JAZB Framework v1.1: Judiciary AI Zero-Trust Broker

JAZB (Judiciary AI Zero-Trust Broker) is a human-sovereign enterprise governance architecture for artificial intelligence designed to govern the establishment, delegation, interpretation, exercise, assurance, and revocation of organizational Authority. JAZB applies Zero Trust, least privilege, separation of duties, jurisdictional separation, Human-Established Law, bounded autonomy, accountable decision rights, and continuous governance assurance to AI-enabled operations. The framework distinguishes technical capability from legitimate Authority and establishes an architecture in which humans remain the source of organizational Law while artificial intelligence may interpret and exercise bounded Authority without becoming the source of its own Authority. JAZB separates enterprise governance from machine capability. Business purpose, human decision rights, Law establishment, architecture, residual-risk acceptance, technical operation, expansion of autonomy, and independent assurance are treated as distinct governance responsibilities. Technical access, credentials, network reachability, model capability, workflow ownership, or administrative control do not independently establish legitimate Authority. JAZB defines separate Internal and Border Jurisdictions. The Judge serves as the AI interpretation and decision layer for Internal Jurisdiction, while Enterprise AI Customs governs lawful passage across the Organization's external Organizational Boundary. These jurisdictions are supported by Human-Established Law Layers, Commissioners, operational AI AGENTs, Port Authority, Port Directors, Customs AGENTs, Judicial Instruments, independent Actuation Authority, the Chain of Authority, the Chain of Evidence, emergency governance, Governance Escape Resistance, trusted recovery, and explicit Law-establishment procedures. The framework is designed to complement established enterprise architecture, cybersecurity, identity, risk-management, privacy, Zero Trust, AI-governance, service-management, and management-system practices rather than replace existing technical controls or standards. Version 1.2 is an enterprise architecture maturation of JAZB. It preserves the human-sovereign Authority model, dual-jurisdiction architecture, behavioral governance, bounded execution, and enforcement principles established in Versions 1.0 and 1.1 while expanding JAZB into a more explicit enterprise governance and operating architecture. Version 1.2 introduces clearer enterprise decision rights for business ownership, Law establishment, architecture, residual-risk acceptance, technical operation, expansion, and independent assurance. It formalizes use-case governance, autonomy selection, Current State and Target State architecture, Architecture Decision Records, progressive adoption gates, provider and third-party governance, portfolio-level oversight, implementation economics, and the distinction between AI capability and organizational authorization to use that capability. Version 1.2 also formalizes Continuous Governance Assurance. JAZB no longer treats governance as a condition permanently established by policy, configuration, or prior testing. Governance coverage must be continuously demonstrated as systems, models, providers, data, identities, tools, methods, destinations, organizational ownership, and external obligations change. The framework therefore adopts a repeating governance assurance cycle: Establish → Operate → Observe → Validate → Discover → Remediate → Revalidate Material change may invalidate previously valid assumptions and require Authority, architecture, enforcement, or assurance reevaluation. A successful prior test does not constitute permanent assurance. Technical recovery does not automatically restore prior Authority. Missing evidence, stale assurance, unknown state, provider opacity, or an unmediated consequential path must not be represented as positive proof that governance is operating correctly. Version 1.2 also strengthens the treatment of residual risk and third-party dependency. Material residual-risk acceptance remains a human governance responsibility. External providers, managed services, models, subprocessors, and technical dependencies may support JAZB operation, but contractual approval, certification, provider self-reporting, or technical availability do not independently establish complete JAZB governance coverage. Prevention and containment claims remain bounded to paths that are actually mediated by the required governance or enforcement architecture, or by equivalent controls capable of reliably preventing the consequential action. Known gaps, unmediated paths, uncertain attribution, missing telemetry, third-party opacity, exceptions, and unresolved limitations must remain visible in the assurance record. This release contains the seven core JAZB Framework publications: Publication 1 | Phase I: Foundational ArchitectureEstablishes the enterprise governance architecture, foundational doctrine, human sovereignty model, organizational decision rights, Authority Governance Lifecycle, Human-Established Law model, Internal and Border Jurisdictions, continuous governance assurance model, enterprise control relationships, and core architectural principles. Publication 2 | Phase II: Authority & Judicial SpecificationFormalizes Rights, Duties, Liberty, Authority, Delegation, Baseline and Elevated Authority, Point Policy, judicial decision semantics, Judicial Instruments, independent Actuation Authority, effective-target and method governance, the Chain of Authority, the Chain of Evidence, and internal Authority workflows. Publication 3 | Phase III: Enterprise AI Customs SpecificationDefines Border Jurisdiction, lawful ingress and egress, Port Authority, Port Director, Customs AGENT, Ports of Entry, external-service ownership, governed passage, cross-boundary delegation, inspection, enforcement, third-party opacity, provider change, external-boundary assurance, and border Governance Escape Resistance. Publication 4 | Phase IV: Security & Resilience SpecificationDefines compromise handling, Governance Escape Resistance, Law-state integrity, evidence integrity, governance continuity, degraded operation, material-change revalidation, dependency failure, human residual-risk disposition, trusted recovery, recovery reauthorization, emergency resilience, and continuous governance assurance under failure and change. Publication 5 | Phase V: Implementation & Adoption GuideProvides the enterprise operating model for JAZB adoption, including use-case governance, autonomy selection, business ownership, enterprise decision rights, Current and Target State architecture, inventories, pilot deployment, Architecture Decision Records, Law establishment, Authority deployment, Enterprise AI Customs, testing, measurement, provider governance, training, cost and scale considerations, maturity, controlled expansion, and continuous assurance. Publication 6 | Phase VI: Standards & Compliance MappingMaps JAZB to major AI governance, cybersecurity, Zero Trust, risk, privacy, control, and management-system frameworks while preserving source boundaries. Formal crosswalks distinguish Direct Alignment, Complementary Alignment, Implementation Support, and No Equivalence. Phase VI expressly separates architectural alignment from certification, legal compliance, implementation effectiveness, or external endorsement. Publication 7 | Phase VII: Reference SpecificationProvides the canonical normative implementation and conformance reference for JAZB Version 1.2. It preserves JAZB-RS-001 through JAZB-RS-168 and extends the specification through JAZB-RS-230, adding normative requirements for enterprise governance, decision rights, autonomy, continuous governance assurance, material-change revalidation, provider limitations, recovery reauthorization, implementation architecture, conformance currency, independent assurance, and crosswalk governance. Together, the seven publications define an Authority-centric enterprise architecture in which business purpose, human governance, technical capability, credential possession, network reachability, model capability, behavioral anomaly, administrative control, or access to governance mechanisms do not independently constitute legitimate Authority. JAZB does not claim to eliminate AI risk, guarantee safe AI behavior, replace conventional cybersecurity or privacy controls, or establish legal compliance. It provides an architecture for making legitimate Authority explicit, constraining how that Authority may be exercised, identifying when governance and operational reality diverge, and restoring demonstrable governance through accountable human decisions and continuous assurance. JAZB is designed around two foundational principles: Capability does not constitute Authority. Artificial intelligence may exercise Authority. It must never become the source of its own Authority. Author: Michael CostnerFramework website: jazbframework.orgVersion: 1.2Publication date: October 2026DOI: 10.5281/zenodo.23088094

