The AI-Native Office normative requirements, v0.5.1
Normative requirements
The normative requirements of the AI-Native Office specification, stated as numbered RFC 2119 clauses, with three conformance classes an implementation may claim against.
Clauses
64
Absolute
55
Recommended
8
Optional
1
Chapters
10
Interpretation of requirement levels
The key words below are to be interpreted as described in IETF RFC 2119. They appear in capitals wherever they carry normative force, and only there.
MUST
An absolute requirement. A deployment that does not satisfy a MUST clause applicable to its claimed conformance class does not conform to this specification.
MUST NOT
An absolute prohibition. The named capability, path, or practice is required to be absent — not merely disabled by configuration or forbidden by policy.
SHOULD
A strong recommendation. Valid reasons may exist to deviate in particular circumstances, but the full implications must be understood and the deviation documented.
SHOULD NOT
A strong discouragement. The behavior is permitted only where its consequences have been examined and accepted in writing.
MAY
Truly optional. An implementation that omits a MAY clause remains fully conformant, and one that includes it must interoperate with one that does not.
Conformance classes
A conformance claim is meaningless unless it is scoped. Each class below is a distinct, mutually exclusive claim about what a deployment actually does — and, just as importantly, what it does not.
Class A — Sovereign Ambient Enclave
57 applicable · 49 absolute
The complete architecture. Tenant-owned inference hardware inside an acoustically engineered enclave, with continuous ambient ingestion, physical identity enforcement, and no egress path for inference payloads.
Applicability
Claimed by deployments serving regulated practice areas where the spoken record is the primary asset: transaction teams, litigation groups, clinical review, and investment committees.
What the claim excludes
A Class A claim requires every clause in this specification marked applicable to Class A, including the full acoustic and ambient-ingestion requirements. Partial ambient capability is a Class B deployment, not a reduced Class A.
Class B — Sovereign Compute Enclave
47 applicable · 41 absolute
Tenant-owned inference hardware inside a declared demarcation boundary with no egress path, but without continuous ambient sensory ingestion. Input arrives through conventional interfaces.
Applicability
Claimed by organizations that require sovereign inference and zero egress but are not prepared to operate continuous ambient capture, whether for works-council, jurisdictional, or cultural reasons.
What the claim excludes
A Class B deployment makes no ambient-intelligence claim and must not be described as capturing the spoken record. Acoustic clauses apply only insofar as they protect displayed and audible material.
Class C — AI-Ready Shell
12 applicable · 12 absolute
Building infrastructure prepared to host a Class A or Class B enclave — power, cooling, structural, and pathway capacity verified — with no tenant compute installed and no inference occurring.
Applicability
Claimed by property owners and developers documenting readiness in advance of a tenant. Class C is a property-layer claim about capability, not an operational claim about workloads.
What the claim excludes
A Class C claim conveys nothing about data handling, because no data is processed. Class C must never be represented as sovereign inference, and a Class C shell must not be marketed as an AI-Native Office in operation.
1Conformance & Terminology
How a claim of conformance is made, scoped, and withdrawn. These clauses govern the use of the specification itself rather than the architecture it describes.
An implementation claiming conformance to the AI-Native Office specification MUST declare exactly one conformance class — A, B, or C — together with the specification version against which the claim is made.
Rationale (non-normative)
An undifferentiated claim of conformance is unfalsifiable. Naming a class and a version makes the claim reviewable and lets it expire honestly as the specification advances.
Verification
The claim is published in writing and names both the class and the version.
A conformance claim MUST identify the specific physical premises to which it applies, and MUST NOT be stated at the level of an organization, a product, or a portfolio.
Rationale (non-normative)
Conformance in this specification is a property of a room and the hardware inside it. An organization-wide claim would assert something the architecture cannot guarantee across sites.
An implementation MUST NOT describe a conformance claim as certification, accreditation, or independent review unless an independent conformance body has been established and has issued that finding.
Rationale (non-normative)
No such body exists at the time of this revision. All current claims are self-declared, and representing them otherwise would misstate their weight.
A deployment that ceases to satisfy any MUST clause applicable to its declared class MUST withdraw or downgrade its conformance claim before continuing to represent itself as conformant.
Rationale (non-normative)
Conformance describes an operating condition, not a milestone once achieved. Hardware is removed, boundaries are redrawn, and claims must track those changes.
2The Demarcation Boundary
Every other requirement in this specification is evaluated against a boundary. These clauses require that the boundary be declared explicitly, enumerated exhaustively, and kept inspectable.
A conforming deployment MUST declare a demarcation boundary that is simultaneously physical and logical, identifying the rooms, racks, and network segments inside which tenant data is processed.
