Most importantly, there must be an evidentiary trail: who built it, who trained it, what data categories were used, who deployed it, what safeguards were installed, who could override it, what version was operating when harm occurred, and who preserved the logs.