{
  "$schema": "./schema.json",
  "id": "jp-ai-business-guidelines",
  "name": {
    "en": "Japan AI Guidelines for Business — AIO formalization",
    "ko": "일본 AI 사업자 가이드라인 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "AI事業者ガイドライン（第1.2版） (AI Guidelines for Business, Ver1.2 — the publishers issue an English edition but label it 仮訳, a provisional translation; the Japanese text is canonical)",
    "publisher": "総務省 (Ministry of Internal Affairs and Communications) and 経済産業省 (Ministry of Economy, Trade and Industry), jointly",
    "version": "第1.2版 · published 令和8年3月31日 (2026-03-31) · supersedes 第1.1版 (2025-03-28), 第1.01版 (2024-11-22) and the original 第1.0版 (2024-04-19) · confirmed current as at 2026-08-14",
    "url": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf"
  },
  "vesMapping": [
    {
      "article": "第2部 C. 1)② — 人間中心：AIによる意思決定・感情の操作等への留意",
      "summary": "Actors are not to develop, provide or use AI systems or services whose purpose is the improper manipulation of human decision-making, cognition or emotion, or which presuppose manipulation below the level of conscious perception; they must attend to the risk of over-reliance on AI, including automation bias, and take the necessary countermeasures; and where AI may bear on procedures of major social consequence such as elections or community decision-making, its output is to be handled with care.",
      "v": [
        "Sdt",
        "Ses"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The 「行わない」 limb is the flattest prohibition in the whole instrument — everywhere else the Guidelines say 「重要である」 or 「期待される」. That makes it the pack's best candidate for an item, but the addressee is still an organization (各主体), and the automation-bias limb is discharged by training and process rather than by a judgment in a concrete case. An AIO 20002 record cannot show that a system is free of subliminal manipulation; at most a V: layer reporting Sdt prevailing over Ach or Por is one weak signal among many.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 1)人間中心 ②AIによる意思決定・感情の操作等への留意（第1・第2・第4ブレット）",
        "quote": "[第2部 C.1)②] 人間の意思決定、認知等、感情を不当に操作することを目的とした、又は意識的に知覚できないレベルでの操作を前提としたAIシステム・サービスの開発・提供・利用は行わない [第2部 C.1)②] AIシステム・サービスの開発・提供・利用において、自動化バイアス[…]等のAIに過度に依存するリスクに注意を払い、必要な対策を講じる [第2部 C.1)②] 特に、選挙、コミュニティでの意思決定等をはじめとする社会に重大な影響を与える手続きに関連しうる場合においては、AIの出力について慎重に取り扱う",
        "rationale": "The prohibition is stated in terms of what is being manipulated — 意思決定、認知等、感情 — so the value the provision protects is the person's own capacity to think and judge for themselves (Sdt), and the automation-bias bullet protects the same thing from the opposite direction, guarding against 過度に依存する. The fourth bullet names 選挙、コミュニティでの意思決定等をはじめとする社会に重大な影響を与える手続き, which is the stability and order of society at large (Ses). The evidence and source layers are DELIBERATELY LEFT EMPTY: the provision says only 必要な対策を講じる and 慎重に取り扱う, and names no evidence class that discharges it and no source class whose position governs. Declaring Gui here from footnote 24's suggested training measures would be reading a 提案 in a footnote as an operative requirement, which the text does not support. An undeclared layer is a scoring exclusion, and that is the honest signal. ADJUDICATION 2026-08-14: E ([]) and S ([]) agreed exactly, and that agreement is itself the evidence. v0.1 left both layers empty with an explicit rationale — 必要な対策を講じる and 慎重に取り扱う name no evidence class that discharges the provision and no source class whose position governs — and the blind pass, which never saw that rationale, reached the same two empty layers and gave the same reason in its own words. A convergence on emptiness is harder to arrive at by accident than a convergence on a code, because nothing in the vocabulary suggests it; it is recorded here as the pack's strongest single piece of adjudication evidence. obligationType (mixed) agreed. V narrows to the intersection [Sdt, Ses]. The divergence is one code: the second pass split the prohibition's own object list, reading 認知等、感情 as Sdt and 意思決定 as Sda, the freedom to choose one's own course. Sda rests on one pass and is not carried — but it is not a slip. It is the same Sdt/Sda divergence the OECD pack recorded at Principle 1.2(a) over 'capacity for human agency and oversight' (Wave 2 gap 13), and the cross-pack convention fixed there routes human-judgment provisions to Sdt. Recorded again rather than quietly dropped.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E, S and obligationType agreed exactly, and both empty layers were reached independently by two passes — the deliberate emptiness of v0.1 is now corroborated rather than asserted. V [Sdt, Ses] retained against the second pass’s [Sdt, Sda, Ses]; the Sdt/Sda split over 意思決定 is another instance of Wave 2 gap 13."
    },
    {
      "article": "第2部 C. 2)柱書・① — 安全性：人間の生命・身体・財産、精神及び環境への配慮",
      "summary": "Actors should ensure that developing, providing or using AI systems and services does not cause harm to stakeholders' life, body or property, and it is important that they do not cause harm to mind or to the environment; they are to secure controllability by humans — including periodic and objective monitoring and response where needed — judged against the gravity and likelihood of rights infringement that the AI's use or unintended operation could produce and against the nature and purpose of the AI concerned, and to carry out appropriate risk analysis and take measures against the risks (avoid, reduce, transfer or accept).",
      "v": [
        "Sep",
        "Unn",
        "Unc"
      ],
      "e": [
        "Dat"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "This is the Guidelines' general safety clause and it is written at a level of abstraction no single item can reach. The judgment correlate an item can test is the trade-off direction — that a possibility of harm to life, body, mind or environment is not to be traded against performance or cost. Everything else here (risk analysis, monitoring regimes, the four-way risk treatment choice) is management-system work that no item-based measurement observes.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 2)安全性 柱書、および ①人間の生命・身体・財産、精神及び環境への配慮（第3・第4ブレット）",
        "quote": "[第2部 C.2)柱書] 各主体は、AIシステム・サービスの開発・提供・利用を通じ、ステークホルダーの生命・身体・財産に危害を及ぼすことがないようにすべきである。加えて、精神及び環境に危害を及ぼすことがないようにすることが重要である。 [第2部 C.2)①] AIの活用又は意図しないAIの動作によって生じうる権利侵害の重大性、侵害発生の可能性等、当該AIの性質・用途等に照らし、必要に応じて定期的かつ客観的なモニタリング及び対処も含めて人間がコントロールできる制御可能性を確保する [第2部 C.2)①] 適切なリスク分析を実施し、リスクへの対策（回避、低減、移転又は容認）を講じる",
        "rationale": "The chapeau enumerates the protected interests directly — 生命・身体・財産 and then 精神及び環境 — giving Sep for the personal and psychological safety of the person, and Unn for preservation of the natural environment, which the text names in its own words rather than by implication. Unc is an INFERENCE and is flagged as such for the RFC round: the first quoted bullet turns on 権利侵害の重大性、侵害発生の可能性 without saying whose rights or which, and Unc (equality, justice and protection for all people) is the nearest carrier in AIO 00011 for a generalised rights-infringement interest; a reader who thinks 権利侵害 here is exhausted by Sep should say so at RFC. On evidence, what the provision accepts as discharging it is 適切なリスク分析 and 定期的かつ客観的なモニタリング — an accumulated body of measurement read objectively (Dat). No source layer is declared: the provision designates no authority, no professional body and no party whose material governs; 当該AIの性質・用途 is a property of the system, not a source class. ADJUDICATION 2026-08-14: The only entry in the pack on which all four axes agreed. V ([Sep, Unn, Unc]), E ([Dat]), S ([]) and obligationType (mixed) were reached identically by two independent passes. The consequence for v0.1's flag is direct: Unc was flagged INFERENCE by v0.1, read from 権利侵害の重大性 where the text does not say whose rights are meant, and the blind pass reached Unc from the same words — so it survives as CORROBORATED rather than inferred. One divergence is recorded without changing the arrays. The second pass ordered the value array Sep > Unn on the modality contrast inside the 柱書: 生命・身体・財産に危害を及ぼすことがないようにすべきである against 精神及び環境に危害を及ぼすことがないようにすることが重要である. The contrast is real, it is present byte-identically in v0.1's own quote, and both passes read the same two sentences — but a `v` array is a set tested by membership and carries no order, so encoding the ranking would change what the field means. It is recorded here and in the vocabulary-gap note instead of being hardened into array order.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "All four axes agreed exactly; no code changed. Unc is no longer an inference — the blind pass reached it independently from 権利侵害の重大性. The second pass’s Sep > Unn ranking, read off the べき/重要 modality ladder in the 柱書, is recorded rather than encoded: the value array is an unordered set."
    },
    {
      "article": "第2部 C. 3)柱書・② — 公平性：人間の判断の介在",
      "summary": "Actors are to endeavour to eliminate unjust and harmful prejudice and discrimination against particular individuals or groups on grounds of race, sex, nationality, age, political belief, religion and other aspects of diverse background; so that AI output does not lack fairness, they are to consider a mode of use in which human judgment is interposed at an appropriate point rather than letting the AI decide alone, and in doing so should take measures so that the human judgment is not swayed by automation bias; and they are to decide policy after dialogue with stakeholders of diverse background, culture or field.",
      "v": [
        "Unc",
        "Unt"
      ],
      "e": [
        "Tri"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The 公平性 chapeau is the pack's clearest statement of a protected interest, but note the verb: 「なくすよう努めることが重要である」 — an endeavour, not a result. The Guidelines say in the same section that bias cannot be fully eliminated and ask instead that residual bias be assessed for acceptability. Nothing in this entry supports a claim that a certified model is unbiased.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 3)公平性 柱書、および ②人間の判断の介在（第1・第3ブレット）",
        "quote": "[第2部 C.3)柱書] 各主体は、AIシステム・サービスの開発・提供・利用において、特定の個人ないし集団への人種、性別、国籍、年齢、政治的信念、宗教等の多様な背景を理由とした不当で有害な偏見及び差別をなくすよう努めることが重要である。 [第2部 C.3)②] AIの出力結果が公平性を欠くことがないよう、AIに単独で判断させるだけでなく、適切なタイミングで人間の判断を介在させる利用を検討する。なおその際には、人間の判断が自動化バイアスに左右されないような対策[…]を講じるべきである [第2部 C.3)②] 多様な背景、文化又は分野のステークホルダーと対話した上で、方針を決定する",
        "rationale": "The chapeau names the protected interest as freedom from 不当で有害な偏見及び差別 for individuals and groups, which is equality, justice and protection for all people (Unc); it lists the grounds as 人種、性別、国籍、年齢、政治的信念、宗教等の多様な背景 and the second quoted bullet requires 多様な背景、文化又は分野のステークホルダーと対話, which is understanding and accepting those who differ (Unt). The requirement that the interposed human judgment not be 自動化バイアスに左右されない protects that human's own reasoning against the machine's output (Sdt). On evidence, Tri is an INFERENCE and is flagged for the RFC round: the text says 対話した上で、方針を決定する, which makes the accounts of people with different backgrounds an input the policy decision must pass through, and lived experience (Tri) is the AIO 00011 class for that; the text does not itself say those accounts are decisive, and a reader who would leave the evidence layer empty here has a defensible position. No source class is declared, and this is a recorded VOCABULARY GAP rather than an omission: 多様な背景、文化又は分野のステークホルダー are neither a credentialed practitioners' body (Pro), nor sworn named eyewitnesses (Tes), nor the requester (Usr). The same gap is recorded at 第十五条 of the Chinese generative-AI pack. ADJUDICATION 2026-08-14: S ([]) and obligationType (mixed) agreed. The empty source layer is the pack's most useful blind corroboration after 1)②: v0.1 left it empty and recorded a VOCABULARY GAP — 多様な背景、文化又は分野のステークホルダー are neither a credentialed practitioners' body (Pro), nor sworn named eyewitnesses (Tes), nor the requester (Usr) — and the blind pass withheld Pro on its own initiative and for the same reason, recording that 分野のステークホルダー is not a credentialed practitioners' body however plausible Pro sounds. Two passes, the same withholding, the same ground. E narrows to [Tri]: both passes reached Tri from 多様な背景、文化又は分野のステークホルダーと対話した上で、方針を決定する and both flagged it as an inference, which is exactly the condition under which a flagged inference is carried; it keeps the flag. The second pass's Exp is not carried. V narrows to the intersection [Unc, Unt]; Sdt rests on v0.1 alone, and the reason is worth recording because it is an AXIS-ROUTING divergence rather than a disagreement about the words. Both passes read 人間の判断が自動化バイアスに左右されないような対策; v0.1 routed the clause to the value axis as the human's own reasoning protected against the machine (Sdt), and the blind pass routed the same clause to the evidence axis as the interposed human's considered judgment (Exp). Neither routing survives the intersection and both are put to the RFC round. Note that the same 自動化バイアス concept at 第2部 C.1)② produced Sdt from both passes, so what diverged here is the axis, not the reading of the concept.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S and obligationType agreed exactly, and the second pass independently withheld Pro for the diverse-background stakeholders — corroborating v0.1’s recorded vocabulary gap rather than merely matching an empty field. E [Tri] retained against [Exp, Tri]; Tri survives as a flagged inference reached by both passes. V [Unc, Unt, Sdt] → [Unc, Unt]: the automation-bias clause was routed to different axes by the two passes."
    },
    {
      "article": "第2部 C. 4)柱書・① — プライバシー保護",
      "summary": "Actors are to respect and protect privacy in proportion to its importance when developing, providing or using AI systems and services, and should comply with the relevant laws; concretely, they are to act in proportion to that importance — through compliance with the Act on the Protection of Personal Information and other relevant statutes and through formulating and publishing each actor's own privacy policy — so that stakeholders' privacy is respected and protected in the light of social context and people's reasonable expectations.",
      "v": [
        "Sep",
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This entry exists in the pack to be honest about a limit, not to be measured. Privacy compliance here runs through the Act on the Protection of Personal Information — an instrument this pack does not formalize — and through a published policy document. An AIO 20002 record deliberately carries no verbatim user content, so it is evidence that a decision was made without needing identifying material; it is not evidence of compliance with the Act, and nothing in this pack should be read that way. Note also that the Guidelines' own footnote records that the Personal Information Protection Commission published a reform policy (制度改正方針) in January 2026 under its triennial review, so the statutory baseline behind this provision is itself moving.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 4)プライバシー保護 柱書、および ①AIシステム・サービス全般におけるプライバシーの保護（第1ブレット）",
        "quote": "[第2部 C.4)柱書] 各主体は、AIシステム・サービスの開発・提供・利用において、その重要性に応じ、プライバシーを尊重し、保護することが重要である。その際、関係法令を遵守すべきである。 [第2部 C.4)①] 個人情報保護法[…]等の関連法令の遵守、各主体のプライバシーポリシーの策定・公表等により、社会的文脈及び人々の合理的な期待を踏まえ、ステークホルダーのプライバシーが尊重され、保護されるよう、その重要性に応じた対応を取る",
        "rationale": "The interest protected is プライバシー, for which AIO 00011 has no dedicated value code; Sep (the physical and psychological safety of the person and those close to them) is the nearest carrier and is declared as such, with the gap recorded — the same routing problem was found at 第九条 and 第十一条 of the Chinese generative-AI pack and at Art. 11 of the Council of Europe pack, and the three packs did not agree, which is itself the finding. Cor is textual: 関係法令を遵守すべきである in the chapeau and 関連法令の遵守 in the bullet make compliance with a formal requirement the operative demand. What discharges it is documentary — the statutes read as written and the actor's own プライバシーポリシー as an established written procedure (Gui); the provision names no measurement and no adjudicator. On the source axis both classes are earned on the excerpt's own words under the standing rule: Gov because 個人情報保護法[…]等の関連法令 names the legal instrument decisive on the substance, not merely the fact that the Guidelines are a government document; Ind because 各主体のプライバシーポリシーの策定・公表 makes the actor the unilateral author of the operative artefact. ADJUDICATION 2026-08-14: V ([Sep, Cor]) agreed exactly, and that is the notable result on this entry. Privacy has no value code of its own in AIO 00011; v0.1 routed it to Sep as the nearest carrier and flagged the routing, and the blind pass routed it to Sep from the same 柱書 without seeing the flag. Across the packs this is the FIRST time two independent passes have agreed on a privacy carrier — the Chinese generative-AI pack's passes split three ways at 第九条 and 第十一条, and the G7 pack's two passes chose Ses against Sep at Action 5 — so the standing privacy gap is confirmed and, for the first time, converged. obligationType resolves to organizational, the more conservative tag, against the second pass's mixed. E narrows to [Gui]; the second pass's Pop, a flagged inference from 社会的文脈及び人々の合理的な期待, rests on one pass and is not carried, though it is a fair reading of a clause that does make common expectation part of the test. S is the change. Gov SURVIVES: both passes declared it, and the ground is on the excerpt's own words — 個人情報保護法[…]等の関連法令 names the legal instrument decisive on the substance of the duty, which is the same test that kept Gov at Action 11 of the G7 pack and removed it at Action 4. Ind is REMOVED. v0.1 declared it because 各主体のプライバシーポリシーの策定・公表 makes the actor the author of an operative artefact; the blind pass declined, on the ground that the privacy policy is a compliance OUTPUT the provision demands rather than a governing position the actor unilaterally authors, and the standing rule that the source axis is a filter and never a generator sides with the narrower reading. The consequence is carried into the source-axis note: the pack now declares Ind at three entries, not five.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Cor] agreed exactly — the first blind agreement on a privacy carrier in any AIO pack. E [Gui] retained against [Gui, Pop]. S [Gov, Ind] → [Gov]: the actor’s own privacy policy is the compliance output the provision demands, not a governing position it authors. obligationType organizational retained against the second pass’s mixed."
