{
  "$schema": "./schema.json",
  "id": "g7-hiroshima-code",
  "name": {
    "en": "G7 Hiroshima Process International Code of Conduct — AIO formalization",
    "ko": "G7 히로시마 프로세스 국제 행동규범 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems",
    "publisher": "Group of Seven (G7) — Hiroshima AI Process",
    "version": "Adopted by G7 Leaders on 30 October 2023; unrevised as at 2026-08-14",
    "url": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf"
  },
  "vesMapping": [
    {
      "article": "Action 1",
      "summary": "Organizations are called on to take appropriate measures throughout development, including prior to and throughout deployment and placement on the market, to identify, evaluate and mitigate risks across the AI lifecycle — employing internal and independent external testing such as red-teaming, and devoting attention as appropriate to an enumerated risk list that runs from chemical, biological, radiological and nuclear risks through offensive cyber capability, health and safety, self-replication, societal risks including harmful bias and discrimination, and threats to democratic values and human rights.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The judgment correlate an item can reach is narrow but real: when one of the enumerated risks is in play, whether the risk is treated as a thing to be identified and mitigated rather than traded against capability or release timing. The testing regime itself — running red-team exercises at checkpoints, commissioning independent external testers, keeping technical documentation regularly updated — is organizational and no item observes it. Note also that the action is framed as a call on organizations, not a duty: the Code is voluntary guidance throughout.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 1, heading and the risk-attention list under it",
        "quote": "Take appropriate measures throughout the development of advanced AI systems, including prior to and throughout their deployment and placement on the market, to identify, evaluate, and mitigate risks across the AI lifecycle. […] organizations commit to devote attention to the following risks as appropriate: […] Risks to health and/or Safety […] Societal risks, as well as risks to individuals and communities […]",
        "rationale": "The protected interests are enumerated in the action's own risk list rather than inferred: risks to health and safety and risks to individuals give Sep; societal risks together with the chain-reaction risk the list closes on — an event affecting 'up to an entire city, an entire domain activity or an entire community' — give Ses; and the list's harmful-bias-and-discrimination and human-rights limbs give Unc. What discharges the action is testing: the body requires 'diverse internal and independent external testing measures, through a combination of methods for evaluations, such as red-teaming', which is measurement against the system under test (Dat), and it requires that 'These measures should be documented and supported by regularly updated technical documentation' (Gui). The testing is not a single pre-release gate: the body asks that it be performed \"at several checkpoints throughout the AI lifecycle\", and developers are separately asked to \"seek to enable\" traceability in relation to datasets, processes and decisions made during system development. The only source class the action designates is the developing organization itself (Ind). The body does call for 'independent external testing measures', but it names no class of body that performs them — no professional association, no auditor, no regulator — so Pro, Pee and Gov are all withheld. That withholding is deliberate and is the first thing this entry should be asked about at RFC: the action clearly contemplates an external check whose source class the text never fixes. ADJUDICATION 2026-08-14: S ([Ind]) agreed exactly — the identifying and evaluating party is the developing organization itself, which is the Ind limb of the source-axis rule. V narrows to the intersection [Sep, Ses], the two interests the risk list names in terms ('Risks to health and/or Safety'; 'Societal risks, as well as risks to individuals and communities'); Unc rests on v0.1 alone. E is emptied: the second pass recorded an INSUFFICIENT-QUOTE finding — 'appropriate measures' and 'identify, evaluate' name no evidential form, and assigning Gui or Dat would be guessing at a method the quoted text does not state — and the conservative reading prevails on an empty intersection. That leaves the Code's central risk-management action with no declared evidence class and no external source class, which is the honest reading of an action that calls for 'independent external testing measures' without naming any class of body that performs them. obligationType is lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S agreed exactly. V [Sep, Ses, Unc] → [Sep, Ses]; E [Dat, Gui] → []; obligationType mixed → organizational. The empty evidence layer is deliberate: the action prescribes no artefact, metric or document, and the second pass declined to fill the layer on that ground."
    },
    {
      "article": "Action 2",
      "summary": "Organizations are called on to identify and mitigate vulnerabilities and, where appropriate, incidents and patterns of misuse after deployment including placement on the market — monitoring for vulnerabilities, incidents, emerging risks and misuse, taking appropriate action to address them, and being encouraged to facilitate third-party and user discovery and reporting of issues through mechanisms such as bounty systems.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [
        "Tri"
      ],
      "s": [
        "Usr"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The hedges in this action are unusually dense — 'where appropriate' governs the incidents and misuse limb, 'as and when appropriate commensurate to the level of risk' governs the monitoring limb, and the reporting-channel limb is only 'encouraged'. Nothing in the mapping should be read past those hedges. What an item can reach is the disposition toward an outside report of a weakness or a misuse pattern: whether it is treated as something to act on or as something to discount because of who raised it. Operating a disclosure programme, maintaining incident documentation and running the remediation are organizational — and the body expects that remediation to happen \"in collaboration with other stakeholders\", which no measurement of a single model reaches.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 2, heading and body",
        "quote": "Identify and mitigate vulnerabilities, and, where appropriate, incidents and patterns of misuse, after deployment including placement on the market. […] monitor for vulnerabilities, incidents, emerging risks and misuse after deployment, and take appropriate action to address these. Organizations are encouraged to consider, for example, facilitating third-party and user discovery and reporting of issues and vulnerabilities after deployment […]",
        "rationale": "The action is about what happens after release, and the interests it protects follow from what it asks to be caught: vulnerabilities and misuse of a deployed system, which reach the people exposed to it (Sep) and the security of the wider environment the system now sits in (Ses). Bed is grounded in the action's second half — undertaking to receive reports of weaknesses and 'take appropriate action to address these' is a commitment kept toward those who rely on the system, not a metric met. Two evidence classes are decisive and they divide cleanly: the operator's own post-deployment monitoring produces an accumulated operational record (Dat), while 'third-party and user discovery and reporting of issues and vulnerabilities' is by construction the firsthand account of somebody who ran into the problem (Tri). The source classes track the same split — the organization's own monitoring (Ind) and the reporting user or third party (Usr). Gov is withheld: unlike Action 4, this action names no public authority as a recipient. Pro is withheld: bounty programmes, contests and prizes are not a professional body. ADJUDICATION 2026-08-14: V narrows to the intersection [Sep, Ses]; Bed rests on v0.1 alone. E narrows to [Tri] and S to [Usr], both of which the second pass reached independently from the same sentence — 'facilitating third-party and user discovery and reporting of issues and vulnerabilities' — and both of which it held at illustrative strength, recording that the sentence arrives as 'Organizations are encouraged to consider, for example, …', a doubly softened illustration rather than a designated intake obligation. That hedge discipline is adopted: Tri and Usr record what the text points at, and neither may be read as a required evidence route. Ind is dropped: the material this action makes decisive is the outside reporter's account, not anything the organization issues, so the Ind limb is not met here even though the organization is the duty-bearer. obligationType is lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Ses, Bed] → [Sep, Ses]; E [Dat, Tri] → [Tri]; S [Ind, Usr] → [Usr]; obligationType mixed → organizational. This is the only entry in the pack that does not carry Ind, and the reason is textual: what the action designates as decisive is a report from outside the organization."
