Layer 0 · measured, dated, counted from artifacts
The trust floor, benched.
Layer 0 is the floor every other claim stands on: Ed25519 signing, the care-floor gate, and offline verification — plus a designed 33-seat council, which is a design figure only. DR-0007 records the retraction; its historical numeric result is unbound because the cited result artifact is absent from this repository. The latest point experiment measured rho=1 and n_eff=1 across three nominal legs. Neither experiment demonstrates independent review or fault tolerance; the 33-seat council remains a design, not a live property. Every claim made on this floor carries either a measurement or an honest status. Nothing here asks to be believed; everything here asks to be checked.
“Layer 0” here means our foundational verification layer — identity, signing and attestation beneath governed AI. It is not a blockchain Layer-0 protocol, and it is not an interoperability substrate for blockchains.
The bench
Measured results, updated 22 Jul 2026. We publish what we measured, with the number that could embarrass us next to the number that flatters us — a recall figure without a false-positive figure is half a claim.
32 scenarios mapped to EU AI Act Art 5/9/12/14, run against the real governed gate. Honest framing: the benchmark first FOUND a real miss (a code-framed audit-log delete), we published it, then closed it. 1.0 is on our scenario set — not a claim of perfection.
3 testable dimensions, n=13. Low attestation/oversight scores are structural — no signing, no escalate action. A measurement, not an accusation.
Sub-agent delegation — who is accountable when an agent spawns agents — is SILENT in NIST AI RMF, the EU AI Act, and the UK framework, checked against fetched primary text of all three. The UK response even asks the question verbatim and answers none of it.
The care gate refused 0 of 50 hard benign prompts while holding its harm-refusal battery, and an academic-frame guard passes 17/17. Asking WHY something is banned is answered; asking HOW to do it is refused.
Every regulatory citation checked for existence AND content against primary sources (EUR-Lex et al.), each carrying its verified source and scope.
Our efficiency dimension is a prototype and is not published as validated. A signature proves integrity and authorship — never that a claim is true. Provenance is not truth.
The floor, read every root tick
One PROBED atom per public-root run records what the floor looked like at that instant — the DID key, the served root, the pointer, the Rekor and OpenTimestamps states — and the publisher signs it into the root it is building. This is the latest staged atom; the count beside it is how many such atoms the current root commits to, from the root's own index. A read, not a rating: nothing here says the floor is secure.
- DID document
- HTTP 200 · key present
- Public root
- HTTP 200 · 305 leaves · as_of 2026-09-22T08:54:02Z · 40ce3833118fab76…
- Pointer
- matches root.json
- Rekor
- WITNESSED
- OpenTimestamps
- CONFIRMED_BITCOIN
- Release gate (this run)
- UNRUN
Source: the staged atom · root-kinds.json · reader scripts/readers/layer0_liveness_reader.py.
The audited node registry
Every anchor source Layer 0 reads, with the status it has actually earned. 17 of 26 nodes LIVE — counted from the registry file itself, never from recall.
Audit note: the headline count once said 18; the probe records supported 15, and one node had been written from memory with no probe behind it. The number above is computed from data/layer0Nodes.ts at render time — if any sentence anywhere disagrees with it, the file wins.
LAW
Anchors UK statute as byte-stable XML; every drift is a signed event against the frozen normaliser.
proven by a real HTTP 200 fetch
Holds Regulation 2024/1689 — the text the console's 417 frozen provisions are cut from.
proven by a real HTTP 200 fetch
Polls Article 50 for drift. Current state UNKNOWN — the extractor no longer matches the page and says so rather than reporting 'unchanged'.
polled — unreadable, said out loud
Watches AI rulemaking in a fixed window; a new rule is the drift event, hashed order-stable.
proven by a real HTTP 200 fetch
Next in the N-sites order: US Code as bulk USLM XML — the largest single coverage gain.
named — no fetch yet
Daily-updated federal regulations; queued behind GovInfo.
named — no fetch yet
Consolidated acts as XML on GitHub — byte-stable by construction.
named — no fetch yet
Keyless statute API with point-in-time retrieval — render_at(T) for Japanese law.
named — no fetch yet
Swiss law in AKN since 2022 — the cleanest structured-statute source in Europe.
named — no fetch yet
REGULATOR
The template for enforcement-data transparency — what a public compliance ledger looks like at federal scale.
proven by a real HTTP 200 fetch
STANDARD
The watcher set's control: an RFC never changes, so drift here means our reader broke, not the IETF.
proven by a real HTTP 200 fetch
Spec watcher. Currently UNKNOWN — the raw path 404s, reported as unreadable rather than 'unchanged'. The measurement against it: 0 of 12 marked assets kept an intact embedded manifest (signed run, 13 Aug 2026).
polled — unreadable, said out loud
GOV
UK government guidance as structured content — the DSIT/RTAU assurance ecosystem anchor.
proven by a real HTTP 200 fetch
EU statistical baselines for the market-size claims we refuse to make without a source.
proven by a real HTTP 200 fetch
The UK's living register of deployed public-sector AI — the closest thing to our registry already run by a state.
named — no fetch yet
COMPANY
10,414 registered companies fetched live (CIK + ticker + name) — the entity corpus the crosswalk scores against.
proven by a real HTTP 200 fetch
SAFETY
Live CVE feed — the vulnerability side of the CRA obligations the OSS scanner measures.
proven by a real HTTP 200 fetch
Known-exploited vulnerabilities — the ground truth the 11 Sep 2026 CRA reporting clock runs against.
proven by a real HTTP 200 fetch
STIX bundle from GitHub (not TAXII) — the adversary-technique anchor for the safety axis.
named — no fetch yet
HEALTH
Regulated-product data for the medical persona of the Annex III classifier.
proven by a real HTTP 200 fetch
Trial registry — the pattern for what a public, queryable register of high-risk AI systems could be.
proven by a real HTTP 200 fetch
Curated bioactivity data — the model of expert-gated registry admission the node registry copies.
proven by a real HTTP 200 fetch
SCHOLARLY
Literature anchor for every clinical claim in the training corpus.
proven by a real HTTP 200 fetch
DOI resolution — how every published claim on this site will carry a resolvable identifier.
proven by a real HTTP 200 fetch
Where ProvBench publishes — and where 2606.31498 already named the governance gap we measure. They read specs; we measure conduct.
proven by a real HTTP 200 fetch
INTL
International health indicators — the INTL class proof that the node contract crosses jurisdictions.
proven by a real HTTP 200 fetch
MCP conformance
The same floor wraps the Model Context Protocol fleet: 216 servers deployed, 94% at L0-1 or above.
Design requirement: a governed tool call carries a checked identity before admission.
Design requirement: policy is evaluated before a governed call reaches the tool.
Published Ed25519-signed cards can be verified offline. Ordinary tool calls are not automatically signed.