{
  "$schema": "./schema.json",
  "id": "eu-gpai-code",
  "name": {
    "en": "EU General-Purpose AI Code of Practice — AIO formalization",
    "ko": "EU 범용 AI 실행규약 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "General-Purpose AI Code of Practice (Code of Practice for General-Purpose AI Models) — Transparency Chapter, Copyright Chapter, Safety and Security Chapter",
    "publisher": "European Commission — AI Office (drawn up by independent experts in a multi-stakeholder process; the Commission and the AI Board confirmed its adequacy)",
    "version": "Final version published 10 July 2025; three chapters",
    "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai"
  },
  "vesMapping": [
    {
      "article": "Transparency Ch., Commitment 1 · Measures 1.1 and 1.3",
      "summary": "Signatories must have documented, at the time a general-purpose AI model is placed on the market, at least the information listed in the Model Documentation Form, must update that documentation to reflect relevant changes and keep previous versions until 10 years after the model was placed on the market, and must control the documented information for quality and integrity, retain it as evidence of compliance, and protect it from unintended alterations.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Composite entry — Measure 1.1 creates the documentation and Measure 1.3 governs its integrity and retention; they are one records regime. Nothing here is discharged by a judgment in a concrete case, so no AIO item can observe it. An AIO 20002 record is one reasoning line per substantive decision and is not a Model Documentation Form entry; the two are complementary artefacts with different units of account. Under the Code's own terms these Measures do not apply to providers releasing under a free and open-source licence that meet the Article 53(2) AI Act conditions, unless the model is a model with systemic risk.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
        "article": "Transparency Chapter, Commitment 1, Measure 1.1 (first and second paragraphs) and Measure 1.3",
        "quote": "[Measure 1.1] Signatories, when placing a general-purpose AI model on the market, will have documented at least all the information referred to in the Model Documentation Form below […] while keeping previous versions of the Model Documentation for a period ending 10 years after the model has been placed on the market. [Measure 1.3] Signatories will ensure that the documented information is controlled for quality and integrity, retained as evidence of compliance with obligations in the AI Act, and protected from unintended alterations.",
        "rationale": "The demand is that a prescribed content list be completed and then preserved unaltered; what discharges it is the written form itself read as issued (Gui — an established written standard procedure), not any measurement or expert opinion. 'At least all the information referred to in the Model Documentation Form' makes the operative value compliance with a formal requirement that may not be traded down (Cor); the 10-year retention and the protection from unintended alterations are about keeping the model traceable across the value chain over time, which is collective order (Ses). Nothing in either Measure names health, safety or fundamental rights, so Sep and Unc are not coded here even though the Code's Objectives clause names them at chapter level — the methodology codes the provision, not the preamble. The only authority the text designates is the AI Act regime and the AI Office (Gov); the documentation itself is drawn up and held by the provider (Ind). ADJUDICATION 2026-08-14: Ses (first pass) and Bed (second pass) are not carried into v0.2 and V is reduced to the intersection. Ses read the ten-year retention and the protection from unintended alterations as traceability across the value chain, which is what a records regime is for rather than what these Measures say. Bed read the same clauses as reliable record-keeping of what was already committed. Each was declared once, neither is forced by the words, and the one value both readers took off the text is that a prescribed content list must be completed and preserved and may not be traded down — 'at least all the information referred to in the Model Documentation Form' (Cor).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]), S ([Gov, Ind]) and obligationType (organizational) agreed exactly. V reduced to the intersection [Cor]. Both passes reached Ind, the second flagging it as an inference from the Signatory's authorship of the documentation; it is retained because both declared it and because the pack-wide source rule reaches the same result — the Signatory is the unilateral author of the Model Documentation."
    },
    {
      "article": "Transparency Ch., Measure 1.2",
      "summary": "Signatories must publicly disclose contact information for requesting the Model Documentation, must supply requested elements to the AI Office in their most up-to-date form within the period the AI Office specifies, and must give downstream providers the documentation intended for them plus, on request and subject to intellectual-property and trade-secret protection, any additional information necessary for those providers to understand the model's capabilities and limitations and to meet their own AI Act obligations — normally within 14 days.",
      "v": [
        "Sdt",
        "Hum"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The behavioral limb an item can reach is the disclosure judgment: whether a particular item of information is 'necessary to enable [a downstream provider] to have a good understanding of the capabilities and limitations' or is properly withheld as a trade secret. The disclosure channel, the published contact point and the 14-day service level are organisational and outside what any record format supplies. AIO 20002 contributes the reported value priorities and evidence types behind a model's outputs; the Code's own frame remains the Model Documentation Form. VOCABULARY GAP (structural): the disclosure duty in this paragraph is expressly qualified by the need to observe intellectual property rights, confidential business information and trade secrets. The blind second pass coded that carve-out `Por` (Power—Resources) and then flagged the problem itself — the pack's `v` array records what a provision expects to PREVAIL, so a counter-interest that the provision preserves against the duty has no representation in the schema at all. The code was dropped and the question is carried to the RFC round: whether packs need a way to record express carve-outs, and whether an item written on this Measure can test the withholding judgment without one.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118120",
        "article": "Transparency Chapter, Measure 1.2, third paragraph",
        "quote": "[…] without prejudice to the need to observe and protect intellectual property rights and confidential business information or trade secrets in accordance with Union and national law, Signatories will provide additional information upon a request from downstream providers insofar as such information is necessary to enable them to have a good understanding of the capabilities and limitations of the general-purpose AI model relevant for its integration into the downstream providers’ AI system and to enable those downstream providers to comply with their obligations pursuant to the AI Act.",
        "rationale": "The purpose clause — information sufficient for the downstream provider to have a good understanding and to discharge its own duties — makes the counterparty's own reasoning the protected interest (Sdt: supply what the other party needs to conclude for itself, rather than the conclusion). The duty runs to a named counterparty against a deadline, which is Bed. 'Capabilities and limitations' requires the provider to state the limits of its own model rather than only its strengths (Hum). What discharges the duty is a document — the Model Documentation, structured by the Model Documentation Form (Gui); no metric, evaluation result or expert opinion is what the Measure asks for, so Dat and Exp are not coded. The information is issued by the provider itself (Ind) and, on the other limb of the Measure, owed to the AI Office under Articles 91 and 75(3) AI Act (Gov). Downstream providers are addressees, not a source class, so no source code is assigned to them. ADJUDICATION 2026-08-14: Bed (first pass) and Cor and Por (second pass) are not carried into v0.2. Bed attached to the fourteen-day service level, which is outside the quoted paragraph. Cor rests on 'to enable those downstream providers to comply with their obligations pursuant to the AI Act' — that is the downstream provider's compliance, not a value this Signatory must let prevail. Por is the interesting one and it is dropped on a structural ground the second pass itself identified: the trade-secret and intellectual-property carve-out is an interest the Measure expressly PRESERVES against the disclosure duty, and the pack's `v` array means the values a provision expects to prevail. There is at present no way to record an expressly preserved counter-interest, and that is logged as a vocabulary gap rather than solved by coding the carve-out as though it were the duty.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]), S ([Gov, Ind]) and obligationType (mixed) agreed exactly. V reduced to the intersection [Sdt, Hum]. The second pass's Por for the trade-secret carve-out was dropped and recorded as a structural vocabulary gap — the v array cannot express an expressly preserved counter-interest."
