Skip to main content

STANDARD

Huitzo Assurance Levels

A graded, verifiable standard for how AI is operated. Written in the open, starting at version 0.1.

Version
v0.1
Status
Draft. Expect breaking changes.
Published
2026-07-06
Feedback
[email protected]

Draft notice

This is a working draft published for feedback, not a finished industry standard. Level names are provisional. Changes are versioned in the changelog below. Send feedback to [email protected].


WHY A STANDARD

Why a standard for operating AI

AI adoption is trustworthy when the organization can prove, to a skeptical third party, exactly what its AI applications did, who approved it, and what data never left.

Today there is no finished, adoptable standard that tells an organization what that proof looks like or how to grade its own operation against it. We believe the industry needs a clear, graded standard for how AI is operated: verifiable levels of assurance an organization can climb, from basic execution logging to fully provable, boundary-enforced AI operation. Huitzo is building toward publishing that standard openly, with our own platform as its reference implementation.

This page is the first public draft of that standard. It defines four assurance levels an organization can climb. Each level states what it guarantees and how a skeptical third party can check it. The levels grade the operation of AI applications, not the quality of the models they call.


THE FOUR LEVELS

The four levels

Levels are cumulative. Each level includes every guarantee of the levels below it.

L0 L1 L2 L3
FIG. 01. FOUR LEVELS, CUMULATIVE. A DIRECTION, NOT A CLAIM.
  • L0 Unrecorded operation

    None. The baseline this standard exists to move organizations off.

  • L1 Recorded execution

    Every run of every AI application produces a durable, complete execution record.

  • L2 Attributable, tamper-evident records

    Everything in Level 1, and records are cryptographically signed, attributable, and tamper-evident.

  • L3 Provable, boundary-enforced operation

    Everything in Level 2, and the record can be checked against reality instead of taken on faith.

L0

Unrecorded operation

None. The baseline this standard exists to move organizations off.

AI applications run, but the organization cannot produce a complete record of what any given run did. Questions from an auditor are answered from memory, dashboards, or vendor logs the organization does not control. Most AI deployments operate here today.

HOW TO CHECK IT

  • Ask the operator for the record of one specific past run.
  • At Level 0, no such record exists, or it is partial and lives in systems the organization does not control.

L1

Recorded execution

Every run of every AI application produces a durable, complete execution record.

The record answers, for any single run: which application and version ran, when, what steps executed, where AI was invoked and with which model, what scope of data the AI step received, and what the outcome was. Records are retained under the organization’s own control.

HOW TO CHECK IT

  • Pick any past execution at random. The operator produces its record.
  • The record answers what ran, what each step did, what the AI step received, and what happened next, without consulting any other system.

L2

Attributable, tamper-evident records

Everything in Level 1, and records are cryptographically signed, attributable, and tamper-evident.

Each record is signed when it is emitted, so any later alteration is detectable. Each run is attributable to a specific application version, and any action that required human sign-off records who approved it and when. A skeptical third party can verify a record without trusting the person who handed it over.

HOW TO CHECK IT

  • Verify the record’s signature against the operator’s published verification key.
  • Alter any byte of the record and confirm verification fails.
  • For an action that required approval, confirm the record names the approver and the time of the decision.

L3

Provable, boundary-enforced operation

Everything in Level 2, and the record can be checked against reality instead of taken on faith.

The data boundary is enforced by the architecture, and the record demonstrates what data never left the network. The record carries enough evidence to be independently checked against reality, so an auditor can test whether it is true rather than merely well-formed. This is the level the Huitzo platform is being built to meet.

HOW TO CHECK IT

  • Take a recorded past execution and independently check the record against what actually happened.
  • Inspect the boundary evidence in the record against the deployment’s actual network configuration.
  • Confirm the record demonstrates what data never left the network, not just what the application intended.


THE REFERENCE ARTIFACT

See a Level 2 record, not a description of one

A standard about proof should come with an inspectable artifact. We published a sample signed audit record, with every field annotated in plain English and a real Ed25519 signature you can verify.


WHAT THIS DRAFT DOES NOT COVER

What this draft does not cover yet

04.1

A conformance test suite. v0.1 defines the levels and how to check them by hand; a repeatable, automated way to demonstrate conformance is future work.

04.2

Model quality and safety evaluation. The levels grade how AI applications are operated and evidenced, not whether a given model is accurate or safe for a task.

04.3

A certification program. Huitzo will train and certify individuals and organizations in the responsible implementation of AI, so 'we run AI the right way' becomes something a company can demonstrate, not just assert. No credential exists today.

04.4

Independent governance. This draft is written and maintained by Huitzo. Our own platform is being built as its reference implementation, and we say so plainly.


LAST UPDATED 2026-07-06.


CHANGELOG

v0.1 2026-07-06 Initial public draft. Four levels, manual checks only.

This draft gets better through argument. If a level is too weak, too strong, or uncheckable in your environment, we want that feedback before v0.2.


AI operating system for regulated companies

Simple by design. Built to scale. Runs where your data lives.

Product access
Huitzo Hub is available by invitation for teams evaluating the product.