Open an old proposal deck and find the certification logo in the footer.
The certificate expired eleven months ago. The provider changed its model supplier twice. The service team now uses a workflow that never appeared in the original review.
The badge still glows green.
That is not assurance. It is an image file with excellent job security.
If the badge cannot turn off, it means nothing.
A credible assurance mark must track current truth. Scope can narrow. Conditions can appear. A material change can trigger review. A serious failure can suspend the claim. Time can expire it.
Losing the positive signal is not a defect in the product. It is proof that the product governs something real.
Status is a state, not a sticker
A static logo carries almost no information on its own.
Who was reviewed? Which service? Which AI uses? Which tools and data classes? What evidence period? Which exclusions? Who made the decision? Is the result still current?
The Federal Trade Commission's seal guidance warns that an unqualified seal can imply broad benefits its issuer may not support. The FTC tells marketers to place the basis and limits of the claim clearly and prominently. It warns that a logo may not give people enough reason to click for the missing context.
That logic travels cleanly to AI assurance.
“Certified AI” is broad enough to mean almost anything. A current record for a named service, named uses, dates, exclusions, and status can be inspected.
One is atmosphere.
The other is a claim.
Seven states make the claim honest
The proposed registry uses seven public states. Each answers a different buyer question.
| State | Buyer meaning | Permitted public treatment |
|---|---|---|
| Certified | The named boundary meets the stated requirements for the current period | Active treatment linked to the live record |
| Conditional | The boundary has a positive decision with a visible, time-bound condition | Amber treatment with the condition adjacent |
| Under review | A material change or credible concern is being assessed | Review banner; no omission of the open review |
| Suspended | The positive claim is paused | Inactive treatment; no active certification claim |
| Withdrawn | The certification ended before ordinary expiry | Historical record only; current mark use prohibited |
| Expired | The approved period ended without a current renewal | Historical dates only; current mark use prohibited |
| Superseded | A newer record replaced this one | Historical record linked to the current version |
These are design decisions in a proposed architecture. They are not live Petrichor certificate states.
Petrichor's current AI Assurance work is readiness and implementation, not certification. The certification, registry, and mark described here are a proposed market architecture that still requires independent governance, validation, and legal review.
The mark must change everywhere
Suspending a row in a private spreadsheet is not enough.
The change has to reach every surface where the positive claim appears:
→ the public registry record
→ the digital badge on the provider's domain
→ the certificate verification page
→ the machine-readable status endpoint
→ the buyer notification path
→ the mark-usage license
→ the status history
A screenshot will survive. An old PDF will circulate. A sales deck may remain attached to a three-year-old email. The live record cannot erase those artifacts, but it can make them verifiably stale.
That is why the certificate itself should carry a verification URL, a unique ID, dates, and a direct instruction to check current status.
Scope laundering is the quiet failure
The loud fraud is a copied badge.
The common failure is subtler. A provider earns a claim for one bounded service, then places the mark on its company homepage. A buyer reasonably reads the signal as company-wide. The provider never states that broader claim in words. The design does the misleading work for them.
Call it scope laundering.
The proposed defense is blunt:
- Name the legal entity and service beside the mark.
- Put “verify scope” in the lockup.
- Link to one canonical record.
- State exclusions near the positive claim.
- Prohibit use in contexts that imply wider coverage.
- Track authorized domains and investigate copies.
- Remove active treatment when status changes.
The USPTO's certification-mark guidance makes control central to certification-mark ownership. Authorized users display the mark. The certifying organization owns it and controls its use. The legal structure for this proposed system still needs counsel and an independent owner.
Failure states protect the firms doing real work
Status is valuable only when it is scarce.
Wei's proof-of-work frame explains the social mechanic. If everyone can keep the token after the work stops, the token stops distinguishing anyone. The disciplined provider then shares the same visual signal as the careless one.
Suspension protects the buyer. It protects the provider too.
The provider that reports a material change, pauses a claim, fixes the issue, and returns through review is demonstrating a functioning system. A standard that hides every failure teaches the market to distrust every success.
Status must be losable.
Material change must move the public state
The proposed surveillance design includes events such as:
- a new model, supplier, or material tool class;
- a new use with a different risk profile;
- a client-data exposure;
- falsified or missing evidence;
- repeated violation of client restrictions;
- loss of the accountable owner;
- a credible complaint;
- mark misuse;
- ordinary expiry; or
- a new standard version that replaces the old record.
Not every change requires suspension. Some need a record update, targeted review, scope amendment, or temporary condition. The rule is simpler than the procedure:
The public signal cannot remain more positive than the current facts.
Integrity still needs a defined scope
A badge that can turn off has integrity.
The buyer still needs to know what it covers.
See the exact questions an AI assurance claim must answer.
Frequently asked
Would every model update suspend the status?
No. The proposed scheme would classify changes by materiality. Some changes need documentation only. Others trigger targeted review, a visible condition, or suspension.
Can a static PDF ever be trustworthy?
It can preserve the decision made on a date. It cannot prove the decision remains current. The PDF needs an ID, dates, scope, and a link to the live record.
Why show a suspension publicly?
The public claim is positive and buyer-facing. A material loss of confidence in that claim must be visible, subject to lawful limits on incident detail and personal data.
Does Petrichor operate this registry now?
No. The diagram, states, registry, and mark are proposed. Petrichor's current work prepares firms with boundaries, controls, evidence, and client permission material.