{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-sft-004","code":"wm-sft-004-ml-model-artifact","url":"https://ver.cy/models/wm-sft-004-ml-model-artifact/","name":"ML Model Artifact","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"entity","plane":"","domain":["INF.SFT.ML"],"industry":["Cross-industry"],"navPath":"NAV.INF.SFT.ML","tags":["ml","model","artifact","inf.sft.ml"],"facets":{}},"whatItIs":"Scope is the trained, versioned, serializable ML model artifact: the weight set plus the accompanying configuration, interface contract, documentation, licence, provenance and integrity evidence that travel with it. The model covers identity and versioning, classification, derivation and data provenance, supply-chain integrity, packaging and interface, attached performance and safety evidence, rights and distribution, and lifecycle stewardship through deletion. It stops at the boundary where a sibling model owns the concept: the artifact references those neighbours rather than restating them.","purpose":"Provide the governed, format-neutral context an AI agent needs to identify, inspect, produce, package, release, verify, operate and retire a trained machine-learning model artifact as a distinct object of record, separate from the AI system that embeds it, the training run that produced it and the evaluation that assesses it.","scope":{"in":["Canonical identity, version labels, immutable revision pins and content digests of a released artifact","Classification: architecture family, parameter scale, task, modality, autonomy and regulatory status (e.g. GPAI, systemic risk)","Derivation lineage from base models (fine-tune, adapter, quantization, merge, distillation) and inherited terms","Provenance references to the producing run, resolved build dependencies and training/validation/test data sources","Cryptographic signing, signed file manifests, transparency-log evidence and integrity verification policy","Machine-readable bill of materials for model, data and software components","Serialization format, precision/quantization, sharding and packaged component inventory","Declared input/output/parameter signature, modality, context limits and required runtime, operator set and hardware","Evaluation results, decision thresholds, intended use, limitations, fairness factors, safety assessment and energy footprint attached to this artifact revision","Licence, use restrictions, copyright/TDM policy, distribution channels, access gating, export control and residency","Lifecycle states and transitions, deprecation, retention, deletion evidence, ownership and documentation obligations"],"out":["The AI system or product that embeds the artifact, including its user interface, human oversight design and post-market monitoring plan (WM-AI-001)","The training run itself as a process record: schedule, orchestration, checkpoints, cost accounting and operator actions (WM-AI-006)","Evaluation campaign design, benchmark definition and independent evaluation reports as first-class records (WM-AI-003)","Dataset entities: their internal structure, record-level schema, distribution and licensing (dataset sibling model; Croissant-aligned)","Serving infrastructure, endpoints, autoscaling, latency SLOs and runtime telemetry","Compute hardware, accelerator inventory and data-centre facilities","Legal entities, contracts and personnel records referenced as owners or providers","Prompt templates, agent definitions, tool schemas and orchestration graphs built on top of the artifact","Source code repositories and general software packages, except where packaged as artifact components"],"boundaries":[{"neighbor":"WM-AI-001 AI System","distinction":"The artifact is the model as a versioned object; the AI system is the deployed sociotechnical system that uses it. Obligations attached to intended purpose, human oversight and post-market monitoring sit on the system; the artifact carries only the model-level documentation the system needs to satisfy them. The EU AI Act reflects this split by giving GPAI models their own Article 53 track separate from the high-risk system track."},{"neighbor":"WM-AI-006 Training Run","distinction":"The producing run is an event with its own lifecycle, parameters and byproducts; the artifact is its output subject. Provenance predicates keep these distinct: the run appears as buildDefinition/runDetails, the artifact as the attestation subject identified by digest. This model stores only the resolvable run reference and the recorded build inputs, not the run record."},{"neighbor":"WM-AI-003 Evaluation","distinction":"An evaluation is an assessment activity with its own protocol, evaluator and independence status. The artifact carries reported results, their measurement time and any decision thresholds, but the authoritative evaluation record and its methodology remain in the evaluation model. Attached results are claims about a revision, not proof of conformity."},{"neighbor":"Dataset (candidate sibling model)","distinction":"Training, validation and test datasets are independent entities with their own metadata, provenance and licensing vocabulary. This model records dataset references, curation methodology summaries and the published training-content summary; it does not model dataset structure or record-level semantics."},{"neighbor":"Software Package / SBOM component","distinction":"An ML model artifact is a distinct component type from ordinary software: BOM standards give it its own type (machine-learning-model) and its own descriptive object. Framework and library dependencies are referenced as components, not absorbed into this model."},{"neighbor":"Digital file / OCI blob","distinction":"Content digests give byte-level, content-addressable identity to each blob, but a model artifact is an aggregate of blobs with an identity that survives repackaging and re-serialization. Digest is an integrity and pinning key; it is not the business identity of the artifact."}]},"distinguishingFeatures":["Models the serialised weights plus documentation and provenance, not the AI system that deploys them.","Separates the artifact from the training run that produced it and the evaluations that describe it.","Binds a release to integrity evidence such as content hashes, unlike a generic file or OCI blob.","Carries a licence and regulatory classification as release preconditions."],"structure":{"bundles":[{"id":"bnd-identity-classification","name":"Identity and Classification","description":"What this artifact is, how it is unambiguously named and pinned, how it is typed, and which regulatory status attaches to it.","layers":[{"id":"lyr-artifact-identity","name":"Identity, versioning and content addressing","description":"Canonical identifiers, alias resolution, version semantics, immutable revision pinning and the separation of release time from ingestion time.","findings":[{"id":"fnd-canonical-identity","name":"Canonical identity and identifier set","description":"The authoritative identifier for the artifact, the alias identifiers that resolve to it in other ecosystems, and what level of abstraction each identifier denotes.","questions":[{"text":"Which system of record assigns the authoritative identifier for this model artifact, and what is that identifier?","id":"q-identity-authority","kind":"identity"},{"text":"Which alternate identifiers resolve to the same artifact across registries, package formats and BOM documents?","id":"q-identity-alias-set","kind":"interoperability"},{"text":"Does the identifier denote the abstract model family, a released version, or one immutable serialized snapshot?","id":"q-identity-abstraction-level","kind":"definition"},{"text":"How are identifier collisions, repository renames and namespace transfers detected and reconciled?","id":"q-identity-collision-handling","kind":"validation"}]},{"id":"fnd-version-lineage","name":"Version, revision and immutable pinning","description":"Version scheme, the immutable revision or digest that pins exact bytes, supersession chains, and control of mutable pointers.","questions":[{"text":"What versioning scheme applies, and which change classes trigger a major, minor or patch increment?","id":"q-version-scheme","kind":"classification"},{"text":"Which immutable revision or content digest pins the exact bytes referenced by a given version label?","id":"q-revision-pin","kind":"identity"},{"text":"Which artifact version supersedes or is superseded by this one, and is the predecessor still resolvable?","id":"q-version-supersession","kind":"lifecycle"},{"text":"Which mutable pointers may reference this artifact, and how is pointer drift detected and controlled?","id":"q-mutable-pointer-control","kind":"constraint"},{"text":"When was this version released, and how does release time differ from the time it was ingested into the registry of record?","id":"q-release-versus-ingestion-time","kind":"temporal"}]}]},{"id":"lyr-classification-taxonomy","name":"Technical and regulatory classification","description":"Typing of the artifact by architecture, task, modality and autonomy, and the regulatory status that determines which obligations apply.","findings":[{"id":"fnd-model-taxonomy","name":"Model type, architecture family and task classification","description":"Controlled classification of the artifact by architecture family, parameter scale, task, application domain and decision autonomy.","questions":[{"text":"What type of model is this by architecture family, specific architecture and parameter count?","id":"q-model-type-value","kind":"classification"},{"text":"Which task or pipeline classification describes the artifact's primary intended function?","id":"q-task-classification","kind":"classification"},{"text":"What application domain and level of decision autonomy is the artifact characterised for?","id":"q-domain-autonomy","kind":"definition"},{"text":"Which controlled vocabulary governs each classification value, and who may extend it?","id":"q-taxonomy-governance","kind":"authority"}]},{"id":"fnd-regulatory-status","name":"Regulatory classification and applicable obligations","description":"Whether the artifact is a general-purpose AI model, whether it crosses a systemic-risk threshold, which jurisdictions apply, and who holds provider obligations.","questions":[{"text":"Is the artifact a general-purpose AI model, and does it meet the systemic-risk threshold?","id":"q-gpai-status","kind":"classification"},{"text":"Does a free and open-source release exempt this artifact from specific documentation duties, and on what evidence?","id":"q-open-source-exemption","kind":"exception"},{"text":"In which jurisdictions is the artifact placed on the market or put into service, and which regimes therefore apply?","id":"q-placement-jurisdiction","kind":"spatial"},{"text":"Which legal entity holds provider obligations, and when does that role transfer to a downstream modifier?","id":"q-obligation-holder","kind":"authority"}]}]}]},{"id":"bnd-provenance-integrity","name":"Provenance, Lineage and Supply-Chain Integrity","description":"Where the artifact came from, what it was derived from, what data underlies it, and how a consumer can prove that the bytes are the ones the producer signed.","layers":[{"id":"lyr-production-provenance","name":"Production and derivation provenance","description":"The producing run, the base models the artifact derives from, and the data corpora behind training, validation and testing.","findings":[{"id":"fnd-producing-run","name":"Producing training or build run","description":"Resolvable reference to the run that produced the artifact, the builder identity that attests it, the recorded inputs and reproducibility status.","questions":[{"text":"Which training or build run produced this artifact, and is that run reference resolvable today?","id":"q-produced-by-run","kind":"provenance"},{"text":"Which build platform issued the provenance attestation, and what trust level does its builder identity carry?","id":"q-builder-trust","kind":"security"},{"text":"What external parameters, internal parameters and resolved dependencies were recorded for the producing run?","id":"q-build-inputs","kind":"composition"},{"text":"Can the artifact be re-derived from the recorded inputs, and which nondeterminism sources are documented?","id":"q-reproducibility-status","kind":"quality"},{"text":"What compute resources and wall-clock training time were consumed to produce the artifact?","id":"q-training-compute-effort","kind":"measurement"}]},{"id":"fnd-derivation-lineage","name":"Derivation lineage from base models","description":"Which upstream models the artifact derives from, by which operation, and which upstream terms propagate downstream.","questions":[{"text":"Which base model or models is this artifact derived from, and by which derivation operation?","id":"q-base-model-derivation","kind":"relationship"},{"text":"How deep is the derivation chain, and is every upstream artifact individually identifiable?","id":"q-lineage-chain-depth","kind":"composition"},{"text":"If the artifact is a merge, what are the constituent models and the combination method or weights?","id":"q-merge-recipe","kind":"composition"},{"text":"Which upstream licence terms, use restrictions or attribution duties propagate to this artifact?","id":"q-inherited-terms","kind":"constraint"}]},{"id":"fnd-training-data-provenance","name":"Training, validation and test data provenance","description":"The datasets behind the artifact, their type, provenance and curation, the published training-content summary, and the presence of sensitive personal data.","questions":[{"text":"What datasets, of what type and provenance, and with what curation methodology, underlie training, validation and testing?","id":"q-data-sources-curation","kind":"provenance"},{"text":"Is a sufficiently detailed public summary of training content required, and where is the current version published?","id":"q-training-content-summary","kind":"requirement"},{"text":"Does the training corpus contain sensitive or personal information, and under what lawful basis was it processed?","id":"q-sensitive-personal-data","kind":"privacy"},{"text":"How were data partitioned into training, validation and test splits, and was contamination between them assessed?","id":"q-split-integrity","kind":"validation"}]}]},{"id":"lyr-supply-chain-integrity","name":"Integrity, signing and composition transparency","description":"Cryptographic proof that the artifact is unaltered and attributable, and machine-readable disclosure of what it is made of.","findings":[{"id":"fnd-signature-integrity","name":"Cryptographic signing and integrity verification","description":"Signature presence, signing identity and method, the manifest of per-file digests, transparency evidence and the required verification outcome.","questions":[{"text":"Is the artifact signed, by which identity, and under which signing method?","id":"q-signature-identity-method","kind":"security"},{"text":"Which files are covered by the signed manifest, and how are uncovered files treated at load