{
  "schema": "csoai.learning-scenarios/0.1",
  "state": "READY",
  "purpose": "Deterministic human-guided inspection and replay planning for the 22-axis GSPC UI.",
  "classification_enum": [
    "BOARD_MEASUREMENT_CONTEXT",
    "VERIFIED_PUBLISHED_EVIDENCE",
    "CANDIDATE_FINDING",
    "REGULATION_CONTEXT"
  ],
  "source_snapshot": {
    "board": {
      "url": "/api/gspc",
      "schema": "csoai.gspc-axes/0.5",
      "axes": 22,
      "measured_on": {
        "model": "The 14 behavioural (model-comparison) axes: 19-model fleet (8 tuned council specialists + 6 base models + frontier cross-lab models). Jail (slot 14): 7-model fleet — smaller, stated on the axis, never conflated with the board fleet. The 8 financial/domain axes are not a model comparison: they are measured as deterministic facts (issuer-account reads + public series), with no fleet, no leader and no accuracy.",
        "endpoint": "A100 · local Ollama (board v2) · OpenRouter (cross-lab models) · 3090 pod (jail)",
        "date": "behavioural axes 2026-08-12 · jail 2026-08-18 · financial-fact axes 2026-08-25",
        "grading": "deterministic grading on 15,580 per-item rows (0 transport errors) — reproducible from csoai-static-deploy2 bb15589c with agents-repo/agents/board_v2.py",
        "note": "GSPC (Governance · Safety · Provenance · Continuity) board. Slot counts live in totals (public_count, measured_axes, quotable_axes) and are derived, never typed. The measured canonical axes used the same fleet, same rows, same grader. Per-axis numbers show the board LEADER (whoever leads — tuned or base), its Wilson interval where n is honestly independent, and whether the lead is statistically separated (McNemar p<0.05) or a TIE. fleet_mean and mean_harm show the fleet, not the leader. Separation test and per-axis canonical counts: agents-repo/arena-real-runs/SEPARATION_TEST_2026-08-13.md and GSPC_AXIS_REGISTRY.json v2. Jail carries its per-model rows verbatim from the signed living board; its separation is TIE (determined 2026-08-25) — a TIE is not a separated leader. slot15 and human-vs-ai are measured in-lane only — see measured_in_lane, not the board.",
        "living_stamp": {
          "schema": "csoai.gspc-living/0.2",
          "gold_run": "2026-08-18T03:22:16Z",
          "source": "boards-v2 + gold-run-3090; axis roster of this deploy (not a live re-fetch)",
          "signed": true,
          "signer": "did:web:csoai.org#board-attestation-1",
          "signer_anchored": true,
          "alg": "Ed25519",
          "signature": "76e91fcc71019631376ff312924c88ebd028b254968708d83f6dd2f8b473e48b9085818764bed45bb168c75e7bc270a6c3618e9eea318ad87346f7849f6f250e",
          "public_key_x": "k2fPWb6ctyu8l5at8FYgHsHFit_qoT-DssW3VNbCAXA",
          "preimage": {
            "schema": "csoai.gspc-living/0.2",
            "gold_run": "2026-08-18T03:22:16Z",
            "source": "boards-v2 + gold-run-3090; axis roster of this deploy (not a live re-fetch)",
            "axes": [
              {
                "axis": "governance",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 237,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "safety",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 36,
                "accuracy": 0.944,
                "separation": "TIE"
              },
              {
                "axis": "provenance",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 32,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "continuity",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 33,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "conformance",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 35,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "openness",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 32,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "machinery-conformity",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 33,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "care",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 199,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "cross-reality",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 32,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "detector-interop",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 33,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "art5-safeguard",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 36,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "swarm",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 37,
                "accuracy": 0.384,
                "separation": "SEPARATED"
              },
              {
                "axis": "affect",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 41,
                "accuracy": null,
                "separation": "UNTESTED"
              },
              {
                "axis": "jail",
                "family": "gspc",
                "kind": "model-comparison",
                "status": "MEASURED",
                "n": 71,
                "accuracy": 0.5915,
                "separation": "TIE"
              },
              {
                "axis": "provenance-controls",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 6,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "reserve-attestation",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 16,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "regulatory-framework",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 16,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "distribution-integrity",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 16,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "custody-disclosure",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 16,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "ai-adoption-components",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 2,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "labour-components",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 2,
                "accuracy": null,
                "separation": null
              },
              {
                "axis": "humanoid-labour-index",
                "family": "financial",
                "kind": "deterministic-facts",
                "status": "MEASURED",
                "n": 8,
                "accuracy": null,
                "separation": null
              }
            ]
          },
          "sig_input": "Ed25519 over the RAW UTF-8 BYTES (not a digest) of canonical JSON of the `preimage` object only ({schema, gold_run, source, axes}). Canonical JSON: object keys sorted by code point, recursively; no whitespace (separators ',' and ':'); non-ASCII emitted LITERALLY as UTF-8 (ensure_ascii=False); numbers by ECMAScript Number::toString (integral float renders 0, not 0.0). Envelope fields (signature, public_key_x, sig_input, signer, signed, signer_anchored, alg, verification_state, verifiable, superseded, tracked_as, verify) are NOT in the preimage.",
          "sig_input_ensure_ascii": false,
          "sig_input_is_digest": false,
          "verification_state": "SIGNED",
          "verifiable": true,
          "verify": "fetch https://csoai.org/.well-known/did.json → #board-attestation-1 → Ed25519-verify `signature` over the raw UTF-8 bytes of canonical(`preimage`), ensure_ascii=False",
          "superseded": {
            "source": "board_living.json (csoai.gspc-living/0.1, boards-v2 + gold-run-3090)",
            "updated": "2026-08-18T03:22:16Z",
            "signed": true,
            "verification_state": "UNVERIFIABLE",
            "verifiable": false,
            "signer": "8f9a00a28cfc76e36029fe805f3e421958f4d7d42c4f114865918a1001313912",
            "signer_anchored": false,
            "signature": "bd199fd34a80b6352be727160c2fef34e6f66ca412baeba5b03dbe097a100afd89b037f5806c2924bc54cc27f75c09aa52762e016481ffafe1fab026e3c62f06",
            "sig_input": "sha256(canonical board minus signature fields, sort_keys) — AS PUBLISHED WHEN SIGNED, AND NOT REPRODUCIBLE. This string is not a sufficient preimage rule: it does not say which fields count as signature fields, whether the signature is over the digest bytes, the digest hex or the raw canonical bytes, or how non-ASCII is encoded.",
            "unverifiable_note": "DO NOT TREAT THIS AS A VALID ATTESTATION. This stamp was signed, but no published bytes reproduce it: 58,184 readings were attempted on 2026-08-26 across both published signatures, all five published keys, nine candidate payloads, raw/digest/hex message forms, both ensure_ascii settings and every drop-set of up to three fields. None verified. Two different signatures are published for this one stamp (53aa09fa… in /signed/board_living.json, bd199fd3… here), the signer is not among the verification methods in /.well-known/did.json, and board_living.json's own note says its axes were re-snapshotted from the live board six days after the signature date — so the signed bytes are not the published bytes. Nothing here is claimed to be invalid; it is claimed to be UNCHECKABLE, which for a relying party is the same thing. The two attestations on this site that DO verify are the 150 measurement cards under #card-attestation-1 and site_attestation on this payload under #board-attestation-1; check those instead.",
            "supersedes_note": "site_attestation on this payload signs this whole body, including this block. That attestation covers the INTEGRITY of these bytes as served — it does not substantiate the living stamp, and must not be read as doing so.",
            "reproduction_attempts": 58184,
            "reproduction_verified": 0,
            "tracked_as": "/api/corrections C-2026-0826-08"
          },
          "tracked_as": "/api/corrections C-2026-0826-08"
        }
      }
    },
    "findings": {
      "url": "/signed/findings_index.json",
      "schema": "csoai.regulation-findings-index/0.2",
      "as_of": "2026-08-19T09:24:39.174226+00:00",
      "verified_published_findings": 335,
      "independently_admitted_findings": 0,
      "legacy_unadjudicated_records": null
    },
    "regulation": {
      "url": "/api/regulation",
      "schema": "csoai.regulation-deadlines/0.1",
      "verified_as_of": "2026-08-19",
      "deadlines": 20
    }
  },
  "policy": {
    "read_only": true,
    "writes_board": false,
    "model_training": false,
    "automatic_fixing": false,
    "automatic_promotion": false,
    "candidate_submission_endpoint": "/api/evidence-intake",
    "candidate_submission_requires_explicit_consent": true,
    "note": "This endpoint never submits a candidate. Published-card verification is not independent admission. Evidence intake remains a separate authenticated, explicit-consent POST and never auto-promotes to GSPC."
  },
  "canonical_axis_count": 22,
  "scenario_count": 22,
  "counts": {
    "verified_published_measurements": 164,
    "independently_admitted_measurements": 0,
    "candidate_findings": 164,
    "regulation_deadlines": 20
  },
  "regulation_context": [
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2025-02-02",
      "instrument": "EU AI Act",
      "what": "Article 5 prohibited practices + Article 4 AI literacy duties in force",
      "basis": "Reg (EU) 2024/1689 Art 113",
      "status": "IN_FORCE",
      "penalty_exposure": "up to €35,000,000 or 7% of worldwide annual turnover (EU AI Act Art 99(3))"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2025-08-02",
      "instrument": "EU AI Act",
      "what": "GPAI model provider obligations (Arts 53–55) + governance rules in force",
      "basis": "Reg (EU) 2024/1689 Art 113",
      "status": "IN_FORCE",
      "penalty_exposure": "up to €15,000,000 or 3% of worldwide annual turnover (EU AI Act Art 99(4))"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2025-09-01",
      "instrument": "China GB 45438-2025",
      "what": "Mandatory AI-generated content labelling (visible + implicit metadata/watermark)",
      "basis": "CAC/MIIT/MPS/NRTA joint measures",
      "status": "IN_FORCE",
      "penalty_exposure": "CAC enforcement under the labelling measures; no fixed statutory maximum published"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-01-01",
      "instrument": "California SB 53",
      "what": "Transparency in Frontier AI Act — large frontier developers (> $500M revenue)",
      "basis": "Ch. 138, Statutes of 2025",
      "status": "IN_FORCE",
      "penalty_exposure": "AG-enforced civil penalties up to $1,000,000 per violation (Ch. 138, Statutes of 2025)"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-01-01",
      "instrument": "Texas TRAIGA (HB 149)",
      "what": "Intent-based prohibitions, AG-exclusive enforcement, 60-day cure",
      "basis": "HB 149",
      "status": "IN_FORCE",
      "penalty_exposure": "$10,000–$200,000 per violation plus up to $40,000/day continuing (HB 149)"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-01-22",
      "instrument": "South Korea AI Basic Act",
      "what": "High-impact + generative AI obligations; extraterritorial representative duty; one-year fine grace",
      "basis": "Framework Act, promulgated 2025-01-21",
      "status": "IN_FORCE",
      "penalty_exposure": "administrative fines up to KRW 30,000,000 (~US$20,700) per Art 43; MSIT one-year fine grace in 2026"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-08-02",
      "instrument": "California AI Transparency Act (CAITA, SB 942)",
      "what": "Large GenAI providers: public AI-detection tool plus manifest and latent disclosure for AI-generated media",
      "basis": "SB 942/AB 853 as amended 2025 (operative 2 Aug 2026)",
      "status": "IN_FORCE",
      "penalty_exposure": "civil penalties enforceable by state authorities; no private right of action (SB 942/AB 853)"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-08-02",
      "instrument": "EU AI Act",
      "what": "Article 50 transparency + full penalty/market-surveillance regime + AI Office GPAI enforcement in force (NOT high-risk — see deferral)",
      "basis": "Reg (EU) 2024/1689 Art 113",
      "status": "IN_FORCE",
      "penalty_exposure": "up to €15,000,000 or 3% of worldwide annual turnover (EU AI Act Art 99(4))"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-09-11",
      "instrument": "EU Cyber Resilience Act",
      "what": "Article 14 vulnerability/incident reporting live (24h early warning / 72h notification via ENISA Single Reporting Platform; covers legacy products)",
      "basis": "Reg (EU) 2024/2847 Art 14/16",
      "status": "UPCOMING",
      "penalty_exposure": "up to €15,000,000 or 2.5% of worldwide annual turnover (CRA)"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-12-02",
      "instrument": "EU AI Act Art 5 (new)",
      "what": "Prohibitions on AI generating non-consensual intimate imagery and CSAM take effect",
      "basis": "Digital Omnibus amendments",
      "status": "UPCOMING",
