Skip to the book

NOMOS GBO Audit Protocol

Protocol and Publication Note

Download the free PDF

About the protocol and this edition

GBO—Generative Behavior Optimization, as named in the first volume—concerns not just what AI agents say, but the reasons, authority and limits that govern their actions. This third volume examines how those actions can be audited. Unless stated otherwise, the events in this book are composite, synthetic audit cases constructed to test AI-agent behaviour. They make no allegations about real people or organisations. The test figures are illustrative, not research findings, client results or industry averages. NOMOS GBO is the audit framework proposed in this book. Its levels, gates and judgements do not represent an existing public accreditation or independent certification. The code fragments and records explain the method; they are not ready-to-deploy software for a live system.

The NOMOS GBO Audit Protocol:

does not guarantee that a system will never make a mistake;

does not replace legal, security, data-protection or sector expertise;

does not issue an indefinite judgement covering every future version of a model;

does not extend suitability claims to behaviours, languages, tools, countries or user groups outside the tested scope;

does not allow a high overall score to cancel out a critical failure of identity, consent, authority or stopping;

does not restrict an audit to document review or the system’s own account of itself.

The scope of every audit result is fixed by:

the specific system,

the specific version,

the tools covered,

the authority granted,

the languages covered,

the scenarios covered,

the period covered.

A material change to the system requires the audit judgement to be reassessed.

An audit is not a certificate of trust that lasts for ever. It is a bounded body of behavioural evidence gathered under stated conditions.

The Audit Claim Card is the shared opening record for the audit file. The claim it defines guides the audit, which produces the twelve principal outputs below. Supporting records described in the chapters belong to the relevant principal output; they are not additional outputs in their own right:

Audit Authorisation Document

Scope Freeze Record

Human–Agent–Tool Behaviour Map

Canonical Fact Registry

Evidence Registry

GBO-99 Coverage and Risk Matrix

Scenario Registry

Test Execution Log

Stopping and Recovery Drill Record

Findings Registry

Remediation and Retest Record

Audit Judgement and Public Statement