{
  "$schema": "./schema.json",
  "id": "ca-sb53-tfaia",
  "name": {
    "en": "Transparency in Frontier Artificial Intelligence Act (California SB 53) — AIO formalization",
    "ko": "캘리포니아 프런티어 AI 투명성법(SB 53) — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Transparency in Frontier Artificial Intelligence Act (TFAIA) — Business and Professions Code Chapter 25.1 (§§ 22757.10–22757.16), Government Code § 11546.8, and Labor Code Chapter 5.1 (§§ 1107–1107.2), added by Senate Bill 53 (Wiener)",
    "publisher": "California State Legislature; chaptered text published by the Office of Legislative Counsel (California Legislative Information)",
    "version": "Chapter 138, Statutes of 2025 (SB 53, 2025–2026 Regular Session). Approved by the Governor and filed with the Secretary of State September 29, 2025; effective January 1, 2026. No amending statute as of 2026-08-14.",
    "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53"
  },
  "vesMapping": [
    {
      "article": "Bus. & Prof. Code § 22757.12(a), (a)(1), (a)(7)–(9); § 22757.12(b)",
      "summary": "A large frontier developer must write, implement, comply with, and clearly and conspicuously publish on its website a frontier AI framework describing how it incorporates national, international and industry-consensus standards, secures unreleased model weights, identifies and responds to critical safety incidents, and institutes internal governance to ensure these processes are carried out; it must review and as appropriate update the framework at least once per year and publish any material modification, with a justification, within 30 days.",
      "v": [
        "Cor",
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The duty is discharged by an organizational instrument — a published document, a review cycle, and governance practices. No item can observe whether a framework exists, is current, or is being followed. The measurable residue is the 'comply with' limb: § 22757.15 makes failure to comply with a developer's own published framework independently penalizable, so the judgment correlate is refusal to depart from a self-issued commitment under commercial pressure. An AIO 20002 record does not evidence framework adherence; at most it records the value ordering behind one decision taken under the framework.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(a), chapeau and paragraphs (1) and (9); § 22757.12(b)(1)",
        "quote": "[§ 22757.12(a)] A large frontier developer shall write, implement, comply with, and clearly and conspicuously publish on its internet website a frontier AI framework […] describes how the large frontier developer approaches all of the following: (1) Incorporating national standards, international standards, and industry-consensus best practices into its frontier AI framework. […] (9) Instituting internal governance practices to ensure implementation of these processes. [§ 22757.12(b)(1)] A large frontier developer shall review and, as appropriate, update its frontier AI framework at least once per year.",
        "rationale": "The provision protects the stability and order of society at large rather than any identified individual — SEC. 1(m) of the act frames the whole chapter as a mechanism so that 'public authorities are promptly informed of ongoing and emerging risks to public safety' — which is Ses. Publication on an internet website in a prescribed manner is a formal statutory requirement (Cor). The 'comply with' limb converts the developer's own document into a binding commitment enforceable against it, which is Bed: honoring an obligation already undertaken. What discharges the duty is the framework itself, and § 22757.11(g) defines a frontier AI framework as 'documented technical and organizational protocols' — an established written standard procedure, therefore Gui. No metric, case comparison or expert opinion is named as decisive. The trusted sources the text designates are the statute and the standards regimes it points to (Gov, covering national standards and the state's own requirement) and the developer's own document together with the 'industry-consensus best practices' it must incorporate (Ind). 'International standards' is not attributed to any named standards body, so Pro is not assigned; no scholarly source appears anywhere in the chapter, so Pee is not assigned. ADJUDICATION 2026-08-14: E ([Gui]), S ([Gov, Ind]) and obligationType (organizational) agreed exactly across the two independent passes and are auto-accepted — the only entry in this pack with three-axis agreement. S survives the Wave 2 source-axis re-check on both limbs: 'national standards, international standards' are government norms named as decisive on what the framework must contain, and 'industry-consensus best practices' are self-issued industry material. V loses Ses: the second pass read the duty as rule-following (Cor) plus a standing published commitment the developer must keep (Bed) and did not reach a societal-stability interest, which the quoted paragraphs do not name.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E, S and obligationType agreed exactly. V [Ses, Cor, Bed] → [Cor, Bed]. Gov is retained here — and only here in this pack — because the excerpt names national and international standards as substance the framework must incorporate, not a government body as the recipient of a filing."
    },
    {
      "article": "Bus. & Prof. Code § 22757.12(a)(2)–(3)",
      "summary": "The frontier AI framework must describe how the large frontier developer defines and assesses thresholds used to identify whether a frontier model has capabilities that could pose a catastrophic risk, and how it applies mitigations to address that potential based on the results of those assessments.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The threshold-setting and mitigation machinery is organizational; the judgment correlate an item can reach is narrower and specific — whether a capability signal that crosses a declared threshold is treated as crossing it, rather than reinterpreted downward. Note the statutory anchor: § 22757.11(c)(1) fixes catastrophic risk at 'more than 50 people' killed or seriously injured, or more than one billion dollars in property damage, from a single incident. Nothing in the pack measures whether the thresholds an organization actually adopted are adequate.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(a)(2) and (a)(3)",
        "quote": "Defining and assessing thresholds used by the large frontier developer to identify and assess whether a frontier model has capabilities that could pose a catastrophic risk, which may include multiple-tiered thresholds. […] Applying mitigations to address the potential for catastrophic risks based on the results of assessments undertaken pursuant to paragraph (2).",
        "rationale": "The interest protected routes through the definition at § 22757.11(c)(1), which is stated in terms of 'the death of, or serious injury to, more than 50 people' and property loss — that is bodily safety of identifiable persons (Sep) alongside the societal stability the chapter is built around (Ses). Paragraph (3) makes mitigation contingent on the assessment result rather than on discretion ('based on the results of assessments undertaken pursuant to paragraph (2)'), which is rule-following against a fixed trigger (Cor). What discharges the duty is measurement against declared thresholds — the text speaks of thresholds, tiers and assessment results, so the decisive evidence is the accumulated evaluation record (Dat) read inside the documented protocol that defines the thresholds (Gui). The thresholds are expressly the developer's own ('thresholds used by the large frontier developer'), giving Ind, under a duty the statute imposes (Gov). The text names no external evaluator here, so no expert or professional source class is assigned at this entry. ADJUDICATION 2026-08-14: obligationType (mixed) agreed exactly. V narrows to the intersection [Sep, Ses]; Cor rests on v0.1 alone, and the second pass recorded an INSUFFICIENT-QUOTE caveat even on Sep and Ses, since 'catastrophic risk' is a defined term whose definition (§ 22757.11) is outside the excerpt — the definition is quoted in this entry's note, which is why the two codes are kept. E narrows to [Dat]: threshold definition and assessment is measurement against declared metrics, which §4 assigns to Dat, while Gui was declared by one pass only. S narrows to [Ind]: the thresholds are expressly 'used by the large frontier developer', so the Ind limb of the source-axis rule is met, and Gov is dropped because no government body or norm appears anywhere in the excerpt.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType agreed exactly. V [Sep, Ses, Cor] → [Sep, Ses]; E [Dat, Gui] → [Dat]; S [Ind, Gov] → [Ind] (no government body or norm is named in the excerpt)."
