{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-ai-001","code":"wm-ai-001-ai-system","url":"https://ver.cy/models/wm-ai-001-ai-system/","name":"AI System","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"aggregate","plane":"","domain":["INF.AI.SYS"],"industry":["Cross-industry"],"navPath":"NAV.INF.AI.SYS","tags":["ai","system","inf.ai.sys"],"facets":{}},"whatItIs":"WM-AI-001 covers the machine-based system that infers from input how to generate outputs influencing physical or virtual environments, taken together with the provider/deployer arrangements, configuration baseline, human oversight, logging, evaluation evidence and regulatory status that make it operable and auditable. It is format-neutral: JSON, YAML, Markdown, HTML, Git, MCP and MongoDB are projections of the same semantics. It stops at the boundary of the model artifact, the agent actor, the dataset and the incident report, which are separately modelled and linked by typed edges.","purpose":"Describe a governed AI-enabled system as a unit of accountability that is larger than any single model artifact: its identity, declared purpose, composition, classification, lifecycle, operation, oversight, assurance evidence and retirement.","scope":{"in":["Authoritative system identity, trade name, identification reference and public registration identifiers","Declared intended purpose, conditions of use, excluded uses and reasonably foreseeable misuse","Autonomy and adaptiveness profile, output types and the environments outputs can influence","Regulatory and internal risk classification, including derogation claims and profiling flags","Versioned configuration baseline and the component set frozen in it (AI bill of materials)","Binding to model artifacts, upstream providers and external model services","Input data dependencies, input specifications and deployer-controlled input governance","Operator roles: provider, deployer, importer, distributor, authorised representative and internal AI actor functions","Lifecycle stage, market status, change control and substantial-modification determination","Deployment topology, processing locations, integration interfaces and market jurisdictions","Automatic event logging, runtime operational state and containment triggers","Human oversight measures, assignment, competence and intervention mechanisms","Performance metrics, declared accuracy, validation and testing evidence","Cybersecurity controls and adversarial threat posture","Conformity assessment, declarations, standards applied and public registration records","Transparency disclosure to affected persons and machine-readable marking of synthetic output","Risk management system and impact assessment on persons and fundamental rights","Post-market monitoring, serious incident detection and reporting linkage","Retention, decommissioning, withdrawal and deletion"],"out":["Internal structure, weights, architecture, training run and evaluation of the model artifact itself (WM-SFT-004)","Agent actor goals, tool repertoire, planning loops and autonomous task execution semantics (WM-AI-002)","The AI incident report record and its regulatory narrative content (WM-AI-010)","Dataset content, dataset licensing and dataset lineage as first-class records","Legal entity, organisational structure and personnel records of the provider or deployer","Generic software product packaging, release engineering and non-AI functionality inherited from WM-SFT-002","Data subject, natural person and consent records","Enterprise risk register, audit programme and management-system certification scope of the organisation","Hardware/device product records where the AI system is only an embedded safety component","Contract, procurement and commercial terms records"],"boundaries":[{"neighbor":"AI model artifact (WM-SFT-004)","distinction":"The model artifact is a versioned trained object with parameters and a training provenance chain. WM-AI-001 records only the binding: which artifact version is invoked, in which role, under which access mode. Regulators separate the two regimes explicitly, treating general-purpose models and AI systems as distinct objects of obligation."},{"neighbor":"AI agent (WM-AI-002)","distinction":"An AI system may expose zero, one or many agent actors. Agent-specific semantics (goal decomposition, tool invocation, memory, delegation) belong to WM-AI-002; WM-AI-001 records only that agent actors exist, their autonomy envelope and the containment controls around them."},{"neighbor":"AI incident report (WM-AI-010)","distinction":"WM-AI-001 owns detection, classification and the reporting obligation state for the system; the incident report record itself, with its narrative, causal analysis and authority correspondence, is a separate record that names the affected AI system."},{"neighbor":"Software product or service (WM-SFT-002)","distinction":"WM-AI-001 specialises the software parent with the elements that only apply when a system infers outputs rather than executing fully specified rules: inference-derived behaviour, adaptiveness after deployment and autonomy. Deterministic rule engines without an inference step are out of scope even when embedded in the same product."},{"neighbor":"Dataset / training corpus record","distinction":"WM-AI-001 records the input data specification and the identifiers of datasets relied upon, not the dataset contents, collection method or labelling procedure, which are documented in the model artifact and dataset models."},{"neighbor":"Conformity certificate and notified-body record","distinction":"Certificates are issued to a version of a system by an external body and have their own identity and expiry. WM-AI-001 holds the reference and status, not the certificate lifecycle of the issuing body."},{"neighbor":"Medical device or other sectoral product record","distinction":"Where the AI system is a device software function, sectoral lifecycle regimes add pre-authorised change control constructs that are not present in the horizontal regime; WM-AI-001 carries a change-plan reference rather than duplicating sectoral device documentation."}]},"distinguishingFeatures":["The unit of accountability is the whole AI-enabled system, larger than any single model artefact.","Unlike an AI agent record, it describes a governed product or deployment, not an actor with delegated authority.","Carries risk classification, intended purpose and oversight arrangements that a plain software product lacks.","References incidents, datasets and certificates but does not own them."],"structure":{"bundles":[{"id":"identity-purpose-and-classification","name":"Identity, Purpose and Classification","description":"What this AI system is, which version of it is in force, what it is declared to do, and how it is classified for risk and behaviour.","layers":[{"id":"system-identity-and-versioning","name":"System Identity and Versioning","description":"Authoritative and public identifiers for the system and the versioned configuration baseline they resolve to.","findings":[{"id":"ai-system-identity","name":"AI system identity and designation","description":"The identifier set that pins one AI system as an accountable object: the master-system key, the commercial trade name, the provider's internal identification reference and any public registry entry identifiers.","questions":[{"text":"Which identifier is the authoritative master-system identifier for this AI system, and which system of record issues it?","id":"q-identity-master-key","kind":"identity"},{"text":"What trade name and identification reference distinguish this system from other systems supplied by the same provider?","id":"q-identity-trade-name","kind":"identity"},{"text":"How is the system-level identity kept distinct from the identities of the model artifacts it invokes and the product it is embedded in?","id":"q-identity-vs-artifact","kind":"relationship"},{"text":"Which external registries hold an identifier for this system, and how are those identifiers reconciled with the master key?","id":"q-identity-registry-reconciliation","kind":"interoperability"}]},{"id":"version-and-configuration-baseline","name":"Version and configuration baseline","description":"The released, frozen combination of software, firmware, model