflow capacity, fallback, quality comparison, or evaluation.
Rationale (non-normative)
Hybrid routing defeats the entire architecture while preserving its vocabulary. A single fallback path to a hosted endpoint makes every prior guarantee conditional.
ANO-4.4MUSTClass A, B, C
A conforming deployment MUST be provisioned with power and thermal capacity sufficient to sustain its accelerator hardware at continuous full utilization rather than at intermittent or bursty load.
Rationale (non-normative)
Ambient and agentic workloads are continuous by nature. Sizing to office-equipment duty cycles produces thermal throttling that is then misdiagnosed as a model limitation.
ANO-4.5MUSTClass A, B
A conforming deployment MUST provide backup power sufficient to bring inference hardware and storage to an orderly shutdown without loss of tenant data.
ANO-4.6SHOULDClass A, B
Inference hardware in a conforming deployment SHOULD be sited to keep end-to-end response latency dominated by computation rather than by network transit.
Rationale (non-normative)
The architecture's experiential claim is that machine capability feels adjacent. Latency budget spent on transit is the one cost this siting exists to eliminate.
ANO-4.7MUSTClass C
A Class C shell MUST document its available power capacity, thermal rejection capacity, floor loading, and cable pathway capacity in terms that permit a prospective tenant to size an enclave against them.

5The Acoustic Enclave

Physical containment of the captured field. Continuous ambient capture is defensible only where the room can be shown to contain what it hears, which makes acoustics a security control.

Formalizes The Sovereign Enclave

ANO-5.1MUSTClass A
An enclave in a Class A deployment MUST achieve a Sound Transmission Class rating of not less than STC 55 across every partition, door, and penetration bounding the captured acoustic field.
Rationale (non-normative)
STC 55 is the threshold at which raised speech ceases to be intelligible on the far side of an assembly. Stating a number converts confidentiality from an assertion into an inspectable building property.
Verification
Field testing of the assembled construction, not the rated assembly specification alone.
ANO-5.2MUSTClass A
Acoustic performance in a Class A deployment MUST be verified by field measurement of the constructed enclave after installation of all services, and MUST NOT be claimed solely on the basis of laboratory ratings for the specified assemblies.
Rationale (non-normative)
Rated assemblies routinely underperform once penetrated by conduit, ductwork, and outlets. The delivered room is the only meaningful subject of the measurement.
ANO-5.3MUSTClass A
Every mechanical, electrical, and plumbing penetration of a Class A enclave boundary MUST be acoustically sealed and MUST be included in the verification required by ANO-5.2.
ANO-5.4MUSTClass A
A Class A enclave MUST maintain an ambient noise floor low enough for reliable speech capture at the far field of the room, so that ingestion accuracy does not depend on participants addressing a device directly.
Rationale (non-normative)
Ambient intelligence fails quietly when the room is noisy: the system degrades to capturing only the loudest speaker, which is rarely the most consequential one.
ANO-5.5SHOULDClass B
A Class B deployment SHOULD apply the acoustic requirements of this chapter to any space in which privileged material is displayed or discussed, notwithstanding the absence of ambient capture.
ANO-5.6MUSTClass C
A Class C shell claiming acoustic readiness MUST identify which specific spaces are capable of achieving STC 55 and what construction is outstanding, and MUST NOT represent an unbuilt rating as achieved.

6Sensory Ingestion

How ambient reality enters the system, and what the ingestion layer is forbidden to retain. Statelessness is required here precisely because raw capture is the largest available liability.

