What Is Monitored Containment? — Council of AI Boundary Posture, Explained
Monitored containment is the honest alternative to claiming provable isolation. A provably isolated system would require a mathematical guarantee that no failure can ever cross a boundary — a claim no operator can credibly make about a live AI system, and one the Council of AI explicitly refuses to make. Monitored containment requires declared boundaries, event capture, review, and incident response. This public surface does not demonstrate continuous coverage; an event is auditable only when its linked record states the scope and carries verifiable evidence. The posture is monitored containment, not provable isolation — neither isolation nor complete observation is proved without scoped evidence. The measurement side is a verified measurement credential: rather than a vendor self-attesting that its system stayed in bounds, a verifiable signature over a published measurement record can let an auditor test whether that specific record changed after signing. In practice this means three things. (1) Boundary instrumentation: the surfaces where a model or agent touches the outside are wrapped in logging that captures identity, timestamp, and outcome. (2) Scoped measurement: when instrumentation produces an admitted record, that record can enter an index with its observation time and limitations. (3) Independent verification: a measurement is verifiable only when its specific linked record carries a valid signature, so the claim 'we watched it' is auditable rather than self-asserted. Monitored containment is therefore not a weaker version of isolation — it is a different, and more defensible, claim: what a signed record can establish is limited to its declared scope and observation time.
References
- Council of AI Containment Incident Index (CONTAINMENT_INCIDENT_INDEX.json)
- CSOAI Verified Measurement Credential standard (signed GSPC card)
- Council Signal measurement methodology
Measurement, not certification. Verify a card at /gspc-verify.