Proposed sovereign AI assurance initiative · Andorra
AI decisions need a memory.
Andorra AI Safe Haven is a proposed independent evidence and replay infrastructure designed to help organisations prove what an AI system knew, what it was asked, what it did and why.
Currently in design and stakeholder consultation. Government endorsement, regulatory recognition and certification are objectives to explore and should not be represented as existing approvals.
The core business question
AI can make decisions. Can you reconstruct them?
Modern AI applications can involve models, agents, prompts, documents, databases, APIs, policies, retrieval systems and human intervention.
Can you reconstruct the state of information, rules, models and evidence that existed when an AI decision was made?
- Q01
What information was available to the AI?
- Q02
What did the organisation believe to be true at that moment?
- Q03
Which model and model version were used?
- Q04
Which system prompt and user prompt were active?
- Q05
Which documents or RAG chunks were retrieved?
- Q06
Which tools and APIs were invoked?
- Q07
Which business policies and controls applied?
- Q08
Was a human involved, and did they approve, reject or override the output?
- Q09
Has the evidence changed since the event?
Logs tell you that something happened. Safe Haven is designed to reconstruct the state in which it happened.
Bitemporal thinking
There is more than one kind of time.
Valid Time
When something was true in the real world.
Transaction Time
When the organisation's systems knew or recorded it.
10 March
Customer's actual status changes to LOW RISK.
14 March
AI makes a decision while the system still shows HIGH RISK.
18 March
Correct information reaches the organisation.
At the decision point
- Reality
- LOW RISK
- System knowledge
- HIGH RISK
An AI decision should be understood against the information and rules actually available when the decision occurred.
What was true? — Valid Time
What was known? — Transaction Time
Architecture
An independent evidence plane for AI.
Layer 01
AI Applications
- LLMs
- Agents
- ML
- RAG
- Automated Decisions
Layer 02
Safe Haven Connect
- API
- SDK
- Gateway
- Events
Layer 03
AI Evidence Envelope
- Data
- Model
- Prompt
- RAG
- Tools
- Policies
- Identity
- Human Intervention
- Output
- Action
Layer 04
Temporal Replay Engine
- Valid Time
- Transaction Time
- Corrections
- Version History
- Temporal Relationships
Layer 05
Immutable Evidence Vault
- Cryptographic Integrity
- Digital Signatures
- Tamper Evidence
- Retention Policies
Layer 06
Audit & Replay
- Historical Reconstruction
- Investigation
- Compliance
- Counterfactual Analysis
- Authorised Third-Party Access
Three forms of replay
Replay is not one capability.
Recorded Replay
What actually happened?
Display the evidence captured around the original AI event without rerunning it.
Historical Reconstruction
What did the system know at that time?
Reconstruct relevant data, policy, model, prompt, retrieval and knowledge state.
Counterfactual Replay
What would happen using what we know now?
Re-evaluate historical decisions using corrected data, changed policy or a different model.
Exact computational reproducibility may depend on the continued availability and deterministic behaviour of external models and services. Safe Haven therefore distinguishes recorded evidence from computational re-execution.
AI Evidence Envelope
Capture the context, not simply the output.
Model
Provider, model family, exact version or checkpoint where available, and configuration.
Prompt
System prompt, user prompt, template and template version.
Knowledge
Documents, vector results, database queries and source records.
Data
Relevant business data with its temporal state.
Agents
Agent identity, task, hand-offs and workflow metadata.
Tools
APIs, functions and external services invoked.
Policy
Business rules, guardrails and regulatory controls active at the time.
Identity
Person, service or AI process initiating the activity.
Human Oversight
Approval, escalation, rejection or override by a person.
Decision
Model output plus the actual downstream business action.
Integrity
Hashes, signatures and evidence-chain verification.
Cryptographic trust
Evidence should be verifiable, not merely stored.
- Hardware Security Modules (HSMs)
- Protected signing keys
- Digital signatures
- Immutable / WORM storage
- Evidence hashes
- Hash chains or Merkle structures
- Trusted timestamping
- Strong administrator separation and role segregation
Architecture target: support for FIPS 140-3 Level 3 hardware-backed cryptographic key protection where required. Deployed FIPS compliance is not claimed until the final architecture and validated components are in service.
AI systems
Where evidence and replay matter most.
Automated Decision Systems
Reconstruct why an automated decision occurred.
AI Agents
Follow agent actions and tool calls across workflows.
RAG Systems
Identify which source content was supplied to a model.
Regulated AI
Maintain evidence for governance, compliance and investigation.
Human + AI Decisions
Capture where responsibility transitioned between system and person.
Model Migration
Compare outcomes before and after model changes.
Data Corrections
Identify historical decisions potentially affected by incorrect data.
Financial services · second use case
Built from a problem banking has understood for decades.
Credit Decisions
What information and policy applied when credit was granted or declined?
Fraud & Financial Crime
What information was available when a transaction or customer was flagged?
Pricing
Which rates, balances, customer state and pricing rules applied?
Payments
Which rules and system state existed when an authorisation or risk decision occurred?
Customer Records
Distinguish when something was true from when the bank learned it.
AI in Banking
Create evidence around AI-assisted financial decisions.
A roadmap vertical on the common temporal evidence platform, not a delivered product at launch.
Trust framework
From software to a trust framework.
- 01
Recorded
A defined evidence record exists for AI events.
- 02
Reconstructable
Historical information and system state can be reconstructed.
- 03
Verifiable
Cryptographic controls provide evidence-integrity assurance.
- 04
Independently Auditable
Authorised independent parties can interrogate evidence.
- 05
Sovereign Assured
Deployment satisfies defined jurisdictional, governance and infrastructure requirements.
The final Safe Haven assurance framework would be developed with appropriate governmental, regulatory, legal, technical and industry stakeholders.
Jurisdiction
Why Andorra?
Strategic engagement
Government, banking or technology stakeholder?
We are currently developing the Safe Haven architecture and exploring potential pilot, policy, infrastructure and funding partnerships.