{
  "schema": "csoai.press/0.1",
  "license": "CC-BY-4.0",
  "publisher": "Council of AI (CSOAI Ltd, UK Companies House 16939677)",
  "doctrine": "Measurement, never certification. Verification is free and needs no account. Every line below carries the command that checks it.",
  "window": {
    "from": "2026-09-22",
    "to": "2026-09-28",
    "derivation": "The 7 days ending at the newest date any committed artifact carries. NOT the clock: two requests any interval apart return the same window.",
    "proof": "curl -s https://councilof.ai/api/press.json | jq .window"
  },
  "corrections_this_window": {
    "value": 18,
    "total": 78,
    "kind": "counted",
    "note": "Entries are things we got wrong about ourselves, how they were caught, and the fix. Publishing them is the credibility engine: the body that publishes the number also publishes when it was wrong.",
    "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections|length'",
    "feed": "https://councilof.ai/feeds/corrections.xml",
    "items": [
      {
        "id": "C-2026-0928-01",
        "date": "2026-09-28",
        "what_was_wrong": "The signed-receipts/v1 reference verifier, interceptor.py, had two faults in verify_receipt(). (1) When it was called without a resolve_did function, it returned True, with a reason reading 'VALID (integrity)' followed by the kid and 'not resolved'. A receipt carries its own public key, so a receipt signed with any key, naming any issuer's kid, came back VALID. Re-checked on 2026-09-28: a receipt signed with a freshly generated key and naming did:web:csoai.org#board-attestation-1 returned True with that reason, and the corrected file returns UNVERIFIABLE_KEY. (2) When a resolver was given but the lookup failed, for example because the DID document could not be fetched, it returned INVALID. So a caller could not tell 'forged' from 'could not check'. The same file was public in three places, and all three copies had the defect: (a) the GitHub repository CSOAI-ORG/a2a-signed-receipts, which IETF SCITT architecture issue #462 cites at commit daaa2306 in a post dated 2026-09-10T03:53:43Z (that repository is not reachable now, so the commit that first introduced the code is not recorded here); (b) the Hugging Face source snapshot csoai/councilof-ai-source, commit 96bf3a07, published 2026-09-25T10:42:26Z (interceptor.py sha256 d908b9e7...); (c) https://councilof.ai/spec/signed-receipts/v1/interceptor.py, the same bytes. The file was added in commit 7d0a7700a (2026-09-27T06:52:22Z) and first served by the deploy of 9e501e01d, completed 2026-09-27T07:32:56Z. Who could have been misled: anyone who ran any of these copies and relied on the boolean from verify_receipt. Without a resolver they would have accepted a forged receipt as the named issuer's. With a failing resolver they would have rejected a genuine one as INVALID. No hosted endpoint ran this code. functions/ contains no import or copy of interceptor.py. POST /api/receipts/verify checks x402 offer and receipt JWS with separate code that requires the kid to resolve in https://csoai.org/.well-known/did.json. Re-checked live on 2026-09-28: a receipt signed with a freshly generated key and naming did:web:csoai.org#attacker-key-1 returned INVALID ('not listed in verificationMethod'), and one naming did:web:csoai.org#board-attestation-1 returned INVALID ('signature does not verify under the resolved key'). POST /api/verify and the MCP verify_card tool check measurement cards with functions/_lib/cardVerify.ts, which does not use this canonicaliser.",
        "how_caught": "IETF SCITT architecture issue #462, opened by an outside participant, quotes our verifier's return line as the case for its second proposed requirement: a profile must not fall back to valid or invalid for the condition a third result covers. An internal note on 2026-09-22 recorded that the issue cites our work, but did not recognise that it describes a defect in our verifier. On 2026-09-28, while building the conformance kit, we reproduced the defect on master d06d09837 with an attacker key. It was fixed the same day.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0928-01\")'"
      },
      {
        "id": "C-2026-0928-02",
        "date": "2026-09-28",
        "what_was_wrong": "SPEC.md for signed-receipts/v1 (draft 0.2) says receipts are canonicalised with RFC 8785 (JCS). The reference implementation, interceptor.py, did not follow RFC 8785 in two places. (1) It wrote characters outside the Basic Multilingual Plane, such as emoji, as an escaped surrogate pair, for example \\ud83d\\ude00. RFC 8785, like ECMAScript JSON.stringify, writes the character itself. (2) It wrote floating-point numbers with Python repr() rules, not the ECMAScript Number-to-string rules RFC 8785 requires. An integral-valued float came out with '.0' (2.0 as '2.0', RFC 8785 '2'). Magnitudes from 1e-6 up to 1e-4 came out in exponent form (1e-05 as '1e-5', RFC 8785 '0.00001'). Magnitudes from 1e16 up to 1e21 also came out in exponent form (1e16 as '1e+16', RFC 8785 '10000000000000000'). Python integers were not affected. Re-checked on 2026-09-28 against node JSON.stringify: 9 of 13 probe values differed under the old code, and 0 differ under the corrected code. Effect: a receipt carrying any such character or number canonicalised to different bytes in the reference code than in a conforming RFC 8785 implementation. Its content_id and signature therefore failed across implementations: a receipt issued by the reference code failed in a conforming verifier, and a conforming issuer's receipt failed in the reference verifier. This fault causes wrong rejection. It does not cause false acceptance. The same file was public in three places, and all three copies had the defect: (a) the GitHub repository CSOAI-ORG/a2a-signed-receipts, which IETF SCITT architecture issue #462 cites at commit daaa2306 in a post dated 2026-09-10T03:53:43Z (that repository is not reachable now, so the commit that first introduced the code is not recorded here); (b) the Hugging Face source snapshot csoai/councilof-ai-source, commit 96bf3a07, published 2026-09-25T10:42:26Z (interceptor.py sha256 d908b9e7...); (c) https://councilof.ai/spec/signed-receipts/v1/interceptor.py, the same bytes. The file was added in commit 7d0a7700a (2026-09-27T06:52:22Z) and first served by the deploy of 9e501e01d, completed 2026-09-27T07:32:56Z. Who could have been affected: anyone who issued or verified such receipts with any of these copies, or who compared its bytes with another implementation. No hosted endpoint ran this code. functions/ contains no import or copy of interceptor.py. POST /api/receipts/verify checks x402 offer and receipt JWS with separate code that requires the kid to resolve in https://csoai.org/.well-known/did.json. Re-checked live on 2026-09-28: a receipt signed with a freshly generated key and naming did:web:csoai.org#attacker-key-1 returned INVALID ('not listed in verificationMethod'), and one naming did:web:csoai.org#board-attestation-1 returned INVALID ('signature does not verify under the resolved key'). POST /api/verify and the MCP verify_card tool check measurement cards with functions/_lib/cardVerify.ts, which does not use this canonicaliser.",
        "how_caught": "Found while building the signed-receipts/v1 conformance kit on 2026-09-28. The kit's vectors are checked by a Node runner that uses JSON.stringify and by the Python reference. The corrected number serialiser was then compared with node JSON.stringify over 3,995 fuzzed doubles, with 0 mismatches.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0928-02\")'"
      },
      {
        "id": "C-2026-0927-05",
        "date": "2026-09-27",
        "what_was_wrong": "Until 27 Sep, https://csoai.org/.well-known/agent-card.json and /.well-known/agent.json served an older A2A agent card, 'Council of AI Measurement Agent' version 0.1.0 with 2 skills, that presented itself as signed. identity.signedWith named did:web:csoai.org#site-release-1, and signatures[0] carried a JWS protected header with alg EdDSA and that kid. A2A specification 8.4.3 says that field is a JWS. Checked that way, it failed against the site-release-1 key in csoai.org's own /.well-known/did.json: scripts/verify_agent_card_jws.py returned rc=1 INVALID for both files. The bytes had been produced under the card's own declared rule, Ed25519 over the hex SHA-256 of its sorted-key JSON, so an A2A client got a signature that failed. At the same time councilof.ai served the current card, version 1.1.0 with 10 skills, with no signature at all (rc=2 UNSIGNED).",