versions, prompts and policies that constitutes 'this system as placed on the market', together with its integrity evidence and effective dates.","questions":[{"text":"Which version and configuration baseline of the system is currently placed on the market or put into service?","id":"q-baseline-current","kind":"state"},{"text":"Which component versions — model, software, firmware, prompts, policies — are frozen in this baseline?","id":"q-baseline-components","kind":"composition"},{"text":"How is the integrity of the released baseline demonstrated, and by which build or signing provenance?","id":"q-baseline-integrity","kind":"provenance"},{"text":"When did this baseline take effect and when did it supersede the previous baseline?","id":"q-baseline-supersession","kind":"temporal"}]}]},{"id":"intended-purpose-and-operating-domain","name":"Intended Purpose and Operating Domain","description":"The declared purpose, conditions of use, exclusions and foreseeable misuse that bound every later assessment.","findings":[{"id":"intended-purpose-and-use-context","name":"Intended purpose and operating domain","description":"The provider's declared use, including specific context and conditions of use, the intended user groups and environments, and the excluded uses and reasonably foreseeable misuses against which risk is assessed.","questions":[{"text":"What is the intended purpose declared by the provider, including the specific context and conditions of use?","id":"q-purpose-declared","kind":"definition"},{"text":"Which uses are explicitly excluded, and which reasonably foreseeable misuses have been identified?","id":"q-purpose-exclusions","kind":"constraint"},{"text":"Which sectors, environments and affected populations does the declared purpose reach?","id":"q-purpose-population","kind":"spatial"},{"text":"Who may change the declared intended purpose, and what re-assessment does such a change trigger?","id":"q-purpose-change-authority","kind":"authority"}]}]},{"id":"risk-and-behavioural-classification","name":"Risk and Behavioural Classification","description":"How the system is classified for regulatory risk and how its inference behaviour, autonomy and adaptiveness are characterised.","findings":[{"id":"regulatory-risk-classification","name":"Regulatory and risk classification","description":"The determination of which regime applies — prohibited practice, high-risk by product-safety route, high-risk by listed use case, transparency-only, or minimal — including any derogation claim and the profiling exception that defeats it.","questions":[{"text":"Under which classification route does the system fall, and which listed use case or harmonisation instrument triggers it?","id":"q-class-route","kind":"classification"},{"text":"If a derogation from high-risk classification is claimed, which condition is relied on and what evidence supports it?","id":"q-class-derogation","kind":"decision"},{"text":"Does the system perform profiling of natural persons, which removes any derogation?","id":"q-class-profiling","kind":"exception"},{"text":"Which events require the classification to be reassessed before the system continues in service?","id":"q-class-reassessment","kind":"lifecycle"}]},{"id":"autonomy-and-adaptiveness-profile","name":"Autonomy and adaptiveness profile","description":"Characterisation of how much the system decides without a human decision point, whether it changes its own behaviour after deployment, what output types it produces and which physical or virtual environments those outputs can influence.","questions":[{"text":"What level of autonomy does the system exercise between human decision points, and where are those points placed?","id":"q-autonomy-level","kind":"classification"},{"text":"Does the system adapt after deployment, and through which mechanism — online learning, retrieval updates, or prompt and policy changes?","id":"q-adaptiveness-mode","kind":"state"},{"text":"How is the boundary drawn between inference-derived behaviour and deterministic rule execution inside this system?","id":"q-inference-boundary","kind":"definition"},{"text":"Which physical or virtual environments can the system's outputs influence, and through which actuators or downstream integrations?","id":"q-environment-influence","kind":"constraint"}]},{"id":"ai-system-definition-adoption","name":"AI system definition","description":"An AI system is a machine-based or engineered system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. OECD, the EU AI Act and the Council of Europe Framework Convention share this inference-centred wording; ISO/IEC 22989 uses engineered system and human-defined objectives without the verb infers.","questions":[{"text":"Which definition of AI system is adopted for this instance and how is it distinguished from ordinary rule-executing software?","id":"ai-system-definition-adoption-q01","kind":"definition"},{"text":"Does this instance infer how to generate predictions, content, recommendations or decisions from inputs in a way that can influence physical or virtual environments?","id":"ai-system-definition-adoption-q02","kind":"classification"},{"text":"Which definitional conflicts between OECD, EU, ISO/IEC 22989 and NIST AI RMF 1.0 are recorded for this instance rather than claimed as conformance?","id":"ai-system-definition-adoption-q03","kind":"interoperability"}]},{"id":"socio-technical-classification-profile","name":"OECD classification dimensions","description":"The OECD framework classifies AI systems along People and Planet, Economic Context, Data and Input, AI Model, and Task and Output. NIST AI RMF 1.0 reuses these socio-technical dimensions to map lifecycle risk. The profile characterises a deployment; it is not itself a legal risk class.","questions":[{"text":"Who uses the system, who is impacted, and what human-rights, wellbeing, labour or environmental effects are in scope?","id":"socio-technical-classification-profile-q01","kind":"relationship"},{"text":"In which industrial sector, business function and technical-maturity setting is the system deployed?","id":"socio-technical-classification-profile-q02","kind":"classification"},{"text":"What tasks does the system perform, does it combine tasks into a composite or autonomous control system, and what action does it take on the environment?","id":"socio-technical-classification-profile-q03","kind":"classification"},{"text":"Does this socio-technical profile justify treating the system as in-scope for heightened governance even if no high-risk legal class applies?","id":"socio-technical-classification-profile-q04","kind":"decision"}]},{"id":"gpai-system-boundary","name":"General-purpose AI system boundary","description":"A general-purpose AI system is an AI system based on a general-purpose AI model and capable of serving a variety of purposes, for direct use or for integration in other AI systems. The GPAI model itself is not this entity. Downstream providers integrate a model into their AI system.","questions":[{"text":"Is this record a general-purpose AI system, a single-purpose system, or a downstream system that integrates a GPAI model?","id":"gpai-system-boundary-q01","kind":"classification"},{"text":"Which general-purpose or other models are integrated, and is integration vertical or contractual with another entity?","id":"gpai-system-boundary-q02","kind":"composition"},{"text":"Is any integrated model still in research, development or prototyping before being placed on the market, and therefore outside GPAI-model placing rules?","id":"gpai-system-boundary-q03","kind":"exception"}]}]}]},{"id":"composition-and-supply-chain","name":"Composition and Supply Chain","description":"What the system is made of, which models and data it depends on, and which parties are accountable for each part.","layers":[{"id":"system-composition-and-dependencies","name":"System Composition and Dependencies","description":"Component inventory, model artifact bindings and the input data the system consumes in operation.","findings":[{"id":"component-inventory-and-ai-bom","name":"Component inventory and AI bill of materials","description":"The enumerated set of models, libraries, services, hardware and data stores that constitute the system in a given baseline, with