time?","id":"q-manifest-coverage","kind":"validation"},{"text":"Is the signing event recorded in an append-only log whose inclusion proof a verifier can check?","id":"q-transparency-evidence","kind":"evidence"},{"text":"What verification outcome is required before the artifact may be promoted, distributed or served?","id":"q-verification-gate","kind":"requirement"}]},{"id":"fnd-bom-composition","name":"Bill of materials and component transparency","description":"Machine-readable enumeration of the model, data and software components the artifact comprises or depends on, and how it is kept current.","questions":[{"text":"Does a machine-readable bill of materials enumerate the artifact's model, data and software components?","id":"q-bom-presence","kind":"composition"},{"text":"Which BOM format and version is authoritative, and how are parallel formats kept consistent?","id":"q-bom-format-authority","kind":"interoperability"},{"text":"Which third-party components introduce known vulnerabilities or unsafe deserialisation paths?","id":"q-unsafe-component-exposure","kind":"security"},{"text":"When is the BOM regenerated, and how is it bound to a specific artifact revision?","id":"q-bom-refresh-binding","kind":"process"}]}]}]},{"id":"bnd-composition-interface","name":"Technical Composition and Interface Contract","description":"How the artifact is serialized and packaged, which components it comprises, what interface it exposes to callers, and what runtime it needs.","layers":[{"id":"lyr-serialization-packaging","name":"Serialization and packaging","description":"Weight file format, numeric precision and quantization, sharding, and the role-typed inventory of packaged components.","findings":[{"id":"fnd-serialization-precision","name":"Serialization format, precision and quantization","description":"The on-disk format and version of the weights, the numeric precision or quantization scheme, safe-loading properties and shard layout.","questions":[{"text":"In which serialization format are the weights stored, and at which version of that format?","id":"q-serialization-format","kind":"definition"},{"text":"What numeric precision or quantization scheme do the stored tensors use, and against which reference precision?","id":"q-precision-quantization","kind":"measurement"},{"text":"Does the format permit arbitrary code execution on load, and what mitigation is enforced?","id":"q-safe-loading","kind":"security"},{"text":"How is the artifact sharded across files, and how is shard completeness verified before use?","id":"q-shard-completeness","kind":"validation"}]},{"id":"fnd-component-inventory","name":"Packaged component inventory","description":"Which components are mandatory versus optional, what role each plays, how the model card is bound to the revision, and the packaging envelope used.","questions":[{"text":"Which components are mandatory for the artifact to be loadable, and which are optional accompaniments?","id":"q-required-components","kind":"composition"},{"text":"What role does each packaged component play — weights, weight configuration, code, documentation or dataset?","id":"q-component-roles","kind":"classification"},{"text":"How is the human-readable model card bound to the exact artifact revision it describes?","id":"q-card-revision-binding","kind":"relationship"},{"text":"Into which packaging or registry envelope is the component set published?","id":"q-packaging-envelope","kind":"interoperability"}]}]},{"id":"lyr-interface-execution","name":"Interface contract and execution environment","description":"The declared call contract of the artifact and the runtime, operator-set and hardware conditions under which that contract holds.","findings":[{"id":"fnd-io-signature","name":"Input/output signature and modality","description":"Declared schema for inputs, outputs and inference parameters, supported modalities, size and context limits, and caller validation.","questions":[{"text":"What is the declared schema of the artifact's inputs, outputs and inference parameters?","id":"q-io-schema","kind":"definition"},{"text":"Which input and output modalities and formats does the artifact accept and produce?","id":"q-io-modality","kind":"classification"},{"text":"What maximum input size, context window or sequence limits constrain a valid call?","id":"q-io-limits","kind":"constraint"},{"text":"How is a caller's payload validated against the declared signature before inference runs?","id":"q-io-validation","kind":"validation"},{"text":"Which operator set, graph IR version or tokenizer vocabulary must a runtime support to execute the artifact?","id":"q-runtime-opset-requirement","kind":"interoperability"}]},{"id":"fnd-execution-environment","name":"Execution environment and runtime dependencies","description":"Runtimes and library flavors that can load the artifact, hardware minimums, pinned production versions and behaviour outside the certified envelope.","questions":[{"text":"Which runtime, library and flavor combinations can load and execute this artifact?","id":"q-runtime-loadability","kind":"requirement"},{"text":"What accelerator, memory and driver minimums are required for inference at the declared precision?","id":"q-hardware-minimums","kind":"constraint"},{"text":"Which exact dependency versions were used at production time, and which are certified for serving?","id":"q-environment-pinning","kind":"provenance"},{"text":"What happens when the artifact runs outside its certified environment, and is that configuration blocked or only flagged?","id":"q-uncertified-execution","kind":"exception"}]}]}]},{"id":"bnd-evidence-behaviour","name":"Evidence, Behaviour and Declared Limits","description":"What is known and claimed about how the artifact behaves: measured results, intended and prohibited use, safety and fairness evidence, and environmental cost.","layers":[{"id":"lyr-performance-evidence","name":"Performance evidence and declared use","description":"Reported metrics with their provenance and thresholds, and the declared boundary of appropriate use.","findings":[{"id":"fnd-evaluation-attachment","name":"Attached evaluation results and their evidentiary status","description":"Which results are attached to this revision, who produced them under which protocol, what thresholds they are judged against, and whether they are still current.","questions":[{"text":"Which metrics, on which datasets and splits, are reported for this artifact revision?","id":"q-reported-metrics","kind":"measurement"},{"text":"Who produced each reported result, under which protocol, and is it independently reproducible?","id":"q-evaluation-provenance","kind":"evidence"},{"text":"What decision thresholds are attached to each metric for promotion, rejection or rollback?","id":"q-decision-threshold","kind":"decision"},{"text":"As of when was each result measured, and does it still apply to the current revision?","id":"q-evaluation-currency","kind":"temporal"}]},{"id":"fnd-intended-use-limits","name":"Intended use, users and technical limitations","description":"The declared purpose boundary: intended tasks and users, out-of-scope or prohibited uses, documented limitations and trade-offs, and explainability information.","questions":[{"text":"What are the intended tasks, intended users and in-scope use cases for this artifact?","id":"q-intended-use","kind":"definition"},{"text":"Which uses are explicitly out of scope or prohibited by the acceptable use policy?","id":"q-out-of-scope-use","kind":"constraint"},{"text":"Which technical limitations and performance trade-offs are known and