Regulators are converging on a single demand: prove why the system decided what it decided. Most evidence trails answer a different question.
Emerging AI regulation keeps asking the same thing in different words: show why the system reached its decision, and show that a human could have intervened. The evidence most systems can produce is a log — a timestamped record of what happened, in what order.
A log proves sequence. It does not prove cause. It can show that an input arrived and an output followed, and say nothing about which factors actually drove the outcome or whether a human check was real rather than a rubber stamp. When the question is why, a record built to capture what answers a question no one asked — and the gap only becomes visible when it is too late to reconstruct the answer.
Project Ledger works backward from the question a regulator, auditor, or court will actually ask, and applies Corvion’s causal-influence research to the design of the record itself — so the evidence captures why a decision was reached, not only the order in which events occurred.
Studying what a record must contain to stand as evidence, rather than as an after-the-fact story.
Asking what has to be recorded in the moment, because it cannot be honestly rebuilt later.
Treating the points where a human could intervene as first-class events worth recording as such.
Designing the record for the moment someone disputes the decision, not only for routine audit.
Project Ledger studies what an evidentiary record for an automated decision should contain. It does not certify, attest, or provide assurance that any system is compliant with any law or standard, and it is not legal advice or an audit opinion.
This is a live research direction at Corvion, run in the open by design. The work centers on a single question: what a record has to contain to prove why an automated decision was made — not just what happened.
Our approach is to define that question rigorously — the criteria, the failure modes, and what would count as an answer — before building anything to serve it. We publish findings here as the work develops, including the results that don’t hold up.
We’re looking for internal audit and model-risk functions, assurance practitioners, standards contributors, and regulators willing to tell us what a record would have to contain to satisfy them.