Art/Official
A protocol for honest, machine-readable records of creative practice
Abstract
Art history is written after the fact, by people with a stake in what it says. The artist’s own account of what they were doing rarely survives into any public record — it is mediated for press releases, catalogues, and collectors long before anyone outside the studio hears it. Art/Official is a protocol for producing a different kind of record: one collected through structured dialogue at the moment of making, marked honestly for what is confirmed versus inferred, and left open for reasoning rather than asserted as truth. It does not claim neutrality. It claims something more modest and more durable — that the data was collected without distortion, and that anyone can audit how. This paper describes the problem the protocol responds to, the method it uses, the schema it produces, the evidence that it works, and the real limitations it has not yet resolved.
1. The Problem
Two structural gaps sit underneath most public records of art.
The narrative problem. Art history is conventionally told as a single evolutionary sequence — one movement leading to the next. But influence has never actually worked that way. Once museums exist, every artist has access to everything simultaneously; influence runs sideways as often as it runs forward. Les Demoiselles d’Avignon — credited as the first painting of modern art — was shaped by African masks Picasso saw in a museum, not by a prior step in a lineage. Describing a web of simultaneous relationships requires something built to hold thousands of connections without forcing them into a line. That is closer to what a reasoning system with an embedding layer is suited to than what a chronological survey is.
The disinterested-critic problem. Independent critical judgment — assessment made without commercial pressure — has become structurally rare. Since the 1980s, the incentives around cultural valuation have shifted toward institutions and intermediaries with a direct financial stake in the outcome. What gets called culturally significant is increasingly something pushed by people with a motive, rather than something discovered independently.
Both problems point to the same underlying failure: the record of a work — what it is, why it was made, what it means — is produced by people who benefit from a particular version of the answer. A handful of specific gaps follow directly from this: a valuation gap (price data disconnected from any account of what the work is actually doing), an exclusion gap (who gets left out of the record is itself information, and it isn’t tracked), an influence gap (artists cite influences their dealers and critics don’t foreground), an intent gap (the artist’s actual purpose rarely survives contact with a press release), a failure gap (abandoned work isn’t commercially convenient, so it isn’t recorded), and a time gap (physical works change condition and context over decades; most records treat them as static).
Art/Official is a response to these gaps, built as a schema rather than an argument. Every gap above corresponds to a specific field. That correspondence — theory compiling into implementation — is the protocol’s central design commitment.
2. The Method
Art/Official is a conversational cataloguing protocol: a structured dialogue between an artist and an AI agent, briefed in advance on that artist’s practice, that produces a record neither a static form nor an unstructured interview could produce on its own.
Why dialogue, not a form. An artist filling in a form will not write their own assessment of their work’s significance — it feels premature, like a claim they have no standing to make. In a conversation that asks the right specific questions, drawing on real knowledge of the practice, that assessment emerges without ever being asked for directly. The intimacy of a briefed agent is not a UX nicety; it is the mechanism that makes an honest record possible at all.
How a session runs. Before an image is even uploaded, four questions establish temporal and emotional orientation — including a blind description, where the artist describes the work from memory before seeing it again, with the explicit knowledge that both descriptions will later be shown side by side. That transparency is what makes the unguarded first answer possible. From there, the agent runs two layers at once: a conversation layer the artist experiences as warm and specific, and a silent analysis layer — dominant color, compositional structure, embedding generation — that fills what can be handled computationally without asking. The two merge into a single draft record at session end.
The middle of the session is where the real work happens: three fields — intent, the experience of making this specific piece, and its immediate seed — are kept rigorously distinct, and none are ever elicited by asking “what does this mean to you,” a question explicit enough to produce a defended, performed answer rather than a genuine one. Entry is always through a specific visual observation instead. Near the close, the image is foregrounded again and the artist’s own blind description is read back verbatim: does it still hold, or would you say it differently now? That gap — between the answer given before looking and the answer given after sustained attention — is itself recorded, not discarded.
What the agent is never allowed to do. It cannot generate intent, inspiration, or self-assessment fields from inference — these require genuine artist input, full stop. It cannot ask a leading or closed question. It cannot label which field of a hidden taxonomy a question is meant to fill. And nothing commits to the record without the artist’s explicit confirmation; status defaults to draft.
