GDI is a decision-record architecture. Its current evidence supports schema behavior, deterministic reference rules, and local interoperability tests. The repository has not established improved institutional outcomes, legal conformity, or meaningful human control in deployed settings.
A complete GDR can document a process in which the human reviewer had little time, incomplete evidence, high override costs, or no practical power to change the result. Record completeness and substantive judgment are different constructs.
Human Influence Telemetry addresses this gap by testing evidence access, independent reasoning, intervention capability, appeal ownership, repair responsibility, and system-change authority. GDI supplies the record structure. HIT tests whether the recorded human role retained practical force.
A record hash can detect later modification to fields included in the hash profile. It cannot establish that the original record was accurate, complete, timely, or honestly produced. Integrity depends on canonicalization, field selection, key custody where signatures are used, and protection of the record-generation path.
A cryptographically valid ScopeBlind/Acta receipt can strengthen attribution, integrity, ordering, and chain evidence. It does not establish payload truth, governance quality, legal sufficiency, or practical human influence.
The reference implementation accepts confidence values between 0 and 1 and compares them with institutional thresholds. These values may represent different quantities across models and tasks. Some systems provide no meaningful confidence estimate. Deployment requires domain-specific calibration, error-cost analysis, drift monitoring, and a rule for absent or invalid confidence.
Mappings to NIST AI RMF, ISO/IEC 42001, the European Union Artificial Intelligence Act, and OECD principles identify potentially relevant evidence. They do not establish applicability, conformity, certification, or legal sufficiency. ISO clause-level conclusions require access to the licensed standard. Legal conclusions require qualified review.
Decision Evidence Applicability Specification evaluates one defined evidence artifact against one identified governance requirement.
An applicability determination does not establish that the evidence, control, finding, or legal conclusion can be transferred across regimes without loss of meaning or force.
The same artifact may be:
- relevant under several regimes;
- sufficient under one and insufficient under another;
- structurally reusable but legally non-equivalent;
- acceptable only when combined with local evidence;
- cryptographically authentic but substantively weak;
- technically complete but outside the governed actor or lifecycle stage.
DEAS remains a working specification. Its schema, authoritative mappings, overlays, cases, reviewer protocol, and validation suite are incomplete.
Microsoft Agent Governance Toolkit, ScopeBlind/Acta, Credo AI, and other adjacent systems may change scope, terminology, or implementation. Repository comparisons are dated and provisional.
GDI and DEAS must not claim functions performed by those systems without an implemented and tested capability. In particular, the repository must separate:
- runtime action enforcement from decision reconstruction;
- signed-receipt verification from payload semantics;
- policy packs and harmonized control mappings from evidence-applicability determinations;
- documentary evidence relevance from legal or standards sufficiency.
The included insurance and agent-tool examples are synthetic. They test representation and control logic. They do not establish effects in healthcare, employment, public benefits, finance, biopharma, public administration, or national-security settings.
GDI assumes that relevant actions and evidence reach the governance layer. Hidden channels, compromised telemetry, collusive agents, prompt injection, tampered inputs, or an unobserved execution path can produce an incomplete or false record.
A decision record may support explanation, audit, or appeal. Audience needs, legal duties, trade secrets, privacy, accessibility, and procedural rights determine what explanation must be provided and to whom.
Decision records can contain personal data, sensitive evidence, model inputs, and employee identifiers. Implementers must define minimization, access controls, retention, redaction, subject rights, and lawful processing outside the core schema.
The reference implementation and mappings were developed by the project author. External review, replication, adversarial testing, legal or standards review, and comparative deployment studies remain open research needs.
These limitations must be revised whenever the schema, hash profile, framework mappings, reference implementation, adjacent-system scope, DEAS determination model, or empirical evidence changes.