No instrument below names a vendor, and none yet mandates independent attestation. What they converge on is verifiable, tamper-evident records of AI system behaviour — and a self-attested log cannot satisfy a verifiability requirement. Stated as written, not as we might wish.
High-risk AI systems must technically allow automatic logging sufficient for post-market monitoring. Logging is mandated; log integrity is the open question. High-risk obligations apply from 2 December 2027.
Per-decision attestation with consensus timestamps; Annex IV technical-documentation packages with signed sidecars; the auditor portal for independent retrieval. POST /v1/tiered-attest · POST /v1/attest
Generative and agentic AI sit outside the guidance's formal scope as "novel and rapidly evolving"; institutions' own risk management and governance must cover them, and unsafe-or-unsound exposure remains.
Model-risk evidence reports mapped to supervisory expectations; tamper-evident decision records a bank can produce to its examiner without asking Rubric's permission. POST /v1/export/report
The first US statutory hook for machine-verifiable claims about AI systems: disclosures must be produced in a format machines can parse and check.
OSCAL 1.1.2 export per attestation and W3C Verifiable Credentials — machine-readable and machine-verifiable. GET /v1/attestations/:id/oscal
Security planning moves to machine-readable OSCAL, with signed artifacts as the evidentiary basis for authorization decisions.
Native OSCAL 1.1.2 export; ML-DSA-65-signed artifacts; NIST AI RMF evidence certificates issued only against non-empty evidence sets. GET /v1/attestations/:id/oscal
The Buch letter to significant-institution CEOs (with an ESRB systemic-risk warning alongside) demands AI-risk action plans, third-party risk management "fit for purpose," comprehensive logging as a baseline control — and names post-quantum cryptography as a strategic investment that must begin immediately.
Post-quantum by default: every attestation is ML-DSA-65 (FIPS 204) signed. Real-time SIEM delivery for the logging baseline: Splunk HEC, Elastic webhooks, CEF. POST /v1/webhooks
Records with a certified process or digital identification can be admitted without a witness on the stand.
Evidence reports issued to the self-authenticating standard, with SHA3-256 sidecars and ledger anchors any party can check. POST /v1/export/report
A 2026 formal-methods analysis (arXiv:2604.24890; IACR 2026/804) showed RFC 3161 timestamps can be substituted undetected and expiring certificates strand archives. The remediation the researchers propose is the durable-timestamp pattern Rubric runs on Hedera.
Conformance in review; Trust List signing follows approval. The Hedera anchor-assertion schema is a funded, published deliverable of our current roadmap.
This page states what each instrument requires as written and what Rubric ships today — nothing is labeled live that isn't. For the underlying analysis, see The Attestation Brief; for verification of any claim, no permission is needed: every attestation resolves to Hedera topic 0.0.10416909.
Request sample evidence Documentation Verify a recordEchelon Intelligence Group LLC · rubric-protocol.com · The proof outlives the company that made it.