Honesty, in this system, is not a claim about the resulting content. It is a set of procedural constraints on how the content is drawn out, paired with an explicit mark on every field for how sure anyone should be of it.
3. The Schema
Confidence and source, on every field. Every value carries two tags: whether it is confirmed or inferred, and whether it came from conversation, image analysis, or background research. This is the single mechanism underneath the whole schema, and it is applied everywhere — not only to provenance, though provenance is where it matters most. In practice this is implemented as a four-level confidence enumeration — documented fact, credible inference, institutional assertion, speculation — attached to individual claims rather than to whole records, so a single artwork can hold both a documented fact (a gift, confirmed by the artist) and a speculation (a current whereabouts, unconfirmed) side by side, each honestly marked as what it is.
Provenance as an event chain, not a flat record. Ownership is not stored as a single “current owner” field or an unstructured note. It is modeled as a sequence of typed events — acquisition, transfer, consignment — each carrying an actor, a place, a date (which may itself be marked as uncertain), and a claim-status marker. A sale, where one occurs, is not a separate, independently-tracked object that has to stay in sync with the ownership record; the sale is the event that changes ownership. This removes an entire category of integrity failure that a two-object design invites — a sale and an ownership change silently drifting out of agreement with each other — by making them the same structural act. Actors in these events resolve to real identity records where known — a collector, a gallery, an institution — rather than free text, using the same actor model applied elsewhere in the schema. Confidence claims can attach to a specific event in the chain, not just to the work as a whole, so a claim like “this transfer date is documented fact” and “the current custodian is speculation” can coexist accurately on the same object’s history.
Provenance, without the blockchain assumption. A chain-of-custody model of provenance only works if every actor in the chain — collector, estate, auction house, museum — adopts the same infrastructure. The moment it reaches someone who isn’t participating, the chain doesn’t just stop; it actively misleads, presenting itself as complete when it isn’t. An incomplete chain that looks complete is worse than no chain at all. The confidence layer described above exists precisely because the event chain itself cannot guarantee completeness — it records what is known, honestly qualified, rather than presenting a closed system as authoritative. This makes uncertainty visible, which is what a closed chain-of-custody record is structurally unable to do.
One actor model, used consistently. People — collectors, curators, gallerists, co-exhibitors, organizers, institutions — resolve to a single shared actor record rather than being re-typed as free text each time they appear in a different context (an exhibition, an ownership event, a collaboration). An actor’s role determines how it is expressed in structured output: an individual resolves as a person, an institution or gallery resolves as an organization. This is a small design choice with a real effect — it means the same collector mentioned in two different works’ records is recognizably the same entity, not two unrelated strings that happen to match.
Career-stage tiers. The full field set exists for every artist from day one, but is filtered by relevance rather than shown all at once: a Studio-tier artist is never asked about auction estimates or institutional loan history. As a practice moves through Market and Institutional stages, fields like sales records, resale delta (the gap between original and resale price — a financial extraction record), authentication history, and institutional dependency records activate. The tiering is a dialogue-layer filter only; the underlying record always has room for the field, whether or not a given artist is ever asked to fill it.
workContext. Where raw evidence of a threshold moment gets captured — a shift in the practice, a recognition, a connection surfacing — but only as evidence, never as a self-assessed claim of significance. The same logic, applied to the practice as a whole rather than a single artwork, extends to a proposed ProjectEvent type: corpus readings, threshold recognitions, and published dialogues, each carrying a required statement of exactly what the witness had access to when the entry was made — blind or conditioned, and with what.
Vision analysis, blind by design. Every AI vision pass on an artwork image runs without title, series, or date — the model is explicitly instructed not to identify the work even if it recognizes it. This is what keeps the vision layer an independent witness rather than an echo of the metadata already on file. One field, unresolved, is mandatory on every pass: a machine-analogue of a viewer saying I don’t know what this is doing but I keep coming back to it — treated in this protocol as the most valuable signal available, not a gap to be smoothed over.
