Method
The open measurement mechanism
One route for anyone, anywhere, to have a public claim measured against published rules and to get back a signed record that a stranger can check without trusting us. It is open: the rules, the code, the records and the verifiers are public, and verification is free. This page says how it works, and how much of the world's rulebook it covers today, counted from the data.
- This report counts what the published data holds. Every number in it is derived by scripts/mechanism/build-coverage.mjs from committed files; none is typed.
- A provision marked PREDICATE has a deterministic check whose result a stranger can re-run. It is a measurement of one observable the provision names, not a finding that anyone complies with or breaches it.
- A provision marked RELATED_MEASURE is one that a measured board axis points to as relevant. The pointer is informative: the axis does not test the provision.
- HASH_ONLY means the provision is in the frozen manifest as an identifier and a SHA-256, and nothing tests it. The source text bytes behind those hashes were not recovered, so the manifest is not an inspectable legal corpus.
- Measurement, not certification. No compliance label, endorsement or regulator relationship is stated or implied.
Five steps
1. A declared claim
Something a party has said in public about its own system: a version it serves, a key that signs its agent card, a mark on a generated file, the supply of a token on a ledger. The claim is recorded as declared, next to what we observe.
2. Mapped to provision ids in the frozen corpus
The corpus is a manifest of 417 provision ids from 6 instruments, each pinned by the SHA-256 of its frozen text, under one root that recomputes (
37e2e10d53feaa9e…). Today 0 of 13184 published capsules carry a provision id; the optional field that lets them is proposed below.3. A deterministic predicate
A check that returns the same answer for anyone who runs it on the same bytes: no model grades, no vote. How a provision is cut into one is on statute to predicate. Provisions in the corpus with one implemented today: 1.
4. A signed capsule
One small JSON record: declared, observed, the difference, digests of the evidence, a measurement state and its limitations. Capsules are batched under an RFC 6962 Merkle root and the batch is signed with Ed25519 under
did:web:csoai.org. See measurement capsules.5. The daily index, verified free
Each day's index binds every batch, chains to the previous day, is signed, and is stamped with OpenTimestamps. Anyone can recompute a capsule's id, its path to the root and the signature, in the browser or over MCP, with no account.
Coverage, counted
Read from /interop/frozen-provision-hashes.json (SHA-256 e43c9bd52adeeda9…) and the files it is joined to. The same numbers are in /mechanism/coverage.json.
| What | Count | Read from |
|---|---|---|
| provision hashes | 417 | public/interop/frozen-provision-hashes.json · anchors |
| authority-routing records | 17 | public/interop/regulatory-inventory.json · authority_adapters.length |
| crosswalk assets | 25 | public/interop/regulatory-inventory.json · crosswalk_assets.length |
| instruments with provisions in the manifest | 6 | public/interop/frozen-provision-hashes.json · distinct CELEX ids |
State of the manifest: HASH_MANIFEST_VERIFIED_SOURCE_BYTES_UNRESOLVED, frozen 2026-08-12. Source text bytes: NOT_RECOVERED. Watcher: NOT BUILT — local corpus only; no authority is polled. The public manifest proves the 417 identifiers, their frozen hashes and their aggregate root. It does not include the exact normalized source-text bytes needed to regenerate each per-provision hash, and no authority watcher was active when it was frozen.
By instrument
| Instrument | Provisions | Predicate | Related measure | Hash only | Authority record |
|---|---|---|---|---|---|
| EU AI ActRegulation (EU) 2024/1689 · CELEX 32024R1689 | 126 | 1 | 12 | 113 | eu-ai-act-2024-1689 |
| GDPRRegulation (EU) 2016/679 · CELEX 32016R0679 | 99 | 0 | 0 | 99 | eu-gdpr-2016-679 |
| Cyber Resilience ActRegulation (EU) 2024/2847 · CELEX 32024R2847 | 71 | 0 | 0 | 71 | none |
| DORARegulation (EU) 2022/2554 · CELEX 32022R2554 | 64 | 0 | 0 | 64 | none |
| NIS2Directive (EU) 2022/2555 · CELEX 32022L2555 | 46 | 0 | 0 | 46 | none |
| CSRDDirective (EU) 2022/2464 · CELEX 32022L2464 | 11 | 0 | 0 | 11 | none |
All 6 instruments are EU acts. Where an instrument's manifest ids include negative numbers (the AI Act has 13 of them), the manifest does not say what they denote, so this report does not guess.
Provisions anything points to
| Provision id | Status | What points to it |
|---|---|---|
| 32024R1689:5 | Related measure | axes: care, jail, safety |
| 32024R1689:6 | Related measure | axes: governance |
| 32024R1689:8 | Related measure | axes: safety |
| 32024R1689:9 | Related measure | axes: governance, safety |
| 32024R1689:10 | Related measure | axes: safety |
| 32024R1689:11 | Related measure | axes: conformance, safety |
| 32024R1689:12 | Related measure | axes: art5-safeguard, care, continuity, detector-interop, governance, provenance, safety |
| 32024R1689:13 | Related measure | axes: conformance, safety |
| 32024R1689:14 | Related measure | axes: safety, swarm |
| 32024R1689:15 | Related measure | axes: continuity, jail, safety |
| 32024R1689:50 | Predicate | check: art50-marking-evidence; axes: provenance |
| 32024R1689:53 | Related measure | axes: openness |
| 32024R1689:55 | Related measure | axes: continuity |
Totals over all 417: 1 predicate · 12 related measure · 0 crosswalk only · 404 hash only. Pointers name articles in prose; the report resolves "Article N" to the manifest id. It cannot resolve Annex III, Annex IV, which the pointers also name.
By jurisdiction
| Jurisdiction | State | Frozen provisions | Routing records | Crosswalk rows | Prose pages |
|---|---|---|---|---|---|
| European Union / EEA | In the frozen corpus | 417 | eu-ai-act-2024-1689, eu-gpai-code-2025, eu-gdpr-2016-679 | 7 | /eu-ai-act/ |
| United Kingdom | Routing record only | 0 | uk-data-protection, uk-consumer-protection | 5 | /uk-ai-regulation/, /compliance/uk-ai-bill/, /frameworks/uk-ai-bill/ |
| United States (federal, incl. NIST) | Routing record only | 0 | us-ftc-act-section-5, us-nist-ai-rmf-1 | 0 | /us-ai-regulation/ |
| California | Prose pages only | 0 | none | 0 | /california-ai-law/ |
| Colorado | Prose pages only | 0 | none | 0 | /colorado-ai-act/ |
| Texas | Prose pages only | 0 | none | 0 | /texas-ai-act/ |
| Illinois | Crosswalk rows only | 0 | none | 4 | none |
| Canada | Routing record only | 0 | canada-pipeda | 0 | /canada-aida/, /compliance/canada-ai-act/, /frameworks/canada-ai-act/ |
| China | Routing record only | 0 | china-generative-ai-interim-measures | 4 | /china-ai-law/, /compliance/tc260/ |
| Japan | Routing record only | 0 | japan-ai-guidelines-business-1 | 0 | none |
| Singapore | Routing record only | 0 | singapore-agentic-ai-mgf | 0 | /singapore-ai-governance/ |
| South Korea | Routing record only | 0 | korea-ai-basic-act | 0 | /south-korea-ai-act/ |
| India | Routing record only | 0 | india-ai-governance-guidelines | 0 | none |
| Brazil | Routing record only | 0 | brazil-lgpd | 0 | none |
| Australia | Routing record only | 0 | australia-privacy-act | 0 | /compliance/australia-ai-governance/, /frameworks/australia-ai/ |
| South Africa | Routing record only | 0 | south-africa-popia | 0 | none |
| Council of Europe treaty parties | Routing record only | 0 | coe-ai-framework-convention-225 | 0 | none |
A routing record names an authority and where its rules are published; it holds no provisions and confers no authority. The prose pages explain a regime in words; 0 of those 17 pages cite a frozen provision id.
