A source someone can inspect
The proof should name where the fact came from: tenant export, policy, incident log, disclosure statement, workflow map, deployment record, or owner attestation.
A public explanation of the evidence PAI looks for across readiness, disclosure, workflow control, and agent deployment records.
This page explains the public proof PAI expects when teams claim an AI system is ready, disclosed, controlled, or safely deployed.
The proof should name where the fact came from: tenant export, policy, incident log, disclosure statement, workflow map, deployment record, or owner attestation.
The proof should say which users, systems, data classes, connectors, and actions are in scope and which are explicitly outside scope.
The proof should identify the approval, logging, review, access, escalation, or rollback control that contains the risk.
The proof should identify who owns the system, who reviews exceptions, and who can change the deployment boundary.
The proof should make clear when it was collected and when it should be checked again.
The proof should support an answer that a buyer, user, journalist, or regulator can understand without reading the whole file.
Licence inventory, Copilot configuration, security posture, sharing settings, DLP posture, and automation footprint.
WorkflowHandoffs, systems, approvals, exceptions, manual steps, and the difference between current and AI-assisted work.
ControlsA before-and-after view that shows which PSF controls improve, degrade, or need explicit mitigation.
DisclosureThe public facts needed to explain where AI is used, what humans review, and what the organisation will not claim.
DeploymentSystem owner, tool access, action limits, evaluation evidence, telemetry, rollback, and incident response.
BenchmarkA public reference point for comparing readiness signals across agent deployment patterns.
The next useful step is collecting inspectable evidence, then linking it to the relevant public record, disclosure, readiness benchmark, or deployment resource.