Everyone requires a human
in the loop.
No one can prove it.
Doctrine and law — DoD Directive 3000.09, EU AI Act Article 14, NIST AI RMF — all mandate meaningful human control over autonomous action. None of them provides an artifact that proves it. Today that proof is a log the operator controls: forgeable, backfillable, rubber-stampable. EMILIA Protocol produces an offline-verifiable receipt that a named human authorized the exact action — checkable by a third party without trusting the operator. EP turns human oversight from a policy promise into a cryptographic artifact — no irreversible autonomous action without a verifiable human receipt.
The hard problem isn't the policy. It's the proof.
When an autonomous system acts, the record that a named, accountable human authorized that exact engagement — at the right scope, currently, under the right authority — is an operator-owned log. After an incident, no inspector general, court, coalition partner, or treaty-verification regime can confirm it without trusting the very operator under review. EMILIA closes exactly that gap.
Not every cycle. The moments that matter.
Per-cycle human approval is incompatible with machine tempo. EMILIA issues receipts at the points where a human grants, scopes, or renews autonomous authority.
A human authorizes each consequential action before it executes. No valid receipt bound to the exact action — the system fails closed. For the highest-consequence decisions where machine tempo allows a human gate.
A human authorizes a bounded engagement envelope — effect class, target set, geofence, time window — and retains a halt authority. Autonomy operates only inside the envelope, only while unrevoked and unexpired.
Shipped mechanisms, mapped to the requirement.
Four instruments mandate it. None can prove it.
"Appropriate levels of human judgment over the use of force" — plus auditable, traceable, governable AI.
A receipt proves a named human — or two-person quorum — authorized the exact engagement, within a defined envelope, verifiable offline by an inspector general or coalition partner without trusting the operator. (The primary U.S. defense hook.)
Civilian high-risk AI must be "effectively overseen by natural persons" who can decide not to use it and intervene.
The receipt proves a natural person authorized the action; fail-closed enforcement is the "decide not to use it"; revocation is the stop button. (Civilian tailwind — the Act excludes exclusively military/defense systems; there, DoD 3000.09 governs.)
Documented, auditable human oversight across GOVERN / MAP / MEASURE / MANAGE.
Receipts are the auditable record of who authorized what, under which policy — verifiable, not asserted.
The entire debate turns on demonstrating "meaningful human control."
EMILIA turns meaningful human control from doctrine into a cryptographic artifact a third party can check.
It proves authorization. Not wisdom.
Serious programs will ask exactly where the line is. So we draw it.
A specific, pinned human — or quorum of distinct humans — authorized this exact action or bounded envelope, at a stated scope, within a validity window, under a referenced authority. Given signature soundness and uncompromised signing keys, the record cannot be forged, replayed, re-targeted, or repudiated, and anyone can verify it offline.
That the human understood the action (a display / WYSIWYS concern), that they were uncoerced, or that the action was lawful or wise. EMILIA is the evidence of authorization — a necessary, not sufficient, condition for meaningful human control. Over-claiming is how accountability tech loses trust.
Make meaningful human control checkable.
A lighthouse pilot: deploy EMILIA in observe-mode on one human-control boundary, produce the verifiable evidence trail, and demonstrate the compliance artifact in a tabletop review. No production change. Offline and air-gap ready. Apache-2.0.