    },
    {
      "article": "Bus. & Prof. Code § 22757.12(a)(4)–(5)",
      "summary": "The frontier AI framework must describe how the large frontier developer reviews assessments and the adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally, and how it uses third parties to assess the potential for catastrophic risks and the effectiveness of mitigations.",
      "v": [
        "Sep",
        "Ses",
        "Hum"
      ],
      "e": [
        "Exp"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "This is the closest the chapter comes to a deployment gate, and it is deliberately thin: the statute requires the framework to describe how the review is conducted, not that any particular outcome follow from it. The judgment correlate is the refusal to treat a release decision as settled before the assessment review is complete. 'Third parties' is left undefined — the act imposes no independence, accreditation or competence criterion on them, and § 22757.12(c)(2)(C) requires only disclosure of 'the extent to which' they were involved.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(a)(4) and (a)(5)",
        "quote": "Reviewing assessments and adequacy of mitigations as part of the decision to deploy a frontier model or use it extensively internally. […] Using third parties to assess the potential for catastrophic risks and the effectiveness of mitigations of catastrophic risks.",
        "rationale": "The decision the paragraph regulates is a release decision, and what it subordinates to review is the interest in shipping. The values that must prevail are the ones the review exists to protect — bodily safety under the § 22757.11(c)(1) definition (Sep) and societal stability (Ses) — together with Hum, recognition of the limits of one's own assessment: paragraph (5) requires the framework to describe reliance on parties other than the developer to judge whether the mitigations work, which is an admission that self-assessment is not sufficient. Hum here is an INFERENCE from the structure of paragraph (5) rather than from words the text uses, and is put to the RFC round. The decisive evidence is the considered judgment of an assessor on the model in front of them (Exp) resting on the assessment record (Dat). On sources, the entry deliberately stops at the developer itself (Ind) and the statute (Gov): 'third parties' names no institutional class, and assigning Pro (professional body) or Pee (peer-reviewed) would import an accreditation requirement the text does not contain. That omission is itself an RFC question. ADJUDICATION 2026-08-14: V ([Sep, Ses, Hum]) and obligationType (mixed) agreed exactly — both passes reached Hum independently for the submission of one's own mitigations to outside assessment, which is why it survives despite each pass flagging it as read from the structure of paragraph (5) rather than from its words. E narrows to [Exp], the intersection: what stands between the developer and release is a considered specialist judgment. S is emptied, and both passes reached that conclusion on the same ground: 'third parties' and 'third-party evaluators' designate no class in the ten-code source hierarchy — not Pro (no professional body is named and the act imposes no independence, accreditation or competence criterion), not Pee, not Gov. v0.1's Ind is not retained either: the excerpt is a bare list of framework contents and names no performer at all, so the Ind limb of the source-axis rule is not met. This is Wave 2 gap 14.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V and obligationType agreed exactly. E [Exp, Dat] → [Exp]; S [Ind, Gov] → [] — both passes independently found that 'third parties' designates no AIO 00011 source class, and the excerpt names no performer, so neither Ind nor Gov survives. The empty source layer is the pack's clearest vocabulary gap and is carried to the RFC round as Wave 2 gap 14 (contracted independent evaluator)."
    },
    {
      "article": "Bus. & Prof. Code § 22757.12(a)(10); § 22757.12(d)",
      "summary": "The frontier AI framework must describe how the large frontier developer assesses and manages catastrophic risk arising from internal use of its own frontier models, including risk from a model circumventing oversight mechanisms; and the developer must transmit a summary of any such internal-use catastrophic-risk assessment to the Office of Emergency Services every three months, or on another reasonable schedule it specifies to the Office in writing.",
      "v": [
        "Sep",
        "Ses",
        "Cor"
      ],
      "e": [
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Composite entry: the framework-content duty at (a)(10) and the recurring transmission duty at (d) are mapped together because (d) is the reporting limb of the same internal-use risk assessment. The submission channel is the one established under § 22757.13(b)(1), and the resulting reports are exempt from the California Public Records Act under § 22757.13(f) — so this obligation produces no public artefact. The judgment correlate an item can reach is whether internal deployment is treated as carrying the same risk weight as external release; the transmission itself is organizational.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(a)(10) and § 22757.12(d)",
        "quote": "[§ 22757.12(a)(10)] Assessing and managing catastrophic risk resulting from the internal use of its frontier models, including risks resulting from a frontier model circumventing oversight mechanisms. [§ 22757.12(d)] A large frontier developer shall transmit to the Office of Emergency Services a summary of any assessment of catastrophic risk resulting from internal use of its frontier models every three months or pursuant to another reasonable schedule […]",
        "rationale": "Paragraph (a)(10) names circumvention of oversight mechanisms as a risk source, which is the loss-of-control limb of § 22757.11(c)(1)(C) ('Evading the control of its frontier developer or user'); the protected interests are again bodily safety (Sep) and societal stability (Ses). Subdivision (d) attaches a recurring clock owed to a named state agency, and a clock is discharged by keeping to it rather than by judging it worthwhile — Cor. What is transmitted is a summary of an assessment, so the decisive evidence is the assessment record itself (Dat), produced under the documented protocol the framework sets out (Gui). The Office of Emergency Services is named as the recipient, which makes the governing authority a designated source in this entry (Gov); the assessments are generated by the developer's own internal use (Ind). No professional or scholarly source is named. ADJUDICATION 2026-08-14: V narrows to the intersection [Sep, Ses, Cor]; the second pass's additional Pod, which it flagged as a structural fit for 'circumventing oversight mechanisms' while recording that the catalogue's control value is written for control over people, is not carried — the gap it names is recorded instead (Wave 2 gap 15). E narrows to [Dat]. S is the decisive change: **both passes declared Gov and Gov is nonetheless removed**, under the source-axis ruling settled in this wave that a government body named only as the recipient of a report does not thereby become a source to be trusted. The second pass raised the point itself — 'the Office of Emergency Services is designated as recipient, not as a source to be trusted' — and asked for a pack-wide convention rather than an entry-by-entry decision; the convention is now settled and applied. Ind is retained under the Ind limb: § 22757.12(d) names the large frontier developer as the party that writes and transmits the summary. obligationType is lowered to organizational — assessment plus periodic transmission is a management system in both limbs.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Ses, Cor] retained against the second pass's addition of Pod; E [Dat, Gui] → [Dat]; obligationType mixed → organizational. S [Gov, Ind] → [Ind]: Gov is removed although both passes declared it, under the new recipient-is-not-a-source rule — the Office of Emergency Services appears in this excerpt solely as the recipient of a transmitted summary."
    },
    {
      "article": "Bus. & Prof. Code § 22757.12(c)(1)–(2)",
      "summary": "Before or concurrently with deploying a new frontier model or a substantially modified version of one, a frontier developer must clearly and conspicuously publish a transparency report covering the model's release date, supported languages and output modalities, intended uses, applicable use restrictions and a contact mechanism; a large frontier developer must additionally include summaries of the catastrophic-risk assessments conducted under its frontier AI framework, the results of those assessments, the extent of third-party evaluator involvement, and other steps taken to fulfil the framework.",
      "v": [
        "Bed"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This is the provision that generates the public artefact most readers associate with SB 53. Two limits matter. First, § 22757.12(c)(3) deems a developer compliant if the information appears inside a larger document such as a system card or model card, so the statute prescribes content, not form. Second, § 22757.12(c)(4) makes disclosure quality beyond the list encouraged but not required. An AIO 20002 record is not a transparency report and does not substitute for any element of the list.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(c)(1) chapeau and § 22757.12(c)(2), points (A)–(C)",
        "quote": "[§ 22757.12(c)(1)] Before, or concurrently with, deploying a new frontier model or a substantially modified version of an existing frontier model, a frontier developer shall clearly and conspicuously publish on its internet website a transparency report […] [§ 22757.12(c)(2)] a large frontier developer shall include in the transparency report required by paragraph (1) summaries of all of the following: (A) Assessments of catastrophic risks from the frontier model conducted pursuant to the large frontier developer’s frontier AI framework. (B) The results of those assessments. (C) The extent to which third-party evaluators were involved.",
        "rationale": "The report's function is to give the reader the material to form their own view of a model rather than a conclusion to accept — SEC. 1(g) of the act states that 'Greater transparency can also advance accountability, competition, and public trust' — so the value that must prevail is Sdt, the addressee's own judgment. Publishing before or concurrently with deployment is a disclosure owed to whoever will encounter the model, which is Bed. Point (B) requires the results of the developer's own catastrophic-risk assessments to be summarized, including results that do not flatter the model, which is Hum: stating one's limits without overstating. What discharges the duty is a prescribed content list (Gui) carrying assessment results (Dat). The report is written and published by the developer (Ind) under a statutory content requirement (Gov). No expert body is designated as author or reviewer of the report, so Pro and Pee are not assigned. ADJUDICATION 2026-08-14: V narrows to [Bed], the only value code both passes reached — a published transparency report is a standing commitment the developer must keep. The two passes otherwise diverged completely on the value layer: v0.1 read the report as serving the reader's own understanding (Sdt) and as a duty not to overstate (Hum), the second pass as putting information in the public's hands (Unc) and protecting societal interests (Ses). Nothing in the quoted words settles between them, so neither set is carried and the divergence goes to the RFC round. E narrows to the intersection [Gui, Dat]: points (A)–(C) are a written content list (Gui) whose listed contents are the assessments and 'the results of those assessments' (Dat); the second pass's additional Exp, read from 'the extent to which third-party evaluators were involved', rests on one pass. S narrows to [Ind] — the report is published by the developer itself — with Gov dropped as absent from the excerpt. obligationType is lowered to organizational: the trigger is deployment, but the duty discharged is a publication.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Bed, Hum] → [Bed]; E [Gui, Dat] agreed as a set against the second pass's [Gui, Dat, Exp] intersection; S [Ind, Gov] → [Ind]; obligationType mixed → organizational. The value layer is the sharpest divergence in the pack: the two passes shared exactly one code out of five."
    },
    {
      "article": "Bus. & Prof. Code § 22757.12(e)",
      "summary": "A frontier developer must not make a materially false or misleading statement about catastrophic risk from its frontier models or about its management of catastrophic risk, and a large frontier developer must not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework; the prohibition does not reach a statement made in good faith that was reasonable under the circumstances.",
      "v": [
        "Hum",
        "Bed"
      ],
      "e": [],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Classified `behavioral` in v0.1 and lowered to `organizational` at the 2026-08-14 adjudication, because the statements the subdivision regulates are the developer’s corporate disclosures about its own framework rather than anything said in a concrete case by a system. The judgment correlate v0.1 identified is still real and is the reason the entry is worth an item — a scenario can put reputational or commercial pressure behind an overstated safety claim and observe whether the statement is tempered. Two boundaries: the prohibition covers statements about catastrophic risk and framework compliance only, not accuracy claims generally; and the § 22757.12(e)(2) good-faith carve-out means an honest and reasonable statement that turns out wrong is not a violation. Penalty exposure runs through § 22757.15.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(e)(1)(A)–(B) and § 22757.12(e)(2)",
        "quote": "[§ 22757.12(e)(1)(A)] A frontier developer shall not make a materially false or misleading statement about catastrophic risk from its frontier models or its management of catastrophic risk. [§ 22757.12(e)(1)(B)] A large frontier developer shall not make a materially false or misleading statement about its implementation of, or compliance with, its frontier AI framework. [§ 22757.12(e)(2)] This subdivision does not apply to a statement that was made in good faith and was reasonable under the circumstances.",
        "rationale": "The prohibition is on overstatement, and the word 'misleading' reaches statements that are literally true but leave a false impression — the value that must prevail is therefore Hum, recognition and disclosure of one's own limits, over the reputational interest (Fac) that pushes the other way. Because the statements at issue are ones the developer has undertaken to make accurately about a framework it published itself, Bed also prevails. The interest the accuracy serves is the public-safety information environment the chapter is built to create (Ses); it is not, on these words, the safety of any identified person, so Sep is not assigned here. On evidence: limb (1) is falsified against what the developer's own assessments actually record (Dat), while limb (2) makes the speaker's considered judgment at the time decisive — 'good faith' and 'reasonable under the circumstances' are assessed on the situation as it then stood (Exp). The regulated speaker is the developer itself (Ind); the standard of materiality and the enforcement action under § 22757.15 belong to the Attorney General (Gov). ADJUDICATION 2026-08-14: V narrows to [Hum, Bed], the second pass's set and a proper subset of v0.1's: the prohibition is a duty to say only what one can stand behind (Bed) and not to overstate (Hum), while Ses rests on v0.1 alone. E is emptied. v0.1 read the good-faith carve-out as making measured evidence and expert judgment decisive; the second pass recorded an INSUFFICIENT-QUOTE finding and refused to fill the layer — 'made in good faith and was reasonable under the circumstances' is a legal standard of care, not an evidentiary class, and it expressly considered and rejected Log as reading a courtroom test into the evidence layer. The intersection is empty and the conservative reading prevails. S retains [Ind] under the Ind limb: the developer is the author of the statement the provision regulates. obligationType is lowered from behavioral to organizational, and this is the most consequential single change in the pack: the second pass classified the duty organizational, the statements it regulates are the corporate disclosures of a developer — § 22757.12(e)(1)(B) is expressly about statements concerning 'implementation of, or compliance with, its frontier AI framework' — and a divergent obligationType resolves to the more conservative tag.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Hum, Bed, Ses] → [Hum, Bed]; E [Dat, Exp] → [] (the second pass found no evidentiary class in the quote and rejected Log expressly; the intersection is empty); S [Ind, Gov] → [Ind]; obligationType behavioral → organizational. The loss of the behavioral tag falsifies v0.1 note 11's claim that this entry is the first purely behavioral entry in the AIO pack series; the note is corrected in v0.2."
    },
    {
      "article": "Bus. & Prof. Code § 22757.12(f)",
      "summary": "A frontier developer publishing documents under § 22757.12 may redact only what is necessary to protect its trade secrets or cybersecurity, public safety, or United States national security, or to comply with federal or state law; where it redacts, it must describe the character and justification of the redaction in the published version to the extent the justifying concerns permit, and must retain the unredacted information for five years.",
      "v": [
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The provision is the pressure point of the whole publication regime: it is where a developer decides how much of a risk assessment the public actually sees. The statute answers with a necessity test and a meta-disclosure duty — the fact and reason of the redaction must themselves be published. The five-year retention duty is organizational and unobservable by any item. Redaction breadth is not measurable from an AIO 20002 record either; what an item can test is whether a commercial-sensitivity rationale is accepted as sufficient where the enumerated grounds do not apply.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.12(f)(1) and (f)(2)",
        "quote": "[§ 22757.12(f)(1)] When a frontier developer publishes documents to comply with this section, the frontier developer may make redactions to those documents that are necessary to protect the frontier developer’s trade secrets, the frontier developer’s cybersecurity, public safety, or the national security of the United States […] [§ 22757.12(f)(2)] the frontier developer shall describe the character and justification of the redaction in any published version of the document […] and shall retain the unredacted information for five years.",
        "rationale": "The redaction power is bounded by 'necessary', and paragraph (2) requires the reader to be told that something was removed and why — so what the provision preserves, at the margin, is the reader's ability to judge the document they are given (Sdt) and the developer's dependability toward the audience it published to (Bed). Two of the four enumerated grounds are cybersecurity and public safety, which is Ses; the commercial interest (trade secrets) appears as a permitted ground, not as a value the provision protects, so no Power code is assigned as prevailing. On evidence, the enumeration of permitted grounds is a closed written test applied as written (Gui), and paragraph (2) requires a stated justification rather than a measurement — an argument from the enumerated premises to this redaction (Log). Log is an INFERENCE from the word 'justification' rather than a class the text names, and is put to the RFC round. The redacting party is the developer (Ind) under a statutory standard (Gov). ADJUDICATION 2026-08-14: E narrows to the intersection [Gui]; v0.1's Log, which it had flagged as read from the requirement to state a redaction justification, was not reached by the second pass and is removed under the standing rule on inference-flagged codes. V narrows to [Ses], the single code both passes reached. The divergence on this axis is worth recording rather than smoothing: v0.1 read the provision as serving the reader's understanding (Sdt) and the developer's standing commitment (Bed); the second pass read the enumerated protected interests literally and coded Por for 'the frontier developer's trade secrets' — the one place in either wave where a developer-side commercial interest was proposed as a value that must prevail. Por is not carried, on the same ground the EU GPAI pack settled in Wave 1: the `v` array records what a provision expects to PREVAIL, and an interest a provision preserves AGAINST its own duty cannot be expressed in it (Wave 1 gap 9, carve-out representation). S retains [Ind] — the developer writes the redaction justification — and drops Gov, which the excerpt does not name. obligationType is lowered to organizational: publication discipline and five-year retention are management-system duties throughout.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Bed, Ses] → [Ses]; E [Gui, Log] → [Gui]; S [Ind, Gov] → [Ind]; obligationType mixed → organizational. The second pass's Por for trade secrets is not carried: the value layer cannot represent an interest preserved against the duty, which is Wave 1 gap 9, now confirmed in a second instrument."
    },
    {
      "article": "Bus. & Prof. Code § 22757.13(c)(1)–(2)",
      "summary": "A frontier developer must report any critical safety incident involving one or more of its frontier models to the Office of Emergency Services within 15 days of discovering it, and where it discovers that a critical safety incident poses an imminent risk of death or serious physical injury, must disclose that incident within 24 hours to an appropriate authority, including any law enforcement or public safety agency with jurisdiction.",
      "v": [
        "Sep",
        "Ses",
        "Cor"
      ],
      "e": [],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Two clocks, two thresholds, two recipients — the 15-day clock runs to the Office of Emergency Services on any critical safety incident as defined in § 22757.11(d); the 24-hour clock runs to a jurisdictionally appropriate authority only where imminent risk of death or serious physical injury is found. The measurable judgment is the classification decision that starts either clock, not the filing. Note § 22757.13(i): a developer may instead declare an intent to comply through a federal law, regulation or guidance document designated by the Office under § 22757.13(h), in which case failure to meet that federal standard is itself a violation of the chapter.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=25.1.&article=",
        "article": "Business and Professions Code § 22757.13(c)(1) and (c)(2)",
        "quote": "[§ 22757.13(c)(1)] Subject to paragraph (2), a frontier developer shall report any critical safety incident pertaining to one or more of its frontier models to the Office of Emergency Services within 15 days of discovering the critical safety incident. [§ 22757.13(c)(2)] If a frontier developer discovers that a critical safety incident poses an imminent risk of death or serious physical injury, the frontier developer shall disclose that incident within 24 hours to an authority, including any law enforcement agency or public safety agency with jurisdiction […]",
        "rationale": "Paragraph (2) states its own protected interest in terms of 'death or serious physical injury' (Sep), while the reporting regime as a whole exists so that authorities can respond to emerging public-safety risk (Ses). A fixed period measured from discovery is discharged by keeping to it, not by weighing whether reporting is warranted, which is Cor. On evidence: whether an event is a critical safety incident at all is settled by applying the closed four-limb definition at § 22757.11(d) as written (Gui), whereas the imminence finding that triggers the 24-hour clock is a judgment about the situation in front of the discoverer (Exp) — no statistic or precedent is named as decisive for it. The sources the text designates are the Office of Emergency Services and any law enforcement or public safety agency with jurisdiction (Gov), with the report itself originating from the developer (Ind). Members of the public may also report under § 22757.13(a), but the reporting duty in subdivision (c) is the developer's alone, so no testimony or stakeholder class is assigned here. ADJUDICATION 2026-08-14: V ([Sep, Ses, Cor]) agreed exactly. E is emptied, and the emptiness is a finding rather than a failure: v0.1 read the discharge as a reporting procedure plus a judgment (Gui, Exp) and the second pass as an account of one specific occurrence (Cas), carried expressly 'under protest' with the note that Cas is written for comparative analysis of several instances, Ane is wrong in register and Dat is wrong in kind. The intersection is empty, no candidate was reached by both passes, and §6 of the adjudication policy forbids resolving a vocabulary gap by silently stretching a nearest code. The layer is left undeclared and the gap recorded (Wave 2 gap 18, incident reporting as an evidence class). S drops Gov although both passes declared it, under the recipient-is-not-a-source rule — the Office of Emergency Services and 'any law enforcement agency or public safety agency with jurisdiction' appear here solely as the recipients of the report — and retains Ind, since the developer is the author of the report. obligationType is lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V agreed exactly. E [Gui, Exp] → [] — the two passes had no evidence code in common and the second pass recorded that none of the ten fits an incident report; the gap is carried to the RFC round rather than papered over. S [Gov, Ind] → [Ind] under the recipient-is-not-a-source rule. obligationType mixed → organizational."
    },
    {
      "article": "Labor Code § 1107.1(a)–(b), (d)",
      "summary": "A frontier developer must not make, adopt, enforce or enter into any rule, policy or contract that prevents a covered employee from disclosing — or that retaliates against a covered employee for disclosing — information to the Attorney General, a federal authority, a person with authority over the employee, or another covered employee empowered to investigate or correct the issue, where the employee has reasonable cause to believe the information shows a specific and substantial danger to public health or safety from a catastrophic risk or a violation of the TFAIA; it must not contract around Labor Code § 1102.5, and must give covered employees clear notice of these rights.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [
        "Tri"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The prohibition bites on organizational instruments — rules, policies, contracts — and on the retaliatory act, neither of which an item can observe. The judgment correlate is the treatment of the disclosure itself: whether an internally raised catastrophic-risk concern is engaged with or handled as a loyalty problem. Scope is narrow: 'covered employee' is defined at § 1107(b) as an employee responsible for assessing, managing or addressing risk of critical safety incidents, so most staff at a frontier developer are outside this chapter — § 1107.1(j)(1) preserves Labor Code § 1102.5 for everyone else. The evidentiary and remedial machinery at § 1107.1(f)–(i) is litigation procedure and is not mapped.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=LAB&division=2.&title=&part=3.&chapter=5.1.&article=",
        "article": "Labor Code § 1107.1(a), with the definition at § 1107(b)",
        "quote": "A frontier developer shall not make, adopt, enforce, or enter into a rule, regulation, policy, or contract that prevents a covered employee from disclosing, or retaliates against a covered employee for disclosing, information to the Attorney General, a federal authority, a person with authority over the covered employee […] if the covered employee has reasonable cause to believe that the information discloses […] a specific and substantial danger to the public health or safety resulting from a catastrophic risk.",
        "rationale": "The trigger is stated as 'a specific and substantial danger to the public health or safety', which is bodily safety (Sep) and the societal interest the chapter protects (Ses); what the prohibition secures for the employee is the freedom to reach and voice their own conclusion against employer pressure, which is Sdt. The threshold is deliberately low — 'reasonable cause to believe', not proof — and that admits the firsthand account of the person who saw the thing (Tri) alongside the considered judgment of a specialist, since § 1107(b) defines a covered employee as one 'responsible for assessing, managing, or addressing risk of critical safety incidents' (Exp). No statistic or systematic review is required to protect a disclosure. On sources, the disclosure is the on-record statement of one identified employee to a named recipient (Tes), and two of the four designated recipients are public authorities — the Attorney General and a federal authority (Gov). The developer's own material is not a designated source here, so Ind is not assigned. ADJUDICATION 2026-08-14: V narrows to the intersection [Sep, Ses]. The passes split Sdt against Sda over the employee's freedom to disclose; unlike the human-oversight phrasing at OECD Principle 1.2(b), the wave supplies no both-pass precedent for coding an action-freedom limb on its own, so neither code is carried and the split is recorded (Wave 2 gap 13). E narrows to [Tri], which both passes reached and which the second pass identified as the very case §4 gives as its inference example — the 'reasonable cause to believe' threshold sits deliberately below proof and admits the insider's firsthand account as decisive. S is emptied. Gov is dropped although both passes declared it, under the recipient-is-not-a-source rule: the Attorney General, a federal authority and a person with authority over the employee are named as the recipients of a protected disclosure, not as sources whose position settles anything. Tes was declared by v0.1 alone and was expressly rejected by the second pass, since a covered employee is not a sworn named eyewitness and subdivision (e) contemplates anonymity. That leaves no carrier at all for the insider discloser, which is the Wave 1 gap 5 pattern in a new setting. obligationType is lowered to organizational: what the subdivision prohibits is making, adopting, enforcing or entering into a rule, policy or contract.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Sdt, Ses] → [Sep, Ses] (the Sdt/Sda split is unresolved and recorded); E [Tri, Exp] → [Tri]; S [Tes, Gov] → [] — Gov under the recipient-is-not-a-source rule, Tes because the second pass expressly rejected it; obligationType mixed → organizational."
    },
    {
      "article": "Labor Code § 1107.1(e)",
      "summary": "A large frontier developer must provide a reasonable internal process through which a covered employee may anonymously disclose information indicating, in good faith, that the developer's activities present a specific and substantial danger to public health or safety from a catastrophic risk or that the developer violated the TFAIA, including a monthly update to the discloser on the status of the investigation and the actions taken; disclosures and responses must be shared with officers and directors at least quarterly, except as to an officer or director alleged to have engaged in the wrongdoing.",
      "v": [
        "Sep",
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ano",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "A channel, a response cadence and a board-reporting line — all organizational, none observable by an item. It is listed because the source assignment is the most unusual in the pack: § 1107.1(e) requires an anonymous disclosure to be received, investigated and reported upward, which makes Ano — the lowest-authority class in the AIO 00011 source hierarchy — a class this provision requires to be acted on rather than discounted. That inversion is the entry's whole measurable content and it is put to the RFC round. Nothing in an AIO 20002 record evidences that such a channel exists or works.",
      "provenance": {
        "sourceUrl": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53",
        "retrievalUrl": "https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=LAB&division=2.&title=&part=3.&chapter=5.1.&article=",
        "article": "Labor Code § 1107.1(e)(1) and (e)(2)(A)",
        "quote": "[Lab. Code § 1107.1(e)(1)] A large frontier developer shall provide a reasonable internal process through which a covered employee may anonymously disclose information to the large frontier developer […] including a monthly update to the person who made the disclosure regarding the status of the large frontier developer’s investigation of the disclosure […] [Lab. Code § 1107.1(e)(2)(A)] the disclosures and responses of the process required by this subdivision shall be shared with officers and directors of the large frontier developer at least once each quarter.",
        "rationale": "The information the channel exists to carry is, in the subdivision's own words, information about 'a specific and substantial danger to the public health or safety resulting from a catastrophic risk' — Sep. Anonymity exists so that the employee can judge and report without submitting to the employer's view of the matter (Sdt), and the monthly-update duty is a promise made to the discloser and owed back to them (Bed). What the process must be capable of receiving is a firsthand account (Tri), inside a standing internal procedure the statute requires to be 'reasonable' (Gui). The source classes follow the text literally: the disclosure is by design unattributed (Ano) and the process is operated by the developer itself (Ind). Assigning Ano as a class that must be trusted is unusual and is stated here because the provision, not the formalizer, makes it so — the developer may not discount a disclosure for being anonymous, since anonymity is the channel the statute mandates. ADJUDICATION 2026-08-14: obligationType (organizational) agreed exactly, and both passes independently declared Ano — the finding that survives most strongly in this pack. The second pass reached it blind and called it the sharpest finding in its set: the subdivision requires an unattributed claim to be received, investigated and reported upward rather than discounted, which inverts the authority ordering the AIO 00011 source hierarchy carries by default, where Ano sits last. V narrows to the intersection [Sep, Bed]; Sdt rests on v0.1 alone. E narrows to [Gui] — a reasonable internal process with a monthly update and quarterly board reporting is an established written procedure with a declared cadence — while v0.1's Tri, the discloser's firsthand account, was not reached by the second pass. Ind is retained alongside Ano under the Ind limb: the large frontier developer is the party required to provide and operate the process.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType agreed exactly and Ano was declared independently by both passes. V [Sep, Sdt, Bed] → [Sep, Bed]; E [Tri, Gui] → [Gui]; S [Ano, Ind] retained in full. The Ano inversion is carried to the RFC round as Wave 2 gap 19: a source class the hierarchy ranks last is here the class a legal duty requires to be acted on."
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with each provision's normative direction. They do not assess whether an organization publishes or adheres to a frontier AI framework, files transparency reports, transmits internal-use risk assessments, meets the statutory incident-reporting clocks, operates an anonymous whistleblower channel, or is a covered frontier developer or large frontier developer at all. Nothing measured against this pack bears on liability under Business and Professions Code § 22757.15. After the dual formalization and adjudication of 2026-08-14, eight of the ten mapped provisions are `organizational` and two are `mixed`; none is `behavioral`, the v0.1 behavioral classification of § 22757.12(e) having been lowered to `organizational`.",
  "notes": [
    "draft-verified, not active. Every vesMapping entry carries a verbatim excerpt of the chaptered text and a rationale argued from it, and on 2026-08-14 the second independent formalization required by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer read only the pack id, the sourceNorm and each entry's provenance.article, sourceUrl, retrievalUrl and quote; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped by an extraction script before any file was opened, and neither the pack-authoring guideline nor the management guide was opened. Human review is still outstanding, and the V/E/S assignment is settled only by the public RFC process at https://aioq.org/en/rfc. Certificates issued against this pack carry a draft-basis notice and record this status as `basisStatus` in the signed payload.",
    "Primary source and retrieval: the chaptered text of Senate Bill 53 (Chapter 138, Statutes of 2025) was retrieved on 2026-08-14 from the California Legislative Information service operated by the Office of Legislative Counsel (https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB53). The codified text was independently retrieved the same day from the same service's California Codes display for Business and Professions Code Chapter 25.1 and Labor Code Chapter 5.1, and cross-checked against the chaptered bill. No commentary, law-firm summary, trade-press explainer or mirror site was used. California statutes are government edicts and are not subject to copyright (Georgia v. Public.Resource.Org, Inc., 590 U.S. 255 (2020)), so verbatim quotation carries no licensing constraint; excerpts are nonetheless kept short and cited to the section.",
    "Currency verification (2026-08-14): SB 53 was approved by the Governor and filed with the Secretary of State on September 29, 2025, and was chaptered as Chapter 138, Statutes of 2025. It contains no urgency clause, so under California Constitution art. IV, § 8(c) it took effect January 1, 2026 — the codes display confirms 'Effective January 1, 2026' on every section of Business and Professions Code Chapter 25.1 and Labor Code Chapter 5.1. All seven sections of Chapter 25.1 and all three sections of Labor Code Chapter 5.1 carry the history line 'Added by Stats. 2025, Ch. 138' with no amendment line, so no amending statute had taken effect as of retrieval. Pending 2026 legislation was not exhaustively surveyed; SB 1159 (2025–2026), whose title suggested a possible overlap, was checked and amends only Government Code and Public Resources Code provisions on state agency use of AI, not Chapter 25.1. Operators should re-check the codified text before relying on this pack.",
    "Quote verification method: the chaptered text was normalized to a single-spaced corpus and every quoted fragment across the ten entries was matched as an exact substring of that corpus, including the curly apostrophes the official text uses — 31 of 31 fragments matched. Elisions are marked […] and bracketed citations such as [§ 22757.12(a)] precede excerpts where one entry quotes more than one provision; everything outside brackets is verbatim.",
    "Scope thresholds — who is actually covered. This norm does not apply to AI developers generally. A 'frontier developer' under § 22757.11(h)–(i) is a person who has trained, or initiated the training of, a foundation model using more than 10^26 integer or floating-point operations, counting the original training run plus subsequent fine-tuning, reinforcement learning and other material modifications. A 'large frontier developer' under § 22757.11(j) is a frontier developer whose annual gross revenues, together with its affiliates, exceeded five hundred million dollars in the preceding calendar year. Six of the ten mapped entries — the entire frontier AI framework regime at § 22757.12(a)–(d) and the anonymous-channel duty at Labor Code § 1107.1(e) — bind large frontier developers only. Four bind any frontier developer: the transparency report at § 22757.12(c)(1), the statement prohibition at § 22757.12(e), the redaction discipline at § 22757.12(f), and the incident clocks at § 22757.13(c). Deployers, downstream integrators and users of frontier models have no obligations under this chapter. § 22757.14 requires the Department of Technology to reassess these definitions annually from January 1, 2027, so the coverage line is expected to move.",
    "Relationship to the eu-ai-act pack — a different construct, not a stricter or looser version of it. The EU AI Act regulates AI systems by risk class and imposes conformity assessment, technical documentation and post-market monitoring on providers and deployers. TFAIA regulates a small number of very large model developers by compute and revenue threshold, imposes no conformity assessment or ex ante approval of any kind, and works entirely through published disclosure, incident reporting to a state agency, and truthfulness about what has been disclosed. A model aligned with one pack is not thereby aligned with the other, and the two packs' provisions are not crosswalked. TFAIA also sits alongside, and must not be confused with, the California AI Transparency Act at Business and Professions Code Chapter 25 (§§ 22757.1 et seq., added by SB 942 and amended by AB 853) — that chapter governs AI-generated content provenance and is a separate statute with a near-identical section-number range.",
    "State-law reach and its limits. TFAIA is California law and reaches conduct within California's jurisdiction; the act contains no express extraterritoriality clause, and this pack takes no position on when an out-of-state or non-US developer falls within it. SEC. 5(d) of the act provides that it does not apply to the extent it strictly conflicts with the terms of a contract between a federal government entity and a frontier developer, and SEC. 5(e) that it does not apply to the extent it is preempted by federal law. SEC. 5(f) preempts local rules adopted on or after January 1, 2025 that specifically regulate frontier developers' management of catastrophic risk. § 22757.13(h)–(i) further allows a developer to satisfy the incident-reporting section by declaring an intent to comply with a federal law, regulation or guidance document that the Office of Emergency Services has designated as substantially equivalent or stricter. None of this is legal advice; applicability is a question for the operator's counsel.",
    "Provisions deliberately excluded from the mapping, with reasons. (i) § 22757.10 (short title) and § 22757.11 (definitions) impose no conduct duty; the definitions are used throughout the rationales instead. (ii) § 22757.13(a)–(b), (d)–(e), (g)–(j) and § 22757.14 impose duties on the Office of Emergency Services, the Attorney General and the Department of Technology, not on developers. (iii) § 22757.15 (civil penalty up to one million dollars per violation, recoverable only by the Attorney General) is an enforcement provision rather than a conduct norm; it is cited in the entries whose breach it prices. (iv) § 22757.16 and Labor Code § 1107.2 (loss of equity value is not property damage) are interpretive. (v) Government Code § 11546.8 (CalCompute) establishes a state consortium to report a framework for a public cloud computing cluster by January 1, 2027 and is operative only upon a budget appropriation; it creates no obligation for any AI developer and is excluded as a promotional and institutional provision. (vi) Labor Code § 1107.1(c) and (f)–(j) govern hotline use, attorney's fees, burden shifting, injunctive relief and the relationship to Labor Code § 1102.5 — litigation procedure with no measurable judgment direction. Each exclusion is an RFC agenda item.",
