Proof-Carrying Data Obligations for AI Audit Trails: Implementation Lessons toward the PCT Open Specification

The European Union AI Act (Regulation (EU) 2024/1689) requires, in Article 12, that high-risk AI systems "technically allow for the automatic recording of events (logs) over the lifetime of the system", in order to ensure "a level of traceability of the functioning" of the system. The Act prescribes the property, not the mechanism; in practice the requirement is met by vendor-specific log formats whose semantics are not portable and whose integrity protection is procedural rather than cryptographic. The OPSF draft Proof Claims Token (PCT) specification defines a portable, signed, JWT-inspired token in which data carries its obligations with it: before any action - an AI model call, a cross-border transfer, a processing operation - the token is verified, the action is allowed or blocked, and an audit record is generated. This working paper reports what one implementer learned while building a publicly available PCT v0.1 issuer and validator in the GraQle SDK, alongside a separate RFC 6962 Merkle-commitment layer for audit records in the same SDK. We ask two questions: (RQ1) how should a PCT deployment commit its audit records to an external transparency log without anchoring every record individually? and (RQ2) which EU AI Act obligations can be carried inside the PCT extension mechanism beyond the five fields of the core specification's x-ai-act namespace? We make four contributions. First, we describe the reference issuer/validator (graqle.pct) and state precisely what it does and does not yet implement. Second, we offer two additive proposals to the specification - batch-mode commitment of audit records with a published deadline and pinning of the governing constraint version inside the signed or hashed content. Third, we document the x-ai-eu extension namespace, an eleven-field binding to EU AI Act articles that we filed publicly with OPSF on 27 June 2026 , and map each field to the article it serves. Fourth, we give an analytical (not measured) account of the anchoring cost that batch-mode removes. Evidence status. This paper contains no measured performance results. The reference implementation has unit tests but has not been benchmarked, and we know of no production deployment of it. Where quantities appear they are either public facts with a citation, configuration defaults readable in the public repository, or arithmetic consequences of stated parameters. The paper is offered to the OPSF technical committee as implementer input; it is not an OPSF document and implies no endorsement.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23056743
Primary Topic
Adversarial Robustness in Machine Learning
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Proof-Carrying Data Obligations for AI Audit Trails: Implementation Lessons toward the PCT Open Specification

Harish Kumar
Zenodo (CERN European Organization for Nuclear Research)
Adversarial Robustness in Machine Learning
article

Proof-Carrying Data Obligations for AI Audit Trails: Implementation Lessons toward the PCT Open Specification

Harish Kumar
article en

Abstract

The European Union AI Act (Regulation (EU) 2024/1689) requires, in Article 12, that high-risk AI systems "technically allow for the automatic recording of events (logs) over the lifetime of the system", in order to ensure "a level of traceability of the functioning" of the system. The Act prescribes the property, not the mechanism; in practice the requirement is met by vendor-specific log formats whose semantics are not portable and whose integrity protection is procedural rather than cryptographic. The OPSF draft Proof Claims Token (PCT) specification defines a portable, signed, JWT-inspired token in which data carries its obligations with it: before any action - an AI model call, a cross-border transfer, a processing operation - the token is verified, the action is allowed or blocked, and an audit record is generated. This working paper reports what one implementer learned while building a publicly available PCT v0.1 issuer and validator in the GraQle SDK, alongside a separate RFC 6962 Merkle-commitment layer for audit records in the same SDK. We ask two questions: (RQ1) how should a PCT deployment commit its audit records to an external transparency log without anchoring every record individually? and (RQ2) which EU AI Act obligations can be carried inside the PCT extension mechanism beyond the five fields of the core specification's x-ai-act namespace? We make four contributions. First, we describe the reference issuer/validator (graqle.pct) and state precisely what it does and does not yet implement. Second, we offer two additive proposals to the specification - batch-mode commitment of audit records with a published deadline and pinning of the governing constraint version inside the signed or hashed content. Third, we document the x-ai-eu extension namespace, an eleven-field binding to EU AI Act articles that we filed publicly with OPSF on 27 June 2026 , and map each field to the article it serves. Fourth, we give an analytical (not measured) account of the anchoring cost that batch-mode removes. Evidence status. This paper contains no measured performance results. The reference implementation has unit tests but has not been benchmarked, and we know of no production deployment of it. Where quantities appear they are either public facts with a citation, configuration defaults readable in the public repository, or arithmetic consequences of stated parameters. The paper is offered to the OPSF technical committee as implementer input; it is not an OPSF document and implies no endorsement.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 9%
Adversarial Robustness in Machine Learning
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.