The viva: defending your command live against the examiner
The short answer
The viva tests command, not knowledge
Recall was tested in writing. The viva tests whether you can defend the specific decisions in your own dossier against an examiner who has read all of it. Studying frameworks for a viva is preparing for the wrong exam; study your own record until you know exactly where your evidence ends.
What you will be able to do
- Evaluate a live examiner's challenge to one of your command decisions and judge whether the decision is defensible on the evidence you actually have, indefensible and requiring concession, or somewhere in between requiring a qualified answer.
- Distinguish a defensible answer (grounded in a dated, inspectable artifact in your dossier) from a bluff (an assertion the record does not support), and explain why the second one destroys your credibility on everything else.
- Trace any answer you give back to the specific artifact that backs it: the AI systems inventory, the conformity file, the evaluation report, the incident log, the evidence annex. (see Topic 13.1)
- Concede an indefensible decision cleanly, naming the gap, the risk it created, and the concrete remediation, without collapsing your standing on the decisions that are sound.
- Judge the difference between an examiner attacking your evidence and an examiner attacking you, and respond to each without losing composure or ceding a defensible position.
- Construct, on the spot, a defense of a decision the examiner frames in a way you did not anticipate, by returning to the underlying principle and the record rather than reaching for a rehearsed script.
- Assess your own viva performance against the standard the AIGP (Artificial Intelligence Governance Professional) credential tests for and then goes past: not "do you know the rule" but "did you apply it, and can you defend the application."
- Recognize the seven recurring challenge archetypes an examiner uses (show-me, edge case, gap probe, personal, counterfactual, self-location, temporal drift) and reach for the correct response to each even when the specific question is one you did not prepare.
- Deliver a viva answer in the four-beat structure (name the decision, name the evidence, state the tradeoff, hold or concede) automatically enough that you never freeze and never wander outside your record under pressure.
The lesson
There is a moment in every serious accountability process when the paper stops and a person starts talking. This moment has an ancient name, the Viva Voce, the test of the living voice. It measures something rote recall cannot touch.
It tests your actual command of a system under adversarial pressure. Reciting Article 5 of the EU AI Act or the NIST Risk Management Framework offers zero protection here. The examiner only cares about the specific documented decisions inside your dossier and the examiner holds a severe advantage.
They have already read every document, log and audit before you sit down. No slide deck will save you now. No footnote can answer for you.
When you speak, your professional credibility is either validated by the facts you've logged or dismantled by the gaps you left behind. A meticulously organized document file is worthless if the person who built it cannot actively defend the reasoning behind it when the questions start. Every oral defense is governed by a single unforgiving rule, the boundary principle.
Your documented record, the dated inspectable artifacts you assembled before this process began forms the absolute perimeter of your defense. Inside this boundary sit the claims your evidence actually supports. The moment your spoken claim attempts to exceed your documented evidence, you trigger a failure state.
Any spoken assertion that lands outside the fixed record is a bluff. It does not matter how confidently you deliver it. A single detected bluff contaminates every other defensible position in your record.
Once an examiner catches an unsupported claim, they know your judgment cannot distinguish between a defensible position and an indefensible one. They can no longer trust anything you say. To survive this room, your only rational strategy is absolute candor, restricted entirely to what your fixed record can prove.
The boundary principle converts an oral defense from a test of persuasion into a test of strict calibration. You cannot speak past what you have built. Every challenge an examiner throws at your record requires one of three highly specific types of answers.
We map these responses into a strict three-zone framework. The bullseye is the full defense. You use this only when your decision is completely grounded in a dated inspectable artifact.
The middle ring is the qualified answer. This applies when your reasoning is sound, but your evidence is only partial. The mechanics here are critical.
You must explicitly name your own evidence gap out loud before the examiner discovers it. Transparency locks you safely inside your boundary. The outer ring is the concession.
You land here when a decision is indefensible or the artifact simply does not exist. Corporate instinct suggests that admitting a mistake signals weakness. In an AI eye of it, the opposite is true.
To execute a clean concession, you admit the gap plainly, name the specific risk that gap created, and state your concrete remediation. Aggressively defending an indefensible decision destroys credibility, whereas executing a clean concession proves your calibration is trustworthy. Under adversarial pressure, you need a delivery mechanism to maintain discipline and stay inside that evidence target.
This is the four beats protocol. It structures every valid answer you will give. Beat one, plainly name the specific decision that was made.
Beat two, name the specific artifact of evidence. If you cannot name the document and its date, you must immediately jump to a concession. You have no defense.
Beat three, state the trade-off or alternative that you accepted. This proves the decision was a deliberate choice, not an accident. Beat four, hold your position or concede cleanly with a remediation.
The hardest discipline lives right here at the end. Once the answer is delivered, you stop talking completely. Examiners use silence deliberately to see if you will stumble.
You must read the room and recognize their tactics. You will face two types of pressure. An evidence attack targets gaps in your record.
A personal attack targets your competence or your ego. The rule of engagement for a personal attack is strict. Never defend your ego.
Calmly route your answer back to a physical artifact you built in the record. The four beats protocol protects you from your own anxiety, ensuring you never improvise your way into a fatal bluff. This boundary is not a theoretical exercise.
Legal and regulatory bodies strictly enforce it. Consider the deepfake robocall crisis that struck the political landscape in January, 2024. During the New Hampshire primary, an operative sought to suppress voter turnout.
The mechanism was an artificial intelligence clone of President Joe Biden, pushed through thousands of automated calls. Long before the accountability process began, the operative's documented record was fixed. He had drafted the script, hired an acquaintance to generate the clone, and directed the transmission.
When the Federal Communications Commission stepped in to execute the reckoning, they worked directly from that paper trail. The record dictated severe financial penalties, a $6 million fine for the operative, and a $1 million settlement for the telecom carrier that transmitted the calls. The accountability then escalated from civil fines into the criminal justice system.
New Hampshire indicted the operative on 13 felony voter suppression counts. In every forum, his defense was bounded entirely by what the record proved he did. He could only argue the legal classification of the act.
He could not dispute the documented facts. We see the exact same enforcement mechanism in the European Union. The Italian Garante hit the maker of the replica chatbot with a 5 million euro fine.
That penalty was driven by a missing artifact. The company failed to produce a documented impact assessment regarding the protection of minors. And when federal lawyers submitted AI-hallucinated citations in court, the judge sanctioned them.
Eloquence cannot save a professional if the underlying artifact does not exist. A documented record establishes guilt, certainly. But more importantly, it permanently fixes the exact perimeter of every defense that can possibly follow.
Professionals usually collapse in the boardroom because of psychological drift, even when their technical documentation is sound. Mistake one is preparing for the wrong exam. They study broad compliance frameworks the night before instead of intimately memorizing the artifacts inside their own dossier.
Mistake two is yielding to corporate instinct. They attempt to defend every single decision to avoid appearing uncertain, destroying their credibility in the process. Mistake three is yielding to silence.
They pad their answers with extra words to fill the deliberate quiet left by the examiner. Padding invariably forces the professional to wander outside their documented record, generating an accidental bluff. Mistake four is treating intent as evidence, asserting that you meant to run that audit offers zero defense against a missing file.
A truly calibrated professional maps these gaps in advance. Like an executive defending high-risk calling tools, they succeed entirely by conceding their undocumented decisions cleanly under fire without breaking protocol. Survival in a deposition or an audit depends entirely on knowing exactly where your evidence stops.
It does not depend on how smoothly you can speak. To sit in the hot seat, you must translate these frameworks into immediate Monday morning action steps. This is the three-day protocol for examination readiness.
On day one, you walk the record from memory. Your objective is to locate the exact physical boundary of your evidence without opening the file. On day two, you run a hostile pass over your own dossier.
You must pre-identify the three weakest decisions in your record. For each one, prepare a strict risk and remediation statement so you are ready to concede from a position of command. On day three, you execute a timed adversarial mock examination.
You answer live and you do not look at your dossier. The ultimate scoring rhetoric for this final day is your bluff count. A passing grade requires zero bluffs paired with clean concessions on the items that are genuinely indefensible.
This process highlights the specific tension of governance. You need thorough documentation to set the perimeter, but your live command is the only thing the examiner actually measures. In the room where you finally account for your work, knowing the precise boundary of your evidence is your only professional armor.
The ideas, one by one
The boundary principle governs everything
You can defend what your documented record supports and nothing else. The examiner compares your spoken answers to your written commitments in real time, so the moment your voice claims more than your record backs, the gap becomes the story. Preparation is calibration to your own evidence, not rehearsal of eloquent answers.
Every answer is one of three kinds
A full defense (grounded in a dated artifact, held and stopped), a qualified answer (sound reasoning, partial evidence, gap named before the examiner names it), or a concession (indefensible, conceded cleanly with a remediation). The skill is knowing which kind you are in within seconds of the challenge landing.
A clean concession is a display of command, not weakness
Conceding the genuinely indefensible while defending the sound is exactly what the viva measures. Defending an indefensible decision does not save it; it destroys your credibility on every defensible one, because you have shown your judgment cannot tell a good call from a bad one.
Answer in four beats
Name the decision, name the evidence, state the tradeoff, then hold or concede. If you cannot complete the second beat, you are already outside your record and should go straight to an honest concession rather than bluffing.
Distinguish the evidence attack from the personal attack
Meet a challenge to your record with evidence or a clean concession. Meet a challenge to you with a calm route-back to an artifact, never with a defense of your ego and never with overreach. The build-before-you-govern spine exists so you can answer the personal attack by pointing at the model you built and broke.
Intent is not evidence
"We were going to run that audit" defends nothing. You can defend what you did, not what you meant to do; meaning to do the work lives in concession territory. Say it, back it with the artifact, stop.
A thorough dossier is necessary but not sufficient
The viva tests whether you understand the record, not whether it exists. Someone who inherited a complete file they did not build fails on the first follow-up. The dossier is the ground; command of it is what the viva measures.
The bluff count is the number that matters
In practice and in reality, a viva with zero bluffs and several clean concessions is a strong pass; a viva with one undetected bluff is a fail, because in a real proceeding that single bluff is where you lose everything. Find your bluffs in a simulated viva so a real examiner never finds them.
This is the closest simulation of what actually happens to AI leaders
The regulator interview, the deposition, the board's private session, the acquirer's diligence, all are vivas by another name, and all are governed by the boundary principle. The graduate who can sit this viva has crossed a line the AIGP exam does not draw. (see Topic 13.4)
Challenges come in a small number of shapes
Show-me, edge case, gap probe, personal, counterfactual, self-location, and temporal drift cover nearly everything an examiner asks. You cannot rehearse every question, but you can rehearse the seven responses, so an unfamiliar question resolves into a familiar move.
The language of command points at inspectable artifacts
The difference between a bluff and a defense is often the exact words: the weak answer leans on confidence, habit, or ego, and the strong answer names a specific dated artifact and stays inside what it supports. Make every clause point at something the examiner can check.
Silence is often a test, not a verdict
After a held answer, an examiner may go quiet to see whether you will keep talking and drift outside your record. Holding the silence is the disciplined move; filling it usually hands the examiner a new opening.
Candor is the only rational strategy under a fixed record
When your decisions are documented, hiding a gap or overstating a control does not reduce your exposure; it compounds it, because the misstatement is now a second, worse problem layered on the first. The Kramer robocall reckoning shows it plainly: a fixed record made candor the only move that did not make things worse.
The artifacts you wrote honestly are the ground you stand on
Every earlier module's artifact becomes part of the boundary you defend in the viva. Honest disclosure letters, evaluation reports, and decision memos give you defensible ground; ones written to look good give way exactly where an examiner pushes. The viva is where the honesty of your earlier work is finally priced.
Being examined well teaches you to examine well
The graduate held to the boundary principle becomes the person who demands it of vendors, teams, and systems they approve. That is how the discipline raises its own standard: rigorous, fair examination propagates through the people who survived it.
You read it. Now prove it.
Explain this lesson in your own words, the way you would to a colleague, without looking back at it. It is graded against the lesson itself, by the same grader our learners face. One free try a day, no account needed.
The conversation
The same lesson, talked through at length by two hosts: the full transcript of the audio deep dive.
Listen to it as episode 97 of the podcast.
Read the full conversation
Imagine stepping into a boardroom, right, and the air has just been completely sucked out of the room. Yeah, the classic high-stakes scenario. Exactly, because the paper trail has stopped.
The months of audits, the endless compliance checklists, the internal memos, they're all complete. Right. And they are sitting right there in this thick binder on the table, and you are sitting across from an examiner.
Which is terrifying for most people. It is, because this person might be a federal regulator or, you know, an internal board member or maybe opposing counsel in a deposition. Yeah, and they've read everything.
Right, they have read your entire file, every single document your team submitted. And they lean forward, they look you dead in the eye, and they say, walk me through why you decided this. Yeah, and no slide deck can save you there.
No slide deck, no hastily forwarded email, no footnote. You have to answer in your own living voice. And that specific moment is really where careers are either cemented or just completely dismantled.
So today, we are pulling together this really fascinating stack of source materials to figure out exactly how to survive that exact moment. It's so critical for anyone in a leadership position today. It really is.
So we're synthesizing recent regulatory filings, federal court transcripts, FCC enforcement actions, and some cutting-edge AI governance playbooks. Right. And the mission of this deep dive into the source material is to basically give you a master class on defending your command live against an examiner.
Which is an incredible skill to build. Yeah, we're going to unpack the exact frameworks, the hidden psychological traps, and the strategic disciplines you absolutely need to survive and honestly dominate this reckoning. Because it really is a major transformation happening in the corporate world right now.
How so? Like, what's driving it? Well, what you described in that boardroom scene, it actually has a name that dates back centuries. It's called the viva voce. Viva voce.
Right, which is Latin for living voice. Oh, wow. Okay.
Yeah. And traditionally, you know, it's an oral examination where a doctoral candidate or maybe a legal professional has to defend their work face-to-face against an examiner who, like you said, has already studied the record. So they already know the material.
Exactly. And we're seeing this ancient mechanism become the ultimate executive test, especially in AI governance. Right.
Regulators and courts are just moving rapidly away from treating governance as this, like, simple compliance checkbox. Like just filing the paperwork and moving on. Yeah, that's not enough anymore.
Yeah. They are demanding a really rigorous live discipline. So the people actually building and deploying these AI systems are being forced to sit across from authorities and defend their command of the work out loud.
Precisely. Out loud and under pressure. But to survive this test, we have to fundamentally reframe what the test is actually measuring, right? Oh, absolutely.
Because I feel like an executive's first instinct is always to cram. Oh, yeah. They try to memorize the dossier like they're studying for the bar exam.
Right. But the source material makes a really foundational distinction here, which is that the Viva tests command, not knowledge. And that distinction is basically the mandatory first rule of this entire discipline.
Command versus knowledge. Yeah. If it were simply a knowledge quiz, I mean, the examiner would just ask you to recite the specific data privacy provisions of the EU AI Act.
Right. Or ask you to list the core functions of the NIST AI risk management framework or whatever. Exactly.
But recall was already tested in your written exams and in your documentation. So they don't care about your memory. Well, they know you have a good memory.
The Viva tests your judgment under live pressure. Right. Recall is just what you can retrieve from your memory bank.
Command is what you can stand behind when a hostile party is actively trying to tear it down. OK. So when that examiner leans across the table, what exactly are they probing for? Like what actually constitutes command in that real time interaction? So the sources outline four specific pillars of command that the examiner is basically testing simultaneously.
OK. Let's go through them. The first pillar is fundamental.
And it's simply, did you do the work? Did you do the work? Right. An examiner who has thoroughly read your dossier can figure out within maybe two follow up questions whether you actually built those artifacts yourself. Yeah.
Or if you just inherited a folder that a vendor or a predecessor handed you. OK. Wait.
I want to challenge that immediately. Sure. Because this is a huge reality for a lot of professionals listening right now.
Absolutely. Let's say I'm hired as the new vice president of AI governance. Right.
And my predecessor left a dossier that is immaculate. OK. I mean, it's perfectly thorough, beautifully organized.
Every compliance box is checked and Christ referenced. A perfect file. Right.
Why isn't that enough? Like, does it really matter to the regulator if I just inherited it? As long as the organization has the proper documentation on file. It matters entirely. Really? Yes.
Because the thoroughness of documentation and the command of the decision making process are just two completely different concepts. How so? Well, documentation only proves that a decision was made. Let's say the examiner points to, I don't know, page 40 of that immaculate dossier and asks, Why did you pick this specific demographic field to monitor for bias, but you excluded the adjacent one? Oh, man.
Right. Your beautifully organized file has no answer for that. The file only states that the field was picked.
Because the paper doesn't capture the discarded alternatives. Exactly. It doesn't capture the messy meetings where you debated the tradeoffs and why you said no to the other options.
Precisely. Command lives exclusively in the head of the decision maker, not in the paper. Wow.
Yeah. So if you inherited that file, you have zero access to those discarded alternatives. So when they ask why, you just freeze.
You freeze. You have to trace the reasoning backwards until you actually own the rationale behind the decision. Otherwise, the VIVA just instantly exposes the difference between someone who files reports and someone who commands the system.
That sets a terrifyingly high bar. It does. But I guess that brings us to the second pillar.
Once they establish you actually did the work, they want to know, are your decisions defensible? Right. And defensible does not just mean documented like we just talked about. Right.
It means, does your underlying reasoning survive pressure when the examiner pushes you on edge cases that your pristine file didn't even consider? Right. And the third pillar is where the psychology of all this really starts to come into play, which is, where does your record end? This is the deepest test, honestly. And it's arguably the one where most executives completely fail.
Because they overstep. Yeah. Every single answer you give in that room is being continuously measured against your written commitments.
Like against the actual binder on the table. Exactly. Do your spoken answers stay safely inside what you actually documented? Or under pressure, do you start asserting things that your dossier just physically cannot support? Which leads directly to the fourth pillar.
And this one sounds almost counterintuitive when you're in a room trying to project authority. Oh, yeah. The fourth pillar is, can you concede? Right.
Like, can you identify an indefensible call out loud in real time? Because an examiner is ultimately testing your calibration. Calibration. OK, explain that.
If they press you on a genuine flaw in your system and you try to defend it as if it were a perfect decision, you've just proven to them that you cannot tell a good call from a bad one. Wow. OK, so if command is fundamentally about knowing the precise limits of your own work.
Right. Knowing the difference between what you actually built and what is just hypothetical, then there has to be a universal law governing where those limits are drawn. And the source material provides that exact law.
OK. What is it? It's the most critical concept for anyone facing an examination. It's called the boundary principle.
And the rule is, the boundary principle governs everything. The boundary principle. Yeah.
This principle states that your documented, dated record draws a hard, physical line in the room. OK. Inside that line is everything your evidence actually supports.
The training data you verified, the systems you inventoried, the security controls you rigorously tested. That's your solid ground. Exactly.
That is solid ground. Outside that line is everything else. Like what? It's what you meant to do, what you assumed the engineering team was handling, what you kind of hoped was happening in production but didn't actually check.
OK. So think of it like drawing a strict perimeter on a map. I love that analogy.
Inside the perimeter is a fortress. The ground is solid. You're protected.
You have the evidence. Right. But outside the perimeter is a complete minefield.
Oh, totally. And the moment you step outside that perimeter just to, you know, sound confident or maybe appease the examiner. You step on a mine.
You step on a mine. Yeah. That outer edge of your documented evidence is what the framework calls the bluff boundary.
The bluff boundary. Right. In Aviva, you are permitted to defend absolutely anything inside the line.
You can defend nothing outside it. Nothing. Nothing.
And this is not some arbitrary corporate rule. It's a structural reality of legal and regulatory accountability. Because the examiner is cross-referencing you in real time.
Exactly. They are actively comparing your spoken answers to your written record. The moment your living voice claims more than your paper record supports, the gap between the two becomes the entire story.
To make this incredibly concrete for you, the listener, the source materials highlight this massive real world anchor case. Oh, yeah. It perfectly illustrates the boundary principle.
We need to talk about the Steve Kramer FCC case from January 2024. It really is a textbook example of how a record traps you. Yeah.
So for context, just impartially looking at the facts here, Steve Kramer was a political operative who orchestrated a robocall campaign during the New Hampshire primary. Right. And he utilized an AI voice clone of President Joe Biden, essentially instructing voters to skip the primary election.
Right. Now, the accountability that followed didn't just appear out of thin air. Right.
The FCC didn't just read a news article and immediately issue a fine. Exactly. They built an exhaustive record.
They essentially constructed a boundary around Kramer's actions. What was inside that boundary? Well, the FCC established through hard documentation that Kramer personally drafted the script. He hired an acquaintance to generate the cloned synthetic voice.
He specifically chose which voter phone numbers to spoof to make the calls look legitimate. Wow. OK.
And he directed a specific telecom firm to blast those calls out. So all of that was inside his evidence perimeter. Yes.
And the financial consequences based on that record were absolutely staggering. The FCC finalized a $6 million penalty against Kramer. Which is massive.
Massive. But it extended beyond him, too, right? Yeah, to Lingo Telecom. Right.
Lingo Telecom, the carrier that actually transmitted the calls, initially faced a $2 million proposed penalty. Yes. And they eventually settled for $1 million.
Plus, they were forced into a binding compliance plan that required strict adherence to stirshaken rules. And let's define stirshaken for the listener just because it highlights how granular this record actually gets. Yeah, please.
Stirshaken is essentially a digital fingerprint protocol for phone calls. It's basically designed to prove that the caller ID hasn't been spoofed. Right.
So the regulator looked at Lingo Telecom's record, saw it instantly. His boundary was fixed. Inside the boundary, he made the calls.
So how did he win the acquittal then? He contested how the law classified his actions within that boundary. Oh, interesting. Yeah.
His defense successfully argued that the specific New Hampshire state statutes regarding voter suppression did not legally extend to the unsanctioned primary election that he targeted. Ah, OK. So even when he prevailed, his entire defense had to operate strictly inside the perimeter that his own documented record had already drawn.
That is the power of the record. It really is. It doesn't just establish guilt.
It draws the absolute limit of reality in that courtroom or boardroom. Exactly. If he had tried to step outside that boundary like, if he had bluffed and claimed ignorance of the technology.
The prosecution would have just used his own emails and receipts to annihilate him. Right. So the discipline that VIVA demands of you is to operate inside your own boundary just as strictly as Kramer's lawyers did.
You do not prepare for an examination by rehearsing clever, eloquent answers. You prepare by knowing your record so intimately that you can feel, on a visceral level, whether your answer is standing on solid evidence or whether you have wandered outside it into that minefield. And the sources actually outline specific behavioral tells that signal you are crossing that bluff boundary, right? Yes.
The tells are very real. Like, when you are operating inside your record, your answers are grounded. You can name a specific artifact, like a policy document or an audit log, and it's a date, without even needing to open the binder.
Right. And interestingly, as you gain confidence inside your boundary, your answers actually get shorter. That makes sense.
Yeah, because you're simply describing what you did in the past tense. But the human body has an early warning system when the evidence runs out. It does.
The moment you cross that bluff boundary, your vocabulary shifts. Yep. And the most glaring tell is the word intent.
Intent. Yes. Executives start using phrases like, well, we intended to run that safety check or, you know, our normal protocol would have been.
Your answers start getting longer, fluffier. Exactly. You stop describing what you specifically did, and you start describing what the industry typically does in theory.
And fundamentally, you feel this overwhelming urge to sound confident. Right. That internal pressure.
The need to substitute performative confidence for actual documented evidence. That is the definitive signal that you have crossed the bluff boundary. Wow.
And because the boundary principle is a structural, physical reality in that room, every single response you give to an examiner is dictated by where their challenge lands relative to that boundary. Which is where the examination transitions from this intimidating interrogation into a series of very deliberate strategic choices. Okay.
Because the rule is every answer you give is one of exactly three kinds. Let's break down the mechanics of those three responses. Absolutely.
So type one is the full defense. The full defense. Right.
This occurs when the examiner's challenge lands squarely inside your solid ground. Inside the perimeter. Exactly.
You have the dated artifact, the evidence directly supports your decision, and you answer without hesitation. So you just lay it out. Yeah.
You name the decision you made, point to the artifact, state the specific tradeoff you accepted, and then you stop talking. It's clean and absolute. Completely.
Now type two is where the reality of corporate life sets in. Right. Because things are rarely perfect.
Exactly. Type two is the qualified answer. Okay.
This happens when the examiner's challenge lands in kind of a middle ring. Your underlying reasoning might be sound, but your documented evidence is only partial. And this scenario absolutely terrifies executives.
Oh, completely. They feel that if they admit they only have half the data, they're going to look incompetent. Right.
And I see this constantly in tech. Honestly, no one has perfect data. Ever.
So let's say I'm in front of a regulator defending a machine learning model, right? Okay. If I only have 70% of the evidence I need to back up my claim, won't pointing that out just hand the regulator a reason to fine us? Like, how do I defend partial evidence without sounding like I'm trying to cover up a massive oversight? This is where understanding the psychology of the examiner is vital. The tactic here is brilliant in its simplicity.
You must name the gap out loud before the examiner does. Name the gap before they do. Yes.
Let's explore a very common AI scenario from the source material. Demographic drift. Just to define that quickly for the listener.
Demographic drift essentially means that an AI model's accuracy degrades over time for specific groups. Right. Maybe based on age or ethnicity, because the real-world data it encounters starts to look different from the data it was originally trained on.
Exactly. Now, suppose your team monitored this model for demographic drift on three specific protected attributes. Let's say age, gender, and geographic location.
But you lack the underlying demographic data to monitor a fourth attribute, say income level, which the regulator specifically cares about. So if the examiner asks about fairness across the board, the instinct is to just say, yes, we rigorously monitor for drift and kind of just hope they don't ask about income. And that hope is a bluff.
When asked, you must state the limitation explicitly. You defend the three attributes you did measure, and you actively flag the limitation on the fourth. So how does that sound in practice? You look at the examiner, and you say, we monitor drift on age, gender, and location.
And those reports are in the annex. However, I want to be precise. We did not have the underlying data to monitor income level.
And I flagged that specific limitation in our internal risk report rather than claiming coverage we did not have. Oh, man. That completely neutralizes the attack.
It really does. It's an incredible display of command. Naming your own gap is not a display of weakness.
It is the ultimate proof that you know exactly where your bluff boundary is. It tells the examiner that your calibration is trustworthy. Exactly.
You are demonstrating that you do not over-claim ambiguous evidence as settled fact, which is the breeding ground for regulatory disasters. This connects directly to a massive misconception executives have about intents, doesn't it? Oh, yes. Because the moment they realize a gap exists, they try to fill it with good intentions.
Right. They say, well, we were going to run that income level audit next quarter. Yeah.
Like, that helps. It doesn't. Intent is not evidence.
Offering intent as a defense is a fatal error in Aviva. Because you're basically offering a type 3 answer while desperately trying to disguise it as a type 1 defense. Exactly.
And the examiner sees right through it. Which brings us to the reality of the type 3 response itself, the concession. Yes.
This happens when the challenge lands completely outside your evidence. Right. The decision you made was objectively wrong, a critical control was completely untested, or maybe the artifact you need simply does not exist.
And facing a type 3 scenario is the ultimate test of executive maturity. Because the natural human reaction is just to panic, deflect, or bluff. Completely.
But the framework demands a different approach. Retreating gracefully through a clean concession is actually a display of profound command. I have to push back on this.
Go for it. You're suggesting that sitting in front of a regulator, someone who has the statutory power to fine the company millions of dollars, and openly admitting a failure is a smart strategy. I am.
That feels like professional suicide. Why would a concession ever be viewed as command? Because of how human credibility functions in an adversarial setting. Okay, explain that.
Defending an indefensible decision destroys your credibility on every single sound decision you made. Oh. Think about the examiner's perspective.
If you stubbornly defend a process that is clearly broken, you've just demonstrated that your judgment is fundamentally flawed. You're broadcasting that you cannot tell the good call from a bad one. So if I can't trust you when you're clearly wrong, I have zero reason to trust you when you claim to be right.
Precisely. An examiner will trust the executive who cleanly concedes an indefensible point far more than the executive who tries to defend every single page of the dossier. But for this to work, the concession must be surgically clean, right? It has to be perfect.
Let's build the anatomy of that clean concession, because getting this wrong is just as dangerous as bluffing. It is. The source material breaks it down into a strict three-part framework.
Right. Step one, you admit the decision was wrong, or the control was untested, with absolutely zero hedging, zero caveats, and zero blaming. Yeah.
You cannot say, well, our third-party vendor didn't provide the data in time. Right, because you own the choice to rely on that vendor in the first place. Exactly.
Blaming a vendor is a failure of command. So that's step one. What's step two? Step two, you name the specific risk that your gap created.
You have to prove to the examiner that you fully understand the negative consequences of your failure. And step three, you name the concrete remediation and exactly where that fix now lives in your operational process. Let's apply this to a highly technical scenario just to illustrate it.
Yeah, let's do it. Imagine you deployed a generative AI chatbot without conducting a specific type of security test, say, a red team pass for prompt injection. Okay, just to clarify for the listener, prompt injection is a cyber attack where a user essentially tricks the AI by feeding it malicious instructions, forcing it to ignore its safety guidelines, and perhaps reveal sensitive data.
Right. And red teaming is hiring specialized security professionals to deliberately try to break the AI using these tactics before you launch. Perfect definition.
So the examiner discovers you skipped this test and they challenge you. A clean concession sounds exactly like this. You were right.
We deployed the model without a dedicated red team pass on prompt injection. The specific risk was that a malicious user could extract the underlying system prompt or access restricted data, which unfortunately did happen. What I have since built into our mandatory release gate is an adversarial evaluation suite that must be cleared before any new feature ships.
Wow. It is a flawless pivot. Isn't it? You lost the specific battle over that one decision, but you preserved your total credibility for the rest of the examination.
Exactly. And this dynamic leads us to the ultimate metric of success in Aviva. It's a concept called the bluff count.
The bluff count. I love this concept because it completely upends how people view success. It really does.
Because executive instinct tells us that a perfect examination means zero concessions. We think we have to win every single point. And that instinct is totally wrong.
Aviva's success is not measured by having zero concessions. Okay. Aviva with zero bluffs and three clean concessions is a strong pass.
You have proven you know your limits and can remediate errors. Right. However, Aviva with zero concessions but one undetected bluff that the examiner catches is an absolute failure.
One single bluff constitutes a total failure. Why is the penalty so severe? Because of a deeply ingrained legal and investigative doctrine. Falsus in uno, falsus in omnibus.
False in one thing, false in everything. Exactly. In a real regulatory proceeding or especially under oath in a courtroom, that one bluff is where your entire defense collapses.
Because you lied once. Right. The moment the examiner catches you asserting something as fact that your record cannot support, every other defense you mount becomes tainted.
The examiner will just assume you are bluffing about the sound decisions too. That makes total sense. So the bluff count is the single most important number in your professional life during an examination.
It must remain at zero. Zero. Okay.
So now that we understand the three types of answers, we need a reliable, repeatable rhythm to actually deliver them. Right. Because understanding the theory is one thing, but when opposing counsel is staring you down and your adrenaline is spiking, you need muscle memory.
You need a system. And the source material provides a tactical life raft for executives under pressure. What is it? It's a cadence.
Answer in four beats. Four beats. Yeah.
If you internalize this structural shape, you will never freeze because your brain always knows exactly what the next beat is. Let's walk through the beats. Beat one, name the decision.
Right. What did you actually decide? Not what the steering committee pondered, not what the industry standards suggest. What did you decide? Yes.
We chose to keep a human in the loop for all final approvals. Exactly. Yeah.
Then you move to beat two, name the evidence. Name the evidence. You point to the specific dated artifact in your dossier.
That control is documented in the agent governance policy dated March 14th. Okay. This beat is the guardian of the boundary principle.
If you open your mouth and realize you cannot complete beat two like you have no artifact to name, you immediately know you are in type three concession territory. You're outside the pruner. Exactly.
Then we hit beat three, state the tradeoff. Yes. What cost did you accept to make that decision? And I frequently encounter resistance on beat three when training executives.
Really? Why? They'll argue, what if the decision was incredibly obvious? What if we discovered a massive bias flaw in the algorithm and shut it down? Obviously we shut it down. There was no tradeoff. It was just the right thing to do.
Honestly, that makes intuitive sense to me. If a model is actively discriminating against users, shutting it off isn't a tradeoff, it's a moral imperative. Why does an executive have to invent a tradeoff for doing the right thing? Because in corporate operations, no decision is free.
Okay. If you cannot name the tradeoff, you signal to the examiner that you backed into the decision by default rather than actively managing the system. I see.
Even if shutting down a biased algorithm was the obvious ethical choice, the tradeoff might have been a six-week delay to the product launch roadmap. Right. It might have been a loss of market share to a competitor.
It might have been absorbing higher operational costs to manually review the data while the AI was offline. You have to prove you understood the gravity of the choice. Exactly.
Naming the cost you accepted proves analytical depth. Saying, it was obviously the right call, is a weak answer. It shows you only looked at the benefit, not the systemic impact.
Wow. And then we hit beat four. Hold or concede.
You finish stating the tradeoff and then you stop talking entirely. Or, if you realize you're outside your boundary, you execute the clean concession. Exactly.
But I really want to linger on the command to hold because the psychological pressure of silence in these rooms is immense. Oh, it's suffocating. You deliver your four beats and the examiner just stares at you.
And that silence is rarely accidental. Really? It's a tactic. Absolutely.
Yeah. It is a deliberate tactical test deployed by skilled examiners. They stay silent after you hold your answer to see if your anxiety will force you to nervously pad your response.
Oh, man. And the moment you start padding to fill the dead air, you inevitably wander outside your documented record. You step right onto the mine.
Wow. A held answer ends definitively. It does not trail off into a rambling justification.
Holding the silence is a profound psychological discipline. Right. If you allow your discomfort to fill that silence, you will almost always hand the examiner a brand new opening into your bluff boundary.
So the four beats, name the decision, name the evidence, state the tradeoff, hold. They protect you from your own internal anxiety. Yes.
But you also have to protect yourself from the examiner's external tactics. And this requires an understanding of how an interrogation is structured. The most vital instruction the source material provides for navigating the actual dialogue is to clearly distinguish the evidence attack from the personal attack.
Okay. How do those two attacks differ in practice? An evidence attack goes directly at your record. Okay.
The examiner might say, your data provenance file is missing a source origin for this specific training corpus. How do you defend utilizing it? Right, which is fair. It's a completely legitimate question about the integrity of your work.
You meet it rationally with evidence or you execute a clean concession. The examiner is simply doing their job. But a personal attack bypasses the record completely and goes directly at your ego.
Exactly. They might say, you don't really understand how neural networks operate, do you? You're just a compliance manager playing at software engineering. And that is no longer a question about your record.
That is psychological pressure specifically designed to make you crumble or worse, overreach out of pride. Because if you defend your ego, if you say, I have a decade of experience in Silicon Valley and I understand this perfectly, you have taken the bait. You've taken the bait, you sound defensive, and you have moved the conversation away from the evidence.
The only correct response to a personal attack is to route the challenge immediately back to the work. It's like defending a fortress, right? If the enemy attacks the structural integrity of the walls, you show them the reinforced stone. But if they stand outside and yell that you are a terrible mason, you don't argue with them about your skills.
You just point to the wall you built. You let the artifacts settle the argument. That analogy captures the dynamic perfectly.
You respond to the insult by saying, I built and stress tested a classification model myself. And the detailed failure analysis is on page 20 of the dossier. Let me walk you through the specific failure mode I uncovered and how it directly shaped our evaluation suite.
