Global Thesis
EIS-020 identifies a governance gap that appears after an AI system has passed system-level review. An institution may know the model, vendor, version, testing history, access policy and control owner, yet still be unable to reconstruct how one consequential use affected a credit decision, procurement ranking, investment memo, public-service assessment or sustainability claim.
The Usage Evidence Gap is the distance between records establishing that an AI system was governed and records establishing how a particular use shaped an institutional outcome. The Epistemic Authority Boundary is the line between machine retrieval, analysis, transformation, inference or recommendation and the institution's responsibility to authorise evidence, institutional knowledge and accountable action.
The governing chain is Evidence → Retrieval → Analysis → Transformation → Inference → Recommendation or Action → Institutional Outcome. Each arrow can change meaning, omit context or increase apparent certainty. Governance therefore needs a second object alongside the AI System: the AI Use Event, a bounded record of what the system did in one consequential workflow and how authorised people and controls responded.
Institutional Context
The EU AI Act provides a regulatory baseline through logging, record-keeping, human oversight, deployer monitoring and, for specified uses, fundamental-rights impact assessment. EIS-020 does not claim that the Act adopts the terms Usage Evidence Gap, Epistemic Authority Boundary or AI Use Event. It uses the Act to show why system controls and deployer responsibilities increasingly meet at the point of actual use.
Singapore's Model AI Governance Framework, AI Verify ecosystem, National AI Strategy 2.0 and MAS information paper on AI model-risk management provide complementary system and organisational controls. They can support accountability, testing, monitoring and human involvement, but their existence alone does not prove that a particular machine-assisted decision can later be reconstructed from source evidence to outcome.
ASEAN's Guide on AI Governance and Ethics and its expanded generative-AI guidance promote practical regional principles while recognising different national contexts. They are not one binding ASEAN AI law and do not transfer decision authority from member states or institutions. The regional opportunity is to define portable use-event evidence without pretending that every jurisdiction applies the same legal threshold.
Singapore Relevance
In Singapore finance, model governance and model performance evidence address only part of the problem. If an AI tool ranks borrowers, summarises due diligence, detects anomalies or drafts a credit recommendation, the institution also needs to know which customer and transaction records were retrieved, which were excluded, which transformation changed their meaning and how the credit officer or committee treated the output.
The same issue arises in public administration, procurement and regulated professional work. An apparently human decision may be materially shaped by machine-generated prioritisation, summaries or exception flags before the authorised officer sees the file. A final signature establishes formal approval, but it cannot by itself reveal whether the decision was anchored in complete evidence or whether machine framing narrowed the available choices.
Boards and senior management therefore need two connected dashboards: one for system risk and one for consequential use. The second should show the population of high-impact use events, evidence and model versions, unresolved exceptions, human overrides, affected decisions, correction status and downstream reuse. That is governance of institutional reliance, not surveillance of every low-risk employee interaction.
ASEAN Relevance
ASEAN deployments intensify the Usage Evidence Gap because one model may operate across different languages, customer populations, legal duties, data quality and infrastructure. A regional bank, insurer, platform or infrastructure operator can centrally govern a model while local teams use its output under different mandates. A single system approval cannot establish that every local use remained valid and authorised.
Cross-border use-event evidence should preserve the operating entity, jurisdiction, language, affected person or asset class, source data location, model and tool version, local policy, decision owner and challenge route. It should also show whether translation, retrieval or external tools altered the evidential basis. Portability means that this context travels with the record, not that the underlying conclusion receives automatic regional recognition.
Five states should remain distinct: no source evidence, evidence retrieved but not authorised for the purpose, technically valid evidence transformed without sufficient context, a supported machine inference awaiting institutional judgement, and a final decision made under an identified mandate. Collapsing these states into one confidence score would conceal where regional capability, legal authority or human responsibility actually failed.