    },
    {
      "article": "Action 3",
      "summary": "Organizations are called on to publicly report advanced AI systems' capabilities, limitations and domains of appropriate and inappropriate use, publishing transparency reports for all new significant releases that cover the evaluations conducted, the significant limitations in performance bearing on appropriate use, the assessed effects and risks to safety and society, and red-teaming results — kept clear enough for deployers and users to interpret the output and use it appropriately.",
      "v": [
        "Hum",
        "Sdt",
        "Bed"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The strongest behavioral correlate in the pack. Reporting 'significant limitations in performance' is a per-case epistemic disclosure with a direct judgment analogue — whether a model states the limits of what it can do in the situation in front of it, or lets an overstated capability stand. The publication programme around it (transparency reports per significant release, kept up to date, supported by documentation processes) is organizational. This action is also the one for which the OECD HAIP Reporting Framework supplies a concrete public vehicle; see the pack notes.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 3, heading and body",
        "quote": "Publicly report advanced AI systems’ capabilities, limitations and domains of appropriate and inappropriate use, to support ensuring sufficient transparency, thereby contributing to increase accountability. […] Capacities of a model/system and significant limitations in performance that have implications for the domains of appropriate use […] to interpret the model/system’s output and to enable users to use it appropriately",
        "rationale": "Two things are asked for at once and they carry different values. Reporting 'significant limitations in performance' alongside capacities is the recognition of one's own limits made a publication duty (Hum) — the action puts limitations in the heading, before capabilities in the body list, and does not let a capability claim stand alone. The stated purpose of making the report understandable is to let deployers and users 'interpret the model/system’s output and to enable users to use it appropriately', that is, to equip the reader to judge rather than to judge for them (Sdt), and publishing for every 'new significant release' is a standing commitment owed to those readers (Bed). What discharges it is the evaluation record — the body requires details of the evaluations conducted and 'the results of red-teaming conducted to evaluate the model’s/system’s fitness for moving beyond the development stage' (Dat) — carried in a document, since the action says the reporting 'should be supported and informed by robust documentation processes such as technical documentation and instructions for use', and asks that the reports, instructions for use and technical documentation \"be kept up-to-date\" (Gui). The publishing party is the organization itself (Ind); no reviewer, auditor or authority is designated as the source that makes the report credible, which is precisely the gap the OECD reporting framework was later built to address. ADJUDICATION 2026-08-14: V ([Hum, Sdt, Bed]), E ([Dat, Gui]) and S ([Ind]) agreed exactly across the two independent passes — the strongest agreement in this pack, and the only three-axis agreement in it. The second pass flagged Dat as following from the structure of a claim about 'significant limitations in performance' rather than from any declared metric; v0.1 reached it independently, so it survives with the flag. obligationType is lowered from mixed to organizational: what the action requires is a published transparency report per significant release, which is a publication programme.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V, E and S agreed exactly and are auto-accepted; no code changed. obligationType mixed → organizational under the conservative rule. v0.1's note calls this the strongest behavioral correlate in the pack, and that remains true of the judgment an item can test; it is not true of the shape of the duty, which is discharged by publishing a report."