supplier, version, licence and vulnerability status, expressed in a machine-readable bill-of-materials format.","questions":[{"text":"Which components constitute the system in the released baseline, and which are third-party rather than self-developed?","id":"q-bom-components","kind":"composition"},{"text":"For each component, what is its supplier, licence and origin of supply?","id":"q-bom-provenance","kind":"provenance"},{"text":"In which machine-readable bill-of-materials format and specification version is the inventory published?","id":"q-bom-format","kind":"interoperability"},{"text":"Which components carry known vulnerabilities or an unsupported end-of-life status at the time of release?","id":"q-bom-vulnerability","kind":"security"}]},{"id":"model-artifact-binding","name":"Model artifact binding","description":"Which model artifacts and versions the system invokes, in which functional role, under which access mode and commercial terms, and how upstream model changes reach the system.","questions":[{"text":"Which model artifacts and versions does the system invoke, and in which role — primary, fallback, guardrail or embedding?","id":"q-model-binding-roles","kind":"relationship"},{"text":"Is each model artifact self-developed, obtained from an upstream provider, or consumed as an external hosted service?","id":"q-model-supply-mode","kind":"ownership"},{"text":"What licence or contractual terms govern use, modification and redistribution of each bound model artifact?","id":"q-model-terms","kind":"authority"},{"text":"How are upstream model changes detected and propagated into the system baseline?","id":"q-model-change-propagation","kind":"process"}]},{"id":"input-data-dependencies-and-governance","name":"Input data dependencies and governance","description":"The data streams the system consumes in operation, who controls them, the input specifications published to deployers, and the representativeness and personal-data properties that determine whether operation stays within the declared purpose.","questions":[{"text":"Which input data streams does the system consume in operation, and which party controls each stream?","id":"q-input-streams","kind":"composition"},{"text":"How is input data shown to be relevant and sufficiently representative in view of the intended purpose?","id":"q-input-representativeness","kind":"quality"},{"text":"Which input fields contain personal or special-category data, and what lawful basis and safeguards apply?","id":"q-input-personal-data","kind":"privacy"},{"text":"What input data specifications are published to deployers so that operation remains inside the validated envelope?","id":"q-input-specification","kind":"requirement"}]}]},{"id":"actors-roles-and-accountability","name":"Actors, Roles and Accountability","description":"Which legal entities and internal functions hold which duties for this system, and when a role changes hands.","findings":[{"id":"operator-roles-and-responsibility-assignment","name":"Operator roles and responsibility assignment","description":"Assignment of provider, deployer, importer, distributor and authorised representative roles to legal entities, mapped onto the internal functions that design, develop, test, deploy, operate, oversee and govern the system, plus the conditions under which a deployer becomes a provider.","questions":[{"text":"Which legal entity holds each operator role for this system in each market where it is supplied?","id":"q-roles-entities","kind":"ownership"},{"text":"Which named role is accountable for placing the system on the market and for keeping technical documentation current?","id":"q-roles-accountable-person","kind":"authority"},{"text":"Which internal functions — design, development, test and evaluation, deployment, operation, human oversight, governance — are staffed for this system?","id":"q-roles-internal-functions","kind":"relationship"},{"text":"Under which conditions does a deployer or distributor assume provider obligations for this system?","id":"q-roles-transfer-trigger","kind":"exception"}]}]}]},{"id":"lifecycle-change-and-deployment","name":"Lifecycle, Change and Deployment","description":"Where the system is in its life, how change to it is authorised, and where it actually runs.","layers":[{"id":"lifecycle-state-and-change-control","name":"Lifecycle State and Change Control","description":"Lifecycle stage, market status and the governance of modifications including pre-authorised change plans.","findings":[{"id":"lifecycle-state-and-transitions","name":"Lifecycle state and transitions","description":"The current lifecycle stage and market status of the system, the history of transitions between them, who authorised each transition, and the gate criteria that must be met before advancing.","questions":[{"text":"Which lifecycle stage is the system in — design and development, data handling, verification and validation, deployment, or operation and monitoring?","id":"q-lifecycle-stage","kind":"lifecycle"},{"text":"What is the current market or service status: on the market, in service, no longer placed on the market, recalled, or withdrawn?","id":"q-lifecycle-market-status","kind":"state"},{"text":"Who authorised each recorded state transition, and on what evidence?","id":"q-lifecycle-transition-authority","kind":"provenance"},{"text":"Which gate criteria must be satisfied before the system may move to the next stage?","id":"q-lifecycle-gate-criteria","kind":"process"}]},{"id":"change-control-and-substantial-modification","name":"Change control and substantial modification","description":"The determination of whether a proposed change is a substantial modification requiring renewed conformity assessment, the pre-authorised change envelope where one exists, and the impact assessment and test evidence that gate each release.","questions":[{"text":"Does the proposed change constitute a substantial modification that was not foreseen in the initial conformity assessment?","id":"q-change-substantiality","kind":"decision"},{"text":"Which changes are covered by a pre-authorised change plan, and under which modification protocol are they executed?","id":"q-change-preauthorised","kind":"process"},{"text":"What impact assessment supports the change, and which tests must pass before the new baseline is released?","id":"q-change-impact-evidence","kind":"evidence"},{"text":"What sequence of planned changes over the system lifetime is recorded in the technical documentation?","id":"q-change-planned-sequence","kind":"temporal"}]}]},{"id":"deployment-topology-and-jurisdiction","name":"Deployment Topology and Jurisdiction","description":"Where and on what the system runs, what it integrates with, and which legal regimes apply in each market.","findings":[{"id":"deployment-environment-and-jurisdictional-placement","name":"Deployment environment and jurisdictional placement","description":"The environments and locations in which the system is deployed and processing occurs, the hardware and runtime resources it requires, the interfaces through which it interacts with other software, hardware and AI systems, and the jurisdictions where it is placed on the market or put into service.","questions":[{"text":"In which environments and physical or cloud locations is the system deployed, and where is inference processing actually performed?","id":"q-deploy-locations","kind":"spatial"},{"text":"Which hardware and computational resources does the system require to operate as intended?","id":"q-deploy-hardware","kind":"composition"},{"text":"Through which interfaces does the system interact with other software, hardware or AI systems that are not part of it?","id":"q-deploy-interfaces","kind":"interoperability"},{"text":"In which jurisdictions is the system placed on the market or put into service, and which regulatory regime governs each?","id":"q-deploy-jurisdictions","kind":"authority"}]}]}]},{"id":"operation-oversight-and-assurance","name":"Operation, Oversight and Assurance","description":"How the system behaves in service, how humans keep control of it, how well it performs and how resilient it is to attack.","layers":[{"id":"runtime-operation-and-logging","name":"Runtime Operation and Logging","description":"Automatic event recording over the system