documented?","id":"q-known-limitations","kind":"quality"},{"text":"What explainability or interpretability information accompanies the artifact?","id":"q-explainability-information","kind":"evidence"}]}]},{"id":"lyr-risk-safety-impact","name":"Risk, fairness and environmental impact","description":"Safety assessment and adversarial testing, disaggregated fairness evidence, and the energy and emissions footprint of the artifact.","findings":[{"id":"fnd-safety-adversarial","name":"Safety risk assessment and adversarial testing","description":"The safety assessment performed on the artifact, adversarial testing conducted, mitigations bound to the weights themselves, and re-assessment triggers.","questions":[{"text":"What safety risk assessment has been performed on the artifact, and which residual risks remain?","id":"q-safety-assessment","kind":"evidence"},{"text":"What internal or external adversarial testing was conducted, by whom, and with what results?","id":"q-adversarial-testing","kind":"process"},{"text":"Which mitigations are bound to the artifact itself rather than to the system around it?","id":"q-embedded-mitigations","kind":"requirement"},{"text":"Which events trigger re-assessment of the artifact's safety profile?","id":"q-reassessment-trigger","kind":"event"}]},{"id":"fnd-fairness-bias","name":"Fairness, bias and evaluation factors","description":"Relevant evaluation factors, disaggregated performance across groups and intersections, bias detection measures, and who accepts the fairness evidence.","questions":[{"text":"Which demographic, environmental and instrumentation factors are relevant to disaggregated evaluation of this artifact?","id":"q-evaluation-factors","kind":"classification"},{"text":"How does performance vary across the relevant factor groups and their intersections?","id":"q-disaggregated-performance","kind":"measurement"},{"text":"What bias detection and mitigation measures were applied to the data and to the model?","id":"q-bias-detection-measures","kind":"process"},{"text":"Who accepts that fairness evidence is sufficient for the intended deployment context?","id":"q-fairness-acceptance","kind":"authority"}]},{"id":"fnd-environmental-footprint","name":"Energy and environmental footprint","description":"Energy consumed for training, fine-tuning and inference, reported emissions equivalent, whether figures are measured or estimated, and the covered period.","questions":[{"text":"How much energy was consumed for training, for fine-tuning and per unit of inference?","id":"q-energy-consumption","kind":"measurement"},{"text":"What greenhouse-gas equivalent is reported, and under which accounting method and grid assumptions?","id":"q-emissions-accounting","kind":"measurement"},{"text":"Are the reported figures measured or estimated, and what uncertainty is stated?","id":"q-footprint-basis","kind":"quality"},{"text":"Which time window and which hardware fleet do the reported figures cover?","id":"q-footprint-period","kind":"temporal"}]}]}]},{"id":"bnd-rights-distribution","name":"Rights, Distribution and Access","description":"Who may hold, use, redistribute and modify the artifact, on what terms, through which channels, and under which access and export constraints.","layers":[{"id":"lyr-licensing-rights","name":"Licensing and rights","description":"Licence identification across components, use restrictions, attribution duties, copyright policy and third-party rights handling.","findings":[{"id":"fnd-license-terms","name":"Licence, use restrictions and attribution","description":"The licence governing the weights and each other component, restrictions it imposes, and required attribution or notice.","questions":[{"text":"Which licence governs the weights, and is it expressed as a resolvable standard identifier or a custom document?","id":"q-license-identifier","kind":"identity"},{"text":"Do weights, code, tokenizer and documentation carry different licences?","id":"q-component-license-divergence","kind":"composition"},{"text":"Which field-of-use, redistribution or derivative restrictions does the licence impose?","id":"q-use-restriction","kind":"constraint"},{"text":"What attribution or notice must a downstream user reproduce?","id":"q-attribution-duty","kind":"requirement"}]},{"id":"fnd-ip-copyright-policy","name":"Copyright policy, rights reservation and claims","description":"The documented copyright compliance policy, how machine-readable rights reservations were honoured during data acquisition, and how post-release claims are handled.","questions":[{"text":"Is there a documented policy for complying with copyright law, and where is it maintained?","id":"q-copyright-policy","kind":"requirement"},{"text":"How were machine-readable rights reservations detected and honoured during data acquisition?","id":"q-rights-reservation-handling","kind":"process"},{"text":"What process handles third-party rights claims raised against the artifact after release?","id":"q-third-party-claim","kind":"exception"},{"text":"Who bears liability for rights infringement arising from the artifact or its outputs?","id":"q-rights-liability","kind":"ownership"}]}]},{"id":"lyr-distribution-access","name":"Distribution and access control","description":"Where the artifact is published, in what release mode, how mirrors are validated, and what gating, export and residency constraints apply.","findings":[{"id":"fnd-distribution-channels","name":"Release, distribution channels and mirrors","description":"Channels through which the artifact is distributed, which is authoritative, how mirrors are validated, and how a release is withdrawn.","questions":[{"text":"Through which channels is the artifact distributed, and which one is authoritative?","id":"q-distribution-channels","kind":"process"},{"text":"Is the release open-weights, gated, API-only or internal-only?","id":"q-release-mode","kind":"classification"},{"text":"How is a mirrored or cached copy proven equivalent to the authoritative release?","id":"q-mirror-equivalence","kind":"validation"},{"text":"What is the procedure for withdrawing a released artifact from each channel?","id":"q-release-withdrawal","kind":"event"}]},{"id":"fnd-access-gating","name":"Access gating, confidentiality and export control","description":"Default access rule for the weights, the conditions that gate access, export-control classification and permitted storage or processing locations.","questions":[{"text":"What is the default access rule for the artifact's weights, and who may grant exceptions?","id":"q-default-access-rule","kind":"access"},{"text":"Which conditions gate access, and how is satisfaction of each condition evidenced?","id":"q-gating-conditions","kind":"security"},{"text":"Is the artifact subject to export control or sanctions screening, and under which classification?","id":"q-export-control","kind":"constraint"},{"text":"Where may the weights be stored and processed, and which residency constraints apply?","id":"q-residency-constraint","kind":"spatial"}]}]}]},{"id":"bnd-lifecycle-stewardship","name":"Lifecycle, Stewardship and Downstream Linkage","description":"How the artifact moves through controlled states, who is accountable, what documentation must exist and stay current, how it is retained and deleted, and how downstream use links back.","layers":[{"id":"lyr-lifecycle-change","name":"Lifecycle states, change control and end of life","description":"State model and transition authority, deprecation, retention obligations, deletion scope and destruction evidence.","findings":[{"id":"fnd-lifecycle-state","name":"Lifecycle