The Authorization Artifact Test
Two Questions for Ex-Ante AI Governance
An ex-ante regulatory regime requires more than evidence that a system behaved appropriately. It requires a verdict that exists before consequential action and can be reviewed independently of the system that proposed that action. This article introduces the Authorization Artifact Test, a two-prong instrument for determining whether a candidate AI governance architecture can, in principle, satisfy that requirement.
The full paper is published on Zenodo: doi.org/10.5281/zenodo.20013583. It supplements the formal impossibility result established in On the Impossibility of Observability-Based Authorization (Meyman, 2026; doi.org/10.5281/zenodo.19647542). This article summarizes the test and its regulatory consequences.
Why a New Test Is Needed
The AI governance market is saturated with architectures described as guardrails, monitoring systems, observability platforms, and human-in-the-loop review. Each of these can be valuable for risk management, incident detection, and post-execution review. None of them, by structural class, can produce the authorization artifact that an ex-ante regulatory regime requires.
The companion paper establishes this as a formal impossibility result. Observability architectures observe what an AI system has produced, inferred, attempted, scored, or self-evaluated. Their outputs are causally posterior to the actions they would authorize, and their verdicts cannot be reconstructed without access to the governed system. Two structurally independent failure modes, each fatal to the regulatory requirement.
The Authorization Artifact Test operationalizes that result. It does not introduce new doctrine. It identifies, in operational form, what existing regulatory regimes already require.
The Test
The test asks two questions, in this order:
Prong One: Pre-Execution Emission
Is the authorization artifact emitted prior to the execution of the action it authorizes?
The artifact must exist before the action it authorizes. A record produced after execution is evidence. A signal produced during execution is control or interruption. Neither is an authorization artifact in the ex-ante sense.
A negative answer disqualifies the architecture. A positive answer is necessary but not sufficient.
Prong Two: Independent Verifiability
Can a third party reconstruct the verdict from the policy, the context, the proposed action specification, and the artifact alone, without observing or instrumenting the governed system?
The artifact must be reconstructable by a third party in possession of policy, context, proposed action specification, and the artifact itself, without access to the governed system. If verification requires observing the model, replaying the model, inspecting its internal states, reproducing its traces, or trusting its self-assessment, the requirement is not met.
A negative answer disqualifies the architecture even if Prong One is satisfied.
Composite Test
The composite test combines both prongs:
Does the architecture produce an artifact that exists before execution and is reproducible without access to the governed system?
If the answer is no, the architecture cannot satisfy an ex-ante authorization requirement, regardless of latency, automation, sophistication, or vendor description.
What the Test Classifies
The test is categorical. It classifies architectures by function, not by label.
Architectures that fail the test:
- Output monitoring and observability stacks. Records of what the model did, not verdicts reconstructable without access to the model. Fail at Prong Two, typically also at Prong One.
- Guardrail and filter layers. Halting execution upon observation is not equivalent to producing an ex-ante authorization verdict. The artifact, if any, is generated after the model has produced the candidate. Fail at Prong One.
- Human-in-the-loop review of system outputs. A human reviewer who confirms or rejects a model's proposed action on the basis of records produced by observing the model is exercising observational review. The structural problem does not change.
- Self-evaluating models. A model that evaluates its own outputs against internal rules is observing itself. The signal is downstream of the model's generative process. Fail at Prong Two.
Architectures that pass:
- Enforcement architectures. Systems that interpose a non-bypassable authorization gate between proposed action and execution, evaluate the proposed action against externally specified policy without observing the model's generative process, and emit a verdict reconstructable from policy, context, and proposed action specification.
The label assigned to the architecture is immaterial. An architecture described as an AI governance platform, a policy enforcement system, an AI safety layer, or a compliance assurance suite must answer the same two questions. The description does not substitute for the answer.
Mapping to Existing Regulatory Regimes
The test is regime-neutral. It restates a structural requirement that ex-ante regimes impose under varying statutory formulations. The full paper provides detailed mappings; the summary below indicates where the structural requirement is lodged in each regime.
EU AI Act, Article 14 (Human Oversight)
Effective oversight, in the regime's structural sense, requires that the overseer be in a position to intervene before consequential action, on the basis of a verdict the overseer can independently evaluate. A monitoring layer that surfaces outputs to a human reviewer after generation places the human in the position of confirming an action the system has already produced. This is not the human oversight Article 14 contemplates.
GDPR, Article 22 (Solely Automated Decision-Making)
The right to contest a solely automated decision presupposes that the decision can be reviewed. Review, in the ex-ante sense, is review of a verdict over a defined decision space, not review of the system's internal states. An observability architecture produces records of what the system did. It does not produce a verdict in the regime's sense.
HIPAA Security Rule (45 C.F.R. § 164.312)
Access control under § 164.312(a) requires that access decisions be authorized rather than merely recorded. An audit-control mechanism that captures the system's actions for retrospective review does not, by itself, perform access control. Access control is a pre-execution determination of permissibility.
DFARS 252.204-7012
The clause incorporates NIST SP 800-171 access-control obligations. A contractor architecture that does not produce a pre-execution verdict reconstructable by a third-party assessor cannot satisfy the access-control obligation in the ex-ante sense the clause contemplates.
