Methodology & AI Act Transparency
Allviss produces AI-drafted intelligence-style analysis (a BLUF, competing hypotheses, indicators, NATO-standard probability language) from open-source material, written for a human reader. This page states plainly what that means for how the output should be used, and what accountability measures are in place — in the spirit of the EU AI Act's transparency obligation (Article 50).
The intelligence cycle
Underneath the analytic steps sits the doctrinal intelligence cycle: the Norwegian Armed Forces' unclassified Etterretningsdoktrine 2021 describes an intelligence process whose four phases allviss runs as an ordered pipeline for every analysis.
- Direction (Styring). Classify the question, break it into the specific pieces of information still needed, and plan what to collect before going looking for it.
- Collection (Innhenting). Search across open sources — Brave and Mojeek web search, news and RSS feeds, and our standing knowledge base — in parallel.
- Analysis (Analyse). The four analytic steps below: turn collected material into a scoped problem, a knowledge base, competing hypotheses, and testable indicators.
- Dissemination (Formidling). Render the same analysis to email, the web report, and PDF, adapted to the reader.
How allviss reasons
Allviss follows the four-step structured-analysis method taught at the Norwegian Intelligence School (Etterretningsskolen). The published account of that framework is Skjelderup, Haugestad, Pedersen & Stivang, Etterretningsanalyse: Kritisk tenkning og strukturerte analyseteknikker (Fagbokforlaget, 2025). A method is a shared professional practice, not something one book owns — what follows is our own account of how allviss executes it, condensed for a public reader. The full account, written so a domain expert can check each claim against the code that implements it, is in our engineering documentation.
Every analysis runs the same four analytic steps, inside the Analysis phase of the cycle above:
- Step 1 — scope the problem. Classify the question as a secret (a hidden fact), a mystery (an undecided outcome), or a complexity (a situation with reflexive actors) — and set how deep the analysis needs to go.
- Step 2 — what do we know. Build an explicit knowledge base: findings, stakeholder implications, gaps, and a Key Assumptions Check where every assumption states what would prove it wrong.
- Step 3 — what might happen. Generate competing, falsifiable hypotheses — never just one story — including a most-likely, a most-dangerous, an alternative, and a null hypothesis that the apparent pattern is over-stated. This step runs an Analysis of Competing Hypotheses (ACH) matrix, rating every piece of evidence against every hypothesis and favouring the hypothesis with the fewest inconsistencies — the doctrinal counter to confirmation bias, since the analyst is trying to disconfirm, not to confirm a favourite. A separate devil's-advocate pass challenges Step 2's assumptions and can only downgrade an over-confident rating, never inflate one.
- Step 4 — test and monitor. Turn each hypothesis into observable indicators — concrete, time-bound, and tied to a named source — so a later run can check what actually happened.
The report leads with a Bottom Line Up Front and standalone falsifiable Key Judgments — 2 to 5 numbered, dated statements, each carrying a probability word mapped to a fixed numeric band (NATO/PHIA-style words of estimative probability) so "likely" means the same thing in every report.
Quality gates and source independence
Generated output is not trusted because it parsed. A two-tier evaluator checks each step first with deterministic structural rules and then, where those flag something, with an independent model review; a failed check triggers one retry. A separate grounding gate checks Step 3's evidence against the collected source material and fails closed on anything that cannot be verified — an unproven citation never silently passes. Source corroboration is weighted by counting independent voices, not rows: reference URLs are clustered by shared domain, shared wire-service byline, and near-duplicate headline, so ten reprints of one wire story count as one voice, not ten — the doctrinal defence against circular reporting.
What the model cannot yet do
Two gaps, stated plainly rather than papered over. First, there is no calibration record: allviss cannot yet tell you whether its past "likely" calls have historically meant 70%. Probability words map to fixed numeric bands, but nothing yet scores past forecasts against real-world outcomes — read the probability language as a well-specified estimate, not a track-record-backed one. Second, Steps 2 through 4 are produced by a single model rather than a team reasoning from genuinely independent priors; the challenge layers run on different models, which is real cross-model checking, but it is not the same as independent analysts.
Every report says what it is
Every channel Allviss delivers through — the PDF report, the web report, the chat assistant, and onboarding email — carries an explicit AI-generated disclosure, not a one-time notice buried in terms of service. Reports are generated with that disclosure built into the drafting step itself, not added after the fact.
Decision support, not a decision-maker
Allviss is built and positioned as a prioritization and flagging aid for a human analyst — never as a substitute for one, and never as an automated determination of fact. Report language is written to state implications and watch items, not verdicts, and to flag rather than assert when a claim cannot be adequately sourced.
Traceable, checkable output
- Audit trail. Every analysis records why a given source or query was pursued, available on request.
- Cited, weighted sources. Reports cite their sources inline. Independent corroboration is weighted separately from repeated wire-service reprints of the same story, so ten copies of one article can't masquerade as ten independent sources.
- Independent fact-check pass. Before a human expert reviews a report, an independent audit step re-checks its claims against the actual source text it cites, flagging anything unsupported, taken out of context, or stale.
Data protection
Users can request export or deletion of their data at any time (GDPR Articles 15 and 17). Retention periods and encryption-at-rest are documented and enforced, not left to policy alone. User-submitted questions and report content are never exposed outside the authenticated account that owns them — including in our own operational tooling and logs.
What we haven't finished
We'd rather say this plainly than imply otherwise: there is no lawyer-reviewed risk-tier determination on file yet, and "human oversight" today is a product-design commitment rather than a hard technical gate — nothing currently stops a reader from acting on a report without pausing at the disclosure. We're not claiming more than that.