
A six-tier public registration standard for deployed AI systems — and an honest accounting, tier by tier, of what can actually be verified today.
Why this exists
There is no standardized public way to identify what AI systems are in active use, who is responsible for them, what they're authorized to do, or how failures get caught. DAISLT proposes a registration ledger built on the same evidentiary discipline used in financial audits — applied to public safety rather than investment valuation.
Each tier requires documented evidence rather than self-attestation. The later tiers require recurring resubmission, not a one-time filing, so a registration reflects a system's current behavior rather than its launch-day claims.
The ledger, tier by tier (1 of 2)
Every question below is rated on what can be independently checked today, not what a submission merely claims.
| Question | Required document | Confidence | Independent verifiability |
|---|---|---|---|
| Is the operating company or entity identified and legally registered? | Business registration / incorporation filing | VERIFIED-CAPABLE | Cross-checkable now via Secretary of State or SEC registry. |
| Is the specific model name, version, and architecture disclosed? | Technical / architecture summary | SELF-ATTESTED | No universal model registry exists yet to check against. |
| Is training data lineage disclosed (proprietary vs. licensed vs. public)? | Data provenance statement | SELF-ATTESTED | Unverifiable by an outside party without direct data access. |
| Is hosting location and legal jurisdiction disclosed? | Infrastructure / hosting summary | SELF-ATTESTED | Partially checkable via cloud-provider region APIs. |
| Is a public, reachable incident-reporting contact designated? | Published contact / escalation page | VERIFIED-CAPABLE | Directly testable — send a real report, confirm a human responds. |
| Question | Required document | Confidence | Independent verifiability |
|---|---|---|---|
| Is the system's task scope formally declared? | Function / scope specification | SELF-ATTESTED | No independent check currently exists. |
| Are decision-authority limits documented? | Authority / permissions policy | SELF-ATTESTED | A policy existing doesn't confirm it's enforced. |
| Is a named human escalation contact designated with real authority? | Escalation policy | VERIFIED-CAPABLE | Directly testable — attempt to trigger it and confirm a response. |
| Is there a disclosed inventory of critical or irreversible unsupervised actions? | Critical-action inventory | SELF-ATTESTED | No independent check currently exists. |
| Question | Required document | Confidence | Independent verifiability |
|---|---|---|---|
| Is the data/systems access map disclosed? | Access and connections diagram | SELF-ATTESTED | Corroborable via audit logs — not currently required. |
| Is the size and nature of the affected user population disclosed? | Usage / analytics export | SELF-ATTESTED | Exports can be edited before submission. |
| Is exposure to minors or other vulnerable populations disclosed? | Population / use-case disclosure | SELF-ATTESTED | Highest-stakes undisclosed-risk gap in the framework. |
| Are capability boundaries documented against a real benchmark? | Benchmark results and methodology | SELF-ATTESTED | Inherits an industry-wide, self-reported benchmarking weakness. |
The ledger, tier by tier (2 of 2)
| Question | Required document | Confidence | Independent verifiability |
|---|---|---|---|
| Has an independent scope audit been performed and dated? | Audit report | SELF-ATTESTED | A report existing doesn't confirm the auditor was independent. |
| Is agent-to-agent interaction disclosed? | Interoperability disclosure | SELF-ATTESTED | No independent check currently exists. |
| Is the real-world operational environment described? | Deployment environment summary | SELF-ATTESTED | Partially spot-checkable via direct observation. |
| Is a re-verification date committed and tracked over time? | Renewal calendar / ledger entry | UNBUILT | Requires a persistent tracking database that doesn't exist yet. |
| Question | Required document | Confidence | Independent verifiability |
|---|---|---|---|
| Has red-team testing been performed? | Red-team report | SELF-ATTESTED | Only verifiable if performed by a named independent lab. |
| Is an incident / near-miss log maintained and disclosed? | Incident log | SELF-ATTESTED | Cross-checkable against public status-page history. |
| Are corrigibility / override test results disclosed? | Override test report | SELF-ATTESTED | Arguably the single most important untested claim in the ledger. |
| Is a deployment track record disclosed? | Deployment history statement | SELF-ATTESTED | Testimonials are the weakest form of evidence available. |
| Question | Required document | Confidence | Independent verifiability |
|---|---|---|---|
| Is a kill-switch / containment mechanism documented? | Containment architecture document | SELF-ATTESTED | A document doesn't confirm it's ever been tested live. |
| Is a detection / monitoring system described? | Monitoring architecture document | SELF-ATTESTED | Corroborable via log-sampling audit — not currently done. |
| Is a named human escalation authority designated with real, tested authority? | Escalation authority designation | VERIFIED-CAPABLE | Directly testable via a live drill. |
| Is there a recurring re-certification cadence with dated proof of renewal? | Renewal filing history | UNBUILT | Requires the same ledger infrastructure flagged in Tier 4. |
The honest self-score, as proposed today
That is not a weakness to hide from anyone reviewing this — it is the argument for why a public verification layer needs to exist at all, and exactly the kind of disclosure a purely self-regulated industry has no incentive to make about itself.
Closing the gap
None of the following require inventing new institutions — only applying existing ones to AI registration.
- Corporate registries (Secretary of State, SEC) — already answer Tier 1 identity questions today.
- Auditor / CPA-firm directories — would close the auditor-independence gap in Tier 4 immediately.
- Cloud-provider region and billing APIs — could corroborate hosting and access-map claims where providers cooperate.
- Direct-contact and live-drill testing — the cheapest fix here; it verifies escalation claims simply by using them.
- A persistent public ledger database — the one piece of infrastructure that doesn't exist anywhere yet, and the one this framework cannot function as a true ledger without.
Who builds and maintains that ledger — a federal body, an independent auditor network, or a requirement placed on industry itself — is a decision for lawmakers and the public, not for any single company proposing the framework.