Evidence
What proof of control looks like. Regulators expect to see outcomes, not promises.
The gap between policy and evidence
A policy document that says "we do not make performance claims" is not evidence. It is a promise. An auditor or regulator wants proof: what stops a performance claim from reaching production? How do you know the control is working?
Example: automated content scan
Objective
Content generated by an AI system shall not make performance claims without evidence.
Control
Automated scan on every generated output. The scan rejects any content containing phrases like "outperform", "beat", "superior to", "best in class" unless accompanied by a citation or an evidence marker flagged for human review.
Evidence
- Logs showing the scan runs on 100% of outputs (no bypass path)
- Count of outputs rejected per month
- Sample of rejections with rationale and remediation
- Performance: scan latency, false positive rate, override rate
Evidence we operate ourselves
The practice runs its own AI service, Monarch-X Ai. Every answer it gives is stamped with a date, time and reference, and the record is kept in a tamper-evident chain that anyone holding the reference can check without an account. Spend is prepaid and capped, and the meter is always visible. Those are the same controls we describe here: coverage, automation, an audit trail, and a stop when something is wrong — in production, not on paper.
What makes evidence credible
- Coverage: The control applies to all instances, not a sample.
- Automation: The control runs without human intervention; it cannot be forgotten.
- Audit trail: Logs prove the control ran and what it did.
- Remediation: When the control flags an issue, the process stops or escalates.
Why this matters under the EU AI Act
Annex III high-risk systems must demonstrate "appropriate human oversight" and "accuracy, robustness, and cybersecurity." A policy document does not demonstrate this. Logs, test results, and operational metrics do.
This approach is central to AI assurance and sovereign cloud integration engagements.