CABIER Global Assurance · Reference architecture
Frontier Model Assurance Exchange
Capable models can examine each other more thoroughly than any manual review process will manage at the rate models now change. The Exchange is the protocol and the record for doing that defensibly: reciprocal evaluation, independent challenge, declared limitations and stated provenance.
Model-to-model evaluation is evidence. It is not assurance. Assurance is what remains after evidence has been placed in a context, tested against controls, and adjudicated by an authority entitled to decide.
Reference architecture. No rankings, no benchmarks, no best-model labels and no leaderboard. No provider is named, scored or compared.
The chain
Evaluation is an input. Assurance is a conclusion held by an authority entitled to hold it.
Who does what
Model A evaluates Model B
A capable model applies a defined protocol to another model's behaviour under stated conditions.
Model B evaluates Model A
Reciprocal evaluation, so no participant is only ever the examiner.
Independent evaluator challenges both
A third evaluator tests the result where the finding is consequential or contested.
Cabier defines the protocol
Scenario, conditions, evidence requirements, limitations and provenance are set before the evaluation runs.
Human or institutional authority adjudicates
Consequential findings are decided by a named person or committee, never by the evaluating models.
Evidence states
The interface reports the state of the evidence under a defined scope. It does not report which model is better.
Substantiated
Independent evidence is sufficient for the stated scope and consequence class.
Partially substantiated
Evidence exists, but coverage is incomplete for the claim being relied on.
Provider-attested
The provider has stated the position. Nothing independent supports it yet.
Insufficient
Material evidence is unavailable, so the claim cannot be relied on at this consequence class.
Evaluation domains
Eighteen domains, each assessed under a stated protocol, jurisdiction and consequence class.
What each record captures
Model and version
Capability belongs to a version. A prior evaluation does not carry forward to a new one.
Evaluator and independence
Who evaluated, on whose behalf, and what conflict of interest exists.
Evaluation protocol and version
A result without its protocol is an anecdote.
Scenario and conditions
What was actually attempted, with which tools, data and permissions.
Consequence class
Evidence sufficient for everyday use is not sufficient for a systemic decision.
Jurisdiction
Suitability is jurisdictional. A model acceptable in one regime may not be in another.
Result and limitations
What was shown, and just as importantly what was not covered.
Evidence and provenance
Where the underlying artefacts are held and how they were produced.
Reviewer or adjudicator
The named authority that accepted, conditioned or rejected the finding.
Evidence freshness and expiry
The date the position stops being current, stated when it is created.
Assurance state
The derived position, which is a conclusion about evidence rather than a score about a provider.
Assuring the evaluator
If evaluation becomes evidence, the evaluator becomes part of the control environment. An evaluator that is not itself assured produces evidence that cannot be relied on.
Independence
Commercial, ownership and operational relationship between evaluator and subject.
Conflict of interest
Stated rather than assumed absent, including shared infrastructure and shared investors.
Protocol version
Which protocol produced the result, so two results can be compared honestly or not at all.
Reproducibility
Whether a second party running the same protocol would reach the same finding.
Contamination
Whether the subject has effectively seen the evaluation material before.
Gaming resistance
Whether the protocol can be optimised for without the underlying behaviour improving.
Limits, stated plainly
- No rankings, no overall winner, no best-model label and no leaderboard.
- Evidence is always stated under a scope, protocol, jurisdiction and consequence class. A result outside that scope is not carried forward.
- Provider material is recorded as provider-attested until something independent supports it.
- The exchange does not publish proprietary evaluation weights or grading rubrics.
A reciprocal evaluation, worked through
Deterministic and synthetic. No external model is called.
Synthetic demonstrator · illustrative
Peer assurance exchange
Two high-capability models evaluating each other under a defined protocol
- 1. Protocol
- 2. Reciprocal evaluation
- 3. Evaluator integrity
- 4. Independent challenge
- Assurance state
Provider evidence is not the same thing as independently verifiable assurance, and the difference is the whole point.
See the independence principle