EVIDE Research Series

Working Papers

Governance is not event recording. Governance is transformation qualification.

The formal research foundations behind EVIDE. Two working papers, developed in sequence, that define first what accountability-relevant meaning must survive a boundary crossing, and then how a running system continuously verifies that it has.

Working Paper I

Recursive Semantic Governance (RSG)

Preserving Accountability Across AI Boundary Transformations

Current AI governance architectures treat accountability as a collection of discrete, static artifacts - audit logs, explainability outputs, snapshot-based compliance states. This model fails at the boundary: the moment a decision crosses from one system, agent, or governance layer to another. RSG replaces static event accumulation with state transformation qualification, and formally defines what accountability-relevant meaning must survive a boundary crossing for responsibility to remain attributable.

"Governance is not event recording. Governance is transformation qualification."
Core Primitives
  • Semantic Custody - measurable preservation of governance-relevant meaning across boundaries
  • Governance Vectors - structured accountability state: Decision, Authority, Intervention, Threshold, Continuity, Evidentiary
  • Boundary-Trained Connectors - controlled semantic translation between governance layers
  • Recursive Boundary Alignment - iterative stabilization cycles at every crossing
  • Recursive Evidentiary Governance - externally anchored, independently verifiable governance chronology
Inside the Paper
  • Formal notation: G\u207f(t), semantic divergence \u0394s, causal persistence C\u209a
  • Four canonical architectural diagrams, incl. Recursive Drift Amplification
  • Eight governance failure mode characterizations
  • Full end-to-end walkthrough: AI-assisted insurance claim processing
  • Positioning vs. MCP, LangChain/LangGraph, AutoGen, EU AI Act, NIST AI RMF, ISO/IEC 42001
Working Paper II

Governance Loop Engineering (G-LOOP-E)

Continuous Verification of Accountability Survivability Across Recursive Boundary Crossings

RSG answers the question of what must survive a boundary crossing. It does not, by design, specify how a running system continuously confirms that survival holds between crossings, across many iterations, inside a live orchestration pipeline. G-LOOP-E is the operational layer built directly on RSG primitives that closes this gap - reframing the exit condition of an iterative system loop away from behavioral convergence and toward accountability verification.

"RSG defines what must survive a boundary crossing. G-LOOP-E defines how a running system continuously verifies that it has."
Core Concepts
  • Governance Heartbeat - a recurring verification pulse, scheduled or event-triggered
  • Governance Preservation Loop (GPL) - the formal verification cycle: CONTINUE, DEFER, HALT
  • Reconstructability Test - can accountability still be independently reconstructed if the process stopped now
  • Inspector Independence - executive isolation and semantic asymmetry against correlated failure
Inside the Paper
  • Scheduled vs. triggered heartbeats, with deadband and refractory period against trigger cascades
  • The DEFER Budget - bounding cumulative, undetected degradation across consecutive cycles
  • Four verification depth levels (D0–D3), independent of heartbeat frequency
  • Six loop-specific failure modes, incl. Convoy Drift and Silent Decoupling
  • The Convoy Model - an illustrative figure for non-technical stakeholders
Applied Synthesis

EVIDE Governance Lab: From Research Protocols to Real-World Defensibility

What Each Lab Project Means for Legal Defensibility

RSG and G-LOOP-E define the formal architecture: what accountability-relevant meaning must survive a boundary crossing, and how a running system verifies that survival continuously. This companion document translates six validated Lab projects, built on that architecture, into what each one means in practice -- the question it answers, a real-world scenario, and what changes for an organization that has to defend an AI-assisted decision months or years later.

"EVIDE documents. It does not decide. Every capability produces evidence for a human or a court to evaluate -- none of them determines an outcome."
At a Glance

The table below summarizes all six Lab projects side by side.