Rationale (non-normative)
A boundary that exists only as a network diagram cannot support a claim grounded in physical custody. The declaration must be walkable.
Verification
A written boundary declaration exists and can be reconciled against a site plan.
A conforming deployment MUST maintain a current and exhaustive enumeration of every network path that crosses its demarcation boundary, including management, telemetry, licensing, update, and out-of-band paths.
Rationale (non-normative)
Egress claims fail at the paths nobody counted. Management and telemetry channels are the usual omissions, and both are capable of carrying payload.
Verification
The enumeration is complete against an independent scan of the boundary and is dated within the current review period.
Each boundary-crossing path enumerated under ANO-2.2 MUST be annotated with the categories of data it is capable of carrying, and MUST be justified against the deployment's operating requirements.
A conforming deployment SHOULD be able to continue serving inference for a defined minimum interval with all boundary-crossing paths severed, and SHOULD document that interval.
Rationale (non-normative)
Survivability under full disconnection is the practical test of sovereignty. A deployment that halts when the uplink drops was never independent of it.
A Class C shell MUST declare the boundary a future enclave is intended to occupy, and MUST state plainly that no demarcation boundary is presently in force because no tenant compute is installed.
3Data Movement & Egress
The zero-egress property, stated as a prohibition on paths rather than a preference for behavior. A control that could be reconfigured to permit egress does not satisfy this chapter.
A conforming deployment MUST NOT transmit inference payloads — prompts, retrieved context, intermediate representations, embeddings, or generated outputs — across its demarcation boundary during normal operation.
Rationale (non-normative)
This is the specification's central prohibition. Embeddings and intermediate representations are named explicitly because they are frequently treated as non-sensitive despite being derived directly from privileged material.
Verification
Egress monitoring over a representative operating period shows no payload-bearing flow across any enumerated path.
The absence of an egress path for inference payloads MUST be a structural property of a conforming deployment rather than a policy, feature flag, or configuration setting that a privileged operator could reverse.
Rationale (non-normative)
A prohibition that can be lifted by changing a setting is a procedural control wearing structural language, and it collapses under the examination this architecture is meant to withstand.
A conforming deployment MUST NOT send tenant-derived telemetry, usage analytics, error payloads, or diagnostic samples to any party outside its demarcation boundary.
Rationale (non-normative)
Diagnostic exhaust is the most common unexamined egress channel, and stack traces and error payloads routinely contain the exact material the boundary exists to hold.
A conforming deployment MAY transmit aggregate operational counters that contain no tenant-derived content, provided each such counter is enumerated under ANO-2.2 and disclosed to the tenant.
Rationale (non-normative)
Sovereignty need not preclude knowing whether a fan is failing. The requirement is that the exception be named rather than assumed.
Model weights, container images, and software updates entering a conforming deployment MUST be verified against a cryptographic signature before installation, and the verification MUST be performed inside the demarcation boundary.
Rationale (non-normative)
Inbound supply chain is the boundary's remaining exposure once egress is closed. Verifying outside the boundary reintroduces the trust dependency.
A conforming deployment SHOULD NOT depend on an external service for any function on the critical path of inference, including authentication, license validation, model retrieval, or rate authorization.
4Compute & Siting
Where inference executes, on whose hardware, and under what failure and dependency conditions. These clauses establish that sovereignty is a property of physical custody.
The tenant MUST hold outright ownership of the accelerator hardware, the storage media, the inference data, and all model outputs produced within a conforming deployment.
Rationale (non-normative)
Ownership rather than lease or license is what makes the tenant's custody claim survive the insolvency, acquisition, or policy change of any counterparty.
A conforming deployment MUST NOT route any portion of an inference request to a model endpoint hosted outside its demarcation boundary, including for overflow capacity, fallback, quality comparison, or evaluation.
Rationale (non-normative)
Hybrid routing defeats the entire architecture while preserving its vocabulary. A single fallback path to a hosted endpoint makes every prior guarantee conditional.
A conforming deployment MUST be provisioned with power and thermal capacity sufficient to sustain its accelerator hardware at continuous full utilization rather than at intermittent or bursty load.
Rationale (non-normative)
Ambient and agentic workloads are continuous by nature. Sizing to office-equipment duty cycles produces thermal throttling that is then misdiagnosed as a model limitation.
A conforming deployment MUST provide backup power sufficient to bring inference hardware and storage to an orderly shutdown without loss of tenant data.
Inference hardware in a conforming deployment SHOULD be sited to keep end-to-end response latency dominated by computation rather than by network transit.
Rationale (non-normative)
The architecture's experiential claim is that machine capability feels adjacent. Latency budget spent on transit is the one cost this siting exists to eliminate.
