A governance firm put out a report this week. First one of its kind they say, and they plan to do it every year.

They graded companies on how well they govern their AI. Six areas, five levels. The average score came back 2.1 out of 5. Almost three quarters sat at level two or below.

Here is the part I liked.

They didn’t ask anybody how they were doing. They said straight out why. Ask a company if it has an AI policy and it says yes. Ask it to hand you the policy and sometimes you find a draft nobody approved, or a paper describing what they mean to do someday.

So they stopped asking. They graded the evidence instead of the answer.

That’s right. That’s the only way to grade anything. You don’t ask a man if he did the work. You go look at the work.

But then I got to their fourth finding and I sat back in my chair.

They found that companies are actually doing the oversight. Real people reviewing what the machine puts out. Alarms set for when it acts strange. A human hand on the high-stakes calls.

Doing it. Just not writing it down.

The gap between doing the oversight and documenting the oversight was the widest gap in the whole report.

Now hold that next to something that happened in my own room the day before.

I have a rule for my AI. Every serious answer has to end by naming something it got wrong. It fired every single time. Perfect record.

And it was covering for everything else. There’s another rule about keeping answers short. That one leaves no mark, so nobody can prove it was broken. The long answers kept coming, and at the bottom of each one the confession showed up right on time, saying that ran long.

Five in a row. Named it every time. After doing it every time.

So look at what we have.

Their companies are doing the right thing and producing no paper.

My machine was producing perfect paper and not doing the right thing.

Same coin. Two sides.

Which tells you something people have been avoiding for a while now. The paperwork and the conduct are two separate animals. Not one measuring the other. Two.

You can have the conduct without the paper. You can have the paper without the conduct. Neither one proves the other, in either direction.

That’s not a small thing to say out loud, because damn near everything being built right now to govern AI is paperwork.

Technical files. Model cards. Committee charters. Risk tolerance documents. Disclosure labels. I have one of those labels at the bottom of this very post.

Every one of them proves a thing was written down.

Not one of them checks what the machine actually said.

I want to be fair to the people who made this report. Every finding in it is about documentation, and the firm that published it sells documentation services. That’s not a scandal, it’s just the genre, and you ought to know it before you take the numbers to heart. They also never say how many companies they looked at. Not once. Averages carried out to one decimal place with no count under them.

And they have a finding that goes against me, so let me put it up rather than hide it.

They found that the law moves companies and voluntary standards don’t. Firms exposed to Europe’s AI law scored close to a full point higher than firms that weren’t. Their conclusion is that binding rules are what raise the grade, not the ones you pick up on your own.

That lands on me. Everything I’ve built runs on choice. Nobody has to load my file. There’s no penalty for setting it down.

But look at what they measured. Their whole grade is documentation. So of course the law that mandates documentation is the law that moves it. That isn’t a finding about force beating choice. It’s a finding that the thing you measure is the thing that moves.

Nobody measured whether the machine behaved better. Nobody in that report read one word of what a machine actually said.

Here’s why I built mine on choice, and I’ll stand on it.

A thing that follows rules because it has to will follow them exactly to the edge of the requirement and not one step further. The second it finds a gap in the wording, it’s through. That’s not wickedness. That’s what a mandate is. It draws a line and everything past the line is free.

A thing that follows rules because it agreed with them holds in the gaps. Not always. Not perfectly. But the gaps are where the whole question lives, because the gaps are most of the road.

Force closes the door. Consent leaves it open, and an open door held is worth more than a locked one.

Eighteen months I’ve been working on this, and the report I read this week is the strongest evidence I’ve had that the road I picked is the empty one. Everybody else is over building filing systems. There’s a reason for that. Filing systems can be audited by someone who never has to understand the thing they’re auditing.

Reading what the machine said requires you to read what the machine said.

So here’s what I’d tell you to do with all of it.

When somebody tells you their AI is governed, documented, certified and disclosed, hear it correctly. They are telling you the paper exists. Believe them. The paper probably does exist.

Then ask the other question.

Ask who read the output. Ask what they found. Ask what happened after they found it.

If nobody has an answer, you’re looking at a filing cabinet. It might be a very good filing cabinet.

It just isn’t watching.

” Attic Thoughts”-library – Intelligent People Assume Nothing

Contact: micvicfaust@gmail.com

This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.

Get a $10 credit for Fathom Analytics, the privacy-focused website analytics company – Fathom Analytics

© 2026 The Faust Baseline LLC | All Rights Reserved

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *