The model may help you plan.
It goes nowhere near
the proof.
Almost every AI governance tool asks a model to describe what happened, then keeps the description. That record is only as good as the model on the day it was asked — and it cannot be re-derived when someone disputes it two years later.
The evidence has to survive the model changing.
object. An obligation
is not. Any record
whose meaning depends
on a model version
expires quietly, and
nobody is told.
Models are retrained, replaced and deprecated. Prompts are edited. Providers change defaults without notice. If your compliance record was produced by asking a model to summarise what happened, the record inherits every one of those changes — and there is no way to establish, afterwards, which version answered.
The separation is the answer, and it is architectural rather than procedural. Planning is where novelty and judgement live, and a model is genuinely useful there. Enforcement and proof are where determinism is required, and a model has no place in either. Those concerns run in different processes with a versioned contract between them.
The consequence is the claim worth making: no AI-generated content enters the evidence record. What is recorded is what was examined, on which build, in what state, and what was found.
The frameworks asking for it.
- EU AI Act
- Annex IV technical documentation for every high-risk system, the risk management system, post-market monitoring, and transparency obligations — held for a decade and produced on demand. The nine Annex IV headings, and what is produced against each, are set out on the compliance page.
- NIST AI RMF
- Govern, map, measure and manage, expressed as executable controls rather than a maturity narrative — so that a claim of "managed" has an examination behind it.
- ISO/IEC 42001
- AI management system requirements, mapped once across overlapping scope with ISO/IEC 27001 and SOC 2 rather than maintained three times.
- Model risk supervision
- Where a supervisor already governs model risk — CBUAE in the Gulf, sectoral model-risk practice elsewhere — the same evidence answers it: what the model was, what it was used for, who approved it, and on what basis.
- Inventory first
- Every obligation above presumes you can enumerate your AI systems and their provenance. Most institutions cannot, and discover it during the first assessment rather than before it.
Three rules that make the record defensible.
Separation
Where the model is allowedThe planning layer may use AI. The enforcement layer must not. Different processes, versioned contract between them. The AI-shaped risk is concentrated where you would expect it, and it is small.
Determinism
Once sealed, no reinterpretationA sealed blueprint executes without prompt-time interpretation. Identical inputs, under an identical version and configuration, produce an identical trace. That is what makes replay mean anything.
No generated evidence
The record is examination, not proseNothing a model wrote becomes a finding. A record states what was examined and what was found, with its reference. A check that cannot be grounded is reported as unestablished — never rendered as a pass.
Where no AI guideline has landed yet.
not published an AI
guideline. All of them
will. The institutions
that built the evidence
habit first are not the
ones scrambling in
year one.
Many jurisdictions supervise AI today through existing instruments — operational risk, outsourcing, cyber and technology risk, model risk — rather than through a dedicated AI guideline. That is a timing difference, not a reprieve.
It also carries a specific hazard. Where a supervisor requires new or amended requirements to be tested within a fixed window of their effective date, an AI guideline arrives with its clock already running. Twelve months is a comfortable period to test a control set that exists, and a very short one to build an inventory from nothing.
The work that answers a future AI guideline is the work that answers today's obligations. Enumerate the systems, record who approved what and on what basis, and produce evidence that does not depend on a model to be believed. The Bank of Mauritius mapping is one worked example of the same discipline.
Where these claims stop.
The boundaries on the main page apply here without amendment. Three more are specific to AI governance.
- Not model assurance
- This governs how an AI system is documented, approved, constrained and evidenced. It does not evaluate a model's accuracy, fairness or safety, and does not substitute for the testing that establishes those properties.
- Not conformity
- Producing Annex IV documentation is not a conformity assessment and does not make a system conformant. That determination is made by the provider, and where required, by a notified body.
- Inventory is bounded
- Coverage of an AI inventory is bounded by what has been registered and instrumented. Systems outside that boundary are reported as outside it — never as absent.
Bring the AI system you would least like to be asked about.
A diligence call covers what the documentation obligation actually requires, where the model is and is not permitted, and what the evidence does and does not establish. Thirty minutes. With the founder.