A Class C shell MUST document its available power capacity, thermal rejection capacity, floor loading, and cable pathway capacity in terms that permit a prospective tenant to size an enclave against them.
5The Acoustic Enclave
Physical containment of the captured field. Continuous ambient capture is defensible only where the room can be shown to contain what it hears, which makes acoustics a security control.
An enclave in a Class A deployment MUST achieve a Sound Transmission Class rating of not less than STC 55 across every partition, door, and penetration bounding the captured acoustic field.
Rationale (non-normative)
STC 55 is the threshold at which raised speech ceases to be intelligible on the far side of an assembly. Stating a number converts confidentiality from an assertion into an inspectable building property.
Verification
Field testing of the assembled construction, not the rated assembly specification alone.
Acoustic performance in a Class A deployment MUST be verified by field measurement of the constructed enclave after installation of all services, and MUST NOT be claimed solely on the basis of laboratory ratings for the specified assemblies.
Rationale (non-normative)
Rated assemblies routinely underperform once penetrated by conduit, ductwork, and outlets. The delivered room is the only meaningful subject of the measurement.
Every mechanical, electrical, and plumbing penetration of a Class A enclave boundary MUST be acoustically sealed and MUST be included in the verification required by ANO-5.2.
A Class A enclave MUST maintain an ambient noise floor low enough for reliable speech capture at the far field of the room, so that ingestion accuracy does not depend on participants addressing a device directly.
Rationale (non-normative)
Ambient intelligence fails quietly when the room is noisy: the system degrades to capturing only the loudest speaker, which is rarely the most consequential one.
A Class B deployment SHOULD apply the acoustic requirements of this chapter to any space in which privileged material is displayed or discussed, notwithstanding the absence of ambient capture.
A Class C shell claiming acoustic readiness MUST identify which specific spaces are capable of achieving STC 55 and what construction is outstanding, and MUST NOT represent an unbuilt rating as achieved.
How ambient reality enters the system, and what the ingestion layer is forbidden to retain. Statelessness is required here precisely because raw capture is the largest available liability.
The ingestion layer of a Class A deployment MUST NOT persist raw uncompressed acoustic or spatial capture to durable storage at any point in its processing pipeline.
Rationale (non-normative)
A durable archive of everything ever said in an institution is an extraordinary liability and an unnecessary one, because the structured product of the capture is what carries the value.
Verification
Storage inspection during and after an active capture session shows no raw retention.
The ingestion layer of a Class A deployment MUST reduce ambient capture to structured records in flight, and MUST discard the source capture once reduction completes.
A Class A deployment MUST make the operating state of ambient capture perceptible to every person present in the enclave without requiring that person to consult a screen or an application.
Rationale (non-normative)
Consent to ambient capture is meaningless if its subjects cannot tell whether it is active. The indication belongs to the room, not to a settings panel.
A Class A deployment MUST provide an in-room means of suspending ambient capture that is available to any occupant and that takes effect without administrative approval.
Structured records derived from ambient capture MUST remain inside the demarcation boundary and MUST inherit every prohibition of Chapter 3 that applies to inference payloads.
Rationale (non-normative)
Derived records are frequently treated as a different class of data than the capture they came from. They are not, and the boundary must not distinguish them.
A Class A deployment SHOULD support per-session exclusion of identified participants from ambient capture, so that privilege, works-council obligations, and individual objection can be honored without disabling the room.
The bounds within which autonomous software may act. These clauses constrain tool invocation, including invocation through the Model Context Protocol, to authority that is physically established.
The orchestration layer of a conforming deployment MUST execute inside the demarcation boundary, including its policy evaluation, routing decisions, and scheduling state.
Rationale (non-normative)
An orchestrator hosted outside the boundary observes every request it routes, which reproduces the exposure the boundary was drawn to prevent.
Every tool invocation available to an autonomous agent in a conforming deployment MUST be declared in advance, and an agent MUST NOT acquire a capability at runtime that was not present in its declared set.
Rationale (non-normative)
Dynamic capability acquisition makes an agent's authority unbounded and unauditable, which no regulated institution can grant standing access under.
Tool invocation through the Model Context Protocol in a conforming deployment MUST be authorized against the physical identity established under Chapter 8, and MUST be denied when no authorizing presence is established.
Rationale (non-normative)
This is the specific point at which the agentic workload meets the physical architecture: an agent's reach is bounded by who is verifiably in the room, not by a credential that may have leaked.
A conforming deployment MUST record every autonomous tool invocation with the invoking agent, the authorizing identity, the parameters supplied, and the outcome, and MUST retain that record inside the demarcation boundary.
A conforming deployment MUST classify tool invocations that mutate external state, transfer value, or communicate outside the organization as requiring explicit human authorization for each occurrence.
