# Governed AI Development (GAD): The Standardization Track

Atlas North Institute. July 17, 2026. PROVISIONAL working document, not itself normative: venue selections and intellectual-property terms below are candidates pending a counsel-supported IP workstream and a version-dated standards-landscape crosswalk.
Every factual claim below about the GAD corpus is checkable against the named
artifacts; nothing in this document extends the specification.

## 1. What GAD is, in one paragraph

Governed AI Development is a formal specification for making AI-executed work
independently verifiable. A conforming run produces an integrity-linked, signed core bundle that
can be packaged with anchors and later attestations in a versioned
evidence envelope. A separately executable evaluator judges that package
against the protocol's conditions on a different machine, without access
to the producing system. The status of the work stops being a judgment
someone renders and becomes a computation anyone can rerun. The specification
governs its own evolution through a distinct signed
specification-succession procedure defined within the specification
itself (deliberately separate from plan succession, with which it shares
a name and nothing further): every amendment names its predecessor and
successor by digest, and the current document (v1.3) sits at the head of
a seven-record signed lineage that begins with a disclosed, dev-signed
genesis.

## 2. The problem a standard would address

Organizations are delegating consequential work to AI systems faster than
they can verify it. Many current AI-assurance practices still rely heavily on vendor
attestations, screenshots, mutable logs, and organization-level audit
processes. Valuable neighboring work exists (signed attestations,
supply-chain provenance frameworks, transparency systems), but these
artifacts often do not provide a portable, mechanically evaluable record
of one bounded AI-executed run, and two parties often lack a common
protocol for mechanically agreeing on what an exported record supports
about such a run.

GAD's answer is record-level conformance: a bundle either satisfies the
nine record-validity conditions under the named specification, schemas,
registries, keys, and evaluator implementation, or it does not, and the
determination is reproducible by any party holding the bundle, the named
policy, the evaluator implementation, and the public verification
material. Defensibility is a deliberately separate computation under a
named trust policy: required anchors, replay requirements, and an
evaluator independent under that policy. The unit of record-level evaluation is the exported record rather than
the producer's testimony; constructor and operational assurance remain
separate inspection questions. This is the property a standard can carry
that a product cannot: it makes record-level verification a protocol
between parties who need not trust each other's narratives.

## 3. What exists today (the corpus, verified)

Everything below is on disk, cold-verified, and cited by digest.

1. The normative specification, GAD v1.3, sealed at succession-7
   (document sha256 9c31d03f9c29cbf1ab882eb966cfeec7b1a16e37f3f4d5a6907405c9ab975892,
   named as successor by the signed succession-7 record and independently
   recomputed three ways). Session-scoped constructor algorithm, derive-based
   verification candidacy with a fail-closed excluded-node branch, labeled
   sealing lifecycle, and a three-level conformance model (bundle,
   constructor, operational) that refuses to collapse into a slogan.
2. The amendment lineage: seven operator-signed succession records from a
   disclosed genesis, each chain-linked by derivation, each independently
   verifiable by one command (succession-verify, strict mode). No
   in-place edit has been recognized as a valid specification successor.
3. The separately executable evaluator (gad-evaluate): schemas compiled strict, a
   meta-validated transition table (12 valid traces accepted, 24 invalid
   rejected), predicate and evidence-strength registries, and a policy
   overlay. It runs from a bundle and public keys alone.
4. Demonstrated record classes, each judged VALID by the separately executable evaluator on a second machine
   and operating system, each falsified by a one-byte flip:
   the ungated multi-node class (run 20, root bf7ab081..., live RFC 3161
   anchor); the remediation class (a failed check, debugged and re-verified,
   legal in the witness); and the gated class (run 36, root 042a3d6f...,
   typed principal-signed gate entries, R7 evaluated, keys taken from the
   bundle's own export).
5. Trial 0: a four-movement conformance trial closed by a ratification
   manifest signed under the operator authority key and anchored by an RFC
   3161 token (imprint 27d1eff7...), with a finalized conformance matrix,
   the exact evaluator output bound by digest, and a bound byte-flip
   counterexample. Scope stated inside the signed bytes: record-level
   results only.
6. The findings register: 64 entries, every defect and its author named,
   every closure citing its evidence, external review findings catalogued
   with their dispositions. Four disclosed cross-model review rounds of the ratification package and three of the specification itself (adversarial review passes executed by a frontier AI system, labeled as such; they are not the independent human review Phase 5 names), every finding either discharged by a signed succession or registered open with a closure condition.
7. A reference constructor stack (orchestration engine plus desktop
   supervisor) that has produced specifically identified records accepted
   as bundle-conformant by the evaluator, including the
   gate plane, the between-sessions verifier, and the sealed-record
   inertness guard. Per the specification's own Section 12A, the reference
   stack holds no privileged status: conformance is per-record, permanently.