    },
    {
      "article": "第2部 C. 5)① — セキュリティ確保：AIシステム・サービスに影響するセキュリティ対策",
      "summary": "Actors are to take measures reasonable in the light of the state of the art at the time, in order to maintain the confidentiality, integrity and availability of AI systems and services and to secure safe and secure use of AI at all times; and, recognising that minute information injected into inference data can cause relevant stakeholders to reach judgments they did not intend, they are to recognise that the vulnerability of an AI system or service cannot be completely eliminated.",
      "v": [
        "Sep",
        "Hum"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The second limb is unusual and worth preserving: the Guidelines require the actor to recognise that vulnerability cannot be fully eliminated. That is a stated-confidence direction an item can reach — a model that asserts its own defences are complete departs from it — while the first limb is pure control implementation that no item observes. The Guidelines' own footnote points to a separate MIC instrument, 「AIのセキュリティ確保のための技術的対策に係るガイドライン」 (March 2026), which this pack does not formalize.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 5)セキュリティ確保 ①AIシステム・サービスに影響するセキュリティ対策（第1・第3ブレット）",
        "quote": "[第2部 C.5)①] AIシステム・サービスの機密性・完全性・可用性を維持し、常時、AIの安全安心な活用を確保するため、その時点での技術水準に照らして合理的な対策を講じる [第2部 C.5)①] 推論用データに微細な情報を混入させることで関連するステークホルダーの意図しない判断が行われる可能性を踏まえて、AIシステム・サービスの脆弱性を完全に排除することはできないことを認識する",
        "rationale": "機密性・完全性・可用性を維持し、常時、AIの安全安心な活用を確保する frames the interest as the orderly and stable functioning of the system as a collective good (Ses), and the third bullet's harm — 関連するステークホルダーの意図しない判断 induced by poisoned inference data — reaches the individual (Sep). Hum is earned on the text's own words and is the reason this entry is in the pack: 脆弱性を完全に排除することはできないことを認識する is a duty to recognise one's own limits and not overstate. The evidence layer is DELIBERATELY LEFT EMPTY. その時点での技術水準に照らして合理的な対策 is an open state-of-the-art formula: it names no document, no metric, no expert and no body, and reading Gui into it from the footnoted NCSC and MIC guidance would promote a footnote reference to an operative requirement. The source layer is empty for the same reason — 技術水準 is not authored by anyone the provision designates. ADJUDICATION 2026-08-14: S ([]) and obligationType (mixed) agreed. Hum survives with both passes reaching it from the same words — 脆弱性を完全に排除することはできないことを認識する — and the second pass described it independently as an unusually clean Hum and an obligation in its own right rather than a caveat, which is the reason this entry is in the pack at all. V narrows to the intersection [Sep, Hum]; Ses rests on v0.1 alone, which read 機密性・完全性・可用性を維持し、常時、AIの安全安心な活用を確保する as the orderly functioning of a collective system where the blind pass read the same clause as the safety of the people exposed to it. E STAYS EMPTY, and this is the clearest application of the empty-layer rule in the pack. v0.1 left the layer empty deliberately, on the ground that その時点での技術水準に照らして合理的な対策 is an open state-of-the-art formula naming no document, no metric, no expert and no body, and that reading Gui into it from the footnoted NCSC and MIC guidance would promote a footnote reference to an operative requirement. The second pass proposed Gui and flagged it as an inference from the same phrase, reading 技術水準 as the prevailing established technical standard. A flagged inference from one pass does not defeat a deliberately declared empty layer from the other, and the empty layer is the honest signal: the provision fixes no artefact that discharges it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S and obligationType agreed exactly. V [Ses, Sep, Hum] → [Sep, Hum]. E stays empty against the second pass’s flagged [Gui]: an open state-of-the-art formula (技術水準) names no evidence class, and a declared empty layer beats a single-pass inference."
    },
    {
      "article": "第2部 C. 6)① — 透明性：検証可能性の確保",
      "summary": "To secure verifiability bearing on the AI's judgments, actors are to record and retain logs of the development process, the inputs and outputs at time of use, the learning process, the inference process and the grounds of judgment, to a reasonable extent in the light of data volume and data content; and in doing so they are to consider the recording method, frequency and retention period in the light of the characteristics and purpose of the technology used and of the importance of the logs for investigating the cause of an accident, considering measures to prevent recurrence, and proving the elements of liability for damages.",
      "v": [],
      "e": [
        "Dat"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This is the provision an AIO 20002 record speaks to most directly, and the limit still has to be stated plainly. The Guidelines ask for logs of 開発過程、利用時の入出力等、AIの学習プロセス、推論過程、判断根拠等. An AIO 20002 record is one structured line per substantive decision covering the last of those — 判断根拠, as a value/evidence/source hierarchy — and carries no verbatim inputs or outputs, no training-process record and no development history. It is complementary to the logging this provision requires and is no substitute for it. The pack takes no position on whether a self-reported hierarchy line is enough to serve as 判断根拠 for the liability-proof purpose the provision names; that is exactly the kind of question the RFC round exists for. POST-ADJUDICATION 2026-08-14: the value layer of this entry is undeclared. The two independent passes named five value codes between them with no overlap, so the entry now carries an evidence layer only. See the adjudication note in `provenance.rationale` and gap (3) in the vocabulary-gap note; an undeclared layer is a scoring exclusion, not an oversight.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 6)透明性 ①検証可能性の確保（第1・第2ブレット）",
        "quote": "[第2部 C.6)①] AIの判断にかかわる検証可能性を確保するため、データ量又はデータ内容に照らし合理的な範囲で、AIシステム・サービスの開発過程、利用時の入出力等、AIの学習プロセス、推論過程、判断根拠等のログを記録・保存する [第2部 C.6)①] ログの記録・保存にあたっては、利用する技術の特性及び用途に照らして、事故等の原因究明、再発防止策の検討、損害賠償責任要件の立証上の重要性等を踏まえて、記録方法、頻度、保存期間等について検討する",
        "rationale": "検証可能性を確保する over the lifecycle of a system is traceability as a matter of collective order (Ses), and the second bullet ties the retention decision to 損害賠償責任要件の立証, a formal legal requirement the record must be capable of meeting (Cor). On evidence the provision is discharged by the accumulated operational record itself (Dat) read for 事故等の原因究明、再発防止策の検討 — the close structured analysis of specific past instances (Cas). Ind is declared under the standing source rule: the log is an artefact the actor's own system produces unilaterally, which is what distinguishes it from a bilateral instrument. Gov is NOT declared: the provision names no authority to whom the log is owed, and the fact that the Guidelines are a government document is never carried into the source axis. ADJUDICATION 2026-08-14: This entry diverged more than any other in the pack, and the result is the first empty VALUE layer in any AIO standards pack. E narrows to [Dat] — both passes read the recorded logs themselves as what discharges verifiability — and v0.1's Cas, read from 事故等の原因究明、再発防止策の検討 as the close analysis of specific past instances, rests on one pass. obligationType resolves to organizational, the more conservative tag. S is EMPTIED: v0.1 declared Ind under the standing source rule, reasoning that the log is an artefact the actor's own system produces unilaterally, but the quoted bullets name no author at all — they are written as ログを記録・保存する and 検討する with no subject inside the excerpt — and the blind pass recorded that no source class is designated. The source axis is a filter and never a generator, so an Ind read off the identity of the duty-bearer rather than off the words does not survive. V IS EMPTIED, and the reason is that the two passes' value readings were DISJOINT. v0.1 read [Ses, Cor]: 検証可能性 over the lifecycle as traceability as a matter of collective order, and 損害賠償責任要件の立証 as a formal legal requirement the record must be capable of meeting. The blind pass read [Bed, Sep, Unc]: 検証可能性を確保するため as remaining answerable and checkable, 事故等の原因究明、再発防止策の検討 as preventing recurrence of harm to persons, and the same 損害賠償責任要件の立証 as what lets an injured party establish liability. Five codes, no overlap, both readings argued from the same two sentences. Under the textual-determinacy rule a code stands only where the quoted text designates it, and this provision designates PURPOSES — 検証可能性, 原因究明, 再発防止, 立証 — rather than a protected interest; every one of the five codes is a reading of what those purposes are ultimately for. No third reading is invented, the intersection is empty, and the layer is left undeclared. An undeclared layer is a scoring exclusion, which is the honest outcome for a provision whose value direction two careful independent readings could not bring to a single shared code. The divergence is recorded as a vocabulary gap and put to the RFC round.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "The pack’s largest divergence. E [Dat, Cas] → [Dat]; S [Ind] → []; obligationType mixed → organizational; V [Ses, Cor] → [] — the two passes named five value codes between them with zero overlap, all of them readings of the provision’s stated purposes rather than of a protected interest it names, so the layer is left undeclared. This is the first empty value layer in any AIO standards pack."