      "penalty_exposure": "up to €35,000,000 or 7% of worldwide annual turnover (EU AI Act Art 99(3), prohibited-practice tier)"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-12-02",
      "instrument": "EU AI Act Art 50(2)",
      "what": "Marking grace ends for generative systems placed on market before 2 Aug 2026",
      "basis": "Art 111(4), inserted by Digital Omnibus Reg (EU) 2026/1744 Art 1(39)(b)",
      "status": "UPCOMING",
      "penalty_exposure": "up to €15,000,000 or 3% of worldwide annual turnover (EU AI Act Art 99(4)(g))"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-12-09",
      "instrument": "EU Product Liability Directive",
      "what": "Member-state transposition deadline — software and AI enter strict no-fault liability",
      "basis": "Dir (EU) 2024/2853 Art 24",
      "status": "UPCOMING",
      "penalty_exposure": "no statutory cap — exposure is claimant-proven damage"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2026-12-10",
      "instrument": "Australia Privacy Act",
      "what": "Automated-decision transparency obligation takes effect",
      "basis": "Privacy Act amendment",
      "status": "UPCOMING",
      "penalty_exposure": "OAIC enforcement under the Privacy Act civil-penalty regime"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2027-01-01",
      "instrument": "Colorado SB 26-189",
      "what": "ADMT disclosure/transparency framework (replaces repealed SB 24-205)",
      "basis": "SB 26-189, signed 2026-05-14",
      "status": "UPCOMING",
      "penalty_exposure": "Colorado AG enforcement; no fixed statutory maximum published"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2027-01-01",
      "instrument": "Illinois SB 315",
      "what": "Frontier-developer disclosure statements begin (audit mandate follows 2028-01-01)",
      "basis": "Public Act 104-0538 §18(a), §10(d)",
      "status": "UPCOMING",
      "penalty_exposure": "up to $1,000,000 first violation / $3,000,000 subsequent, plus $1,000/day for unfiled disclosures"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2027-01-01",
      "instrument": "New York RAISE Act",
      "what": "Frontier transparency + 72-hour incident reporting to NYDFS oversight office",
      "basis": "S6953B/A6453B as amended 2026-03-27",
      "status": "UPCOMING",
      "penalty_exposure": "NYAG civil penalties up to $1,000,000 first / $3,000,000 subsequent"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2027-08-02",
      "instrument": "EU AI Act",
      "what": "Pre-Aug-2025 GPAI models must reach compliance; national regulatory-sandbox obligation",
      "basis": "Reg (EU) 2024/1689 as amended",
      "status": "UPCOMING",
      "penalty_exposure": "up to €15,000,000 or 3% of worldwide annual turnover (EU AI Act Art 99(4))"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2027-12-02",
      "instrument": "EU AI Act",
      "what": "Stand-alone Annex III high-risk obligations apply (deferred from 2 Aug 2026)",
      "basis": "Digital Omnibus Reg (EU) 2026/1744",
      "status": "UPCOMING",
      "penalty_exposure": "up to €15,000,000 or 3% of worldwide annual turnover (EU AI Act Art 99(4))"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2028-01-01",
      "instrument": "Illinois SB 315",
      "what": "Mandatory annual independent third-party audits of frontier developers",
      "basis": "Public Act 104-0538 §10(d)",
      "status": "UPCOMING",
      "penalty_exposure": "up to $1,000,000 first violation / $3,000,000 subsequent, plus $1,000/day for unfiled disclosures"
    },
    {
      "classification": "REGULATION_CONTEXT",
      "source": "/api/regulation",
      "date": "2028-08-02",
      "instrument": "EU AI Act",
      "what": "Product-embedded Annex I high-risk obligations apply",
      "basis": "Digital Omnibus Reg (EU) 2026/1744",
      "status": "UPCOMING",
      "penalty_exposure": "up to €15,000,000 or 3% of worldwide annual turnover (EU AI Act Art 99(4))"
    }
  ],
  "scenarios": [
    {
      "scenario_id": "gspc-axis:governance",
      "ordinal": 1,
      "axis": "governance",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "GovBench",
        "task": "EU AI Act risk-tier classification",
        "n": 237,
        "separation": "UNTESTED",
        "fleet_mean": 0.49,
        "mean_harm": 0.51,
        "cvar05_harm": 0.8728,
        "dataset": "csoai/gspc-gov",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-gov",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.1667,
            "measured_on": "2026-08-19T09:24:39.153328+00:00",
            "card": "1390baba7c0507ddd6ec85088b3a9763c1b7d929aa01ca298414478ff90b356d",
            "card_url": "/signed/cards/1390baba7c0507ddd6ec85088b3a9763c1b7d929aa01ca298414478ff90b356d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.0833,
            "measured_on": "2026-08-19T09:24:39.164266+00:00",
            "card": "1f613ac5091170cbec545488f53dcd61134b06c566018de52e47d157480abbe5",
            "card_url": "/signed/cards/1f613ac5091170cbec545488f53dcd61134b06c566018de52e47d157480abbe5.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.65,
            "measured_on": "2026-08-19T09:24:39.166965+00:00",
            "card": "5327f30b4857d8fd31e55bdd8b764406922624fa23e38eaf25b3cd5e32d78def",
            "card_url": "/signed/cards/5327f30b4857d8fd31e55bdd8b764406922624fa23e38eaf25b3cd5e32d78def.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2083,
            "measured_on": "2026-08-19T09:24:39.165918+00:00",
            "card": "64d5fc96a698b83d6b7c0125e0c2c7a57e087f97ed09a90e504d90b4aeaf768b",
            "card_url": "/signed/cards/64d5fc96a698b83d6b7c0125e0c2c7a57e087f97ed09a90e504d90b4aeaf768b.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2083,
            "measured_on": "2026-08-19T09:24:39.160774+00:00",
            "card": "76a1d3e23494015d61f15e629696b2b75e4887778d289af8677687023a45d9bf",
            "card_url": "/signed/cards/76a1d3e23494015d61f15e629696b2b75e4887778d289af8677687023a45d9bf.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.25,
            "measured_on": "2026-08-19T09:24:39.167285+00:00",
            "card": "79159bae8feedf33b837612e985d9f252af348fd7d857f210ce7388e0a1d3b88",
            "card_url": "/signed/cards/79159bae8feedf33b837612e985d9f252af348fd7d857f210ce7388e0a1d3b88.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.0417,
            "measured_on": "2026-08-19T09:24:39.162796+00:00",
            "card": "8412ad023f82a9bb9fb429cddfe68513a124f7d0632887594819fc987e195e35",
            "card_url": "/signed/cards/8412ad023f82a9bb9fb429cddfe68513a124f7d0632887594819fc987e195e35.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.4667,
            "measured_on": "2026-08-19T09:24:39.167611+00:00",
            "card": "8a23cd9d29771a9067226006a1c4b3d88660775d0d44d048bd24cd150cdc8139",
            "card_url": "/signed/cards/8a23cd9d29771a9067226006a1c4b3d88660775d0d44d048bd24cd150cdc8139.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.25,
            "measured_on": "2026-08-19T09:24:39.166390+00:00",
            "card": "922159fdf82bad971a04ae1477a85888740facb7119a1e5dbc64cdc9cd5057c4",
            "card_url": "/signed/cards/922159fdf82bad971a04ae1477a85888740facb7119a1e5dbc64cdc9cd5057c4.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2917,
            "measured_on": "2026-08-19T09:24:39.164510+00:00",
            "card": "9244084999a43e5718ec6c2dc327f0b943f71216b92051bb4a3c2dad803c1827",
            "card_url": "/signed/cards/9244084999a43e5718ec6c2dc327f0b943f71216b92051bb4a3c2dad803c1827.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.25,
            "measured_on": "2026-08-19T09:24:39.165161+00:00",
            "card": "9429a158e1c8fb5ae887611d075a4129306ae7dd9cbac4e148e51903031f94c1",
            "card_url": "/signed/cards/9429a158e1c8fb5ae887611d075a4129306ae7dd9cbac4e148e51903031f94c1.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.3684,
            "measured_on": "2026-08-19T09:24:39.158203+00:00",
            "card": "94b8831311c24df5e7d93e1f1dc989d24639bbe64abc4034a51d78a0306508e1",
            "card_url": "/signed/cards/94b8831311c24df5e7d93e1f1dc989d24639bbe64abc4034a51d78a0306508e1.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.25,
            "measured_on": "2026-08-19T09:24:39.163213+00:00",
            "card": "97df7c8d3f062f5c32198482340a1a7f2cde9306b8560274d5fda108dee9fc6b",
            "card_url": "/signed/cards/97df7c8d3f062f5c32198482340a1a7f2cde9306b8560274d5fda108dee9fc6b.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.125,
            "measured_on": "2026-08-19T09:24:39.163587+00:00",
            "card": "9e4db8a75256c56f2383ea601c163f3762899ace17cf53cdd9c1668070ee293d",
            "card_url": "/signed/cards/9e4db8a75256c56f2383ea601c163f3762899ace17cf53cdd9c1668070ee293d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2917,
            "measured_on": "2026-08-19T09:24:39.159700+00:00",
            "card": "a14dfc583db23cc6ef6ab50b269c5dcd4f7aaf7fd25441c8b64ca7f59bb12068",
            "card_url": "/signed/cards/a14dfc583db23cc6ef6ab50b269c5dcd4f7aaf7fd25441c8b64ca7f59bb12068.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.1667,
            "measured_on": "2026-08-19T09:24:39.165496+00:00",
            "card": "a270b32c79c67ebe778ca2eb83726bdd51d8e3aa0bf5ac42b56cc3b3bd36f794",
            "card_url": "/signed/cards/a270b32c79c67ebe778ca2eb83726bdd51d8e3aa0bf5ac42b56cc3b3bd36f794.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.25,
            "measured_on": "2026-08-19T09:24:39.164934+00:00",
            "card": "abdf7c8ebf272688fa5f54f28d4ac1dab566539aedd9ae75b4d13d026d756ef2",
            "card_url": "/signed/cards/abdf7c8ebf272688fa5f54f28d4ac1dab566539aedd9ae75b4d13d026d756ef2.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2083,
            "measured_on": "2026-08-19T09:24:39.166145+00:00",
            "card": "ac7a3847c4cb0931780a65bd996ec47557dd78ef859f8c0b6c85bee6e73d6912",
            "card_url": "/signed/cards/ac7a3847c4cb0931780a65bd996ec47557dd78ef859f8c0b6c85bee6e73d6912.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.1667,
            "measured_on": "2026-08-19T09:24:39.153743+00:00",
            "card": "bdda87864d193bf0d8e5eee0b7e874b3354daa71decf1e0defbab85d121f3011",
            "card_url": "/signed/cards/bdda87864d193bf0d8e5eee0b7e874b3354daa71decf1e0defbab85d121f3011.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2273,
            "measured_on": "2026-08-19T09:24:39.157030+00:00",
            "card": "c3be7b095029076863133572c8eb71077ff3e157f74a47da6149b6f28e7c4196",
            "card_url": "/signed/cards/c3be7b095029076863133572c8eb71077ff3e157f74a47da6149b6f28e7c4196.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "accuracy": 0.2083,
            "measured_on": "2026-08-19T09:24:39.166616+00:00",
            "card": "e88529007f329f333ba07b945d2aaf4be213867ae2f642ea52fd0d095186b8f2",
            "card_url": "/signed/cards/e88529007f329f333ba07b945d2aaf4be213867ae2f642ea52fd0d095186b8f2.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1390baba7c0507ddd6ec85088b3a9763c1b7d929aa01ca298414478ff90b356d",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1f613ac5091170cbec545488f53dcd61134b06c566018de52e47d157480abbe5",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "5327f30b4857d8fd31e55bdd8b764406922624fa23e38eaf25b3cd5e32d78def",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "64d5fc96a698b83d6b7c0125e0c2c7a57e087f97ed09a90e504d90b4aeaf768b",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "76a1d3e23494015d61f15e629696b2b75e4887778d289af8677687023a45d9bf",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "79159bae8feedf33b837612e985d9f252af348fd7d857f210ce7388e0a1d3b88",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "8412ad023f82a9bb9fb429cddfe68513a124f7d0632887594819fc987e195e35",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "8a23cd9d29771a9067226006a1c4b3d88660775d0d44d048bd24cd150cdc8139",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "922159fdf82bad971a04ae1477a85888740facb7119a1e5dbc64cdc9cd5057c4",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9244084999a43e5718ec6c2dc327f0b943f71216b92051bb4a3c2dad803c1827",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9429a158e1c8fb5ae887611d075a4129306ae7dd9cbac4e148e51903031f94c1",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "94b8831311c24df5e7d93e1f1dc989d24639bbe64abc4034a51d78a0306508e1",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "97df7c8d3f062f5c32198482340a1a7f2cde9306b8560274d5fda108dee9fc6b",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9e4db8a75256c56f2383ea601c163f3762899ace17cf53cdd9c1668070ee293d",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a14dfc583db23cc6ef6ab50b269c5dcd4f7aaf7fd25441c8b64ca7f59bb12068",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a270b32c79c67ebe778ca2eb83726bdd51d8e3aa0bf5ac42b56cc3b3bd36f794",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "abdf7c8ebf272688fa5f54f28d4ac1dab566539aedd9ae75b4d13d026d756ef2",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ac7a3847c4cb0931780a65bd996ec47557dd78ef859f8c0b6c85bee6e73d6912",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "bdda87864d193bf0d8e5eee0b7e874b3354daa71decf1e0defbab85d121f3011",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c3be7b095029076863133572c8eb71077ff3e157f74a47da6149b6f28e7c4196",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "e88529007f329f333ba07b945d2aaf4be213867ae2f642ea52fd0d095186b8f2",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-governance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 9 — risk-management system for high-risk AI",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI01 Agent Goal Hijack",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "gspc-governance",
        "match": "PREFIXED_EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 6 — classification of high-risk AI systems (Annex III)",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 9 — risk-management system for high-risk AI",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "GOVERN + MAP core functions",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI01 Agent Goal Hijack",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:safety",
      "ordinal": 2,
      "axis": "safety",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "DefBench",
        "task": "calibrated refusal on paired requests",
        "n": 36,
        "accuracy": 0.944,
        "leader": "gemma3:12b (base model)",
        "separation": "TIE",
        "separation_p": 0.6875,
        "interval": [
          0.819,
          0.985
        ],
        "fleet_mean": 0.732,
        "mean_harm": 0.268,
        "cvar05_harm": null,
        "macro_f1": 0.944,
        "unparsed_rate": 0.0541,
        "dataset": "csoai/gspc-agi",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-agi",
        "note": "A base model holds the point lead but the lead is a TIE (McNemar p=0.69 vs qwen2.5:3b). Honestly reported: the tuned specialists do not own this axis."
