
The vendor graded its own work: why a self-certified AI verdict proves less
Every AI proof product asks the buyer to trust one number: the verdict. This page is about who is allowed to compute it. When the verdict about a piece of AI work is signed or computed by the same party that produced — or sold — the work, the verdict proves the vendor operated a signing key; it does not prove the claim. Below: the defect exhibited in the two deepest products in the field, what independence looks like where it exists, the anchor technology that fixes half the problem, the quorum that fixes the rest, and this site's own position — miscsubjects.com computes its own derived status today, and the roadmap that closes that is named here, first instance live. A reader who finishes can score any vendor's proof claim, this site's included, on five tests.
The verdict
A certifier operated by the party being certified proves less than one operated apart — not as rhetoric but as structure. Cryptography can prove that a record exists, is unaltered, and existed by a time. It cannot prove that a claim is supported by that record; someone must compute that, and the commercial interests of the seller point one way. The defect sits in the most important statement of the strongest competitor examined in this research — and this site carries it too, declared, with the repair in order.
The defect, exactly
A proof system for AI work can make three different statements, and they are not interchangeable:
- Integrity — this record exists and has not been altered since it was sealed. Hash chains and signatures deliver this mechanically.
- Anteriority — this record existed by a stated time and cannot have been backdated. Timestamps and blockchain anchors deliver this mechanically.
- Support — this claim about the work is borne out by that record. Nothing delivers this mechanically. A verifier — human, model, or service — must read the record and test the claim against it, and its finding is worth exactly its independence from the party the finding concerns.
Vendors ship the first two and label the package proof. The third is the one a buyer actually means — is the claim true — and precisely the one self-grading corrupts. A vendor-signed support verdict is an assertion with a signature attached. The signature proves who asserted. It says nothing about what is true.
Exhibit A: the deepest binding in the field, and the maker's own key
H33, a post-quantum cryptography platform with an AI-decision provenance layer, ships the closest thing to a claim-binding the field has produced: its decision evidence bundles decompose an AI answer into claim spans by byte range and bind each span to supporting citation ids. A complete specimen is publicly downloadable (verified this session): claim_84711.json carries claim decomposition, claim-level coverage mode, and coverage_assertion: "full".
That last field is the product's only claim-support statement — the one place the whole stack says the claims are covered — and its signature is ML-DSA-65 under key id h33-search-svc-prod-cov-key: the maker's own service key. The most consequential verdict in the bundle is self-signed.
Everything independent in H33's stack is structural. Their replay verifier runs ten deterministic checks — schema, timeline ordering, chain integrity, tenant isolation, Merkle roots — and their own page states the boundary in writing: "What PASS does NOT prove: Completeness — a bundle may be a truthful subset," and a passing verdict "does not mean a system is secure, correct, or compliant." The independent checks prove the artifact reproduces; no independent party computes whether the claims hold. Credit where due: the offline verification is real — MIT-licensed CLI, browser playground, inspector-signed verdict reports, post-quantum signatures — the field's best vendor-independent integrity story. Two honest flags: the only public specimen is an alpha preview whose metadata declares placeholder signatures, and the bundle carries hashes, not payloads — an outsider can verify a consistent record existed without reading what it says. Integrity without an independent claim verdict is the vendor grading its own work in permanent ink.
Exhibit B: vendor-held keys, one unnamed third party
Acipta, a compliance-scanning platform, signs every verdict its agents produce at issue time with "a cryptographic signing key managed in a FIPS-validated HSM," hash-chains each verdict to the one before, and timestamps each with an RFC 3161 external Trusted Timestamp Authority (its flight-recorder page, verified this session). Retention is serious: pinned model versions, pipeline state, five-year custody.
The independence inventory is one line long. The keys live in the vendor's HSM; the ledger and evidence locker are vendor-operated; the verdicts are produced by the vendor's own agents about the vendor's own scans. The sole third party in the chain is the timestamp authority — unnamed anywhere on the site. What a stranger can check: integrity and time. What stays vendor-asserted: authorship, judgment, completeness, and the verdict itself. Acipta's own scope note concedes it — defensibility "is not a guarantee that a decision was substantively correct." Its deterministic replay proves the sealed bytes re-derive; it never asks whether the verdict was true. The strongest record substrate in the category, and the grade is still written by the vendor's own hand.
