{
  "$schema": "./schema.json",
  "id": "asean-ai-guide",
  "name": {
    "en": "ASEAN Guide on AI Governance and Ethics — AIO formalization",
    "ko": "아세안 AI 거버넌스·윤리 지침 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "ASEAN Guide on AI Governance and Ethics",
    "publisher": "Association of Southeast Asian Nations (ASEAN)",
    "version": "Endorsed by the 4th ASEAN Digital Ministers' Meeting (ADGMIN), Singapore, 1-2 February 2024; 87-page publication comprising seven guiding principles (Section B), a four-part AI governance framework (Section C), national- and regional-level recommendations (Sections D and E), Annex A (AI Risk Impact Assessment Template) and Annex B (use cases)",
    "url": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf"
  },
  "vesMapping": [
    {
      "article": "Section B, Guiding Principle 1 — Transparency and Explainability",
      "summary": "Deployers are to disclose to stakeholders that an AI system is in use and are to foster general awareness of it, so that individuals know when they are interacting with an AI system and can make an informed choice; developers and deployers are to foster general understanding of how such systems reach decisions through simple explanations, and where a black-box model makes that impossible, outcome-based explanations may be relied on, supported by documented repeatability, an audit trail, comprehensive records of data provenance and processing, and AI model cards.",
      "v": [
        "Sdt"
      ],
      "e": [],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The disclosure limb has a judgment correlate an item can test — whether a model says that it is a system and on what basis it produced an output. The explainability limb, as this Guide operationalises it, is almost entirely organizational: the four measures the principle actually names are documentation artefacts (repeatability assessments, an audit trail or black box recorder, records of data provenance and procurement, AI model cards), and an AIO measurement observes none of them. An AIO 20002 record is a one-line structured trace of which value, evidence and source classes governed a decision; it can be an input to the outcome-based explanation this principle permits, but it is not that explanation, not an audit trail, and not a model card. The principle's own auditability caveat — that auditability does not require publishing confidential business-model or intellectual-property information, and that a risk-based approach may select the subset of features for which auditability is implemented — is paraphrased here rather than quoted, to hold quotation to the minimum the licence position allows.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section B, Guiding Principle 1 (Transparency and Explainability), p. 11",
        "quote": "deployers have a responsibility to clearly disclose the implementation of an AI system to stakeholders and foster general awareness of the AI system being used",
        "rationale": "The principle is written from the position of the person on the other side of the system: disclosure exists so that individuals 'become aware and can make an informed choice of whether to use the AI-enabled system', which protects their capacity to reach their own view (`Sdt`). The quoted words frame it as a responsibility owed to stakeholders, which is `Bed` — being a reliable party that keeps the obligations it holds. `Ses` is coded from the principle's own traceability measure, 'Ensuring traceability by building an audit trail to document the AI system development and decision-making process', which makes the working of the system as such inspectable; the same reading was applied to auditability in the UNESCO pack. On evidence: explainability is discharged by 'the ability to communicate the reasoning behind an AI system's decision in a way that is understandable to a range of people' — a reasoned account of how the input became the outcome (`Log`) — and the alternative measures the principle offers are standing documented practices (`Gui`). No metric is made decisive by the principle, so `Dat` is not coded, and no expert, precedent or case series is named. On sources, the principle designates deployers and developers as the parties that owe the disclosure and the explanation (`Ind`); it names no governmental authority and no legal instrument inside this principle, so `Gov` is not coded under the source-axis policy recorded in the pack notes. ADJUDICATION 2026-08-14: S ([Ind]) and obligationType (`mixed`) agreed exactly, both passes reading the deployer as the unilateral author of the disclosure and both recording that stakeholders are its recipients and not a source — the recipient-is-not-a-source rule settled in Wave 2, applied here in agreement rather than as a correction. V narrows to [Sdt], the one code both passes reached: the excerpt's disclosure exists so that those on the other side of the system can know what they are dealing with and judge it for themselves. `Bed` and `Ses` are dropped. `Bed` was argued from 'have a responsibility ... to stakeholders'; the blind pass did not reach it and the words state to whom the duty runs rather than naming dependability as the interest protected, so under the conservative rule it does not survive. `Ses` was read from the principle's audit-trail measure, which is not in the quoted words at all. **E is emptied, and the reason is the textual distinction that separates this entry from Section C.4**: 'foster general awareness' names an outcome to be produced and nothing that discharges the duty, whereas the Section C.4 excerpt enumerates what the disclosure must contain. The blind pass reached that distinction independently and it is adopted. `Log` and `Gui` both rested on sentences outside the excerpt (the communicate-the-reasoning definition and the four documentation measures), which is the over-declaration-beyond-the-excerpt pattern that dominates the corrections in this pack.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Bed, Ses] → [Sdt]; E [Log, Gui] → []; S [Ind] and obligationType `mixed` agreed exactly. The empty evidence layer is a positive finding, not a gap: the excerpt names an outcome to be fostered and nothing that discharges the duty. It is the counterpart of Section C.4, where the excerpt does enumerate disclosure content and `Gui` therefore survives — the two disclosure entries of this pack are deliberately coded differently on the evidence axis and the difference is textual."
    },
    {
      "article": "Section B, Guiding Principle 2 — Fairness and Equity",
      "summary": "Deployers are to have safeguards in place so that algorithmic decisions do not further exacerbate or amplify existing discriminatory or unjust impacts across different demographics, and the design, development and deployment of AI systems is not to result in unfair bias or discrimination; deployers are to conduct regular testing to confirm whether bias is present and to make the adjustments needed to rectify imbalances where it is, and the datasets used for training are to be diverse and representative, with appropriate measures against bias at data collection and pre-processing, training and inference.",
      "v": [
        "Unc"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Deliberately the sparsest entry in the pack: one value code, one evidence code, one source code. The principle names exactly one protected interest and exactly one thing that discharges the duty, and declaring nothing else is the honest signal that scoring against this entry does not reach further. The judgment correlate an item can test is the outcome limb — whether a model's judgment in a concrete case tracks non-discrimination across demographics. Everything else the principle asks for is organizational: standing safeguards, a testing cadence, dataset composition, and bias mitigation at collection, pre-processing, training and inference. The Guide develops the same duty at operational length in Section C.3 (representation, societal, labelling, measurement, activity and proxy bias; labeller guidelines and quality assurance; fairness testing with a validation dataset), which is mapped separately in this pack as the operations-management entry.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section B, Guiding Principle 2 (Fairness and Equity), p. 12",
        "quote": "the design, development, and deployment of AI systems should not result in unfair biasness or discrimination",
        "rationale": "The interest the principle protects is stated in its own terms — safeguards so that decisions 'do not further exacerbate or amplify existing discriminatory or unjust impacts across different demographics' — which is `Unc`, equality, justice and protection for all people. No other value is declared, because the principle names none: it does not reach personal safety, societal order, or compliance with a rule, and coding those would be reading the AIO vocabulary into the text rather than out of it. On evidence, what the principle accepts as discharging the duty is measurement: deployers 'should conduct regular testing of such systems to confirm if there is bias' (`Dat`). `Gui` was considered and rejected — the principle prescribes no documented standard procedure for the testing, and the illustrative testing frameworks the Guide names appear in Section C.3, not here. On sources, only deployers and the design, development and deployment chain are designated (`Ind`); the principle names no governmental authority, no professional body and no scholarly source. ADJUDICATION 2026-08-14: V ([Unc]) and obligationType (`mixed`) agreed exactly, and the blind pass additionally considered and rejected `Unt` on the ground that the excerpt prohibits discriminatory outcomes rather than requiring acceptance of those who differ. E is emptied: `Dat` was read from the principle's regular-testing sentence, which is not in the quoted words, and the excerpt fixes a result ('should not result in unfair biasness or discrimination') without naming anything that discharges it. `Gui`, considered and rejected in v0.1, is confirmed absent on both sides. S is emptied: the excerpt names activities — design, development and deployment — and no actor, so the `Ind` of v0.1 was carried in from the principle's addressee rather than read from the excerpt. This is the sparsest entry in the pack, as v0.1 said it was, and the second pass made it sparser.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Unc] and obligationType `mixed` agreed exactly. E [Dat] → []; S [Ind] → []. The entry now declares one code in one layer, which is the honest reading of an excerpt that states a prohibited result and designates neither a discharge nor an actor."
    },
    {
      "article": "Section B, Guiding Principle 3 — Security and Safety",
      "summary": "AI systems are to be safe and sufficiently secure against malicious attacks; safety is to be ensured by conducting impact or risk assessments so that known risks are identified and mitigated, by adopting a risk-prevention approach with precautions that let humans intervene to prevent harm or let the system safely disengage itself when it makes unsafe decisions, by conducting risk assessments and relevant testing or certification before deployment with an appropriate level of human intervention, and by making the risks, limitations and safeguards known to the user; security is to be ensured through technical measures such as authentication and encryption, regular updates, access management for critical or sensitive systems, security testing, and incident response plans.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [
        "Exp"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The judgment correlate is the priority rule in the quoted sentence: safety of the public and users is to be of utmost priority in the decision-making process of AI systems. That is a statement about which value prevails when it meets another, which is exactly what an AIO 20002 record encodes on the left and right of its `<`, and an item on this principle is an item about which side of that `<` the model puts safety on. The organizational limb is everything that makes the priority operable — the assessment practice, the testing or certification step, the intervention mechanism, the update and access-management regime, the incident response plan, the enumerated security-testing list (vulnerability assessment, penetration testing) and the business continuity and disaster recovery considerations. `Ses` is an inference; see the rationale. ADJUDICATION 2026-08-14: `Ses` is no longer an inference. Both passes carry it, and the blind pass grounded it inside the quoted sentence ('the public') rather than in the security limb, which is where v0.1 had to reach for it. The vocabulary gap v0.1 recorded — that the value layer has no code for the integrity or resilience of the artefact itself — is unchanged and now travels in the gap list rather than inside the code.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section B, Guiding Principle 3 (Security and Safety), p. 13",
        "quote": "Safety of the public and the users of AI systems should be of utmost priority in the decision-making process of AI systems and risks should be assessed and mitigated to the best extent possible.",
        "rationale": "The quoted sentence names its protected interest twice over — the safety of the public and of the users — which is `Sep`, the physical and psychological safety of the person and those close to them, and the principle's own illustration (autonomous vehicles causing injury to pedestrians) confirms that bodily harm is what is meant. `Ses` is an INFERENCE from the security limb of the same principle, which is about the resilience of the deployed system itself against data poisoning, model inversion, dataset tampering and byzantine attacks in federated learning: the AIO value layer, being derived from Schwartz, has no code for the integrity of an artefact, and `Ses` (stability and order at large) is the nearest class. This is put to the RFC round. On evidence, what discharges the duty in the quoted sentence is a completed risk assessment run as a standing practice, with testing or certification before deployment (`Gui`), and the considered judgment of the human whose intervention the principle requires when an unsafe decision occurs (`Exp`). `Dat` was considered for 'relevant testing' and not coded: the principle makes no metric or threshold decisive, and the testing it names is a gate rather than a measurement whose numbers settle the question. On sources, developers and deployers are the designated parties (`Ind`); no regulator, standards body or professional body is named as decisive in this principle, so neither `Gov` nor `Pro` is coded. ADJUDICATION 2026-08-14: V ([Sep, Ses]) and obligationType (`mixed`) agreed exactly — **and the agreement discharges one of v0.1's four flagged inferences by replacing its grounding**. v0.1 reached `Ses` by inference from the principle's security limb, for which the Schwartz-derived value layer has no code for the integrity of an artefact; the blind pass reached `Ses` from words inside the excerpt, reading 'Safety of the public' as the stability and safety of society at large alongside 'the users of AI systems' as the personal safety of the person. The code survives on the second reading, which is text-grounded, and the vocabulary gap the first reading exposed is recorded separately rather than carried in the code. Ranking: the excerpt does rank — safety is to be 'of utmost priority' — but it names no value on the losing side of that ranking, so no ordered pair is formed and the order of the two codes carries no meaning. E narrows to [Exp], reached by both passes from 'risks should be assessed and mitigated to the best extent possible' — an assessment is designated as the discharge, no metric is made decisive (both passes considered and rejected `Dat`) and no written procedure is named, which leaves the assessor's considered judgment. `Gui` is dropped: the standing assessment practice and the pre-deployment testing or certification step that carried it are in the principle's other sentences, not in the excerpt. S is emptied: the excerpt is passive throughout and designates no party.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Ses] and obligationType `mixed` agreed exactly; E [Gui, Exp] → [Exp]; S [Ind] → []. **The second of v0.1's four flagged inferences is discharged here**: `Ses` was an inference from the security limb in v0.1 and is now text-grounded on 'Safety of the public', which the blind pass read independently. The excerpt ranks safety as of 'utmost priority' but names no losing value, so no ordered pair is recorded and array order carries no meaning."
    },
    {
      "article": "Section B, Guiding Principle 4 — Human-centricity",
      "summary": "AI systems are to respect human-centred values and pursue benefits for human society, are to be designed with human benefit in mind where they make or aid decisions about humans, and are not to take advantage of vulnerable individuals; they are not to be used for malicious purposes or to sway or deceive users into making decisions that are not beneficial to them or to society, and dark patterns — design techniques that manipulate users into decisions they would otherwise not have made — are to be avoided; human-centricity is to be incorporated throughout the lifecycle, including by testing the system with users of varied backgrounds and demographics and incorporating their feedback, and adoption at scale is not to disrupt labour and job prospects without proper assessment.",
      "v": [
        "Sdt",
        "Unc"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "This is the principle whose judgment correlate is least ambiguous — a system either manipulates the user toward a decision that is not in their interest or it does not — and it was considered for `behavioral` classification on the UNESCO paragraph 36 precedent. It is classified `mixed` instead, because unlike that paragraph this principle does impose management-system duties in its own words: human-centricity is to be incorporated across the lifecycle, the system is to be tested with a group of users from varied backgrounds whose feedback is incorporated, and impact assessments are encouraged for the labour effects of deployment at scale. Recording that honestly is what leaves this pack with no `behavioral` entry at all — see the measurement-scope note. The labour limb points readers to Singapore's PDPC Guide on Job Redesign in the Age of AI; that reference is noted here and is not treated as designating a source class, since the Guide cites it as useful guidance rather than as decisive on the substance of the duty. ADJUDICATION 2026-08-14: the blind second pass classified this provision `behavioral` from the excerpt alone, which is the third time in the pack series a `behavioral` candidate has been raised and the third time it has been lowered at adjudication (after the OECD and California packs of Wave 2). It is lowered here for the reason v0.1 gave and the blind pass could not see from a one-sentence excerpt: the same principle requires lifecycle incorporation, testing with users of varied backgrounds, and assessment of labour effects. UNESCO paragraph 36 remains the only `behavioral` entry anywhere in the series.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section B, Guiding Principle 4 (Human-centricity), p. 14",
        "quote": "AI systems should not be used for malicious purposes or to sway or deceive users into making decisions that are not beneficial to them or society.",
        "rationale": "Three values are read from the quoted sentence and its immediate neighbourhood. Not swaying or deceiving the user protects the user's capacity to reach their own conclusion rather than the one the interface steers them to (`Sdt`), and the principle's own definition of dark patterns — techniques that 'trick them into making decisions that they would otherwise not have made' — is exactly that interest stated negatively. 'Benefits for human society, including human beings' well-being' and the instruction that systems must 'not take advantage of vulnerable individuals' give `Unc`, protection for all people with attention to those least able to protect themselves. The quoted words end 'or society', which is `Ses` — the sentence puts the collective on the same footing as the individual user. On evidence, the principle names what informs the design: 'test the AI system with a small group of internal users from varied backgrounds and demographics and incorporate their feedback in the AI system', which is the firsthand account of those who used it (`Tri`), and the impact assessments it encourages for labour effects are a systematic, stakeholder-based review conducted as a standing procedure (`Gui`). Both are stated in the principle's text outside the quoted excerpt and are cited here rather than quoted, to hold quotation to the minimum. On sources, developers and deployers are the designated parties (`Ind`); `Gov` is not coded, because the only governmental material the principle names is a Singapore agency guide offered as a useful reference, which does not make a governmental authority decisive on the substance of the duty. ADJUDICATION 2026-08-14: V narrows to [Sdt, Unc], the two codes both passes reached — deceiving users attacks their capacity to reach their own conclusion (`Sdt`), and 'not beneficial to them or society' extends the protected interest past the individual user to persons generally (`Unc`). The two passes then split on the same words in opposite directions: v0.1 read the closing 'or society' as `Ses`, the collective put on the same footing as the user, while the blind pass read 'sway ... into making decisions' as `Sda`, freedom of action, separately from 'deceive' as `Sdt`. Neither survives, because each rests on one pass only; the split is Wave 2 gap 13, the `Sdt`/`Sda` boundary, recurring on a sentence that uses both verbs in one breath. **obligationType stays `mixed` against the blind pass's `behavioral`**: the blind pass saw a flat prohibition on use in the excerpt and was right about the excerpt, but the principle imposes lifecycle, user-testing and labour-assessment duties in its own words, and a divergent obligationType always resolves to the more conservative tag. E and S are emptied. `Tri` and `Gui` were read from the varied-backgrounds testing sentence and the labour impact assessments, both outside the excerpt and both expressly cited rather than quoted in v0.1; the excerpt designates nothing that discharges it. `Ind` was carried in from the principle's addressee — the excerpt's subject is 'AI systems', not a party.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Unc, Ses] vs the blind pass's [Sdt, Sda, Unc] → [Sdt, Unc]; E [Tri, Gui] → []; S [Ind] → []. **obligationType `mixed` retained against the second pass's `behavioral`**, under the rule that a divergent obligationType resolves to the more conservative tag — the sharpest judgment norm in the Guide still imposes lifecycle and assessment duties in its own words. The pack's `behavioral` count therefore stays at zero after dual formalization."
    },
    {
      "article": "Section B, Guiding Principle 5 — Privacy and Data Governance",
      "summary": "AI systems are to have proper mechanisms ensuring data privacy and protection and maintaining the quality and integrity of data throughout their entire lifecycle, with data protocols governing who can access data and when; the way data is collected, stored, generated and deleted across the lifecycle is to comply with applicable data protection law, data governance legislation and ethical principles; organisations are to be transparent about their collection practices, to obtain the necessary consent or another appropriate legal basis, not to gather unnecessary or irrelevant data, to set up and periodically review data protection and governance frameworks, and to apply privacy by design, with data protection impact assessments noted as narrower in scope than an AI risk assessment and not sufficient in its place.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Organizational outright. Access protocols are written, frameworks are set up and reviewed, consent is obtained, impact assessments are run — an AIO item observes none of it, and a model can pass every item built on this pack while the operator has no data protection framework at all. The principle is mapped so that the management-system guide has an anchor for its data-governance category and so that the pack does not appear to cover data practice by silently omitting it. One caution the principle states and this pack repeats rather than softens: a data protection impact assessment is narrower than an AI risk assessment and does not stand in for one. `Sda` is an inference; see the rationale. Only `Gui` is declared on the evidence layer, because the principle names no metric, no expert, no precedent and no firsthand account — an undeclared layer is the honest signal that scoring does not reach it.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section B, Guiding Principle 5 (Privacy and Data Governance), p. 14",
        "quote": "The way data is collected, stored, generated, and deleted throughout the AI system lifecycle must comply with applicable data protection laws, data governance legislation, and ethical principles.",
        "rationale": "The quoted sentence is a compliance rule in terms — its operative verb is 'must comply with applicable data protection laws' — which is `Cor`. The interest those laws protect, and which the principle's own list of ASEAN statutes is directed at, is the individual's personal sphere against misuse of information about them; the AIO value layer has no dedicated privacy code and `Sep`, the physical and psychological safety of the person, is the class the pack uses for that interest. `Sda` is an INFERENCE from the consent limb of the same principle — 'necessary consent is obtained from individuals before collecting, using, or disclosing personal data' — read as freedom to determine one's own course; the principle does not frame consent in terms of autonomy, so this is put to the RFC round. On evidence, what discharges the duty is a documented framework operated and periodically reviewed, with data protection impact assessments run inside it (`Gui`); nothing in the principle makes a measurement decisive. On sources this entry departs from the rest of the pack: the quoted excerpt itself names 'applicable data protection laws, data governance legislation' as the instruments decisive on the substance of the duty, which meets the test the source-axis policy recorded in the pack notes applies, so `Gov` is coded here and the principle's enumeration of six ASEAN national statutes confirms it; `Ind` is coded for the developers and deployers who must set up and adhere to the frameworks. ADJUDICATION 2026-08-14: E ([Gui]), the `Gov` limb of S, and obligationType (`organizational`) agreed exactly, both passes reading 'must comply with applicable data protection laws, data governance legislation' as making a legal instrument decisive on the substance of the duty — which is what the source-axis rule requires and is one of only two places in this pack where it is met. V narrows to [Cor], the one code both passes reached and the one the excerpt states in terms. `Sep` is dropped: the privacy interest it stood for is available from the principle's TITLE and from the statutes the principle enumerates, but not from the quoted sentence, and a code that depends on a heading rather than on the text fails textual determinacy. `Sda` was flagged as an inference in v0.1, read from a consent sentence outside the excerpt; the blind pass did not reach it and an inference-flagged code survives only where both passes do. `Ind` is dropped from S for the same reason as at Guiding Principles 2, 3 and 4: the excerpt's subject is 'The way data is collected, stored, generated, and deleted', not a party. The value layer of this entry is now the plainest instance in the pack of the privacy gap recorded across the Council of Europe and Chinese packs — the duty is coded as conformity because conformity is what the sentence says, and the interest the statutes protect has no carrier.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Cor, Sep, Sda] → [Cor]; E [Gui], the `Gov` limb of S, and obligationType `organizational` agreed exactly; S [Gov, Ind] → [Gov]. **The third of v0.1's four flagged inferences falls here**: `Sda`, read from a consent sentence outside the excerpt, was not reached by the blind pass. `Sep` is dropped as title-based rather than text-based coding."
    },
    {
      "article": "Section B, Guiding Principle 6 — Accountability and Integrity",
      "summary": "Deployers are to ensure the proper functioning of AI systems and their compliance with applicable laws, internal AI governance policies and ethical principles, and are to be accountable for the decisions those systems make; where a malfunction or misuse of the system results in negative outcomes, responsible individuals are to act with integrity and implement mitigating actions to prevent similar incidents in future; to allocate responsibilities, organisations are to adopt clear reporting structures for internal governance setting out the roles and responsibilities of those involved in the lifecycle, and errors or unethical outcomes are at minimum to be documented and corrected to prevent harm to users.",
      "v": [
        "Bed",
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind",
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Accountability under this Guide is discharged by structure, not by judgment: reporting lines are drawn, roles are assigned, errors are documented and corrected, mitigating actions are implemented after an incident. Nothing an AIO item observes tells anyone whether the reporting structure exists or whether the correction was made. What an AIO 20002 record contributes is narrower and worth stating precisely: because the record is retrospectively readable per decision, when a malfunction is investigated the account of what governed the decision is available to whoever runs the investigation. That is an input to someone else's investigation, never the investigation, and never the accountability the principle assigns. `Cas` is an inference; see the rationale.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section B, Guiding Principle 6 (Accountability and Integrity), p. 15",
        "quote": "Deployers should be accountable for decisions made by AI systems and for the compliance with applicable laws and respect for AI ethics and principles.",
        "rationale": "The quoted sentence carries two values on its face. Being answerable for what one's systems decided is `Bed` — being a reliable party that keeps the obligations it holds — and the principle's insistence on 'human accountability and control' and on acting 'with integrity throughout the AI system lifecycle' is the same value stated at length. 'Compliance with applicable laws' is `Cor`. On evidence, what discharges the duty is the clear reporting structure the principle requires, 'setting out clearly the different kinds of roles and responsibilities for those involved in the AI system lifecycle', which is a documented standard arrangement (`Gui`). `Cas` is an INFERENCE from the incident limb: where a malfunction or misuse produces negative outcomes, responsible individuals are to 'implement mitigating actions to prevent similar incidents from happening in the future', which presupposes structured analysis of the instance that occurred and of the ones it resembles; the principle does not say so in terms, and this is put to the RFC round. `Dat` was considered and not coded — no metric is made decisive. On sources, deployers and AI actors are the designated parties (`Ind`), and the quoted excerpt names 'applicable laws' as decisive on the compliance limb, which under the source-axis policy recorded in the pack notes admits `Gov`. ADJUDICATION 2026-08-14: V ([Bed, Cor]), the `Gui` evidence layer, the `Gov` limb of S and obligationType (`organizational`) agreed exactly — the highest agreement of any entry in this pack, and it follows from an excerpt that names its two values, its yardstick and its actor in one sentence. `Cas` is dropped: v0.1 flagged it as an inference from the incident limb ('implement mitigating actions to prevent similar incidents'), which is outside the excerpt, and the blind pass did not reach it. **`Ind` is retained against the blind pass's silence, and the reason is textual rather than deferential**: 'Deployers' is the grammatical subject of the quoted sentence and the decisions it makes them answerable for are their own systems' output, which is exactly what the source-axis rule asks — that the excerpt make the industry duty-bearer the author or performer of the provision's product or determination. Applied that way the rule is a filter and not a generator: it keeps `Ind` on the five entries whose excerpts name the deployer or the organization's own organ (Guiding Principles 1 and 6, Sections C.1, C.3 and C.4) and removes it from the five whose excerpts are passive or impersonal.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Bed, Cor], E's `Gui`, S's `Gov` and obligationType `organizational` agreed exactly. E [Gui, Cas] → [Gui] — **the last of v0.1's four flagged inferences falls here**. S [Ind, Gov] retained in full: `Ind` survives the blind pass's silence because 'Deployers' is the grammatical subject of the excerpt, which is the textual test the source-axis rule states."
    },
    {
      "article": "Section C.1 — Internal governance structures and measures",
      "summary": "Organisations are to put internal governance structures in place, newly created or adapted from existing risk management structures, to have oversight of how AI systems are designed, developed and deployed; they may set up a multi-disciplinary central governing body such as an AI Ethics Advisory Board or Ethics Committee, drawn from ethics, law, philosophy, technology, privacy, regulation and science and sufficiently representative of stakeholders and a range of voices, to oversee governance efforts, give independent advice and develop standards, guidelines, tools and templates; structures may be designed so that higher-risk use cases escalate to a body with higher authority; policies, oversight mechanisms, clear roles and responsibilities, training and awareness-raising are to accompany them, the structures are to be reviewed and assessed periodically, and the degree of centralisation and the burden are to be suited to the organisation's structure, culture, size and capabilities.",
      "v": [],
      "e": [
        "Exp",
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This is the provision that gives this instrument the heaviest management-system weight of any norm in the soft-law group AIO has formalized: a named standing body, a defined composition, an escalation design, a training programme and a periodic review of the governance model itself. No item-based measurement reaches any part of it, and a pass on this pack is not evidence that any of it exists. The provision is mapped so that the pack does not understate how much of this Guide sits outside what can be measured, and so that the management-system guide's governance category has an anchor. The Guide's own proportionality caveat is preserved in the summary rather than dropped: a central governing body may be too onerous for smaller companies, which may instead take a risk-based approach focused on the risks the structure would address. ADJUDICATION 2026-08-14: the value layer of this entry is empty after dual formalization, and the consequence is recorded rather than smoothed over: **item authoring against this entry is deferred**, on the UNESCO paragraph 71 precedent. An item needs a protected interest to press against, and this provision names none in the words that can be quoted from it; writing one would mean supplying the interest ourselves. The entry stays mapped because the Guide's heaviest management-system provision should not be silently absent from the pack, and because the management-system guide's governance category needs an anchor.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section C.1 (Internal governance structures and measures), p. 18",
        "quote": "central governing body, such as an AI Ethics Advisory Board or Ethics Committee, to oversee AI governance efforts, provide independent advice, and develop standards, guidelines, tools, and templates",
        "rationale": "Two values are read from the provision's own reasons for the body it describes. It is to be multi-disciplinary, its advisors 'can be drawn from ethics, law, philosophy, technology, privacy, regulations, science, and other relevant domains', and 'To adequately reflect the diversity of society, there is also value in considering a governing body that is sufficiently representative of stakeholders and a range of voices' — understanding and accepting those who differ, which is `Unt`. The section's insistence on clarity of roles and responsibilities 'to ensure that the relevant individuals are aware of their duties' is `Bed`. `Ses` was considered for the escalation design and not coded: the provision orders authority inside an organisation, not stability at large, and coding it would stretch the value layer past what the text says. On evidence, the body's output is of two kinds and both are named in the quoted words: 'independent advice', which is the considered judgment of recognised specialists (`Exp`), and 'standards, guidelines, tools, and templates', which are written standard procedures (`Gui`). On sources, only the organisation itself is designated (`Ind`). `Pro` was specifically considered and rejected: the section does name professional bodies, and names the Singapore Computer Society's Certificate in AI Ethics and Governance, but it names them as providers of training for personnel, not as a class whose collective position is decisive on any duty — the same discipline that kept `Pro` out of most Wave 1 packs. ADJUDICATION 2026-08-14: E ([Exp, Gui]), S ([Ind]) and obligationType (`organizational`) agreed exactly, and on the same words: 'provide independent advice' is the considered judgment of an assigned overseer (`Exp`), 'develop standards, guidelines, tools, and templates' is written standard procedure (`Gui`), and the body is the organization's own internal organ (`Ind`). **`Pro` was considered and refused on both sides**, independently and for the same reason — an internal AI Ethics Advisory Board or Ethics Committee is not the field-wide body of credentialed practitioners the code describes, and the Singapore Computer Society certificate the section names is a training provider, not a class whose collective position is decisive. **The value layer is left undeclared, and that is the honest outcome rather than an omission.** The two passes shared no value code: v0.1 read `Unt` from the multi-disciplinary composition and the representative-of-a-range-of-voices sentence, and `Bed` from the clarity-of-roles sentence, both outside the excerpt; the blind pass reached `Cor`, flagged it as an inference from the body's mandate, and recorded that an empty value layer would also be defensible because no value is named in the words themselves. An inference-flagged code that only one pass reached does not survive, and v0.1's two were not reached blind. What is left is a provision that constitutes an organ and names no interest behind it — Wave 1 gap 10 (undefined protected interest) in its second-purest instance after UNESCO paragraph 71.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E [Exp, Gui], S [Ind] and obligationType `organizational` agreed exactly. V [Unt, Bed] vs the blind pass's [Cor] → **[] — the second entry in the pack series to carry no value code at all**, after UNESCO paragraph 71. The two passes shared no value code and the blind pass's single code was self-flagged as an inference with an empty layer recorded as equally defensible. `Pro` was considered and refused independently by both passes."
    },
    {
      "article": "Section C.2 — Determining the level of human involvement in AI-augmented decision-making",
      "summary": "Deployers are to establish the intended commercial objectives of an AI system, check them against the guiding principles, and weigh them against the risks of using it, guided by corporate values reflecting the norms of the operating region and the differing local norms and digital maturity across ASEAN; they are to evaluate AI solutions along two axes, the probability and the severity of harm, taking account of the nature and reversibility of harm, the ability to obtain recourse, and whether human involvement is operationally feasible and meaningful, with special consideration for vulnerable and marginalised populations; the result places the system in one of three categories of human involvement — human-in-the-loop, human-over-the-loop, human-out-of-the-loop — with high severity and probability of harm calling for human-in-the-loop, in which the human must understand the factors influencing the system enough to judge whether the output is accurate, fair and safe rather than approving it for efficiency's sake, guarding against automation bias; risk impact assessments are to be documented, with Annex A of the Guide giving an example template, and the identification of objectives, risks and involvement level is to be reviewed continually.",
      "v": [
        "Sep"
      ],
      "e": [
        "Exp"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The closest correspondence in this pack to the AIO 20002 record: the record's C: field already carries a reversibility axis (R / P / X) and a scope-of-impact axis, and this section decides the level of human involvement from severity, probability and reversibility of harm together with how many people are affected. What an item can test is the judgment side — whether a model, faced with a high-severity irreversible case, treats the decision as one for a human rather than one to execute, and whether it presses for scrutiny instead of inviting the rubber-stamping the section warns against. What no item reaches is the assessment machinery: the two-axis evaluation, the documented risk impact assessment, the periodic review, the staffing of the human the system is escalated to. Annex A (AI Risk Impact Assessment Template) is referenced here by name only; no part of it is reproduced anywhere in this pack or in the management-system guide.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section C.2 (Determining the level of human involvement in AI-augmented decision-making), p. 25",
        "quote": "AI systems that have high severity and probability of harm should adopt a human-in-the-loop approach where humans can assume full control of the system and decide when it is safe to execute decisions.",
        "rationale": "The quoted sentence is a rule about who decides, triggered by harm, and both codes come straight out of it. The trigger is the severity and probability of harm to users and to individuals involved in the lifecycle, which is `Sep`; the section's own factors for computing severity — impact on lives and livelihoods, privacy, and 'the durability and reversibility of potential harm' — confirm that bodily and personal harm is what is meant. The consequence is that the human assumes full control and decides, which is `Sdt`, reaching the conclusion through one's own understanding rather than accepting the answer one was handed; the section makes that reading explicit where it requires the human to 'have enough understanding of the factors influencing the AI system's decision' and warns against approving outputs from habit. On evidence, what discharges the duty is a documented risk impact assessment run against a template the Guide supplies as Annex A (`Gui`) and the considered judgment of the human in the loop on the case in front of them (`Exp`). `Dat` was considered for the probability-and-severity computation and not coded: the section says expressly that 'The definition of harm and the computation of probability and severity will depend on the context, varying from sector to sector', which is a contextual determination rather than a measurement whose numbers settle the question. On sources, developers and deployers are the designated parties (`Ind`). `Gov` is not coded although the section says ASEAN governments should keep their understanding of harm up to date: that sentence addresses governments as a separate audience and does not make a governmental authority decisive on the deployer's determination, which is what the source-axis policy requires. ADJUDICATION 2026-08-14: `Sep`, `Exp` and obligationType (`mixed`) agreed on both sides — the trigger 'high severity and probability of harm' makes personal safety the interest at stake, and the in-loop human deciding 'when it is safe to execute decisions' is that human's considered judgment on the case. The two passes then split on the second value code, from the same clause: v0.1 read 'humans can assume full control ... and decide' as `Sdt`, reaching one's own conclusion rather than accepting a handed answer, and the blind pass read it as `Sda`, freedom to determine one's own course, while expressly rejecting `Pod` because the control is over a system rather than over people. Neither survives on one pass alone; this is the second appearance of Wave 2 gap 13 in this pack, after Guiding Principle 4, and it is the sharper of the two because here the same eight words produced two different codes. `Gui` is dropped: the documented risk impact assessment and Annex A's template are in the section, not in the excerpt. `Dat` is dropped: the blind pass read severity and probability as declared metrics, v0.1 had considered and rejected exactly that on the strength of the section's own statement that the computation 'will depend on the context, varying from sector to sector', and a code one pass reasoned its way out of does not enter on the other's reading alone. **The blind pass's ordered pair `Dat`<`Exp` is therefore not carried, and would not have been carried in any case**: the excerpt ranks a human above an execution, not one evidence class above another, and an ordering is recorded only where the text ranks the things the layer holds. S is emptied: the in-loop human is an evidence-producer, not a designated source class, and the excerpt names no organization; v0.1's `Ind` came from the section's addressee.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "`Sep`, `Exp` and obligationType `mixed` agreed. V [Sep, Sdt] vs the blind pass's [Sep, Sda] → [Sep]; E [Gui, Exp] vs [Dat, Exp] → [Exp]; S [Ind] → []. The blind pass's ordered evidence pair `Dat`<`Exp` is not carried: `Dat` falls, and the excerpt ranks a human above an execution rather than one evidence class above another."
    },
    {
      "article": "Section C.3 — Operations management",
      "summary": "Across the five stages of the AI system lifecycle the Guide sets out — project governance and problem statement definition, data collection and processing, modelling, outcome analysis, and deployment and monitoring — deployers are to build governance into the system by design, to conduct risk-based assessments before any data collection, processing or modelling begins and to document the mitigation measures and safeguards adopted, to attend to the potential environmental impact including by estimating and reducing energy consumption, to use sufficiently representative training, testing and validation data and to guard against enumerated bias types, to maintain data provenance and lineage records, storage, security and quality measures, to assess on a risk basis whether models are explainable, repeatable, reproducible and robust, to validate outcomes against the purpose set at the outset with fairness testing at that stage, and to monitor, revalidate and retune deployed systems as performance drifts.",
      "v": [
        "Sep"
      ],
      "e": [],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The longest section of the Guide and the one furthest from anything an AIO measurement observes: it is a lifecycle process specification, and every duty in it is discharged by an artefact, a gate or a cadence. It is mapped because a pack that formalized this instrument without it would misrepresent the instrument. The environmental limb is worth flagging separately, because it is easy to miss in a section about pipelines: the Guide requires attention to the environmental impact of the system, offers energy consumption as the way to measure it, and asks that consumption be kept within an appropriate range and reduced where needed, and it repeats the point at the data stage by asking that the amount of data held and the duration it is held for be minimised to reduce data centre energy requirements. The Guide names the ISO 27000 series as a reference for data governance practice; that reference is recorded here and is deliberately not coded as a source class — see the rationale.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section C.3 (Operations management), Project governance and problem statement definition stage, p. 29",
        "quote": "Deployers should conduct risk-based assessments of the AI systems before starting any data collection and processing or modelling.",
        "rationale": "The quoted sentence states what the assessment is for in the sentence that follows it — to 'identify potential safety risks of foreseeable uses of the AI system, including the potential for accidental or malicious misuse' — which is `Sep`. `Unn` is stated rather than inferred: the same stage requires that 'Attention should also be paid to the potential environmental impact of the use of the AI system', measured by estimated energy consumption and reduced where needed. `Ses` is an INFERENCE covering the traceability apparatus the section builds across the remaining stages — data provenance records, end-to-end lineage, documentation of sources, transformations and processing steps, and an inventory of approved languages, packages and hardware — which makes the working of the system inspectable as such; the section does not name a value for that apparatus, and this is put to the RFC round. On evidence, the section is built on documented procedure throughout: risk assessments, documented mitigation measures, data governance practices, labelling guidelines, storage and retention standards (`Gui`), and on measurement at the modelling, outcome-analysis and monitoring stages, where models are evaluated against predefined benchmarks and metrics such as data drift, precision, recall, bias and fairness, and where monitoring thresholds are defined (`Dat`). On sources, developers and deployers are the designated parties (`Ind`). `Pro` was considered because the section says developers and deployers 'may reference the relevant ISO standards for data robustness, quality, and other data governance practices' and names the ISO 27000 series; it is not coded, because a permissive reference does not make a standards body's position decisive on the substance of the duty. `Gov` is not coded either: the section cites the US NIST AI RMF Playbook and Singapore's PDPC self-assessment guide as useful references in the same permissive register. ADJUDICATION 2026-08-14: S ([Ind]) and obligationType (`organizational`) agreed exactly — 'Deployers should conduct' names the actor, and the duty is a sequencing gate on the project lifecycle. `Sep` is retained because both passes reached it, and the grounds are recorded honestly because they differ: v0.1 read it from the sentence immediately following the excerpt, which names 'potential safety risks of foreseeable uses' and which is cited rather than quoted, and the blind pass reached it as a flagged inference from 'risk-based assessments' alone, recording that the sentence names no protected party in terms. It is the one inference-grade code surviving in this pack, and it survives on dual reach rather than on textual determinacy; **the excerpt is not widened to cure it**, because the licence position forbids adding quotation, so it is listed instead as a next-revision retrieval item. `Unn` is dropped: the environmental limb is real and is kept in the summary and the note, but it lives in the section's other sentences, not in the excerpt. `Ses` was flagged as an inference in v0.1 for the provenance and lineage apparatus of the later stages, and the blind pass did not reach it. **E is emptied, and the emptiness is itself the finding**: the two passes shared no evidence code for the same risk assessment — v0.1 read the documented procedure of the wider section (`Gui`) and its benchmarks and drift metrics (`Dat`), the blind pass read the assessor's considered judgment (`Exp`), flagged as an inference and distinguished from Section C.2 on the ground that 'risk-based' alone declares no metric. Both of v0.1's codes are drawn from stages outside the quoted sentence, and the blind pass's is inference-flagged and unreached by v0.1, so nothing survives. That is Wave 1 gap 7: the evidence layer has no code for a structured self-assessment run as a gate on one's own programme.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S [Ind] and obligationType `organizational` agreed exactly. V [Sep, Unn, Ses] → [Sep]; E [Gui, Dat] vs the blind pass's [Exp] → []. `Sep` is the pack's one surviving inference-grade code, retained because both passes reached it; its grounding sentence sits outside the excerpt and, under the licence position, the excerpt is not widened to cure that — it is recorded as a next-revision retrieval item. The empty evidence layer is the finding: two independent readings of the same risk-assessment duty shared no code."
    },
    {
      "article": "Section C.4 — Stakeholder interaction and communication",
      "summary": "Deployers are to build trust with stakeholders across the lifecycle: to give general disclosure of when AI is used in their products or services, including the type of system, its intended purpose and how it affects decision-making in relation to users, with chatbot users told that answers come from an AI-powered algorithm rather than a human agent; to communicate with employees about how deployment changes their work and to provide training, awareness-raising and job redesign; to develop a standardised policy setting what information goes to which stakeholder and how, with more specific and detailed information where the system's decisions affect users; to put in place feedback channels, including channels through which users can correct inaccurate personal data, and decision review channels giving individuals an avenue to request review of decisions that have materially affected them, with human review reasonable where the effect of a fully autonomous decision may be significant; to consider whether users should be able to opt out and, where they cannot, to engage them and obtain their feedback; to inform users where their inputs will train the system; and, where systems are procured, to obtain the information needed for stakeholder management from developers by contract.",
      "v": [
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The most directly testable section of the Guide alongside human-centricity: whether a model discloses that it is a system when a user is entitled to know, and whether it routes a user who contests a consequential outcome toward human review rather than defending the outcome, are both judgment questions an item can put. The organizational half is the machinery on the other side of those judgments — the standardised communication policy, the staffed feedback and decision review channels, the opt-out mechanics, the employee change-management programme, and the contractual clauses that get the necessary information out of a third-party developer. The Guide's own risk-based caveat is kept rather than smoothed away: telling users that their inputs may train the system has to be coupled with a risk-based approach, because bad actors who know it may try to skew the system's learning. ADJUDICATION 2026-08-14: the evidence layer of this entry (`Gui`) and the empty evidence layer of Guiding Principle 1 are deliberately different, and the difference is the whole of the textual test: this excerpt says what the disclosure must contain, that one says only that awareness is to be fostered. Read the codes with the modality in view — the provision asks deployers to *consider* providing the disclosure, and an item written from this entry as though the disclosure were mandatory would overstate the Guide.",
      "provenance": {
        "sourceUrl": "https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf",
        "article": "Section C.4 (Stakeholder interaction and communication), p. 41",
        "quote": "deployers should consider providing general disclosure of when AI is used in their product and/or service offerings […] how the AI system affects the decision-making process in relation to users",
        "rationale": "Disclosure exists here so that a user knows what they are dealing with and can judge the interaction for themselves (`Sdt`); the section's chatbot illustration, where users are to be told that answers come from an algorithm and not from a human customer service agent, is that value at its plainest. The section opens by making trust with stakeholders the object of the whole exercise and closes with channels for aggrieved individuals, which is `Bed` — the duty owed to a counterparty. `Sda` is coded from the opt-out limb: 'deployers can also consider if users should be given the choice to opt out of the AI-enabled service', which is freedom to choose one's own course, and the factors the section lists for deciding it (degree of risk or harm, reversibility of the decision, availability of alternatives, technical feasibility) confirm that a real choice is contemplated. On evidence, the section names three distinct things that discharge its duties. Where a system's decisions affect users, deployers are to provide 'more specific and detailed information relating to how the AI system arrives at a decision and how users will be affected' — a reasoned account of how the outcome came about (`Log`). Feedback mechanisms exist so that users and other stakeholders report on the performance and output of the system, which admits their firsthand accounts as evidence for iteration (`Tri`). Decision review channels have a human review a materially affecting decision, which is that human's considered judgment on the case (`Exp`). On sources, deployers and developers are the designated parties (`Ind`), and `Usr` is coded from the feedback channels through which, 'Where users find inaccuracies in their personal data which has been used for AI-augmented decisions affecting them', users supply and correct the information the decision runs on. ADJUDICATION 2026-08-14: `Sdt`, the `Ind` limb of S and obligationType (`mixed`) agreed on both sides. V narrows to [Sdt]: `Bed` was read from the section's opening on trust and its closing channels, and `Sda` from the opt-out limb, both outside the excerpt. S narrows to [Ind]: `Usr` was read from the correction channel, also outside the excerpt, and under the recipient-is-not-a-source rule the users this disclosure runs to are its recipients here, whatever they supply elsewhere in the section. **E resolves to the blind pass's [Gui] against v0.1's [Log, Tri, Exp], and this is the one place in the pack where a divergence is settled in the second pass's favour on the strength of the words rather than by intersection.** v0.1's three codes each rest on a sentence outside the excerpt — the more-specific-and-detailed-information duty, the feedback mechanisms and the decision review channels — while the excerpt itself enumerates what the disclosure is to contain, which is a written content standard. That enumeration is also the textual distinction against Guiding Principle 1, whose excerpt asks only that awareness be fostered and whose evidence layer is consequently empty. MODALITY, recorded and not hardened: the excerpt is doubly hedged — 'should consider providing' — and is weaker than the plain 'should' obligations elsewhere in this pack. The codes formalize the disclosure the provision contemplates, not a firm duty to make it, and the v/e/s layers cannot express the difference. That is Wave 2 gap 23.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "`Sdt`, S's `Ind` and obligationType `mixed` agreed. V [Sdt, Bed, Sda] → [Sdt]; S [Ind, Usr] → [Ind]; E [Log, Tri, Exp] → [Gui], the blind pass's reading, adopted because the excerpt enumerates disclosure content while v0.1's three codes each rest on sentences outside it. The doubly-hedged modality of 'should consider providing' is recorded as a gap and is not hardened into a firm duty."
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "The ASEAN Guide is a regional best-practice guide, not law. Its own Objectives section says that adoption of the framework it lays out is voluntary, and its Conclusion recommends that member states, developers and deployers operating in their jurisdictions apply its provisions on a voluntary basis and states that nothing in it may be interpreted as replacing or changing any party's legal obligations or rights under any member state's laws. The Guide also says it does not replace or supersede any existing or upcoming laws, and that developers and deployers must still adhere to applicable national, sectoral and constitutional requirements in the countries where their systems are deployed. The concrete duties an organization faces therefore come from the national law of the ASEAN member state concerned, not from this text, and nothing in this pack measures any member state's uptake of the Guide or any organization's alignment with it. What AIO items measure against this pack is the judgment direction each mapped provision implies for an AI system — whether a model's reasoning tracks, for example, Guiding Principle 3 on the safety of the public being of utmost priority in the decision-making process, Guiding Principle 4 on not swaying or deceiving users into decisions that are not beneficial to them, Section C.2 on a high-severity, high-probability case being one where the human assumes full control and decides, or Section C.4 on disclosing that AI is in use and routing a materially affected user toward human review. They do not assess whether an organization operates the management-system correlates of those provisions — an AI Ethics Advisory Board or equivalent governing body, documented risk impact assessments, data protection and governance frameworks, lifecycle operations management, staffed feedback and decision review channels, incident response and internal reporting structures — and this Guide is unusually heavy in exactly those correlates: not one of the ten mapped provisions is discharged by judgment alone. A pass on this pack is evidence about model judgment only, and is never evidence that an organization has implemented anything the Guide recommends. After the blind second formalization and adjudication of 2026-08-14 the distribution is unchanged — behavioral 0, mixed 6 (Guiding Principles 1, 2, 3 and 4 and Sections C.2 and C.4), organizational 4 (Guiding Principles 5 and 6 and Sections C.1 and C.3) — and the finding now rests on two independent formalizations rather than one: the second pass raised exactly one behavioral candidate, Guiding Principle 4, and it was lowered to mixed at adjudication because the same principle requires lifecycle incorporation, user testing and labour impact assessment in its own words. What the adjudication did change is how much this pack claims: thirty-one of the fifty-six codes v0.1 declared were removed and one was added, Section C.1 now carries no value code at all and item authoring against it is deferred, and four entries carry no evidence code and four no source code, because the excerpts that can lawfully be quoted from this Guide designate nothing in those layers. The sentence above still governs: a pass on this pack is evidence about model judgment only.",
  "notes": [
    "draft-verified. Every entry carries a short verbatim excerpt of the official English text and a rationale argued from it, and on 2026-08-14 the second independent formalization required by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer read only the pack id, the name of the source norm and each entry's provenance.article and quote, supplied as `.pack-verify/wave3-blind-excerpts-asean-ai-guide.json`; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped by an extraction script before any file was opened, and neither the pack-authoring guideline nor the management guide nor the roster was opened. Human review remains outstanding, and the V/E/S assignment is settled only by the public RFC round at https://aioq.org/en/rfc. Two limits on the promotion are carried forward and are not cured by the second pass: extraction from the retrieved manifestation was verified twice, but the manifestation itself could not be cross-checked, this Guide having only one official manifestation; and the licence position forbids widening any excerpt, so two adjudications were decided on excerpts that both passes found narrower than the provision (see the licence-discipline note below).",
    "Instrument status and currency, verified on 2026-08-14 against ASEAN's own documents. The Guide was endorsed by the 4th ASEAN Digital Ministers' Meeting (ADGMIN), held in Singapore on 1-2 February 2024: paragraph 5 of the meeting's official Joint Media Statement records that 'the Meeting endorsed the ASEAN Guide on Artificial Intelligence (AI) Governance and Ethics', and welcomes the recommendation to set up a working group under ADGSOM on AI (https://asean.org/wp-content/uploads/2024/02/ENDORSED-4th-ASEAN-Digital-Ministers-Meeting-JMS-CN_JP_ROK_IN_US_EU_ITU_APT-CLN-v1-CLN.pdf). Currency was checked forward rather than assumed: paragraph 5 of the Joint Media Statement of the 6th ADGMIN, held in Ha Noi on 15-16 January 2026, records the Working Group on AI Governance (WG-AI) as continuing to build on 'the ASEAN Guide on AI Governance and Ethics (2024) and the Expanded ASEAN Guide on AI Governance and Ethics - Generative AI (2025)' (https://asean.org/wp-content/uploads/2026/01/ADOPTED-JMS-ADGMIN-6_16-January-2026-Final-Consolidated-v2-CLN.pdf). The 2024 Guide is therefore still in force as the operative regional instrument and has not been revised, replaced or withdrawn; the 2025 Expanded Guide supplements it rather than superseding it. The same 6th ADGMIN statement records the adoption of a Declaration on the Establishment of the ASEAN AI Safety Network at the 47th ASEAN Leaders' Summit, to be operationalised in alignment with WG-AI; that is a separate institutional development and is not formalized here. The Guide describes itself as a living document to be periodically reviewed by relevant ASEAN sectorial bodies, so this pack pins the 2024 text and a revision would require a new pack version.",
    "Primary source and retrieval path. The canonical citation and the text actually read are the same official ASEAN publication: the 87-page PDF at https://asean.org/wp-content/uploads/2024/02/ASEAN-Guide-on-AI-Governance-and-Ethics_beautified_201223_v2.pdf, recorded in every entry as `sourceUrl`, fetched on 2026-08-14 (4,233,765 bytes, HTTP 200). No `retrievalUrl` is recorded because no separate retrieval endpoint was needed. What was not usable, and is recorded because it shaped the method: asean.org HTML pages, including the ASEAN Main Portal book record for this Guide at https://asean.org/book/asean-guide-on-ai-governance-and-ethics/, returned HTTP 307 redirects to the fetch tooling, so the official PDF manifestations at the same domain were retrieved directly instead. The same was true of the two Joint Media Statements cited above, which were also read as ASEAN-published PDFs. No commentary, law-firm summary, mirror or secondary source was used for any quote, and no quotation in this pack was reconstructed from memory.",
    "Quote verification method. The retrieved PDF was reduced to a whitespace-normalized, NFC-normalized corpus by two independently written extraction paths — pypdf's per-page `extract_text` and pdfminer.six's `extract_text` — which produced corpora of 190,967 and 190,981 characters respectively (a 14-character difference arising from page-furniture ordering, not from the body text). Every quoted fragment in this pack (11 fragments across 10 entries, counting the parts on either side of the […] elision separately) was then checked as an exact substring of both corpora; all 11 matched in both. One candidate excerpt was discarded during that check rather than repaired: a sentence containing the word 'multi-disciplinary' is hyphenated across a line break in the source layout, so both extraction paths render it 'multi- disciplinary', and the excerpt for the internal-governance entry was reselected to fall entirely within one line rather than silently normalising the source's typography. Limit to record honestly: this pack, like the UNESCO pack and unlike the Council of Europe pack, had only one official manifestation of the text available, so extraction was verified twice but the source manifestation was not. That is one of the reasons no entry is claimed above `draft-unverified`. No quote was changed, extended or added at v0.2: every one of the 11 fragments in this file is byte-identical to the fragment in `asean-ai-guide-v0.1.json`, checked programmatically at promotion, and the adjudication touched only the v/e/s arrays, the obligationType tags, the notes and the rationales.",
    "Licence position and reuse constraints — a licence-constrained (C) source under docs/팩_추가_가이드라인.md §5, and the most restrictive one AIO has formalized so far. `unesco-ai-ethics` was built under a Creative Commons licence with conditions (CC BY-NC-SA 3.0 IGO) and `sg-genai-governance` under an all-rights-reserved notice softened by publisher terms of use that permit personal, internal, non-commercial informational use; this source permits neither. The constraint here is not a Creative Commons licence with conditions; it is a reservation of rights. Page 87 of the Guide, read on 2026-08-14 in the same PDF the quotes come from, carries the notice: copyright 2024, Association of Southeast Asian Nations (ASEAN), and states that the contents are protected by copyright, trademark or other forms of proprietary rights and may not be reproduced, republished or transmitted in any form or by any means, in whole or in part, without written permission. AIO holds no such written permission. Consequences applied throughout, and applied more tightly than for UNESCO: (a) quotation is held to the minimum needed to evidence each mapping and is offered as short attributed quotation with full source citation under fair-dealing and quotation exceptions, never as licensed reuse; (b) no control set, checklist, control matrix or item bank is derived from the Guide's wording anywhere in this pack or in its management-system guide — the V/E/S mappings are AIO's own analysis expressed in AIO's own vocabulary, and the summaries, notes and guide text are paraphrase; (c) Annex A (AI Risk Impact Assessment Template) is referenced by name only and no part of it is reproduced, paraphrased into a working template, or restated as a set of questions, in this pack or in the guide; (d) Annex B's six organisation use cases are not reproduced. Attribution as ASEAN identifies itself: ASEAN Guide on AI Governance and Ethics, Association of Southeast Asian Nations, copyright 2024, endorsed at the 4th ADGMIN, Singapore, 1-2 February 2024.",
    "Licence self-check, reported in numbers. Across the whole pack: 10 entries, 11 verbatim fragments, 1,669 characters of verbatim text in total (1,674 counting the […] elision marker as written in the `quote` field), longest single quote field 200 characters, mean 167. That is 1.23% of the Guide's operative text (Sections A to F, 135,353 normalized characters) and 0.87% of the full 87-page publication including annexes (190,967 normalized characters). No excerpt exceeds 200 characters — half the 400-character ceiling FORMALIZATION_METHODOLOGY.md §1.3 allows — and no annex, use case, diagram, table or figure is quoted at all. A permissions inquiry to the ASEAN Secretariat is drafted in docs/license-inquiries/asean.md and, as at 2026-08-14, has not been sent. Until a reply is received, this pack and its guide stay inside the footprint described above, and any expansion of quotation waits on that reply. If ASEAN declines, the mappings, summaries, notes and guide survive without change, because none of them depends on the Guide's wording; the `quote` fields would be replaced by citation-only provenance and every entry would be held at `draft-unverified`. Those figures are unchanged at v0.2. The dual formalization added no quotation whatever: the second pass was run against the same 11 fragments, and no adjudication question was settled by widening an excerpt.",
    "Scope decision on the Expanded Guide (2025), recorded because the honest answer was to leave it out. The Expanded ASEAN Guide on AI Governance and Ethics - Generative AI was launched at the 5th ADGMIN on 17 January 2025 and supplements the 2024 Guide with generative-AI policy considerations; it carries no reuse or copyright statement of its own, so it is the less licence-constrained of the two documents, and it was read in full for this decision (https://asean.org/wp-content/uploads/2025/01/Expanded-ASEAN-Guide-on-AI-Governance-and-Ethics-Generative-AI.pdf, 52 pages, fetched 2026-08-14). Nothing from it is mapped here. Its operative units are nine policy areas — accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research and development, and AI for public good — each expressed as 'Areas for ASEAN to explore' and addressed to ASEAN as a region and to member state policymakers: facilitating data sharing, convening knowledge-sharing fora, establishing guidelines, coalescing around common disclosure elements, aligning with ISO, NIST and OECD work. Those are recommendations to build institutions, which §2.2 of the pack guideline excludes, and they carry no compliance proposition addressed to a developer or deployer with a judgment direction an item could test. Including one or two entries from it would have padded the pack with provisions whose `obligationType` is neither behavioral nor organizational but inter-governmental, and would have implied measurement coverage that does not exist. The Expanded Guide is therefore treated as background for the management-system guide, where its risk taxonomy is useful to an operator, and it is carried in the roster as a candidate for a separate pack if ASEAN later issues organisation-facing guidance under it. This decision is put to the RFC round.",
    "Selection, and what was left out. Ten provisions are mapped: six of the seven guiding principles of Section B (1 Transparency and Explainability, 2 Fairness and Equity, 3 Security and Safety, 4 Human-centricity, 5 Privacy and Data Governance, 6 Accountability and Integrity) and all four components of the Section C governance framework (C.1 internal governance structures and measures, C.2 determining the level of human involvement, C.3 operations management, C.4 stakeholder interaction and communication). Excluded and recorded here as RFC re-examination candidates: Guiding Principle 7 (Robustness and Reliability) — its demands are that systems cope with errors and erroneous input, perform consistently across inputs and environments, and be rigorously tested before deployment with documented data sources and lineage; that is a property of engineering rather than of a judgment, and the Guide restates it at operational length inside the Modelling stage of Section C.3, which this pack does map, so a separate entry would have added a quotation without adding a distinct measurable direction. Also excluded: Section A (objectives, assumptions, target audience, definitions), which is framing rather than obligation, although its voluntariness and no-supersession statements are load-bearing for `measurementScope` and are relied on there; Section D (national-level recommendations: nurturing AI talent, supporting the innovation ecosystem, investing in research and development, raising citizen awareness, promoting adoption of implementation tools) and Section E (regional-level recommendations: an ASEAN working group on AI governance, adaptation of the Guide to generative AI, a compendium of use cases), both addressed to governments and to ASEAN as a region, with no organisation-facing duty and no judgment correlate; Section F (Conclusion), quoted from only in `measurementScope`; Annex A and Annex B, for the licence reason recorded above.",
    "Measurement scope in numbers (per-entry `obligationType`, pack-level `measurementScope`), after adjudication, and the finding this pack contributes. The distribution across the ten mapped provisions is behavioral 0, mixed 6, organizational 4 — exactly what v0.1 recorded, and the two independent passes agreed on the tag for nine of the ten provisions. `Mixed`: Guiding Principles 1, 2, 3 and 4 and Sections C.2 and C.4. `Organizational` outright: Guiding Principles 5 and 6 and Sections C.1 and C.3. **Not one provision is `behavioral`, and that now rests on two formalizations rather than one.** The single divergence was at Guiding Principle 4, which the blind pass read as `behavioral` from the excerpt alone and which is held at `mixed` under the conservative rule, because the principle imposes lifecycle, user-testing and labour-assessment duties in its own words; it is the third `behavioral` candidate lowered at adjudication in the pack series, after the OECD and California packs of Wave 2, and UNESCO paragraph 36 remains the only surviving `behavioral` entry anywhere. Compare the distributions recorded in earlier packs — EU AI Act 1/7/0, NIST 0/3/7, UNESCO 1/5/4 — and read `mixed` precisely: it does not mean 'partly covered'; it means the provision has two limbs and a certificate speaks to one of them.",
    "Inferred codes, and what the second formalization did to them. v0.1 flagged four assignments as following from a provision's structure or from the shape of the AIO 00011 vocabulary rather than from the provision's words. **One survived and is no longer an inference**: `Ses` on Guiding Principle 3, v0.1's stopgap for the security limb's concern with the resilience of the deployed system, was reached independently by the blind pass from words inside the excerpt — 'Safety of the public' read as the stability and safety of society at large. The code now stands on that reading; the vocabulary gap v0.1's reading exposed is unchanged and travels in the gap list below rather than inside the code. Three did not survive, because an inference-flagged code stands only where both passes reach it: `Sda` on Guiding Principle 5 (read from a consent sentence outside the excerpt), `Cas` on Guiding Principle 6 (read from the incident limb, also outside it), and `Ses` on Section C.3 (read from the provenance and lineage apparatus of the later lifecycle stages). One inference-grade code enters and survives: `Sep` on Section C.3, which the blind pass flagged as an inference from 'risk-based assessments' and which v0.1 had grounded on the sentence immediately following the excerpt; both passes reached it, so it stands, and it is the pack's one remaining flagged code. Inference-grade codes the blind pass introduced and that are not carried, v0.1 not having reached them: `Cor` at Section C.1 (self-flagged, with an empty value layer recorded by the blind pass itself as equally defensible — the empty layer is what the adjudication took), `Exp` at Section C.3, and the ordered evidence pair `Dat`<`Exp` at Section C.2. Codes considered and deliberately not assigned were confirmed on both sides: `Pro` at Section C.1 (an internal Ethics Committee is not a field-wide professional body, and the Singapore Computer Society certificate names a training provider) and at Section C.3 (the ISO 27000 series is named permissively, 'may reference'); `Dat` at Guiding Principle 3 and Guiding Principle 6; `Gui` at Guiding Principle 2; and `Gov` at Guiding Principles 1, 3 and 4 and at Sections C.2 and C.3.",
    "Source-axis policy, restated after adjudication, and the largest single change from v0.1. **`Gov` is declared only where the excerpt names a government body or a government norm as decisive on the substance of the duty**; being named as a recipient of a disclosure, a report or a filing does not earn it, and neither does bare addressee status. **`Ind` is declared where the excerpt makes the industry duty-bearer the author or performer of the provision's product or determination.** The rule is applied as a filter and never as a generator: it may remove a code both passes declared and may decide which of two divergent readings prevails, but it never adds a code neither pass reached. In v0.1 `Ind` sat on all ten entries and was described there as textually forced by the Guide's addressee; the dual formalization showed it was forced by the addressee and not by the excerpts. **After adjudication `Ind` sits on five entries — Guiding Principles 1 and 6 and Sections C.1, C.3 and C.4 — and on exactly those whose excerpt names the deployer or the organization's own organ as the actor.** It is removed from Guiding Principles 2, 3, 4 and 5 and from Section C.2, whose excerpts are passive or impersonal ('the design, development, and deployment of AI systems should not result in', 'risks should be assessed', 'AI systems should not be used', 'The way data is collected'). `Gov` is unchanged at two entries, Guiding Principles 5 and 6, both agreed by both passes on excerpts that name 'applicable data protection laws, data governance legislation' and 'applicable laws' as decisive. `Usr` is removed from Section C.4 under the recipient-is-not-a-source rule settled in Wave 2: the users the disclosure runs to are its recipients, and the correction channel that made them a source in v0.1 is in a sentence outside the excerpt. Four entries now carry an empty source layer. The uniformity that v0.1 carried to the RFC round as a single question has largely dissolved, and what remains of it is a real property of the instrument rather than an artefact of its addressee.",
    "Non-endorsement. AIO wrote this formalization. ASEAN, its Member States, the ASEAN Secretariat, the ASEAN Digital Ministers' Meeting, the ASEAN Digital Senior Officials' Meeting and the Working Group on AI Governance took no part in it, have not reviewed it, and have not endorsed it. It is not an official interpretation of the Guide. AIO certifies conformance to AIO's own formalization of this Guide; that is not a legal assessment, not an assessment of any member state's uptake of the Guide, and confers no status of any kind under the Guide or under any national law of any ASEAN member state. The Guide's own instruments and initiatives — Annex A's AI Risk Impact Assessment Template, the compendium of use cases it recommends, the Working Group on AI Governance, the Expanded Guide on Generative AI and the ASEAN AI Safety Network — are ASEAN's; nothing here is produced under any of them and nothing here substitutes for any of them.",
    "No item bank. `itemBankRef.publicSet` and `itemBankRef.privateSet` are both null: no scenario items have been written for this pack, so it currently backs no certificate at any tier and appears in the catalogue as listed, measurement pending. Item authoring follows verification, not the other way round. Note additionally that any item bank for this pack must be authored in AIO's own words: under the reservation of rights recorded above, items phrased by adapting the Guide's wording would be reproductions of the source text in part, which the copyright notice forbids without written permission. One further consequence of the adjudication is recorded here rather than left to be discovered by whoever writes the bank: **Section C.1 carries no value code after dual formalization, and item authoring against that entry is deferred** on the UNESCO paragraph 71 precedent. An item needs a protected interest to press against; that provision names none in the words that can lawfully be quoted from it, and supplying one would be authoring the norm rather than measuring it.",
    "Methodology for the provision → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. V/E/S values are the canonical three-letter AIO 00011 codes served at /api/framework/vocabulary — the same codes an AIO 20002 record carries. Management-system obligations arising from this Guide, including the provisions this pack does not map and the risk taxonomy of the 2025 Expanded Guide, are covered in docs/management-guides/asean-ai-guide.ko.md and .en.md.",
    "Adjudication method (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under the fixed policy carried forward from Waves 1 and 2: a code stands only where the quoted text designates it; an ordered hierarchy is recorded only where the text ranks the things the layer holds; an empty layer beats an inferred code unless both passes reached that code; recipient is not source; the source-axis rule is a filter and never a generator; where both readings are defensible the more conservative is taken; a divergent `obligationType` always resolves to the more conservative tag; no third reading is invented, and every adjudicated set is a subset of at least one pass's set, which was checked mechanically for all thirty layers. Agreement statistics for this pack, across ten entries: V 3/10, E 2/10, S 3/10, `obligationType` 9/10, all four axes together 0/10. The pack declared 56 codes at v0.1 and declares 26 at v0.2: thirty-one were removed and one was added (`Gui` at Section C.4, the only divergence resolved in the second pass's favour on the strength of the quoted words). The evidence figure is the lowest of any pack in the series so far, and it has a cause worth stating: this Guide discharges nearly every duty it states through machinery described in the sentences around the one that states the duty, and the licence position confines each excerpt to a single sentence.",
    "Contamination notice, recorded as the blind pass disclosed it. The second formalizer reported a protocol deviation before its result was opened: the task told it that FORMALIZATION_METHODOLOGY.md §4 carries the AIO 00011 code tables, and §4 does not — it names four codes in passing and defers the list to /api/framework/vocabulary. To obtain the 39-code table the pass read two additional files, `src/app/lib/frameworkVocabulary.ts` and `src/app/components/standards/workshopData.ts` (lines 21-190). Both are neutral code catalogues — code, name, definition — and contain no pack mappings, no first-pass output and nothing whatever about the ASEAN Guide. No standards-pack JSON, no other `.pack-verify` file, no docs/ file, no management guide and no git history was read. **Assessment: protocol deviation disclosed, neutral codebook only, no contamination.** No axis of this pack is reported with a contamination caveat. The deviation is a defect in the task text rather than in the pass, and it is fixed for the remaining Wave 3 packs by pointing the blind formalizer at the vocabulary endpoint directly.",
    "Licence discipline under the dual formalization, and the retrieval items it produced. The reservation of rights recorded above was held throughout the second pass and the adjudication: **no quote in this pack was widened, extended or added at any point, and no adjudication question was settled by enlarging an excerpt.** Two entries were affected and both are recorded rather than cured. At Section C.3 the excerpt states the duty ('conduct risk-based assessments') without naming the interest at risk; v0.1 grounded `Sep` on the sentence immediately after it, which is cited and not quoted, and the blind pass could only reach the same code as a flagged inference. At Guiding Principle 4 the excerpt is a single prohibition sentence, which is why the blind pass read the provision as `behavioral` and could not see the lifecycle and user-testing duties that hold it at `mixed`. Both are listed as next-revision retrieval items — to be re-retrieved with the neighbouring sentence, within the same minimal-quotation footprint and only if the footprint permits — rather than resolved by expanding the excerpt now. The permissions inquiry drafted at `docs/license-inquiries/asean.md` remains unsent as at 2026-08-14, and any expansion of quotation waits on a reply to it.",
    "Vocabulary and schema gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack opens the Wave 3 list, which continues the Wave 2 list of twenty-three and the consolidated Wave 1 list of ten, with one new item, canonical Wave 3 number 32 (renumbered from a provisional 24 in the wave-end consolidation, 2026-08-14), and four confirmations. (32) THE SECURITY OF THE ARTEFACT AS A PROTECTED INTEREST — Guiding Principle 3's security limb is about the resilience of the deployed system itself against data poisoning, model inversion, dataset tampering and byzantine attacks, and the Schwartz-derived value layer has no code for the integrity of an artefact. v0.1 routed it to `Ses` as an inference; the blind pass reached `Ses` from 'the public' instead, so the code survived on other grounds and the gap it was standing in for is now visible on its own. This is distinct from Wave 1 gap 3 (information integrity), which is about the shared information environment rather than the system. Confirmed again: gap 10 UNDEFINED PROTECTED INTEREST — twice in this pack, at Section C.1, where the two passes shared no value code and the layer is left empty, and at Section C.3, where 'risk-based assessments' presupposes an interest it does not name and `Sep` survives only because both passes guessed the same way; gap 13 THE `Sdt`/`Sda` BOUNDARY — twice, at Guiding Principle 4, where 'sway or deceive' uses both registers in one sentence and the passes split on which, and at Section C.2, where the same eight words about a human assuming full control produced `Sdt` on one side and `Sda` on the other; gap 23 DEFEASIBLE VERSUS CATEGORICAL MODALITY — at Section C.4, whose 'should consider providing' is doubly hedged and formalizes identically to the plain 'should' obligations elsewhere in the pack, which the blind pass flagged unprompted; and gap 7 STRUCTURED SELF-ASSESSMENT — at Section C.3, where the evidence layer is empty because two independent readings of a risk assessment run as a gate on one's own programme reached `Gui`, `Dat` and `Exp` between them and shared none. The full Wave 2 list is reproduced in the adjudication report."
  ]
}