NIST AI Risk Management Framework (GOVERN Function)
The AI RMF is voluntary guidance, not an ex-ante regime. As GOVERN-function guidance matures and as federal procurement increasingly references the AI RMF, the structural requirement that authorization decisions be reviewable independently of the model becomes operationally relevant.
Why the Mappings Hold
The mappings rest on a structural reading of each regime: that ex-ante authorization is the only reading consistent with the regime's operative purpose.
Human oversight under EU AI Act Article 14 that arrives after consequential action is not oversight in any operative sense; the overseer cannot intervene in an action already executed. Contestability of decisions under GDPR Article 22 whose basis cannot be reconstructed is not contestability; the data subject cannot contest a verdict no third party can reproduce. Access control under HIPAA § 164.312(a) that admits unauthorized actions and reviews them later is logging, not control. The same structural reading applies to DFARS 252.204-7012.
A reading that makes ex-ante authorization optional reads down the regime's operative purpose. The structural reading is the reading that preserves the regime's effect.
Consequences for Ex-Ante Regulatory Practice
The structural result has consequences for the architectures that regulatory regimes encounter. These consequences hold a priori, before any deployment is observed, and apply uniformly across any ex-ante regime imposing the structural requirement.
Observability does not satisfy authorization obligations. Architectures that monitor, log, score, classify, filter, or retrospectively review system behavior do not thereby satisfy ex-ante authorization obligations. The conclusion is independent of latency, accuracy, automation, or sophistication.
Intervention does not substitute for authorization. The ability to halt, block, interrupt, or escalate execution after detecting a condition does not constitute authorization. Intervention may prevent an action from completing. It does not establish that the action was permitted under governing policy before execution.
Human review does not cure observational dependence. Human involvement does not convert an observability architecture into an authorization architecture when the human operates on system-generated records. Human review satisfies the requirement only when the human operates within the authorization procedure itself, before execution, and the resulting verdict is incorporated into an independently verifiable artifact.
Authorization requires enforcement architecture. This requirement is satisfied only by an architecture that evaluates proposed actions against externally specified policy before execution, without deriving the verdict from observation of the governed system's generative process. No combination of monitoring, filtering, escalation, signing, logging, or retrospective review supplies this missing structure.
The Requirement Is Current, Not Aspirational
The structural requirement identified by the Authorization Artifact Test is the requirement currently imposed by the regimes mapped above. It is not a future requirement, an aspirational standard, or a target toward which industry practice is to evolve. The regimes are in force.
Transition arrangements, proportionality readings, and feasibility deferrals do not redefine the requirement. They defer the moment at which the requirement is enforced. Once the impossibility result is part of the record, acceptance of observability-grade architectures as satisfying ex-ante authorization requirements is no longer merely a permissive interpretation. It becomes an approval of an architecture that, by formal result, cannot produce the artifact the regime requires. The approval is traceable to the date on which the impossibility result entered the record.
The Authorization Artifact Test does not impose a new obligation. It identifies, in operational form, what existing obligations require.
Operational Use
The test is short enough to be posed in any consultation, hearing, audit, or conformity assessment. Its function is classificatory.
- In regulatory assessment and conformity evaluation, the test supplies a threshold inquiry. If either condition is absent, the architecture does not satisfy an ex-ante authorization requirement.
- In standards development and regulatory guidance, the test distinguishes evidence-generating architectures from authorization-producing architectures. Standards that purport to require authorization must specify properties consistent with both prongs.
- In regulatory consultation and policy design, the test clarifies whether a proposed requirement imposes an ex-ante authorization obligation or a post hoc accountability obligation.
- In evaluation of architectural claims, the test provides a neutral basis for classification. The label assigned is immaterial.
For practical use, the test reduces to two questions:
First, before execution, is there a verdict?
Second, can that verdict be independently reconstructed without access to the governed system?
If the answer to either question is no, the architecture is not an ex-ante authorization architecture.
Two Statements That Summarize the Distinction
Across the FERZ research corpus, two statements compactly state the structural distinction the test operationalizes:
Observability explains what happened. Enforcement determines what is allowed to happen.
Enforcement is realized through a non-bypassable authorization boundary that emits a proof-carrying decision prior to execution.
The Authorization Artifact Test asks regulators, assessors, and standards bodies to apply this distinction in the cases that come before them. It does not ask them to adopt a framework, endorse a methodology, or accept a vendor's account of its own architecture. It asks two questions that, taken together, are dispositive.
Read the Full Paper
The complete regulatory application note, including the full regime mappings, the structural-reading argument, and the operational deployment guidance, is published on Zenodo:
The Authorization Artifact Test: Applying the Impossibility Result to Ex-Ante Regulatory Regimes Edward Meyman. FERZ, Inc. May 2026. DOI: 10.5281/zenodo.20013583
The companion technical note, which establishes the formal impossibility result the test operationalizes, is also on Zenodo:
On the Impossibility of Observability-Based Authorization: A Formal Impossibility Result for Ex-Ante AI Governance Edward Meyman. FERZ, Inc. April 2026. DOI: 10.5281/zenodo.19647542
Both papers are part of the FERZ research program on deterministic AI governance. The full corpus is available at the FERZ Zenodo community.
