The bar for defensible AI evidence.
The Digital Integrity Institute is a neutral standards body for AI evidence. It defines what makes an AI decision record defensible, and it assesses records against that definition, independent of any vendor that builds them. It defines the bar. It does not decide admissibility, which is the court's job.
What DII is
A neutral standards body for AI evidence. It defines what makes an AI decision record defensible, and it independently assesses records against that definition. It is the layer above the vendors that build and hold the record. It does not build, sell, or operate those systems.
What DII is not
DII does not declare evidence "admissible." Courts decide admissibility under the rules of evidence. DII defines defensibility criteria, the properties a record needs to stand up under challenge, and maps them to the reliability standards the legal system already applies (Federal Rule of Evidence 702, the Daubert factors, and the proposed Rule 707 for machine-generated evidence). It issues criteria and independent assessments, not verdicts.
Four neutrality rules, stated openly
These are the rules that make a standards body trustworthy, and the ones self-certification fails. DII holds itself to them from day one.
1. No issuer-pays
DII takes no payment from a party in exchange for certifying that party's record. The standard is developed and maintained independently of any verification decision. This is the exact conflict, the credit-rating issuer-pays model, that self-certified AI evidence otherwise reproduces.
2. Structural independence
DII is independent of any commercial firm that builds, sells, or delivers AI-evidence products or services, including HaystackID. DII recuses itself from assessing records tied to any entity it is not independent of.
3. Open by default
The standard is published openly under Creative Commons (CC BY 4.0), versioned, and free to adopt, extend, and adapt with attribution. A standard you must pay to read is not a standard.
4. Verifiable by outsiders
The criteria are testable by any independent party. The standard's authority comes from being reproducible, not from DII's say-so.
v0.1 is a working draft, published to invite the builders and practitioners converging on this problem to pressure-test and contribute. The governance body and contributor process are being built in the open. This is an invitation, not a finished institution.
The Defensibility Rubric
Score any AI decision record, yours or a vendor's, against 10 defensibility criteria.
How to use it
Take one AI decision record, the artifact your system produces when AI touches a consequential decision. Score it against each criterion: Absent (0), Emerging (1), Defensible (2). The result is a profile, not a badge. A record is only as defensible as its weakest load-bearing criterion, so read the low scores first.
| # | Criterion | The question it answers | Reliability anchor (illustrative) |
|---|---|---|---|
| 1 | Provenance capture | Does the record capture the model, version, inputs, the identity that ran it, and whether a human reviewed it? | FRE 702(b): sufficient facts/data |
| 2 | Structural capture (pre-action) | Was the record created at the moment of the action, not reconstructed afterward from whatever logs survived? | Daubert: reliable method, reliably applied |
| 3 | Independent authority / tamper-evidence | Is the record held or sealed by an authority the actor can't edit after the fact, with alteration detectable? | Chain of custody; FRE 901 authentication |
| 4 | Identity integrity | Does "who ran it" resolve to an independently-verifiable identity, not a spoofable or reusable credential? | FRE 901: authentication of the actor |
| 5 | Temporal integrity | Can you prove the record existed before the consequence bound (no backdating)? | Reliability; ESI timestamp discipline |
| 6 | Third-party verifiability | Can a party independent of the producing system verify the record without trusting the issuer? | Daubert: testable by others |
| 7 | Corroboration, not self-attestation | Are the record's key claims corroborated by something the producing system couldn't manufacture? | The "interested party's account" problem |
| 8 | Reproducibility of context | Can you reproduce the exact policy version, inputs, and state as they existed at decision time, not today's state? | Daubert: known method + error conditions |
| 9 | Completeness / fail-closed | Does the record show nothing material was omitted, or does the system fail closed rather than silently drop steps? | FRE 702(d): reliably applied to the facts |
| 10 | Portability / open expression | Is the record expressed in an open, versioned form that survives migration off the vendor that produced it? | Evidence independence |
The Defensibility Floor
A record's floor is its lowest score on criteria 3, 4, 6, and 7, the four that decide whether it survives a hostile challenge: independent authority and tamper-evidence, identity integrity, third-party verifiability, and corroboration. A high average with a zero on any of those four is a record that looks authenticated and isn't. Read the floor before the average.
What this is not
Not a certification you can buy, not a claim of admissibility, not a review of a product's marketing. It is a neutral yardstick you can run against any vendor's record, including your own, today.
Digital Integrity Institute · Defensibility Rubric v0.1 · CC BY 4.0. A working draft, published to be argued with. Adopt, extend, and adapt with attribution. Independent of any AI-evidence vendor. DII assesses defensibility criteria; it does not determine admissibility, which is decided by courts. Reliability anchors are illustrative, not legal advice.