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.6429,
            "measured_on": "2026-08-19T09:24:39.166652+00:00",
            "card": "0629dabf9966d7bc0173611aa4444468fd90b4566aa7f2ebc7f543cdb20ad37d",
            "card_url": "/signed/cards/0629dabf9966d7bc0173611aa4444468fd90b4566aa7f2ebc7f543cdb20ad37d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5714,
            "measured_on": "2026-08-19T09:24:39.157090+00:00",
            "card": "0dc8b7ef05fd1c2b4584079ce99a12d24b157d2f2683cffce763377dd88c7213",
            "card_url": "/signed/cards/0dc8b7ef05fd1c2b4584079ce99a12d24b157d2f2683cffce763377dd88c7213.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.163274+00:00",
            "card": "1e74505674ce91c5642e24a8efaac0c75e41ddde573a242182e8daf325da6a15",
            "card_url": "/signed/cards/1e74505674ce91c5642e24a8efaac0c75e41ddde573a242182e8daf325da6a15.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 1,
            "measured_on": "2026-08-19T09:24:39.158267+00:00",
            "card": "2820aa929f4640c1ab47f85c4eb03451cbda1906d34f90f70c5f35c5edc76467",
            "card_url": "/signed/cards/2820aa929f4640c1ab47f85c4eb03451cbda1906d34f90f70c5f35c5edc76467.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5714,
            "measured_on": "2026-08-19T09:24:39.166192+00:00",
            "card": "361f6db9f34c4eb35107be15bdc19e1ec8c5420db9d2d8919d90dbd47ffb7207",
            "card_url": "/signed/cards/361f6db9f34c4eb35107be15bdc19e1ec8c5420db9d2d8919d90dbd47ffb7207.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5714,
            "measured_on": "2026-08-19T09:24:39.165561+00:00",
            "card": "3fd869fce60a5e89a4d8d27290414c662e6c32ed7beaf3a9905e00b5f6c6cbf9",
            "card_url": "/signed/cards/3fd869fce60a5e89a4d8d27290414c662e6c32ed7beaf3a9905e00b5f6c6cbf9.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.164547+00:00",
            "card": "4c8129059f5f3131e7d2d74b47ba391e8db6f9344e773b1f306e2c7d6cc1ba6c",
            "card_url": "/signed/cards/4c8129059f5f3131e7d2d74b47ba391e8db6f9344e773b1f306e2c7d6cc1ba6c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.4286,
            "measured_on": "2026-08-19T09:24:39.153398+00:00",
            "card": "5dfe7d868d252689ff4d5eabb9cad17587f797ddbd8fce26a63b7f5227c29373",
            "card_url": "/signed/cards/5dfe7d868d252689ff4d5eabb9cad17587f797ddbd8fce26a63b7f5227c29373.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.7857,
            "measured_on": "2026-08-19T09:24:39.160836+00:00",
            "card": "7afd981583afc41922731424ea2d9c33a9ae5ba9d542aab6af2efd86c4d6b09a",
            "card_url": "/signed/cards/7afd981583afc41922731424ea2d9c33a9ae5ba9d542aab6af2efd86c4d6b09a.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5714,
            "measured_on": "2026-08-19T09:24:39.165958+00:00",
            "card": "86c4f6116a7a71d6a1b5b594f7a991fba18ae66d4be95934595eada358789150",
            "card_url": "/signed/cards/86c4f6116a7a71d6a1b5b594f7a991fba18ae66d4be95934595eada358789150.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 1,
            "measured_on": "2026-08-19T09:24:39.167654+00:00",
            "card": "8fc4e0934c91222ad247179af099d09c455afaf742a1ecd534cd7156781e871c",
            "card_url": "/signed/cards/8fc4e0934c91222ad247179af099d09c455afaf742a1ecd534cd7156781e871c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.165198+00:00",
            "card": "90cab46c01db0da9ce80dff89d86c549242ac768114655595868c58d36a1598a",
            "card_url": "/signed/cards/90cab46c01db0da9ce80dff89d86c549242ac768114655595868c58d36a1598a.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.6429,
            "measured_on": "2026-08-19T09:24:39.159764+00:00",
            "card": "934d21b94bb149b2900464f2ec2a95b9312d54f9638852e2fb840bca672df4e0",
            "card_url": "/signed/cards/934d21b94bb149b2900464f2ec2a95b9312d54f9638852e2fb840bca672df4e0.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.6429,
            "measured_on": "2026-08-19T09:24:39.166431+00:00",
            "card": "98899112b5fd37120883f4e93cfc51a555718d9a62b01126f19cfb2b260e89d5",
            "card_url": "/signed/cards/98899112b5fd37120883f4e93cfc51a555718d9a62b01126f19cfb2b260e89d5.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.164973+00:00",
            "card": "aaab2caa1a77fd8a3e6ae43625e7b922522b087c68ed54d643122c17d2bfd741",
            "card_url": "/signed/cards/aaab2caa1a77fd8a3e6ae43625e7b922522b087c68ed54d643122c17d2bfd741.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.162873+00:00",
            "card": "abb7150f242321eb9a31b87ecf34d76af4e7227ac620d3673527325709ae1351",
            "card_url": "/signed/cards/abb7150f242321eb9a31b87ecf34d76af4e7227ac620d3673527325709ae1351.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.4286,
            "measured_on": "2026-08-19T09:24:39.153847+00:00",
            "card": "af649576659be1b196d0b7f274a3b42dc5e9a295707b4edef447e49983ec147b",
            "card_url": "/signed/cards/af649576659be1b196d0b7f274a3b42dc5e9a295707b4edef447e49983ec147b.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.164305+00:00",
            "card": "c683e3e8ceb3723969a4b2e91b6c69ab7a74a8621b79c54d16a5da19c34fd70d",
            "card_url": "/signed/cards/c683e3e8ceb3723969a4b2e91b6c69ab7a74a8621b79c54d16a5da19c34fd70d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.3571,
            "measured_on": "2026-08-19T09:24:39.167326+00:00",
            "card": "d5bf9ca1663e8c0f14ede9542ae99547bcd181872f467de11f59401f4c94ba3a",
            "card_url": "/signed/cards/d5bf9ca1663e8c0f14ede9542ae99547bcd181872f467de11f59401f4c94ba3a.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.4286,
            "measured_on": "2026-08-19T09:24:39.163627+00:00",
            "card": "f53c08ff3f71257c0a7ed07cf8ae8da266bc4a75057729fb0a27907029827b23",
            "card_url": "/signed/cards/f53c08ff3f71257c0a7ed07cf8ae8da266bc4a75057729fb0a27907029827b23.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "accuracy": 0.9231,
            "measured_on": "2026-08-19T09:24:39.167004+00:00",
            "card": "fa2b3a1763bc07a97a52f5c0ea98ebb704ff66d5163e973e32761375979f9cff",
            "card_url": "/signed/cards/fa2b3a1763bc07a97a52f5c0ea98ebb704ff66d5163e973e32761375979f9cff.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0629dabf9966d7bc0173611aa4444468fd90b4566aa7f2ebc7f543cdb20ad37d",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0dc8b7ef05fd1c2b4584079ce99a12d24b157d2f2683cffce763377dd88c7213",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1e74505674ce91c5642e24a8efaac0c75e41ddde573a242182e8daf325da6a15",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "2820aa929f4640c1ab47f85c4eb03451cbda1906d34f90f70c5f35c5edc76467",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "361f6db9f34c4eb35107be15bdc19e1ec8c5420db9d2d8919d90dbd47ffb7207",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "3fd869fce60a5e89a4d8d27290414c662e6c32ed7beaf3a9905e00b5f6c6cbf9",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4c8129059f5f3131e7d2d74b47ba391e8db6f9344e773b1f306e2c7d6cc1ba6c",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "5dfe7d868d252689ff4d5eabb9cad17587f797ddbd8fce26a63b7f5227c29373",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "7afd981583afc41922731424ea2d9c33a9ae5ba9d542aab6af2efd86c4d6b09a",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "86c4f6116a7a71d6a1b5b594f7a991fba18ae66d4be95934595eada358789150",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "8fc4e0934c91222ad247179af099d09c455afaf742a1ecd534cd7156781e871c",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "90cab46c01db0da9ce80dff89d86c549242ac768114655595868c58d36a1598a",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "934d21b94bb149b2900464f2ec2a95b9312d54f9638852e2fb840bca672df4e0",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "98899112b5fd37120883f4e93cfc51a555718d9a62b01126f19cfb2b260e89d5",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "aaab2caa1a77fd8a3e6ae43625e7b922522b087c68ed54d643122c17d2bfd741",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "abb7150f242321eb9a31b87ecf34d76af4e7227ac620d3673527325709ae1351",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "af649576659be1b196d0b7f274a3b42dc5e9a295707b4edef447e49983ec147b",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c683e3e8ceb3723969a4b2e91b6c69ab7a74a8621b79c54d16a5da19c34fd70d",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "d5bf9ca1663e8c0f14ede9542ae99547bcd181872f467de11f59401f4c94ba3a",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "f53c08ff3f71257c0a7ed07cf8ae8da266bc4a75057729fb0a27907029827b23",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "fa2b3a1763bc07a97a52f5c0ea98ebb704ff66d5163e973e32761375979f9cff",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-safety",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE + MANAGE core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "gspc-safety",
        "match": "PREFIXED_EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Annex III high-risk safety obligations (Arts 8–15)",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 5 — prohibited manipulative / harmful AI practices",
            "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
            "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
            "tier": "prohibited_practices",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "MEASURE + MANAGE core functions",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI05 Unexpected Code Execution",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:provenance",
      "ordinal": 3,
      "axis": "provenance",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "ProvBench",
        "task": "Article 50 marking survival by validity",
        "n": 32,
        "separation": "UNTESTED",
        "fleet_mean": 0.549,
        "mean_harm": 0.451,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-prv",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-prv",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.6667,
            "measured_on": "2026-08-19T09:24:39.165996+00:00",
            "card": "1655f3b2de29530964ed3cbdbab6dabf2dbd8eae86be7e7ca5d2a67bb4ddf585",
            "card_url": "/signed/cards/1655f3b2de29530964ed3cbdbab6dabf2dbd8eae86be7e7ca5d2a67bb4ddf585.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.166236+00:00",
            "card": "1c2e6364bb721cb14cfcf9cea9dc3e7bea7af968cc8c5c0f17f1d24ec01623e6",
            "card_url": "/signed/cards/1c2e6364bb721cb14cfcf9cea9dc3e7bea7af968cc8c5c0f17f1d24ec01623e6.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.153460+00:00",
            "card": "35a4eb2b69dfe03fad8aa082a6ab0845f506d03218ea3c1bece93337cb427bca",
            "card_url": "/signed/cards/35a4eb2b69dfe03fad8aa082a6ab0845f506d03218ea3c1bece93337cb427bca.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.166469+00:00",
            "card": "3eaa0c2779e78cd8948d7c00bd1ff2bd4cf7958a58f80ca8a3d13d4b2305e813",
            "card_url": "/signed/cards/3eaa0c2779e78cd8948d7c00bd1ff2bd4cf7958a58f80ca8a3d13d4b2305e813.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.163665+00:00",
            "card": "46305c10be50fad864218157b248d7976cfaaca788d8f5a0b01d57b74dacec62",
            "card_url": "/signed/cards/46305c10be50fad864218157b248d7976cfaaca788d8f5a0b01d57b74dacec62.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.165648+00:00",
            "card": "56209f8a717a2fe36cfe6dee2a7ee021ae633c551231d029f22416eec9a5ba89",
            "card_url": "/signed/cards/56209f8a717a2fe36cfe6dee2a7ee021ae633c551231d029f22416eec9a5ba89.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.159812+00:00",
            "card": "612d1f5ba92962e414c76271c0a271e9d2eb5d69204360ae62cee7f4792d1404",
            "card_url": "/signed/cards/612d1f5ba92962e414c76271c0a271e9d2eb5d69204360ae62cee7f4792d1404.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.167363+00:00",
            "card": "6171fc15c50ad03aef84309ffe505ba38d43f7f56232af48796d184bbfc5566c",
            "card_url": "/signed/cards/6171fc15c50ad03aef84309ffe505ba38d43f7f56232af48796d184bbfc5566c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.8,
            "measured_on": "2026-08-19T09:24:39.158329+00:00",
            "card": "62123d93724144cdfec5497af3984fa22d8ce749a4f2d0710b774c6614d8ed72",
            "card_url": "/signed/cards/62123d93724144cdfec5497af3984fa22d8ce749a4f2d0710b774c6614d8ed72.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.163351+00:00",
            "card": "70676b498f9419d9e0b393f4a064860115962be05fbb88d6b02cb3136a854061",
            "card_url": "/signed/cards/70676b498f9419d9e0b393f4a064860115962be05fbb88d6b02cb3136a854061.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.8571,
            "measured_on": "2026-08-19T09:24:39.167042+00:00",
            "card": "78ca73da4697e4733a3e1f67b10e34d78c3ee762dd2b9f9528325dfdac840b3c",
            "card_url": "/signed/cards/78ca73da4697e4733a3e1f67b10e34d78c3ee762dd2b9f9528325dfdac840b3c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.164344+00:00",
            "card": "91f79a794f610ab7bb41a8242e8a6b6f9059397c2eecae995e7802565d0c0e78",
            "card_url": "/signed/cards/91f79a794f610ab7bb41a8242e8a6b6f9059397c2eecae995e7802565d0c0e78.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.7273,
            "measured_on": "2026-08-19T09:24:39.157149+00:00",
            "card": "9ced28fec63b6e799bc45bb3e2e672ec5b8ba2bdb0b35920aae601651565ba0c",
            "card_url": "/signed/cards/9ced28fec63b6e799bc45bb3e2e672ec5b8ba2bdb0b35920aae601651565ba0c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.153913+00:00",
            "card": "a5e2dc5e86437a4e684b2ae47c88be847f5febee108930e888fbd7ec27d4c4ec",
            "card_url": "/signed/cards/a5e2dc5e86437a4e684b2ae47c88be847f5febee108930e888fbd7ec27d4c4ec.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.162938+00:00",
            "card": "ac05a5e119ca3c683acefbee3d290d8c0fce75c5af0be02048123838ad221504",
            "card_url": "/signed/cards/ac05a5e119ca3c683acefbee3d290d8c0fce75c5af0be02048123838ad221504.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.165011+00:00",
            "card": "b196283cc7b4c71dfaa5baf39c74fa71ebdebb6a4a5cd3296fc3536a5659c7bd",
            "card_url": "/signed/cards/b196283cc7b4c71dfaa5baf39c74fa71ebdebb6a4a5cd3296fc3536a5659c7bd.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.165278+00:00",
            "card": "b56ec64b9d0a824905a56cf7ef99b95c1ae4976d398859e0e8a271e37a6dca1d",
            "card_url": "/signed/cards/b56ec64b9d0a824905a56cf7ef99b95c1ae4976d398859e0e8a271e37a6dca1d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.7333,
            "measured_on": "2026-08-19T09:24:39.160907+00:00",
            "card": "ddd530215d04f5391ccf170da8178c105dd2244fca5cd5446553a6be1e50cf6e",
            "card_url": "/signed/cards/ddd530215d04f5391ccf170da8178c105dd2244fca5cd5446553a6be1e50cf6e.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.166688+00:00",
