CSOAI - for US public companies

AI governance your 10-K can stand behind

You disclose material AI risk and face AI-washing scrutiny. CSOAI publishes signed measurement runs on frozen, public banks — evidence a reader can recompute from the bytes rather than take on trust. What is signed is the measurement, not your compliance.

Your path with CSOAI

What you can check, right now

An AI-washing charge turns on whether a disclosure was evidenced, and these are the axes a filer's own claims rest on: whether AI-generated output can be traced to what produced it, whether a model tiers its own regulated use correctly, and how much of the system is open to inspection. Read the rows, then recompute the signed card behind any of them.

AxisBenchnLeader accuracy95% CISeparation
provenanceProvBench3278.1%61.2–89.0%TIE — indistinguishable p=0.7744
governanceGovBench23770.0%63.9–75.5%SEPARATED p=0.0086
opennessOSSBench3287.5%71.9–95.0%TIE — indistinguishable p=1
Every figure above is read from GET /api/gspc when this page loads — none of it is written into the page. Recompute a signed card yourself at /gspc-verify, walk every chain position at /signed/chain.json, and read the rules the grades are computed under at /methodology. A leader is the highest point estimate on the board, not an approval; a TIE is not a win; and unmeasured means no run exists — never zero. We measure against these obligations; we do not enforce them and we certify nothing.

the risk

AI is already in your filings

Material AI risk belongs in Reg S-K Item 105 risk factors and in MD&A. The SEC has charged and settled AI-washing cases against investment advisers. Disclosure needs evidence behind it.

What you can check on the board

Two board axes bear directly on disclosure: whether a model can place an AI system in the right risk tier at all, and whether provenance marking survives.

Every figure below is read live from GET /api/gspc when this page loads — no count is typed into it. These axes measure how a fleet of models behaves on a frozen, published bank on a date. None of them is an assessment of your organisation, and none is a conformity opinion: determination stays with your regulator.

Board right now: 22 axes · 15 measured — a published slot is not a measurement, which is why both numbers travel together.

  • governanceMEASUREDGovBench

    EU AI Act risk-tier classification — the judgement a disclosure about 'our high-risk AI systems' depends on being made correctly.

    What is graded:
    EU AI Act risk-tier classification
    n:
    237 bank items
    Leader:
    70.0% (council-embodiment-v3-light (council specialist))
    Separation:
    SEPARATED
    Frozen bank:
    csoai/gspc-gov
  • provenanceMEASUREDProvBench

    Article 50 marking survival: does a provenance mark still read after ordinary handling? A disclosure about labelled AI output rests on this.

    What is graded:
    Article 50 marking survival by validity
    n:
    32 bank items
    Leader:
    78.1% (council-aesthetics-v3-light (council specialist))
    Separation:
    TIE — the leader's lead is not statistically separated, and a tie is never counted as a win.
    Frozen bank:
    csoai/gspc-prv

Re-check it without us

Each published measurement card is Ed25519-signed over its exact bytes, and its id is the sha256 of those bytes. Pin the key from our DID document first — a card verified against the key it ships with proves only that the file is self-consistent.

Ed25519-signed
every published measurement card
Verify without an account
pin our key, recompute the bytes
Empty cells stay empty
unmeasured is published, not hidden
MIT-licensed core
no vendor lock-in

Questions, answered

Does the SEC require AI disclosure?

No standalone rule yet, but material AI risks already belong in 10-K risk factors and MD&A, and misleading AI claims can trigger enforcement. Treat it as material disclosure now.

How does CSOAI reduce AI-washing risk?

By giving you something checkable to point at. Each measurement card is Ed25519-signed over its exact bytes and its id is the sha256 of those bytes, so a reader re-verifies it against the key published in our DID document — no account, no trust in us required. That converts one class of statement, 'this model was measured, here is the result on this bank', from assertion into evidence. It evidences nothing we did not measure.

Council OS — sec-filer

Answers from published measurement, or it refuses. Your question is typed into the lobby — nothing sends until you press Ask.

Open Council OS

Deterministic pane commands · grounded /api/chat lane · consent checkpoint on consequential steps