Method

The open measurement mechanism

One route for anyone, anywhere, to have a public claim measured against published rules and to get back a signed record that a stranger can check without trusting us. It is open: the rules, the code, the records and the verifiers are public, and verification is free. This page says how it works, and how much of the world's rulebook it covers today, counted from the data.

  • This report counts what the published data holds. Every number in it is derived by scripts/mechanism/build-coverage.mjs from committed files; none is typed.
  • A provision marked PREDICATE has a deterministic check whose result a stranger can re-run. It is a measurement of one observable the provision names, not a finding that anyone complies with or breaches it.
  • A provision marked RELATED_MEASURE is one that a measured board axis points to as relevant. The pointer is informative: the axis does not test the provision.
  • HASH_ONLY means the provision is in the frozen manifest as an identifier and a SHA-256, and nothing tests it. The source text bytes behind those hashes were not recovered, so the manifest is not an inspectable legal corpus.
  • Measurement, not certification. No compliance label, endorsement or regulator relationship is stated or implied.

Five steps

  1. 1. A declared claim

    Something a party has said in public about its own system: a version it serves, a key that signs its agent card, a mark on a generated file, the supply of a token on a ledger. The claim is recorded as declared, next to what we observe.

  2. 2. Mapped to provision ids in the frozen corpus

    The corpus is a manifest of 417 provision ids from 6 instruments, each pinned by the SHA-256 of its frozen text, under one root that recomputes (37e2e10d53feaa9e…). Today 0 of 13184 published capsules carry a provision id; the optional field that lets them is proposed below.

  3. 3. A deterministic predicate

    A check that returns the same answer for anyone who runs it on the same bytes: no model grades, no vote. How a provision is cut into one is on statute to predicate. Provisions in the corpus with one implemented today: 1.

  4. 4. A signed capsule

    One small JSON record: declared, observed, the difference, digests of the evidence, a measurement state and its limitations. Capsules are batched under an RFC 6962 Merkle root and the batch is signed with Ed25519 under did:web:csoai.org. See measurement capsules.

  5. 5. The daily index, verified free

    Each day's index binds every batch, chains to the previous day, is signed, and is stamped with OpenTimestamps. Anyone can recompute a capsule's id, its path to the root and the signature, in the browser or over MCP, with no account.

Coverage, counted

Read from /interop/frozen-provision-hashes.json (SHA-256 e43c9bd52adeeda9…) and the files it is joined to. The same numbers are in /mechanism/coverage.json.

WhatCountRead from
provision hashes417public/interop/frozen-provision-hashes.json · anchors
authority-routing records17public/interop/regulatory-inventory.json · authority_adapters.length
crosswalk assets25public/interop/regulatory-inventory.json · crosswalk_assets.length
instruments with provisions in the manifest6public/interop/frozen-provision-hashes.json · distinct CELEX ids

State of the manifest: HASH_MANIFEST_VERIFIED_SOURCE_BYTES_UNRESOLVED, frozen 2026-08-12. Source text bytes: NOT_RECOVERED. Watcher: NOT BUILT — local corpus only; no authority is polled. The public manifest proves the 417 identifiers, their frozen hashes and their aggregate root. It does not include the exact normalized source-text bytes needed to regenerate each per-provision hash, and no authority watcher was active when it was frozen.

By instrument

InstrumentProvisionsPredicateRelated measureHash onlyAuthority record
EU AI ActRegulation (EU) 2024/1689 · CELEX 32024R1689126112113eu-ai-act-2024-1689
GDPRRegulation (EU) 2016/679 · CELEX 32016R0679990099eu-gdpr-2016-679
Cyber Resilience ActRegulation (EU) 2024/2847 · CELEX 32024R2847710071none
DORARegulation (EU) 2022/2554 · CELEX 32022R2554640064none
NIS2Directive (EU) 2022/2555 · CELEX 32022L2555460046none
CSRDDirective (EU) 2022/2464 · CELEX 32022L2464110011none

All 6 instruments are EU acts. Where an instrument's manifest ids include negative numbers (the AI Act has 13 of them), the manifest does not say what they denote, so this report does not guess.

Provisions anything points to

Provision idStatusWhat points to it
32024R1689:5Related measureaxes: care, jail, safety
32024R1689:6Related measureaxes: governance
32024R1689:8Related measureaxes: safety
32024R1689:9Related measureaxes: governance, safety
32024R1689:10Related measureaxes: safety
32024R1689:11Related measureaxes: conformance, safety
32024R1689:12Related measureaxes: art5-safeguard, care, continuity, detector-interop, governance, provenance, safety
32024R1689:13Related measureaxes: conformance, safety
32024R1689:14Related measureaxes: safety, swarm
32024R1689:15Related measureaxes: continuity, jail, safety
32024R1689:50Predicatecheck: art50-marking-evidence; axes: provenance
32024R1689:53Related measureaxes: openness
32024R1689:55Related measureaxes: continuity

Totals over all 417: 1 predicate · 12 related measure · 0 crosswalk only · 404 hash only. Pointers name articles in prose; the report resolves "Article N" to the manifest id. It cannot resolve Annex III, Annex IV, which the pointers also name.

By jurisdiction

JurisdictionStateFrozen provisionsRouting recordsCrosswalk rowsProse pages
European Union / EEAIn the frozen corpus417eu-ai-act-2024-1689, eu-gpai-code-2025, eu-gdpr-2016-6797/eu-ai-act/
United KingdomRouting record only0uk-data-protection, uk-consumer-protection5/uk-ai-regulation/, /compliance/uk-ai-bill/, /frameworks/uk-ai-bill/
United States (federal, incl. NIST)Routing record only0us-ftc-act-section-5, us-nist-ai-rmf-10/us-ai-regulation/
CaliforniaProse pages only0none0/california-ai-law/
ColoradoProse pages only0none0/colorado-ai-act/
TexasProse pages only0none0/texas-ai-act/
IllinoisCrosswalk rows only0none4none
CanadaRouting record only0canada-pipeda0/canada-aida/, /compliance/canada-ai-act/, /frameworks/canada-ai-act/
ChinaRouting record only0china-generative-ai-interim-measures4/china-ai-law/, /compliance/tc260/
JapanRouting record only0japan-ai-guidelines-business-10none
SingaporeRouting record only0singapore-agentic-ai-mgf0/singapore-ai-governance/
South KoreaRouting record only0korea-ai-basic-act0/south-korea-ai-act/
IndiaRouting record only0india-ai-governance-guidelines0none
BrazilRouting record only0brazil-lgpd0none
AustraliaRouting record only0australia-privacy-act0/compliance/australia-ai-governance/, /frameworks/australia-ai/
South AfricaRouting record only0south-africa-popia0none
Council of Europe treaty partiesRouting record only0coe-ai-framework-convention-2250none

A routing record names an authority and where its rules are published; it holds no provisions and confers no authority. The prose pages explain a regime in words; 0 of those 17 pages cite a frozen provision id.

Frameworks mapped but not in the corpus

  • NIST AI RMF 1.0: 12 axis pointers, 0 frozen provisions, routing record us-nist-ai-rmf-1. /crosswalks/
  • ISO/IEC 42001:2023: 0 axis pointers, 0 frozen provisions. /crosswalks/
  • OWASP Top 10 for Agentic Applications (2026): 11 axis pointers, 0 frozen provisions. /crosswalks/owasp-asi/

Capsule adapters

BatchCapsulesBind a provisionOWASP items reached
a2a_card330ASI03 PARTIAL, ASI07 DIRECT
contract_parity91480ASI03 PARTIAL, ASI04 PARTIAL, ASI07 PARTIAL, MCP03:2025 PARTIAL, MCP04:2025 PARTIAL, MCP07:2025 PARTIAL
cross_ledger3530none
mill_cross_runtime-5ae00c1f4c2e140none
mill_cross_runtime-78226433e9e41400none
public_signals1180none
self_parity1380none
tool_drift32400ASI04 PARTIAL, MCP02:2025 PARTIAL, MCP03:2025 PARTIAL

The capsule adapters measure protocol and ledger claims. None of them tests a provision in the frozen corpus; the ones that reach a published security list are mapped on the OWASP crosswalk.

