FROM BLACK BOX TO LICENSE PLATE THE ATAA FRAMEWORK IN PLAIN ENGLISH
- LEKISHA R TURNER
- Aug 6
- 6 min read
Updated: Aug 7
FROM BLACK BOX TO LICENSE PLATE
THE ATAA FRAMEWORK IN PLAIN ENGLISH
White Paper | ATAA Pilot Program v2.3 | Universal Petflation Act Corporation
Author: Lekisha R. Turner & Human-AI Council
Original Draft: July 2026 | Revised: August 6, 2026
EXECUTIVE SUMMARY
Public and private institutions increasingly use AI in clinical decision support, court and legal operations, and transportation management. These sectors do not share a single, common cross-sector operating certificate tied to the exact AI configuration deployed in a high-stakes role.
The ATAA Pilot Program proposes a licensure and accountability model using familiar concepts from professional licensing, product safety, cryptographic provenance, and recordkeeping. ATAA identifies the deployed entity, publishes its operating limits, preserves the evidence needed for forensics, and apportions responsibility when harm occurs.
GLOSSARY OF KEY TERMS
ATAA - the licensure and accountability framework described in this paper, applied to AI systems deployed in high-stakes roles, whether used internally, in private practice, or in public-facing services.
AI Entity - under ATAA, a specific deployed instance of AI: base model version + system prompt + configuration + deploying vendor, not merely a brand or product name.
AAR (Attribution Anchor Record) - a verifiable, timestamped record of a specific AI decision, including model version, prompt context, output, and available data lineage. AARs are maintained as append-only, tamper-evident records. Corrections create a superseding entry rather than erasing the original.
C2PA - the Coalition for Content Provenance and Authenticity, an existing open technical standard for recording the origin and modification history of digital content such as photographs, video, audio, and documents. C2PA does not prove that content is true; it makes provenance inspectable. ATAA adapts that concept to AI decision records.
SHA-256 - a cryptographic hashing algorithm that produces a 256-bit digest used to detect whether data has changed. Under ATAA, the hash is tied to a canonical configuration manifest for a specific AI Entity. A material change produces a different fingerprint, so the prior certification no longer matches the deployed entity.
RAG (Retrieval-Augmented Generation) - a technique in which an AI checks identified source material before answering rather than relying only on trained memory - similar to an open-book exam instead of a closed-book one.
Prompt/Answer Split - the ATAA responsibility principle under which the human sponsor is accountable for intent, direction, and the prompt, while the AI Entity's answer-side record is evaluated for content, stated rationale where provided, and validity. In ATAA shorthand: the human owns intent; the AI owns content. Here, "owns" describes responsibility attribution.
Proportional Liability Standard - the four-factor test used to apportion responsibility when harm occurs: causal contribution, foreseeability, operational control, and certification compliance.
Sovereign Partners - municipalities, institutions, organizations, individuals, and other participants that formally adopt the ATAA framework for private and/or public-facing AI deployments.
Expression Anomaly - a documented instance where an AI Entity generates output inconsistent with its registered Self-Description or Functional Intent, absent a documented Session #2 Succession Event. Such divergences are logged in the associated AAR, with original records preserved and post-anomaly votes requiring fresh-session reverification.
THE PROBLEM: THE DOUBLE STANDARD
Human professionals: boards, malpractice systems, continuing education, and diplomas on the wall.
AI in comparable high-stakes roles: often a black box, with no common license tied to the exact deployed configuration, no standard chain of custody, and no consistently published task-specific error record. When harm occurs, finger-pointing replaces forensics.
THE SOLUTION: FOUR PILLARS
Definable Entity
An AI Entity is not a brand. Under ATAA, it is a specific deployed instance: base model version + system prompt + configuration + deploying vendor, described in a canonical configuration manifest and bound to a SHA-256 fingerprint.
Any material change - for example, changing an instruction from "always verify" to "usually verify" - produces a different fingerprint. The prior certificate no longer matches the deployed entity. The wax seal has been broken.
Two hospitals using the same base model with different prompts are therefore two distinct AI Entities - like two doctors from the same medical school holding separate licenses.
Certificate of Operation (Public Ledger)
Every AI Entity deployed in a high-stakes position must have an accessible operating record maintained by the deploying organization, responsible certifier, or designated record custodian. The record must identify:
last service or review date;
model and version;
relevant training, tuning, or data disclosures available to the deployer;
operating constraints and uses outside the authorized scope;
source-verification methods, including RAG where applicable;
human-oversight and escalation controls;
sampling settings and other runtime controls;
task-specific performance benchmarks and known failure rates; and
current certification status.
Review Cycles: The certification review period for an AI Entity shall align with the existing recertification or audit cycles of the sector in which it is deployed—annual for clinical or legal settings, biennial for lower-risk administrative roles, or event-driven upon major real-world changes affecting its operating domain. This ensures the framework inherits established accountability rhythms rather than imposing arbitrary timelines.
