Working paper

The Reproducibility Criterion for Machine-Generated Evidence: Sufficient Conditions and Certification Limits for Independently Verifiable AI Decisions

Raza Sharif, Founder, CyberSecAI Ltd · ORCID 0009-0001-5126-4722
Published 14 September 2026 · Zenodo · DOI 10.5281/zenodo.22746394
Read the PDF All versions (Zenodo) ORCID record

Abstract

A working paper proving necessary and sufficient conditions for an AI decision to be independently reproducible as evidence: deterministic decoding, attested model identity, sealed inputs, and an attested execution environment, covering the complete computational closure of the inference function. It includes an empirical demonstration that partial attestation is forgeable by a single unrecorded parameter, a three-grade reproducibility taxonomy, and a mapping to the proposed U.S. Federal Rule of Evidence 707 and to Articles 12 and 14 of the EU AI Act. The margin certificate is stated and machine-checked in Lean, and the approach is implemented in the IETF draft on agent audit trails and validated on a running system.

The core result

A temperature-zero AI decision is reproducible when the winning token's lead exceeds the maximum that lead can shrink under bounded numerical perturbation, that is, when the lead is greater than twice the wobble. Reproducibility of the whole answer requires that protection to hold through every decision, including where to stop, under fixed decision rules, the same model, the same full input, and a controlled execution environment.

Keywords

AI evidence · reproducibility · attestation · audit trail · digital forensics · deterministic inference · large language models · chain of custody · evidence admissibility · verifiable AI · tamper-evident logging