Vianordis · Published documents

The argument, the specification, and how to test both.

Three documents, maintained on separate version series and written to be read together. All are published under Open Review: they are put out for criticism, corrections of fact are applied in the next edition and listed, and substantive critique is credited.

How the set fits together

The position paper carries the argument and the regulatory case. The specification turns it into a normative technical profile. The guide is the practical layer — how to pilot a governed action and how to measure whether the control chain actually held. Each document defines what it does not do, and the vocabulary is defined once, in the position paper, and reused by the other two.

If you are reading one document, read the position paper. If you are evaluating an implementation, read the specification. If you are running a pilot, read the guide.

Position Paper 01

The AI Control Gap

Why approving a model is not approving an action

Version
v0.5.4
Status
Open Review
Issued
26 August 2026
Extent
37 pages
File
PDF · 991 KB

AI no longer only produces text — it reads mailboxes, joins records across systems, prepares transactions and triggers actions, which makes a model's output a business event. Most organisations now control which model may be used. Far fewer can demonstrate, for one specific action, who authorised it, on whose behalf, under which mandate and policy version, and whether the thing approved is the thing that executed. This paper argues that access is not authority, and sets out what an executable control layer would have to do.

Covers
  • Shadow Execution: how the risk outgrew the Shadow AI framing
  • Impact tiers and provenance assurance — the two control variables the other documents reuse
  • What this architecture does not solve, stated before the case for it
  • Where the EU AI Act, NIS2 and the BSI Act, DORA, the GDPR and the Cyber Resilience Act converge on the same technical objectives
Specification

GAIP Candidate Specification

Governed Action Interchange Profile — exchanging and verifying a governed action

Version
0.4
Status
Candidate — Open Review
Issued
26 August 2026
Extent
67 pages
File
PDF · 3.0 MB

The normative counterpart to the position paper: a wire profile for a governed action, written so that two systems that have never met can exchange one and independently verify it. It defines the Governed Action Envelope, the control invariants an implementation must hold, the processing procedure and state machine, and the tests an implementation has to fail correctly. It deliberately defines no conformance scheme and no conformance levels.

Covers
  • The Governed Action Envelope: principal, intent, parameters, mandate, preconditions, approval record
  • Digest definitions, domain separation and the signer matrix
  • Canonicalisation and cryptographic profiles for JSON and CBOR
  • Target-adapter assurance modes, thirteen test vectors and the required negative tests
Guide

Adoption & Measurement Guide

Piloting governed AI actions, and measuring whether the control chain works

Version
0.1.4
Status
Open Review
Issued
26 August 2026
Extent
22 pages
File
PDF · 584 KB

The practical layer. It walks one worked example end to end — AI-assisted invoice processing, including what still fails in it — then gives an adoption path that starts by making AI actions visible rather than by migrating anything. The measurement protocol is written so that an organisation can run it, and publish the result, without using Vianordis, including a result that goes against us. The guide is non-normative and contains no field measurements.

Covers
  • A worked example, with the failure cases left in
  • A six-phase adoption path and the exit criteria for scaling it
  • Brownfield routing: enforcement modes M0–M4 and the integration patterns
  • A maturity model for leadership, and a pilot scorecard with a publication template

Archive

Superseded editions stay online so that anything already cited resolves. They are retained for reference only and should not be cited as current.

Position Paper 01 · Superseded

The AI Control Gap

Architecture Profile Edition

Version
v0.4
Status
Superseded archive edition
Issued
26 August 2026
Extent
86 pages
File
PDF · 3.0 MB

The single-volume edition that preceded the current set. It was replaced on 26 August 2026 by Position Paper 01 v0.5.4, the GAIP Candidate Specification 0.4 and the Adoption & Measurement Guide 0.1.4.

Several statements in this edition were later corrected — among them the Cyber Resilience Act vulnerability-handling reference, the attribution of the PDP/PEP vocabulary, the DORA concentration-risk article, and the GAIP 0.1 conformance levels, which have since been withdrawn. Do not cite this edition as current.

Corrections and critique

These are review editions. If a fact is wrong, a source is misread, or an argument does not survive contact with your estate, we would rather hear it than not — corrections are applied in the next edition and listed, and substantive critique is credited unless you prefer otherwise.

Send a correction

All documents are published by GoSec Cloud OÜ, Tallinn, under Creative Commons Attribution 4.0 International. Law as at 26 August 2026. Not legal advice.