Project Core Question Without With Key Terms
Evidentiary Deposit Can we prove the event existed? Event remembered Independent proof the event occurred FCC (+ Evidentiary Profile)
Observer Reconstructability * Does the read change by observer? Divergence unexplained Divergence explained, not assumed Declared Visibility
Authority Visibility Asymmetry * Does a visibility claim alone move findings? Narrative could sway findings Only verified signals move findings Declared Visibility
Authority Continuity Was authority still valid? Authority assumed Continuous authorization evidence AuthorityLock
Epistemic Stabilization Buffer Was the decision stable enough? Immediate crystallization Proof the decision was stabilized first ESB
Governance Preservation Loop Did reconstructability survive over time? One-time verification Proof reconstructability was maintained GPL / G-LOOP-E

* Controlled calibration experiment, not yet a field-validated capability. See the corresponding section in the full paper for scope.

Legend - Key Terms

* The working papers linked on this page were written before some Lab dimensions below reached their current, implemented form. Where a paper's account differs from the definitions below, the definitions below - and their linked documentation - describe the system as it exists today.

FCC - Forensic Cross-Check - A server-computed cross-check between a closure's declared classification and the observational conditions around it (stable / degraded / unknown / broken). It is an observer of continuity, not a decider of correctness - other Lab engines evaluate independently of it, not by relaying it.
DWC - Decision Wave Compression - A per-closure observability signal (not_detected / detected / critical / unknown), derived from the declared runtime visibility, boundary readiness, and any unresolved signals for that single closure. It reports observational quality at one closure, not throughput or volume across many.*
FAC - Formal Accountability Collapse - A per-closure signal (not_detected / detected / critical / unknown), derived from whether authority was declared, the declared attribution status of the threshold authority, and that same closure's Forensic Cross-Check state. An earlier research formulation used this same name for a different, systemic condition; the implemented dimension described here is what the API returns today.*
Declared Visibility (Observer Position) - What a party states about how much of an event they could see - tested to confirm whether a stated visibility can shape the system's formal findings.
AuthorityLock (Authority Continuity) - Verifies that the authority behind an action was still valid when the action executed - not only when it was declared.
ESB - Epistemic Stabilization Buffer - An optional, bounded observation window on an already-accepted intake, closed with one of three declared verdicts: stable, unstable, or deferred - preserving the state as unresolved rather than forcing a conclusion when none can be reached in time.
GPL / G-LOOP-E - Governance Preservation Loop - Repeats the reconstructability check throughout a process's life, not only once at the start. "GPL" is the Lab's slug; "G-LOOP-E" is the working-paper name - same concept, two names.
Discussion Draft

The Evidentiary Status of Internal Reasoning Signals

From "Who Says So?" to "How Do We Know?"

Anthropic's July 2026 interpretability research introduced the J-lens, a technique that reads causally active representations inside a model before they reach its output -- and showed, through direct intervention, that a model's good behaviour under evaluation can depend in part on its private recognition that it is being tested. This paper takes that finding as a starting point and asks a broader question: as AI systems begin exposing signals about their own reasoning, what evidentiary status should each of those signals receive? It proposes that a system's self-report, an external party's attestation, and a causally validated internal reading are not three points on one scale of trust, but three distinct categories that a responsible governance architecture should never collapse into a single notion of "proof."

"The decisive governance question will not be whether internal signals exist. It will be what evidentiary status each of them should receive."
Declared · Established · Measured

Three categories, not one scale of increasing strength -- each grounded differently.

Level Grounded by Example
Declared The system's own assertion reasoning_state: policy_check = true
Established A separate accountable party, under a named protocol AuthorityLock · RFC 3161
Measured A causally validated reading of internal state J-lens (Anthropic, 2026)

This three-level framework is an original proposal developed within the EVIDE Governance Lab. Anthropic's research supplies the empirical grounding for the Measured category and the motivating problem; it does not propose this taxonomy.

Working Paper

EVIDE ANCHOR

Declaring the Operational Perimeter Before an Agent Acts

Motivated by a real incident in which an AI agent mistook a production database for a disposable test environment: the boundary between production and development was never technically enforced nor independently declared - it existed only as an implicit expectation. EVIDE ANCHOR introduces Declaration, an architectural primitive of EVIDE: an explicit, attributable, time-locatable statement of the operational perimeter an agent was authorized within, before it acted - preserved without verifying its truthfulness.