## 4. Why this is standards-shaped

Most specifications arrive at standards bodies as prose plus intentions. GAD
arrives with the properties committees exist to demand:

1. Separately executable evaluation. The evaluator needs the bundle, a policy, and public keys; it does not need the constructor, the operator, or the authoring organization. Independence beyond separability is a named-policy condition inside defensibility, and the specification keeps that distinction explicit.
2. Falsifiability. Every VALID verdict in the corpus is paired with a
   demonstrated counterexample: flip one byte, the verdict flips, exit
   nonzero. A conformance claim that cannot fail is marketing; these can.
3. Versioned change control that is itself auditable. The succession
   mechanism is a working, cryptographically enforced predecessor of a
   standards body's change process: signed amendments, explicit succession
   classes, a public register of findings, and a document that cannot be
   validly superseded through unrecorded in-place editing, even by its
   authors.
4. A conformance program in embryo. The three conformance levels, the record
   classes with live exemplars, the fixture suite, and the register's
   closure conditions are the skeleton of a test program a body could adopt
   nearly as-is.
5. Honest scope. The specification's own header labels all results
   Propositions and Claims pending independent formal and cryptographic
   review, and the ratification manifest binds that scope into the signed
   bytes. A standard that begins by stating what it does not claim is a
   standard reviewers can trust.

## 5. What GAD does not claim (and a standard must not)

Record-level conformance does not establish that the work inside a record is
good, that a constructor is conformant in general, that an operator's
processes are sound, or that the evaluator itself is correct. The first is a
human judgment; the second and third are separate conformance levels
requiring their own inspection; the fourth is precisely what independent
review (Phase 5) exists to test. Any standardization effort inherits these
boundaries verbatim.

## 6. The standardization strategy, in three stages

The venue question is secondary to the readiness question, so the strategy
runs incubation before institution.

### Stage 1 (now through Phase 5): open publication and independent review

1. Complete an IP and licensing workstream, with standards and IP counsel,
   to select terms compatible with the intended incubation and formal
   venues. Candidate posture, to be validated rather than assumed: the
   specification and companion documents under CC BY 4.0; the evaluator,
   schemas, fixtures, and reference tooling under Apache-2.0; a written
   patent non-assertion covenant. Different venues impose different
   incoming and outgoing rights regimes (the RFC Independent Stream, for
   one, applies its own), so terms are chosen against the venue, not
   before it. Unclear ownership, incompatible licenses, or undisclosed patent claims
   can obstruct contribution and adoption; settle the intended rights
   posture, in writing, before selecting a venue.
2. Commission Phase 5: independent formal review (the transition table, the
   algorithm, the conditions) and independent cryptographic review (the
   canonicalization, the chain construction, the signature and anchor
   scheme). Reviewers who owe the project nothing, findings folded into the
   register in public, discharges by succession. Two to three reviewers with
   published reports is the credibility floor.
3. Close the two standing internal rulings (the anchor-class policy question
   and the gated-dependents commissioning semantics) so the document a body
   receives has zero known open design questions.
4. Land the constructor-manifest binding so the concrete
   candidacy-derivation procedure is mechanically identified in each
   record and can be assessed end to end under the published
   constructor-conformance protocol.

### Stage 2 (incubation): a second implementation and a community venue

1. The single strongest standardization argument is a second, independent
   constructor producing records the same evaluator accepts. Recruit or fund
   one; the specification's Profile One and the published fixtures are the
   on-ramp. Interoperability evidence outranks eloquence at every body.
2. Incubate in a lightweight open venue whose IPR regime is designed for
   exactly this: a W3C Community Group, or an open-governance home of the
   Linux Foundation type. The goal of incubation is not prestige; it is a
   public issue tracker, a multi-party contributor base, and an IPR pool,
   all of which formal bodies check for.
3. Rename internal instruments outward: the findings register becomes the
   public errata and issues process; successions become the published
   change-control policy; the record classes become the conformance test
   suite's chapters.

