# Every primitive here mapped to the frame it belongs to, and what each one fails

slug: attested-finding-conformance-map · https://miscsubjects.com/a/attested-finding-conformance-map · category: governance · tags: conformance, evidence-law, standards, ancestry, eu-ai-act · updated 2026-07-30T05:19:53.670Z

Nothing in this build is a new idea. The arrangement is new; every part has an ancestor with a standard, a literature and a professional body behind it. This page maps each field to the frame it belongs to, and says in each row what is **not** satisfied.

The reason to write it: a corpus that defends its own vocabulary with its own pages gives a cold reader nowhere familiar to stand. Roughly four hundred of this site's articles are about its own protocol. Binding each primitive to an external recognised frame is the way out of that, and it converts a novel unverified claim into a recognised requirement met with a receipt.

## Evidence law: the findings are 902(14)-shaped by construction

| frame | the field here | what satisfies it | what does NOT |
|---|---|---|---|
| **FRE 902(13)** — certified record of a regulularly conducted activity | the invocation receipt | every invocation writes id, timestamp, actor, object, input and output fingerprints and provider status, automatically, as a regular activity of the system | no custodian declaration has been drafted or signed |
| **FRE 902(14)** — certified data copied from an electronic device, authenticated by hash | artifact SHA-256, record SHA-256, rule-set hash, chain head, anchor id | hashes are published before deliberation and recomputable by anyone; the offline verifier rehashes every object | the qualified-person certification that makes the self-authentication operative is not written |
| **FRCP 37(e)** — failure to preserve ESI | RECORDS_ABSENT | absence is a positive assertion made before anyone knew there would be a dispute, naming the records a competent reviewer would have expected | nothing here proves the absent record ever existed |
| **eIDAS Art. 41** — qualified electronic timestamp | the anchor packet | drand + Bitcoin give cryptographic anteriority | a qualified timestamp carries a legal presumption of time and integrity, and none is obtained; this is the largest missing item in this table |

## Audit standards: RECORDS_ABSENT is a mechanised scope limitation

| frame | the field here | what satisfies it | what does NOT |
|---|---|---|---|
| **ISA 500** — sufficient appropriate audit evidence | verdict tiers and the span obligation | a finding must quote the shortest verbatim span that carries it, or return SPAN: NONE | no evidence-sufficiency threshold is defined per rule set |
| **ISA 705** — modified opinions arising from scope limitation | RECORDS_ABSENT + CANNOT_CONCLUDE | the instrument's analogue of a qualified opinion: name what was unavailable and decline to conclude on it | there is no equivalent of an adverse opinion, and no materiality concept |
| **RADPEER**-style imaging peer review | the panel plus the recorded adversary | blinded independent readings with disagreement recorded rather than resolved by seniority | no human reader has participated in any panel |

## EU AI Act: the clause-by-clause table, with what is not satisfied

Article 12 and Article 14 were supplied verbatim to a panel under the external-statutory rule set, hashed at `3e3bcd8d47d14c159f9d9303438b0839…` before the run. The panel's verdict was **CANNOT_CONCLUDE**, unanimously across conforming channels, because applicability turns on whether this system is a high-risk AI system under Article 6 and Annex III, and neither was supplied. That is the correct answer and it is the demonstration: the mapping below is the operator's own claim, not the panel's finding, and the two are kept apart on purpose.

