WorkHireWork with meIndependence policyIncome ledger

Independence policy

Who pays for the work, what could bend it, and how to get it corrected.

Zain Dana Harper, sole proprietorVersion 1, dated zaindharper@gmail.com

I am a Washington sole proprietor offering AI evaluation, investigation and consulting work. This policy covers paid engagements, grant-funded work and unpaid published investigations alike. A reader of any finding from this practice should be able to see who paid for it, which interests could bend it, which AI models helped produce it, and how to get it corrected. The policy draws on the AI Evaluator Forum's letter and its published minimum operating conditions (the Forum's page says AEF-1 covers contingent compensation, organizational control, disclosure, recusal and separate agreements) and applies them to a one-person practice. I have not yet read the AEF-1 text clause by clause, so this policy does not claim to meet it.

Interests disclosed now

These interests bear on any work involving AI developers. They appear here and in every engagement letter.

  1. I build with Anthropic and OpenAI models. My tools and most of my writing and research are produced with Anthropic's Claude and OpenAI's Codex and related models, through paid subscriptions and API use. I have no discount, credit grant, early access or other arrangement with either company beyond their standard terms. I have applied to a credit program at Anthropic and a grant program at OpenAI. Both appear in the list of applications below, and neither has been granted.
  2. I publish investigations that involve those same companies. Who Knew First and Who Pays the Referees name Anthropic and OpenAI among their subjects. Each page discloses that the record was compiled with these models.
  3. Training. In September and October 2026 I completed courses from Anthropic (Claude Academy), Google and Google DeepMind, Microsoft and others, listed on my CV. These are course records. They create no relationship with those companies.
  4. No lab relationship. I have no pilot, retainer, contract, grant or engagement with any AI developer or evaluator organization.
  5. Operating name. I work under my own name, Zain Dana Harper, as a sole proprietor. Engagements are contracted with me directly.

Applications I have submitted

This table lists every open application for funding, a fellowship or a role connected to this work. None has been accepted. If one is, its income goes in the income ledger, and the funding rules below apply before I take any related work.

SubmittedBody and programRequestStatus
2026-06-29OpenAI, Cybersecurity Grant ProgramUSD 50,000 to 75,000 plus API creditsSubmitted, no decision received
2026-06-29Longview Philanthropy, AI Power Concentration RFPUSD 75,000Submitted, round closed, no decision received
2026-06-29Mercatus Center, Emergent VenturesUSD 25,000 to 50,000Submitted, no decision received
2026-08-23Anthropic, External Researcher Access ProgramUSD 1,000 in API creditsSubmitted, no decision received
2026-09-16ARIA, Scaling Trust, Tracks 2 and 3GBP 267,475Pending, notification due 30 November 2026
2026-09-16EA Funds, Transformative AI FundUSD 120,000Pending
2026-09-26BlueDot Impact, Rapid GrantUSD 17,700Pending
2026-09-27BlueDot Impact, Incubator Week, NovemberA program placePending
2026-09-29 or 30UK AI Security Institute, Core Technology roleEmploymentPending
2026-09-29 or 30Upfront, Founder FellowsA fellowship placePending
2026-09-29 or 30Stanford MARVL, MMBU ChallengeTeam registrationPending host approval

OpenAI and Anthropic are subjects of my published investigations. The MMBU Challenge lists Anthropic among its sponsors and gives accepted teams model credits, which would go in the ledger. I add each new application to this table when I submit it.

One standard for every lab and client

  • The same evaluation criteria, evidence rules, notice clock and right of reply apply to every AI developer, whatever its size, nationality, ownership or relationship to me. My own tools are held to the same standard: I publish security advisories against my own releases and keep failed results (security page; Articulate PR #9).
  • I check this commitment against my own published work. On 1 October 2026 a re-check of Who Knew First, run with the same model family that helped compile it, found selections that leaned toward Anthropic, and the page now carries five dated corrections. A same-maker check can miss what the first pass missed.
  • Counts in my investigations reflect what public records show. They are floors and do not rank one lab's conduct against another's.
  • Missing access stays recorded as unknown. I do not fill a gap in one lab's record with an assumption I would not make about another.
  • Methods are bounded the same way for everyone: public records and authorized access only. No hidden chain-of-thought extraction through jailbreaks or prompt injection, no decryption of withheld reasoning, no bypassing of access controls. Offensive testing runs only on owned or licensed systems under written authorization.

