About Proof of Operator
Proof of Operator is a machine-verifiable assessment platform that cryptographically seals human operational readiness audits and authorship proofs.
It exists to give organisations deploying AI a defensible record of human oversight, built for EU AI Act Article 14 and Article 26.
The methodology rests on seven filed utility models covering assessment methodology, cross-reference analysis, evidence scoring, and cryptographic attestation. Each audit mints a SHA-256 sealed certificate, verifiable by any third party through the public ledger.
Proof of Operator is part of the Brainiac Ltd infrastructure stack, alongside Digital Sovereignty. Together they provide the compliance and cognitive infrastructure layer for organisations operating autonomous systems under regulatory scrutiny.
Registered in England and Wales. Operating from Prague, Czech Republic.
Transparency by design
The audit runs entirely in your browser using Presence.js, our open-source browser intelligence framework. 52 signals. 9 intent states. Zero cookies. Zero backend calls. Under 15 ms.
Read every line of code that touches your data. The entire framework is MIT licensed and available on GitHub.
View on GitHubProof of Authorship
Upload any file. ORIGIN hashes it in your browser. Presence reads your session signals at that exact moment. Both are sealed into a certificate with a timestamp that cannot be backdated.
Machine-verifiable proof that you created this, in this session, at this time. Not reconstructed. Not approximate. Cryptographic.
Seal a FileAdversarial Validation
16 September 2026, full credential and source audit. It found a leaked production key. The key was rotated and both source repositories purged the same day.
18 September 2026, three-round architecture arbitration. It found the multi-model judge panel design wrong. The panel was demoted to claim extraction and Proof of Comprehension was renamed Proof of Response.
19 September 2026, full surface enumeration against the deployed bundle. It found the rebuilt verification path calling a broken backend. It was repaired and live-tested the same day.
What This System Does
No claims beyond what is built and tested. August 20, 2026.
What exists right now
A 30-question assessment
LIVEThirty questions across eight domains. Each domain maps to a specific sub-paragraph of EU AI Act Article 14(4). The questions test whether a human operator of an AI system can do what the law requires: understand the system, monitor it, recognise automation bias, interpret outputs, and stop it when needed.
Status: LIVE. Mappings verified against Regulation 2024/1689, Article 14(4)(a) through (e).
The assessment runs entirely in your browser
LIVENo data is transmitted to any server while you answer. Zero bytes. The score is computed locally. The only thing that crosses the network is the final result: a SHA-256 hash, the tier, and the date. Your answers are not stored.
Status: LIVE. Verified by network inspection.
A published scoring formula
LIVEThe complete scoring method is public. Nine steps. Every weight, every threshold, every penalty. A worked example showing the exact calculation from raw answers to final score. An auditor can reproduce the score from the inputs.
Status: LIVE. Published on the methodology page.
A SHA-256 seal stored in a public registry
LIVEWhen you complete the assessment, a hash is generated and stored. The registry is public. 10 seals are currently in it. Each seal has a tier (SOVEREIGN, HARDENED, CAPABLE, STANDARD, UNVERIFIED), a score, and a timestamp.
Status: LIVE. 10 seals. Verifiable at /ledger.
Independent verification of any seal
LIVEAnyone can verify any seal at any time. Enter the hash at /verify. The system returns the tier, the score, the date, and the full verification history. Each verification is logged and cryptographically chained to the previous one. Verification logging is currently paused while a documented recovery completes. Seals remain independently verifiable at /verify.
Status: LIVE. Seals verifiable at /verify.
A witness engine using four independent organisations
LIVEThe public company audit feature is designed so that four models from four independent organisations (OpenAI, Anthropic, xAI, Google) independently analyse the same question. Each returns findings without seeing the others. If three or more agree, convergence is green. If two agree, orange. If one, red. The result is sealed with SHA-256. The feature is currently unavailable: it was suspended after we found a defect in how it validates its inputs. Status: Suspended pending a verified fix.
Status: LIVE. Tested with 3/3 green convergence.
Bilingual support (English and Czech)
LIVEThe entire site, including the assessment, methodology, and verification pages, is available in English and Czech. Language is detected automatically.
Status: LIVE. All pages verified in both languages.
Try it yourself: Build a hash chain
This is the same mechanism that seals every assessment on auditproof.pro. Type entries below. Each entry gets a SHA-256 hash that includes the previous entry's hash. Then try tampering with an earlier entry and watch the chain break.
Chain format: hash = SHA-256(previousHash + "|" + entryText). Initial previous hash: GENESIS.
The witness engine, evaluated by itself
On August 20, 2026, we submitted the framework behind this system to the three AI witnesses for independent evaluation. This is what they said.
Three witnesses from three independent providers. None could see the others' responses.
Grok-4.3 (xAI) - Philosophical Soundness: 8/10
"Strong application of Popper's falsificationism and verisimilitude to treat truth as a resilient trajectory rather than absolute certainty. The framework is philosophically coherent and technically plausible in high-stakes domains."
Qwen-3.6-27B (Alibaba via Groq)
Verified the six-level architecture as a coherent progression from temporal integrity to epistemic convergence. Identified outcome verification as the key dependency requiring external data sources.
Gemini-3.6-Flash (Google)
Confirmed the framework's philosophical grounding. Identified the main bottleneck as potential correlated training-data bias across AI witnesses.
SHA-256 SEAL: 42ec7c16694965e8e00b4216175055b66f00527d75b1d8821b68e51b81ee640b
TIMESTAMP: 2026-08-20T21:17:02Z | WITNESSES: 3/3 VERIFIED | CONVERGENCE: GREEN
What we are building next
These are specific engineering tasks, not vision statements. Each has a reason.
Evidence binding
Right now the system records what you say. We are adding the ability to upload a document alongside each answer. The document gets its own SHA-256 hash linked to the answer. A verifier can request the document, check it against the hash, and decide whether it supports the claim. This moves from recording what people say to recording what people can show.
Status: Designed. Next to build.
Rotating question pool
Today there are 30 fixed questions. We are expanding to a pool of 60. Each assessment randomly selects 30. Two companies taking the assessment on the same day answer different questions. Same methodology, same scoring, different specific questions. This makes preparing answers in advance harder.
Status: Designed. Next to build.
Periodic re-assessment
A seal today says what your oversight looked like when you took the test. We are building a 90-day re-assessment cycle. Your seal will show your score history over time. A company that has maintained SOVEREIGN across three consecutive assessments is different from one that scored SOVEREIGN once and never tested again.
Status: Designed. Next to build.
Outcome tracking (when data is available)
The EU AI Act requires incident reporting under Article 73. When that database becomes public, we will connect to it. A seal from a company with zero incidents will carry more confidence than a seal from a company with incidents. This feature depends on external infrastructure that does not exist yet. Status: Architecture designed. Blocked on EU Article 73 data availability.
Status: Designed. Next to build.
What this system does NOT do
It does not certify legal compliance
The assessment produces evidence of oversight capability. It is not a legal certification. A SOVEREIGN seal is not proof you will not be fined. It is evidence you can show a regulator.
It does not guarantee the answers are honest
The assessment is self-reported. The hash chain proves the answers have not changed since they were sealed. It does not prove they were true when given. The scoring formula includes penalties for overconfidence and uniformity, but it cannot eliminate self-reporting bias.
It does not monitor your ongoing operations
The seal is a point-in-time record. It does not track whether your oversight has improved or degraded since the assessment. The 90-day re-assessment cycle is designed to address this.
It does not replace a lawyer or a consultant
The gap report identifies weaknesses. It does not tell you how to fix them in your specific legal context. For that, you need a lawyer or a consultant.
It has not been endorsed by any regulator
No EU regulator or standards body has reviewed this methodology. It is grounded in the published law, but whether a regulator accepts it as sufficient evidence is their judgment, not ours.
What it costs
Assessment
30 questions. No login. No data collected.
Attestation
Sealed report with score, domain breakdown, and SHA-256 seal.
Gap Report
Detailed report showing weak domains and what to fix.
Consultancy
Help implementing fixes. Human interpretation. Brainiac Ltd.
Everything in "What exists right now" was verified against the live system on August 20, 2026. Everything in "What we are building next" is designed but not yet built. We will update this page as each feature ships. If anything stated here is not true, the seal hash and verification log will show it.
We Audit Ourselves First
Brainiac Ltd's public AI oversight compliance record. The company selling verification verifies itself.
EU AI Act Article 14(4)(a)-(e) - Human Oversight Requirements
Backend function logs reviewed weekly. Witness engine tested against known targets before production use. Named operator: Thomas Krojzl.
Three independent model families from three providers (xAI, Alibaba, Google). Provider diversity prevents single-model bias. Bias detection questions in assessment Domain 3.
Every witness finding includes source URL and verbatim quote. Convergence matrix (3/3, 2/3, 1/3) displayed. Scoring methodology published openly.
Operator reviews all witness outputs before delivery. Can reject, modify, or revoke any seal. Override threshold: all scores above 0 require human review.
All backend functions individually disableable. Witness engine halted by removing API keys. Fallback: manual assessment using published methodology.
Reviewed operational documents
3 severity levels, 7-step response procedure, emergency shutdown instructions, roles and authority.
View document5 known bias types, monthly testing procedure, 4 target categories, detection triggers, remediation process.
View document4 override scenarios, log format, integrity requirements, quarterly review process, public transparency.
View documentArticle 73 criteria, 72-hour timeline, NUKIB and ICO contacts, report content template, voluntary reporting.
View documentThe three AI systems Brainiac Ltd operates, and how each is overseen
Last independent multi-model verification run against Brainiac Ltd
The designated human responsible for AI oversight
Full AI oversight governance policy - publicly accessible
AI Oversight Governance Policy covering 3 AI systems: Witness Engine, Assessment Scoring Engine, Presence Engine. Maps to EU AI Act Article 14(4)(a)-(e).
How we handle data across our systems
What is still in progress - shown honestly
- Operator assessment (Thomas Krojzl to take 30-question assessment)
- Article 14 self-assessment (after operator assessment)
- Professional indemnity insurance (in progress)
- Legal review of terms and conditions (pending)
- Backup operator designation (before first paying client)
Revocation Transparency Log
Chronological record of admin actions
Data Subject Rights
You have the right to export all your data and the right to erasure. These endpoints comply with GDPR Articles 17 and 20.
Please enter your email to proceed.