The Missing Ratchet: Why AI Governance Needs What Aviation, Pharmaceuticals, and Financial Reporting Already Built
Attribution: The three-layer contract framing sharpened in an exchange on LinkedIn with Pedro Penedo, Partner at KPMG Portugal, 2026-07-30 to 2026-07-31.
Every quality discipline that ever reached mass scale in the physical world was built the same way. Aviation. Pharmaceuticals. Building construction. Food safety. Financial reporting. Software security. Each began as a pre-formation craft where reputation was the only signal, suffered predictable failures, and eventually formed the same three-piece structure that let it scale without collapsing under its own liability.
That three-piece structure is what AI is currently trying to skip.
The pattern is specific enough to name.
The three-layer contract
Every mature quality discipline in the physical world produces the same record at the moment a decision or product commits: an immutable capture of what was done, plus an immutable reference to what "reasonable practice" meant at that specific moment, plus a signed attestation binding the two. Three layers, not one.
Layer 1 is the decision record itself. In aviation, it's the flight-data recorder, the maintenance log, the pilot's certification of the pre-flight check. In pharmaceuticals, it's the clinical-trial data captured at each study visit, cryptographically sealed against post-hoc modification. In construction, it's the as-built plans stamped by the engineer of record. In financial reporting, it's the transaction ledger locked at period-close. All of these share one property: they were fixed at the moment of the action, not reconstructed from adjacent evidence later.
Layer 2 is a reference to the standard that was in force at time T. In aviation, the FAA type certificate references the specific airworthiness directives applicable at the certification date. In pharmaceuticals, the FDA approval letter references the specific ICH guidelines in force. In construction, the building permit references the specific code cycle. In financial reporting, the audit opinion references the specific GAAP standard version. Every one of these disciplines learned, expensively, that a decision record without a reference to the standard it was measured against is worthless once the standard drifts.
Layer 3 is a signed attestation from a named person or entity, binding layer 1 to layer 2. Not the corporate signature. A specific human name, addressable, cross-examinable. In aviation, it's the licensed A&P mechanic's stamp. In pharmaceuticals, it's the principal investigator's signature on the case-report form. In construction, it's the engineer of record's seal. In financial reporting, it's the audit partner's name on the opinion. Layer 3 is what makes layers 1 and 2 legally load-bearing.
Any two of the three leaves the standard drifting. All three together produce something specific: a two-sided liability contract that ratchets quality upward while protecting against retroactive re-scoring.
Why the third piece is not optional
The trap that AI governance keeps walking into is treating "reasonable practice at time T" as a phrase that will figure itself out later. It will not.
Reasonableness is a moving definition. It drifts upward as professional norms mature, as regulatory guidance publishes, as best-practice literature accumulates. Without a captured record of what was considered reasonable at the moment of a specific decision, future reviewers apply future standards backwards. The bar keeps moving up. Eventually the standard for judging past work becomes unachievable by past work, and the entire discipline gets stuck in a defensive crouch nobody can profitably operate in.
The medical malpractice bar has this problem in miniature. "Standard of care at the time of treatment" is a specific legal concept. Courts are supposed to judge against what the standard was in force, not what it became. But hospitals rarely capture layer 2 explicitly — nobody attaches "here is the standard we measured against, timestamped and signed" to a specific treatment decision. So when a suit arrives, defense counsel has to reconstruct the then-current standard from journals, guidelines, and expert testimony, sometimes across years of drift. That reconstruction is expensive, imperfect, and defense often loses to plaintiff experts citing later-published best-practices as if they were the earlier standard.
Aviation avoided this. When a Boeing 737 built to 1990 code has a component failure in 2020, the FAA does not ask whether the component would have met 2020 airworthiness directives. It asks whether the component met the 1990 airworthiness directives in force at type certification, and whether all subsequent required updates were applied. The captured layer 2 reference — this specific plane's certification is bound to this specific code cycle — makes that determination cleanly. Boeing is on the hook for what the 1990 standard required plus every subsequent AD it should have applied. It is not on the hook for a 2020 standard that did not exist when the plane was built.
That is the ratchet.
Why every mature discipline formed this way
Every industry that reached mass scale went through the same historical arc.
Craft era: individual reputation is the only quality signal. Buyers assess trust one relationship at a time. The market cannot scale because trust does not scale.
Guild era: professional bodies publish standards. Guild membership signals compliance. The standards start to be documented, revised, dated. Layer 2 is starting to exist even if layer 3 is still informal.
Regulatory era: government adopts guild standards, makes some mandatory, publishes them under names and version numbers. Layer 2 becomes citable. Some form of layer 3 emerges (licensure, professional registration).
Certification era: independent third-party auditors verify compliance with layer 2 at specific moments. Layer 3 becomes a formal signed attestation. Insurance markets price against certification status. The three-layer contract is now fully operational.
Each of these eras took decades in the physical world. Aviation started around 1903, got its first federal air-safety regulator in 1926, its first independent certification body arguably in 1958 with the modern FAA. Financial reporting had roughly the same arc: AICPA founded 1887, GAAP standardization in the 1930s, PCAOB independent oversight in 2002. Building construction: guild-era masonic traditions, ICC founding 1994. The point is not the specific dates. The point is that each discipline eventually built the same three-layer structure, and each one only reached mass scale after doing so.
AI is currently stuck between the craft era and the regulatory era, with the guild era mostly skipped. That is a real problem.
What "guild era skipped" looks like right now
The current AI governance discourse fractures across four broadly unproductive directions.
The capability discourse argues that better models will make governance easier. It has been argued for a decade. It has never been true. Better models create more decisions per second, and thus more governance surface, not less.
The alignment discourse argues that AI safety is a technical problem to be solved by better training procedures. This is a real research agenda that produces useful work, but it is orthogonal to the accountability problem. An aligned model can still produce a decision whose provenance cannot be reconstructed six months later.
The regulation discourse argues that governments should mandate AI safety standards. This is where the EU AI Act, various US executive orders, and state-level AI regulations sit. The problem is that all of these regulations reference a body of "reasonable practice" that does not yet exist in coherent form. Regulators are being asked to publish rules against a standard that no guild has yet defined. When the underlying guild layer is missing, top-down regulation either becomes prescriptive-and-brittle (specifying exact technical implementations that age poorly) or vague-and-unenforceable (specifying principles that nobody knows how to audit).
The governance discourse — Pedro Penedo of KPMG Portugal has been articulating this well from the EU side, and it aligns with what I have been building on the US expert-witness side — argues that the accountability structure has to be designed into the AI system at deployment time, not bolted on afterward. Governance-at-decision-time not governance-on-paper. Evidence not intent.
That governance discourse is the guild-era work. It is being done in isolated pockets by practitioners who each recognize the same failure pattern from different angles. What is missing is the widely-cited rubric that names the three-layer structure explicitly, published early enough that it becomes the reference-of-record that later regulation and later certification bodies build against.
The vacuum is filling. First-mover shapes the frame.
The ratchet mechanism
The three-layer contract is defensive when read narrowly: it bounds liability, protects the named principal against retroactive re-scoring, and creates predictable exposure. Those are useful properties. They are not the interesting properties.
The interesting property is that the same three-layer structure incentivizes upward quality drift, because buyers can distinguish and price the difference.
Consider LEED certification. A LEED-certified building commands 10 to 30 percent rent premium over an uncertified equivalent, leases faster, and holds higher resale value. The premium exists because layer 2 (the LEED rating system, in specific version at time of certification) plus layer 3 (the accredited certifier's signed attestation) let buyers verify a specific quality claim without having to trust the developer. Once buyers can verify, buyers pay. Once buyers pay, developers build to spec. Once enough developers build to spec, the next version of LEED can ratchet the requirements higher without collapsing the market, because the previous cohort is grandfathered under the layer 2 reference that applied at their certification date.
The same pattern operates across every mature quality discipline. UL-listed electrical products command 8 to 15 percent price premium. FDA-cleared medical devices command orders-of-magnitude premium over uncleared. SOC 2 Type II attestation is the price of entry to enterprise SaaS procurement. HIPAA compliance auditing is a several-billion-dollar-a-year sub-industry. Each of these markets did not exist before the three-layer contract structure existed. Each formed when the structure formed.
For AI systems specifically, the equivalent market would price something like the following. An enterprise deploying an AI compliance-decision system would rationally pay premium for one whose deliverable ships with a full three-layer packet: cryptographically captured decision records, explicit reference to the reasonable-practice rubric in force at deployment date, signed attestation by a named principal accepting liability under that rubric. A system that ships with a marketing PDF titled "Our Approach to Responsible AI" would command no premium and would eventually be procurement-excluded from any regulated buyer.
That market does not exist yet. It is about to.
