Certification marks and trust registries
A public registry and certification mark for civic tools, readable by a user as a badge and by an agent as machine-readable code. Every user, agent, and agency relying on a tool checks the same assessment instead of each vetting it alone.
The impact of agents
As more services run through an AI agent, and agencies come to rely on more third-party tools, the marks and claims those tools display multiply faster than anyone can verify them. An agent has nothing it can check programmatically at all. Physical goods have CE marks, electrical safety tags, and food-grade certifications; digital tools have no equivalent that is both widely recognized and independently assured.
What must be verified
A widely recognized, independently assured certification mark and public trust registry give a user, agency, or agent a rapid signal that a digital tool has been assessed against known standards. In the EU model the mark is machine-readable, so the agent can query it programmatically. The certifying body or registry operator must keep that assessment current and hold the record behind the mark.
Protecting access
Small builders may be priced out of expensive verification processes: a FedRAMP certification at the Moderate class runs to roughly US$500K–1.5M upfront, and EU conformity assessment needs a Notified Body. The users who rely on the long tail of volunteer-built tools inherit that cost, since the tools that serve them end up with no signal at all. A mark also only works if what it certifies is stated in plain words, or the user reading the registry learns nothing from it.
Keeping the path open
- Tier certification to risk, so a low-consequence tool can qualify without an enterprise-scale audit.
- Pair every machine-readable mark with a plain-language statement of what was checked.
- Give the registry entry's badge a text alternative a screen reader can announce, since a visual mark alone tells a user who can't see it nothing about the tool's status.
Response surface
A registry entry carries both a badge a person can read and a code an agent can query.
The badge is for the user reading a product page; the mark is for their agent, which checks the registry before relying on a tool. Both resolve to the same record, so neither can drift from the other.
Maturity
Emerging. The public registry and trust-badge response is in operation but narrow: a machine-readable mark an agent can query is legislated under CE marking yet not operationally implemented, FedRAMP-style certification is mature for cloud but only beginning to cover AI, and the DPGA registry is live but voluntary and limited in scope.
Precedents
EU AI Act Article 48, CE marking for high-risk systems. Providers of high-risk AI systems must undergo conformity assessment and affix a CE marking, the symbol long used for physical product safety, and for systems provided digitally the Act requires a digital CE marking accessible through the software interface or a machine-readable code. Where a Notified Body conducted the assessment, its identification number must follow the mark. Article 79 carries the withdrawal power: market surveillance authorities may require an operator to bring a system into compliance, withdraw it, or recall it.
EU AI Act Article 43, who performs the assessment. For the high-risk categories at points 2 to 8 of Annex III the Act routes a provider to conformity assessment based on internal control, with no notified body involved. A notified body enters at point 1, and there only where harmonised standards were not applied or were applied in part. The mark records the provider's own assessment, across most of the scope, under a procedure the reader of the mark never sees.
The FedRAMP Marketplace (US). The registry lists certified cloud service offerings alongside the agencies that certified them and the assessors the program recognizes. FedRAMP's own name for the model is do once, use many: a provider is certified once, and the resulting security package can be reused by any federal agency. GSA has since prioritized 20x authorizations for AI cloud services, beginning with conversational engines already on the government schedule, so a registry model matured on cloud is reaching AI one service category at a time.
The Digital Public Goods Alliance registry. The registry lists verified digital public goods assessed against a nine-indicator standard covering SDG relevance, approved open licenses, clear ownership, platform independence, documentation, non-PII data extraction, privacy and applicable laws, standards and best practices, and do-no-harm-by-design. Applicants submit evidence online and a technical team reviews against each indicator. Approved status lapses after a year unless the tool is reassessed.
IEEE CertifAIEd, applied by the City of Vienna. The programme assesses an AI system against ethics criteria covering transparency, accountability, algorithmic bias, and privacy, and issues a mark on the result. Vienna took the mark on a municipal service, so a city government rather than a vendor carried it.
What carries over to agent use
High for the registry pattern; moderate for the CE-marking analogue. The DPGA model (open standard, evidence-based review, public registry) is directly transferable to a national registry of verified civic technology. FedRAMP's do-once-use-many model solves a real coordination problem, but its cost structure has to be reworked for small builders.
The EU's digital CE marking is the precedent that matters most for agents: a machine-readable trust signal embedded in the product interface rather than a registry listing alone, which is the form an agent can query programmatically.
Where things go wrong
A trust registry surfaces whether a decision-support tool was ever assessed against a standard. It would not by itself stop a flawed tool, but recording the absence of any conformity assessment makes that gap visible to agencies relying on it.
Sources
16 references
The instrument, the operating deployment, or the official record itself.
- FedRAMP Marketplace
- FedRAMP 20x — certification classes A to D
- FedRAMP Consolidated Rules for 2026 — definitions
- FedRAMP — programme home
- FedRAMP — how agencies can reuse an authorization
- GSA/FedRAMP 20x AI prioritisation announcement
- Digital Public Goods Alliance Standard
- Digital Public Goods Alliance Registry
- IEEE CertifAIEd — AI ethics certification programme
- CEN-CENELEC — acceleration measures for AI Act standards
Writing about the subject rather than the framework itself, including vendor commentary.
- EU AI Act — Article 48, CE Marking for High-Risk AI Systems
- EU AI Act — Article 43, Conformity Assessment
- EU AI Act — Article 79, Procedure at National Level for AI Systems Presenting a Risk
- FPF / OneTrust — Conformity assessments under the EU AI Act (white paper)
- UNICEF — Digital Public Goods Accelerator guide (what is a DPG)
- IEEE Beyond Standards — CertifAIEd applied to the City of Vienna