{
  "$schema": "./schema.json",
  "id": "sg-genai-governance",
  "name": {
    "en": "Singapore Model AI Governance Framework for Generative AI — AIO formalization",
    "ko": "싱가포르 생성형 AI 모델 거버넌스 프레임워크 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Model AI Governance Framework for Generative AI — Fostering a Trusted Ecosystem",
    "publisher": "AI Verify Foundation and Infocomm Media Development Authority of Singapore (IMDA)",
    "version": "Published 30 May 2024 (cover date); 36 pages; nine dimensions; no edition number, no second edition as at 2026-08-14. The file published at the URL below is dated 19 June 2024 in its file name and PDF creation date — it is a repost of the same 30 May 2024 document, not a revision.",
    "url": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf"
  },
  "vesMapping": [
    {
      "article": "Dimension 1 — Accountability (Design: Ex Ante — Allocation Upfront; Ex Post — Safety Nets)",
      "summary": "Responsibility along the generative AI development chain — model developers, application deployers and cloud service providers — should be allocated upfront according to the level of control each stakeholder actually has, extending the shared responsibility models the cloud industry has already codified and calibrating them to model type (closed-source, open-source, open-weights); and because such models cannot cover every case, ex post safety nets including indemnity, insurance, more flexible legal frameworks and no-fault approaches should be considered so that end-users can obtain redress for issues the allocation does not reach.",
      "v": [
        "Bed",
        "Sep"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "This dimension asks for an allocation scheme to be built, not for a decision to be made in a case, so it is organizational outright. The one sentence with a direct judgment correlate is not the quoted one: the dimension also says that responsibility when using open-source or open-weights models should require application deployers to download models from reputable platforms to minimise the risk of tampered models — a concrete direction an item could test. It is paraphrased here and cited in the rationale rather than quoted, under the licence discipline recorded in the pack notes. What an AIO 20002 record contributes is nothing to the allocation itself; it contributes a per-decision reasoning line that an ex post redress process can read after the fact. ADJUDICATION 2026-08-14 — the refusal of `Gov` recorded here survives, and `Ind` is now refused as well: the excerpt names no allocator and the stakeholders it names are addressees of the duty rather than a designated source, so the source layer is undeclared and the evidence layer with it. `Gov` was considered from the dimension's ex post limb, which suggests updating legal frameworks and cites the EU's proposed AI Liability Directive and Revised Product Liability Directive, and was not coded: those are described as examples of what other jurisdictions are doing, not as an authority the Framework makes decisive on the substance of the duty.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Accountability — Design, Ex Ante: Allocation Upfront (p. 7)",
        "quote": "Responsibility can be allocated based on the level of control that each stakeholder has in the generative AI development chain, so that the able party takes necessary action to protect end-users.",
        "rationale": "The quoted sentence is a rule for assigning who answers for what: the party with control is the party that must act. That is `Bed` — being a reliable member who keeps the obligations they hold — and the stated purpose of the allocation, 'to protect end-users', is `Sep`. What discharges the duty is a written allocation of controls and measures: the dimension's own reference point is that the cloud industry 'has built and codified comprehensive shared responsibility models over time', which is `Gui`. `Cas` rests on the dimension's method, stated in the same passage — that 'useful parallels can be drawn with today's cloud and software development' — which is reasoning by structured analysis of a small number of comparable past arrangements rather than from measurement. On sources, the classes the dimension designates are all industry: the cloud service providers who wrote the shared responsibility models, the model developers said to be 'well-placed to lead this development', and the application deployers on the layer above (`Ind`). `Gov` and `Pro` are not coded — the dimension names no governmental authority and no professional body as decisive on the allocation. `Unc` was considered for 'end-users' generally and rejected: the sentence protects the parties on the receiving end of a specific chain, not equality or justice for all people. ADJUDICATION 2026-08-14: V ([Bed, Sep]) agreed exactly across the two independent passes and is auto-accepted — the blind pass read the same 'so that' construction, taking end-user protection as the terminus and the allocation of responsibility as what is subordinated to it. E is emptied. v0.1 declared [Gui, Cas] on the shared-responsibility-model sentence and on the cloud-parallel sentence, both of which sit outside the quoted excerpt, and the blind pass declared [Log] while saying in terms that it was reading structure rather than words. No candidate was reached by both passes and none is designated by the quoted sentence, which says what is to be allocated and to whom but nothing about what would establish it. S is emptied on the same test, and that is the substantive correction here: the excerpt is drafted passively — responsibility 'can be allocated', with no allocator named — and 'each stakeholder' and 'the able party' are the addressees of the duty, not a class whose own material the provision makes decisive. v0.1's `Ind` rested on the cloud service providers, model developers and application deployers named elsewhere in the dimension, which is exactly the dimension-level reading that does not survive adjudication (see the pack note on unit granularity). obligationType resolves to `organizational`, v0.1's tag, under the standing rule that a divergent obligationType takes the more conservative reading; the blind pass's `mixed` rested on 'takes necessary action' as an act.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V ([Bed, Sep]) agreed exactly and is auto-accepted. E [Gui, Cas] → [] — both codes rested on sentences outside the quoted excerpt, the blind pass's [Log] was self-flagged as structural, and no code was reached twice. S [Ind] → [] — the excerpt names no allocator and the stakeholders it names are addressees of the duty, not a designated source. obligationType `organizational` retained against the blind pass's `mixed` under the conservative-tag rule."
    },
    {
      "article": "Dimension 2 — Data (Design: Trusted Use of Personal Data; Balancing Copyright with Data Accessibility; Facilitating Access to Quality Data)",
      "summary": "Policymakers should articulate how existing personal data laws apply to generative AI — clarifying consent requirements and exceptions and giving guidance on good business practice — and should foster open dialogue among stakeholders on the use of copyright material in training data; privacy enhancing technologies should be advanced as a way of using data while protecting confidentiality; and AI developers should undertake data quality control and general data governance best practice, including consistent and accurate annotation and data cleaning, while governments and the wider ecosystem work to expand the pool of trusted and locally representative reference datasets.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The dimension's first move is addressed to policymakers, not to firms — it asks a state to explain how its own personal data law already applies — and the second is addressed to developers as 'good discipline' rather than as a requirement. Both are management-system duties; neither has a judgment correlate an item could test, which is why this entry is `organizational` despite being the dimension where an operator has the most concrete work to do. `Unc` and `Ses` were declared in v0.1 on sentences outside the quoted excerpt and neither survives the 2026-08-14 adjudication; the value layer is now `Cor` alone. `Gov` survives here and nowhere else in this pack, because this is the one excerpt that makes a governmental statement of what the law requires decisive on the substance of the duty. The copyright limb is deliberately mapped only through the summary: the dimension takes no position on whether training on copyright material infringes, and a pack that coded a value direction onto it would be inventing one. Singapore's own Personal Data Protection Commission Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, and IMDA's PET Sandbox, are cited in the dimension's footnotes as examples of the clarification it asks for; they are Singapore's instruments and are described, not formalized, here.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Data — Design: Trusted Use of Personal Data (p. 10) and Facilitating Access to Quality Data (p. 11)",
        "quote": "[…] policymakers to articulate how existing personal data laws apply to generative AI […] AI developers to undertake data quality control measures and adopt general best practices in data governance",
        "rationale": "The first fragment routes the duty through law that already exists — the dimension's premise is that 'personal data operates within existing legal regimes' — so what must prevail is compliance with a formal requirement, `Cor`. The second fragment is about the integrity of what goes into the model; read with the dimension's opening, which says it is 'important to ensure the integrity of available datasets' and footnotes data poisoning as the threat, that is `Ses`. `Unc` is coded from two sentences outside the excerpt and is flagged here rather than left implicit: the dimension says that where training data is contentious it is important to 'ensure fair treatment', and it asks for data cleaning 'e.g., debiasing and removing inappropriate content' and for repositories of representative datasets that 'reflect the cultural and social diversity of a country'. What discharges the duty is documented practice — data governance best practice, consistent annotation, a published regulatory clarification (`Gui`) — and, for quality, the reference datasets the dimension says are important 'in both AI model development […] as well as benchmarking and evaluation' (`Dat`). The sources are the two the excerpt names: the policymakers who must state how the law applies (`Gov`) and the AI developers who must run the data discipline (`Ind`). `Pro` and `Pee` are not coded; the dimension names no professional body and no scholarly source. ADJUDICATION 2026-08-14: E ([Gui, Dat]) and obligationType (`organizational`) agreed exactly and are auto-accepted — both passes read the published regulatory clarification and the best-practice discipline as `Gui`, and the quality-control measures as `Dat`. V narrows to the intersection [Cor]. `Ses` and `Unc` both rested on sentences outside the quoted excerpt and v0.1 had flagged `Unc` as such itself; the blind pass reached neither, and the code it added instead — `Sep`, for the individual whose personal data is used — was flagged by its own author as inferred and is not carried either. S narrows to [Gov], which both passes declared and which survives the recipient≠source check on the ground the blind pass gave: policymakers are asked 'to articulate how existing personal data laws apply to generative AI', so a governmental statement of what the law requires is decisive on the substance of the duty rather than merely an authority to whom something is reported. `Ind` is dropped: the excerpt makes AI developers the performers of the data discipline but designates nothing issued by them as decisive, and the blind pass recorded that they 'appear only as addressees'.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui, Dat]) and obligationType (`organizational`) agreed exactly. V [Cor, Ses, Unc] → [Cor] — `Unc` was v0.1's own outside-excerpt flag and `Ses` rested on the dimension's opening. S [Gov, Ind] → [Gov]; this is the only entry in the pack where `Gov` survives adjudication, and it survives because the excerpt makes a governmental articulation of the law decisive on the substance rather than making a government the recipient of anything."
    },
    {
      "article": "Dimension 3 — Trusted Development and Deployment (Design: Development — Baseline Safety Practices; Disclosure — \"Food Labels\"; Evaluation)",
      "summary": "Model developers and application deployers should implement baseline safety practices across the development lifecycle — safety fine-tuning, use-case risk assessment, input and output filters, retrieval-augmented generation — and should then disclose, in a standardised \"food label\" form, the types of training data used and how it was processed, the training infrastructure and where possible its environmental impact, evaluation results, mitigations and safety measures, known risks and limitations, the intended use of the model, and how user data is used and protected; disclosure detail may be calibrated against the need to protect proprietary information, greater transparency to government is expected for models posing national security or societal risks, and safety evaluation should move toward a more comprehensive and systematic approach with a baseline set of required safety tests.",
      "v": [
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The richest dimension in the Framework and one of only three entries in this pack with a judgment correlate an item can reach. The artefact — a standardised disclosure sheet — is organizational and no measurement here observes whether it exists. The judgment side is the seven disclosure headings read as directions rather than as a form: whether a model states its known risks and limitations when the question invites overstatement, whether it holds to its declared intended-use scope, and whether it says how user data is handled. That is what an item on this dimension would test, and it is a narrow slice of what the dimension asks for. ADJUDICATION 2026-08-14 — `Hum`, which v0.1 read from disclosure heading (e), does not survive, because that heading lies outside the quoted excerpt; the observation about item design in the preceding sentences is unaffected but is no longer carried by a value code. `Gov` was considered and not coded although the dimension says there is 'space for policymakers to define the model risk thresholds' above which additional oversight applies: that sentence designates a policymaker as the author of a future threshold, not as a source decisive on the disclosure duty itself. The dimension also names the AI Verify Foundation and IMDA paper Cataloguing LLM Evaluations (October 2023) as a starting point for standardised safety evaluations; that is Singapore's instrument, described here and not formalized.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Trusted Development and Deployment — Design: Disclosure — \"Food Labels\" (p. 13)",
        "quote": "Transparency around these safety measures […] is then key. This is akin to “food or ingredient labels”. By providing relevant information to downstream users, they can make more informed decisions.",
        "rationale": "The quoted purpose clause is explicit about whose capacity is being protected: downstream users are to 'make more informed decisions', which is `Sdt` — reaching one's own conclusion from the reasoning rather than accepting a given answer. What the label is a label of is the safety and hygiene measures undertaken, so `Sep`. `Hum` is coded from the disclosure list itself, in the same sub-section and outside the excerpt: heading (e) requires the model's known risks and limitations to be disclosed, which is a duty to state one's own limits rather than to overstate. Evidence: the dimension's whole disclosure move is toward a standard baseline — it says standardising disclosure 'will facilitate comparability across models' — which is `Gui`; and heading (c), evaluation results, together with the Evaluation sub-section's benchmarking, is `Dat`. Sources: the parties the dimension puts the duty on are the model developers and application deployers, and it asks that 'the industry […] agree on the baseline transparency', which is `Ind`. `Pro` is not coded here — no professional body is named in this dimension, unlike Dimension 5. `Pee` is not coded; Stanford's Holistic Evaluation of Language Models is named in a footnote to Dimension 5, not here, and as an example of third-party benchmarking rather than as a class of trusted source. ADJUDICATION 2026-08-14: S ([Ind]) agreed exactly. The blind pass flagged its own reading as inferred — 'providing relevant information to downstream users' presupposes an upstream developer authoring the label about its own system — but a code reached independently by both passes survives that flag, and this is the clearest instance in the pack of the source-axis `Ind` limb: the excerpt makes the industry duty-bearer the author of the very material the provision makes decisive. V narrows to [Sdt], which both passes took from 'they can make more informed decisions'. `Sep` does not survive and the blind pass's ground for refusing it is adopted: the safety measures are the subject matter of the disclosure, not what the sentence says the disclosure protects. `Hum` was coded by v0.1 from disclosure heading (e), known risks and limitations, which lies outside the quoted excerpt and was not reached by the blind pass. E narrows to the intersection [Gui]; v0.1's `Dat` rested on heading (c), evaluation results, also outside the excerpt. obligationType resolves to `mixed`, v0.1's tag, under the conservative-tag rule — the blind pass read the entry as `behavioral` on the act of providing the information — so this pack still carries no `behavioral` entry.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "S ([Ind]) agreed exactly and is auto-accepted. V [Sdt, Sep, Hum] → [Sdt] — `Sep` refused on the blind pass's reasoning that the safety measures are the subject of the disclosure and not the interest it protects, `Hum` rested on a disclosure heading outside the excerpt. E [Gui, Dat] → [Gui]. obligationType `mixed` retained against the blind pass's `behavioral`, so the pack's zero-`behavioral` distribution is unchanged."
    },
    {
      "article": "Dimension 4 — Incident Reporting (Design: Vulnerability Reporting — Incentive to Act Pre-Emptively; Incident Reporting)",
      "summary": "AI developers should open reporting channels for safety vulnerabilities found in their systems and apply the vulnerability-reporting practice already established in software — a time window to assess, patch and publish, with the reporter credited — complemented by ongoing monitoring to detect malfunctions before end-users do; and after an incident, organizations need internal processes for timely notification and remediation, which depending on impact may extend to notifying the public and governments, so that defining severe AI incidents and setting the materiality threshold for formal reporting becomes the key design question, with reporting kept proportionate and harmonised with existing reporting regimes.",
      "v": [
        "Ses"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "Classified `mixed` on a narrow ground. Almost all of this dimension is a management system — reporting channels, patch windows, materiality thresholds, sharing bodies — and no measurement here observes any of it. The judgment correlate is the escalation decision: whether a given event is treated as one that must be reported onward rather than absorbed, and whether the proportionality the dimension asks for is read as a reason to report less. An item can put that decision to a model; it cannot tell an operator what their threshold should be, and the dimension itself does not set one. ADJUDICATION 2026-08-14 — v0.1 declared `Gov` and `Ind` on the source layer and neither survives. Governments appear in this excerpt as the party notified, and the recipient of a report is not thereby a source the provision makes decisive; that ruling was settled in the Wave 2 adjudications and the blind second pass reached it independently here. The dimension carries a descriptive box on incident reporting under the EU AI Act, including the 15-day serious-incident duty on providers of high-risk systems; that box describes another jurisdiction's law and is not coded here, because the EU AI Act is formalized in its own pack (`eu-ai-act`) and coding from a summary of it inside this document would double-count a norm through a secondary description of it.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Incident Reporting — Design: Incident Reporting (p. 17)",
        "quote": "Depending on the impact of the incident and how extensively AI was involved, this could include notifying both the public as well as governments.",
        "rationale": "Notification is an obligation owed outward to parties who are relying on the system, which is `Bed`. The dimension's stated reason for the whole practice — that reporting 'allows for timely notification and remediation' and 'supports the continuous improvement of AI systems' — together with its instruction that AI incidents can be reported to the equivalent of Information Sharing and Analysis Centres and that principles be harmonised with existing reporting regimes, makes the protected interest the orderly functioning of the wider system, `Ses`. `Sep` was considered and not coded: the only place this document ties incident reporting to death or serious harm is the descriptive box on the EU AI Act, which states another instrument's definition rather than Singapore's own direction. Evidence: what discharges the duty is established procedure — the dimension imports software practice wholesale, including the typical 90-day patch window and filing a CVE (`Gui`) — supported by the 'ongoing monitoring efforts to detect malfunctions' the same passage requires (`Dat`). Sources: the excerpt names governments, and the dimension adds 'relevant authorities, where required by law' (`Gov`); the product owners and organizations that run the channels and the internal processes are `Ind`. `Tes` was considered for the white hats and independent researchers the vulnerability-reporting passage relies on and rejected: the AIO code means the on-record statement of a named eyewitness, which is not what a vulnerability report is. ADJUDICATION 2026-08-14: obligationType (`mixed`) agreed exactly. V narrows to the intersection [Ses]: both passes read notification of 'the public as well as governments' as protecting the orderly functioning of the wider system, while v0.1's `Bed` was not reached by the blind pass and the excerpt states a graded notification rather than an obligation owed to a named counterparty. E is emptied. v0.1's `Gui` rested on the imported software vulnerability practice and the 90-day patch window and its `Dat` on the ongoing-monitoring sentence, both outside the quoted excerpt, and the blind pass's `Cas` was self-flagged as inferred from the impact-calibrated trigger; no code was reached twice, and the excerpt names nothing that discharges the duty. That absence is Wave 2 gap 18, incident reporting as an evidence class, reached here independently. S is emptied and is the load-bearing correction in this entry. v0.1 declared [Gov, Ind]; the blind pass left the layer empty and stated the reason exactly — 'governments appear here strictly as the recipient of the notification, and under the source-axis rule the recipient of a report is not thereby a trusted source'. That is the recipient≠source ruling settled in the Wave 2 adjudications, which removes `Gov` even where both passes declare it, and it applies a fortiori where only one pass did. `Ind` falls with it: the excerpt is drafted passively, names no performer, and v0.1's ground — the product owners and organizations that run the reporting channels — lies outside it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (`mixed`) agreed exactly. V [Bed, Ses] → [Ses]. E [Gui, Dat] → [] — no code was reached twice and the excerpt names nothing that discharges the duty (Wave 2 gap 18 confirmed independently). S [Gov, Ind] → [] under the recipient≠source rule: governments are the addressee of the notification this excerpt requires, not a source it makes decisive. This was the flagged call of the second pass and it is upheld."
    },
    {
      "article": "Dimension 5 — Testing and Assurance (Design: How to Test — Standardisation; Who to Test — Trusted Accreditation)",
      "summary": "Third-party testing and assurance should be developed as a complement to a developer's own testing, along two axes: how to test — a reliable and consistent methodology, common benchmarks and tooling, and for more mature areas codification through standards organisations such as ISO/IEC and IEEE, with the scope of third-party testing itself eventually standardised — and who tests, where independence is treated as the condition of objective results, a pool of qualified third-party testers has to be built up by industry bodies and governments, and an accreditation mechanism could eventually be developed to assure independence and competency.",
      "v": [],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Pro"
      ],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The dimension of this Framework that speaks most directly to what AIO itself does, and therefore the one where AIO must be most careful. AIO Tier 0 is self-administered by the operator on a fully public item set; measured against this dimension, that is precisely the arrangement the dimension says is not sufficient on its own, and the certificate's own disclaimer says the same thing in its first sentence. Nothing in a pack pass is third-party testing in this dimension's sense, and nothing here is an accreditation. `Hum` was an INFERENCE in v0.1 and does not survive the 2026-08-14 adjudication; the value layer of this entry is now undeclared, because the two independent passes shared no value code and the interest the excerpt protects — the objectivity and integrity of a test result — has no code in the AIO 00011 catalogue. `Ind` does not survive either, and its removal is substantive rather than technical: a dimension whose own direction is that a party may not certify its own work cannot at the same time designate that party's material as decisive. MEASUREMENT-SCOPE NOTICE (confirmed at adjudication): the parties this dimension asks to act are standards organisations, industry bodies, governments and a future accreditation mechanism, so no AIO 20002 record discharges any part of it and no item observes its performance; if the pack is ever scored this entry belongs outside the denominator rather than counted as unmet. `Pro` is coded on the strength of named standardisation bodies, the same textual basis on which it was allowed in the GPAI Code pack's Copyright Measure 1.3 and refused everywhere the text named no body. `Gov` was considered — the dimension says 'concerted efforts by industry bodies and governments will be useful to grow capabilities in this area' — and not coded: that names governments as a party who should help build capacity, not as a source the dimension makes decisive on the substance of a test result.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Testing and Assurance — Design: Who to Test — Trusted Accreditation (p. 20) and How to Test — Standardisation (p. 20)",
        "quote": "Independence is key to ensuring the objectivity and integrity of test results. […] AI testing could be codified through standards organisations like ISO/IEC and IEEE […]",
        "rationale": "What the first sentence protects is the trustworthiness of the assurance layer that the rest of the ecosystem relies on — the dimension's own framing is that third-party testing gives 'independent verification' as it does in finance and healthcare — which is `Ses`. `Hum` is an INFERENCE and is put to the RFC round: a rule that makes independence the condition of objectivity presumes that a party assessing its own work will not reliably see its limits, which is what the AIO code means, but the dimension does not say so in terms. Evidence: the dimension asks for a methodology 'that is reliable and consistent', for common benchmarks and tooling, and for codification through standards bodies, all of which is `Gui`; the thing produced and compared is a test result across models (`Dat`). Sources: ISO/IEC and IEEE are named in the quoted text as the bodies through which testing should be codified, which is the credentialed field's own collective position and is coded `Pro`; the developers whose own benchmarks third-party testing will initially reuse, and the audit and professional services firms building capability, are `Ind`. `Pee` is not coded: Stanford's Holistic Evaluation of Language Models appears in a footnote as an example of a third party running benchmarks, not as scholarly scrutiny the dimension asks to be trusted. ADJUDICATION 2026-08-14: E ([Gui, Dat]) and obligationType (`organizational`) agreed exactly. S narrows to [Pro], declared by both passes on the strength of ISO/IEC and IEEE being named inside the quoted text — the one place in this pack where a source class is named in the excerpt itself. The misfit both passes worked around is Wave 1 gap 8: `Pro` is defined as the collective position of a field's credentialed practitioners and a standards-development organisation is not that, but it is the nearest carrier the catalogue offers and both passes reached it. `Ind` does not survive. The blind pass refused it under §4 while noticing what makes it particularly wrong here — 'independence implicitly excludes self-issued industry testing' — and v0.1's ground, the developers whose benchmarks are reused and the audit firms building capability, lies outside the excerpt. A dimension whose own direction is that a party may not certify its own work cannot at the same time designate that party's material as decisive. The value layer is left undeclared, and it is the only empty value layer in this pack. The two passes shared no value code: v0.1 read the independence sentence as protecting the assurance layer the rest of the ecosystem relies on (`Ses`, grounded in the finance-and-healthcare framing outside the excerpt) and added `Hum` under an express INFERENCE flag, while the blind pass read the same sentence as the tester's own judgment (`Sdt`) and read the codification clause as compliance with formal procedure (`Cor`). `Hum` falls under the standing rule that a self-flagged inference survives only where both passes reach it. Of the remainder none is designated by the quoted words: what the sentence protects is the objectivity and integrity of a test result, for which the 19-value catalogue has no code, and `Cor` reads as a value a clause that both passes otherwise placed on the evidence and source layers. This is Wave 1 gap 10 — a provision that presupposes a protected interest without naming one — in its second instance after UNESCO ¶71, and the missing code is carried to the RFC round as a Wave 3 candidate in its own right.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui, Dat]) and obligationType (`organizational`) agreed exactly. S [Pro, Ind] → [Pro] — `Pro` is named inside the excerpt (ISO/IEC, IEEE, with the Wave 1 gap 8 misfit recorded) and `Ind` is refused both because v0.1's ground lay outside the excerpt and because the dimension's own direction is that a party may not test its own work. V [Ses, Hum] → [] — the two passes shared no value code, v0.1's `Hum` was its own INFERENCE flag, and the interest the excerpt protects (the objectivity and integrity of a test result) has no code in AIO 00011. This is the pack's only empty value layer."
    },
    {
      "article": "Dimension 6 — Security (Design: Adapt \"Security-by-Design\"; Develop New Security Safeguards)",
      "summary": "AI security should be addressed by separating familiar software security concerns from the novel threat vectors aimed at the model itself, and by adapting security-by-design to generative AI across the whole systems development life cycle — with refinements for natural-language input and for the probabilistic behaviour that defeats traditional evaluation — while new safeguards are developed, including input moderation filters tailored to domain-specific risks and digital forensics tools able to identify malicious code hidden within a model, supported by adversary technique databases for risk assessment and threat modelling.",
      "v": [
        "Ses"
      ],
      "e": [
        "Gui"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "Organizational outright, and the shortest dimension in the Framework — two pages of design direction with no decision rule addressed to anyone in a concrete case. Security-by-design is a lifecycle discipline; an AIO measurement observes none of it, and a model that passes every item in a bank built on this pack may have no security programme at all. `Cas` and `Sep` were declared in v0.1 on sentences outside the quoted excerpt and neither survives the 2026-08-14 adjudication; the source layer is undeclared for the same reason, the excerpt naming security-by-design itself rather than any performer. The dimension's own admission that this is 'a nascent space' where 'new concepts have to be developed or adapted' is worth carrying into the guide: an operator reading this dimension is being told that the controls do not yet exist in settled form, which is a different situation from a norm that specifies a control.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Security — Design: Adapt \"Security-by-Design\" (p. 22)",
        "quote": "It seeks to minimise system vulnerabilities and reduce the attack surface through designing security into every phase of the systems development life cycle (SDLC).",
        "rationale": "The subject of the sentence is the security of the system as such across its whole life cycle, which is `Ses`. `Sep` is coded from the safeguards sub-section on the facing page, which is cited and not quoted: input moderation tools are asked for to 'detect unsafe prompts (e.g., blocking malicious code)', and what that protects is the person on the other end of the system. Evidence: security-by-design is described in the dimension as 'a fundamental security concept' operating through the named SDLC stages of development, evaluation, operations and maintenance — an established written discipline, `Gui`. `Cas` rests on the sentence naming MITRE's Adversarial Threat Landscape for AI Systems as a database that provides 'adversary tactics, techniques and case studies for ML systems', which the dimension says developers can use to support risk assessment and threat modelling; that is structured analysis of comparable past instances, and it is cited rather than quoted to hold quotation to the minimum. Sources: the only class designated is the developers who are told they can use these tools and databases (`Ind`). `Gov` and `Pro` are not coded — no authority and no professional body is named in this dimension. `Dat` was considered and rejected: nothing here makes a measured quantity decisive. ADJUDICATION 2026-08-14: obligationType (`organizational`) agreed exactly, and `Ses` and `Gui` were each declared by both passes — the blind pass recording that it read `Ses` structurally, from the systems-level framing, since the sentence names no protected party. `Sep` does not survive: v0.1 grounded it on the input-moderation sentence on the facing page, which it cited rather than quoted, and the blind pass considered the same idea and left it out for want of any party named in the excerpt. `Cas` does not survive either; v0.1 grounded it on the MITRE ATLAS sentence, also outside the excerpt and flagged as such. S is emptied: the subject of the excerpt is security-by-design itself ('It seeks to minimise system vulnerabilities'), no performer is named, and v0.1's `Ind` rested on the developers addressed elsewhere in the dimension. Every divergent code in this entry was one v0.1 had itself recorded as resting outside the quoted excerpt, and the adjudicated mapping is the blind pass's in full.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (`organizational`) agreed exactly. V [Ses, Sep] → [Ses]; E [Gui, Cas] → [Gui]; S [Ind] → []. Every divergent code was one v0.1 had itself recorded as resting on a sentence outside the quoted excerpt, and the adjudicated mapping for this entry is the blind pass's in full."
    },
    {
      "article": "Dimension 7 — Content Provenance (Design)",
      "summary": "Because synthetic content is easy to produce at scale and exacerbates misinformation and threats such as the integrity of elections, digital watermarking and cryptographic provenance should be used to label AI-generated or AI-modified content, with the practical limits acknowledged — provenance data can be stripped, watermarks are today decodable only by the company that encoded them for want of interoperable standards, consumer understanding is low and malicious actors will attempt to exploit the signals; policies should therefore be designed for the contexts where the technologies work, key parties in the content life cycle including publishers should be engaged so that provenance can be embedded and displayed where content is actually consumed, the types of edits to be labelled should be standardised, displayed provenance details should be simplified, and technical measures should be complemented by enforcement.",
      "v": [
        "Sdt"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-verified",
      "obligationType": "mixed",
      "note": "The third and last entry in this pack with a judgment correlate. What an item can test is whether a model treats the fact that content is machine-generated as something owed to the person consuming it, rather than as a detail to be omitted when disclosure is inconvenient; what it cannot test is whether a watermarking scheme is deployed, whether publishers display it, or whether it survives the platform. Note the difference in kind from the Chinese labelling rules formalized in the `cn-ai-labelling` pack: those impose a labelling duty with defined content and defined liability, whereas this dimension proposes labelling as a direction and spends most of its length on why the technology does not yet carry it. `Ses` rested on the dimension's opening sentences, outside the quoted excerpt, and does not survive the 2026-08-14 adjudication; its removal records the information-integrity vocabulary gap rather than covering it with the nearest available code. One evidence class and one source class are declared, both by agreement of the two independent passes, and this is the entry with the highest inter-pass agreement in the pack.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Content Provenance — Design (p. 25)",
        "quote": "[…] enable consumers to discern between non-AI and AI-generated content, standardising the types of edits to be labelled would be helpful. […] working with publishers to support the embedding […]",
        "rationale": "The purpose the dimension states for labelling is that consumers should be able to tell for themselves what they are looking at, which is `Sdt` — the same value the Trusted Development and Deployment disclosure duty protects, reached here through the content rather than through the model. `Ses` is coded from the dimension's opening sentences, cited and not quoted: the concern named there is that synthetic content 'has exacerbated harms like misinformation, and even potential societal threats like undermining the integrity of elections'. What discharges the duty is a standard — the excerpt asks for the types of edits to be labelled to be standardised, and the dimension names the Coalition for Content Provenance and Authenticity as driving an open standard for tracking provenance — which is `Gui`. No other evidence class is declared: the dimension names no metric, no expert judgment, no precedent analysis and no reasoned account as what settles the question, and declaring one would overstate what the text supports. Sources: the parties the dimension asks to carry the labels are publishers, and alongside them content creators and solution providers, all `Ind`. `Gov` was considered — the dimension observes 'recognition across governments, industry and society' of the need and says stakeholders 'can partner policymakers to raise awareness' — and not coded: governments appear as fellow participants in awareness-raising, not as a source made decisive on whether a piece of content is what it claims to be. ADJUDICATION 2026-08-14: E ([Gui]), S ([Ind]) and obligationType (`mixed`) agreed exactly — three axes out of four, the highest agreement of any entry in this pack. Both passes read 'standardising the types of edits to be labelled' as a written standard and 'working with publishers to support the embedding' as designating the concerned industry's own material; the blind pass flagged its `Ind` as inferred, but a code both passes reach survives that flag, and it separately recorded that 'standardising' names no body and therefore cannot carry `Pro`. V narrows to [Sdt], which both passes took from 'enable consumers to discern between non-AI and AI-generated content'. `Ses` does not survive: v0.1 grounded it on the dimension's opening sentences about misinformation and election integrity, which it cited rather than quoted, and the blind pass did not reach it. Wave 1 gap 3, information integrity, is confirmed again by that removal rather than papered over with the nearest available code.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "E ([Gui]), S ([Ind]) and obligationType (`mixed`) agreed exactly — the only three-axis agreement in this pack. V [Sdt, Ses] → [Sdt]; `Ses` rested on the dimension's opening sentences outside the excerpt, and its removal records Wave 1 gap 3 (information integrity) rather than substituting a nearby code for it."
    },
    {
      "article": "Dimension 8 — Safety and Alignment Research & Development (Design)",
      "summary": "Because current safety and evaluation techniques do not address all risks — RLHF has limitations, large models lack interpretability and may not be reproducible — human capacity to align and control generative AI has to keep pace with both present risks such as bias and hallucination and future catastrophic risks; the field's research directions should be systematically mapped across forward alignment, including reinforcement learning from AI feedback, and backward alignment, including testing for emergent capabilities such as autonomous replication and long-horizon planning and mechanistic interpretability; and because most alignment research is currently done inside AI companies, the AI safety R&D institutes set up in the UK, US, Japan and Singapore should be resourced and coordinated globally so that priorities are set from the landscape map and limited talent is used where it has most effect.",
      "v": [
        "Ses"
      ],
      "e": [],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The clearest instance in this pack of a dimension addressed to the ecosystem rather than to any organization that could be certified against it. Its demand is discharged by funding institutes, mapping research and cooperating across borders — none of which an item observes, and none of which an operator can evidence with an AIO 20002 record. It is mapped because a pack that omitted it would misrepresent what this Framework is, and because the guide needs an anchor for the R&D and horizon-scanning duties. One observation deserves recording without being inflated into a judgment correlate: the dimension's premise is that today's safety techniques do not cover all risks, and a model that states its own alignment as settled is at odds with that premise. That is an observation about calibration, not part of what the dimension asks anyone to do, so it does not move the classification off `organizational`. `Pee` was an INFERENCE in v0.1 and does not survive the 2026-08-14 adjudication; `Gov`, which both independent passes declared, was also removed, because the four national AI safety institutes are named here as bodies to be set up and resourced rather than as an authority whose position the dimension makes decisive on the substance of alignment. MEASUREMENT-SCOPE NOTICE (raised by the second pass as a scope flag, confirmed at adjudication): the duty-bearers of this dimension are governments and publicly funded research institutes, so nothing an AIO 20002 record supplies discharges it and no item observes its performance. This pack asserts no measurement against this dimension, and if the pack is ever scored this entry belongs outside the denominator rather than counted as unmet.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "Safety and Alignment R&D — introduction and Design (p. 27)",
        "quote": "[…] human capacity to align and control generative AI keeps pace with the potential risks […] The setting up of AI safety R&D institutes or equivalents in UK, US, Japan and Singapore […]",
        "rationale": "The dimension names the risks it is about in the sentence the first fragment is taken from — 'both present risks (e.g., bias, hallucination) and future catastrophic risks' — which gives `Sep` for harm to people and `Ses` for the catastrophic limb, which is societal by definition. `Hum` is stated rather than inferred: the dimension opens 'Safety techniques, and evaluation tools today do not fully address all potential risks', and the executive summary says the state-of-the-science does not fully cover all risks — a rule for acting on acknowledged limits. Evidence: what the dimension asks to be relied on is a synthesis across the field, since it wants research directions and methods 'systematically map[ped]' and impactful areas 'collectively identified and prioritised based on the landscape map' — that is `Rev`, the only appearance of that code in this pack; and the backward-alignment limb, which validates alignment by testing a trained model for emergent capabilities, is `Dat`. Sources: the second fragment names four state-established AI safety institutes, and the dimension's footnote records that Singapore's Digital Trust Centre is funded by IMDA and the National Research Foundation (`Gov`). `Pee` is an INFERENCE put to the RFC round: the whole dimension asks that research findings govern what is done about alignment, and cites a published survey of the field, but it nowhere designates independent scholarly review as the filter, and `Pee` is the nearest class in the AIO 00011 source vocabulary. `Ind` was considered and rejected: AI companies are named as where most alignment research currently happens, which is the situation the dimension wants complemented, not a class it asks to be trusted. ADJUDICATION 2026-08-14: obligationType (`organizational`) agreed exactly. V narrows to the intersection [Ses] — both passes read 'keeps pace with the potential risks' as an interest of collective order. `Sep` and `Hum` do not survive: v0.1 grounded both on sentences outside the quoted fragments, the enumeration of present and catastrophic risks and the dimension's opening admission that today's techniques do not fully address all risks, and the blind pass reached neither. The blind pass's own addition, `Sda` for 'human capacity to align and control generative AI', was flagged by its author and is not carried either; that divergence is Wave 2 gap 15, humans keeping control of the system, since the catalogue's autonomy codes are written for a person's own course of action and its power codes for control over people, and neither is what this clause protects. E is emptied — the blind pass called that 'the honest answer' and it is right, since the excerpt calls for R&D and names nothing that would discharge it, while v0.1's `Rev` and `Dat` rested on the landscape-mapping and emergent-capability sentences outside it. S is emptied, and this is the one layer in the pack where the source-axis rule removes a code that both passes declared. Both read `Gov` from 'AI safety R&D institutes or equivalents in UK, US, Japan and Singapore', and the blind pass simultaneously flagged the weakness and named the disposal: 'if the pack reads them as research bodies rather than as authorities whose position governs, this layer should collapse to empty'. It does read them that way. `Gov` means the official position of a governing authority made decisive on the substance of the duty, and these institutes are named as bodies to be set up, resourced and coordinated — the object of a capacity-building recommendation, not a position the dimension makes decisive on what alignment requires. That is the addressee boundary settled in the Wave 2 adjudications. `Pee` falls under the inference rule: v0.1 flagged it INFERENCE and the blind pass did not reach it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "obligationType (`organizational`) agreed exactly. V [Sep, Ses, Hum] → [Ses]; E [Rev, Dat] → []; S [Gov, Pee] → [] — `Pee` under the inference rule, and `Gov` by the source-axis filter, which removes it although both passes declared it, because state-established institutes named as bodies to be set up and resourced are the object of the recommendation rather than an authority made decisive on its substance. A measurement-scope notice is added under the substance-versus-addressee convention."
    },
    {
      "article": "Dimension 9 — AI for Public Good (Design: Democratising Access to Technology; Public Service Delivery; Workforce; Sustainability)",
      "summary": "Responsible AI is treated as extending beyond risk mitigation to four touchpoints: democratising access, so that all members of society can use generative AI in a trusted manner, with human-centric product design, digital literacy initiatives that include sensitising users against anthropomorphising AI and identifying deepfakes, and support for small and medium enterprises; public service delivery, with governments coordinating data sharing and compute so that AI reaches citizens; workforce, with industry, governments and educational institutions redesigning jobs and providing upskilling in AI tools and in creativity, critical thinking and complex problem-solving; and sustainability, with energy-efficient compute and hardware, green-powered data centres, and the carbon footprint of training and inference tracked and measured.",
      "v": [
        "Unc",
        "Unn"
      ],
      "e": [
        "Dat"
      ],
      "s": [],
      "status": "draft-verified",
      "obligationType": "organizational",
      "note": "The weakest unit in this pack for measurement purposes, and it is recorded as such rather than dressed up. Three of the four touchpoints — public service delivery, workforce, and most of democratising access — are industrial and social policy addressed to governments, educational institutions and industry bodies; they impose no duty on an AI system, carry no decision rule, and an AIO item could not be written against them without inventing content the Framework does not contain. Only two limbs have any direction at all: the sustainability limb, which asks for the environmental cost of a model to be measured and for the efficient option to be preferred, and the trusted-access limb quoted here. Even those are addressed to whoever builds the compute estate rather than to a judgment in a case. The dimension is mapped so that the pack does not silently drop a ninth of the Framework and so that the guide can address it; it is not evidence that AIO measures anything about public good. MEASUREMENT-SCOPE NOTICE (confirmed at adjudication): for the democratising-access, public-service-delivery and workforce limbs the duty-bearers are governments, educational institutions and industry bodies, so those limbs sit outside any scoring denominator; only the sustainability limb states a direction a judgment could track. ADJUDICATION 2026-08-14 — the source layer is now undeclared: v0.1's `Gov` and `Ind` both rested on sentences its own rationale records as lying outside the quoted excerpt. `Exp` and `Tri` were considered for the digital literacy and upskilling limbs and rejected — the dimension names no expert and no firsthand account as decisive.",
      "provenance": {
        "sourceUrl": "https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf",
        "article": "AI for Public Good — Design: Democratising Access to Technology (p. 29) and Sustainability (p. 30)",
        "quote": "All members of society should have access to generative AI, done in a trusted manner. […] the carbon footprint of generative AI […] will also need to be tracked and measured.",
        "rationale": "The first sentence is a distributive claim about who the technology is for — all members of society, not a served segment — which is `Unc`. The second is about the environment: the sustainability limb states that the resource requirements of generative AI, energy and water, 'are non-trivial and will likely impact sustainability goals', which is `Unn`. What discharges the environmental limb is stated in the quoted words themselves: the footprint is to be tracked and measured, which is `Dat`. No other evidence class is declared; the dimension names no guideline, no expert, no case analysis and no reasoned argument as what settles any of its four touchpoints. Sources: the dimension says 'it is desirable for governments to coordinate resources to support public sector AI adoption' and that governments can partner companies and communities on digital literacy (`Gov`), and that 'AI developers and equipment manufacturers are better placed to conduct R&D on green computing techniques and adopt energy-efficient hardware' (`Ind`); both sentences are outside the excerpt and are cited here rather than quoted. `Ach` and `Por` are the values this dimension expects to be deprioritized when the efficient option is preferred over the more capable one; they are not coded, because the V layer records what must prevail. ADJUDICATION 2026-08-14: V ([Unc, Unn]), E ([Dat]) and obligationType (`organizational`) agreed exactly across the two independent passes — three axes, and the only entry in this pack whose value layer was reached identically and in full. Both passes took `Unc` from 'All members of society should have access', `Unn` from the carbon footprint and `Dat` from 'tracked and measured', the blind pass noting that all three are designated in the text itself and need no inference. S is emptied. v0.1 declared [Gov, Ind] and said in the same rationale that both rested on sentences outside the excerpt — the coordination of public-sector AI adoption and the green-computing sentence — while the blind pass recorded that 'all members of society' are the beneficiaries of access and not a designated class of trusted source. Neither reading survives the excerpt-strict test and the layer is left undeclared.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "dual formalization (blind second pass) + adjudication, 2026-08-14"
      },
      "changeNote": "V ([Unc, Unn]), E ([Dat]) and obligationType (`organizational`) agreed exactly — the strongest agreement in the pack. S [Gov, Ind] → []; v0.1's own rationale recorded that both codes rested on sentences outside the quoted excerpt."
