Products Demo Docs Blog About Contact Sign in Sign up
Blog · · Philippe Laporte

When the Sign-Off Stops Being the Last Line of Defense

The compliance sign-off has carried the trust for years. Under the EU AI Act's traceability obligations, it can no longer carry it alone.

The reviewer cannot verify what they cannot see

Poland's AI vendors selling into regulated sectors — banking, insurance, public administration — are running into the same wall from a different direction. A compliance officer or ISO 42001 assessor is asked to sign off on an AI system's outputs. They read a model card, a validation report, maybe a sample of predictions. Then they sign.

That signature has carried the trust for years. It does not scale, and under the EU AI Act's record-keeping and traceability obligations it increasingly cannot survive scrutiny either. A reviewer who attests to correctness without a way to independently check the underlying computation is holding liability they cannot actually discharge.

Executor and prover are not the same role

The fix is not a stricter reviewer. It is separating who runs the inference from who proves it ran correctly. An executor that also vouches for its own output is grading its own exam. Cyberian's architecture keeps those two roles apart: the system performing the inference is never the same system generating the evidence of what it did.

That separation is what makes a cryptographic receipt possible. The receipt is independently verifiable, reproducible, and tamper-evident, without exposing model internals to the party checking it. A Polish GRC boutique advising a bank on its AI Act obligations does not need to trust a vendor's word or a reviewer's judgment call. It can check the receipt.

Where this stands today

Cryptographic receipts with probabilistic replay are live today for embedding workloads, and for any ONNX-exportable model through bring-your-own-ONNX upload. For generative and mixed workloads, the honest position is design-partner stage, not a production claim. Either way, the direction is the same: the human sign-off stops being the last line of defense and becomes one more thing that can be checked, rather than simply believed.

Poland's compliance ecosystem — its ISO 42001 practices and its KNF-regulated financial institutions — is a reasonable place to watch this shift happen first. The obligations are arriving on a fixed clock. The tooling to meet them honestly is not yet standard. That gap is where receipts start to displace trust tiers built entirely on who reviewed what, and replace them with something anyone downstream can check, not just something the first signer believed.


PL
Philippe Laporte
Founder and CEO of Cyberian Systems, building verified AI inference infrastructure for regulated industries.

Try the live demo · Follow on LinkedIn · RSS