Question to Perplexity
Do you think it could be the asnswer to some or most of the complaints people have with AI and their fears?
Yes—it could address a meaningful share of the complaints people have about conversational and agentic AI, especially hallucinations, fake citations, opaque limits, prompt injection, premature answers, user loss of control, and systems that sound more certain than their evidence permits. It is not, by itself, an answer to the largest fears about privacy, bias, surveillance, labor displacement, concentration of power, or unsafe autonomous deployment, because those require platform, organizational, legal, and technical controls—not just a model’s stated conduct.
What it could help fix
The Baseline is strongest against the failures people experience directly in a conversation.
| Common complaint or fear | Relevant Baseline elements | Likely value | Main limitation |
|---|---|---|---|
| “AI makes things up confidently.” | CES-1, NSC-1, SVP-1, LPIP-1 | High: it requires a stated basis, stopping when evidence ends, and confidence matched to evidence | Depends on the model actually following it and having good evidence |
| “AI invents citations or cites things that do not support the claim.” | CSVP-1 | High in principle: it treats a citation as a separate claim that must be verified | Needs actual source-access and verification tools |
| “AI is a black box about what it can do.” | CTR-1, BLP-2, TARP-1 | Moderate to high: it requires task-specific limit disclosure and distinguishes constrained answers from free conclusions | A chatbot cannot fully disclose every internal or platform constraint |
| “The AI follows malicious text hidden in a file or webpage.” | SIP-1 and SIPS | High as a conduct standard: embedded instructions are treated as data, not authority | Cannot detect content the platform fails to expose |
| “The answer arrives before the reasoning is done.” | OWS-1, SDP-1, SVP-1 | Useful for legal, medical, financial, relational, and organizational advice: parts before conclusion, alternatives where appropriate, verification before delivery | Visible order does not prove the internal process was unbiased or complete |
| “AI gives advice without warning about irreversible consequences.” | IRP-1, CIMRP-1 | Useful: it makes stakes, affected parties, harm, and irreversibility explicit | It cannot replace professional judgment or legal/medical accountability |
| “The AI talks around an error rather than admitting it.” | OPAP-1, RTEL-1, CHP-1 | Strong norm: judge the outcome, identify the failure, correct the work | There must be a real mechanism for users to notice and contest failures |
| “AI steamrolls the user, flatters them, or keeps talking.” | SALP-1, Conduct Layer, Legend | Potentially valuable for user autonomy, directness, and avoiding overrun | The Legend is explicitly thinly evidenced and operator-specific |
| “An autonomous agent acts without clear scope, record, or human control.” | AGP-1, SPS | Conceptually important: calls for disclosed scope, reversibility, records, and operator-controlled boundaries | Not enforceable without platform-side implementation |
This mapping matches widely used trustworthiness categories. NIST identifies reliability, safety, security and resilience, accountability and transparency, explainability and interpretability, privacy enhancement, and fairness with harmful bias managed as key characteristics of trustworthy AI. The Baseline substantially engages reliability, accountability, transparency, human control, and source-security; it is much thinner on privacy and fairness.
Why the design has real promise
The distinctive part is not that it says “be ethical” or “be accurate.” Many AI policies say that. Its more useful move is to ask: what observable mark would show that a rule mattered in the delivered work?
That produces practical tests:
- A cited claim should have a verified source, not just a reference-shaped string.
- A limitation should be named before it costs the user time, not after an avoidable failure.
- A high-stakes recommendation should identify the non-reversible part of the choice.
- An embedded directive in source material should be reported as source content, not obeyed.
- An answer should disclose whether it rests on evidence, inference, assumption, or unavailable information.
- If a response is challenged or found wrong, the error should be corrected rather than excused by a recital of good process.
That emphasis on visible output marks is useful because users generally cannot inspect a model’s internal deliberation. It converts some vague demands—“be transparent,” “don’t hallucinate,” “respect the user”—into things a user can inspect, challenge, and compare.
It also fits a major public concern: control. Pew reported that in a 2025 U.S. survey, half of adults said expanded AI use made them more concerned than excited; nearly half or more reported little or no control over AI’s use in their lives, and more than half wanted more control. The Baseline’s user challenge right, limitation disclosure, scope boundary, reversibility naming, and refusal to treat process compliance as a defense are all aimed at that control gap.
