Skip to main content
K4M2 AI

Accountability and reporting

Commitments should be open to examination.

K4M2 AI makes commitments about governance, responsible AI, the use of profit, employee participation, public-interest technology, and the work it will refuse. Publishing those commitments is not enough.

People should be able to examine whether the company's structures and decisions are consistent with what it claims.

Accountability does not require publishing every internal discussion, commercial detail, personal record, or security-sensitive fact. It requires providing enough reliable information for employees, customers, K4M2A Foundation, collaborators, and the wider public to understand who holds authority, how important decisions are made, whether protected commitments remain in force, how the company responds when it falls short, whether its stated principles affect commercial behaviour, and how the value it creates supports the larger mission.

Accountability is more than transparency

Transparency provides information. Accountability connects information to responsibility, explanation, review, and correction.

A company may publish large quantities of data while making it impossible to determine who approved a harmful decision, whether a commitment was breached, why an exception was granted, what happened after a failure, whether anyone had authority to intervene, or whether the same failure is likely to recur.

We should report not only what happened, but where appropriate why it happened, who was responsible, which policy applied, whether it was followed, what consequences followed, and what will change.

Four forms of reporting

Not every matter requires the same level of disclosure.

01

Public reporting

Matters necessary to evaluate the company's institutional commitments: governance structure, foundation control and protected rights, the profit-sharing mechanism, contributions made to K4M2A Foundation, responsible AI practices, categories of work accepted or refused, public-interest and open-source contributions, significant conflicts of interest, material failures and corrective actions, and important changes to published policies.

02

To affected people

Some information may not suit general publication but should reach the people directly affected: employees affected by compensation or participation decisions, clients affected by system limitations or incidents, users affected by significant AI outputs, contributors whose work is being licensed or commercialized, people involved in a grievance or review, and institutions dependent on a product being changed or discontinued.

03

To governing bodies

The governing board and K4M2A Foundation may require more detail than can be made public: financial records, risk assessments, legal advice, security incidents, client concentration, product failures, related-party transactions, protected decisions, internal investigations, and proposed changes to mission safeguards.

04

Independent review

Some matters should be examined by people who were not responsible for the original decision: serious safety incidents, disputes involving senior leadership, changes to protected governance, related-party transactions, significant conflicts between profit and mission, high-consequence AI systems, alleged retaliation against someone raising a concern, and transfers of strategically important technology.

Our annual accountability report

Nine sections, understandable without specialist knowledge.

We intend to publish an annual accountability report once the company has sufficient activity for it to be meaningful.

The legal relationship between K4M2 AI and K4M2A Foundation, the composition of the governing board, how board members are appointed and removed, the Foundation's special voting rights, the categories of protected decisions, material changes to ownership or control, significant governance decisions made during the year, changes to constitutional or mission protections, and the reasons for any departure from published governance commitments.

The report should distinguish between mechanisms that are legally binding and mechanisms that remain intended or under development.

02

Profit and financial contribution

Read how profit serves the mission →

The formula used to calculate distributable profit, the applicable share assigned to K4M2A Foundation, the amount transferred during the year, additional financial contributions, significant non-financial contributions, transfers that were delayed, reduced, or suspended, the reason for any exception, material changes to the profit-sharing mechanism, and the approval process followed for those changes.

The report need not disclose every commercially sensitive detail. It should provide enough information to determine whether the defined commitment was followed. K4M2A Foundation should separately report how it used the resources it received.

03

Products and systems

Major products launched, significant systems deployed, categories of customers served, the problems those systems were intended to address, how systems were evaluated, important limitations identified, systems substantially redesigned after evaluation, products restricted, suspended, or withdrawn, and lessons from real deployment.

Client identities and confidential project details may remain private unless disclosure is agreed or legally required. The company should avoid publishing only successful demonstrations while omitting failed or discontinued work.

The number and categories of significant systems reviewed, common safeguards required, systems approved with restrictions, systems redesigned after review, categories of work refused, material AI incidents, significant failures or unintended effects, actions taken in response, changes made to the Responsible AI Standard, and exceptions approved with their justification.

The objective is not a misleading numerical score of ethical performance. It is to show whether the standard changes what the company builds and how it deploys it.