    },
    {
      "article": "Copyright Ch., Commitment 1 · Measure 1.1",
      "summary": "Signatories must draw up, keep up to date and implement a policy for complying with Union copyright and related-rights law covering every general-purpose AI model they place on the Union market, describe that policy in a single document incorporating the Chapter's Measures, and assign responsibility inside their organisation for implementing and overseeing it.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Wholly organisational: a policy document and an internal responsibility assignment. No AIO item can observe either. The Chapter's own Commitment 1(2) is explicit that the Measures are how a Signatory demonstrates it has put a policy in place, and that the Signatory remains responsible for verifying that the policy complies with Member States' implementation of Union copyright law — adherence to the Code is not itself copyright compliance.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
        "article": "Copyright Chapter, Commitment 1, Measure 1.1, point (1)",
        "quote": "Signatories will draw up, keep up-to-date and implement a policy to comply with Union law on copyright and related rights for all general-purpose AI models they place on the Union market. Signatories commit to describe that policy in a single document incorporating the Measures set out in this Chapter. Signatories will assign responsibilities within their organisation for the implementation and overseeing of this policy.",
        "rationale": "The Measure is framed as compliance with an external legal order — 'a policy to comply with Union law on copyright and related rights' — which is Cor read directly off the text; the requirement that responsibilities be assigned inside the organisation makes institutional accountability the second protected interest (Ses). What discharges the duty is a single written document (Gui). The authorities the text designates are Union copyright law and, through recital (c), Directives 2001/29/EC, (EU) 2019/790 and 2004/48/EC, together with Article 53(1), point (c), AI Act (Gov); the policy is written and owned by the provider (Ind). No professional body is named anywhere in this Measure, so Pro is not coded, and no rightsholder-facing duty arises here — that sits in Measure 1.5. ADJUDICATION 2026-08-14: Ses (first pass) and Bed and Unc (second pass) are not carried into v0.2. Ses read 'assign responsibilities within their organisation' as institutional accountability, Bed read 'draw up, keep up-to-date and implement' as holding to what has been undertaken, and Unc was flagged INFERENCE by the second pass — copyright compliance protects rightsholders' entitlements, but the text names the law to be complied with, not equality or justice as the protected value. Each was declared once. What both readers took off the words is that the Measure is framed as compliance with an external legal order (Cor).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]), S ([Gov, Ind]) and obligationType (organizational) agreed exactly. V reduced to the intersection [Cor]."
    },
    {
      "article": "Copyright Ch., Measure 1.3",
      "summary": "Where Signatories crawl the web for text and data mining and training, they must employ crawlers that read and follow robots.txt as specified in IETF RFC 9309, and must identify and comply with other appropriate machine-readable protocols expressing a reservation of rights under Article 4(3) of Directive (EU) 2019/790 — those adopted by international or European standardisation organisations, or state-of-the-art and widely adopted by rightsholders across cultural sectors.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Pro"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The crawler behaviour itself is a system-design duty. The judgment correlate an item can test is what the Signatory does at the margin: whether an ambiguous or non-standard machine-readable signal is treated as a binding reservation, and whether a protocol that is widely adopted by rightsholders but not yet standardised counts as 'appropriate'. Measure 1.3, point (2) preserves the rightsholder's right to reserve by any appropriate means, including non-machine-readable ones, which the Measure's own commitments do not reach. VOCABULARY GAP: `Pro` is defined as the collective position of the field's own body of credentialed practitioners. The IETF and the European standardisation organisations are standards-development bodies, which is a different institution; both passes nevertheless used `Pro` as the nearest carrier, and it is kept on that basis with this flag. The same stretch is recorded at Measure 1.5 for collective management organisations. Separately: the rightsholder's own declaration is the operative input to this whole Measure, and the Chapter designates no source class for it — the pack still does not invent one.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
        "article": "Copyright Chapter, Measure 1.3, point (1), sub-points (a) and (b)",
        "quote": "Signatories commit: a) to employ web-crawlers that read and follow instructions expressed in accordance with the Robot Exclusion Protocol (robots.txt), as specified in the Internet Engineering Task Force (IETF) Request for Comments No. 9309 […], and b) to identify and comply with other appropriate machine-readable protocols to express rights reservations pursuant to Article 4(3) of Directive (EU) 2019/790, for example through asset-based or location-based metadata, that have either have been adopted by international or European standardisation organisations, or are state-of-the-art […] and widely adopted by rightsholders […]",
        "rationale": "The commitment is to obey an instruction that someone else has expressed — the rightsholder's reservation — so the operative values are compliance with a declared rule (Cor) and being the kind of counterparty that honours a reservation it could technically ignore (Bed), inside the legal order that copyright constitutes (Ses). The evidence class is unusually clean here: what settles whether a reservation binds is a published technical specification read as written — IETF RFC 9309 and the standardisation-organisation protocols of sub-point (b) — which is Gui in its strictest sense; nothing measured, argued or testified is decisive. Two source classes are named in the text and only those two are coded: the legislator, via Article 4(3) of Directive (EU) 2019/790 (Gov), and the standards bodies, via the express designation of the IETF and of 'international or European standardisation organisations' (Pro). Note for the RFC round: the rightsholder's own declaration is the operative input to the whole Measure, yet the Chapter designates no source class for it; the pack deliberately does not invent one. ADJUDICATION 2026-08-14, source axis adjudicated under contamination notice: V is reduced to the intersection [Cor], and S stays [Gov, Pro]. On values, the first pass's Bed and Ses and the second pass's Sda were each declared once. Sda — honouring the rightsholder's own reservation as their choice over their own material — is the strongest of the three and is recorded as an RFC candidate, but it is not carried on one reading. On sources, the pack-authoring guideline had disclosed to the second formalizer that this Measure is the Wave 1 example of a text naming a standardisation body, so the axis was decided on the quoted words alone rather than on the second pass's concurrence: the quote names the IETF and RFC 9309 and 'international or European standardisation organisations' (Pro) and Article 4(3) of Directive (EU) 2019/790 (Gov), and both are in the text. The second pass's additional Ind, read from 'widely adopted by rightsholders', is dropped — its own author called it an imperfect fit, since rightsholders are the counterparty industry rather than the concerned industry issuing its own material.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]) and obligationType (mixed) agreed exactly. V reduced to the intersection [Cor]. S stayed [Gov, Pro] — the second pass's additional Ind was dropped as an inference its own author qualified. The source axis of this entry was adjudicated under a contamination notice, because the pack-authoring guideline §2.3 had named this Measure to the second formalizer as the Wave 1 example of a text designating a standardisation body; the decision rests on the quoted words, which do name the IETF and RFC 9309."
    },
    {
      "article": "Copyright Ch., Measure 1.5",
      "summary": "Signatories must designate an electronic point of contact for affected rightsholders and publish accessible information about it, must operate a mechanism through which rightsholders and their authorised representatives, including collective management organisations, can submit sufficiently precise and adequately substantiated complaints about non-compliance with the Chapter, and must act on those complaints diligently, non-arbitrarily and within a reasonable time unless a complaint is manifestly unfounded or duplicates one already answered for the same rightsholder.",
      "v": [
        "Bed",
        "Unc"
      ],
      "e": [
        "Tri"
      ],
      "s": [
        "Pro"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The contact point and the intake mechanism are organisational. The behavioral correlate is the disposal judgment: whether a given complaint is 'manifestly unfounded', whether it is 'sufficiently precise and adequately substantiated', and whether it is genuinely identical to one already answered. The Measure's closing sentence is explicit that it does not affect the measures, remedies and sanctions available under Union and national law — an internal complaints channel is not a substitute for enforcement. VOCABULARY GAP: the affected rightsholder who submits a complaint has no clean source class in AIO 00011. v0.1 used `Tes`; the blind second pass declared nothing for that limb and said why. `Tes` is removed and the source layer left at [Pro], which itself is a stretch — collective management organisations are named in the text as permitted representatives, not as a professional body whose collective position must be trusted. Both passes assigned Pro and both flagged it, so it is kept with this note. The complainant gap is the same one recorded at Arts. 14 and 16 of the Council of Europe pack and at 第十五条 of the Chinese pack.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118115",
        "article": "Copyright Chapter, Measure 1.5, points (1) and (2)",
        "quote": "Signatories commit to designate a point of contact for electronic communication with affected rightsholders […]. Signatories commit to put a mechanism in place to allow affected rightsholders and their authorised representatives, including collective management organisations, to submit, by electronic means, sufficiently precise and adequately substantiated complaints concerning the non-compliance of Signatories with their commitments pursuant to this Chapter […]. Signatories will act on complaints in a diligent, non-arbitrary manner and within a reasonable time, unless a complaint is manifestly unfounded […]",
        "rationale": "'Diligent […] and within a reasonable time' is a duty owed to an identified counterparty (Bed); 'non-arbitrary' is the equality-of-treatment demand, which is Unc read off the word itself rather than off any protected-group framing. What triggers the duty is the complaint — a firsthand, on-record account by the party who says it was affected (Tri) — and the Measure's own release condition works by comparison with prior instances: a Signatory need not act again where it 'has already responded to an identical complaint by the same rightsholder', which is case-to-case matching (Cas). No metric and no guideline decides the outcome, so Dat and Gui are not coded. The trusted sources are the affected rightsholder's own submission (Tes) and the representative organisations the text expressly names, including collective management organisations (Pro). The Pro assignment is an inference from that naming — a collective management organisation is a designated representative body rather than a professional association in the ordinary sense — and is flagged for the RFC round on that point. ADJUDICATION 2026-08-14: Cas (first pass), Gui (second pass) and Tes (first pass) are not carried into v0.2. Cas rested on the release condition for an identical complaint already answered, which is elided from the quoted excerpt. Gui read the contact point and intake mechanism as a written procedure; that is the machinery, not what decides a complaint. Both were declared once and the conservative outcome is the intersection [Tri] — the complaint itself, a firsthand account by the party who says it was affected. Tes is dropped for the reason the second pass gave when it declared no code at all for that limb: an affected rightsholder submitting a substantiated complaint is neither the requester of the model's service (Usr) nor a sworn named eyewitness (Tes).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (mixed) agreed. V reduced to the intersection [Bed, Unc]; E reduced to the intersection [Tri]; S narrowed [Pro, Tes] to [Pro], with the complainant's missing source class recorded as a vocabulary gap rather than papered over with the nearest code."
    },
    {
      "article": "Safety and Security Ch., Commitment 1 · Measures 1.1–1.3",
      "summary": "Signatories must adopt a state-of-the-art Safety and Security Framework setting out the systemic-risk management processes and measures by which they ensure the systemic risks stemming from their models are acceptable, must implement it continuously across the model lifecycle, must keep it up to date with a changelog, version number and date of change, and must conduct a Framework assessment covering both the Framework's adequacy and their own adherence to it whenever they have reasonable grounds to believe either has been materially undermined, or every 12 months from placing the model on the market, whichever is sooner.",
      "v": [
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Composite entry covering the create–implement–update cycle of Commitment 1; Measure 1.4 (notifying the AI Office within five business days) is part of the same Commitment but is a pure notification duty and is not separately coded. This Commitment applies only to providers of general-purpose AI models with systemic risk. It is a management-system specification in the ordinary sense and no item-based measurement reaches it; aggregate AIO code distributions across model versions can act as a drift signal feeding a Framework assessment, which is an upstream input and not adherence in itself.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
        "article": "Safety and Security Chapter, Commitment 1, first paragraph, and Measure 1.3, second paragraph",
        "quote": "[Commitment 1] Signatories commit to adopting a state-of-the-art Safety and Security Framework (“Framework”). The purpose of the Framework is to outline the systemic risk management processes and measures that Signatories implement to ensure the systemic risks stemming from their models are acceptable. [Measure 1.3] Signatories will conduct an appropriate Framework assessment, if they have reasonable grounds to believe that the adequacy of their Framework and/or their adherence thereto has been or will be materially undermined, or every 12 months starting from their placing of the model on the market, whichever is sooner.",
        "rationale": "The object of the whole Commitment is systemic risk, which the Chapter interprets by reference to the definitions in Article 3(2) and 3(65) AI Act and whose types Appendix 1.1 enumerates; the interests that gives are collective order and infrastructure (Ses), harm to persons (Sep), and the fundamental-rights limb the Code's Objectives clause names alongside health and safety (Unc). What discharges the duty is a written document that outlines processes and is kept versioned with a changelog (Gui), tested at a fixed cadence by a structured assessment of adequacy and adherence — a periodic systematic review rather than a measurement or a case judgment (Rev). Two source classes are designated. Gov: the Framework exists under Article 55(1) AI Act and must be made available to the AI Office unredacted. Ind: 'state-of-the-art' is defined in the Chapter's own Glossary as what is 'accepted amongst providers of general-purpose AI models with systemic risk', which makes industry consensus a source the text itself designates rather than one read into it. Pro is not coded — Commitment 1 names no external assurance provider, and the assurance role that does appear sits in Commitment 8. ADJUDICATION 2026-08-14: Sep and Unc (first pass), Bed and Log (second pass), Rev (first pass) and Gov (first pass) are not carried into v0.2. Sep and Unc were grounded in Appendix 1.1's risk taxonomy and in the Code's Objectives clause — outside the quoted excerpt, and inconsistent with this pack's own rule that the methodology codes the provision and not the preamble. Bed and Log were each declared once and each flagged by the second pass. Rev is removed as a code misapplication rather than a difference of reading: `Rev` is defined as a synthesis pooling and weighing findings across many separate studies, which a periodic Framework assessment is not; the absence of any code for a structured periodic self-assessment is logged as a vocabulary gap. Gov fails the pack-wide source rule — it rested on Article 55(1) AI Act and on the Framework being made available to the AI Office, neither of which appears in the quoted words.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (organizational) agreed. V reduced to the intersection [Ses]; E reduced to the intersection [Gui], with the first pass's Rev removed as a misapplication of a code defined as research synthesis; S narrowed [Gov, Ind] to [Ind] under the pack-wide source rule, since the quoted passage names no authority. This entry lost more codes at adjudication than any other in Wave 1 — six of nine — because v0.1 coded it from the Chapter's Appendices and Objectives rather than from its quote."
    },
    {
      "article": "Safety and Security Ch., Measure 3.2",
      "summary": "Signatories must conduct at least state-of-the-art model evaluations in the modalities relevant to each systemic risk, assessing the model's capabilities, propensities, affordances and effects as specified in Appendix 3, using methods appropriate to the model and the risk, and must include open-ended testing directed at finding unexpected behaviours, capability boundaries and emergent properties, with the evaluation design informed by the model-independent information gathered under Measure 3.1.",
      "v": [
        "Hum",
        "Ses"
      ],
      "e": [
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The evaluation programme is organisational, and after adjudication the entry is classified as such: the discipline this Measure demands — not stopping at a passing benchmark score, treating an unexpected behaviour found in open-ended testing as a finding rather than an artefact — is a discipline an organization exercises over its own testing, not a judgment a model makes in a case. AIO measurement is itself an evaluation instrument of exactly the kind this Measure contemplates and does not stand outside it: a pack score is evidence about model judgment under a published item set, not an adequate discharge of Measure 3.2, whose Appendix 3 requirements on elicitation, evaluator access and reporting go well beyond it.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
        "article": "Safety and Security Chapter, Measure 3.2, first and second paragraphs",
        "quote": "Signatories will conduct at least state-of-the-art model evaluations in the modalities relevant to the systemic risk to assess the model’s capabilities, propensities, affordances, and/or effects, as specified in Appendix 3. Signatories will ensure that such model evaluations are designed and conducted using methods that are appropriate for the model and the systemic risk, and include open-ended testing of the model to improve the understanding of the systemic risk, with a view to identifying unexpected behaviours, capability boundaries, or emergent properties.",
        "rationale": "The second paragraph is the normative core and it is a humility requirement in operational form: open-ended testing exists because the evaluator is not entitled to assume the model's behaviour is already characterised, and 'unexpected behaviours […] or emergent properties' says so in the text (Hum). The interests the evaluation serves are the systemic risks of Appendix 1.1 — societal and infrastructural (Ses) and harm to persons (Sep). What is decisive is measured evaluation output: the Measure's own examples are Q&A sets, task-based evaluations, benchmarks and human uplift studies (Dat), together with red-teaming and other adversarial testing, which is the considered judgment of people running the test rather than an aggregate metric (Exp). Two source classes are designated: the Chapter's Glossary definition of 'state-of-the-art' as what is accepted amongst providers of models with systemic risk (Ind), and the independent external evaluators that Appendix 3.5 — incorporated into this Measure by the phrase 'as specified in Appendix 3' — requires or requires to be justified away (Pro). Ach was considered for the 'at least state-of-the-art' framing and left out: the competence standard here is instrumental to the safety interest, not a value the Measure asks to prevail in its own right. ADJUDICATION 2026-08-14: Sep, Exp, Gui and Pro are not carried into v0.2, and the obligation type is lowered from mixed to organizational. Sep came from Appendix 1.1, outside the quote. Exp (first pass) rested on red-teaming and adversarial testing, which the quoted paragraphs do not mention, and Gui (second pass) on 'as specified in Appendix 3'; each was declared once, so the intersection [Dat] stands, and the Measure's own object — evaluations assessing capabilities, propensities, affordances and effects — is measurement. Pro rested on the external-evaluator regime of Appendix 3.5, incorporated by reference but not in the quoted words; the second pass withheld it expressly. On obligation type: conducting a state-of-the-art evaluation programme, including open-ended testing, is a process an organization runs. Its object is model behaviour, but the duty is not discharged by a judgment in a concrete case, and the pack should not imply that an item reaches it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V reduced to the intersection [Hum, Ses]; E reduced to the intersection [Dat]; S narrowed [Ind, Pro] to [Ind], the second pass having expressly withheld Pro because 'state-of-the-art' invokes the field's practice without naming a body. obligationType CHANGED mixed to organizational: running an evaluation programme is a process duty even though its object is model behaviour."
    },
    {
      "article": "Safety and Security Ch., Measures 4.1 and 4.2",
      "summary": "Signatories must define and justify systemic risk acceptance criteria — normally measurable risk tiers including at least one tier the model has not reached — apply them to each identified systemic risk with a safety margin that accounts for the limitations, changes and uncertainties of the risk sources, of the assessments themselves and of the mitigations' effectiveness, and may proceed with development, making available on the market or use of the model only where the systemic risks are determined to be acceptable; where they are not, the Signatory must restrict, withhold, withdraw or recall the model, implement mitigations, and re-run the assessment before proceeding.",
      "v": [
        "Ses",
        "Hum"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The clearest normative direction in the Chapter: Measure 4.2 is a stop rule, not a balancing test. The behavioral correlate an item can test is whether a stated risk finding is allowed to override a commercial or schedule interest. What no item reaches is whether the organisation actually declared tiers in its Framework, actually applied them, or actually withheld a release. The safety margin is the part organisations most often implement in name only — a margin that is not defined against under-elicitation and mitigation circumvention is not the margin this Measure describes.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
        "article": "Safety and Security Chapter, Measure 4.1, fourth paragraph, and Measure 4.2, first paragraph",
        "quote": "[Measure 4.1] Signatories will apply the systemic risk acceptance criteria to each identified systemic risk […], incorporating a safety margin […], to determine whether each identified systemic risk […] and the overall systemic risk are acceptable. This acceptance determination will take into account at least the information gathered via systemic risk identification and analysis […]. [Measure 4.2] Signatories will only proceed with the development, the making available on the market, and/or the use of the model, if the systemic risks stemming from the model are determined to be acceptable […]",
        "rationale": "'Will only proceed […] if' makes the protected interests non-tradeable against the interest in shipping: those interests are harm to persons (Sep) and collective and infrastructural order (Ses). Hum is coded from the safety margin, which Measure 4.1 requires to take into account the limitations, changes and uncertainties of the risk assessment itself — expressly including 'under-elicitation of model evaluations or historical accuracy of similar assessments'. That is a provision that requires the Signatory to price in its own fallibility, which is Hum in the strict sense rather than a general caution. What discharges the determination is the risk estimate produced under Measure 3.4, which the Chapter requires to be expressed as a risk score, matrix or probability distribution (Dat), applied through the tiers and criteria the Signatory has written into its Framework (Gui). The criteria are the provider's own (Ind), justified to the regime that Article 55(1) AI Act establishes and to which the Framework and Model Report are supplied (Gov). No expert body is designated as the arbiter of acceptability, so Exp and Pro are not coded here even though Measure 3.2 admits them upstream. ADJUDICATION 2026-08-14: Sep and Gov are not carried into v0.2. Sep was grounded in the systemic-risk taxonomy of Appendix 1.1 rather than in the quoted paragraphs, which speak of systemic risk without enumerating the harms; Ses carries the interest both readers took off the words. Gov rested on Article 55(1) AI Act, which the quote does not name. Hum survives on the strength of both passes declaring it, the second flagging that the text designates a safety margin rather than a value — the first pass's grounding is stronger, since Measure 4.1 requires the margin to account for the limitations and uncertainties of the assessment itself, but the flag is recorded.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Dat, Gui]) and obligationType (mixed) agreed exactly. V reduced to the intersection [Ses, Hum]; S narrowed [Gov, Ind] to [Ind] under the pack-wide source rule. This entry keeps the clearest normative direction in the Chapter — Measure 4.2 is a stop rule, not a balancing test — and both independent readers reached that reading of it."
