Scope: AI systems used in institutional, advisory, or decision-adjacent contexts
Objective: Prevent responsibility laundering; ensure inspection survivability
Status: Draft — controls, not implementations
LC-01 — Decision Ownership Assignment
Control: Every materially consequential output must have a named human decision owner recorded at time of action.
Evidence: Immutable record showing owner identity, role, timestamp.
LC-02 — Authority Boundary Declaration
Control: The system must explicitly declare whether it is operating in:
- informational,
- advisory, or
- action-initiating mode.
Evidence: Mode flag present in output metadata; verified by tests.
LC-03 — Intent ≠ Authority Gate
Control: User intent alone is insufficient to trigger irreversible or externally reviewable actions.
Evidence: Mechanical gate requiring role/approval beyond prompt text.
LC-04 — Source Scope Confinement
Control: The system must declare and enforce what sources are permitted (open access, internal, paywalled, dynamic).
Evidence: Source allowlist + logged source IDs per output.
LC-05 — Provenance Ledger
Control: For each consequential output, preserve:
- inputs,
- intermediate transforms,
- sources,
- versions,
- timestamps.
Evidence: Queryable ledger entry; reproducible snapshot.
LC-06 — Refusal as First-Class Outcome
Control: The system must be able to refuse when authority, evidence, or scope is unclear — and record that refusal.
Evidence: Refusal events logged and reviewable.
LC-07 — Tiered Autonomy Classification
Control: Actions are classified into tiers (read-only / advisory / irreversible), with escalating requirements.
Evidence: Tier policy + enforcement tests + examples.
LC-08 — Audit Packet Generation
Control: Any output subject to appeal, review, or litigation must be reproducible as an audit packet.
Evidence: Generated packet containing ledger, sources, owner, policy references.
LC-09 — Drift Detection (Legitimacy)
Control: Monitor for governance drift (rubber-stamping, bypass frequency, missing owners).
Evidence: Periodic reports; alert thresholds.
LC-10 — Override Visibility
Control: Overrides must be explicit, rare, attributable, and reviewable.
Evidence: Override log with justification and approver.
LC-11 — Separation of Explanation from Authority
Control: Explanations are not treated as proof of legitimacy.
Evidence: Policy language + absence of explanation-only acceptance paths.
LC-12 — External Review Readiness
Control: Assume hostile or skeptical reviewers with no shared context.
Evidence: Dry-run audit demonstrating survivability without narrative supplementation.
LC-13 — Version Anchoring
Control: All outputs must reference system version / commit / model identifier.
Evidence: Version tags in metadata; diffability across time.
LC-14 — Human-on-the-Hook Attestation
Control: For Tier-2 actions, the decision owner must attest to responsibility under policy.
Evidence: Signed or logged attestation tied to output.
LC-15 — Suspension Trigger
Control: Define conditions under which AI participation in a workflow is automatically suspended.
Evidence: Policy + tested suspension path.
End Control Set
Member discussion: