AI Safety Assurance

Technical assurance evidence for governed AI systems

EvidenceBound maps a narrow technical control layer to broader governance frameworks. The objective is to produce inspectable evidence for operator decisions, not to market a technical receipt as legal compliance.

NIST AI RMF support mappingISO/IEC 42001 evidence supportEU AI Act technical evidence
Position

Controls that can produce evidence.

EvidenceBound binds exact evidence, policy, deterministic checks, negative states, approvals and recovery lineage. These artifacts can support governance processes when an organization maps them to its actual role, risk classification, policies and assurance program.

Explicit boundary: this mapping is not ISO certification, not legal advice, not a conformity assessment, and not evidence that any organization or AI system is compliant with the EU AI Act or another law.
NIST AI RMF 1.0

GOVERN · MAP · MEASURE · MANAGE

The NIST AI RMF is voluntary and use-case agnostic. Its Core organizes risk management into four functions. EvidenceBound addresses only selected technical evidence needs inside those broader organizational activities.

RMF functionEvidenceBound supportBoundary
GOVERNVersioned policy identity, explicit approval boundaries, durable decision receipts, accountable operator state.Does not create governance culture, assign legal accountability or define an organization's risk appetite.
MAPDeclared evidence sources, action scope, dependency lineage and blast-radius context.Does not determine all affected stakeholders, domain harms or socio-technical context.
MEASURERepeatable deterministic verification, conformance tests, negative-path evidence and retained result identity.Does not replace domain TEVV, model evaluation, red teaming or independent assessment.
MANAGEFail-closed outcomes, interrupt/kill boundaries, correction lineage, recovery receipts and explicit proceed/block decisions.Does not choose organizational risk treatment or authorize deployment on behalf of accountable operators.

Official source: NIST AI Risk Management Framework and NIST AI RMF Playbook.

ISO/IEC 42001:2023

Evidence support for an AI management system

ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. EvidenceBound can supply technical records into such a management system; it is not the management system itself.

Potential evidence contribution

Policy versioning, traceability, deterministic test receipts, human approval evidence, incident/correction lineage, retained action identity and recovery state.

Outside EvidenceBound

Organizational objectives, management responsibility, competency, legal obligations, internal audit scope, certification, broader risk treatment and continual-improvement governance.

Official source: ISO/IEC 42001:2023 — Artificial intelligence management system.

EU AI Act

Technical evidence that may support regulated workflows

For AI systems that fall within regulated categories, the EU AI Act can require risk-management, documentation, traceability/logging, human oversight, robustness, cybersecurity and other controls. EvidenceBound can support some technical evidence around those duties, but applicability is a legal and system-classification question.

AreaPossible EvidenceBound artifactNot established by EvidenceBound
Risk controlsVersioned executable policy, blocked states, scoped action boundaries.Complete statutory risk-management system or legal sufficiency.
Logging / traceabilityContent-addressed task, evidence, policy, result and recovery lineage.All logging duties, retention periods or regulator-specific formats.
Human oversightExplicit approval requirement, interruption/kill boundary, operator decision receipt.Whether the assigned human oversight arrangement satisfies the law.
Robustness / cybersecurityAdversarial conformance tests, fail-closed negative paths, integrity checks.Security certification, penetration-test result or overall system robustness.

Official sources: European Commission — AI Act and European Commission — Navigating the AI Act.

Operational evidence model

One evidence chain, several assurance consumers.

declared role + system context ↓ operator-owned policy + evidence identity ↓ deterministic verification + typed negative states ↓ human decision + blast-radius boundary ↓ retained receipt + correction/recovery lineage ↓ organization-specific governance / audit / legal review