A six-tier public registration standard for deployed AI systems — and an honest accounting, tier by tier, of what can actually be verified today.

Why this exists

There is no standardized public way to identify what AI systems are in active use, who is responsible for them, what they're authorized to do, or how failures get caught. DAISLT proposes a registration ledger built on the same evidentiary discipline used in financial audits — applied to public safety rather than investment valuation.

Each tier requires documented evidence rather than self-attestation. The later tiers require recurring resubmission, not a one-time filing, so a registration reflects a system's current behavior rather than its launch-day claims.

The ledger, tier by tier (1 of 2)

Every question below is rated on what can be independently checked today, not what a submission merely claims.

01Identity & Source Registration
QuestionRequired documentConfidenceIndependent verifiability
Is the operating company or entity identified and legally registered?Business registration / incorporation filingVERIFIED-CAPABLECross-checkable now via Secretary of State or SEC registry.
Is the specific model name, version, and architecture disclosed?Technical / architecture summarySELF-ATTESTEDNo universal model registry exists yet to check against.
Is training data lineage disclosed (proprietary vs. licensed vs. public)?Data provenance statementSELF-ATTESTEDUnverifiable by an outside party without direct data access.
Is hosting location and legal jurisdiction disclosed?Infrastructure / hosting summarySELF-ATTESTEDPartially checkable via cloud-provider region APIs.
Is a public, reachable incident-reporting contact designated?Published contact / escalation pageVERIFIED-CAPABLEDirectly testable — send a real report, confirm a human responds.
02Function & Authority Declaration
QuestionRequired documentConfidenceIndependent verifiability
Is the system's task scope formally declared?Function / scope specificationSELF-ATTESTEDNo independent check currently exists.
Are decision-authority limits documented?Authority / permissions policySELF-ATTESTEDA policy existing doesn't confirm it's enforced.
Is a named human escalation contact designated with real authority?Escalation policyVERIFIED-CAPABLEDirectly testable — attempt to trigger it and confirm a response.
Is there a disclosed inventory of critical or irreversible unsupervised actions?Critical-action inventorySELF-ATTESTEDNo independent check currently exists.
03Reach & User Impact Disclosure
QuestionRequired documentConfidenceIndependent verifiability
Is the data/systems access map disclosed?Access and connections diagramSELF-ATTESTEDCorroborable via audit logs — not currently required.
Is the size and nature of the affected user population disclosed?Usage / analytics exportSELF-ATTESTEDExports can be edited before submission.
Is exposure to minors or other vulnerable populations disclosed?Population / use-case disclosureSELF-ATTESTEDHighest-stakes undisclosed-risk gap in the framework.
Are capability boundaries documented against a real benchmark?Benchmark results and methodologySELF-ATTESTEDInherits an industry-wide, self-reported benchmarking weakness.

The ledger, tier by tier (2 of 2)

04Context & Certainty Verification
QuestionRequired documentConfidenceIndependent verifiability
Has an independent scope audit been performed and dated?Audit reportSELF-ATTESTEDA report existing doesn't confirm the auditor was independent.
Is agent-to-agent interaction disclosed?Interoperability disclosureSELF-ATTESTEDNo independent check currently exists.
Is the real-world operational environment described?Deployment environment summarySELF-ATTESTEDPartially spot-checkable via direct observation.
Is a re-verification date committed and tracked over time?Renewal calendar / ledger entryUNBUILTRequires a persistent tracking database that doesn't exist yet.
05Alignment & Behavioral Evidence
QuestionRequired documentConfidenceIndependent verifiability
Has red-team testing been performed?Red-team reportSELF-ATTESTEDOnly verifiable if performed by a named independent lab.
Is an incident / near-miss log maintained and disclosed?Incident logSELF-ATTESTEDCross-checkable against public status-page history.
Are corrigibility / override test results disclosed?Override test reportSELF-ATTESTEDArguably the single most important untested claim in the ledger.
Is a deployment track record disclosed?Deployment history statementSELF-ATTESTEDTestimonials are the weakest form of evidence available.
06Safeguards & Renewal
QuestionRequired documentConfidenceIndependent verifiability
Is a kill-switch / containment mechanism documented?Containment architecture documentSELF-ATTESTEDA document doesn't confirm it's ever been tested live.
Is a detection / monitoring system described?Monitoring architecture documentSELF-ATTESTEDCorroborable via log-sampling audit — not currently done.
Is a named human escalation authority designated with real, tested authority?Escalation authority designationVERIFIED-CAPABLEDirectly testable via a live drill.
Is there a recurring re-certification cadence with dated proof of renewal?Renewal filing historyUNBUILTRequires the same ledger infrastructure flagged in Tier 4.

The honest self-score, as proposed today

4
of 25 — verified-capable now
19
of 25 — self-attested only
2
of 25 — infrastructure unbuilt

That is not a weakness to hide from anyone reviewing this — it is the argument for why a public verification layer needs to exist at all, and exactly the kind of disclosure a purely self-regulated industry has no incentive to make about itself.

Closing the gap

None of the following require inventing new institutions — only applying existing ones to AI registration.

  • Corporate registries (Secretary of State, SEC) — already answer Tier 1 identity questions today.
  • Auditor / CPA-firm directories — would close the auditor-independence gap in Tier 4 immediately.
  • Cloud-provider region and billing APIs — could corroborate hosting and access-map claims where providers cooperate.
  • Direct-contact and live-drill testing — the cheapest fix here; it verifies escalation claims simply by using them.
  • A persistent public ledger database — the one piece of infrastructure that doesn't exist anywhere yet, and the one this framework cannot function as a true ledger without.

Who builds and maintains that ledger — a federal body, an independent auditor network, or a requirement placed on industry itself — is a decision for lawmakers and the public, not for any single company proposing the framework.