Rules for accountable and traceable AI: system design, requirements management, signal validation and provenance authentication.
-
-
Most AI governance documents AI processes and outputs after the fact. Controls exist as written attestations rather than as things that can be tested, and evidence is assembled retrospectively, separately, for each regime an organisation answers to. A firm subject to the EU AI Act, ISO/IEC 42001 and a sector regulator will typically produce three overlapping evidence packs by hand, none of which is reusable, and all of which describe the system as designed rather than as operated.
-
-
Surfacing problems of explainability and tracing the priors that shape evidence-based reasoning.
Data lineage is a solved problem in principle. The W3C PROV family specifies how to record that an entity was generated by an activity attributed to an agent, and the standards work. What is not solved is provenance of reasoning — the priors, assumptions, source judgements and conditions that shape an output, whether the output came from a person or a machine.
Most current work approaches this through explainability, which produces an account of a decision after the decision has been made. An explanation generated after the fact is a reconstruction, and its relationship to what actually happened is an open question. A record made at the time is a different kind of object.
-
Mapping what counts as proof and the conditions that shape it.
Every serious domain has already answered this. Legal systems have rules of admissibility and weight. Clinical and social research have reporting standards (CONSORT, STROBE, PRISMA and their relatives). Intelligence practice grades sources and information separately. Audit works in assurance levels. Regulators work in conformity assessment.
Machine-generated material does not fit cleanly into any of them. It arrives without a chain of custody, frequently without a stable account of its inputs, and with a confidence signal that is either absent or not comparable to anything the receiving domain recognises. The practical consequence is that the same output is treated as authoritative in one function and inadmissible in another, within the same organisation.
-
Investigating why intelligence matters, how it forms and operates, where it lives and what it can do .
The question is deliberately about location. Most current discussion treats intelligence as a property of a model, and measures it accordingly, against benchmarks. But the performance that matters to an organisation is produced by an arrangement: an analyst, a set of tools, a body of institutional knowledge, a set of records, and a workflow that determines what any of them get to see.
Benchmark performance is a poor predictor of performance in that arrangement. This is not a controversial observation, but very little follows from it in practice, because there is no established way to measure what a particular arrangement can do in a particular context.

