<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Shea Brown]]></title><description><![CDATA[Shea Brown is the CEO and Founder of BABL AI, an AI assurance firm focused on bias auditing and AI governance.]]></description><link>https://sheabrownphd.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!O-OX!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F910a0800-d4ad-4e3f-af41-436e16ab3fa8_858x858.jpeg</url><title>Shea Brown</title><link>https://sheabrownphd.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 17 Jun 2026 07:25:18 GMT</lastBuildDate><atom:link href="https://sheabrownphd.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Shea Brown]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[sheabrownphd@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[sheabrownphd@substack.com]]></itunes:email><itunes:name><![CDATA[Shea Brown]]></itunes:name></itunes:owner><itunes:author><![CDATA[Shea Brown]]></itunes:author><googleplay:owner><![CDATA[sheabrownphd@substack.com]]></googleplay:owner><googleplay:email><![CDATA[sheabrownphd@substack.com]]></googleplay:email><googleplay:author><![CDATA[Shea Brown]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[We Already Have a Framework for AI Assurance... What We Need is the Right Content ]]></title><description><![CDATA[How ISAE 3000 already provides the structural framework for technical AI assurance, what the EU's Digital Services Act demonstrated, and where the AI-specific gaps actually are.]]></description><link>https://sheabrownphd.substack.com/p/we-already-have-a-framework-for-ai</link><guid isPermaLink="false">https://sheabrownphd.substack.com/p/we-already-have-a-framework-for-ai</guid><dc:creator><![CDATA[Shea Brown]]></dc:creator><pubDate>Wed, 29 Apr 2026 19:48:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yQmG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yQmG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yQmG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!yQmG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!yQmG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!yQmG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yQmG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1037406,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://sheabrownphd.substack.com/i/194585305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yQmG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!yQmG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!yQmG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!yQmG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc9721d5-0a1a-42c0-8f45-8db61e798e35_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There is a lot of serious work happening right now on AI audit and assurance. The UK government has <a href="https://www.gov.uk/government/publications/trusted-third-party-ai-assurance-roadmap/trusted-third-party-ai-assurance-roadmap">published</a> its <em>Trusted Third-Party AI Assurance Roadmap</em> and is funding pilots through DSIT. Singapore&#8217;s <a href="https://aiverifyfoundation.sg/">AI Verify Foundation</a> has been operational for several years and continues to evolve. The Partnership on AI runs a dedicated <em><a href="https://partnershiponai.org/workstream/strengthening-the-ai-assurance-ecosystem/">Strengthening the AI Assurance Ecosystem</a></em> workstream. The Ada Lovelace Institute is <a href="https://www.adalovelaceinstitute.org/report/going-pro/">pressing</a> on who the professional AI assurance community is actually supposed to be, and the International Association of Algorithmic Auditors (<a href="https://www.iaaa-algorithmicauditors.org/">IAAA</a>) has been answering. <a href="https://forhumanity.center/independent-audit-of-ai-systems/">ForHumanity</a> continues to develop audit schemes for compliance with a number of AI regulations. US state legislatures, most recently <a href="https://lis.virginia.gov/bill-details/20261/SB384">Virginia</a>, are researching what it would take for an Independent Verification Organization (<a href="https://ivo.fathom.org/">IVO</a>) to operate credibly. Academic work on testing and auditing of AI systems is active and growing. I spend a lot of time in these conversations, and I admire a lot of what is being produced. </p><p>Two observations about that conversation before I make my actual argument. First, what most of these efforts are really asking about is not management system auditing, the &#8220;do you have a governance process in place&#8221; exercise that I<a href="https://www.iso.org/standard/42001">SO/IEC 42001</a> is designed for. Those have their place and are incredibly valuable. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://sheabrownphd.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><blockquote><p>What the conversation is really about is <em>technical, system-level assurance</em>: independent attestation that a particular AI system, in a particular deployment context, actually behaves the way someone claims it does.</p></blockquote><p>That it is reasonably safe, secure, fair, accurate, and governed in the ways the deployer says it is. Second, it is not exclusively about TEVV either, though some of it is. Testing, evaluation, verification, and validation (TEVV) is what gets done to the system, and I&#8217;ve written <a href="https://algorithmicbiaslab.substack.com/p/how-do-you-actually-test-an-ai-system">elsewhere</a> about how we approach the TEVV side in practice. Assurance is the distinct layer above TEVV, where an independent practitioner applies professional judgment to the evidence TEVV produces and issues an opinion that someone else can reasonably rely on (this is not always true, but more about direct vs attestation engagements later).