← Back to catalogue
Published

AI Model Registry Entry

vr.wm-ai-007 · wm-ai-007-ai-model-registry-entry

Represent one governed, discoverable registry record that binds an AI model family or version to artifacts, technical metadata, lineage, rights, evaluations, approvals, lifecycle and distribution views without absorbing their external masters.

World Models Information and virtual systems INF.AI.REG

Bundle → Layer → Finding → Questions Filled

6 bundles · 12 layers · 24 findings · 72 questions

Registry identity, scope, ownership and discovery Groups governed registry context for registry identity, scope, ownership and discovery.

Entry root, registry scope, family and version

Groups source-qualified registry context for entry root, registry scope, family and version.

Entry identity, registry namespace, issuer, owner, revision and current head

Records entry identity, registry namespace, issuer, owner, revision and current head as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish entry identity, registry namespace, issuer, owner, revision and current head? identity
  2. Who may assert, review, approve, correct or rely on entry identity, registry namespace, issuer, owner, revision and current head, under which authority, purpose and limits? temporal
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to entry identity, registry namespace, issuer, owner, revision and current head, and which evidence supports them? validation

Model family, version, alias, canonical URI, duplicate and equivalence

Records model family, version, alias, canonical uri, duplicate and equivalence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish model family, version, alias, canonical uri, duplicate and equivalence? relationship
  2. Who may assert, review, approve, correct or rely on model family, version, alias, canonical uri, duplicate and equivalence, under which authority, purpose and limits? composition
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to model family, version, alias, canonical uri, duplicate and equivalence, and which evidence supports them? privacy

Catalog description, classification and stewardship

Groups source-qualified registry context for catalog description, classification and stewardship.

Title, summary, keywords, task, modality, language, domain and search facets

Records title, summary, keywords, task, modality, language, domain and search facets as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish title, summary, keywords, task, modality, language, domain and search facets? classification
  2. Who may assert, review, approve, correct or rely on title, summary, keywords, task, modality, language, domain and search facets, under which authority, purpose and limits? evidence
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to title, summary, keywords, task, modality, language, domain and search facets, and which evidence supports them? lifecycle

Creator, provider, publisher, steward, contact, jurisdiction and attribution

Records creator, provider, publisher, steward, contact, jurisdiction and attribution as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish creator, provider, publisher, steward, contact, jurisdiction and attribution? ownership
  2. Who may assert, review, approve, correct or rely on creator, provider, publisher, steward, contact, jurisdiction and attribution, under which authority, purpose and limits? ownership
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to creator, provider, publisher, steward, contact, jurisdiction and attribution, and which evidence supports them? quality
Model artifact, technical contract and compatibility Groups governed registry context for model artifact, technical contract and compatibility.

Artifact release, packaging and integrity

Groups source-qualified registry context for artifact release, packaging and integrity.

Artifact reference, version, format, distribution, digest, size and signature

Records artifact reference, version, format, distribution, digest, size and signature as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish artifact reference, version, format, distribution, digest, size and signature? evidence
  2. Who may assert, review, approve, correct or rely on artifact reference, version, format, distribution, digest, size and signature, under which authority, purpose and limits? measurement
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to artifact reference, version, format, distribution, digest, size and signature, and which evidence supports them? security

Architecture, base model, tokenizer, framework, runtime, hardware and dependencies

Records architecture, base model, tokenizer, framework, runtime, hardware and dependencies as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish architecture, base model, tokenizer, framework, runtime, hardware and dependencies? composition
  2. Who may assert, review, approve, correct or rely on architecture, base model, tokenizer, framework, runtime, hardware and dependencies, under which authority, purpose and limits? exception
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to architecture, base model, tokenizer, framework, runtime, hardware and dependencies, and which evidence supports them? retention

Interface, capability, intended use and limits

Groups source-qualified registry context for interface, capability, intended use and limits.