lifetime and the live operational state of deployed instances.","findings":[{"id":"automatic-event-logging-capability","name":"Automatic event logging capability","description":"The technical capability to record events automatically over the lifetime of the system at a granularity sufficient to identify risk situations, support post-market monitoring and enable deployer-side operational monitoring, with distinct event and record times and protected integrity.","questions":[{"text":"Which events does the system automatically record over its lifetime, and at what granularity?","id":"q-log-event-types","kind":"requirement"},{"text":"How are event time and record or ingestion time captured and distinguished in each log entry?","id":"q-log-time-semantics","kind":"temporal"},{"text":"Who may read operational logs, under which controls, and for which purposes?","id":"q-log-access-control","kind":"access"},{"text":"How is log integrity protected against alteration or deletion during the retention period?","id":"q-log-integrity","kind":"security"}]},{"id":"runtime-operational-state","name":"Runtime operational state","description":"The live state of each deployed instance, the indicators observed continuously, and the conditions that trigger automatic containment, fallback or shutdown.","questions":[{"text":"What is the current operational state of each deployed instance — active, degraded, suspended or offline?","id":"q-runtime-instance-state","kind":"state"},{"text":"Which runtime indicators are observed continuously to detect deviation from validated behaviour?","id":"q-runtime-indicators","kind":"measurement"},{"text":"Which runtime conditions trigger automatic containment, fallback or shutdown of the system?","id":"q-runtime-containment","kind":"event"}]}]},{"id":"human-oversight-and-intervention","name":"Human Oversight and Intervention","description":"Built-in and deployer-implemented oversight measures, the persons assigned to them and the mechanisms by which they intervene.","findings":[{"id":"human-oversight-measures-and-controls","name":"Human oversight measures and intervention controls","description":"The oversight measures designed into the system, those that must be implemented by the deployer, the persons assigned with the necessary competence, training, authority and support, and the mechanisms by which they can interrupt, override or reverse system behaviour.","questions":[{"text":"Which oversight measures are built into the system by the provider and which must be implemented by the deployer?","id":"q-oversight-split","kind":"requirement"},{"text":"Which natural persons are assigned oversight duties, and what competence, training and authority do they hold?","id":"q-oversight-assignment","kind":"ownership"},{"text":"How can an overseer interrupt, override or reverse a system output, and within what time window?","id":"q-oversight-intervention","kind":"process"},{"text":"How is automation bias in overseers detected and mitigated for this system?","id":"q-oversight-automation-bias","kind":"quality"}]}]},{"id":"performance-measurement-and-evaluation","name":"Performance Measurement and Evaluation","description":"Declared metrics and the test and validation evidence that substantiates them.","findings":[{"id":"performance-metrics-and-declared-accuracy","name":"Performance metrics and declared accuracy","description":"The metrics chosen to express accuracy, robustness and fairness for the intended purpose, the justification of their appropriateness, the levels declared to deployers and the conditions and degradation modes under which those levels hold.","questions":[{"text":"Which metrics express accuracy, robustness and fairness for this intended purpose, and why are they appropriate?","id":"q-metrics-appropriateness","kind":"measurement"},{"text":"What levels of accuracy and robustness are declared to deployers, and under which conditions do they hold?","id":"q-metrics-declared-levels","kind":"quality"},{"text":"What are the known limitations, degradation conditions and reasonably foreseeable unintended outcomes?","id":"q-metrics-limitations","kind":"constraint"},{"text":"How often are metrics recomputed in operation, and against which reference period and dataset?","id":"q-metrics-recomputation","kind":"temporal"}]},{"id":"test-validation-and-evaluation-evidence","name":"Test, validation and evaluation evidence","description":"The executed validation and testing procedures, the datasets used, the retained test logs and reports dated and countersigned by responsible persons, and the disposition of results that failed acceptance criteria.","questions":[{"text":"Which validation and testing procedures were executed, on which datasets, and with what results?","id":"q-eval-procedures","kind":"evidence"},{"text":"Which test logs and reports are retained, dated and countersigned by the responsible persons?","id":"q-eval-signoff","kind":"validation"},{"text":"How are evaluation datasets shown to be separated from training data and fit for the evaluation claim made?","id":"q-eval-data-separation","kind":"provenance"},{"text":"Which evaluation results failed acceptance criteria, and how were those failures dispositioned before release?","id":"q-eval-failures","kind":"exception"}]}]},{"id":"security-and-adversarial-resilience","name":"Security and Adversarial Resilience","description":"Protective controls and the AI-specific threat posture of the system.","findings":[{"id":"security-controls-and-adversarial-threat-posture","name":"Security controls and adversarial threat posture","description":"The cybersecurity measures protecting the system and the explicit mapping of its exposure to adversarial attack classes — evasion, poisoning, privacy and abuse — with the resilience test results and the detection and response path for AI-specific security events.","questions":[{"text":"Which cybersecurity measures protect the system against unauthorised access, model theft and infrastructure compromise?","id":"q-security-controls","kind":"security"},{"text":"Which adversarial attack classes are in the threat model for this system, and which residual exposures are accepted?","id":"q-security-threat-classes","kind":"classification"},{"text":"How is resilience against each in-scope attack class tested, and with what measured result?","id":"q-security-resilience-testing","kind":"measurement"},{"text":"What is the detection and response path for a security event that alters AI-specific behaviour rather than infrastructure?","id":"q-security-response-path","kind":"event"}]}]}]},{"id":"governance-conformity-and-transparency","name":"Governance, Conformity and Transparency","description":"The assurance case, the public record and what affected people are told.","layers":[{"id":"conformity-and-public-registration","name":"Conformity and Public Registration","description":"Assessment route, declarations, standards applied and the public registry record.","findings":[{"id":"conformity-assessment-and-declaration","name":"Conformity assessment and declaration","description":"The assessment procedure followed, any notified body involved, the certificate and its expiry, the harmonised standards or common specifications applied, the justification where alternatives were adopted, and the declaration of conformity issued for a specific version.","questions":[{"text":"Which conformity assessment procedure was followed, and was a notified body involved?","id":"q-conformity-route","kind":"evidence"},{"text":"Which declaration of conformity and marking has been issued, by which entity, and for which system version?","id":"q-conformity-declaration","kind":"authority"},{"text":"Which harmonised standards or common specifications were applied, and where an alternative solution was adopted, how is equivalence justified?","id":"q-conformity-standards","kind":"validation"},{"text":"When does the certificate expire and which events force re-assessment before that date?","id":"q-conformity-expiry","kind":"temporal"}]},{"id":"public-registration-record","name":"Public registration record","description":"The public database entry representing the system, the split of registration duties between provider and deployer, which fields are publicly visible and how currency