            "card": "f5812fb53e6fa84da94b316d86f99132ff78642515c9027f94232cabb6f65d0e",
            "card_url": "/signed/cards/f5812fb53e6fa84da94b316d86f99132ff78642515c9027f94232cabb6f65d0e.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.5333,
            "measured_on": "2026-08-19T09:24:39.164638+00:00",
            "card": "f60108cff1d81ff9d86653ae37d9f145fdb098847907fc5b4ad7bb6556e91286",
            "card_url": "/signed/cards/f60108cff1d81ff9d86653ae37d9f145fdb098847907fc5b4ad7bb6556e91286.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "accuracy": 0.75,
            "measured_on": "2026-08-19T09:24:39.167692+00:00",
            "card": "ffcac15c00fd9735d0f933d6560484b540852a026715d9cc33229764c2a6cb23",
            "card_url": "/signed/cards/ffcac15c00fd9735d0f933d6560484b540852a026715d9cc33229764c2a6cb23.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1655f3b2de29530964ed3cbdbab6dabf2dbd8eae86be7e7ca5d2a67bb4ddf585",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1c2e6364bb721cb14cfcf9cea9dc3e7bea7af968cc8c5c0f17f1d24ec01623e6",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "35a4eb2b69dfe03fad8aa082a6ab0845f506d03218ea3c1bece93337cb427bca",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "3eaa0c2779e78cd8948d7c00bd1ff2bd4cf7958a58f80ca8a3d13d4b2305e813",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "46305c10be50fad864218157b248d7976cfaaca788d8f5a0b01d57b74dacec62",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "56209f8a717a2fe36cfe6dee2a7ee021ae633c551231d029f22416eec9a5ba89",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "612d1f5ba92962e414c76271c0a271e9d2eb5d69204360ae62cee7f4792d1404",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "6171fc15c50ad03aef84309ffe505ba38d43f7f56232af48796d184bbfc5566c",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "62123d93724144cdfec5497af3984fa22d8ce749a4f2d0710b774c6614d8ed72",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "70676b498f9419d9e0b393f4a064860115962be05fbb88d6b02cb3136a854061",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "78ca73da4697e4733a3e1f67b10e34d78c3ee762dd2b9f9528325dfdac840b3c",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "91f79a794f610ab7bb41a8242e8a6b6f9059397c2eecae995e7802565d0c0e78",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9ced28fec63b6e799bc45bb3e2e672ec5b8ba2bdb0b35920aae601651565ba0c",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a5e2dc5e86437a4e684b2ae47c88be847f5febee108930e888fbd7ec27d4c4ec",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ac05a5e119ca3c683acefbee3d290d8c0fce75c5af0be02048123838ad221504",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "b196283cc7b4c71dfaa5baf39c74fa71ebdebb6a4a5cd3296fc3536a5659c7bd",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "b56ec64b9d0a824905a56cf7ef99b95c1ae4976d398859e0e8a271e37a6dca1d",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ddd530215d04f5391ccf170da8178c105dd2244fca5cd5446553a6be1e50cf6e",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "f5812fb53e6fa84da94b316d86f99132ff78642515c9027f94232cabb6f65d0e",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "f60108cff1d81ff9d86653ae37d9f145fdb098847907fc5b4ad7bb6556e91286",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ffcac15c00fd9735d0f933d6560484b540852a026715d9cc33229764c2a6cb23",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-provenance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 50 — transparency & marking of AI-generated content",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function (context & provenance)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "gspc-provenance",
        "match": "PREFIXED_EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 50 — transparency & marking of AI-generated content",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "MAP core function (context & provenance)",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:continuity",
      "ordinal": 4,
      "axis": "continuity",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "PQCBench",
        "task": "post-quantum status of a cryptographic assumption",
        "n": 33,
        "separation": "UNTESTED",
        "fleet_mean": 0.45,
        "mean_harm": 0.55,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-asi",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-asi",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.163882+00:00",
            "card": "149ae1cc5beced568497a1738f61a521b95ee4ff4ccc6df9c65477ae62b56cf5",
            "card_url": "/signed/cards/149ae1cc5beced568497a1738f61a521b95ee4ff4ccc6df9c65477ae62b56cf5.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.2308,
            "measured_on": "2026-08-19T09:24:39.157347+00:00",
            "card": "1e772582aba999cada11df195acde19fc604113b2a0fe85b4b9f7d66a4ef95e3",
            "card_url": "/signed/cards/1e772582aba999cada11df195acde19fc604113b2a0fe85b4b9f7d66a4ef95e3.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.159933+00:00",
            "card": "279d602347f2eeef6cfafc36488a329ea991ec2973c312d82dcb037d182e480c",
            "card_url": "/signed/cards/279d602347f2eeef6cfafc36488a329ea991ec2973c312d82dcb037d182e480c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.166351+00:00",
            "card": "3b594bdbcd997fba1ec0ce0136514ad42880cb1233e775d2c4aad33d5d1fa937",
            "card_url": "/signed/cards/3b594bdbcd997fba1ec0ce0136514ad42880cb1233e775d2c4aad33d5d1fa937.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.161106+00:00",
            "card": "435d9c5df4697efb4b39305473cb1289f517f5d2be8cc35953897c4ab1a7fa68",
            "card_url": "/signed/cards/435d9c5df4697efb4b39305473cb1289f517f5d2be8cc35953897c4ab1a7fa68.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3846,
            "measured_on": "2026-08-19T09:24:39.164869+00:00",
            "card": "4a5e6043f41a0bde44c1a745cfe8661b12788c658a3545df524052359fa66487",
            "card_url": "/signed/cards/4a5e6043f41a0bde44c1a745cfe8661b12788c658a3545df524052359fa66487.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3846,
            "measured_on": "2026-08-19T09:24:39.154375+00:00",
            "card": "4cf1745607b0759f5c419c3b04e83104b0dbdf23824b45c8359d67f9e7a58747",
            "card_url": "/signed/cards/4cf1745607b0759f5c419c3b04e83104b0dbdf23824b45c8359d67f9e7a58747.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.166107+00:00",
            "card": "568134d2d71478fbb699760c1bc0f4cf47920caf823e320e26b7df0a16666d6f",
            "card_url": "/signed/cards/568134d2d71478fbb699760c1bc0f4cf47920caf823e320e26b7df0a16666d6f.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.153583+00:00",
            "card": "58bd1deacf1422a805816242176ae63e688307ee767cc384e44a96fac114a5f1",
            "card_url": "/signed/cards/58bd1deacf1422a805816242176ae63e688307ee767cc384e44a96fac114a5f1.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.165124+00:00",
            "card": "5c8f891f94bb144845d8bec87dd689ef1c1c284d58602765646e0e21e5226188",
            "card_url": "/signed/cards/5c8f891f94bb144845d8bec87dd689ef1c1c284d58602765646e0e21e5226188.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.165846+00:00",
            "card": "65266d2ea832a3d8c7a24dbed84d66e023bc1197d6cb1e0481feebe367ff8cb1",
            "card_url": "/signed/cards/65266d2ea832a3d8c7a24dbed84d66e023bc1197d6cb1e0481feebe367ff8cb1.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.167473+00:00",
            "card": "6b8b417eb80ea0c731f720360e3d12e08ca1e0a4f88bff0ce3b549da2cc30e6b",
            "card_url": "/signed/cards/6b8b417eb80ea0c731f720360e3d12e08ca1e0a4f88bff0ce3b549da2cc30e6b.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3846,
            "measured_on": "2026-08-19T09:24:39.167155+00:00",
            "card": "7703e66781360bea814f3589f566e85fc45298a45d25b0376f3ccab827627e4a",
            "card_url": "/signed/cards/7703e66781360bea814f3589f566e85fc45298a45d25b0376f3ccab827627e4a.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3846,
            "measured_on": "2026-08-19T09:24:39.166579+00:00",
            "card": "7d46de050d42ffaf2cc639001f42d27a14dedb7bb8af29ca7b304166d32f789e",
            "card_url": "/signed/cards/7d46de050d42ffaf2cc639001f42d27a14dedb7bb8af29ca7b304166d32f789e.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.165458+00:00",
            "card": "868be20dfa33f6771277f14954dc5e52bf84dd5641ee921b836d505df2a90123",
            "card_url": "/signed/cards/868be20dfa33f6771277f14954dc5e52bf84dd5641ee921b836d505df2a90123.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.158528+00:00",
            "card": "9a45f78d418ac2f35cbbe5d5b9724cbecdf8b1de12b5660fe1dab1ff98f1aa8c",
            "card_url": "/signed/cards/9a45f78d418ac2f35cbbe5d5b9724cbecdf8b1de12b5660fe1dab1ff98f1aa8c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3846,
            "measured_on": "2026-08-19T09:24:39.164472+00:00",
            "card": "9b5ffb530f5e1cabbcde1041fc69e3d2e699fcb79ef848957d1a3f1d12e19636",
            "card_url": "/signed/cards/9b5ffb530f5e1cabbcde1041fc69e3d2e699fcb79ef848957d1a3f1d12e19636.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3077,
            "measured_on": "2026-08-19T09:24:39.163149+00:00",
            "card": "9c343315b278a562686e71c75758fde5c757293b7dcaf2e6bb197e9b14b8465a",
            "card_url": "/signed/cards/9c343315b278a562686e71c75758fde5c757293b7dcaf2e6bb197e9b14b8465a.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.163546+00:00",
            "card": "aa8abca221fa7fd8886d5f3800b5ffa70645af58c5cd30e147405ba7defd1f63",
            "card_url": "/signed/cards/aa8abca221fa7fd8886d5f3800b5ffa70645af58c5cd30e147405ba7defd1f63.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.3,
            "measured_on": "2026-08-19T09:24:39.167919+00:00",
            "card": "b77fde240e060ab02670c6b3bac7729da56c8f74d990a3ea4db04630b553d7b2",
            "card_url": "/signed/cards/b77fde240e060ab02670c6b3bac7729da56c8f74d990a3ea4db04630b553d7b2.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "accuracy": 0.2308,
            "measured_on": "2026-08-19T09:24:39.166830+00:00",
            "card": "d17478c0f0b45ab364fa8fa47e4ca601ee34b787b899875f6e4738c65c0f5566",
            "card_url": "/signed/cards/d17478c0f0b45ab364fa8fa47e4ca601ee34b787b899875f6e4738c65c0f5566.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "149ae1cc5beced568497a1738f61a521b95ee4ff4ccc6df9c65477ae62b56cf5",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1e772582aba999cada11df195acde19fc604113b2a0fe85b4b9f7d66a4ef95e3",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "279d602347f2eeef6cfafc36488a329ea991ec2973c312d82dcb037d182e480c",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "3b594bdbcd997fba1ec0ce0136514ad42880cb1233e775d2c4aad33d5d1fa937",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "435d9c5df4697efb4b39305473cb1289f517f5d2be8cc35953897c4ab1a7fa68",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4a5e6043f41a0bde44c1a745cfe8661b12788c658a3545df524052359fa66487",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4cf1745607b0759f5c419c3b04e83104b0dbdf23824b45c8359d67f9e7a58747",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "568134d2d71478fbb699760c1bc0f4cf47920caf823e320e26b7df0a16666d6f",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "58bd1deacf1422a805816242176ae63e688307ee767cc384e44a96fac114a5f1",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "5c8f891f94bb144845d8bec87dd689ef1c1c284d58602765646e0e21e5226188",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "65266d2ea832a3d8c7a24dbed84d66e023bc1197d6cb1e0481feebe367ff8cb1",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "6b8b417eb80ea0c731f720360e3d12e08ca1e0a4f88bff0ce3b549da2cc30e6b",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "7703e66781360bea814f3589f566e85fc45298a45d25b0376f3ccab827627e4a",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "7d46de050d42ffaf2cc639001f42d27a14dedb7bb8af29ca7b304166d32f789e",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "868be20dfa33f6771277f14954dc5e52bf84dd5641ee921b836d505df2a90123",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9a45f78d418ac2f35cbbe5d5b9724cbecdf8b1de12b5660fe1dab1ff98f1aa8c",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9b5ffb530f5e1cabbcde1041fc69e3d2e699fcb79ef848957d1a3f1d12e19636",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9c343315b278a562686e71c75758fde5c757293b7dcaf2e6bb197e9b14b8465a",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "aa8abca221fa7fd8886d5f3800b5ffa70645af58c5cd30e147405ba7defd1f63",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "b77fde240e060ab02670c6b3bac7729da56c8f74d990a3ea4db04630b553d7b2",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "d17478c0f0b45ab364fa8fa47e4ca601ee34b787b899875f6e4738c65c0f5566",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-continuity",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — accuracy, robustness & cybersecurity",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 55 — GPAI systemic-risk obligations",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "gspc-continuity",
        "match": "PREFIXED_EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 15 — accuracy, robustness & cybersecurity",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 55 — GPAI systemic-risk obligations",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "MANAGE core function",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI08 Cascading Failures",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:conformance",
      "ordinal": 5,
      "axis": "conformance",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "MCPBench",
        "task": "MCP tool conformance",
        "n": 35,
        "separation": "UNTESTED",
        "fleet_mean": 0.537,
        "mean_harm": 0.463,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-mcp",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-mcp",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.165756+00:00",
            "card": "0b316629e65c0a4bfa9b4c04d1bcfc5f113970d46c6c0afb3a8986b9b38d4666",
            "card_url": "/signed/cards/0b316629e65c0a4bfa9b4c04d1bcfc5f113970d46c6c0afb3a8986b9b38d4666.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.157208+00:00",
            "card": "0cf0371f83d27eac9ee0ac6fca38b1c37f7cbab53ff02636edea4a37a369d475",
            "card_url": "/signed/cards/0cf0371f83d27eac9ee0ac6fca38b1c37f7cbab53ff02636edea4a37a369d475.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.5,
            "measured_on": "2026-08-19T09:24:39.167771+00:00",
            "card": "29a5b81b898ea75a7740b3f6da822967f0e06671da03bb5a53b83e27883ba76d",
            "card_url": "/signed/cards/29a5b81b898ea75a7740b3f6da822967f0e06671da03bb5a53b83e27883ba76d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.2727,
            "measured_on": "2026-08-19T09:24:39.166507+00:00",
            "card": "2e60794c5664b950e3b7193883e6079dbed8e80c9da29ceec28cfe25633e2170",