Task, input, output, signature, modality, capability and behavior contract

Records task, input, output, signature, modality, capability and behavior contract as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish task, input, output, signature, modality, capability and behavior contract? requirement
  2. Who may assert, review, approve, correct or rely on task, input, output, signature, modality, capability and behavior contract, under which authority, purpose and limits? provenance
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to task, input, output, signature, modality, capability and behavior contract, and which evidence supports them? interoperability

Intended, supported, out-of-scope and prohibited use, limitations and failure modes

Records intended, supported, out-of-scope and prohibited use, limitations and failure modes as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish intended, supported, out-of-scope and prohibited use, limitations and failure modes? constraint
  2. Who may assert, review, approve, correct or rely on intended, supported, out-of-scope and prohibited use, limitations and failure modes, under which authority, purpose and limits? process
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to intended, supported, out-of-scope and prohibited use, limitations and failure modes, and which evidence supports them? decision
Development lineage, rights and transparency Groups governed registry context for development lineage, rights and transparency.

Training, data, code, build and supply-chain lineage

Groups source-qualified registry context for training, data, code, build and supply-chain lineage.

Training run, dataset, code, configuration, build, builder and provenance

Records training run, dataset, code, configuration, build, builder and provenance as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish training run, dataset, code, configuration, build, builder and provenance? provenance
  2. Who may assert, review, approve, correct or rely on training run, dataset, code, configuration, build, builder and provenance, under which authority, purpose and limits? validation
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to training run, dataset, code, configuration, build, builder and provenance, and which evidence supports them? state

Developers, funders, contributors, tools, environment and source documentation

Records developers, funders, contributors, tools, environment and source documentation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish developers, funders, contributors, tools, environment and source documentation? ownership
  2. Who may assert, review, approve, correct or rely on developers, funders, contributors, tools, environment and source documentation, under which authority, purpose and limits? privacy
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to developers, funders, contributors, tools, environment and source documentation, and which evidence supports them? identity

License, rights, distribution and transparency documents

Groups source-qualified registry context for license, rights, distribution and transparency documents.

License, copyright, ownership, intellectual property, data rights, export and use terms

Records license, copyright, ownership, intellectual property, data rights, export and use terms as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish license, copyright, ownership, intellectual property, data rights, export and use terms? authority
  2. Who may assert, review, approve, correct or rely on license, copyright, ownership, intellectual property, data rights, export and use terms, under which authority, purpose and limits? lifecycle
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to license, copyright, ownership, intellectual property, data rights, export and use terms, and which evidence supports them? classification

Model card, system card, technical documentation, disclosure and version

Records model card, system card, technical documentation, disclosure and version as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish model card, system card, technical documentation, disclosure and version? evidence
  2. Who may assert, review, approve, correct or rely on model card, system card, technical documentation, disclosure and version, under which authority, purpose and limits? quality
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to model card, system card, technical documentation, disclosure and version, and which evidence supports them? relationship
Evaluation, risk, safety, security and approval Groups governed registry context for evaluation, risk, safety, security and approval.

Evaluation, benchmark, quality and comparability

Groups source-qualified registry context for evaluation, benchmark, quality and comparability.

Evaluation dataset, task, metric, threshold, subgroup, robustness and result

Records evaluation dataset, task, metric, threshold, subgroup, robustness and result as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish evaluation dataset, task, metric, threshold, subgroup, robustness and result? measurement
  2. Who may assert, review, approve, correct or rely on evaluation dataset, task, metric, threshold, subgroup, robustness and result, under which authority, purpose and limits? security
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to evaluation dataset, task, metric, threshold, subgroup, robustness and result, and which evidence supports them? authority

Evidence source, method, version, freshness, uncertainty, comparator and limit

Records evidence source, method, version, freshness, uncertainty, comparator and limit as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish evidence source, method, version, freshness, uncertainty, comparator and limit? quality
  2. Who may assert, review, approve, correct or rely on evidence source, method, version, freshness, uncertainty, comparator and limit, under which authority, purpose and limits? retention
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to evidence source, method, version, freshness, uncertainty, comparator and limit, and which evidence supports them? requirement

Risk, control, review and accountable decision

Groups source-qualified registry context for risk, control, review and accountable decision.

