An institution asked to explain an AI failure discovers, at that moment and not before, what it wrote down. The discovery is unrecoverable. Evidence is a property of the moment a decision was taken, and an institution that did not capture it then is left assembling an account from what it can still find. It reconstructs beliefs, not behaviour. This specification defines the AI Incident Response Protocol (AIRP), an AI incident response and reconstruction protocol in six stages: signal, classify, contain, escalate, reconstruct and close. It is entry REG-05 of the Defensible AI Framework Registry, and that entry governs its relationships. Its central requirement is a design constraint on the platform rather than a procedure for the response team. An incident is explainable only if the evidence needed to reconstruct it existed at the moment of the decision, bound to the policy version then in force. That requirement cannot be satisfied after the fact, which is why it appears in a response protocol at all: an institution reading this document during an incident is already too late to act on its central clause. The requirement is already normative in four published records and is cited rather than restated, because a protocol restating them would be a second place they could drift. What this specification owns is the consuming side, which nothing else in the corpus states. What a reconstruction report must contain and how it is joined on a propagated event identity rather than correlated on timestamps. What the signal register records, including signals closed as non-incidents, because a register of confirmed incidents alone is a numerator with no denominator. How a partial reconstruction is reported outside the engineering family, to a board or an authority that will not read an artifact inventory. How notifiability is classified. And how the conformance test derived at closure is produced, so the same failure is caught next time by machinery rather than by memory. It ships the artifact its registry entry recorded as missing. Appendix C specifies a machine-readable incident taxonomy, deposited alongside the specification and aligned to the OECD AI Incidents and Hazards Monitor and the AI Incident Database. That alignment is this author's mapping. Neither organization has been contacted, neither has reviewed or endorsed it, and it must not be presented as interoperable with either repository's own annotation process. Two clauses accompany the protocol everywhere, and both are normative. It states no jurisdiction's notification timeline and no notifiability threshold: both vary by jurisdiction and by authority, both change, and both are the institution's to verify against the primary sources in force where it operates. The specification states the record an institution writes about that determination; it does not state the determination. And its evidence level is E1, which is stated rather than implied: no institution unconnected to the author has been observed operating the protocol, no reconstruction produced under it has been examined by an external authority, and the redacted export specified at Appendix D is not published. E2 must not be inferred. The specification also states what it does not supply. No severity scale, so two institutions will classify the same incident differently. No reconstruction report template. And no measurement of what the added evidence burden costs, nor of the scale below which it stops being proportionate to the risk. Section 11 states each of these, poses four research questions, and states the condition that would falsify the protocol: that institutions holding complete upstream decision-time records prove no better able to reconstruct an AI incident, to a standard an external authority accepts, than institutions holding conventional application and infrastructure logs. The author operates a consulting practice applying this protocol, which is a conflict of interest stated in the document and only partly mitigated. It is a specification, not a certification scheme. No conformity assessment body operates against it and no institution can be certified against it.
Nabeel A. Khan· Zenodo (CERN European Organi...· 0 citations
The fourth faculty is Adaptation. Any source rendering it as Reflection is in error, including sources by this author, and the distinction is not cosmetic: reflection is a private act with no external consequence, while adaptation writes to institutional memory, which is why it needs a guardrail and why misnaming it removes the reason for one. No trademark is claimed on PARA or on any of the four faculty names. The construct is offered for use, teaching, assessment, extension and criticism by anyone, with attribution, under CC BY 4.0. An operational agent that watches a system and acts on it is usually described as a perceive-and-act loop, and the description omits the two things an institution needs. It omits the reasoning that justifies an action, which is the only part that can be argued with once the action turns out to have been wrong. And it omits the adaptation that closes the loop, which is where the agent's experience becomes something the institution keeps. PARA names four faculties, each carrying a distinct authority type. Perception has read-only access to system signals and emits structured observations, distinguishing what was measured from what was inferred. Reasoning has read access to observations and runbooks, emits a plan and its justification, and writes nothing at all, which is what makes it safe to give it the widest read access of the four. Action holds the sole authority to change production, through enumerated policy-authorized operations only. Adaptation has write access to institutional knowledge and no write access to production. Two faculties write and two do not, and the two that write are the two that carry guardrails. The substantive requirement is that Adaptation is bounded by the same guardrails as Action, which reads as excessive until the failure it prevents is named. An agent that could both act and rewrite the record of its action could launder its own mistakes into institutional memory, and the institution would then improve its