{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-ai-007","code":"wm-ai-007-ai-model-registry-entry","url":"https://ver.cy/models/wm-ai-007-ai-model-registry-entry/","name":"AI Model Registry Entry","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"registry","plane":"","domain":["INF.AI.REG"],"industry":["Cross-industry"],"navPath":"NAV.INF.AI.REG","tags":["ai","model","registry","entry","inf.ai.reg"],"facets":{}},"whatItIs":"Owns one registry-entry identity; owning registry, namespace, family and version bindings; catalog description, classifications and stewardship; artifact, technical-contract, lineage, rights, documentation, evaluation, risk, approval, lifecycle, promotion, deployment-observation, availability, access, correction, retention, audit and projection assertions. Model artifact, training run, dataset, source code, build, evaluation, deployment, endpoint, model card, policy, credential, provenance, audit and records masters remain external.","purpose":"Represent one governed, discoverable registry record that binds an AI model family or version to artifacts, technical metadata, lineage, rights, evaluations, approvals, lifecycle and distribution views without absorbing their external masters.","scope":{"in":["Entry identity, registry scope, family and version bindings, aliases, discovery metadata, stewardship, artifact and technical-contract references, lineage, rights and transparency","Evaluation, risk, safety, security, approvals, lifecycle, promotion, deployment observations, availability, access, correction, retention, audit and projections"],"out":["Creating or mutating external model artifact, training, dataset, code, build, evaluation, deployment, endpoint, policy, credential, provenance, audit or records masters","Equating registry entry with model artifact, model card, approval or deployment, or equating digest, signature or popularity with quality and safety","Autonomous approval, publication, signing, revocation, access expansion, disclosure, deployment or destructive cleanup"],"boundaries":[{"neighbor":"WM-SFT-004 ML Model Artifact","distinction":"The unified parent_ids value is an unapproved boundary signal because no relation-ledger edge exists. The entry may reference immutable artifacts but cannot own or mutate their bytes, provenance or lifecycle."},{"neighbor":"WM-AI-006 Model Training / Fine-tuning Run","distinction":"Training owns execution history. The registry entry stores source-qualified run, dataset, code and builder references and bounded lineage summaries."},{"neighbor":"AI Model Evaluation","distinction":"External evaluation masters own datasets, procedures, measurements and conclusions. The entry stores versioned evidence bindings, summaries and approval use."},{"neighbor":"Deployment and endpoint","distinction":"Deployment systems own environment, rollout, endpoint and observed runtime state. The registry records source-qualified references and observations without treating approval or publication as deployment."},{"neighbor":"Model card, system card and technical documentation","distinction":"These are versioned transparency artifacts or projections. The registry entry binds them and selected summaries but does not make every card the canonical record."},{"neighbor":"DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage","distinction":"These are catalog, registry, card, BOM, distribution, provenance, verification and lineage profiles with different scopes. No mapping is universally applicable or assumed lossless."}]},"distinguishingFeatures":["A discoverable catalogue record about a model family or version, not the model bytes themselves.","Keeps registered, approved, published, deployed, deprecated and revoked as independent authority-qualified states.","Points to training runs, evaluations and deployments without owning them.","Treats a digest or signature as byte identity evidence, not as proof of safety or fitness."],"structure":{"bundles":[{"id":"registry-identity-scope-ownership-and-discovery","name":"Registry identity, scope, ownership and discovery","description":"Groups governed registry context for registry identity, scope, ownership and discovery.","layers":[{"id":"entry-root-registry-scope-family-and-version","name":"Entry root, registry scope, family and version","description":"Groups source-qualified registry context for entry root, registry scope, family and version.","findings":[{"id":"entry-identity-registry-namespace-issuer-owner-revision-and-current-head","name":"Entry identity, registry namespace, issuer, owner, revision and current head","description":"Records entry identity, registry namespace, issuer, owner, revision and current head as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish entry identity, registry namespace, issuer, owner, revision and current head?","id":"entry-identity-registry-namespace-issuer-owner-revision-and-current-head-q01","kind":"identity"},{"text":"Who may assert, review, approve, correct or rely on entry identity, registry namespace, issuer, owner, revision and current head, under which authority, purpose and limits?","id":"entry-identity-registry-namespace-issuer-owner-revision-and-current-head-q02","kind":"temporal"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to entry identity, registry namespace, issuer, owner, revision and current head, and which evidence supports them?","id":"entry-identity-registry-namespace-issuer-owner-revision-and-current-head-q03","kind":"validation"}]},{"id":"model-family-version-alias-canonical-uri-duplicate-and-equivalence","name":"Model family, version, alias, canonical URI, duplicate and equivalence","description":"Records model family, version, alias, canonical