of the entry is maintained.","questions":[{"text":"Which public database entry represents this system, and what is its resolvable identifier or URL?","id":"q-registration-entry","kind":"identity"},{"text":"Which registration fields must be supplied and kept up to date by the provider, and which by the deployer?","id":"q-registration-fields","kind":"requirement"},{"text":"Which registration data are publicly visible and which are restricted to authorities?","id":"q-registration-visibility","kind":"access"},{"text":"When was the registration entry created and last updated, and what triggers a mandatory update?","id":"q-registration-currency","kind":"temporal"}]}]},{"id":"transparency-and-disclosure","name":"Transparency and Disclosure","description":"What affected people are told and how machine-generated output is marked.","findings":[{"id":"disclosure-to-users-and-content-marking","name":"Disclosure to affected persons and content marking","description":"How natural persons are informed that they interact with an AI system or are subject to its decisions, how synthetic audio, image, video and text output is marked in a machine-readable and detectable form, which exemptions are relied on and how disclosure meets accessibility requirements.","questions":[{"text":"How and at what moment are natural persons informed that they are interacting with an AI system?","id":"q-disclosure-interaction","kind":"requirement"},{"text":"How is synthetic output marked in a machine-readable format that is detectable as artificially generated or manipulated?","id":"q-disclosure-marking","kind":"interoperability"},{"text":"Which disclosure exemptions are relied on for this system, and what safeguards replace disclosure?","id":"q-disclosure-exemptions","kind":"exception"},{"text":"How is the disclosure made accessible to persons with disabilities and to persons subject to automated decisions?","id":"q-disclosure-accessibility","kind":"access"}]}]},{"id":"risk-management-and-impact-assessment","name":"Risk Management and Impact Assessment","description":"The continuous risk process and the assessment of effects on persons and their rights.","findings":[{"id":"risk-management-system","name":"Risk management system","description":"The continuous iterative risk process maintained across the system lifetime: identification and characterisation of risks by probability and severity of harm, the treatment measures adopted, the residual risks accepted and by whom, and the review cadence and out-of-cycle triggers.","questions":[{"text":"How is the risk management system established, documented and maintained as a continuous iterative process across the lifetime of the system?","id":"q-risk-process","kind":"process"},{"text":"How is each identified risk characterised in terms of probability of occurrence and severity of harm?","id":"q-risk-characterisation","kind":"measurement"},{"text":"Which residual risks are accepted, by which role, and on what documented grounds?","id":"q-risk-residual-acceptance","kind":"decision"},{"text":"What cadence governs risk review, and which events force an out-of-cycle reassessment?","id":"q-risk-review-trigger","kind":"temporal"}]},{"id":"impact-assessment-on-persons","name":"Impact assessment on persons and rights","description":"Whether an impact assessment on fundamental rights is required for a given deployment, what it covers, how it relates to the data protection impact assessment, which groups are affected and how the findings summary reaches the authority.","questions":[{"text":"Is an impact assessment on fundamental rights required for this deployment, and what must it cover?","id":"q-impact-required","kind":"requirement"},{"text":"How does the AI impact assessment relate to and reuse the data protection impact assessment for the same processing?","id":"q-impact-dpia-relation","kind":"relationship"},{"text":"Which categories of persons or groups are likely to be affected, and how were they or their representatives consulted?","id":"q-impact-affected-groups","kind":"ownership"},{"text":"What summary of findings is submitted to the competent authority, and where is the full assessment retained?","id":"q-impact-summary-submission","kind":"evidence"}]}]}]},{"id":"post-market-incidents-and-retirement","name":"Post-market, Incidents and Retirement","description":"How the system is watched after release, what happens when it harms, and how it ends.","layers":[{"id":"post-market-monitoring-and-incidents","name":"Post-market Monitoring and Incidents","description":"The monitoring plan and signal set, and the detection and reporting of serious incidents.","findings":[{"id":"post-market-monitoring-plan","name":"Post-market monitoring plan and signals","description":"The proportionate monitoring system that actively collects and analyses performance data over the lifetime of the system, including data supplied by deployers, the thresholds that trigger investigation, and the integration with pre-existing sectoral post-market systems.","questions":[{"text":"What does the post-market monitoring plan require to be collected, analysed and reviewed over the system's lifetime?","id":"q-pmm-plan-content","kind":"process"},{"text":"Which data do deployers supply to the provider, through which channel and at what frequency?","id":"q-pmm-deployer-feed","kind":"relationship"},{"text":"Which thresholds in monitored data trigger investigation or corrective action?","id":"q-pmm-thresholds","kind":"measurement"},{"text":"How is monitoring integrated with pre-existing sectoral post-market systems without duplicating obligations?","id":"q-pmm-sector-integration","kind":"interoperability"}]},{"id":"serious-incident-detection-and-reporting","name":"Serious incident detection and reporting","description":"What counts as a serious incident for this system, how awareness is established and timestamped, which reporting deadline class applies, which authority receives the report, and what investigation and corrective action follow.","questions":[{"text":"What qualifies as a serious incident for this system, and by which detection route is it recognised?","id":"q-incident-definition","kind":"event"},{"text":"By which deadline must the incident be reported after awareness, and which deadline class applies?","id":"q-incident-deadline","kind":"temporal"},{"text":"To which market surveillance authority is the report addressed, and who signs it on behalf of which operator?","id":"q-incident-authority","kind":"authority"},{"text":"What investigation, risk assessment and corrective action follow the report, and how is the outcome recorded?","id":"q-incident-followup","kind":"process"}]}]},{"id":"retention-decommissioning-and-deletion","name":"Retention, Decommissioning and Deletion","description":"How long records are kept, how the system is withdrawn and how personal data is disposed of without destroying auditability.","findings":[{"id":"record-retention-and-decommissioning","name":"Record retention and decommissioning","description":"Retention periods and legal bases for logs, technical documentation and evaluation evidence; the withdrawal, recall and decommissioning procedure including deployer notification and data disposition; and the terminal status record that keeps a withdrawn system discoverable.","questions":[{"text":"How long are logs, technical documentation and evaluation evidence retained, and under which legal or contractual basis?","id":"q-retention-periods","kind":"retention"},{"text":"What steps decommission the system, including withdrawal from market, deployer notification and disposition of data and models?","id":"q-decommission-steps","kind":"process"},{"text":"How are personal data in logs, caches and derived stores deleted or minimised while preserving audit capability?","id":"q-deletion-personal-data","kind":"privacy"},{"text":"What terminal status is recorded for a withdrawn system, and where does that record remain discoverable?","id":"q-terminal-status","kind":"state"}]}]}]}]},"agentConduct":{"may":["Register an AI system with its intended purpose and component inventory.","Propose a risk classification with the jurisdiction it applies to.","Record evaluation results and operational logs under the declared retention.","Flag a change in purpose, model or autonomy for reassessment."],"mustNot":["Assert conformance to a law or standard without stored evidence.","Inherit regulatory obligations across jurisdictions without a recorded basis.","Mix provider-held and deployer-held records.","Deploy a change to purpose, risk class or bound models without assessment and authorisation.","Keep personal data from inputs or logs beyond minimisation and retention rules."],"requiresHuman":["Approving the risk classification and intended purpose.","Authorising release or substantial modification.","Deciding on withdrawal or retirement of the system."]