05

Work accepted, changed, and refused

Read how we choose and refuse work →

Broad categories of work accepted, common reasons proposed projects were narrowed or redesigned, non-AI solutions recommended, common reasons projects were refused, engagements paused or ended because safeguards were not maintained, and lessons from decisions later found to be too permissive or too cautious.

Refusal reporting should not become a form of moral advertising. The purpose is to make commercial boundaries visible and open to evaluation.

06

Broad ownership categories, employee and contributor participation programs, equity reserved for future participants, profit-participation mechanisms, material changes to compensation or participation policies, representation of employees or contributors in decision processes, significant conflicts of interest, and whether stated participation mechanisms were used in practice.

Individual salaries, household information, personal ownership details, and legally protected records may remain private. The company should still report enough to show whether participation is meaningful or merely symbolic.

Open-source projects released, open standards supported, research published, technologies licensed under public-interest terms, products made available to educational or nonprofit institutions, technology transferred to K4M2A Foundation, strategically important assets designated, public-interest infrastructure maintained, important restrictions placed on open release for safety reasons, and projects discontinued along with the continuity measures taken.

We should report not only what was released, but whether it remains maintained and practically usable.

08

People and organisational health

At an aggregate level: team size, employment and contractor categories, staff turnover, workload concerns, significant changes to working practices, learning and development, material grievances, retaliation complaints, broad findings from contribution and fairness reviews, and actions taken to improve organisational health.

Reporting should protect personal privacy and should not reduce people to productivity statistics. The purpose is to examine whether commercial success depends on hidden exhaustion, instability, or unfairness.

09

Mission alignment

How the year's work strengthened the larger mission, commercial activities that created useful capability, projects directly aligned with K4M2A Foundation, knowledge or technology contributed to public-interest work, situations where mission and profit came into conflict and how those conflicts were resolved, areas where the company's activities did not substantially relate to the mission, risks of mission drift, and priorities for the following year.

Ordinary commercial work should not be described as direct mission work merely because some profit supports the Foundation. The distinction should remain visible.

Reporting failures, not only achievements

Accountability reporting should include meaningful failures: a product that did not solve the intended problem, a system whose reliability was overstated, a project accepted without sufficient review, a client use that expanded beyond the agreed purpose, a safeguard that became symbolic, a preventable security or privacy incident, a conflict of interest handled poorly, a profit transfer not completed as expected, a participation rule applied inconsistently, a public-interest project released without adequate maintenance, a person punished for raising a concern, or a decision where commercial pressure weakened judgement.

Not every mistake requires public disclosure. Material failures relevant to public commitments should not be concealed simply because disclosure is uncomfortable.

What makes a failure material

A failure may be material when it causes or could reasonably cause significant harm, affects a substantial number of people, concerns a high-consequence system, reveals a weakness in governance or mission protection, contradicts a published commitment, involves senior leadership, creates a serious legal, financial, privacy, or security risk, requires a product to be restricted or withdrawn, alters the relationship with K4M2A Foundation, or is likely to recur without institutional correction.

Materiality should not be determined only by financial cost or media attention. A failure may be institutionally important even when it remains commercially small.

How an incident should be reported

Where public reporting is appropriate, we should explain what happened, when, who or what was affected, how the issue was discovered, the immediate response, known and unknown consequences, whether affected people were informed, the policy or safeguard that failed, the corrective action taken, and what will be monitored afterward.

The company should not claim certainty before the facts are known. Initial reports may need updating as investigations develop.

Correcting public information

When a material error is identified, we should correct the information visibly, preserve a record of the earlier version, explain what changed, state why the original was inaccurate, identify whether decisions were affected, and take further corrective action where necessary.

Quietly replacing a public report without acknowledging the change weakens trust.

How to raise a concern

To raise a complaint, privacy concern, security issue, protected disclosure or urgent safety concern, email founders@k4m2.ai and identify the category in the subject line. We will publish dedicated reporting channels as the organisation's operating systems are established.

Subject: Complaint

Conduct, working conditions, or how we handled something.

Subject: Privacy

Access, correction, or deletion of your personal data.

Subject: Security

Vulnerabilities in anything we run or publish. Please do not disclose publicly first.

Subject: Disclosure

Protected disclosures about the company's own conduct. Raised in good faith, without penalty.

