Governance · Enterprise Risk

You can’t evidence what AI said about you.

Investors, regulators and procurement teams increasingly ask AI to assess your company — and those assessments leave no durable record. When scrutiny arises later, the enterprise cannot reconstruct what was said, or how it responded. This is a structural governance gap, not a compliance oversight.

By Tim de Rosen AIVO Standard · Governance research Published Jan 2026 ≈ 6 min read

Using large-scale AI systems to summarise, compare and evaluate a company has become a routine precursor to consequential decisions. Investors query AI during diligence. Procurement teams use it for supplier screening. Journalists, regulators and litigants increasingly consult AI outputs as context.

In these settings, AI systems act as representational intermediaries: they don’t merely retrieve information, they synthesise, contextualise and prioritise claims about an enterprise in ways that influence human judgment. And they operate outside the governance perimeter of the organisations they describe — the enterprise neither controls the system nor receives any record of what it said. That condition creates a distinct problem that existing risk, compliance and audit frameworks do not address.

The failure mode

It isn’t AI error. It’s evidentiary absence.

The governance issue here isn’t whether the AI was wrong. It’s that a material representation was made, relied upon, and left no record — and that becomes consequential the moment review turns retrospective.

1
A third party queries an AI system about the enterprise.
2
The AI generates a representation — a characterisation, assessment or claim.
3
That representation influences a perception, a decision, or an action.
4
No authoritative record of the representation is created.
5
Scrutiny arises later — a board review, an audit, a dispute, a regulatory inquiry.
6
The enterprise cannot evidence what was said, or how it responded.

The questions that follow — “What did the AI say at the time? Was it accurate? Did leadership know? Was corrective action taken?” — in most cases cannot be answered with evidence. The absence is structural, not negligent: governance frameworks presume the existence of records, and this presumption no longer holds.

Why it can’t be reconstructed after the fact

These representations don’t sit still

You can’t simply re-run the query later and recover what was said. External AI representations have three properties that defeat retrospective reconstruction.

Property 01

Temporal variance

The same query at a different time produces materially different output — from model updates, retrieval-layer changes and shifting training data.

Property 02

Context sensitivity

Small changes in phrasing, intent or conversational context alter which facts are selected, how uncertainty is expressed, and whether caveats appear at all.

Property 03

Non-reproducibility

An output observed at one moment often can’t be reliably reproduced later — even when the exact prompt is preserved.

These are well known to AI practitioners — and almost never reflected in enterprise governance assumptions.

Why it matters to the board

Three places the gap surfaces

Board oversight

Can’t evidence what you acted on

Boards are increasingly expected to oversee AI exposure — but the risk isn’t that leadership failed to act; it’s that they can’t evidence what they were acting on.

Legal & disputes

The asymmetry favours the claimant

If an AI-mediated statement is alleged to have influenced conduct, then without contemporaneous records rebuttal becomes speculative, adverse-inference risk rises, and factual uncertainty favours the other side.

Audit & assurance

Non-auditable by default

Audit depends on traceability and evidence survivability. External AI representations introduce a category of material influence that is, by default, not auditable.

“The risk is not that boards failed to act — but that they cannot evidence what they were acting on.”
The response

Preserve the evidence — don’t police the AI

A natural objection is the timing paradox: how can an enterprise know when to preserve evidence if it doesn’t know what the AI said? The answer is that this isn’t continuous surveillance — it’s activation conditions. Enterprises already recognise trigger-based governance responses: litigation holds, incident-response protocols, regulatory inquiries. The same logic applies — evidence preservation is activated by context, not constant monitoring.

The paper describes a response class rather than a product. A governance-aligned response to the evidentiary gap would have five properties:

  • Contemporaneous capture of external AI representations, at the time they occur.
  • Preservation of the original context and parameters.
  • Immutability of the stored record.
  • Separation from behavioural control or content manipulation — it changes nothing about what AI says.
  • No continuous-monitoring obligation — it creates the ability to explain, not a new duty to surveil.
“The objective is not to change what AI systems say, but to ensure that what was said can later be evidenced.”
Scoped deliberately

What this argument is not

This is not a claim that enterprises have a duty to monitor or correct external AI outputs, nor that AI accuracy is the primary risk, nor that harm has occurred in every case. It identifies a failure mode that becomes material only when scrutiny arises — and recognises evidence survivability as a governance requirement in its own right. Governance is concerned with explainability under review, not the frequency of failure.

The full paper

Read the complete working paper

This article is an overview. The full paper defines external AI representations and decision-adjacent queries, documents the evidentiary failure mode and its properties, situates it within governance, audit, legal and ESG frameworks, and sets out the architectural response class — published open-access on Zenodo with a permanent DOI.

Citation: de Rosen, T. (2026). External AI Representations and the Evidentiary Gap in Enterprise Governance. AIVO Standard. Zenodo. https://doi.org/10.5281/zenodo.18443706 · Licensed CC-BY-4.0.