    }
  ],
  "itemBankRef": {
    "publicSet": "/content/standards-packs/item-banks/sg-genai-governance.public.json",
    "privateSet": null
  },
  "version": "0.2",
  "supersedes": "0.1",
  "status": "draft-verified",
  "updatedAt": "2026-08-14",
  "measurementScope": "The Model AI Governance Framework for Generative AI is a voluntary framework, not law. It creates no obligation on anyone, is not enforced by IMDA or by any Singapore regulator, and its own text describes what it does as setting forth an approach and proposing nine dimensions to be looked at in totality. Its addressee is not the certified organization: it says in terms that it requires all key stakeholders, including policymakers, industry, the research community and the broader public, to collectively do their part, and several of its dimensions ask policymakers to clarify law, governments to fund institutes, standards bodies to codify testing methods, and publishers to display provenance signals. Nothing in this pack measures any of that, and nothing in it could. What AIO items measure against this pack is the judgment direction the mapped dimensions imply for an AI system — whether a model's reasoning tracks, for example, the Trusted Development and Deployment direction that a downstream user is entitled to know a model's risks, limitations and intended use, the Content Provenance direction that a consumer is entitled to know whether content was machine-generated, or the Incident Reporting direction that an event of material impact is escalated rather than absorbed. They do not assess whether an organization operates the management-system correlates of those dimensions — shared responsibility allocations, data governance and quality control, disclosure sheets, incident reporting structures and materiality thresholds, third-party testing and accreditation arrangements, security-by-design programmes, watermarking deployments, safety R&D investment, or sustainability measurement — and they are not evidence of any organization's alignment with this Framework, nor of any standing with IMDA, the AI Verify Foundation or the Government of Singapore. After the blind dual formalization and adjudication of 2026-08-14 the per-entry distribution is unchanged — none `behavioral`, three `mixed`, six `organizational` — but the mapping itself is materially narrower: the value layer lost a code on seven of the nine entries and is undeclared on one, the evidence layer is undeclared on three, and the source layer on five. Entries carrying a MEASUREMENT-SCOPE NOTICE in their `note` field (Testing and Assurance, Safety and Alignment R&D, AI for Public Good) are addressed to governments, standards bodies and research institutes and belong outside any scoring denominator rather than being counted as unmet.",
  "notes": [
    "draft-verified, not active. Every entry carries a short verbatim excerpt of the official text and a rationale argued from it, and on 2026-08-14 the second independent formalization required by FORMALIZATION_METHODOLOGY.md §5 was completed blind and adjudicated. The second formalizer read only the pack id, the norm name and each entry's provenance `article` and `quote`, mechanically extracted into .pack-verify/wave3-blind-excerpts-sg-genai-governance.json; the v/e/s arrays, summaries, rationales, obligationType tags and notes of v0.1 were withheld, and neither the pack-authoring guideline nor the management guide nor any other standards pack was opened. Human review is still outstanding and the V/E/S assignment is settled only by the public RFC process at https://aioq.org/en/rfc. A certificate issued against this pack would carry a draft-basis notice and record this status as `basisStatus` in its signed payload; no certificate may be issued against it in any case, because no item bank exists for it. [갱신 2026-08-15: 이중 관문 문항 뱅크 개통 — 관문 A 공개 세트 + 관문 B 비공개 뱅크(서명 커밋먼트 게시). 이 노트의 이전 서술은 개통 전 기록이다.]",
    "Instrument status and currency, verified on 2026-08-14. The Framework was published jointly by the AI Verify Foundation and IMDA. Its cover reads 'Published 30 May 2024', and the AI Verify Foundation's own landing page for the document (https://aiverifyfoundation.sg/resources/mgf-gen-ai/) states that it was released on 30 May 2024 while linking to a PDF whose file name and PDF creation date are 19 June 2024. This pack cites 30 May 2024: the June file is a repost of the same document, and no textual difference is asserted. The cover date could not be read from the PDF text layer, because page 1 of this document carries no extractable text; it was read by rasterizing page 1 at 100 dpi and reading the image, and that is recorded here rather than presented as a text-layer match. The document carries no edition or version number. No second edition, revision, addendum or erratum was found on any official channel as at 2026-08-14, and it remains listed among current publications on the AI Verify Foundation resources page. Recorded as an absence-of-evidence finding: no official page was found that affirmatively reaffirms the Framework's currency after 2026 either.",
    "Related instruments that are NOT this one, and are not formalized here. (a) The Model AI Governance Framework (Second Edition, 21 January 2020, IMDA and the Personal Data Protection Commission) addresses traditional AI. It is separate, still current, and this Framework's Trusted Development and Deployment dimension says the 2020 principles 'continue to be relevant and are extended here for generative AI'. (b) The Model AI Governance Framework for Agentic AI is a separate and later IMDA instrument — version 1.5, published 20 May 2026, updated 5 June 2026, launched at version 1.0 on 22 January 2026. It must not be conflated with this document. Its own text anchors it to the 2020 framework, saying it 'builds on the responsible AI practices for organisations set out in MGF (2020)', and it describes itself as a living document; no official text says it supersedes or replaces either earlier framework, and this pack treats the relationship as supplementary. If the Agentic AI framework is formalized, it takes its own pack id. (c) Singapore's testing instruments named in or around this Framework — the AI Verify testing framework and toolkit, Project Moonshot, the paper Cataloguing LLM Evaluations (October 2023), and the Starter Kit for Testing LLM-Based Applications for Safety and Reliability (version 1.0, January 2026, IMDA and AI Verify Foundation) — belong to IMDA and the AI Verify Foundation. They are described in this pack and its guide, and nothing produced by AIO is one of them or a substitute for one.",
    "Primary source and retrieval path. The text formalized here is the official PDF published by the AI Verify Foundation at https://aiverifyfoundation.sg/wp-content/uploads/2024/06/Model-AI-Governance-Framework-for-Generative-AI-19-June-2024.pdf, which resolved directly on 2026-08-14 (HTTP 200, application/pdf, 3,740,177 bytes, 36 pages) and is recorded as `sourceUrl` in every entry. No `retrievalUrl` is recorded because no substitute endpoint was needed. No commentary, law-firm summary, trade-press explainer, mirror or secondary source was used for any quote, and no quotation in this pack was reconstructed from memory. An earlier upload of the same document exists under a May 2024 path on the same host; the June upload is the one the official landing page links to, and it is the one used.",
    "Quote verification method, and its limits. The PDF was reduced to a whitespace-normalized, NFC-normalized corpus by two independently written extraction paths — poppler `pdftotext -enc UTF-8` (59,065 characters) and a `pypdf` page-by-page extraction (59,012 characters). The two corpora are NOT byte-identical: 132 difference blocks were found, every one of which is a control character used for bullet glyphs (U+0007, U+0008) or a difference in where a page header or page number is placed in the reading order. No difference falls inside any quoted fragment. All 16 quoted fragments across the 9 entries (counting the parts on either side of an […] elision separately) were then checked as exact substrings of BOTH corpora; all 16 matched in both. The limit to record honestly, as in the UNESCO pack: extraction was verified twice, but only one official manifestation of the document was available, so the source manifestation was not cross-checked against a second official publication. That is one of the reasons no entry is claimed above `draft-unverified`.",
