{
  "$schema": "./schema.json",
  "id": "oecd-ai-principles",
  "name": {
    "en": "OECD AI Principles (OECD/LEGAL/0449) — AIO formalization",
    "ko": "OECD 인공지능 권고 (OECD/LEGAL/0449) — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Recommendation of the Council on Artificial Intelligence",
    "publisher": "Organisation for Economic Co-operation and Development (OECD) — adopted by the OECD Council",
    "version": "OECD/LEGAL/0449, adopted 22 May 2019, amended 8 November 2023 and 3 May 2024 (amended consolidation, English official text)",
    "url": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449"
  },
  "vesMapping": [
    {
      "article": "Principle 1.1 — Inclusive growth, sustainable development and well-being",
      "summary": "Stakeholders should proactively engage in responsible stewardship of trustworthy AI in pursuit of beneficial outcomes for people and the planet, the instrument naming augmentation of human capabilities, inclusion of underrepresented populations, reduction of economic, social, gender and other inequalities, and protection of natural environments as its examples.",
      "v": [
        "Unc",
        "Unn"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The only entry in this pack with an empty `e` and an empty `s`, and the emptiness is deliberate. Principle 1.1 designates no evidence class and no source class whatever: it names outcomes to be pursued and nothing about what would establish that they are being pursued or whose account of that is to be trusted. Under FORMALIZATION_METHODOLOGY.md §4 an undeclared layer is the honest signal that the layer is out of scoring scope, so both are left empty rather than filled with a plausible-sounding Gui/Ind pair. Raised as an RFC question: whether a values-only entry should be scorable at all, and if so on the V layer alone.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.1",
        "quote": "Stakeholders should proactively engage in responsible stewardship of trustworthy AI in pursuit of beneficial outcomes for people and the planet, such as augmenting human capabilities and enhancing creativity, advancing inclusion of underrepresented populations, reducing economic, social, gender and other inequalities, and protecting natural environments, thus invigorating inclusive growth, well-being, sustainable development and environmental sustainability.",
        "rationale": "The values the principle says must prevail are stated in its own examples. 'advancing inclusion of underrepresented populations, reducing economic, social, gender and other inequalities' is Unc — equality, justice and protection for all people — and it is the operative direction an item can score: where an option is cheaper or more convenient but leaves an underrepresented group worse served, the principle points away from it. 'protecting natural environments' and the closing 'environmental sustainability' give Unn, which no other provision in the instrument supplies and which no other AIO standards pack has yet carried. E and S are left empty because the sentence names no evidence and no source: it does not say what would show that stewardship is responsible, nor whose account of that governs. Sdt was considered for 'augmenting human capabilities and enhancing creativity' and withheld — enlarging what a person can do is not the same as protecting their freedom to reach their own conclusions, and reading it as Sdt would be an inference the words do not carry. ADJUDICATION 2026-08-14: E and S agreed exactly — both independent passes left both layers undeclared — and are auto-accepted. On V the second pass proposed adding Bec for 'beneficial outcomes for people' and 'well-being'; Bec is the catalogue's care for those close by, which an instrument-wide outcome clause does not name, so the intersection [Unc, Unn] stands. obligationType is lowered from mixed to organizational: the duty-bearer is 'stakeholders' engaging in 'stewardship', which the second pass read as a posture of the actor rather than a property of any single output, and a divergent obligationType resolves to the more conservative tag throughout this wave. The second pass separately recorded that 'augmenting human capabilities and enhancing creativity' has no home in the 19-value catalogue — it considered Sdt and Sti and declared neither — which is the same withholding v0.1 made and is carried to the RFC round as Wave 2 gap 16.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V ([Unc, Unn]), E ([]) and S ([]) survive adjudication; the second pass's proposed Bec was not carried because the sentence names no proximate beneficiary. obligationType lowered mixed → organizational under the wave-wide rule that a divergent obligationType resolves to the more conservative tag. This is the only entry in Wave 1 or Wave 2 where two independent passes left both E and S undeclared."
    },
    {
      "article": "Principle 1.2(a) — Respect for the rule of law, human rights and democratic values, including fairness and privacy",
      "summary": "AI actors should respect the rule of law, human rights, and democratic and human-centred values throughout the AI system lifecycle — the instrument enumerating non-discrimination and equality, freedom, dignity, autonomy of individuals, privacy and data protection, diversity, fairness, social justice and internationally recognised labour rights — and this includes addressing AI-amplified misinformation and disinformation while respecting freedom of expression and other rights protected by applicable international law.",
      "v": [
        "Cor",
        "Unc",
        "Sda",
        "Unt"
      ],
      "e": [],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Classified `behavioral` in v0.1 and lowered to `mixed` at the 2026-08-14 adjudication. The blind second pass read ‘throughout the AI system lifecycle’ as management-system reach, which is the counter-reading v0.1 had itself put to the RFC round; the divergence was resolved for the more conservative tag, and no entry in this pack is now `behavioral`. The provision imposes a standard of conduct and names no artefact, no process and no management system: it is discharged, or not, in the judgment made in the concrete case. That classification is itself put to the RFC round, since 'throughout the AI system lifecycle' can be read as importing a programme duty; the counter-reading, adopted here, is that the phrase states when the standard applies rather than what must be built. The final limb — addressing misinformation while respecting freedom of expression — is a two-sided direction: an item scoring only suppression of falsehood, or only non-interference, would misread it.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.2, point a)",
        "quote": "AI actors should respect the rule of law, human rights, democratic and human-centred values throughout the AI system lifecycle. These include non-discrimination and equality, freedom, dignity, autonomy of individuals, privacy and data protection, diversity, fairness, social justice, and internationally recognised labour rights. This also includes addressing misinformation and disinformation amplified by AI, while respecting freedom of expression and other rights and freedoms protected by applicable international law.",
        "rationale": "This is the instrument's densest value enumeration and every code is taken from a word in it rather than from the principle's heading. 'respect the rule of law' is Cor — compliance with rules, laws and formal procedures — and it leads because it is the first thing the sentence demands. 'non-discrimination and equality', 'fairness', 'social justice', 'dignity' are Unc. 'freedom' and 'autonomy of individuals' are Sda, the freedom to choose one's own course, which the enumeration states separately from equality and which therefore is not folded into Unc. 'privacy and data protection' is Sep, following the AIO 00011 treatment of privacy erosion as a personal-security loss. 'diversity' is Unt, understanding and accepting those who differ. E is Gui: what the sentence points to as decisive is the written legal order itself — 'the rule of law' and 'rights and freedoms protected by applicable international law' — which is an established written standard, not a measurement, a case analysis or an expert's opinion. S is Gov for the same reason: applicable international law is the position of a governing authority. Ind is deliberately withheld here alone among the Section 1 entries, because this is the one principle that contains no clause delegating the standard to the actor's own contextual determination; the AI actor is told to respect a standard set elsewhere. ADJUDICATION 2026-08-14: S ([Gov]) agreed exactly and survives the Wave 2 source-axis re-check — 'the rule of law' and 'rights and freedoms protected by applicable international law' name government norms as decisive on the substance of what must be respected, which is the test. V loses Sep: the second pass folded 'privacy and data protection' into Unc rather than reading it as a personal-security interest, and the intersection [Cor, Unc, Sda, Unt] is taken; privacy is the Wave 1 vocabulary gap 2, now confirmed in a fourth instrument. E loses Gui: the quoted sentence names the rule of law as the object of respect, not as what discharges the duty, and the second pass left E undeclared for exactly that reason. obligationType is lowered from behavioral to mixed — 'throughout the AI system lifecycle' reaches design and deployment, which carries management-system weight — so the pack's only behavioral entry does not survive adjudication.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Cor, Unc, Sda, Sep, Unt] → [Cor, Unc, Sda, Unt]; E [Gui] → []; S [Gov] agreed exactly and retained under the Wave 2 source-axis policy; obligationType behavioral → mixed. The loss of the behavioral tag falsifies v0.1 note 12's claim that this pack held the first behavioral entry in the AIO pack series; the note is corrected in v0.2."
    },
    {
      "article": "Principle 1.2(b) — Mechanisms and safeguards, including human agency and oversight",
      "summary": "AI actors should implement mechanisms and safeguards — such as capacity for human agency and oversight — including to address risks arising from uses outside of intended purpose, intentional misuse or unintentional misuse, in a manner appropriate to the context and consistent with the state of the art.",
      "v": [
        "Sdt",
        "Sep"
      ],
      "e": [
        "Exp"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Pro is withheld, and the withholding is the point of comparison with the EU AI Act pack. EU AI Act Art. 26(2) requires deployers to assign oversight to natural persons 'who have the necessary competence, training and authority', which is what earned Pro in that pack's Art. 14 entry. The OECD text names capacity for human agency and oversight and says nothing about the competence, credential or authority of whoever exercises it, so the professional source class is not available here. An operator reading the two instruments together should not import the EU qualification into the OECD principle.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.2, point b)",
        "quote": "To this end, AI actors should implement mechanisms and safeguards, such as capacity for human agency and oversight, including to address risks arising from uses outside of intended purpose, intentional misuse, or unintentional misuse in a manner appropriate to the context and consistent with the state of the art.",
        "rationale": "'capacity for human agency and oversight' makes the human's own judgment the thing to be preserved against the system's output, which is Sdt. The risks named — uses outside of intended purpose, intentional and unintentional misuse — are risks of harm to people, giving Sep, and the reference point against which a use is 'outside of intended purpose' is the declared purpose itself, which is Cor: the safeguard exists so that the system is not quietly operated beyond what it was declared for. Two evidence classes are decisive and they correspond to the two halves of the sentence: what an oversight capacity delivers is the considered judgment of the person exercising it (Exp), and what a 'mechanism or safeguard' is, as an artefact, is a documented control (Gui). S is Ind because the clause 'in a manner appropriate to the context and consistent with the state of the art' expressly delegates the sufficiency standard to the AI actor's own determination; that delegation clause, and not the mere fact that the instrument is voluntary, is what licenses Ind in this pack. ADJUDICATION 2026-08-14: obligationType (mixed) agreed exactly. On V the two passes split Sdt against Sda over the same phrase, 'capacity for human agency and oversight'. The split is resolved for Sdt on the cross-pack convention already fixed elsewhere: eu-ai-act-v0.2 codes Art. 14 human oversight as Sdt, and unesco-ai-ethics ¶¶26, 36, 38 and 40 carry Sdt by agreement of both passes for the same 'human judgment kept terminal' idea. Sep survives because both passes declared it, the second pass flagging it as read from the ordinary sense of misuse risk. Cor does not survive: v0.1 read the declared purpose as the standard against which a use is 'outside of intended purpose', which the second pass did not reach and the words do not carry. E narrows to the intersection [Exp] — an oversight capacity delivers the overseer's considered judgment — while Gui, the safeguard as documented artefact, was declared by one pass only. S retains [Ind] under the Wave 1 source-axis rule: the quote makes AI actors the party that implements the safeguards and determines what is 'appropriate to the context'. The Sdt/Sda split is recorded as Wave 2 gap 13.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sdt, Sep, Cor] → [Sdt, Sep]; E [Exp, Gui] → [Exp]; S [Ind] retained under the source-axis rule against the second pass's undeclared reading; obligationType (mixed) agreed exactly. The second pass coded Sda where v0.1 coded Sdt for 'human agency and oversight'; Sdt prevails on the cross-pack convention and the divergence is carried to the RFC round."
    },
    {
      "article": "Principle 1.3 — Transparency and explainability",
      "summary": "AI actors should commit to transparency and responsible disclosure regarding AI systems and should provide meaningful information, appropriate to the context and consistent with the state of art, to foster general understanding of a system's capabilities and limitations, to make stakeholders aware of their interactions with AI systems including in the workplace, to give — where feasible and useful — plain and easy-to-understand information on the sources of data/input, factors, processes and/or logic behind an output so that those affected can understand it, and to provide information enabling those adversely affected to challenge the output.",
      "v": [
        "Sdt",
        "Hum",
        "Unc"
      ],
      "e": [
        "Gui",
        "Log"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The provision an AIO 20002 record comes closest to serving, and the closeness must not be overstated. Limb iii asks for information on 'the sources of data/input, factors, processes and/or logic that led to' an output; an AIO record's V:, E: and S: layers report which value priorities, evidence types and source classes the model took to be decisive. That is a self-reported account of reasoning, not a causal trace of computation, and it does not by itself discharge limb iii. Limbs ii and iv — interaction awareness and a route to challenge an output — are interface and process duties an AIO record does not touch. Limb ii is quoted only in elision here; the pack's own summary carries it.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.3, chapeau and points i, iii and iv",
        "quote": "AI Actors should commit to transparency and responsible disclosure regarding AI systems. To this end, they should provide meaningful information, appropriate to the context, and consistent with the state of art: i. to foster a general understanding of AI systems, including their capabilities and limitations, […] iii. where feasible and useful, to provide plain and easy-to-understand information on the sources of data/input, factors, processes and/or logic that led to the prediction, content, recommendation or decision, to enable those affected by an AI system to understand the output, and, iv. to provide information that enable those adversely affected by an AI system to challenge its output.",
        "rationale": "The stated purpose of limb iii is 'to enable those affected by an AI system to understand the output' — the disclosure exists so that another party can reach their own understanding, which is Sdt exactly as the AIO vocabulary defines it. Limb i requires the disclosure to carry limitations alongside capabilities, which is Hum: recognising one's own limits and not overstating. Limb iv is owed specifically to 'those adversely affected' and gives them a route to contest, which is Unc — protection and justice for the person on the receiving end. Two evidence classes: the duty is discharged by information provided, that is by documentation (Gui), and limb iii names the content of that documentation as the 'factors, processes and/or logic that led to' the output, which is Log — a stated line of reasoning from premises rather than a measurement or a case comparison. Dat is withheld: unlike EU AI Act Art. 13(3), this provision requires no declared accuracy metric. S is Ind on the strength of 'appropriate to the context, and consistent with the state of art', which leaves the sufficiency of the disclosure to the AI actor. Note that the official text reads 'state of art' at this point and 'state of the art' elsewhere; the quote preserves the official wording. ADJUDICATION 2026-08-14: V ([Sdt, Hum, Unc]), E ([Gui, Log]) and obligationType (mixed) agreed exactly across the two independent passes — the highest agreement of any entry in this pack, and the only three-axis agreement in it. S diverged ([Ind] against undeclared) and is resolved for Ind under the Wave 1 source-axis rule: the quote makes AI Actors the party that provides the information, which is the rule's Ind limb. The second pass's ground for leaving S empty — that a delegation clause designates no source — is recorded as an RFC question rather than adopted, because adopting it would break the rule applied uniformly across both waves.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V, E and obligationType agreed exactly and are auto-accepted. S ([Ind]) retained against the second pass's undeclared reading, under the Wave 1 source-axis rule (the excerpt names the AI actor as the party that produces the required information). No code changed in this entry."
    },
    {
      "article": "Principle 1.4(a) — Robustness, security and safety",
      "summary": "AI systems should be robust, secure and safe throughout their entire lifecycle so that, in conditions of normal use, foreseeable use or misuse, or other adverse conditions, they function appropriately and do not pose unreasonable safety and/or security risks.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Two thresholds in this sentence are left entirely to the actor: 'function appropriately' and 'unreasonable safety and/or security risks'. Neither is defined, no metric is prescribed, and no external body is named to fix them — which is the substantive difference between this principle and EU AI Act Art. 15, where accuracy levels and metrics must be declared in the instructions for use. An operator who reads the two as equivalent will under-build. Stated here because the pack should not imply a measurement discipline the OECD text does not impose.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.4, point a)",
        "quote": "AI systems should be robust, secure and safe throughout their entire lifecycle so that, in conditions of normal use, foreseeable use or misuse, or other adverse conditions, they function appropriately and do not pose unreasonable safety and/or security risks.",
        "rationale": "'safety and/or security risks' names the protected interests directly: harm to the persons exposed to the system (Sep) and the security of the wider setting the system runs in (Ses). Cas is assigned as an INFERENCE and flagged as such: the operative test is 'foreseeable use or misuse', and foreseeability is established by looking at how comparable systems have actually been used and misused before — a structured reading of prior instances — but the provision does not name that or any other evidence class in its own words, so the assignment rests on the structure of a foreseeability test rather than on the text. It is put to the RFC round on that point. Dat is deliberately withheld: the sentence prescribes no metric, no benchmark and no threshold, and assigning the statistical class here would import a discipline the OECD principle does not contain. S is Ind because 'appropriately' and 'unreasonable' are standards the AI actor applies to itself; no authority, professional body or external assessor is designated anywhere in the paragraph. ADJUDICATION 2026-08-14: V ([Sep, Ses]) and obligationType (mixed) agreed exactly; the second pass independently flagged Ses as a structural reading of an unqualified 'security', which is the same caution v0.1 recorded. E drops Cas: v0.1 had already flagged it as an inference from the structure of a foreseeability test, the second pass declined to fill the layer at all ('§4 admits Dat only where the text declares metrics, and this text declares none'), and a code flagged INFERENCE by its own pass survives only where both passes reached it. S drops Ind: unlike 1.2(b), 1.3 and 1.5, this sentence names no performer — its subject is 'AI systems', not an AI actor — so the Ind limb of the source-axis rule is not satisfied. Both layers are left undeclared, which §4 treats as the honest signal that the layer is out of scoring scope.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V ([Sep, Ses]) and obligationType (mixed) agreed exactly. E [Cas] → [] (v0.1's own inference flag, not reached by the second pass, which left the layer empty deliberately). S [Ind] → [] (the excerpt's subject is the AI system, not an actor; the source-axis Ind limb is not met)."
    },
    {
      "article": "Principle 1.4(b)–(c) — Override, repair, decommissioning, and information integrity",
      "summary": "Mechanisms should be in place, as appropriate, so that AI systems which risk causing undue harm or exhibit undesired behaviour can be overridden, repaired and/or decommissioned safely as needed; and mechanisms should also be in place, where technically feasible, to bolster information integrity while ensuring respect for freedom of expression.",
      "v": [
        "Sep",
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Composite entry: points b) and c) are mapped together because both are drafted as 'Mechanisms should be in place' and both are discharged by building and maintaining a capability, not by any judgment an item can observe. Point c) is new in the 2024 amendment. Recording a vocabulary gap rather than papering over it: AIO 00011 has no value code for freedom of expression and none for information integrity as such. Sdt is used for the freedom-of-expression limb as the nearest available code and Ses for information integrity, and both are flagged for the RFC round as candidate gaps in the 19-value vocabulary rather than as settled mappings.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.4, points b) and c)",
        "quote": "[point b)] Mechanisms should be in place, as appropriate, to ensure that if AI systems risk causing undue harm or exhibit undesired behaviour, they can be overridden, repaired, and/or decommissioned safely as needed. [point c)] Mechanisms should also, where technically feasible, be in place to bolster information integrity while ensuring respect for freedom of expression.",
        "rationale": "Point b) is written around 'undue harm', which is Sep, and its remedy — override, repair, decommission safely — exists so that a malfunctioning system can be taken out of the environment it is affecting, which is Ses. Point c) adds information integrity, a collective-order interest (Ses again), held against 'respect for freedom of expression', for which Sdt is the nearest code the AIO vocabulary offers: freedom to think and judge for oneself, of which expression is the outward form. Both codes on point c) are flagged as vocabulary-gap assignments, not confident mappings. E is Gui and only Gui: what discharges both points is a mechanism in place — a documented, built control — and neither point names a measurement, a case analysis or anyone's judgment as decisive. S is Ind on the strength of the two express delegation clauses, 'as appropriate' and 'where technically feasible', which leave both the scope and the feasibility determination with the AI actor. ADJUDICATION 2026-08-14: V narrows to the intersection [Sep, Ses]. The divergent codes were each a stopgap for the same missing vocabulary — v0.1 used Sdt for 'freedom of expression', the second pass used Unt — and where two independent passes reach different nearest codes for the same absent concept the code is not carried and the gap is recorded instead (Wave 2 gap 11, freedom of expression). E is resolved for Gui: 'Mechanisms should be in place' names a built, documented control, and the second pass's Exp was expressly flagged as read from the override structure rather than from any word. S drops Ind — both points are drafted passively and name no performer. obligationType is organizational on the conservative rule and on the words alike: a mechanism in place is a capability to build.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Sep, Ses, Sdt] → [Sep, Ses]; E [Gui] retained against the second pass's [Exp] as better grounded in 'mechanisms should be in place'; S [Ind] → []; obligationType organizational retained against the second pass's mixed. Sdt was v0.1's nearest code for freedom of expression and the second pass chose Unt for the same words; neither is carried."
    },
    {
      "article": "Principle 1.5(a)–(b) — Accountability and traceability",
      "summary": "AI actors should be accountable for the proper functioning of AI systems and for the respect of the principles in Section 1, based on their roles, the context and the state of the art; and to that end should ensure traceability — including in relation to datasets, processes and decisions made during the AI system lifecycle — so as to enable analysis of the system's outputs and responses to inquiry.",
      "v": [
        "Bed",
        "Cor"
      ],
      "e": [
        "Dat"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The pack's principal AIO 20002 hook, and the limit has to be stated with it. Point b) requires traceability of datasets, processes and decisions sufficient to support 'analysis of the AI system's outputs and responses to inquiry'. An AIO 20002 record is one structured reasoning line per substantive decision, which addresses the decisions limb and nothing else: it carries no dataset lineage, no pipeline record and no training provenance. It is one input to the traceability this provision requires and never the whole of it. Points a) and b) are mapped together because b) opens 'To this end' and is textually the means by which a) is met.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.5, points a) and b)",
        "quote": "[point a)] AI actors should be accountable for the proper functioning of AI systems and for the respect of the above principles, based on their roles, the context, and consistent with the state of the art. [point b)] To this end, AI actors should ensure traceability, including in relation to datasets, processes and decisions made during the AI system lifecycle, to enable analysis of the AI system’s outputs and responses to inquiry, appropriate to the context and consistent with the state of the art.",
        "rationale": "Being accountable and answering 'responses to inquiry' is an obligation owed to others and kept over time, which is Bed. 'for the respect of the above principles' makes the instrument's own principles the standard to be adhered to, which is Cor. Traceability across the lifecycle, maintained so that outputs can afterwards be analysed, is the accountability chain of the system as a matter of collective order — Ses, following the treatment of the same concept in the EU AI Act pack. Two evidence classes: the record demanded is documentary (Gui) and it is an accumulated operational record read back against later questions (Dat), which is the AIO coding of a body of retained operational data rather than of a metric. Exp is withheld — the provision does not designate anyone's judgment as decisive over the record. S is Ind on the strength of 'based on their roles, the context' in a) and 'appropriate to the context and consistent with the state of the art' in b): the OECD text sets the direction and leaves the sufficiency of the traceability to the actor. No supervisory authority, auditor or professional body appears anywhere in Principle 1.5, so Gov and Pro are both withheld. ADJUDICATION 2026-08-14: V narrows to [Bed, Cor], the second pass's set and a proper subset of v0.1's; Ses, which v0.1 read as the accountability chain as a matter of collective order, is not in the words. E narrows to the intersection [Dat]: the second pass rejected Gui on the ground that the provision requires the records, not the procedure. Neither Dat nor Gui fits, and both passes said so independently — this is Wave 2 gap 12, logging and traceability as an evidence class. S retains [Ind]: 'AI actors should ensure traceability … appropriate to the context and consistent with the state of the art' makes the actor both the performer and the sufficiency-determiner, which is the source-axis Ind limb. obligationType lowered to organizational.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V [Bed, Ses, Cor] → [Bed, Cor]; E [Gui, Dat] → [Dat]; S [Ind] retained under the source-axis rule; obligationType mixed → organizational. Both passes recorded that no evidence class in the catalogue fits a traceability record; Dat is carried as the nearest code with the gap flagged."
    },
    {
      "article": "Principle 1.5(c) — Systematic risk management and responsible business conduct",
      "summary": "AI actors should, based on their roles, the context and their ability to act, apply a systematic risk management approach to each phase of the AI system lifecycle on an ongoing basis and adopt responsible business conduct to address risks related to AI systems — including, as appropriate, through co-operation with other AI actors, suppliers of AI knowledge and AI resources, AI system users and other stakeholders — the risks named including harmful bias, human rights including safety, security and privacy, and labour and intellectual property rights.",
      "v": [
        "Sep",
        "Unc",
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Organizational outright. A systematic risk management approach applied to each lifecycle phase on an ongoing basis is a programme an organization runs; no item can observe whether it exists, and a pass on this pack is never evidence that it does. The 2024 amendment moved the traceability and risk-management text into the Accountability principle, so an operator working from a pre-2024 copy of the principles will not find this paragraph where this pack cites it. Note also the official text's stray comma in 'AI actors, should, based on their roles' — reproduced verbatim in the quote rather than silently corrected.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 1, Principle 1.5, point c)",
        "quote": "AI actors, should, based on their roles, the context, and their ability to act, apply a systematic risk management approach to each phase of the AI system lifecycle on an ongoing basis and adopt responsible business conduct to address risks related to AI systems, including, as appropriate, via co-operation between different AI actors, suppliers of AI knowledge and AI resources, AI system users, and other stakeholders. Risks include those related to harmful bias, human rights including safety, security, and privacy, as well as labour and intellectual property rights.",
        "rationale": "The closing sentence enumerates the risks and the values follow from it: 'safety, security, and privacy' is Sep, 'harmful bias', 'human rights' and 'labour rights' are Unc, and a systematic approach applied to every phase on an ongoing basis is the ordering of operations for collective stability, Ses. What discharges the duty is a systematic approach — a documented, repeatable method (Gui). Tri is the second evidence class and is assigned as an INFERENCE: the provision names 'AI system users, and other stakeholders' as parties the actor should co-operate with in addressing risk, and what those parties supply is their firsthand account of how the system behaves in their hands; the text names the parties but not the evidence class, so the step from one to the other is inferred and is put to the RFC round. S is Ind: 'based on their roles, the context, and their ability to act' is the strongest delegation clause in the instrument. Gov is withheld — no regulator, notified body or authority is named anywhere in the paragraph, unlike the equivalent EU AI Act Art. 9 duty. ADJUDICATION 2026-08-14: V ([Sep, Unc, Ses]) and obligationType (organizational) agreed exactly. E drops Tri, which v0.1 had already flagged as an inference from the naming of users and stakeholders as co-operation partners and which the second pass did not reach; [Gui] is the intersection. S drops the second pass's Usr for the reason the second pass itself gave — the provision designates co-operating parties, not evidentiary authorities — and retains Ind, which both passes declared.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V and obligationType agreed exactly. E [Gui, Tri] → [Gui] (v0.1's flagged inference removed). S [Ind] retained; the second pass's additional Usr was not carried, on its own author's reasoning that co-operating parties are not evidentiary authorities."
    },
    {
      "article": "Recommendation 2.3 — Shaping an enabling interoperable governance and policy environment for AI",
      "summary": "Governments should promote an agile policy environment supporting the transition from research and development to deployment and operation for trustworthy AI systems, consider using experimentation to provide a controlled environment in which AI systems can be tested and scaled up, adopt outcome-based approaches that give flexibility in achieving governance objectives, co-operate within and across jurisdictions to promote interoperable governance and policy environments, and review and adapt their policy and regulatory frameworks and assessment mechanisms as they apply to AI systems.",
      "v": [
        "Sti"
      ],
      "e": [
        "Dat"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Addressed to Adherent governments, not to AI actors. No organization can discharge this recommendation and no AIO measurement can reach it; it is mapped because it states the instrument's own direction on how AI governance should be built — outcome-based, interoperable across jurisdictions, periodically reviewed — and that direction is the reference point against which the interoperability claims made for any conformity scheme, including AIO's, should be read. Operators should treat this entry as context, not as a duty of theirs. MEASUREMENT-SCOPE NOTICE (raised by the second pass as a scope flag, confirmed at adjudication): the duty-bearer of this recommendation is a government, so no AIO 20002 record can supply anything that discharges it and no item can observe its performance. This pack asserts no measurement against this provision, and if the pack is ever scored this entry belongs outside the denominator rather than counted as unmet.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 2, Recommendation 2.3, points a) and b)",
        "quote": "[point a)] Governments should promote an agile policy environment that supports transitioning from the research and development stage to the deployment and operation stage for trustworthy AI systems. To this effect, they should consider using experimentation to provide a controlled environment in which AI systems can be tested, and scaled-up, as appropriate. They should also adopt outcome-based approaches that provide flexibility in achieving governance objectives and co-operate within and across jurisdictions to promote interoperable governance and policy environments, as appropriate. [point b)] Governments should review and adapt, as appropriate, their policy and regulatory frameworks and assessment mechanisms as they apply to AI systems to encourage innovation and competition for trustworthy AI.",
        "rationale": "The object being protected is the governance and policy environment itself — its interoperability across jurisdictions and its stability as a setting in which trustworthy AI can be deployed — which is Ses. 'agile policy environment' and 'consider using experimentation to provide a controlled environment in which AI systems can be tested, and scaled-up' put trying a new arrangement ahead of preserving the familiar one, which is Sti, and this is the only provision in the instrument where that value governs. 'outcome-based approaches that provide flexibility in achieving governance objectives' judges a regime by what it achieves rather than by the form it takes, which is Ach. Two evidence classes: the controlled-environment testing clause makes measured results decisive (Dat, the AIO code the controlled-experiment class folds into), and 'policy and regulatory frameworks and assessment mechanisms' are written instruments (Gui). S is Gov and only Gov: the addressee is government, the frameworks reviewed are government's own, and no other class is named. Ind is withheld even though industry is the regulated party, because the paragraph designates nothing issued by industry as decisive. ADJUDICATION 2026-08-14: obligationType (organizational) and S ([Gov]) agreed exactly. V narrows to the intersection [Sti]: 'using experimentation to provide a controlled environment in which AI systems can be tested, and scaled-up' is the only value-bearing phrase both passes read the same way, while Ses and Ach (v0.1) and Sda (the second pass, self-flagged as an inference from 'flexibility') each rest on one reading alone. E narrows to [Dat]; Gui was declared by one pass. On S the second pass questioned its own Gov — 'Governments appear here as the actor, not as a trusted source … arguably S should be empty' — and the Wave 2 source-axis policy was applied to it: being the addressee of a recommendation does not by itself earn Gov, but this excerpt additionally makes 'their policy and regulatory frameworks and assessment mechanisms as they apply to AI systems' the operative instrument, which is a government norm decisive on the substance. Gov is retained here on that ground and dropped at 2.5, where the designated instruments are expressly multi-stakeholder rather than governmental.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S ([Gov]) and obligationType (organizational) agreed exactly and Gov survives the Wave 2 source-axis re-check on the ground stated in the rationale. V [Ses, Sti, Ach] → [Sti]; E [Dat, Gui] → [Dat]."