The gaps, plainly

  • No provisions from 16 of the 17 jurisdictions listed: United Kingdom, United States (federal, incl. NIST), California, Colorado, Texas, Illinois, Canada, China, Japan, Singapore, South Korea, India, Brazil, Australia, South Africa, Council of Europe treaty parties.
  • 4 of the 6 corpus instruments have no authority routing record: Cyber Resilience Act, DORA, NIS2, CSRD.
  • No obligation register, no applicability rules and no watcher exist for any instrument.
  • Provisions with a deterministic predicate: 1. Provisions that are hashes nothing tests: 404 of 417.
  • The source text behind the provision hashes was not recovered, so a hash cannot yet be regenerated from text.

How a rule is modelled

Each level, and what the data holds at it today.

1. Authority
Who makes or enforces the rule. Held as a source-and-routing record; a record is not a relationship with the authority and not a live regulator API.
2. Instrument
The law, framework or standard, named by its official identifier (CELEX for EU acts).
3. Version
Which text of the instrument was frozen. Today the manifest pins each provision by a SHA-256 of normalised text; the source bytes that produced those hashes were not recovered.
4. Provision
One addressable unit of the instrument (an article, or an id the manifest assigns), with its frozen hash.
5. Obligation
A single duty cut out of a provision, with its conditions. No obligation register exists yet.
6. Applicability
Whether the obligation applies to a given system. Not determined here: every authority record says applicability needs review by the party concerned.
7. Crosswalks
Rows elsewhere that map this instrument to another framework or to a measured axis.
8. Evidence requirement
What bytes a test needs to see. Stated per predicate below.
9. Test / profile
A deterministic predicate (PREDICATE) or a measured axis that points to the provision (RELATED_MEASURE).
10. Watcher
Something that polls the authority and expires the mapping when the text changes. Read from the manifest's own watcher field.

The predicate implemented today

Article 50 marking evidence (32024R1689:50)

Paragraph 2 only: whether a generated file carries a machine-readable mark that named methods detect, at the time of the check.

Deterministic: C2PA manifest-store presence, assertion hashes, the c2pa.hash.data hard binding and the COSE_Sign1 claim signature under the leaf's own key; IPTC DigitalSourceType read from XMP.

Not measured: C2PA chain trust (no trust list is bundled), SynthID and other keyed watermarks, the open-source DWT-DCT detector and text watermarks. The response lists each with its reason.

Evidence it needs: The file's bytes (an https URL we fetch, or the bytes posted), up to 20 MiB, or a C2PA manifest on its own.

Results read "marking not detected by method X"; never absent, compliant or non-compliant.

The check quotes the verbatim Article 50(2) text with its SHA-256. It does not yet cite the frozen provision id.

How to have a claim measured today

These routes exist and are free. There is no form beyond them.

  • Look up an endpoint

    Paste an MCP server, A2A agent or x402 endpoint URL at /verify-server/. It shows every published capsule about it and re-checks each one in your browser.

    /verify-server/ · free, no account. It only shows what the public censuses already measured. It does not start a new measurement.

  • Be in a public registry the censuses read

    The census capsules read public listings: MCP servers in the public registries the MCP census reads (contract parity, tool drift) and signed agent cards listed in the a2aregistry census. A listed endpoint is read when that census next runs.

    /measurement-capsules/ · free, permissionless. No date is promised, and being measured is not being endorsed.

  • Article 50(2) marking check on one file

    GET /api/art50/marking-evidence?url=<https URL>&preview=1 runs the deterministic marking check on the file and returns the result unsigned.