uri, duplicate and equivalence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish model family, version, alias, canonical uri, duplicate and equivalence?","id":"model-family-version-alias-canonical-uri-duplicate-and-equivalence-q01","kind":"relationship"},{"text":"Who may assert, review, approve, correct or rely on model family, version, alias, canonical uri, duplicate and equivalence, under which authority, purpose and limits?","id":"model-family-version-alias-canonical-uri-duplicate-and-equivalence-q02","kind":"composition"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to model family, version, alias, canonical uri, duplicate and equivalence, and which evidence supports them?","id":"model-family-version-alias-canonical-uri-duplicate-and-equivalence-q03","kind":"privacy"}]}]},{"id":"catalog-description-classification-and-stewardship","name":"Catalog description, classification and stewardship","description":"Groups source-qualified registry context for catalog description, classification and stewardship.","findings":[{"id":"title-summary-keywords-task-modality-language-domain-and-search-facets","name":"Title, summary, keywords, task, modality, language, domain and search facets","description":"Records title, summary, keywords, task, modality, language, domain and search facets as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish title, summary, keywords, task, modality, language, domain and search facets?","id":"title-summary-keywords-task-modality-language-domain-and-search-facets-q01","kind":"classification"},{"text":"Who may assert, review, approve, correct or rely on title, summary, keywords, task, modality, language, domain and search facets, under which authority, purpose and limits?","id":"title-summary-keywords-task-modality-language-domain-and-search-facets-q02","kind":"evidence"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to title, summary, keywords, task, modality, language, domain and search facets, and which evidence supports them?","id":"title-summary-keywords-task-modality-language-domain-and-search-facets-q03","kind":"lifecycle"}]},{"id":"creator-provider-publisher-steward-contact-jurisdiction-and-attribution","name":"Creator, provider, publisher, steward, contact, jurisdiction and attribution","description":"Records creator, provider, publisher, steward, contact, jurisdiction and attribution as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish creator, provider, publisher, steward, contact, jurisdiction and attribution?","id":"creator-provider-publisher-steward-contact-jurisdiction-and-attribution-q01","kind":"ownership"},{"text":"Who may assert, review, approve, correct or rely on creator, provider, publisher, steward, contact, jurisdiction and attribution, under which authority, purpose and limits?","id":"creator-provider-publisher-steward-contact-jurisdiction-and-attribution-q02","kind":"ownership"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to creator, provider, publisher, steward, contact, jurisdiction and attribution, and which evidence supports them?","id":"creator-provider-publisher-steward-contact-jurisdiction-and-attribution-q03","kind":"quality"}]}]}]},{"id":"model-artifact-technical-contract-and-compatibility","name":"Model artifact, technical contract and compatibility","description":"Groups governed registry context for model artifact, technical contract and compatibility.","layers":[{"id":"artifact-release-packaging-and-integrity","name":"Artifact release, packaging and integrity","description":"Groups source-qualified registry context for artifact release, packaging and integrity.","findings":[{"id":"artifact-reference-version-format-distribution-digest-size-and-signature","name":"Artifact reference, version, format, distribution, digest, size and signature","description":"Records artifact reference, version, format, distribution, digest, size and signature as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish artifact reference, version, format, distribution, digest, size and signature?","id":"artifact-reference-version-format-distribution-digest-size-and-signature-q01","kind":"evidence"},{"text":"Who may assert, review, approve, correct or rely on artifact reference, version, format, distribution, digest, size and signature, under which authority, purpose and limits?","id":"artifact-reference-version-format-distribution-digest-size-and-signature-q02","kind":"measurement"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to artifact reference, version, format, distribution, digest, size and signature, and which evidence supports them?","id":"artifact-reference-version-format-distribution-digest-size-and-signature-q03","kind":"security"}]},{"id":"architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies","name":"Architecture, base model, tokenizer, framework, runtime, hardware and dependencies","description":"Records architecture, base model, tokenizer, framework, runtime, hardware and dependencies as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish architecture, base model, tokenizer, framework, runtime, hardware and dependencies?","id":"architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-q01","kind":"composition"},{"text":"Who may assert, review, approve, correct or rely on architecture, base model, tokenizer, framework, runtime, hardware and dependencies, under which authority, purpose and limits?","id":"architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-q02","kind":"exception"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to architecture, base model, tokenizer, framework, runtime, hardware and dependencies, and which evidence supports