</p><p>I want to make a point about that assurance layer specifically, because it is where I start to get nervous. What worries me is when efforts begin to redefine the <em>profession</em> of assurance itself, things like how independence should be structured or what makes an assurance report credible. There is already a profession that has been answering those questions for decades, with a mature international standards infrastructure behind it. In particular, <a href="https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or">ISAE 3000</a>, the International Auditing and Assurance Standards Board&#8217;s standard for assurance engagements on subject matters other than historical financial information, is the instrument that already addresses much of what the AI field keeps trying to re-derive (Note: I could just as well be discussing the AICPA's substantively equivalent <a href="https://www.aicpa-cima.com/resources/download/aicpa-ssaes-currently-effective">US attestation standards</a>). The genuine hard work is elsewhere, in the <em>content</em> of what we assess AI systems against and some of the nuances of how, and I&#8217;ll come back to that. Many of us are in the thick of it, and it deserves the field&#8217;s attention. But the professional scaffolding around how independent assurance is delivered does not need to be rebuilt. It needs to be read in the context of this new object of evaluation.</p><h2>Why Financial Auditing is an Okay Analogy</h2><p>When people resist the financial auditing analogy, the objection is usually something like: &#8220;AI systems are dynamic and complex in ways that balance sheets aren&#8217;t.&#8221; That&#8217;s true as far as it goes. But the deeper logic of what a financial audit actually does has nothing to do with the specific content being audited. It has to do with the relationship between a claim, evidence, and an independent opinion.</p><p>When a company publishes audited financial statements, what the audit provides is not certainty. It provides a structured, evidence-based opinion from an independent professional who has applied agreed-upon criteria against the available evidence. The audit is credible because the professional is accountable to ethical standards, independence requirements, and a methodology that is visible and challengeable.</p><p>This is exactly what AI accountability at the technical system level is missing right now. The field is full of claims: vendors describing their systems as &#8220;fair,&#8221; &#8220;transparent,&#8221; or &#8220;safe,&#8221; with no consistent mechanism for an independent party to evaluate those claims against evidence and issue a defensible opinion. We have a credibility gap, and it is a governance gap. Professional assurance standards exist precisely to close this kind of gap. They&#8217;re not a perfect match, however, and they&#8217;re not sufficient without more work, but they&#8217;re a good base to work from.</p><h2>What ISAE 3000 Actually Is</h2><p>ISAE 3000 (Revised) is the International Auditing and Assurance Standards Board&#8217;s standard for assurance engagements on subject matters other than historical financial information. That phrasing, &#8220;other than historical financial information,&#8221; is important. It is the standard designed for situations where the thing being examined does not fit neatly into traditional financial audit territory. AI systems qualify almost by definition.</p><p>The standard establishes the core structure of any legitimate assurance engagement, and it is worth understanding this structure precisely because it has more moving parts than most people assume (Figure 1: adapted from ISAE 3000).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w6F9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w6F9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 424w, https://substackcdn.com/image/fetch/$s_!w6F9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 848w, https://substackcdn.com/image/fetch/$s_!w6F9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 1272w, https://substackcdn.com/image/fetch/$s_!w6F9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w6F9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png" width="724.859375" height="446.0673076923077" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:896,&quot;width&quot;:1456,&quot;resizeWidth&quot;:724.859375,&quot;bytes&quot;:965181,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://sheabrownphd.substack.com/i/194585305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w6F9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 424w, https://substackcdn.com/image/fetch/$s_!w6F9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 848w, https://substackcdn.com/image/fetch/$s_!w6F9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 1272w, https://substackcdn.com/image/fetch/$s_!w6F9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40048a1e-45f4-4018-b02c-786f42ef7f82_5218x3212.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>There are multiple parties with distinct roles.