"EVIDE ANCHOR preserves declared authority."
What it establishes
  • Six declaration_type categories: environment, privileges, purpose, tools, prohibited operations, agent configuration - free text, not a closed enum
  • The Atomic Declaration Rule: one Declaration, one attributable statement - independent facts are never merged into a composite declaration
  • declaration_digest, computed server-side over the canonical form (RFC 8785), returned in the response - never supplied by the client
  • declared_relations: a later Declaration can state that it supersedes, clarifies, or revokes an earlier one, without ever rewriting it
  • Validated through five end-to-end scenarios executed via a real MCP client, including a combination of Declarations, Evidence References, and the Epistemic Stabilization Buffer in the same record
What it does not claim
  • Does not verify whether a declaration corresponds to operational reality, nor compare declared against observed
  • Does not enforce or apply any declared policy, limit, or privilege
  • Does not attribute responsibility or establish fault
  • Does not assume that the absence of a declaration equals the absence of the corresponding constraint
  • Never infers, completes, or interprets declarations that do not exist
Research Discussion Note

Building Better AI without Losing the Evidence

Preserving What Matters for AI Providers, Users and Independent Examination

A multi-round, adversarial research exercise searched EU law, technical standards, and the law and regulatory practice of the United States, the United Kingdom, South Korea and China for functional equivalents to a simple hypothesis: that a significant deviation from a system's own observable baseline can trigger the preservation of a bounded evidentiary record, independently of the party under observation - without deciding, at that moment, what the deviation means.

"The evidentiary layer preserves the bounded record. The competent authority or authorised examiner decides what that record means."
The Evidentiary Metronome
  • Reference Profile / Baseline - versioned and bound to the hardware, firmware, model and policy version in force, anchored externally so the system cannot silently redefine its own normal
  • Boundary Observation - arbitration-anchored signals (a safety filter's correction, a controller switch, a re-planning event) rather than raw decision latency or an exposed confidence score
  • Decision Boundary Deviation (DBD) - a statistical or arbitration-level deviation from baseline; the term deliberately does not claim fault, danger or intent
  • Evidentiary Materiality Condition and Evidentiary Trigger - determine whether a deviation is significant enough to warrant preservation, not whether it was wrong
  • Evidentiary Checkpoint - preserves a Minimum Evidentiary Set through an independent evidentiary layer, without chain-of-thought, model weights or source code
Status and Scope
  • A research discussion note, shared for external comment - not a legislative proposal or a technical specification
  • Well grounded for EU law: AI Act, Machinery Regulation, Product Liability Directive, Cyber Resilience Act, General Product Safety Regulation
  • Reasonably grounded for the United States, the United Kingdom, South Korea and China
  • Not yet grounded to the same standard for Canada, Japan, IEC 61508, ISO 26262, the IEEE standards portfolio, the NIST AI Risk Management Framework, or the Medical Device Regulation
  • The earlier working name, "Decision Conflict Signature," has been abandoned - it borrowed a causal vocabulary from cognitive psychology that the underlying observation cannot support

External Review & Research Feedback # Direct link

Observations received on the Research Discussion Note

Selected external observations received following publication of “Building Better AI without Losing the Evidence”. The observations are presented in condensed form and remain attributable to their respective authors. All observations were made unsolicited, as public LinkedIn comments; no compensation or engagement was exchanged in either direction.

Piotr Reder LinkedIn Public LinkedIn comment · 19 September 2026

Observed that the baseline determines what constitutes a deviation, while the Evidentiary Materiality Condition (EMC) determines which deviations are worth preserving. Control over the EMC therefore represents a second boundary not covered by external anchoring of the baseline alone.

# Direct link
Richard Whitney LinkedIn
  1. Move the Section 6 “confident-wrong” limitation earlier in the Note.
  2. Version binding protects bytes, not meaning; semantic drift requires explicit disclosure.
  3. Integrity and availability are distinct properties.
  4. Prioritize the falsification experiment in Section 10.
  5. Do not collapse custody independence into absence of economic interest: control, custody, economic interest, and examination authority are distinct dimensions.
# Direct link
Gerard Foy LinkedIn

Asked whether an evidentiary checkpoint distinguishes between a system’s declaration that an action was authorised and the authority-related evidence available at the relevant moment that may support that declaration, including its source, scope and applicability. Preserving those materials should remain separate from determining whether the authority was valid, sufficient or applicable.