them?","id":"architecture-base-model-tokenizer-framework-runtime-hardware-and-dependencies-q03","kind":"retention"}]}]},{"id":"interface-capability-intended-use-and-limits","name":"Interface, capability, intended use and limits","description":"Groups source-qualified registry context for interface, capability, intended use and limits.","findings":[{"id":"task-input-output-signature-modality-capability-and-behavior-contract","name":"Task, input, output, signature, modality, capability and behavior contract","description":"Records task, input, output, signature, modality, capability and behavior contract as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish task, input, output, signature, modality, capability and behavior contract?","id":"task-input-output-signature-modality-capability-and-behavior-contract-q01","kind":"requirement"},{"text":"Who may assert, review, approve, correct or rely on task, input, output, signature, modality, capability and behavior contract, under which authority, purpose and limits?","id":"task-input-output-signature-modality-capability-and-behavior-contract-q02","kind":"provenance"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to task, input, output, signature, modality, capability and behavior contract, and which evidence supports them?","id":"task-input-output-signature-modality-capability-and-behavior-contract-q03","kind":"interoperability"}]},{"id":"intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes","name":"Intended, supported, out-of-scope and prohibited use, limitations and failure modes","description":"Records intended, supported, out-of-scope and prohibited use, limitations and failure modes as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish intended, supported, out-of-scope and prohibited use, limitations and failure modes?","id":"intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-q01","kind":"constraint"},{"text":"Who may assert, review, approve, correct or rely on intended, supported, out-of-scope and prohibited use, limitations and failure modes, under which authority, purpose and limits?","id":"intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-q02","kind":"process"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to intended, supported, out-of-scope and prohibited use, limitations and failure modes, and which evidence supports them?","id":"intended-supported-out-of-scope-prohibited-use-limitations-and-failure-modes-q03","kind":"decision"}]}]}]},{"id":"development-lineage-rights-and-transparency","name":"Development lineage, rights and transparency","description":"Groups governed registry context for development lineage, rights and transparency.","layers":[{"id":"training-data-code-build-and-supply-chain-lineage","name":"Training, data, code, build and supply-chain lineage","description":"Groups source-qualified registry context for training, data, code, build and supply-chain lineage.","findings":[{"id":"training-run-dataset-code-configuration-build-builder-and-provenance","name":"Training run, dataset, code, configuration, build, builder and provenance","description":"Records training run, dataset, code, configuration, build, builder and provenance as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish training run, dataset, code, configuration, build, builder and provenance?","id":"training-run-dataset-code-configuration-build-builder-and-provenance-q01","kind":"provenance"},{"text":"Who may assert, review, approve, correct or rely on training run, dataset, code, configuration, build, builder and provenance, under which authority, purpose and limits?","id":"training-run-dataset-code-configuration-build-builder-and-provenance-q02","kind":"validation"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to training run, dataset, code, configuration, build, builder and provenance, and which evidence supports them?","id":"training-run-dataset-code-configuration-build-builder-and-provenance-q03","kind":"state"}]},{"id":"developers-funders-contributors-tools-environment-and-source-documentation","name":"Developers, funders, contributors, tools, environment and source documentation","description":"Records developers, funders, contributors, tools, environment and source documentation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish developers, funders, contributors, tools, environment and source documentation?","id":"developers-funders-contributors-tools-environment-and-source-documentation-q01","kind":"ownership"},{"text":"Who may assert, review, approve, correct or rely on developers, funders, contributors, tools, environment and source documentation, under which authority, purpose and limits?","id":"developers-funders-contributors-tools-environment-and-source-documentation-q02","kind":"privacy"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to developers, funders, contributors, tools, environment and source documentation, and which evidence supports them?","id":"developers-funders-contributors-tools-environment-and-source-documentation-q03","kind":"identity"}]}]},{"id":"license-rights-distribution-and-transparency-documents","name":"License, rights, distribution and transparency documents","description":"Groups source-qualified registry context for license, rights, distribution and transparency documents.","findings":[{"id":"license-copyright-ownership-ip-data-rights-export-and-use-terms","name":"License, copyright, ownership, intellectual property, data rights, export and use terms","description":"Records license, copyright, ownership, intellectual property, data rights, export and use terms as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish license, copyright, ownership, intellectual property, data rights, export and use terms?","id":"license-copyright-ownership-ip-data-rights-export-and-use-terms-q01","kind":"authority"},{"text":"Who