You point at the artifact. Yes. Having actual documented work is your ultimate shield against personal intimidation.
Now beyond the broad categories of evidence and personal attacks, the source material identifies several recurring shapes that these challenges take, known as the challenge archetypes. Right. And recognizing the shape of the attack is incredibly empowering because it means you don't have to memorize a thousand different answers.
You just need to recognize the archetype and deploy the corresponding strategic move. Exactly. There are seven main challenge archetypes in the source material, but let's go deep on the most dangerous one.
Let's do it. The most common is the show me. The show me.
The examiner simply demands the artifact. You claim you ran a comprehensive bias audit. Show me.
OK, what's the trap there? The trap here is psychological comfort. Executives often try to describe what a bias audit would theoretically say instead of doing the hard work of locating the actual document in the moment. They slip into abstract consulting speak.
Well, a standard bias audit looks at these three variables. And the examiner instantly knows you don't have command of the file. The correct move is to physically or digitally locate the dated artifact and name it.
Then there is the gap probe. This is where the examiner asks, where is the provenance documentation for this specific data set? The psychology of the gap probe is fascinating. Usually when an examiner asks this, they already know or strongly suspect that the gap exists.
Really? So it's a trap. They are not asking for information. They are testing your self-awareness.
They want to see if you know the gap is there. And the trap is trying to bluff past it, hoping they haven't noticed. Exactly.
The correct move is to embrace the gap probe, name the gap yourself, state the specific risk it creates, and name the remediation before the examiner has the satisfaction of dragging it out of you. Wow. Okay, we discussed the personal attack routing it back to the artifact.
Let's look at the counterfactual. Right. The examiner asks, why didn't you just use the vendor's default safety threshold? This is a direct test of Beat 3, the tradeoff.
Ah, the tradeoff. Yes. The trap is claiming that there was no alternative or that it wasn't discussed.
You must be able to name the alternative that you rejected and articulate the exact business or technical reason why you rejected it. Now, my favorite archetype, just because it is so deviously effective, is the self-location. Oh, this one is brutal.
The examiner leans back and asks, in your professional opinion, what is the weakest decision in this entire file? It is the purest test of calibration and command. And the trap here is driven entirely by ego, isn't it? Completely. Executives will try to deflect or they'll offer a trivial, humble-brag weakness to try and maintain a facade of perfection.
It's the equivalent of the terrible job interview answer. My biggest weakness is that I just care too much about compliance. I work too hard.
It is exactly that, and it infuriates examiners. I bet. If you give a non-answer, you are proving you either don't know your own system's flaws or you lack the courage to discuss them.
So what's the correct move? You must accurately and proactively name the genuinely weakest decision in your record. You look them in the eye and say, our sentiment analysis vendor repeatedly refuses to disclose the provenance of their training data. That is objectively the weakest point in our supply chain, and here is the systemic risk it creates for us.
That displays total command. It really does. The final archetype we should cover is temporal drift.
This occurs frequently because technology moves faster than regulation. Right. So the examiner asks, your data retention policy was legally compliant when you drafted it two years ago, but given the new privacy frameworks released last month, would you defend that exact same policy today? And the trap here feels like a catch-22.
It is. If you say no, you're disowning your own past work. If you say yes, you look stubbornly out of touch with modern standards.
Right. The correct move is to bifurcate the timeline. Bifurcate it.
Yeah. You firmly defend the past standard that governed the decision at the time it was made. Then you explicitly name the new standard and outline exactly what you would do differently today to meet it.
These archetypes are not just academic theories discussed in classrooms, though. No, not at all. These exact tactics are currently dismantling executives in boardrooms and courtrooms across the globe.
The frameworks we are discussing apply far beyond a formal doctoral defense. The stakes in these real-world arenas are existential for companies. Let's talk about the litigation deposition.
Okay. In this arena, opposing counsel has subpoenaed your documents, and they are questioning you under oath. This is the purest, most aggressive form of the evidence attack.
Yes, it is. A major case study from the source material involves the ride-sharing platform Uber Eats. This is a high-profile discrimination case.
Right, involving a black courier who experienced repeated documented failures with the app's facial verification software, which ultimately impacted his ability to work. Yes. And when this reached deposition, opposing counsel didn't debate the theoretical ethics of AI bias.
No, they didn't have to. Exactly. They used the record.
Once the written record of those repeated specific verification failures was established during the deposition, once it was clear the company had data showing the system was failing this demographic, the defensible territory for the company vanished. Because they couldn't bluff past their own logs? Exactly. Settlement became the only rational move.
A deposition does not care about your eloquence or your corporate intentions. It cares exclusively about what your documents prove you knew and did. And we're also seeing this intensely in regulator interviews.
Yes. European data protection authorities in particular are aggressively utilizing record-based examinations. Look at the Italian Data Protection Authority, the Garante, and their action against the Replica AI chatbot.
The Garante didn't just send a warning letter. They banned the service from processing Italian users' data and imposed a massive 5 million euro fine. Which is a huge blow.
Yeah. And the core of their action was based on the company's failure to protect minors from emotionally inappropriate AI interactions. That regulatory action developed through a strict examination of what the company knew, what they documented, and what they decided regarding age verification controls.
It's all about the record again. Yes. In these regulatory interviews, the privacy officer who can point to a dated comprehensive impact assessment can defend their position.
The officer who cannot produce the artifact is forced into a concession. It is a viva voce conducted by an entity with sweeping statutory power. And we cannot discuss real-world arenas without mentioning what this source material implies is the ultimate failed viva, the hallucinated citations case.
Oh, this one serves as a stark, permanent warning for relying on AI without maintaining a record. What happened here? Well, in federal court, lawyers submitted a legal brief filled with citations to past court cases that were completely hallucinated, invented out of thin air by a generative AI tool. Unbelievable.
So when the judge realized the cases couldn't be found, he called the lawyers in for a hearing. He essentially demanded a viva voce. He asked them to defend the filing.
And they couldn't. It was the boundary principle at its harshest. Because there was no boundary.
Exactly. Because the AI had fabricated the cases, there were no underlying artifacts. There were no actual court documents to produce.
No amount of legal eloquence, no impassioned arguments about their intent to provide good counsel could save them. If you have no record, you have no defense. Period.
Period. They were severely sanctioned. This dynamic dictates outcomes in congressional hearings.
Yeah. And critically, during acquirer due diligence, where a Type 3 gap might not result in a public fine, but it will quietly kill a nine-figure acquisition deal. So to synthesize all of these frameworks, the source material offers this really brilliant immersive scenario.
Jenna's Viva. Yes. Let's examine Jenna's Viva.
Jenna is a hypothetical, newly appointed AI governance lead for a mid-sized technology firm that specializes in voter outreach software. And given the Steve Kramer FCC case we discussed earlier, voter outreach software is currently one of the most highly scrutinized regulatory spaces in the world. Exactly.
So Jenna sits down with an external auditor. The examiner immediately launches a massive gap probe. The examiner says, Jenna, your platform accepts raw audio uploads from political campaigns.
Therefore, a bad actor could simply upload an externally generated deepfake voice clone. Defend your team's claim that your synthetic voice blocking software protects against deepfake calls. This is a lethal test by the examiner.
It really is. They are probing the exact edge case of the system, and Jenna does not bluff. She instantly recognizes that this scenario lands completely outside her documented evidence, because her blocking software only analyzes audio generated inside their platform, not external uploads.
So she executes a flawless, clean concession. Yes. She looks at the examiner and says, I cannot defend that claim in the context of external uploads.
You have described the exact New Hampshire vector, and our current upload feature leaves that vector open. The specific risk is that we transmit a malicious deepfake that we did not generate, putting us in the exact legal position Lingo Telecom was in when they settled for a million dollars. That is incredible.
She ties her concession directly to the real world precedent, proving she understands the severity of the gap. Then she delivers the third step, the remediation. Because of that documented gap, what I am currently building into our next mandatory release gate is an agnostic synthetic audio detector applied to every single upload, paired with a strict cryptographic provenance check.
Wow. She lost the battle over the current software version, but she established total unshakable credibility with the auditor. But the examiner isn't done.
No. They pivot to a personal attack to test her composure. They say, Jenna, you are a lawyer by training.
You have a law degree, not a computer science degree. You don't actually understand how these voice cloning detection models work under the hood. Jenna recognizes the archetype.
She doesn't defend her intelligence or her law degree. She routes the attack directly back to the work. How does she do it? She says, I personally trained and deliberately broke an open source voice classification model to understand its limits, and my technical failure analysis is located in Section 4 of the dossier.
I know exactly how brittle these statistical detectors are in production, which is exactly why my remediation strategy relies on a verified cryptographic consent chain, not just a software detector. Jenna's success in that room wasn't improvised brilliance. No, it wasn't.
It was rigorously prepared. She knew the exact location of her bluff boundary before she ever sat down. Which brings us to the final action plan for you, the listener.
How do you prepare to be Jenna? Before we outline the exact steps you should take on Monday morning, there is a fundamental ethical requirement embedded in this framework, isn't there? Yes, the dual duty of candor and fairness. Explain that. Well, as the professional being examined, you operate under a strict duty of candor.
You never intentionally hide a gap. You never overstate the efficacy of a security control. When you are operating against a fixed documented record, lying doesn't just damage your ethics, it mathematically compounds your legal exposure.
But the examiner bears a burden as well, the duty of fairness. Yes. An examiner must evaluate the record rigorously and mercilessly, but they must strictly distinguish a professional examination from personal harassment.
Right. An examiner who relies solely on personal attacks to intimidate an executive is not conducting a viva, they are just bullying. That's a great point.
And mastering the discipline of being examined well ultimately trains you to be a fair, highly rigorous examiner of others. Whether you are auditing a third party vendor's security claims or reviewing your own internal engineering teams, you will know how to probe the evidence, not attack the person. As we wrap up this analysis, here is a final provocative thought to consider.
We spend so much of our professional lives trying to project an image of absolute perfection. We really do. But true professional power doesn't actually come from being invulnerable to criticism.
True power comes from being so intimately acquainted with your own vulnerabilities and so honest about where your evidence ends that no one can ever surprise you with your own flaws. That's a powerful way to look at it. If you know exactly where your armor is thin, you control the battlefield.
Which translates directly to the Monday morning move. The Monday morning move. Yes.
Do not spend this weekend trying to memorize every page of your compliance dossier. That is testing recall, not command. Right.
So what should they do instead? Instead, when you sit at your desk on Monday morning, run a hostile pass over your own record. Look at it through the eyes of the examiner. Okay.
So look for the holes? Exactly. Locate the top three decisions in your current project that you are least able to defend with concrete evidence. The ones that make you slightly nervous? Yes.
The ones that keep you up at night. Define the exact evidence gap for those three decisions. Define the specific systemic risk those gaps create for the organization.
And finally, define the concrete remediation strategy you will deploy. Preload those clean concessions into your mind. If you know exactly where your bluff boundary lies before the examiner even walks into the room, you will never step on that mine.
You will not just survive the reckoning, you will command it. Thank you for joining this deep dive into the source material. We will see you next time.
Real cases
These are real accountability moments where a person, or an institution, had to defend AI-related decisions against an examiner who had studied the record. The lesson each carries is the boundary principle: the record set what could be defended.
Example 1: The New Hampshire robocall reckoning (the anchor). After the January 2024 deepfake Biden robocalls, the accountability came in layers, and each layer worked from a fixed record. The FCC proposed a 6 million US dollar penalty against Steve Kramer and finalized it in 2024, having established that he drafted the script, commissioned the AI voice clone, chose the spoofed number, and directed the calls (Federal Communications Commission, FCC 24-59, Notice of Apparent Liability, 2024; Forfeiture Order, 2024). Separately, Lingo Telecom, the carrier that transmitted the calls, faced a proposed 2 million US dollar penalty and settled with the FCC for 1 million US dollars plus a binding compliance plan requiring strict adherence to the STIR/SHAKEN caller-ID authentication rules (Federal Communications Commission, "FCC Settles Spoofed AI-Generated Robocalls Case," 21 August 2024). New Hampshire indicted Kramer on thirteen felony voter-suppression counts and thirteen misdemeanor candidate-impersonation counts, though a state jury acquitted him on those charges in June 2025, accepting his argument that the statutes did not reach an unsanctioned primary rather than disputing what he had done (New Hampshire Department of Justice, 2024; New Hampshire v. Kramer, jury verdict, June 2025). The teaching point is not the size of the penalties, nor even the criminal outcome. It is that in every forum, the decisions had been documented before the defense began, and the documentation, not the later explanation, set the boundary of what anyone could argue. Even in the forum where Kramer prevailed, he did so by contesting the law, not the record of his own conduct, which he did not deny. The carrier's defense was narrow and led to a settlement precisely because the record showed it had failed a specific, nameable control. Command, or its absence, was legible in the record.
Example 2: A congressional hearing as a viva. When AI executives are called before legislative committees, the format is a viva in all but name. The members have staff-prepared records, they ask a decision to be defended, and the answer is measured against the public record of what the company did. The executives who fare worst are those who assert capabilities or safeguards the record does not support and are then confronted with the contradiction. The pattern is consistent across many such hearings and is worth studying as a genre: the boundary principle governs a legislative hearing exactly as it governs a doctoral defense. Claims that exceed the documented record become the story. (Illustrative of the format generally; the specific dynamics repeat across multiple US and EU hearings from 2023 onward.)
Example 3: The litigation deposition. In a deposition, opposing counsel has your documents and questions you under oath about the decisions in them. It is the purest evidence-attack viva that exists. The Uber Eats courier case, where a Black driver's repeated facial-verification failures led the company to settle rather than defend the discrimination claim to a full hearing, turned on exactly this dynamic: once the record of repeated failures was established, the defensible territory shrank to the point where settlement was the rational move. (see Topic 11.2) The deposition does not care about your eloquence. It cares about what your documents show and whether your sworn answers stay inside them.
Example 4: The regulator interview. European data-protection authorities and sector regulators increasingly conduct interviews as part of AI investigations, sitting the responsible officer down and asking them to defend specific processing decisions against the file. The Italian Garante's action against the maker of the Replika chatbot, which banned the service for failing to protect minors and later imposed a 5 million euro fine, developed through exactly this kind of record-based examination of what the company knew and decided. (see Topic 11.6) The officer who can point to a dated impact assessment defends; the officer who cannot, concedes. The interview is a viva conducted by someone with statutory power.
Example 5: The acquirer's due diligence. When one company acquires another, the acquirer's technical and legal teams grill the target's leaders on their AI systems: what is in the training data, what is the provenance, what are the open liabilities. This commercial viva is where an AI systems inventory that was assembled honestly pays off and one that was assembled to look good falls apart. (see Topic 8.3) The diligence team has read the data room; the target's officer defends against that record. A gap discovered here does not fine you; it discounts the price or kills the deal. The stakes teach the same lesson: build the record honestly, because someone who has read it will one day ask you to defend it out loud.
Example 6: The internal board's private session. The most frequent viva an AI leader faces is the least visible: the board's private session, where directors who have read the pre-read ask the officer to defend a decision without management present to help. This is where the dossier assembled in Topic 13.1 either carries the officer or exposes them. (see Topic 13.1) The board is not hostile, but it is examining, and the officer who understands their own record defends it while the officer who inherited it flounders on the first follow-up.
Example 7: The whistleblower's own viva. Accountability runs in both directions. A person who raises an alarm about their own organization's AI is also examined against the record, by the organization, by regulators, and sometimes by the public. When a former OpenAI researcher publicly argued the company's training practices violated copyright and offered to provide documents, the strength of the position rested on what could be shown, not on the sincerity of the concern. (see Topic 11.5) The lesson generalizes: whether you are defending your command or challenging someone else's, the boundary principle governs. Claims are worth exactly what the record behind them can support. (This case is referenced with care; the individual was later found dead, and the point here is strictly about record-based accountability.)
Example 8: The court that demanded the record be inspectable. In State v. Loomis, the Wisconsin Supreme Court allowed a risk-assessment tool at sentencing only on the condition that its opacity and limits be disclosed in writing, so that the decision could be inspected. (see Topic 13.1) The court was, in effect, insisting on a defensible record before it would let an AI-informed decision stand. That is the institutional form of the same demand a viva makes of a person: a decision is only as good as the inspectable reasoning behind it, and a decision no one can examine is a decision no one should trust.
Example 9: The hallucinated-citations sanction as a failed viva. When a federal judge fined two lawyers whose brief carried dozens of AI-invented citations, the courtroom exchange that preceded the sanction was a viva in miniature. The judge asked the lawyers to defend the filing, and the record, the fake cases, could not be defended because the cited authorities did not exist. (see Topic 11.1) The lesson is the boundary principle at its harshest. There was no artifact behind the claims, so there was nothing to defend, and no amount of eloquence could conjure a record that was never there. A viva cannot be won by confidence when the underlying evidence is fabricated; it can only be lost more slowly.
Where people go wrong
- "A viva is a knowledge test, so I should study the frameworks harder." Wrong target. The viva does not test whether you know the EU AI Act or the NIST AI RMF; the written assessments already did that. It tests whether you can defend the decisions in your own dossier. Studying frameworks the night before a viva is preparing for the wrong exam. Study your own record until you know exactly where your evidence stops.
- "I should defend every decision; conceding makes me look weak." This is the most damaging misconception in the topic. Defending an indefensible decision does not protect that decision; it destroys your credibility on every defensible one, because you have shown the examiner your judgment cannot tell a good call from a bad one. A clean concession with a named remediation is a display of command. The person who concedes nothing is trusted on nothing.
- "If I sound confident enough, I can carry an answer past a weak point." Confidence is not the currency. The examiner is comparing your words to your record, not weighing your tone. An eloquent claim that the record does not support is a bluff, and a good examiner detects the gap regardless of how you sound. Calibration beats confidence every time.
- "The examiner attacking me personally means I am losing." Not necessarily. A personal attack is often a probe of your composure, not a substantive point against your record. Treat it as a test to route back to the work, not as a wound to defend. Losing composure over a personal attack, or overreaching to prove yourself, does more damage than the attack itself.
- "I can defend a decision by explaining what I intended to do." Intent is not evidence. "We were going to run that audit" defends nothing; the audit either exists in the record or it does not. The boundary principle is unforgiving here: you can defend what you did, not what you meant to do. Meaning to do the work lives outside your record, in concession territory.
- "A longer, more detailed answer is a stronger answer." Padding is a tell. A held answer names the decision, the evidence, and the tradeoff, and then stops. Candidates who keep talking after they have made their point usually do so because they are anxious, and the extra words often wander outside the record and hand the examiner a new opening. Say it, back it, stop.
- "My dossier is thorough, so the viva is a formality." A thorough dossier is necessary but not sufficient. The viva tests whether you understand the dossier, not whether it exists. An officer who inherited a complete, well-organized file they did not build will fail on the first follow-up question, because thoroughness of documentation and command of it are different things. (see Topic 13.1)
- "I can defend a decision by pointing to what the industry usually does." Wrong. Industry practice is not your record. "Everyone uses that vendor" defends nothing about whether you assessed the vendor. The examiner is testing your decision and your evidence, not the market's habits. Common practice may inform a decision, but the artifact that records your own assessment is what you defend.
- "Silence from the examiner means my answer failed." Not necessarily. A skilled examiner often stays silent after a held answer to see whether you will keep talking and wander outside your record. Silence is frequently a test of your discipline, not a verdict on your answer. Fill it and you may hand the examiner a new opening; hold it and you pass the test the silence was.
- "A counterfactual question is a trap I should refuse." A counterfactual ("why not automate this?") is not a trap; it is a fair test of whether you understood your tradeoff. Refusing to engage it, or claiming there was no alternative, signals you backed into the decision. Name the alternative you rejected and why, and the counterfactual becomes a chance to show command.
- "If I concede one decision, I have failed the viva." The opposite. Conceding the genuinely indefensible while defending the sound is exactly the calibration the viva measures. A viva where you conceded two decisions cleanly and defended nine on the record is a strong pass. A viva where you defended all eleven, including the two that were indefensible, is a fail disguised as a win, and a real examiner sees through it.
Questions people ask
- What is viva voce (viva)?
- From the Latin for "living voice," an oral examination in which the person who did the work defends it face to face against an examiner who has already studied the record. In this program, the live defense of your AI governance command against an AI examiner that has ingested your entire dossier.
- What is the boundary principle?
- The rule that you can defend only what your documented record supports, and nothing outside it. Because the examiner compares your spoken answers to your written record in real time, any claim that exceeds the record creates a contradiction the examiner will find. Preparation for a viva is calibration to this boundary, not rehearsal of answers.
- What is full defense?
- A viva answer to a challenge that lands inside your evidence. It names the decision, names the dated artifact that backs it, states the tradeoff accepted, and stops. The strongest of the three kinds of answer, available only when the record supports the claim.
- What is qualified answer?
- A viva answer to a challenge where the reasoning is sound but the evidence is partial. The move is to defend the reasoning while naming the evidence gap out loud, before the examiner names it, keeping the answer inside the bluff boundary.
- What is concession?
- A viva answer to a challenge that lands outside your evidence, where the decision was wrong, the control was untested, or the artifact does not exist. A clean concession admits the gap plainly, names the risk it created, and names a concrete remediation. Conceding the genuinely indefensible is a display of command, not weakness. More on Concession
Keep going
This lesson builds AI evaluation and testing design, and that page shows the roles that hire for it. Every Certified AI Governance Professional (CAIGP) lesson.