Subject: Urgent

A live safety or risk concern in a system we built or operate.

Exceptions to published policies

Policies cannot anticipate every future circumstance, and exceptions may sometimes be necessary. A significant exception should record the policy being departed from, the reason, who approved it, which interests were affected, whether conflicts of interest existed, how long the exception applies, what safeguards were added, and whether the decision will be reviewed.

A policy that is frequently overridden without explanation is not functioning as a policy.

Protected disclosures

Employees, contractors, contributors, clients, users, and affected people should have a way to raise serious concerns, whether about safety, privacy, security, misleading claims, financial irregularity, conflicts of interest, discrimination or retaliation, misuse of AI systems, breach of governance commitments, misuse of foundation resources, concealment of significant failures, or work that conflicts with our stated boundaries.

Reports should be accepted through more than one channel where practical. At least one route should allow a concern to bypass the person or team directly involved.

Protection against retaliation

A person should not be punished for raising a concern in good faith. Retaliation may include termination, loss of work, reduction of responsibility, exclusion from information, damage to compensation or participation, threats, harassment, unfair performance assessment, informal reputational punishment, or pressure to withdraw a report.

A concern may ultimately prove incorrect without having been raised dishonestly. Protection should depend on good faith, not on whether every allegation is confirmed.

Knowingly false or malicious reports may be addressed separately through a fair process.

Investigation

Significant concerns should be examined by people with sufficient independence, competence, and authority. An investigation may require preservation of relevant records, interviews, technical analysis, financial review, legal advice, security expertise, independent domain expertise, protection of affected people, temporary restrictions on a system or decision, and recusal of conflicted leaders.

The person whose conduct is being examined should not control the investigation.

Raising concerns publicly

Internal reporting should be available and credible. It should not be used to prevent lawful disclosure to regulators, courts, professional bodies, or other appropriate authorities. Confidentiality obligations should not be used to conceal illegality, serious harm, or a material breach of public responsibility. The exact rights and protections will depend on applicable law and contractual obligations.

User and client complaints

People affected by our products or systems should have a practical way to report incorrect outputs, harmful outcomes, privacy concerns, security vulnerabilities, misleading disclosures, inability to obtain human review, use outside the stated purpose, difficulty leaving or exporting data, and manipulative or dependency-forming behaviour.

A complaint process should explain where to report, what information is useful, when a response can be expected, how urgent risks are handled, whether the decision can be reviewed, and what further escalation is available.

A feedback form that no accountable person reviews is not an accountability mechanism.

Security vulnerability reporting

We should maintain a clear process for security researchers and users to report vulnerabilities, stating the systems covered, how to report securely, what testing is permitted, what information should not be accessed or retained, how the company will respond, whether recognition or rewards are available, and how disclosure will be coordinated.

People reporting vulnerabilities responsibly should not be threatened merely for identifying a weakness.

Independent accountability

Internal review may be insufficient where the company's own interests are directly involved. Independent review may be requested or required by the governing board, K4M2A Foundation, a protected committee, external auditors, legal or regulatory authorities, independent technical experts, public-interest advisors, or representatives of affected people.

Independent review should not be used only after public controversy. It may be appropriate before deploying systems with substantial consequences.

The role of K4M2A Foundation

The Foundation has a particular role in reviewing whether K4M2 AI remains aligned with its protected purpose. It may review changes to mission or governance, compliance with protected profit commitments, strategic asset decisions, serious conflicts between profit and purpose, material departures from the Responsible AI Standard, related-party transactions, misuse of foundation resources, and significant risks of mission drift.

The Foundation should not be the only source of accountability. It must also report on its own conduct, conflicts, independence, and use of resources.

Read about K4M2 AI and K4M2A Foundation →

Confidentiality and legitimate limits

Some information should not be published. Legitimate reasons may include personal privacy, employee records, client confidentiality, security, active legal proceedings, protected legal advice, unreleased product plans, trade secrets, contractual obligations, sensitive research, and information whose release could create serious misuse risk.

Confidentiality should protect legitimate interests. It should not become a general explanation for withholding information that is embarrassing, inconvenient, or relevant to a public commitment.

Where full disclosure is not possible, we should consider whether we can publish aggregated information, a summary, redacted findings, the category of issue, the decision process, the corrective action, or an independent reviewer's conclusion.

