CSOAI - for financial services

Model risk, DORA, and the EU AI Act - what we actually hold

Credit scoring and life and health insurance pricing are named high-risk uses under the EU AI Act, and DORA's operational-resilience duties reach the ICT your models run on. CSOAI does not sell one control set that satisfies all of that. What we publish is a signed measurement board and a dated corpus feed that carries DORA's provisions as a hashed baseline alongside the AI Act's.

Your path with CSOAI

What you can check, right now

Two of these carry a measurement and two are declared slots with no run behind them, and a finance reader is shown all four deliberately. provenance-controls is the one financial axis with a real run — a deterministic mainnet read whose n counts issuer accounts, not bank items. The empty rows are the honest state of the financial family today.

AxisBenchnLeader accuracy95% CISeparation
governanceGovBench23770.0%63.9–75.5%SEPARATED p=0.0086
provenance-controlsChainFacts6issuer accounts (not bank items)no leader accuracy6 of the 16 instruments named in the registrynot applicable — no accuracy to boundnot applicable — no fleet, no leader
distribution-integritynothing measuredunmeasuredunmeasuredUNMEASURED
reserve-attestationnothing measuredunmeasuredunmeasuredUNMEASURED
Every figure above is read from GET /api/gspc when this page loads — none of it is written into the page. Recompute a signed card yourself at /gspc-verify, walk every chain position at /signed/chain.json, and read the rules the grades are computed under at /methodology. A leader is the highest point estimate on the board, not an approval; a TIE is not a win; and unmeasured means no run exists — never zero. We measure against these obligations; we do not enforce them and we certify nothing.

high-risk

Credit and life/health insurance AI are named uses

Annex III(5) names evaluating creditworthiness or establishing a credit score for natural persons, and risk assessment and pricing in relation to life and health insurance. Article 10 data governance, Article 14 human oversight and Article 11 technical documentation follow from that classification.

What you can check on the board

One axis on the financial half of the board carries a real run; the rest of that family is published as open slots so the gap is visible rather than quietly missing.

Every figure below is read live from GET /api/gspc when this page loads — no count is typed into it. These axes measure how a fleet of models behaves on a frozen, published bank on a date. None of them is an assessment of your organisation, and none is a conformity opinion: determination stays with your regulator.

Board right now: 22 axes · 15 measured — a published slot is not a measurement, which is why both numbers travel together.

  • provenance-controlsMEASUREDChainFacts

    On-chain issuer control facts for tokenised instruments — a deterministic read, no model and no score. Read its own limits carefully: what these facts imply about risk or solvency is not measured.

    What is graded:
    on-chain issuer control facts (allowlisting / freeze capability / identity domain)
    n:
    6 issuer accounts (not bank items)
  • reserve-attestationUNMEASURED

    Published as an open slot with no run behind it. It is here precisely because an empty cell is a first-class published status, not something to hide from a finance reader.

    What is graded:
    is a third-party reserve attestation publicly published and current? (deterministic Y/N + date)
    n:
    0 nothing measured
  • governanceMEASUREDGovBench

    EU AI Act risk-tier classification — whether a model places a credit or insurance use in the tier the statute puts it in.

    What is graded:
    EU AI Act risk-tier classification
    n:
    237 bank items
    Leader:
    70.0% (council-embodiment-v3-light (council specialist))
    Separation:
    SEPARATED
    Frozen bank:
    csoai/gspc-gov
  • continuityMEASUREDPQCBench

    Post-quantum status of a cryptographic assumption — the resilience question DORA's ICT duties eventually reach.

    What is graded:
    post-quantum status of a cryptographic assumption
    n:
    33 bank items
    Leader:
    60.6% (council-destruction-v3-light (council specialist))
    Separation:
    TIE — the leader's lead is not statistically separated, and a tie is never counted as a win.
    Frozen bank:
    csoai/gspc-asi

Re-check it without us

Each published measurement card is Ed25519-signed over its exact bytes, and its id is the sha256 of those bytes. Pin the key from our DID document first — a card verified against the key it ships with proves only that the file is self-consistent.

Ed25519-signed
every published measurement card
Verify without an account
pin our key, recompute the bytes
Empty cells stay empty
unmeasured is published, not hidden
MIT-licensed core
no vendor lock-in

Questions, answered

Is credit scoring high-risk under the EU AI Act?

Yes. Annex III(5)(b) lists AI intended to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, with a carve-out for systems used to detect financial fraud. Bias examination, human oversight and technical documentation duties follow.

Does CSOAI cover DORA?

Not as a mapped control set, and we will not say otherwise. DORA is one of the instruments in our dated corpus feed, seeded and hashed so drift in its text is detectable. The published crosswalk maps the EU AI Act against the UK DRCF principles, Illinois SB 315 and TC260 — DORA is not among its rows, and neither is NIST AI RMF.

Council OS — finance

Answers from published measurement, or it refuses. Your question is typed into the lobby — nothing sends until you press Ask.

Open Council OS

Deterministic pane commands · grounded /api/chat lane · consent checkpoint on consequential steps