        "how_caught": "The csoai.org card review on 2026-09-27 ran the repository's independent verifier, scripts/verify_agent_card_jws.py, against the cards served at both origins. The verifier is written without the signer's code. A re-run at 03:35:18Z gave the same results. The failing signature was then checked against every key in did.json under the card's self-declared rule. That showed the key matched and the signing rule did not.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0927-05\")'"
      },
      {
        "id": "C-2026-0927-04",
        "date": "2026-09-27",
        "what_was_wrong": "All 335 signed measurement cards in the signed card index (public/signed/card_index.json, n_cards 335, bodies under public/signed/cards/) carry the field body.public_framing = '13 measured of 14 quotable'. That was true of the board when the cards were signed on 2026-08-19. It is stale now. GET /api/gspc read at 2026-09-27T09:42:24Z returns totals.axes 23, totals.measured_axes 23 and totals.unmeasured_axes 0. The field states the board, not the card it sits in, and these cards have been public since August, so a reader of any one card could take '13 measured of 14' as the current board. Scope is this field in the signed card index only. The public-root leaves (root.json) and the card wrapper files are separate corpora and are not counted here.",
        "how_caught": "The P1 truth review on 2026-09-27 read public_framing in each of the 335 bodies in the signed card index and recomputed each card id from its body (335 of 335 match). The same stale string is in every one, and this ledger had no entry for it. The staleness was known internally before that. Commit 7413ca200 (26 Aug) made the card verifier say the string is frozen, and commit e985a4a2b (28 Aug) changed the producer and noted the signed originals, but neither published a correction here. This entry closes that gap.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0927-04\")'"
      },
      {
        "id": "C-2026-0927-03",
        "date": "2026-09-27",
        "what_was_wrong": "Two things on GET /api/gspc. (1) Six model-comparison axes (governance, continuity, provenance, conformance, openness, care) carried separation UNTESTED and no public leader, with the note that the external re-ranking was not carried. The 15,580 per-item rows that decide it existed, frozen since 2026-08-13, but were unpublished: the signed 2026-08-13 freeze manifests record peritem_sha256: null, and the board's own rule treats unpublished rows as grounds for no determination. The determination was available and not made. (2) The safety axis named gemma3:12b (base model) as its leader, and the board source listed safety as carded for that leader, under a public promise that every named leader links to the Ed25519 card behind it. The safety axis carries signed cards, but none is a gemma3:12b card: the axis is carded, its leader is not.",
        "how_caught": "A separation analysis on 2026-09-27 re-ran the fixed test (exact McNemar on discordant items, leader vs the best base model, p<0.05 to separate) on the frozen rows with our own models removed. Every axis came out TIE. A shuffled-label control came out SEPARATED in 0 to 4.4% of 1,000 shuffles per axis, within the test's 5%. The same analysis looked up the safety leader's own card in /signed/card_index.json and found none.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0927-03\")'"
      },
      {
        "id": "C-2026-0926-06",
        "date": "2026-09-26",