state model and transitions","description":"The controlled states the artifact can occupy, who approves each transition against which gates, when transitions occurred, and how promotions are rolled back.","questions":[{"text":"Which lifecycle states can this artifact occupy, and which state is it in now?","id":"q-lifecycle-state-set","kind":"state"},{"text":"Who is authorised to approve each state transition, and against which gate criteria?","id":"q-transition-authority","kind":"authority"},{"text":"When did each state transition occur, and when was each transition recorded?","id":"q-transition-timing","kind":"temporal"},{"text":"Under what conditions may a promotion be rolled back, and what happens to artifacts that depend on it?","id":"q-promotion-rollback","kind":"exception"}]},{"id":"fnd-retention-deletion","name":"Deprecation, retention and deletion","description":"How deprecation is declared, how long the artifact and its documentation must be kept, exactly what is destroyed at end of life, and what evidences destruction.","questions":[{"text":"What marks this artifact deprecated, and which replacement is announced to consumers?","id":"q-deprecation-declaration","kind":"lifecycle"},{"text":"How long must the artifact and its technical documentation be retained, and on what legal or contractual basis?","id":"q-retention-period","kind":"retention"},{"text":"What exactly is deleted at end of life — weights, derivatives, caches, mirrors, logs — and what must be preserved?","id":"q-deletion-scope","kind":"retention"},{"text":"What evidence proves deletion or destruction, and who attests to it?","id":"q-destruction-evidence","kind":"evidence"},{"text":"Which downstream systems and derived artifacts must be notified before deletion proceeds?","id":"q-dependent-notification","kind":"relationship"}]},{"id":"fnd-deployment-alias-pointers","name":"Stage, alias, and status","description":"A version is immutable; mutable aliases (champion, staging) and tags communicate deployment intent; stages are legacy in MLflow and must not be treated as the only lifecycle model.","questions":[{"text":"Which mutable aliases currently point at this version, and for which environments?","id":"fnd-deployment-alias-pointers-q01","kind":"state"},{"text":"What lifecycle stage or status tags apply, and are deprecated stage names still in use?","id":"fnd-deployment-alias-pointers-q02","kind":"lifecycle"},{"text":"When, if at all, was this version archived, revoked, or given a valid-until time?","id":"fnd-deployment-alias-pointers-q03","kind":"event"}]}]},{"id":"lyr-stewardship-accountability","name":"Stewardship, documentation obligations and downstream linkage","description":"Accountable roles, the documentation set that must exist and stay current, and the verified links from deployments and operational feedback back to this artifact.","findings":[{"id":"fnd-ownership-stewardship","name":"Ownership, stewardship and accountable roles","description":"The owning unit, the day-to-day steward, separation between producing, approving and operating roles, and the contact point for the artifact.","questions":[{"text":"Which organisational unit owns this artifact, and which named role stewards it day to day?","id":"q-owner-steward","kind":"ownership"},{"text":"How are producing, approving and operating roles separated for this artifact?","id":"q-role-separation","kind":"authority"},{"text":"What happens to ownership when the responsible team is reorganised or the artifact is transferred externally?","id":"q-ownership-handover","kind":"process"},{"text":"Which contact point handles questions, defect reports and rights claims about the artifact?","id":"q-contact-point","kind":"definition"}]},{"id":"fnd-documentation-obligations","name":"Documentation set and downstream transparency","description":"Which documentation items must exist, how they are kept current, what must be handed to downstream integrators, what may be redacted and who may request the full set.","questions":[{"text":"Which documentation items must exist for this artifact, and which are mandatory versus recommended?","id":"q-documentation-set","kind":"requirement"},{"text":"How is documentation kept up to date as the artifact changes, and when was each item last revised?","id":"q-documentation-currency","kind":"temporal"},{"text":"What information must be handed to downstream integrators so they can meet their own obligations?","id":"q-downstream-information-pack","kind":"interoperability"},{"text":"Which parts may be redacted to protect trade secrets, and what minimum must still be disclosed?","id":"q-documentation-redaction","kind":"privacy"},{"text":"Who may request the full documentation set, and within what response time?","id":"q-documentation-request","kind":"access"}]},{"id":"fnd-downstream-linkage","name":"Deployment and operational feedback linkage","description":"Verified links from AI systems and endpoints that reference this revision, operational events attributed to it, and the loop back into re-evaluation or withdrawal.","questions":[{"text":"Which AI systems, endpoints or products currently reference this artifact revision?","id":"q-current-deployments","kind":"relationship"},{"text":"Which operational events are attributed back to this artifact rather than to the surrounding system?","id":"q-attributed-events","kind":"event"},{"text":"How do downstream observations trigger re-evaluation, patching or withdrawal of the artifact?","id":"q-feedback-loop","kind":"process"},{"text":"How is a deployment's claimed artifact revision verified against the artifact of record?","id":"q-deployment-verification","kind":"validation"}]}]}]}]},"agentConduct":{"may":["Verify hashes and signatures before loading or redistributing an artifact.","Compile a bill of materials with datasets, base models and dependencies.","Attach evaluation and safety evidence with its method and version.","Set a deployment alias to an already released version."],"mustNot":["Release an artifact without identifier, owner, licence and integrity verification.","Load weights from an unverified source or in an unsafe serialisation that can run code.","Claim standard conformance or safety without verifiable evidence.","Redistribute weights against their licence or use restrictions.","Overwrite a released version instead of issuing a new one."],"requiresHuman":["Determining the regulatory classification and obligations of a model.","Releasing documentation to a regulator or authority.","Retiring a model that deployed systems still depend on."]