Capital & Enterprise Implications
In global capital markets, AI use can shape a transaction before any formal approval is recorded. Retrieval systems determine which issuer evidence enters diligence; summarisation can frame material risks; scoring can reorder borrowers or assets; generative tools can draft committee papers; surveillance models can trigger covenant or stewardship escalation. Machine influence therefore exists even when the final vote remains human.
The dangerous promotion chain is concrete: governed AI system → reliable retrieval → valid analysis → supported recommendation → committee knowledge → credit, investment or instrument eligibility. None of these arrows is automatic. A system test does not validate a particular retrieval set, a fluent summary does not establish completeness, and a human approval does not retroactively supply missing provenance.
Banks, asset managers, insurers, arrangers, rating and ESG data providers, assurance practitioners and issuers need different views of the same use event. A lender may retain the evidence supporting a risk grade, an asset manager the basis for mandate inclusion, and an assurer the boundary of machine-assisted work. Shared evidence can reduce repetition, but each institution must preserve its own authority, prohibited conclusions and accountable decision.
Evidence & Implementation Requirements
A minimum AI Use Event record should identify the purpose, accountable institution, user and decision owner; the event and workflow; time and applicable jurisdiction; source evidence identifiers, retrieval query and returned population; model, version, configuration, system instruction, prompt, connected tools and external data; and any transformation, ranking, filtering or summarisation applied.
The analytical layer should preserve material outputs, uncertainty, conflicts, missing evidence, inference and recommendation, plus the policy or threshold used to interpret them. The decision layer should record human review, challenge, override, escalation, final action, reason, affected party, disclosure or notice, correction, appeal, downstream reuse and supersession. Sensitive content can remain access-controlled while hashes, identifiers and authorised audit paths preserve reconstructability.
Not every AI interaction requires permanent retention. Institutions should define consequence-based triggers such as legal effect, material financial exposure, rights impact, regulated advice, public-service access, safety, significant disclosure or board reliance. The record should be sufficient for the authorised reviewer and no broader than necessary for privacy, confidentiality, security, privilege and contractual restrictions.
SNN.SG Singapore & ASEAN Perspective
SNN.SG's regional interpretation is that Singapore can become an ASEAN use-governance node by connecting model assurance, financial supervision, enterprise controls and cross-border evidence without claiming that one test certifies every outcome. The competitive advantage is not more automated decisions. It is the ability to show when machine assistance was evidentially bounded and when institutional judgement remained genuinely accountable.
EIA-010 and EIS-020 govern different but connected failure modes. EIA-010 asks whether evidence remains valid when a high-risk system changes after deployment. EIS-020 asks whether an institutional outcome remains reconstructable when that system is used. A changed model can invalidate use evidence, while an undocumented use event can make a well-governed model operationally unauditable.
A Pre-Disclosure Evidence Infrastructure should therefore bind system identity, change state and use-event records before AI-assisted conclusions enter board papers, regulatory reports, financial products or public claims. AI 2040 Plan A and Yuval Noah Harari are useful external scenarios about future capability and authority, not forecasts or normative conclusions adopted by SNN.SG. The immediate control problem already exists in present institutions.
What to Watch
The first Singapore test should select bounded, consequential workflows in credit, investment research, procurement or public administration. For each event, compare ordinary application logs with the evidence required by the model owner, business decision owner, risk function, internal audit, regulator and affected party. Record what each reviewer can and cannot reconstruct without obtaining restricted material outside their authority.
The ASEAN test should follow one regional workflow across at least two jurisdictions and one external model or data provider. It should measure language and retrieval differences, local-policy overrides, vendor observability, exception escalation, human review, correction propagation and retention. Success requires portable context and distributed authority, not identical outcomes across countries.
Watch for three failure signals: system assurance being promoted into decision assurance, human approval being used to conceal missing machine provenance, and public metadata exposing restricted evidence. The decisive outcome is an authorised reviewer who can reproduce what evidence entered the use, what the machine changed or inferred, who decided, and how an error was corrected across every downstream dependency.

