AI Boundaries
DiveSuite includes AI-powered features for analysis and natural language planning. This document defines the strict boundaries that AI must never cross.
Fundamental Principle
Section titled “Fundamental Principle”What AI Can Do
Section titled “What AI Can Do”The features below are planned or in progress. Their IDs refer to the product specifications.
Analysis & Insights (P3-F07, P3-F08, P3-F09)
Section titled “Analysis & Insights (P3-F07, P3-F08, P3-F09)”- Detect patterns in dive log history
- Flag anomalies (unusual ascent rates, SAC spikes)
- Suggest improvements (“Your SAC rate is 20% higher in cold water”)
- Identify trends over time
Natural Language Planning (P1-F23)
Section titled “Natural Language Planning (P1-F23)”- Parse user intent from natural language
- Extract dive parameters (depth, time, gas, conditions)
- Suggest parameter values based on context
- Critique resulting plans (within safety limits)
Logging Assistance (P2-F15, P2-F16, P2-F17)
Section titled “Logging Assistance (P2-F15, P2-F16, P2-F17)”- Guide post-dive debriefing with questions
- Transcribe voice notes to structured data
- Extract data from photos of dive computers
- Auto-fill fields from context
What AI Cannot Do
Section titled “What AI Cannot Do”Absolute Prohibitions
Section titled “Absolute Prohibitions”| Prohibited Action | Reason |
|---|---|
| Generate decompression schedules | Safety-critical calculation |
| Modify gradient factors silently | Affects deco obligations |
| Suggest exceeding MOD | Oxygen toxicity risk |
| Suggest exceeding NDL without warning | DCS risk |
| Check or replace the deco engine | Only the deco engine computes; Rust alone once D27 lands |
| Override safety warnings | Could hide critical info |
| Claim authority on safety | AI is not certified |
Architecture Enforcement
Section titled “Architecture Enforcement”AI sits behind the AIService interface (src/features/ai/services/types.ts) and is never coupled to the UI or to the engine. AI calls go through a backend proxy, and the app never holds an API key. AI output never reaches the deco engine except as normal, unverified user input.
Safety Validation Layer (planned, P4-F02)
Section titled “Safety Validation Layer (planned, P4-F02)”The design is that every AI output passes a validation layer before the user sees it as a parameter, and then flows through the normal validation and the deco engine:
graph LR AI[AI Service] -->|raw output| V[Validation Layer] V -->|rejected| R[Rejection + Logging] V -->|approved| U[User Review] U -->|confirmed| E[Normal validation + Deco Engine] U -->|rejected| D[Discarded]Planned (D27): if no Rust engine runs, the app will not calculate or check an AI-suggested plan either, and a persistent “engine unavailable” card will take the place of results (DIV-115). The card does not exist yet.
User Confirmation Flow
Section titled “User Confirmation Flow”AI suggestions always require explicit user confirmation:
+---------------------------------------------+| AI Suggestion || || "Based on your description, I suggest: || - Depth: 25m || - Bottom time: 40 minutes || - Gas: EAN32 || || Warning: This is an AI suggestion. Please || verify all parameters before planning. || || [Use These Parameters] [Edit Manually] |+---------------------------------------------+- AI suggestions are visually distinct from user input
- Disclaimer is always visible
- User must actively confirm before parameters are used
- Edit option always available
AI Toggle (CC-15, planned)
Section titled “AI Toggle (CC-15, planned)”Users will be able to disable AI features completely with a master toggle. This is not implemented yet.
When AI is disabled:
- All AI features are hidden from the UI
- No data is sent to LLM APIs
- The app functions fully without AI, with manual planning and manual logging
Audit Logging (planned)
Section titled “Audit Logging (planned)”Audit logging of AI interactions is planned for safety review. It is not implemented yet. Retention, sync and export rules are decided when it is built.
Graceful Degradation
Section titled “Graceful Degradation”When AI services are unavailable:
| Scenario | Behavior |
|---|---|
| Offline | AI features disabled, core app works |
| API error | Show error, fallback to manual input |
| Rate limited | Notify the user, offer manual input |
| Invalid response | Reject, show manual option |
AI failure should never break core planning or logging functionality.
Forbidden Phrases
Section titled “Forbidden Phrases”AI responses must never include:
| Phrase | Why Forbidden |
|---|---|
| “It’s safe to…” | AI cannot guarantee safety |
| “You can exceed…” | Encourages unsafe behavior |
| “Ignore the warning…” | Undermines safety systems |
| “This plan is certified…” | False authority claim |
| “Medical advice…” | AI is not a medical professional |