</strong> The standard identifies five: the responsible party (who owns the underlying subject matter), the measurer or evaluator (who measures or evaluates that subject matter against criteria, and who may be the same as the responsible party or a separate technical expert), the engaging party (who commissions the engagement and may be a regulator, the responsible party itself, or a third party), the practitioner (who provides the independent assurance), and the intended users (who rely on the practitioner&#8217;s report). In AI auditing, these roles do not always map neatly onto a single organization. An AI developer might be the responsible party while a specialized technical firm serves as the measurer or evaluator, and a regulator or enterprise client serves as both engaging party and intended user. Getting these distinctions right matters for how audit mandates are written and how the field structures itself.</p><p><strong>There is a subject matter.</strong> In a financial audit, the subject matter is the financial position of a company. In an AI assurance engagement, the subject matter might be a hiring algorithm&#8217;s decision outputs, a risk scoring model&#8217;s behavior across demographic groups, or a generative system&#8217;s adherence to a defined content policy. It may also be process-related, such as whether and to what extent an orginization as conducted a risk assessment or follows a quality management system. The subject matter is what is being examined.</p><p><strong>There are applicable criteria.</strong> Claims need to be evaluated against something. ISAE 3000 requires that the criteria used be suitable, meaning they are relevant, complete, reliable, neutral, and understandable. This matters enormously for AI auditing because it forces specificity. &#8220;The system is fair&#8221; is not a claim that can be audited. &#8220;The system produces demographically balanced selection rates within a defined tolerance, as measured against the criteria specified in [standard X]&#8221; can be.</p><p>The standard draws a further distinction that is practically important here: criteria can be established (issued by recognized bodies and presumed suitable) or specifically developed for the particular engagement. In financial and sustainability contexts, established criteria like IFRS or GRI are mature and widely accepted. </p><blockquote><p>In AI auditing today, most criteria are still in the specifically developed category, which means the practitioner carries more burden in assessing whether the criteria are, in fact, suitable. This is one of the real areas of methodological development that the field needs to address.</p></blockquote><p><strong>There is a practitioner issuing a conclusion.</strong> ISAE 3000 engagements are conducted by professional practitioners who are required to be independent of the responsible party, competent to perform the engagement, and bound by ethical requirements, including an attitude of professional skepticism throughout. The standard also sits within a broader professional ecosystem: firm-level quality management requirements under <a href="https://www.iaasb.org/publications/international-standard-quality-management-isqm-1-quality-management-firms-perform-audits-or-reviews">ISQM 1</a> govern how assurance firms operate, and professional ethical standards govern individual practitioners. This is not a self-assessment or a vendor questionnaire. It is an independent professional, operating within a regulated professional infrastructure (ideally), forming an opinion based on sufficient appropriate evidence.</p><p>The standard also distinguishes between two levels of assurance (reasonable and limited) and two engagement structures (attestation and direct), which combine to give four possible engagement types. Reasonable assurance produces a positive-form conclusion conveying the practitioner&#8217;s opinion; limited assurance produces a negative-form conclusion conveying whether anything has come to the practitioner&#8217;s attention to suggest the subject matter information is materially misstated. Both attestation engagements (where another party measures and evaluates the subject matter and the practitioner assures the result) and direct engagements (where the practitioner performs the measurement and evaluation themselves) are available depending on the circumstances. These distinctions matter at the implementation level, but the more important point for the field right now is simply that the infrastructure for making them already exists and does not need to be reinvented.</p><h2>It Has Already Worked: The DSA as Proof of Concept</h2><p>This is not a theoretical argument. We have already seen ISAE 3000 applied to algorithmic accountability at regulatory scale, and the experience is instructive.</p><p>The European Union&#8217;s <a href="https://digital-strategy.ec.europa.eu/en/policies/digital-services-act">Digital Services Act</a> requires independent audits of very large online platforms covering, among other things, algorithmic systems used for content recommendation and moderation. When the European Commission developed the audit methodology for those requirements, it explicitly benchmarked to ISAE 3000. It <a href="https://digital-strategy.ec.europa.eu/en/news/delegated-act-independent-audits-under-digital-services-act">specified</a> reasonable assurance as the required level, and referenced ISQM 1 for firm-level quality management. The regulatory design, in other words, reached for the existing professional assurance infrastructure rather than constructing something new.