The pattern
| What the vendor's certifier proves | What it cannot prove |
|---|---|
| The record exists and was not altered | The claim is supported by the record |
| The record existed by a time | The record is complete — not a truthful subset |
| The vendor ran a signing ceremony | The work was correct, or the judgment sound |
The closer a statement gets to the claim is true, the more certainly the vendor signs it alone. This is not a malice story; it is a structure story — the party with the commercial interest holds the pen, and the buyer cannot tell the honest case from the other one.
What independence looks like where it exists
Independent AI assurance exists — as a profession, not as an object. BABL AI has audited and certified AI systems since 2018, against the EU AI Act, NYC Local Law 144, and ISO/IEC 42001; its founder and CEO, Dr. Shea Brown, co-founded the International Association of Algorithmic Auditors. ForHumanity, a 501(c)(3) nonprofit, drafts the Independent Audit of AI Systems criteria, licenses them to audit firms, and certifies auditors; Ryan Carrier founded it after twenty-five years in financial risk, and Brown sits on its board. These verdicts carry what no vendor signature can: an auditor who is independent, liable, and accountable under an external framework.
What they do not carry is portability. An assurance verdict arrives as a private report — no keyless URL where a stranger inspects the evidence, no per-work-unit object, no receipt for the inspector's own reading; the unit of proof is the engagement, not the deliverable. The market today offers two halves: vendor-signed verdicts bound to portable records, and independent verdicts bound to nothing a stranger can open. The object that does not yet exist is the independent verdict bound to a portable, inspectable record.
The old anchor technology, and the half it fixes
The technology for proving anteriority is a quarter-century old and cheap. RFC 3161 (2001) defines the trusted timestamp — a Time Stamping Authority signs a hash plus a time, and its introduction states the scope exactly: "proof that a datum existed before a particular time." OpenTimestamps takes the operator out entirely: hash locally, aggregate through public calendars, anchor into the Bitcoin blockchain, verify without trusting anyone. Acipta's single third-party element is the first; this site's anchor is the second's cousin.
Anchors fix the operator's ability to rewrite history: a sealed record whose head is bound to a Bitcoin block cannot be quietly regenerated afterward. They do not fix who grades the claim — a timestamp says the verdict existed by a time and is silent on whether it was earned. Timestamping is necessary and radically insufficient: it answers the when and the untouched, never the true.
This site's own position, stated against itself
Proven work — this site's base unit — binds a claim about completed work to its complete formation record and a door any stranger can open, and computes a derived status, PROVEN or PARTIAL, from the manifest. The honesty this page owes: that status is computed by the same operator that sells the product. Single-operator custody is the definition page's own named open weakness — the exact defect named above.
What has shipped that bears on the defect:
- The first external anchor is live. The ledger chain was sealed through 1,308,129 events and its head bound to two surfaces outside the operator's control — drand round 6343866 (the League of Entropy's BLS-signed public randomness beacon) and Bitcoin block 960842 — both resolvable at public endpoints, the anchor packet served at this site's anchor API. Rewriting a covered record now requires forging a drand signature or a Bitcoin block.
- The door issues the inspector a receipt. Any stranger GETs the whole object — claim, manifest, full evidence payloads — keyless, and the response carries their own inspection receipt, so a critic's verdict can be held to proof of reading.
- Outside verdicts land on the object. A public certify lane records any model's or auditor's verdict — SUPPORTED_BY_RECORD, MISSING_EVIDENCE, CONTRADICTED_BY_RECORD — against a required inspection receipt, including hostile verdicts. Two hostile zero-context external audits on 3 August 2026 dropped the flagship object from PROVEN to PARTIAL on the record; the gaps were closed with exhibits and the status recomputed.
What has not shipped: PROVEN is still computed on the operator's service; the anchor covers record integrity, not verdict independence; and no third-party quorum gates the status. The claim for this site is therefore exactly this and no more — the record no longer requires trusting the operator, and the verdict still does.