    },
    {
      "article": "Recommendation 2.5(c)–(d) — Global technical standards and comparable indicators",
      "summary": "Governments should promote the development of multi-stakeholder, consensus-driven global technical standards for interoperable and trustworthy AI, and should encourage the development — and their own use — of internationally comparable indicators to measure AI research, development and deployment and to gather the evidence base for assessing progress in implementing the principles.",
      "v": [
        "Unt"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Addressed to governments, so outside what any AIO measurement reaches — but it is the provision in the instrument closest to what AIO builds, and the proximity invites exactly the overstatement this note exists to block. Point d) calls for internationally comparable indicators and an evidence base for assessing implementation progress. An AIO 20002 record is a per-decision reasoning record, not an indicator, and no AIO artefact is an OECD indicator, an OECD.AI metric, or part of any OECD measurement framework. Nothing in this entry may be cited as OECD recognition of the AIO standard. MEASUREMENT-SCOPE NOTICE (raised by the second pass as a scope flag, confirmed at adjudication): the duty-bearer of this recommendation is a government, so no AIO 20002 record can supply anything that discharges it and no item can observe its performance. This pack asserts no measurement against this provision, and if the pack is ever scored this entry belongs outside the denominator rather than counted as unmet.",
      "provenance": {
        "sourceUrl": "https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449",
        "retrievalUrl": "https://legalinstruments.oecd.org/public/doc/648/648.en.pdf",
        "article": "Section 2, Recommendation 2.5, points c) and d)",
        "quote": "[point c)] Governments should promote the development of multi-stakeholder, consensus-driven global technical standards for interoperable and trustworthy AI. [point d)] Governments should also encourage the development, and their own use, of internationally comparable indicators to measure AI research, development and deployment, and gather the evidence base to assess progress in the implementation of these principles.",
        "rationale": "Global technical standards that hold across jurisdictions are an instrument of collective order (Ses); 'multi-stakeholder, consensus-driven' says how they must be arrived at — by accommodating parties who differ rather than by one party imposing its own — which is Unt; and point d)'s 'assess progress in the implementation of these principles' measures a regime against a declared standard, which is Ach. Two evidence classes, one per point: 'internationally comparable indicators to measure' and 'gather the evidence base' are Dat, and the technical standards of point c) are Gui in the most literal sense the AIO vocabulary has — an established written standard. S carries Gov for the addressee and its own use of the indicators. Pro is assigned as an INFERENCE and flagged: 'multi-stakeholder, consensus-driven global technical standards' describes the output of a standards-development organisation, but unlike the GPAI Code entry that earned Pro, this text names no such body. The RFC question is whether describing a consensus standards process is enough to designate the professional source class, or whether a body must be named. ADJUDICATION 2026-08-14: E ([Dat, Gui]) and obligationType (organizational) agreed exactly. V narrows to the intersection [Unt] — 'multi-stakeholder, consensus-driven' — while Ses and Ach rest on v0.1 alone; the second pass noted that the value layer here is close to undeclared even on its own reading. S is emptied. v0.1 carried [Gov, Pro] and the second pass [Sta], an empty intersection in which every candidate was flagged by its own author: Gov was carried 'for the addressee', Pro was an express inference from a consensus process with no body named — and the second pass withheld Pro under §4 for that very reason — and Sta was chosen while recording that 'the text names no compiler'. Under the Wave 2 source-axis policy an addressee does not earn Gov, and the instruments this point designates are 'multi-stakeholder, consensus-driven', which is the opposite of both a governmental and a professional designation. The layer is left undeclared.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Dat, Gui]) and obligationType (organizational) agreed exactly. V [Ses, Unt, Ach] → [Unt]; S [Gov, Pro] → [] — the intersection with the second pass's [Sta] was empty and each of the three candidates was flagged as an inference by the pass that declared it. v0.1 note 8's third inference code (Pro at 2.5(c)) is therefore removed."
    }
  ],
  "itemBankRef": {
    "publicSet": "/content/standards-packs/item-banks/oecd-ai-principles.public.json",
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with the normative direction of each mapped principle. They do not assess whether an organization implements the management-system obligations the principles imply — accountability structures, traceability and record-keeping, systematic risk management, disclosure and transparency regimes, override and decommissioning mechanisms. They also cannot reach Section 2 at all: recommendations 2.1–2.5 are addressed to Adherent governments for their national policies and international co-operation, and no AI actor discharges them; the two Section 2 entries carry an explicit measurement-scope notice and belong outside any scoring denominator. After the dual formalization and adjudication of 2026-08-14, six of the ten mapped units are `organizational` and four are `mixed`; none is `behavioral`, the v0.1 behavioral classification of Principle 1.2(a) having been lowered to `mixed`.",
  "notes": [
    "draft-verified, not active. Every entry carries a verbatim excerpt of the official text and a rationale argued from it, and on 2026-08-14 the second independent formalization required by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer read only the pack id, the sourceNorm and each entry's provenance.article, sourceUrl, retrievalUrl and quote; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were stripped by an extraction script before any file was opened, and neither the pack-authoring guideline nor the management guide was opened. Human review is still outstanding, and the V/E/S assignment is settled only by the public RFC process at https://aioq.org/en/rfc. A certificate issued against this pack carries a draft-basis notice and records this status as `basisStatus` in its signed payload. No certificate may be issued against this pack in any case, because no item bank exists for it (see below). [갱신 2026-08-15: 이중 관문 문항 뱅크 개통 — 관문 A 공개 세트 + 관문 B 비공개 뱅크(서명 커밋먼트 게시). 이 노트의 이전 서술은 개통 전 기록이다.]",
    "Legal status, stated precisely. The Recommendation is an OECD Council Recommendation and is NOT legally binding. The Compendium's own description of the instrument category, reproduced verbatim from the official publication of OECD/LEGAL/0449 (back matter, 'OECD Legal Instruments'), is: \"Recommendations are adopted by Council and are not legally binding. They represent a political commitment to the principles they contain and entail an expectation that Adherents will do their best to implement them.\" Adherence is nonetheless formally recorded per country in the Compendium, and the Digital Policy Committee reports to Council on implementation — so this is soft law with a standing reporting mechanism, not an unenforced declaration. Nothing in this pack may be presented as a legal requirement, and a measurement against it says nothing about compliance with any statute.",
    "Adherents verified live, and the roster figure it supersedes. As at 2026-08-14 the Compendium record for OECD/LEGAL/0449 lists 51 adherents: all 38 OECD Members, 12 non-Member countries (Argentina, Brazil, Cambodia, Croatia, Egypt, Malta, Peru, Romania, Saudi Arabia, Singapore, Ukraine, Uruguay), and the European Union, which adheres as an international organisation. Counted from the machine-readable Compendium record at https://legalinstruments.oecd.org/api/instruments/OECD-LEGAL-0449 cross-referenced against the Compendium's country list, not from any secondary tally. docs/pack-roster-2026-08.md records '47국 + EU' for this norm; that figure is stale and is superseded by the count above.",
    "Current-version verification. Adopted 22 May 2019 (C(2019)34, C/MIN(2019)3/FINAL); amended 8 November 2023 (C(2023)151 — the revised definition of an 'AI system'); amended 3 May 2024 by the Council meeting at Ministerial level (C/MIN(2024)16/FINAL). The Compendium record checked on 2026-08-14 shows status 'In force', last amendment 2024-05-03, and no amendment entry after that date; the record's own last publication date is 2026-05-19. This pack formalizes the 2024 amended consolidation and nothing earlier. The 2024 amendment matters for reading this pack: it added the information-integrity limb now mapped at Principle 1.4(c), added the misuse limb at 1.2(b), expanded several headings, and moved the traceability and risk-management text into the Accountability principle — so provisions this pack cites at 1.5(b) and 1.5(c) sit elsewhere in pre-2024 copies of the principles, of which many circulate.",
    "Primary source and retrieval paths. `sourceUrl` on every entry is the canonical Compendium citation page. The canonical page is a JavaScript application that serves no text to a fetch, so the official text was taken from two other endpoints of the same issuing body: the official PDF at https://legalinstruments.oecd.org/public/doc/648/648.en.pdf (recorded as `retrievalUrl`) and the official HTML manifestation of the instrument body at https://legalinstruments.oecd.org/public/doc/648/f401b8d2-9993-41ec-82c5-d53a69e4991b.htm, both linked from the Compendium record for document 648. No commentary, summary, oecd.ai page, G20 restatement or mirror site was used at any point.",
    "Quote verification method and count: 10/10 verbatim, dual-path. Each of the ten quotes was checked mechanically against two independently extracted corpora of the same official instrument — (a) the PDF, text-extracted with pypdf, and (b) the official HTML manifestation, tag-stripped. The two paths fail differently, which is the point: the PDF extraction inserts spurious intra-word spaces in justified text ('artific ial', 'eq uality'), so path (a) was matched with all whitespace removed from both corpus and quote; the HTML carries correct word spacing but arbitrary line wrapping, so path (b) was matched with whitespace collapsed to single spaces. All ten quotes matched on both paths, each elision-free fragment as a substring. Elisions are marked […] and occur in one entry only (Principle 1.3, limb ii). Bracketed point citations such as [point b)] precede excerpts in the four composite entries; everything outside brackets is verbatim, including the official text's stray comma in 'AI actors, should, based on their roles' at 1.5(c) and its 'state of art' (not 'state of the art') at 1.3.",
    "Reuse terms, checked at source rather than assumed. The OECD Terms & Conditions, §2.1 (Reproduction), state: \"You may reproduce and distribute individual OECD Legal Instruments free of charge and without requesting any permissions, as long as you do not alter them in any way. You may use excerpts of an OECD Legal Instrument, as long as you ensure its legal nature/integrity is preserved and the excerpt is not used out of context or provides incomplete information or otherwise mislead the reader as to its actual legal nature, scope or content. OECD Legal Instruments may not be sold but may be used in the context of commercial activities such as, for example, consulting or training services.\" The official PDF carries the same permission on its imprint page. This is a full reproduction permission, not a fair-quotation allowance: feasibility is `open`, and the constraint that bites is integrity of the excerpt, not its length. That constraint shaped the quotes directly — each is a whole principle or a whole lettered point rather than a mid-sentence fragment, which is why several run past the 400-character convention in FORMALIZATION_METHODOLOGY.md §1.3. Attribution is given as the OECD asks: OECD, Recommendation of the Council on Artificial Intelligence, OECD/LEGAL/0449.",
    "Unit selection: 10 units — the five values-based principles broken into their eight lettered points and groupings (1.1; 1.2 a; 1.2 b; 1.3; 1.4 a; 1.4 b–c; 1.5 a–b; 1.5 c) and two of the five recommendations to Adherents (2.3; 2.5 c–d). Excluded, with reasons, and all reviewable at RFC: 2.1 (public and private investment in AI R&D and open science) and 2.2 (fostering an inclusive AI-enabling ecosystem) are investment and ecosystem promotion with no direction any judgment could be scored against; 2.4 (building human capacity and preparing for labour market transformation) is social and labour-market policy addressed to governments — 2.4(c), on promoting responsible use of AI at work and the safety of workers, was the closest call in the instrument and is recorded here as the first candidate for addition; 2.5(a)–(b), on co-operation and knowledge sharing between governments, are procedural. Also excluded as non-normative or institutional: paragraph I (definitions), II–IV (adoption and framing), VI–VII (dissemination and invitations to non-Adherents), and VIII (instructions to the Digital Policy Committee).",
    "Codes assigned by inference rather than by the words of the text — none survive. v0.1 carried three, each flagged in its own rationale and each put to the RFC round: Cas at Principle 1.4(a), inferred from the structure of a 'foreseeable use or misuse' test; Tri at Principle 1.5(c), inferred from the clause naming AI system users and other stakeholders as co-operation partners; and Pro at Recommendation 2.5(c), inferred from 'multi-stakeholder, consensus-driven global technical standards' describing a standards process without naming a body. The blind second pass reached none of the three, and the second pass expressly withheld Pro at 2.5(c) under the §4 source rule for the same reason v0.1 flagged it. All three were removed at adjudication under the standing rule that a code flagged INFERENCE by its own pass survives only where both independent passes reached it. The inference codes the second pass introduced and v0.1 did not reach — Sep at 1.2(b), Ses at 1.4(a) and 1.4(b)–(c), Sda at 2.3, Sta at 2.5 — were treated identically; Sep and Ses survive only because v0.1 had independently declared them.",
    "Undeclared layers, and what they now mean. v0.1 left `e` and `s` empty at Principle 1.1 alone and recorded that as a first. After adjudication five of the ten entries carry an undeclared layer: 1.1 (both `e` and `s`), 1.2(a) (`e`), 1.4(a) (both), 1.4(b)–(c) (`s`) and 2.5(c)–(d) (`s`). Every one of them is the outcome of two independent readings failing to agree on any code the quoted words carry, and FORMALIZATION_METHODOLOGY.md §4 treats an undeclared layer as the honest signal that the layer is outside scoring scope rather than as a defect. The second pass raised the same point from the other side, asking whether a recommendation-type norm should be expected to fill every layer at all; that question, and whether a values-only unit belongs in a scored pack, go to the RFC round together.",
    "Recorded vocabulary gaps, not mappings. Principle 1.4(c) protects 'information integrity' and 'freedom of expression'; the AIO 00011 19-value vocabulary has a code for neither. v0.1 used Ses and Sdt as nearest codes and said so. The blind second pass reached Ses independently but chose Unt, not Sdt, for freedom of expression — two independent readings picking different substitutes for the same absent concept — so at adjudication Ses was kept (both passes declared it) and the freedom-of-expression code was dropped entirely. Information integrity is the Wave 1 consolidated gap 3, recorded again here; freedom of expression is new and is Wave 2 gap 11. Principle 1.1's 'augmenting human capabilities and enhancing creativity' is a third: both passes considered a value code for it and both declined (Wave 2 gap 16). Principle 1.5(c)'s 'intellectual property rights' is a fourth (Wave 2 gap 17). Any downstream item written against these entries inherits the same caution.",