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-01
DOI
https://doi.org/10.5281/zenodo.23088094
Primary Topic
Ethics and Social Impacts of AI
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

JAZB Framework v1.1: Judiciary AI Zero-Trust Broker

Michael Costner
Zenodo (CERN European Organization for Nuclear Research)
Ethics and Social Impacts of AI
article

JAZB Framework v1.1: Judiciary AI Zero-Trust Broker

Michael Costner
article en

Abstract

JAZB (Judiciary AI Zero-Trust Broker) is a human-sovereign enterprise governance architecture for artificial intelligence designed to govern the establishment, delegation, interpretation, exercise, assurance, and revocation of organizational Authority. JAZB applies Zero Trust, least privilege, separation of duties, jurisdictional separation, Human-Established Law, bounded autonomy, accountable decision rights, and continuous governance assurance to AI-enabled operations. The framework distinguishes technical capability from legitimate Authority and establishes an architecture in which humans remain the source of organizational Law while artificial intelligence may interpret and exercise bounded Authority without becoming the source of its own Authority. JAZB separates enterprise governance from machine capability. Business purpose, human decision rights, Law establishment, architecture, residual-risk acceptance, technical operation, expansion of autonomy, and independent assurance are treated as distinct governance responsibilities. Technical access, credentials, network reachability, model capability, workflow ownership, or administrative control do not independently establish legitimate Authority. JAZB defines separate Internal and Border Jurisdictions. The Judge serves as the AI interpretation and decision layer for Internal Jurisdiction, while Enterprise AI Customs governs lawful passage across the Organization's external Organizational Boundary. These jurisdictions are supported by Human-Established Law Layers, Commissioners, operational AI AGENTs, Port Authority, Port Directors, Customs AGENTs, Judicial Instruments, independent Actuation Authority, the Chain of Authority, the Chain of Evidence, emergency governance, Governance Escape Resistance, trusted recovery, and explicit Law-establishment procedures. The framework is designed to complement established enterprise architecture, cybersecurity, identity, risk-management, privacy, Zero Trust, AI-governance, service-management, and management-system practices rather than replace existing technical controls or standards. Version 1.2 is an enterprise architecture maturation of JAZB. It preserves the human-sovereign Authority model, dual-jurisdiction architecture, behavioral governance, bounded execution, and enforcement principles established in Versions 1.0 and 1.1 while expanding JAZB into a more explicit enterprise governance and operating architecture. Version 1.2 introduces clearer enterprise decision rights for business ownership, Law establishment, architecture, residual-risk acceptance, technical operation, expansion, and independent assurance. It formalizes use-case governance, autonomy selection, Current State and Target State architecture, Architecture Decision Records, progressive adoption gates, provider and third-party governance, portfolio-level oversight, implementation economics, and the distinction between AI capability and organizational authorization to use that capability. Version 1.2 also formalizes Continuous Governance Assurance. JAZB no longer treats governance as a condition permanently established by policy, configuration, or prior testing. Governance coverage must be continuously demonstrated as systems, models, providers, data, identities, tools, methods, destinations, organizational ownership, and external obligations change. The framework therefore adopts a repeating governance assurance cycle: Establish → Operate → Observe → Validate → Discover → Remediate → Revalidate Material change may invalidate previously valid assumptions and require Authority, architecture, enforcement, or assurance reevaluation. A successful prior test does not constitute permanent assurance. Technical recovery does not automatically restore prior Authority. Missing evidence, stale assurance, unknown state, provider opacity, or an unmediated consequential path must not be represented as positive proof that governance is operating correctly. Version 1.2 also strengthens the treatment of residual risk and third-party dependency. Material residual-risk acceptance remains a human governance responsibility. External providers, managed services, models, subprocessors, and technical dependencies may support JAZB operation, but contractual approval, certification, provider self-reporting, or technical availability do not independently establish complete JAZB