Formalizes Stateless Multimodal Routing

ANO-6.1MUST NOTClass A
The ingestion layer of a Class A deployment MUST NOT persist raw uncompressed acoustic or spatial capture to durable storage at any point in its processing pipeline.
Rationale (non-normative)
A durable archive of everything ever said in an institution is an extraordinary liability and an unnecessary one, because the structured product of the capture is what carries the value.
Verification
Storage inspection during and after an active capture session shows no raw retention.
ANO-6.2MUSTClass A
The ingestion layer of a Class A deployment MUST reduce ambient capture to structured records in flight, and MUST discard the source capture once reduction completes.
ANO-6.3MUSTClass A
A Class A deployment MUST make the operating state of ambient capture perceptible to every person present in the enclave without requiring that person to consult a screen or an application.
Rationale (non-normative)
Consent to ambient capture is meaningless if its subjects cannot tell whether it is active. The indication belongs to the room, not to a settings panel.
ANO-6.5MUSTClass A
Structured records derived from ambient capture MUST remain inside the demarcation boundary and MUST inherit every prohibition of Chapter 3 that applies to inference payloads.
Rationale (non-normative)
Derived records are frequently treated as a different class of data than the capture they came from. They are not, and the boundary must not distinguish them.
ANO-6.6SHOULDClass A
A Class A deployment SHOULD support per-session exclusion of identified participants from ambient capture, so that privilege, works-council obligations, and individual objection can be honored without disabling the room.
ANO-6.7MUST NOTClass B
A Class B deployment MUST NOT represent itself as providing ambient intelligence, ambient capture, or continuous sensory ingestion.

7Orchestration & Agent Authority

The bounds within which autonomous software may act. These clauses constrain tool invocation, including invocation through the Model Context Protocol, to authority that is physically established.

Formalizes Edge-Native Agentic Orchestration

ANO-7.1MUSTClass A, B
The orchestration layer of a conforming deployment MUST execute inside the demarcation boundary, including its policy evaluation, routing decisions, and scheduling state.
Rationale (non-normative)
An orchestrator hosted outside the boundary observes every request it routes, which reproduces the exposure the boundary was drawn to prevent.
ANO-7.2MUSTClass A, B
Every tool invocation available to an autonomous agent in a conforming deployment MUST be declared in advance, and an agent MUST NOT acquire a capability at runtime that was not present in its declared set.
Rationale (non-normative)
Dynamic capability acquisition makes an agent's authority unbounded and unauditable, which no regulated institution can grant standing access under.
ANO-7.3MUSTClass A, B
Tool invocation through the Model Context Protocol in a conforming deployment MUST be authorized against the physical identity established under Chapter 8, and MUST be denied when no authorizing presence is established.
Rationale (non-normative)
This is the specific point at which the agentic workload meets the physical architecture: an agent's reach is bounded by who is verifiably in the room, not by a credential that may have leaked.
ANO-7.4MUSTClass A, B
A conforming deployment MUST record every autonomous tool invocation with the invoking agent, the authorizing identity, the parameters supplied, and the outcome, and MUST retain that record inside the demarcation boundary.
ANO-7.5MUSTClass A, B
A conforming deployment MUST classify tool invocations that mutate external state, transfer value, or communicate outside the organization as requiring explicit human authorization for each occurrence.
Rationale (non-normative)
Autonomy is acceptable for reasoning and retrieval and unacceptable for irreversible action. The line is drawn at consequence, not at capability.
ANO-7.6MUSTClass A, B
Retrieval assets built from tenant material — indexes, knowledge graphs, embeddings, and evaluation sets — MUST be stored inside the demarcation boundary and MUST be owned by the tenant.
ANO-7.7SHOULDClass A
A conforming deployment SHOULD express retrieval over typed relationships between people, documents, decisions, and events rather than over undifferentiated similarity alone.
Rationale (non-normative)
The ambient record's distinctive value is relational: who met whom, about what, and in what order. Flat similarity search discards precisely that structure.

8Identity & Physical Access

Entry to the enclave is an authentication event. These clauses require that physical presence be established, recorded, and bound to the inference sessions it authorizes.