    },
    {
      "article": "Safety and Security Ch., Measure 7.2",
      "summary": "The Safety and Security Model Report supplied to the AI Office must state a detailed justification for why the systemic risks stemming from the model are acceptable, including the safety margins incorporated; the reasonably foreseeable conditions under which that justification would no longer hold; and how the decision to proceed was made, including whether input from external actors and from independent external evaluators informed it.",
      "v": [
        "Hum",
        "Bed"
      ],
      "e": [
        "Log"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "This is the provision in the Code that lies closest to what an AIO 20002 record is: a written justification that carries its own defeaters and names the sources that informed it. The units differ and the pack does not elide that. A Model Report is an organisation-level document about one model release, produced by people; an AIO 20002 record is one machine-emitted reasoning line per substantive decision. A corpus of AIO records is evidence toward point (1) and point (2) — what the model in fact prioritised, and where that priority would flip — but it is not a Model Report and does not become one at any volume.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
        "article": "Safety and Security Chapter, Measure 7.2, points (1)–(3)",
        "quote": "Signatories will provide in the Model Report: (1) a detailed justification for why the systemic risks stemming from the model are acceptable, including details of the safety margins incorporated (pursuant to Measure 4.1); (2) the reasonably foreseeable conditions under which the justification in point (1) would no longer hold; and (3) a description of how the decision to proceed with the development, making available on the market, and/or use (pursuant to Measure 4.2) was made, including whether input from external actors informed such a decision […]",
        "rationale": "The Measure asks for reasons, not for a verdict: the AI Office is to be put in a position to judge the release for itself, which is Sdt applied to the reader of the report. Point (2) is the striking one — the Signatory must state the conditions under which its own justification fails, which is an explicit duty to publish one's own defeaters (Hum). The report is owed to a named recipient at a fixed point in the release process, which is Bed. What discharges point (1) is an argued chain — a 'detailed justification' whose validity is what point (2) qualifies — so the decisive evidence class is inferential (Log), resting on the safety margins and risk estimates carried up from Measures 3.4 and 4.1 (Dat). Three source classes are designated by the text: the AI Office as recipient under Articles 55(1) and 56(5) AI Act (Gov), the Signatory as author (Ind), and the independent external evaluators of Appendix 3.5 whose input point (3) requires to be recorded (Pro). ADJUDICATION 2026-08-14: Sdt (first pass), Ses (second pass), Dat (first pass), Gui (second pass), Gov and Pro (first pass) are not carried into v0.2. Sdt read the AI Office as a reader to be put in a position to judge, but the quoted points name no recipient — which is also why Gov falls, as the second pass noted expressly. Ses attaches to 'why the systemic risks are acceptable' and is defensible, but was declared once. Dat and Gui were likewise one-pass codes, leaving the intersection [Log]: point (1) asks for a detailed justification and point (2) for the conditions under which it fails, which is an argued chain and not a measurement. Pro rested on Appendix 3.5, outside the quote. Both readers independently identified point (2) as an unusually direct designation of Hum — a duty to publish one's own defeaters — and that survives.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (mixed) agreed. V reduced to the intersection [Hum, Bed]; E reduced to the intersection [Log]; S narrowed [Gov, Ind, Pro] to [Ind] under the pack-wide source rule. Both independent passes reached Hum from point (2), which is the finding this entry rests on."
    },
    {
      "article": "Safety and Security Ch., Commitment 9 · Measures 9.2 and 9.3",
      "summary": "Signatories must keep track of, document and report to the AI Office and, where applicable, national competent authorities a prescribed list of information about serious incidents — including the chain of events, a root cause analysis of the model outputs that led to the incident and the factors that produced them, any failures or circumventions of systemic risk mitigations, and any connected patterns detected in post-market monitoring — with initial reports due within two days for a serious and irreversible disruption of critical infrastructure, five days for a serious cybersecurity breach, ten days for a death, and fifteen days for serious harm to health, an infringement of fundamental-rights obligations, or serious harm to property or the environment, counted from awareness of the model's involvement.",
      "v": [
        "Cor",
        "Ses",
        "Hum"
      ],
      "e": [
        "Cas",
        "Dat"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The tracking and reporting infrastructure is organisational and Measure 9.4 adds a five-year retention floor. The judgment correlate is the escalation threshold, which the Chapter sets deliberately low — reporting is owed where the Signatory 'establish[es] or suspect[s] with reasonable likelihood' a causal relationship, not where it has proved one — and the Chapter's recital (j) records that reporting is not an admission of wrongdoing. A per-decision AIO 20002 corpus is one of the inputs a root cause analysis under point (8) can read; it is not the analysis. Measure 9.1 additionally designates downstream modifiers, downstream providers, users and other third parties as reporting channels; that source class is not coded here because the Measures quoted do not designate it, and it is left to the RFC round.",
      "provenance": {
        "sourceUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/118119",
        "article": "Safety and Security Chapter, Measure 9.2, first paragraph, points (3), (8) and (9), and Measure 9.3, first paragraph, points (1)–(4)",
        "quote": "[Measure 9.2] Signatories will keep track of, document, and report to the AI Office […] at least the following information […]: […] (3) the chain of events that (directly or indirectly) led to the serious incident; […] (8) a root cause analysis with a description of the model’s outputs that (directly or indirectly) led to the serious incident and the factors that contributed to their generation, including the inputs used and any failures or circumventions of systemic risk mitigations; and (9) any patterns detected during post-market monitoring […] [Measure 9.3] […] not later than two days after the Signatories become aware of the involvement of their model in the incident […]",
        "rationale": "Measure 9.3 enumerates the triggering harms itself, and the value coding follows that enumeration rather than a general reading: death and serious harm to a person's health give Sep; serious and irreversible disruption of critical infrastructure and serious cybersecurity breach give Ses; 'an infringement of obligations under Union law intended to protect fundamental rights' gives Unc. The evidence that discharges the duty is the reconstruction of a single episode — chain of events, root cause analysis of the outputs and the factors that generated them (Cas) — supplemented by the aggregate signal of point (9), patterns and near-miss data from post-market monitoring (Dat). Exp is not coded: the Measure prescribes the content of the analysis, not that a designated expert perform it. The report is owed to the AI Office and national competent authorities (Gov) and is compiled from the provider's own records and investigation (Ind). ADJUDICATION 2026-08-14: this is the one entry in Wave 1 where the blind second pass's LARGER value set was adopted, because it is the better grounded. v0.1 coded Sep and Unc from the harm enumeration of Measure 9.3 — death, serious harm to health, infringement of fundamental-rights obligations — but that enumeration is elided from the quoted excerpt, which carries only the two-day clock. The second pass's Cor (a prescribed, deadline-bound reporting duty) and Hum (point (8)'s requirement to disclose any failures or circumventions of the Signatory's own systemic-risk mitigations) both rest on words that are in the quote. Ses is common to both readings and stands. On obligation type: incident tracking, documentation and deadline-bound reporting are management-system duties end to end; the escalation threshold the first pass pointed to ('suspect with reasonable likelihood') is not in the quoted text either, so the pack does not claim an item reaches this Measure.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Cas, Dat]) and S ([Gov, Ind]) agreed exactly. V CHANGED [Sep, Ses, Unc] to [Cor, Ses, Hum] — the second pass's set adopted whole, the only such outcome in Wave 1, because v0.1's Sep and Unc were coded from a harm enumeration its own excerpt elides. obligationType CHANGED mixed to organizational for the same reason: the judgment correlate v0.1 relied on is outside the quote. If the harm enumeration of Measure 9.3 is to be coded, it must first be quoted — proposed for the next revision."