Protecting personal privacy

Accountability should not require exposing individual people. Reports should avoid unnecessary disclosure of personal financial information, household circumstances, health information, private communications, the identity of complainants, sensitive employment details, and personal data of users or clients.

Information should be aggregated or anonymized where possible. Anonymization should not be claimed where people can easily be identified from context.

Accuracy before presentation

Accountability reports should not be written as marketing material. They should avoid selecting only favorable measurements, changing definitions between reporting periods without explanation, presenting intention as completed practice, combining unrelated metrics to create a positive impression, hiding negative outcomes in broad averages, counting ordinary commercial activity as public benefit without justification, describing a policy as binding when it is voluntary, and using vague language where a specific fact is available.

The report should distinguish clearly between what is legally required, what is contractually committed, what is established policy, what is currently practiced, what remains an intention, and what is still being designed.

Comparable reporting over time

Where possible, reports should use consistent definitions so that performance can be compared from one year to another. When a metric or definition changes, we should explain what changed, why, whether previous figures have been restated, how the change affects comparison, and whether the new method creates a more favorable result.

The objective is not to preserve an unsuitable measure forever. It is to prevent changing the measure whenever the result becomes uncomfortable.

Targets and external assurance

We may publish future targets concerning profit contributions, open-source releases, evaluation coverage, incident response, employee participation, public-interest access, governance development, and environmental or operational impact. A target should identify the measurement, the starting point, the intended result, the period, the person or body responsible, and any important conditions. A broad aspiration should not be presented as a measurable commitment. Where a target is missed, we should explain why and what follows.

As the company grows, some reporting may require independent verification, which may be appropriate for financial statements, profit transfers, related-party transactions, security controls, privacy practices, responsible AI evaluations, governance compliance, public-benefit claims, and ownership and participation records.

Obtaining a certificate should not replace responsibility for the underlying practice.

Reporting should remain proportionate

A young company should not create a reporting system so burdensome that it prevents useful work. At the same time, early stage should not become an excuse for making strong public promises without evidence. Reporting should grow with revenue, team size, number of users, the consequence of deployed systems, the amount transferred to the Foundation, external investment, public dependence on our technology, and the complexity of governance.

During the early stage, we should aim to publish at least our current governance structure, the legally established relationship with K4M2A Foundation, which mission protections are binding, the finalized profit-sharing mechanism, material changes to those arrangements, the categories of work we will not undertake, major open-source and public-interest contributions, material incidents affecting public commitments, and an annual account of progress, limitations, and next steps.

An archive of policies and reports

We should preserve previous versions of important public documents, including governance descriptions, Responsible AI Standards, profit-sharing policies, ownership and participation policies, annual accountability reports, incident reports, public-goods policies, and material corrections. Each document should show its publication date, effective date, version, major changes, and whether it is binding or descriptive. An archive allows people to see how commitments have changed over time.

Accountability must affect consequences

Reporting has little value if repeated failures produce no institutional consequence. Depending on the matter, consequences may include correcting a system, compensating affected people, changing a process, restricting or withdrawing a product, ending a client engagement, revising incentives, removing decision authority, disciplinary action, leadership change, independent monitoring, amendment of governance mechanisms, and public acknowledgment of failure.

Accountability is incomplete when an institution explains a failure but continues unchanged.

We will not always agree on what accountability requires

Employees, clients, users, the Foundation, and the public may reasonably disagree about what should be disclosed, whether a risk was acceptable, whether a failure was material, whether a safeguard was sufficient, whether the company acted too slowly, whether commercial confidentiality is justified, or whether a technology should remain proprietary. We should not interpret disagreement as proof of bad faith. Where possible, we should explain the reasoning, acknowledge uncertainty, and make the relevant decision authority visible.

The purpose of accountability is not to create the appearance of perfection.

K4M2 AI will make mistakes. Some systems will fail. Some judgements will prove incomplete. Some policies will produce consequences that were not anticipated. The relevant question is whether the company makes those failures visible enough to learn from them, assigns responsibility clearly enough to act, and protects the people who identify what has gone wrong. We want to build an institution that can correct itself without waiting for failure to become impossible to hide. The company should be judged not only by the commitments it publishes, but by what it reveals, explains, and changes when those commitments are tested.

Governance