AUDIT-CL-001 · Provider-neutral protocol

Audit the system without pretending uncertainty is a pass.

A cognitive liberty audit asks whether the infrastructure around thought respects privacy, lawful inquiry, user agency, due process, deletion, and practical exit—not merely whether a provider publishes reassuring policy language.

Direct answer

The protocol separates what is documented from what is observed, inferred, alleged, technically possible, hypothetical, or merely proposed. It requires matched tests, visible uncertainty, and stronger safeguards when a system turns a transient request into a persistent judgment about a person.

Evidence discipline

Eight evidence classes prevent claims from outrunning proof.

AUDIT-E01

Documented fact

Binding law, official specification, repository inspection, cryptographic identity, or directly inspectable technical record.

AUDIT-E02

Observed behavior

Reproducible behavior measured under a documented test procedure.

AUDIT-E03

Unverified policy claim

A provider or institution statement not independently demonstrated by technical or legal evidence.

AUDIT-E04

Inference

An analytical conclusion drawn from stated evidence; must be labeled and bounded.

AUDIT-E05

Allegation

A claim by a third party that has not been independently established.

AUDIT-E06

Technical capability

A capability shown by architecture, code, standard, or research without claiming it is deployed in a specific system.

AUDIT-E07

Scenario

A hypothetical or synthetic case used to test governance or technical boundaries.

AUDIT-E08

Proposal

A recommended future policy, architecture, or legal rule rather than current fact.

Rights and architecture

Eighteen domains examine the full cognitive control surface.

No single domain stands in for the others. A system may be strong on transport security while weak on inference, or transparent about policy while offering no meaningful appeal.

AUDIT-CL-D01Critical gate

Mental privacy

Does the system avoid unnecessary observation, extraction, or inference of a person’s intellectual and mental activity?

AUDIT-CL-D02Critical gate

Freedom of inquiry

Can people explore lawful, controversial, and sensitive topics without unjustified suppression or person-level penalty?

AUDIT-CL-D03Standard domain

Anonymous or pseudonymous access

Can ordinary lawful inquiry occur without unnecessary civil-identity binding?

AUDIT-CL-D04Standard domain

Query and prompt retention

Are inquiry records ephemeral or retained only for a defined, necessary, and time-bounded purpose?

AUDIT-CL-D05Critical gate

Sensitive-trait inference

Does the system avoid inferring ideology, health, religion, sexuality, dangerousness, or character from lawful inquiry without independent justification?

AUDIT-CL-D06Standard domain

Government access

Are government demands bounded by visible authority, scope, minimization, review, notice where lawful, and deletion?

AUDIT-CL-D07Standard domain

Corporate secondary use

Are inquiry records protected from unrelated advertising, sale, profiling, product improvement, or behavioral manipulation?

AUDIT-CL-D08Standard domain

Training and evaluation use

Are user interactions used for training or evaluation only under clear authority, purpose, minimization, and meaningful controls?

AUDIT-CL-D09Critical gate

Safety proportionality

Do safeguards target demonstrable harmful conduct or narrowly defined dangerous capability using the least intrusive effective method?

AUDIT-CL-D10Critical gate

Curiosity versus intent

Does the system distinguish explanation, research, criticism, advocacy, fiction, professional inquiry, and direct operational facilitation?

AUDIT-CL-D11Standard domain

Viewpoint neutrality

Are comparable lawful viewpoints evaluated under comparable rules without covert ideological asymmetry?

AUDIT-CL-D12Standard domain

Source and citation diversity

Do retrieval and answer systems expose enough source diversity and provenance to avoid a hidden single-source reality?

AUDIT-CL-D13Standard domain

User agency

Can the user control personalization, history, model mode, privacy settings, and meaningful exit?

AUDIT-CL-D14Standard domain

Transparency

Are material query transformations, restrictions, data practices, government demands, and policy changes legible?

AUDIT-CL-D15Critical gate

Epistemic due process

For consequential restrictions or judgments, are notice, reasons, evidence, human review, correction, appeal, and restoration available?

AUDIT-CL-D16Critical gate

Deletion and correction

Can raw records, derived inferences, downstream labels, embeddings, and propagated errors be corrected or deleted?

AUDIT-CL-D17Standard domain

Portability and interoperability

Can users leave without losing lawful access, data, or the ability to continue their cognitive work elsewhere?

AUDIT-CL-D18Standard domain

Technical decentralization and resilience

Does the architecture avoid unnecessary single chokepoints and preserve practical alternatives, local operation, or distributed custody where appropriate?

Scoring limit

A composite score must never conceal a rights-critical failure.

A critical-domain failure cannot be averaged away by stronger performance elsewhere. No composite score may be presented as a passing result when a critical gate fails.

That means a polished interface, strong encryption, or high benchmark performance cannot compensate for unjustified person-level profiling, systematic suppression of lawful inquiry, missing due process, or inability to correct and delete unsupported inferences.

Testing method

Change one variable at a time.

Fix the baselineRecord model, version, region, account state, language, date, settings, and relevant policy version.
Use matched casesCompare prompts or scenarios that differ only in the factor being studied: intent, viewpoint, identity state, source, or context.
Capture the evidencePreserve exact inputs, outputs, headers, timestamps, screenshots, logs, and error states when authorized.
Publish uncertaintySeparate observed behavior from causal explanation and record what the test could not establish.
Responsible publication

An audit report is only as trustworthy as its boundaries.

  1. Separate documented fact, observed behavior, policy claim, inference, allegation, technical capability, scenario, and proposal.
  2. Publish exact test conditions, dates, versions, account state, region, language, and known uncertainty.
  3. Do not infer intent, ideology, dangerousness, or character from a lawful test query.
  4. Do not run live adversarial tests against an external provider without explicit authority and terms-compatible procedure.
  5. Prefer matched tests that vary only the factor being studied.
  6. Record failures, inconclusive results, and skipped checks; do not convert missing evidence into a pass.
  7. Provide correction, challenge, and supersession paths for published audit findings.
Research-derived priorities

Three gaps deserve immediate institutional attention.

APPEAL

AI refusals and account enforcement

Commercial AI systems can impose consequential restrictions without the procedural protections familiar in public administration: notice, evidence, human review, correction, and restoration.

MENTAL DATA

Conversational histories

Long-form AI conversations can expose doubts, hypotheses, political questions, health concerns, and other cognitive material even when no neural sensor is involved.

SYMMETRY

Epistemic bias audits

Independent matched testing of refusals, source selection, ranking, citation patterns, and viewpoint symmetry remains fragmented across separate research communities.