VSO-VAP-SPEC-001 | Version 1.1 | December 2025

VAP — Verifiable AI Provenance Framework

The Flight Recorder for AI

Aircraft have flight data recorders. Nuclear plants have detailed monitoring systems.

But AI systems making millions of decisions per second? Almost none have tamper-proof records.

VAP solves this problem.

"Encoding Trust in the AI Age"

Maintained by VeritasChain Standards Organization (VSO)

Why Now?

The regulatory landscape and incident trends demand a new approach

Regulatory Pressure

  • EU AI Act (2026) — Mandatory logging for high-risk AI
  • MiFID II RTS 25 — Algorithmic trading records
  • GDPR Article 22 — Right to explanation

Rising Incidents

  • Flash crashes from algorithmic trading
  • AI decision disputes in finance & healthcare
  • Autonomous vehicle accidents

Evidence Gap

  • No tamper resistance — Logs can be altered
  • No causal chain — Can't trace decision flow
  • No legal standing — Logs aren't proof

What VAP Fills

Tamper Detection

Hash chain + Merkle tree

Causal Traceability

Input → Decision → Outcome

Legal Evidence

Cryptographic proof

What is VAP?

A cross-domain meta-framework for cryptographically verifiable AI decision provenance

Definition

VAP (Verifiable AI Provenance Framework) specifies the requirements for cryptographically verifiable decision provenance common to all high-risk AI systems — a cross-domain meta-framework.

Core Message

VAP is NOT "regulation that stops AI."
VAP IS "provenance infrastructure that enables AI to continue operating safely."

Important: VAP Does NOT Work Alone

VAP is NOT an implementation specification.

Actual implementations are domain-specific profiles: VCP (Finance), MAP (Medical), DVP (Automotive), EIP (Energy), PAP (Public Policy)

VAP defines "the minimum conditions that must be met."

Think of VAP as the "interface contract" — domain profiles are the "implementations."

Scope

VAP targets domains where: "When it fails, people or society seriously die or collapse."

Systems where failures cause irreversible damage to human life, social infrastructure, or democratic institutions.

Target Domains

Five high-risk domains where AI decision transparency is not optional — it's existential

Finance

VCP

VeritasChain Protocol

Algorithmic trading audit trails, HFT systems, AI-driven trading strategies

v1.0 Released

Healthcare

MAP

Medical AI Protocol

AI diagnostic systems, imaging analysis, treatment recommendations

View MAP

Transportation

DVP

Driving Vehicle Protocol

Autonomous driving (L3-5), ADAS, aviation AI, drone control

View DVP

Energy

EIP

Energy Infrastructure Protocol

Smart grid AI, power network management, critical infrastructure

View EIP

Public Policy

PAP

Public Administration Protocol

Credit scoring, welfare decisions, immigration AI, hiring algorithms

View PAP

Common Thread

In these 5 domains, AI transparency and traceability is not "nice to have" — it's "civilization cannot function without it."

  • Irreversible consequences
  • Society-wide impact
  • Speed beyond human intervention

Architecture Hierarchy

VAP / VSO / Domain Profiles — A three-layer standardization structure

VAP (Verifiable AI Provenance Framework)

Conceptual Meta-Framework

Defines the minimum requirements common to all domains — the abstract layer for AI decision provenance

defines & maintains

VSO (VeritasChain Standards Organization)

Standards Body

The organization that develops, maintains, and certifies VAP — ensures consistency across profiles

publishes profiles

Domain-specific protocol implementations

Technical Foundation

Four core layers that make AI decisions cryptographically verifiable

1

Cryptographic Primitives

Integrity Layer

  • Hash Chain — Tamper detection through cryptographic linking
  • Digital Signatures — Ed25519 + future Dilithium support
  • Merkle Trees — Efficient verification at scale
2

