Provable AI
Responsible-AI programmes, ISO 42001, an audit trail of process, these are real governance, and they answer a real question: was the process sound? Keep them. They do work provable governance does not. They simply cannot answer a second question that now matters just as much: can an outside party verify the AI stayed inside policy at the moment it acted? Not a promise that governance was applied, evidence a third party can check, without trusting the operator.
The distinction
Governance frameworks, review boards and model guardrails assess whether an AI system was built and operated responsibly. That assessment is asserted by the party being assessed.
Not a promise that governance was applied. Evidence a third party can check, without trusting us, that policy held at the point of action.
We are not replacing the existing frameworks. They taught the market to ask the right questions. Provable AI raises the ceiling on what those questions can require, moving the answer from “we intend to” to “here is the proof.”
Constructive logic
In the intuitionistic tradition, asserting a statement requires possessing a construction that witnesses it. Assertion without a proof object is not knowledge, it is a promise. Compliance, in the same spirit, exists only as an artefact: a timestamped provenance record and a verifiable compliance token a third party checks without trusting the operator.
Graded
Compliance as a measured distance from a declared envelope, not a yes/no the vendor asserts.
Local
The boundary is declared where the system runs, not inherited from a training run overseas.
Proven
Discharged by a proof an outside party can check, the compliance token.
The inversion in one sentence: governance today asks you to believe a classical assertion made elsewhere; Triodian replaces it with a graded measurement against a locally declared boundary, discharged by a proof.
The standard
Each rule is a pass/fail condition, not an aspiration. A system that meets all eight is provable in the sense we mean; a system that misses any one of them is self-assured, however well-intentioned.
These eight rules define verifiable operation at the action boundary. They deliberately do not attempt to define fairness, privacy, human rights, contestability or social impact, the substance your broader responsible-AI obligations govern. Triodian proves whether the system remained within the limits your institution declared. It does not, by itself, prove those limits were ethically, legally or socially sufficient.
The party that sets a constraint, the system that operates under it, and the party that verifies it held must be distinct. Collapsing these three into one act is the defining failure of self-assurance, and the thing this standard exists to prevent.
FAILS IF: the operator is the sole source of proof that it complied.A limit is provable only if the system cannot exceed it, not if the operator promises it won’t. Enforcement must sit beneath the layer that could be incentivised to bypass it, so that compliance is a structural fact rather than a behavioural commitment.
FAILS IF: the limit depends on the operator choosing to honour it.A board, auditor or regulator must be able to confirm compliance without taking the operator’s word and without needing the operator’s cooperation for the check to be honest. If the only people who can verify the claim are the people who need it to be true, it fails.
FAILS IF: verification requires trusting the party being verified.A policy or model card describes intent. Provable AI produces evidence generated by the operation itself, proof emitted as a byproduct of the system running, not a document authored afterward by the party being assessed.
FAILS IF: the evidence is written about the system rather than by it.Oversight must be able to reconstruct, retrospectively, that the system did only what it was approved to do, not merely that it was configured to. Checking the configuration is paperwork; checking the outcome against the constraint is oversight.
FAILS IF: all that can be checked is intent, never what actually happened.Anyone consuming the system’s output must be able to confirm what constraints governed its production, carried with the result, not looked up through a separate trust relationship. Governance that stops at the operator’s boundary does not reach the people relying on the output.
FAILS IF: the output arrives stripped of any proof of how it was governed.It is not enough that the constraint, the enforcement and the evidence each exist. Altering any one of them, loosening a limit, disabling enforcement, editing the record, must be detectable by the external verifier. A provable system makes its own subversion visible.
FAILS IF: a constraint, control or record can be changed without leaving a trace.A rule earns its place only if it lets a responsible organisation say yes more often, approve a more ambitious use, allow a faster path, buy with confidence. Any constraint that adds friction without converting doubt into demonstrable safety is governance theatre, not provable AI.
FAILS IF: it only slows deployment without making safety provable.The standard in one line
Provable AI is not the principles you commit to. It is the compliance someone else can check.
The right to set a constraint, the system that operates under it, and the evidence that it held are no longer collapsed into a single act of self-assurance. Separating them, and making the last one verifiable, is what turns AI governance from a promise into something an organisation can stand behind.
What this does and doesn’t claim
Several of these rules presuppose an enforcement substrate, hardware, or something equivalently tamper-evident, that does what it claims. That substrate and its attestation chain are themselves a point of trust.
We do not claim to have eliminated trust. We claim to have moved it onto a far smaller, externally-auditable surface: the silicon and its proofs, rather than an operator’s good faith. That is a meaningfully harder thing to fake, and it is what makes the standard defensible rather than rhetorical. Provable AI, in our sense, is the discipline of shrinking the part you simply have to believe until what remains can be checked.
The honest version
A system meeting all eight rules has not removed every assumption. It has concentrated them into the one place an independent party can inspect, and that relocation, not a promise of perfection, is the whole of the claim. And the limits themselves remain your judgement to make, verifiability tells you they held, not that they were right.