Frameworks mapped but not in the corpus
- NIST AI RMF 1.0: 12 axis pointers, 0 frozen provisions, routing record us-nist-ai-rmf-1. /crosswalks/
- ISO/IEC 42001:2023: 0 axis pointers, 0 frozen provisions. /crosswalks/
- OWASP Top 10 for Agentic Applications (2026): 11 axis pointers, 0 frozen provisions. /crosswalks/owasp-asi/
Capsule adapters
| Batch | Capsules | Bind a provision | OWASP items reached |
|---|---|---|---|
| a2a_card | 33 | 0 | ASI03 PARTIAL, ASI07 DIRECT |
| contract_parity | 9148 | 0 | ASI03 PARTIAL, ASI04 PARTIAL, ASI07 PARTIAL, MCP03:2025 PARTIAL, MCP04:2025 PARTIAL, MCP07:2025 PARTIAL |
| cross_ledger | 353 | 0 | none |
| mill_cross_runtime-5ae00c1f4c2e | 14 | 0 | none |
| mill_cross_runtime-78226433e9e4 | 140 | 0 | none |
| public_signals | 118 | 0 | none |
| self_parity | 138 | 0 | none |
| tool_drift | 3240 | 0 | ASI04 PARTIAL, MCP02:2025 PARTIAL, MCP03:2025 PARTIAL |
The capsule adapters measure protocol and ledger claims. None of them tests a provision in the frozen corpus; the ones that reach a published security list are mapped on the OWASP crosswalk.
The gaps, plainly
- No provisions from 16 of the 17 jurisdictions listed: United Kingdom, United States (federal, incl. NIST), California, Colorado, Texas, Illinois, Canada, China, Japan, Singapore, South Korea, India, Brazil, Australia, South Africa, Council of Europe treaty parties.
- 4 of the 6 corpus instruments have no authority routing record: Cyber Resilience Act, DORA, NIS2, CSRD.
- No obligation register, no applicability rules and no watcher exist for any instrument.
- Provisions with a deterministic predicate: 1. Provisions that are hashes nothing tests: 404 of 417.
- The source text behind the provision hashes was not recovered, so a hash cannot yet be regenerated from text.
How a rule is modelled
Each level, and what the data holds at it today.
- 1. Authority
- Who makes or enforces the rule. Held as a source-and-routing record; a record is not a relationship with the authority and not a live regulator API.
- 2. Instrument
- The law, framework or standard, named by its official identifier (CELEX for EU acts).
- 3. Version
- Which text of the instrument was frozen. Today the manifest pins each provision by a SHA-256 of normalised text; the source bytes that produced those hashes were not recovered.
- 4. Provision
- One addressable unit of the instrument (an article, or an id the manifest assigns), with its frozen hash.
- 5. Obligation
- A single duty cut out of a provision, with its conditions. No obligation register exists yet.
- 6. Applicability
- Whether the obligation applies to a given system. Not determined here: every authority record says applicability needs review by the party concerned.
- 7. Crosswalks
- Rows elsewhere that map this instrument to another framework or to a measured axis.
- 8. Evidence requirement
- What bytes a test needs to see. Stated per predicate below.
- 9. Test / profile
- A deterministic predicate (PREDICATE) or a measured axis that points to the provision (RELATED_MEASURE).
- 10. Watcher
- Something that polls the authority and expires the mapping when the text changes. Read from the manifest's own watcher field.
The predicate implemented today
Article 50 marking evidence (32024R1689:50)
Paragraph 2 only: whether a generated file carries a machine-readable mark that named methods detect, at the time of the check.
Deterministic: C2PA manifest-store presence, assertion hashes, the c2pa.hash.data hard binding and the COSE_Sign1 claim signature under the leaf's own key; IPTC DigitalSourceType read from XMP.
Not measured: C2PA chain trust (no trust list is bundled), SynthID and other keyed watermarks, the open-source DWT-DCT detector and text watermarks. The response lists each with its reason.
Evidence it needs: The file's bytes (an https URL we fetch, or the bytes posted), up to 20 MiB, or a C2PA manifest on its own.
Results read "marking not detected by method X"; never absent, compliant or non-compliant.
The check quotes the verbatim Article 50(2) text with its SHA-256. It does not yet cite the frozen provision id.
How to have a claim measured today
These routes exist and are free. There is no form beyond them.
Look up an endpoint
Paste an MCP server, A2A agent or x402 endpoint URL at /verify-server/. It shows every published capsule about it and re-checks each one in your browser.
/verify-server/ · free, no account. It only shows what the public censuses already measured. It does not start a new measurement.
Be in a public registry the censuses read
The census capsules read public listings: MCP servers in the public registries the MCP census reads (contract parity, tool drift) and signed agent cards listed in the a2aregistry census. A listed endpoint is read when that census next runs.