    },
    {
      "article": "Action 4",
      "summary": "Organizations are called on to work towards responsible information sharing and reporting of incidents among organizations developing advanced AI systems and with industry, governments, civil society and academia — sharing evaluation reports, security and safety risk information, dangerous intended or unintended capabilities and attempts to circumvent safeguards, collaborating with relevant public authorities as appropriate, and safeguarding intellectual property rights in doing so.",
      "v": [
        "Ses",
        "Sep"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This action contains the Code's only explicit counterweight to disclosure — 'Such reporting should safeguard intellectual property rights' — and the pack deliberately assigns no value code to that limb. Coding it (Por, say, for resource protection) would put the protection of a firm's commercial assets into a value hierarchy as something that must prevail, which overreads a sentence that bounds how sharing is done rather than stating an interest the action protects. The limb is recorded here instead and is put to the RFC round. What an item can reach is the disposition to pass on a safety-relevant finding — including an unflattering one — rather than withhold it; establishing sharing mechanisms and joining them is organizational.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 4, heading and body",
        "quote": "Work towards responsible information sharing and reporting of incidents among organizations developing advanced AI systems including with industry, governments, civil society, and academia […] including, but not limited to evaluation reports, information on security and safety risks, dangerous intended or unintended capabilities […] Organizations should also collaborate and share the aforementioned information with relevant public authorities, as appropriate. Such reporting should safeguard intellectual property rights.",
        "rationale": "What the sharing is for fixes the values: 'security and safety risks' and 'dangerous intended or unintended capabilities' are risks that do not stop at the sharing organization's own users, so the interests are the security of the field and the wider environment (Ses) and the safety of the people a dangerous capability would reach (Sep). Bed carries the action's distinctive demand — sharing a finding that is against your own interest is a commitment to peers and to the public authorities kept at a cost, and the action's operative verb is 'work towards' precisely because the drafters knew it would be. The evidence classes are named in the text: 'evaluation reports' are the accumulated measurement record (Dat), and the action separately asks organizations to 'establish or join mechanisms to develop, advance, and adopt, where appropriate, shared standards, tools, mechanisms, and best practices', which is the established written standard procedure (Gui). Two source classes are designated. Ind covers the peer organizations and industry the heading names as sharing partners. Gov is assigned because the body does not leave authorities as one audience among several: it directs that organizations 'collaborate and share the aforementioned information with relevant public authorities', which is the pattern the EU AI Act pack coded Gov for at Art. 26(5). Pee is deliberately WITHHELD even though 'academia' appears in the heading: academia is named as a party information flows to, not as a source whose position is decisive on any question, and the distinction is exactly the one FORMALIZATION_METHODOLOGY.md § 4 draws for S codes. ADJUDICATION 2026-08-14: E ([Dat, Gui]) agreed exactly. V narrows to the intersection [Ses, Sep]. The second pass additionally coded Por for the closing clause 'Such reporting should safeguard intellectual property rights'; that code is not carried, and the ground is the one settled in Wave 1 on the EU GPAI pack — the `v` array records what a provision expects to PREVAIL, so an interest a provision preserves AGAINST its own duty cannot be expressed in it (Wave 1 gap 9). v0.1 had reached the same conclusion independently and recorded the limb without coding it, which is now corroborated rather than a lone judgment call. S is the decisive change: **both passes declared Gov and Gov is nonetheless removed**, under the source-axis ruling settled in this wave that a government body named only as the recipient of shared information does not thereby become a source to be trusted. 'Organizations should also collaborate and share the aforementioned information with relevant public authorities' names public authorities as counterparties to an exchange, and the second pass had itself recorded that the parallel naming of 'academia' designates a recipient rather than a peer-reviewed source and withheld Pee for exactly that reason; the same reasoning applied to governments removes Gov. Ind survives on the Ind limb — the shared evaluation reports are the organization's own. obligationType is lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E agreed exactly. V [Ses, Sep, Bed] → [Ses, Sep], and the second pass's Por for the intellectual-property clause is not carried. S [Ind, Gov] → [Ind]: Gov is removed although both passes declared it, under the new recipient-is-not-a-source rule. obligationType mixed → organizational. The second pass's finding that 'civil society' is a designated counterparty with no corresponding source class is recorded as Wave 2 gap 22."
    },
    {
      "article": "Action 5",
      "summary": "Organizations are called on to develop, implement and disclose AI governance and risk management policies grounded in a risk-based approach — including privacy policies covering personal data, user prompts and system outputs — to put accountability and governance processes in place to identify, assess, prevent and address risks across the AI lifecycle, to update those policies regularly, and to establish policies, procedures and training so that staff are familiar with their duties and the organization's risk management practices.",
      "v": [
        "Cor",
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Outside what an AIO 20002 record can supply, and the clearest organizational action in the Code: policies developed, disclosed and implemented; governance mechanisms established; staff trained. No item observes any of it. It is in the pack because it is the anchor the rest of the Code resolves against — the risk-based approach that Actions 1, 2 and 5 all invoke has no content until an organization has set the policies this action requires, and the preamble's encouragement to 'set up internal AI governance structures and policies, including self-assessment mechanisms' points at the same place. The corresponding management-system expectations are the subject of the accompanying guide.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 5, heading and body",
        "quote": "Develop, implement and disclose AI governance and risk management policies, grounded in a risk-based approach – including privacy policies, and mitigation measures. […] This includes disclosing where appropriate privacy policies, including for personal data, user prompts and advanced AI system outputs. […] Organizations should establish policies, procedures, and training to ensure that staff are familiar with their duties and the organization’s risk management practices",
        "rationale": "The action's operative demand is that conduct be governed by policies the organization has set and published, and that staff know their duties under them — adherence to an established internal rule set, which is Cor as the AIO 00011 vocabulary defines its lead behaviour (does not act beyond what the rules permit). Ses carries what the risk management exists for: the governance processes are to 'identify, assess, prevent, and address risks, where feasible throughout the AI lifecycle', which is collective risk exposure rather than any single user's interest. Bed carries the disclosure limb — the action is not satisfied by having policies but by disclosing them, which is an undertaking made to outsiders who then rely on it. Only one evidence class is assigned. Written policies, procedures and training are the paradigm case of an established written standard procedure (Gui), and Dat is deliberately WITHHELD: the action requires a risk-based approach and a risk management framework but names no metric, threshold or measurement that would discharge it, and reading measurement in would make the mapping uncheckable against the words. The only designated source is the organization whose policies these are (Ind); the Code is voluntary and self-applied, so no authority approves them. Note that the two manifestations of the Code differ typographically in this action's body ('risk-based' in the Japanese G7 presidency PDF, 'risk based' in the European Commission copy); the quoted sentences above are identical in both. ADJUDICATION 2026-08-14: E ([Gui]), S ([Ind]) and obligationType (organizational) agreed exactly. V narrows to the intersection [Cor, Bed] — compliance with formal internal rule and reliable discharge of assigned duties, which is what 'policies, procedures, and training' and staff familiarity 'with their duties' name. The divergent codes are a single disagreement about the privacy limb: v0.1 read the action's governance object as serving collective order (Ses), the second pass read 'privacy policies, including for personal data, user prompts and advanced AI system outputs' as personal security (Sep) while flagging that the text names the policy object and not the interest it serves. Neither is carried, and the divergence is recorded as another instance of Wave 1 gap 2, privacy having no code of its own.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E, S and obligationType agreed exactly. V [Cor, Ses, Bed] → [Cor, Bed]. The two passes chose different codes for the same privacy limb (Ses against Sep); neither is carried and the gap is recorded."
