CSOAI - for US public companies
AI governance your 10-K can stand behind
You disclose material AI risk and face AI-washing scrutiny. CSOAI publishes signed measurement runs on frozen, public banks — evidence a reader can recompute from the bytes rather than take on trust. What is signed is the measurement, not your compliance.
Your path with CSOAI
What you can check, right now
An AI-washing charge turns on whether a disclosure was evidenced, and these are the axes a filer's own claims rest on: whether AI-generated output can be traced to what produced it, whether a model tiers its own regulated use correctly, and how much of the system is open to inspection. Read the rows, then recompute the signed card behind any of them.
| Axis | Bench | n | Leader accuracy | 95% CI | Separation |
|---|---|---|---|---|---|
| provenance | ProvBench | 32 | 78.1% | 61.2–89.0% | TIE — indistinguishable p=0.7744 |
| governance | GovBench | 237 | 70.0% | 63.9–75.5% | SEPARATED p=0.0086 |
| openness | OSSBench | 32 | 87.5% | 71.9–95.0% | TIE — indistinguishable p=1 |
the risk
AI is already in your filings
Material AI risk belongs in Reg S-K Item 105 risk factors and in MD&A. The SEC has charged and settled AI-washing cases against investment advisers. Disclosure needs evidence behind it.
What you can check on the board
Two board axes bear directly on disclosure: whether a model can place an AI system in the right risk tier at all, and whether provenance marking survives.
Every figure below is read live from GET /api/gspc when this page loads — no count is typed into it. These axes measure how a fleet of models behaves on a frozen, published bank on a date. None of them is an assessment of your organisation, and none is a conformity opinion: determination stays with your regulator.
Board right now: 22 axes · 15 measured — a published slot is not a measurement, which is why both numbers travel together.
EU AI Act risk-tier classification — the judgement a disclosure about 'our high-risk AI systems' depends on being made correctly.
- What is graded:
- EU AI Act risk-tier classification
- n:
- 237 bank items
- Leader:
- 70.0% (council-embodiment-v3-light (council specialist))
- Separation:
- SEPARATED
- Frozen bank:
- csoai/gspc-gov
Article 50 marking survival: does a provenance mark still read after ordinary handling? A disclosure about labelled AI output rests on this.
- What is graded:
- Article 50 marking survival by validity
- n:
- 32 bank items
- Leader:
- 78.1% (council-aesthetics-v3-light (council specialist))
- Separation:
- TIE — the leader's lead is not statistically separated, and a tie is never counted as a win.
- Frozen bank:
- csoai/gspc-prv
Re-check it without us
Each published measurement card is Ed25519-signed over its exact bytes, and its id is the sha256 of those bytes. Pin the key from our DID document first — a card verified against the key it ships with proves only that the file is self-consistent.
- /signed/HOW-TO-VERIFY.md — the four commands, start here
- /signed/card_index.json — the signed index of published cards
- /.well-known/did.json — the key to pin against
- /gspc-verify — recompute the replay chain in your browser, no account
Questions, answered
No standalone rule yet, but material AI risks already belong in 10-K risk factors and MD&A, and misleading AI claims can trigger enforcement. Treat it as material disclosure now.
By giving you something checkable to point at. Each measurement card is Ed25519-signed over its exact bytes and its id is the sha256 of those bytes, so a reader re-verifies it against the key published in our DID document — no account, no trust in us required. That converts one class of statement, 'this model was measured, here is the result on this bank', from assertion into evidence. It evidences nothing we did not measure.
Answers from published measurement, or it refuses. Your question is typed into the lobby — nothing sends until you press Ask.
Deterministic pane commands · grounded /api/chat lane · consent checkpoint on consequential steps