Defensible AI

What Defensible AI Means in a Regulated Environment

2026Nextvise

In October 2025, Deloitte agreed to partially refund the Australian government for a report worth about A$440,000. The report contained references to sources that do not exist and a quote attributed to a Federal Court judgment that was never written. This was not a firm without policies or review, it was a firm that could not defend a specific output the moment someone checked it.

That gap, between following the rules and being able to prove a specific output followed them, is the whole subject of this piece. It is the difference between compliant and defensible, and in a regulated environment it is the difference that decides whether you survive scrutiny.

Compliant is not defensible

The distinction is not ours; it is well established in compliance, records management, and law. Being compliant means you have the policy, passed the assessment, and hold the certificate. Being defensible means that when one specific decision is challenged, you can produce the evidence that it followed the rule, evidence that stands up in an audit or in court.

You can be fully compliant and completely indefensible at the same time. You had the AI policy. You ran the annual assessment. You have the certificate on the wall. Then a regulator points at one decision your AI made in March and asks: what rule did you check it against, who approved it, and where is the record?

Compliance answers for the system. Defensibility answers for the decision. Only one of those is the question that gets asked when something goes wrong.

Why AI breaks point-in-time compliance

Traditional compliance is a snapshot: an audit once a year, a certificate, a dashboard. That model assumes the thing being governed changes slowly.

AI does not. A single model in production makes thousands of decisions between two audits, and in a regulated setting, many of those decisions are themselves regulated acts: a dose stated, a transaction cleared, a claim coded, an adverse event classified. A certificate issued in January cannot defend an output produced in July. The unit that has to be defensible is not the system. It is the output.

What the regulations actually ask for

Read the rules closely and they point at the same thing: evidence on the decision itself, not the intention behind the system.

EU AI Act, Article 12 requires high-risk AI systems to technically enable the automatic recording of events (logs) over the system's lifetime. Article 19 requires providers to keep those logs for an appropriate period, at least six months. The law is asking for a per-decision record, by design.

EU AI Act, Article 14 requires effective human oversight by a natural person, someone with the competence and the authority to intervene. A reviewer who clicks "approve" with no real influence does not satisfy it.

ISO/IEC 42001, the AI management system standard, is evidence-driven: an AIMS audit tests the documented records of how you govern AI, not your good intentions.

Different regimes, one common demand: show the evidence, per decision, after the fact.

So what is Defensible AI?

An AI deployment is defensible when every output it produces is checked against the exact rule that governs it, before it reaches your systems, not reconstructed afterward; approved by a named human wherever the risk requires, real oversight, on the record; and recorded in a tamper-evident trail you can produce on demand, for a regulator, an auditor, or a court.

Defensible AI is not a certificate and not a dashboard. It is the ability to answer for a single decision, on the day you are asked, with evidence that holds.

Most AI governance tools make you compliant, they help you write the policy and pass the assessment. Defensibility is the higher bar. It is the one tested the day an output is challenged, and the one a certificate cannot cover for you.

The standard we build to

Nextvise is the infrastructure for Defensible AI. It validates every AI output against the requirements of the regulation that governs it, returns it signed, and keeps a record you can defend, and it escalates anything that does not hold to a named human, on the record.

Compliance tells the regulator you have a policy. A Nextvise record shows them the decision.

― basis: EU AI Act Art. 12 (record-keeping) · Art. 14 (human oversight) · Art. 19 (log retention, ≥ 6 months) · ISO/IEC 42001 (AI management system)

Get Audit-Ready
← Back to Insights