Certification Is Not Runtime Authorization
AI governance is assigning greater weight to standing conformity determinations. Under the EU Artificial Intelligence Act, providers must subject high-risk systems to the applicable conformity-assessment procedure before placing them on the market or putting them into service.¹ For many Annex III systems, that procedure is internal control rather than third-party certification. ISO/IEC 42001 specifies requirements for AI management systems, while ISO/IEC 42006 specifies additional requirements for bodies that audit and certify those systems.² These instruments can carry legal, contractual, or institutional consequences, depending on the regime. This article is about what those consequences establish.
A note on scope before anything else. This article uses "deployment certificate" as shorthand for one member of a broader class: a standing, scope-bound determination concerning a certified referent. That referent may be an AI system, a defined configuration or deployment, an organization, or an AI management system. Particular regimes may call the resulting status a license, approval, authorization, conformity status, or certificate. Some regimes expressly denominate their standing permission as an authorization, which is why the title carries a qualifier. The controlling features are the instrument's referent and temporal effect, not its label.
Certification establishes standing eligibility. Runtime authorization determines whether a specific proposed act may cross the execution boundary. The claim defended here is narrow and, we believe, decisive. Enforcement of standing eligibility does not, without an additional runtime dependency, produce an independently reconstructable pre-execution verdict over a specific proposed act.
What a certificate answers
Governance architectures answer distinct questions at distinct layers. Authority determines who may authorize. Authorization determines whether a specific proposed action is permitted. Enforcement determines whether that authorization governs execution.³ No answer at one layer satisfies the question at another.
A standing-status determination in this class has a characteristic shape. Its object is a certified referent: an AI system, a defined configuration or deployment, an organization, or an AI management system. Its output is a status concerning that referent. Where an applicable regime makes that status a condition of operation, market access, or participation, it functions as standing eligibility. Its temporal effect is standing: the status holds until it lapses, is suspended, is restricted, or is withdrawn.
A runtime action-release determination has a different shape on all three dimensions. Its object is a specific proposed action. Its output is an action-bound release result. Its temporal effect is pre-execution and exhausted in the release or refusal of that act. In its deterministic-governance-conformant form, the determination resolves within ALLOW, DENY, or ABSTAIN and produces evidence sufficient for independent reconstruction.
These are different instruments. Neither is a defective version of the other. A standing status is not exhausted by a single action, and an action verdict does not by itself establish standing eligibility. The instruments may supply inputs to one another, but either composition requires an additional decision rule. The error this article addresses is not certification itself. It is the treatment of a standing status as if it answered the action question.
The two-layer control pattern
Three established high-consequence regimes illustrate a recurring two-layer pattern: the separation of standing eligibility from event-specific release controls. Each is stated here at the structural level and analyzed in full in the companion paper.
In U.S. Part 121 domestic and flag operations, a certificate holder prepares a dispatch release for each flight. The pilot in command and an authorized aircraft dispatcher sign only if both believe the flight can be made safely.⁴ The aircraft's eligibility to operate does not replace that release.
In regulated hospital settings, FDA approval governs marketing of a drug for approved uses, but it does not itself authorize administration to a particular patient. Federal hospital rules require drugs and biologicals to be prepared and administered under authorized practitioner orders and applicable administration controls.⁵ Those orders may include qualifying standing orders and protocols, so the example demonstrates a patient-specific control layer, not necessarily a fresh verdict for every dose.
In a typical card-network transaction, an authorization request is routed to the issuer, which approves or declines it and returns the result before subsequent clearing and settlement.⁶ Network participation does not itself decide the transaction.
These regimes illustrate a recurring control pattern: standing eligibility and action-specific release answer different questions. The comparison concerns the existence and object of the pre-event determination, not equivalence of enforcement mechanisms. The pattern is not universal, and this article does not claim it is. It appears where the cost of a single wrong action is high enough that eligibility alone was judged insufficient, and in each case the response was to add a control that operates closer to, and is more specific to, the governed event.
That is the pattern against which the certification turn in AI governance should be read. When certification is presented as sufficient governance, the unresolved question is whether each effect-bearing action must still clear a runtime authorization boundary.