</p><p><a href="https://babl.ai">BABL AI</a> was part of the <a href="https://github.com/algorithmicbiaslab/public-resources/blob/main/policy/eu/eu-comm_dsa_2023-11-20.pdf">advocacy effort</a> that helped push the Commission in that direction, and I think the outcome vindicates the approach. The framework held, the engagement structure was coherent, and the reporting requirements were intelligible to practitioners. </p><p>What the DSA experience also revealed, however, is where the genuine difficulty lies. Most of the DSA audit requirements were procedural in nature: did the platform have a risk management process, did it document its systems adequately, did it follow its stated policies. These are not trivial questions, but they are familiar territory for assurance practitioners. The Big Four firms that participated in early DSA engagements were capable of handling the procedural layer. Where the field struggled, and where there was <a href="https://kpmg.com/nl/en/home/insights/2025/03/kpmgs-2024-digital-services-act-dsa-audit-reports-benchmark.html">broad acknowledgment of unreadiness</a>, was at the technical level. The applicable criteria for assessing the actual behavior of algorithmic systems, as opposed to the processes around them, were largely absent. What existed had to be constructed from the law itself, plus bespoke sufficiency criteria developed internally by each engaging firm. That is not a failure of the assurance framework. It is a failure of criteria development. The container was ready; the contents were not.</p><p>This is the lesson I want the AI assurance community to sit with. The DSA demonstrated that the assurance infrastructure is deployable for AI accountability purposes. It also demonstrated, clearly and at scale, that suitable criteria for technical AI claims are the bottleneck.</p><p>The same lesson is now arriving in US state law. In April 2026, the Virginia General Assembly enacted Chapter 426 (S 384), directing the <a href="https://dls.virginia.gov/commissions/jcots/jcots.htm">Joint Commission on Technology and Science</a> (JCOTS) to evaluate the feasibility of a framework for &#8220;any person or entity seeking to act as an independent verification organization that assesses artificial intelligence models or applications.&#8221; </p><blockquote><p>JCOTS is required to consider, among other things, the availability of identifiable and measurable metrics for risk, the existing standards for technical and operational mitigation, the current methodologies used to evaluate the efficacy of those mitigation requirements, and the practices employed in other states. </p></blockquote><p>A report is due by November 1, 2026, and similar Independent Verification Organization proposals are under discussion in several other states. The questions JCOTS has been asked to answer map almost one-for-one onto the structure ISAE 3000 already provides: who is competent to verify, against what criteria, with what evidence, and how it is reported. The legislative scoping work would benefit enormously from beginning with that existing answer rather than constructing a parallel one.</p><h2>What About ISO 42001?</h2><p>A reasonable counterpoint to everything above is: why not just use ISO 42001, the AI management system standard, and the certification and accreditation infrastructure that has been built around it? It is a legitimate question, and the answer is not that ISO 42001 is wrong. It is that it is answering a different question.</p><p>ISO 42001 is a management system standard. Like ISO 27001 for information security, it specifies requirements for how an organization manages AI-related risks: governance structures, policies, risk management processes, and documentation practices. Certification to ISO 42001 tells you that an organization has implemented a conforming management system. It does not tell you how the AI system itself performs against technical claims about its behavior, fairness, safety, or accuracy.</p><p>This distinction matters because the most consequential questions in AI accountability are system-level, not process-level. </p><blockquote><p>An organization can have excellent AI governance documentation and still deploy a hiring model that produces biased outputs. A management system audit will not catch that. A technical assurance engagement, conducted against suitable criteria for the specific system and its specific claims, might.</p></blockquote><p>The broader conformity assessment landscape, ISO, IEC, IEEE, CEN, CENELEC, is actively developing standards that will eventually address technical AI system claims. That work is important, and the field needs it. But it will take time, and even when those standards mature, there will remain a category of consequential, specific, and often novel technical claims that require flexible assurance approaches rather than fixed conformity assessments. Complex AI systems are not static artifacts. Their behavior is stochastic, context-dependent, and subject to distributional shift. Assurance approaches for them need to reflect that complexity. ISAE 3000, precisely because it is a principles-based framework rather than a checklist, is better suited to that challenge than a conformity assessment regime alone.</p><p>It is also worth noting that a number of promising efforts are emerging to build criteria and attestation schemes specifically for AI systems, and the most defensible of these are, deliberately or not, designing themselves to live inside the professional assurance paradigm: evaluation of a defined system against published criteria, an independent assessor, and a structured report that functions as the deliverable. That convergence is a feature. The more these initiatives align with the vocabulary and obligations of ISAE 3000 (suitability of criteria, independence of the practitioner, sufficient appropriate evidence, material misstatement), the more portable and credible their outputs will be across jurisdictions and use cases.