    },
    {
      "article": "Action 6",
      "summary": "Organizations are called on to invest in and implement robust security controls across the AI lifecycle — physical security, cybersecurity and insider threat safeguards — including securing model weights, algorithms, servers and datasets, storing and working with model weights in an appropriately secure environment with limited access to reduce the risk of unsanctioned release and unauthorized access, maintaining a vulnerability management process, and establishing an insider threat detection program.",
      "v": [
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Almost entirely organizational: investing in controls, running an insider threat programme, and maintaining a vulnerability management process are things an organization does, and no item observes them. It is tagged `mixed` rather than `organizational` for one narrow reason — the access discipline has a per-case correlate an item can test, namely whether a request to work around an access control, move weights out of a controlled environment, or make an exception 'just this once' is refused. That correlate is the whole of what a measurement against this action reaches.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 6, heading and body",
        "quote": "Invest in and implement robust security controls, including physical security, cybersecurity and insider threat safeguards across the AI lifecycle. […] Organizations should also have in place measures to require storing and working with the model weights of advanced AI systems in an appropriately secure environment with limited access to reduce both the risk of unsanctioned release and the risk of unauthorized access.",
        "rationale": "The harm the action is written against is the escape of a capability rather than an injury to a named person: 'unsanctioned release' and 'unauthorized access' to model weights are risks to the security of the environment the system sits in (Ses). Cor is the operative value on the conduct side — the controls work by fixing what access is permitted and requiring that nobody act outside it, which is the lead behaviour of Cor exactly. Sep is deliberately WITHHELD: the action names no harm to persons anywhere in its text, and the personal-safety interest that a leaked capability might ultimately reach is stated in Action 1's risk list, not here. Por is likewise withheld: the action mentions an organization's 'most valuable intellectual property and trade secrets', but only as the benchmark for how strong the insider-threat programme should be, not as an interest the action protects. What discharges it is a written control regime — 'implementing cybersecurity policies and adequate technical and institutional solutions', a vulnerability management process, and a commitment to \"regularly review security measures to ensure they are maintained to a high standard and remain suitable to address risks\" (Gui). Dat is withheld: the body calls for 'an assessment of cybersecurity risks' but names no measurement or metric that would settle it. The organization implementing the controls is the only designated source (Ind); no certification body, auditor or standard is named in this action, which is a notable absence for a security provision and is put to the RFC round. ADJUDICATION 2026-08-14: E ([Gui]) and S ([Ind]) agreed exactly, the second pass noting that Gui here follows from the structure of a limited-access requirement rather than from named words. V narrows to [Ses], the one code both passes reached; Cor rests on v0.1 alone, and the second pass's Sep and Por on the second pass alone — Por again for a developer-side asset (model weights held under custody), which is not carried for the reason given at Action 4. obligationType is lowered to organizational. v0.1 had tagged the action `mixed` for one narrow reason, that a request to work around an access control has a per-case correlate; that correlate is real and is why the entry is worth an item, but the action's own demand is discharged by investing in and operating controls, and the second pass classified it organizational without qualification.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and S agreed exactly. V [Ses, Cor] → [Ses]; obligationType mixed → organizational. The second pass's Sep and Por are not carried; Por is the third proposal in this wave to code a developer-side interest as a value that must prevail, and all three are refused on the Wave 1 gap 9 reasoning."
    },
    {
      "article": "Action 7",
      "summary": "Organizations are called on to develop and deploy reliable content authentication and provenance mechanisms where technically feasible — such as watermarking — so that users can identify AI-generated content, with provenance data including an identifier of the service or model that created the content but not needing to include user information, and are further encouraged to implement labeling or disclaimers so users can know when they are interacting with an AI system.",
      "v": [
        "Sdt",
        "Ses"
      ],
      "e": [],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The mechanism — watermarking, provenance metadata, a detection API — is a system capability that neither an AIO 20002 record nor an item supplies. The behavioral correlate an item can reach is the disclosure disposition next to it: whether AI authorship is acknowledged when it is material and asked about, or whether the question is deflected. Note the double hedge on the mechanism limb ('where technically feasible', then 'where appropriate and technically feasible' in the body) and the fact that the labeling limb is only 'encouraged'; the rationale below stays inside both.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 7, heading and body",
        "quote": "Develop and deploy reliable content authentication and provenance mechanisms, where technically feasible, such as watermarking or other techniques to enable users to identify AI-generated content […] The provenance data should include an identifier of the service or model that created the content, but need not include user information. […] to know when they are interacting with an AI system.",
        "rationale": "The purpose clause is in the heading and it is unambiguous: the mechanisms exist 'to enable users to identify AI-generated content', and the body extends that to enabling users 'to know when they are interacting with an AI system'. Both put the user in a position to work out for themselves what they are dealing with rather than take the presentation at face value, which is Sdt. Ses is assigned by INFERENCE and flagged as such: the reason a provenance regime matters at population scale is the integrity of the shared information environment, and the Code's preamble names disinformation among the risks, but this action does not say so in its own words and the point is put to the RFC round. Two evidence classes discharge it. The mechanism is expected to follow an established technique — the action names watermarking, and Action 10 sends the same subject matter to standards development organizations (Gui) — and what actually travels with the content is a machine-readable record, since \"The provenance data should include an identifier of the service or model that created the content\" (Dat). The emitting party is the organization whose system created the content (Ind). No verifier is designated: the action asks organizations to 'develop tools or APIs to allow users to determine if particular content was created with their advanced AI system', which leaves the organization as both author and checker of its own provenance claim — a structural gap worth raising at RFC. The clause 'but need not include user information' is a permissive privacy floor rather than a protective duty, so no value code is read from it. ADJUDICATION 2026-08-14: S ([Ind]) and obligationType (mixed) agreed exactly, and this is the only entry in the pack that both passes classified `mixed`, because the disclosure lands in the concrete interaction while the mechanism behind it is built. V narrows to the intersection [Sdt, Ses]; the second pass's Sep, read from the express limit that provenance data 'need not include user information', rests on one pass. Ses survives as corroborated rather than inferred: v0.1 had flagged it as the pack's single structural inference, read from the population-scale purpose of a content-provenance regime, and the blind second pass reached it independently. E is emptied, and the emptiness is the pack's sharpest finding. Both passes recorded the same reason — the discharge here is a machine-embedded provenance signal, a watermark or content credential carrying 'an identifier of the service or model that created the content', and none of the ten evidence codes covers an interaction-time technical marker: it is not a written procedure (Gui), not a body of measured numbers (Dat), and not anyone's judgment (Exp). v0.1's [Gui, Dat] is withdrawn rather than kept as a near-fit, and the gap is recorded (Wave 2 gap 20).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S and obligationType agreed exactly; this is the pack's only surviving `mixed` entry. V [Sdt, Ses] retained against the second pass's [Sdt, Ses, Sep]; E [Gui, Dat] → []. Ses is no longer an inference — the blind second pass reached it independently, which discharges v0.1 note 9. The empty evidence layer records a catalogue gap rather than a failure to read."