What the plain version looks like
Take a photo of your homework at submission. Hash the photo. Pin the rubric the teacher published that day next to it. Sign your name on both. Store it somewhere the teacher cannot alter.
Later, when the teacher accuses you of changing your answers, you produce the photo and the hash. Proof.
Later, when the teacher grades you against next year's rubric, you produce the photo, the hash, and the rubric-that-was-in-force-at-submission. Different proof.
Later, when you discover you got question five wrong because your textbook had an error, you append a correction note. You do not rewrite the original photo. You are on the hook for what the photo shows against the rubric that was in force. You are protected against a rubric that came out later.
Three layers. All three needed. Every mature quality discipline in the physical world runs on this.
The specific claim I am making
The reason AI governance keeps producing well-intentioned policy documents that fail contact with real regulatory or litigation pressure is that the underlying three-layer contract is missing. Regulators are asking for evidence, not intent. Buyers are asking for verifiable quality, not stated principles. Courts, when they get involved, are asking for immutable decision records bound to timestamped standards signed by named principals.
None of that is exotic. It is the specific record structure every mature engineering discipline produces at the moment of the action. AI has not built the record yet, because AI has skipped the guild-era work of defining what reasonable practice means with sufficient specificity to be captured as a layer 2 reference.
The Bell Tuning framework whitepapers I published in April 2026 are one instance of an attempt at that guild-era work. Five papers, timestamped, publicly available, defining specific measurable properties of AI decision-log audit that can be captured immutably. Not authoritative. Not universal. But timestamped, signed, publishable, and thus citable as layer 2 for any deliverable I ship. That is what the guild layer looks like at the individual practitioner scale before it consolidates into a formal body.
Others are doing versions of this work in adjacent domains. Pedro Penedo of KPMG Portugal is developing writing on the accountability-at-decision-time framing from the EU regulatory side. The ISO/IEC 42001 AI Management Systems standard is a top-down attempt at a similar structure. Various academic groups are producing methodology papers that could become layer 2 references if adopted.
What has not happened is anyone naming the three-layer contract structure explicitly, as the historical pattern that every mature quality discipline followed, as the specific market-forming mechanism that will apply to AI whether the current governance discourse anticipates it or not.
That is what this article is. Not a policy proposal. Not a regulatory prescription. A naming of a pattern that has already worked six times in the physical world and is going to work a seventh time in AI, and an argument that whoever authors the earliest widely-cited version of what reasonable practice means for AI-decision audit becomes the reference that later regulation, later certification bodies, and later litigation cite against.
What comes next
The regulatory-industrial complex around AI governance is going to form in the next three to five years. It will look like the certification-and-insurance structure around building codes, or medical devices, or financial audit, or software security. The specific shape it takes depends on which practitioners publish coherent rubrics early enough to become the reference-of-record.
The plaintiff and defense bar are already forming around the litigation side of this. Post-2024 federal court rulings on AI-methodology expert testimony have been quietly building a case-law layer for what reasonable AI-audit practice means. State attorneys general are enforcing algorithmic-discrimination and consumer-protection statutes that require exactly the three-layer packet to defend against. Insurance carriers are pricing E&O and cyber policies against the specific structural properties of AI systems and their governance overhead.
The three-layer contract is going to become the ordinary deliverable every AI system in a regulated environment ships. That transition is inevitable. What is not inevitable is who authors the widely-cited definition of what belongs in each layer.
If you are building AI systems in a regulated environment, you are building for the ratchet whether you know it or not. The choice is whether you build with layers 1, 2, and 3 designed in from deployment, or whether you build with only layer 1 and try to reconstruct the other two under litigation or regulatory pressure. The latter fails.
If you are a standards-drafting body, a professional association, or a regulator, the guild-layer vacuum is filling now. First-mover shapes the frame. The next twenty-four months are the window.
If you are a buyer of AI systems, start asking vendors for the full three-layer packet on one specific decision from six months ago, on demand. The vendors that can produce it are the ones that built the ratchet in. The vendors that cannot produce it will not survive the transition.
The physical world figured this out. The AI universe is about to.
- Expert-witness engagement menu — Rule 702 audit + Preliminary Case Assessment $2,500
- Bell Tuning framework — 5 whitepapers on AI decision-log audit methodology (April 2026)
- Published Snapshot samples — 12 verticals, independent-verifier declaration on each
- Prior expert-witness engagements — Rule 26(a)(2)(B)(v) disclosure