<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Oversight — Christa Burger</title><link>https://christaburger.com/tags/oversight/</link><description>Christa Burger is a CISO and VP of Cybersecurity — twenty-plus years across cybersecurity, risk, resilience, and governance in finance and technology. Building operating systems that build and reinforce trust.</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>christa@christaburger.com (Christa Burger)</managingEditor><webMaster>christa@christaburger.com (Christa Burger)</webMaster><copyright>© 2026 Christa Burger. All rights reserved.</copyright><lastBuildDate>Tue, 08 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://christaburger.com/tags/oversight/index.xml" rel="self" type="application/rss+xml"/><item><title>The First Time They Disagree</title><link>https://christaburger.com/blog/the-first-time-they-disagree/</link><pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate><dc:creator>Christa Burger</dc:creator><guid>https://christaburger.com/blog/the-first-time-they-disagree/</guid><category>Series: Formation Governance</category><description>What an embedded evaluator needs when the welcome meeting is over.</description><content:encoded><![CDATA[<figure><img src="https://christaburger.com/images/plexus-network.jpg" alt="Abstract digital network of interconnected nodes and concentric rings representing oversight and connection" /></figure><p>Oversight is easiest to support before it changes a decision.</p>
<p>At the beginning of an evaluation arrangement, everyone can agree that transparency matters. The charter is being drafted. The right people have joined the meeting. Someone may even be getting a badge. The harder test arrives later, when the evaluator finds something material, the release matters, the team is tired, and the difference between &ldquo;we should understand this better&rdquo; and &ldquo;we can proceed&rdquo; has a price attached to it.</p>
<p>That is the meeting an oversight model has to survive.</p>
<p>In his September essay, Dario Amodei argues for embedding independent evaluators inside frontier AI companies, with continuing access to systems and people and rights to publish findings. He draws on a banking-supervision analogy, which is useful because supervision is not just a report. It is an operating relationship with access, escalation, independence, and consequences. <a href="https://www.darioamodei.com/essay/machines-of-loving-grace">We Must Pace the Frontier</a></p>
<p>The practical questions are not glamorous, but they decide whether the arrangement works. Access to what? In what format? With which logs, interviews, system records, and authority to ask follow-up questions? How does the evaluator know whether the evidence set is complete enough for the claim being made? What happens when the team believes the evaluator has misunderstood a test result? Who owns the decision if the disagreement remains unresolved?</p>
<p>There are ordinary ways to starve an evaluator who technically has access. The relevant data can be available but unusable. Logs can omit the behavior that matters. Every question can require an introduction to someone who is busy, traveling, or not quite sure who owns the current version. A badge opens doors. It does remarkably little about naming conventions.</p>
<p>METR has already named several important conditions for serious investigation: model and transcript access, employee interviews, adequate resources, communication with oversight bodies, and disclosure of how redactions affect conclusions. That gives the field something concrete to build on. <a href="https://metr.org">METR&rsquo;s investigation framework</a></p>
<p>The next step is to make those conditions visible with the finding itself. A useful report should show what investigators requested, what they received, what remained unavailable, and what each gap prevented them from determining. &ldquo;No evidence of a problem&rdquo; means one thing after direct access to the relevant behavior and another thing when the behavior was never logged. Sensitive evidence may need restricted handling; the public account should still explain how the restriction affected the conclusion.</p>
<p>The disagreement path matters just as much. If an evaluator identifies a concerning behavior and the lab believes it is an artifact of the test, that may be true. The right response is a documented competing explanation and a way to distinguish between them. Preserve the original observation, the alternative account, the evidence that would resolve the question, and the decision taken while uncertainty remains. A finding should be able to change because the evidence changed. It should also be possible to tell when the language changed because the meeting got uncomfortable.</p>
<p>Consequences need the same clarity. An embedded evaluator does not need unilateral control over company operations to matter. A serious finding does need a route to someone who can accept the risk, require a remedy, restrict an action, or explain why proceeding is justified. That decision needs an owner and a record. Otherwise the organization can comply with evaluation indefinitely while leaving the underlying condition untouched. The report becomes another artifact the system knows how to produce.</p>
<p>The most useful preflight exercise is simple: run a bounded disagreement before the stakes are existential. Give the evaluator an incomplete evidence set, a disputed finding, and a real escalation path. Watch how long it takes to reach the right people. Watch whether uncertainty survives the executive summary. Watch who can request more work, who pays for it, and whether the decision-maker receives the evaluator&rsquo;s actual conclusion.</p>