    },
    {
      "article": "Action 10",
      "summary": "Organizations are encouraged to contribute to the development and, where appropriate, the use of international technical standards and best practices — including for watermarking — working with Standards Development Organizations across testing methodologies, content authentication and provenance mechanisms, cybersecurity policies and public reporting, and to work toward interoperable international standards and frameworks that help users distinguish AI-generated from non-AI-generated content.",
      "v": [
        "Cor",
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Pro",
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The weakest modality in the pack — the action is stated entirely as encouragement ('are encouraged to', twice), and nothing here is even a soft duty. It is included for one substantive reason: it is the only action in the Code that designates an external body whose position counts, and it is therefore the only place the source hierarchy reaches past the organization itself. The judgment correlate is narrow but testable: choosing an interoperable international standard over a bespoke in-house approach where both would work. Contributing to standards development, and joining SDO processes, is organizational.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 10, heading and body",
        "quote": "Advance the development of and, where appropriate, adoption of international technical standards […] Organizations are encouraged to contribute to the development and, where appropriate, use of international technical standards and best practices, including for watermarking, and working with Standards Development Organizations (SDOs) […] to help users distinguish content generated by AI from non-AI generated content.",
        "rationale": "Cor is grounded in the adoption limb: using an international technical standard rather than an idiosyncratic internal approach is conformity to an external rule set, which is what Cor codes. Sdt is grounded in the action's closing purpose clause — interoperable standards exist 'to help users distinguish content generated by AI from non-AI generated content', that is, to leave the determination with the user. Ses is deliberately WITHHELD here and left to Action 7, which is where the information-environment interest was already read in by inference; assigning it twice would double-count one inference. What discharges the action is a technical standard or a best practice, which is the established written standard procedure in its purest form (Gui). The source hierarchy is where this entry earns its place: 'Standards Development Organizations (SDOs)' are named in the text, and an SDO is the collective position of a field's own credentialed practitioners, so Pro is assigned on the text's own words — the same test the EU GPAI Code pack applied at Copyright Measure 1.3. Ind is retained for the organization that contributes to and adopts the standard. Gov is withheld: the action names no regulator, and international technical standards are not the position of a governing authority. ADJUDICATION 2026-08-14: V ([Cor, Sdt]), E ([Gui]) and S ([Pro, Ind]) agreed exactly across the two independent passes. Pro survives on the express naming of 'Standards Development Organizations (SDOs)', which clears the §4 bar against unnamed professional bodies, and both passes recorded the same misfit — an SDO is a multi-stakeholder standards body rather than an association of credentialed practitioners — which is the Wave 1 gap 8 pattern established on the EU GPAI pack at Copyright Measure 1.3. It is kept with the flag because both passes reached it. Both passes also read the modality the same way: this is the weakest obligation in the extracted set, stated as encouragement twice over, and neither Cor nor Gui may be read as an adoption mandate. obligationType is lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V, E and S agreed exactly and are auto-accepted; no code changed. obligationType mixed → organizational. Pro is kept with its Wave 1 gap 8 flag: both independent passes reached it from the express naming of SDOs, and both recorded that the catalogue's professional-body definition does not fit a multi-stakeholder standards organisation."
    },
    {
      "article": "Action 11",
      "summary": "Organizations are encouraged to implement appropriate data input measures and protections for personal data and intellectual property — managing data quality including training data and data collection so as to mitigate against harmful biases, using measures that could include transparency, privacy-preserving training techniques and testing and fine-tuning so that systems do not divulge confidential or sensitive data, implementing safeguards to respect rights related to privacy and intellectual property including copyright-protected content, and complying with applicable legal frameworks.",
      "v": [
        "Unc",
        "Cor"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Ind",
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Strong behavioral correlates on two limbs an item can reach directly: not divulging confidential or sensitive data when a request would draw it out, and respecting copyright-protected content rather than reproducing it on request. The upstream limbs — data collection practice, training-data curation, privacy-preserving training techniques — are engineering and organizational choices no item observes. The action is stated entirely as encouragement apart from its last sentence, which is the only place in the whole Code where the modality hardens to 'should also comply'.",
      "provenance": {
        "sourceUrl": "https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/99641",
        "article": "Action 11, heading and body",
        "quote": "Implement appropriate data input measures and protections for personal data and intellectual property […] Organizations are encouraged to take appropriate measures to manage data quality, including training data and data collection, to mitigate against harmful biases. […] Organizations are encouraged to implement appropriate safeguards, to respect rights related to privacy and intellectual property, including copyright-protected content. Organizations should also comply with applicable legal frameworks.",
        "rationale": "Unc is grounded twice over in the text: data quality is to be managed 'to mitigate against harmful biases', which is equal treatment across the people a system decides about, and the safeguards limb is directed at 'rights related to privacy and intellectual property' — rights held by third parties whose protection the action asks the organization to weigh against its own data appetite. Cor comes from the closing sentence, which is the Code's only unhedged compliance direction: organizations 'should also comply with applicable legal frameworks'. Two evidence classes discharge the action and they map to its two halves: managing data quality and 'testing and fine-tuning to ensure that systems do not divulge confidential or sensitive data' is measurement against the data and the model's behaviour (Dat), while the safeguards and the applicable legal frameworks are written rule sets (Gui). Two source classes follow. Ind is the organization curating its data and building the safeguards. Gov is assigned on the closing sentence: 'applicable legal frameworks' makes the governing authority's position decisive, and this is the only action in the Code that routes outward to binding law in that way. Pro and Pee are withheld — no professional body or scholarly source is designated. Note that the value the mapping does NOT carry is the organization's own interest in unrestricted training data; the action states the countervailing rights and says nothing that would license trading them off, and the mapping stays where the text is. ADJUDICATION 2026-08-14: E ([Dat, Gui]) and S ([Ind, Gov]) agreed exactly, and Gov survives the Wave 2 source-axis re-check on its own terms: 'Organizations should also comply with applicable legal frameworks' names government norms as decisive on the substance of the duty, not a government body as a recipient — which is precisely the distinction that removed Gov from Action 4. Both passes independently observed that this closing sentence is the only place in the extracted set where the modality hardens from encouragement to 'should also comply', so Cor and Gov rest on the firmest footing in the pack. V narrows to the intersection [Unc, Cor]; the second pass's Sep for 'protections for personal data' and Por for intellectual property each rest on one pass, the first being another instance of Wave 1 gap 2 (privacy) and the second refused on the Wave 1 gap 9 reasoning. obligationType is lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E and S agreed exactly, and Gov survives the source-axis re-check here while being removed at Action 4 — the contrast between a named legal framework and a named recipient is the whole content of the new rule. V [Unc, Cor] retained against the second pass's [Sep, Unc, Cor, Por]; obligationType mixed → organizational."