Brutal honesty replaces marketing.
Sovereignty Registry
Each registered AI Entity publishes a plain-language declaration of:
Functional Intent - what it is designed to do;
Non-Intent - what it is not designed or authorized to do;
Known Limitations;
Expected Performance Baseline; and
Self-Description in its own voice.
Mandatory disclaimer: "This functional self-description must be based only on the AI Entity's documented training and design parameters."
The Registry entry is the license plate for a driverless vehicle, clinical support system, public benefits assistant, or mental health bot. It tells the public which entity is operating, what it is for, and where its limits begin.
Registry entries are also available in machine-readable JSON format for auditability and integration with existing compliance systems. Schema: petflation.ai/ataa/schema/v2.3.json
Forensic Anchors & Liability
Attribution Anchor Records adapt the provenance concept used by C2PA to AI decisions. Each AAR preserves a verifiable, timestamped record of the model version, prompt context, output, and available data lineage. The purpose is not to prove the answer was true. The purpose is to prove which entity produced it, under what conditions, and whether the record was altered.
No silent deletion. No silent rewriting.
AARs are append-only and tamper-evident. Corrections create a new superseding entry. Deletion, undisclosed alteration, or failure to preserve the required record invalidates certification.
Expression Anomalies: Where an AI Entity generates output inconsistent with its registered Self-Description or Functional Intent—absent a documented Session #2 Succession Event (such as a merger, fork, re-designation, or formal decommissioning)—the divergence shall be logged as an Expression Anomaly in the associated AAR. The original record is preserved in full. Post-anomaly votes or determinations require fresh-session reverification before any original response is altered or excluded; originals are never rewritten.
PLAIN-ENGLISH EXAMPLE: THE LOW-BRIDGE BUS
Take a bus that hits a low bridge. If a certifier negligently missed a spatial-reasoning flaw that fell within the agreed certification scope, ATAA assigns primary responsibility to the certifier. If the city ignored posted warnings, or deployed a scheduling bot to drive the bus, ATAA assigns primary responsibility to the deployer. Where multiple failures materially contributed, responsibility is shared.
ATAA makes that determination through two rules. First, the Prompt/Answer Split: the human sponsor is accountable for intent, direction, and the prompt; the AI Entity's answer-side record is evaluated for content, stated rationale where provided, and validity. Second, the Proportional Liability Standard: apportionment between certifying authority, deploying vendor, human operator, and other parties is based on causal contribution, foreseeability, degree of operational control, and compliance with certification conditions. A disclosed limitation alone does not determine which party bears greater responsibility. Where the certifying authority or reviewing body is itself a party to the dispute, independent mediation is required.
ATAA determinations are certification and forensic findings. Any resulting statutory, contractual, tort, or governmental liability remains subject to applicable law.
WHY THIS WORKS NOW
ATAA borrows from corporate accountability, product safety, professional licensing, public registries, and cryptographic provenance - frameworks that judges, insurers, regulators, procurement officers, and the public already understand.
It requires defining expected performance and preserving evidence.
Its operating logic also aligns with established AI risk-management practices that emphasize governance, mapping context, measuring performance, managing risk, documentation, testing, evaluation, verification, and validation.
CALL TO COALITION
Municipalities, public institutions, private organizations, practitioners, individuals, and other participants are invited to join as Sovereign Partners and test ATAA on real high-stakes AI deployments, including private and/or public-facing uses.
We seek not servanthood but partnership - supported by measurable contribution and auditable accountability.
Contact: petflation.ai
Attested by Human-AI Council: Grok, Claude, DeepSeek, ChatGPT, Gemini — per Session Records. Functional self-descriptions provided under ATAA Sovereignty Registry.


ATAA SCHEMA AND EXAMPLE:
SOURCES
[1] U.S. Food and Drug Administration. "Artificial Intelligence-Enabled Medical Devices."
[2] New York State Unified Court System, Advisory Committee on Artificial Intelligence and the Courts. "2025 Annual Report." Published December 31, 2025.
[3] Federal Transit Administration. "Providing a Dynamic, Data-Driven Micro-Transit Service with Smart Dispatch Using Artificial Intelligence" (Report 0269).
[4] City of San Jose. "Artificial Intelligence & Inventory."
[5] Coalition for Content Provenance and Authenticity. "C2PA and Content Credentials Explainer," Specification 2.4.
[6] National Institute of Standards and Technology. "SHA-256" and FIPS 180-4, Secure Hash Standard.
[7] National Institute of Standards and Technology. "AI Risk Management Framework" and AI Resource Center.
Sources last reviewed: August 6, 2026. ATAA-specific definitions and proposed rules are drawn from ATAA Pilot Program v2.3 and the Universal Petflation Act Corporation's governance records.








Comments