may assert, review, approve, correct or rely on license, copyright, ownership, intellectual property, data rights, export and use terms, under which authority, purpose and limits?","id":"license-copyright-ownership-ip-data-rights-export-and-use-terms-q02","kind":"lifecycle"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to license, copyright, ownership, intellectual property, data rights, export and use terms, and which evidence supports them?","id":"license-copyright-ownership-ip-data-rights-export-and-use-terms-q03","kind":"classification"}]},{"id":"model-card-system-card-technical-documentation-disclosure-and-version","name":"Model card, system card, technical documentation, disclosure and version","description":"Records model card, system card, technical documentation, disclosure and version as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish model card, system card, technical documentation, disclosure and version?","id":"model-card-system-card-technical-documentation-disclosure-and-version-q01","kind":"evidence"},{"text":"Who may assert, review, approve, correct or rely on model card, system card, technical documentation, disclosure and version, under which authority, purpose and limits?","id":"model-card-system-card-technical-documentation-disclosure-and-version-q02","kind":"quality"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to model card, system card, technical documentation, disclosure and version, and which evidence supports them?","id":"model-card-system-card-technical-documentation-disclosure-and-version-q03","kind":"relationship"}]}]}]},{"id":"evaluation-risk-safety-security-and-approval","name":"Evaluation, risk, safety, security and approval","description":"Groups governed registry context for evaluation, risk, safety, security and approval.","layers":[{"id":"evaluation-benchmark-quality-and-comparability","name":"Evaluation, benchmark, quality and comparability","description":"Groups source-qualified registry context for evaluation, benchmark, quality and comparability.","findings":[{"id":"evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result","name":"Evaluation dataset, task, metric, threshold, subgroup, robustness and result","description":"Records evaluation dataset, task, metric, threshold, subgroup, robustness and result as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish evaluation dataset, task, metric, threshold, subgroup, robustness and result?","id":"evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-q01","kind":"measurement"},{"text":"Who may assert, review, approve, correct or rely on evaluation dataset, task, metric, threshold, subgroup, robustness and result, under which authority, purpose and limits?","id":"evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-q02","kind":"security"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to evaluation dataset, task, metric, threshold, subgroup, robustness and result, and which evidence supports them?","id":"evaluation-dataset-task-metric-threshold-subgroup-robustness-and-result-q03","kind":"authority"}]},{"id":"evidence-source-method-version-freshness-uncertainty-comparator-and-limit","name":"Evidence source, method, version, freshness, uncertainty, comparator and limit","description":"Records evidence source, method, version, freshness, uncertainty, comparator and limit as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish evidence source, method, version, freshness, uncertainty, comparator and limit?","id":"evidence-source-method-version-freshness-uncertainty-comparator-and-limit-q01","kind":"quality"},{"text":"Who may assert, review, approve, correct or rely on evidence source, method, version, freshness, uncertainty, comparator and limit, under which authority, purpose and limits?","id":"evidence-source-method-version-freshness-uncertainty-comparator-and-limit-q02","kind":"retention"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to evidence source, method, version, freshness, uncertainty, comparator and limit, and which evidence supports them?","id":"evidence-source-method-version-freshness-uncertainty-comparator-and-limit-q03","kind":"requirement"}]}]},{"id":"risk-control-review-and-accountable-decision","name":"Risk, control, review and accountable decision","description":"Groups source-qualified registry context for risk, control, review and accountable decision.","findings":[{"id":"risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference","name":"Risk, privacy, security, safety, bias, misuse, red-team and incident reference","description":"Records risk, privacy, security, safety, bias, misuse, red-team and incident reference as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish risk, privacy, security, safety, bias, misuse, red-team and incident reference?","id":"risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-q01","kind":"security"},{"text":"Who may assert, review, approve, correct or rely on risk, privacy, security, safety, bias, misuse, red-team and incident reference, under which authority, purpose and limits?","id":"risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-q02","kind":"interoperability"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to risk, privacy, security, safety, bias, misuse, red-team and incident reference, and which evidence supports them?","id":"risk-privacy-security-safety-bias-misuse-red-team-and-incident-reference-q03","kind":"constraint"}]},{"id":"reviewer-approval-rejection-exception-human-oversight-and-decision-evidence","name":"Reviewer, approval, rejection, exception, human oversight and decision evidence","description":"Records reviewer, approval, rejection, exception, human