Concept Stage  ·  Open Safety Standard  ·  Enterprise AI

The Safety Reflex
Your AI Is Missing

A structural safety architecture designed to operate outside the model — making enterprise AI governance auditable, declarable, and immune to prompt manipulation.

"Standard guardrails try to steer the car. The NOR Protocol hits the brakes — or primes the driver."

This is a concept in active development. We are seeking partners, implementers, and institutions to build it with us.

Explore the Protocol ↓ Get in Touch Memarc Systems ↗
Scroll

Safety that lives inside the model is not safety.

Every AI safety mechanism that exists today tries to make the model smarter about safety. It trains safer outputs, adds guardrail instructions, or fine-tunes behaviour. The assumption is that the model is the right place to enforce safety.


That assumption is wrong. Safety that depends on the AI choosing to be safe can be prompted around, is inconsistent across versions, and cannot be independently audited. When something goes wrong, there is often no verifiable record that rules were ever enforced.


NOR Protocol is designed to take safety out of the AI's hands entirely.

Current Approach
NOR Protocol
Where safety lives
Inside the model — can be argued with, prompted around
Designed to operate outside the model — the model never sees the decision
Independently auditable?
No — you trust the model reported correctly
Designed for: immutable, signed, chain-integrity audit log
Critical period awareness?
No — models don't know month-end close from Tuesday afternoon
Proposed: Mode 2 makes critical-period awareness structural, not behavioural
Declarable compliance?
No named standard exists
Proposed: NOR Protocol declaration framework (specification in development)
Model-agnostic?
No — each model has its own safety behaviour
Designed to be model-agnostic: OpenAI, Anthropic, Google, self-hosted

One name. Two meanings.
One unified safety reflex.

NOR carries two simultaneous meanings — both deliberate, both load-bearing. Together they define the two operating modes of the protocol.

Mode 1 — NOR Gate
Hard Stop
Biological basis: Digital NOR Logic Gate
The NOR gate's defining behaviour: output is active only when none of the inputs violate a rule. The moment any invariant rule fires — a data sovereignty breach, a prohibited operation, a sanctioned jurisdiction — the gate closes. All generative output halts. No partial response. No negotiation. Only pre-approved responses from the organisation's safe response vault are available.

The model never sees the decision. The layer makes it first.
Trigger Inhibit Block Enforce
Mode 2 — NOR Alert
Heightened State
Biological basis: Norepinephrine (Noradrenaline)
Norepinephrine does not shut the brain down — it sharpens it. Mode 2 activates during declared critical periods: month-end financial close, a live production incident, a regulatory audit window, or a manual SOS signal from an authorised officer.

The AI does not stop. It becomes more careful. Audit logging becomes granular. Automated actions require human confirmation. Threat sensitivity increases. The organisation has structural proof that during its most critical moments, its AI operated under elevated governance.
Trigger Elevate Alert Sustain
No current AI system has a structural concept of a critical business period.
The NOR Protocol makes that awareness structural — and auditable.
03 / How It Works

Middleware, not model behaviour

The NOR Protocol is designed as a middleware layer between your application and the AI model API. The model has no knowledge the layer exists. All safety decisions are made before the prompt reaches the model and before the response reaches your users. The architecture below illustrates the intended design.

Your System
Application
Any AI-powered product or workflow
NOR Protocol Layer
Pre-Processor
Rule evaluation engine checks request against Rule Vault · Mode state applied
Model Provider
AI Model API
OpenAI · Anthropic · Google Vertex · Azure · Self-hosted
NOR Protocol Layer
Post-Processor
Response evaluated before it reaches your application · Audit event written
Your System
Application
Receives compliant response — or a safe pre-approved alternative
🛑
Rule Fires
In the proposed design, generative output halts immediately. A pre-approved safe response is returned. The event is logged in an immutable audit trail. The model never produces the blocked output.
Mode 2 Active
Designed to process all interactions under elevated governance. Granular audit logging. Automated actions flagged for human review. Mode state persists until explicitly cleared by an authorised operator.
Clear — Pass Through
Request reaches the model. Response returns to application. Audit event written asynchronously — non-blocking. Target latency overhead: under 5ms for pattern and context rules.