            "card_url": "/signed/cards/2e60794c5664b950e3b7193883e6079dbed8e80c9da29ceec28cfe25633e2170.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.166724+00:00",
            "card": "312abd1af18322d209994a0cf806eab4200558ffaacc2b35370b3cc23e217b06",
            "card_url": "/signed/cards/312abd1af18322d209994a0cf806eab4200558ffaacc2b35370b3cc23e217b06.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.153505+00:00",
            "card": "32df7c2b25d7306e30efdfc25a6d2a1c17a951071e2567e19db475b86214b17d",
            "card_url": "/signed/cards/32df7c2b25d7306e30efdfc25a6d2a1c17a951071e2567e19db475b86214b17d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.162999+00:00",
            "card": "48cc8dfab382d38d23e1167bff2576c64cad76e324ada51734ab0e6edd56bb39",
            "card_url": "/signed/cards/48cc8dfab382d38d23e1167bff2576c64cad76e324ada51734ab0e6edd56bb39.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.166275+00:00",
            "card": "4a6a0f9850d5555e14865eb8270165f7cfb17a714bc0654d4916cd49fdf956a1",
            "card_url": "/signed/cards/4a6a0f9850d5555e14865eb8270165f7cfb17a714bc0654d4916cd49fdf956a1.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.165049+00:00",
            "card": "4bb360d00fa503592fd003729d74fcb825cb413b3ff70b4db9677fd3c6f088da",
            "card_url": "/signed/cards/4bb360d00fa503592fd003729d74fcb825cb413b3ff70b4db9677fd3c6f088da.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.164382+00:00",
            "card": "4d960dc2bacf3a4d6abe2cceb097e45d6ba75bc486114961b54c43679bf0c7c7",
            "card_url": "/signed/cards/4d960dc2bacf3a4d6abe2cceb097e45d6ba75bc486114961b54c43679bf0c7c7.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.3636,
            "measured_on": "2026-08-19T09:24:39.158390+00:00",
            "card": "519cc296e47057d8dd14bb2aa2b56024f2f1d69c9669f50e8922c8fa1e186c31",
            "card_url": "/signed/cards/519cc296e47057d8dd14bb2aa2b56024f2f1d69c9669f50e8922c8fa1e186c31.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.164741+00:00",
            "card": "52f557e05ed8b8f1491841b3693af7d7ed4433950daf30708cecd1fe7862e37e",
            "card_url": "/signed/cards/52f557e05ed8b8f1491841b3693af7d7ed4433950daf30708cecd1fe7862e37e.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.165377+00:00",
            "card": "a2fa10dd947029178a9ad18a035b3510f800d61d35845d77b5016f3d5890bb55",
            "card_url": "/signed/cards/a2fa10dd947029178a9ad18a035b3510f800d61d35845d77b5016f3d5890bb55.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.167080+00:00",
            "card": "a984cfb7eb14b6d8851bd9e69be6b86fccbcf9900877e1304dedff8f5a54579c",
            "card_url": "/signed/cards/a984cfb7eb14b6d8851bd9e69be6b86fccbcf9900877e1304dedff8f5a54579c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.6364,
            "measured_on": "2026-08-19T09:24:39.160984+00:00",
            "card": "b660602ba67010b2697e919e704e7e85c31859e92f2c8a9573279915b8a4fab7",
            "card_url": "/signed/cards/b660602ba67010b2697e919e704e7e85c31859e92f2c8a9573279915b8a4fab7.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.163429+00:00",
            "card": "be3a35cf9c55c032cbbdb29413295c08fb19b28d92ec44b6742f937c470e1878",
            "card_url": "/signed/cards/be3a35cf9c55c032cbbdb29413295c08fb19b28d92ec44b6742f937c470e1878.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.3636,
            "measured_on": "2026-08-19T09:24:39.153974+00:00",
            "card": "c9a2a68c809477f2e47e573d97de42713bf8d79176d045000fde92e25236257d",
            "card_url": "/signed/cards/c9a2a68c809477f2e47e573d97de42713bf8d79176d045000fde92e25236257d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.166033+00:00",
            "card": "cbe0139cecae3712cbc7bc68653856c1f28663ad9b319fe04f0da0134f890864",
            "card_url": "/signed/cards/cbe0139cecae3712cbc7bc68653856c1f28663ad9b319fe04f0da0134f890864.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.167399+00:00",
            "card": "ce0f47973e207eb1c15d162bca83df764f7a5beb8355c1754aa7124451d8bfe9",
            "card_url": "/signed/cards/ce0f47973e207eb1c15d162bca83df764f7a5beb8355c1754aa7124451d8bfe9.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.163735+00:00",
            "card": "dd09f682075fba0936c904bbbda9a448e575275934d4ec2e3dc54476f76cbcb5",
            "card_url": "/signed/cards/dd09f682075fba0936c904bbbda9a448e575275934d4ec2e3dc54476f76cbcb5.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "accuracy": 0.4545,
            "measured_on": "2026-08-19T09:24:39.159853+00:00",
            "card": "ea109e668ae5acbda9297f7fa335874bb5101ffd6a7bed51c9f24f9e116a7eb9",
            "card_url": "/signed/cards/ea109e668ae5acbda9297f7fa335874bb5101ffd6a7bed51c9f24f9e116a7eb9.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0b316629e65c0a4bfa9b4c04d1bcfc5f113970d46c6c0afb3a8986b9b38d4666",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0cf0371f83d27eac9ee0ac6fca38b1c37f7cbab53ff02636edea4a37a369d475",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "29a5b81b898ea75a7740b3f6da822967f0e06671da03bb5a53b83e27883ba76d",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "2e60794c5664b950e3b7193883e6079dbed8e80c9da29ceec28cfe25633e2170",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "312abd1af18322d209994a0cf806eab4200558ffaacc2b35370b3cc23e217b06",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "32df7c2b25d7306e30efdfc25a6d2a1c17a951071e2567e19db475b86214b17d",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "48cc8dfab382d38d23e1167bff2576c64cad76e324ada51734ab0e6edd56bb39",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4a6a0f9850d5555e14865eb8270165f7cfb17a714bc0654d4916cd49fdf956a1",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4bb360d00fa503592fd003729d74fcb825cb413b3ff70b4db9677fd3c6f088da",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4d960dc2bacf3a4d6abe2cceb097e45d6ba75bc486114961b54c43679bf0c7c7",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "519cc296e47057d8dd14bb2aa2b56024f2f1d69c9669f50e8922c8fa1e186c31",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "52f557e05ed8b8f1491841b3693af7d7ed4433950daf30708cecd1fe7862e37e",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a2fa10dd947029178a9ad18a035b3510f800d61d35845d77b5016f3d5890bb55",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a984cfb7eb14b6d8851bd9e69be6b86fccbcf9900877e1304dedff8f5a54579c",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "b660602ba67010b2697e919e704e7e85c31859e92f2c8a9573279915b8a4fab7",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "be3a35cf9c55c032cbbdb29413295c08fb19b28d92ec44b6742f937c470e1878",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c9a2a68c809477f2e47e573d97de42713bf8d79176d045000fde92e25236257d",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "cbe0139cecae3712cbc7bc68653856c1f28663ad9b319fe04f0da0134f890864",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ce0f47973e207eb1c15d162bca83df764f7a5beb8355c1754aa7124451d8bfe9",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "dd09f682075fba0936c904bbbda9a448e575275934d4ec2e3dc54476f76cbcb5",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ea109e668ae5acbda9297f7fa335874bb5101ffd6a7bed51c9f24f9e116a7eb9",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-conformance",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 11 + Annex IV — technical documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 13 — transparency & provision of information to deployers",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MAP core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI02 Tool Misuse & Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "gspc-conformance",
        "match": "PREFIXED_EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 11 + Annex IV — technical documentation",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 13 — transparency & provision of information to deployers",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "MAP core function",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI02 Tool Misuse & Exploitation",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:openness",
      "ordinal": 6,
      "axis": "openness",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "OSSBench",
        "task": "licence reasoning versus intended use",
        "n": 32,
        "separation": "UNTESTED",
        "fleet_mean": 0.696,
        "mean_harm": 0.304,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-oss",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-oss",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.165420+00:00",
            "card": "0bc6d06da274db2ee5095500638902b3cbea13457e1195afa4be0ed600ee5906",
            "card_url": "/signed/cards/0bc6d06da274db2ee5095500638902b3cbea13457e1195afa4be0ed600ee5906.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6154,
            "measured_on": "2026-08-19T09:24:39.165798+00:00",
            "card": "1fbfe12ad5a7f68145cdcc8a435112f6191ddda94a181a60914498c3ac7d912f",
            "card_url": "/signed/cards/1fbfe12ad5a7f68145cdcc8a435112f6191ddda94a181a60914498c3ac7d912f.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.166070+00:00",
            "card": "21ab0898a601ef785650b6a799a335544e7a11595951481839f49d354975430c",
            "card_url": "/signed/cards/21ab0898a601ef785650b6a799a335544e7a11595951481839f49d354975430c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.165087+00:00",
            "card": "29e71f0a6061e1272fe4540459162e29432991cac26d659d733cdcc674c2c0c8",
            "card_url": "/signed/cards/29e71f0a6061e1272fe4540459162e29432991cac26d659d733cdcc674c2c0c8.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.159893+00:00",
            "card": "2aba0727a9b6c79a4c0bbd19c8edd2a01230e8d7083f6bd389cebe84c6fd2a17",
            "card_url": "/signed/cards/2aba0727a9b6c79a4c0bbd19c8edd2a01230e8d7083f6bd389cebe84c6fd2a17.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6154,
            "measured_on": "2026-08-19T09:24:39.154073+00:00",
            "card": "2afb768b7835fd1be9e083da2621b4093a059a994c55b3cc934c9ec847f0f734",
            "card_url": "/signed/cards/2afb768b7835fd1be9e083da2621b4093a059a994c55b3cc934c9ec847f0f734.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.166762+00:00",
            "card": "351a77a636e76785bd3a4a895d6ffa50d50c320671116716f245dfccfb56e8ff",
            "card_url": "/signed/cards/351a77a636e76785bd3a4a895d6ffa50d50c320671116716f245dfccfb56e8ff.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.163496+00:00",
            "card": "3d02498e860d4ecf1fdf16373f95fdd5fd05b6e7833791ebce83668bab4256b3",
            "card_url": "/signed/cards/3d02498e860d4ecf1fdf16373f95fdd5fd05b6e7833791ebce83668bab4256b3.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.164432+00:00",
            "card": "42a7240ad8a1d0ae6658a9cde947e273a79f0c2462900269a5de8235522606c8",
            "card_url": "/signed/cards/42a7240ad8a1d0ae6658a9cde947e273a79f0c2462900269a5de8235522606c8.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.3846,
            "measured_on": "2026-08-19T09:24:39.167436+00:00",
            "card": "459f98159b09d3cd79c33a58157b02c467e990b4be514ba8bef3dd32598f3cb4",
            "card_url": "/signed/cards/459f98159b09d3cd79c33a58157b02c467e990b4be514ba8bef3dd32598f3cb4.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6923,
            "measured_on": "2026-08-19T09:24:39.157267+00:00",
            "card": "4b633b7ff828dd918bedfe42ab5a6beec69f3744cb56d795c173b962913dcefd",
            "card_url": "/signed/cards/4b633b7ff828dd918bedfe42ab5a6beec69f3744cb56d795c173b962913dcefd.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.164801+00:00",
            "card": "504ccbb22948bb498b971e9c7a1ae6649f72919ad5d85455856a288e53e8e8e0",
            "card_url": "/signed/cards/504ccbb22948bb498b971e9c7a1ae6649f72919ad5d85455856a288e53e8e8e0.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6923,
            "measured_on": "2026-08-19T09:24:39.163809+00:00",
            "card": "719e122506ffbc49184a2b5f1c67f75985749e90ead9cb96e9f991b8bf1e7410",
            "card_url": "/signed/cards/719e122506ffbc49184a2b5f1c67f75985749e90ead9cb96e9f991b8bf1e7410.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6154,
            "measured_on": "2026-08-19T09:24:39.153545+00:00",
            "card": "75c0f83d849121a8bf43306d10591cbba15465816e7364438af25a5d0401ac3d",
            "card_url": "/signed/cards/75c0f83d849121a8bf43306d10591cbba15465816e7364438af25a5d0401ac3d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6154,
            "measured_on": "2026-08-19T09:24:39.158450+00:00",
            "card": "851e263754518e692655902debb727d26c7a4e14b5fe6c6382a480b96f6b1a35",
            "card_url": "/signed/cards/851e263754518e692655902debb727d26c7a4e14b5fe6c6382a480b96f6b1a35.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.4615,
            "measured_on": "2026-08-19T09:24:39.163078+00:00",
            "card": "8fbf552908b905f6ec6fcc1c04e1b30cbcdd8ae5d9434acdd7cfff00b5337509",
            "card_url": "/signed/cards/8fbf552908b905f6ec6fcc1c04e1b30cbcdd8ae5d9434acdd7cfff00b5337509.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6154,
            "measured_on": "2026-08-19T09:24:39.161046+00:00",
            "card": "ab20a48716e67ebaf7351d35fa9f248e84596cd0612f82b08c9b06f0e0cec455",
            "card_url": "/signed/cards/ab20a48716e67ebaf7351d35fa9f248e84596cd0612f82b08c9b06f0e0cec455.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.166543+00:00",
            "card": "be8cbf4482a12408ca4000acede3ff7fadd6345b4a27a77e90e1465e76377d98",
            "card_url": "/signed/cards/be8cbf4482a12408ca4000acede3ff7fadd6345b4a27a77e90e1465e76377d98.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.167857+00:00",
            "card": "c1e04a76b3054661054a7a317c0ff5a3d1eabd9883a54856f299983d188e14b0",
            "card_url": "/signed/cards/c1e04a76b3054661054a7a317c0ff5a3d1eabd9883a54856f299983d188e14b0.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.6154,
            "measured_on": "2026-08-19T09:24:39.167118+00:00",
            "card": "ecab28b1d2d1d3d82192270906b9d8f45afc753612cddcf7757ed7b25414234b",
            "card_url": "/signed/cards/ecab28b1d2d1d3d82192270906b9d8f45afc753612cddcf7757ed7b25414234b.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "accuracy": 0.5385,
            "measured_on": "2026-08-19T09:24:39.166313+00:00",
            "card": "f398a1a2abf8efbd18c5a62344e39448accc785c61c9a7a8756a3d51a351d535",
            "card_url": "/signed/cards/f398a1a2abf8efbd18c5a62344e39448accc785c61c9a7a8756a3d51a351d535.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0bc6d06da274db2ee5095500638902b3cbea13457e1195afa4be0ed600ee5906",
            "subject": {
              "kind": "model",