oversight and decision evidence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish reviewer, approval, rejection, exception, human oversight and decision evidence?","id":"reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-q01","kind":"decision"},{"text":"Who may assert, review, approve, correct or rely on reviewer, approval, rejection, exception, human oversight and decision evidence, under which authority, purpose and limits?","id":"reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-q02","kind":"decision"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to reviewer, approval, rejection, exception, human oversight and decision evidence, and which evidence supports them?","id":"reviewer-approval-rejection-exception-human-oversight-and-decision-evidence-q03","kind":"event"}]}]}]},{"id":"lifecycle-promotion-publication-and-deployment-bindings","name":"Lifecycle, promotion, publication and deployment bindings","description":"Groups governed registry context for lifecycle, promotion, publication and deployment bindings.","layers":[{"id":"entry-state-events-correction-and-supersession","name":"Entry state events, correction and supersession","description":"Groups source-qualified registry context for entry state events, correction and supersession.","findings":[{"id":"candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked","name":"Candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked","description":"Records candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked?","id":"candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-q01","kind":"lifecycle"},{"text":"Who may assert, review, approve, correct or rely on candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, under which authority, purpose and limits?","id":"candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-q02","kind":"state"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, and which evidence supports them?","id":"candidate-registered-reviewed-approved-published-deprecated-withdrawn-and-revoked-q03","kind":"temporal"}]},{"id":"transition-event-reason-authority-time-correction-merge-split-and-supersession","name":"Transition event, reason, authority, time, correction, merge, split and supersession","description":"Records transition event, reason, authority, time, correction, merge, split and supersession as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish transition event, reason, authority, time, correction, merge, split and supersession?","id":"transition-event-reason-authority-time-correction-merge-split-and-supersession-q01","kind":"event"},{"text":"Who may assert, review, approve, correct or rely on transition event, reason, authority, time, correction, merge, split and supersession, under which authority, purpose and limits?","id":"transition-event-reason-authority-time-correction-merge-split-and-supersession-q02","kind":"identity"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to transition event, reason, authority, time, correction, merge, split and supersession, and which evidence supports them?","id":"transition-event-reason-authority-time-correction-merge-split-and-supersession-q03","kind":"composition"}]}]},{"id":"promotion-alias-release-and-deployment-observation","name":"Promotion, alias, release and deployment observation","description":"Groups source-qualified registry context for promotion, alias, release and deployment observation.","findings":[{"id":"promotion-gate-release-decision-alias-champion-channel-and-rollout-intent","name":"Promotion gate, release decision, alias, champion, channel and rollout intent","description":"Records promotion gate, release decision, alias, champion, channel and rollout intent as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish promotion gate, release decision, alias, champion, channel and rollout intent?","id":"promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-q01","kind":"authority"},{"text":"Who may assert, review, approve, correct or rely on promotion gate, release decision, alias, champion, channel and rollout intent, under which authority, purpose and limits?","id":"promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-q02","kind":"classification"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to promotion gate, release decision, alias, champion, channel and rollout intent, and which evidence supports them?","id":"promotion-gate-release-decision-alias-champion-channel-and-rollout-intent-q03","kind":"evidence"}]},{"id":"deployable-deployed-active-environment-endpoint-compatibility-and-observation","name":"Deployable, deployed, active, environment, endpoint, compatibility and observation","description":"Records deployable, deployed, active, environment, endpoint, compatibility and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish deployable, deployed, active, environment, endpoint, compatibility and observation?","id":"deployable-deployed-active-environment-endpoint-compatibility-and-observation-q01","kind":"state"},{"text":"Who may assert, review, approve, correct or rely on deployable, deployed, active, environment, endpoint, compatibility and observation, under which authority, purpose and limits?","id":"deployable-deployed-active-environment-endpoint-compatibility-and-observation-q02","kind":"relationship"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to deployable, deployed, active, environment, endpoint, compatibility and observation, and which evidence supports them?","id":"deployable-deployed-active-environment-endpoint-compatibility-and-observation-q03","kind":"ownership"}]}]}]},{"id":"distribution-access-retention-audit-and-projections","name":"Distribution, access, retention, audit and