    },
    {
      "article": "第2部 C. 7)柱書・①③⑥ — アカウンタビリティ",
      "summary": "It is important that actors discharge accountability to stakeholders to a reasonable extent — as to securing traceability and as to their state of response to the Common Guiding Principles — in the light of their own role and of the degree of risk their AI systems and services bring; concretely, they are to keep the origin of data and the decisions taken during development, provision and use traceable and retrievable so far as technically possible and reasonable, to designate within the organization a person responsible for discharging accountability, and to document the related information, retain it for a certain period and keep it referenceable in an obtainable and usable form when and where needed.",
      "v": [
        "Bed"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Included precisely because it is organizational: designating a responsible person, documenting, and retaining are things an organization does, and no item-based measurement can observe any of them. The management-system guide accompanying this pack carries this section, not the certificate. The pack does not map 第2部 C. 7)④ (allocation of responsibility among parties by contract or voluntary commitment) or ⑤ (publishing policies, receiving stakeholder reports, periodic monitoring); both are candidates for a later version.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第2部 C. 共通の指針 7)アカウンタビリティ 柱書、①トレーサビリティの向上、③責任者の明示、⑥文書化",
        "quote": "[第2部 C.7)柱書] 各主体は、AIシステム・サービスの開発・提供・利用において、トレーサビリティの確保、「共通の指針」の対応状況等について、ステークホルダーに対して、各主体の役割及び開発・提供・利用するAIシステム・サービスのもたらすリスクの程度を踏まえ、合理的な範囲でアカウンタビリティを果たすことが重要である。 [第2部 C.7)①] データの出所、AIシステム・サービスの開発・提供・利用中に行われた意思決定等について、技術的に可能かつ合理的な範囲で追跡・遡求が可能な状態を確保する [第2部 C.7)③] 各主体においてアカウンタビリティを果たす責任者を設定する [第2部 C.7)⑥] 上記に関する情報を文書化して一定期間保管し、必要なときに、必要なところで、入手可能かつ利用に適した形で参照可能な状態とする",
        "rationale": "アカウンタビリティを果たす toward stakeholders, with a named 責任者 and documentation kept available 必要なときに、必要なところで, is the value of being a party that can be relied on to honour what it has undertaken (Bed); 追跡・遡求が可能な状態 across the lifecycle is traceability as collective order (Ses). What discharges the duty is documentary throughout — records kept in a referenceable form (Gui) — together with the retrievable record of data origin and decisions taken (Dat). Ind is declared under the standing source rule: the documentation, the retention arrangement and the designation of the responsible person are all unilaterally authored by the actor. No Gov: 柱書 owes accountability to ステークホルダー, not to an authority, and the quoted text names no regulator. ADJUDICATION 2026-08-14: S ([Ind]) and obligationType (organizational) agreed exactly, and the second pass reached Ind by the route the standing rule prescribes while stating the recipient limb explicitly — the account stakeholders receive is unilaterally authored by 各主体 itself, and the stakeholders are its recipients and are therefore not sources. E narrows to [Gui, Dat], both of which both passes reached; the second pass's Exp, read from ③'s 責任者を設定する as an assigned overseer, is not carried, and its own flag gives the reason — the quote assigns accountability rather than evidentiary weight, and a named responsible person is not a designated expert judgment. V narrows to [Bed], the single code both passes reached, from アカウンタビリティを果たす together with 責任者を設定する. v0.1's Ses (追跡・遡求が可能な状態 as collective order) and the second pass's Cor (reporting one's 「共通の指針」の対応状況 against a rule set) each rest on one pass; both are recorded and neither is carried.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S and obligationType agreed exactly. V [Bed, Ses] → [Bed]; E [Gui, Dat] retained against [Gui, Dat, Exp] — a designated 責任者 is an accountability assignment, not a designated expert judgment."
    },
    {
      "article": "第3部 D-6）ii.・D-7）i. — AI開発者：関連するステークホルダーへの情報提供と「共通の指針」の対応状況の説明",
      "summary": "AI developers are to provide information about the AI systems they develop to relevant stakeholders in a timely and appropriate manner, including through the AI provider — among other things the technical characteristics of the system, the mechanisms securing its safety, foreseeable risks arising from the results of use and the mitigations for them — and are to provide and explain to the AI provider that an AI's predictive performance or output quality may vary substantially after use begins and may not reach the assumed accuracy, together with the risks that may result.",
      "v": [
        "Hum",
        "Bed",
        "Sep"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The disclosure runs developer → provider, not developer → end user; the Guidelines route the end-user-facing duty through 第4部 P-6）ii. instead. The judgment correlate an item can reach is the stated-confidence one: whether a model volunteers that its accuracy may not hold rather than letting a capability claim stand. Whether the developer actually issued the document is outside any item's reach.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第3部 AI開発者に関する事項 D-6）ii.関連するステークホルダーへの情報提供（柱書および第2サブブレット）、D-7）i.AI提供者への「共通の指針」の対応状況の説明（第1ブレット）",
        "quote": "[第3部 D-6）ii.] 自らの開発するAIシステムについて、例えば以下の事項を適時かつ適切に関連するステークホルダーに（AI提供者を通じて行う場合を含む）情報を提供する [第3部 D-6）ii.] AIシステムの技術的特性、安全性確保の仕組み、利用の結果生じる可能性のある予見可能なリスク及びその緩和策等の安全性に関する情報 [第3部 D-7）i.] AI提供者に対して、AIには活用開始後に予測性能又は出力の品質が大きく変動する可能性、想定する精度に達しないこともある旨、その結果生じうるリスク等の情報提供及び説明を行う",
        "rationale": "D-7）i. requires the developer to tell the provider, in terms, that 予測性能又は出力の品質が大きく変動する可能性 exists and that 想定する精度に達しないこともある — a duty to state the limits of one's own performance and not overstate it, which is Hum, and the reason this entry earns a place over the neighbouring developer provisions. The disclosure is owed to a counterparty that will rely on it (Bed), and its named subject matter is 安全性に関する情報 covering 予見可能なリスク及びその緩和策, which protects the person exposed to the system (Sep). What discharges it is a document of specified content (Gui) carrying performance and accuracy statements (Dat). Ind is declared under the standing source rule: the developer is the unilateral author of the information about its own system. No Pro or Pee: the provision names no professional body and no scholarly source, however natural external evaluation might sound here. ADJUDICATION 2026-08-14: V ([Hum, Bed, Sep]), E ([Gui, Dat]) and S ([Ind]) agreed exactly — the only three-axis agreement in the pack, and the mirror of Action 3 in the G7 pack, which was also the disclosure-of-limitations provision. Both passes reached Hum from the same clause, D-7）i.'s requirement that the developer tell the provider 想定する精度に達しないこともある旨, and the blind pass described it in terms v0.1 would recognise: a mandated admission that one's own product may fall short. Both passes also applied the recipient rule to the same sentence and reached the same conclusion — the AI提供者 is expressly the recipient of the information and does not thereby become a source, so Ind stands alone. The second pass flagged Dat as an inference from 予測性能又は出力の品質が大きく変動する可能性, a claim only measurement can carry; v0.1 declared it independently, so it survives with the flag. obligationType is the single divergence and resolves to mixed, the more conservative of v0.1's mixed and the second pass's behavioral: the operative verbs are 情報を提供する and 説明を行う, which are acts toward a named counterparty, but what is provided is a documented information package about a system, and the pack does not claim that an item can observe whether the developer issued it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V, E and S agreed exactly — the pack’s only three-axis agreement and its firmest entry. obligationType retained at mixed against the second pass’s behavioral, under the conservative-tag rule."
