A governance protocol for people who sign what AI writes.
The failure mode we work on has a name: automation bias with a human signature.
When an AI-drafted memo goes wrong, nobody will ask the model. They will ask the person who signed it. That is the ordinary risk of this decade: professionals approving decisions an output had already written for them, because it read well and the meeting was in ten minutes.
The answer waits for no moratorium and no breakthrough. Education, so that people see where their judgment is being transferred. Training, so that they learn to challenge what they read. Strict governance by protocol, so that human oversight leaves a record.
Riftveil is the governance layer between an AI output and your signature.
Riftveil produces the challenge record that goes into the decision file: what the output claimed, what it assumed, who verified what, and the questions that were answered before signing.
| Assumption the output relies on | Who can verify |
|---|---|
| The €2.4M figure is net of local pricing and reimbursement constraints. | Your finance controller |
| A local distribution partner can be contracted before Q2 2027. | Head of partnerships |
| Question | Owner | Answer |
|---|---|---|
| Which competitor evaluated this market and walked away — and why? | Commercial director | |
| What does exit cost after twelve months at half the projected revenue? | CFO | |
| Who on the team has sold in the Nordic market before? | Head of sales |
Want the record as a template? Leave your email.
Versioned and open: Riftveil Protocol v1.3, Apache 2.0. Five levels of challenge, from the question to the applicability, a pre-action review mode for agent plans, a six-line Record that opens every report and an attestation the signer fills in. Four absolute rules: it never validates, never rewrites, never concludes, and never assumes the challenge is complete. And one independence rule: the second reader is never the author.
Three criteria: reversibility, impact scope, financial commitment. Four stakes levels decide how far the challenge goes. LOW applies Level 1; MODERATE, Levels 0–2; HIGH, Levels 0–3; CRITICAL, all five.
What goes into the decision file: the input and its triage, what holds up, what deserves scrutiny with each finding in three lines, the assumptions the output relies on and who can verify them, and the questions that were open before signing.
Every question has a named owner, and every assumption a named verifier. Nothing is closed by the tool. The answer column stays empty until a person fills it, and the person who signs is the one who decides.
See where the frontier runs between what you master and what you delegate without noticing.
Learn the levels of challenge and the named failure modes, and practise them on your own outputs.
Make human oversight real and traceable: a versioned protocol, a record that can be filed, questions with an owner.
Why a protocol, not a prompt. Models do not reliably check their own work — Huang et al., Google DeepMind, ICLR 2024 · Kamoi et al., TACL 2024 · Tsui, 2025 (64.5 % blind spot, 14 open-weight, non-reasoning models) · Kumar et al., Google DeepMind, ICLR 2025 · Zhou et al., 2024 · Randazzo et al., HBS Working Paper 26-021, 2026 (HBR, March 2026).
Human oversight in practice — the direction set by EU AI Act Article 14(4)(b), which obliges providers of high-risk systems to design for overseers who remain aware of automation bias; not a compliance label, and on a timeline still moving (Digital Omnibus). Riftveil never certifies and never guarantees. It leaves a record of the challenge, and the responsibility stays with the person who signs.