Why OpenIRB
Intelligence scales. Review must scale with it.
The challenge is not merely that AI is powerful. The challenge is that intelligent systems can operate across organizations, domains, and populations faster than traditional oversight can understand, document, or correct them.
The gap
Existing controls do not answer the full review question.
Identity
Identity tells us who an actor is. It does not tell us whether the actor should act in this context, for this purpose, under this consent posture.
Access control
Access control tells us what a system can technically reach. It does not prove that the access is ethically justified, institutionally approved, or still within scope.
Logs
Logs tell us what happened. They do not always prove what authority applied, what consent was valid, or what evidence supported the decision at the time.
The review question
OpenIRB starts with one question.
Should this system be allowed to act, recommend, decide, learn, deploy, or scale under this evidence, consent, authority, risk, and monitoring posture?
If an institution cannot answer that question with a reviewable record, it does not yet have reviewable intelligence.
The upgrade
From compliance artifact to living review system.
A one-time approval cannot govern systems that drift, adapt, learn, update, change scope, or operate through agents. OpenIRB treats review as a lifecycle.
| Old posture | OpenIRB posture |
|---|---|
| Point-in-time approval | Continuing review |
| Static document | Versioned evidence packet |
| Committee minutes | Decision artifact |
| Local log | Auditable receipt |
| Broad permission | Scoped authority and revocation |
| Human oversight by assertion | Human oversight by design and record |