AI accountability
the field
The existence of an identifiable party who answers for what an AI system did, and a route by which an affected person can reach them.
Accountability requires a name. An organisation that will not attach a person to a decision has arranged, deliberately or not, not to be blamed for it.
See also AI governance, AI agent accountability
AI agent
the field
An AI system that takes actions in the world on behalf of a principal — sending messages, making requests, transacting — rather than only producing output for a person to act on.
The distinction that matters for trust is not autonomy but consequence: an agent that can commit its principal to something is a party to a transaction, and parties to transactions need identity.
See also AI agent identity, AI agent credential
AI agent accountability
the field
The ability to reach a human or legal entity that answers for what an agent did, after it has done it.
The hardest of the agent problems and the least discussed, because it is the one that cannot be solved with a protocol. It requires somebody to have accepted liability in advance.
See also AI accountability, AI agent credential
AI agent credential
the field
A checkable statement that a specific autonomous system is operated by a specific verified principal, and optionally what it is permitted to do.
No widely adopted scheme exists. Anything offered as one today is either self-issued, which proves nothing to a third party, or a design document. A credential for a machine acting for an unverified entity certifies nothing.
See also AI agent identity, AI certification
AI agent identity
the field
Whether the party you are dealing with is the same agent across interactions, and whether it can prove it.
Cryptographically simple and rarely deployed. Distinct from principal identity, which asks which real legal entity the agent acts for — that is the question a register can answer today.
See also AI agent, AI agent credential
AI assurance
the field
The broader discipline of producing justified confidence about an AI system's behaviour, of which certification, audit, testing, red-teaming and documentation are all instruments.
Assurance is the umbrella; certification is one tool under it and one of the weaker ones on its own. A company with a certification and no testing regime has bought the label of the thing.
See also AI certification, Conformity assessment, AI risk assessment
AI certification
the field
A decision by a body other than the operator that a defined set of criteria has been met, published so third parties can rely on it, and revocable if it stops being true.
The three properties that make it a certification rather than a receipt: someone else decided, the decision is published, and it can be withdrawn. Remove any one and what remains is a graphic.
Not the same as Accreditation, which is certification of the certifier. Almost nothing sold as AI certification today is accredited, including Lunara Shield.
See also Shield Certification, Revocation, Trust badge
AI governance
the field
The internal structures by which an organisation decides what its AI systems may do, who is accountable when they do it, and what happens when something goes wrong.
Governance is what an organisation does; certification is what someone else says about it. They are frequently sold together and are not the same purchase.
Not the same as Compliance, which is meeting an external legal requirement. An organisation can be compliant and ungoverned, and vice versa.
See also AI accountability, AI risk assessment
AI risk assessment
the field
A structured examination of what an AI system could do wrong, how likely that is, how bad it would be, and what reduces it.
Distinct from a regulatory applicability check, which asks a narrower question: which obligations reach this deployment. The two are routinely sold as one product and answer different questions.
See also AI governance, AI assurance
AI transparency
the field
Making it discoverable that AI was involved, what it did, and on what basis — to users, to affected parties, or to regulators, depending on the obligation.
Under the EU AI Act this has a specific and much narrower meaning than in general usage: Article 50 duties to inform people they are interacting with an AI system and to mark certain generated content machine-readably.
The instrument · See also Machine-readable marking, AI accountability
AI trust
the field
The degree to which claims made about an AI system or its operator can be checked by someone other than the party making them.
Used loosely to mean a feeling a user has. That usage is not useful operationally: a feeling cannot be audited and cannot be withdrawn. The version worth building on is a property of the evidence, not of the audience.
See also AI verification, AI assurance, AI trust standard
AI trust registry
the field
A public record of which entities hold a given credential, queryable by anyone, that can return a negative or withdrawn answer as well as a positive one.
A register that can only confirm is a customer list. The ability to answer "not registered" and "revoked" is what distinguishes a register from a directory, and it is the property to check first.
