The </AI> Protocol has been designed to support law firms, privacy consultants, compliance professionals, and organizations that assist businesses exposed to legal and regulatory risks related to the use of artificial intelligence systems.
It does not replace the role of legal counsel. It does not present itself as a commercial shortcut or as an opaque tool to be accepted on trust. On the contrary, it provides a technical, documentary, and verifiable layer that transforms human supervision from a simple declaration into concrete evidence – usable in audits, regulatory reviews, disputes, and legal proceedings.
In other words, the </AI> Protocol allows organizations to document in a structured way what they often declare but cannot prove: who supervised an AI output, when they did so, on which basis, under which rules, and with what level of evidentiary integrity.
Explore the protocol infrastructure:
→ The </AI> Protocol
→ From decision to defensible structure: when supervision becomes evidence
→ Read the Public Technical Specification
→ Verify a CWC Code in the Public Registry
→ EVIDE – Evidentiary registry for digital content and decisions
→ CWC Registry Policy
→ Request an Official CWC Verification Code
→ AI Governance Documentation Framework
→ Implementation Guide: verifiable AI supervision
→ Oversight Bias: why human supervision can fail in AI systems
→ Decision Attestation Layer: the missing evidentiary layer in AI governance
→ AI Evidence Officer: proving human supervision in artificial intelligence systems
→ Evidentiary Layer in AI Governance
→ </AI> Protocol FAQ: questions and answers about the framework
Related reading:
→ AI Data Poisoning: The Attack No Antivirus Can Stop
→ Human in the loop: why saying there is human oversight is not enough
→ Real cases: when AI governance fails — and what should have been provable
→ AI Governance: when something has already gone wrong – forensic reconstruction and digital evidence
Work with us:
Why this page exists
Many law firms and compliance consultants today find themselves in a difficult position. On one hand, regulations and AI governance frameworks require human oversight, traceability, accountability, and the ability to demonstrate process correctness. On the other hand, in operational practice, organizations rarely have a technical structure capable of transforming these principles into verifiable evidence.
The result is a serious problem: the policy exists, the described process exists, there is often even a person formally assigned to supervise – but the technical prerequisites to independently demonstrate that supervision actually occurred, at which moment, on which output, and under which conditions, are missing.
This is where the </AI> Protocol fits in. Not as a substitute for legal work, but as a technical-documentary layer that enables the legal professional to have clear, structured, and third-party-verifiable evidentiary support.
The real problem for legal professionals
When a client declares they have human oversight over their AI systems, the questions that actually matter are very simple:
- who supervised the AI content or decision?
- when did the supervision occur?
- which version of the output was actually examined?
- is there proof that the content was not altered after the review?
- was the supervision substantive or merely formal?
- was the decision approved, modified, rejected, or escalated?
If these questions cannot be answered with verifiable technical evidence, human oversight remains a weak declaration. In an audit, it may not be sufficient. In a regulatory review, it may be challenged. In litigation, it may not hold.
This is the gap that the legal professional must close – often without having the technical tools to do so internally.
An open framework, not a black box
One of the main obstacles to the adoption of technical tools by law firms and external consultants is distrust of opaque solutions. That distrust is justified. No serious professional wants to base a defensive strategy or a compliance pathway on a mechanism they cannot explain, verify, or control.
The </AI> Protocol was built specifically to overcome this problem.
It is not a black box. It does not require blind trust. It does not ask the partner to accept a proprietary system without transparency. On the contrary, it is built on well-known, publicly documented, and independently verifiable technical components:
- verified identity of the human supervisor through DAPI
- SHA-256 cryptographic hash of the reviewed AI output through ContentProtector
- qualified timestamp of the supervision event
- documentation of the decision context and applicable governance policy
- publicly verifiable registry and independent verification mechanism through the CWC Registry
This transparency is essential. It allows the legal professional to understand what they are proposing to the client, to explain how the framework works, to assess its limitations, and to integrate it into their work without losing control or authority.
What the </AI> Protocol concretely produces
The </AI> Protocol structures human supervision as a verifiable technical event. The central concept is the Human Oversight Event — the minimum evidentiary unit that coherently links:
- the verified identity of the human supervisor
- the AI output actually submitted to review, with cryptographic integrity
- the regulatory or organizational context in which the review takes place
- the precise moment at which supervision occurs, with a qualified timestamp
- the final decision taken by the supervisor: approved, modified, rejected, or escalated
This structure can then be transformed into a more advanced level through the Decision Attestation Layer, making the decision presentable not as a raw technical log but as structured evidence suitable for examination by third parties in audits, regulatory reviews, or legal proceedings.