Status enforcement is not action release
It would be a mistake, and an unfair one, to say that certification lacks enforcement. It has two kinds, and both deserve credit before the distinction is drawn.
The first kind operates through consequence. A system operating without required conformity status may face market exclusion, legal exposure, contractual consequence, or some combination of the three. This is real pressure, and in many settings it is sufficient pressure. It is also, in architectural terms, deterrence: compliance induced by changing the expected cost of noncompliance, not by making an affirmative action-bound result a precondition of execution. We have addressed that structure elsewhere and will not repeat the argument here.⁷
The second kind is direct. Credential status can be enforced technically. Infrastructure can validate a credential at deployment, at startup, or at an access boundary, and refuse operation when the credential is invalid, expired, or revoked. That is direct enforcement, it can be fail-closed, and it should be named accurately: direct enforcement of standing eligibility.
Credential validation can become runtime authorization, but only when the proposed act is itself an input to the decision, the act is evaluated against the credential's scope and applicable policy, and execution depends on an affirmative action-bound result. At that point, the architecture is no longer enforcing standing status alone. It has added the runtime dependency described here.
Where certification operates through market or legal consequence, its enforcement is deterrent. Where infrastructure rejects an invalid credential, it is direct status enforcement. If the architecture stops there, a system with valid standing may execute an action for which no action-specific release result exists. The credential may be current, valid, and strictly enforced while remaining silent on whether the proposed action was evaluated before release.
The test is functional, not nominal. If the proposed action is not an input to the pre-execution determination, valid standing alone cannot establish an action-specific authorization verdict. If the proposed action is an input, the action is evaluated against applicable policy and authority state, and execution is unavailable without an affirmative action-bound result, the architecture has added runtime authorization, whatever it calls the instrument.
That classification does not by itself establish deterministic-governance conformance. It establishes the action-bound, pre-execution release dependency. The control may still lack deterministic evaluation, the ALLOW/DENY/ABSTAIN verdict space, established provenance for the inputs grounding the result, or evidence sufficient for independent reconstruction.
Changes to standing do not answer the action question
The strongest reply available to the certification position is revocability. If the credential can be withdrawn, the argument runs, then standing permission is continuous rather than episodic, and the status tracks the certified referent's continued conformity over time.
Revocability does make status mutable; it does not by itself make assessment continuous. Expiration, suspension, restriction, and withdrawal are distinct ways in which standing may change, and monitoring or reassessment may provide the evidence for that change. None produces an action-bound release result without an action-bound check. Unless release of each proposed action depends on a contemporaneous affirmative action-bound result, the credential still does not establish that the particular action was authorized before execution.
Where standing changes on observed degradation, a further structural limit applies. The evidence that triggers the change is causally posterior to the behavior that produced it. A signal generated by completed behavior can ground consequences for the future. It cannot supply the pre-execution determination that authorization requires for the actions already taken.⁸ That limit attaches to the behavior-triggered case, and this article claims no more than that.
Status outcomes and action verdicts
Certification regimes are not naive about uncertainty. A certifying body may deny, suspend, defer, or condition standing status when evidence is insufficient, and a regime that withholds status pending adequate evidence is failing closed at the status level. That capability is real and should not be argued away.
ABSTAIN is different by object, not by caution. ABSTAIN blocks execution pending authorized human override. Escalation follows from ABSTAIN; it is not a fourth verdict.⁹ If an override is given, it is attributable and recorded. Failure to complete authorization does not become permission for the act.
A deferred standing-status determination leaves the certified referent without the required standing status for the defined scope. An ABSTAIN verdict leaves a proposed action unexecuted. The first is a judgment about the certified referent's standing. The second is a refusal at the boundary where a particular act would have become real.
Certification, authorization, and observability compose
None of this is an argument against certification, and it is not an argument that runtime authorization replaces it. The functions compose, and each does work the others cannot.