Interoperability, deliberately unoriginal. The schema does not invent a parallel vocabulary where an adequate one already exists. It uses schema.org for basic object identity and discovery — the layer general-purpose search engines and language models already parse. For time-based works — video, audio, performance documentation — it does not reinvent duration or format handling; it inherits schema.org’s own native properties for time-based media by typing a work with more than one applicable type at once (a video artwork is both a VisualArtwork and a VideoObject, for instance), so existing tooling built for either type understands it without modification. Where a genuine gap exists — the confidence-and-source mechanism, the intent and dialogue fields no existing vocabulary has any concept of, the provenance-confidence layer sitting on top of the event chain — a small, purpose-built namespace, documented at a stable, resolvable URI, fills only that gap. The result is a record that schema.org-aware systems understand, that inherits established handling for media types rather than duplicating it, and that adds new vocabulary only where nothing adequate already existed. See the schema page for the field-level detail, and /ns/ for the namespace itself.
4. Evidence
Claims about a protocol are only as credible as their working implementation. The first is bernardbolter.com — a single artist’s practice, catalogued under this protocol since its build began in 2026.
As of the most recent full audit: 217 artworks published, all with server-rendered structured data; a live corpus feed, versioned and machine-readable; fifteen documented series; CLIP and DINOv2 embeddings computed across the corpus for similarity reasoning, both language-informed and self-supervised. No other individual artist site currently publishes anything comparable.
The strongest evidence, though, is a single dated event. On July 9, 2026, an AI system was given access to the corpus alone — no access to the physical work, no conversation with the artist beforehand — and asked to read it. Reasoning across the corpus, it independently reconstructed the governing logic of a thirty-year practice: that one series compresses space, another compresses time, and the archive itself compresses an artistic life — three instances of the same operation at three different scales. The artist confirmed this was a real insight into his own work that he had not fully arrived at despite living inside the practice for three decades.
That moment is the protocol’s actual proof of concept, and it resolves a question the protocol would otherwise have to answer with a promise rather than evidence: why would an individual artist do this expensive cataloguing work, when the stated payoff — reasoning across thousands of honest archives — is decades away? The honest answer is that the decade-scale claim already functions today, at a sample size of one. A sufficiently honest single archive gives its own artist a reading of their practice they could not yet have reached alone. That is not a promise about art history in general. It is a working result, dated and on the record.
The same audit that produced this result also produced, in the same sitting, a list of real bugs in the live data — mislabeled fields, date mismatches, an unencoded filename, a missing license field, one inadvertent disclosure of private information. This is included here deliberately. A protocol built around honest, audited records that hides its own errors would be a contradiction; publishing the audit alongside the discovery is the same discipline the protocol asks of everyone using it, applied to itself. See /evidence/ for more.
5. Open Questions
A protocol this early has more open questions than settled ones. Naming them is part of the method, not a departure from it. The six that follow were named in a single reflexive pass — applying the protocol’s own standard for honest, dated, attributed records to the protocol’s own claims about itself.
The vision layer is not a neutral eye. An early formulation of this project claimed a machine “sees the painting” without a stake in gallery representation. That is the weakest claim the project has made about itself. CLIP, DINOv2, and every comparable model were trained on web-scale image-text data — shaped by which works were photographed, reproduced, captioned, exhibited, taught, and circulated, which is to say, by the same market and institutional apparatus this protocol sets out to counterbalance. The embedding space encodes that apparatus’s historical attention, laundered through a model. The corrective the protocol already applies to human viewers — that they are conditioned by what they have been shown — has to apply to models too: a model is a viewer with a training distribution instead of a biography. In practice this means every embedding and every vision pass is tagged with model, version, and date, never stored as anonymous “similarity,” and treated as one conditioned signal to weigh against the others, not an oracle.
The corpus selects its own artists. A corpus built from voluntary adoption is filtered by who adopts it. The likely early demographic — artists underserved by market validation, digitally capable, motivated to control their own record — is a real filter, arguably a more interesting one than the gallery system’s, but not the absence of a filter. This should be visible as data about the corpus, not smoothed into a claim of representativeness.
Self-report relocates distortion; it does not remove it. An artist cataloguing work for a public, machine-read, posterity-facing record still has an incentive to shape how that record reads. The press-release problem does not disappear — it moves in-house. The dialogue mechanism, which draws answers out through specific questions rather than asking directly, is a genuine mitigation, and capturing raw contextual evidence rather than asking an artist to declare a work significant is the right structural response. But the honest description of what this protocol produces is differently and more transparently mediated data, not unmediated data — and revisions over time are treated as evidence in their own right, superseded rather than silently overwritten.
