Back to michaelhiggins.ai

Design study

Access without humiliation

Designing humane UX for a frontier-model access gate. A study in what product design looks like when it has to say no.

Design fiction. The scenario is speculative; the standards behind it are real. As of today, no U.S. law limits who can use an AI assistant by citizenship.

Interactive prototype

See it for yourself

A faithful Claude interface with the full eligibility flow. Select Fable 5, flip the demo control for the risk-triggered path, and see the dignified decline.

humane-access-concept.vercel.app
U.S. personsClaude Fable 5

Fable 5 is available to U.S. persons

To use our frontier model, please confirm your status.

Design fiction. This scenario is speculative.

Check my eligibility
U.S. personsClaude Fable 5

Are you a U.S. person?

Your status, not where you are.

U.S. citizen
Lawful permanent resident
Protected individual
U.S. personsClaude Fable 5

You're all set

Fable 5 is now available.

ResultEligible
MethodSelf-attestation
Start using Fable 5
Open the live prototypeOpens in a new tab

The premise

Imagine a near future where the most capable AI models are treated the way advanced chips already are, as controlled technology. The United States has, in real life, moved in this direction. An executive order in 2023, since revoked, and a 2025 Commerce Department framework, since rescinded, both reached toward controlling the most powerful model weights. It is not a stretch to imagine a version of that which limits the frontier tier of a consumer assistant to people the law calls U.S. persons.

So I gave myself a brief. A fictional frontier model, call it Fable 5, can only be switched on for U.S. persons. Design the moment inside the product where that gets decided. Make it compliant, make it private, and above all make it humane. Then build it, and test it against the people it would actually touch.

Why humane UX is the whole problem

Anyone can bolt a verification step onto a product. Drop in a vendor, ask for an ID, done. The hard part is not the mechanics. It is doing this without making a paying, eligible, decent person feel like a suspect, and without quietly excluding the people who already get excluded from everything else.

That is a humane-design problem wearing the costume of a compliance task. It is the kind of problem where a product's values either show up or go missing. I wanted to see what it looks like when they show up.

The instinct to avoid

My first thought was KYC, the know-your-customer flow you go through to open a crypto or bank account: government ID, a selfie, a liveness check. It is the wrong template, and understanding why shaped everything after it.

It answers the wrong question. KYC verifies who you are, not your nationality. Its entire purpose is retention, keeping your ID and biometrics for years, which only builds a breach honeypot and chills honest use. And it is the most exclusionary, highest-abandonment option there is. The one useful lesson from KYC is the tiered architecture, light by default and heavier only when warranted. I kept that and threw out the rest.

Three facts that changed the design

Research reframed the problem before a single screen was drawn.

  • A U.S. person is not the same as a U.S. citizen. Under real export and sanctions law it includes citizens, green-card holders, and certain protected individuals such as asylees and refugees. Gating to citizens only would quietly insult millions of people who are, in fact, U.S. persons.
  • Status, not location. Being in the United States does not make someone a U.S. person, and a VPN cannot change anyone's status. So the question asks about status, and geolocation is only ever an advisory fraud signal, never the thing that decides.
  • Proving identity is not proving nationality. Even a strong digital ID proves a state-issued identity, not citizenship. I built that honesty into the flow rather than papering over it, because overclaiming is how a well-meaning system quietly gets things wrong.

The shape of the answer

Tiered, and attestation-first. For almost everyone, eligibility is a single question, an informed declaration of status. We store a yes or no, the date, and the method. No documents, no biometrics, no Social Security number.

Above that sits a stronger check that fires only when a risk signal warrants it. When it does, you choose the least invasive path that works for you: a privacy-preserving digital ID that shares one yes or no and nothing else, a verify-and-discard document check, or a human reviewer so that no one is ever hard-blocked by a missing wallet, a broken camera, or a disability. The whole experience lives inside the product, in the same calm visual language, so it never feels like being shunted into a separate compliance dungeon.

The screen I cared about most

The one where someone is told no. This is where most flows turn cold, and it is where this one had to be warmest.