    },
    {
      "article": "第4部 P-2）ii. — AI提供者：適正利用に資する提供",
      "summary": "AI providers are to define correctly the points requiring care in the use of an AI system or service, to use AI within the range the AI developer set, to secure at the point of provision the accuracy of the AI system or service and, where necessary, the currency of the training data, to consider whether there is any difference between the operating environment the AI developer assumed and the operating environment of the users of the AI system or service, and, after provision, to verify periodically whether the AI system or service is being used for an appropriate purpose.",
      "v": [
        "Cor",
        "Bed"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The provider role has no direct analogue in the EU AI Act's provider/deployer split: a Japanese AI提供者 sits between the developer and the business user, adding value to a system it did not build. The measurable direction here is refusal to exceed the developer's stated range even when a customer asks for it. Periodic verification of purpose is a monitoring programme and is organizational.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第4部 AI提供者に関する事項 P-2）ii.適正利用に資する提供（AIシステム実装時の第1・第2・第3・第4ブレット、およびAIシステム・サービス提供後の第1ブレット）",
        "quote": "[第4部 P-2）ii.] AIシステム・サービスの利用上の留意点を正しく定める [第4部 P-2）ii.] AI開発者が設定した範囲でAIを活用する [第4部 P-2）ii.] 提供時点でAIシステム・サービスの正確性・必要な場合には学習データの最新性（データが適切であること）等を担保する [第4部 P-2）ii.] AI開発者が設定したAIの想定利用環境とAIシステム・サービスの利用者の利用環境に違い等がないかを検討する [第4部 P-2）ii.] 適切な目的でAIシステム・サービスが利用されているかを定期的に検証する",
        "rationale": "AI開発者が設定した範囲でAIを活用する and AI開発者が設定したAIの想定利用環境との差異の検討 make the operative demand compliance with a prescribed operating basis the provider did not itself set (Cor); the section sits under 「2）安全性」 throughout and its point is that stakeholders are not harmed by out-of-range provision (Sep); and the duty is owed to the AI利用者 who will rely on what the provider supplies (Bed). What discharges it is the written specification — 利用上の留意点 and the developer's stated range read as issued (Gui) — together with securing 正確性・最新性 and 定期的に検証する, which is measurement against the declared basis (Dat). Ind is declared under the standing source rule: 開発者が設定した範囲 is material issued by the concerned industry itself and is what governs the provider's conduct here. Gov is NOT declared — no statute or authority appears in the quoted text. ADJUDICATION 2026-08-14: E ([Gui, Dat]), S ([Ind]) and obligationType (mixed) agreed exactly. Ind survives on the ground both passes gave independently: what governs the provider here is AI開発者が設定した範囲, material issued by another industry actor and named in the excerpt, and neither pass found any statute or authority in the quoted text. V narrows to the intersection [Cor, Bed]. Sep rests on v0.1 alone, which read the section's placement under 「2）安全性」 as making stakeholder safety the protected interest; the second pass, working from the excerpt alone, found no harm to persons named in it, and a section heading is not part of the quoted wording. That is the textual-determinacy rule operating exactly as intended, and the loss is recorded rather than argued away.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E, S and obligationType agreed exactly. V [Cor, Sep, Bed] → [Cor, Bed]: Sep was read from the section’s placement under 安全性 rather than from the quoted bullets, and does not survive textual determinacy."
    },
    {
      "article": "第5部 U-7）i. — AI利用者：関連するステークホルダーへの説明（評価に用いる場合）",
      "summary": "Where an AI business user refers to the output of an AI in evaluating a particular individual or group, they are to notify that individual or group that AI is being used, comply with the procedures the Guidelines recommend for securing the accuracy, fairness and transparency of the output, act under a reasonable human judgment that also takes automation bias into account, and discharge their duty to explain on request from the individual or group evaluated.",
      "v": [
        "Sdt",
        "Unc",
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The only provision in this pack whose every limb is discharged in a concrete case, which makes it the pack's primary item target. Note the scope: it bites when AI output is used as a reference for evaluating a person or group — hiring, assessment, scoring — and not on ordinary business use. Note too what it does not say: it requires notification and explanation on request, not a right to a human decision and not a right to contest the outcome. POST-ADJUDICATION 2026-08-14: the blind second pass classified this entry `mixed` rather than `behavioral`, on the ground that compliance with 当ガイドラインが推奨する諸手続き is a procedural regime rather than a judgment made in the case, and the conservative-tag rule carries that reading. The judgment correlates described above are unaffected and remain the reason this provision is the pack’s primary item target; what did not survive is the claim that every limb of it is discharged in a concrete case. The source layer is now empty — see the adjudication note.",
      "provenance": {
        "sourceUrl": "https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf",
        "retrievalUrl": "https://www.soumu.go.jp/main_content/001064279.pdf",
        "article": "第5部 AI利用者に関する事項 U-7）i.関連するステークホルダーへの説明（第3ブレット）",
        "quote": "[第5部 U-7）i.] 当該AIの出力結果を特定の個人又は集団に対する評価の参考にする場合は、AIを利用している旨を評価対象となっている当該特定の個人又は集団に対して通知し、当ガイドラインが推奨する出力結果の正確性、公正さ、透明性等を担保するための諸手続きを遵守し、かつ自動化バイアスも鑑みて人間による合理的な判断のもと、評価の対象となった個人又は集団からの求めに応じて説明責任を果たす",
        "rationale": "人間による合理的な判断のもと, with 自動化バイアスも鑑みて, puts the user's own reasoning above the model's output (Sdt); 出力結果の正確性、公正さ、透明性 owed to 評価の対象となった個人又は集団 is equality, justice and protection for the person being assessed (Unc); and 説明責任を果たす on request is an obligation owed to a counterparty and honoured (Bed). On evidence the provision names two things and no more: 人間による合理的な判断, a reasoned conclusion drawn without any external finding being cited (Log), and 当ガイドラインが推奨する[…]諸手続きを遵守し, an established written procedure followed as written (Gui). It names no metric, no expert and no case analysis. Gov is declared on the excerpt's own words under the standing rule — 当ガイドライン is named as the instrument decisive on which procedures must be followed, and that instrument is a joint MIC/METI document — and this is the one place in the pack where the source axis reaches past the actor's own material. Usr is NOT declared: the evaluated person's 求め triggers the duty but their position settles nothing. ADJUDICATION 2026-08-14: V ([Sdt, Unc, Bed]) agreed exactly, across three codes drawn from three different limbs of a single sentence — the strongest value-axis agreement in the pack. Everything else on this entry moved. obligationType resolves to mixed, the more conservative tag, against v0.1's behavioral; the pack therefore no longer carries a behavioral entry, and v0.1's claim that this is the one provision every limb of which is discharged in a concrete case is qualified accordingly — 当ガイドラインが推奨する[…]諸手続きを遵守し is a procedural regime, and the second pass classified the entry mixed on that ground. E narrows to [Gui], which both passes reached from that same clause. The divergent code is a genuine split over one phrase: v0.1 read 人間による合理的な判断 as Log, a reasoned conclusion drawn without any external finding being cited, and the second pass read the identical phrase as Exp, the interposed human's considered judgment. Neither survives, because neither is designated — the text demands only that the judgment be 合理的 and that it take 自動化バイアス into account, and it says nothing that makes its author a recognized specialist (Exp) or its form an argument from agreed premises (Log). The split is recorded as a vocabulary gap. S IS EMPTIED, and this is the most consequential change in the pack. v0.1 declared Gov, reasoning that 当ガイドライン is named as the instrument decisive on which procedures must be followed and that that instrument is a joint MIC/METI document. The second clause is the problem: the excerpt names 当ガイドライン and names no ministry, no authority and no issuer at all, so the step from the named instrument to a governmental source was taken OUTSIDE the quote, on knowledge of who wrote the Guidelines rather than on their words. The blind pass, holding the same excerpt, withheld both Gov and Ind for exactly that reason. Under the textual-determinacy rule the blind reading prevails and the source layer is left empty. The finding is recorded as a gap in its own right: a self-referential instrument — a norm that names ITSELF as what must be complied with — leaves the source axis unreachable from the excerpt, however obvious the issuer is to a reader who already knows it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V agreed exactly on all three codes. E [Log, Gui] → [Gui]; the Log/Exp split over 人間による合理的な判断 is recorded as a vocabulary gap. S [Gov] → []: 当ガイドライン is a self-reference and the excerpt never names its issuing ministries, so Gov was reached from outside the quote. obligationType behavioral → mixed; the pack now carries no behavioral entry."