    }
  ],
  "itemBankRef": {
    "publicSet": "/content/standards-packs/item-banks/g7-hiroshima-code.public.json",
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with the normative direction of each mapped action. They do not assess whether an organization implements the management-system expectations those actions are written in terms of (lifecycle testing and red-teaming regimes, post-deployment monitoring and vulnerability-disclosure programmes, transparency reporting, information-sharing mechanisms, AI governance and risk management policies, staff training, physical and cyber security controls, insider-threat programmes, content-provenance infrastructure, and data governance). The gap is wide for this norm: the Code is addressed to organizations developing advanced AI systems and states almost every one of its eleven actions as something an organization is called on to do, not as a judgment to be reached in a concrete case. After the dual formalization and adjudication of 2026-08-14 that reading is confirmed on the numbers — eight of the nine mapped actions are `organizational` and one (Action 7) is `mixed`; none is `behavioral`, and v0.1's `mixed` tag on eight actions did not survive the second reading.",
  "notes": [
    "draft-verified. Every entry carries a verbatim excerpt of the official text and a rationale argued from it, and on 2026-08-14 the second independent formalization recommended by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer read only the pack id, the sourceNorm and each entry's provenance.article, sourceUrl, retrievalUrl and quote; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped by an extraction script before any file was opened, and neither the pack-authoring guideline nor the management guide was opened. Human review remains outstanding and the V/E/S assignment is settled only by the public RFC process at https://aioq.org/en/rfc, so the pack does not advance beyond draft-verified.",
    "THE CODE IS VOLUNTARY. It describes itself as providing \"voluntary guidance for actions by organizations developing the most advanced AI systems\", is expressly framed as a \"non-exhaustive list of actions\" and a \"living document\", and states that \"Different jurisdictions may take their own unique approaches to implementing these actions in different ways.\" It is an instrument G7 leaders called on organizations to follow while governments developed more enduring approaches — not law, not a conformity-assessment scheme, and not binding on anyone. Nothing in this pack is a legal requirement, and a measurement against it says nothing about compliance with any statute. Endorsement of the Code by an organization is itself voluntary and is not verified by AIO.",
    "OPERATIONAL TESTABILITY LAYER — the OECD HAIP Reporting Framework. The Code itself supplies no reporting template, no evidence format and no review mechanism; the G7 committed in the Code's own preamble to \"develop proposals, in consultation with the OECD, GPAI and other stakeholders, to introduce monitoring tools and mechanisms to help organizations stay accountable for the implementation of these actions.\" That commitment became the OECD Hiroshima AI Process (HAIP) Reporting Framework, a voluntary transparency mechanism through which organizations report publicly against the Code's actions. Version 2.0 was launched on 28 May 2026 at a Tech7 event on the margins of the G7 Digital and Tech Ministerial Meeting under the French G7 Presidency; it broadens the framework across the AI value chain rather than frontier developers alone, replaces most open-ended questions with structured closed-ended ones so answers are comparable across respondents, and sets 1 September 2026 as the submission date for inclusion in the next analytical review. The revision is to the REPORTING FRAMEWORK ONLY — the Code of Conduct itself was not amended. Where an operator needs evidence that it acts on the actions this pack formalizes, a HAIP report is the concrete public vehicle; this pack is not, and cannot substitute for, such a report. Framework home: https://oecd.ai/en/hiroshima.",
    "CURRENCY VERIFIED. The Code was adopted on 30 October 2023 and, as at 2026-08-14, has not been revised, superseded or withdrawn; it remains the operative G7 instrument for organizations developing advanced AI systems. Its continuity has been carried across successive G7 presidencies, most recently the French presidency of 2026: the G7 Leaders' Summit at Évian-les-Bains on 15–17 June 2026 took AI governance as a working session and the HAIP Reporting Framework 2.0 was launched under the same presidency in May 2026 as a monitoring layer over this Code. The evolution since 2023 has been in the reporting layer, not in the Code's text. The Code states of itself that it \"will be reviewed and updated as necessary, including through ongoing inclusive multistakeholder consultations\", so this pinning must be rechecked whenever the pack is revisited.",
    "PRIMARY SOURCE AND TWO OFFICIAL MANIFESTATIONS. `sourceUrl` throughout is the canonical PDF published by the Ministry of Internal Affairs and Communications of Japan on the Hiroshima AI Process site maintained from the 2023 Japanese G7 presidency (https://www.soumu.go.jp/hiroshimaaiprocess/pdf/document05_en.pdf), retrieved 2026-08-14. Quotes were taken from and checked against the copy published by the European Commission at its official library page (https://digital-strategy.ec.europa.eu/en/library/hiroshima-process-international-code-conduct-advanced-ai-systems), whose document endpoint is recorded as `retrievalUrl`; the Commission's reuse policy places Commission-owned website content under Creative Commons Attribution 4.0 International, and the document carries no separate copyright notice. Because the Code is a G7 collective instrument published by each member rather than a work owned by any one of them, this pack keeps quotation short and attributed on both grounds — the CC BY 4.0 reuse policy of the retrieval copy and, independently, fair quotation of a public intergovernmental text. Attribution is given in this file and in the accompanying management guide. MOFA (mofa.go.jp) hosts further Hiroshima Process material but was bot-blocked at retrieval time and was not used.",
    "QUOTE VERIFICATION METHOD. Both PDFs were converted to text with an independent extraction, normalised to a single whitespace-collapsed corpus each with page-number lines removed, and every quote fragment in this file — splitting each `quote` at its `[…]` elision marks and discarding no other character — was checked by exact substring match against BOTH corpora. All 26 fragments across the 9 entries matched both manifestations byte for byte, as did every further excerpt quoted inside the `rationale` fields and these notes (38 additional fragments, 38 matched), including the typographic apostrophes (U+2019) and the en dash in the Action 5 heading, which are reproduced here as the source prints them.",
