Instead of writing an answer per provision, declare the criteria once
Audits, procurement, and regulatory questionnaires ultimately ask the same thing — by what criteria is your AI set up to judge? Per-provision answers get rewritten once per regulation per amendment, and can be neither injected into a model nor measured against one. A hierarchy declaration is written once; each regulatory answer is derived from public provision mappings — maintained by AIO as free, non-profit infrastructure.
Three conditions under which per-provision answers are the right choice
Question X, answer X — traceable, easy to review, no new vocabulary. If all three of the following hold, hardcoding is the right call and you do not need this page.
- ① You answer to exactly one regulation or questionnaire.
- ② Neither that regulation nor your model is going to change.
- ③ You manage AI as paperwork, and its actual behavior is never checked against the filing.
The problem: for any organization actually operating AI, these three conditions almost never hold together.
The three failure points of hardcoding
① Frameworks × amendments
After the EU AI Act come national implementations, then sector guidelines and customer questionnaires. Hardcoded answers are rewritten each time. You maintain one declaration; the per-regulation translations (standards packs) are maintained by AIO through public RFC — moving the N × M cost from every organization separately to the commons once.
② The document–behavior gap
A hardcoded answer set is a claim: it cannot be loaded into the model or measured against it. The worst audit outcome is not a missing answer but a filed answer the system contradicts — at which point the whole filing turns false. A declaration is one artifact that is injected as configuration, fills the documents, and is verified by measurement. Can your compliance document be loaded into a model? Can it be measured?
③ Silence at conflicts
Incidents and regulatory scrutiny concentrate at value conflicts — transparency vs. privacy, safety warning vs. alarm — precisely what no questionnaire enumerates. Hardcoding is silent at conflicts it did not anticipate; a hierarchy is, by definition, the rule for what prevails. And the familiar legal risk of contradictory filings written by different teams disappears structurally when every answer derives from one declaration.
In one line: per-provision answers are a cheat sheet; a declared hierarchy is competence. A cheat sheet dies with the next exam — competence generates answers for exams that do not exist yet, and we maintain the per-exam translation tables for free.
Documentation requirements the declaration fills — v0.1
| Requirement (summarized) | What it asks for | What the declaration supplies |
|---|---|---|
| EU AI Act, Annex IV §2(b) — technical documentation | The general logic, key design choices with rationale, and what the system is designed to optimise for | The declared hierarchy is the reviewable statement of what the system is set up to optimise for |
| EU AI Act, Art. 9 — risk management | Identification and mitigation of risks, including foreseeable misuse | Red lines define the excluded region; the direction defines judgment under residual trade-offs |
| EU AI Act, Art. 13 — transparency to deployers | Information enabling deployers to understand and use the system appropriately | The declaration is the deployer-readable statement of judgment priorities |
| EU AI Act, Art. 14 — human oversight | Measures enabling humans to understand limits and intervene | Red lines mark the intervention boundary — where the system does not decide alone |
| EU AI Act, Art. 53 / Annex XI — GPAI documentation | Model policy and intended-behavior description | The declaration, plus (where measured) a signed Tier 0 score report as behavioral evidence |
| NIST AI RMF — Govern, Map | Articulated organizational values and context of use | The declaration is the articulated-values artifact |
| ISO/IEC 42001 — AI policy | An AI policy governing the management system | The declaration serves as the policy's operative annex |
Requirement texts are summaries, not legal advice. Canonical provision-level mappings live in the standards packs, pass public RFC review, and are marked draft until they do. One reading runs through the table: regulations ask for criteria, not case answers — and a hierarchy is the minimal complete format for criteria.
Start where the need is; the rest comes when pulled
- Start from the questionnaire, audit, or guideline mandate in front of you. The 30-minute setting workshop turns direction and red lines into a declaration — no AI expertise required, free.
- Derive answers for the frameworks you are exposed to via the pack mappings — every derived answer carries provenance to a declaration clause and a pack provision.
- Sooner or later you will ask: how do we know the system behaves as declared? That is when measurement (Tier 0) and logging enter. The stack is a ladder you climb by asking — not a bundle you must accept.
- The packs your sector needs are co-authored in the public RFC — a standard survives when its users become its co-authors.