We make AI you can prove — not “no AI.”

The safe-sounding answer in regulated work is to ban the models. It is also the wrong one — governed, verifiable generation wins, if you can prove it.

by Gopal Joshi · a stringify ai perspective

There’s a comfortable answer to AI risk in a regulated business, and it’s the wrong one. Faced with a model that might leak data or invent a fact, the safe-sounding move is to not really use it — to wrap “governed AI” around something that quietly doesn’t generate much of anything. It passes the review. It also wastes the entire opportunity.

We took the other position, on purpose. The stringify story is governed, verifiable generative AI — not “no generation.” We say “AI you can prove,” never “we don’t use models.” Because the value regulated teams actually want is in the generation and the agentic work; refusing to do it doesn’t make you safe, it makes you irrelevant — and it hands the ground to whoever is willing to make it provable instead.

Proof, made ordinary#

The alternative to banning the models isn’t blind trust — it’s evidence, applied every time. Every answer carries its source, so a claim can be traced instead of believed. Every action lands on the record, so it can be reviewed after the fact. The data stays inside the tenant’s walls, so “nothing leaves” is an architectural fact rather than a contractual hope. A generated answer with all three attached isn’t guesswork; it’s a defensible output. That’s the whole product: proof, made so ordinary it comes standard.

“No AI” is safe the way an unplugged machine is safe. The point was to run it.

What a record has to be to count#

Not everything called an audit trail would survive being looked at, so it is worth being specific about what makes one worth having.

It has to be produced by the work rather than assembled afterwards. A log written by a separate process that observed the work is a description of the work; a record emitted by the step itself is the work. The difference only shows up under scrutiny, which is precisely when it matters.

It has to be complete in a way that is checkable. A record with discretionary gaps — steps that write an entry only sometimes, or only when a flag is on — cannot be reasoned about, because absence stops meaning anything. If nothing was recorded, that has to mean nothing happened.

It has to survive the answer being wrong. This is the part people skip. A record’s job is not to show that the system performed well; it is to make a bad outcome legible afterwards. A trail that only looks good when things went well is a marketing artefact wearing a compliance costume.

And it has to be readable by the person who will actually be asking. An auditor, a compliance lead, a regulator — none of them are going to reconstruct intent from a stream of identifiers. Provenance that requires an engineer to interpret it has moved the problem rather than solved it.

Why “no generation” quietly loses#

A tool that mostly declines is easy to govern and easy to ignore. Users route around it — they paste into a public model instead, which is exactly the ungoverned behaviour everyone was trying to prevent. So the abstinence approach doesn’t even deliver the safety it promises; it just moves the risk somewhere no one is watching. Governed, verifiable generation is the version people actually adopt, which makes it the version that actually reduces shadow AI.

Governed does not mean generation-free. The record — source, scope, audit — is what turns a probabilistic answer into one a regulated team can stand behind.

There is a measurement trap hiding in here, and it catches careful organisations more often than careless ones. A banned tool produces no incidents, and no incidents reads as success. But the absence of incidents in a system nobody uses is not evidence of safety; it is the absence of evidence of anything. Meanwhile the work is still happening, somewhere, in a channel that generates no record at all. The organisation has traded a measurable risk for an unmeasurable one and recorded it as an improvement.

The objection worth taking seriously#

The strongest counter-argument is not that proof is impossible. It is that proof is not the same as correctness, and that a well-sourced wrong answer is more dangerous than an obviously wrong one, because it arrives wearing evidence.

That is right, and we should not soften it. Provenance tells you where an answer came from and what was done with it. It does not tell you the answer is true. A citation to a real document says the model consulted that document; it does not say the model read it correctly. Anyone selling you provenance as a correctness guarantee is selling you something else.

What proof actually changes is who can catch the error and when. An unsourced answer can only be checked by someone who already knows the answer, which defeats the purpose of asking. A sourced one can be checked by anyone willing to open the source, which is a much larger group and includes the reviewer, the auditor, and the person whose name goes on the output. And an answer on the record can be re-examined after the fact, when a problem surfaces months later and the question is not “was it right” but “what happened.”

So the honest claim is narrower than “provable means safe.” It is that proof moves a mistake from undiscoverable to discoverable, and that this is the difference between a system a regulated team can adopt and one it cannot.

The second objection is that all of this is overhead on work that used to be fast. True, and it is the right trade only where the cost of a wrong answer is high — which is exactly the work regulated teams were blocked on. For everything else, the dial turns down.

How to check this#

Ask what the record contains when a step fails, not when it succeeds. Ask whether provenance is generated by the work or assembled from logs afterwards. Ask what an answer looks like when the model has nothing to cite — whether it says so, or fills the gap.

So we don’t ask a customer to choose between capable and compliant. We make the capable version provable, and let the proof do the reassuring. Not a neutered AI that survives review by doing nothing — real AI, with a record. Not probably. Provably.

one standard · inherited two ways · proven the same

one standard · inherited two ways · proven the same