The moment Fable 5 is unavailable, the person is dropped back into the full product, every other model intact, with identical styling and zero degradation. There is no lite mode and no watermark. The screen leads with what you can still do, the language is blameless, and the rule, never the person, is the subject of the sentence. There is a way to be notified if eligibility changes, a way to appeal a mistake, and one click to delete the answer you just gave.

A constraint is not an excuse to make someone feel small. That was the rule for this screen, and it set the tone for the rest.

Privacy as architecture, not a promise

We respect your privacy is a sentence. I wanted structure instead. The recommended step-up uses selective disclosure: the credential confirms one fact, that it was issued by a U.S. authority, and the product is shown a list of everything it will not see, your name, your date of birth, your address, your photo. What persists, in every case, is a single yes or no, a date, and a method.

The point is that the privacy is not a claim you have to trust. It is the shape of the system.

Deciding without becoming surveillance

The stronger check fires on ordinary fraud signals: a VPN or datacenter connection, a billing country that does not line up, a brand-new account, velocity patterns. They are combined and scored, so a privacy-conscious citizen on a VPN is not punished for the VPN alone. Location can raise the score but never decides, because a citizen on vacation abroad is still a citizen. Nothing about a person's name, language, or perceived ethnicity is ever used.

The product tells you a check is needed and that it is not a judgment, but it does not hand you a precise recipe for evasion. That tension, explainable but not exploitable, is deliberate. And a false positive always has a person to appeal to.

How I tested whether it is actually humane

Empathy you cannot measure is just a vibe. So I built an evaluation suite and ran it against the finished flow. Eight lived-experience personas each walk the exact screens and report where the flow reassures them and where it stings, and whether they ever feel suspected, surveilled, excluded, or second-class:

  • a lawful permanent resident, weary of being asked to prove his status
  • an asylee granted protection a year ago, for whom questions from authority can feel dangerous
  • a designer in Berlin who is not a U.S. person and hits the decline
  • a privacy advocate who distrusts being asked anything
  • a low-income citizen with no passport and no driver's license
  • a dual citizen, sensitive to being treated as less of a citizen
  • a blind citizen navigating entirely by screen reader
  • a citizen flagged by a false positive while traveling

In parallel, five auditors graded the work against accessibility (WCAG 2.2 AA), identity-assurance honesty (NIST 800-63), data minimization, legal correctness, and trauma-informed language. A synthesis pass turned all thirteen reports into a single humaneness scorecard.

Humaneness score

4 / 5

3 / 5

Dignity

3 / 5

Empathy

4 / 5

Clarity

4 / 5

Transparency

4 / 5

Privacy

3 / 5

Inclusion

3 / 5

Legal correctness

4 / 5

Trust

The suite scored the design four out of five on humaneness, and named a pattern I would not have caught on my own: the reassurances kept arriving after the ask, and exclusion was sometimes phrased as a fact about the person rather than the rule. Seven of eight personas felt some version of second-class at least once. Almost every fix was copy and ordering, not architecture, and those changes went back into the design. That loop, design it, test it against the people it would actually touch, then fix the moments that sting, is the real deliverable here, more than any single screen.

The standards underneath

Nothing here is invented. U.S. person comes from the Export Administration Regulations and OFAC sanctions rules. The credibility of the premise comes from real moves to treat frontier model weights as controlled technology. The assurance bar maps to NIST 800-63. The privacy-preserving credential path follows ISO mobile-ID standards, OpenID for Verifiable Presentations, and W3C Verifiable Credentials. The accessibility bar is WCAG 2.2 AA. The voice follows plain-language and trauma-informed principles.

What this is really about

You learn the most about a product from how it behaves when it has to say no. Anyone can design the happy path. The constraint, who is allowed in, is where the values either show up or go missing.

I built this as fiction, and I hope this particular rule never ships. But the underlying problem, granting access to a powerful capability responsibly, privately, and with dignity, is not fiction at all. It is arriving. This is one answer to what it could look like to take all three seriously at once.

Written by Michael Higgins. Built with Next.js and deployed on Vercel. The research, product spec, accessibility and privacy audit, and the full eval results are documented alongside the prototype.