# Direct link
Hlias Staurou LinkedIn

Distinguished deviation from an observed baseline (“unusual”) from deviation from a declared or established boundary (“out of bounds”). The two may diverge: unusual behaviour can remain within established limits, while statistically ordinary behaviour can cross a limit. A checkpoint should therefore state which type of deviation triggered preservation.

# Direct link
Zoli Somogyi LinkedIn

Observed that the Evidentiary Metronome is substantially grounded in physical and autonomous-system contexts, while enterprise agentic software presents different challenges. In open-ended LLM workflows, defining a meaningful behavioural baseline may be difficult, and a prompt-injected or otherwise incorrect API action may execute consistently with the system’s observable pattern, leaving a deviation-based trigger silent. Asked whether such a trigger could replace strict Zero Trust API boundaries and deterministic guardrails.

# Direct link
Research Discussion Note

Provenance, Stability and Falsifiability of Evidentiary Status

Extending the Declared / Established / Measured Framework

When an AI system produces a signal about its own internal state, an important question is: what evidentiary status does that signal deserve? In July 2026, EVIDE introduced the Declared / Established / Measured framework to distinguish self-reported claims, independently established determinations, and causally grounded measurements. This Note asks the next question: once an evidentiary status has been assigned, what must survive about that classification so that its meaning can still be trusted later?

Research continuity
July 2026

The Evidentiary Status of Internal Reasoning Signals

What evidentiary status does the signal deserve?

September 2026

Building Better AI without Losing the Evidence

What evidence should survive, and under whose control, so that later examination remains possible?

This Note

Provenance, Stability and Falsifiability of Evidentiary Status

What must survive about the classification itself so that its evidentiary meaning can still be trusted later?

"Classification is not adjudication. Evidentiary status is not truth. Preservation does not exercise judgment."
Classification Provenance
  • Control Independence — whether a party other than the classifier, or the party described, can alter, delete, withhold or substitute the classification
  • Custody Independence — whether the record is held by a party other than the classifier, and would survive the custodian's own disappearance or withdrawal
  • Measurement Independence — organisational separation between who measures and who builds or operates the system measured, distinct from causal grounding
  • Examiner Independence and Examination Authority — whether the evaluating party is distinct from the one that classified the signal, and under what recognised basis it may examine the record at all
  • Economic Interest — disclosed rather than automatically disqualifying: what matters is the concrete capacity a relationship gives to alter or withhold a record, not its mere existence
Semantic Stability and Falsifiability
  • Category Drift — a signal absorbed into a summary, dashboard, or examiner's own reasoning acquiring a higher evidentiary status than its origin supports
  • Taxonomy Drift — the criteria defining Declared, Established or Measured changing across versions without disclosure where an earlier classification is read
  • Interpretation Drift — what a classification is taken to establish changing over time or across readers, with no formal reclassification
  • Record-Context Drift — the method, taxonomy version, or stated limitations becoming separated from the classification, even as the bare label survives
  • Two levels of falsifiability — whether the taxonomy holds together as a structure, and whether a specific Declared, Established, or Measured assignment can be shown wrong
Architectural Progression
EVIDE How I document an event. External evidentiary anchoring of the declared application event at the boundary of responsibility.
RSG How I qualify the governance transformation. The accountability-relevant meaning that must survive a boundary crossing.
G-LOOP-E How I continuously verify that governance is surviving. A verification cadence above individual crossings.

Ongoing Research

Both papers are living working papers, developed inside the EVIDE Governance Lab and updated as the framework matures. Future research directions - including a Governance Recovery track beyond CONTINUE / DEFER / HALT - are documented in each paper's closing section.

The boundary is where governance succeeds or fails. The loop is what keeps asking, between boundaries, whether it still can.

This series continues as the EVIDE Governance Lab's research develops.