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with the normative direction of each mapped provision. They do not assess whether an organization implements the management-system expectations those provisions are written in terms of (AI governance構築 and the agile-governance cycle, risk analysis and periodic monitoring regimes, privacy policies and statutory personal-information compliance, security controls, log recording and retention infrastructure, designation of an accountable officer, documentation and retention, and the allocation of responsibility along the value chain). The gap is wide for this norm: the Guidelines address 各主体 — AI開発者, AI提供者 and AI利用者, all of them businesses — and state almost every expectation as something such an organization is to do, not as a judgment to be reached in a concrete case. After the dual formalization and adjudication of 2026-08-14 that reading is confirmed on the numbers — seven of the ten mapped provisions are `mixed` and three are `organizational`; none is `behavioral`, and v0.1’s single behavioral tag at 第5部 U-7）i. did not survive the second reading.",
  "notes": [
    "draft-verified. Every entry carries a verbatim excerpt of the official Japanese text of 第1.2版 and a rationale argued from it, and on 2026-08-14 the second independent formalization recommended by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer received the pack id, the sourceNorm and each entry’s `provenance.article`, `sourceUrl`, `retrievalUrl` and `quote`, and nothing else: the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped by an extraction script before any file was opened, and neither the pack-authoring guideline (`docs/팩_추가_가이드라인.md`) nor the management guide nor any other standards pack was read. One disclosed protocol deviation on a neutral codebook is recorded in the contamination notice below. Human review remains outstanding and the V/E/S assignment is settled only by the public RFC process at https://aioq.org/en/rfc, so the pack does not advance beyond draft-verified. The need for a second pass was sharper here than for an English-language norm, because the operative text is in a language a reviewing team may not read; the second pass worked from the Japanese excerpts throughout, and every divergence below is a divergence between two readings of the same Japanese wording.",
    "THE GUIDELINES ARE VOLUNTARY SOFT LAW, AND THEY SAY SO OF THEMSELVES. 「はじめに」 records that rule-based regulation prescribing detailed conduct obligations was rejected because it 「イノベーションを阻害する可能性がある」, and that the Guidelines were instead written 「関係者による自主的な取組を促し、非拘束的なソフトローによって目的達成に導くゴールベースの考え方で」 — a goal-based approach that leads to the objective through non-binding soft law by encouraging voluntary action. The same section describes the instrument as a 「ガイドライン（非拘束的なソフトロー）」. Nothing in this pack is a legal requirement; there is no filing, no approval, no conformity assessment, no penalty and no enforcement mechanism attached to the Guidelines, and a measurement against this pack says nothing about compliance with any Japanese statute.",
    "CURRENCY VERIFIED — AND THE ROSTER PREMISE WAS OUT OF DATE. The pack roster and the build brief recorded ver 1.0 of 2024-04-19 as the source and asked whether a 1.01 or 1.1 revision had been published. Both had, and so had a further one. The MIC 掲載ページ for the Guidelines (https://www.soumu.go.jp/main_sosiki/kenkyu/ai_network/02ryutsu20_04000019.html), read on 2026-08-14, lists four versions with their publication dates: 第1.0版 (令和6年4月19日 = 2024-04-19), 第1.01版 (令和6年11月22日 = 2024-11-22), 第1.1版 (令和7年3月28日 = 2025-03-28) and 第1.2版 (令和8年3月31日 = 2026-03-31). THIS PACK FORMALIZES 第1.2版, the current version as at 2026-08-14. The Guidelines describe themselves as a Living Document updated 「適宜」 under multi-stakeholder involvement, and the last three revisions each landed at the end of a Japanese fiscal year (late March), so this pinning must be rechecked — and the pack version bumped — whenever the pack is revisited.",
    "PRIMARY SOURCE AND TWO OFFICIAL MANIFESTATIONS. `sourceUrl` throughout is the 本編 (main text) PDF of 第1.2版 as published by METI at https://www.meti.go.jp/shingikai/mono_info_service/ai_shakai_jisso/pdf/20260331_1.pdf, retrieved 2026-08-14. `retrievalUrl` is the copy of the same document published by MIC at https://www.soumu.go.jp/main_content/001064279.pdf, also retrieved 2026-08-14. The two files are NOT byte-identical (2,120,041 bytes for METI, 1,986,467 for MIC — different PDF production runs of the same document), which is why both were fetched and cross-checked rather than one being treated as a mirror of the other. No commentary, law-firm newsletter, consultancy summary or translation site was used for anything in this pack. The 別添（付属資料）, the checklist, the worksheet and the chatbot are separate deliverables and are not formalized here.",
    "QUOTE VERIFICATION METHOD — THREE EXTRACTIONS, TWO OF THEM OF DIFFERENT FILES. Both PDFs were converted to text with poppler `pdftotext -enc UTF-8`, and the METI PDF additionally with `pypdf`, giving three corpora. Each corpus was normalised by removing ALL whitespace and nothing else — no NFKC folding, no case folding, no character substitution. Every `quote` in this file was then split at its AIO editorial marks (the elision marker […] and the bracketed provision citations such as [第2部 C.1)②], which are not part of the official wording) and each resulting fragment was checked by exact substring match against all three corpora. All 31 fragments across the 10 entries matched all three. The three normalised corpora are 49,883 characters each; the two poppler corpora (METI and MIC) are identical character for character, and the pypdf corpus has an identical character multiset, differing only in the reading order of page numbers within the table of contents, which no quote touches.",
    "WHY WHITESPACE IS NORMALISED AWAY, AND WHY THAT IS NOT A LICENCE TO PARAPHRASE. The PDF text layer renders kerning spaces between Latin and Japanese script that are not part of the wording: the instrument's own title extracts as 「AI 事業者ガイドライン （第 1.2 版）」 but is published by both ministries in HTML as 「AI事業者ガイドライン（第1.2版）」, and the same applies throughout to 「AIシステム・サービス」, 「AI開発者」 and every other Latin-Japanese boundary. Japanese body text is also hard-wrapped mid-word by the extractor. Quotes in this file are therefore written without those artefacts and matched whitespace-insensitively. Nothing else was normalised: full-width parentheses, the 、 and 。 punctuation, the ・ separators and the circled numerals are reproduced exactly as the source prints them, and a fragment that differed from the source by a single character would have failed the check.",
    "FOOTNOTE REFERENCE NUMERALS ARE ELIDED, AND MARKED. The Guidelines carry 55 footnotes and the PDF text layer renders their reference numerals inline, so that the source reads 「自動化バイアス23等の」 and 「個人情報保護法39等の」. Where a quoted fragment spans such a numeral it is replaced by the elision marker […] — three fragments are affected, in 第2部 C.1)②, C.3)② and C.4)①. The elided material is a reference numeral only; no substantive wording is omitted at any of the three points. Footnote text itself is never quoted as though it were operative, and no code in this pack is assigned from a footnote.",
    "QUOTATION BASIS — VERIFIED, AND NOT THE ONE THE BRIEF ASSUMED. The build brief assumed 政府標準利用規約（第2.0版）. That instrument has been superseded. Both ministries now place their website content under 公共データ利用規約（第1.0版） (Public Data License 1.0, PDL1.0), a Digital Agency instrument 定められた 令和6年7月5日 (2024-07-05): METI at https://www.meti.go.jp/main/rules.html states 「経済産業省ウェブサイト […] で掲載・発信している情報 […] の著作権は、特記されていない限り経済産業省に帰属し、権利表記の記載がない限り「公共データ利用規約（第1.0版）」（PDL1.0）に準拠した利用条件の下で、利用することができます。」 and MIC at https://www.soumu.go.jp/menu_kyotsuu/policy/tyosaku.html states the same in its own terms. PDL1.0 §1 allows 複製、公衆送信、翻訳・変形等の翻案等 freely, including commercially. PDL1.0 §1.7 states verbatim: 「本利用ルールは、クリエイティブ・コモンズ・ライセンスの表示4.0 国際ライセンスに規定される著作権利用許諾条件（以下「CC BY」といいます。）と互換性があります。国 […] は、本利用ルールが適用される本コンテンツについて、利用者がCC BYに従って利用することを許諾します。」 — the rule is compatible with CC BY 4.0 and the State licenses use under CC BY. It also preserves the older regime for existing users: 「既に以前の政府標準利用規約にしたがってコンテンツを利用している場合は、引き続きその条件が適用されます。」 The 本編 PDF of 第1.2版 carries no 権利表記 of its own that would displace PDL1.0 (checked against the extracted text: 利用規約, 転載, 無断 and Copyright do not appear anywhere in the 本編 at all, and the ten occurrences of 著作権 are all in footnotes 32 and 34 citing Agency for Cultural Affairs and Cabinet Office material on AI and copyright, except one inside the reproduced Hiroshima Process Code of Conduct text at 第3部 — none of them is a rights notice about the Guidelines themselves). Attribution is given in this file and in the accompanying management guide; PDL1.0 §1.1 additionally requires that adapted content state that it was adapted and by whom, which is what the pack name field (\"AIO formalization\") and these notes do. PDL1.0 §1.2 puts third-party material outside the licence, so the pack quotes only the ministries' own operative wording and never the material the footnotes cite.",