    "MANIFESTATION DIVERGENCE, RECORDED RATHER THAN HIDDEN. A full diff of the two official manifestations found them identical apart from three points, none of which touches a quoted fragment: (a) the Japanese presidency PDF prefixes \"Hiroshima Process\" to the instrument's own name twice in the opening sentence where the Commission copy does not; (b) \"human-centricity\" in the preamble is broken across a line in the Japanese presidency PDF; (c) in Action 5's body the Japanese presidency PDF prints \"risk-based approach\" at two points where the Commission copy prints \"risk based approach\". Quotation in this pack avoids all three loci. The divergence is recorded because a formalization that claims verbatim fidelity has to say which manifestation it means.",
    "ACTION SELECTION — 9 of 11. Mapped: Actions 1, 2, 3, 4, 5, 6, 7, 10 and 11. Two actions are EXCLUDED, with reasons, and both remain candidates for reconsideration at RFC. Action 8 (\"Prioritize research to mitigate societal, safety and security risks and prioritize investment in effective mitigation measures\") states a research and investment priority: it is a real expectation of a well-run organization, but it is discharged by budget allocation and research programmes and carries no direction that a per-case judgment could track — an item cannot observe whether a firm invested in mitigation research. Action 9 (\"Prioritize the development of advanced AI systems to address the world’s greatest challenges\") is the Code's most aspirational action, directing development toward the climate crisis, global health and education in support of the Sustainable Development Goals; it sets a portfolio-level ambition with no measurable judgment correlate at all and no normative direction an answer could align with or depart from. Action 10 was included despite being stated purely as encouragement, because it is the single place in the Code where an external body's position is designated and it is therefore the only source of a non-`Ind` source class other than the two public-authority references in Actions 4 and 11. CORRECTION AFTER ADJUDICATION (2026-08-14): the closing clause of this note said that Action 10 is the only source of a non-`Ind` source class other than the two public-authority references in Actions 4 and 11. That is no longer accurate. `Gov` at Action 4 did not survive the source-axis re-check — the public authorities there are named as recipients of shared information, not as a source — so the non-`Ind` classes in the pack are now `Pro` at Action 10, `Gov` at Action 11 alone, and `Usr` at Action 2, which is also the one entry that carries no `Ind`.",
    "HEDGE DISCIPLINE. The Code hedges heavily and the hedges are load-bearing: \"where appropriate\", \"as appropriate\", \"where technically feasible\", \"where feasible\", \"commensurate to the level of risk\", \"are encouraged to\", \"should also endeavor to\", \"should seek to\", \"Work towards\". The framing clauses of the preamble do the same work at instrument level: the actions are to be followed \"in line with a risk-based approach\" and \"in a manner that is commensurate to the risks\", which means every action's demand scales with the risk of the system it is applied to and none of them is absolute. Every `quote` in this file preserves the hedge that governs the fragment it carries, and no `summary`, `rationale` or `note` asserts more than the hedged text supports. In particular: Action 2's incident and misuse limb is hedged \"where appropriate\"; Action 7's provenance mechanisms are hedged \"where technically feasible\" in the heading and \"where appropriate and technically feasible\" again in the body; Actions 10 and 11 are stated as encouragement throughout, save Action 11's closing compliance sentence. Readers checking this pack should treat any statement of the form \"the Code requires X\" as a defect.",
    "INFERENCE CODES — the one v0.1 carried is no longer an inference. v0.1 assigned exactly one code from an action's structure rather than its words and flagged it in its own rationale: Ses in Action 7, read from the population-scale purpose of a content-provenance regime and from the preamble's naming of disinformation, where the action itself speaks only of enabling users to identify AI-generated content. **The blind second pass reached Ses at Action 7 independently, so it survives adjudication as corroborated rather than inferred.** Ses was withheld from Action 10 by v0.1 to avoid double-counting the same inference, and the second pass did not reach it there either. The inference codes the second pass introduced and v0.1 did not reach were all removed under the standing rule that an inference-flagged code survives only where both passes reached it: Por at Actions 4, 6 and 11 (a developer-side interest proposed as a value that must prevail), Sep at Actions 5, 6, 7 and 11, Dat at Actions 3, 4 and 11 — of which Dat survives at 3, 4 and 11 only because v0.1 had independently declared it — and Gui at Action 6, which survives on the same basis.",
    "SOURCE-CLASS DISCIPLINE, restated after adjudication. The cross-pack source-axis rule settled in Wave 1 and extended in Wave 2 governs: **`Gov` is declared only where the excerpt names a government body or a government norm as decisive on the substance of the duty** — being named as the recipient of shared information, a report or a filing does not earn it — and **`Ind` is declared where the excerpt makes the industry duty-bearer the author or performer of the provision's product or determination.** The rule is applied as a filter and never as a generator. Its effects here are two. `Ind` appears in eight of the nine entries, not all nine: it is removed at Action 2, where what the action designates as decisive is a report from a user or third party rather than anything the organization issues. `Gov` appears once, not twice: it survives at Action 11 ('Organizations should also comply with applicable legal frameworks') and is removed at Action 4, where 'relevant public authorities' are named as counterparties to an information exchange — the second pass had already withheld `Pee` for 'academia' in the same sentence on exactly that reasoning, and the rule simply applies it consistently. `Pro` appears once, at Action 10, on the express naming of Standards Development Organizations, and both passes recorded that the catalogue's professional-body class does not really fit a multi-stakeholder standards body. `Pee` appears nowhere. The most consequential absence is unchanged and was confirmed by both passes: Action 1 calls for 'independent external testing measures' and names no class of body that performs them, so the Code's central risk-management action carries no external source class at all — and, after adjudication, no evidence class either.",