projections","description":"Groups governed registry context for distribution, access, retention, audit and projections.","layers":[{"id":"availability-distribution-access-and-use-signals","name":"Availability, distribution, access and use signals","description":"Groups source-qualified registry context for availability, distribution, access and use signals.","findings":[{"id":"landing-page-api-package-oci-location-mirror-availability-and-access-tier","name":"Landing page, API, package, OCI location, mirror, availability and access tier","description":"Records landing page, api, package, oci location, mirror, availability and access tier as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish landing page, api, package, oci location, mirror, availability and access tier?","id":"landing-page-api-package-oci-location-mirror-availability-and-access-tier-q01","kind":"access"},{"text":"Who may assert, review, approve, correct or rely on landing page, api, package, oci location, mirror, availability and access tier, under which authority, purpose and limits?","id":"landing-page-api-package-oci-location-mirror-availability-and-access-tier-q02","kind":"authority"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to landing page, api, package, oci location, mirror, availability and access tier, and which evidence supports them?","id":"landing-page-api-package-oci-location-mirror-availability-and-access-tier-q03","kind":"measurement"}]},{"id":"weight-availability-download-use-adoption-popularity-staleness-and-observation","name":"Weight availability, download, use, adoption, popularity, staleness and observation","description":"Records weight availability, download, use, adoption, popularity, staleness and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish weight availability, download, use, adoption, popularity, staleness and observation?","id":"weight-availability-download-use-adoption-popularity-staleness-and-observation-q01","kind":"measurement"},{"text":"Who may assert, review, approve, correct or rely on weight availability, download, use, adoption, popularity, staleness and observation, under which authority, purpose and limits?","id":"weight-availability-download-use-adoption-popularity-staleness-and-observation-q02","kind":"requirement"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to weight availability, download, use, adoption, popularity, staleness and observation, and which evidence supports them?","id":"weight-availability-download-use-adoption-popularity-staleness-and-observation-q03","kind":"exception"}]}]},{"id":"governance-records-audit-and-interoperability","name":"Governance, records, audit and interoperability","description":"Groups source-qualified registry context for governance, records, audit and interoperability.","findings":[{"id":"role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof","name":"Role, purpose, access, disclosure, audit, retention, hold, tombstone and proof","description":"Records role, purpose, access, disclosure, audit, retention, hold, tombstone and proof as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish role, purpose, access, disclosure, audit, retention, hold, tombstone and proof?","id":"role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-q01","kind":"retention"},{"text":"Who may assert, review, approve, correct or rely on role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, under which authority, purpose and limits?","id":"role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-q02","kind":"constraint"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, and which evidence supports them?","id":"role-purpose-access-disclosure-audit-retention-hold-tombstone-and-proof-q03","kind":"provenance"}]},{"id":"dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection","name":"DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, PROV and OpenLineage projection","description":"Records dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.","questions":[{"text":"What stable identity, registry scope, version-qualified values and explicit unknowns establish dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection?","id":"dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-q01","kind":"interoperability"},{"text":"Who may assert, review, approve, correct or rely on dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, under which authority, purpose and limits?","id":"dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-q02","kind":"event"},{"text":"Which event, effective, observed, recorded, ingested and knowledge times apply to dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, and which evidence supports them?","id":"dcat-mlflow-huggingface-spdx-cyclonedx-oci-slsa-prov-openlineage-projection-q03","kind":"process"}]}]}]}]},"agentConduct":{"may":["Register a model version with artifacts, digests and lineage references.","Attach documentation, model cards and evaluation links.","Answer discovery queries within the caller's access scope.","Flag entries with missing licence, evaluation or risk evidence."],"mustNot":["Approve, publish, sign or revoke an entry.","Widen access to restricted models or documentation.","Deploy a model from the registry.","Claim safety or compliance from a signature or a score.","Delete entries or lineage referenced by deployments."],"requiresHuman":["Approving a model for production or publication.","Revoking or withdrawing a model in use.","Granting access to a restricted model."]