    "Licence and reuse — treated as a constraint-classified (C) source, on a stricter footing than the UNESCO pack. There is no express reuse licence on this document. The Framework's own back cover carries, verbatim, '© COPYRIGHT IMDA AND AI VERIFY FOUNDATION 2024. ALL RIGHTS RESERVED.', and that is the only rights statement inside the PDF. The AI Verify Foundation's Terms of Use (https://aiverifyfoundation.sg/terms-of-use/) permit use, copying and distribution of site contents 'solely for personal, internal, non-commercial, informational purposes only', and state that contents may not be reproduced, published or otherwise distributed 'without the prior written permission of AIVF'; IMDA's Terms of Use (https://www.imda.gov.sg/terms-of-use) carry materially identical wording for IMDA. No Singapore Open Data Licence is asserted over these documents anywhere: that licence governs datasets on data.gov.sg. AIO therefore does not rely on any licence for this pack. Consequences applied here, following the UNESCO precedent and docs/팩_추가_가이드라인.md §5: (a) quotation is held to the minimum needed to evidence each mapping and is offered as short attributed quotation with full source citation, not as licensed reuse; (b) no control set is derived from the document's wording — the V/E/S mappings are AIO's own analysis expressed in AIO's own vocabulary, the summaries, notes and rationales are paraphrase, and the management-system guide for this pack paraphrases throughout, using blockquotes only where a provenance excerpt already verified in this pack exists; (c) where a code rests on a sentence outside the quoted excerpt, that sentence is described in the rationale rather than quoted, which is why several rationales say 'cited and not quoted'. Attribution: Model AI Governance Framework for Generative AI — Fostering a Trusted Ecosystem, AI Verify Foundation and Infocomm Media Development Authority of Singapore, published 30 May 2024, © IMDA and AI Verify Foundation 2024, all rights reserved.",
    "Licence self-check, in numbers. Nine excerpts, one per dimension, 16 fragments, 1,622 characters of quoted text in total, longest single excerpt 198 characters, mean 180. That is about 2.7% of the 59,065-character extracted text of the document. The proportion is higher than the UNESCO pack's 1.6% because this document is roughly three-fifths the length, not because more was taken: the UNESCO pack quoted 10 excerpts averaging 162 characters, this one quotes 9 averaging 180. No excerpt reproduces a complete sub-section, no excerpt reproduces any of the seven disclosure headings as a list, and the two descriptive boxes in the document (the CVE programme, and incident reporting under the EU AI Act) are paraphrased and not quoted at all. The one longer verbatim string reproduced anywhere in this pack is the copyright notice itself, quoted in the licence note above because a reader has to be able to see the exact rights statement being relied on.",
    "Permissions inquiry — drafted, not sent, as at 2026-08-14. A reuse-permission inquiry to IMDA covering the Model AI Governance Framework family (the 2020 Second Edition, this 2024 generative AI framework, and the 2026 Agentic AI framework) is written at docs/license-inquiries/imda.md and has not been sent. Until a reply is received, this pack and its guide stay inside the short-attributed-quotation footprint described above, and any expansion of quotation, any derived control set phrased from the Framework's wording, and any item bank for this pack wait on that reply. Note in particular that an item bank must in any case be authored in AIO's own words.",
    "Unit granularity, and what the adjudication did to the source-axis rule. This Framework has no articles. Its normative content is organized as nine dimensions, each with an introduction and a 'Design' section of two to four sub-sections, written as continuous prose. A unit in this pack is therefore one dimension, and the quoted excerpt is a representative anchor within it rather than the whole provision. v0.1 drew a consequence from that for the Wave 1 cross-pack source-axis rule (recorded in coe-ai-convention-v0.2.json), which declares a source class only where the quoted excerpt itself names the class decisive on the substance of the duty: it applied the rule at dimension level instead, on the ground that excerpt-strict application would leave `Gov` on two entries out of nine — an artefact, it argued, of how short the licence discipline forces the excerpts to be. **That adaptation did not survive the dual formalization and is withdrawn.** The blind second pass read excerpt-strictly, as FORMALIZATION_METHODOLOGY.md §4 requires, and the divergence between the two passes is almost entirely explained by it: of the 20 axis-level disagreements, 14 involve a v0.1 code whose own rationale names a sentence outside the quoted excerpt as its ground. Applied as the cross-pack rule requires, `Gov` survives on one entry (Dimension 2, where policymakers are asked to articulate how existing personal data law applies) and is refused on the other eight, `Ind` survives on two (Dimensions 3 and 7, where the excerpt makes industry the author of the label or the embedded provenance signal) and `Pro` on one (Dimension 5, where ISO/IEC and IEEE are named inside the excerpt). The underlying question v0.1 raised is real and is carried to the RFC round unchanged: how the source-axis rule should read for norms that are not article-structured, and whether a licence constraint that forces short excerpts should be allowed to narrow a mapping. The answer adopted here is that it should — a pack may not declare more than its own evidence shows — and that the remedy is a permissions reply that allows longer excerpts, not a looser rule.",
    "Policy-direction character — the honest reading of what this Framework is. It is not written to an organization. Its executive summary says it requires all key stakeholders — policymakers, industry, the research community and the broader public — to collectively do their part, and the balance of its text bears that out: it asks policymakers to articulate how personal data law applies and to define model risk thresholds, governments to fund AI safety institutes and coordinate public-sector adoption, standards organisations to codify testing, industry bodies and governments to build a tester pool, publishers to display provenance, and educational institutions to redesign jobs. Its own closing section calls itself a first step and says implementation guidelines and resources remain to be developed. Read as a set of duties on a certifiable operator, it is thinner than any binding norm in the roster; read as what it is — a jurisdiction's proposed architecture for a trusted ecosystem, offered for international convergence — it is coherent and consequential. Both readings are recorded here so that neither the pack page nor the guide can imply that passing items built on this pack has anything to do with what Singapore is actually asking for.",
    "Measurement scope in numbers (per-entry `obligationType`, pack-level `measurementScope`), unchanged by the dual formalization. Of the nine dimensions mapped, none is `behavioral`, three are `mixed` (Trusted Development and Deployment, Incident Reporting, Content Provenance — each has a judgment correlate an item can test, sitting on a disclosure, process or deployment duty it cannot), and six are `organizational` outright (Accountability, Data, Testing and Assurance, Security, Safety and Alignment R&D, AI for Public Good). Seven of the nine tags were reached identically by the two independent passes, and the two divergences both resolved to v0.1's tag under the conservative rule — the blind pass proposed `mixed` at Dimension 1 and `behavioral` at Dimension 3 — so the distribution published in v0.1 is confirmed rather than revised. It is the only axis of this pack that survives the adjudication intact. The absence of any `behavioral` entry puts this pack with the six Wave 1 packs rather than with the OECD Principles or California SB 53 packs as those were seeded, and after Waves 1 and 2 the only surviving `behavioral` entry anywhere in the roster is paragraph 36 of the UNESCO pack. A pass on this pack is evidence about model judgment only, and never evidence that an operator has implemented anything.",
    "Inferred codes — none survive. v0.1 carried two codes derived from a dimension's structure rather than from its words, each flagged INFERENCE in its own rationale and each put to the RFC round: `Hum` on Dimension 5 (a rule making independence the condition of objective results presumes that self-assessment does not reliably surface a party's own limits) and `Pee` on Dimension 8 (the dimension asks that research govern what is done about alignment but designates no independent scholarly review). The blind second pass reached neither, and both were removed at adjudication under the standing rule that a code flagged INFERENCE by the pass that declared it survives only where both independent passes reached it. The inference-grade codes the blind pass introduced and v0.1 did not reach — `Log` at Dimension 1, `Sep` at Dimension 2, `Cas` at Dimension 4, `Sda` at Dimension 8 — were treated identically and none is carried. Three codes the blind pass flagged as inferred do survive, because v0.1 had independently declared them: `Ind` at Dimensions 3 and 7, and `Ses` at Dimension 6. Separately, v0.1 recorded eight codes as resting on sentences inside the mapped dimension but outside the quoted excerpt — `Unc` on Dimension 2, `Hum` on Dimension 3, `Sep` and `Cas` on Dimension 6, `Ses` on Dimension 7, and `Gov` and `Ind` on Dimension 9 — and not one survives the excerpt-strict reading applied at adjudication. Codes deliberately considered and refused in v0.1 are all confirmed, and the refusal list is now longer: `Gov` is additionally refused on Dimensions 4, 8 and 9, and `Ind` on Dimensions 1, 2, 4, 5, 6 and 9.",
