Claim Limits in AI Audit Records: Naming What a Record Cannot Prove

The EU Artificial Intelligence Act requires high-risk AI systems to record events automatically, requires providers and deployers to keep those logs, and gives authorities access to them. The Act says what logs are for - traceability, monitoring, post-market surveillance - but it does not say what a log proves. That silence matters. A well-made audit record is good evidence of a small number of things: that an event was recorded, by which system or party, at what time, and that the record has not been altered since. It is not evidence that the decision was correct, that the inputs were true, that the model was unbiased, that a human reviewer exercised real judgement, or that the law was satisfied. Yet a record that is tidy, signed and complete-looking invites exactly those inferences. We call this the over-reading problem, and its institutional consequence the "auditable-but-wrong" moral hazard: an organisation that can produce an impeccable record of a bad decision is better placed to defend that decision than one that kept no record at all. This position paper argues that AI audit records should carry an explicit claim-limit declaration: a short statement, readable by people and processable by machines, of what the record attests and what it does not. We (i) read Article 12, Article 13, Article 14, Article 19 and Article 26 of the Act for what they ask of records; (ii) offer a vendor-neutral taxonomy that separates four things a record can attest (occurrence, integrity, origin, time) from eight things it cannot attest on its own (completeness, input veracity, output correctness, fairness, explanatory fidelity, quality of human oversight, legality, and generalisation); (iii) show that declared limits are an established practice in neighbouring fields - the auditor's opinion under the International Standards on Auditing, the rules of evidence on electronic records, the eIDAS presumptions, content-provenance and software-supply-chain specifications, and model cards and datasheets; and (iv) state normative requirements for the content, placement, language and stability of such a declaration, with two plain-language illustrations (a credit assessment record and a remote biometric identification record) and a worked application of the taxonomy to the published evaluation record of the author's own system. We also examine how the idea can fail: as boilerplate, as a liability shield, and through limit inflation. The paper is conceptual. It reports no empirical results, and its taxonomy has not been tested with auditors, courts or regulators.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23056641
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Claim Limits in AI Audit Records: Naming What a Record Cannot Prove

Harish Kumar
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

Claim Limits in AI Audit Records: Naming What a Record Cannot Prove

Harish Kumar
article en

Abstract

The EU Artificial Intelligence Act requires high-risk AI systems to record events automatically, requires providers and deployers to keep those logs, and gives authorities access to them. The Act says what logs are for - traceability, monitoring, post-market surveillance - but it does not say what a log proves. That silence matters. A well-made audit record is good evidence of a small number of things: that an event was recorded, by which system or party, at what time, and that the record has not been altered since. It is not evidence that the decision was correct, that the inputs were true, that the model was unbiased, that a human reviewer exercised real judgement, or that the law was satisfied. Yet a record that is tidy, signed and complete-looking invites exactly those inferences. We call this the over-reading problem, and its institutional consequence the "auditable-but-wrong" moral hazard: an organisation that can produce an impeccable record of a bad decision is better placed to defend that decision than one that kept no record at all. This position paper argues that AI audit records should carry an explicit claim-limit declaration: a short statement, readable by people and processable by machines, of what the record attests and what it does not. We (i) read Article 12, Article 13, Article 14, Article 19 and Article 26 of the Act for what they ask of records; (ii) offer a vendor-neutral taxonomy that separates four things a record can attest (occurrence, integrity, origin, time) from eight things it cannot attest on its own (completeness, input veracity, output correctness, fairness, explanatory fidelity, quality of human oversight, legality, and generalisation); (iii) show that declared limits are an established practice in neighbouring fields - the auditor's opinion under the International Standards on Auditing, the rules of evidence on electronic records, the eIDAS presumptions, content-provenance and software-supply-chain specifications, and model cards and datasheets; and (iv) state normative requirements for the content, placement, language and stability of such a declaration, with two plain-language illustrations (a credit assessment record and a remote biometric identification record) and a worked application of the taxonomy to the published evaluation record of the author's own system. We also examine how the idea can fail: as boilerplate, as a liability shield, and through limit inflation. The paper is conceptual. It reports no empirical results, and its taxonomy has not been tested with auditors, courts or regulators.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.