Insights
Working positions on how assurance must change when systems are AI-engineered, autonomous, emergent, and without precedent.
Detailed positions for decisions that require more than a checklist.
Each brief defines the assurance question, the evidence that matters, the intended outcome, and the professional boundary on any conclusion.
Why code audits are not enough
Source inspection remains valuable, but it cannot by itself establish the behavior of a complex, AI-engineered production system.
Assurance in the age of AI-engineered software
AI changes not only how quickly software is produced, but how complete human implementation knowledge can reasonably remain.
Understanding emergent behavior
Consequential behavior can arise from interactions no component owner intended or fully described.
The system is the unit of assurance
Trust decisions are made about operating capabilities, not isolated repositories, models, or test reports.
Independence for technical assurance
Technical depth and independence are complementary: an opinion must understand the system without inheriting the incentives that shaped it.
Evidence before confidence
Confidence is useful only when its basis, scope, contradiction, expiry, and relationship to the actual system are visible.
Assuring autonomous authority
The defining risk of an autonomous system is not intelligence alone, but the authority attached to its decisions.
Novel systems without precedent
When no mature standard or comparison class exists, assurance must make its reasoning more explicit—not less demanding.
Common evidence base
Four evidence planes. One independent conclusion.
Reasoned assurance principles
Practical system implications
Boundaries and counterexamples
Begin an engagement
Bring us the system that cannot be reduced to a standard audit.
We will begin with the decision, the claims, and the system boundary.
Start a confidential conversation ↗