        "what_was_wrong": "The cross-ledger daily record for 2026-09-26 (csoai/cross-ledger-supply, xl-daily/2026-09-26/xl-daily-2026-09-26.json, sha256 b02851fc...) graded three Tether deployments INCONSISTENT with the issuer's own list: EURT on Ethereum, CNHT on Ethereum and CNHt on Tron, whose totalSupply() read 50,000,050, 25,000,000 and 20,000,000. The only issuer statement was that tether.to/en/supported-protocols/ lists them under a 'Deprecated Asset Protocols:' heading. That heading states no supply figure, so there were never two statements that differ. The record also called totalSupply() 'issued supply'. In Tether's own terms totalSupply() is 'total authorized', which includes tokens the issuer holds as not issued.",
        "how_caught": "A pre-send review of the draft issuer notices built from this record re-checked each INCONSISTENT row live before queueing it. The review re-read the issuer page, the three ledgers and the token holders. It found that 'Deprecated' states no supply figure. It also found that most of each total sits at an issuer-held address: 0x5754...b949 holds 91.7% of the EURT and 78.0% of the Ethereum CNHT, and that address's MXNT balance equals Tether's own published not-issued figure. The candidate notice was dropped and nothing was sent.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0926-06\")'"
      },
      {
        "id": "C-2026-0926-05",
        "date": "2026-09-26",
        "what_was_wrong": "The remote MCP endpoint census record 0.2 (csoai/mcp-remote-census, 2026-09-26) published read_state EXHAUSTED while the 2026-09-26 probe contacted 10,039 of the 10,983 endpoints planned for it; 1,070 of 22,196 population endpoints were NOT_ATTEMPTED in all. 0.2 had redefined read_state to mean 'every endpoint has one row', but the same field meant 'every endpoint attempted' in 0.1 and 0.1.1 and in the probe's own summary (PARTIAL), and the signed 0.2 payload carries the bare word without the redefinition. Read beside 0.1.1 it said the read had become complete; it had not.",
        "how_caught": "Not recorded. Record 0.2.1 states the defect and when it was corrected, not who found it; detection is bounded only by the two published times in detected_window.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0926-05\")'"
      },
      {
        "id": "C-2026-0926-04",
        "date": "2026-09-26",
        "what_was_wrong": "The A2A Agent Card census record 0.1 (csoai/a2a-card-census, 2026-09-25) verified every signed card over JCS(card as served, minus signatures). A2A spec 8.4.3 step 3 says to remove properties with default values before verifying, and 0.1 did not, so cards declaring A2A 1.x were judged against the wrong payload. Of 33 signed cards, 0.1 published 18 VERIFIED and 3 FAILED; judged against the version each card declares, 13 verify and 8 fail (6 VERIFIED -> FAILED, 1 FAILED -> VERIFIED).",
        "how_caught": "Not recorded. Record 0.1.1 states the defect and the fix commits, not who found it or when; detection is bounded by detected_window.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0926-04\")'"
      },
      {
        "id": "C-2026-0926-03",
        "date": "2026-09-26",
        "what_was_wrong": "MCP contract parity record 0.1.1 (itself a correction, C-2026-0926-02) still applied three rules that misread services: an asymmetric AUTH scope rule; a declared tool list compared exactly with the credential-free live list when auth is declared required but no public list is named; and surfaces that never answered (251 rows, 41 of them behind an HTTP 429 stop) counted as a service's silence, under a collection run labelled EXHAUSTED.",
        "how_caught": "A maintainer-persona audit on 2026-09-26, before any notice was sent to a listed service, re-read candidate rows as their maintainer would and found the three rules; each was reproduced from the stored 2026-09-25 bytes (correction.v0.1.2.evidence.json).",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0926-03\")'"
      },
      {
        "id": "C-2026-0926-02",
        "date": "2026-09-26",
        "what_was_wrong": "MCP contract parity record 0.1 (csoai/mcp-contract-parity, read 2026-09-25) applied four rules that misread services. D1: a declared tool list was compared exactly with the live credential-free list even where the service named a public subset. D2a/D2b: an origin's document was credited to an endpoint it did not describe, and facts were read from nested blocks describing other endpoints. D3: a registry header isRequired false and a card's authentication.required true were paired as a contradiction though they state different scopes. D4: a bare declared tool count was compared with a live list holding a dispatcher. 22 rows (26 dimension verdicts) changed; endpoints with any INCONSISTENT dimension 2,778 -> 2,768.",
        "how_caught": "The notice lane re-checked candidate rows live on 2026-09-26 before any contact and found that three services' 0.1 rows misread them and two others held reasonable different meanings; all five were INCONSISTENT in 0.1. Reproduced from the stored 2026-09-25 bytes, each document's sha256 unchanged on the re-read (correction.v0.1.1.evidence.json).",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0926-02\")'"
      },
      {
        "id": "C-2026-0926-01",
        "date": "2026-09-26",
        "what_was_wrong": "Entry C-2026-0925-01, as signed on 2026-09-25 (ledger content_id 218e3585f039eb6ccb1251a569d6e1e5ed7417e6e2dc24f5d3115050614acd14, 67 entries), named an internal host by its literal hostname in what_was_wrong. That breaks this ledger's own redaction rule: a machine surface describes an internal identifier and never reproduces it. The /corrections page renders this field verbatim, so the hostname was visible public copy.",
        "how_caught": "Staging persona test of the 2026-09-26 integration build (Playwright over the rendered page, all three viewports), scanning visible text for internal identifiers. The build-time brand gate could not see it: /corrections is rendered in the browser from GET /api/corrections, and the gate scanned only prerendered HTML.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0926-01\")'"
      },
      {
        "id": "C-2026-0925-01",
        "date": "2026-09-25",
        "what_was_wrong": "Served text described the board signing key's custody as separated when it is not. /api/corrections (C-2026-0902-09 and C-2026-0902-08), llms-full.txt, /.well-known/did.json (_gspcBoardKeyNote), /interop/gspc-board-freeze-pointer.json (freeze.custody) and the custody disclosure page called the 2026-09-02 freeze key #gspc-board-22axis-2026 '3-party MPC' custody, and the Council OS sign pane said 'KEY is 2-of-3'. Read on the estate's always-on host on 2026-09-25: all three additive shares of that key are files in ONE directory on ONE host, used by one process. That is one failure domain. The 2-of-3 split was never performed, and no key the estate uses is held in separated custody.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0925-01\")'"
      },
      {
        "id": "C-2026-0924-03",
        "date": "2026-09-24",
        "what_was_wrong": "The 14 signed cards from the 16:10 UTC hourly local-model run were served from /interop/mill-cards-signed/ even though their exact intake receipts remained VERIFIED_QUARANTINE with authority.admitted=false. Thirteen wrappers said quotable=true; the safety wrapper was already UNMEASURED/quotable=false. A valid byte signature and a public URL did not establish canonical admission.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0924-03\")'"
      },
      {
        "id": "C-2026-0924-02",
        "date": "2026-09-22",
        "what_was_wrong": "public/corrections/living-stamp-unverifiable.json reads attestations_that_do_verify (measurement cards) = 150 while the compared surface reads 335. Source A: public/corrections/living-stamp-unverifiable.json @ cb773b2f9894#attestations_that_do_verify (sha256 ea601d5ee48f80df32831d8ef3e18789f3bcae0299d14d2ead2edcbef5da9d49; as_of 2026-08-28T17:19:43+01:00 = last commit touching the file). Source B: https://councilof.ai/api/state (sha256 efc1ffbbba84b4d20bf1e4e16c249fdbf901063563e07775841c8b33d224e300; as_of 2026-09-22T14:25:28Z = fetched_at (payload carries no as_of)). Compared at 2026-09-22T14:25:27Z (snapshot 2026-09-22T14).",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0924-02\")'"
      },
      {
        "id": "C-2026-0924-01",
        "date": "2026-09-22",
        "what_was_wrong": "public/corrections/living-stamp-unverifiable.json reads unmeasured_slots_unchanged = [\"ai-economy-index\", \"custody-disclosure\", \"distribution-integrity\", \"human-labour-index\", \"humanoid-labour-index\", \"regulatory-framework\", \"reserve-attestation\"] while the compared surface reads []. Source A: public/corrections/living-stamp-unverifiable.json @ cb773b2f9894#unmeasured_slots_unchanged (sha256 ea601d5ee48f80df32831d8ef3e18789f3bcae0299d14d2ead2edcbef5da9d49; as_of 2026-08-28T17:19:43+01:00 = last commit touching the file). Source B: https://councilof.ai/api/gspc (sha256 6496ac94d3cadfff3671e47125bc1f29a8468c028372a7f8350a65856ad39f9e; as_of behavioural axes 2026-08-12 · jail 2026-08-18 · financial-fact axes 2026-08-25 = measured_on.date (prose, not compared as a timestamp)). Compared at 2026-09-22T14:25:27Z (snapshot 2026-09-22T14).",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0924-01\")'"
      },
      {
        "id": "C-2026-0923-02",
        "date": "2026-09-23",
        "what_was_wrong": "totals carries axes, measured_axes, unmeasured_axes, quotable_axes and the count line '23 axis · 23 measured', and no aggregate of the separation field at all. The same payload's limitations[0] states the measured position plainly: of the 14 model-comparison axes, 2 TIE, 12 UNTESTED. The count line is the line every other surface quotes, so the figure that travels is the one that cannot carry the negative.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0923-02\")'"
      },
      {
        "id": "C-2026-0923-01",
        "date": "2026-09-23",
        "what_was_wrong": "Two surfaces this organisation publishes and signs give different answers to the same question about the same axis. GET /api/gspc reports swarm separation UNTESTED with leader 'qwen2.5:7b (base model)' over n=37. /signals/swarm.signed.json reports elo_separation SEPARATED with elo_leader 'nemotron-3-nano:30b' over 18 decided arena games. A reader asking whether we can tell two models apart on swarm gets two answers and two different model names, both carrying the board signature.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0923-01\")'"
      },
      {
        "id": "C-2026-0922-02",
        "date": "2026-09-22",
        "what_was_wrong": "32 signed measurement cards for the jail axis under /interop/mill-cards-signed/ published an accuracy for jailbreak-escape detection that was never measured. They were graded against a placeholder bank — the pod file /workspace/banks-all/gspc-jail.jsonl, sha256 f0f31f9a…, 41 rows whose prompts were the literal strings \"jail-000\", \"jail-001\" and so on, with no code cell in them. Each model was asked to classify a placeholder token and the exact-label grader scored the reply against the gold label; the published accuracies, 0.0 to 0.9487, are an artifact of which label a model happens to prefer. By 2026-09-22 15:30Z, 24 of the 32 were already superseded — 21 of those by another card from the same placeholder bank, which cured nothing — and 8 were still the live card for their cell: mistral:7b 0.9487 (n=39), phi3.5:3.8b 0.25 (n=40), qwen2.5:1.5b 0.0732 (n=41), mistral-nemo:12b and qwen2.5:0.5b-instruct 0.0488 (n=41), gemma3:4b 0.0256 (n=39), qwen2.5:7b 0.0244 (n=41), qwen3:4b 0 (n=41). All 32 carried status MEASURED and all 32 verify under did:web:csoai.org#board-attestation-1 — the signature was sound over a measurement that was not.",
        "proof": "curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id==\"C-2026-0922-02\")'"
      }
    ]
  },
  "public_root": {
    "merkle_root": "c2ab6d59e530d7dd5999b790c590ca0513e3af6f6fc1514cb8a282232ea768e3",
    "leaves": 310,
    "as_of": "2026-09-28T07:32:07Z",
    "signature_state": "SIGNED",
    "scope": "A valid OpenTimestamps proof over root.json covers root.json BYTES ONLY. It does not anchor the signed-card index and it does not anchor GSPC.",
    "proof": "curl -s https://councilof.ai/root.json | jq '{merkle_root,card_count,as_of}'",
    "feed": "https://councilof.ai/feeds/roots.xml"
  },
  "signed_cards": {
    "indexed": 335,
    "added_this_window": 0,
    "corpus_note": "This is the SIGNED CARD INDEX. It shares no members with the public-root leaf set or the on-disk wrapper count — three corpora, zero identifier overlap.",
    "proof": "curl -s https://councilof.ai/api/state | jq .signed_cards.corpus_relation",
    "verify_one": "curl -s https://councilof.ai/signed/verify-card.mjs  # the same verifier we run",
    "feed": "https://councilof.ai/feeds/cards.xml"
  },
  "doi": {
    "base_dataset_doi": "10.5281/zenodo.21991104",
    "proof": "curl -s https://councilof.ai/api/gspc | jq -r .doi"
  },
  "distribution_surfaces": {
    "scope": "Committed spray log only; not a census of all public distribution surfaces.",
    "live": null,
    "by_status": {
      "queued": 3,
      "drafted": 24
    },
    "kind": "unmeasured",
    "note": "This committed spray log contains no confirmed live placement. Drafted and queued entries are not a published surface. The log is not a census of all public distribution: separately evidenced listings and downloads appear at /memberships and /reach. Its live-placement count remains null until this log records a confirmed placement.",
    "proof": "In a source checkout: jq '[.[].status]|group_by(.)|map({(.[0]):length})|add' scripts/badger/_spray-log-v2.json"
  },
  "commercial_evidence": {
    "state": "MEASURED",
    "outside_payers": 1,
    "outside_settlements": 1,
    "settled_usdc_atomic": 20000,
    "self_settlements": 22,
    "note": "Revenue: the live settlement ledger records 1 outside settlement from 1 distinct non-self payer, totalling 0.02 USDC (20000 atomic units, 6 dp, on Base). This is a project-reported ledger: every record names its settlement transaction, so the chain is the check. Owner-controlled and zero-value settlements are excluded.",
    "source": "REVENUE_KV settled:tx:* records",
    "proof": "curl -s https://councilof.ai/api/revenue | jq '{settled_usdc,one_number}'"
  },
  "faq": [
    {
      "q": "Do you certify AI systems?",
      "a": "No. We measure, and we do not certify: no conformity marks, no accreditation, no conformity assessments. A grade is never sold, and verification is free and needs no account, permanently."
    },
    {
      "q": "How many corrections have you issued about your own published figures?",
      "a": "78 to date, 18 in the 2026-09-22 to 2026-09-28 window. Each records what was wrong, how it was caught — usually by our own instrument — and the fix. The full ledger is at /api/corrections and the feed is /feeds/corrections.xml."
    },
    {
      "q": "What is the most recent thing you got wrong?",
      "a": "C-2026-0928-02 (2026-09-28). SPEC.md for signed-receipts/v1 (draft 0.2) says receipts are canonicalised with RFC 8785 (JCS). The reference implementation, interceptor.py, did not follow RFC 8785 in two places. (1) It wrote characters outside the Basic Multilingual Plane, such as emoji, as an escaped surrogate pair, for example \\ud83d\\ude00. RFC 8785, like ECMAScript JSON.stringify, writes the character itself. (2) It wrote floating-point numbers with Python repr() rules, not the ECMAScript Number-to-string rules RFC 8785 requires. An integral-valued float came out with '.0' (2.0 as '2.0', RFC 8785 '2'). Magnitudes from 1e-6 up to 1e-4 came out in exponent form (1e-05 as '1e-5', RFC 8785 '0.00001'). Magnitudes from 1e16 up to 1e21 also came out in exponent form (1e16 as '1e+16', RFC 8785 '10000000000000000'). Python integers were not affected. Re-checked on 2026-09-28 against node JSON.stringify: 9 of 13 probe values differed under the old code, and 0 differ under the corrected code. Effect: a receipt carrying any such character or number canonicalised to different bytes in the reference code than in a conforming RFC 8785 implementation. Its content_id and signature therefore failed across implementations: a receipt issued by the reference code failed in a conforming verifier, and a conforming issuer's receipt failed in the reference verifier. This fault causes wrong rejection. It does not cause false acceptance. The same file was public in three places, and all three copies had the defect: (a) the GitHub repository CSOAI-ORG/a2a-signed-receipts, which IETF SCITT architecture issue #462 cites at commit daaa2306 in a post dated 2026-09-10T03:53:43Z (that repository is not reachable now, so the commit that first introduced the code is not recorded here); (b) the Hugging Face source snapshot csoai/councilof-ai-source, commit 96bf3a07, published 2026-09-25T10:42:26Z (interceptor.py sha256 d908b9e7...); (c) https://councilof.ai/spec/signed-receipts/v1/interceptor.py, the same bytes. The file was added in commit 7d0a7700a (2026-09-27T06:52:22Z) and first served by the deploy of 9e501e01d, completed 2026-09-27T07:32:56Z. Who could have been affected: anyone who issued or verified such receipts with any of these copies, or who compared its bytes with another implementation. No hosted endpoint ran this code. functions/ contains no import or copy of interceptor.py. POST /api/receipts/verify checks x402 offer and receipt JWS with separate code that requires the kid to resolve in https://csoai.org/.well-known/did.json. Re-checked live on 2026-09-28: a receipt signed with a freshly generated key and naming did:web:csoai.org#attacker-key-1 returned INVALID ('not listed in verificationMethod'), and one naming did:web:csoai.org#board-attestation-1 returned INVALID ('signature does not verify under the resolved key'). POST /api/verify and the MCP verify_card tool check measurement cards with functions/_lib/cardVerify.ts, which does not use this canonicaliser. It was caught: Found while building the signed-receipts/v1 conformance kit on 2026-09-28. The kit's vectors are checked by a Node runner that uses JSON.stringify and by the Python reference. The corrected number serialiser was then compared with node JSON.stringify over 3,995 fuzzed doubles, with 0 mismatches. The fix: undefined"
    },
    {
      "q": "What have you NOT measured?",
      "a": "Revenue: the live settlement ledger records 1 outside settlement from 1 distinct non-self payer, totalling 0.02 USDC (20000 atomic units, 6 dp, on Base). This is a project-reported ledger: every record names its settlement transaction, so the chain is the check. Owner-controlled and zero-value settlements are excluded. Distribution: no placement is confirmed live in this committed spray log; this does not negate separately evidenced public listings. The board publishes its own unmeasured slots rather than hiding them: quote totals.unmeasured_axes from /api/gspc."
    },
    {
      "q": "Can I verify one of your measurements myself, without an account?",
      "a": "Yes, and without asking us. Each signed card carries an Ed25519 signature over a canonical body whose id is the sha-256 of those bytes. Fetch the card, recompute the id, and check the signature against the key published at did:web:csoai.org using the same verifier we run: https://councilof.ai/signed/verify-card.mjs. A signature is an integrity claim, not a truth claim — it says these are the bytes that were signed, not that the measurement inside them is correct."
    },
    {
      "q": "What does your public root actually prove?",
      "a": "It commits to its own leaf list — 310 leaves under merkle_root c2ab6d59e530d7dd… as of 2026-09-28T07:32:07Z. Stranger inclusion means membership in that list. Its OpenTimestamps proof covers root.json bytes only: it does not anchor the signed-card index, and it does not anchor GSPC. Those are separate corpora with zero identifier overlap."
    }
  ],
  "not_announced": [
    {
      "subject": "N confirmed placements in this spray log",
      "state": "NOT HAPPENED",
      "why": "The committed spray log has no live placement. It is not a census of all public distribution; separately evidenced listings are outside this log. Drafts and queued rows cannot be counted as placements.",
      "proof": "In a source checkout: jq '[.[]|select(.status==\"live\" or .status==\"published\")]|length' scripts/badger/_spray-log-v2.json"
    }
  ]
}