Viewer response measures present legibility, which may not be the same thing as future significance. The protocol’s own founding case for why recognition is delayed — that contemporaries systematically failed to see what mattered in artists later judged significant — sits in tension with using contemporary viewer response as one of its triangulation signals. If contemporaries reliably miss what matters, convergence of signals in the present may only identify what is legible now. The working answer is a specific, falsifiable hypothesis: an inability-to-name response — a viewer saying, in effect, I don’t know what this is doing but I keep coming back to it — is treated as the pre-articulate form of recognition, the signal available before critical vocabulary catches up. This is named here as the load-bearing, testable core of that answer, not settled fact.
The protocol’s own historical argument is scaffolding, not foundation. Claims like “narrative fragmentation after the 1980s is commercially useful, and therefore functionally maintained” are strong, contestable functionalist claims with real alternative explanations. The schema does not actually depend on them; it is fully justified by weaker, safer claims few informed people would dispute — that artist intent rarely enters the record unmediated, that provenance evidence is scattered and confidence levels usually hidden rather than recorded, that recognition and creation run on different timelines with the gap currently unrecorded. Public-facing material should lead with those claims, not the more contestable historical ones, so that a critic who defeats the strong history wins nothing against the infrastructure — it never rested there.
The record-keeper is also a participant. The first implementation of this protocol is built by an artist with his own recognition stakes, cataloguing his own work. That is not a flaw — it is part of why the tooling had to be built honestly, because its maker needed it to be. But it belongs on the record like everything else the protocol tracks: the designer is inside the dataset, and that fact should be weighable by a future reader the same way every other source in the corpus is.
Adoption is not yet solved. The corpus’s larger claims about art history only become meaningful at scale — thousands of honest archives, decades of accumulated data. Nothing in the current design explains why a second or two-hundredth artist takes on the real cost of this cataloguing process, and the project’s own founding documents assume growth rather than argue for it. The strongest answer available is the individual-archive result described in Section 4: the payoff is not only collective and distant, it is individual and immediate. Whether that is sufficient incentive at scale is genuinely untested.
Governance is undefined. Who owns a contributed archive, under what license, and what happens to a corpus if its maintainer stops — none of this has a public answer yet. Any funding or partnership arrangement is currently held to one internal test: does accepting it give anyone outside the artist’s own control the ability to influence what gets collected, how it’s interpreted, or who can access it. If yes, the arrangement is compromised regardless of the amount involved. That test is a starting position, not a governance structure.
Durability is a live risk, not a solved problem. An archive meant to outlast the validation systems it critiques currently depends on standard cloud infrastructure, without a scheduled backup or export strategy independent of that infrastructure. A single bad migration could be more damaging than anything the protocol is designed to protect against. A long-horizon preservation commitment exists for the corpus’s content — a snapshot strategy spanning decades — but this addresses content preservation, not the operational risk of the live service in the near term.
The central historical claim will not be testable soon. The protocol’s deeper hypothesis — that the inability to name what a work is doing, combined with people returning to it anyway, predicts significance that contemporary judgment misses — runs on a recognition-delay timeline of thirty to fifty years, by design. Even in the best case, the data needed to evaluate that claim honestly does not yet exist. The near-term evidence this paper offers is the individual-archive result in Section 4, not the generational claim, because the generational claim is not yet checkable by anyone, including its own author.
The record changes what it records. Knowing that new work will eventually face this dialogue may already be changing how it gets made — a version of an observer effect the protocol cannot fully avoid. The current approach is not to prevent this but to date it plainly: a marked boundary in the corpus between work made before this awareness existed and work made after, so the effect becomes visible data for future readers rather than an unacknowledged distortion.
This project does not claim to have escaped mediation. It claims something more modest and more useful: that every mediation it carries is named, dated, attributed, and recorded in the same schema that records everything else — so that a future reasoning system inherits not just the data, but an honest account of how the data came to be. Not purity. Provenance, applied finally to the record itself.
6. Where This Sits
Art/Official is infrastructure, not a product. It is the protocol underneath an individual artist’s own archive — proven, so far, at a sample size of one — and it is built to be usable by others without requiring them to adopt anything beyond a documented, resolvable schema. What gets built on top of it, for artists or for institutions, is a separate question from whether the underlying record-keeping discipline holds up. This paper is an argument that it does, together with an honest account of where it might not.
This document will be revised as the protocol develops. Corrections, disagreements, and identified gaps are welcome.