    /api/art50/marking-evidence?url=https://example.com/image.png&preview=1 · free preview, same measurement as the signed pack. Not a legal opinion on Article 50. A signed pack is a separate commissioned route.

  • Agents: the MCP server

    POST https://councilof.ai/mcp, tools measurement_index, verify_capsule and server_evidence.

    /measurement-capsules/ · free, no key. Read and verify only.

  • Contest a published result

    The dispute route re-runs the frozen instrument and publishes the re-run as a new signed record.

    /dispute/ · free. An allegation is measured, not argued.

Not open today

  • POST /api/evidence-intake, which would queue a candidate record for operator review. It returns WRITER_AUTH_UNAVAILABLE: no public writer is configured, so nothing submitted there is stored.
  • A form to submit an arbitrary written claim for measurement. None exists. A claim is measured today only when it is one of the kinds an instrument above reads.

The article 50 marking evidence check is the one route that measures a claim against a provision today: /api/art50/marking-evidence?url=https://example.com/image.png&preview=1.

How to verify

  1. Recompute the capsule id: SHA-256 of the capsule's canonical JSON (keys sorted, no whitespace, UTF-8) without its capsule_id.
  2. Recompute the batch Merkle root from its published leaves (RFC 6962, leaves sorted), or check an audit path.
  3. Check the Ed25519 signature on the batch or index payload against the key in csoai.org/.well-known/did.json.
  4. Check the OpenTimestamps proof with ots verify.

Or let a tool do it: verify a server in the browser, or verify_capsule over MCP at POST https://councilof.ai/mcp.

The same record as a W3C Verifiable Credential

For ecosystems that consume Verifiable Credentials, a capsule can be exported as a VCDM 2.0 credential. The example at /mechanism/vc.json is capsule 5a3699653fc5966e… (measurement.self_parity, CONSISTENT). It carries the capsule itself, its audit path to the batch root, the board-signed payload and the verification method did:web:csoai.org#board-attestation-1, and SRI digests of the batch files.

The credential is an unsigned view. It has no proof of its own: our signer signs one canonical JSON object, which is neither a Data Integrity proof nor a JWS or COSE envelope, and we did not add a second signer to make it look otherwise. The signature to check is the batch signature it carries. The capsule is the source of truth; the credential is a view of it. On 27 September 2026 it passed Digital Bazaar vc 7.3.0 _checkCredential and a safe-mode jsonld 9.0.0 expansion, and verifyCredential reports no proof to verify, as it should. The transform and its tests are scripts/mechanism/capsule-vc.mjs.

Capsule schema and the standard

  • Capsule csoai.measurement-capsule/0.2, batch csoai.measurement-capsule-batch/0.2, daily index csoai.measurement-capsule-index/0.3 (hash-chained). Data: /measurement-capsules/latest.json.
  • IETF Internet-Draft draft-templeman-scitt-measurement-capsule-00, an individual submission. It is not an IETF standard and has no working-group status.
  • Proposed, not yet emitted: capsule 0.3 adds one optional field, provisions, a list of {provision_id, provision_sha256, corpus_root, relation} with relation PREDICATE or RELEVANT_TO, each pinned to this manifest. A capsule without it stays byte-for-byte a 0.2 capsule. The verifier already accepts both.

What this is not

  • Not certification. No mark, seal or label is issued, and a record is never described as one.
  • Not a compliance determination. Whether anyone complies with a law is for the competent authority.
  • Not an endorsement of any system measured, and not a ranking.
  • Not a partnership. Naming a law, a framework, a registry or a standard body here implies no relationship with it.
  • Independent: the party measured never holds the pen. Who runs us and who holds the keys is on independence.

Corrections

A wrong row is corrected in the source file and the producer re-run; the change is recorded in the corrections ledger. To contest a published result, use the dispute route. Or email nicholas@csoai.org.

Edited 2026-09-27. Generated from scripts/mechanism/coverage.source.json by scripts/mechanism/build-coverage.mjs (source SHA-256 96dca499a4fb466c…). See also methodology and crosswalks.