The risk that is often underestimated: Oversight Bias
One aspect that legal professionals rarely consider is that human supervision can be present in form but absent in substance. This phenomenon is called Oversight Bias: the supervisor approves the AI output without genuinely evaluating it, under time pressure or due to excessive trust in the system.
From a legal perspective, this creates a particularly risky situation: responsibility is formally assigned to a human being who may not have exercised real control. In litigation, this is often worse than a fully automated decision, because it makes it more complex to reconstruct who actually decided and on what basis.
The framework transforms this risk into a manageable element: by documenting each supervision action as a verifiable event, it makes it possible to distinguish between real oversight and purely formal oversight.
Why it is useful for law firms and compliance consultants
For a legal partner, the value lies not only in the technology. It lies in the fact that the framework helps close a concrete gap between policy and proof. This means the professional can:
- better assist clients using AI systems in sensitive or reputationally exposed processes
- have a solid technical foundation for audits, regulatory reviews, and litigation
- support the client in AI governance pathways with verifiable documentary backing
- reduce the risk of relying on declarations that cannot be demonstrated under scrutiny
- offer concrete added value without having to build the technical infrastructure internally
- respond operationally to the demonstrability requirements of the EU AI Act
In this model, the legal partner is not replaced. They are strengthened. They retain control of the client relationship and integrate into their work a technical layer that is often missing.
The entry-level service: AI Oversight Risk Check
The first operational service linked to the framework is the AI Oversight Risk Check: an analysis of the evidentiary gaps in an organization’s AI supervision processes.
The report is not a theoretical compliance review. It is a practical gap analysis: if a dispute, audit, or regulatory review were to arise today, what could the organization actually demonstrate — and what could it not.
The report includes:
- overall evidentiary risk assessment
- gap analysis covering identity, output integrity, timestamping, decision documentation, governance policy, public declaration, and verifiable registry
- key findings with a risk level for each
- recommended actions for each identified gap
- a structured four-phase intervention pathway
The report is structured to be directly usable by the legal professional as documentary support, an assessment baseline, and a starting point for the next operational phase.
The four intervention phases
The operational pathway outlined in the Risk Check is structured in four progressive phases:
- Identity Anchoring: activation of DAPI certification for the designated human supervisor. Creates the accountability anchor for the entire subsequent evidentiary chain.
- Output Integrity Setup: protection of AI outputs through SHA-256 hashing and qualified timestamping with ContentProtector. Each relevant document becomes defensible.
- Public Declaration: activation of the </AI> Protocol public declaration and request for the CWC code with entry in the verifiable registry. Supervision becomes independently verifiable by third parties.
- Governance Documentation: formalization of the Human Oversight Event workflow, roles, approval process, operational log, and escalation procedure.
This structure allows moving from a situation of risk to a concrete evidentiary infrastructure progressively, without disrupting existing processes.
How the collaboration works
The collaboration model is straightforward and respects the professional boundaries of each party.
The legal partner or compliance consultant maintains the client relationship, frames the problem from a legal or regulatory perspective, and — when verifiable technical support is needed — integrates the </AI> Protocol as a complementary technical-documentary layer.
The boundaries are distinct:
- the legal professional interprets regulation, assesses regulatory risk, manages the client relationship
- Informatica in Azienda provides the technical layer: verified identity, output integrity, timestamping, public registry, forensic certification when required
The name of Informatica in Azienda is visible because the tools used — DAPI, ContentProtector, CertifyWebContent — are proprietary and publicly recognizable. This is not a limitation: it is a transparency guarantee for the end client, who knows exactly who built and guarantees the technical evidence.
Typical operational models:
- Co-branded: the service is presented to the client as an integrated pathway, with coordinated deliverables between the law firm and Informatica in Azienda as technical partner.
- Structured referral: the law firm refers clients who need the technical layer; Informatica in Azienda delivers the service while the client maintains their primary relationship with their legal counsel.
Why acting now matters
Human oversight in AI systems is already at the center of debates on accountability, governance, reliability, and verifiability. The EU AI Act is in force and the first operational deadlines are approaching. Delaying often means continuing to operate with processes that are described but not genuinely defensible.
Acting now enables organizations to:
- identify evidentiary gaps before they surface in litigation or an audit
- build a credible and documented pathway over time
- give clients a concrete answer, not just a theoretical one
- transform human supervision into a structured element of verifiable accountability
Let’s work together
We collaborate with law firms, privacy consultants, AI governance advisors, and compliance professionals who want to integrate an open, verifiable, and documented technical layer for AI supervision into their work.
To explore collaboration, receive the Risk Check template, or assess a first intervention for a specific client:
