The attestation-verification gap
Giving an unverified declaration real weight instead of asking every submitter to prove it up front. Without something backing the declaration, an agency must either demand proof most submitters can't produce, or treat every declaration as meaningless.
The impact of agents
Attestation ("I declare that this is true") and verification ("I can prove that this is true") sit at opposite ends of the assurance spectrum. For the foreseeable future, most provenance signals a government channel collects will be attestations. As agent-prepared submissions become ordinary, the volume of unverifiable declarations grows with them: an agency comes to hold a mass of assertions it can neither check at intake nor safely ignore, and an attestation with no consequence when false stops telling anyone anything.
What must be verified
Government needs an assertion from a submitter to mean something without standing up full verification infrastructure for every submission. That confidence must be traceable to a real, if pseudonymous, identity, and strong enough that a false assertion costs the submitter something real once discovered, rather than resting on evidence inspected up front. The agency receiving the submission must bind the assertion to an identity and track false attestation after the fact.
Protecting access
Organizations, law firms, and lobby groups can produce verified credentials. Most individuals can't. Without a wallet or digital ID, or with a well-founded refusal to enroll in one, a submitter lands on the unverified side. The result is a de facto two-tier intake: the verified submission is weighted up, and the attested one reads as suspect. Legal-sounding certification text adds a further deterrent. A submitter reading in a second language, unsure what they would be liable for, walks away rather than sign.
Keeping the path open
- State plainly that unverified attestation is a valid and respected way to submit.
- Build no interface that visually privileges the verified tier.
- Write the declaration in plain language, framed as a norm rather than a penalty.
- Reserve sanction-grade consequence for the formal proceedings that warrant it.
Response surface
The declaration is made binding after the fact rather than verified up front, tying each submission to an identity and scaling the consequence to what the process decides.
How was this prepared?
Most people tell us how their submission was prepared.
The two ways to sign are drawn as peers: same size, same weight, no badge or check marking the verified path as better.
The verified-identity slot appears only in the formal proceeding, where it is wired but inactive: labeled for a verified government digital ID and marked unavailable. There the binding declaration must be checked before signing. The control above previews that version.
Maturity
- Established
For the individual components: attestation forms, identity verification, and risk-based assurance levels are each settled.
- Frontier Headline
As a coherent response that pulls them into a submission intake scaling assurance to the stakes, tying the assertion to consequence, and keeping access open: not yet attempted for government consultation contexts.
Precedents
Qualified Electronic Attestations under eIDAS 2.0, and Login.gov tiers. Under Regulation (EU) 2024/1183 a Qualified Electronic Attestation of Attributes is issued by an accredited trust service provider that has verified the attribute against authentic sources. Login.gov offers three service tiers spanning authentication, basic identity verification, and enhanced identity verification, under a live US federal deployment. Verification against authoritative sources is operating in both, under an accreditation regime in the EU and as a live federal service in the US.
Rule 11 sanctions in Mata v Avianca. A lawyer certifying that a brief was human-verified is making a self-declaration, and the court sanctioned attorneys who filed a false one. The attestation is verifiable after the fact, and a consequence attaches when it proves false.
NIST SP 800-63A identity proofing (rev. 4). The US guidelines scale proofing to the risk of the transaction: IAL1 validates core attributes against authoritative or credible sources, IAL2 collects further evidence and applies more rigorous processes to confirm the applicant is the rightful owner of it, and IAL3 adds a trained proofing agent in an attended, on-site session with at least one biometric. Every rung sits above self-assertion, and an intake that takes an unproofed declaration sits below IAL1 entirely, which is where most government submission processes sit today.
What carries over to agent use
High transferability for the framework; the implementation is the design problem.
The legal precedent's consequence relies on professional-body accountability: a lawyer sanctioned under Rule 11 has a bar membership at stake. An anonymous public commenter has no equivalent membership to lose, so the consequence-based confidence the legal model relies on doesn't fully travel to consultation intake. What does travel is the framework's proportionality: scaling how much an agency asks for to what the submission decides has precedent in risk-based verification and in eIDAS's own tiers. What stays undesigned is a workable, non-punitive form of after-the-fact consequence for someone with no professional standing to lose and, often, no fixed identity to track.
Where things go wrong
The attestation-verification gap concerns the assurance of user submissions, so it does not directly govern automated decisions. Its core principle still applies on the agency side: an assertion must be either independently verified or backed by real after-the-fact consequence, which is exactly what an unaccountable automated process that issues adverse determinations violates.
Sources
4 references
The instrument, the operating deployment, or the official record itself.