Formalizes Physical Identity & MCP

ANO-8.1MUSTClass A, B
A conforming deployment MUST treat entry to the enclave as an authentication event of equal standing to a software credential, and MUST record it as such.
Rationale (non-normative)
A sovereign compute environment is only as strong as its physical access log. Treating the door as facilities management rather than as identity infrastructure leaves the strongest control unrecorded.
ANO-8.3MUSTClass A, B
Physical access records for a conforming deployment MUST be retained inside the demarcation boundary and MUST be subject to the prohibitions of Chapter 3.
Rationale (non-normative)
Access logs describe who was in the room and when, which is itself privileged information in a transaction, litigation, or clinical context.
ANO-8.4MUST NOTClass A, B
A conforming deployment MUST NOT permit administrative access to inference hardware, storage, or orchestration state from outside its demarcation boundary.
Rationale (non-normative)
Remote administrative access is a payload-capable path with the highest privilege in the system, and its convenience is the most common reason sovereignty claims fail on inspection.
ANO-8.7MUSTClass C
A Class C shell MUST document the physical access control provisions available at the intended enclave location, and MUST NOT claim identity binding, because no inference sessions exist to bind.

9Ownership & Governance

The Tripartite Ownership Model, stated as enforceable separations rather than as commercial preference. These clauses define what each party is forbidden to hold.

Formalizes The Economics

ANO-9.1MUSTClass A, B
A conforming deployment MUST separate the property owner, the tenant, and the software integrator into distinct parties whose holdings do not overlap, in accordance with the Tripartite Ownership Model.
Verification
Executed agreements reflect the separation and are available for examination.
ANO-9.2MUST NOTClass A, B
The property owner in a conforming deployment MUST NOT hold ownership of, access to, or a contingent interest in tenant compute hardware, inference data, retrieval assets, or model outputs.
Rationale (non-normative)
This separation is what allows a landlord to finance and install sovereign infrastructure without acquiring rights that would make the tenant's custody claim unsustainable.
ANO-9.4MUSTClass A, B
A conforming deployment MUST provide the tenant with a documented exit under which inference capability, retrieval assets, and accumulated institutional memory remain operable after termination of any agreement with the software integrator or the property owner.
Rationale (non-normative)
Sovereignty that evaporates at contract termination was vendor dependence with a longer notice period.
ANO-9.5MUSTClass A, B
A conforming deployment MUST disclose to the tenant every third-party license, model license, and usage restriction that constrains the tenant's use of outputs produced within the enclave.
ANO-9.6MUST NOTClass A, B
A conforming deployment MUST NOT use tenant material to train, fine-tune, evaluate, or improve any model or system made available to another party.
Rationale (non-normative)
Cross-tenant improvement is the mechanism by which a sovereignty claim is most often quietly voided, and it is rarely visible in the operating architecture.
ANO-9.7MUSTClass C
A Class C shell MUST disclose the ownership structure under which a future enclave would be delivered, so that a prospective tenant can evaluate the separation required by ANO-9.1 before committing.

10Auditability & Evidence

What a deployment must be able to show an examiner. The specification's compliance argument is structural, which obligates it to be demonstrable on inspection.

Formalizes The Compliance Moat

ANO-10.1MUSTClass A, B
A conforming deployment MUST be able to demonstrate the absence of an egress path for inference payloads to an examiner on site, without relying on an attestation issued by a third party.
Rationale (non-normative)
The specification's compliance argument is that architecture can be shown rather than asserted. That claim obligates the deployment to be demonstrable on inspection.
ANO-10.2MUSTClass A, B
A conforming deployment MUST maintain records of physical access, tool invocation, model and software version history, and boundary configuration changes, sufficient to reconstruct the operating state of the enclave at any past point within its retention period.
ANO-10.3MUSTClass A, B
Audit records in a conforming deployment MUST be append-only and MUST NOT be alterable by the software integrator.
Rationale (non-normative)
An audit record that the operating party can edit does not constrain the operating party.
ANO-10.4MUSTClass A, B
A conforming deployment MUST identify the specific statutory or regulatory obligations its architecture is intended to satisfy, and MUST map each to the clauses of this specification relied upon.
Rationale (non-normative)
A structural compliance claim is only useful if it names what it is compliant with. An unmapped claim cannot be examined and should not be credited.
ANO-10.5SHOULDClass A, B
A conforming deployment SHOULD re-verify the acoustic performance required by Chapter 5 and the path enumeration required by ANO-2.2 after any construction, reconfiguration, or hardware change affecting the enclave.
ANO-10.6MUSTClass A, B, C
A conforming deployment MUST publish the date of its most recent conformance self-assessment alongside any conformance claim it makes.