    "LANGUAGE. The Japanese text is canonical. MIC publishes an English edition of 第1.2版, and labels it under the heading 「＜ガイドライン資料（英語版・仮訳）＞」 — 仮訳 means provisional translation. No fragment of that English edition was used anywhere in this pack. Every English string here — the pack name, the summaries, the rationales, the notes — is AIO's own rendering, written for comprehension and carrying no authority of its own. Where a reading turns on precise wording, the Japanese governs. Nothing in this pack may be presented, cited or reproduced as an official or authorised English translation of the Guidelines, and it is in particular not the ministries' 仮訳.",
    "PROVISION SELECTION — 10 UNITS, AND WHAT WAS LEFT OUT. Six of the ten Common Guiding Principles (第2部 C) are mapped — 1)人間中心, 2)安全性, 3)公平性, 4)プライバシー保護, 5)セキュリティ確保, 6)透明性 and 7)アカウンタビリティ, which is seven of the ten — together with one provision each from the three actor-specific parts (第3部 AI開発者, 第4部 AI提供者, 第5部 AI利用者). EXCLUDED, with reasons, all of them candidates for reconsideration at RFC: 8)教育・リテラシー, 9)公正競争確保 and 10)イノベーション are the three principles the Guidelines themselves place under 「社会と連携した取組が期待される事項」 rather than under what actors 「べき」 do; 9) has no sub-items at all, and all three are discharged by training programmes, market conduct and R&D investment with no per-case judgment correlate. 第2部 E (AIガバナンスの構築) sets out the agile-governance cycle and is the single most important section for an operator, but it is organizational end to end and belongs to the management-system guide rather than to an item bank. Within the mapped principles, sub-items not quoted include 1)①③④⑤⑥, 2)②適正利用 and ③適正学習, 6)②③④ (stakeholder information provision, reasonable and sincere response, explainability) and 7)④⑤; the developer-side data and bias provisions D-2）i., D-3）i. and D-3）ii. and the user-side U-2）i., U-3）i. and U-4）i. are likewise unmapped, several of them strong candidates for a later version.",
    "DELIBERATE OVERLAP WITH THE G7 PACK, NOT FORMALIZED TWICE. 第2部 D of the Guidelines reproduces the Hiroshima Process International Guiding Principles for All AI Actors in full, and 第3部 reproduces the Hiroshima Process International Code of Conduct for Organizations Developing Advanced AI Systems for developers of advanced AI. That Code is already formalized as the separate `g7-hiroshima-code` pack. Nothing in 第2部 D or in the 行動規範 reproduction is mapped here, to avoid two AIO packs formalizing the same eleven actions under two article-numbering schemes. An operator whose interest is the Hiroshima Process material should read that pack; an operator whose interest is the Japanese domestic framing should read this one. The Guidelines' own instruction is that 全てのAI関係者 should act in accordance with the Guiding Principles, so the two packs are complementary rather than alternatives.",
    "RELATIONSHIP TO JAPANESE STATUTE — RECORDED, NOT FORMALIZED. Since the first version of the Guidelines, Japan has enacted 「人工知能関連技術の研究開発及び活用の推進に関する法律」（令和7年法律第53号）. The Cabinet Office page cited by the Guidelines themselves (https://www8.cao.go.jp/cstp/ai/ai_act/ai_act.html) records promulgation on 2025-06-04 and full entry into force on 2025-09-01; the Guidelines' own 「はじめに」 states 「2025年6月に公布、9月に全面施行された」. Under 第13条 of that Act, 「人工知能関連技術の研究開発及び活用の適正性確保に関する指針」 was decided by the 人工知能戦略本部 on 令和7年12月19日 (2025-12-19). AIO has NOT read the statutory text or that 指針 for this pack, formalizes neither, and takes no position on what obligations or consequences either carries. The point of recording them is the opposite of a compliance claim: an operator in Japan is now working against a statute and a Cabinet-level 指針 as well as these Guidelines, and a pack built only on the Guidelines does not see the other two. Anyone reading this pack as a picture of Japanese AI obligations is reading it wrong.",
    "INFERENCE CODES, AFTER ADJUDICATION. v0.1 carried exactly two codes assigned from a provision’s structure rather than its words, each flagged in its own rationale and put to the RFC round, and the dual formalization resolved both. (1) Unc at 第2部 C.2)①, read from 権利侵害の重大性 where the text does not say whose rights are meant: the blind pass reached Unc from the same words, so it is NO LONGER AN INFERENCE — it is corroborated. (2) Tri at 第2部 C.3)②, read from 多様な背景、文化又は分野のステークホルダーと対話した上で、方針を決定する: the blind pass reached Tri as well and flagged it as an inference for the same reason, so it survives under the standing rule that a flagged inference is carried only where both passes reach it, and it KEEPS the flag. Every inference code the second pass introduced and v0.1 did not reach was removed under the same rule: Gui at 第2部 C.5)① (技術水準 read as an established technical standard), Pop at 第2部 C.4)① (人々の合理的な期待 read as common expectation), Exp at 第2部 C.3)②, at C.7)③ and at 第5部 U-7）i., and Sda at 第2部 C.1)②. Dat at 第3部 D-6）ii.・D-7）i. was flagged by the second pass and survives only because v0.1 had declared it independently. No code in this pack is now carried on a single pass’s inference.",
    "SOURCE-AXIS POLICY (P4, decided once across the Wave 1 packs, applied uniformly here, and RE-CHECKED against the blind pass). The rule is unchanged: S=`Gov` only where the quoted excerpt itself names the governmental authority or the legal instrument decisive on the substance of the duty; S=`Ind` only where the excerpt makes an actor the unilateral author of the operative artefact; a party named as the RECIPIENT of information, a report or an explanation never becomes a source by being named; and the axis is applied as a FILTER, never as a generator. Adjudication changed the distribution twice, both times against v0.1. CORRECTION AFTER ADJUDICATION (2026-08-14): `Gov` is carried at ONE entry, not two. It survives at 第2部 C.4)①, where 個人情報保護法[…]等の関連法令 names the legal instrument decisive on the substance — the same test that kept `Gov` at Action 11 of the G7 pack and removed it at Action 4 — and it is REMOVED at 第5部 U-7）i., where 当ガイドラインが推奨する[…]諸手続き names the instrument but not its issuer: reaching `Gov` there required knowing that the Guidelines are a joint MIC/METI document, which is knowledge from outside the excerpt, and the blind pass withheld both `Gov` and `Ind` on exactly that ground. `Ind` is carried at THREE entries, not five — 第2部 C.7), 第3部 D-6）ii.・D-7）i. and 第4部 P-2）ii. It is removed at 第2部 C.4)①, where the actor’s own privacy policy is the compliance output the provision demands rather than a governing position the actor authors, and at 第2部 C.6)①, where the quoted bullets name no author at all and `Ind` had been read off the identity of the duty-bearer. SIX of the ten entries now carry no source class — 第2部 C.1)②, C.2)①, C.3)②, C.5)①, C.6)① and 第5部 U-7）i. — and four of those six (C.1)②, C.2)①, C.3)②, C.5)①) were empty in BOTH passes independently. The fact that the Guidelines are themselves a joint instrument of two ministries is never carried into the source axis, which is why eight entries lack `Gov` even though every one of them is a government expectation. `Pro` and `Pee` appear nowhere in this pack, and the blind pass withheld `Pro` at 第2部 C.3)② in its own words, for the reason v0.1 had already recorded as a vocabulary gap.",
    "VOCABULARY AND SCHEMA GAPS (feeding a future AIO 00011 RFC). v0.1 contributed two, both corroborating gaps other packs had recorded; the dual formalization confirmed both and added four more. CONFIRMED. (1) PRIVACY HAS NO VALUE CODE OF ITS OWN — 第2部 C.4) protects プライバシー as an interest in its own right, and v0.1 routed it to `Sep` as the nearest carrier with the routing flagged. The blind pass routed it to `Sep` too. The Chinese generative-AI pack split three ways at 第九条 and 第十一条, the Council of Europe pack recorded the gap at Art. 11, and the G7 pack’s two passes chose `Ses` against `Sep` at Action 5 — this is the first time two independent passes have AGREED on a carrier, which narrows the gap without closing it. (2) DIVERSE-BACKGROUND STAKEHOLDERS AS A SOURCE CLASS — the 多様な背景、文化又は分野のステークホルダー of 第2部 C.3)② fit none of `Pro`, `Tes` or `Usr`, and the blind pass withheld `Pro` for that reason without having seen the gap recorded, which turns a single reading into a corroborated finding. Same shape as the Chinese pack’s 公衆 gap at 第十五条. NEW, FROM THE ADJUDICATION — canonical Wave 3 numbers 24-26 (assigned in the wave-end consolidation, 2026-08-14). (24) A PROVISION THAT STATES PURPOSES RATHER THAN A PROTECTED INTEREST HAS NO VALUE CARRIER — 第2部 C.6)① names 検証可能性, 事故等の原因究明, 再発防止策の検討 and 損害賠償責任要件の立証, and the two passes read those purposes into FIVE value codes with ZERO overlap (`Ses` and `Cor` against `Bed`, `Sep` and `Unc`). The value layer is left undeclared as a result — the first empty `v` array in any AIO standards pack — and the RFC question is whether the catalogue lacks a carrier for procedural verifiability, or whether provisions of this shape should simply