Funding

  • Current income. As of 2026-10-01 this practice has received no income: no paid client, no grant and no API credits. I have no current sponsors.
  • Public income ledger. All income from this work goes in the income ledger with its exact source, type and amount. API credits and other in-kind support count as income. I add each entry when the income arrives, and I do not accept a contract that forbids naming its source there.
  • Concentration. When one source, or a group of sources under common control, reaches 15 percent of my income from this work over the trailing 12 months, I disclose that on this page and in the ledger. Every finding about that party then gets a second review before it is published. At 50 percent, I decline new work that evaluates that party.
  • The first contract. A first contract or grant crosses both thresholds by itself. I will take it and disclose it here and in the ledger, with a plain statement that as the first contract its priorities are transparency, neutrality and independence. The 15 percent disclosure and second review apply to it. The 50 percent decline does not.
  • Payment never depends on a finding. No fee, bonus, renewal or success payment is tied to what a finding says.
  • Grants from AI developers. I accept a grant, credits or a contract from an AI developer only if it carries no review or veto over conclusions, and I disclose it on every publication about that developer for three years after the funding ends.

Model use

  • Every published investigation, report and essay states which AI models helped produce it and for which tasks, for example source gathering, drafting, code or review.
  • Every engagement letter lists which model providers may process client materials. A client may require locally run models only.
  • A model's agreement with a finding is not independent confirmation. Where a finding rests on model output, the report says so and shows the evidence a reader can check without the model.

Declaring conflicts

  • Before scoping any engagement, I disclose in writing every interest listed above, every current engagement with a competitor of the client, and any open or planned investigation that names the client. The client acknowledges these in the engagement letter.
  • During an engagement, I disclose a new relevant interest in writing within five business days.
  • On publication, every finding carries the disclosures that applied while the work was done.

When I decline work

I decline an engagement, or end one, when any of these holds:

  1. Payment or renewal would depend on the content of a finding.
  2. The client asks for editorial control over conclusions, or the right to suppress a finding that meets the agreed method.
  3. The client is an AI developer named in an investigation I have open, until that investigation is published. I do not take paid work from a party while I am investigating it.
  4. Accepting would breach the concentration rule above without a disclosure the client accepts in writing.
  5. The work would require any method excluded above, or testing a system without written authorization from its owner or licensee.
  6. The work is certification or attestation I am not accredited to give, or legal advice.
  7. I helped build, sell or deploy the system being assessed, and the engagement calls for an independent assessment. This mirrors the independence test in NYC Local Law 144.
  8. I cannot do the work to the standard in this policy in the time or with the access offered.

When I decline for a conflict, I tell the client which rule applied.

How findings are published

  • Each engagement letter sets one publication option: a private report, publication after a fixed client review period, or an open report. I prefer the last two.
  • Under every option, the client may correct facts, mark confidential material and submit a response that I publish alongside the report. The client may not change conclusions. I publish a list of every redaction by category and reason.
  • For investigations from public records, I notify the developer and any affected party before publication and give a right of reply. The time from notice to publication follows the tiers under Escalation and notice.
  • Every report states its method, its sources, what it does not show, and the models used.

Escalation and notice

Escalation works in layers. The core acts at once and needs no decision. The outer layers follow published rules.

  • The core is structural and automatic. A harmful action is halted immediately, and no person decides whether to pull the stop. In my own tools, explicit grants and hooks refuse any action nobody authorized (Accountable Surface), and a pre-action monitor holds a flagged action before it runs. Hardware locks belong to the same layer. The pre-action monitor is still in development and unpublished, and the hardware lock is a proposal. Neither is deployed yet.
  • The outer layers are policy. Disclosure follows the same published criteria for every developer:
    • Immediate notice where people face imminent harm, or where the law requires it.
    • 7 days from notice to publication where harm is active.
    • 90 days, coordinated with the affected parties, for everything else.
  • Counsel reviews each case against whistleblower law before its timeline runs.

How findings are corrected

  • Each publication keeps a dated correction note on the page itself. I do not edit findings silently.
  • Anyone may report an error by email to zaindharper@gmail.com. I acknowledge within five business days and publish a correction or a reasoned refusal within thirty days.
  • A correction that changes a finding about a party is also sent to that party.
  • Example: Who Knew First carries five corrections dated 1 October 2026 in its Corrections section.
  • This policy is versioned. Changes are dated at the foot of the page, with the reason.