governance coverage. Prevention and containment claims remain bounded to paths that are actually mediated by the required governance or enforcement architecture, or by equivalent controls capable of reliably preventing the consequential action. Known gaps, unmediated paths, uncertain attribution, missing telemetry, third-party opacity, exceptions, and unresolved limitations must remain visible in the assurance record. This release contains the seven core JAZB Framework publications: Publication 1 | Phase I: Foundational ArchitectureEstablishes the enterprise governance architecture, foundational doctrine, human sovereignty model, organizational decision rights, Authority Governance Lifecycle, Human-Established Law model, Internal and Border Jurisdictions, continuous governance assurance model, enterprise control relationships, and core architectural principles. Publication 2 | Phase II: Authority & Judicial SpecificationFormalizes Rights, Duties, Liberty, Authority, Delegation, Baseline and Elevated Authority, Point Policy, judicial decision semantics, Judicial Instruments, independent Actuation Authority, effective-target and method governance, the Chain of Authority, the Chain of Evidence, and internal Authority workflows. Publication 3 | Phase III: Enterprise AI Customs SpecificationDefines Border Jurisdiction, lawful ingress and egress, Port Authority, Port Director, Customs AGENT, Ports of Entry, external-service ownership, governed passage, cross-boundary delegation, inspection, enforcement, third-party opacity, provider change, external-boundary assurance, and border Governance Escape Resistance. Publication 4 | Phase IV: Security & Resilience SpecificationDefines compromise handling, Governance Escape Resistance, Law-state integrity, evidence integrity, governance continuity, degraded operation, material-change revalidation, dependency failure, human residual-risk disposition, trusted recovery, recovery reauthorization, emergency resilience, and continuous governance assurance under failure and change. Publication 5 | Phase V: Implementation & Adoption GuideProvides the enterprise operating model for JAZB adoption, including use-case governance, autonomy selection, business ownership, enterprise decision rights, Current and Target State architecture, inventories, pilot deployment, Architecture Decision Records, Law establishment, Authority deployment, Enterprise AI Customs, testing, measurement, provider governance, training, cost and scale considerations, maturity, controlled expansion, and continuous assurance. Publication 6 | Phase VI: Standards & Compliance MappingMaps JAZB to major AI governance, cybersecurity, Zero Trust, risk, privacy, control, and management-system frameworks while preserving source boundaries. Formal crosswalks distinguish Direct Alignment, Complementary Alignment, Implementation Support, and No Equivalence. Phase VI expressly separates architectural alignment from certification, legal compliance, implementation effectiveness, or external endorsement. Publication 7 | Phase VII: Reference SpecificationProvides the canonical normative implementation and conformance reference for JAZB Version 1.2. It preserves JAZB-RS-001 through JAZB-RS-168 and extends the specification through JAZB-RS-230, adding normative requirements for enterprise governance, decision rights, autonomy, continuous governance assurance, material-change revalidation, provider limitations, recovery reauthorization, implementation architecture, conformance currency, independent assurance, and crosswalk governance. Together, the seven publications define an Authority-centric enterprise architecture in which business purpose, human governance, technical capability, credential possession, network reachability, model capability, behavioral anomaly, administrative control, or access to governance mechanisms do not independently constitute legitimate Authority. JAZB does not claim to eliminate AI risk, guarantee safe AI behavior, replace conventional cybersecurity or privacy controls, or establish legal compliance. It provides an architecture for making legitimate Authority explicit, constraining how that Authority may be exercised, identifying when governance and operational reality diverge, and restoring demonstrable governance through accountable human decisions and continuous assurance. JAZB is designed around two foundational principles: Capability does not constitute Authority. Artificial intelligence may exercise Authority. It must never become the source of its own Authority. Author: Michael CostnerFramework website: jazbframework.orgVersion: 1.2Publication date: October 2026DOI: 10.5281/zenodo.23088094

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Openalex Percentile: Top 7%
Ethics and Social Impacts of AI
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.