Two readings of published instruments, made in September 2026. The first reads four instruments that will oblige deployers to keep recordsagainst a single question: do they require a record to say who authorised aconsequential action, and to be checkable by somebody other than the partythat produced it? The EU AI Act, the ForHumanity certification criteria, theCoSAI Risk Map and the NIST AI RMF. Three of the four specify what a recordmust contain and all three require one to be kept. None requires it to becapable of being shown unaltered by anyone other than its author. NIST isrecorded as not applicable throughout, because a framework that deliberatelyspecifies no controls is not failing to specify one. ISO/IEC 42001 has noverdict because its text is paywalled, which is recorded as a fact about thefield rather than guessed at. The second reads two articles of the EU AI Act against each other. Article 86gives an affected person the right to clear and meaningful explanations of therole of an AI system in a decision and the main elements of the decisiontaken, across seven of the eight areas of Annex III. Article 12 specifies whata log must contain for one of them, remote biometric identification, which isalso the only place the Act requires the record to name the natural personswho verified a result. The duty to explain is therefore seven times wider thanthe duty to record, and the counts show what deployed software can answer: often agent systems read at pinned commits, two can recover the source of astored fact by following a link rather than inferring it, and eight cannot sayafterwards that two stored facts ever disagreed. Neither reading is legal advice. Every verdict names the article, clause,control or criterion it rests on, so that a wrong one is cheap to demonstrate.An earlier version of the first reading said the Act contained no requirementto record a person's identity; that was false, Article 12(3)(d) requires itfor one category, and the correction is recorded on the face of both documentsrather than made quietly. The per-system verdicts these counts come from are deposited separately atdoi:10.5281/zenodo.22290922.
Troy Clifford· Zenodo (CERN European Organi...· 0 citations
Two readings of published instruments, made in September 2026. The first reads four instruments that will oblige deployers to keep recordsagainst a single question: do they require a record to say who authorised aconsequential action, and to be checkable by somebody other than the partythat produced it? The EU AI Act, the ForHumanity certification criteria, theCoSAI Risk Map and the NIST AI RMF. Three of the four specify what a recordmust contain and all three require one to be kept. None requires it to becapable of being shown unaltered by anyone other than its author. NIST isrecorded as not applicable throughout, because a framework that deliberatelyspecifies no controls is not failing to specify one. ISO/IEC 42001 has noverdict because its text is paywalled, which is recorded as a fact about thefield rather than guessed at. The second reads two articles of the EU AI Act against each other. Article 86gives an affected person the right to clear and meaningful explanations of therole of an AI system in a decision and the main elements of the decisiontaken, across seven of the eight areas of Annex III. Article 12 specifies whata log must contain for one of them, remote biometric identification, which isalso the only place the Act requires the record to name the natural personswho verified a result. The duty to explain is therefore seven times wider thanthe duty to record, and the counts show what deployed software can answer: often agent systems read at pinned commits, two can recover the source of astored fact by following a link rather than inferring it, and eight cannot sayafterwards that two stored facts ever disagreed. Neither reading is legal advice. Every verdict names the article, clause,control or criterion it rests on, so that a wrong one is cheap to demonstrate.An earlier version of the first reading said the Act contained no requirementto record a person's identity; that was false, Article 12(3)(d) requires itfor one category, and the correction is recorded on the face of both documentsrather than made quietly. The per-system verdicts these counts come from are deposited separately atdoi:10.5281/zenodo.22290922.
Troy Clifford· Zenodo (CERN European Organi...· 0 citations
Two readings of published instruments, made in September 2026. The first reads four instruments that will oblige deployers to keep recordsagainst a single question: do they require a record to say who authorised aconsequential action, and to be checkable by somebody other than the partythat produced it? The EU AI Act, the ForHumanity certification criteria, theCoSAI Risk Map and the NIST AI RMF. Three of the four specify what a recordmust contain and all three require one to be kept. None requires it to becapable of being shown unaltered by anyone other than its author. NIST isrecorded as not applicable throughout, because a framework that deliberatelyspecifies no controls is not failing to specify one. ISO/IEC 42001 has noverdict because its text is paywalled, which is recorded as a fact about thefield rather than guessed at. The second reads two articles of the EU AI Act against each other. Article 86gives an affected person the right to clear and meaningful explanations of therole of an AI system in a decision and the main elements of the decisiontaken, across seven of the eight areas of Annex III. Article 12 specifies whata log must contain for one of them, remote biometric identification, which isalso the only place the Act requires the record to name the natural personswho verified a result. The duty to explain is therefore seven times wider thanthe duty to record, and the counts show what deployed software can answer: often agent systems read at pinned commits, two can recover the source of astored fact by following a link rather than inferring it, and eight cannot sayafterwards that two stored facts ever disagreed. Neither reading is legal advice. Every verdict names the article, clause,control or criterion it rests on, so that a wrong one is cheap to demonstrate.An earlier version of the first reading said the Act contained no requirementto record a person's identity; that was false, Article 12(3)(d) requires itfor one category, and the correction is recorded on the face of both documentsrather than made quietly. The per-system verdicts these counts come from are deposited separately atdoi:10.5281/zenodo.22290922.
Troy Clifford· Zenodo (CERN European Organi...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.