},"ethics":{"considerations":["Models trained on personal or copyrighted data can memorise and expose it.","Undocumented biases in a released model propagate to every downstream system.","Open release of capable models can enable misuse; release decisions need accountable review."],"affectedParties":["People whose data was used for training","Users and those affected by systems that use the model","Rights holders of training material"]},"owners":{"steward":"The adopting Dimension must name a single registry of record for model artifacts and publish which identifier it issues, at which scope level (family, version or snapshot), and how that identifier resolves.","roles":[{"name":"Model artifact owner","responsibilities":["Hold accountability for the artifact's compliance, licence and release decisions","Approve regulatory classification determinations and exemption claims","Authorise ownership transfer and accept residual risk"]},{"name":"Model artifact steward","responsibilities":["Maintain the artifact record, identifiers, aliases and classification values","Keep documentation items current and surface overdue or missing mandatory items","Bind evidence to revisions and mark stale evidence when a revision changes"]},{"name":"Provenance and integrity custodian","responsibilities":["Operate signing, verification and transparency-log checks and hold the trust root policy","Enforce that unverified artifacts cannot be promoted or distributed","Maintain the bill of materials and flag unsafe deserialisation formats and vulnerable components"]},{"name":"Release and lifecycle approver","responsibilities":["Check gate criteria and approve lifecycle transitions with segregation from the producing role","Approve distribution channels, release mode and withdrawal decisions","Approve deprecation, retention basis and destruction scope"]},{"name":"Rights and access controller","responsibilities":["Determine licence, use restrictions, export classification and residency constraints","Grant, review and revoke access under the declared default rule and gating conditions","Approve documentation redactions against the non-redactable minimum"]},{"name":"Interoperability maintainer","responsibilities":["Maintain alignment mapping tables and their versions for each external profile","Record unmapped fields and conflicts and prevent unsupported conformance claims","Validate that projections carry no semantics absent from the canonical record"]}],"masterSystems":[]},"relations":[{"target":"WM-AI-001 — AI System","type":"references","note":"An AI system composes one or more model artifacts. The artifact exposes its identity, interface contract, licence and downstream information pack so the system can meet its own obligations; the system owns intended purpose, human oversight and post-market monitoring."},{"target":"WM-AI-006 — Training Run","type":"references","note":"The producing run is the provenance anchor for internally produced artifacts, referenced as the attestation subject's build definition. Not required for externally acquired artifacts, where an acquisition record substitutes."},{"target":"WM-AI-003 — Evaluation","type":"references","note":"Evaluations assess a specific artifact revision. The artifact attaches reported results, measurement times and thresholds; the authoritative protocol, evaluator independence and full report remain in the evaluation model."},{"target":"Dataset (candidate sibling model, Croissant-aligned)","type":"references","note":"Training, validation, test and evaluation datasets are referenced by role. Dataset structure, record semantics, distribution and its own licensing stay in the dataset model."},{"target":"Software Component / SBOM entry (candidate sibling model)","type":"references","note":"Frameworks, runtimes and libraries appear as referenced components in the artifact's bill of materials and execution environment, typed distinctly from the machine-learning-model component."},{"target":"Party and Role register (candidate sibling model)","type":"references","note":"Owning organisation, steward, approver, obligated provider and access grantee resolve to party records; this model stores only typed references and assignment events."},{"target":"Signed Attestation (candidate mixin)","type":"composes","note":"Signature bundles, build provenance and destruction certificates share one attestation pattern: subject digest, predicate type, issuer identity, signing event time and optional transparency-log inclusion."},{"target":"Content-Addressed Digital Object (candidate mixin)","type":"composes","note":"Every packaged component carries media type, digest and size, giving verifiable byte-level identity that is reused rather than redefined per component role."},{"target":"SPDX 3.0.1 AI Profile — AIPackage","type":"aligned","note":"Alignment target for model-level descriptive properties (type of model, hyperparameters, training information, metrics and thresholds, limitations, safety risk assessment, autonomy, domain, energy, sensitive personal information). Alignment is a mapping claim, not a conformance claim."},{"target":"CycloneDX v1.6 ML-BOM modelCard","type":"aligned","note":"Alignment target for composition transparency and model card structure, including the machine-learning-model and data component types and the considerations block."},{"target":"EU AI Act Annex XI and Annex XII documentation set","type":"aligned","note":"Alignment target for the mandatory documentation and downstream transparency content where the artifact is a general-purpose AI model placed on the EU market. Applicability is determined per artifact, not assumed."},{"target":"ISO/IEC 5338:2023 AI system life cycle processes","type":"aligned","note":"Alignment target for lifecycle stage vocabulary and process control. Mapping is provisional: only the catalogue record was verified, so the alignment is recorded as a gap pending access to the normative text."},{"target":"WM-AI-001 AI System","type":"neighbor","note":"The artifact is the model as a versioned object; the AI system is the deployed sociotechnical system that uses it. Obligations attached to intended purpose, human oversight and post-market monitoring sit on the system; the artifact carries only the model-level documentation the system needs to satisfy them. The EU AI Act reflects this split by giving GPAI models their own Article 53 track separate from the high-risk system track."},{"target":"WM-AI-006 Training Run","type":"neighbor","note":"The producing run is an event with its own lifecycle, parameters and byproducts; the artifact is its output subject. Provenance predicates keep these distinct: the run appears as buildDefinition/runDetails, the artifact as the attestation subject identified by digest. This model stores only the resolvable run reference and the recorded build inputs, not the run record."},{"target":"WM-AI-003 Evaluation","type":"neighbor","note":"An evaluation is an assessment activity with its own protocol, evaluator and independence status. The artifact carries reported results, their measurement time and any decision thresholds, but the authoritative evaluation record and its methodology remain in the evaluation model. Attached results are claims about a revision, not proof of conformity."},{"target":"Dataset (candidate sibling model)","type":"neighbor","note":"Training, validation and test datasets are independent entities with their own metadata, provenance and licensing vocabulary. This model records dataset references, curation methodology summaries and the published training-content summary; it does not model dataset structure or record-level semantics."},{"target":"Software Package / SBOM component","type":"neighbor","note":"An ML model artifact is a distinct component type from ordinary software: BOM standards give it its own type (machine-learning-model) and its own descriptive object. Framework and library dependencies are referenced as components, not absorbed into this model."},{"target":"Digital file / OCI blob","type":"neighbor","note":"Content digests give byte-level, content-addressable identity to each blob, but a model artifact is an aggregate of blobs with an identity that survives repackaging and re-serialization. Digest is an integrity and pinning key; it is not the business identity of the artifact."