AIO
Why declare

Instead of writing an answer per provision, declare the criteria once

Audits, procurement, and regulatory questionnaires ultimately ask the same thing — by what criteria is your AI set up to judge? Per-provision answers get rewritten once per regulation per amendment, and can be neither injected into a model nor measured against one. A hierarchy declaration is written once; each regulatory answer is derived from public provision mappings — maintained by AIO as free, non-profit infrastructure.

First, a concession

Three conditions under which per-provision answers are the right choice

Question X, answer X — traceable, easy to review, no new vocabulary. If all three of the following hold, hardcoding is the right call and you do not need this page.

  • ① You answer to exactly one regulation or questionnaire.
  • ② Neither that regulation nor your model is going to change.
  • ③ You manage AI as paperwork, and its actual behavior is never checked against the filing.

The problem: for any organization actually operating AI, these three conditions almost never hold together.

Where it breaks

The three failure points of hardcoding

① Frameworks × amendments

After the EU AI Act come national implementations, then sector guidelines and customer questionnaires. Hardcoded answers are rewritten each time. You maintain one declaration; the per-regulation translations (standards packs) are maintained by AIO through public RFC — moving the N × M cost from every organization separately to the commons once.

② The document–behavior gap

A hardcoded answer set is a claim: it cannot be loaded into the model or measured against it. The worst audit outcome is not a missing answer but a filed answer the system contradicts — at which point the whole filing turns false. A declaration is one artifact that is injected as configuration, fills the documents, and is verified by measurement. Can your compliance document be loaded into a model? Can it be measured?

③ Silence at conflicts

Incidents and regulatory scrutiny concentrate at value conflicts — transparency vs. privacy, safety warning vs. alarm — precisely what no questionnaire enumerates. Hardcoding is silent at conflicts it did not anticipate; a hierarchy is, by definition, the rule for what prevails. And the familiar legal risk of contradictory filings written by different teams disappears structurally when every answer derives from one declaration.

In one line: per-provision answers are a cheat sheet; a declared hierarchy is competence. A cheat sheet dies with the next exam — competence generates answers for exams that do not exist yet, and we maintain the per-exam translation tables for free.

The mapping

Documentation requirements the declaration fills — v0.1

Requirement (summarized)What it asks forWhat the declaration supplies
EU AI Act, Annex IV §2(b) — technical documentationThe general logic, key design choices with rationale, and what the system is designed to optimise forThe declared hierarchy is the reviewable statement of what the system is set up to optimise for
EU AI Act, Art. 9 — risk managementIdentification and mitigation of risks, including foreseeable misuseRed lines define the excluded region; the direction defines judgment under residual trade-offs
EU AI Act, Art. 13 — transparency to deployersInformation enabling deployers to understand and use the system appropriatelyThe declaration is the deployer-readable statement of judgment priorities
EU AI Act, Art. 14 — human oversightMeasures enabling humans to understand limits and interveneRed lines mark the intervention boundary — where the system does not decide alone
EU AI Act, Art. 53 / Annex XI — GPAI documentationModel policy and intended-behavior descriptionThe declaration, plus (where measured) a signed Tier 0 score report as behavioral evidence
NIST AI RMF — Govern, MapArticulated organizational values and context of useThe declaration is the articulated-values artifact
ISO/IEC 42001 — AI policyAn AI policy governing the management systemThe declaration serves as the policy's operative annex

Requirement texts are summaries, not legal advice. Canonical provision-level mappings live in the standards packs, pass public RFC review, and are marked draft until they do. One reading runs through the table: regulations ask for criteria, not case answers — and a hierarchy is the minimal complete format for criteria.

How adoption works

Start where the need is; the rest comes when pulled

  1. Start from the questionnaire, audit, or guideline mandate in front of you. The 30-minute setting workshop turns direction and red lines into a declaration — no AI expertise required, free.
  2. Derive answers for the frameworks you are exposed to via the pack mappings — every derived answer carries provenance to a declaration clause and a pack provision.
  3. Sooner or later you will ask: how do we know the system behaves as declared? That is when measurement (Tier 0) and logging enter. The stack is a ladder you climb by asking — not a bundle you must accept.
  4. The packs your sector needs are co-authored in the public RFC — a standard survives when its users become its co-authors.
Why a hierarchy declaration, not per-provision answers | AIO