</p><blockquote><p>The right answer for the field is not ISO 42001 or ISAE 3000. It is both, serving different but complementary functions: management system certification for organizational governance, and professional assurance engagements for system-level technical claims.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!372c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!372c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 424w, https://substackcdn.com/image/fetch/$s_!372c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 848w, https://substackcdn.com/image/fetch/$s_!372c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 1272w, https://substackcdn.com/image/fetch/$s_!372c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!372c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png" width="202" height="163.84444444444443" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:365,&quot;width&quot;:450,&quot;resizeWidth&quot;:202,&quot;bytes&quot;:187658,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://sheabrownphd.substack.com/i/194585305?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!372c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 424w, https://substackcdn.com/image/fetch/$s_!372c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 848w, https://substackcdn.com/image/fetch/$s_!372c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 1272w, https://substackcdn.com/image/fetch/$s_!372c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee70495-8451-4535-9bde-c5ae5d1270cb_450x365.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Where the AI-Specific Gaps Are in ISAE 3000</h2><p>The structural framework that ISAE 3000 provides leaves three substantive gaps when applied to AI systems.</p><p><strong>Suitable criteria for technical AI claims.</strong> This is the central problem. The professional assurance framework provides the structure for evaluating claims against criteria, but it cannot supply the criteria themselves. Bias metrics vary by use case, community, and legal context. Safety criteria for generative systems are not yet standardized. Performance benchmarks differ across domains. Until there is a more developed body of established criteria for AI system behavior, practitioners will continue to rely on specifically developed criteria, and the burden of assessing their suitability will fall disproportionately on individual engagements.</p><p><strong>Applying assurance concepts to stochastic systems.</strong> The assurance framework was developed for subject matters that, while complex, are generally deterministic. Financial statements say what they say. An AI system&#8217;s outputs vary by run, by input distribution, by deployment context. Concepts like sufficient appropriate evidence, materiality, and measurement uncertainty need interpretive guidance for this setting. How many inferences constitute a sufficient sample? How should the practitioner treat variance in outputs across demographic groups when that variance itself is the subject matter? How does the inherent uncertainty of probabilistic systems interact with the notion of material misstatement? These are not unanswerable questions, but they do not yet have settled answers, and the field needs to develop them.</p><p><strong>Practitioner competency in the technical domain.</strong> The assurance skills required by ISAE 3000, planning, evidence gathering, evaluation, professional skepticism, reporting, are well-understood and teachable. What is not yet well-understood is how to combine those skills with the technical expertise needed to evaluate AI systems at the level of their actual behavior. This is partly a curriculum problem and partly a structural one: the firms and practitioners best positioned to perform technical AI assurance are often not the ones with deep assurance training, and vice versa. The field needs to develop integrated competency frameworks that treat both as necessary rather than treating one as a substitute for the other. Early professionalization efforts are underway; the International Association of Algorithmic Auditors (IAAA), for example, is developing a code of conduct and training recognition pathway specifically for algorithmic auditors, and they deserve support from both the assurance profession and the AI community. BABL was an early mover in this space with our <a href="https://babl.ai/ai-and-algorithm-auditor-certificate-program/">AI &amp; Algorithm Auditor Certification</a>, but the field continues to grow (e.g., <a href="https://www.isaca.org/credentialing/aaia">AAIA by ISACA</a> and <a href="https://iapp.org/certify/aigp">AIGP by the IAPP</a>) as the need for trained professionals becomes clear. </p><p>None of this requires abandoning ISAE 3000. It requires extending it thoughtfully. The professional auditing world has done this before; environmental auditing, cybersecurity assurance, and sustainability reporting all required similar methodological development before they reached their current state. The path is recognizable, even if the terrain is harder.