Evidence-as-Code: Making AI Governance Verifiable

As autonomous AI systems move from recommendation to execution, governance can no longer remain a collection of policy documents, periodic assessments, and retrospective audit reports. An agent may select tools, access resources, delegate subtasks, modify external systems, and act across cloud and edge environments in seconds. By the time a conventional review begins, the decision context may have disappeared and the effects may already have propagated. This article introduces Evidence-as-Code as an architectural principle for making AI governance continuously verifiable. Under this principle, every consequential agent action produces structured evidence describing identity, authority, delegation, policy evaluation, execution, outcome, and subsequent control events such as revocation. Evidence is generated as part of the control path, cryptographically bound to its context, correlated across distributed components, and evaluated automatically against governance requirements. Evidence-as-Code extends Policy-as-Code and observability. Policy-as-Code expresses what should be allowed; enforcement decides what is allowed at runtime; telemetry describes what the system did; Evidence-as-Code establishes why an action was permitted, under whose authority it occurred, which controls were applied, and whether the resulting claim can be independently verified. Within SGAEIA, this creates the missing assurance layer between bounded authority, Zero Trust, authenticated delegation, and Continuous GRC. This article presents a conceptual reference model derived from architectural synthesis across AI risk management, machine-readable compliance, provenance, workload identity, observability, and software-supply-chain attestations. It does not claim empirical validation, certification, or legal conformity. This publication is Article 6 of 8 in the SGAEIA Research Series and develops the evidence and assurance layer of the Secure Governed Autonomous Edge Intelligence Architecture.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-13
DOI
https://doi.org/10.5281/zenodo.22736487
Citations
2
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
12.50
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Evidence-as-Code: Making AI Governance Verifiable

Aridio Silva
2 citations
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
12.50
article

Evidence-as-Code: Making AI Governance Verifiable

Aridio Silva
article en
2 citations

Abstract

As autonomous AI systems move from recommendation to execution, governance can no longer remain a collection of policy documents, periodic assessments, and retrospective audit reports. An agent may select tools, access resources, delegate subtasks, modify external systems, and act across cloud and edge environments in seconds. By the time a conventional review begins, the decision context may have disappeared and the effects may already have propagated. This article introduces Evidence-as-Code as an architectural principle for making AI governance continuously verifiable. Under this principle, every consequential agent action produces structured evidence describing identity, authority, delegation, policy evaluation, execution, outcome, and subsequent control events such as revocation. Evidence is generated as part of the control path, cryptographically bound to its context, correlated across distributed components, and evaluated automatically against governance requirements. Evidence-as-Code extends Policy-as-Code and observability. Policy-as-Code expresses what should be allowed; enforcement decides what is allowed at runtime; telemetry describes what the system did; Evidence-as-Code establishes why an action was permitted, under whose authority it occurred, which controls were applied, and whether the resulting claim can be independently verified. Within SGAEIA, this creates the missing assurance layer between bounded authority, Zero Trust, authenticated delegation, and Continuous GRC. This article presents a conceptual reference model derived from architectural synthesis across AI risk management, machine-readable compliance, provenance, workload identity, observability, and software-supply-chain attestations. It does not claim empirical validation, certification, or legal conformity. This publication is Article 6 of 8 in the SGAEIA Research Series and develops the evidence and assurance layer of the Secure Governed Autonomous Edge Intelligence Architecture.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 1%
Ethics and Social Impacts of AI
12.50
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.