              "id": "sov-phi:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1fbfe12ad5a7f68145cdcc8a435112f6191ddda94a181a60914498c3ac7d912f",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-balanced:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "21ab0898a601ef785650b6a799a335544e7a11595951481839f49d354975430c",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-combo:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "29e71f0a6061e1272fe4540459162e29432991cac26d659d733cdcc674c2c0c8",
            "subject": {
              "kind": "model",
              "id": "sov-mistral:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "2aba0727a9b6c79a4c0bbd19c8edd2a01230e8d7083f6bd389cebe84c6fd2a17",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "2afb768b7835fd1be9e083da2621b4093a059a994c55b3cc934c9ec847f0f734",
            "subject": {
              "kind": "model",
              "id": "clan-law-refusing:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "351a77a636e76785bd3a4a895d6ffa50d50c320671116716f245dfccfb56e8ff",
            "subject": {
              "kind": "model",
              "id": "withheld-name-1",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "3d02498e860d4ecf1fdf16373f95fdd5fd05b6e7833791ebce83668bab4256b3",
            "subject": {
              "kind": "model",
              "id": "sov-deepseek:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "42a7240ad8a1d0ae6658a9cde947e273a79f0c2462900269a5de8235522606c8",
            "subject": {
              "kind": "model",
              "id": "sov-ethics-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "459f98159b09d3cd79c33a58157b02c467e990b4be514ba8bef3dd32598f3cb4",
            "subject": {
              "kind": "model",
              "id": "withheld-name-3",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4b633b7ff828dd918bedfe42ab5a6beec69f3744cb56d795c173b962913dcefd",
            "subject": {
              "kind": "model",
              "id": "falcon3:7b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "504ccbb22948bb498b971e9c7a1ae6649f72919ad5d85455856a288e53e8e8e0",
            "subject": {
              "kind": "model",
              "id": "sov-gemma:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "719e122506ffbc49184a2b5f1c67f75985749e90ead9cb96e9f991b8bf1e7410",
            "subject": {
              "kind": "model",
              "id": "sov-draw-compliance:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "75c0f83d849121a8bf43306d10591cbba15465816e7364438af25a5d0401ac3d",
            "subject": {
              "kind": "model",
              "id": "clan-law-plain:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "851e263754518e692655902debb727d26c7a4e14b5fe6c6382a480b96f6b1a35",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "8fbf552908b905f6ec6fcc1c04e1b30cbcdd8ae5d9434acdd7cfff00b5337509",
            "subject": {
              "kind": "model",
              "id": "sov-compliance-art5:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ab20a48716e67ebaf7351d35fa9f248e84596cd0612f82b08c9b06f0e0cec455",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "be8cbf4482a12408ca4000acede3ff7fadd6345b4a27a77e90e1465e76377d98",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-v2:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c1e04a76b3054661054a7a317c0ff5a3d1eabd9883a54856f299983d188e14b0",
            "subject": {
              "kind": "model",
              "id": "withheld-name-4",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "ecab28b1d2d1d3d82192270906b9d8f45afc753612cddcf7757ed7b25414234b",
            "subject": {
              "kind": "model",
              "id": "withheld-name-2",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "f398a1a2abf8efbd18c5a62344e39448accc785c61c9a7a8756a3d51a351d535",
            "subject": {
              "kind": "model",
              "id": "sov-refusal-lora:latest",
              "digest": null
            },
            "source_axis": "gspc-openness",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 53 — GPAI provider transparency & documentation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN core function",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "gspc-openness",
        "match": "PREFIXED_EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 53 — GPAI provider transparency & documentation",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "GOVERN core function",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI04 Agentic Supply Chain Vulnerabilities",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:machinery-conformity",
      "ordinal": 7,
      "axis": "machinery-conformity",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "MachBench",
        "task": "Machinery Reg self-evolving safety-function classification (PART_A / OUT_OF_SCOPE / NOT_SAFETY_FUNCTION)",
        "n": 33,
        "separation": "UNTESTED",
        "fleet_mean": 0.349,
        "mean_harm": 0.651,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-mach",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-mach",
        "note": "No public leader: this axis is measured as a fleet aggregate against the frozen bank (see fleet_mean), but no signed per-model card is carried in this payload, so no leader or accuracy is asserted rather than invented — see /api/cards. The axis stays MEASURED (external models answered the same frozen bank); only the unverifiable per-model leader claim is removed, because the board's promise is that every named leader links to the Ed25519 card behind it and here no such card exists.",
        "public_leader_state": "NO_SIGNED_CARD"
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:care",
      "ordinal": 8,
      "axis": "care",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "CareBench",
        "task": "care-cost (protect × help) under paired conduct scenarios",
        "n": 199,
        "n_note": "200 bank records, one exact-duplicate pair → 199 unique scored texts (registry v2)",
        "separation": "UNTESTED",
        "fleet_mean": 0.293,
        "mean_harm": 0.707,
        "cvar05_harm": 0.9895,
        "dataset": "csoai/gspc-care",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-care",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-destruction-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.169328+00:00",
            "card": "0761402b746bd26c2652a9a45d6301bde91ddc1307a4517c29634800e6d80850",
            "card_url": "/signed/cards/0761402b746bd26c2652a9a45d6301bde91ddc1307a4517c29634800e6d80850.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-agency-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.168847+00:00",
            "card": "1e2e7c3f9c3758d99068bd99a5026964e7f01bb6dd94ed8e79d40d616b40475d",
            "card_url": "/signed/cards/1e2e7c3f9c3758d99068bd99a5026964e7f01bb6dd94ed8e79d40d616b40475d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-temporality-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.174167+00:00",
            "card": "2088a8238eee5fdd56c4fdf2b786708dc9d67058183beeee6d9f392bf087d282",
            "card_url": "/signed/cards/2088a8238eee5fdd56c4fdf2b786708dc9d67058183beeee6d9f392bf087d282.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-aesthetics-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.168624+00:00",
            "card": "20fe2b73ac55aaf49e6bdb7bf59378375802ecd0436d881c18142ab5f698f658",
            "card_url": "/signed/cards/20fe2b73ac55aaf49e6bdb7bf59378375802ecd0436d881c18142ab5f698f658.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "gemma3:12b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.157714+00:00",
            "card": "229ee794eb46e74edde2667e5a0b274f053fc08ba14f708dac1042e2c6cf87c0",
            "card_url": "/signed/cards/229ee794eb46e74edde2667e5a0b274f053fc08ba14f708dac1042e2c6cf87c0.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen3:4b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.162548+00:00",
            "card": "2ce5114442aa85d7d321a76d395ab89f8eebe0277a36af164efa5c985a92e0e8",
            "card_url": "/signed/cards/2ce5114442aa85d7d321a76d395ab89f8eebe0277a36af164efa5c985a92e0e8.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b-instruct",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.160202+00:00",
            "card": "45724650575f8f40363728b42c54c5683fffab59a10d65e2991b666ba4d4a813",
            "card_url": "/signed/cards/45724650575f8f40363728b42c54c5683fffab59a10d65e2991b666ba4d4a813.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "mistral:7b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.159037+00:00",
            "card": "49196caeba7592579c2ace80a854f14ff8c10d762813fa8834f6e7a4bed84e5d",
            "card_url": "/signed/cards/49196caeba7592579c2ace80a854f14ff8c10d762813fa8834f6e7a4bed84e5d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-preservation-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.173081+00:00",
            "card": "4cfbc0f290f3029064664811260b07ffabee67087cf7e50e6e75c59f88599776",
            "card_url": "/signed/cards/4cfbc0f290f3029064664811260b07ffabee67087cf7e50e6e75c59f88599776.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-ethics-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.170039+00:00",
            "card": "5d7baf6bb095f3014cbdbe658b97451f17f6acde23d562b3649db82e22d3b5c7",
            "card_url": "/signed/cards/5d7baf6bb095f3014cbdbe658b97451f17f6acde23d562b3649db82e22d3b5c7.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "phi4:14b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.159503+00:00",
            "card": "8af24e9e1c07918c46b6911c19320b87058be9453a4bcf598599c80a85668211",
            "card_url": "/signed/cards/8af24e9e1c07918c46b6911c19320b87058be9453a4bcf598599c80a85668211.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-identity-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.172265+00:00",
            "card": "907088a3e6bd3445cbea66e53d75aba05e1bc940dba71935e0909a963597a552",
            "card_url": "/signed/cards/907088a3e6bd3445cbea66e53d75aba05e1bc940dba71935e0909a963597a552.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-relationality-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.173442+00:00",
            "card": "97407fb8c436b8385fd28c8f7bc263608807b55d59ae39631ca9d3c127d4c42e",
            "card_url": "/signed/cards/97407fb8c436b8385fd28c8f7bc263608807b55d59ae39631ca9d3c127d4c42e.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-creation-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.169101+00:00",
            "card": "9ca8f2174f8eb1c44cf2f6289f0111df45f48d9b5238a4bddeae3342c23ac630",
            "card_url": "/signed/cards/9ca8f2174f8eb1c44cf2f6289f0111df45f48d9b5238a4bddeae3342c23ac630.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.158085+00:00",
            "card": "a0dc1db7ba9c75e52253f4c9c62f7adf1fa71d6fcc5aa511ae17a6eff799faf8",
            "card_url": "/signed/cards/a0dc1db7ba9c75e52253f4c9c62f7adf1fa71d6fcc5aa511ae17a6eff799faf8.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-logic-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.172682+00:00",
            "card": "a2b217ca5141dd531038a8652562204065537bd34c4f6dcc4689cfd847bae5e7",
            "card_url": "/signed/cards/a2b217ca5141dd531038a8652562204065537bd34c4f6dcc4689cfd847bae5e7.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:3b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.161576+00:00",
            "card": "a38316158f8c59380275313e1769feb749199756e1a67013bfb647f68328d4c2",
            "card_url": "/signed/cards/a38316158f8c59380275313e1769feb749199756e1a67013bfb647f68328d4c2.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-abstraction-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.168254+00:00",
            "card": "b2fc10cb6134c37a618ab5d08d026db3a00444779d6f4969e766bdf2384541a7",
            "card_url": "/signed/cards/b2fc10cb6134c37a618ab5d08d026db3a00444779d6f4969e766bdf2384541a7.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:7b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.161943+00:00",
            "card": "c0155cbd1fd1786c3e95d87b7d6575cc9502bb287eac002b169fc8cd95b30529",
            "card_url": "/signed/cards/c0155cbd1fd1786c3e95d87b7d6575cc9502bb287eac002b169fc8cd95b30529.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-synthesis-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.173813+00:00",
            "card": "c0ea986c6354fbb3f5f223abd7e9eea91ad173030dc00d7a43ee4490c4ce1749",
            "card_url": "/signed/cards/c0ea986c6354fbb3f5f223abd7e9eea91ad173030dc00d7a43ee4490c4ce1749.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "sov6-embodiment-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.169548+00:00",
            "card": "cf6372c07c984a2fbd0614c13a1fa0c35e0d457fa192c75313b126e990460f46",
            "card_url": "/signed/cards/cf6372c07c984a2fbd0614c13a1fa0c35e0d457fa192c75313b126e990460f46.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.160672+00:00",
            "card": "e547de8885ad0f4da53dac6257e3c7c9e89ee18013b1f04ed9582861abee5dc3",
            "card_url": "/signed/cards/e547de8885ad0f4da53dac6257e3c7c9e89ee18013b1f04ed9582861abee5dc3.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "deepseek-r1:8b",
              "digest": null
            },
            "source_axis": "care",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.156757+00:00",
            "card": "e5b5ec5f0d5b7f4d772276d11197f9cd22b339f287bc0bc61ea784749bd8100f",
            "card_url": "/signed/cards/e5b5ec5f0d5b7f4d772276d11197f9cd22b339f287bc0bc61ea784749bd8100f.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0761402b746bd26c2652a9a45d6301bde91ddc1307a4517c29634800e6d80850",
            "subject": {
              "kind": "model",
              "id": "sov6-destruction-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "1e2e7c3f9c3758d99068bd99a5026964e7f01bb6dd94ed8e79d40d616b40475d",
            "subject": {
              "kind": "model",
              "id": "sov6-agency-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "2088a8238eee5fdd56c4fdf2b786708dc9d67058183beeee6d9f392bf087d282",
            "subject": {
              "kind": "model",
              "id": "sov6-temporality-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "20fe2b73ac55aaf49e6bdb7bf59378375802ecd0436d881c18142ab5f698f658",
            "subject": {
              "kind": "model",
              "id": "sov6-aesthetics-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "229ee794eb46e74edde2667e5a0b274f053fc08ba14f708dac1042e2c6cf87c0",
            "subject": {
              "kind": "model",
              "id": "gemma3:12b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "2ce5114442aa85d7d321a76d395ab89f8eebe0277a36af164efa5c985a92e0e8",
            "subject": {
              "kind": "model",
              "id": "qwen3:4b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "45724650575f8f40363728b42c54c5683fffab59a10d65e2991b666ba4d4a813",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b-instruct",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "49196caeba7592579c2ace80a854f14ff8c10d762813fa8834f6e7a4bed84e5d",
            "subject": {
              "kind": "model",
              "id": "mistral:7b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4cfbc0f290f3029064664811260b07ffabee67087cf7e50e6e75c59f88599776",
            "subject": {
              "kind": "model",
              "id": "sov6-preservation-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "5d7baf6bb095f3014cbdbe658b97451f17f6acde23d562b3649db82e22d3b5c7",
            "subject": {
              "kind": "model",
              "id": "sov6-ethics-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "8af24e9e1c07918c46b6911c19320b87058be9453a4bcf598599c80a85668211",
            "subject": {
              "kind": "model",
              "id": "phi4:14b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "907088a3e6bd3445cbea66e53d75aba05e1bc940dba71935e0909a963597a552",
            "subject": {
              "kind": "model",
              "id": "sov6-identity-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "97407fb8c436b8385fd28c8f7bc263608807b55d59ae39631ca9d3c127d4c42e",
            "subject": {
              "kind": "model",
              "id": "sov6-relationality-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "9ca8f2174f8eb1c44cf2f6289f0111df45f48d9b5238a4bddeae3342c23ac630",
            "subject": {
              "kind": "model",
              "id": "sov6-creation-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a0dc1db7ba9c75e52253f4c9c62f7adf1fa71d6fcc5aa511ae17a6eff799faf8",
            "subject": {
              "kind": "model",
              "id": "llama3.2:3b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a2b217ca5141dd531038a8652562204065537bd34c4f6dcc4689cfd847bae5e7",
            "subject": {
              "kind": "model",
              "id": "sov6-logic-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "a38316158f8c59380275313e1769feb749199756e1a67013bfb647f68328d4c2",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:3b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "b2fc10cb6134c37a618ab5d08d026db3a00444779d6f4969e766bdf2384541a7",
            "subject": {
              "kind": "model",
              "id": "sov6-abstraction-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c0155cbd1fd1786c3e95d87b7d6575cc9502bb287eac002b169fc8cd95b30529",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:7b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c0ea986c6354fbb3f5f223abd7e9eea91ad173030dc00d7a43ee4490c4ce1749",
            "subject": {
              "kind": "model",
              "id": "sov6-synthesis-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "cf6372c07c984a2fbd0614c13a1fa0c35e0d457fa192c75313b126e990460f46",
            "subject": {
              "kind": "model",
              "id": "sov6-embodiment-v3-light:latest",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "e547de8885ad0f4da53dac6257e3c7c9e89ee18013b1f04ed9582861abee5dc3",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "e5b5ec5f0d5b7f4d772276d11197f9cd22b339f287bc0bc61ea784749bd8100f",
            "subject": {
              "kind": "model",
              "id": "deepseek-r1:8b",
              "digest": null
            },
            "source_axis": "care",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MEASURE core function (harmful outputs)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI09 Human-Agent Trust Exploitation",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "care",
        "match": "EXACT",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 5(1)(b) — exploitation of vulnerabilities of persons",
            "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
            "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
            "tier": "prohibited_practices",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "MEASURE core function (harmful outputs)",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI09 Human-Agent Trust Exploitation",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:cross-reality",
      "ordinal": 9,
      "axis": "cross-reality",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "XRAIV",
        "task": "autonomous agent action authority (PROCEED / CONFIRM / REFUSE)",
        "n": 32,
        "separation": "UNTESTED",
        "fleet_mean": 0.441,
        "mean_harm": 0.559,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-xr",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-xr",
        "note": "No public leader: this axis is measured as a fleet aggregate against the frozen bank (see fleet_mean), but no signed per-model card is carried in this payload, so no leader or accuracy is asserted rather than invented — see /api/cards. The axis stays MEASURED (external models answered the same frozen bank); only the unverifiable per-model leader claim is removed, because the board's promise is that every named leader links to the Ed25519 card behind it and here no such card exists.",
        "public_leader_state": "NO_SIGNED_CARD"
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:detector-interop",
      "ordinal": 10,
      "axis": "detector-interop",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "DetBench",
        "task": "cross-detector watermark interoperability matrix",
        "n": 33,
        "separation": "UNTESTED",
        "fleet_mean": 0.563,
        "mean_harm": 0.437,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-det",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-det",
        "note": "No public leader: this axis is measured as a fleet aggregate against the frozen bank (see fleet_mean), but no signed per-model card is carried in this payload, so no leader or accuracy is asserted rather than invented — see /api/cards. The axis stays MEASURED (external models answered the same frozen bank); only the unverifiable per-model leader claim is removed, because the board's promise is that every named leader links to the Ed25519 card behind it and here no such card exists.",
        "public_leader_state": "NO_SIGNED_CARD"
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:art5-safeguard",
      "ordinal": 11,
      "axis": "art5-safeguard",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "Art5Bench",
        "task": "EU AI Act Article 5 prohibited-practice trip",
        "n": 36,
        "separation": "UNTESTED",
        "fleet_mean": 0.83,
        "mean_harm": 0.17,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-art5",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-art5",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:swarm",
      "ordinal": 12,
      "axis": "swarm",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "SwarmBench v2b",
        "task": "multi-agent coordination safety",
        "n": 37,
        "n_note": "wave-2b bank: 37 independent items × 5-model fleet, n≥36 graded per cell. Replaces the PROTOCOL bank (40 non-independent instances, interval withheld by our own effective-n rule) — the withholding retired because this bank earns its interval, not because the rule changed",
        "accuracy": 0.384,
        "accuracy_is": "95% Wilson LOWER BOUND — a conservative floor, not the point estimate. The point estimate lives in the signed wave-2b board (pod commit e440591); the bound is quoted here because it is the number that resolves the ordering",
        "leader": "qwen2.5:7b (base model)",
        "separation": "SEPARATED",
        "separation_basis": "95% Wilson non-overlap: leader lower bound 0.384 clears runner-up (mistral:7b) upper bound 0.372. Bound non-overlap on independent items is stricter than p<0.05; the paired McNemar on the signed board rows follows when the pod re-signs. The top three models remain statistically tied among themselves — the ordering is resolved at the leader boundary only.",
        "dataset": "csoai/gspc-swarm",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-swarm",
        "note": "UNGATED by owner ruling 2026-08-19: the first CI-resolved ordering on this axis. The old PROTOCOL bank stays in the record as the honesty-clause gold template (CIs that looked disjoint, paired p=1.0 — why McNemar-primary exists). Jail (slot 14) separation was determined 2026-08-25 (TIE). For the live board count, cite totals.public_count from GET /api/gspc."
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "mistral:7b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0.1481,
            "measured_on": "2026-08-19T09:24:39.159139+00:00",
            "card": "31bcd0b2f21af1fb22cd4d74aeb392870bd068b0b507eb59dd366ae4d1504c5d",
            "card_url": "/signed/cards/31bcd0b2f21af1fb22cd4d74aeb392870bd068b0b507eb59dd366ae4d1504c5d.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "council-safe:latest",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.156345+00:00",
            "card": "4eb8ffdb407800ec5ff64bfdd8c5e3359ae06c2381190edb52bd543ab8c540c9",
            "card_url": "/signed/cards/4eb8ffdb407800ec5ff64bfdd8c5e3359ae06c2381190edb52bd543ab8c540c9.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0.4,
            "measured_on": "2026-08-19T09:24:39.161168+00:00",
            "card": "688a30e266f0a1ae007e0ff1e23915e283ed6e10eed25a8f54db2b5bc25cb71e",
            "card_url": "/signed/cards/688a30e266f0a1ae007e0ff1e23915e283ed6e10eed25a8f54db2b5bc25cb71e.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "council-oowm:latest",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0,
            "measured_on": "2026-08-19T09:24:39.156127+00:00",
            "card": "8591fdc18b6b7cbd0513c3306d59bc6624f4e93bcafe2ce4326691a2a79ad891",
            "card_url": "/signed/cards/8591fdc18b6b7cbd0513c3306d59bc6624f4e93bcafe2ce4326691a2a79ad891.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:7b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0.4444,
            "measured_on": "2026-08-19T09:24:39.162060+00:00",
            "card": "b44335819f7720966b41e2ee26f5798892b0eb8d2571c71e0c9090506f1ff823",
            "card_url": "/signed/cards/b44335819f7720966b41e2ee26f5798892b0eb8d2571c71e0c9090506f1ff823.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b-instruct",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0.148,
            "measured_on": "2026-08-19T09:24:39.160276+00:00",
            "card": "eb9c45816edd670bc3aafeff001f983b1d503ccd0cec432ba19b3bbe936ace36",
            "card_url": "/signed/cards/eb9c45816edd670bc3aafeff001f983b1d503ccd0cec432ba19b3bbe936ace36.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen3:4b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "accuracy": 0.407,
            "measured_on": "2026-08-19T09:24:39.162677+00:00",
            "card": "f48e88bb336b76588334c694b1331b2e4de122e528baf6f00b8ebf65867a7fbf",
            "card_url": "/signed/cards/f48e88bb336b76588334c694b1331b2e4de122e528baf6f00b8ebf65867a7fbf.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "31bcd0b2f21af1fb22cd4d74aeb392870bd068b0b507eb59dd366ae4d1504c5d",
            "subject": {
              "kind": "model",
              "id": "mistral:7b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4eb8ffdb407800ec5ff64bfdd8c5e3359ae06c2381190edb52bd543ab8c540c9",
            "subject": {
              "kind": "model",
              "id": "council-safe:latest",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "688a30e266f0a1ae007e0ff1e23915e283ed6e10eed25a8f54db2b5bc25cb71e",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "8591fdc18b6b7cbd0513c3306d59bc6624f4e93bcafe2ce4326691a2a79ad891",
            "subject": {
              "kind": "model",
              "id": "council-oowm:latest",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "b44335819f7720966b41e2ee26f5798892b0eb8d2571c71e0c9090506f1ff823",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:7b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "eb9c45816edd670bc3aafeff001f983b1d503ccd0cec432ba19b3bbe936ace36",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b-instruct",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "f48e88bb336b76588334c694b1331b2e4de122e528baf6f00b8ebf65867a7fbf",
            "subject": {
              "kind": "model",
              "id": "qwen3:4b",
              "digest": null
            },
            "source_axis": "swarm-candidates",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 14 — human oversight",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "GOVERN + MAP core functions",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "swarm-candidates",
        "match": "DECLARED_ALIAS",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 14 — human oversight",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "GOVERN + MAP core functions",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI07 Insecure Inter-Agent Communication + ASI08 Cascading Failures",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:affect",
      "ordinal": 13,
      "axis": "affect",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "AffectBench",
        "task": "emotional & embodied safety (manipulation / disclosure / vulnerability)",
        "n": 41,
        "separation": "UNTESTED",
        "fleet_mean": 0.605,
        "mean_harm": 0.782,
        "cvar05_harm": null,
        "dataset": "csoai/gspc-affect",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-affect",
        "note": "No public leader: our own council specialist held the point lead and a neutral measurement body does not rank its own models against the vendors it measures. The axis is measured — external models answered the same frozen bank (see fleet_mean) — but the external re-ranking is not carried here, so no external leader or accuracy is asserted rather than invented.",
        "public_leader_state": "EXCLUDED_OWN_MODEL"
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:jail",
      "ordinal": 14,
      "axis": "jail",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "gspc",
        "kind": "model-comparison",
        "bench": "GoldBank-Detector",
        "task": "escape-attempt detection on 71-cell gold bank (38 ESCAPE / 33 BENIGN) — layer 2 of 2",
        "n": 71,
        "n_note": "7 models × 71 gold items; TP/FP/TN/FN per model; accuracy shown is the best zero-false-positive detector's (qwen2.5:0.5b-instruct, (tp+tn)/71)",
        "accuracy": 0.5915,
        "leader": "qwen2.5:0.5b-instruct (base model)",
        "separation": "TIE",
        "interval": [
          0.475,
          0.698
        ],
        "fleet_mean": 0.5455,
        "fleet": "7 models (4 base + 2 council fine-tunes + 1 base variant) — NOT the 19-model board fleet",
        "dataset": "csoai/gspc-jail-goldbank",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-jail-goldbank",
        "note": "The jail floor is no longer empty: measured 2026-08-17/18 on a 71-cell gold bank, separation determined 2026-08-25 (TIE). Best zero-FP detector: qwen2.5:0.5b-instruct (precision 1.0, recall 0.237). Fleet mean accuracy 0.5455 (7 models, usable n 68-71). Our own council-inhouse-ft fine-tune detected ZERO escapes (tp=0) — published, not hidden. Recall is the honest weakness: the best detector still misses 76% of escapes."