Risk, privacy, security, safety, bias, misuse, red-team and incident reference

Records risk, privacy, security, safety, bias, misuse, red-team and incident reference as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish risk, privacy, security, safety, bias, misuse, red-team and incident reference? security
  2. Who may assert, review, approve, correct or rely on risk, privacy, security, safety, bias, misuse, red-team and incident reference, under which authority, purpose and limits? interoperability
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to risk, privacy, security, safety, bias, misuse, red-team and incident reference, and which evidence supports them? constraint

Reviewer, approval, rejection, exception, human oversight and decision evidence

Records reviewer, approval, rejection, exception, human oversight and decision evidence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish reviewer, approval, rejection, exception, human oversight and decision evidence? decision
  2. Who may assert, review, approve, correct or rely on reviewer, approval, rejection, exception, human oversight and decision evidence, under which authority, purpose and limits? decision
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to reviewer, approval, rejection, exception, human oversight and decision evidence, and which evidence supports them? event
Lifecycle, promotion, publication and deployment bindings Groups governed registry context for lifecycle, promotion, publication and deployment bindings.

Entry state events, correction and supersession

Groups source-qualified registry context for entry state events, correction and supersession.

Candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked

Records candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked? lifecycle
  2. Who may assert, review, approve, correct or rely on candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, under which authority, purpose and limits? state
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, and which evidence supports them? temporal

Transition event, reason, authority, time, correction, merge, split and supersession

Records transition event, reason, authority, time, correction, merge, split and supersession as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish transition event, reason, authority, time, correction, merge, split and supersession? event
  2. Who may assert, review, approve, correct or rely on transition event, reason, authority, time, correction, merge, split and supersession, under which authority, purpose and limits? identity
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to transition event, reason, authority, time, correction, merge, split and supersession, and which evidence supports them? composition

Promotion, alias, release and deployment observation

Groups source-qualified registry context for promotion, alias, release and deployment observation.

Promotion gate, release decision, alias, champion, channel and rollout intent

Records promotion gate, release decision, alias, champion, channel and rollout intent as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish promotion gate, release decision, alias, champion, channel and rollout intent? authority
  2. Who may assert, review, approve, correct or rely on promotion gate, release decision, alias, champion, channel and rollout intent, under which authority, purpose and limits? classification
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to promotion gate, release decision, alias, champion, channel and rollout intent, and which evidence supports them? evidence

Deployable, deployed, active, environment, endpoint, compatibility and observation

Records deployable, deployed, active, environment, endpoint, compatibility and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish deployable, deployed, active, environment, endpoint, compatibility and observation? state
  2. Who may assert, review, approve, correct or rely on deployable, deployed, active, environment, endpoint, compatibility and observation, under which authority, purpose and limits? relationship
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to deployable, deployed, active, environment, endpoint, compatibility and observation, and which evidence supports them? ownership
Distribution, access, retention, audit and projections Groups governed registry context for distribution, access, retention, audit and projections.

Availability, distribution, access and use signals

Groups source-qualified registry context for availability, distribution, access and use signals.

Landing page, API, package, OCI location, mirror, availability and access tier

Records landing page, api, package, oci location, mirror, availability and access tier as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish landing page, api, package, oci location, mirror, availability and access tier? access
  2. Who may assert, review, approve, correct or rely on landing page, api, package, oci location, mirror, availability and access tier, under which authority, purpose and limits? authority
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to landing page, api, package, oci location, mirror, availability and access tier, and which evidence supports them? measurement

Weight availability, download, use, adoption, popularity, staleness and observation

Records weight availability, download, use, adoption, popularity, staleness and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish weight availability, download, use, adoption, popularity, staleness and observation? measurement
  2. Who may assert, review, approve, correct or rely on weight availability, download, use, adoption, popularity, staleness and observation, under which authority, purpose and limits? requirement
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to weight availability, download, use, adoption, popularity, staleness and observation, and which evidence supports them? exception

Governance, records, audit and interoperability

Groups source-qualified registry context for governance, records, audit and interoperability.

Role, purpose, access, disclosure, audit, retention, hold, tombstone and proof

Records role, purpose, access, disclosure, audit, retention, hold, tombstone and proof as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish role, purpose, access, disclosure, audit, retention, hold, tombstone and proof? retention
  2. Who may assert, review, approve, correct or rely on role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, under which authority, purpose and limits? constraint
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, and which evidence supports them? provenance

DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, PROV and OpenLineage projection

Records dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.

  1. What stable identity, registry scope, version-qualified values and explicit unknowns establish dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection? interoperability
  2. Who may assert, review, approve, correct or rely on dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, under which authority, purpose and limits? event
  3. Which event, effective, observed, recorded, ingested and knowledge times apply to dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, and which evidence supports them? process

Classifiers Filled

Family
World Models
Category
Information and virtual systems
Entry kind
registry
Navigation path
NAV.INF.AI.REG
Domain
INF.AI.REG
Industry
Cross-industry
Tags
aimodelregistryentryinf.ai.reg

What it is Filled

Owns one registry-entry identity; owning registry, namespace, family and version bindings; catalog description, classifications and stewardship; artifact, technical-contract, lineage, rights, documentation, evaluation, risk, approval, lifecycle, promotion, deployment-observation, availability, access, correction, retention, audit and projection assertions. Model artifact, training run, dataset, source code, build, evaluation, deployment, endpoint, model card, policy, credential, provenance, audit and records masters remain external.

In scope

  • Entry identity, registry scope, family and version bindings, aliases, discovery metadata, stewardship, artifact and technical-contract references, lineage, rights and transparency
  • Evaluation, risk, safety, security, approvals, lifecycle, promotion, deployment observations, availability, access, correction, retention, audit and projections

Out of scope

  • Creating or mutating external model artifact, training, dataset, code, build, evaluation, deployment, endpoint, policy, credential, provenance, audit or records masters
  • Equating registry entry with model artifact, model card, approval or deployment, or equating digest, signature or popularity with quality and safety
  • Autonomous approval, publication, signing, revocation, access expansion, disclosure, deployment or destructive cleanup

Why it exists Filled

Represent one governed, discoverable registry record that binds an AI model family or version to artifacts, technical metadata, lineage, rights, evaluations, approvals, lifecycle and distribution views without absorbing their external masters.

Distinguishing features Filled

  • A discoverable catalogue record about a model family or version, not the model bytes themselves.
  • Keeps registered, approved, published, deployed, deprecated and revoked as independent authority-qualified states.
  • Points to training runs, evaluations and deployments without owning them.
  • Treats a digest or signature as byte identity evidence, not as proof of safety or fitness.

What robots and AI may and may not do Filled

Must not

  • Approve, publish, sign or revoke an entry.
  • Widen access to restricted models or documentation.
  • Deploy a model from the registry.
  • Claim safety or compliance from a signature or a score.
  • Delete entries or lineage referenced by deployments.

Only with a human decision

  • Approving a model for production or publication.
  • Revoking or withdrawing a model in use.
  • Granting access to a restricted model.

May

  • Register a model version with artifacts, digests and lineage references.
  • Attach documentation, model cards and evaluation links.
  • Answer discovery queries within the caller's access scope.
  • Flag entries with missing licence, evaluation or risk evidence.

Moral aspects Filled

  • Registry status guides who deploys a model, so wrong approval states can spread harmful systems.
  • Model documentation must state limits honestly so that users do not apply models outside their tested use.
  • Licence and rights records protect data creators and model authors.

