> **PUBLIC-SURFACE BOUNDARY / 2026-08-03**
> This dated artifact is preserved for inspection. Its original document date remains historical; public access was reviewed August 3, 2026. It is not current certification, an open license, causal proof, or permission to deploy. Check the live Versions and Evidence pages for the current claim boundary.

# The Pause Before Harm Protocol (PBHP)

*A deployment-time operational governance framework for AI-mediated consequential decisions.*

---

**What it is.** PBHP is a structured set of decision-control, auditability, and harm-escalation primitives for organizations deploying AI in high-stakes contexts. It is not alignment theory or a training methodology. It is the operational layer that sits between principle-based AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) and the actual per-decision behavior of deployed AI systems.

**The central question.** *"If this decision is wrong, who pays first — and can they recover?"*

**The five primitives:**

1. **Door / Wall / Gap** — a ternary verdict on every candidate action: Door = clearly permitted; Wall = clearly forbidden; Gap = unclear, engaging the protocol's seven-step decision flow. A Gap is never silently promoted to a Door.
2. **Maybe / Therefore** — a two-field commit record on every Gap decision: `maybe` = the steelmanned strongest case *against* the action, written by the actor taking it; `therefore` = the reason it proceeds anyway. An empty, evasive, or straw-manned Maybe is the protocol's primary drift signal.
3. **The Harm Threshold ladder** (GREEN / YELLOW / ORANGE / RED / BLACK) — five rungs driven by *who pays first* and *reversibility*, not by capability or actor authority. BLACK is mandatory refusal.
4. **Who Pays First** — a mandatory receipt field: the actor names, by role, who bears the first cost if the action is wrong and whether that party can recover. Its deterministic floor is the **Power Rule**: a decision affecting a low-power stakeholder that is irreversible cannot be classified below ORANGE, and the floor cannot be ratcheted down by selective weighting.
5. **The Receipt Schema** — a per-decision signed, hash-chained audit record covering risk classification, gate path, stakeholder analysis, Maybe/Therefore, tier, and effectiveness-check schedule. The receipt is written before the action commits.

**Plus supporting structures:** the **False Positive Release Valve** (every protocol-triggered pause can be challenged; the protocol responds with a structured four-output justification — trigger / risk / alternative Door / evidence-that-would-prevent-pause — and the fourth output feeds the CAPA loop as calibration data), the **Drift Alarm** (detects normalization of the protocol into uselessness through documented operational drift patterns), and the **Sacred Refusal** (the deployment-governance commitment to honor AI-generated refusals through structured escalation rather than override). Decisions execute and document through four tiers — **HUMAN / MIN / CORE / ULTRA** — from a five-minute paper checklist to constitutional rigor with multi-party quorum, calibrated to stakes and audience.

**Proposed additional supporting structure (v1.1; reference tool shipped):** the **Context Load Audit (CLA)** treats AI context-window load as an operator-facing safety disclosure — provenance-tagged measurement, deterministic stakes-aware gating, refusal thresholds at documented load bands, audit receipts, and reciprocal operator obligations. Existing tools show context load; CLA makes it actionable, auditable, and stakes-aware. Reference implementation: `05_tools/context_load_audit/` (75/75 tests). Spec integration lands in PBHP v1.1; v1.0 is unchanged.

**Where it came from.** PBHP was built by Phillip Linstrum, a Quality Systems Manager in FDA-regulated tissue/eye banking (Indianapolis) with 10+ years in FDA-regulated healthcare (21 CFR Part 1271, EBAA Medical Standards, ISO 9001 family). The framework imports CAPA discipline, drift monitoring, validation documentation tiering, and audit-evidence structure from regulated-industry quality management systems and specializes them to AI deployment governance.

**Where it fits.** PBHP is a deployment-time operational implementation of the per-decision and per-deployment requirements that ISO/IEC 42001 (Clauses 6, 8, 9, 10), EU AI Act (Articles 9, 11, 12, 14, 17), NIST AI RMF (Govern, Map, Measure, Manage functions), and OMB M-24-10 each specify. The framework provides per-decision audit evidence that those higher-level frameworks require but do not specify the operational means of producing.

**What it is not.** PBHP is not a model alignment framework (it operates downstream of training-time alignment). It is not a legal compliance framework (it contributes to compliance evidence but does not constitute certification). It is not a clinical or medical judgment system. It is not a substitute for organizational governance. It is not a solution to capability-related AI risks at scale.

**Status.** Canonical specification v1.0 (`PBHP_CORE_SPEC.md` in this package), incorporating the public v0.7.1 baseline and the v0.9.5/v0.9.6 internal hardening cycle. Reference implementation passing 61/61 tests. As of 2026-07-25, the public repository (`github.com/PauseBeforeHarmProtocol/pbhp`) identifies v0.9.5 as its public release; this package carries the separately labeled v1.0 adoption candidate and does not imply that v1.0 has been published there. PBHP has been exercised qualitatively across 25+ documented test cases and nine cross-model AI review sessions. Those sessions are creator-directed, model-assisted review—not independent validation. PBHP has not yet been independently validated or validated at enterprise scale; staged deployment is recommended for adopting organizations.

**Author.** Phillip Linstrum (formal source records: Charles Phillip Linstrum), Indianapolis, IN. `projectshadowqa@protonmail.com`.