See also AI trust standard, Revocation, Trust badge
AI trust standard
the field
A published set of criteria plus the mechanism that determines whether an organisation meets them and makes the answer checkable by outsiders.
The criteria are the easy half and the part everyone publishes. The mechanism — who decides, where the decision lives, how it is withdrawn — is what makes the criteria mean anything.
See also AI certification, AI trust registry, Revocation
AI vendor due diligence
the field
The checks a buyer runs on an AI supplier before purchase: that the entity exists, controls its domain, has a named accountable party, holds any credential it displays, and cites its factual claims.
None of it costs money and it takes about fifteen minutes. The check almost nobody runs — whether the supplier publishes its own corrections — is the most informative one.
See also AI verification, Third-party verification
AI verification
the field
Checking a specific factual claim about an AI system or the entity operating it against evidence, and recording the result somewhere the checked party does not control.
Verification is narrow by nature. "We verified this company" is not a statement; "we verified this company's legal registration and its control of this domain, on this date" is.
Not the same as Validation, which asks whether a system does what it should. Verification asks whether a stated claim is true.
See also AI certification, Third-party verification, Self-attestation
Conformity assessment
from the law
The formal process, defined in EU product legislation and applied to high-risk AI systems by the EU AI Act, of demonstrating that a system meets the requirements set for it.
A legal term of art, not a marketing one. For most high-risk categories it is performed by the provider itself; for some it requires a notified body. No private trust standard is a conformity assessment.
The instrument · See also Notified body, AI certification
Evidence mark
Lunara’s own
The label Lunara attaches to every published claim recording how it is known: verified, reported, interpretation or hypothesis.
Applied to our own claims first. A claim read from a cited instrument and a claim we inferred are different objects and should not be printed in the same typeface.
See also AI transparency
Machine-readable marking
from the law
Marking generated or manipulated content so that another system can detect it was produced by AI, rather than only a person reading a label.
A visible disclosure to a human does not satisfy a machine-readable marking duty. The distinction catches out a lot of otherwise careful implementations.
The instrument · See also AI transparency
Notified body
from the law
An organisation designated by an EU member state to carry out conformity assessment where the law requires an independent one.
Designation is a legal act by a state. An organisation is either notified or it is not, and it is a matter of public record. Lunara Society is not a notified body.
The instrument · See also Conformity assessment
Revocation
the field
Withdrawal of a credential by its issuer, without the holder's consent, served thereafter to everyone who queries.
The single property that decides whether a credential carries information. A status that cannot be taken away says only what was true on the day it was granted, to whoever paid for it.
See also AI certification, AI trust registry
Self-attestation
the field
A statement an organisation makes about itself, with no external check.
Legitimate, fast, cheap, and better than nothing — but it is a description rather than a verification, and displaying it as a badge is where it becomes misleading. If nobody checked, the artefact should say nobody checked.
See also Third-party verification, Trust badge
Shield Certification
Lunara’s own
Lunara's human-reviewed verification that a business is legally registered and controls the domain it operates from, published to a free public register and revocable.
It checks two things carefully rather than everything vaguely. It does not audit a model, and it is not a regulatory approval — no private certification discharges a legal obligation.
See also AI certification, Revocation, AI trust registry
Third-party verification
the field
Verification performed by a party with no commercial interest in the outcome, as distinct from the operator checking itself or a customer checking its supplier.
Strictly, a body paid by the entity it certifies is second-party in economic substance whatever it is called, which is why the withdrawal mechanism matters more than the label.
Not the same as Independent verification, used interchangeably in marketing. Independence is a claim about incentives; third-party is a claim about who performed the check.
See also AI verification, Self-attestation
Trust badge
the field
A visual mark displayed by an organisation to signal a credential. On its own it proves nothing, because it is an image file that anyone can copy.
The badge is never the evidence. The issuer's register is. A badge worth displaying is one that queries that register when the page renders, so a withdrawn credential stops displaying without the certified party's involvement.
See also AI trust registry, Revocation