Skip to content

HACCP for AI: An Auditable Self-Control Standard for Artificial Intelligence

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

Almost every serious instrument in AI governance now requires an organisation to run a risk process. None of them tells the organisation where in its own lifecycle the control points sit, what measurable limit applies at each one, what happens automatically when a limit is breached, or who is competent to verify the measurement. That layer, process control, is missing, and it is the layer on which everything else depends. A management system without control points produces documentation; it does not produce safety. This paper supplies that layer by importing a method that has governed an invisible hazard across a globally distributed production chain for more than fifty years: Hazard Analysis and Critical Control Points. The claim is deliberately narrow. HACCP is not proposed as a rival to ISO/IEC 42001, to Article 9 of the EU AI Act, or to the NIST AI Risk Management Framework. It is proposed as the process-control layer their architecture presupposes and does not contain, and as the one methodology in existence with a property AI governance urgently needs and currently lacks: scale invariance. The same seven principles govern a village bakery and a multinational dairy, which is why one inspector, one standard and one accreditation system can cover both. The method is given in the full twelve-step Codex sequence, with a three-tier proportionality rule (deployer, provider, frontier developer), a hazard taxonomy, a control-point decision tree, a catalogue of seven control points, and a taxonomy of limits that separates critical limits from operational limits and indicator thresholds, and reclassifies the compute thresholds now written into law as the third kind. Version 5.0 adds what an expert reader of version 4.0 was entitled to ask for: the instruments. A plan that says “monitor the violation rate” has not yet said anything an engineer can implement. Part II therefore imports, with their arithmetic, the measurement tools that make food-safety limits real: attribute sampling plans that state how many outputs to inspect and how many failures to tolerate before a lot is rejected, with their operating characteristics; statistical process control that gives the operational limit a precise meaning as a warning limit on a control chart; a seven-step protocol for validating an evaluation as a measuring instrument, with inter-rater reliability, uncertainty and a scope statement; and record schemas (a configuration manifest, a monitoring record, a deviation register) that make version identity and traceability a matter of implementation rather than intention. Part III applies the instruments in four worked plans, including a new one for an agent with tool access, and specifies a pre-registrable inter-rater study by which the method's central claim to auditability can be tested and, if warranted, refuted. The paper states its own limits without softening. The most consequential gap in AI-governance infrastructure is metrological: there is no analogue of ISO/IEC 17025 for capability evaluation, and until there is, independent attestation of a capability-based limit is not available to anyone. One structural disanalogy has no food-safety precedent at all: a pathogen does not model the control system trying to detect it, and a sufficiently capable AI system may. Both are treated as design constraints on the method rather than as objections to be answered later. The framework is accordingly strongest where most AI harm occurs, in organisations that deploy and provide AI systems, and is stated to be aspirational at the frontier until independent measurement exists. This record contains three files: the full paper (version 5.0, 73 pages), a two-page Executive Summary for policy readers, and a 15-page Practitioner Brief containing Part II (the instruments) as a standalone document. Version 5.0 supersedes version 4.0 (July 2026); earlier versions remain available under the same concept DOI. CC BY 4.0.

View source

Similar papers

#artificial intelligence Open access May 2023

Evaluating the Performance of Large Language Models on GAOKAO Benchmark

GAOKAO-Bench is introduced, an intuitive benchmark that employs questions from the Chinese GAOKAO examination as test samples, including both subjective and objective questions that contribute a robust evaluation benchmark for future large language models and offers valuable insights into the advantages and limitations of such models.

Xiaotian Zhang, Chun-yan Li, Yi Zong et al. · 216 citations · ⚡17

PRISM: Self-Pruning Intrinsic Selection Method for Training-Free Multimodal Data Selection

Empirically, PRISM reduces the end-to-end time for data selection and model tuning to just 30% of conventional pipelines, and achieves this efficiency while simultaneously enhancing performance, surpassing models fine-tuned on the full dataset across eight multimodal and three language understanding benchmarks.

Jinhe Bi, Yifan Wang, Danqi Yan et al. · 73 citations · ⚡4
#artificial intelligence Conference Open access Apr 2020

ECCOLA - a Method for Implementing Ethically Aligned AI Systems

The method, ECCOLA, is presented, which aims at making the high-level AI ethics principles more practical, making it possible for developers to more easily implement them in practice.

Ville Vakkuri, Kai-Kristian Kemell, P. Abrahamsson · 64 citations · ⚡6

Let the Flows Tell: Solving Graph Combinatorial Optimization Problems with GFlowNets

This paper designs Markov decision processes (MDPs) for different combinatorial problems and proposes to train conditional GFlowNets to sample from the solution space and demonstrates that GFlowNet policies can efficiently find high-quality solutions.

Dinghuai Zhang, H. Dai, Esmeralda S. Whitammer et al. · 59 citations · ⚡8

Ethically Aligned Design of Autonomous Systems: Industry viewpoint and an empirical study

An empirical study on the current state of practice in artificial intelligence ethics is conducted by means of a multiple case study of five case companies, which indicates a gap between research and practice in the area.

Ville Vakkuri, Kai-Kristian Kemell, Joni Kultanen et al. · 56 citations · ⚡6
#artificial intelligence Conference Open access Jun 2018

The Key Concepts of Ethics of Artificial Intelligence

It is suggested that the focus on finding keywords is the first step in guiding and providing direction for future research in the AI ethics field.

Ville Vakkuri, P. Abrahamsson · 39 citations · ⚡2

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.