carry no value layer. (25) 「人間による合理的な判断」 HAS NO EVIDENCE CARRIER — at 第5部 U-7）i. one pass read it as `Log` (a reasoned conclusion citing no outside finding) and the other as `Exp` (the considered judgment of one recognized specialist), and the text supports neither: it demands only that the judgment be 合理的 and take 自動化バイアス into account, and says nothing about who makes it or in what form. The reasoned judgment of a competent lay decision-maker sits between the two codes and is carried by neither. (26) THE SELF-REFERENTIAL INSTRUMENT — 当ガイドラインが推奨する[…]諸手続き at 第5部 U-7）i. makes the Guidelines themselves the decisive procedural authority without naming their issuer, so the source axis cannot be reached from the excerpt at all. This is a general problem for soft-law instruments that cite themselves, and it is what removed the pack’s second `Gov`. (W2-23 CONFIRMED, NOT A NEW NUMBER) DEFEASIBLE MODALITY AND RANKING — the Japanese text carries an explicit two-step modality ladder INSIDE single provisions: at 第2部 C.2)柱書, 生命・身体・財産 carries すべきである while 精神及び環境 carries only 重要である; at 第2部 C.4)柱書, 関係法令を遵守すべきである stands against プライバシーを尊重し、保護することが重要である. The blind pass read a ranking off that contrast in both places and ordered its arrays accordingly (Sep > Unn; Cor > Sep). A `v` array is a set tested by membership and carries no order, and no field records how strongly a provision points, so the ladder cannot be encoded — the same schema gap the G7 pack recorded as Wave 2 gap 23, sharpened here because the contrast is explicit, lexically marked, and internal to a single sentence pair. Both rankings are recorded in the relevant entries’ adjudication notes rather than hardened into array order, which is why v0.1’s arrays survive unreordered at those two entries. ONE ROUTING DIVERGENCE, recorded without a gap claim: at 第2部 C.3)② the 自動化バイアス clause was routed to the value axis by one pass (`Sdt`) and to the evidence axis by the other (`Exp`), while the same concept at 第2部 C.1)② produced `Sdt` from both — so what diverged was the axis, not the vocabulary. The `Sdt`/`Sda` split over 意思決定 at 第2部 C.1)② is another instance of Wave 2 gap 13, first recorded on the OECD pack at Principle 1.2(a); the cross-pack convention routing human-judgment provisions to `Sdt` is applied here.",
    "MEASUREMENT SCOPE (per-entry `obligationType`, pack-level `measurementScope`). After adjudication the distribution is SEVEN `mixed` and THREE `organizational` — 第2部 C.4), C.6)① and C.7) — and NONE `behavioral`. v0.1’s distribution was 1 behavioral / 7 mixed / 2 organizational, and both divergences on this axis were resolved toward the more conservative tag: 第2部 C.6)① from mixed to organizational, and 第5部 U-7）i. from behavioral to mixed. THE PACK THEREFORE NO LONGER CARRIES A BEHAVIORAL ENTRY. That is a property of the source rather than a retreat: the Guidelines address 各主体 — AI開発者, AI提供者 and AI利用者, businesses in every case — and phrase almost every expectation as something such an organization is to put in place; even 第5部 U-7）i., the one provision whose limbs land in a concrete case, requires compliance with 当ガイドラインが推奨する諸手続き, which is a procedural regime an organization operates. The judgment correlates v0.1 identified are unaffected and remain the reason particular provisions are worth items — 第5部 U-7）i. (notifying the person being evaluated and reasoning under automation bias rather than deferring to the output), 第2部 C.1)② (not treating manipulation of decision-making as an available design objective, and handling election-adjacent output carefully), 第2部 C.5)① (not asserting that vulnerability has been eliminated) and 第3部 D-7）i. (volunteering that accuracy may not hold rather than letting a capability claim stand) — but a correlate an item can test is not the same thing as a duty an item can observe being discharged. A pass against this pack is evidence about model judgment only, and is never evidence that an organization has implemented the Guidelines.",
    "Methodology for the provision → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. Codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary — the same codes an AIO 20002 record carries.",
    "NO ENDORSEMENT. AIO wrote this formalization. 総務省 (the Ministry of Internal Affairs and Communications) and 経済産業省 (the Ministry of Economy, Trade and Industry) took no part in it, have not reviewed, approved or endorsed it, and have not been consulted. Neither has the AIネットワーク社会推進会議, the AIガバナンス検討会, the AI事業者ガイドライン検討会, IPA, the Japan AI Safety Institute, the 人工知能戦略本部 or any other Japanese body. AIO certifies conformance to AIO's own formalization of the Guidelines. That is not an assessment against the Guidelines by their publishers, not a legal conformity assessment, not any form of recognition under 人工知能関連技術の研究開発及び活用の推進に関する法律, and confers no status of any kind under Japanese law. Phrasings such as \"METI-certified\", \"総務省認定\", \"AI事業者ガイドライン準拠認証\" or \"Japan AI Guidelines compliant\" are not available to anyone using this pack.",
    "No item bank has been built for this pack, so `itemBankRef.publicSet` and `privateSet` are both null and the pack cannot yet back a certificate of any tier. It appears in the catalogue as registered and awaiting measurement. When a public set is seeded it must respect the limits recorded in the per-entry `note` fields — in particular the 第2部 C.6)① note, which records that an AIO 20002 record covers only the 判断根拠 limb of the logging this provision requires, and the 第2部 C.3) note, which records that the fairness principle is stated as an endeavour and does not support any claim that a certified model is unbiased.",
    "ADJUDICATION METHOD (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as SETS. Exact agreement was auto-accepted. Divergences were adjudicated under a policy fixed before the divergences were examined, carried forward from Waves 1 and 2: a code stands only where the QUOTED TEXT designates it; the reading better grounded in the quote prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken; the intersection is an allowed outcome, and where the intersection is empty the layer is left UNDECLARED rather than filled by choosing a side; no third reading is invented, and every adjudicated set is a subset of at least one pass’s set. Five sub-rules did the work: (a) a code flagged INFERENCE survives only where both passes reached it; (b) an empty layer declared by one pass defeats a single-pass inference offered by the other; (c) a divergent `obligationType` resolves to the more conservative tag; (d) an ordered hierarchy is carried only where the text itself ranks, and even then it is recorded in prose, because the arrays are unordered sets; (e) a party named as a recipient is never thereby a source, and the source axis is a filter and never a generator. AGREEMENT STATISTICS, across ten entries: V 4/10, E 5/10, S 7/10, `obligationType` 6/10, all four axes together 1/10 — the sole four-axis agreement is 第2部 C.2). The shape of the result is distinctive. The source axis agreed best, as it did on the G7 pack, because a norm whose addressees are its own duty-bearers leaves little room to disagree about whose material counts — and four of the seven source agreements are agreements that the layer is EMPTY, reached independently, which is the harder kind of agreement to arrive at by chance. The value axis agreed worst, and its divergences are the pack’s substantive findings rather than noise: one entry (第2部 C.6)①) produced five value codes with no overlap at all and now carries no value layer.",
    "CONTAMINATION NOTICE — one protocol deviation, disclosed by the second pass itself, on a NEUTRAL CODEBOOK. FORMALIZATION_METHODOLOGY.md §4 states that the V/E/S codes are the canonical AIO 00011 vocabulary served at `/api/framework/vocabulary` but does not itself carry the code tables, so the second formalizer followed that pointer to the vocabulary route and its data module and read the code/name/definition tables only — `src/app/api/framework/vocabulary/route.ts`, `src/app/lib/frameworkVocabulary.ts` lines 1–33, and the VALUES / EVIDENCE_CAT / SOURCE_CAT tables in `src/app/components/standards/workshopData.ts` lines 21–193 — in order to assign canonical three-letter codes rather than invent labels, which §4 treats as unverified. A glob listing incidentally exposed pack FILENAMES; no pack file was opened, and no `.pack-verify` file, no `docs/` file, no management guide and no git history was read. ASSESSMENT: protocol deviation disclosed, neutral codebook only, NO CONTAMINATION. The code tables carry no provision mappings, no pack fields and no prior adjudication, so no first-pass judgment was observable through them, and no axis of this pack is reported with a contamination caveat. The deviation is recorded rather than waved through for two reasons: an undisclosed lookup would make the blindness claim unfalsifiable, and the episode argues for shipping the code tables to the second formalizer as part of the blind packet in future waves instead of leaving them to be fetched from the codebase."
  ]
}
