Santara

The AI-Native Standard · v1.0

What “AI-native” has to mean, if it is going to mean anything

Every operations vendor now says “AI-powered”. The phrase survives a twenty-year-old system with a chat box bolted to the corner, which is why it no longer tells an operator anything. This is the bar underneath the phrase: nine criteria, each evidenced by an artefact rather than a claim, and a public register of who has met them.

21 August 2026 · 2-year term · re-attested every 12 months

The distinction

AI-powered describes a purchase. AI-native describes a design.

A product can buy a model and remain exactly what it was. The difference the standard measures is not how much AI is present, it is who the system was built for — the operator working it, or the machine running it.

AI-powered

Built for a human to operate. The AI is somewhere in it.

  • The AI is a destination — a panel, a button, an assistant you visit.
  • Nothing happens on a day nobody logs in.
  • Output is a summary of a screen the operator could already read.
  • Removing the model removes a feature, not the product.

AI-native

Built for the machine to operate. The human supervises it.

  • The system starts the work; the operator arrives to a decision already made.
  • It writes to the real world under limits the operator set in advance.
  • Every figure traces to a record, and every action can be overruled.
  • Removing the model breaks the promise the product is sold on.

The standard says nothing about which model a product uses, how large it is, or how it scores on a benchmark. Those change every quarter and none of them tell an operator whether their Tuesday runs itself.

The criteria

Three pillars, nine criteria

Each criterion is written so an assessor can mark it without interpretation, and each one publishes the way products usually fail it. A standard that cannot be failed is a logo.

I

Autonomy

Does the machine do the work, or does it wait to be asked?

Rules outA product where the AI is a place you go — a chat box, an “ask AI” button, a summary panel — and nothing happens on a day nobody visits it.

C1

Unprompted operation

The system does its work on its own schedule, not on the operator's prompt.

Inference runs on a recurring schedule or on an inbound event, per customer, without a human initiating it — and the operator receives the output on a day they never open the product.

Evidence required

  • The scheduler or event definition, with its cadence and its per-customer scope.
  • Run records for a representative customer over 14 consecutive days.
  • The delivery path that reaches the operator outside the product (email, push, message).

How it failsThe AI exists only behind a button. Runs correlate exactly with sessions, because a session is what causes one.

C2

Decision-first surface

The system's primary output is a decision, not a dashboard.

The default surface is generated rather than queried: it names what changed, what it costs and what to do, ranked. A dashboard that requires the operator to notice the problem themselves does not satisfy this, however much AI produced the numbers in it.

Evidence required

  • The default surface as shipped, for a real customer, on an ordinary day.
  • The ranking rule — why item one is above item two.
  • Proof that each item carries an action, not only an observation.

How it failsCharts with an AI-written caption. The work of deciding what matters is still the operator's; the model only narrated the data.

C3

Write authority

The system changes the world, not only the screen.

At least one class of outbound write is executed by the system against a real external or operational system of record — price, availability, assignment, task, message — under limits the customer set in advance.

Evidence required

  • The inventory of writes the system can perform, each with its limit and its owner.
  • A worked example from a production customer, showing the value before and after.
  • The reversal path for each class of write.

How it failsEverything is a recommendation. The product is advice with a copy button, and the actual operations still happen somewhere else.

II

Accountability

Can the person who is responsible for the outcome trust it and overrule it?

Rules outOutput that cannot be traced to a record, cannot be explained at the point of decision, or acts without limits an operator agreed to in advance.

C4

Traceable grounding

Every figure the system states traces to a record it can name.

AI output is grounded in the customer's live operational state, and each item carries a reference to the rows it was derived from. A number that exists only in the generated text fails, whether or not it happens to be right.

Evidence required

  • The stored link from each generated item to its source records.
  • The grounding set — what the model is given, and what it is not.
  • A spot check: pick three items at random, follow each to its rows.

How it failsA generated paragraph containing figures with no lineage. Nobody can tell a stale number from a wrong one, so eventually nobody checks either.

C5

Legible reasoning and override

It says why, where the decision is made, and it can be overruled there.

Each output carries its reasoning in the operator's language at the point of decision — not in a log, not on request — and the operator can disagree in one step. An override is honoured: the system does not re-impose the decision on the next run.

Evidence required

  • The reasoning as the operator sees it, on the surface where they act.
  • The override control, and the record it writes.
  • Proof that a later run respects the override rather than reverting it.

How it fails“Confidence: high.” A score is not a reason, and a system that silently reverts a human's correction is not being overruled, it is being argued with.

C6

Bounded and audited action

Every autonomous action has a published limit, an audit record and a named owner.

Limits are enforced in the system, not in policy prose; each run is recorded with its inputs, its outputs and what it changed; the limits are published where a customer can read them before they turn the system on.

Evidence required

  • The enforced bounds — floors, ceilings, rate limits, approval thresholds.
  • The run log, including runs that were withheld and why.
  • The public statement of what the system may do unattended.

How it failsLimits described in a trust-centre page and enforced nowhere, or enforced in code that no customer is shown. Both are unverifiable, which for this purpose is the same as absent.

III

Resilience

Is it native, or is it dependent?

Rules outTwo opposite failures at once: a product that stops working when the model is down, and a product that would work exactly the same if the model were removed.

C7

Deterministic fallback

With the model switched off, the system still produces a correct, safe result.

Every path that uses a model has a non-model path that degrades the output without breaking the operation. Demonstrated live, with inference disabled: the day's work still arrives, smaller.

Evidence required

  • The fallback for each model-dependent surface.
  • A run with inference disabled, end to end.
  • The behaviour on model timeout, refusal and malformed output.

How it failsA provider incident becomes a customer incident. AI-native is not AI-dependent; a system that cannot run a Tuesday without a model has outsourced its floor, not its ceiling.

C8

Closed feedback loop

What the operator does with the output changes the output.

Acceptance, dismissal, correction and completion are captured as signal and demonstrably alter later runs — through suppression, ranking, thresholds or retraining. Capturing the signal without using it does not satisfy this.

Evidence required

  • Where operator response is stored.
  • The mechanism by which it changes a later run.
  • A measured before-and-after on a real cohort.

How it failsA thumbs-down that goes into a table nobody reads. The system repeats a rejected suggestion weekly and calls it consistency.

C9

Critical-path dependence

Remove the AI and the product stops being the product.

The AI sits on the path the customer pays for, not beside it. Removing it must break the core promise — not merely remove a feature — and the company must be able to name what it would have to rebuild.

Evidence required

  • The primary customer promise, and where inference sits on it.
  • What breaks, specifically, if inference is removed permanently.
  • Pricing and packaging: whether the AI is sold as an add-on.

How it failsThe AI is a tier. It can be switched off for most of the customer base without anyone noticing, which is the clearest evidence that it was never the product.

Certification

How a certificate is granted

01

Submit evidence

Artefacts, not a questionnaire: schedulers, run logs, schema, the surface as it ships, and a production example for each write the system performs unattended.

02

Assessment

Each of the nine is graded Met, Met in part, or Not met against the submitted artefacts. A grade that cannot be traced to an artefact is not issued.

03

Publication

The full assessment is published — every grade, every finding, and every open condition with the date it is due. Certificates with hidden conditions are not issued.

04

Term and review

A two-year term with annual re-attestation. A missed condition moves the certificate to provisional; a false statement in evidence revokes it, publicly.

Certified

  • All nine criteria assessed against submitted evidence.
  • At least seven graded Met.
  • No criterion in Pillar II (Accountability) graded Not met.
  • Every Met-in-part carries a published remediation with a date.

Certified — provisional

  • At least six graded Met.
  • No more than one graded Not met, and not in Pillar II.
  • Full remediation published, and re-assessed within 180 days.

Not certified

  • Anything below the provisional bar, or evidence that cannot be verified.

The register

Certified AI-Native Operations Management Software

Every certificate issued under this version, with its grades in full.

Met in part is a real outcome, not a soft pass. It may only be carried with a remediation and a date, and both are printed on the certificate.

FAQ

Questions about the standard

Is this an industry body?

Not yet, and it does not claim to be. Version 1.0 is one company's published bar, held to in public. Independent assessment — a second assessor and a review board Santara does not sit on alone — opens with v1.1. Read it as a standard that can be argued with, because the evidence behind every grade is published.

What is the difference between AI-powered and AI-native?

AI-powered describes a purchase; AI-native describes a design. A product can buy a model and remain exactly what it was. Under this standard, a product is AI-native when the machine runs the work on its own schedule, acts on the world within limits the operator set, explains and accepts correction at the point of decision, and would stop being the product if the model were removed.

Can a product fail?

Yes, and the ways it fails are published alongside each criterion. A product whose AI only runs when someone clicks fails Autonomy. A product that states figures with no traceable source fails Accountability. A product whose AI can be switched off for most customers without anyone noticing fails Resilience. Grades are Met, Met in part, or Not met, and a Met in part may only be carried with a dated, published remediation.

How long does a certificate last?

Two years, with re-attestation every twelve months, because products move faster than terms. A missed condition moves the certificate to provisional at the next re-attestation. A false statement in submitted evidence revokes it, publicly.

How does a company apply?

Through the contact form, marked for assessment. Applicants submit artefacts rather than a questionnaire: the scheduler or event definition, run records over a fortnight, the default surface as it ships, the inventory of writes the system performs unattended with their enforced limits, and a demonstration of the product running with inference disabled.

Disclosure

Santara wrote this standard and holds the first certificate.

That is a conflict of interest and it does not go away by being unmentioned. What can be done about it is to make the assessment arguable: Santara’s certificate publishes the artefact behind every grade, including the two criteria it did not fully meet and the dates it has committed to closing them. If a grade is wrong, the evidence is there to say so with.

Independent assessment — a second assessor, and a review board that Santara does not sit alone on — opens with the next version. Until then the standard should be read as one company’s published bar, held to in public, rather than as an industry body’s.