Observability Is Not Enforcement: A Doctrinal Framework for Distinguishing Compliance Instrumentation from Runtime Authorization in AI Governance Architectures (Working Paper v2.0)
Abstract
AI compliance instrumentation can produce extensive evidence without controlling whether a governed action occurs. Many contemporary systems embed explainability artifacts, monitoring dashboards, drift detection, and integrity-protected audit bundles into development pipelines, improving audit readiness and regulatory traceability. These systems frequently do not condition execution on authorization at the point of action. This working paper introduces a doctrinal framework that distinguishes: • Evidence-routing compliance systems, which collect, transform, and route artifacts for review, and• Runtime authorization boundaries, which condition a governed effect on a valid authorization artifact carrying an action-bound ALLOW verdict. The distinction is formalized along five doctrinal axes: enforcement locus, integrity-protection semantics, failure behavior, bypass resistance, and override governance. The paper’s six-criterion Enforcement Test Protocol (ETP) is a binary minimum test: a 6/6 result establishes a scoped runtime authorization boundary for a declared governed effect and set of execution paths; a 0–5/6 result means the asserted scoped-boundary claim has not been established, without automatically classifying the system as evidence routing. Version 2.0.0 makes the protocol assessment-ready: every evaluation proceeds against a declared scope and a declared trust-assumptions statement, diagnostic reporting preserves failure detail without creating a maturity scale, and a non-normative appendix names illustrative evidence categories per criterion. Verdict semantics are exact and fail-closed. The verdict space is ALLOW, DENY, and ABSTAIN. DENY is terminal for the requested action. ABSTAIN blocks execution pending authorized human resolution, in which the boundary materially consumes the human’s authority-bound input and emits the verdict on which execution depends. An evaluator unable to reach ALLOW or DENY emits ABSTAIN; absence or invalidity of an authorization artifact means no permission, without implying that a verdict was emitted. The paper situates the boundary result within the FERZ corpus: the Authorization Artifact Test supplies the two-prong evidence threshold of pre-execution existence and independent reconstruction; the Authorization Boundary Integrity Model separates Output Integrity, Input Integrity, and Replay Integrity, of which the ETP primarily tests the first; the Five Tests Standard supplies the Provenance test and the recognized replay modes, State-Replay and Protocol-Replay; Governance Laundering names Policy Theater (FM-1); and The Closed-World Bargain states the composition threshold a bounded gate must meet before any authorization-infrastructure claim. Passing one test must not be reported as passing all of them. Through a running example in automated loan decisioning and an architectural analysis of the EU AI Act as amended by Regulation (EU) 2026/1744, GDPR Article 22(1) and 22(3), and current U.S. federal AI policy, the paper distinguishes evidence that supports compliance from architecture that can prevent a governed effect. The ETP evaluates an architectural claim, not legal compliance; the paper does not assert that any cited legal instrument generally requires a runtime authorization boundary. The central thesis is architectural and testable: A control claim that depends on preventing a specific action is advisory unless execution is conditioned on authorization for that action. FERZ doctrine: Monitoring creates evidence of what occurred. Runtime authorization creates evidence of what was permitted before occurrence. Observability and authorization are complementary functions, not interchangeable layers. Neither function, standing alone, establishes provenance, independent reconstruction, or complete governance. The paper contributes a publicly usable evaluation protocol for enterprise buyers, regulators, auditors, and researchers who need to distinguish monitoring-based governance claims from enforcement architectures. Version 2.0.0 (August 2026): aligns terminology and evaluation logic with the Authorization Artifact Test, the Authorization Boundary Integrity Model, the Five Tests Standard v1.2.0, the Governance Laundering taxonomy, and The Closed-World Bargain. Renames the enforcement category to runtime authorization boundaries; migrates the artifact class term to authorization artifact; reserves admissibility for input-side evidence origin and adopts permissibility for output-side constraints; makes Criterion 2 integrity-mechanism neutral; defines a passing ETP score as a scoped runtime authorization boundary; distinguishes integrity verification from independent reconstruction; adds declared trust assumptions, diagnostic reporting, and non-normative evidence categories; and updates the legal analysis to current primary sources, including Regulation (EU) 2026/1744. Clarifies that an evaluator unable to reach ALLOW or DENY emits ABSTAIN, while absence or invalidity of an authorization artifact means no permission without implying that a verdict was emitted; this supersedes the v1.1.0 formulation under which missing evidence resolved to ABSTAIN. Version 1.1.0 (July 2026): updates U.S. federal policy references following the rescission of Executive Order 14110; migrates the standard citation to the Five Tests Standard (5TS) v1.2.0; clarifies fail-closed verdict semantics, with missing evidence and evaluation failure resolving to ABSTAIN; adds Enforcement Test Protocol scope notes on implementation tier and input integrity. The framework, taxonomy, and test criteria are unchanged from v1.0. Citation and license. Copyright © 2026 FERZ, Inc. This work is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0). Cite the concept DOI 10.5281/zenodo.18663864 for the work and the version DOI [assigned on publication of this edition] for this edition. Canonical page: ferz.ai. Full corpus: the FERZ community on Zenodo.
// Source
Authors: Edward Meyman
Institutions: Ferghana Polytechnical Institute, Ferro (United States)