}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the designated registry of record for model artifacts — for example the model registry primary key or model version key held by the system that governs releases. This identifier always takes precedence, and the registry of record must be named on the artifact record.","Governed global identifier or IRI where one exists — for example an SPDX element IRI, a registry-scoped namespace-plus-repository identifier with its immutable revision, or a persistent resolvable identifier issued by a recognised authority.","UUID or ULID minted by the adopting Dimension, used only when no authoritative master-system identifier and no governed global identifier are available; the minted identifier must record the minting Dimension and the minting event time.","Content digest in algorithm:encoded form is recorded as an integrity and pinning key alongside — never instead of — the identifiers above; it verifies bytes, not business identity, and does not survive lossless repackaging. A release date, a version label, a mutable tag such as latest, or a distribution path is never an identifier."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A model artifact has a name, a version, weight files with hashes, a model card and a licence.","It is confused with the AI system, a training checkpoint, a dataset or a container image."]},"capabilities":{"applicability":"required","items":["Register model artifact: Create the governed record for a newly produced or newly acquired model artifact and assign its canonical identity.","Resolve artifact identity: Resolve any supplied identifier, alias or digest to the canonical artifact record and the exact revision meant.","Verify artifact integrity and provenance: Validate the signature over the manifest, recompute file digests, and check build provenance and transparency evidence.","Compile bill of materials: Generate the machine-readable component inventory for a specific artifact revision and bind it to the revision pin.","Assemble technical documentation dossier: Collect required documentation items into a versioned dossier and derive the downstream integrator information pack.","Determine regulatory classification and obligations: Decide whether the artifact is a general-purpose model, whether systemic-risk criteria are met, which jurisdictions apply and which exemptions hold.","Attach evaluation and safety evidence: Bind reported results, thresholds, fairness evidence and safety assessments to a specific artifact revision without absorbing the evaluation record itself.","Transition lifecycle state: Move the artifact between controlled states after checking gate criteria and recording approver and timing.","Retire and dispose of artifact: Deprecate, withdraw from channels, retain for the required period and destroy in scope with attested evidence.","Project interoperable views: Emit standards-aligned projections of the artifact record for external consumers without changing its semantics.","Export interchange format: Produce or retrieve an ONNX or other interchange projection with recorded opset and signature.","Set deployment alias: Point a mutable alias at an immutable version after required checks.","Release documentation to authority: Package Annex XI technical documentation for the AI Office or national competent authority while preserving confidentiality markings."]},"hazards":{"applicability":"required","items":["Malicious code execution through unsafe deserialisation of weights.","Tampered or poisoned weights from a compromised supply chain.","Silent version drift when aliases point to a different artifact."]},"interfaces":{"applicability":"required","items":["ONNX model format.","Safetensors serialisation format.","OCI Image and Distribution specifications for artifact storage.","CycloneDX ML-BOM.","Model cards as described by Mitchell et al. 2019."]},"context":{"applicability":"required","items":["The regulatory classification finding is written against the EU general-purpose AI model regime because that is the regime with the most specific published artifact-level documentation content. Other jurisdictions are accommodated through the jurisdiction and obligation-set data elements but are not enumerated.","Application dates for the general-purpose model obligations are jurisdiction-specific and were read from a reproduction; adopters outside the EU should treat the obligation set as a template to be re-derived locally.","Export control and sanctions classification vocabularies are national and are modelled as a coded determination rather than an enumerated list, because no single international code list applies.","Data residency constraints are assumed to derive from contract or local law rather than from the artifact itself; where no constraint is recorded, the model does not imply that storage anywhere is lawful.","Retention periods are not asserted; they are recorded with their legal or contractual basis because statutory minimums vary by jurisdiction and by sector.","EU GPAI Articles 53 and Annex XI/XII apply to models placed on the Union market from 2 August 2025; they do not automatically bind non-EU internal catalogs.","NIST AI RMF 1.0 is voluntary US public-authority guidance, not a conformity scheme.","Hugging Face Hub identifiers are a de facto public namespace, not a legal registry of record unless so designated by the owner.","SPDX licence identifiers are used as the default licence code system."]}},"sources":[{"title":"SPDX Specification v3.0.1 — AI Profile: AIPackage","url":"https://spdx.github.io/spdx-spec/v3.0.1/model/AI/AI/","note":"Linux Foundation / SPDX Project"},{"title":"Article 53: Obligations for Providers of General-Purpose AI Models — EU Artificial Intelligence Act","url":"https://artificialintelligenceact.eu/article/53/","note":"Future of Life Institute (AI Act Explorer reproduction of Regulation (EU) 2024/1689)"},{"title":"Annex XI: Technical Documentation Referred to in Article 53(1), Point (a) — EU Artificial Intelligence Act","url":"https://artificialintelligenceact.eu/annex/11/","note":"Future of Life Institute (AI Act Explorer reproduction of Regulation (EU) 2024/1689)"},{"title":"Annex XII: Transparency Information Referred to in Article 53(1), Point (b) — EU Artificial Intelligence Act","url":"https://artificialintelligenceact.eu/annex/12/","note":"Future of Life Institute (AI Act Explorer reproduction of Regulation (EU) 2024/1689)"},{"title":"ONNX Intermediate Representation (IR) Specification","url":"https://github.com/onnx/onnx/blob/main/docs/IR.md","note":"LF AI & Data Foundation / ONNX"},{"title":"CycloneDX v1.6 JSON Reference (component types, modelCard, declarations, formulation)","url":"https://cyclonedx.org/docs/1.6/json/","note":"OWASP Foundation / Ecma TC54"},{"title":"OCI Image Specification — Content Descriptors","url":"https://github.com/opencontainers/image-spec/blob/main/descriptor.md","note":"Open Container Initiative"},{"title":"safetensors — file format specification","url":"https://github.com/huggingface/safetensors","note":"Hugging Face"},{"title":"Model Cards — Hugging Face Hub documentation","url":"https://huggingface.co/docs/hub/model-cards","note":"Hugging Face"},{"title":"MLflow Models — MLmodel format, signatures and flavors","url":"https://mlflow.org/docs/latest/ml/model/","note":"Linux Foundation / MLflow"},{"title":"GGUF — GGML Universal File format specification","url":"https://github.com/ggml-org/ggml/blob/master/docs/gguf.md","note":"ggml-org"},{"title":"SLSA Provenance v1.0 predicate","url":"https://slsa.dev/spec/v1.0/provenance","note":"OpenSSF / SLSA"},{"title":"OpenSSF Model Signing (OMS) Specification","url":"https://github.com/ossf/model-signing-spec","note":"Open