HACCP for AI: An Auditable Self-Control Standard for Artificial Intelligence

Almost every serious instrument in AI governance now requires an organisation to run a risk process. None of them tells the organisation where in its own lifecycle the control points sit, what measurable limit applies at each one, what happens automatically when a limit is breached, or who is competent to verify the measurement. That layer, process control, is missing, and it is the layer on which everything else depends. A management system without control points produces documentation; it does not produce safety. This paper supplies that layer by importing a method that has governed an invisible hazard across a globally distributed production chain for more than fifty years: Hazard Analysis and Critical Control Points. The claim is deliberately narrow. HACCP is not proposed as a rival to ISO/IEC 42001, to Article 9 of the EU AI Act, or to the NIST AI Risk Management Framework. It is proposed as the process-control layer their architecture presupposes and does not contain, and as the one methodology in existence with a property AI governance urgently needs and currently lacks: scale invariance. The same seven principles govern a village bakery and a multinational dairy, which is why one inspector, one standard and one accreditation system can cover both. The method is given in the full twelve-step Codex sequence, with a three-tier proportionality rule, deployer, provider, frontier developer, a hazard taxonomy, a control-point decision tree, a catalogue of seven control points, and a taxonomy of limits that separates critical limits from operational limits and indicator thresholds, and reclassifies the compute thresholds now written into law as the third kind. Version 5.0 supplied the instruments: attribute sampling plans with their operating characteristics, statistical process control that gives the operational limit an exact meaning, a seven-step protocol for validating an evaluation as a measuring instrument, and record schemas that make version identity and traceability a matter of implementation. Version 6.0 adds what September 2026 asked for. At the United Nations Security Council the heads of the two largest frontier laboratories called for external evaluators embedded with employee-like access, "similar to a food inspector"; for common standards so that countries can compare evidence and verify compliance; for incident classification and reporting protocols; for a way to measure and pace the automation of AI research; and for standards that preserve meaningful human oversight. Food law has settled forms for each, and this version writes them into the plan: the resident inspector, with the eleven properties the September proposals ask for read against the articles of the European official-controls regulation that already provide them, an inspection record, and a funding model that makes independence enforceable rather than promised; a four-level incident severity scale built on recorded facts, with the statutory clocks in force; the pre-registered safety case as the condition of a training run; measurable pace indicators for self-improvement with slowing and pausing as written corrective actions; and the planted error, the metal-detector test piece of food lines, as the measure of whether human review is real. The instruments of Part II are updated to the 2026 evaluation literature, including evaluation awareness as a threat to validity, and the year's five public incidents are read as deviations, each with the record that would have been required next. The paper states its own limits without softening. The most consequential gap in AI-governance infrastructure is metrological: there is no analogue of ISO/IEC 17025 for capability evaluation, and until there is, independent attestation of a capability-based limit is not available to anyone. One structural disanalogy has no food-safety precedent at all: a pathogen does not model the control system trying to detect it, and a sufficiently capable AI system may. Both are treated as design constraints on the method rather than as objections to be answered later. The framework is accordingly strongest where most AI harm occurs, in organisations that deploy and provide AI systems, and is stated to be aspirational at the frontier until independent measurement exists; the resident inspector is the part of it a frontier laboratory can adopt this year, because its independence can be accredited before its measurements can. This record contains three files: the full paper (version 6.0, 86 pages), a two-page Executive Summary for policy readers, and a 20-page Practitioner Brief containing Part II (the instruments) as a standalone document. Version 6.0 supersedes version 5.0.1 (September 2026); earlier versions remain available under the same concept DOI. CC BY 4.0.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-05
DOI
https://doi.org/10.5281/zenodo.23172367
Primary Topic
Safety Systems Engineering in Autonomy
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

HACCP for AI: An Auditable Self-Control Standard for Artificial Intelligence

Simone Paciaroni
Zenodo (CERN European Organization for Nuclear Research)
Safety Systems Engineering in Autonomy
article

HACCP for AI: An Auditable Self-Control Standard for Artificial Intelligence

Simone Paciaroni
article en

Abstract

Almost every serious instrument in AI governance now requires an organisation to run a risk process. None of them tells the organisation where in its own lifecycle the control points sit, what measurable limit applies at each one, what happens automatically when a limit is breached, or who is competent to verify the measurement. That layer, process control, is missing, and it is the layer on which everything else depends. A management system without control points produces documentation; it does not produce safety. This paper supplies that layer by importing a method that has governed an invisible hazard across a globally distributed production chain for more than fifty years: Hazard Analysis and Critical Control Points. The claim is deliberately narrow. HACCP is not proposed as a rival to ISO/IEC 42001, to Article 9 of the EU AI Act, or to the NIST AI Risk Management Framework. It is proposed as the process-control layer their architecture presupposes and does not contain, and as the one methodology in existence with a property AI governance urgently needs and currently lacks: scale invariance. The same seven principles govern a village bakery and a multinational dairy, which is why one inspector, one standard and one accreditation system can cover both. The method is given in the full twelve-step Codex sequence, with a three-tier proportionality rule, deployer, provider, frontier developer, a hazard taxonomy, a control-point decision tree, a catalogue of seven control points, and a taxonomy of limits that separates critical limits from operational limits and indicator thresholds, and reclassifies the compute thresholds now written into law as the third kind. Version 5.0 supplied the instruments: attribute sampling plans with their operating characteristics, statistical process control that gives the operational limit an exact meaning, a seven-step protocol for validating an evaluation as a measuring instrument, and record schemas that make version identity and traceability a matter of implementation. Version 6.0 adds what September 2026 asked for. At the United Nations Security Council the heads of the two largest frontier laboratories called for external evaluators embedded with employee-like access, "similar to a food inspector"; for common standards so that countries can compare evidence and verify compliance; for incident classification and reporting protocols; for a way to measure and pace the automation of AI research; and for standards that preserve meaningful human oversight. Food law has settled forms for each, and this version writes them into the plan: the resident inspector, with the eleven properties the September proposals ask for read against the articles of the European official-controls regulation that already provide them, an inspection record, and a funding model that makes independence enforceable rather than promised; a four-level incident severity scale built on recorded facts, with the statutory clocks in force; the pre-registered safety case as the condition of a training run; measurable pace indicators for self-improvement with slowing and pausing as written corrective actions; and the planted error, the metal-detector test piece of food lines, as the measure of whether human review is real. The instruments of Part II are updated to the 2026 evaluation literature, including evaluation awareness as a threat to validity, and the year's five public incidents are read as deviations, each with the record that would have been required next. The paper states its own limits without softening. The most consequential gap in AI-governance infrastructure is metrological: there is no analogue of ISO/IEC 17025 for capability evaluation, and until there is, independent attestation of a capability-based limit is not available to anyone. One structural disanalogy has no food-safety precedent at all: a pathogen does not model the control system trying to detect it, and a sufficiently capable AI system may. Both are treated as design constraints on the method rather than as objections to be answered later. The framework is accordingly strongest where most AI harm occurs, in organisations that deploy and provide AI systems, and is stated to be aspirational at the frontier until independent measurement exists; the resident inspector is the part of it a frontier laboratory can adopt this year, because its independence can be accredited before its measurements can. This record contains three files: the full paper (version 6.0, 86 pages), a two-page Executive Summary for policy readers, and a 20-page Practitioner Brief containing Part II (the instruments) as a standalone document. Version 6.0 supersedes version 5.0.1 (September 2026); earlier versions remain available under the same concept DOI. CC BY 4.0.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 11%
Safety Systems Engineering in Autonomy
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.