Insight · Provenance

AI generated compliance content has a provenance problem.

A regulator does not care whether content was authored by a human or a model. It cares whether the organization can substantiate every claim. Provenance is what makes substantiation possible.

18 December 20259 min read

A great deal of public debate about AI generated compliance content circles the wrong question. Whether content was drafted by a subject matter expert, a contractor, or a model is largely irrelevant to a regulator. The question the regulator asks is different, older, and harder. Can the organization substantiate the claim that this content correctly reflects the requirement it purports to teach, on the date it was delivered, to the cohort it was delivered to.

Content authored by humans has always had a provenance problem. It has just been quiet about it. An author wrote a paragraph, in their head. The paragraph made it into a module. The reasoning behind it lived in the author, not in the artifact. The author left. The reasoning left with them. Substantiation, in this world, is a narrative reconstruction after the fact.

The wrong debate

The debate that gets most airtime (human versus model as author) is not the debate a regulator would recognize. Regulators do not ask who typed the sentence. They ask whether the organization can produce, on demand, the chain from source clause to delivered content, and identify each hand and each model in between.

“Speed without provenance is a liability. Provenance is the only thing that makes speed defensible.”
Knowledge Foundry, Integrity Notes

Why generation magnifies the problem

Content generated by a model magnifies the human authored provenance problem by an order of magnitude. Volume goes up. Speed goes up. The reasoning behind each generated element is opaque by default. Buried in a prompt, a system message, and a set of weights the buyer cannot inspect. If a regulator or an incident review asks why a specific paragraph exists in a specific module, the honest answer, in most current AI authoring workflows, is we don't know. The organization authored the paragraph without knowing why. That is a worse posture than the baseline it replaced.

What integrity has to do

The corrective is not to slow down or to prohibit generation. It is to require, of any generation system used for compliance content, that generation be bound to structure and provenance at the moment it occurs. Each generated element must carry a cryptographic link back to the framework node it satisfies, the source clause behind the node, and the human reviewer who approved the generation. That link must be verifiable independently. By an auditor, by an incident review team, by the organization itself, without trusting the vendor's assertions.

  • Foundry Hash. A cryptographic hash bound to each generated element at the moment of generation. The hash pins the content to the framework node, the source clause, and the reviewer sign off behind it.
  • Master Integrity Root. A single root of trust for the program. Any tampering downstream (a paragraph quietly edited, a source citation swapped) invalidates the root. Integrity is verifiable in one query.
  • Forensic Revision Chain. Each revision is chained, signed, and timestamped. The chain answers, without ambiguity, what changed, when, why, and on whose authority.

Buy provenance, or buy the next incident

For any regulated buyer evaluating a training platform that can generate content, the disqualifying question is not whether the platform can generate content. Most can. The disqualifying question is whether the platform can, on demand, substantiate each generated element against a specific framework node, a specific source clause, and a specific approver, without relying on the vendor's word. If the answer is no, the buyer is accepting an evidentiary posture worse than the baseline that came before. If the answer is yes, and the substantiation is cryptographic rather than narrative, the buyer is in a better evidentiary posture than they have ever been.

Bring a subject to the Foundry. We build the framework in 45 minutes and you keep it.