},"ethics":{"considerations":["AI systems can make or shape decisions about people; transparency and human oversight protect their rights.","Misclassified risk lets high-impact uses escape safeguards.","Logs and inputs may contain personal data that needs minimisation."],"affectedParties":["People subject to the system's outputs","Deployers and operators","Providers","Supervisory authorities"]},"owners":{"steward":"The adopting Dimension must name a single accountable owner package for WM-AI-001 that holds the system-of-record for system master identifiers and resolves collisions between provider-internal and public registry identifiers.","roles":[{"name":"Model steward (WM-AI-001)","responsibilities":["Maintain the model structure, controlled vocabularies and alignment mappings","Adjudicate boundary disputes with WM-SFT-004, WM-AI-002 and WM-AI-010","Approve breaking changes and publish migration notes"]},{"name":"Accountable provider owner","responsibilities":["Own the system master identifier, intended purpose and classification determination","Keep technical documentation, declarations and registration entries current","Authorise baselines and substantial modifications"]},{"name":"Deployment and oversight lead","responsibilities":["Assign competent human oversight and maintain intervention mechanisms","Ensure input data relevance and monitor operation against declared metrics","Suspend use and notify the provider and authorities when risk emerges"]},{"name":"Assurance and conformity officer","responsibilities":["Maintain evaluation evidence, risk management file and impact assessments","Manage conformity assessment, certificates and standards-applied records","Record conformance claims only where an assessment record exists"]},{"name":"Records and retention custodian","responsibilities":["Operate append-only log, evidence and submission stores with integrity chaining","Apply retention schedules and execute documented deletion or minimisation","Preserve auditability across decommissioning"]},{"name":"Incident reporting officer","responsibilities":["Determine awareness time and applicable deadline class","Submit reports to the competent authority and track acknowledgement","Drive investigation, causal analysis and corrective action to closure"]}],"masterSystems":[]},"relations":[{"target":"WM-SFT-002","type":"child","note":"AI System specialises the software-product parent with inference-derived behaviour, autonomy and adaptiveness; non-AI packaging, release and functional semantics stay in the parent."},{"target":"WM-SFT-004","type":"composes","note":"An AI system uses one or more model artifacts; this model holds the binding (version, role, access mode, upstream provider) and delegates parameters, training provenance and model-level evaluation to the artifact model."},{"target":"WM-AI-002","type":"composes","note":"An AI system may expose agent actors; this model records their existence, autonomy envelope and containment controls while agent goals, tools and delegation semantics live in the agent model."},{"target":"WM-AI-010","type":"references","note":"An AI incident report names affected AI systems; this model holds detection, awareness time, deadline class and submission linkage, not the report narrative or authority correspondence."},{"target":"Organisation / legal entity model","type":"references","note":"Provider, deployer, importer, distributor and authorised representative are legal entities resolved by reference; this model stores role assignment and effective period only."},{"target":"Dataset model","type":"references","note":"Evaluation datasets and operational input sources are referenced by identifier and version; dataset content, collection and labelling remain in the dataset model."},{"target":"W3C PROV-O provenance mix-in","type":"composes","note":"Baseline generation, change authorisation, evaluation runs and state transitions are expressed as Entity/Activity/Agent with wasGeneratedBy, used, wasAttributedTo, wasAssociatedWith, startedAtTime and endedAtTime."},{"target":"Regulation (EU) 2024/1689 technical documentation (Annex IV)","type":"aligned","note":"Findings are mapped to the nine Annex IV documentation points as an alignment; no conformance is claimed and mapping gaps are recorded rather than asserted as satisfied."},{"target":"Regulation (EU) 2024/1689 EU database registration (Annex VIII)","type":"aligned","note":"Registration data elements are aligned to Sections A, B and C so a projection can populate a public entry without redefining the fields locally."},{"target":"NIST AI RMF 1.0 (AI 100-1)","type":"aligned","note":"Trustworthiness characteristics and the GOVERN/MAP/MEASURE/MANAGE functions are used as an evaluation and governance vocabulary; the framework is voluntary and creates no conformance obligation."},{"target":"NIST AI 100-2 E2025 adversarial ML taxonomy","type":"aligned","note":"The threat-class mapping data element draws its controlled vocabulary from the evasion, poisoning, privacy and abuse taxonomy and its lifecycle stages of attack."},{"target":"ECMA-424 CycloneDX Bill of Materials Specification","type":"aligned","note":"The component inventory finding projects to a standard machine-readable BOM rather than defining a private inventory schema."},{"target":"ISO/IEC 42001:2023 AI management system","type":"aligned","note":"Organisation-level AI policy, impact assessment and supplier controls are supplied by the management system; this model consumes them by reference and does not restate management-system clauses."},{"target":"Sectoral device lifecycle regime (FDA PCCP)","type":"extends","note":"Where the AI system is a device software function, the change-control finding extends to carry a pre-authorised Description of Modifications, Modification Protocol and Impact Assessment."},{"target":"AI model artifact (WM-SFT-004)","type":"neighbor","note":"The model artifact is a versioned trained object with parameters and a training provenance chain. WM-AI-001 records only the binding: which artifact version is invoked, in which role, under which access mode. Regulators separate the two regimes explicitly, treating general-purpose models and AI systems as distinct objects of obligation."},{"target":"AI agent (WM-AI-002)","type":"neighbor","note":"An AI system may expose zero, one or many agent actors. Agent-specific semantics (goal decomposition, tool invocation, memory, delegation) belong to WM-AI-002; WM-AI-001 records only that agent actors exist, their autonomy envelope and the containment controls around them."},{"target":"AI incident report (WM-AI-010)","type":"neighbor","note":"WM-AI-001 owns detection, classification and the reporting obligation state for the system; the incident report record itself, with its narrative, causal analysis and authority correspondence, is a separate record that names the affected AI system."},{"target":"Software product or service (WM-SFT-002)","type":"neighbor","note":"WM-AI-001 specialises the software parent with the elements that only apply when a system infers outputs rather than executing fully specified rules: inference-derived behaviour, adaptiveness after deployment and autonomy. Deterministic rule engines without an inference step are out of scope even when embedded in the same product."},{"target":"Dataset / training corpus record","type":"neighbor","note":"WM-AI-001 records the input data specification and the identifiers of datasets relied upon, not the dataset contents, collection method or labelling procedure, which are documented in the model artifact and dataset models."},{"target":"Conformity certificate and notified-body record","type":"neighbor","note":"Certificates are issued to a version of a system by an external body and have their own identity and expiry. WM-AI-001 holds the reference and status, not the certificate lifecycle of the issuing body."},{"target":"Medical device or other sectoral product record","type":"neighbor","note":"Where the AI system is a device software function, sectoral lifecycle regimes add pre-authorised change control constructs that are not present in the horizontal regime; WM-AI-001 carries a change-plan reference rather than duplicating sectoral device documentation."},{"target":"WM-SFT-002","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the system of record that owns the AI system record — for example the provider's product or system register key; this is always the primary key.","Governed global identifier or IRI issued by a recognised authority — for example a public AI database registration entry identifier, a notified-body certificate number, or a namespaced IRI — carried as a typed alias with its issuing authority.","UUID or ULID minted by the adopting Dimension, used only when neither of the above exists; it must be recorded as Dimension-assigned so it is never mistaken for an external identifier.","Content digests of a canonical serialisation may disambiguate re-issued artifacts but never serve as the primary identifier.","A date, a version label, a trade name or a hostname is not an identifier and must not be used as a key."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["An AI system record names a provider, an intended purpose, components including models, a risk class and an oversight arrangement.","Often confused with the AI model artefact, an AI agent and a generic software product."]},"capabilities":{"applicability":"required","items":["Register AI system: Create the governed record for an AI system, assign its master identifier and bind provider, trade name, identification reference and intended purpose.","Classify risk and regulatory status: Determine the applicable regime and record the classification route, any derogation condition, the profiling flag and the assessment evidence.","Assemble component inventory: Produce a machine-readable bill of materials for a baseline covering models, libraries, services, hardware, datasets and their suppliers, licences and vulnerabilities.","Baseline configuration: Freeze and attest a configuration baseline, recording component versions, integrity digests and effective dates, and superseding the prior baseline.","Evaluate and record performance: Execute validation and testing against declared metrics and acceptance criteria and retain dated, signed evaluation evidence.","Emit and retain operational logs: Record events automatically over the system lifetime with distinct event and record times, protect their integrity and retain them for the prescribed minimum period.","Assess and authorise change: Classify a proposed change as routine, pre-authorised or substantial, run the required impact assessment and tests, and authorise or refuse the new baseline.","Publish registration record: Submit and maintain the public registration entry for the system, splitting provider and deployer fields and keeping status and instructions current.","Detect and report serious incident: Recognise a serious incident, timestamp awareness, select the applicable deadline class, submit the report to the competent authority and drive investigation and corrective action.","Withdraw and decommission system: Withdraw or recall the system, notify deployers and authorities, execute data disposition under the retention schedule and record the terminal status.","Authorise placing on the market or putting into service: Confirm technical documentation, human oversight, verification and validation, and conformity evidence before first making available or first use.","Operate with human oversight: Run the system inside its operating envelope with designated human interpretation, override and halt paths.","Assess risk and impact: Identify harms, treat risks, and perform or update AI system impact assessments and fundamental-rights assessments as required.","Monitor post-market performance: Collect experience of use, measure drift and accuracy, and identify corrective or preventive actions, including linkage to incident reports.","Produce and disclose conformity evidence: Assemble technical documentation, instructions, logs, declarations and registration data for deployers, competent authorities or the EU database."]},"hazards":{"applicability":"required","items":["Use outside the intended purpose without reassessment.","Harm to people from unmonitored model drift.","Regulatory breach from wrong risk classification.","Privacy loss through retained logs."]},"interfaces":{"applicability":"required","items":["ISO/IEC 42001 AI management system.","ISO/IEC 22989 AI concepts and terminology.","ISO/IEC 23894 AI risk management.","NIST AI Risk Management Framework.","EU AI Act (Regulation (EU) 2024/1689)."]},"context":{"applicability":"required","items":["The regulatory backbone of this model is the EU horizontal regime; findings that assume registration in a public database, CE-style declarations, notified bodies, market surveillance authorities and awareness-triggered incident deadlines are EU-specific and must be re-mapped elsewhere.","Incident reporting deadline classes (general, accelerated, death) as modelled reflect the EU provisions retrieved; other jurisdictions use different triggers and clocks.","The medical-device change-control extension reflects US FDA practice and does not generalise to other sectors or regions.","No Chinese, UK, Japanese, Korean, Canadian, Brazilian or Indian AI regimes were consulted; obligations there are unmodelled.","Personal-data handling assumes an EU-style controller/processor and impact-assessment framing; jurisdictions with different data-protection architectures will need a different mapping.","Accessibility and worker-consultation duties assume EU-style requirements.","The EU AI Act is treated as the most operational legally binding product-safety-style regime for system duties, not as a global law.","The OECD definition is treated as the intergovernmental alignment hub used by the EU and the Council of Europe.","NIST AI RMF 1.0 is treated as a voluntary United States-origin framework usable by any organisation, not as a statutory class.","Council of Europe CETS 225 is treated as a human-rights, democracy and rule-of-law overlay on lifecycle activities, with national defence out of scope.","ISO/IEC 22989, 42001 and 42005 are treated as international terminology, management-system and impact-assessment alignments that organisations may adopt regardless of jurisdiction."]}},"sources":[{"title":"Article 3: Definitions — Regulation (EU) 2024/1689 (AI Act)","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3","note":"European Commission — AI Act Service Desk"},{"title":"Annex IV: Technical Documentation referred to in Article 11(1) — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-4","note":"European Commission — AI Act Service Desk"},{"title":"Annex VIII: Information to be submitted upon registration of high-risk AI systems — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-8","note":"European Commission — AI Act Service Desk"},{"title":"Article 12: Record-keeping — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12","note":"European Commission — AI Act Service Desk"},{"title":"Article 26: Obligations of deployers of high-risk AI systems — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26","note":"European Commission — AI Act Service Desk"},{"title":"Article 73: Reporting of serious incidents — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-73","note":"European Commission — AI Act Service Desk"},{"title":"Article 6: Classification rules for high-risk AI systems — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-6","note":"European Commission — AI Act Service Desk"},{"title":"Article 50: Transparency obligations for providers and deployers of certain AI systems — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50","note":"European Commission — AI Act Service Desk"},{"title":"Article 72: Post-market monitoring by