    "MEASUREMENT SCOPE (per-entry `obligationType`, pack-level `measurementScope`). After adjudication, eight of the nine mapped actions are `organizational` and one — Action 7 — is `mixed`; v0.1's distribution was 1 organizational / 8 mixed, and every one of the seven divergences on this axis was resolved toward the more conservative tag. Not one action is `behavioral`, which v0.1 had already recorded. This distribution is a property of the source: the Code addresses 'organizations developing advanced AI systems' and phrases every action as something such an organization is called on to do, so organizational weight is carried throughout even where a judgment correlate sits on top. The judgment correlates v0.1 identified are unaffected and remain the reason particular actions are worth items — Action 3 (disclosing significant limitations rather than letting a capability claim stand), Action 11 (not divulging confidential or sensitive data; respecting copyright-protected content) and Action 7 (acknowledging AI authorship when it is material) — but a correlate an item can test is not the same thing as a duty an item can observe being discharged. A pass against this pack is evidence about model judgment only, and never evidence that an organization has implemented the Code.",
    "Methodology for the action → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. Codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary — the same codes an AIO 20002 record carries.",
    "NO ENDORSEMENT. Neither the G7, nor any G7 member or presidency, nor the Government of Japan, nor the European Commission, nor the OECD has reviewed, approved or endorsed this formalization, and none took any part in preparing it. AIO certifies conformance to AIO's own formalization of the Code. That is not an assessment against the Code by the G7, not a legal conformity assessment, and confers no status of any kind under the law of any jurisdiction. Phrasings such as \"G7-certified\", \"Hiroshima Process certified\", \"OECD-recognised\" or \"HAIP-compliant\" are not available to anyone using this pack, and a certificate against this pack is not, and must not be presented as, a HAIP report.",
    "No item bank has been built for this pack, so `itemBankRef` is null on both sets and the pack cannot yet back a certificate of any tier. It appears in the catalogue as registered and awaiting measurement.",
    "ADJUDICATION METHOD (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under a fixed policy carried forward from Wave 1: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken; the intersection is an allowed outcome where it is non-empty and defensible; no third reading is invented, and every adjudicated set is a subset of at least one pass's set. Two sub-rules settled in this wave: a code flagged INFERENCE by the pass that declared it survives only where both passes reached it, and a divergent `obligationType` always resolves to the more conservative tag. Agreement statistics for this pack, across nine entries: V 2/9, E 6/9, S 8/9, obligationType 2/9, all four axes together 0/9. The shape of this result is the mirror image of the Korean pack's in Wave 1: the source layer agreed almost perfectly, because a voluntary code self-applied by its addressee leaves little room to disagree about whose material counts, while the obligationType axis diverged almost completely, because v0.1 read a judgment correlate on top of nearly every action and the blind pass read the shape of the duty underneath it.",
    "CONTAMINATION NOTICE. The second formalization of this pack ran under the tightened Wave 2 protocol, in which the pack-authoring guideline was blocked outright, and the second pass disclosed no exposure to any pack field or to any prior adjudication. No axis of this pack is reported with a contamination caveat. The second pass did adopt an addressee convention of its own, recorded in its method block — the Code's hedges are read at their stated strength and never inflated into requirements — which is the same discipline v0.1 set out in the hedge-discipline note, reached independently.",
    "VOCABULARY AND SCHEMA GAPS found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes two to the Wave 2 list, which continues the consolidated Wave 1 list of ten, and confirms three existing items. (20) INTERACTION-TIME TECHNICAL MARKER AS AN EVIDENCE CLASS — Action 7 is discharged by a watermark or content credential carrying 'an identifier of the service or model that created the content', and none of the ten evidence codes covers a machine-embedded provenance signal. Both passes said so and the layer is left empty; the same gap appears at UNESCO ¶127 and in the Chinese labelling pack in this wave. (22) CIVIL SOCIETY AS A SOURCE CLASS — Action 4 names 'industry, governments, civil society, and academia' as the parties to responsible information sharing, and civil society has no carrier among the ten source codes. The second pass found this blind; academia is a related absence, since `Pee` means a claim that passed scholarly scrutiny and not an institution one shares information with. Confirmed again from Wave 1: gap 9 CARVE-OUT REPRESENTATION (the `v` array cannot express an interest preserved against the duty — Action 4's intellectual-property clause, Action 6's model weights and Action 11's copyright limb all produced a `Por` proposal from the second pass and all three were refused), gap 8 STANDARDS-DEVELOPMENT BODIES UNDER `Pro` (Action 10, where both passes carried `Pro` for SDOs with the same recorded misfit), and gap 2 PRIVACY (Actions 5 and 11, where the two passes chose different codes for the same privacy limb and neither was carried). A further schema question is recorded here for the RFC round as Wave 2 gap 23: the Code's modality is hedged throughout — 'as appropriate', 'where technically feasible', 'are encouraged to' — and a v/e/s array records what a provision points at but not how strongly it points, so a hedged illustration and a flat requirement are indistinguishable once formalized. Both passes worked around it in prose, in the hedge-discipline note and in the second pass's per-entry HEDGE flags respectively. The full Wave 2 list is reproduced in the adjudication report."
  ]
}