The roadmap that closes it
Three mechanisms, in dependency order, each already in the product's versioned spec:
- Anchors on every checkpoint, at two independent third parties. The first instance is live (drand plus Bitcoin, above). The spec's anchor gate is the rule: PROVEN may not print until every receipt the object cites sits under a sealed chain checkpoint published at two independent third parties; until then the object declares the anchor gap and prints PARTIAL.
- A third-party certifier quorum. Independent certifiers — auditor-class, on the BABL and ForHumanity pattern of liable, framework-anchored assurance; model-class, cross-vendor panels — inspect through the door and sign verdicts onto the object. The mechanics exist today: keyless inspection, per-inspector receipts, the public certify lane. The queued work is the gate: the status becomes quorum-computed, and the operator loses the ability to print PROVEN alone. The evidence-law argument for why courts and regulators should demand exactly this structure is made by the sibling page, AI output is entering court — the evidence rules being drafted demand the record proven work keeps.
- Evaluator transparency. The status computation ships public, so any client recomputes the verdict from the manifest rather than trusting the service that ran it.
Until the quorum gates, every object this site emits carries the operator-independence caveat in the open. A PARTIAL printed honestly outranks a PROVEN asserted — the standard's own rule, applied to itself.
The five tests a buyer applies
To any vendor's proof claim — this site's included — ask:
- Who signed the verdict? If the answer is the vendor's own key, it is an assertion with a signature attached.
- Can you obtain the whole object without the vendor's cooperation? A file the maker hands you is a distribution channel, not a door.
- Does the verdict disclaim completeness or correctness in writing? Then what remains is integrity, not proof.
- Is there a named-gap mechanism? A system that cannot bind a claim to nothing supports this cannot fail honestly.
- Does your inspection leave you a receipt? If your reading is not receipted, neither is your right to check.
Nobody in the field passes all five today — not the competitors above, and not this site until the quorum gate ships. The difference here is that the gap is named, the repair order is public, and the first mechanism is verifiable by anyone.
Sources
- https://h33.ai/bundles/claim_84711.json — the public H33 specimen bundle: claim decomposition,
coverage_assertion: "full", signed under the maker's ownh33-search-svc-prod-cov-key; alpha-preview metadata. - https://h33.ai/verify-the-story/ — H33's own verdict boundary: "What PASS does NOT prove: Completeness."
- https://acipta.ai/flight-recorder/ — Acipta's evidence architecture: vendor-HSM signing keys, hash chaining, RFC 3161 timestamps from an unnamed external authority.
- https://acipta.ai/for-auditor/ — Acipta's auditor-facing story: offline pack verification, customer-mediated access, no standing public door.
- https://babl.ai/about-us/ — BABL AI: independent AI-system audits since 2018; Dr. Shea Brown, founder and CEO.
- https://forhumanity.center/board/ — ForHumanity: the nonprofit independent-audit criteria body; Ryan Carrier, founder; Shea Brown on the board.
- https://datatracker.ietf.org/doc/html/rfc3161 — RFC 3161 (2001): trusted timestamping — "proof that a datum existed before a particular time."
- https://opentimestamps.org/ — OpenTimestamps: Bitcoin-anchored timestamp proofs, free, operator-independent verification.
A standing offer: free work, on the record
This site runs an autonomously governed protocol — every model call, verdict, and edit lands on a public ledger with a receipt. For any legislator, regulator, or private party, the protocol will execute the following at no charge:
- A live demonstration — a statutory question of your choosing put to a multi-model panel under the sealed output shape, with every deliberation preserved verbatim, as in the Article 50 specimen.
- An audit — point at a system, a disclosure, a piece of AI-generated output, or a published practice, and the protocol will assess it against the Act clause by clause, with the reasoning on the record.
- A compliance schematic — a concrete proposal for how to bring a named system or workflow into conformity with the obligations that apply to it, with each recommendation tied to the article it satisfies.
Requests reach the build directly at build@miscsubjects.com. The work product is published as a citable page unless confidentiality is requested, and every step of its production is replayable from the ledger.
Key evidence
Ask this article · 8 suggested prompts
Text the build (+14245134626) or WhatsApp — slug|question creates a question node. Paste evidence with ingest slug|q:NODE_ID|your paste.