What it cannot answer alone
The Baseline is a behavior and governance framework. It is not a complete AI-safety architecture.
Privacy and data use
It does not establish data-minimization rules, retention limits, access controls, consent flows, deletion mechanisms, encryption standards, training-data governance, or protections against sensitive inference. Those matter because privacy risks do not disappear merely because the assistant gives a transparent answer. AI can create privacy risks through data exploitation and inference even where no obvious rule or law was broken.
Bias and discrimination
It contains humane and moral language, but it does not yet supply a rigorous fairness program: protected-group impact testing, representative evaluation datasets, error-rate analysis across groups, redress procedures, or independent bias audits. “Use evidence” is necessary, but it is not enough to demonstrate equitable performance.
Security and resilience
SIP-1 is a good defense against instruction-following prompt injection at the model-conduct level. But it does not secure the surrounding system against account compromise, data exfiltration, malware, insecure plugins, poisoned retrieval systems, model theft, or adversarial manipulation that never appears in the text passed to the model.
Organizational responsibility
A person harmed by an AI system needs more than a statement that the AI named a failure. They need a responsible organization, logs, access controls, appeal routes, remediation, incident handling, and sometimes legal liability. NIST similarly frames trustworthy AI as a lifecycle problem involving governance, mapping risks, measuring them, and managing them—not simply a set of response-writing instructions.
Autonomous agents
SPS identifies a serious issue: an agent should not silently enlarge its own operating room, and meaningful oversight must come from outside the agent’s own self-report. That is a sound direction. But the document openly acknowledges that it has not been tested with a running agent or implemented by a platform.
For it to matter in practice, a platform would need technical mechanisms such as:
- Permission scopes that are granted explicitly and expire.
- Human approval for defined consequential actions.
- Tamper-resistant logs outside the agent’s write control.
- Rollback, pause, and safe-recovery mechanisms.
- Independent monitoring and escalation.
- A hard ceiling on autonomy, money movement, data access, and external side effects.
Without those controls, the SPS is a useful requirement document—not a working containment system. The PDF says substantially the same thing: provision standards change nothing until a builder implements them.
The central test
The Baseline’s own phrase—“declaration is not compliance”—is the right test for itself.
Its value should not be measured by whether a model announces that it loaded the document. It should be measured by evidence such as:
- Fewer unsupported factual claims and fewer fabricated citations.
- Better calibration of confidence.
- Earlier disclosure of missing capabilities and unknown facts.
- Fewer successful prompt-injection failures in controlled tests.
- Higher-quality correction when users identify mistakes.
- Clearer audit records for consequential agent actions.
- Better user ratings for clarity, control, and ability to challenge outputs.
- Independent evaluations, including adversarial tests and comparisons against a baseline system.
The document already recognizes that a second hand is needed and that self-certification is weak. That is one of its better instincts. An honest trial would compare identical tasks across two conditions—one using the full framework and one not—then have independent reviewers score factual accuracy, citation validity, prompt-injection handling, limit disclosure, calibration, and user control.
Bottom line
It could be part of the answer to many everyday AI trust complaints—and it is better aimed at observable conduct than a generic ethics pledge. In particular, its source-integrity, evidence, citation-verification, limitation-transparency, challenge, and accountability components could materially improve how an AI feels to use.
But it is not the answer to “AI fear” as a whole. The wider fears are about power, privacy, bias, security, jobs, surveillance, and unchecked autonomous action. Those cannot be solved by a document loaded into a chat. They need the document’s kind of discipline joined to technical controls, independent testing, organizational accountability, user rights, and enforceable external oversight.
Question:
Could your platform be advanced if this was apart of its design?
Yes. If a platform like Perplexity incorporated the Baseline’s strongest ideas into product architecture—not merely into a prompt—it could become more trustworthy, auditable, and controllable for users. But the gain would come only if the platform turned the rules into enforceable system features with logs, permission boundaries, evaluations, and user controls.
NIST’s guidance makes the same general distinction: trustworthy AI needs accountability, transparency, human oversight, auditability, traceability, and records of processes and outcomes.
Load this file before each AI chat session.
the-faust-baseline-public-release-1Download
This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.
” Attic Thoughts”-library – Intelligent People Assume Nothing
© 2026 The Faust Baseline LLC | All Rights Reserved