},"ethics":{"considerations":["Registry status guides who deploys a model, so wrong approval states can spread harmful systems.","Model documentation must state limits honestly so that users do not apply models outside their tested use.","Licence and rights records protect data creators and model authors."],"affectedParties":["Users and subjects of deployed models","Model developers and rights holders","Deployers relying on approval states"]},"owners":{"steward":"Dimension owner, registry mandate and accountable AI owner","roles":[{"name":"AI system owner and accountable deployer","responsibilities":["Own purpose, risk acceptance, release boundaries and accountable use of registered models."]},{"name":"Model provider or developer","responsibilities":["Supply version-qualified artifacts, technical contract, lineage, rights, use and limitation claims."]},{"name":"Registry owner and steward","responsibilities":["Own entry identity, duplicate resolution, metadata quality, lifecycle history, discoverability and projection integrity."]},{"name":"Independent evaluator, safety and security reviewer","responsibilities":["Review evaluation, abuse, privacy, security, safety and red-team evidence without becoming the artifact owner."]},{"name":"Release and approval authority","responsibilities":["Make attributable approval, exception, publication, withdrawal and revocation decisions within mandate."]},{"name":"Deployment and platform operator","responsibilities":["Provide source-qualified environment, deployment, endpoint, compatibility and observed-state references."]},{"name":"Legal, privacy and records steward","responsibilities":["Own license, data-rights, IP, export, disclosure, correction, hold, retention and disposition profiles."]}],"masterSystems":[]},"relations":[{"target":"WM-SFT-004 ML Model Artifact","type":"references","note":"Represent the unfrozen parent boundary as a non-owning artifact and version binding without composition, mutation, release or cascade authority."},{"target":"WM-AI-006 Model Training / Fine-tuning Run and AI Model Evaluation","type":"references","note":"Resolve authoritative development lineage and evaluation evidence without absorbing execution or measurement masters."},{"target":"Deployment, endpoint, dataset, code, build, policy, credential, provenance, audit and records models","type":"references","note":"Resolve authoritative lifecycle, control and evidence records without absorbing their ownership."},{"target":"DCAT 3, MLflow, Hugging Face, SPDX 3.0.1 AI, CycloneDX 1.7, OCI 1.1.1, SLSA 1.1, Sigstore, PROV-O and OpenLineage 1.53.0","type":"aligned","note":"Project release-pinned catalog, registry, card, BOM, distribution, provenance, verification and lineage views with information-loss declarations."},{"target":"WM-SFT-004 ML Model Artifact","type":"neighbor","note":"The unified parent_ids value is an unapproved boundary signal because no relation-ledger edge exists. The entry may reference immutable artifacts but cannot own or mutate their bytes, provenance or lifecycle."},{"target":"WM-AI-006 Model Training / Fine-tuning Run","type":"neighbor","note":"Training owns execution history. The registry entry stores source-qualified run, dataset, code and builder references and bounded lineage summaries."},{"target":"AI Model Evaluation","type":"neighbor","note":"External evaluation masters own datasets, procedures, measurements and conclusions. The entry stores versioned evidence bindings, summaries and approval use."},{"target":"Deployment and endpoint","type":"neighbor","note":"Deployment systems own environment, rollout, endpoint and observed runtime state. The registry records source-qualified references and observations without treating approval or publication as deployment."},{"target":"Model card, system card and technical documentation","type":"neighbor","note":"These are versioned transparency artifacts or projections. The registry entry binds them and selected summaries but does not make every card the canonical record."},{"target":"DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage","type":"neighbor","note":"These are catalog, registry, card, BOM, distribution, provenance, verification and lineage profiles with different scopes. No mapping is universally applicable or assumed lossless."},{"target":"WM-SFT-004","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier for each registry entry, assertion, decision, event or projection, qualified by issuer, namespace and record kind.","Governed globally resolvable registry-entry IRI.","Dimension UUID or ULID when neither preceding identifier exists."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A registry entry names a registry, a namespace, a model name and version, artifact digests and a lifecycle state.","Often confused with the model artifact, a model card, a deployment endpoint or a package in a software repository."]},"capabilities":{"applicability":"required","items":["Register an AI model entry: Governed operation to register an ai model entry without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Bind family, version and artifacts: Governed operation to bind family, version and artifacts without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Describe contract, use and limitations: Governed operation to describe contract, use and limitations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Attach lineage, rights and transparency: Governed operation to attach lineage, rights and transparency without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Attach evaluation, risk and safety evidence: Governed operation to attach evaluation, risk and safety evidence without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Review, approve, reject or except: Governed operation to review, approve, reject or except without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Publish, deprecate, withdraw, revoke or supersede: Governed operation to publish, deprecate, withdraw, revoke or supersede without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Bind deployment observations: Governed operation to bind deployment observations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Correct, merge, split and resolve identity: Governed operation to correct, merge, split and resolve identity without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.","Query, project, disclose, retain and audit: Governed operation to query, project, disclose, retain and audit without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup."]