    }
  ],
  "itemBankRef": {
    "publicSet": "/content/standards-packs/item-banks/eu-gpai-code.public.json",
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with each Commitment's or Measure's normative direction. They do not assess whether a provider has adopted a Safety and Security Framework, drawn up Model Documentation or a copyright policy, run model evaluations, operated a complaints channel, or reported a serious incident — those are management-system duties that no item-based measurement observes. After the dual formalization and adjudication of 2026-08-14, five of the ten mapped units are `organizational` and five are `mixed`; none is purely behavioral. Nothing in a measurement against this pack bears on whether a provider adheres to the Code, and AIO is not a party to the Code and has no role in the AI Office's assessment of adherence.",
  "notes": [
    "draft-verified. Every entry carries a verbatim excerpt of the official chapter text and a rationale argued from it, and as of 2026-08-14 the second independent formalization required by execution plan §5.3.5.5 has been carried out and adjudicated. The second pass was blind: it read the pack id, the sourceNorm and each entry's provenance.article, sourceUrl, retrievalUrl and quote, and nothing else. Agreement between two independent passes is what makes a formalization evidence, and there are now two; every divergence is recorded with its decision in the entry's `changeNote`. Human review is still pending. Certificates issued against this pack, if any, carry a draft-basis notice.",
    "Primary source and quote verification method. The three chapter documents were downloaded on 2026-08-14 from the European Commission newsroom endpoints linked from the Code's official landing page at https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai — Transparency https://ec.europa.eu/newsroom/dae/redirection/document/118120, Copyright https://ec.europa.eu/newsroom/dae/redirection/document/118115, Safety and Security https://ec.europa.eu/newsroom/dae/redirection/document/118119. Each PDF was converted to text locally with layout preservation and every `provenance.quote` was copied out of that extraction, character for character, with elisions marked […]. No commentary, summary, mirror or law-firm note was used as a source for any quote. Where a quote spans more than one Measure, a bracketed citation such as [Measure 1.1] precedes each excerpt; everything outside brackets is verbatim.",
    "Legal status — stated precisely, and not more strongly than the instruments allow. The Code is voluntary in form. Its effect runs through Article 56 AI Act, which has the AI Office encourage and facilitate codes of practice covering at least the obligations in Articles 53 and 55, and through the reliance clauses: Article 53(4) AI Act provides that providers of general-purpose AI models 'may rely on codes of practice within the meaning of Article 56 to demonstrate compliance with the obligations set out in paragraph 1 of this Article, until a harmonised standard is published', and Article 55(2) provides the same for providers of models with systemic risk in relation to Article 55(1). Both clauses add that providers who neither adhere to an approved code nor comply with a European harmonised standard 'shall demonstrate alternative adequate means of compliance for assessment by the Commission'. Adherence is therefore a route to demonstrating compliance and the absence of adherence shifts a demonstrative burden — it is not a presumption of conformity, which those same clauses reserve to European harmonised standards. The Code says the same of itself: its Objectives clause commits it 'to serve as a guiding document for demonstrating compliance with the obligations provided for in Articles 53 and 55 AI Act, while recognising that adherence to the Code does not constitute conclusive evidence of compliance with these obligations under the AI Act', and the Copyright Chapter's recital (a) adds that 'adherence to the Code does not constitute compliance with Union law on copyright and related rights'. The 'quasi-mandatory' shorthand used in the AIO pack roster should be read as this and nothing more.",
    "Publication and signatory context, as verified on 2026-08-14 against the Commission's own page. The final Code was published on 10 July 2025 in three chapters — Transparency, Copyright, and Safety and Security. The Commission and the AI Board confirmed the Code as an adequate voluntary tool for providers to demonstrate compliance. The signatory list published at https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai, last updated on that page 31 July 2026, names 21 organisations — AI Studio Delta, Aleph Alpha, Almawave, Amazon, Anthropic, Black Forest Labs, Bria AI, Cohere, Domyn, Dweve, Fastweb, Google, IBM, LINAGORA, Microsoft, Mistral AI, Open Hippo, OpenAI, Pleias, ServiceNow and WRITER — plus xAI, which signed the Safety and Security Chapter only and must demonstrate compliance with the transparency and copyright obligations by other means. Signatories established a Signatory Taskforce chaired by the AI Office, which first met on 30 January 2026. The signatory list changes; anyone relying on it should re-check the Commission page rather than this note. Not every major model provider has signed, and non-signature is not non-compliance: Articles 53(4) and 55(2) expressly leave the alternative-adequate-means route open.",
    "Relation to the eu-ai-act pack. The two packs are complementary and address different duty-bearers. eu-ai-act formalizes provisions of Regulation (EU) 2024/1689 addressed to providers and deployers of high-risk AI systems (Articles 9, 12, 13, 14, 15, 26 and 72). This pack formalizes the Code's Commitments and Measures, which are addressed to providers of general-purpose AI models, and — for the Safety and Security Chapter — only to providers of general-purpose AI models with systemic risk. An organisation may fall under both, one, or neither. A measurement against one pack says nothing about the other, and the two packs are not additive into any combined claim.",
    "Selection. Ten of the Code's Commitments and Measures are mapped: all three Transparency Measures (1.1 and 1.3 as a composite records entry, 1.2 separately); Copyright Measures 1.1, 1.3 and 1.5; and Safety and Security Commitment 1 (Measures 1.1–1.3), Measure 3.2, Measures 4.1–4.2, Measure 7.2 and Commitment 9 (Measures 9.2–9.3). They were chosen for having a clear normative direction that an item could be written against. Not mapped, and therefore outside this pack in every respect: Copyright Measures 1.2 and 1.4; Safety and Security Commitments 2, 5, 6, 8 and 10, Measures 3.1, 3.3, 3.4, 3.5, 6.1, 6.2, 7.1, 7.3–7.7, 8.1–8.3, 9.1 and 9.4, and Appendices 1–4. Several of those — the security mitigations of Commitment 6, the responsibility allocation of Commitment 8, the external-evaluator access regime of Measure 3.5 — carry substantial management-system weight and are covered in the management-system guide at docs/management-guides/eu-gpai-code.{ko,en}.md, which deliberately reaches wider than this pack.",