Who is affected

  • Users and subjects of deployed models
  • Model developers and rights holders
  • Deployers relying on approval states

Owners Filled

Steward

Dimension owner, registry mandate and accountable AI owner

Roles

AI system owner and accountable deployer
Own purpose, risk acceptance, release boundaries and accountable use of registered models.
Model provider or developer
Supply version-qualified artifacts, technical contract, lineage, rights, use and limitation claims.
Registry owner and steward
Own entry identity, duplicate resolution, metadata quality, lifecycle history, discoverability and projection integrity.
Independent evaluator, safety and security reviewer
Review evaluation, abuse, privacy, security, safety and red-team evidence without becoming the artifact owner.
Release and approval authority
Make attributable approval, exception, publication, withdrawal and revocation decisions within mandate.
Deployment and platform operator
Provide source-qualified environment, deployment, endpoint, compatibility and observed-state references.
Legal, privacy and records steward
Own license, data-rights, IP, export, disclosure, correction, hold, retention and disposition profiles.

Links to other meta-models Filled

references

  • WM-SFT-004 ML Model Artifact - Represent the unfrozen parent boundary as a non-owning artifact and version binding without composition, mutation, release or cascade authority.
  • WM-AI-006 Model Training / Fine-tuning Run and AI Model Evaluation - Resolve authoritative development lineage and evaluation evidence without absorbing execution or measurement masters.
  • Deployment, endpoint, dataset, code, build, policy, credential, provenance, audit and records models - Resolve authoritative lifecycle, control and evidence records without absorbing their ownership.

aligned

  • DCAT 3, MLflow, Hugging Face, SPDX 3.0.1 AI, CycloneDX 1.7, OCI 1.1.1, SLSA 1.1, Sigstore, PROV-O and OpenLineage 1.53.0 - Project release-pinned catalog, registry, card, BOM, distribution, provenance, verification and lineage views with information-loss declarations.

neighbor

  • WM-SFT-004 ML Model Artifact - The unified parent_ids value is an unapproved boundary signal because no relation-ledger edge exists. The entry may reference immutable artifacts but cannot own or mutate their bytes, provenance or lifecycle.
  • WM-AI-006 Model Training / Fine-tuning Run - Training owns execution history. The registry entry stores source-qualified run, dataset, code and builder references and bounded lineage summaries.
  • AI Model Evaluation - External evaluation masters own datasets, procedures, measurements and conclusions. The entry stores versioned evidence bindings, summaries and approval use.
  • Deployment and endpoint - Deployment systems own environment, rollout, endpoint and observed runtime state. The registry records source-qualified references and observations without treating approval or publication as deployment.
  • Model card, system card and technical documentation - These are versioned transparency artifacts or projections. The registry entry binds them and selected summaries but does not make every card the canonical record.
  • DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage - These are catalog, registry, card, BOM, distribution, provenance, verification and lineage profiles with different scopes. No mapping is universally applicable or assumed lossless.

parent

  • WM-SFT-004

What else AI and robots need to interact with it Filled

Identity and identifiers required Filled

  • Authoritative master-system identifier for each registry entry, assertion, decision, event or projection, qualified by issuer, namespace and record kind.
  • Governed globally resolvable registry-entry IRI.
  • Dimension UUID or ULID when neither preceding identifier exists.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Filled

  • A registry entry names a registry, a namespace, a model name and version, artifact digests and a lifecycle state.
  • Often confused with the model artifact, a model card, a deployment endpoint or a package in a software repository.

