# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-08-26T11:55:12Z", "synthesisSha256": "3e7358ff9645da0446b1a6e5030d9bdee1e53128fccb17e17b671a0be3b519de", "providerMode": "dual-provider", "providers": [ "Claude", "Grok" ], "waivedProviders": [] }, "metaModel": { "id": "WM-SFT-004", "registryId": "vr.wm-sft-004", "name": "ML Model Artifact", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.SFT.ML" ], "tags": [ "ml", "model", "artifact", "inf.sft.ml" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-sft-004-ml-model-artifact/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-sft-004", "model": { "registry_id": "vr.wm-sft-004", "model_id": "WM-SFT-004", "name": "ML Model Artifact", "entry_kind": "entity", "purpose": "Provide the governed, format-neutral context an AI agent needs to identify, inspect, produce, package, release, verify, operate and retire a trained machine-learning model artifact as a distinct object of record, separate from the AI system that embeds it, the training run that produced it and the evaluation that assesses it.", "scope_statement": "Scope is the trained, versioned, serializable ML model artifact: the weight set plus the accompanying configuration, interface contract, documentation, licence, provenance and integrity evidence that travel with it. The model covers identity and versioning, classification, derivation and data provenance, supply-chain integrity, packaging and interface, attached performance and safety evidence, rights and distribution, and lifecycle stewardship through deletion. It stops at the boundary where a sibling model owns the concept: the artifact references those neighbours rather than restating them.", "in_scope": [ "Canonical identity, version labels, immutable revision pins and content digests of a released artifact", "Classification: architecture family, parameter scale, task, modality, autonomy and regulatory status (e.g. GPAI, systemic risk)", "Derivation lineage from base models (fine-tune, adapter, quantization, merge, distillation) and inherited terms", "Provenance references to the producing run, resolved build dependencies and training/validation/test data sources", "Cryptographic signing, signed file manifests, transparency-log evidence and integrity verification policy", "Machine-readable bill of materials for model, data and software components", "Serialization format, precision/quantization, sharding and packaged component inventory", "Declared input/output/parameter signature, modality, context limits and required runtime, operator set and hardware", "Evaluation results, decision thresholds, intended use, limitations, fairness factors, safety assessment and energy footprint attached to this artifact revision", "Licence, use restrictions, copyright/TDM policy, distribution channels, access gating, export control and residency", "Lifecycle states and transitions, deprecation, retention, deletion evidence, ownership and documentation obligations" ], "out_of_scope": [ "The AI system or product that embeds the artifact, including its user interface, human oversight design and post-market monitoring plan (WM-AI-001)", "The training run itself as a process record: schedule, orchestration, checkpoints, cost accounting and operator actions (WM-AI-006)", "Evaluation campaign design, benchmark definition and independent evaluation reports as first-class records (WM-AI-003)", "Dataset entities: their internal structure, record-level schema, distribution and licensing (dataset sibling model; Croissant-aligned)", "Serving infrastructure, endpoints, autoscaling, latency SLOs and runtime telemetry", "Compute hardware, accelerator inventory and data-centre facilities", "Legal entities, contracts and personnel records referenced as owners or providers", "Prompt templates, agent definitions, tool schemas and orchestration graphs built on top of the artifact", "Source code repositories and general software packages, except where packaged as artifact components" ], "boundary_notes": [ { "neighbor": "WM-AI-001 AI System", "distinction": "The artifact is the model as a versioned object; the AI system is the deployed sociotechnical system that uses it. Obligations attached to intended purpose, human oversight and post-market monitoring sit on the system; the artifact carries only the model-level documentation the system needs to satisfy them. The EU AI Act reflects this split by giving GPAI models their own Article 53 track separate from the high-risk system track.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-016" ] }, { "neighbor": "WM-AI-006 Training Run", "distinction": "The producing run is an event with its own lifecycle, parameters and byproducts; the artifact is its output subject. Provenance predicates keep these distinct: the run appears as buildDefinition/runDetails, the artifact as the attestation subject identified by digest. This model stores only the resolvable run reference and the recorded build inputs, not the run record.", "source_refs": [ "SRC-012", "SRC-013" ] }, { "neighbor": "WM-AI-003 Evaluation", "distinction": "An evaluation is an assessment activity with its own protocol, evaluator and independence status. The artifact carries reported results, their measurement time and any decision thresholds, but the authoritative evaluation record and its methodology remain in the evaluation model. Attached results are claims about a revision, not proof of conformity.", "source_refs": [ "SRC-009", "SRC-006", "SRC-019" ] }, { "neighbor": "Dataset (candidate sibling model)", "distinction": "Training, validation and test datasets are independent entities with their own metadata, provenance and licensing vocabulary. This model records dataset references, curation methodology summaries and the published training-content summary; it does not model dataset structure or record-level semantics.", "source_refs": [ "SRC-021", "SRC-003", "SRC-006" ] }, { "neighbor": "Software Package / SBOM component", "distinction": "An ML model artifact is a distinct component type from ordinary software: BOM standards give it its own type (machine-learning-model) and its own descriptive object. Framework and library dependencies are referenced as components, not absorbed into this model.", "source_refs": [ "SRC-006", "SRC-001" ] }, { "neighbor": "Digital file / OCI blob", "distinction": "Content digests give byte-level, content-addressable identity to each blob, but a model artifact is an aggregate of blobs with an identity that survives repackaging and re-serialization. Digest is an integrity and pinning key; it is not the business identity of the artifact.", "source_refs": [ "SRC-007", "SRC-020", "SRC-013" ] } ] }, "sources": [ { "id": "SRC-001", "title": "SPDX Specification v3.0.1 — AI Profile: AIPackage", "organization": "Linux Foundation / SPDX Project", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/AI/AI/", "version_or_date": "3.0.1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Normative property set for AI/model packages: typeOfModel, hyperparameter, informationAboutTraining, metric, metricDecisionThreshold, limitation, safetyRiskAssessment, autonomyType, domain, energyConsumption, useSensitivePersonalInformation." }, { "id": "SRC-002", "title": "Article 53: Obligations for Providers of General-Purpose AI Models — EU Artificial Intelligence Act", "organization": "Future of Life Institute (AI Act Explorer reproduction of Regulation (EU) 2024/1689)", "url": "https://artificialintelligenceact.eu/article/53/", "version_or_date": "Regulation (EU) 2024/1689; obligations applicable from 2025-08-02", "source_type": "legislation", "primary_source": false, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Provider duties: keep technical documentation current, supply downstream information, copyright policy, publish training-content summary; free/open-source exemption and its systemic-risk carve-out." }, { "id": "SRC-003", "title": "Annex XI: Technical Documentation Referred to in Article 53(1), Point (a) — EU Artificial Intelligence Act", "organization": "Future of Life Institute (AI Act Explorer reproduction of Regulation (EU) 2024/1689)", "url": "https://artificialintelligenceact.eu/annex/11/", "version_or_date": "Regulation (EU) 2024/1689", "source_type": "legislation", "primary_source": false, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Minimum documentation content for GPAI models: tasks, acceptable use, release date, distribution, architecture and parameter count, modality, licence, training design, data provenance and curation, compute, training time, energy; plus adversarial testing for systemic-risk models." }, { "id": "SRC-004", "title": "Annex XII: Transparency Information Referred to in Article 53(1), Point (b) — EU Artificial Intelligence Act", "organization": "Future of Life Institute (AI Act Explorer reproduction of Regulation (EU) 2024/1689)", "url": "https://artificialintelligenceact.eu/annex/12/", "version_or_date": "Regulation (EU) 2024/1689", "source_type": "legislation", "primary_source": false, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Downstream-provider information pack: integration means, input/output size limits including context window, and training/testing/validation data type, provenance and curation." }, { "id": "SRC-005", "title": "ONNX Intermediate Representation (IR) Specification", "organization": "LF AI & Data Foundation / ONNX", "url": "https://github.com/onnx/onnx/blob/main/docs/IR.md", "version_or_date": "main branch, IR version ≥ 11", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Model-level fields (ir_version, opset_import, producer_name/version, domain, model_version, metadata_props, training_info) and the three independent versioning axes (IR, opset, model version)." }, { "id": "SRC-006", "title": "CycloneDX v1.6 JSON Reference (component types, modelCard, declarations, formulation)", "organization": "OWASP Foundation / Ecma TC54", "url": "https://cyclonedx.org/docs/1.6/json/", "version_or_date": "1.6", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "ML-BOM: component type machine-learning-model and data; modelCard with modelParameters (approach, task, architectureFamily, modelArchitecture, datasets, inputs, outputs), quantitativeAnalysis and considerations." }, { "id": "SRC-007", "title": "OCI Image Specification — Content Descriptors", "organization": "Open Container Initiative", "url": "https://github.com/opencontainers/image-spec/blob/main/descriptor.md", "version_or_date": "main branch", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Descriptor mediaType/digest/size, digest grammar algorithm:encoded, registered algorithms (sha256 mandatory, sha512, blake3) and content-addressable verification." }, { "id": "SRC-008", "title": "safetensors — file format specification", "organization": "Hugging Face", "url": "https://github.com/huggingface/safetensors", "version_or_date": "main branch", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Header/dtype/shape/data_offsets/__metadata__ layout, non-overlap and full-indexing constraints, and the explicit safety motivation versus pickle's arbitrary code execution." }, { "id": "SRC-009", "title": "Model Cards — Hugging Face Hub documentation", "organization": "Hugging Face", "url": "https://huggingface.co/docs/hub/model-cards", "version_or_date": "accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Model card metadata fields: license/license_name/license_link, library_name, base_model and base_model_relation (finetune/adapter/quantized/merge), new_version, datasets, pipeline_tag, model-index eval results with source, co2_eq_emissions, gating tags." }, { "id": "SRC-010", "title": "MLflow Models — MLmodel format, signatures and flavors", "organization": "Linux Foundation / MLflow", "url": "https://mlflow.org/docs/latest/ml/model/", "version_or_date": "latest, accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "MLmodel descriptor fields (run_id, model_uuid, time_created, mlflow_version, signature, input_example), input/output/params schema as an interface contract, and flavors as runtime loadability declarations." }, { "id": "SRC-011", "title": "GGUF — GGML Universal File format specification", "organization": "ggml-org", "url": "https://github.com/ggml-org/ggml/blob/master/docs/gguf.md", "version_or_date": "GGUF version 3", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Header, metadata key namespace (general.architecture, general.name, general.license as SPDX expression, general.quantization_version, general.file_type, general.base_model.*), tensor info and alignment rules." }, { "id": "SRC-012", "title": "SLSA Provenance v1.0 predicate", "organization": "OpenSSF / SLSA", "url": "https://slsa.dev/spec/v1.0/provenance", "version_or_date": "v1.0", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "buildDefinition (buildType, externalParameters, internalParameters, resolvedDependencies) and runDetails (builder.id, invocationId, startedOn, finishedOn, byproducts) bound to in-toto subjects by digest." }, { "id": "SRC-013", "title": "OpenSSF Model Signing (OMS) Specification", "organization": "Open Source Security Foundation (OpenSSF) AI/ML Security Working Group", "url": "https://github.com/ossf/model-signing-spec", "version_or_date": "v1.0 line, accessed 2026-08-26", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Detached signature file over a manifest of per-file digests; PKI-agnostic signing (bare key, self-signed, CA chain, Sigstore); SHA-256 default with BLAKE2b alternative; optional annotations for provenance metadata." }, { "id": "SRC-014", "title": "sigstore/model-transparency — supply chain security for ML", "organization": "Sigstore project", "url": "https://github.com/sigstore/model-transparency", "version_or_date": "main branch, v1.0 library", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "DSSE envelope carrying an in-toto statement whose subjects are (file path, digest) pairs with predicate type https://model_signing/signature/v1.0; sharded hashing; verify-then-rehash flow and transparency-log inclusion proofs." }, { "id": "SRC-015", "title": "NIST SP 800-218A — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/218/a/final", "version_or_date": "July 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Scoped to producers of AI models, producers of systems using them and acquirers; anchors secure-development, integrity and acquisition practices for model artifacts." }, { "id": "SRC-016", "title": "NIST AI Risk Management Framework (AI RMF 1.0)", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://airc.nist.gov/AI_RMF_Knowledge_Base/AI_RMF", "version_or_date": "1.0, January 2023, DOI 10.6028/NIST.AI.100-1", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "GOVERN/MAP/MEASURE/MANAGE functions and trustworthiness characteristics; frames documentation, accountability and lifecycle risk treatment for model artifacts and third-party components." }, { "id": "SRC-017", "title": "ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/standard/42001", "version_or_date": "first edition, 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "AI management system requirements including documented information, lifecycle control and third-party relationships. Catalogue record verified only; full normative text is paywalled and was not read." }, { "id": "SRC-018", "title": "ISO/IEC 5338:2023 — Information technology — Artificial intelligence — AI system life cycle processes", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/standard/81118.html", "version_or_date": "first edition, 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "AI-specific life cycle processes layered on ISO/IEC/IEEE 15288 and 12207, supporting definition, control, execution and improvement across life cycle stages. Catalogue record verified only; full text paywalled." }, { "id": "SRC-019", "title": "Model Cards for Model Reporting", "organization": "Mitchell et al., ACM FAT* 2019", "url": "https://arxiv.org/abs/1810.03993", "version_or_date": "FAT* '19, January 2019", "source_type": "scientific", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Original nine-section model card structure: Model Details, Intended Use, Factors, Metrics, Evaluation Data, Training Data, Quantitative Analyses, Ethical Considerations, Caveats and Recommendations; disaggregated evaluation by factor." }, { "id": "SRC-020", "title": "Model Format Specification (modelpack)", "organization": "CNCF / modelpack project", "url": "https://github.com/modelpack/model-spec/blob/main/docs/spec.md", "version_or_date": "main branch, artifactType application/vnd.cncf.model.manifest.v1+json", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Role-typed layer media types separating model weights, weight config, code, docs and datasets in one OCI artifact, with layer annotation keys." }, { "id": "SRC-021", "title": "Croissant — a metadata format for ML-ready datasets", "organization": "MLCommons", "url": "https://mlcommons.org/croissant/", "version_or_date": "Croissant 1.1 (February 2026); Croissant RAI 1.0", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T12:00:00Z", "relevance": "Establishes the dataset sibling boundary: dataset-level metadata, provenance and governance, RAI extension building on PROV-O and DUO." }, { "id": "SRC-022", "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1", "organization": "National Institute of Standards and Technology", "url": "https://doi.org/10.6028/NIST.AI.100-1", "version_or_date": "1.0, January 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Separates the AI model dimension from the AI system; requires documented inventory, intended use and knowledge limits, mapped components, and model explanation, validation, and documentation (MAP/MEASURE/GOVERN)." }, { "id": "SRC-023", "title": "Hugging Face Hub documentation: Model Cards", "organization": "Hugging Face", "url": "https://huggingface.co/docs/hub/en/model-cards", "version_or_date": "Hub docs current 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Defines the de facto public model-artifact card: identity metadata, licence, datasets, base-model derivation, pipeline task, library, evaluation results, and human-readable intended use and limitations." }, { "id": "SRC-024", "title": "SPDX Specification 3.0.1: AIPackage class", "organization": "Linux Foundation / SPDX", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/AI/Classes/AIPackage/", "version_or_date": "3.0.1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Canonical AI package/model artifact properties: spdxId, name, packageVersion, downloadLocation, suppliedBy, releaseTime, verifiedUsing, typeOfModel, hyperparameters, metrics, limitations, energy, sensitive-personal-information, safety risk, validUntilTime." }, { "id": "SRC-025", "title": "ISO/IEC 22989:2022 Information technology — Artificial intelligence — Artificial intelligence concepts and terminology", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/standard/74296.html", "version_or_date": "2022-07 (Edition 1); AMD1 draft adds generative terms", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Terminology baseline for AI model, machine-learning model, and (in AMD1 draft) foundation model and large language model, distinguishing a model from an AI system." }, { "id": "SRC-026", "title": "ISO/IEC 23053:2022 Framework for Artificial Intelligence (AI) Systems Using Machine Learning (ML)", "organization": "ISO/IEC JTC 1/SC 42", "url": "https://www.iso.org/standard/74438.html", "version_or_date": "2022-06", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Places the trained model inside the ML-system framework and pipeline (data, modelling, verification and validation, deployment, operation) so the artifact is a component, not the whole system." }, { "id": "SRC-027", "title": "MLflow Model Registry documentation", "organization": "MLflow / LF AI & Data", "url": "https://mlflow.org/docs/latest/ml/model-registry/", "version_or_date": "docs/latest, accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Operational registry semantics: registered model, immutable version, URI, aliases, tags, lineage to producing run, signatures, and promotion workflows." }, { "id": "SRC-028", "title": "Hugging Face Hub modelcard.md metadata specification", "organization": "Hugging Face", "url": "https://github.com/huggingface/hub-docs/blob/main/modelcard.md", "version_or_date": "hub-docs main, accessed 2026-08-26", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Machine-validated YAML schema for licence, library_name, datasets, base_model, metrics, and model-index evaluation results including source URL and optional verifyToken." }, { "id": "SRC-029", "title": "Introduction to ONNX (Open Neural Network Exchange) 1.23.0", "organization": "LF AI & Data / ONNX", "url": "https://onnx.ai/onnx/intro/index.html", "version_or_date": "ONNX 1.23.0", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Interchange graph semantics for a model artifact: inputs, outputs, nodes, initializers (weights), opset, protobuf serialization, metadata, and shape/type inference." }, { "id": "SRC-030", "title": "Safetensors documentation", "organization": "Hugging Face", "url": "https://huggingface.co/docs/safetensors/index", "version_or_date": "current docs, accessed 2026-08-26", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-08-26T18:00:00Z", "relevance": "Widely used tensor-payload format for weight artifacts, designed as a safer alternative to pickle serialization." } ], "structure": { "bundles": [ { "id": "bnd-identity-classification", "name": "Identity and Classification", "description": "What this artifact is, how it is unambiguously named and pinned, how it is typed, and which regulatory status attaches to it.", "rationale": "Every downstream operation — verification, licensing, evaluation attachment, deletion — depends on resolving exactly which bytes and which release are meant. Standards give the artifact three independent identity layers (registry identifier, version label, content digest) and at least two orthogonal classification axes (technical type and regulatory status), so identity and classification must be settled first.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-002", "SRC-006" ], "layers": [ { "id": "lyr-artifact-identity", "name": "Identity, versioning and content addressing", "description": "Canonical identifiers, alias resolution, version semantics, immutable revision pinning and the separation of release time from ingestion time.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-010" ], "findings": [ { "id": "fnd-canonical-identity", "name": "Canonical identity and identifier set", "description": "The authoritative identifier for the artifact, the alias identifiers that resolve to it in other ecosystems, and what level of abstraction each identifier denotes.", "source_refs": [ "SRC-010", "SRC-007", "SRC-009", "SRC-001" ], "questions": [ { "id": "q-identity-authority", "text": "Which system of record assigns the authoritative identifier for this model artifact, and what is that identifier?", "kind": "identity", "answer_data": [ "Registry-of-record reference", "Authoritative identifier string", "Assignment date and assigning role" ] }, { "id": "q-identity-alias-set", "text": "Which alternate identifiers resolve to the same artifact across registries, package formats and BOM documents?", "kind": "interoperability", "answer_data": [ "Alias identifier list with issuing namespace", "Resolution rule or mapping table", "Precedence order when aliases disagree" ] }, { "id": "q-identity-abstraction-level", "text": "Does the identifier denote the abstract model family, a released version, or one immutable serialized snapshot?", "kind": "definition", "answer_data": [ "Identity scope level code", "Definition of the identified unit", "Example resolution for each level" ] }, { "id": "q-identity-collision-handling", "text": "How are identifier collisions, repository renames and namespace transfers detected and reconciled?", "kind": "validation", "answer_data": [ "Collision detection rule", "Rename/transfer event record", "Reconciliation decision and approver" ] } ], "data_elements": [ { "id": "de-canonical-artifact-id", "name": "Canonical artifact identifier", "description": "Identifier assigned by the registry of record for this artifact.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-009" ] }, { "id": "de-identifier-alias", "name": "Identifier alias", "description": "Equivalent identifier in another namespace (OCI reference, SPDX element IRI, hub repo id, DOI).", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-001", "SRC-009" ] }, { "id": "de-identity-scope-level", "name": "Identity scope level", "description": "Whether the identifier denotes family, version or immutable snapshot.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "de-registry-of-record", "name": "Registry of record", "description": "Reference to the master system that governs the canonical identifier.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-010", "SRC-017" ] } ], "artifacts": [ { "id": "art-artifact-identity-record", "name": "Artifact identity record", "description": "Governed record binding the canonical identifier, its scope level, aliases and the assigning registry.", "media_or_form": [ "structured record in the registry of record", "identifier mapping table", "BOM component entry with bom-ref" ], "serial": false, "identity_strategy": "Keyed by the canonical artifact identifier from the registry of record; aliases stored as attributed secondary keys, never as the primary key.", "source_refs": [ "SRC-010", "SRC-006", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "fnd-version-lineage", "name": "Version, revision and immutable pinning", "description": "Version scheme, the immutable revision or digest that pins exact bytes, supersession chains, and control of mutable pointers.", "source_refs": [ "SRC-005", "SRC-007", "SRC-009", "SRC-013" ], "questions": [ { "id": "q-version-scheme", "text": "What versioning scheme applies, and which change classes trigger a major, minor or patch increment?", "kind": "classification", "answer_data": [ "Version scheme identifier", "Change-class to increment mapping", "Governing policy reference" ] }, { "id": "q-revision-pin", "text": "Which immutable revision or content digest pins the exact bytes referenced by a given version label?", "kind": "identity", "answer_data": [ "Revision pin value", "Digest algorithm and encoded value", "Binding record between label and pin" ] }, { "id": "q-version-supersession", "text": "Which artifact version supersedes or is superseded by this one, and is the predecessor still resolvable?", "kind": "lifecycle", "answer_data": [ "Predecessor and successor references", "Supersession declaration", "Predecessor resolvability status" ] }, { "id": "q-mutable-pointer-control", "text": "Which mutable pointers may reference this artifact, and how is pointer drift detected and controlled?", "kind": "constraint", "answer_data": [ "Mutable pointer inventory", "Repoint event log", "Drift detection rule" ] }, { "id": "q-release-versus-ingestion-time", "text": "When was this version released, and how does release time differ from the time it was ingested into the registry of record?", "kind": "temporal", "answer_data": [ "Release timestamp", "Ingestion timestamp", "Reason for divergence where present" ] } ], "data_elements": [ { "id": "de-version-label", "name": "Version label", "description": "Human-facing version string for the artifact release.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-003" ] }, { "id": "de-revision-pin", "name": "Immutable revision pin", "description": "Commit-like revision or content digest that fixes the exact artifact bytes.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-013" ] }, { "id": "de-supersession-ref", "name": "Supersession reference", "description": "Reference to the version this artifact replaces or is replaced by.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-release-time", "name": "Release time", "description": "Event time at which this version was made available.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-ingestion-time", "name": "Ingestion time", "description": "Observation time at which the registry of record captured this version.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-012" ] } ], "artifacts": [ { "id": "art-version-manifest", "name": "Version and revision manifest", "description": "Record binding version label, immutable pin, supersession links and release/ingestion timestamps.", "media_or_form": [ "registry version record", "package descriptor with digest", "release note entry" ], "serial": true, "identity_strategy": "Canonical artifact identifier plus version label; the immutable revision pin is the tie-breaker and the integrity key.", "source_refs": [ "SRC-007", "SRC-005", "SRC-010" ] } ], "inline_only_rationale": null } ] }, { "id": "lyr-classification-taxonomy", "name": "Technical and regulatory classification", "description": "Typing of the artifact by architecture, task, modality and autonomy, and the regulatory status that determines which obligations apply.", "source_refs": [ "SRC-001", "SRC-006", "SRC-002", "SRC-003" ], "findings": [ { "id": "fnd-model-taxonomy", "name": "Model type, architecture family and task classification", "description": "Controlled classification of the artifact by architecture family, parameter scale, task, application domain and decision autonomy.", "source_refs": [ "SRC-001", "SRC-006", "SRC-011", "SRC-009" ], "questions": [ { "id": "q-model-type-value", "text": "What type of model is this by architecture family, specific architecture and parameter count?", "kind": "classification", "answer_data": [ "Architecture family code", "Specific architecture description", "Parameter count with unit" ] }, { "id": "q-task-classification", "text": "Which task or pipeline classification describes the artifact's primary intended function?", "kind": "classification", "answer_data": [ "Task code from the governing vocabulary", "Secondary task codes", "Modality pairing" ] }, { "id": "q-domain-autonomy", "text": "What application domain and level of decision autonomy is the artifact characterised for?", "kind": "definition", "answer_data": [ "Application domain code", "Autonomy type value", "Characterisation rationale" ] }, { "id": "q-taxonomy-governance", "text": "Which controlled vocabulary governs each classification value, and who may extend it?", "kind": "authority", "answer_data": [ "Vocabulary registry reference and version", "Extension approval role", "Handling of unmapped values" ] } ], "data_elements": [ { "id": "de-architecture-family", "name": "Architecture family", "description": "Coded family of the model architecture.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-011" ] }, { "id": "de-parameter-count", "name": "Parameter count", "description": "Number of trainable parameters, with counting convention.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-task-classification", "name": "Task classification", "description": "Coded task or pipeline the artifact is built to perform.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-009" ] }, { "id": "de-autonomy-type", "name": "Autonomy type", "description": "Characterised level of autonomous decision-making.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-application-domain", "name": "Application domain", "description": "Coded domain of intended application.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Classification is a set of coded attributes carried inline on the artifact record and echoed into model cards and BOM modelParameters; the governing code lists are external registry artifacts owned by a vocabulary model, not artifacts produced by this model. Creating a separate classification document would duplicate the model card and the BOM without adding a distinct governed object." }, { "id": "fnd-regulatory-status", "name": "Regulatory classification and applicable obligations", "description": "Whether the artifact is a general-purpose AI model, whether it crosses a systemic-risk threshold, which jurisdictions apply, and who holds provider obligations.", "source_refs": [ "SRC-002", "SRC-003", "SRC-016", "SRC-017" ], "questions": [ { "id": "q-gpai-status", "text": "Is the artifact a general-purpose AI model, and does it meet the systemic-risk threshold?", "kind": "classification", "answer_data": [ "GPAI determination and basis", "Systemic-risk determination", "Threshold evidence and assessment date" ] }, { "id": "q-open-source-exemption", "text": "Does a free and open-source release exempt this artifact from specific documentation duties, and on what evidence?", "kind": "exception", "answer_data": [ "Licence and public-availability evidence for parameters and architecture", "Exemption scope claimed", "Carve-out check for systemic risk" ] }, { "id": "q-placement-jurisdiction", "text": "In which jurisdictions is the artifact placed on the market or put into service, and which regimes therefore apply?", "kind": "spatial", "answer_data": [ "Jurisdiction codes", "Applicable regime per jurisdiction", "Placement date per jurisdiction" ] }, { "id": "q-obligation-holder", "text": "Which legal entity holds provider obligations, and when does that role transfer to a downstream modifier?", "kind": "authority", "answer_data": [ "Obligated provider reference", "Transfer trigger conditions", "Transfer event record" ] } ], "data_elements": [ { "id": "de-gpai-flag", "name": "General-purpose model flag", "description": "Whether the artifact is classified as a general-purpose AI model.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-002" ] }, { "id": "de-systemic-risk-flag", "name": "Systemic-risk flag", "description": "Whether the artifact is designated as carrying systemic risk.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-placement-jurisdiction", "name": "Placement jurisdiction", "description": "Jurisdiction where the artifact is made available.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-obligated-provider", "name": "Obligated provider", "description": "Legal entity holding provider obligations for the artifact.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-017" ] } ], "artifacts": [ { "id": "art-regulatory-classification-dossier", "name": "Regulatory classification dossier", "description": "Determination record for GPAI status, systemic risk, jurisdictions, exemptions and obligation holder.", "media_or_form": [ "determination record with rationale", "assessment memo", "compliance register entry" ], "serial": true, "identity_strategy": "Artifact identifier plus determination sequence; each re-determination is a new immutable entry citing the evidence and the deciding role.", "source_refs": [ "SRC-002", "SRC-003", "SRC-017" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bnd-provenance-integrity", "name": "Provenance, Lineage and Supply-Chain Integrity", "description": "Where the artifact came from, what it was derived from, what data underlies it, and how a consumer can prove that the bytes are the ones the producer signed.", "rationale": "Provenance and integrity are the only mechanisms by which any other claim about the artifact can be trusted. Build-provenance predicates, signed per-file manifests, transparency logs and bills of materials are separately specified and separately verifiable, so each needs its own finding rather than a single vague 'origin' concept.", "source_refs": [ "SRC-012", "SRC-013", "SRC-014", "SRC-006", "SRC-003", "SRC-015" ], "layers": [ { "id": "lyr-production-provenance", "name": "Production and derivation provenance", "description": "The producing run, the base models the artifact derives from, and the data corpora behind training, validation and testing.", "source_refs": [ "SRC-012", "SRC-009", "SRC-003", "SRC-011", "SRC-021" ], "findings": [ { "id": "fnd-producing-run", "name": "Producing training or build run", "description": "Resolvable reference to the run that produced the artifact, the builder identity that attests it, the recorded inputs and reproducibility status.", "source_refs": [ "SRC-012", "SRC-010", "SRC-003", "SRC-015" ], "questions": [ { "id": "q-produced-by-run", "text": "Which training or build run produced this artifact, and is that run reference resolvable today?", "kind": "provenance", "answer_data": [ "Producing run reference", "Invocation identifier", "Resolvability status and fallback" ] }, { "id": "q-builder-trust", "text": "Which build platform issued the provenance attestation, and what trust level does its builder identity carry?", "kind": "security", "answer_data": [ "Builder identity URI", "Attestation predicate type", "Trust-level assessment" ] }, { "id": "q-build-inputs", "text": "What external parameters, internal parameters and resolved dependencies were recorded for the producing run?", "kind": "composition", "answer_data": [ "External parameter set", "Internal parameter set", "Resolved dependency list with digests" ] }, { "id": "q-reproducibility-status", "text": "Can the artifact be re-derived from the recorded inputs, and which nondeterminism sources are documented?", "kind": "quality", "answer_data": [ "Reproducibility claim level", "Seed and determinism settings", "Known nondeterminism sources" ] }, { "id": "q-training-compute-effort", "text": "What compute resources and wall-clock training time were consumed to produce the artifact?", "kind": "measurement", "answer_data": [ "Compute quantity with unit", "Wall-clock training duration", "Measurement or estimation basis" ] } ], "data_elements": [ { "id": "de-producing-run-ref", "name": "Producing run reference", "description": "Reference to the training or build run that produced the artifact.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-010" ] }, { "id": "de-builder-identity", "name": "Builder identity", "description": "URI identifying the trusted build platform that issued provenance.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-resolved-dependency", "name": "Resolved dependency", "description": "Input artifact consumed by the build, pinned by digest.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "de-training-compute", "name": "Training compute", "description": "Compute consumed for training, with unit and basis.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-run-finished-time", "name": "Run finish time", "description": "Event time at which the producing run completed.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [ { "id": "art-build-provenance-attestation", "name": "Build provenance attestation", "description": "Signed statement binding the artifact digest as subject to its build definition and run details.", "media_or_form": [ "in-toto statement in a signed envelope", "provenance predicate document", "registry-attached attestation" ], "serial": true, "identity_strategy": "Subject digest of the artifact plus predicate type and issuing builder identity; one attestation per producing run.", "source_refs": [ "SRC-012", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "fnd-derivation-lineage", "name": "Derivation lineage from base models", "description": "Which upstream models the artifact derives from, by which operation, and which upstream terms propagate downstream.", "source_refs": [ "SRC-009", "SRC-011", "SRC-006", "SRC-002" ], "questions": [ { "id": "q-base-model-derivation", "text": "Which base model or models is this artifact derived from, and by which derivation operation?", "kind": "relationship", "answer_data": [ "Base model references", "Derivation relation code", "Derivation parameters" ] }, { "id": "q-lineage-chain-depth", "text": "How deep is the derivation chain, and is every upstream artifact individually identifiable?", "kind": "composition", "answer_data": [ "Ordered ancestor chain", "Per-ancestor identifier and pin", "Unresolvable ancestor flags" ] }, { "id": "q-merge-recipe", "text": "If the artifact is a merge, what are the constituent models and the combination method or weights?", "kind": "composition", "answer_data": [ "Constituent model list", "Merge method", "Per-constituent weighting" ] }, { "id": "q-inherited-terms", "text": "Which upstream licence terms, use restrictions or attribution duties propagate to this artifact?", "kind": "constraint", "answer_data": [ "Inherited restriction list", "Propagation rule per upstream licence", "Conflict resolution outcome" ] } ], "data_elements": [ { "id": "de-base-model-ref", "name": "Base model reference", "description": "Reference to an upstream model the artifact derives from.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-011" ] }, { "id": "de-derivation-relation", "name": "Derivation relation", "description": "Operation relating this artifact to its base: fine-tune, adapter, quantized, merge, distillation.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-merge-recipe", "name": "Merge recipe", "description": "Constituent models and combination method for merged artifacts.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-inherited-restriction", "name": "Inherited restriction", "description": "Use or redistribution restriction propagated from an upstream artifact.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-011" ] } ], "artifacts": [ { "id": "art-lineage-graph", "name": "Derivation lineage graph", "description": "Directed record of ancestors, derivation relations and propagated terms for the artifact.", "media_or_form": [ "graph record of typed edges", "BOM dependency/pedigree section", "lineage table in the registry of record" ], "serial": false, "identity_strategy": "Rooted at the artifact's canonical identifier; each edge keyed by ancestor pin plus derivation relation code.", "source_refs": [ "SRC-009", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "fnd-training-data-provenance", "name": "Training, validation and test data provenance", "description": "The datasets behind the artifact, their type, provenance and curation, the published training-content summary, and the presence of sensitive personal data.", "source_refs": [ "SRC-003", "SRC-004", "SRC-002", "SRC-001", "SRC-021" ], "questions": [ { "id": "q-data-sources-curation", "text": "What datasets, of what type and provenance, and with what curation methodology, underlie training, validation and testing?", "kind": "provenance", "answer_data": [ "Dataset references by role", "Provenance statement per dataset", "Curation and filtering methodology" ] }, { "id": "q-training-content-summary", "text": "Is a sufficiently detailed public summary of training content required, and where is the current version published?", "kind": "requirement", "answer_data": [ "Obligation determination", "Published summary location", "Summary version and revision date" ] }, { "id": "q-sensitive-personal-data", "text": "Does the training corpus contain sensitive or personal information, and under what lawful basis was it processed?", "kind": "privacy", "answer_data": [ "Sensitive personal information flag", "Category breakdown", "Lawful basis and safeguards" ] }, { "id": "q-split-integrity", "text": "How were data partitioned into training, validation and test splits, and was contamination between them assessed?", "kind": "validation", "answer_data": [ "Split definition and ratios", "Contamination assessment method", "Assessment result and date" ] } ], "data_elements": [ { "id": "de-dataset-ref-by-role", "name": "Dataset reference by role", "description": "Reference to a dataset used for training, validation or testing, with its role.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-021" ] }, { "id": "de-curation-method", "name": "Curation methodology", "description": "How data were selected, cleaned, filtered and checked for bias.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-sensitive-personal-info-flag", "name": "Sensitive personal information flag", "description": "Whether sensitive personal information was used.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-training-content-summary-ref", "name": "Training content summary reference", "description": "Pointer to the published summary of content used for training.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "art-training-data-summary", "name": "Training data provenance summary", "description": "Documented account of data type, provenance, curation and the publishable training-content summary.", "media_or_form": [ "public training-content summary", "internal data provenance dossier", "AIPackage informationAboutTraining field" ], "serial": true, "identity_strategy": "Artifact identifier plus summary revision; each revision timestamped with its own publication event time.", "source_refs": [ "SRC-002", "SRC-003", "SRC-001" ] } ], "inline_only_rationale": null } ] }, { "id": "lyr-supply-chain-integrity", "name": "Integrity, signing and composition transparency", "description": "Cryptographic proof that the artifact is unaltered and attributable, and machine-readable disclosure of what it is made of.", "source_refs": [ "SRC-013", "SRC-014", "SRC-007", "SRC-006", "SRC-008", "SRC-015" ], "findings": [ { "id": "fnd-signature-integrity", "name": "Cryptographic signing and integrity verification", "description": "Signature presence, signing identity and method, the manifest of per-file digests, transparency evidence and the required verification outcome.", "source_refs": [ "SRC-013", "SRC-014", "SRC-007", "SRC-015" ], "questions": [ { "id": "q-signature-identity-method", "text": "Is the artifact signed, by which identity, and under which signing method?", "kind": "security", "answer_data": [ "Signature reference", "Signing identity and certificate chain or keyless identity", "Signing method code" ] }, { "id": "q-manifest-coverage", "text": "Which files are covered by the signed manifest, and how are uncovered files treated at load time?", "kind": "validation", "answer_data": [ "Covered file list with digests", "Digest algorithm and sharding scheme", "Policy for uncovered or extra files" ] }, { "id": "q-transparency-evidence", "text": "Is the signing event recorded in an append-only log whose inclusion proof a verifier can check?", "kind": "evidence", "answer_data": [ "Transparency log entry identifier", "Inclusion proof availability", "Signing event time" ] }, { "id": "q-verification-gate", "text": "What verification outcome is required before the artifact may be promoted, distributed or served?", "kind": "requirement", "answer_data": [ "Required verification outcome", "Enforcement point", "Action on verification failure" ] } ], "data_elements": [ { "id": "de-signature-ref", "name": "Signature reference", "description": "Pointer to the detached signature or attestation bundle for the artifact.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-014" ] }, { "id": "de-digest-algorithm", "name": "Digest algorithm", "description": "Hash algorithm used for content addressing and manifest entries.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-013" ] }, { "id": "de-file-digest-entry", "name": "File digest entry", "description": "Path-and-digest pair covered by the signature manifest.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014", "SRC-013" ] }, { "id": "de-transparency-log-entry", "name": "Transparency log entry", "description": "Identifier of the append-only log record for the signing event.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-signing-event-time", "name": "Signing event time", "description": "Event time at which the signature was created.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "art-model-signature-bundle", "name": "Model signature bundle", "description": "Detached signature over a manifest of per-file digests, with verification material.", "media_or_form": [ "detached signature file", "signed envelope containing an in-toto statement", "registry-attached signature" ], "serial": true, "identity_strategy": "Keyed by the manifest digest and the signing identity; re-signing produces a new bundle rather than mutating the existing one.", "source_refs": [ "SRC-013", "SRC-014" ] } ], "inline_only_rationale": null }, { "id": "fnd-bom-composition", "name": "Bill of materials and component transparency", "description": "Machine-readable enumeration of the model, data and software components the artifact comprises or depends on, and how it is kept current.", "source_refs": [ "SRC-006", "SRC-001", "SRC-015", "SRC-008" ], "questions": [ { "id": "q-bom-presence", "text": "Does a machine-readable bill of materials enumerate the artifact's model, data and software components?", "kind": "composition", "answer_data": [ "BOM reference", "Component entries by type", "Completeness statement" ] }, { "id": "q-bom-format-authority", "text": "Which BOM format and version is authoritative, and how are parallel formats kept consistent?", "kind": "interoperability", "answer_data": [ "Authoritative BOM format and version", "Secondary formats emitted", "Consistency check procedure" ] }, { "id": "q-unsafe-component-exposure", "text": "Which third-party components introduce known vulnerabilities or unsafe deserialisation paths?", "kind": "security", "answer_data": [ "Vulnerable component list", "Unsafe-format flag per weight file", "Mitigation or conversion action" ] }, { "id": "q-bom-refresh-binding", "text": "When is the BOM regenerated, and how is it bound to a specific artifact revision?", "kind": "process", "answer_data": [ "Regeneration trigger", "Binding key to artifact revision", "Last generation timestamp" ] } ], "data_elements": [ { "id": "de-bom-ref", "name": "Bill of materials reference", "description": "Pointer to the authoritative BOM for this artifact revision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-bom-format", "name": "BOM format and version", "description": "Format identifier and version of the authoritative BOM.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-001" ] }, { "id": "de-component-entry", "name": "Component entry", "description": "One enumerated component with its type, identifier and digest.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-unsafe-format-flag", "name": "Unsafe deserialisation flag", "description": "Whether any packaged weight file uses a format permitting code execution on load.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-008", "SRC-015" ] } ], "artifacts": [ { "id": "art-ml-bom", "name": "Machine learning bill of materials", "description": "BOM enumerating model, data and software components with types, identifiers and digests.", "media_or_form": [ "ML-BOM document", "SPDX AI package document", "component inventory record" ], "serial": true, "identity_strategy": "BOM serial number plus version, bound to the artifact's immutable revision pin.", "source_refs": [ "SRC-006", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bnd-composition-interface", "name": "Technical Composition and Interface Contract", "description": "How the artifact is serialized and packaged, which components it comprises, what interface it exposes to callers, and what runtime it needs.", "rationale": "An agent cannot load, call or port an artifact without the serialization contract, the declared input/output signature and the execution requirements. These are specified by independent format and framework standards and are the layer at which portability actually succeeds or fails.", "source_refs": [ "SRC-008", "SRC-011", "SRC-005", "SRC-010", "SRC-020", "SRC-004" ], "layers": [ { "id": "lyr-serialization-packaging", "name": "Serialization and packaging", "description": "Weight file format, numeric precision and quantization, sharding, and the role-typed inventory of packaged components.", "source_refs": [ "SRC-008", "SRC-011", "SRC-020", "SRC-005" ], "findings": [ { "id": "fnd-serialization-precision", "name": "Serialization format, precision and quantization", "description": "The on-disk format and version of the weights, the numeric precision or quantization scheme, safe-loading properties and shard layout.", "source_refs": [ "SRC-008", "SRC-011", "SRC-005", "SRC-015" ], "questions": [ { "id": "q-serialization-format", "text": "In which serialization format are the weights stored, and at which version of that format?", "kind": "definition", "answer_data": [ "Format identifier", "Format version", "Endianness and layout constraints" ] }, { "id": "q-precision-quantization", "text": "What numeric precision or quantization scheme do the stored tensors use, and against which reference precision?", "kind": "measurement", "answer_data": [ "Tensor data types", "Quantization scheme and version", "Reference precision and measured deviation" ] }, { "id": "q-safe-loading", "text": "Does the format permit arbitrary code execution on load, and what mitigation is enforced?", "kind": "security", "answer_data": [ "Code-execution risk determination", "Mitigation or format conversion applied", "Loader allow-list" ] }, { "id": "q-shard-completeness", "text": "How is the artifact sharded across files, and how is shard completeness verified before use?", "kind": "validation", "answer_data": [ "Shard count and index", "Per-shard digest", "Completeness verification rule" ] } ], "data_elements": [ { "id": "de-serialization-format", "name": "Serialization format", "description": "Coded format in which weights are stored.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-011" ] }, { "id": "de-tensor-dtype", "name": "Tensor data type", "description": "Numeric type of stored tensors.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-011" ] }, { "id": "de-quantization-scheme", "name": "Quantization scheme", "description": "Quantization method and version applied to the weights.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-009" ] }, { "id": "de-shard-count", "name": "Shard count", "description": "Number of files across which weights are split.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020" ] }, { "id": "de-total-size-bytes", "name": "Total artifact size", "description": "Total byte size of the packaged artifact.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-010" ] } ], "artifacts": [ { "id": "art-weight-file-set", "name": "Weight file set", "description": "The serialized tensor files, including headers, offsets and any shard index.", "media_or_form": [ "binary tensor file with typed header", "quantized weight container", "sharded weight file group with index" ], "serial": true, "identity_strategy": "Each file identified by its content digest; the set identified by the artifact revision pin plus a shard index enumerating all digests.", "source_refs": [ "SRC-008", "SRC-011", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "fnd-component-inventory", "name": "Packaged component inventory", "description": "Which components are mandatory versus optional, what role each plays, how the model card is bound to the revision, and the packaging envelope used.", "source_refs": [ "SRC-020", "SRC-009", "SRC-010", "SRC-019" ], "questions": [ { "id": "q-required-components", "text": "Which components are mandatory for the artifact to be loadable, and which are optional accompaniments?", "kind": "composition", "answer_data": [ "Mandatory component list", "Optional component list", "Failure behaviour when a mandatory component is missing" ] }, { "id": "q-component-roles", "text": "What role does each packaged component play — weights, weight configuration, code, documentation or dataset?", "kind": "classification", "answer_data": [ "Role code per component", "Media type per component", "Role-to-layer mapping" ] }, { "id": "q-card-revision-binding", "text": "How is the human-readable model card bound to the exact artifact revision it describes?", "kind": "relationship", "answer_data": [ "Model card reference", "Binding key to revision pin", "Card revision timestamp" ] }, { "id": "q-packaging-envelope", "text": "Into which packaging or registry envelope is the component set published?", "kind": "interoperability", "answer_data": [ "Envelope artifact type", "Manifest configuration type", "Registry location" ] } ], "data_elements": [ { "id": "de-component-file", "name": "Component file", "description": "One packaged file with its path, digest and size.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-020", "SRC-007" ] }, { "id": "de-component-role", "name": "Component role", "description": "Functional role of a packaged component.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-020" ] }, { "id": "de-model-card-ref", "name": "Model card reference", "description": "Pointer to the documentation card describing this revision.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-019" ] }, { "id": "de-packaging-artifact-type", "name": "Packaging artifact type", "description": "Artifact type of the publishing envelope.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-020", "SRC-007" ] } ], "artifacts": [ { "id": "art-package-manifest", "name": "Package manifest", "description": "Manifest listing role-typed component layers with media types, digests and sizes.", "media_or_form": [ "OCI-style image manifest with typed layers", "framework model descriptor file", "package index record" ], "serial": true, "identity_strategy": "Manifest content digest; the manifest is itself content-addressed and is the join point between the artifact identifier and its component digests.", "source_refs": [ "SRC-020", "SRC-007" ] }, { "id": "art-model-card", "name": "Model card", "description": "Human- and machine-readable card carrying metadata and the narrative documentation sections.", "media_or_form": [ "documentation card with structured metadata block", "rendered card page", "card template instance" ], "serial": true, "identity_strategy": "Bound to the artifact revision pin; card revisions are versioned alongside the artifact and carry their own last-revision timestamp.", "source_refs": [ "SRC-009", "SRC-019" ] } ], "inline_only_rationale": null } ] }, { "id": "lyr-interface-execution", "name": "Interface contract and execution environment", "description": "The declared call contract of the artifact and the runtime, operator-set and hardware conditions under which that contract holds.", "source_refs": [ "SRC-010", "SRC-005", "SRC-004", "SRC-006" ], "findings": [ { "id": "fnd-io-signature", "name": "Input/output signature and modality", "description": "Declared schema for inputs, outputs and inference parameters, supported modalities, size and context limits, and caller validation.", "source_refs": [ "SRC-010", "SRC-004", "SRC-006", "SRC-005" ], "questions": [ { "id": "q-io-schema", "text": "What is the declared schema of the artifact's inputs, outputs and inference parameters?", "kind": "definition", "answer_data": [ "Input schema", "Output schema", "Inference parameter schema" ] }, { "id": "q-io-modality", "text": "Which input and output modalities and formats does the artifact accept and produce?", "kind": "classification", "answer_data": [ "Input modality codes", "Output modality codes", "Encoding or format per modality" ] }, { "id": "q-io-limits", "text": "What maximum input size, context window or sequence limits constrain a valid call?", "kind": "constraint", "answer_data": [ "Context window size", "Maximum input and output sizes", "Behaviour on limit breach" ] }, { "id": "q-io-validation", "text": "How is a caller's payload validated against the declared signature before inference runs?", "kind": "validation", "answer_data": [ "Validation mechanism", "Enforcement point", "Rejection semantics" ] }, { "id": "q-runtime-opset-requirement", "text": "Which operator set, graph IR version or tokenizer vocabulary must a runtime support to execute the artifact?", "kind": "interoperability", "answer_data": [ "Operator set domain and version pairs", "IR version", "Tokenizer or vocabulary reference" ] } ], "data_elements": [ { "id": "de-input-schema", "name": "Input schema", "description": "Declared structure and types of accepted inputs.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-006" ] }, { "id": "de-output-schema", "name": "Output schema", "description": "Declared structure and types of produced outputs.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-006" ] }, { "id": "de-io-modality", "name": "Input/output modality", "description": "Modality and format of inputs and outputs.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-context-window", "name": "Context window size", "description": "Maximum input context length accepted by the artifact.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "de-opset-requirement", "name": "Operator set requirement", "description": "Domain and version pairs a runtime must implement.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [ { "id": "art-io-schema-record", "name": "Interface signature record", "description": "Machine-readable declaration of input, output and parameter schemas plus modality and size limits.", "media_or_form": [ "model signature descriptor", "schema document", "interface section of the model descriptor" ], "serial": false, "identity_strategy": "Bound to the artifact revision pin; a change to the signature is a breaking change requiring a new artifact version.", "source_refs": [ "SRC-010", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "fnd-execution-environment", "name": "Execution environment and runtime dependencies", "description": "Runtimes and library flavors that can load the artifact, hardware minimums, pinned production versions and behaviour outside the certified envelope.", "source_refs": [ "SRC-010", "SRC-004", "SRC-003", "SRC-020" ], "questions": [ { "id": "q-runtime-loadability", "text": "Which runtime, library and flavor combinations can load and execute this artifact?", "kind": "requirement", "answer_data": [ "Supported flavor list", "Minimum library versions", "Loader entry point" ] }, { "id": "q-hardware-minimums", "text": "What accelerator, memory and driver minimums are required for inference at the declared precision?", "kind": "constraint", "answer_data": [ "Accelerator requirement", "Memory requirement with unit", "Driver or toolkit minimum version" ] }, { "id": "q-environment-pinning", "text": "Which exact dependency versions were used at production time, and which are certified for serving?", "kind": "provenance", "answer_data": [ "Production environment pin set", "Certified serving environment set", "Divergence justification" ] }, { "id": "q-uncertified-execution", "text": "What happens when the artifact runs outside its certified environment, and is that configuration blocked or only flagged?", "kind": "exception", "answer_data": [ "Detection mechanism", "Blocking or warning decision", "Recorded exception approvals" ] } ], "data_elements": [ { "id": "de-runtime-flavor", "name": "Runtime flavor", "description": "Declared loadable interface a deployment tool can use.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "de-framework-version", "name": "Framework version requirement", "description": "Library or framework version constraint for loading the artifact.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-004" ] }, { "id": "de-accelerator-requirement", "name": "Accelerator requirement", "description": "Required accelerator class and capability level.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-certified-environment", "name": "Certified environment", "description": "Environment configuration approved for serving this artifact.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-010", "SRC-017" ] } ], "artifacts": [ { "id": "art-environment-specification", "name": "Execution environment specification", "description": "Pinned dependency and hardware specification for reproducing and serving the artifact.", "media_or_form": [ "environment specification file", "dependency lock record", "runtime compatibility matrix" ], "serial": true, "identity_strategy": "Bound to the artifact revision pin plus environment profile name; each certified profile is versioned independently.", "source_refs": [ "SRC-010", "SRC-012" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bnd-evidence-behaviour", "name": "Evidence, Behaviour and Declared Limits", "description": "What is known and claimed about how the artifact behaves: measured results, intended and prohibited use, safety and fairness evidence, and environmental cost.", "rationale": "Documentation standards and the GPAI documentation regime converge on the same evidence set — metrics with thresholds, disaggregated results, intended use and limitations, adversarial testing, and energy consumption — and all of it must be attached to a specific revision to be meaningful.", "source_refs": [ "SRC-019", "SRC-009", "SRC-006", "SRC-001", "SRC-003", "SRC-016" ], "layers": [ { "id": "lyr-performance-evidence", "name": "Performance evidence and declared use", "description": "Reported metrics with their provenance and thresholds, and the declared boundary of appropriate use.", "source_refs": [ "SRC-019", "SRC-009", "SRC-001", "SRC-006" ], "findings": [ { "id": "fnd-evaluation-attachment", "name": "Attached evaluation results and their evidentiary status", "description": "Which results are attached to this revision, who produced them under which protocol, what thresholds they are judged against, and whether they are still current.", "source_refs": [ "SRC-009", "SRC-001", "SRC-006", "SRC-019" ], "questions": [ { "id": "q-reported-metrics", "text": "Which metrics, on which datasets and splits, are reported for this artifact revision?", "kind": "measurement", "answer_data": [ "Metric name, type and value", "Evaluation dataset, config and split", "Reporting units and confidence intervals" ] }, { "id": "q-evaluation-provenance", "text": "Who produced each reported result, under which protocol, and is it independently reproducible?", "kind": "evidence", "answer_data": [ "Evaluator identity and independence status", "Protocol or leaderboard source", "Reproduction instructions or blockers" ] }, { "id": "q-decision-threshold", "text": "What decision thresholds are attached to each metric for promotion, rejection or rollback?", "kind": "decision", "answer_data": [ "Threshold value per metric", "Decision rule", "Threshold owner" ] }, { "id": "q-evaluation-currency", "text": "As of when was each result measured, and does it still apply to the current revision?", "kind": "temporal", "answer_data": [ "Measurement event time", "Revision the result was measured against", "Currency status and expiry rule" ] } ], "data_elements": [ { "id": "de-reported-metric", "name": "Reported metric", "description": "Named metric with type, value and evaluation context.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-001" ] }, { "id": "de-evaluation-dataset-ref", "name": "Evaluation dataset reference", "description": "Dataset, config and split against which a metric was measured.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009", "SRC-006" ] }, { "id": "de-metric-decision-threshold", "name": "Metric decision threshold", "description": "Threshold value against which a metric drives a decision.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-measurement-time", "name": "Measurement time", "description": "Event time at which a reported result was measured.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-evaluation-record-ref", "name": "Evaluation record reference", "description": "Pointer to the authoritative evaluation record in the evaluation model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] } ], "artifacts": [ { "id": "art-evaluation-result-set", "name": "Attached evaluation result set", "description": "Structured set of reported results with dataset, metric, value, source and measurement time.", "media_or_form": [ "structured results index in the model card", "quantitative analysis section of a BOM model card", "results table with source attribution" ], "serial": true, "identity_strategy": "Artifact revision pin plus evaluation record reference and measurement time; results are append-only and never edited in place.", "source_refs": [ "SRC-009", "SRC-006" ] } ], "inline_only_rationale": null }, { "id": "fnd-intended-use-limits", "name": "Intended use, users and technical limitations", "description": "The declared purpose boundary: intended tasks and users, out-of-scope or prohibited uses, documented limitations and trade-offs, and explainability information.", "source_refs": [ "SRC-019", "SRC-006", "SRC-003", "SRC-001" ], "questions": [ { "id": "q-intended-use", "text": "What are the intended tasks, intended users and in-scope use cases for this artifact?", "kind": "definition", "answer_data": [ "Intended task statements", "Intended user categories", "In-scope use case list" ] }, { "id": "q-out-of-scope-use", "text": "Which uses are explicitly out of scope or prohibited by the acceptable use policy?", "kind": "constraint", "answer_data": [ "Out-of-scope use list", "Acceptable use policy reference", "Enforcement mechanism" ] }, { "id": "q-known-limitations", "text": "Which technical limitations and performance trade-offs are known and documented?", "kind": "quality", "answer_data": [ "Technical limitation statements", "Performance trade-off descriptions", "Conditions under which limitations bind" ] }, { "id": "q-explainability-information", "text": "What explainability or interpretability information accompanies the artifact?", "kind": "evidence", "answer_data": [ "Explainability approach description", "Available interpretability outputs", "Known interpretability gaps" ] } ], "data_elements": [ { "id": "de-intended-task", "name": "Intended task", "description": "Task the artifact is intended to perform.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-019" ] }, { "id": "de-out-of-scope-use", "name": "Out-of-scope use", "description": "Use explicitly declared inappropriate or prohibited.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-006" ] }, { "id": "de-technical-limitation", "name": "Technical limitation", "description": "Documented limitation constraining reliable performance.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-001" ] }, { "id": "de-acceptable-use-policy-ref", "name": "Acceptable use policy reference", "description": "Pointer to the acceptable use policy governing the artifact.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-explainability-note", "name": "Explainability information", "description": "Description of interpretability approaches available for the artifact.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [ { "id": "art-intended-use-statement", "name": "Intended use and limitations statement", "description": "Declared purpose boundary, prohibited uses, limitations and trade-offs for the artifact.", "media_or_form": [ "intended use section of the model card", "acceptable use policy document", "considerations section of a BOM model card" ], "serial": true, "identity_strategy": "Bound to the artifact revision; each revision of the statement carries its own effective date and approving role.", "source_refs": [ "SRC-019", "SRC-006", "SRC-003" ] } ], "inline_only_rationale": null } ] }, { "id": "lyr-risk-safety-impact", "name": "Risk, fairness and environmental impact", "description": "Safety assessment and adversarial testing, disaggregated fairness evidence, and the energy and emissions footprint of the artifact.", "source_refs": [ "SRC-003", "SRC-001", "SRC-019", "SRC-009", "SRC-016" ], "findings": [ { "id": "fnd-safety-adversarial", "name": "Safety risk assessment and adversarial testing", "description": "The safety assessment performed on the artifact, adversarial testing conducted, mitigations bound to the weights themselves, and re-assessment triggers.", "source_refs": [ "SRC-003", "SRC-001", "SRC-016", "SRC-015" ], "questions": [ { "id": "q-safety-assessment", "text": "What safety risk assessment has been performed on the artifact, and which residual risks remain?", "kind": "evidence", "answer_data": [ "Assessment reference and method", "Identified hazards", "Residual risk statements and acceptance" ] }, { "id": "q-adversarial-testing", "text": "What internal or external adversarial testing was conducted, by whom, and with what results?", "kind": "process", "answer_data": [ "Testing measures and scope", "Tester identity and independence", "Findings and remediation status" ] }, { "id": "q-embedded-mitigations", "text": "Which mitigations are bound to the artifact itself rather than to the system around it?", "kind": "requirement", "answer_data": [ "Weight-level or training-level mitigation list", "Mitigations delegated to the embedding system", "Verification that a mitigation survives fine-tuning" ] }, { "id": "q-reassessment-trigger", "text": "Which events trigger re-assessment of the artifact's safety profile?", "kind": "event", "answer_data": [ "Trigger event catalogue", "Re-assessment deadline per trigger", "Last assessment event time" ] } ], "data_elements": [ { "id": "de-safety-risk-assessment-ref", "name": "Safety risk assessment reference", "description": "Pointer to the safety risk assessment for the artifact.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-adversarial-test-record", "name": "Adversarial test record", "description": "Record of adversarial testing measures, testers and outcomes.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-residual-risk", "name": "Residual risk", "description": "Risk remaining after mitigation, with acceptance decision.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-embedded-mitigation", "name": "Artifact-bound mitigation", "description": "Mitigation implemented within the artifact rather than the surrounding system.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-015" ] } ], "artifacts": [ { "id": "art-safety-assessment-report", "name": "Safety and adversarial testing report", "description": "Report of hazards, adversarial testing measures and results, mitigations and residual risk acceptance.", "media_or_form": [ "safety risk assessment report", "adversarial testing summary", "risk register entry" ], "serial": true, "identity_strategy": "Artifact revision pin plus assessment sequence number; superseded assessments are retained, not overwritten.", "source_refs": [ "SRC-003", "SRC-001", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "fnd-fairness-bias", "name": "Fairness, bias and evaluation factors", "description": "Relevant evaluation factors, disaggregated performance across groups and intersections, bias detection measures, and who accepts the fairness evidence.", "source_refs": [ "SRC-019", "SRC-006", "SRC-003", "SRC-016" ], "questions": [ { "id": "q-evaluation-factors", "text": "Which demographic, environmental and instrumentation factors are relevant to disaggregated evaluation of this artifact?", "kind": "classification", "answer_data": [ "Factor list with definitions", "Rationale for factor selection", "Factors deliberately excluded and why" ] }, { "id": "q-disaggregated-performance", "text": "How does performance vary across the relevant factor groups and their intersections?", "kind": "measurement", "answer_data": [ "Per-group metric values", "Intersectional results", "Group sample sizes and uncertainty" ] }, { "id": "q-bias-detection-measures", "text": "What bias detection and mitigation measures were applied to the data and to the model?", "kind": "process", "answer_data": [ "Detection method per stage", "Mitigation applied", "Post-mitigation measurement" ] }, { "id": "q-fairness-acceptance", "text": "Who accepts that fairness evidence is sufficient for the intended deployment context?", "kind": "authority", "answer_data": [ "Accepting role", "Acceptance criteria", "Acceptance event time" ] } ], "data_elements": [ { "id": "de-evaluation-factor", "name": "Evaluation factor", "description": "Factor along which performance is disaggregated.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "de-disaggregated-result", "name": "Disaggregated result", "description": "Metric value for a specific factor group or intersection.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-006" ] }, { "id": "de-bias-detection-measure", "name": "Bias detection measure", "description": "Method used to detect bias in data or model.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003" ] }, { "id": "de-fairness-assessment-ref", "name": "Fairness assessment reference", "description": "Pointer to the fairness assessment for this artifact.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Fairness evidence for a model artifact is a disaggregated view of the same measurements captured in the attached evaluation result set and the considerations section of the model card; it does not have an independently governed carrier. Where a standalone fairness audit exists, it is an evaluation record owned by WM-AI-003 and is referenced here rather than duplicated as an artifact of this model." }, { "id": "fnd-environmental-footprint", "name": "Energy and environmental footprint", "description": "Energy consumed for training, fine-tuning and inference, reported emissions equivalent, whether figures are measured or estimated, and the covered period.", "source_refs": [ "SRC-001", "SRC-003", "SRC-009" ], "questions": [ { "id": "q-energy-consumption", "text": "How much energy was consumed for training, for fine-tuning and per unit of inference?", "kind": "measurement", "answer_data": [ "Training energy with unit", "Fine-tuning energy with unit", "Inference energy per unit of work" ] }, { "id": "q-emissions-accounting", "text": "What greenhouse-gas equivalent is reported, and under which accounting method and grid assumptions?", "kind": "measurement", "answer_data": [ "Emissions equivalent with unit", "Accounting method", "Grid intensity and location assumptions" ] }, { "id": "q-footprint-basis", "text": "Are the reported figures measured or estimated, and what uncertainty is stated?", "kind": "quality", "answer_data": [ "Measured versus estimated designation", "Instrumentation or estimation model", "Stated uncertainty range" ] }, { "id": "q-footprint-period", "text": "Which time window and which hardware fleet do the reported figures cover?", "kind": "temporal", "answer_data": [ "Coverage start and end times", "Hardware fleet description", "Excluded activities" ] } ], "data_elements": [ { "id": "de-training-energy", "name": "Training energy consumption", "description": "Energy consumed during training, with unit.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-003" ] }, { "id": "de-inference-energy", "name": "Inference energy consumption", "description": "Energy consumed per unit of inference, with unit.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "de-emissions-equivalent", "name": "Emissions equivalent", "description": "Reported greenhouse-gas equivalent for the artifact.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-footprint-basis", "name": "Footprint measurement basis", "description": "Whether figures are measured or estimated and by what method.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-001" ] } ], "artifacts": [ { "id": "art-energy-consumption-record", "name": "Energy and emissions record", "description": "Structured record of training, fine-tuning and inference energy with emissions equivalent and accounting basis.", "media_or_form": [ "energy consumption description record", "emissions declaration in the model card", "AIPackage energy consumption structure" ], "serial": true, "identity_strategy": "Artifact revision pin plus reporting period; each reporting period is a separate immutable entry.", "source_refs": [ "SRC-001", "SRC-009", "SRC-003" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bnd-rights-distribution", "name": "Rights, Distribution and Access", "description": "Who may hold, use, redistribute and modify the artifact, on what terms, through which channels, and under which access and export constraints.", "rationale": "Rights and access are decided at the artifact level, not the system level, and they gate every downstream action. Licence identifiers, copyright and text-and-data-mining policy, distribution channels and gating conditions are all separately specified and separately enforceable.", "source_refs": [ "SRC-009", "SRC-011", "SRC-002", "SRC-003", "SRC-015" ], "layers": [ { "id": "lyr-licensing-rights", "name": "Licensing and rights", "description": "Licence identification across components, use restrictions, attribution duties, copyright policy and third-party rights handling.", "source_refs": [ "SRC-009", "SRC-011", "SRC-002", "SRC-006" ], "findings": [ { "id": "fnd-license-terms", "name": "Licence, use restrictions and attribution", "description": "The licence governing the weights and each other component, restrictions it imposes, and required attribution or notice.", "source_refs": [ "SRC-009", "SRC-011", "SRC-003", "SRC-006" ], "questions": [ { "id": "q-license-identifier", "text": "Which licence governs the weights, and is it expressed as a resolvable standard identifier or a custom document?", "kind": "identity", "answer_data": [ "Licence identifier or expression", "Custom licence name and link", "Resolution status of the identifier" ] }, { "id": "q-component-license-divergence", "text": "Do weights, code, tokenizer and documentation carry different licences?", "kind": "composition", "answer_data": [ "Licence per component role", "Divergence points", "Combined-use implications" ] }, { "id": "q-use-restriction", "text": "Which field-of-use, redistribution or derivative restrictions does the licence impose?", "kind": "constraint", "answer_data": [ "Restriction statements", "Permitted derivative operations", "Redistribution conditions" ] }, { "id": "q-attribution-duty", "text": "What attribution or notice must a downstream user reproduce?", "kind": "requirement", "answer_data": [ "Required notice text", "Placement requirement", "Notice inheritance to derivatives" ] } ], "data_elements": [ { "id": "de-license-identifier", "name": "Licence identifier", "description": "Standard licence identifier or expression governing the weights.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-009" ] }, { "id": "de-license-link", "name": "Licence document link", "description": "Pointer to the licence text where it is custom or not standard-identified.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-component-license", "name": "Component licence", "description": "Licence applying to a specific packaged component role.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-020" ] }, { "id": "de-use-restriction", "name": "Use restriction", "description": "Restriction on field of use, redistribution or derivation.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-003", "SRC-009" ] } ], "artifacts": [ { "id": "art-license-document", "name": "Licence and notice set", "description": "The licence text or identifier plus any required attribution notices, per component role.", "media_or_form": [ "licence document packaged with the artifact", "licence identifier field in the artifact metadata", "notice file" ], "serial": false, "identity_strategy": "Standard licence identifier where one exists; otherwise the licence document digest plus a stable custom licence name.", "source_refs": [ "SRC-009", "SRC-011" ] } ], "inline_only_rationale": null }, { "id": "fnd-ip-copyright-policy", "name": "Copyright policy, rights reservation and claims", "description": "The documented copyright compliance policy, how machine-readable rights reservations were honoured during data acquisition, and how post-release claims are handled.", "source_refs": [ "SRC-002", "SRC-003", "SRC-017" ], "questions": [ { "id": "q-copyright-policy", "text": "Is there a documented policy for complying with copyright law, and where is it maintained?", "kind": "requirement", "answer_data": [ "Policy reference and owner", "Scope of application", "Last review date" ] }, { "id": "q-rights-reservation-handling", "text": "How were machine-readable rights reservations detected and honoured during data acquisition?", "kind": "process", "answer_data": [ "Detection mechanism", "Exclusion handling procedure", "Coverage and known gaps" ] }, { "id": "q-third-party-claim", "text": "What process handles third-party rights claims raised against the artifact after release?", "kind": "exception", "answer_data": [ "Claim intake route", "Assessment and response procedure", "Possible outcomes including withdrawal" ] }, { "id": "q-rights-liability", "text": "Who bears liability for rights infringement arising from the artifact or its outputs?", "kind": "ownership", "answer_data": [ "Liability allocation statement", "Contractual basis", "Indemnity scope and limits" ] } ], "data_elements": [ { "id": "de-copyright-policy-ref", "name": "Copyright policy reference", "description": "Pointer to the copyright compliance policy applying to the artifact.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-rights-reservation-handling", "name": "Rights reservation handling", "description": "Description of how rights reservations were detected and respected.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-rights-claim-record", "name": "Rights claim record", "description": "Record of a third-party rights claim and its disposition.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] } ], "artifacts": [], "inline_only_rationale": "The copyright policy is an organisation-level document owned by the provider's governance model, not an artifact produced per model. What this model holds is a reference to that policy, an inline statement of how reservations were honoured for this artifact's corpus, and claim records that belong to a case-management model. Minting a per-artifact copyright artifact would create an unmaintained copy of an organisational policy." } ] }, { "id": "lyr-distribution-access", "name": "Distribution and access control", "description": "Where the artifact is published, in what release mode, how mirrors are validated, and what gating, export and residency constraints apply.", "source_refs": [ "SRC-003", "SRC-002", "SRC-009", "SRC-007", "SRC-015" ], "findings": [ { "id": "fnd-distribution-channels", "name": "Release, distribution channels and mirrors", "description": "Channels through which the artifact is distributed, which is authoritative, how mirrors are validated, and how a release is withdrawn.", "source_refs": [ "SRC-003", "SRC-004", "SRC-007", "SRC-020" ], "questions": [ { "id": "q-distribution-channels", "text": "Through which channels is the artifact distributed, and which one is authoritative?", "kind": "process", "answer_data": [ "Channel inventory", "Authoritative location reference", "Channel-specific publication times" ] }, { "id": "q-release-mode", "text": "Is the release open-weights, gated, API-only or internal-only?", "kind": "classification", "answer_data": [ "Release mode code", "Basis for the mode decision", "Consequences for documentation duties" ] }, { "id": "q-mirror-equivalence", "text": "How is a mirrored or cached copy proven equivalent to the authoritative release?", "kind": "validation", "answer_data": [ "Equivalence check method", "Digest comparison result", "Divergence handling" ] }, { "id": "q-release-withdrawal", "text": "What is the procedure for withdrawing a released artifact from each channel?", "kind": "event", "answer_data": [ "Withdrawal trigger and approver", "Per-channel withdrawal steps", "Residual copies that cannot be withdrawn" ] } ], "data_elements": [ { "id": "de-distribution-channel", "name": "Distribution channel", "description": "A channel through which the artifact is made available.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-authoritative-location", "name": "Authoritative location", "description": "Reference to the location holding the authoritative copy.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-020" ] }, { "id": "de-release-mode", "name": "Release mode", "description": "Coded mode under which the artifact is released.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-003" ] }, { "id": "de-mirror-ref", "name": "Mirror reference", "description": "Known mirror or cache holding a copy of the artifact.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007" ] } ], "artifacts": [ { "id": "art-release-record", "name": "Release record", "description": "Record of the release event, its mode, channels, authoritative location and withdrawal status.", "media_or_form": [ "release record in the registry of record", "publication event entry", "distribution register row" ], "serial": true, "identity_strategy": "Artifact revision pin plus channel identifier; each channel publication is a distinct immutable event with its own event time.", "source_refs": [ "SRC-003", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "fnd-access-gating", "name": "Access gating, confidentiality and export control", "description": "Default access rule for the weights, the conditions that gate access, export-control classification and permitted storage or processing locations.", "source_refs": [ "SRC-002", "SRC-009", "SRC-015", "SRC-017" ], "questions": [ { "id": "q-default-access-rule", "text": "What is the default access rule for the artifact's weights, and who may grant exceptions?", "kind": "access", "answer_data": [ "Default rule statement", "Exception-granting role", "Exception record format" ] }, { "id": "q-gating-conditions", "text": "Which conditions gate access, and how is satisfaction of each condition evidenced?", "kind": "security", "answer_data": [ "Gating condition list", "Evidence captured per condition", "Revocation conditions" ] }, { "id": "q-export-control", "text": "Is the artifact subject to export control or sanctions screening, and under which classification?", "kind": "constraint", "answer_data": [ "Export classification determination", "Screening procedure", "Restricted destination list" ] }, { "id": "q-residency-constraint", "text": "Where may the weights be stored and processed, and which residency constraints apply?", "kind": "spatial", "answer_data": [ "Permitted storage locations", "Permitted processing locations", "Basis for each constraint" ] } ], "data_elements": [ { "id": "de-access-classification", "name": "Access classification", "description": "Confidentiality or sensitivity classification of the artifact.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-015" ] }, { "id": "de-gating-condition", "name": "Gating condition", "description": "Condition a requester must satisfy to obtain access.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-009" ] }, { "id": "de-export-control-classification", "name": "Export control classification", "description": "Export or sanctions classification assigned to the artifact.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-015" ] }, { "id": "de-permitted-residency", "name": "Permitted residency", "description": "Jurisdiction where the artifact may be stored or processed.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] }, { "id": "de-access-grant-record", "name": "Access grant record", "description": "Record of an access grant, its grantee, scope and expiry.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017", "SRC-009" ] } ], "artifacts": [ { "id": "art-access-policy-record", "name": "Access and gating policy record", "description": "Statement of default access rule, gating conditions, export classification, residency limits and granted exceptions.", "media_or_form": [ "access policy record", "gating agreement and acceptance log", "export classification determination" ], "serial": true, "identity_strategy": "Artifact identifier plus policy version; access grants are separate append-only records keyed by grantee and grant event time.", "source_refs": [ "SRC-017", "SRC-015", "SRC-009" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "bnd-lifecycle-stewardship", "name": "Lifecycle, Stewardship and Downstream Linkage", "description": "How the artifact moves through controlled states, who is accountable, what documentation must exist and stay current, how it is retained and deleted, and how downstream use links back.", "rationale": "AI life cycle and management system standards require defined processes for controlling an artifact across its stages, documented information kept current, accountable roles and controlled end-of-life. The registry's own validation flag records that a separate life cycle is the distinguishing property of this model, so lifecycle governance is a first-class bundle rather than an attribute.", "source_refs": [ "SRC-018", "SRC-017", "SRC-016", "SRC-002", "SRC-015" ], "layers": [ { "id": "lyr-lifecycle-change", "name": "Lifecycle states, change control and end of life", "description": "State model and transition authority, deprecation, retention obligations, deletion scope and destruction evidence.", "source_refs": [ "SRC-018", "SRC-017", "SRC-016" ], "findings": [ { "id": "fnd-lifecycle-state", "name": "Lifecycle state model and transitions", "description": "The controlled states the artifact can occupy, who approves each transition against which gates, when transitions occurred, and how promotions are rolled back.", "source_refs": [ "SRC-018", "SRC-017", "SRC-016", "SRC-010" ], "questions": [ { "id": "q-lifecycle-state-set", "text": "Which lifecycle states can this artifact occupy, and which state is it in now?", "kind": "state", "answer_data": [ "Permitted state set", "Current state value", "State entry event time" ] }, { "id": "q-transition-authority", "text": "Who is authorised to approve each state transition, and against which gate criteria?", "kind": "authority", "answer_data": [ "Approver role per transition", "Gate criteria per transition", "Segregation-of-duty rule" ] }, { "id": "q-transition-timing", "text": "When did each state transition occur, and when was each transition recorded?", "kind": "temporal", "answer_data": [ "Transition event time", "Transition record time", "Reason for any lag" ] }, { "id": "q-promotion-rollback", "text": "Under what conditions may a promotion be rolled back, and what happens to artifacts that depend on it?", "kind": "exception", "answer_data": [ "Rollback trigger conditions", "Rollback procedure", "Dependent notification obligations" ] } ], "data_elements": [ { "id": "de-lifecycle-state", "name": "Lifecycle state", "description": "Current controlled state of the artifact.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-017" ] }, { "id": "de-state-transition-event", "name": "State transition event", "description": "Record of a transition with from-state, to-state, approver and event time.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "de-gate-criteria", "name": "Gate criteria", "description": "Criteria that must be satisfied to enter a state.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017", "SRC-016" ] }, { "id": "de-transition-approver", "name": "Transition approver", "description": "Role or party that approved a transition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "art-lifecycle-transition-log", "name": "Lifecycle transition log", "description": "Append-only log of state transitions with approver, gate evidence, event time and record time.", "media_or_form": [ "append-only transition log", "change control record set", "stage promotion history" ], "serial": true, "identity_strategy": "Artifact revision pin plus monotonically increasing transition sequence number; entries are immutable once written.", "source_refs": [ "SRC-018", "SRC-017" ] } ], "inline_only_rationale": null }, { "id": "fnd-retention-deletion", "name": "Deprecation, retention and deletion", "description": "How deprecation is declared, how long the artifact and its documentation must be kept, exactly what is destroyed at end of life, and what evidences destruction.", "source_refs": [ "SRC-018", "SRC-017", "SRC-002", "SRC-016" ], "questions": [ { "id": "q-deprecation-declaration", "text": "What marks this artifact deprecated, and which replacement is announced to consumers?", "kind": "lifecycle", "answer_data": [ "Deprecation declaration and event time", "Replacement artifact reference", "Consumer notification method" ] }, { "id": "q-retention-period", "text": "How long must the artifact and its technical documentation be retained, and on what legal or contractual basis?", "kind": "retention", "answer_data": [ "Retention period with start trigger", "Legal or contractual basis", "Retention owner" ] }, { "id": "q-deletion-scope", "text": "What exactly is deleted at end of life — weights, derivatives, caches, mirrors, logs — and what must be preserved?", "kind": "retention", "answer_data": [ "Deletion scope inventory", "Preservation exceptions", "Order of operations" ] }, { "id": "q-destruction-evidence", "text": "What evidence proves deletion or destruction, and who attests to it?", "kind": "evidence", "answer_data": [ "Destruction certificate reference", "Attesting role", "Destruction event time" ] }, { "id": "q-dependent-notification", "text": "Which downstream systems and derived artifacts must be notified before deletion proceeds?", "kind": "relationship", "answer_data": [ "Dependent inventory", "Notification lead time", "Objection handling" ] } ], "data_elements": [ { "id": "de-deprecation-time", "name": "Deprecation time", "description": "Event time at which the artifact was declared deprecated.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018" ] }, { "id": "de-retention-period", "name": "Retention period", "description": "Required retention duration for the artifact and its documentation.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-017" ] }, { "id": "de-retention-basis", "name": "Retention basis", "description": "Legal or contractual justification for the retention period.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-017" ] }, { "id": "de-deletion-scope", "name": "Deletion scope", "description": "Enumeration of what is destroyed and what is preserved at end of life.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-016", "SRC-017" ] }, { "id": "de-destruction-certificate-ref", "name": "Destruction certificate reference", "description": "Pointer to the attested evidence of destruction.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-017" ] } ], "artifacts": [ { "id": "art-retention-schedule", "name": "Retention and disposition record", "description": "Retention period, basis, deletion scope, dependent notifications and destruction attestation for the artifact.", "media_or_form": [ "retention schedule entry", "disposition record", "destruction certificate" ], "serial": true, "identity_strategy": "Artifact identifier plus disposition event sequence; the destruction certificate is retained after the artifact itself is destroyed.", "source_refs": [ "SRC-017", "SRC-002" ] } ], "inline_only_rationale": null }, { "id": "fnd-deployment-alias-pointers", "name": "Stage, alias, and status", "description": "A version is immutable; mutable aliases (champion, staging) and tags communicate deployment intent; stages are legacy in MLflow and must not be treated as the only lifecycle model.", "source_refs": [ "SRC-027", "SRC-024" ], "questions": [ { "id": "fnd-deployment-alias-pointers-q01", "text": "Which mutable aliases currently point at this version, and for which environments?", "kind": "state", "answer_data": [ "alias names", "environment mapping", "alias assignment time" ] }, { "id": "fnd-deployment-alias-pointers-q02", "text": "What lifecycle stage or status tags apply, and are deprecated stage names still in use?", "kind": "lifecycle", "answer_data": [ "stage if present", "status tags such as validation_status", "deprecation of stages" ] }, { "id": "fnd-deployment-alias-pointers-q03", "text": "When, if at all, was this version archived, revoked, or given a valid-until time?", "kind": "event", "answer_data": [ "validUntilTime", "retirement event time", "retirement reason", "ingestion time of the event" ] } ], "data_elements": [ { "id": "fnd-deployment-alias-pointers-data01", "name": "Aliases", "description": "Mutable named pointers to this version.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-027" ] }, { "id": "fnd-deployment-alias-pointers-data02", "name": "Status tags", "description": "Key-value status such as validation_status.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-027" ] }, { "id": "fnd-deployment-alias-pointers-data03", "name": "Valid-until time", "description": "End of supported life, RFC 3339.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-024" ] } ], "artifacts": [ { "id": "fnd-deployment-alias-pointers-artifact01", "name": "Registry lifecycle log", "description": "Append-only log of alias assignments, stage transitions, and retirement events.", "media_or_form": [ "application/json", "text/csv" ], "serial": true, "identity_strategy": "Append-only entries keyed by master-system version plus event time.", "source_refs": [ "SRC-027" ] } ], "inline_only_rationale": null } ] }, { "id": "lyr-stewardship-accountability", "name": "Stewardship, documentation obligations and downstream linkage", "description": "Accountable roles, the documentation set that must exist and stay current, and the verified links from deployments and operational feedback back to this artifact.", "source_refs": [ "SRC-017", "SRC-016", "SRC-002", "SRC-004", "SRC-013" ], "findings": [ { "id": "fnd-ownership-stewardship", "name": "Ownership, stewardship and accountable roles", "description": "The owning unit, the day-to-day steward, separation between producing, approving and operating roles, and the contact point for the artifact.", "source_refs": [ "SRC-017", "SRC-016", "SRC-018" ], "questions": [ { "id": "q-owner-steward", "text": "Which organisational unit owns this artifact, and which named role stewards it day to day?", "kind": "ownership", "answer_data": [ "Owning organisational unit reference", "Steward role reference", "Effective date of the assignment" ] }, { "id": "q-role-separation", "text": "How are producing, approving and operating roles separated for this artifact?", "kind": "authority", "answer_data": [ "Role assignment matrix", "Separation rule", "Detected or approved conflicts" ] }, { "id": "q-ownership-handover", "text": "What happens to ownership when the responsible team is reorganised or the artifact is transferred externally?", "kind": "process", "answer_data": [ "Handover procedure", "Transfer event record", "Obligations that transfer with ownership" ] }, { "id": "q-contact-point", "text": "Which contact point handles questions, defect reports and rights claims about the artifact?", "kind": "definition", "answer_data": [ "Contact point identifier", "Scope of issues handled", "Response commitment" ] } ], "data_elements": [ { "id": "de-owning-organization", "name": "Owning organisation", "description": "Organisational unit accountable for the artifact.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-017", "SRC-016" ] }, { "id": "de-steward-role", "name": "Steward role", "description": "Role responsible for day-to-day maintenance of the artifact record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-017" ] }, { "id": "de-contact-point", "name": "Contact point", "description": "Route for questions, defect reports and claims.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-ownership-transfer-event", "name": "Ownership transfer event", "description": "Record of an ownership change with event time and transferred obligations.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-018" ] } ], "artifacts": [], "inline_only_rationale": "Ownership is a set of typed references from the artifact record into an organisation and role model that owns party identity, reporting lines and delegation. Materialising a per-artifact stewardship document would duplicate an authoritative party register and go stale on every reorganisation; the governed carrier here is the assignment reference plus the append-only transfer events held inline on the artifact record." }, { "id": "fnd-documentation-obligations", "name": "Documentation set and downstream transparency", "description": "Which documentation items must exist, how they are kept current, what must be handed to downstream integrators, what may be redacted and who may request the full set.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-017" ], "questions": [ { "id": "q-documentation-set", "text": "Which documentation items must exist for this artifact, and which are mandatory versus recommended?", "kind": "requirement", "answer_data": [ "Documentation item inventory", "Obligation level per item", "Source of each obligation" ] }, { "id": "q-documentation-currency", "text": "How is documentation kept up to date as the artifact changes, and when was each item last revised?", "kind": "temporal", "answer_data": [ "Update trigger per item", "Last revision timestamp per item", "Overdue item list" ] }, { "id": "q-downstream-information-pack", "text": "What information must be handed to downstream integrators so they can meet their own obligations?", "kind": "interoperability", "answer_data": [ "Downstream information item list", "Delivery mechanism", "Minimum content per item" ] }, { "id": "q-documentation-redaction", "text": "Which parts may be redacted to protect trade secrets, and what minimum must still be disclosed?", "kind": "privacy", "answer_data": [ "Redactable content categories", "Non-redactable minimum", "Redaction approver" ] }, { "id": "q-documentation-request", "text": "Who may request the full documentation set, and within what response time?", "kind": "access", "answer_data": [ "Eligible requester categories", "Request route", "Response deadline" ] } ], "data_elements": [ { "id": "de-documentation-item", "name": "Documentation item", "description": "One required documentation item with its location and obligation level.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-003", "SRC-004" ] }, { "id": "de-doc-obligation-level", "name": "Documentation obligation level", "description": "Whether an item is mandatory, conditional or recommended.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-002", "SRC-017" ] }, { "id": "de-doc-last-revision-time", "name": "Documentation last revision time", "description": "Event time at which a documentation item was last revised.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "de-redaction-note", "name": "Redaction note", "description": "Record of content withheld and the justification.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "art-technical-documentation-dossier", "name": "Technical documentation dossier", "description": "Assembled and versioned documentation set for the artifact, including the downstream integrator pack and redaction record.", "media_or_form": [ "technical documentation dossier", "downstream transparency information pack", "documentation index with obligation mapping" ], "serial": true, "identity_strategy": "Artifact identifier plus dossier version; each version records its assembly event time, contained item revisions and redaction decisions.", "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] } ], "inline_only_rationale": null }, { "id": "fnd-downstream-linkage", "name": "Deployment and operational feedback linkage", "description": "Verified links from AI systems and endpoints that reference this revision, operational events attributed to it, and the loop back into re-evaluation or withdrawal.", "source_refs": [ "SRC-016", "SRC-013", "SRC-015", "SRC-017" ], "questions": [ { "id": "q-current-deployments", "text": "Which AI systems, endpoints or products currently reference this artifact revision?", "kind": "relationship", "answer_data": [ "Deploying system references", "Referenced revision pin per deployment", "Reference discovery method" ] }, { "id": "q-attributed-events", "text": "Which operational events are attributed back to this artifact rather than to the surrounding system?", "kind": "event", "answer_data": [ "Attributed event references", "Attribution basis", "Event occurrence times" ] }, { "id": "q-feedback-loop", "text": "How do downstream observations trigger re-evaluation, patching or withdrawal of the artifact?", "kind": "process", "answer_data": [ "Trigger thresholds", "Responsible role", "Resulting lifecycle action" ] }, { "id": "q-deployment-verification", "text": "How is a deployment's claimed artifact revision verified against the artifact of record?", "kind": "validation", "answer_data": [ "Verification method", "Digest or signature comparison result", "Handling of unverifiable claims" ] } ], "data_elements": [ { "id": "de-deploying-system-ref", "name": "Deploying system reference", "description": "AI system or endpoint that references this artifact revision.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-attributed-event-ref", "name": "Attributed event reference", "description": "Operational event attributed to this artifact.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016", "SRC-017" ] }, { "id": "de-observation-time", "name": "Observation time", "description": "Time at which a downstream observation about the artifact was recorded.", "value_kind": "timestamp", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-016" ] }, { "id": "de-verified-revision-flag", "name": "Verified revision flag", "description": "Whether a deployment's claimed revision was cryptographically verified.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-015" ] } ], "artifacts": [], "inline_only_rationale": "Deployments and operational events are entities owned by the AI system model and by incident or monitoring models; this finding holds only the reverse index — typed references plus the verification outcome for each claimed revision. Creating a deployment artifact here would fork the system-of-record for deployments and guarantee divergence." } ] } ] } ] }, "functions": [ { "id": "fn-register-artifact", "name": "Register model artifact", "description": "Create the governed record for a newly produced or newly acquired model artifact and assign its canonical identity.", "inputs": [ "Producing run reference or acquisition record", "Component file set with digests", "Proposed classification values" ], "outputs": [ "Artifact record with canonical identifier", "Immutable revision pin", "Registration event with event time and ingestion time" ], "preconditions": [ "Registry of record is designated", "Component digests computed with an approved algorithm", "Owning organisation and steward assigned" ], "effects": [ "Artifact enters the initial lifecycle state", "Identity becomes resolvable to downstream consumers", "Registration event is appended to the transition log" ], "source_refs": [ "SRC-010", "SRC-007", "SRC-017" ] }, { "id": "fn-resolve-identity", "name": "Resolve artifact identity", "description": "Resolve any supplied identifier, alias or digest to the canonical artifact record and the exact revision meant.", "inputs": [ "Candidate identifier, alias, tag or digest" ], "outputs": [ "Canonical identifier and revision pin", "Identity scope level", "Ambiguity or collision report" ], "preconditions": [ "Alias mapping table is populated", "Mutable pointers are inventoried" ], "effects": [ "Callers operate on an unambiguous revision", "Unresolvable or ambiguous references are logged for reconciliation" ], "source_refs": [ "SRC-007", "SRC-005", "SRC-009" ] }, { "id": "fn-verify-integrity", "name": "Verify artifact integrity and provenance", "description": "Validate the signature over the manifest, recompute file digests, and check build provenance and transparency evidence.", "inputs": [ "Artifact component files", "Signature bundle", "Build provenance attestation" ], "outputs": [ "Verification outcome per file and overall", "Signing identity and builder identity", "Verification event record" ], "preconditions": [ "Trusted root or keyless identity policy configured", "Manifest covers the files to be used" ], "effects": [ "Artifact is marked verified or quarantined", "Failed verification blocks promotion and distribution" ], "source_refs": [ "SRC-013", "SRC-014", "SRC-012", "SRC-007" ] }, { "id": "fn-compile-bom", "name": "Compile bill of materials", "description": "Generate the machine-readable component inventory for a specific artifact revision and bind it to the revision pin.", "inputs": [ "Component inventory", "Resolved dependency list", "Base model lineage" ], "outputs": [ "Bill of materials document", "Component entry set with digests", "Unsafe-format and vulnerability flags" ], "preconditions": [ "Component roles assigned", "Lineage references resolved" ], "effects": [ "Composition becomes machine-readable for consumers", "BOM is bound to the revision and versioned on regeneration" ], "source_refs": [ "SRC-006", "SRC-001", "SRC-020" ] }, { "id": "fn-assemble-documentation", "name": "Assemble technical documentation dossier", "description": "Collect required documentation items into a versioned dossier and derive the downstream integrator information pack.", "inputs": [ "Model card", "Training data summary", "Evaluation results", "Safety assessment", "Licence and access records" ], "outputs": [ "Versioned documentation dossier", "Downstream information pack", "Redaction record and gap list" ], "preconditions": [ "Regulatory classification determined", "Obligation level assigned to each item" ], "effects": [ "Documentation currency becomes auditable", "Missing mandatory items surface as blocking gaps" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-004", "SRC-017" ] }, { "id": "fn-classify-obligations", "name": "Determine regulatory classification and obligations", "description": "Decide whether the artifact is a general-purpose model, whether systemic-risk criteria are met, which jurisdictions apply and which exemptions hold.", "inputs": [ "Model classification and scale attributes", "Release mode and licence", "Placement jurisdictions" ], "outputs": [ "Classification determination with rationale", "Applicable obligation set", "Exemption claim with supporting evidence" ], "preconditions": [ "Licence and public-availability status established", "Obligated provider identified" ], "effects": [ "Documentation and transparency duties are activated or exempted", "Determination is recorded immutably with its evidence and decision time" ], "source_refs": [ "SRC-002", "SRC-003", "SRC-017" ] }, { "id": "fn-attach-evidence", "name": "Attach evaluation and safety evidence", "description": "Bind reported results, thresholds, fairness evidence and safety assessments to a specific artifact revision without absorbing the evaluation record itself.", "inputs": [ "Evaluation record references", "Metric values with context", "Safety and adversarial testing outputs" ], "outputs": [ "Attached result set with measurement times", "Threshold comparison outcome", "Evidence currency status" ], "preconditions": [ "Artifact revision pin exists", "Evaluator identity and protocol recorded" ], "effects": [ "Promotion gates can be evaluated against thresholds", "Stale evidence is flagged when the revision changes" ], "source_refs": [ "SRC-009", "SRC-001", "SRC-003", "SRC-019" ] }, { "id": "fn-transition-lifecycle", "name": "Transition lifecycle state", "description": "Move the artifact between controlled states after checking gate criteria and recording approver and timing.", "inputs": [ "Target state", "Gate evidence", "Approver identity" ], "outputs": [ "Updated lifecycle state", "Transition log entry with event time and record time", "Dependent notification list" ], "preconditions": [ "Gate criteria defined for the target transition", "Approver holds the required authority and is not the producer where separation applies" ], "effects": [ "Downstream consumers see the new state", "Rollback path and dependents are recorded" ], "source_refs": [ "SRC-018", "SRC-017", "SRC-016" ] }, { "id": "fn-retire-artifact", "name": "Retire and dispose of artifact", "description": "Deprecate, withdraw from channels, retain for the required period and destroy in scope with attested evidence.", "inputs": [ "Deprecation decision", "Retention period and basis", "Dependent inventory" ], "outputs": [ "Withdrawal records per channel", "Destruction certificate reference", "Preserved documentation set" ], "preconditions": [ "Retention obligations resolved", "Dependents notified and objections handled" ], "effects": [ "Artifact ceases to be distributable", "Destruction evidence outlives the destroyed artifact" ], "source_refs": [ "SRC-017", "SRC-002", "SRC-016" ] }, { "id": "fn-project-interoperable-view", "name": "Project interoperable views", "description": "Emit standards-aligned projections of the artifact record for external consumers without changing its semantics.", "inputs": [ "Artifact record", "Target alignment profile" ], "outputs": [ "Standards-aligned projection document", "Field mapping and unmapped-field report", "Conflict notes where alignments disagree" ], "preconditions": [ "Field mapping maintained per target profile", "Alignment claimed only where evidence exists" ], "effects": [ "External tools consume the artifact without bespoke integration", "Alignment gaps and conflicts are made explicit rather than silently dropped" ], "source_refs": [ "SRC-006", "SRC-001", "SRC-009", "SRC-020" ] }, { "id": "fn-export-interchange-projection", "name": "Export interchange format", "description": "Produce or retrieve an ONNX or other interchange projection with recorded opset and signature.", "inputs": [ "version identifier", "target format and opset" ], "outputs": [ "interchange file", "opset and signature metadata" ], "preconditions": [ "source payload is loadable in a supported library", "conversion tools are available or a stored projection exists" ], "effects": [ "projection stored as a payload member or derived artifact", "conversion lineage recorded" ], "source_refs": [ "SRC-029", "SRC-027" ] }, { "id": "fn-set-deployment-alias", "name": "Set deployment alias", "description": "Point a mutable alias at an immutable version after required checks.", "inputs": [ "model name", "alias", "target version", "evidence of validation status" ], "outputs": [ "updated alias binding", "lifecycle-log entry" ], "preconditions": [ "target version integrity verified", "validation_status permits the alias", "caller authorized for the environment" ], "effects": [ "alias now resolves to the target version", "previous target loses that alias unless reassigned" ], "source_refs": [ "SRC-027" ] }, { "id": "fn-release-documentation-to-authority", "name": "Release documentation to authority", "description": "Package Annex XI technical documentation for the AI Office or national competent authority while preserving confidentiality markings.", "inputs": [ "version identifier", "requesting authority", "scope of request" ], "outputs": [ "documentation package", "access-exception audit record" ], "preconditions": [ "artifact is a GPAI model subject to Art. 53(1)(a) or an equivalent duty", "caller authorized for the exception" ], "effects": [ "disclosure logged with event time", "trade secrets remain marked per Art. 78 handling" ], "source_refs": [ "SRC-002", "SRC-003" ] } ], "composition": [ { "target": "WM-AI-001 — AI System", "relation": "REFERENCE", "purpose": "An AI system composes one or more model artifacts. The artifact exposes its identity, interface contract, licence and downstream information pack so the system can meet its own obligations; the system owns intended purpose, human oversight and post-market monitoring.", "required": false, "source_refs": [ "SRC-002", "SRC-004", "SRC-016" ] }, { "target": "WM-AI-006 — Training Run", "relation": "REFERENCE", "purpose": "The producing run is the provenance anchor for internally produced artifacts, referenced as the attestation subject's build definition. Not required for externally acquired artifacts, where an acquisition record substitutes.", "required": false, "source_refs": [ "SRC-012", "SRC-015" ] }, { "target": "WM-AI-003 — Evaluation", "relation": "REFERENCE", "purpose": "Evaluations assess a specific artifact revision. The artifact attaches reported results, measurement times and thresholds; the authoritative protocol, evaluator independence and full report remain in the evaluation model.", "required": false, "source_refs": [ "SRC-009", "SRC-006", "SRC-019" ] }, { "target": "Dataset (candidate sibling model, Croissant-aligned)", "relation": "REFERENCE", "purpose": "Training, validation, test and evaluation datasets are referenced by role. Dataset structure, record semantics, distribution and its own licensing stay in the dataset model.", "required": false, "source_refs": [ "SRC-021", "SRC-004", "SRC-006" ] }, { "target": "Software Component / SBOM entry (candidate sibling model)", "relation": "REFERENCE", "purpose": "Frameworks, runtimes and libraries appear as referenced components in the artifact's bill of materials and execution environment, typed distinctly from the machine-learning-model component.", "required": false, "source_refs": [ "SRC-006", "SRC-010" ] }, { "target": "Party and Role register (candidate sibling model)", "relation": "REFERENCE", "purpose": "Owning organisation, steward, approver, obligated provider and access grantee resolve to party records; this model stores only typed references and assignment events.", "required": true, "source_refs": [ "SRC-017", "SRC-002" ] }, { "target": "Signed Attestation (candidate mixin)", "relation": "MIX-IN", "purpose": "Signature bundles, build provenance and destruction certificates share one attestation pattern: subject digest, predicate type, issuer identity, signing event time and optional transparency-log inclusion.", "required": false, "source_refs": [ "SRC-012", "SRC-013", "SRC-014" ] }, { "target": "Content-Addressed Digital Object (candidate mixin)", "relation": "MIX-IN", "purpose": "Every packaged component carries media type, digest and size, giving verifiable byte-level identity that is reused rather than redefined per component role.", "required": true, "source_refs": [ "SRC-007", "SRC-020" ] }, { "target": "SPDX 3.0.1 AI Profile — AIPackage", "relation": "ALIGN", "purpose": "Alignment target for model-level descriptive properties (type of model, hyperparameters, training information, metrics and thresholds, limitations, safety risk assessment, autonomy, domain, energy, sensitive personal information). Alignment is a mapping claim, not a conformance claim.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "CycloneDX v1.6 ML-BOM modelCard", "relation": "ALIGN", "purpose": "Alignment target for composition transparency and model card structure, including the machine-learning-model and data component types and the considerations block.", "required": false, "source_refs": [ "SRC-006" ] }, { "target": "EU AI Act Annex XI and Annex XII documentation set", "relation": "ALIGN", "purpose": "Alignment target for the mandatory documentation and downstream transparency content where the artifact is a general-purpose AI model placed on the EU market. Applicability is determined per artifact, not assumed.", "required": false, "source_refs": [ "SRC-002", "SRC-003", "SRC-004" ] }, { "target": "ISO/IEC 5338:2023 AI system life cycle processes", "relation": "ALIGN", "purpose": "Alignment target for lifecycle stage vocabulary and process control. Mapping is provisional: only the catalogue record was verified, so the alignment is recorded as a gap pending access to the normative text.", "required": false, "source_refs": [ "SRC-018", "SRC-017" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "The adopting Dimension must name a single registry of record for model artifacts and publish which identifier it issues, at which scope level (family, version or snapshot), and how that identifier resolves.", "The Dimension must publish its lifecycle state set, the gate criteria and approving role for each transition, and its retention and deletion schedule before any artifact reaches a released state.", "The Dimension must declare its integrity baseline: accepted digest algorithms, whether signing is mandatory for release, the trust roots or keyless identity policy, and the action taken on verification failure.", "The Dimension must maintain the alignment mapping tables for each external profile it projects to, including unmapped fields and known conflicts, and must not claim conformance without evidence." ], "namespace_guidance": "Use a reverse-DNS or registry-scoped namespace for artifact identifiers, classification code lists and any locally minted properties, so that locally defined terms can never collide with terms governed by an external standard. Keep three namespaces distinct: identifiers issued by the registry of record, alias identifiers issued by external ecosystems, and content digests. Never overload a distribution channel path as the identifier namespace, because channel paths are renameable and mirrorable.", "registry_links": [ "vr.wm-sft-004 — this model's registry entry, nav path NAV.INF.SFT.ML, domain tags INF.SFT.ML", "WM-AI-001 AI System (COMPOSE inbound), WM-AI-006 Training Run (PRODUCES inbound), WM-AI-003 Evaluation (REFERENCE inbound)", "External alignment registries: SPDX AI profile, CycloneDX component and modelCard schema, OCI descriptor media types, model packaging layer media types" ] }, "canon_and_patch": { "canonicalization_rules": [ "The canonical artifact record is storage-neutral: JSON, YAML, Markdown, HTML, Git, MCP and document databases are projections. No projection may add semantics absent from the canonical record.", "Identifiers are canonicalised case-sensitively and without trailing whitespace; digests are canonicalised to lowercase hexadecimal in algorithm:encoded form.", "All timestamps are canonicalised to RFC 3339 with explicit seconds and an explicit offset or Z before comparison or hashing.", "Code-list values are canonicalised to the governing vocabulary's exact term; unmapped local values are carried in an explicitly namespaced extension field rather than being coerced.", "Collections whose order carries no meaning are canonically sorted by their key before any digest of the record is computed, so that equal records hash equally." ], "patch_rules": [ "Findings, questions and data elements are patched by stable local ID; a semantic change to an existing element requires a new ID rather than silent redefinition.", "Evidence-bearing entries — evaluation results, transition log entries, signatures, release records, access grants, destruction certificates — are append-only and are corrected by a superseding entry that cites the entry it supersedes.", "A patch that changes the interface signature, the licence, the serialization format or the regulatory determination is a breaking change and must produce a new artifact version, not an in-place edit.", "Every patch records the patching role, the event time of the change and the record time it was applied, plus the source reference justifying it.", "Removing a source reference requires either a replacement reference or an explicit downgrade of the affected node to a gap." ], "compatibility_rules": [ "Adding an optional data element, artifact or question is backward compatible; making an optional element required, narrowing a cardinality or removing a value from a code list is not.", "Consumers must ignore unknown fields and must not infer meaning from field order or projection formatting.", "Alias identifiers and mutable pointers may be added or repointed without a version bump, but the immutable revision pin they resolved to at each point in time must remain queryable.", "External alignment profile upgrades are tracked as separate mapping versions; the canonical record does not change shape because an alignment target changed." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the designated registry of record for model artifacts — for example the model registry primary key or model version key held by the system that governs releases. This identifier always takes precedence, and the registry of record must be named on the artifact record.", "Governed global identifier or IRI where one exists — for example an SPDX element IRI, a registry-scoped namespace-plus-repository identifier with its immutable revision, or a persistent resolvable identifier issued by a recognised authority.", "UUID or ULID minted by the adopting Dimension, used only when no authoritative master-system identifier and no governed global identifier are available; the minted identifier must record the minting Dimension and the minting event time.", "Content digest in algorithm:encoded form is recorded as an integrity and pinning key alongside — never instead of — the identifiers above; it verifies bytes, not business identity, and does not survive lossless repackaging. A release date, a version label, a mutable tag such as latest, or a distribution path is never an identifier." ], "timestamp_rule": "All time values are recorded as RFC 3339 date-time strings that include explicit seconds and an explicit numeric UTC offset or the literal Z; local wall-clock strings without an offset are rejected. Event time and observation or ingestion time are stored as separate fields whenever they can differ — for example run finish time versus registry ingestion time, signing event time versus transparency-log inclusion time, release time versus mirror synchronisation time, measurement time versus result publication time, and state transition event time versus transition record time. Where a value is a duration rather than an instant, it is stored as a duration with its start trigger stated, not as a bare date.", "serial_naming_rule": "Serial artifacts are named as canonical-artifact-id + artifact-kind + monotonically increasing sequence number, with the immutable revision pin appended where the artifact is revision-bound (for example evaluation result sets, signature bundles, documentation dossier versions and transition log entries). Sequence numbers never restart and never encode a date; the event time is a separate field. A superseding entry cites the sequence number it supersedes, and no serial entry is ever renumbered or reused after issue.", "integrity_rule": "Every packaged component carries a digest computed with an approved algorithm, and the set of components is covered by a signed manifest whose coverage is explicitly enumerated. Verification is a two-step operation — validate the signature, then recompute and compare every covered digest — and any file present but not covered by the manifest is treated as a failure, not as an acceptable extra. Records referencing the artifact must pin the immutable revision, so that a mutable pointer can never silently change what a verified claim applies to. Unsafe deserialisation formats are flagged, and where policy requires, converted to a memory-safe format before release; conversion produces a new artifact revision with its own provenance chain back to the original." }, "policies": [ "No artifact may enter a released state without a resolvable canonical identifier, a named owning organisation and steward, a licence determination, a completed integrity verification and a regulatory classification determination — even where that determination concludes that no external regime applies.", "Alignment with an external standard is recorded as a mapping with named unmapped fields and conflicts; conformance is asserted only where verifiable evidence exists, and paywalled or unverified normative text is recorded as a gap rather than as support.", "Evidence about behaviour — evaluation results, fairness measurements, safety assessments, energy figures — is always bound to a specific immutable revision and a measurement event time, and is marked stale rather than silently carried forward when the revision changes.", "Documentation obligations, retention obligations and destruction evidence survive the artifact: the artifact may be destroyed, but its dossier, transition log and destruction certificate are retained for the full retention period on the recorded legal or contractual basis.", "Redaction of documentation to protect trade secrets is permitted only against a declared non-redactable minimum, and every redaction is recorded with its justification and approver.", "No production alias without recorded owner, licence, hashes, and intended-use text.", "GPAI artifacts placed on the Union market keep Annex XI documentation unless a documented Art. 53(2) exemption applies and systemic risk is absent.", "Builders of a version are separated from validators of that version for MEASURE-style independence.", "Deleted payloads leave a tombstone metadata record unless law requires full erasure." ], "crud": { "read": [ "Resolve any identifier, alias, tag or digest to the canonical artifact record and the exact revision, returning an explicit ambiguity report where resolution is not unique.", "Retrieve the artifact record at a stated point in time, including the lifecycle state, documentation currency and evidence currency as they stood at that time.", "Emit standards-aligned projections and the downstream integrator information pack, honouring the artifact's access classification and redaction record.", "Read the append-only evidence series — transition log, release records, signatures, access grants, evaluation attachments — without mutation." ], "create": [ "Register a new artifact with a canonical identifier, revision pin, owning organisation and steward, capturing both the production or acquisition event time and the ingestion time.", "Append a new immutable evidence entry (attestation, evaluation result set, release record, access grant, transition entry) bound to a revision pin and a sequence number.", "Mint a new artifact version when a breaking change occurs to interface, licence, serialization format or regulatory determination, carrying forward lineage links to the predecessor.", "Create an alignment mapping version for a target external profile, including its unmapped-field and conflict lists." ], "update": [ "Amend descriptive, non-breaking fields in place with the patching role, event time and record time captured, and the justifying source reference attached.", "Repoint a mutable pointer to a different revision, recording the previous target so that historic resolutions remain queryable.", "Supersede an evidence entry by appending a superseding entry that cites it; the superseded entry is retained and remains readable.", "Refresh a documentation item or bill of materials, updating its last-revision timestamp and re-binding it to the current revision pin." ], "delete": [ "Soft-delete by lifecycle transition only: deprecate, then withdraw from each distribution channel with a per-channel withdrawal record, before any destruction is considered.", "Hard-delete artifact bytes only after the retention period expires or an explicit legal instruction overrides it, with dependents notified and objections resolved first.", "Destroy in a declared scope — weights, derived caches, mirrors, and any recorded exclusions — and record what was deliberately preserved.", "Never delete transition log entries, signatures, documentation dossiers or destruction certificates; the destruction certificate outlives the artifact it attests to." ] }, "roles": [ { "name": "Model artifact owner", "responsibilities": [ "Hold accountability for the artifact's compliance, licence and release decisions", "Approve regulatory classification determinations and exemption claims", "Authorise ownership transfer and accept residual risk" ] }, { "name": "Model artifact steward", "responsibilities": [ "Maintain the artifact record, identifiers, aliases and classification values", "Keep documentation items current and surface overdue or missing mandatory items", "Bind evidence to revisions and mark stale evidence when a revision changes" ] }, { "name": "Provenance and integrity custodian", "responsibilities": [ "Operate signing, verification and transparency-log checks and hold the trust root policy", "Enforce that unverified artifacts cannot be promoted or distributed", "Maintain the bill of materials and flag unsafe deserialisation formats and vulnerable components" ] }, { "name": "Release and lifecycle approver", "responsibilities": [ "Check gate criteria and approve lifecycle transitions with segregation from the producing role", "Approve distribution channels, release mode and withdrawal decisions", "Approve deprecation, retention basis and destruction scope" ] }, { "name": "Rights and access controller", "responsibilities": [ "Determine licence, use restrictions, export classification and residency constraints", "Grant, review and revoke access under the declared default rule and gating conditions", "Approve documentation redactions against the non-redactable minimum" ] }, { "name": "Interoperability maintainer", "responsibilities": [ "Maintain alignment mapping tables and their versions for each external profile", "Record unmapped fields and conflicts and prevent unsupported conformance claims", "Validate that projections carry no semantics absent from the canonical record" ] } ], "access": { "default_rule": "Deny by default for artifact weight bytes and for any documentation content marked confidential; allow read of the artifact's identity, classification, interface contract, licence and lifecycle state to authenticated members of the adopting Dimension. Access to the full technical documentation dossier is granted only to roles or authorities with a stated basis, and every grant is time-boxed, scoped and revocable.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Competent authorities may request the full technical documentation dossier under a legal basis; the request, the basis, the disclosed scope and the response time are recorded, and the non-redactable minimum applies regardless of trade-secret claims.", "Downstream integrators receive the transparency information pack without receiving the full internal dossier or the weights, so that they can meet their own obligations without over-disclosure.", "Open-weights releases invert the default for weight bytes only; licence, use restrictions, attribution duties and export screening still apply, and the inversion does not extend to internal safety assessments or access grant records.", "Incident response may grant emergency read access to provenance, signature and deployment linkage data ahead of normal approval, provided the grant is logged, notified to the owner and reviewed within a stated window.", "Export-controlled or residency-constrained artifacts remain deny-by-default in restricted destinations even where the requester would otherwise be entitled; no local exception may override a screening outcome.", "AI Office or national competent authority requests for Annex XI documentation under Article 53 and Article 78 confidentiality handling", "Incident forensics by security roles on hashed payload copies", "Open-published artifacts whose licence and AUP permit anonymous download" ], "audit_requirements": [ "Log every access decision — grant, denial and revocation — with requester identity, scope, basis, decision event time and record time.", "Log every integrity verification attempt with its outcome, the covered file set and the signing and builder identities evaluated.", "Log every disclosure of the documentation dossier with the disclosed scope, redactions applied and the approving role.", "Retain access, verification and disclosure logs for at least the artifact's retention period, and make them immutable and independently reviewable.", "Reconcile deployment linkage claims against the artifact of record periodically, and log unverifiable revision claims as findings requiring action.", "Log every alias change, payload download, documentation disclosure, and deletion with actor, event time, and observation time", "Retain audit logs at least as long as the metadata tombstone" ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Registry ID and Model ID", "Owner and steward contact", "Identity priority and timestamp rule summary", "Access default rule and escalation route" ], "read_order": [ "AGENTS.md — establishes model name, type, and the specification, storage, interface and process entry points before any other action", "Specification URL — the canonical, storage-neutral definition of bundles, layers, findings, questions, data elements and artifacts", "Storage type URL — how the canonical record is projected into the concrete store in use (document database, object store, version control or message interface), including any projection-specific constraints", "Interface URL — the access and query contract, including authentication, access scopes and redaction behaviour", "Processes URL — CRUD, canonicalisation and patch rules, lifecycle transitions, verification gates and retention or deletion procedures", "Registry entry vr.wm-sft-004 — composition links to sibling models and the current review state before creating or modifying any record" ] } }, "coverage": { "claim": "The synthesized WM-SFT-004 model gives a defensible, falsifiable context structure for a trained ML model artifact as a governed object of record — identity and versioning, classification and regulatory status, production and derivation provenance, supply-chain integrity, serialization and interface contract, attached evaluation and safety evidence, rights and distribution, and lifecycle stewardship through deletion — with every node carrying source references and every non-materialized finding carrying an inline-only rationale. It deliberately stops at the boundaries of the AI system (WM-AI-001), the training run (WM-AI-006), the evaluation campaign (WM-AI-003) and the dataset sibling, referencing rather than absorbing them. This is not a claim of conformance with any cited standard and not a claim of universal or metaphysical completeness: several nodes rest on de facto ecosystem specifications rather than normative texts, two ISO standards were verified only at catalogue level, and the EU GPAI provisions were read from a reproduction rather than the Official Journal.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Three distinct identity layers are separated: registry-of-record identifier (authoritative), governed global identifier or IRI, and locally minted UUID/ULID, with content digest explicitly demoted to an integrity and pinning key. Identity scope level (family, version, snapshot) is an explicit data element because standards disagree about what a model identifier denotes. Alias resolution, collisions and namespace transfers are questioned directly." }, { "dimension": "lifecycle", "status": "covered", "notes": "State model, transition authority with segregation from the producing role, gate criteria, rollback and dependent impact are covered, backed by AI life cycle and management system standards. Weakness: those two standards were verified only at catalogue level, so the specific stage vocabulary is left to the adopting Dimension rather than asserted." }, { "dimension": "relationships", "status": "covered", "notes": "Derivation lineage (fine-tune, adapter, quantized, merge), producing run, datasets by role, deployments and superseding versions are all typed reference relations. Composition links to WM-AI-001, WM-AI-006 and WM-AI-003 mirror the registered relations without absorbing their content." }, { "dimension": "temporal", "status": "covered", "notes": "Event time and observation/ingestion time are separated at the rule level and instantiated as distinct data elements: release versus ingestion, run finish versus registration, signing versus log inclusion, measurement versus publication, transition event versus transition record. Durations carry a stated start trigger rather than being encoded as dates." }, { "dimension": "provenance", "status": "covered", "notes": "Build provenance (builder identity, external and internal parameters, resolved dependencies), derivation lineage, training data provenance and curation, and reproducibility status are each separate findings. Provenance attestation is bound to the artifact by subject digest rather than by name." }, { "dimension": "ownership", "status": "covered", "notes": "Owning organisation, steward, approver, obligated provider, contact point, role separation and ownership transfer events are covered. Deliberately held as typed references into a party model rather than duplicated, which is stated as the inline-only rationale." }, { "dimension": "validation", "status": "covered", "notes": "Covered at four levels: identity resolution and collision checks, cryptographic manifest verification, interface schema validation of caller payloads, and shard/mirror completeness and equivalence checks. Failure semantics are specified as blocking rather than advisory at the promotion gate." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default for weights and confidential documentation with an allow for identity, interface, licence and state; four access scopes; five exceptions including authority requests, downstream packs, open-weights inversion, emergency incident access and export screening that cannot be locally overridden." }, { "dimension": "retention and deletion", "status": "covered", "notes": "Deprecation, retention period with stated basis, explicit deletion scope covering derivatives, caches and mirrors, dependent notification, and destruction evidence that outlives the artifact. Non-deletable classes (transition log, signatures, dossiers, destruction certificates) are named." }, { "dimension": "interoperability", "status": "covered", "notes": "Alignment targets are named as mappings with unmapped-field and conflict lists, never as conformance. Operator set, IR version, runtime flavor, packaging envelope and BOM format are modelled as explicit interoperability constraints rather than assumed." }, { "dimension": "security", "status": "covered", "notes": "Signing methods, manifest coverage, transparency-log inclusion, unsafe deserialisation flagging, vulnerable component exposure and export screening are covered. Adversarial testing is scoped to the artifact's own behaviour, not to the surrounding system's controls." }, { "dimension": "measurement and evidence", "status": "covered", "notes": "Metrics with decision thresholds, disaggregated results by factor, evaluator independence, measurement time and currency, energy and emissions with measured-versus-estimated basis. Evidence is revision-bound and goes stale by rule rather than by judgement." }, { "dimension": "privacy", "status": "covered", "notes": "Sensitive personal information in training data with lawful basis, and documentation redaction against a declared non-redactable minimum. Individual data-subject rights handling is out of scope and belongs to the dataset and organisational governance models." }, { "dimension": "licensing and rights", "status": "covered", "notes": "Licence identifier or custom document, per-component licence divergence, use restrictions, attribution duties, inherited upstream terms, copyright policy, rights reservation handling and post-release claims. Liability allocation is questioned but resolved by reference to contracts, not modelled here." }, { "dimension": "spatial", "status": "covered", "notes": "Applies as jurisdiction of placement and as storage/processing residency, not as geometry. No geospatial data elements are defined, which is the correct scope for this entity." } ], "known_omissions": [ "ISO/IEC 42001:2023 and ISO/IEC 5338:2023 are paywalled; only their catalogue records were verified. Every node resting on them for lifecycle stage vocabulary, Annex A control mapping or process naming is therefore an alignment gap, not evidenced conformance, and the specific stage names are left to the adopting Dimension.", "The canonical EUR-Lex text of Regulation (EU) 2024/1689 could not be rendered by the fetch tool; Article 53, Annex XI and Annex XII were read from a reproduction. Exact wording, recital context and any subsequent corrigenda or implementing acts should be re-verified against the Official Journal before any compliance use.", "No agreed threshold exists for what makes a model artifact 'the same artifact' across lossless repackaging or format conversion. The model records conversion as a new revision with lineage, but this is a design decision, not a standards-derived rule.", "Systemic-risk threshold criteria and the Commission training-content summary template are regime-specific and evolving; the model carries the determination and the summary reference but deliberately encodes no threshold value.", "Model weight watermarking, fingerprinting and output provenance marking are not modelled. They are an active area without a settled interoperable specification at artifact level.", "Runtime behavioural drift, online learning and continuously updated weights are only partially served: the model assumes a pinnable revision, and continual-learning systems that mutate weights in place would need an additional state and pinning strategy.", "Cost, pricing and commercial terms for access to the artifact are not modelled; they belong to a commercial agreement model.", "Hyperparameter capture is present in the aligned SPDX property set but is modelled here only as recorded build parameters, because hyperparameters are properly owned by the training run model.", "Cryptographic model signing and SLSA-style build attestations were not grounded in a fetched primary specification and remain a gap.", "Tokenizer, chat-template, and processor files are treated as payload members, not a sibling linguistic-resource model.", "Hardware-compiled engines (TensorRT, CoreML) and encrypted or TEE-sealed weights lack primary coverage here.", "Continual-learning in-place weight updates conflict with immutable-version rules and need a local policy.", "Mixture-of-experts expert-shard identity and federated partial models are not specified.", "Full ISO/IEC 22989:2022 clause text was not retrieved; AMD1 generative terms are used from public OBP fragments only.", "Model-card Toolkit / Mitchell 2018 academic schema is cited by Hugging Face but was not independently fetched." ], "conflicts": [ "Identity: content-addressed ecosystems treat the digest as the identity, while registry and management-system practice treats a governed registry key as the identity. This model resolves the conflict by ranking the registry key first and the digest as a verification and pinning key, and flags that ecosystems which only expose digests will not satisfy the first identity priority without a locally minted identifier.", "Versioning: graph IR specifications maintain three independent version axes (IR version, operator set version, model version) while package and hub ecosystems expose a single revision. Consumers merging both views can mistake one axis for another; the model keeps opset requirements separate from the artifact's own version label.", "Model card scope: the original research formulation, the hub metadata specification and the BOM modelCard object overlap but are not field-compatible — for example, evaluation result structures and consideration categories differ. Projections must map explicitly and declare unmapped fields.", "Regulatory scope: the open-source exemption removes certain documentation duties, yet ecosystem and management-system expectations still call for that documentation. An artifact can be lawfully exempt and simultaneously non-conformant with an internal policy; this model records exemption basis and internal obligation level as separate fields rather than collapsing them.", "Hashing: signing specifications name different default and alternative digest algorithms from container descriptor specifications. A single artifact can therefore carry digests under algorithms that different verifiers do not both accept; the model requires the accepted algorithm set to be declared by the Dimension.", "Energy reporting: regulatory documentation asks for known or estimated energy consumption, hub metadata expresses emissions equivalents, and the SPDX profile separates training, fine-tuning and inference consumption. These are not interconvertible without stated grid and accounting assumptions, so the measurement basis is a required companion field.", "SPDX AIPackage describes both an AI application and a trained model; this meta-model restricts itself to the trained-model reading and records the conflict.", "MLflow still documents stages (Staging/Production/Archived) while recommending aliases; both are modelled, with aliases preferred.", "CycloneDX ML-BOM emphasises supply-chain inventory; SPDX AI profile emphasises licence, energy, and safety metadata; alignment is not equivalence.", "Hugging Face model-index and newer eval_results formats overlap; either may project into attached metrics.", "EU GPAI legal object versus ISO AI-system object: a GPAI model artifact is not automatically an AI system under ISO 22989.", "Content-hash identity versus registry version identity diverges if weights are rewritten in place; this model forbids in-place rewrite." ], "regional_assumptions": [ "The regulatory classification finding is written against the EU general-purpose AI model regime because that is the regime with the most specific published artifact-level documentation content. Other jurisdictions are accommodated through the jurisdiction and obligation-set data elements but are not enumerated.", "Application dates for the general-purpose model obligations are jurisdiction-specific and were read from a reproduction; adopters outside the EU should treat the obligation set as a template to be re-derived locally.", "Export control and sanctions classification vocabularies are national and are modelled as a coded determination rather than an enumerated list, because no single international code list applies.", "Data residency constraints are assumed to derive from contract or local law rather than from the artifact itself; where no constraint is recorded, the model does not imply that storage anywhere is lawful.", "Retention periods are not asserted; they are recorded with their legal or contractual basis because statutory minimums vary by jurisdiction and by sector.", "EU GPAI Articles 53 and Annex XI/XII apply to models placed on the Union market from 2 August 2025; they do not automatically bind non-EU internal catalogs.", "NIST AI RMF 1.0 is voluntary US public-authority guidance, not a conformity scheme.", "Hugging Face Hub identifiers are a de facto public namespace, not a legal registry of record unless so designated by the owner.", "SPDX licence identifiers are used as the default licence code system." ], "adversarial_checks": [ "Counterexample tested — an artifact with no producing run: externally acquired or historically inherited artifacts have no resolvable training run. The producing-run composition link is therefore marked not required and an acquisition record substitutes, so the provenance layer does not collapse for third-party models.", "Counterexample tested — an artifact with no signature: much of the open-weights ecosystem is unsigned. Signature data elements are optional, but the verification gate is a Dimension-declared policy, so an unsigned artifact yields an explicit unverified state rather than a silent pass.", "Counterexample tested — a non-neural, non-deep artifact such as a gradient-boosted tree or a linear model: architecture family, parameter count, context window, quantization and operator set are all optional, so the model does not assume a large language model. Only identity, classification, licence, ownership and lifecycle are structurally required.", "Boundary stress test — post-market monitoring: it is tempting to model incident handling and drift monitoring here, but those obligations attach to the deployed system. The model keeps only a reverse index with a verified-revision flag and states the rationale inline, resisting scope creep into WM-AI-001.", "Boundary stress test — dataset content: training data provenance could easily absorb dataset structure. It is limited to references by role, curation methodology and the publishable content summary, with dataset semantics delegated to a dataset sibling model.", "Rejected structure — a 'hyperparameters' finding: although an aligned property set includes hyperparameters at package level, they are an output of the training run and would create a second, divergent copy. They are carried as recorded build parameters under production provenance instead.", "Rejected structure — a per-artifact fairness document and a per-artifact copyright policy document: neither has an independently governed carrier at artifact level, so both are recorded as inline-only with explicit rationale rather than inflating the artifact count.", "Falsifiability check — every bundle, layer, finding, function and composition link carries source references, and the two nodes leaning on paywalled ISO texts are declared as gaps in known_omissions rather than presented as canonical support.", "Would an agent confuse a sharded Safetensors directory with a different logical version if only the first shard is hashed? Mitigated by requiring hashes of every member plus a manifest hash.", "Would a LoRA adapter be registered as a patch to the base instead of a new artifact? The model forbids payload mutation and requires a derivation record.", "Would open-source GPAI providers drop Annex XI while still needing the public training-content summary and copyright policy? Exemption is modelled as partial.", "Would deprecated MLflow stages be treated as identity? Aliases are indexes; stages are optional status.", "Would evaluation metrics stored here be mistaken for a completed MEASURE campaign? Questions point to WM-AI-003 for protocols.", "Would an ONNX file be governed as a second model rather than a projection? Export function records lineage to the same version." ] }, "researchAdjudication": { "providerMode": "dual-provider", "activeProviders": [ "claude", "grok" ], "waivedProviders": [], "providerPolicy": {}, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "Both providers independently classify WM-SFT-004 as an entity and both draw the same four external boundaries (AI system, training run, evaluation campaign, dataset). The artifact has stable identity that survives repackaging, occupies controlled states, carries custody and rights, and is the subject rather than the actor of provenance and evaluation predicates — which is entity, not event or activity. Claude's boundary set is adopted whole because it adds the digital-file/OCI-blob boundary that Grok omits, explicitly demoting the content digest to an integrity and pinning key rather than the business identity of the artifact; that distinction is what keeps the entity from collapsing into its serialization. No reclassification or split is warranted." }, "decisions": [ { "concept": "Base provider selection", "disposition": "Claude adopted as base", "rationale": "Claude carries six explicit boundary notes against five, full in-scope and out-of-scope enumerations, inline-only rationales for every non-materialized finding, and adversarial checks that stress-test the boundary in both directions. Size is not the reason: the deciding factor is that Claude's boundaries are individually justified and falsifiable, including the digest-versus-identity boundary Grok never draws." }, { "concept": "Entry kind and model boundary", "disposition": "Accepted as entity with Claude's four-neighbour boundary set", "rationale": "Both providers agree on entity and on the same neighbours; adopting the base set whole avoids re-litigating a settled question and preserves the artifact/system/run/evaluation split that the EU GPAI track and provenance predicates both reflect." }, { "concept": "Identity: content digest versus registry key", "disposition": "Base resolution retained — registry key first, digest as verification and pinning key", "rationale": "Both providers reach the same conclusion, but only the base states the failure mode explicitly: ecosystems exposing digests alone cannot satisfy the first identity priority without a locally minted identifier. That named consequence is what makes the rule testable." }, { "concept": "grok:registry-and-global-identity", "disposition": "Rejected as duplicative", "rationale": "The base's fnd-canonical-identity already covers the authoritative registry identifier, the alias identifier set across registries and BOM documents, the abstraction level the identifier denotes, and collision or namespace-transfer handling. Grok's crosswalk question adds no governed structure the base lacks." }, { "concept": "grok:weight-and-format-payload", "disposition": "Rejected as duplicative", "rationale": "Serialization format and version, precision and quantization, safe-loading properties, shard layout and completeness, and the mandatory-versus-optional component roster are already split across two base findings. Only per-member size and media type are absent, which is a data-element detail, not a missing finding." }, { "concept": "grok:gpai-technical-documentation", "disposition": "Rejected as duplicative", "rationale": "Annex XI documentation, the Annex XII downstream pack, the public training-content summary and the free-and-open-source exemption are already distributed across the base's documentation-obligations, regulatory-status and training-data-provenance findings, and both of Grok's artifacts have base counterparts. Re-adding it would fork the documentation carrier." }, { "concept": "grok:sensitive-data-safety-energy", "disposition": "Rejected in favour of the base's finer decomposition", "rationale": "Grok fuses three unrelated concerns into one finding. The base separates sensitive personal data (under training-data provenance, with lawful basis), safety assessment and adversarial testing, and energy and emissions with a measured-versus-estimated basis field. The finer split is what allows each to be independently falsified." }, { "concept": "grok:owner-access-and-retention", "disposition": "Rejected as duplicative", "rationale": "Ownership and stewardship, access gating with export control and residency, and deprecation with retention and destruction evidence are three separate base findings with stronger question sets, including role separation, ownership handover and non-deletable evidence classes." }, { "concept": "grok:task-modality-and-library and grok:architecture-and-scale", "disposition": "Rejected as duplicative", "rationale": "Task, architecture family, parameter scale, modality and loading library are covered by the base's model-taxonomy, io-signature and execution-environment findings. The one marginal residue, learning approach, sits closer to the training run than to the artifact and is deferred rather than minted as structure." }, { "concept": "grok:evaluation-evidence bundle and quantitative-performance layer", "disposition": "Rejected; folded into base lyr-performance-evidence", "rationale": "The base already attaches metrics with datasets and splits, evaluator provenance and independence, decision thresholds and measurement currency to the revision while delegating protocol to WM-AI-003. A separate bundle would create a second home for the same claims." }, { "concept": "grok:stage-alias-and-status", "disposition": "Accepted as fnd-deployment-alias-pointers in lyr-lifecycle-change", "rationale": "The mutable, environment-scoped deployment alias is a governed pointer distinct from the immutable version's own state, evidenced in fetched registry documentation, and it fills a gap the base itself declares open because its lifecycle standards were paywalled. Retitled so the deprecated stage vocabulary is not imported as canonical." }, { "concept": "Hyperparameter ownership conflict", "disposition": "Base rule retained — hyperparameters stay with the training run", "rationale": "Grok copies hyperparameters onto the artifact; the base carries them only as recorded build parameters under production provenance. The base rule prevents a second divergent copy of run-owned data and is consistent with the accepted run boundary, so the conflict is adjudicated rather than left open." }, { "concept": "Model signing, transparency logs and build attestation", "disposition": "Base retained without cross-provider corroboration", "rationale": "Grok explicitly declares signing and SLSA-style attestation as an ungrounded gap in its own research. The base's signing, manifest-coverage, transparency-evidence and verification-gate structure therefore stands on a single provider's sources and is carried through to a publication hold rather than treated as jointly confirmed." }, { "concept": "Three operational functions from Grok", "disposition": "Accepted: interchange projection export, deployment alias assignment, documentation release to authority", "rationale": "Each performs an act the base only questions or implies — payload format conversion, mutable pointer assignment, and regulator-facing disclosure under confidentiality markings — and each is evidence-backed in the source provider. The remaining five Grok functions map one-to-one onto existing base functions and are rejected." }, { "concept": "Regional framing", "disposition": "Base EU-first framing retained with jurisdiction as a data element", "rationale": "Both providers write regulatory classification against the EU GPAI regime because it is the regime with the most specific published artifact-level documentation content. The base accommodates other jurisdictions through the jurisdiction and obligation-set elements without enumerating them, which is the honest position." } ], "publicationHolds": [ "Live-source verification is incomplete: every accepted source URL and version pin must be re-fetched and confirmed resolvable before publication, covering all 21 base sources plus the three Grok sources (SRC-007 MLflow Model Registry, SRC-008 Article 53, SRC-010 ONNX, SRC-013 Annex XI) that back the accepted finding and functions.", "The EU AI Act provisions underpinning regulatory classification, documentation obligations and the training-content summary were read from a third-party reproduction, not the Official Journal. Article 53, Annex XI and Annex XII wording, recital context, corrigenda and implementing acts must be re-verified against EUR-Lex before publication or any compliance-facing use.", "ISO/IEC 42001:2023 and ISO/IEC 5338:2023 were verified only at catalogue-record level because the texts are paywalled. Every node resting on them for lifecycle stage vocabulary, Annex A control mapping or process naming is an alignment gap, not evidenced conformance, and must be labelled as such in the published draft.", "Multi-profile validation is not demonstrated. The model must be exercised against at least four domain profiles before publication: a closed-weights GPAI foundation model, an open-weights fine-tune or LoRA adapter, a non-neural classical artifact such as a gradient-boosted tree, and an externally acquired artifact with no resolvable producing run and no signature.", "The accepted alias finding and fn-set-deployment-alias rest on de facto registry practice with a deprecation in flight (stages being superseded by aliases). Re-verify the current MLflow documentation version at publication time and mark the node as ecosystem practice rather than a normative specification.", "Cryptographic signing, transparency-log inclusion and build-attestation structure is single-provider evidence, since the non-base provider declares it as an unfilled gap. Confirm the OpenSSF Model Signing specification version status and the SLSA v1.0 predicate pin before presenting these nodes as settled." ], "deferredResearch": [ "Artifact sameness across lossless repackaging, re-serialization and format conversion: no standards-derived rule exists. The base records conversion as a new revision with lineage, which is a design decision that needs either external grounding or an explicit Dimension-level policy statement.", "Continual and online learning with in-place weight mutation conflicts with the immutable-revision and pinning assumptions both providers rely on. An additional state model and pinning strategy is required before the model can serve continuously updated weights.", "Mixture-of-experts expert-shard identity, federated partial models, hardware-compiled engines (TensorRT, CoreML) and TEE-sealed or encrypted weights lack primary coverage in either provider and need dedicated source work.", "Model weight watermarking, fingerprinting and output provenance marking have no settled interoperable artifact-level specification; revisit when a candidate specification stabilises.", "ISO/IEC 22989:2022 and ISO/IEC 23053:2022 clause text for foundation-model and learning-approach terminology was never retrieved by either provider; obtain the clause text before adding any terminology-derived classification node.", "Per-payload-member size and media type, and tokenizer, chat-template and processor files as candidate sibling linguistic resources rather than payload members, are open modelling questions carried forward from the non-base provider's omissions.", "Systemic-risk threshold criteria and the Commission training-content summary template are regime-specific and evolving; track for a published template before encoding any threshold value or summary schema." ] }, "statistics": { "sources": 30, "bundles": 6, "layers": 12, "findings": 28, "questions": 116, "artifacts": 24, "functions": 13 } }