Foundations

Four Attributes

The four properties an AI deployment needs to be defensible under regulation: auditable, sovereign, accountable, replayable.

What they are

Auditable — evidence generation happens continuously as the system runs, not retrospectively at quarter-end. Sovereign — the deployment remains within your declared jurisdiction by design, not by policy. Accountable — every consequential action carries a named signature with cryptographic proof. Replayable — any historical decision can be deterministically re-executed and verified.

Compliance profile
Four AttributesAUD28%SOV35%ACC42%RPL18%COVERAGE31%
  • AUDAuditable
    28%

    Evidence is generated continuously, not at quarter-end.

  • SOVSovereign
    35%

    Workloads stay in your declared jurisdiction by design.

  • ACCAccountable
    42%

    Every consequential action carries a named signature.

  • RPLReplayable
    18%

    Re-execute any historical request and verify the outcome.

All four attributes must be met. Three out of four fails the audit.

Why they matter

These four form the minimum requirements for regulatory compliance. A deployment with three out of four fails audit. AIOP makes all four attributes foundational — built into the architecture from day one, not retrofitted as compliance pressure mounts.

Where they live in AIOP

Each attribute maps to specific AIOP subsystems: Evidence Packs enable auditability, deployment modes enforce sovereignty, the Attest primitive ensures accountability, and the Replay engine guarantees replayability. They work together as an integrated whole, not as separate features.

Business Value

Pass regulatory audits consistently.

  • Reduce audit preparation effort substantially.
  • Avoid material fines and reputational damage from non-compliance.
  • Enable AI deployment in regulated sectors where competitors cannot operate.
Value for Teams
CIOs

Present to boards with documented proof, not promises.

Legal teams

Approve deployments faster with clear audit trails.

Operations teams

Replay and debug issues deterministically.

Compliance officers

Have the evidence regulators demand.