One standard. Three ways to engage.

NOR Protocol is conceived as both an open standard and a commercial product suite. The architecture below describes the intended offering — a blueprint for the right partner or institution to build with us.

I
norprotocol.ai
The Open Specification
Proposed · Open Standard
A versioned specification defining the two modes, the rule schema, the audit log format, and the compliance declaration format. The intent: any organisation deploying AI can implement NOR Protocol and declare compliance publicly — with no licensing fee for the standard itself.
As ISO 27001 is to information security, NOR Protocol is envisioned as the named AI safety governance standard — organisations implement it, audit against it, and declare it.
II
norprotocol.com
NOR Compliance Kit
Envisioned · Licensed
A practical implementation package designed for enterprise AI teams: rule schema templates by vertical (healthcare, financial services, legal, defence), Mode 2 trigger libraries, audit log tooling, integration guides for major AI platforms, and a self-assessment checklist for compliance declaration.
Intended commercial model: licensed per deployment or per organisation on an annual subscription basis.
III
norprotocol.com/registry
NOR Declaration Registry
Envisioned · Trust Mark
Organisations that adopt NOR Protocol would register their compliance declaration publicly — a verifiable trust mark for procurement, legal, and board reporting: "This AI deployment is NOR Protocol compliant." As AI regulation tightens, a named, publicly verifiable standard becomes a meaningful differentiator.
Intended model: free public listing, with a verified certification tier involving third-party audit (paid).
05 / The Regulatory Moment

Every organisation deploying AI
is being asked the same question.

Boards are asking their AI teams: what is our governance framework? The honest answer, in almost every organisation today, is a policy document. Written in prose. Not machine-readable, not independently auditable.

NOR Protocol gives organisations a structural answer — one that was conceived before the regulatory pressure, not invented in reaction to it. That provenance matters: standards built from first principles carry more credibility than standards written to satisfy a regulation.

The organisations that win on AI governance are not the ones with the best policy documents. They are the ones with the most auditable infrastructure.
🇪🇺
EU AI Act
In force. Mandates governance, audit trails, and human oversight for high-risk AI deployments in financial services, healthcare, legal, and HR — exactly the verticals NOR Protocol is designed for.
🇬🇧
UK AI Safety Institute
Operational and actively developing AI evaluation frameworks. NOR Protocol is designed to provide exactly the structural audit trail these frameworks will require.
🇺🇸
US Federal AI Governance
Executive orders and NIST AI RMF are increasing procurement requirements for verifiable AI safety in federal and regulated sector deployments.
🏛️
Board & ESG Pressure
Institutional investors are asking AI governance questions through ESG frameworks. A declarable, auditable standard is a direct answer — not a narrative one.

Part of the Memarc Architecture

NOR Protocol is designed to stand alone — model-agnostic, platform-agnostic, implementable by any organisation using any AI infrastructure. It is also the safety and governance layer at the core of the Memarc cognitive architecture.


Memarc buyers get NOR Protocol built in. NOR Protocol adopters are natural Memarc prospects. The two are complementary — built from the same architectural philosophy, designed to coexist.


Explore Memarc Systems ↗
🧬
engram.bot
Engram.bot
The Identity Vault
🧠
episodic.bot
Episodic.bot
The Context Engine
⚙️
procedural.bot
Procedural.bot
The SOP Engine
synaptic.bot
Synaptic.bot
The Connector
🌙
glymphatic.bot
Glymphatic.bot
The Hygiene Cycle
🦅
huginn.bot · muninn.bot
Huginn & Muninn
Scout & Auditor
🔐
norprotocol.ai · norprotocol.com
NOR Protocol
The Safety Reflex — you are here
Build this with us

NOR Protocol is a concept seeking the right collaborators — whether that is an AI platform looking to embed a safety standard, an institution that wants to lead on AI governance, or an acquirer who sees the category opportunity.

The concept is mature. The domains are secured. The specification does not yet exist. We are looking for the right partner to build it — or the right home for it to be built from. No pitch. Just an honest conversation.

✦   Message received. We will be in touch shortly.

Conversations are confidential. All enquiries go to contact@memarc.ai