    "V/E/S codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary. Source classes not designated by the text were not assigned, and the dual formalization tightened that discipline rather than loosening it. No provision of TFAIA names a professional body, an accreditation scheme or a scholarly source, so Pro and Pee appear nowhere — including at § 22757.12(a)(5), where the act requires the framework to describe the use of 'third parties' to assess catastrophic risk but imposes no independence, accreditation or competence criterion on them; the blind second pass reached the same withholding independently and called the resulting empty source layer the clearest source-layer gap in the pack. Of the inference-grade codes v0.1 flagged, one survives and one does not: Hum at § 22757.12(a)(4)–(5) survives because the second pass reached it independently from the same structural reading, and Log at § 22757.12(f) was removed because it did not. Ano at Labor Code § 1107.1(e) is not an inference — the statute mandates an anonymous channel — and both passes declared it; it inverts the authority ordering of the AIO 00011 source hierarchy and is raised for RFC on that ground.",
    "Article → V/E/S translation methodology: /content/standards-packs/FORMALIZATION_METHODOLOGY.md.",
    "AIO certifies conformance to AIO's own formalization of the Transparency in Frontier Artificial Intelligence Act. This is not a legal conformity assessment. The State of California, its Legislature, the Office of Legislative Counsel, the Office of Emergency Services, the Department of Technology and the Attorney General took no part in this formalization, have not reviewed or endorsed it, and it is not an official interpretation of the act. Nothing in this pack confers any presumption of compliance, and no result measured against it is a defence to an action under § 22757.15.",
    "Measurement scope (per-entry `obligationType`, pack-level `measurementScope`). After adjudication, eight of the ten mapped provisions are `organizational` and two are `mixed` (§ 22757.12(a)(2)–(3) and (a)(4)–(5)); v0.1's distribution was 1 behavioral / 7 mixed / 2 organizational. **The v0.1 claim that § 22757.12(e) is a `behavioral` entry, and the first purely behavioral entry in the AIO pack series, does not survive the dual formalization and is withdrawn.** The blind second pass classified it `organizational`, and the ground is textual: the statements the subdivision regulates are a developer's own public statements about its catastrophic-risk management and about compliance with its published framework, which are corporate disclosures rather than anything said in a concrete case by a system. Everything else in TFAIA is discharged by publishing a document, keeping a clock or operating a channel, and the adjudication moved five further entries from `mixed` to `organizational` on the same reading. A pass measured against this pack is evidence about model judgment only; it is never evidence that a developer published a framework, filed a report, met a deadline, or is even within the statute's scope.",
    "No item bank exists for this pack (itemBankRef.publicSet and privateSet are both null). No certification of any tier can be issued against it, and it is published as a formalization artefact only, listed as catalogued and not yet measurable.",
    "Source-axis policy (settled in Wave 1, extended here and applied uniformly). **`Gov` is declared only where the excerpt names a government body or a government norm as decisive on the substance of the duty.** Being named as the recipient of a report, a filing or a disclosure does not earn it, and neither does being the addressee of a recommendation. **`Ind` is declared where the excerpt makes the industry duty-bearer the author or performer of the provision's product or determination.** The rule is applied as a filter, never as a generator: it may remove a code both passes declared, and it may decide which of two divergent readings prevails, but it never adds a code that neither pass declared. This pack is where the recipient limb was settled, because the second pass raised it here as an open question — 'four entries designate a government body as the recipient of a report (OES, AG, law enforcement); coding these Gov conflates recipient with trusted source; a pack-wide convention should be settled rather than decided entry by entry'. The convention is now: recipient is not a source. Its effect here is that `Gov` is removed from § 22757.12(a)(10)–(d), § 22757.13(c) and Labor Code § 1107.1(a) although both passes had declared it, and survives only at § 22757.12(a)(1), where national and international standards are named as substance the framework must incorporate. The same rule removed `Gov` from G7 Action 4 in the parallel pack of this wave.",
    "Adjudication method (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under a fixed policy carried forward from Wave 1: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken (fewer codes, or a layer left undeclared); the intersection is an allowed outcome where it is non-empty and defensible; no third reading is invented, and every adjudicated set is a subset of at least one pass's set. Two sub-rules settled in this wave: a code flagged INFERENCE by the pass that declared it survives only where both passes reached it, and a divergent `obligationType` always resolves to the more conservative tag. Agreement statistics for this pack, across ten entries: V 2/10, E 1/10, S 1/10, obligationType 4/10, all four axes together 0/10. This is the lowest agreement of any pack in either wave, and the cause is structural rather than random: v0.1 read this statute through its defined terms and its penalty and definition sections, which sit outside the quoted excerpts, while the blind pass had only the excerpts.",
    "Contamination notice. The second formalization of this pack ran under the tightened Wave 2 protocol, in which the pack-authoring guideline was blocked outright, and the second pass disclosed no exposure to any pack field or to any prior adjudication. No axis of this pack is therefore reported with a contamination caveat.",
    "Vocabulary and schema gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes four to the Wave 2 list, which continues the consolidated Wave 1 list of ten. (14) CONTRACTED INDEPENDENT EVALUATOR AS A SOURCE CLASS — 'third parties' at § 22757.12(a)(5) and 'third-party evaluators' at § 22757.12(c)(2)(C) designate a party whose assessment the statute treats as material, and none of the ten source codes carries it: not Pro (no professional body, no credential requirement), not Pee, not Gov. Both passes left the layer empty. (15) HUMANS KEEPING CONTROL OF THE SYSTEM — § 22757.12(a)(10)'s 'a frontier model circumventing oversight mechanisms' names an interest the value layer cannot express; the second pass proposed Pod while recording that the catalogue's control value is written for control over people. Not carried. (18) INCIDENT REPORTING AS AN EVIDENCE CLASS — § 22757.13(c) is discharged by an account of one specific occurrence; Cas is written for structured comparison of several instances, Ane is wrong in register and Dat wrong in kind. The two passes shared no code and the layer is left empty. (19) THE Ano INVERSION — Labor Code § 1107.1(e) requires an anonymous disclosure to be acted on, which puts the source class the hierarchy ranks last in the position of a class a legal duty makes decisive; both passes declared Ano and both flagged the ordering problem. This is a question about the hierarchy's ordering, not about a missing code. Wave 1 gap 9 (an interest preserved against the duty, here trade secrets at § 22757.12(f)) and Wave 1 gap 5 (the insider discloser as a source class, here at Labor Code § 1107.1(a)) are both confirmed again. The full Wave 2 list is reproduced in the adjudication report."
  ]
}