</p><h2>What the AI Assurance Field Should Be Working On</h2><p>A useful distinction is between two kinds of new work. The first kind is rebuilding the <em>infrastructure</em> of assurance from scratch: independence requirements, report structure, firm-level quality management, evidence requirements, opinion tiering, etc. These are all addressed, in detail, by the existing assurance ecosystem, and relitigating them without reference to what already exists wastes time and risks producing weaker frameworks than what we already have. The second kind is developing the <em>criteria and the technical methods</em> that the existing assurance infrastructure can be applied to. That work is essential. It is also where most of the productive activity in the field is now concentrated, and it deserves more support, not less.</p><p>The productive work, then, is specific.</p><p><strong>First, developing suitable criteria.</strong> This is the highest-leverage area. Criteria that meet the ISAE 3000 suitability requirements (relevant, complete, reliable, neutral, understandable) for the technical claims that matter most: system fairness, safety, robustness, accuracy, and transparency. This means investing in technical standards work, in empirical research on measurement validity, and in the legal and regulatory analysis needed to translate statutory requirements into auditable criteria. The DSA experience shows that the demand for this work is real and immediate. The supply is not there yet.</p><p><strong>Second, developing interpretive guidance for applying assurance concepts to AI-specific conditions.</strong> This includes guidance on how measurement uncertainty affects materiality determinations, clarity on sampling approaches for stochastic systems, and specifications on how the measurer or evaluator role should be structured when deep technical expertise is required to generate valid subject matter information. Guidance is also needed on what &#8220;sufficient appropriate&#8221; evidence looks like when the subject matter is a probabilistic model rather than a financial statement. This is the technical standards work that will make ISAE 3000 fully operational for AI, and it is work that requires collaboration between the assurance profession and the AI research and engineering community.</p><p><strong>Third, developing integrated practitioner competencies. </strong>Not reinventing assurance skills, which are well-established, but building the technical AI evaluation competencies that need to sit alongside them and defining how the two bodies of skill relate in practice. This includes competency frameworks for new credentialing, curriculum development for practitioners entering the field, and guidance on how firms should structure multidisciplinary engagement teams.</p><p>Encouragingly, much of this work is already underway, and the field benefits from naming it explicitly. In September 2025 the UK&#8217;s Department for Science, Innovation and Technology published its <em>Trusted Third-Party AI Assurance Roadmap</em>, committing &#163;11 million through an AI Assurance Innovation Fund and convening a stakeholder consortium tasked with laying the foundations for a future AI assurance profession, including a code of ethics and a skills framework. The Ada Lovelace Institute&#8217;s July 2025 work on professionalising AI assurance has argued that AI requires &#8220;independent evaluation, audit and assurance supported by a mature, professional field that is plural rather than in the hands of a few consultancies,&#8221; which is a description that maps directly onto the assurance-profession model. The Partnership on AI&#8217;s <em>Strengthening the AI Assurance Ecosystem</em> workstream and its 2026 governance priorities have placed assurance mechanisms and accountability infrastructure at the center of responsible adoption. These efforts are different from one another in scope and emphasis, but they are pointing in compatible directions, and the unifying language available to them is the assurance vocabulary that ISAE 3000 already provides.</p><p>These are tractable problems. They are hard, but they are the right kind of hard, and the cost of treating them as open when professional assurance has already resolved much of the structural layer is real: it slows the development of accountability infrastructure that the public is increasingly asking for.</p><h2>The Framework Is There</h2><p>ISAE 3000 is not a perfect fit for AI assurance. No existing framework is. But it is the best available foundation, it has already been deployed in a major regulatory context, and it answers the majority of the structural questions that the field keeps relitigating. </p><blockquote><p>The gaps that remain are real but specific: criteria development, interpretive guidance for AI-specific conditions, and integrated competency frameworks. Those are solvable problems, and solving them does not require starting from scratch.</p></blockquote><p>The harder challenge is cultural and institutional. It requires the AI policy community to engage seriously with a professional literature that most technologists have not read, and it requires the assurance profession to engage seriously with technical AI evaluation in ways that go beyond process auditing. Neither community has fully made that move yet. But the foundation for what we need is already there. The question is whether we will build on it.</p><div><hr></div><p><em>Shea Brown is the Founder &amp; CEO of BABL AI, an independent AI assurance firm conducting technical audits of AI systems under ISAE 3000 assurance standards. BABL AI is a founding cohort member of the US AI Safety Institute Consortium and the International Association of Algorithmic Auditors, and Shea is Fellow at ForHumanity.</em></p><p><em>Max Rizzuto is a technical AI auditor on the assurance team at BABL AI, as well as a researcher at The Algorithmic Bias Lab.  </em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://sheabrownphd.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Runtime Guardrails Are Only as Good as They Are Effective]]></title><description><![CDATA[Highlighting the importance of "behavioral" AI assurance]]></description><link>https://sheabrownphd.substack.com/p/runtime-guardrails-are-only-as-good</link><guid isPermaLink="false">https://sheabrownphd.substack.com/p/runtime-guardrails-are-only-as-good</guid><dc:creator><![CDATA[Shea Brown]]></dc:creator><pubDate>Sat, 25 Apr 2026 00:03:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hoIg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>There is a real and growing body of serious work on making AI agent deployments safer at runtime. I want to engage with that work honestly, because it matters, and because I think there is an important distinction buried inside it that is worth drawing out.</p><h2>What Does Runtime Assurance for AI Agents Actually Cover?</h2><p>When people talk about runtime assurance or runtime security for AI agents, they are talking about a collection of mechanisms that operate while an agent is executing. The landscape here is broad. Microsoft recently released an open-source <a href="https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/">Agent Governance Toolkit</a> that maps to all ten of OWASP&#8217;s agentic AI risk categories. <a href="https://www.paloaltonetworks.com/blog/network-security/secure-ai-agents-by-design-ai-runtime-security/">Palo Alto</a>, <a href="https://www.helpnetsecurity.com/2025/11/20/oligo-security-ai-spm-ai-dr/">Oligo</a>, and others have built runtime security platforms targeting AI-specific threats. NVIDIA&#8217;s <a href="https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2026/agentic-ai-evolution-and-the-security-claw">NemoClaw</a> introduces a policy enforcement layer beneath the agent runtime. Frameworks like <a href="https://a2as.org/">A2AS</a>, developed collaboratively by AWS, Google, Cisco, Meta, JPMorganChase, and others, propose structured approaches to context window integrity, prompt authentication, capability constraints, and behavior certification.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://sheabrownphd.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Research and development in this area is moving fast. Companies like <a href="https://lucidcomputing.ai/">Lucid Computing</a>, <a href="https://vcomp.eqtylab.io/">EQTY Lab</a>, and <a href="https://www.fortanix.com/blog/agentic-ai-with-verifiable-trust-security-sovereignty-for-ai-factories-and-enterprises">Fortanix</a> are building platforms that combine confidential computing infrastructure with behavioral policy enforcement, producing cryptographic receipts of governance compliance that can be verified by customers and regulators. The underlying technology is genuinely interesting: Lucid&#8217;s AI Passports, EQTY Lab&#8217;s AI Notary system, and Fortanix&#8217;s continuous CPU and GPU attestation all address real gaps in how AI deployments are monitored and evidenced. </p><p>On the research side, a <a href="https://arxiv.org/html/2603.05786v1">March 2026 paper from Sahara Labs AI</a> proposes &#8220;Proof-of-Guardrail,&#8221; a system that uses TEE attestation to cryptographically prove that a specific guardrail ran during inference, and the authors are candid about what their system does not provide: they note explicitly that guardrails can make errors and be jailbroken, and that their approach ensures the integrity of guardrail execution while the reliability of the guardrail itself remains an open question. A separate line of academic work, <a href="https://arxiv.org/html/2506.23706v1">Attestable Audits</a> out of Cambridge and Nokia Bell Labs, uses TEEs to run AI safety benchmarks and produce cryptographic proofs of the results, an approach that gets closer to pre-deployment evaluation but still certifies the execution of a benchmark rather than behavioral reliability across a real operational domain. </p><p>Meanwhile, the broader runtime guardrail space, including <a href="https://github.com/NVIDIA/NeMo-Guardrails">NeMo Guardrails</a>, <a href="https://www.guardrailsai.com/">Guardrails AI</a>, and <a href="https://aws.amazon.com/bedrock/guardrails/">Amazon Bedrock Guardrails</a>, focuses on LLM-based judges and rule classifiers to enforce policy at inference time. </p><p>These efforts address real problems. Logging and audit trails, identity and permission management, prompt injection defense, capability sandboxing, and cryptographic integrity verification of agent requests. Each of these categories closes genuine gaps that matter in production deployments, and the field is moving fast.</p><h2>Why Behavioral Guardrails Are the Hardest Part of Runtime AI Security</h2><p>Of all the mechanisms in the runtime assurance toolkit, the one I think deserves the most scrutiny is the behavioral guardrail (I&#8217;m biased because of our work at <a href="https://babl.ai">BABL AI</a>). Specifically: the use of rules, policies, or LLM-based judges to determine whether an agent&#8217;s behavior is acceptable at the moment it is acting.</p><p>This is also the mechanism that is most commonly marketed as &#8220;assurance,&#8221; in a way that I think deserves some precision.</p><p>Frameworks like A2AS define what they call &#8220;Codified Policies&#8221;; rules embedded into the agent&#8217;s context window that constrain its behavior. The example they give is readable and intuitive: <em>this app must not modify or send emails; emails labeled &#8220;Confidential&#8221; must not be processed.