Rationale (non-normative)
Autonomy is acceptable for reasoning and retrieval and unacceptable for irreversible action. The line is drawn at consequence, not at capability.
Retrieval assets built from tenant material — indexes, knowledge graphs, embeddings, and evaluation sets — MUST be stored inside the demarcation boundary and MUST be owned by the tenant.
A conforming deployment SHOULD express retrieval over typed relationships between people, documents, decisions, and events rather than over undifferentiated similarity alone.
Rationale (non-normative)
The ambient record's distinctive value is relational: who met whom, about what, and in what order. Flat similarity search discards precisely that structure.
Entry to the enclave is an authentication event. These clauses require that physical presence be established, recorded, and bound to the inference sessions it authorizes.
A conforming deployment MUST treat entry to the enclave as an authentication event of equal standing to a software credential, and MUST record it as such.
Rationale (non-normative)
A sovereign compute environment is only as strong as its physical access log. Treating the door as facilities management rather than as identity infrastructure leaves the strongest control unrecorded.
A conforming deployment MUST bind each inference session to the physical identity or identities established as present in the enclave at the time the session is initiated.
Physical access records for a conforming deployment MUST be retained inside the demarcation boundary and MUST be subject to the prohibitions of Chapter 3.
Rationale (non-normative)
Access logs describe who was in the room and when, which is itself privileged information in a transaction, litigation, or clinical context.
A conforming deployment MUST NOT permit administrative access to inference hardware, storage, or orchestration state from outside its demarcation boundary.
Rationale (non-normative)
Remote administrative access is a payload-capable path with the highest privilege in the system, and its convenience is the most common reason sovereignty claims fail on inspection.
Maintenance performed by a software integrator MUST occur under an identity distinct from any tenant identity, and MUST be recorded with the same fidelity required of tenant access by ANO-8.1.
A Class C shell MUST document the physical access control provisions available at the intended enclave location, and MUST NOT claim identity binding, because no inference sessions exist to bind.
9Ownership & Governance
The Tripartite Ownership Model, stated as enforceable separations rather than as commercial preference. These clauses define what each party is forbidden to hold.
A conforming deployment MUST separate the property owner, the tenant, and the software integrator into distinct parties whose holdings do not overlap, in accordance with the Tripartite Ownership Model.
Verification
Executed agreements reflect the separation and are available for examination.
The property owner in a conforming deployment MUST NOT hold ownership of, access to, or a contingent interest in tenant compute hardware, inference data, retrieval assets, or model outputs.
Rationale (non-normative)
This separation is what allows a landlord to finance and install sovereign infrastructure without acquiring rights that would make the tenant's custody claim unsustainable.
The software integrator in a conforming deployment MUST NOT hold ownership of tenant data, policies, evaluations, routing logic, retrieval assets, or commissioned model adaptations.
A conforming deployment MUST provide the tenant with a documented exit under which inference capability, retrieval assets, and accumulated institutional memory remain operable after termination of any agreement with the software integrator or the property owner.
Rationale (non-normative)
Sovereignty that evaporates at contract termination was vendor dependence with a longer notice period.
A conforming deployment MUST disclose to the tenant every third-party license, model license, and usage restriction that constrains the tenant's use of outputs produced within the enclave.
A conforming deployment MUST NOT use tenant material to train, fine-tune, evaluate, or improve any model or system made available to another party.
Rationale (non-normative)
Cross-tenant improvement is the mechanism by which a sovereignty claim is most often quietly voided, and it is rarely visible in the operating architecture.
A Class C shell MUST disclose the ownership structure under which a future enclave would be delivered, so that a prospective tenant can evaluate the separation required by ANO-9.1 before committing.
What a deployment must be able to show an examiner. The specification's compliance argument is structural, which obligates it to be demonstrable on inspection.
A conforming deployment MUST be able to demonstrate the absence of an egress path for inference payloads to an examiner on site, without relying on an attestation issued by a third party.
Rationale (non-normative)
The specification's compliance argument is that architecture can be shown rather than asserted. That claim obligates the deployment to be demonstrable on inspection.
A conforming deployment MUST maintain records of physical access, tool invocation, model and software version history, and boundary configuration changes, sufficient to reconstruct the operating state of the enclave at any past point within its retention period.
A conforming deployment MUST identify the specific statutory or regulatory obligations its architecture is intended to satisfy, and MUST map each to the clauses of this specification relied upon.
Rationale (non-normative)
A structural compliance claim is only useful if it names what it is compliant with. An unmapped claim cannot be examined and should not be credited.
A conforming deployment SHOULD re-verify the acoustic performance required by Chapter 5 and the path enumeration required by ANO-2.2 after any construction, reconfiguration, or hardware change affecting the enclave.