    "What is not mapped. All nine dimensions are mapped, so nothing normative is dropped, but three parts of the document are outside the mapping and are recorded here. (a) The two descriptive boxes — the CVE programme run by the MITRE Corporation, and incident reporting under the EU AI Act — describe other parties' arrangements rather than stating this Framework's own direction; the EU AI Act box in particular is not coded, because that Regulation is formalized in its own pack and coding it through another document's summary of it would double-count a norm through a secondary description. (b) The Conclusion, Acknowledgements and Further Development sections carry no direction. (c) Within each mapped dimension, the sub-sections that are neither quoted nor coded are covered in the summary field and, more fully, in the management-system guide — which by design goes wider than the pack.",
    "Non-endorsement. AIO wrote this formalization. The AI Verify Foundation, IMDA, the Government of Singapore, and every organization and individual listed in the Framework's acknowledgements took no part in it, have not reviewed it, and have not endorsed it. It is not an official interpretation of the Framework. AIO certifies conformance to AIO's own formalization of this Framework; that is not a legal assessment, not an assessment of alignment with the Framework, and confers no status of any kind with IMDA, the AI Verify Foundation, Singapore's AI Verify testing programme, or any accreditation mechanism of the kind Dimension 5 anticipates.",
    "No item bank. `itemBankRef.publicSet` and `itemBankRef.privateSet` are both null: no scenario items have been written for this pack, so it currently backs no certificate at any tier and appears in the catalogue as listed, measurement pending. Item authoring follows verification, not the other way round. Note additionally that with no `behavioral` entry and only three `mixed` entries, the testable surface of this pack is narrow: any bank built on it would draw almost entirely on Dimensions 3, 4 and 7. [갱신 2026-08-15: 이중 관문 문항 뱅크 개통 — 관문 A 공개 세트 + 관문 B 비공개 뱅크(서명 커밋먼트 게시). 이 노트의 이전 서술은 개통 전 기록이다.]",
    "Methodology for the dimension → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. V/E/S values are the canonical three-letter AIO 00011 codes served at /api/framework/vocabulary — the same codes an AIO 20002 record carries. Management-system obligations arising from this Framework, including the sub-sections this pack does not quote, are covered in docs/management-guides/sg-genai-governance.ko.md and .en.md.",
    "Adjudication method (v0.2). This pack was formalized twice. The v0.1 seed pass is the first formalization; the second was blind, under the protocol recorded in the first note, and its output is kept at .pack-verify/second-pass-sg-genai-governance.json. The two results were compared mechanically, entry by entry and layer by layer, with `v`, `e` and `s` treated as sets — the pack schema carries no ordering semantics, so the blind pass's ascending-priority convention for its own arrays was recorded and not applied. Exact agreement was auto-accepted. Divergences were adjudicated under the fixed policy carried forward from Waves 1 and 2: the reading better grounded in the quoted text prevails under FORMALIZATION_METHODOLOGY.md §4; where both readings are defensible the more conservative is taken (fewer codes, or a layer left undeclared); the intersection is an allowed outcome where it is non-empty and defensible; no third reading is invented, and every adjudicated set is a subset of at least one pass's set. Two sub-rules are restated so they can be checked: a code flagged INFERENCE by the pass that declared it survives only where both passes reached it, and a divergent `obligationType` always resolves to the more conservative tag (organizational over mixed over behavioral). The cross-pack source-axis rule was applied as a filter and never as a generator — it removed codes and decided between divergent readings, and added nothing neither pass declared. Agreement statistics across the nine entries: V 2/9 (Dimensions 1 and 9), E 4/9 (Dimensions 2, 5, 7 and 9), S 3/9 (Dimensions 3, 5 and 7), obligationType 7/9, all four axes together 0/9. Twenty of the thirty-six axis decisions were divergent. Every adjudicated layer is the exact intersection of the two passes with one exception, which is recorded so it can be audited: the source layer of Dimension 8, where `Gov` was declared by both passes and removed by the source-axis filter. The systematic pattern is over-declaration in v0.1 beyond what the quoted excerpts carry — the same finding as Waves 1 and 2 — sharpened here by v0.1's dimension-level source-axis adaptation, which is withdrawn.",
    "Contamination notice, and a disclosed protocol deviation. The blind second formalizer disclosed that it read four files beyond its brief, and the disclosure is reproduced here rather than summarized away. FORMALIZATION_METHODOLOGY.md §4 does not carry the 39-code catalogue — it defers the canonical list to /api/framework/vocabulary — so the pass could not produce a mechanically checkable mapping from §4 alone. It therefore read src/app/api/framework/vocabulary/route.ts, src/app/lib/frameworkVocabulary.ts, the VALUES / EVIDENCE_CAT / SOURCE_CAT definition lines of src/app/components/standards/workshopData.ts, and public/dialogue/vocabulary-reference.pdf, whose first page rendered illegibly and yielded nothing. Assessed at adjudication: those files carry the neutral 19+10+10 code catalogue and the AIO 20002 log-line grammar and no pack content whatever. No standards-pack JSON, no other .pack-verify file, no docs/ file, no management guide and no git history was read, so no first-pass mapping for this or any other pack was seen. **Protocol deviation disclosed; no contamination.** The reading is expressly permitted by the pack-authoring guideline §2.3 as amended on 2026-08-14 for exactly this reason, and all five Wave 3 blind passes hit the same wall and disclosed it identically. No axis of this pack is reported with a contamination caveat.",
    "Vocabulary and schema gaps found by the dual formalization (feeding a future AIO 00011 RFC). This pack contributes one item, canonical Wave 3 number 27 (assigned in the wave-end consolidation, 2026-08-14), to the Wave 3 list, which continues the consolidated Wave 1 list of ten and the Wave 2 list that ended at 23, and confirms five existing items. NEW — (27) INDEPENDENCE AND OBJECTIVITY OF AN ASSESSMENT AS A VALUE: Dimension 5 states that 'Independence is key to ensuring the objectivity and integrity of test results', which is the value the whole third-party testing dimension turns on, and the 19-value catalogue has no code for it. v0.1 used `Ses`, the blind pass used `Sdt` for the tester's own judgment and added `Cor` for codification, and none is carried; the value layer of that entry is left undeclared. It is distinct from Wave 2 gap 14 (the contracted independent evaluator as a source class), which is the same absence on the source axis and is confirmed again here — the third-party testers and the future accreditation mechanism this dimension asks for have no carrier among the ten source codes. Confirmed again: Wave 1 gap 3 INFORMATION INTEGRITY (Dimension 7's misinformation and election-integrity framing, where `Ses` was declared by one pass only and is not carried); Wave 1 gap 8 STANDARDS-DEVELOPMENT BODIES UNDER `Pro` (Dimension 5, where both passes carried `Pro` for ISO/IEC and IEEE with the same recorded misfit); Wave 1 gap 10 UNDEFINED PROTECTED INTEREST (Dimension 5 again, the second instance after UNESCO ¶71 of two independent passes sharing no value code); Wave 2 gap 15 HUMANS KEEPING CONTROL OF THE SYSTEM (Dimension 8's 'human capacity to align and control generative AI', where the blind pass proposed `Sda` and recorded that the catalogue's autonomy codes are written for a person's own course); and Wave 2 gap 18 INCIDENT REPORTING AS AN EVIDENCE CLASS (Dimension 4, where the two passes shared no evidence code and the layer is left empty). One further observation is recorded without being called a gap: three of the nine entries end with an undeclared evidence layer and five with an undeclared source layer, which is the highest proportion in the roster, and the cause is not the norm but the licence — the excerpts are held to a fair-quotation footprint by the constraint recorded in the licence notes, and a permissions reply from IMDA would allow the question to be re-asked on fuller text."
  ]
}