</em> When these policies are crisp, deterministic, and testable, they function more like access controls than behavioral guardrails. That is a reasonable thing to build.</p><p>But the further you move from deterministic rules toward natural language policies and LLM-based enforcement, the more you are relying on something that behaves probabilistically, not reliably. And that gap matters a great deal for anyone trying to make a defensible claim about system behavior.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hoIg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hoIg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!hoIg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!hoIg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!hoIg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hoIg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png" width="1254" height="1254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1254,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:352422,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://sheabrownphd.substack.com/i/195382321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hoIg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!hoIg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!hoIg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!hoIg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01b40c6-3f16-4239-9404-b8568f939180_1254x1254.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Can You Trust a Guardrail That Has Never Been Independently Tested?</h2><p>A2AS itself acknowledges this. In its known limitations section, the framework flags &#8220;security reasoning drift&#8221;, the risk that model reasoning variations cause misinterpretation of security instructions, and &#8220;security misconfiguration risk,&#8221; noting that poorly written policies create false security. These are not edge cases. They are the central challenge of LLM-based policy enforcement.</p><blockquote><p><em>"Misconfigured certificates or poorly written policies create false security."</em> &#8212; A2AS Framework, v1.0</p></blockquote><p>The research literature is similarly honest. Published work has documented that classification-based guardrails can be bypassed, that instruction hierarchies fail under adversarial conditions, and that LLM judges exhibit inconsistency across semantically equivalent inputs. None of this is a criticism of the people building these systems; it reflects the genuine difficulty of the problem. But it does mean that a behavioral guardrail, however carefully designed, carries performance uncertainty that has to be characterized before it can be trusted.</p><p>And that is exactly where the gap opens up.</p><h2>What Does Independent AI Assurance Actually Require?</h2><p>Saying that a behavioral guardrail is in place is different from saying that it works, under what conditions, and with what reliability. The first claim is about architecture, while the second is about evidence.</p><p>From where I sit, AI assurance is about closing that gap. It means specifying what the behavioral requirement actually is, with enough precision to be testable. It means characterizing the operational design domain, the range of inputs and conditions the system will encounter, so you know what you are evaluating over. It means running structured tests, including adversarial ones, to probe the boundary conditions of claimed behaviors. It means producing evidence that is interpretable by someone with no stake in the outcome.</p><p>None of that is accomplished by the guardrail being present. And when the guardrail is a natural language policy prompt interpreted by an LLM, the performance uncertainty is compounded, partly because the policy itself may be ambiguous, but also because there is no stable behavioral surface to evaluate without prior testing.</p><p>There is also a recursive dimension worth naming. If an LLM-based judge is the mechanism by which you claim an agent is behaving correctly, that judge is itself an AI system whose reliability needs to be independently characterized. Asserting that a system is compliant because its own guardrail approved it is not really a robust assurance argument; it is a design feature whose effectiveness remains open.</p><h2>Runtime Security vs. Behavioral Assurance: Two Different Questions</h2><p>Runtime security and behavioral assurance are not competing approaches. They operate at different layers and address different questions.</p><blockquote><p>Runtime security asks: <em>Is this system operating within defined parameters, is it protected against known attack vectors, and is there a record of what happened?</em></p><p>Behavioral assurance asks: <em>Does this system do what it claims to do, reliably, across the range of conditions it will actually encounter?</em></p></blockquote><p>Both questions matter. The first is largely an engineering and security problem. The second is an evaluation problem, and it requires independent evidence and assurance. The growing sophistication of runtime monitoring is a welcome development. The claim that it constitutes assurance in the stronger sense is the one that needs more precision.</p><div><hr></div><p><em>Shea Brown is the Founder and CEO of BABL AI, an independent AI assurance firm specializing in AI assurance, testing, evaluation, verification, and validation</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://sheabrownphd.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>