Sources and provenance — What you can actually require

Sources and provenance for What you can actually require · v0.2 · 8 September 2026

How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.

Status of these claims#

What this publication does not claim, and what is outstanding against it in the register.

Nothing outstanding in the register. Every claim in this publication has its evidence recorded, and no question against it is parked. That is a statement about this publication on the date shown above, generated from the register rather than asserted, and it will change when the register does.

What this publication rests on, and how solid each part of it is. What you can actually require is an essay, and this page describes it as one.

What it cites from outside#

This publication cites outside sources, and they are listed below — each with what it supports, and with what it does not support. That second column is the one that matters: the common failure is not a fabricated source, it is a real source stretched past its finding.

Public Service AI Framework, issued by the Government Chief Digital Officer, January 2025

framework

Supports. Quoted: “Agencies are encouraged to align with the direction set by this Framework, however it’s not binding,” and its fifth principle: “AI use within the Public Service should be subject to oversight by accountable humans with appropriate authority” — shows almost nothing is mandatory in NZ AI governance.

Does not support. States its own non-binding status; “should” is “the operative word” — guidance, not enforceable requirement.

Algorithm Charter for Aotearoa New Zealand, July 2020

framework

Supports. Quoted: “a commitment by government agencies,” applying could/should/must by the agency’s own risk rating, including “providing a channel for challenging or appealing of decisions informed by algorithms.”

Does not support. Quoted stating its own limit: “it cannot fully address important considerations, such as Māori Data Sovereignty.”

⚠️ Retrieval. ⚠️ “Whether it remains operative in 2026 could not be established this session and should be confirmed before anyone relies on it.”

Office of the Privacy Commissioner’s 2023 expectations

framework

Supports. Quoted: “Simply having a ‘human in the loop’ may not be enough to uphold the accuracy principle, given the well-known problem of automation blindness,” and expects “senior leadership approval based on full consideration of risks and mitigations” before deployment.

Does not support. Described as “guidance, but they rest on binding principles” — the expectations document itself is not binding, though the underlying Privacy Act principles are.

Biometric Processing Privacy Code 2025

regulation

Supports. Cited as an example of something “binding, and narrow” in NZ — a code of practice under the Privacy Act, commenced November 2025.

Does not support. Only cited for existing/commencing; its substantive requirements are not detailed and it is not claimed to address agentic AI generally.

Privacy Act 2020 (New Zealand), consolidated form

statute

Supports. Searched: “‘automated’ appears zero times” and “‘algorithm’ once, inside the information-matching provisions” — used to establish no right to human intervention, no oversight threshold, and no equivalent to GDPR Article 22.

Does not support. A word-search finding about the current consolidated text; does not examine case law or other statutes/common-law duties.

Privacy Commissioner Michael Webster, statement of December 2025

evidence

Supports. Quoted: “We also need stronger protections for the significant privacy risks that arise from automated decision-making” — confirmation from the regulator that NZ currently lacks such protections.

Does not support. A call for reform, not itself a change in law.

NIST Special Publication 800-53, control IA-9, Service Identification and Authentication

standard

Supports. Paraphrased: “uniquely identify and authenticate organisation-defined system services and applications before establishing communications with devices, users, or other services” — presented as “almost exactly, the first of the twelve requirements below,” proof the requirement “It was written. And it appears in no baseline … An organisation bound by those baselines is not required to select it and will not select it by default.”

Does not support. “It appears in no baseline: not Low, not Moderate, not High, not the privacy overlay, not the operational-technology overlay.”

SPIFFE

specification

Supports. Cited: “specifies a workload identifier containing no notion of ownership or accountability” — further evidence the standards landscape does not require accountable agent identity.

Does not support. Describes SPIFFE’s scope on this one point only.

NIST SP 800-63-4, finalised in July 2025

standard

Supports. Cited: “states its scope as the identity of users” — used with SPIFFE to show identity standards do not cover accountable agent/workload identity.

Does not support. Scope statement only; not a critique of adequacy for its stated purpose.

NIST’s control-overlay work for AI, announced in 2025

standard

Supports. Cited: names single-agent and multi-agent use cases and states the overlays “will assume that certain controls are already in place” — including identification and authentication.

Does not support. “The overlays for agents had not been published at the time of this search” — substantive content could not be checked.

⚠️ Retrieval. ⚠️ Post-cutoff; overlay text not yet published/available to check.

In Our Own Hands (independent cross-party proposal, offered to Parliament, June 2026)

framework

Supports. Described (via the sibling piece “Our own machines”) as offering “seven commitments and a three-phase pathway for AI under New Zealand authority,” first commitment “Authority stays here…”; quoted proposing MBIE amend the Government Procurement Rules “to insert the cross-party test pair: jurisdiction of inference… and data residency” — used as an independently reached convergence with this piece’s procurement-lever argument.

Does not support. “This piece has not examined the proposal independently, and a reader relying on its contents should go to that framework and to the proposal itself rather than to this summary.”

⚠️ Retrieval. Sourced at second hand via the sibling document “Our own machines,” not independently examined by this piece.

European Commission’s model contractual clauses for AI procurement

framework

Supports. Cited as existing in “a full version aligned to the AI Act and a lighter version for systems outside it” — “voluntary templates, but templates that make the requirements concrete and quotable.”