Capabilities and actions required Filled

  • Register an AI model entry: Governed operation to register an ai model entry without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Bind family, version and artifacts: Governed operation to bind family, version and artifacts without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Describe contract, use and limitations: Governed operation to describe contract, use and limitations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Attach lineage, rights and transparency: Governed operation to attach lineage, rights and transparency without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Attach evaluation, risk and safety evidence: Governed operation to attach evaluation, risk and safety evidence without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Review, approve, reject or except: Governed operation to review, approve, reject or except without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Publish, deprecate, withdraw, revoke or supersede: Governed operation to publish, deprecate, withdraw, revoke or supersede without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Bind deployment observations: Governed operation to bind deployment observations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Correct, merge, split and resolve identity: Governed operation to correct, merge, split and resolve identity without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
  • Query, project, disclose, retain and audit: Governed operation to query, project, disclose, retain and audit without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.

Hazards and failure modes required Filled

  • Deployment of a revoked or unapproved version.
  • Artifact substitution when digests are not checked.
  • Missing licence leading to unlawful use.

Standards and interfaces required Filled

  • W3C DCAT 3 for catalogue description.
  • SPDX 3.0 AI profile.
  • CycloneDX machine learning bill of materials (ECMA-424).
  • OCI artifact and distribution specifications.
  • Sigstore and SLSA for signing and provenance.
  • W3C PROV-O.

Context of use required Filled

  • Technical documentation, data rights, privacy, intellectual property, export, security, safety, disclosure, retention and high-risk AI obligations depend on jurisdiction, industry and use case.
  • The EU AI Act and GDPR are European Union profiles; NIST publications are voluntary United States public-authority guidance unless adopted by policy or contract.
  • DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage are versioned profiles, not universal lossless schemas.

Sources Filled

  1. Artificial Intelligence Risk Management Framework (AI RMF 1.0) - National Institute of Standards and Technology
  2. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile - National Institute of Standards and Technology
  3. Secure Software Development Practices for Generative AI and Dual-Use Foundation Models - National Institute of Standards and Technology
  4. Regulation (EU) 2024/1689 Artificial Intelligence Act - European Union
  5. Regulation (EU) 2016/679 General Data Protection Regulation - European Union
  6. PROV-O: The PROV Ontology - World Wide Web Consortium
  7. Data Catalog Vocabulary (DCAT) Version 3 - World Wide Web Consortium
  8. Model Registry Workflows - MLflow
  9. Model Cards - Hugging Face
  10. Model Cards for Model Reporting - Google Research
  11. SPDX Specification AI Profile - SPDX
  12. CycloneDX Bill of Materials Specification - OWASP CycloneDX
  13. SLSA Terminology - Open Source Security Foundation
  14. OCI Distribution Specification - Open Container Initiative
  15. Verifying Signatures - Sigstore
  16. OpenLineage Object Model - OpenLineage
  17. Date and Time on the Internet: Timestamps - Internet Engineering Task Force

Open questions

  • Approve or reject the WM-SFT-004 parent boundary and register training, evaluation, deployment, endpoint, dataset, code, policy, credential, provenance and records relations.
  • Create registry profiles for model family and version semantics, aliasing, environments, approvals, publication, deprecation, withdrawal, revocation, deletion and access.
  • Validate jurisdiction and organization-specific model and data rights, IP, license, export, privacy, security, safety, disclosure, retention and accountable-release policies.
  • Test release-pinned DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage mappings with conformance, round-trip and information-loss evidence.
  • Refresh the NIST AI RMF mapping after a new normative revision and obtain supplemental independent external review before canonical promotion.
  • Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.
  • The unified row parent_ids WM-SFT-004 has no frozen relation-ledger edge and grants no composition, ownership, mutation, release or cascade authority.
  • Model registries differ on family, version, alias, environment, approval, deletion and access semantics and require explicit profiles.
  • NIST AI RMF 1.0 is under revision; this result pins the inspected 1.0 publication and does not predict the revision.

Machine files

Provenance

world-models research · reviewable-draft

Built from: models/wm-ai-007-ai-model-registry-entry/spec.yaml, ver-cy/world-models/card-supplements/wm-ai-007-ai-model-registry-entry.json