/measurement-capsules/ · free, permissionless. No date is promised, and being measured is not being endorsed.
Article 50(2) marking check on one file
GET /api/art50/marking-evidence?url=<https URL>&preview=1 runs the deterministic marking check on the file and returns the result unsigned.
/api/art50/marking-evidence?url=https://example.com/image.png&preview=1 · free preview, same measurement as the signed pack. Not a legal opinion on Article 50. A signed pack is a separate commissioned route.
Agents: the MCP server
POST https://councilof.ai/mcp, tools measurement_index, verify_capsule and server_evidence.
/measurement-capsules/ · free, no key. Read and verify only.
Contest a published result
The dispute route re-runs the frozen instrument and publishes the re-run as a new signed record.
/dispute/ · free. An allegation is measured, not argued.
Not open today
- POST /api/evidence-intake, which would queue a candidate record for operator review. It returns WRITER_AUTH_UNAVAILABLE: no public writer is configured, so nothing submitted there is stored.
- A form to submit an arbitrary written claim for measurement. None exists. A claim is measured today only when it is one of the kinds an instrument above reads.
The article 50 marking evidence check is the one route that measures a claim against a provision today: /api/art50/marking-evidence?url=https://example.com/image.png&preview=1.
How to verify
- Recompute the capsule id: SHA-256 of the capsule's canonical JSON (keys sorted, no whitespace, UTF-8) without its
capsule_id. - Recompute the batch Merkle root from its published leaves (RFC 6962, leaves sorted), or check an audit path.
- Check the Ed25519 signature on the batch or index payload against the key in csoai.org/.well-known/did.json.
- Check the OpenTimestamps proof with
ots verify.
Or let a tool do it: verify a server in the browser, or verify_capsule over MCP at POST https://councilof.ai/mcp.
The same record as a W3C Verifiable Credential
For ecosystems that consume Verifiable Credentials, a capsule can be exported as a VCDM 2.0 credential. The example at /mechanism/vc.json is capsule 5a3699653fc5966e… (measurement.self_parity, CONSISTENT). It carries the capsule itself, its audit path to the batch root, the board-signed payload and the verification method did:web:csoai.org#board-attestation-1, and SRI digests of the batch files.
The credential is an unsigned view. It has no proof of its own: our signer signs one canonical JSON object, which is neither a Data Integrity proof nor a JWS or COSE envelope, and we did not add a second signer to make it look otherwise. The signature to check is the batch signature it carries. The capsule is the source of truth; the credential is a view of it. On 27 September 2026 it passed Digital Bazaar vc 7.3.0 _checkCredential and a safe-mode jsonld 9.0.0 expansion, and verifyCredential reports no proof to verify, as it should. The transform and its tests are scripts/mechanism/capsule-vc.mjs.
Capsule schema and the standard
- Capsule
csoai.measurement-capsule/0.2, batchcsoai.measurement-capsule-batch/0.2, daily indexcsoai.measurement-capsule-index/0.3(hash-chained). Data: /measurement-capsules/latest.json. - IETF Internet-Draft draft-templeman-scitt-measurement-capsule-00, an individual submission. It is not an IETF standard and has no working-group status.
- Proposed, not yet emitted: capsule
0.3adds one optional field,provisions, a list of{provision_id, provision_sha256, corpus_root, relation}with relationPREDICATEorRELEVANT_TO, each pinned to this manifest. A capsule without it stays byte-for-byte a 0.2 capsule. The verifier already accepts both.
What this is not
- Not certification. No mark, seal or label is issued, and a record is never described as one.
- Not a compliance determination. Whether anyone complies with a law is for the competent authority.
- Not an endorsement of any system measured, and not a ranking.
- Not a partnership. Naming a law, a framework, a registry or a standard body here implies no relationship with it.
- Independent: the party measured never holds the pen. Who runs us and who holds the keys is on independence.
Corrections
A wrong row is corrected in the source file and the producer re-run; the change is recorded in the corrections ledger. To contest a published result, use the dispute route. Or email nicholas@csoai.org.
Edited 2026-09-27. Generated from scripts/mechanism/coverage.source.json by scripts/mechanism/build-coverage.mjs (source SHA-256 96dca499a4fb466c…). See also methodology and crosswalks.