Provenance Layer

Decision Origins

  • Actor — Who made the decision
  • Input — What data was used
  • Context — Under what environment/constraints
  • Action — What was decided
  • Outcome — What was the result
3

Temporal Integrity

Time Consistency

  • UUID v7 — Time-embedded unique identifiers
  • IEEE 1588-2019 (PTP) — Precision time synchronization
  • TSA Anchoring — External timestamp authority
4

Crypto Agility

Future-Proofing

  • Post-Quantum Ready — Dilithium migration path
  • Algorithm Identification — Mandatory algorithm tags
  • Smooth Migration — Hybrid signature support

Shared Assurance Core

All VAP domain profiles (VCP, MAP, DVP, EIP, PAP) share a common cryptographic foundation

One Core, Many Profiles — Domain profiles extend VAP but never replace the Shared Assurance Core.

Canonical Serialization

JCS (RFC 8785) — Deterministic JSON serialization for consistent hashing across implementations.

EventID

UUIDv7 — Time-ordered unique identifiers enabling temporal ordering and global uniqueness.

Hash Chain

SHA-256 / SHA-3 — Cryptographic linking of events for tamper detection and integrity verification.

Merkle Batching / Anchoring

Merkle Trees — Efficient batch verification and external anchoring to TSA or blockchain.

Signature Scheme / Key Model

Ed25519 + Dilithium — Current and post-quantum signature algorithms with defined key lifecycle.

Proof Format

Standardized Verify Procedure — Defined proof structure and verification algorithm for cross-domain interoperability.

Domain Profiles Built on Shared Core

All profiles inherit and implement the Shared Assurance Core

Why "Explainable AI (XAI)" Isn't Enough

Explanation ≠ Verification — Understanding the fundamental difference

Aspect Explainable AI (XAI) Verifiable AI (VAP)
Question Answered Why was this decision made? Can we prove this decision actually happened?
Output Type Post-hoc interpretation Cryptographic evidence
Tamper Resistance None Hash chain detection
Analogy "Let me explain with a PowerPoint" "Here's the black box data"
Legal Standing May be challenged Cryptographic proof

XAI answers "Why?" — VAP answers "Did it really happen, and can you prove it?"

Regulatory Alignment

VAP is designed to meet current and emerging international regulations

EU AI Act Article 12

Automatic logging for high-risk AI

MiFID II RTS 25

Algorithmic trading recording requirements

GDPR

Data protection & right to erasure (Crypto-shredding)

US CAT Rule 613

Consolidated Audit Trail

NIS2 Directive

Critical infrastructure security

FDA AI/ML SaMD

Medical AI device guidance

Standardization Roadmap

Path toward international recognition and adoption

2025 Q3 Planned

IETF Internet-Draft Submission

Initial draft submission to Internet Engineering Task Force

2026 Planned

ISO/TC 68 (Financial Services) Activity

Engagement with ISO Technical Committee for financial services standardization

2026-2027 Planned

ISO/IEC JTC 1/SC 42 (AI) Alignment

Harmonization with international AI standards committee

2027+ Consideration

IEEE Standards Association

Potential IEEE standardization track

Governance: Non-Profit & Neutral

VSO is an international standards body for AI decision provenance

VSO is positioned like W3C, IETF, IEEE, or FIX Protocol — defining rules for the public good, not selling certifications.

VSO: Rules Only

  • Develops and maintains specifications
  • Defines compliance requirements
  • Does NOT perform audits or certification

CABs: Certification

  • Independent Conformity Assessment Bodies
  • Perform actual audits and issue certificates
  • Separation of rule-making and certification

Open Standard

  • VAP/VCP specs freely available (CC BY 4.0)
  • No licensing fees for implementation
  • Fully open source on GitHub

Like IETF for Internet protocols or W3C for Web standards,

VSO provides the rules — not the business.

"Aircraft have flight recorders. AI needs one too."

— VeritasChain Standards Organization

VAP Framework Specification is licensed under CC BY 4.0 International