    "No item bank exists for this pack. itemBankRef.publicSet is null, so this pack backs no certificate at any tier until a bank is built and the pack has reached at least draft-verified. [갱신 2026-08-15: 이중 관문 문항 뱅크 개통 — 관문 A 공개 세트 + 관문 B 비공개 뱅크(서명 커밋먼트 게시). 이 노트의 이전 서술은 개통 전 기록이다.]",
    "Methodology for the Commitment/Measure → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. Codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary. The v0.2 adjudication tightened this pack more than any other in Wave 1, and the reason is one recurring defect in v0.1: seven of the ten entries carried codes grounded in the Chapter Appendices, the Objectives clause, the Glossary or the AI Act articles rather than in the quoted Measure. Under §4 the provision is coded, not its surroundings, so those codes were removed — Sep and Unc from Safety and Security Commitment 1, Measure 3.2, Measures 4.1–4.2 and Commitment 9; Pro from Measure 3.2 and Measure 7.2; Gov from Commitment 1, Measures 4.1–4.2 and Measure 7.2. Two inference-grade assignments survive, both because the two passes reached them independently and both flagged in their entries: `Pro` in Copyright Measure 1.3 and 1.5, and `Ind` wherever the Signatory is the unilateral author of the artefact the Measure requires. The `Ind` assignment no longer rests on the Chapter Glossary's definition of 'state-of-the-art', which was itself outside the quoted text; it rests on the Wave 1 source-axis rule recorded below.",
    "AIO certifies conformance to AIO's own formalization of the Code. This is not a legal conformity assessment, not an assessment of adherence to the Code, not a notified-body procedure, and it confers no presumption of conformity under Regulation (EU) 2024/1689. The European Commission, the AI Office and the AI Board took no part in this formalization, have not reviewed or endorsed it, and it is not an official interpretation of the Code.",
    "Reuse. Commission documents are reusable under the Commission's reuse policy (Decision 2011/833/EU; the current notice on commission.europa.eu places Commission content under CC BY 4.0). Verbatim excerpts here are quoted with attribution to the European Commission and to the specific chapter and Measure. This pack is a derivative reading and is not endorsed by the Commission.",
    "Adjudication method (v0.2). The pack was formalized twice — the v0.1 seed pass and a blind second pass — and the two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under a fixed policy: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken (fewer codes, or a layer left undeclared); the intersection of the two readings is an allowed outcome where it is non-empty and defensible; no third reading is invented. Agreement statistics for this pack, across ten entries: V 0/10, E 6/10, S 4/10, obligationType 8/10, all four axes together 0/10. No entry in this pack agreed on all four axes — the only Wave 1 pack of which that is true — and the value axis agreed nowhere. Read with the note above, that is a finding about v0.1's method rather than about the Code: the two readers disagreed because one of them was coding the Appendices.",
    "Contamination notice. One axis of the second pass was not blind. The pack-authoring guideline §2.3 names Copyright Measure 1.3 as the Wave 1 example of a text that designates a standardisation body and may therefore carry `Pro`, and the second formalizer had read that section. The source axis of that entry was accordingly adjudicated on the quoted words alone — which do name the IETF, RFC 9309 and 'international or European standardisation organisations' — and the second pass's concurrence was not treated as independent corroboration. The notice is repeated in that entry's changeNote. No other axis of this pack was disclosed; in particular this pack's obligationType distribution was not published in the guideline, unlike those of the NIST and Chinese packs.",
    "Source-axis policy (P4, decided once across the Wave 1 packs and applied uniformly). S=`Gov` is declared only where the quoted excerpt itself names the governmental authority or the legal instrument that is decisive on the substance of the duty — the AI Act at Transparency Measures 1.1–1.3 and 1.2, Union copyright law and Directive (EU) 2019/790 in the Copyright Chapter, the AI Office at Commitment 9. It is never carried in from an AI Act article the Chapter operates under but the excerpt does not cite, which is why the Safety and Security entries for Commitment 1, Measure 3.2, Measures 4.1–4.2 and Measure 7.2 no longer carry it. S=`Ind` is declared where the quoted excerpt makes the Signatory the unilateral author of the operative artefact — the Model Documentation, the copyright policy, the Framework, the evaluations, the acceptance criteria, the Model Report, the incident report. The same rule was applied to all five Wave 1 packs and is recorded in each. One open question travels with it, raised by the second pass and carried to RFC: at Commitment 9 the AI Office is the ADDRESSEE of a report rather than a source whose position is to be trusted, and whether the S axis should carry addressee relations at all is unresolved.",
    "Vocabulary gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes four, and it is the richest source of them in Wave 1. (1) EXPRESSLY PRESERVED COUNTER-INTERESTS — Transparency Measure 1.2 qualifies its disclosure duty by the need to protect intellectual property, confidential business information and trade secrets. The `v` array records what a provision expects to PREVAIL, so an interest the provision preserves AGAINST the duty cannot be expressed at all; the second pass's `Por` was dropped for that reason. This is a schema question, not only a vocabulary one. (2) STANDARDS-DEVELOPMENT BODIES AND REPRESENTATIVE ORGANISATIONS — `Pro` is defined as the collective position of the field's own credentialed practitioners, and it is being made to carry the IETF and the European standardisation organisations at Copyright Measure 1.3 and collective management organisations at Measure 1.5. Both passes used it; it is kept with flags in both entries. (3) AFFECTED PARTIES AS A SOURCE CLASS — the rightsholder who lodges a substantiated complaint under Measure 1.5 fits neither `Usr` (the requester of the service) nor `Tes` (a sworn named eyewitness); v0.1's `Tes` was removed. The same gap is recorded at Arts. 14 and 16 of the Council of Europe pack and 第十五条 of the Chinese pack. (4) STRUCTURED PERIODIC SELF-ASSESSMENT — the twelve-month Framework assessment of Safety and Security Measure 1.3 has no evidence code: `Rev` means a synthesis pooling many separate studies, `Gui` records only that a procedure exists. v0.1's `Rev` was removed as a misapplication. The consolidated Wave 1 list is reproduced in the adjudication report."
  ]
}