AI Model Registry Entry
Represent one governed, discoverable registry record that binds an AI model family or version to artifacts, technical metadata, lineage, rights, evaluations, approvals, lifecycle and distribution views without absorbing their external masters.
Bundle → Layer → Finding → Questions Filled
6 bundles · 12 layers · 24 findings · 72 questions
Registry identity, scope, ownership and discovery Groups governed registry context for registry identity, scope, ownership and discovery.
Entry root, registry scope, family and version
Groups source-qualified registry context for entry root, registry scope, family and version.
Entry identity, registry namespace, issuer, owner, revision and current head
Records entry identity, registry namespace, issuer, owner, revision and current head as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish entry identity, registry namespace, issuer, owner, revision and current head? identity
- Who may assert, review, approve, correct or rely on entry identity, registry namespace, issuer, owner, revision and current head, under which authority, purpose and limits? temporal
- Which event, effective, observed, recorded, ingested and knowledge times apply to entry identity, registry namespace, issuer, owner, revision and current head, and which evidence supports them? validation
Model family, version, alias, canonical URI, duplicate and equivalence
Records model family, version, alias, canonical uri, duplicate and equivalence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish model family, version, alias, canonical uri, duplicate and equivalence? relationship
- Who may assert, review, approve, correct or rely on model family, version, alias, canonical uri, duplicate and equivalence, under which authority, purpose and limits? composition
- Which event, effective, observed, recorded, ingested and knowledge times apply to model family, version, alias, canonical uri, duplicate and equivalence, and which evidence supports them? privacy
Catalog description, classification and stewardship
Groups source-qualified registry context for catalog description, classification and stewardship.
Title, summary, keywords, task, modality, language, domain and search facets
Records title, summary, keywords, task, modality, language, domain and search facets as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish title, summary, keywords, task, modality, language, domain and search facets? classification
- Who may assert, review, approve, correct or rely on title, summary, keywords, task, modality, language, domain and search facets, under which authority, purpose and limits? evidence
- Which event, effective, observed, recorded, ingested and knowledge times apply to title, summary, keywords, task, modality, language, domain and search facets, and which evidence supports them? lifecycle
Creator, provider, publisher, steward, contact, jurisdiction and attribution
Records creator, provider, publisher, steward, contact, jurisdiction and attribution as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish creator, provider, publisher, steward, contact, jurisdiction and attribution? ownership
- Who may assert, review, approve, correct or rely on creator, provider, publisher, steward, contact, jurisdiction and attribution, under which authority, purpose and limits? ownership
- Which event, effective, observed, recorded, ingested and knowledge times apply to creator, provider, publisher, steward, contact, jurisdiction and attribution, and which evidence supports them? quality
Model artifact, technical contract and compatibility Groups governed registry context for model artifact, technical contract and compatibility.
Artifact release, packaging and integrity
Groups source-qualified registry context for artifact release, packaging and integrity.
Artifact reference, version, format, distribution, digest, size and signature
Records artifact reference, version, format, distribution, digest, size and signature as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish artifact reference, version, format, distribution, digest, size and signature? evidence
- Who may assert, review, approve, correct or rely on artifact reference, version, format, distribution, digest, size and signature, under which authority, purpose and limits? measurement
- Which event, effective, observed, recorded, ingested and knowledge times apply to artifact reference, version, format, distribution, digest, size and signature, and which evidence supports them? security
Architecture, base model, tokenizer, framework, runtime, hardware and dependencies
Records architecture, base model, tokenizer, framework, runtime, hardware and dependencies as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish architecture, base model, tokenizer, framework, runtime, hardware and dependencies? composition
- Who may assert, review, approve, correct or rely on architecture, base model, tokenizer, framework, runtime, hardware and dependencies, under which authority, purpose and limits? exception
- Which event, effective, observed, recorded, ingested and knowledge times apply to architecture, base model, tokenizer, framework, runtime, hardware and dependencies, and which evidence supports them? retention
Interface, capability, intended use and limits
Groups source-qualified registry context for interface, capability, intended use and limits.
Task, input, output, signature, modality, capability and behavior contract
Records task, input, output, signature, modality, capability and behavior contract as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish task, input, output, signature, modality, capability and behavior contract? requirement
- Who may assert, review, approve, correct or rely on task, input, output, signature, modality, capability and behavior contract, under which authority, purpose and limits? provenance
- Which event, effective, observed, recorded, ingested and knowledge times apply to task, input, output, signature, modality, capability and behavior contract, and which evidence supports them? interoperability
Intended, supported, out-of-scope and prohibited use, limitations and failure modes
Records intended, supported, out-of-scope and prohibited use, limitations and failure modes as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish intended, supported, out-of-scope and prohibited use, limitations and failure modes? constraint
- Who may assert, review, approve, correct or rely on intended, supported, out-of-scope and prohibited use, limitations and failure modes, under which authority, purpose and limits? process
- Which event, effective, observed, recorded, ingested and knowledge times apply to intended, supported, out-of-scope and prohibited use, limitations and failure modes, and which evidence supports them? decision
Development lineage, rights and transparency Groups governed registry context for development lineage, rights and transparency.
Training, data, code, build and supply-chain lineage
Groups source-qualified registry context for training, data, code, build and supply-chain lineage.
Training run, dataset, code, configuration, build, builder and provenance
Records training run, dataset, code, configuration, build, builder and provenance as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish training run, dataset, code, configuration, build, builder and provenance? provenance
- Who may assert, review, approve, correct or rely on training run, dataset, code, configuration, build, builder and provenance, under which authority, purpose and limits? validation
- Which event, effective, observed, recorded, ingested and knowledge times apply to training run, dataset, code, configuration, build, builder and provenance, and which evidence supports them? state
Developers, funders, contributors, tools, environment and source documentation
Records developers, funders, contributors, tools, environment and source documentation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish developers, funders, contributors, tools, environment and source documentation? ownership
- Who may assert, review, approve, correct or rely on developers, funders, contributors, tools, environment and source documentation, under which authority, purpose and limits? privacy
- Which event, effective, observed, recorded, ingested and knowledge times apply to developers, funders, contributors, tools, environment and source documentation, and which evidence supports them? identity
License, rights, distribution and transparency documents
Groups source-qualified registry context for license, rights, distribution and transparency documents.
License, copyright, ownership, intellectual property, data rights, export and use terms
Records license, copyright, ownership, intellectual property, data rights, export and use terms as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish license, copyright, ownership, intellectual property, data rights, export and use terms? authority
- Who may assert, review, approve, correct or rely on license, copyright, ownership, intellectual property, data rights, export and use terms, under which authority, purpose and limits? lifecycle
- Which event, effective, observed, recorded, ingested and knowledge times apply to license, copyright, ownership, intellectual property, data rights, export and use terms, and which evidence supports them? classification
Model card, system card, technical documentation, disclosure and version
Records model card, system card, technical documentation, disclosure and version as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish model card, system card, technical documentation, disclosure and version? evidence
- Who may assert, review, approve, correct or rely on model card, system card, technical documentation, disclosure and version, under which authority, purpose and limits? quality
- Which event, effective, observed, recorded, ingested and knowledge times apply to model card, system card, technical documentation, disclosure and version, and which evidence supports them? relationship
Evaluation, risk, safety, security and approval Groups governed registry context for evaluation, risk, safety, security and approval.
Evaluation, benchmark, quality and comparability
Groups source-qualified registry context for evaluation, benchmark, quality and comparability.
Evaluation dataset, task, metric, threshold, subgroup, robustness and result
Records evaluation dataset, task, metric, threshold, subgroup, robustness and result as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish evaluation dataset, task, metric, threshold, subgroup, robustness and result? measurement
- Who may assert, review, approve, correct or rely on evaluation dataset, task, metric, threshold, subgroup, robustness and result, under which authority, purpose and limits? security
- Which event, effective, observed, recorded, ingested and knowledge times apply to evaluation dataset, task, metric, threshold, subgroup, robustness and result, and which evidence supports them? authority
Evidence source, method, version, freshness, uncertainty, comparator and limit
Records evidence source, method, version, freshness, uncertainty, comparator and limit as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish evidence source, method, version, freshness, uncertainty, comparator and limit? quality
- Who may assert, review, approve, correct or rely on evidence source, method, version, freshness, uncertainty, comparator and limit, under which authority, purpose and limits? retention
- Which event, effective, observed, recorded, ingested and knowledge times apply to evidence source, method, version, freshness, uncertainty, comparator and limit, and which evidence supports them? requirement
Risk, control, review and accountable decision
Groups source-qualified registry context for risk, control, review and accountable decision.
Risk, privacy, security, safety, bias, misuse, red-team and incident reference
Records risk, privacy, security, safety, bias, misuse, red-team and incident reference as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish risk, privacy, security, safety, bias, misuse, red-team and incident reference? security
- Who may assert, review, approve, correct or rely on risk, privacy, security, safety, bias, misuse, red-team and incident reference, under which authority, purpose and limits? interoperability
- Which event, effective, observed, recorded, ingested and knowledge times apply to risk, privacy, security, safety, bias, misuse, red-team and incident reference, and which evidence supports them? constraint
Reviewer, approval, rejection, exception, human oversight and decision evidence
Records reviewer, approval, rejection, exception, human oversight and decision evidence as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish reviewer, approval, rejection, exception, human oversight and decision evidence? decision
- Who may assert, review, approve, correct or rely on reviewer, approval, rejection, exception, human oversight and decision evidence, under which authority, purpose and limits? decision
- Which event, effective, observed, recorded, ingested and knowledge times apply to reviewer, approval, rejection, exception, human oversight and decision evidence, and which evidence supports them? event
Lifecycle, promotion, publication and deployment bindings Groups governed registry context for lifecycle, promotion, publication and deployment bindings.
Entry state events, correction and supersession
Groups source-qualified registry context for entry state events, correction and supersession.
Candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked
Records candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked? lifecycle
- Who may assert, review, approve, correct or rely on candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, under which authority, purpose and limits? state
- Which event, effective, observed, recorded, ingested and knowledge times apply to candidate, registered, reviewed, approved, published, deprecated, withdrawn and revoked, and which evidence supports them? temporal
Transition event, reason, authority, time, correction, merge, split and supersession
Records transition event, reason, authority, time, correction, merge, split and supersession as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish transition event, reason, authority, time, correction, merge, split and supersession? event
- Who may assert, review, approve, correct or rely on transition event, reason, authority, time, correction, merge, split and supersession, under which authority, purpose and limits? identity
- Which event, effective, observed, recorded, ingested and knowledge times apply to transition event, reason, authority, time, correction, merge, split and supersession, and which evidence supports them? composition
Promotion, alias, release and deployment observation
Groups source-qualified registry context for promotion, alias, release and deployment observation.
Promotion gate, release decision, alias, champion, channel and rollout intent
Records promotion gate, release decision, alias, champion, channel and rollout intent as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish promotion gate, release decision, alias, champion, channel and rollout intent? authority
- Who may assert, review, approve, correct or rely on promotion gate, release decision, alias, champion, channel and rollout intent, under which authority, purpose and limits? classification
- Which event, effective, observed, recorded, ingested and knowledge times apply to promotion gate, release decision, alias, champion, channel and rollout intent, and which evidence supports them? evidence
Deployable, deployed, active, environment, endpoint, compatibility and observation
Records deployable, deployed, active, environment, endpoint, compatibility and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish deployable, deployed, active, environment, endpoint, compatibility and observation? state
- Who may assert, review, approve, correct or rely on deployable, deployed, active, environment, endpoint, compatibility and observation, under which authority, purpose and limits? relationship
- Which event, effective, observed, recorded, ingested and knowledge times apply to deployable, deployed, active, environment, endpoint, compatibility and observation, and which evidence supports them? ownership
Distribution, access, retention, audit and projections Groups governed registry context for distribution, access, retention, audit and projections.
Availability, distribution, access and use signals
Groups source-qualified registry context for availability, distribution, access and use signals.
Landing page, API, package, OCI location, mirror, availability and access tier
Records landing page, api, package, oci location, mirror, availability and access tier as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish landing page, api, package, oci location, mirror, availability and access tier? access
- Who may assert, review, approve, correct or rely on landing page, api, package, oci location, mirror, availability and access tier, under which authority, purpose and limits? authority
- Which event, effective, observed, recorded, ingested and knowledge times apply to landing page, api, package, oci location, mirror, availability and access tier, and which evidence supports them? measurement
Weight availability, download, use, adoption, popularity, staleness and observation
Records weight availability, download, use, adoption, popularity, staleness and observation as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish weight availability, download, use, adoption, popularity, staleness and observation? measurement
- Who may assert, review, approve, correct or rely on weight availability, download, use, adoption, popularity, staleness and observation, under which authority, purpose and limits? requirement
- Which event, effective, observed, recorded, ingested and knowledge times apply to weight availability, download, use, adoption, popularity, staleness and observation, and which evidence supports them? exception
Governance, records, audit and interoperability
Groups source-qualified registry context for governance, records, audit and interoperability.
Role, purpose, access, disclosure, audit, retention, hold, tombstone and proof
Records role, purpose, access, disclosure, audit, retention, hold, tombstone and proof as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish role, purpose, access, disclosure, audit, retention, hold, tombstone and proof? retention
- Who may assert, review, approve, correct or rely on role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, under which authority, purpose and limits? constraint
- Which event, effective, observed, recorded, ingested and knowledge times apply to role, purpose, access, disclosure, audit, retention, hold, tombstone and proof, and which evidence supports them? provenance
DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, PROV and OpenLineage projection
Records dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection as source-qualified registry context while model artifact, training, dataset, code, evaluation, deployment, endpoint, policy, credential and audit masters remain external.
- What stable identity, registry scope, version-qualified values and explicit unknowns establish dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection? interoperability
- Who may assert, review, approve, correct or rely on dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, under which authority, purpose and limits? event
- Which event, effective, observed, recorded, ingested and knowledge times apply to dcat, mlflow, hugging face, spdx, cyclonedx, oci, slsa, prov and openlineage projection, and which evidence supports them? process
Classifiers Filled
- Family
- World Models
- Category
- Information and virtual systems
- Entry kind
- registry
- Navigation path
- NAV.INF.AI.REG
- Domain
- INF.AI.REG
- Industry
- Cross-industry
- Tags
- aimodelregistryentryinf.ai.reg
What it is Filled
Owns one registry-entry identity; owning registry, namespace, family and version bindings; catalog description, classifications and stewardship; artifact, technical-contract, lineage, rights, documentation, evaluation, risk, approval, lifecycle, promotion, deployment-observation, availability, access, correction, retention, audit and projection assertions. Model artifact, training run, dataset, source code, build, evaluation, deployment, endpoint, model card, policy, credential, provenance, audit and records masters remain external.
In scope
- Entry identity, registry scope, family and version bindings, aliases, discovery metadata, stewardship, artifact and technical-contract references, lineage, rights and transparency
- Evaluation, risk, safety, security, approvals, lifecycle, promotion, deployment observations, availability, access, correction, retention, audit and projections
Out of scope
- Creating or mutating external model artifact, training, dataset, code, build, evaluation, deployment, endpoint, policy, credential, provenance, audit or records masters
- Equating registry entry with model artifact, model card, approval or deployment, or equating digest, signature or popularity with quality and safety
- Autonomous approval, publication, signing, revocation, access expansion, disclosure, deployment or destructive cleanup
Why it exists Filled
Represent one governed, discoverable registry record that binds an AI model family or version to artifacts, technical metadata, lineage, rights, evaluations, approvals, lifecycle and distribution views without absorbing their external masters.
Distinguishing features Filled
- A discoverable catalogue record about a model family or version, not the model bytes themselves.
- Keeps registered, approved, published, deployed, deprecated and revoked as independent authority-qualified states.
- Points to training runs, evaluations and deployments without owning them.
- Treats a digest or signature as byte identity evidence, not as proof of safety or fitness.
What robots and AI may and may not do Filled
Must not
- Approve, publish, sign or revoke an entry.
- Widen access to restricted models or documentation.
- Deploy a model from the registry.
- Claim safety or compliance from a signature or a score.
- Delete entries or lineage referenced by deployments.
Only with a human decision
- Approving a model for production or publication.
- Revoking or withdrawing a model in use.
- Granting access to a restricted model.
May
- Register a model version with artifacts, digests and lineage references.
- Attach documentation, model cards and evaluation links.
- Answer discovery queries within the caller's access scope.
- Flag entries with missing licence, evaluation or risk evidence.
Moral aspects Filled
- Registry status guides who deploys a model, so wrong approval states can spread harmful systems.
- Model documentation must state limits honestly so that users do not apply models outside their tested use.
- Licence and rights records protect data creators and model authors.
Who is affected
- Users and subjects of deployed models
- Model developers and rights holders
- Deployers relying on approval states
Owners Filled
Steward
Dimension owner, registry mandate and accountable AI owner
Roles
- AI system owner and accountable deployer
- Own purpose, risk acceptance, release boundaries and accountable use of registered models.
- Model provider or developer
- Supply version-qualified artifacts, technical contract, lineage, rights, use and limitation claims.
- Registry owner and steward
- Own entry identity, duplicate resolution, metadata quality, lifecycle history, discoverability and projection integrity.
- Independent evaluator, safety and security reviewer
- Review evaluation, abuse, privacy, security, safety and red-team evidence without becoming the artifact owner.
- Release and approval authority
- Make attributable approval, exception, publication, withdrawal and revocation decisions within mandate.
- Deployment and platform operator
- Provide source-qualified environment, deployment, endpoint, compatibility and observed-state references.
- Legal, privacy and records steward
- Own license, data-rights, IP, export, disclosure, correction, hold, retention and disposition profiles.
Links to other meta-models Filled
references
- WM-SFT-004 ML Model Artifact - Represent the unfrozen parent boundary as a non-owning artifact and version binding without composition, mutation, release or cascade authority.
- WM-AI-006 Model Training / Fine-tuning Run and AI Model Evaluation - Resolve authoritative development lineage and evaluation evidence without absorbing execution or measurement masters.
- Deployment, endpoint, dataset, code, build, policy, credential, provenance, audit and records models - Resolve authoritative lifecycle, control and evidence records without absorbing their ownership.
aligned
- DCAT 3, MLflow, Hugging Face, SPDX 3.0.1 AI, CycloneDX 1.7, OCI 1.1.1, SLSA 1.1, Sigstore, PROV-O and OpenLineage 1.53.0 - Project release-pinned catalog, registry, card, BOM, distribution, provenance, verification and lineage views with information-loss declarations.
neighbor
- WM-SFT-004 ML Model Artifact - The unified parent_ids value is an unapproved boundary signal because no relation-ledger edge exists. The entry may reference immutable artifacts but cannot own or mutate their bytes, provenance or lifecycle.
- WM-AI-006 Model Training / Fine-tuning Run - Training owns execution history. The registry entry stores source-qualified run, dataset, code and builder references and bounded lineage summaries.
- AI Model Evaluation - External evaluation masters own datasets, procedures, measurements and conclusions. The entry stores versioned evidence bindings, summaries and approval use.
- Deployment and endpoint - Deployment systems own environment, rollout, endpoint and observed runtime state. The registry records source-qualified references and observations without treating approval or publication as deployment.
- Model card, system card and technical documentation - These are versioned transparency artifacts or projections. The registry entry binds them and selected summaries but does not make every card the canonical record.
- DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage - These are catalog, registry, card, BOM, distribution, provenance, verification and lineage profiles with different scopes. No mapping is universally applicable or assumed lossless.
parent
- WM-SFT-004
What else AI and robots need to interact with it Filled
Identity and identifiers required Filled
- Authoritative master-system identifier for each registry entry, assertion, decision, event or projection, qualified by issuer, namespace and record kind.
- Governed globally resolvable registry-entry IRI.
- Dimension UUID or ULID when neither preceding identifier exists.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Filled
- A registry entry names a registry, a namespace, a model name and version, artifact digests and a lifecycle state.
- Often confused with the model artifact, a model card, a deployment endpoint or a package in a software repository.
Capabilities and actions required Filled
- Register an AI model entry: Governed operation to register an ai model entry without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Bind family, version and artifacts: Governed operation to bind family, version and artifacts without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Describe contract, use and limitations: Governed operation to describe contract, use and limitations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Attach lineage, rights and transparency: Governed operation to attach lineage, rights and transparency without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Attach evaluation, risk and safety evidence: Governed operation to attach evaluation, risk and safety evidence without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Review, approve, reject or except: Governed operation to review, approve, reject or except without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Publish, deprecate, withdraw, revoke or supersede: Governed operation to publish, deprecate, withdraw, revoke or supersede without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Bind deployment observations: Governed operation to bind deployment observations without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Correct, merge, split and resolve identity: Governed operation to correct, merge, split and resolve identity without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
- Query, project, disclose, retain and audit: Governed operation to query, project, disclose, retain and audit without autonomous approval, publication, access expansion, signing, revocation, deployment, disclosure or destructive cleanup.
Hazards and failure modes required Filled
- Deployment of a revoked or unapproved version.
- Artifact substitution when digests are not checked.
- Missing licence leading to unlawful use.
Standards and interfaces required Filled
- W3C DCAT 3 for catalogue description.
- SPDX 3.0 AI profile.
- CycloneDX machine learning bill of materials (ECMA-424).
- OCI artifact and distribution specifications.
- Sigstore and SLSA for signing and provenance.
- W3C PROV-O.
Context of use required Filled
- Technical documentation, data rights, privacy, intellectual property, export, security, safety, disclosure, retention and high-risk AI obligations depend on jurisdiction, industry and use case.
- The EU AI Act and GDPR are European Union profiles; NIST publications are voluntary United States public-authority guidance unless adopted by policy or contract.
- DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage are versioned profiles, not universal lossless schemas.
Sources Filled
- Artificial Intelligence Risk Management Framework (AI RMF 1.0) - National Institute of Standards and Technology
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile - National Institute of Standards and Technology
- Secure Software Development Practices for Generative AI and Dual-Use Foundation Models - National Institute of Standards and Technology
- Regulation (EU) 2024/1689 Artificial Intelligence Act - European Union
- Regulation (EU) 2016/679 General Data Protection Regulation - European Union
- PROV-O: The PROV Ontology - World Wide Web Consortium
- Data Catalog Vocabulary (DCAT) Version 3 - World Wide Web Consortium
- Model Registry Workflows - MLflow
- Model Cards - Hugging Face
- Model Cards for Model Reporting - Google Research
- SPDX Specification AI Profile - SPDX
- CycloneDX Bill of Materials Specification - OWASP CycloneDX
- SLSA Terminology - Open Source Security Foundation
- OCI Distribution Specification - Open Container Initiative
- Verifying Signatures - Sigstore
- OpenLineage Object Model - OpenLineage
- Date and Time on the Internet: Timestamps - Internet Engineering Task Force
Open questions
- Approve or reject the WM-SFT-004 parent boundary and register training, evaluation, deployment, endpoint, dataset, code, policy, credential, provenance and records relations.
- Create registry profiles for model family and version semantics, aliasing, environments, approvals, publication, deprecation, withdrawal, revocation, deletion and access.
- Validate jurisdiction and organization-specific model and data rights, IP, license, export, privacy, security, safety, disclosure, retention and accountable-release policies.
- Test release-pinned DCAT, MLflow, Hugging Face, SPDX, CycloneDX, OCI, SLSA, Sigstore, PROV and OpenLineage mappings with conformance, round-trip and information-loss evidence.
- Refresh the NIST AI RMF mapping after a new normative revision and obtain supplemental independent external review before canonical promotion.
- Claude and Grok each timed out on one bounded attempt; no independent external result was admitted.
- The unified row parent_ids WM-SFT-004 has no frozen relation-ledger edge and grants no composition, ownership, mutation, release or cascade authority.
- Model registries differ on family, version, alias, environment, approval, deletion and access semantics and require explicit profiles.
- NIST AI RMF 1.0 is under revision; this result pins the inspected 1.0 publication and does not predict the revision.
Machine files
Provenance
world-models research · reviewable-draft
Built from: models/wm-ai-007-ai-model-registry-entry/spec.yaml, ver-cy/world-models/card-supplements/wm-ai-007-ai-model-registry-entry.json