Within deterministic-governance-conformant authorization, where certification is required, current credential status can be one governed input. A required standing status that is absent or not valid for the proposed action makes ALLOW unavailable: the runtime boundary treats the absent or invalid credential as a reason no action of the governed class may proceed. Standing eligibility becomes a premise the verdict depends on, evaluated at the moment it matters.
Deterministic-governance-conformant authorization, in turn, produces an authorization artifact bound to the proposed action, the relevant inputs and their established provenance, the applicable policy and version state, the authority chain, the authorization time, and the pre-execution verdict. That package permits an independent third party to reconstruct why the verdict was produced without access to the governed AI system.
And observability remains necessary for what neither of the others establishes: what occurred, whether performance drifted, and what downstream effects followed.
Where a regime requires standing eligibility, action-specific release, and post-execution evidence, the three functions should be assigned separately. Current standing may be an input to the conformant runtime verdict. The authorization artifact establishes what was permitted before release. Observability establishes what occurred afterward. None should be presented as another.
The narrower claim
Authorization is not infallible. Policies can be incomplete, inputs can be wrong, and implementations can fail. The deterministic-governance-conformant instrument defended here is narrower: execution is conditional on an affirmative pre-execution verdict, and failure to complete authorization does not become permission.
The certification turn establishes a legitimate governance requirement: a standing status capable of being denied, suspended, restricted, or withdrawn. That status supplies one layer of the control structure. It does not, without an additional runtime dependency, produce an independently reconstructable pre-execution verdict over a specific proposed act.
A certificate binds the deployment. A verdict binds the act.
This article states the distinction. Its formal treatment, including instrument definitions, the scoped-credential objection, and sourced analysis of the aviation, clinical, and payment regimes, is given in the companion paper: Standing Eligibility versus Runtime Authorization (2026). DOI: 10.5281/zenodo.21941657.¹⁰
FERZ, Inc. builds deterministic runtime authorization infrastructure for AI systems in regulated industries. This article presents a category analysis and does not describe a FERZ product.
Notes
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 43 (conformity assessment). OJ L, 2024/1689, 12.7.2024, as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026.
- ISO/IEC 42001:2023 (Information technology — Artificial intelligence — Management system); ISO/IEC 42006:2025 (Information technology — Artificial intelligence — Requirements for bodies providing audit and certification of artificial intelligence management systems).
- Meyman, Edward (2026). Authority versus Authorization. FERZ, Inc. Zenodo concept DOI: 10.5281/zenodo.21341907.
- 14 C.F.R. § 121.663 (responsibility for dispatch release: domestic and flag operations); see also 14 C.F.R. §§ 121.593–121.597 (dispatching and flight release authority, including flight releases for supplemental operations).
- 42 C.F.R. § 482.23(c) (hospital conditions of participation: preparation and administration of drugs under practitioner orders; qualifying standing orders, order sets, and protocols per § 482.24(c)(3)); U.S. Food and Drug Administration, Understanding Unapproved Use of Approved Drugs "Off Label."
- Susan Herbst-Murphy, Clearing and Settlement of Interbank Card Transactions: A MasterCard Tutorial for Federal Reserve Payments Analysts, Payment Cards Center Discussion Paper No. 13-02, Federal Reserve Bank of Philadelphia, October 2013.
- Meyman, Edward (2026). Deterrence Is Not Authorization: On Sanction-Based Institutions and the Pre-Execution Authorization Boundary in Deployed AI Systems. FERZ, Inc. Zenodo concept DOI: 10.5281/zenodo.21825696.
- Meyman, Edward (2026). On the Impossibility of Observability-Based Authorization: A Formal Impossibility Result for Ex-Ante AI Governance. FERZ, Inc. Zenodo. https://doi.org/10.5281/zenodo.19647542
- Meyman, Edward (2026). A Taxonomy of AI Governance Approaches: Distinguishing Visibility, Alignment, and Authorization, v1.7. FERZ, Inc. Zenodo. https://doi.org/10.5281/zenodo.18275969
- Meyman, Edward (2026). Standing Eligibility versus Runtime Authorization (v1.0). FERZ, Inc. Zenodo. https://doi.org/10.5281/zenodo.21941657