providers and post-market monitoring plan — AI Act","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-72","note":"European Commission — AI Act Service Desk"},{"title":"AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1","url":"https://www.nist.gov/itl/ai-risk-management-framework","note":"National Institute of Standards and Technology (NIST)"},{"title":"AI Risks and Trustworthiness — NIST AI RMF section 3","url":"https://airc.nist.gov/airmf-resources/airmf/3-sec-characteristics/","note":"NIST AI Resource Center (AIRC)"},{"title":"Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, NIST AI 100-2 E2025","url":"https://csrc.nist.gov/pubs/ai/100/2/e2025/final","note":"National Institute of Standards and Technology (NIST)"},{"title":"What is AI? Can you make a clear distinction between AI and non-AI systems?","url":"https://oecd.ai/en/wonk/definition","note":"OECD.AI Policy Observatory"},{"title":"Explanatory memorandum on the updated OECD definition of an AI system (OECD Artificial Intelligence Papers No. 8)","url":"https://www.oecd.org/en/publications/explanatory-memorandum-on-the-updated-oecd-definition-of-an-ai-system_623da898-en.html","note":"Organisation for Economic Co-operation and Development (OECD)"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium (W3C)"},{"title":"RFC 3339: Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/rfc/rfc3339","note":"Internet Engineering Task Force (IETF)"},{"title":"ECMA-424: CycloneDX Bill of Materials Specification","url":"https://ecma-international.org/publications-and-standards/standards/ecma-424/","note":"Ecma International"},{"title":"CycloneDX Machine Learning Bill of Materials (ML-BOM / AI-BOM)","url":"https://cyclonedx.org/capabilities/mlbom/","note":"OWASP CycloneDX"},{"title":"ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system","url":"https://www.iso.org/standard/81230.html","note":"ISO/IEC JTC 1/SC 42"},{"title":"Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions","url":"https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence","note":"U.S. Food and Drug Administration (FDA)"},{"title":"Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), consolidated","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng","note":"European Union"},{"title":"OECD Framework for the Classification of AI systems","url":"https://www.oecd.org/en/publications/oecd-framework-for-the-classification-of-ai-systems_cb6d9eca-en.html","note":"Organisation for Economic Co-operation and Development"},{"title":"Artificial Intelligence Risk Management Framework (AI RMF 1.0)","url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf","note":"National Institute of Standards and Technology"},{"title":"ISO/IEC 22989:2022 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology","url":"https://www.iso.org/standard/74296.html","note":"ISO/IEC JTC 1/SC 42"},{"title":"Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law","url":"https://eur-lex.europa.eu/eli/agree_internation/2026/1081/oj/eng","note":"Council of Europe"},{"title":"ISO/IEC 42005:2025 Information technology — Artificial intelligence (AI) — AI system impact assessment","url":"https://webstore.iec.ch/en/publication/107659","note":"ISO/IEC JTC 1/SC 42"}],"openQuestions":["AI literacy obligations (EU AI Act Art. 4, as amended): the base has no coverage at all. Determine from the consolidated act whether literacy measures attach to the AI system record or to the organisation-level AI management system, then site them accordingly rather than importing Grok's roles finding wholesale.","Regulatory sandbox and real-world testing regimes: decide whether 'in sandbox' and 'in real-world testing, not placed on the market' are lifecycle state values in lifecycle-state-and-transitions or warrant a separate finding, and pin the governing articles.","Documentation escrow and keep-until on provider cessation or insolvency, including authorised-representative and Member State arrangements — absent from the base retention and decommissioning finding.","Agent-surface linkage: whether WM-AI-001 should carry an explicit question enumerating linked WM-AI-002 agent records as typed edges, without importing agent semantics.","Energy, compute and environmental footprint: both providers record this as a gap. Search for a primary system-level (not general-purpose-model-level) reporting requirement; if none is found, keep it as a declared gap rather than asserting structure.","Non-EU regimes and the CoE CETS 225 overlay: UK, China generative-AI and algorithm filing, Canada AIDA, Korea, Japan, Brazil and India are unmodelled, and CETS 225 is present in Grok's evidence but carries no accepted structure in the merged draft.","Sector overlays beyond the medical-device change-control example already in the base: financial services model risk, aviation, automotive UNECE WP.29, employment, education, law enforcement and critical infrastructure.","Sources SRC-014 (OECD explanatory memorandum), SRC-019 (ISO/IEC 42001:2023) and SRC-020 (FDA PCCP final guidance) could not be retrieved in full text during this research: SRC-014 and SRC-019 returned HTTP 403 and SRC-020 returned HTTP 404 on direct fetch. Their titles, identifiers and dates were confirmed via publisher catalogue and site-restricted search metadata. No structural node depends on these three alone.","ISO/IEC 22989 (AI concepts and terminology), ISO/IEC 5338 (AI system life cycle processes), ISO/IEC 23894 (AI risk management) and ISO/IEC 42005 (AI system impact assessment) are paywalled and were not consulted. Terminology here therefore follows the OECD and EU definitions, which may diverge from SC 42 vocabulary in places.","General-purpose AI model obligations (systemic-risk thresholds, model documentation to downstream providers, training-content summaries, codes of practice) are deliberately excluded: they attach to the model, not the system, and belong to WM-SFT-004.","Energy, compute and environmental footprint reporting is not modelled.","Conformity assessment procedure detail, notified-body designation and market-surveillance procedural law are referenced but not decomposed.","Sector-specific overlays beyond the medical-device change-control example (financial services, employment, education, critical infrastructure, law enforcement) are not enumerated.","Accessibility requirements are referenced only where transparency obligations invoke them; a full accessibility conformance surface is not modelled.","Human-subject research ethics, worker consultation procedure and collective bargaining interfaces are out of scope.","Full ISO/IEC 42001 Annex A control catalogue and exact control numbering are not reproduced because the paid standard text was not used as a primary extract; secondary numbering of Annex A domains conflicts and is treated as a gap.","ISO/IEC 22989 full clause text for AI system 3.1.4 and human-in/on/over-the-loop definitions remains paywalled; the model uses official scope, preview terms and EU Art. 14 documentation requirements.","Sector overlays such as medical-device AI, aviation, automotive UNECE WP.29 and financial-services model risk are not expanded.","People's Republic of China generative-AI and algorithm-filing rules, Canada's AIDA, and other non-EU national bills are not modelled as classes.","AI software bill of materials formats (SPDX, CycloneDX) and the draft ISO/IEC 24970 logging standard are emerging and not treated as canonical.","Compute, energy and environmental footprint are only a People-and-Planet hint, not a measurement model.","Military and national-defence systems are excluded by CETS 225 and are not given a specialised profile.","Open-source GPAI exemptions, multi-agent systems of systems, and shadow-AI discovery methods are noted as operating risks rather than fully specified findings."],"resources":{"spec":"/models/wm-ai-001-ai-system/spec.yaml","agents":"/models/wm-ai-001-ai-system/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-ai-001"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-ai-001-ai-system/spec.yaml","ver-cy/world-models/card-supplements/wm-ai-001-ai-system.json"],"providers":["Claude","Grok"],"researchStatus":"reviewable-draft","generatedAt":"2026-08-26T11:04:18Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}