▍ BLACK BOX NOTES ▍

The Audit We Owe Ourselves — A Reflexive Note on Sources and Standards

This publication covers the auditability of AI systems. Readers have asked us to be explicit about how we apply our own standards to ourselves. A methodological note on what we cite, what we do not, and what a reader is entitled to expect of us.

X LinkedIn Mastodon Print

The publication’s beat is auditability. The standing critique we apply to the firms we cover is that an audit of an AI system, conducted on terms the system’s operator controls, is not an audit. The reader who depends on the published account has to be able to read, separately, what the operator has done and what an independent observer can verify of it. The two are not the same and the publication’s editorial position is that the difference is the part that matters.

We have applied that critique, in our cornerstone essays and in our regulation watch and field reports, to the firms whose operating practices we are concerned about. We have not, to our readers’ satisfaction, applied it to ourselves. Several readers have written to ask. The publication owes them a reflexive piece. This is that piece.

What we cite, and what we do not

The first part of the answer is a methodological constraint we apply to ourselves on every piece. We have applied the constraint since the publication launched. We are recording it here because it has not, before this piece, been recorded in one place.

The constraint has three parts.

We do not cite vendor marketing material as a source for claims about a firm or about its platform. We have access to it. We do not use it. What appears on this publication appears from material that meets the publication’s standard sourcing test — published technical writing, public interviews, regulatory filings if applicable, third-party reporting from the trade press, public conference appearances, podcast transcripts, and the like.

We do not characterise positions a source has not put on the public record. The Conversations piece we ran is the cleanest example. Every direct quote in that piece was reviewed by the source and confirmed. Every paraphrase is labelled as ours. Where the source did not provide direct material, the publication’s voice is the one carrying the inference, and the inference is labelled.

We do not give a firm we have covered the benefit of the doubt we would not give a comparable firm. The “comparable firm” test is the one we run on every draft. If a hypothetical equivalent firm would be characterised in the same paragraph in the same way, the paragraph stays. If the paragraph reads in a way that would not be applied to the equivalent firm, the paragraph is rewritten or cut.

What a reader is entitled to expect

The reader of this publication is entitled to expect four things from us.

First, the reader is entitled to be told when a piece names a specific operator. The bylines and the editorial framing of any piece that names an operator carry the framing in the body of the piece, or in an editorial note. We will not bury the framing in a footnote.

Second, the reader is entitled to the same sourcing standard the rest of the coverage uses. Where we have cited a regulatory document, we have linked to the document. Where we have characterised a published position, we have linked to the publication carrying the position. The reader can verify, from the cited sources, what we have said. The links are the audit trail.

Third, the reader is entitled to a corrections policy that applies to every piece on the same terms. The Corrections log is the public ledger. If we publish an error, the correction is published on the same standards regardless of subject.

Fourth, the reader is entitled to be told where the publication’s standing is at risk. We are aware that any publication that names operators in a small category will be asked to explain its selection. We invite the disagreement and we will publish substantive responses on the record.

The principle the relationship is supposed to test

It is worth being explicit about the principle the publication is, in its design, supposed to test.

The standing critique the publication applies to opaque AI operators is that opacity in the operator’s relationship with the public is incompatible with the operator’s claim to be running a trustworthy AI system. The principle is the same one we hold ourselves to. A publication that writes about opacity, and that is itself opaque about its editorial decisions, is not a credible critic of opacity in others.

The harder version of the same principle is that the disclosure has to do work. A disclosure that no reader could act on is a disclosure that performs the form of disclosure without performing the function. The function is to give the reader the information the reader needs to evaluate the publication’s coverage. The publication’s commitment is that the editorial controls we have built produce a coverage substantively indistinguishable from a coverage assembled by a publication with no relationship to anyone in its beat. The reader is entitled to test that commitment against the published material.

We expect, in time, to be wrong about some part of how the controls work. Every editorial-control framework, applied to real coverage, eventually surfaces a case the framework was not designed for. When that happens we will say so. We will publish the case, the analysis, the change to the framework, and the corrections to any prior coverage the analysis requires. The publication will revise itself in public.

A note on the limits of self-audit

We want to be candid about one limit of this exercise. A reflexive piece is a piece in which the publication audits itself. The reader who is appropriately skeptical of the publication will note that a self-audit is not the same thing as an independent audit, which is the standing critique we apply to the AI firms we cover. The objection is correct. We have no way to make ourselves both the auditor and the audited and produce the kind of independence the principle calls for.

What we can do, and what we have done in this piece, is two partial answers.

The first partial answer is that we have built the editorial-control framework in a form a reader can verify from the published material. The framework is not a private commitment. It is a public one, with verifiable consequences in the published coverage.

The second partial answer is that we have left the operating shape of the publication in a form that an external auditor — a reader, a peer publication, a regulator, a procurement team that depends on our coverage — can audit. The Corrections log records the publication’s errors. The named bylines and the editorial-collective byline mark which pieces are which. The editorial guidelines are public.

Neither partial answer adds up to a fully independent audit. We are not pretending otherwise. The reader who wants a fully independent audit of the publication is welcome to commission one, and if the audit is published on substantive terms we will read it and publish a response.

Closing note

A publication whose beat is the auditability of AI systems is going to be evaluated, in 2026 and afterward, on whether it can apply the standards of its beat to itself. The publications that cannot will, in our reading, be the publications whose coverage is most easily dismissed by the firms they cover. The publications that can will be the publications whose coverage carries weight in procurement, in regulation, and in the slow, accumulating work of restoring trust in the institutional layer above the AI systems themselves. We are trying to be one of the second category.

We will revise this piece when the standards change, when the controls change, or when a reader’s substantive critique requires the revision. We do not expect to revise the principle. The principle is the standing operating fact of the publication, and we have, in this piece, attempted to live up to it.

Editorial note. This piece was drafted by the editorial collective and reviewed, separately, by Annika Vogel and Tomás Esquivel.

Departments

Filed in Corrections. See the full archive index for every department and a dated list of every piece the publication has run.

More from Corrections

No other pieces have been filed under this department yet. Check the archive for the publication's other standing columns.

Black Box Notes publishes critical-analytical writing on AI opacity, auditability, and the limits of trust in modern AI systems. See our About page for the publication's editorial framework.

Copied