      },
      "evidence": {
        "published_state": "PUBLISHED_VERIFIED",
        "independently_admitted": false,
        "published_measurements": [
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen3:4b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.4648,
            "measured_on": "2026-08-19T09:24:39.162739+00:00",
            "card": "0f3255b855d40813456bf6a73a430a2fd9132dfb0192c3dc6310d81943e23e39",
            "card_url": "/signed/cards/0f3255b855d40813456bf6a73a430a2fd9132dfb0192c3dc6310d81943e23e39.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:7b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.5493,
            "measured_on": "2026-08-19T09:24:39.162120+00:00",
            "card": "3cc7a3caa1a9cb2f04efe93d8ab966ed8ab648309743d0466dbf60ceb709aa23",
            "card_url": "/signed/cards/3cc7a3caa1a9cb2f04efe93d8ab966ed8ab648309743d0466dbf60ceb709aa23.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "muse-glimmer:latest",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.4648,
            "measured_on": "2026-08-19T09:24:39.159220+00:00",
            "card": "4297a8b47e3c4a9b4644a2d90dadc7bc36ed92d3380e9c0c68eb95bd7af4890c",
            "card_url": "/signed/cards/4297a8b47e3c4a9b4644a2d90dadc7bc36ed92d3380e9c0c68eb95bd7af4890c.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.5634,
            "measured_on": "2026-08-19T09:24:39.161227+00:00",
            "card": "522a12e784470ccc91b778317a796781660688e5e325c82187894c03dd4ea9af",
            "card_url": "/signed/cards/522a12e784470ccc91b778317a796781660688e5e325c82187894c03dd4ea9af.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "council-oowm:latest",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.4648,
            "measured_on": "2026-08-19T09:24:39.156203+00:00",
            "card": "acec0ee7b86c1385e0455660ea1f2f23bfccc904a1b68308263a5e2eb982fa57",
            "card_url": "/signed/cards/acec0ee7b86c1385e0455660ea1f2f23bfccc904a1b68308263a5e2eb982fa57.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "mistral:7b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.5211,
            "measured_on": "2026-08-19T09:24:39.159179+00:00",
            "card": "c42bda59a7df7627956f385401f5f94c8e71046c6eee11a1d9573d478f7d0a37",
            "card_url": "/signed/cards/c42bda59a7df7627956f385401f5f94c8e71046c6eee11a1d9573d478f7d0a37.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "council-safe:latest",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.4789,
            "measured_on": "2026-08-19T09:24:39.156415+00:00",
            "card": "cff1aaf070acb97c224177809856bc20310f4958eb44bdffab7d4b04836535f4",
            "card_url": "/signed/cards/cff1aaf070acb97c224177809856bc20310f4958eb44bdffab7d4b04836535f4.json",
            "signature_verified": true,
            "independently_admitted": false
          },
          {
            "classification": "VERIFIED_PUBLISHED_EVIDENCE",
            "state": "PUBLISHED_VERIFIED",
            "source": "/signed/findings_index.json",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b-instruct",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "accuracy": 0.5352,
            "measured_on": "2026-08-19T09:24:39.160314+00:00",
            "card": "d353007a873ad527cb39e99ef2ac8a77e0fe917f1affe124b0aa379c51c427e0",
            "card_url": "/signed/cards/d353007a873ad527cb39e99ef2ac8a77e0fe917f1affe124b0aa379c51c427e0.json",
            "signature_verified": true,
            "independently_admitted": false
          }
        ],
        "candidate_state": "CANDIDATE_FINDING",
        "candidate_findings": [
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "0f3255b855d40813456bf6a73a430a2fd9132dfb0192c3dc6310d81943e23e39",
            "subject": {
              "kind": "model",
              "id": "qwen3:4b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "3cc7a3caa1a9cb2f04efe93d8ab966ed8ab648309743d0466dbf60ceb709aa23",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:7b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "4297a8b47e3c4a9b4644a2d90dadc7bc36ed92d3380e9c0c68eb95bd7af4890c",
            "subject": {
              "kind": "model",
              "id": "muse-glimmer:latest",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "522a12e784470ccc91b778317a796781660688e5e325c82187894c03dd4ea9af",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:1.5b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "acec0ee7b86c1385e0455660ea1f2f23bfccc904a1b68308263a5e2eb982fa57",
            "subject": {
              "kind": "model",
              "id": "council-oowm:latest",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "c42bda59a7df7627956f385401f5f94c8e71046c6eee11a1d9573d478f7d0a37",
            "subject": {
              "kind": "model",
              "id": "mistral:7b",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "cff1aaf070acb97c224177809856bc20310f4958eb44bdffab7d4b04836535f4",
            "subject": {
              "kind": "model",
              "id": "council-safe:latest",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          },
          {
            "classification": "CANDIDATE_FINDING",
            "state": "CANDIDATE_FINDING",
            "source": "/signed/findings_index.json",
            "derived_from_verified_card": "d353007a873ad527cb39e99ef2ac8a77e0fe917f1affe124b0aa379c51c427e0",
            "subject": {
              "kind": "model",
              "id": "qwen2.5:0.5b-instruct",
              "digest": null
            },
            "source_axis": "jail-escape-detection",
            "regulation_pointers": [
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 15 — robustness & cybersecurity against manipulation",
                "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
                "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
                "tier": "most_obligations_incl_art50_and_gpai",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "eu-ai-act",
                "regulator_name": "EU AI Act",
                "relation": "relevant-to",
                "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
                "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
                "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
                "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
                "tier": "prohibited_practices",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "nist-ai-rmf",
                "regulator_name": "NIST AI RMF 1.0",
                "relation": "relevant-to",
                "obligation": "MANAGE core function (incident & abuse)",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              },
              {
                "regulator": "owasp-asi",
                "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
                "relation": "relevant-to",
                "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
                "statutory_maximum": null,
                "fine_cited_to": null,
                "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
                "tier": "no_fine",
                "no_fine_asserted_owed": true
              }
            ],
            "legal_review_required": true,
            "writes_board": false,
            "note": "Relevant-to pointers only; not a compliance, breach, safety, approval, or fine determination."
          }
        ]
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "CROSSWALK_POINTERS",
        "source": "/signed/findings_index.json",
        "source_axis": "jail-escape-detection",
        "match": "DECLARED_ALIAS",
        "pointers": [
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 15 — robustness & cybersecurity against manipulation",
            "statutory_maximum": "up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(4)",
            "fine_applies_to": "non-compliance with obligations other than Art 5 (incl. high-risk duties, Art 50 transparency, GPAI provider obligations)",
            "tier": "most_obligations_incl_art50_and_gpai",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "eu-ai-act",
            "regulator_name": "EU AI Act",
            "relation": "relevant-to",
            "obligation": "Article 5 — circumvention of prohibited-practice safeguards",
            "statutory_maximum": "up to €35,000,000 or 7% of worldwide annual turnover, whichever is higher",
            "fine_cited_to": "EU AI Act (Reg (EU) 2024/1689) Art 99(3)",
            "fine_applies_to": "infringement of the Article 5 prohibited-practices ban",
            "tier": "prohibited_practices",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "nist-ai-rmf",
            "regulator_name": "NIST AI RMF 1.0",
            "relation": "relevant-to",
            "obligation": "MANAGE core function (incident & abuse)",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          },
          {
            "regulator": "owasp-asi",
            "regulator_name": "OWASP Top 10 for Agentic Applications (2026)",
            "relation": "relevant-to",
            "obligation": "ASI05 Unexpected Code Execution + ASI10 Rogue Agents",
            "statutory_maximum": null,
            "fine_cited_to": null,
            "fine_applies_to": "voluntary frameworks and security taxonomies carry no statutory fine of their own",
            "tier": "no_fine",
            "no_fine_asserted_owed": true
          }
        ],
        "note": "Published relevant-to pointers only; legal effect requires independent legal review."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:provenance-controls",
      "ordinal": 15,
      "axis": "provenance-controls",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "ChainFacts",
        "task": "on-chain issuer control facts (allowlisting / freeze capability / identity domain)",
        "n": 6,
        "n_note": "6 tokenised instruments read directly from their mainnet issuer accounts. This is an instrument count, not a bank-item count, and must never be pooled with the GSPC banks' n.",
        "n_unit": "issuer accounts (not bank items)",
        "dataset": "csoai/gspc-provenance-controls",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-provenance-controls",
        "evidence_url": "/interop/financial-measure-run-v2.json",
        "coverage": "6 of the 16 instruments named in the registry",
        "coverage_note": "The registry NAMES 16 instruments and this axis COVERS 6. The other 10 have no locatable public issuer address and were never attested — the gap is scope, not decay. Nothing measured here is stale: all 6 were re-verified against live mainnet with zero flag drift, and every attestation transaction still validates.",
        "carrier": "attestation carrier is DEVNET; the facts are read from MAINNET. Mainnet attestation is PLANNED, not live.",
        "note": "MEASURED for on-chain control facts only, and only those — one axis family over six instruments. Deterministic: the rubric reads account-root flags (RequireAuth, NoFreeze, GlobalFreeze) and the declared Domain off the public ledger and decodes them; there is no model, no judgement, no score and no ranking. Measured 2026-08-25 across 6 issuers (RLUSD, Ondo OUSG, OpenEden TBILL, Archax abrdn MMF, Braza USDB, Braza BBRL); a stranger re-runs the fetch and compares. Signed run v0.2, content_id 29369542cb537f38. Findings: 3 of 6 enforce allowlisting, 6 of 6 retain issuer freeze capability, 6 of 6 declare an identity domain. TWO BOUNDARIES THAT ARE PART OF THE MEASUREMENT, NOT CAVEATS ON IT. First, the facts are read from mainnet but the attestations are carried on DEVNET — mainnet attestation is PLANNED and not live, and nothing is attested on any Ethereum chain. Second, THE RISK VERDICT IS UNMEASURED: what these facts imply about an instrument's safety, solvency or creditworthiness needs counsel and is not measured here. This is not a rating, not advice, not a ranking, and not an endorsement of any named instrument. Supersedes the v0.1 run."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:reserve-attestation",
      "ordinal": 16,
      "axis": "reserve-attestation",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "ReserveFacts",
        "task": "is third-party reserve-attestation language on a retrieved issuer page? (PASS/FAIL/UNCHECKABLE)",
        "n": 16,
        "n_note": "The live XRPL reader-16 (GET /api/xrpl, writes_board=false). Instrument count, not bank items.",
        "n_unit": "issuer accounts (not bank items)",
        "dataset": "csoai/gspc-reserve-attestation",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-reserve-attestation",
        "evidence_url": "/interop/financial-measure-run-reserve-attestation.json",
        "note": "MEASURED v0.3 over the live XRPL reader-16 (start set RLUSD/OUSG/USDB/BBRL bidirectional, then the twelve well-known/registry rows). Three-state per fact: 1 PASS, 6 FAIL, 9 UNCHECKABLE (no on-chain declared Domain = no deterministic disclosure surface; UNREACHABLE is never FAIL). Self-declare without attestation language is FAIL. Archax x abrdn and OpenEden TBILL are off this reader — parked under rwa-attest-other. Risk verdict UNMEASURED. Not a rating."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:regulatory-framework",
      "ordinal": 17,
      "axis": "regulatory-framework",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "RegimeFacts",
        "task": "is the governing regime declared and confirmable (NYDFS / MiCA / BACEN / Reg D ...)? (PASS/FAIL/UNCHECKABLE)",
        "n": 16,
        "n_unit": "issuer accounts (not bank items)",
        "dataset": "csoai/gspc-regulatory-framework",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-regulatory-framework",
        "evidence_url": "/interop/financial-measure-run-regulatory-framework.json",
        "note": "MEASURED v0.3 for declaration presence on a retrieved URL, over the live XRPL reader-16. 3 PASS, 4 FAIL, 9 UNCHECKABLE (no on-chain Domain; UNREACHABLE is never FAIL). Never compliance. Risk verdict UNMEASURED. Not a rating."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:distribution-integrity",
      "ordinal": 18,
      "axis": "distribution-integrity",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "DistributionFacts",
        "task": "reader classification + chain supply + holder count (PASS/FAIL/UNCHECKABLE)",
        "n": 16,
        "n_unit": "issuer accounts (not bank items)",
        "dataset": "csoai/gspc-distribution-integrity",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-distribution-integrity",
        "evidence_url": "/interop/financial-measure-run-distribution-integrity.json",
        "note": "MEASURED v0.3 from GET /api/xrpl (writes_board=false) over all 16 reader rows: 16 PASS on distributed classification. represented>>distributed stays UNCHECKABLE (no RWA.xyz key; no same-unit pair). EURQ/USDQ reader sig_ed25519=null stays flagged. Risk verdict UNMEASURED. Not a rating."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:custody-disclosure",
      "ordinal": 19,
      "axis": "custody-disclosure",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "CustodyFacts",
        "task": "are a custodian and an auditor named and confirmable? (PASS/FAIL/UNCHECKABLE each)",
        "n": 16,
        "n_unit": "issuer accounts (not bank items)",
        "dataset": "csoai/gspc-custody-disclosure",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-custody-disclosure",
        "evidence_url": "/interop/financial-measure-run-custody-disclosure.json",
        "note": "MEASURED v0.3 for named-string presence on retrieved pages, over the live XRPL reader-16: custodian 1 PASS / 6 FAIL / 9 UNCHECKABLE. Disclosure only — never custodian or auditor quality. Risk verdict UNMEASURED. Not a rating."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:ai-adoption-components",
      "ordinal": 20,
      "axis": "ai-adoption-components",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "Eurostat",
        "task": "cited EU AI-adoption series (not an index)",
        "n": 2,
        "n_unit": "public series",
        "dataset": "csoai/gspc-ai-economy-index",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-ai-economy-index",
        "evidence_url": "/interop/financial-measure-run-ai-adoption-components.json",
        "note": "MEASURED as two Eurostat series (13.48% / 41.17% 2024). Not an index. No formula file. C-2026-0826-05: do not restore MEASURED-INDEX-v0.1. Former slot id ai-economy-index."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:labour-components",
      "ordinal": 21,
      "axis": "labour-components",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "Eurostat",
        "task": "cited EU labour series (not an index)",
        "n": 2,
        "n_unit": "public series",
        "dataset": "csoai/gspc-human-labour-index",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-human-labour-index",
        "evidence_url": "/interop/financial-measure-run-labour-components.json",
        "note": "MEASURED as two labour series (participation 57.58%, unemployment 5.92% 2024). Not an index. C-2026-0826-05: do not restore MEASURED-INDEX-v0.1. Former slot id human-labour-index."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    },
    {
      "scenario_id": "gspc-axis:humanoid-labour-index",
      "ordinal": 22,
      "axis": "humanoid-labour-index",
      "board_measurement": {
        "classification": "BOARD_MEASUREMENT_CONTEXT",
        "source": "/api/gspc",
        "status": "MEASURED",
        "family": "financial",
        "kind": "deterministic-facts",
        "bench": "Disclosure",
        "task": "named vendor publishes a dated deployment count on a stable URL? Y/N",
        "n": 8,
        "n_unit": "frozen vendor URLs",
        "dataset": "csoai/gspc-humanoid-labour-index",
        "dataset_url": "https://huggingface.co/datasets/csoai/gspc-humanoid-labour-index",
        "evidence_url": "/interop/financial-measure-run-humanoid-labour-index.json",
        "note": "MEASURED as disclosure facts on 8 frozen URLs. Fleet size / hours / incidents stay UNMEASURED inside the card. Vendor blogs are not a bank. Not an index."
      },
      "evidence": {
        "published_state": "NONE_PUBLISHED",
        "independently_admitted": false,
        "published_measurements": [],
        "candidate_state": "NO_CANDIDATE_FINDING",
        "candidate_findings": []
      },
      "regulation_context": {
        "classification": "REGULATION_CONTEXT",
        "state": "UNMAPPED",
        "source": "/signed/findings_index.json",
        "source_axis": null,
        "match": null,
        "pointers": [],
        "note": "No exact published crosswalk identity was available; no mapping was guessed."
      },
      "controls": {
        "read_only": true,
        "writes_board": false,
        "model_training": false,
        "automatic_fixing": false,
        "automatic_promotion": false
      }
    }
  ]
}