<p>The welcome meeting can tell us that everyone supports oversight. The first consequential disagreement tells us whether we built it.</p>
<p>If the finding cannot leave the building, the evaluator never really got in.</p>
]]></content:encoded></item><item><title>The Auditor Needs an Audit Trail Too</title><link>https://christaburger.com/blog/the-auditor-needs-an-audit-trail/</link><pubDate>Sat, 29 Aug 2026 00:00:00 +0000</pubDate><dc:creator>Christa Burger</dc:creator><guid>https://christaburger.com/blog/the-auditor-needs-an-audit-trail/</guid><category>Series: Formation Governance</category><description>Independent assurance begins with the reviewer's ability to be wrong.</description><content:encoded><![CDATA[<figure><img src="https://christaburger.com/images/circuit-orchid.jpg" alt="Digital orchid integrated with glowing circuit patterns, representing the fusion of organic judgment and technical systems" /></figure><p>The moment an institution relies on a reviewer, the reviewer becomes part of the system that needs to be governed.</p>
<p>That is true whether the reviewer is a human expert, an independent evaluator, or another AI agent. The assurance function selects evidence, interprets ambiguity, applies a standard, and decides which findings deserve attention. Each action can be done well. Each can also drift. Giving the function a serious title does not exempt it from having an operating model.</p>
<p>AI makes the problem easier to miss. A team can ask one agent to produce a proposal and a second agent to review it. The reviewer agrees with the reasoning, suggests three improvements, and returns a polished assessment. The team now has two artifacts and a feeling of independent confirmation. The useful question is whether the second agent encountered evidence the first agent did not already choose.</p>
<p>Perhaps the proposal omitted a difficult dependency. Perhaps it framed the objective incorrectly. Perhaps the reviewer checked whether the steps were reasonable, and the steps were reasonable for the wrong purpose. Using a different model can help diversify review, but changing the logo at the top of the chat does not establish independence. Shared assumptions travel quite comfortably. They do not even need an integration.</p>
<p>A consequential review needs its own inputs. The reviewer should receive the governing purpose, original constraints, relevant evidence, acceptance criteria, and authority boundary. It should be possible to test a material claim without depending on the drafter&rsquo;s explanation of why the claim is true. If the issue is a permission boundary, inspect the permission and the action. If it is a factual claim, follow the source. If it is an omission, the reviewer needs a way to know the omitted thing exists.</p>
<p>The reviewer&rsquo;s standard also needs a history. Suppose a risk is first treated as a blocker. Three months later, similar evidence is routinely accepted with a note. There may be excellent reasons: stronger mitigations, better testing, a changed operating context. Record them. Otherwise an organization can redefine acceptable behavior through a series of individually plausible decisions and later discover that nobody remembers authorizing the new standard.</p>
<p>Anthropic&rsquo;s Petri work makes a related point about automated auditors and judges: definitions and thresholds need to fit the domain, and calibration against manually reviewed transcripts matters. The authors also discuss problems with overly leading auditors and with scoring behavior accurately. That specificity is valuable because it gives the reviewing system visible failure modes. <a href="https://www.anthropic.com/research">Petri&rsquo;s auditing and judging design</a></p>
<p>A practical assurance design should include a deliberately varied calibration set: clear defects, acceptable work, borderline cases, and cases where the right answer depends on context. Keep some cases out of routine tuning. Ask the reviewer what evidence would change its conclusion. Examine false alarms as seriously as missed problems. A function that objects to everything trains the institution to ignore it; a function that never objects can make the institution feel wonderfully safe. Neither result proves judgment.</p>
<p>The most useful metric may be the disposition of objections. Was the finding substantiated, withdrawn, resolved, overridden, or left open? By whom, and on what evidence? Counts of findings show activity. Dispositions show how assurance interacts with power. If every serious objection becomes a wording adjustment before publication, the pattern matters. If every disagreement becomes a personal contest, that matters too.</p>
<p>The evaluator must also be able to make a mistake visibly. It should be possible to revise a finding, acknowledge an insufficient test, or admit that an interpretation went beyond the record. Independence is not a performance of certainty. It is the ability to follow evidence even when doing so is inconvenient to the evaluator&rsquo;s previous position.</p>
<p>Assurance needs provenance, calibration, correction mechanisms, and accountable judgment. We are asking it to help govern systems that change. It should leave enough evidence for us to notice when it has changed as well.</p>
<p>The most dangerous rubber stamp may be the one that can explain itself.</p>
]]></content:encoded></item></channel></rss>