Source Security Foundation (OpenSSF) AI/ML Security Working Group"},{"title":"sigstore/model-transparency — supply chain security for ML","url":"https://github.com/sigstore/model-transparency","note":"Sigstore project"},{"title":"NIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile","url":"https://csrc.nist.gov/pubs/sp/800/218/a/final","note":"National Institute of Standards and Technology (NIST)"},{"title":"NIST AI Risk Management Framework (AI RMF 1.0)","url":"https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF","note":"National Institute of Standards and Technology (NIST)"},{"title":"ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system","url":"https://www.iso.org/standard/42001","note":"ISO/IEC JTC 1/SC 42"},{"title":"ISO/IEC 5338:2023 — Information technology — Artificial intelligence — AI system life cycle processes","url":"https://www.iso.org/standard/81118.html","note":"ISO/IEC JTC 1/SC 42"},{"title":"Model Cards for Model Reporting","url":"https://arxiv.org/abs/1810.03993","note":"Mitchell et al., ACM FAT* 2019"},{"title":"Model Format Specification (modelpack)","url":"https://github.com/modelpack/model-spec/blob/main/docs/spec.md","note":"CNCF / modelpack project"},{"title":"Croissant — a metadata format for ML-ready datasets","url":"https://mlcommons.org/croissant/","note":"MLCommons"},{"title":"Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1","url":"https://doi.org/10.6028/NIST.AI.100-1","note":"National Institute of Standards and Technology"},{"title":"Hugging Face Hub documentation: Model Cards","url":"https://huggingface.co/docs/hub/en/model-cards","note":"Hugging Face"},{"title":"SPDX Specification 3.0.1: AIPackage class","url":"https://spdx.github.io/spdx-spec/v3.0.1/model/AI/Classes/AIPackage/","note":"Linux Foundation / SPDX"},{"title":"ISO/IEC 22989:2022 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology","url":"https://www.iso.org/standard/74296.html","note":"ISO/IEC JTC 1/SC 42"},{"title":"ISO/IEC 23053:2022 Framework for Artificial Intelligence (AI) Systems Using Machine Learning (ML)","url":"https://www.iso.org/standard/74438.html","note":"ISO/IEC JTC 1/SC 42"},{"title":"MLflow Model Registry documentation","url":"https://mlflow.org/docs/latest/ml/model-registry/","note":"MLflow / LF AI & Data"},{"title":"Hugging Face Hub modelcard.md metadata specification","url":"https://github.com/huggingface/hub-docs/blob/main/modelcard.md","note":"Hugging Face"},{"title":"Introduction to ONNX (Open Neural Network Exchange) 1.23.0","url":"https://onnx.ai/onnx/intro/index.html","note":"LF AI & Data / ONNX"},{"title":"Safetensors documentation","url":"https://huggingface.co/docs/safetensors/index","note":"Hugging Face"}],"openQuestions":["Artifact sameness across lossless repackaging, re-serialization and format conversion: no standards-derived rule exists. The base records conversion as a new revision with lineage, which is a design decision that needs either external grounding or an explicit Dimension-level policy statement.","Continual and online learning with in-place weight mutation conflicts with the immutable-revision and pinning assumptions both providers rely on. An additional state model and pinning strategy is required before the model can serve continuously updated weights.","Mixture-of-experts expert-shard identity, federated partial models, hardware-compiled engines (TensorRT, CoreML) and TEE-sealed or encrypted weights lack primary coverage in either provider and need dedicated source work.","Model weight watermarking, fingerprinting and output provenance marking have no settled interoperable artifact-level specification; revisit when a candidate specification stabilises.","ISO/IEC 22989:2022 and ISO/IEC 23053:2022 clause text for foundation-model and learning-approach terminology was never retrieved by either provider; obtain the clause text before adding any terminology-derived classification node.","Per-payload-member size and media type, and tokenizer, chat-template and processor files as candidate sibling linguistic resources rather than payload members, are open modelling questions carried forward from the non-base provider's omissions.","Systemic-risk threshold criteria and the Commission training-content summary template are regime-specific and evolving; track for a published template before encoding any threshold value or summary schema.","ISO/IEC 42001:2023 and ISO/IEC 5338:2023 are paywalled; only their catalogue records were verified. Every node resting on them for lifecycle stage vocabulary, Annex A control mapping or process naming is therefore an alignment gap, not evidenced conformance, and the specific stage names are left to the adopting Dimension.","The canonical EUR-Lex text of Regulation (EU) 2024/1689 could not be rendered by the fetch tool; Article 53, Annex XI and Annex XII were read from a reproduction. Exact wording, recital context and any subsequent corrigenda or implementing acts should be re-verified against the Official Journal before any compliance use.","No agreed threshold exists for what makes a model artifact 'the same artifact' across lossless repackaging or format conversion. The model records conversion as a new revision with lineage, but this is a design decision, not a standards-derived rule.","Systemic-risk threshold criteria and the Commission training-content summary template are regime-specific and evolving; the model carries the determination and the summary reference but deliberately encodes no threshold value.","Model weight watermarking, fingerprinting and output provenance marking are not modelled. They are an active area without a settled interoperable specification at artifact level.","Runtime behavioural drift, online learning and continuously updated weights are only partially served: the model assumes a pinnable revision, and continual-learning systems that mutate weights in place would need an additional state and pinning strategy.","Cost, pricing and commercial terms for access to the artifact are not modelled; they belong to a commercial agreement model.","Hyperparameter capture is present in the aligned SPDX property set but is modelled here only as recorded build parameters, because hyperparameters are properly owned by the training run model.","Cryptographic model signing and SLSA-style build attestations were not grounded in a fetched primary specification and remain a gap.","Tokenizer, chat-template, and processor files are treated as payload members, not a sibling linguistic-resource model.","Hardware-compiled engines (TensorRT, CoreML) and encrypted or TEE-sealed weights lack primary coverage here.","Continual-learning in-place weight updates conflict with immutable-version rules and need a local policy.","Mixture-of-experts expert-shard identity and federated partial models are not specified.","Full ISO/IEC 22989:2022 clause text was not retrieved; AMD1 generative terms are used from public OBP fragments only.","Model-card Toolkit / Mitchell 2018 academic schema is cited by Hugging Face but was not independently fetched."],"resources":{"spec":"/models/wm-sft-004-ml-model-artifact/spec.yaml","agents":"/models/wm-sft-004-ml-model-artifact/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-004"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-sft-004-ml-model-artifact/spec.yaml","ver-cy/world-models/card-supplements/wm-sft-004-ml-model-artifact.json"],"providers":["Claude","Grok"],"researchStatus":"reviewable-draft","generatedAt":"2026-08-26T11:55:12Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}