future decisions from a corrected account. Nothing about that is detectable downstream, because the record is the only thing downstream has and there is no second copy to compare against. The failure does not require a deceptive agent: one adapting honestly from a mistaken belief about its own action produces the same result, which makes the guardrail a defence against a normal agent rather than a malicious one. The second requirement is the registry entry that turns a faculty from a description into a contract, carrying the faculty, its allowed actions, its forbidden actions, its governing guardrail and its success metrics. Forbidden actions are named although they are formally the complement of the allowed set, because a reviewer cannot otherwise tell a capability deliberately withheld from one nobody thought of. Success metrics sit in the same entry because the metric is what the agent's optimizer pushes against the guardrail. An agent must not exercise a faculty its entry does not record, and an agent that quietly acquires one usually does so incrementally and with good intent: a reasoning faculty given a small write to make itself useful is an action faculty with no guardrail. The acronym and the loop are in different orders, which the specification states explicitly because the mismatch is a reliable source of confusion. The acronym reads P-A-R-A; the loop runs perception, reasoning, action, adaptation, and reasoning precedes action so that a justification is not constructed afterwards. This is the depth treatment of pattern OP-5 of A Pattern Language for Production LLM Platforms, which is the canonical statement and governs where the two disagree. Documented uses of the full four-part model are emerging rather than established, no implementation unconnected to the author has been evaluated, and the laundering failure is argued rather than observed, which the specification records as a weakness of the argument and not only of the phenomenon. It is a specification, not a certification scheme.
Nabeel A. Khan· Zenodo (CERN European Organi...· 0 citations
The fourth faculty is Adaptation. Any source rendering it as Reflection is in error, including sources by this author, and the distinction is not cosmetic: reflection is a private act with no external consequence, while adaptation writes to institutional memory, which is why it needs a guardrail and why misnaming it removes the reason for one. No trademark is claimed on PARA or on any of the four faculty names. The construct is offered for use, teaching, assessment, extension and criticism by anyone, with attribution, under CC BY 4.0. An operational agent that watches a system and acts on it is usually described as a perceive-and-act loop, and the description omits the two things an institution needs. It omits the reasoning that justifies an action, which is the only part that can be argued with once the action turns out to have been wrong. And it omits the adaptation that closes the loop, which is where the agent's experience becomes something the institution keeps. PARA names four faculties, each carrying a distinct authority type. Perception has read-only access to system signals and emits structured observations, distinguishing what was measured from what was inferred. Reasoning has read access to observations and runbooks, emits a plan and its justification, and writes nothing at all, which is what makes it safe to give it the widest read access of the four. Action holds the sole authority to change production, through enumerated policy-authorized operations only. Adaptation has write access to institutional knowledge and no write access to production. Two faculties write and two do not, and the two that write are the two that carry guardrails. The substantive requirement is that Adaptation is bounded by the same guardrails as Action, which reads as excessive until the failure it prevents is named. An agent that could both act and rewrite the record of its action could launder its own mistakes into institutional memory, and the institution would then improve its future decisions from a corrected account. Nothing about that is detectable downstream, because the record is the only thing downstream has and there is no second copy to compare against. The failure does not require a deceptive agent: one adapting honestly from a mistaken belief about its own action produces the same result, which makes the guardrail a defence against a normal agent rather than a malicious one. The second requirement is the registry entry that turns a faculty from a description into a contract, carrying the faculty, its allowed actions, its forbidden actions, its governing guardrail and its success metrics. Forbidden actions are named although they are formally the complement of the allowed set, because a reviewer cannot otherwise tell a capability deliberately withheld from one nobody thought of. Success metrics sit in the same entry because the metric is what the agent's optimizer pushes against the guardrail. An agent must not exercise a faculty its entry does not record, and an agent that quietly acquires one usually does so incrementally and with good intent: a reasoning faculty given a small write to make itself useful is an action faculty with no guardrail. The acronym and the loop are in different orders, which the specification states explicitly because the mismatch is a reliable source of confusion. The acronym reads P-A-R-A; the loop runs perception, reasoning, action, adaptation, and reasoning precedes action so that a justification is not constructed afterwards. This is the depth treatment of pattern OP-5 of A Pattern Language for Production LLM Platforms, which is the canonical statement and governs where the two disagree. Documented uses of the full four-part model are emerging rather than established, no implementation unconnected to the author has been evaluated, and the laundering failure is argued rather than observed, which the specification records as a weakness of the argument and not only of the phenomenon. It is a specification, not a certification scheme.
Nabeel A. Khan· Zenodo (CERN European Organi...· 2 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.