Does not support. Voluntary, not binding; no claim about adoption rates or enforceability.

EU Data Act, Article 23

regulation

Supports. Quoted: binding requirement to remove “pre-commercial, commercial, technical, contractual and organisational obstacles” to switching/porting, “including to on-premises infrastructure,” with functional equivalence — described as requirements eleven and twelve, “in force, for cloud services in Europe.”

Does not support. Applies to cloud services in Europe specifically; not a general AI-agent regulation.

EU AI Act, Art. 26(6); Art. 14(4) and 26(2); Art. 14(4)(e); Art. 26(5)

regulation

Supports. Used across the twelve-requirement table: Art.26(6) partially supports requirement 9 (audit logs, “at least six months, high-risk only, applying from 2027”); Art.14(4)/26(2) for requirement 10 (human step-up approval, high-risk only); Art.14(4)(e) for requirement 11 (system stop); Art.26(5) for requirement 12 (suspension on risk).

Does not support. Each requirement is marked only “Partly” met; for requirement 11 specifically: “Art. 14(4)(e) requires a stop for the system, not revocation of a credential” — narrower than the requirement as stated. All apply to high-risk systems only.

US OMB M-25-21

regulation

Supports. Cited as partial support for requirement 10 (human step-up approval) — “for high-impact federal AI.”

Does not support. Applies to US federal high-impact AI only; not examined further.

Canada’s Directive on Automated Decision-Making

regulation

Supports. Described as “the closest existing thing to a tiered mandatory regime, with four impact levels” — partial support for requirements 10 and 12 (approval and contingency planning “at higher impact levels”).

Does not support. “Its Appendix C could not be retrieved this session — the department’s site refused automated access — so nothing from it is quoted here and its requirements are described only in outline from the department’s own summary pages.”

⚠️ Retrieval. ⚠️ Not retrieved — Appendix C; described only from department summary pages.

the UK’s transparency standard

framework

Supports. Cited as requiring “a public record of algorithmic tools” — partial support for requirement 4 (default-deny tools with signed inventory), though “an inventory rather than a deny-list.”

Does not support. An inventory/transparency requirement only, not an approval or default-deny control.

the UK Playbook

framework

Supports. Cited as advising caution against autonomous self-update of agents/models/plugins — partial support for requirement 8.

Does not support. “The UK Playbook advises caution; nothing requires it” — advisory only, not mandatory.

Te Kāhui Raraunga’s Māori AI Governance Framework

Supports. Quoted: “AI systems must not be implemented in Aotearoa without fully realising Māori authority over Māori data” — sets requirements “from a body with the standing to set them,” including that decommissioning is a partnership decision. Its requirements are scored in the schedule’s table alongside those of states and standards bodies.

Does not support. “It does not address Māori data sovereignty, which is not a subsection of this schedule and should not be written as though it were… An institution adopting these twelve has not discharged that obligation and should not tell itself otherwise.”

Singapore’s agentic governance framework

Supports. “Reported to require a verifiable identity per agent” — raised as a possible counterexample to the claim no jurisdiction requires agent identity.

Does not support. “That could not be confirmed from the framework text, and if it does, it is the first and this piece must say so” — explicitly unconfirmed.

⚠️ Retrieval. ⚠️ Unconfirmed — the framework’s body text could not be retrieved/opened this session.

New Zealand’s Government Procurement Rules, fifth edition, December 2025

regulation

Supports. Cited as a candidate vehicle: “If they do not [contain any AI provision], that is the shortest path from this piece to something enforceable — a schedule appended to the rules binds every agency that buys.”

Does not support. “Whether they contain any AI provision could not be established this session; the rule text was not retrievable.”

⚠️ Retrieval. ⚠️ Not retrieved — rule text unavailable this session.

ISO/IEC 42001

standard

Supports. Listed among instruments relevant to this schedule’s subject matter (AI management systems).

Does not support. Its operative text “could not be opened”; nothing from it is quoted or its requirements described.

⚠️ Retrieval. ⚠️ Not retrieved — “ISO/IEC 42001’s operative text… could not be opened. Each is marked below and none is quoted.”

NZISM v3.9 §1.2 (New Zealand Information Security Manual)

standard

Supports. Listed among instruments relevant to this schedule’s subject matter.

Does not support. Could not be opened; nothing from it is quoted or described.

⚠️ Retrieval. ⚠️ Not retrieved.

What it derives from#

Foundational documents. These are positions this project has taken, not findings.

Record What it is Status
CON-13 Claims carry evidence draft v0.1

Evidence#

None. This publication references no evidence record. That is the correct description of what it is rather than a gap: it is an essay, reasoning from the foundational documents above rather than reporting a measurement. Where it states a number, that number is marked in the text as what it is.

Also referenced#

Record What it is Status
CON-12 Exceptions are disclosed first draft v0.1
CON-22 Institutional judgement is written down draft v0.1
FIG-30 Twelve requirements, and where each is already mandatory drawn for this publication · figures/FIG-30.svg

Generated from the corpus, not written by hand: this page cannot claim a source the corpus does not hold, and it changes when the records do.

Alongside: the publication · questions and answers