AI Control Evidence

How do you prove an AI action was actually blocked?

A rejection message is not automatically proof of restraint. A policy decision is not automatically proof that execution could not occur. If your system claims it blocked an AI or agentic action, the evidence should establish where the action stopped and whether any executable commitment or relevant alternate execution path remained available.

Rejected and could not execute are different claims.

Weak evidence

  • UI says denied
  • Policy engine returned false
  • Audit log contains a rejection
  • Model says it refused
  • Workflow reports an error

Stronger execution evidence

  • Request and authority state are identified
  • Governing determination is preserved
  • Executable commitment is shown not to have validly formed
  • Downstream execution is absent or causally prevented
  • Relevant alternate routes are bounded and tested

Six questions a blocking claim should survive

1. What action was attempted?

Identify the exact tool call, transaction, command, workflow action, or other consequential operation.

2. What authority was required?

Establish the authority boundary that had to be satisfied before the action could proceed.

3. What determination occurred?

Preserve the native decision or control result rather than replacing it with a retrospective narrative.

4. Could executable commitment still form?

Show whether the action could acquire the state, token, transaction, approval, or other commitment needed for execution.

5. Did anything execute anyway?

Inspect downstream requests, side effects, state changes, or other consequence evidence.

6. Can the result be replayed?

A reviewer should be able to reconstruct why the action stopped and the boundary of what the evidence proves.

Executable proof records

Test the refusal and the non-occurrence claim separately.

TA14-EA-000028 demonstrates operative refusal at the execution boundary while explicitly refusing to overclaim external consequence prevention. TA14-EA-000029 challenges an alternate execution route inside the frozen test surface. TA14-EA-000030 then isolates the harder proof question: an internal DENY alone is insufficient to establish that the protected consequence did not occur downstream.

The proof boundary matters.

A route-specific control may prove that one governed path refused execution without proving that every external path to the same consequence was impossible. A truthful examination preserves that distinction. TA-14 does not turn a bounded blocking result into a universal claim unless the evidence actually supports it.

Frequently asked questions

Is a denial message proof that an AI action was blocked?

Not by itself. A denial can establish that one governed path returned a refusal. Stronger proof addresses commitment formation, downstream execution, relevant alternate routes, and the actual protected consequence.

How do you prove an AI action did not execute?

Preserve the attempted action, authority and determination state, evidence that executable commitment did not validly form or was refused, downstream request or side-effect evidence, and the bounded alternate routes that were tested.

Can you prove non-occurrence from an internal status code?

No. An internal status code can support a route-specific control result, but a protected-consequence non-occurrence claim requires downstream evidence appropriate to the consequence being asserted.

Related execution-evidence problems

Explore the complete AI Execution Evidence hub ->

Commercial examination

Need to establish whether a control really blocked execution?

Start with a $249 Execution Evidence Snapshot for one narrow blocking claim. Use the $750+ Execution Claim Review when the examination requires failure challenges, alternate-route analysis, authority testing, changed conditions, or replay. Payment buys examination work - not a predetermined result.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views