Scope: AI systems used in institutional, advisory, or decision-adjacent contexts
Objective: Prevent responsibility laundering; ensure inspection survivability
Status: Draft — controls, not implementations


LC-01 — Decision Ownership Assignment

Control: Every materially consequential output must have a named human decision owner recorded at time of action.
Evidence: Immutable record showing owner identity, role, timestamp.


LC-02 — Authority Boundary Declaration

Control: The system must explicitly declare whether it is operating in:

  • informational,
  • advisory, or
  • action-initiating mode.
    Evidence: Mode flag present in output metadata; verified by tests.

LC-03 — Intent ≠ Authority Gate

Control: User intent alone is insufficient to trigger irreversible or externally reviewable actions.
Evidence: Mechanical gate requiring role/approval beyond prompt text.


LC-04 — Source Scope Confinement

Control: The system must declare and enforce what sources are permitted (open access, internal, paywalled, dynamic).
Evidence: Source allowlist + logged source IDs per output.


LC-05 — Provenance Ledger

Control: For each consequential output, preserve:

  • inputs,
  • intermediate transforms,
  • sources,
  • versions,
  • timestamps.
    Evidence: Queryable ledger entry; reproducible snapshot.

LC-06 — Refusal as First-Class Outcome

Control: The system must be able to refuse when authority, evidence, or scope is unclear — and record that refusal.
Evidence: Refusal events logged and reviewable.


LC-07 — Tiered Autonomy Classification

Control: Actions are classified into tiers (read-only / advisory / irreversible), with escalating requirements.
Evidence: Tier policy + enforcement tests + examples.


LC-08 — Audit Packet Generation

Control: Any output subject to appeal, review, or litigation must be reproducible as an audit packet.
Evidence: Generated packet containing ledger, sources, owner, policy references.


LC-09 — Drift Detection (Legitimacy)

Control: Monitor for governance drift (rubber-stamping, bypass frequency, missing owners).
Evidence: Periodic reports; alert thresholds.


LC-10 — Override Visibility

Control: Overrides must be explicit, rare, attributable, and reviewable.
Evidence: Override log with justification and approver.


LC-11 — Separation of Explanation from Authority

Control: Explanations are not treated as proof of legitimacy.
Evidence: Policy language + absence of explanation-only acceptance paths.


LC-12 — External Review Readiness

Control: Assume hostile or skeptical reviewers with no shared context.
Evidence: Dry-run audit demonstrating survivability without narrative supplementation.


LC-13 — Version Anchoring

Control: All outputs must reference system version / commit / model identifier.
Evidence: Version tags in metadata; diffability across time.


LC-14 — Human-on-the-Hook Attestation

Control: For Tier-2 actions, the decision owner must attest to responsibility under policy.
Evidence: Signed or logged attestation tied to output.


LC-15 — Suspension Trigger

Control: Define conditions under which AI participation in a workflow is automatically suspended.
Evidence: Policy + tested suspension path.


End Control Set