### Stage 3 (institution): the formal submission

Choose by audience, not by brand:

1. IETF, two distinct paths that must not be conflated: an Independent
   Submission RFC (Informational or Experimental) provides permanent,
   citable technical publication but carries no community consensus and is
   explicitly not an IETF standard; standards-track status requires
   demonstrated community interest and, realistically, a chartered working
   group. GAD's envelope, canonicalization, and evaluation flow read
   naturally as an RFC either way, and RFC 3161 anchoring already lives in
   that world. The honest sequencing is Independent Submission for
   permanence, standards-track only if a community forms.
2. ISO/IEC JTC 1/SC 42 (artificial intelligence), if the target audience
   is regulators and enterprise procurement. Entry is a process, not a
   submission: explore the pathway through ANSI and the appropriate U.S.
   mirror committee, beginning with a version-dated standards-landscape
   review and a stakeholder coalition; a New Work Item Proposal is voted
   by national bodies, and a PAS route is a committee decision with
   defined conditions. The claim GAD brings is specific and must be
   demonstrated by clause-level crosswalk, not asserted: a mechanically
   checkable, record-level conformance object that management-system
   standards can reference as evidence.
3. OASIS and IEEE evaluated genuinely rather than listed as alternates:
   IEEE requires a sponsoring Standards Committee and an approved Project
   Authorization Request and may be more accessible than commonly assumed;
   OASIS offers member-driven technical committees with well-defined IPR
   modes. A W3C Community Group remains a candidate incubation venue with
   a transition-friendly IPR structure, with the caveat that its reports
   are not standards and its fit depends on GAD attracting a
   Web-agent-adjacent community.

The working hypothesis, to be validated during incubation, is archival IETF-stream publication for the wire and record formats alongside an explored SC 42 pathway for the conformance and governance framing; venue commitments are made after the IP workstream and landscape crosswalk, not before.

## 7. The submission artifact set (what a body receives on day one)

1. The normative specification (v1.3 lineage head) with its succession
   records and verification tool.
2. The schemas, transition table, and registries, each hash-identified.
3. The reference evaluator with its test suite and the published record
   fixtures (valid and invalid, including the byte-flip counterexamples).
4. The conformance matrix and ratification manifest as the model for
   record-level conformance claims, with the scope language as normative
   boilerplate.
5. A security considerations document derived from the register: the threat
   model the conditions answer, the key custody rules, the anchor classes,
   and the known-limitations inventory, each with its register citation.
6. The change-control policy (successions), the errata process (the
   register), and the IPR declarations.

## 8. Governance and stewardship

Atlas North Institute remains the specification's editor through incubation,
with change control exactly as practiced: no in-place edits, signed
successions, public register. On acceptance into a formal process, editorial authority and change
control would transition according to that body's rules and the
applicable contribution terms, while the pre-transfer succession lineage
remains the permanent provenance record. Reserve the GAD name
and mark early; a standard's name is infrastructure.

## 9. Milestones and exit criteria

1. M1, IP settled: licenses applied, covenant published. Exit: a third party
   can implement without asking permission.
2. M2, Phase 5 complete: at least two independent HUMAN formal or cryptographic review reports published (cross-model review passes, however adversarial, do not satisfy this milestone),
   all findings registered, blockers discharged by succession. Exit: the
   Propositions-and-Claims qualifier can be narrowed for the reviewed
   claims.
3. M3, second implementation: an independent constructor's record evaluates
   VALID under the unmodified evaluator. Exit: interoperability demonstrated.
4. M4, incubation venue live: public tracker, multi-party contributions,
   IPR pool. Exit: the project survives without its founder in the loop for
   a release cycle.
5. M5, formal submission accepted into a body's process. Exit: GAD has a
   designation someone else's procurement document can cite.

## 10. The honest close

GAD's claim to standardhood does not rest on ambition. It rests on a corpus
that already behaves the way standards must: versioned by signature,
falsifiable by construction, evaluated by strangers, and honest in its own
text about what remains unproven. The remaining known work is primarily validation, interoperability,
stewardship, and institutional adoption, and this document is the map
across it. Phase 5 remains intentionally capable of discovering
conceptual, formal, or cryptographic defects that the current review
loop did not see; that possibility is the point of commissioning it.
