IETF SCITT RFC 9943 and AI Supply-Chain Attestation — Turning Model Claims Into Verifiable Evidence
RFC 9943 defines the IETF SCITT architecture for trustworthy and transparent digital supply chains. In that architecture, an issuer creates a Signed Statement as a COSE_Sign1 message; registration with a Transparency Service can add a receipt, producing a Transparent Statement. A signed JSON object is not automatically either one. Council of AI currently publishes its own Ed25519-signed JSON measurement evidence, but does not yet publish a verified COSE_Sign1 conversion or a receipt from an identified SCITT Transparency Service. That integration remains planned. Operators can prepare honestly by binding every claim to an artifact digest, preserving the measurement method and scope, and verifying issuer signatures independently; they should only describe an item as SCITT-registered when a verifiable transparency-service receipt exists.
References
- RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains
- RFC 9052: CBOR Object Signing and Encryption (COSE): Structures and Process
- RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts
- draft-ietf-scitt-scrapi: SCITT Reference APIs
- Council of AI measurement-card verifier (councilof.ai/gspc-verify)
Measurement, not certification. Verify a card at /gspc-verify.