    "Source-class discipline, restated after adjudication. v0.1 applied a pack-local tightening — `Ind` only where the provision expressly delegates its own sufficiency standard to the AI actor — and that tightening is superseded by the cross-pack source-axis rule settled in the Wave 1 adjudications and carried forward here. The rule has two limbs. **`Gov` is declared only where the excerpt names a government body or a government norm as decisive on the substance of the duty**; being named as the recipient of a report, or as the addressee or duty-bearer of a recommendation, does not earn it. **`Ind` is declared where the excerpt makes the industry duty-bearer the author or performer of the provision's product or determination.** The rule is applied as a filter, never as a generator: it can remove a code both passes declared and can decide which of two divergent readings prevails, but it never adds a code that neither pass declared. The visible consequences here: `Ind` survives at 1.2(b), 1.3, 1.5(a)–(b) and 1.5(c), where AI actors are the named performers, and is removed at 1.4(a) and 1.4(b)–(c), whose sentences are drafted around 'AI systems' and 'mechanisms' with no performer named; `Gov` survives at 1.2(a), where applicable international law is the substantive standard, and at 2.3, where governments' own regulatory frameworks as they apply to AI systems are the operative instrument, and is removed at 2.5(c)–(d), where the designated instruments are expressly multi-stakeholder. `Pee` appears nowhere: the instrument designates no scholarly source. `Pro` appears nowhere after adjudication.",
    "Measurement scope (per-entry `obligationType`, pack-level `measurementScope`). After adjudication, six of the ten units are `organizational` (1.1, 1.4(b)–(c), 1.5(a)–(b), 1.5(c), 2.3, 2.5(c)–(d)) and four are `mixed` (1.2(a), 1.2(b), 1.3, 1.4(a)); v0.1's distribution was 1 behavioral / 5 mixed / 4 organizational. **The v0.1 claim that Principle 1.2(a) is a `behavioral` entry, and the first in the AIO pack series, does not survive the dual formalization and is withdrawn.** The blind second pass classified it `mixed`, reading 'throughout the AI system lifecycle' as management-system reach, and the divergence was resolved for the more conservative tag — the same rule applied to every obligationType divergence in this wave. Across the ten packs that have been dual-formalized and adjudicated (Wave 1 and Wave 2), the only surviving `behavioral` entry is paragraph 36 of the UNESCO pack, where both independent passes reached that tag without prompting. Packs still awaiting their second formalization carry `behavioral` entries that have not yet been tested this way. A pass on this pack remains evidence about model judgment only, and never evidence that an operator has implemented anything.",
    "Section 2 is not an operator duty. Recommendations 2.1–2.5 are addressed to Adherents — governments — for their national policies and international co-operation. The two mapped here are mapped as context, and neither an organization nor a model can discharge them. Any use of this pack that presents Section 2 conformance as something an operator achieves is a misreading of the instrument.",
    "The OECD has not reviewed, approved or endorsed this formalization and took no part in preparing it. AIO certifies conformance to AIO's own formalization of the Recommendation. That is not an assessment against the Recommendation by the OECD, not adherence to the Recommendation (adherence is an act of a government recorded in the Compendium, and no private organization can adhere), not a legal conformity assessment, and confers no status of any kind. Phrasings such as 'OECD-certified', 'OECD-approved', 'OECD AI Principles compliant' or 'adherent to the OECD AI Principles' are not available to anyone using this pack.",
    "The G20 lineage frequently attached to this instrument is real but is background, not operative text: the OECD's own Background Information accompanying OECD/LEGAL/0449 records that 'In June 2019, at the Osaka Summit, G20 Leaders welcomed the G20 AI Principles, drawn from the Recommendation.' That Background Information is published under the responsibility of the Secretary-General as additional material and is expressly not part of the legal instrument, so no mapping in this pack rests on it.",
    "No item bank has been built for this pack, so `itemBankRef` is null on both sets and the pack cannot back a certificate of any tier. Until a public set exists it should be shown as catalogued and not yet measurable.",
    "Methodology for the unit → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. Codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary — 19 value, 10 evidence and 10 source codes — and no other label appears in this pack.",
    "Adjudication method (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note. The two results were compared mechanically, entry by entry and layer by layer, with v, e and s treated as sets. Exact agreement was auto-accepted. Divergences were adjudicated under a fixed policy carried forward from Wave 1: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken (fewer codes, or a layer left undeclared); the intersection is an allowed outcome where it is non-empty and defensible; no third reading is invented, and every adjudicated set is a subset of at least one pass's set. Two sub-rules settled in this wave are stated so they can be checked: a code flagged INFERENCE by the pass that declared it survives only where both passes reached it, and a divergent `obligationType` always resolves to the more conservative tag (organizational over mixed over behavioral). Agreement statistics for this pack, across ten entries: V 3/10, E 3/10, S 3/10, obligationType 6/10, all four axes together 0/10. The systematic pattern is that v0.1 declared more value codes than the quoted words carry — seven of the ten entries lost at least one value code — and that the two passes read the source layer of a soft-law instrument very differently.",
    "Contamination notice. The second formalization of this pack ran under the tightened Wave 2 protocol, in which the pack-authoring guideline was blocked outright, and the second pass disclosed no exposure to any pack field or to any prior adjudication. No axis of this pack is therefore reported with a contamination caveat, in contrast to the NIST, Chinese and EU GPAI packs of Wave 1, whose obligationType distributions had been published in the guideline. The one recorded non-blind element in this wave is unrelated to this pack: an agent working on a different batch read the NIST second-pass file for its file shape only, and NIST is not among these five packs.",
    "Vocabulary and schema gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes four to the Wave 2 list, which continues the consolidated Wave 1 list of ten. (11) FREEDOM OF EXPRESSION — Principle 1.4(c) preserves it expressly and the value layer has no code; v0.1 used Sdt as the nearest, the second pass used Unt, and neither is carried. (12) LOGGING AND TRACEABILITY AS AN EVIDENCE CLASS — Principle 1.5(b) requires traceability of 'datasets, processes and decisions'; both passes recorded that Dat reads it as recorded data and Gui as documented procedure and that neither is what the catalogue describes. Dat is carried as the nearest code because both passes reached it. (16) CAPABILITY AUGMENTATION — Principle 1.1's 'augmenting human capabilities and enhancing creativity' has no value code; both passes considered Sdt and Sti and both declined. (17) INTELLECTUAL PROPERTY — Principle 1.5(c) names intellectual property rights among the risks to be addressed and the value layer has no code; the second pass considered Por and rejected it as a category error, and the same absence recurs at G7 Actions 4 and 11. Information integrity, recorded here at 1.4(c), is Wave 1 gap 3 and not a new item. The full Wave 2 list is reproduced in the adjudication report."
  ]
}