docs(profile): stamp the AI Act dates, name one standards home, lead with the self-attestation gap - #28
Conversation
…with the self-attestation gap Seven corrections, five factual and two positioning. The EU AI Act mappings were sold as if they bind today. Under the current provisional timeline the Digital Omnibus defers Annex III to around 2 December 2027 and Annex I to around August 2028; trace-spec already carried the corrected line and nothing else did. The mappings are unchanged and still correct as mappings, so they stay, each stamped with the date it applies from, and the compliance argument now leads with DORA and HIPAA, which are in force today. Article 50 (transparency duties, in force 2 August 2026) was absent from every document in the org. It is the only AI Act deadline anyone can be held to in 2026 and it is provenance-shaped. Added to the Standards Coverage table as what it is: a gap in agent-manifest, adjacency only in TRACE (C2PA references the Trust Record, no normative profile), and real coverage in AGT's agent-os transparency module for Art. 50(1) and 50(3). Three versions of the standards-home story were in circulation and they disagreed. TRACE now names one path, AAIF under the Linux Foundation, and says plainly that the submission has not been filed. The leak-probability table assumed independent failures. A fleet shares a model, a prompt, a tool manifest and a policy bundle, so the 63% is an overestimate and the tail is worse than it reads. Stated rather than dropped. The invited-partner list named nine organizations that had not confirmed. TII is the only confirmed founding partner, so it is the only one named. The opening now leads with the thing no funded control plane can do: its log is written by the thing the log describes. The eBook mapping stays as a section where it earns its place rather than framing the whole page. Also corrected: agent-manifest v0.7.0 to v0.10.0, TRACE SDK v0.5.1 to v0.6.0, trace-tests v0.4.0 to v0.4.1, and the one-pager's claim that AAIF is considering AGT for standardization, which the 07-28 onboarding call closed out. AGT is Microsoft-owned; where it lands is Microsoft's to announce. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Correction pushed. The first commit named AAIF as TRACE's standards home. That is wrong, and the multiple-choice I put to Imran did not include the live option, so the answer came from a bad menu. TRACE is being formed as "TRACE Specification, a Series of LF Projects, LLC" — its own LF series, not co-hosted under CoSAI and not under the LF entity hosting MCP. Formation is in progress with the LF standards team, and agentrust-io/trace-spec#127 (open) brings Three places fixed: the badge, the Principles bullet, and the one-pager's closing line. The point of the original item stands — one path named, no evaluation language — only the path is now the correct one. Still stale and not in this PR, since it is normative text in another repo: |
Response-plan list 1, the org profile items. Line references are against
mainas of 7 Aug 2026.Factual corrections
EU AI Act dates (P0). Every mapping outside the TRACE spec read as if the high-risk obligations bind today. Under the current provisional timeline the Digital Omnibus defers Annex III to around 2 December 2027 and Annex I to around August 2028. The mappings themselves are still correct, so they stay; each now carries the date it applies from, and a note under the conformance-level table explains the deferral and points at the official timeline. The compliance argument leads with DORA and HIPAA, which are in force.
Article 50 (P0). In force since 2 August 2026, absent from every document in the org, and the only AI Act deadline anyone can be held to this year. Added to Standards Coverage honestly rather than as a claim: a gap in agent-manifest, adjacency only in TRACE (a C2PA manifest on the output may reference the Trust Record; no normative profile), and real coverage in AGT for Art. 50(1) and 50(3) via
agent_os/transparency.py.Standards home (P0). Three versions were in circulation. The public page now names one path, AAIF under the Linux Foundation, where OPAQUE is a member, and states plainly that the submission has not been filed. The strategy-tree duplicate is being retired separately.
Leak-probability table (P1).
1 - (1 - 0.01)^nassumes independent failures. A fleet shares a model, a system prompt, a tool manifest and usually one policy bundle. Kept the table and stated the assumption: the 63% at a hundred agents is an overestimate, the tail is worse than it reads, and the point survives either way.Invited-partner list (P2). Nine named organizations, one confirmed. Any of the nine could be asked and say no. Now: TII named, co-editor seats stated as open, plus the line that we name partners once they confirm rather than once we ask.
Positioning
Top of the README (P1). It was structured as a map onto the Zero-Trust for AI Agents eBook. That was the right frame in June; a buyer in August is comparing us to a funded cohort of runtime control planes. The opening now leads with the thing none of them can do anything about: the control plane writes the log that describes its own behavior, and buying a second one does not help. The eBook mapping stays as a section further down, reframed as a checklist to be measured against rather than the organizing principle.
Picked up along the way
agent-manifestv0.7.0 → v0.10.0, TRACE SDK v0.5.1 → v0.6.0,trace-testsv0.4.0 → v0.4.1 in the project table. All three were behind the published releases.technical-one-pager.mdsaid AGT is "now being considered by AAIF for standardization". The 07-28 onboarding call closed that out. Replaced with the accurate and safer line: AGT is Microsoft-owned MIT, and where it lands is Microsoft's to announce.Not touched
The
trace-registrydisclosure at README:165 stays exactly as written. It is the honest statement of a real gap and it should not move until the registry is public.🤖 Generated with Claude Code