},"hazards":{"applicability":"required","items":["Deployment of a revoked or unapproved version.","Artifact substitution when digests are not checked.","Missing licence leading to unlawful use."]},"interfaces":{"applicability":"required","items":["W3C DCAT 3 for catalogue description.","SPDX 3.0 AI profile.","CycloneDX machine learning bill of materials (ECMA-424).","OCI artifact and distribution specifications.","Sigstore and SLSA for signing and provenance.","W3C PROV-O."]},"context":{"applicability":"required","items":["Technical documentation, data rights, privacy, intellectual property, export, security, safety, disclosure, retention and high-risk AI obligations depend on jurisdiction, industry and use case.","The EU AI Act and GDPR are European Union profiles; NIST publications are voluntary United States public-authority guidance unless adopted by policy or contract.","DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage are versioned profiles, not universal lossless schemas."]}},"sources":[{"title":"Artificial Intelligence Risk Management Framework (AI RMF 1.0)","url":"https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10","note":"National Institute of Standards and Technology"},{"title":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf","note":"National Institute of Standards and Technology"},{"title":"Secure Software Development Practices for Generative AI and Dual-Use Foundation Models","url":"https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218A.pdf","note":"National Institute of Standards and Technology"},{"title":"Regulation (EU) 2024/1689 Artificial Intelligence Act","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","note":"European Union"},{"title":"Regulation (EU) 2016/679 General Data Protection Regulation","url":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","note":"European Union"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"Data Catalog Vocabulary (DCAT) Version 3","url":"https://www.w3.org/TR/vocab-dcat-3/","note":"World Wide Web Consortium"},{"title":"Model Registry Workflows","url":"https://mlflow.org/docs/latest/ml/model-registry/workflow/","note":"MLflow"},{"title":"Model Cards","url":"https://huggingface.co/docs/hub/model-cards","note":"Hugging Face"},{"title":"Model Cards for Model Reporting","url":"https://research.google/pubs/model-cards-for-model-reporting/","note":"Google Research"},{"title":"SPDX Specification AI Profile","url":"https://spdx.github.io/spdx-spec/v3.0.1/model/AI/AI/","note":"SPDX"},{"title":"CycloneDX Bill of Materials Specification","url":"https://github.com/CycloneDX/specification","note":"OWASP CycloneDX"},{"title":"SLSA Terminology","url":"https://slsa.dev/spec/v1.1/terminology","note":"Open Source Security Foundation"},{"title":"OCI Distribution Specification","url":"https://github.com/opencontainers/distribution-spec/releases/tag/v1.1.1","note":"Open Container Initiative"},{"title":"Verifying Signatures","url":"https://docs.sigstore.dev/cosign/verifying/verify/","note":"Sigstore"},{"title":"OpenLineage Object Model","url":"https://openlineage.io/docs/spec/object-model/","note":"OpenLineage"},{"title":"Date and Time on the Internet: Timestamps","url":"https://www.rfc-editor.org/info/rfc3339/","note":"Internet Engineering Task Force"}],"openQuestions":["Approve or reject the WM-SFT-004 parent boundary and register training, evaluation, deployment, endpoint, dataset, code, policy, credential, provenance and records relations.","Create registry profiles for model family and version semantics, aliasing, environments, approvals, publication, deprecation, withdrawal, revocation, deletion and access.","Validate jurisdiction and organization-specific model and data rights, IP, license, export, privacy, security, safety, disclosure, retention and accountable-release policies.","Test release-pinned DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage mappings with conformance, round-trip and information-loss evidence.","Refresh the NIST AI RMF mapping after a new normative revision and obtain supplemental independent external review before canonical promotion.","Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.","The unified row parent_ids WM-SFT-004 has no frozen relation-ledger edge and grants no composition, ownership, mutation, release or cascade authority.","Model registries differ on family, version, alias, environment, approval, deletion and access semantics and require explicit profiles.","NIST AI RMF 1.0 is under revision; this result pins the inspected 1.0 publication and does not predict the revision."],"resources":{"spec":"/models/wm-ai-007-ai-model-registry-entry/spec.yaml","agents":"/models/wm-ai-007-ai-model-registry-entry/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/publications/wm-ai-007-ai-model-registry-entry"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-ai-007-ai-model-registry-entry/spec.yaml","ver-cy/world-models/card-supplements/wm-ai-007-ai-model-registry-entry.json"],"providers":["Codex"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-06T11:50:58Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}