| provision | what it requires | the surface here | what is NOT satisfied |
|---|---|---|---|
| **Art. 12(1)** automatic recording of events over the lifetime | logs recorded automatically | every invocation is receipted automatically at `/api/dispatch?receipt=<id>` and publicly at `/receipt/<id>`; 174,309 recorded | "lifetime of the system" is not defined here, and pre-2026-06 history was backfilled rather than recorded live |
| **Art. 12(2)(a)** events relevant to identifying risk or substantial modification | refusals, provider failures, regrades | refusals and provider failures are receipted; a rule-set amendment produces a new hash; 124 historical rows were re-graded and the correction published | no risk-classification taxonomy maps an event to Art. 79(1) risk |
| **Art. 12(2)(b)** facilitating post-market monitoring | the probe row | known-answer probes run through the identical path produce four rates per model | the probe is not scheduled continuously; it has been run once |
| **Art. 12(3)(a)** period of each use, start and end | trace timestamps | first and last event of a trace_id bound the use | a single-invocation use has one timestamp, not a start and an end |
| **Art. 12(3)(b)–(c)** reference database and matching input data | the identity-match rule set | published, and written to return CANNOT_CONCLUDE on resemblance | no biometric identification capability exists here, so these paragraphs have nothing to bind to |
| **Art. 14(4)(a)** understand capacities and limitations | the probe report | the panel's measured false-confidence rate is published where a reviewer sees it | no interface presents the rate at the point of decision |
| **Art. 14(4)(b)** awareness of automation bias | the measured rate again, plus the published false-confidence event | a live case where a channel named the absence of a marker and concluded anyway is published | nothing in the flow forces a reviewer to acknowledge it |
| **Art. 14(4)(d)** decide not to use, disregard, override or reverse | the gate and the receipts | the finding is advisory; the dispatched notification is a separate receipted act; a refusal is itself receipted | no override event has ever been recorded, because no human has been in the loop |
| **Art. 14(4)(e)** intervene or stop | capability enable/disable and the approval gate | a row is disabled by one field; 227 of 887 enabled rows require approval before execution | there is no single stop control over an in-flight assembly |
| **Art. 14(5)** two natural persons verify a biometric identification | `ADJUDICATE_HUMAN_REVIEW` with BLINDED failing closed | the row exists and makes blinding a recorded boolean | **never invoked.** No named human has returned a finding. This is the clearest unmet item in the table |

## Risk-management frameworks

| frame | the surface here | what is NOT satisfied |
|---|---|---|
| **NIST AI RMF — MEASURE** | four rates per model per rule set on a stratified suite published at a hash | fourteen items is too small to characterise anything beyond this suite |
| **NIST AI RMF — MANAGE** | the deterministic gate, the escalation path, the sensitivity regrade on six capability rows | no residual-risk statement, and the escalation terminates at a role rather than a person |
| **ISO/IEC 42001** | rule sets as versioned objects, an objections ledger, a change record with hashes | no management-system documentation, no internal audit programme, no certification |
| **IEC 61508 common-cause failure** | verdict correlation by training family, measured at 0.893 same-family against 0.714 cross-family, and a gate that counts families rather than seats | no systematic-capability argument, no proof-test interval |

## The intellectual ancestry, named

| ancestor | the correspondence | what is new here |
|---|---|---|
| **Toulmin (1958)** — claim, grounds, warrant, qualifier, rebuttal | claim → the assertion; grounds → the quoted span; warrant → the rule-set clause; qualifier → tier and verdict; rebuttal → the published falsifier and the recorded adversary | the warrant is content-addressed, so it cannot be substituted after the objection — sixty years of argument about warrant identification, settled by a hash |
| **Preregistration** | the rule set is pinned as bytes and anchored before the artifact is judged | this is preregistration applied to machine judgment, and it has no analogue in AI evaluation |
| **Adversarial collaboration** | two parties pre-commit to the rules that would settle a disagreement | the machinery operationalises it; **it has not been run with a real second party**, which is the honest state of that claim |
| **Chow's reject option; conformal risk control** | abstention in exchange for a distribution-free error bound | the bound is not computed; what exists is a measured escalation behaviour |
| **Knight & Leveson (1986)** | independently developed programs to one spec fail together | the same result, sharper, because channels share training data |
| **Double reading with arbitration** in population screening | independent readers, disagreement to arbitration, measured sensitivity gain | the readers are models and the arbitration trigger is a published deterministic function |
| **Merkle trees; OpenTimestamps** | hash-linked history with external inclusion proofs | the chain is sealed and anchored; **no OTS proof exists**, and `chain_inclusion` still reads NOT_YET_PROVEN_INCLUDED |
| **Macaroons** | caveat-bearing, attenuable, audience-bound capabilities | witness tokens are audience-bound and fail closed when forwarded |
| **HATEOAS** | representations carry their own next actions | every capability row publishes its own read, patch, invoke and skill routes |

What is claimed as contribution, precisely: not any of these frames. The mechanisation of absence as a mandatory field whose omission voids a finding; the content-addressing of the warrant; the derivation-level divergence check as the gate trigger; and the arrangement of all of it behind one deterministic function with a public error rate.

## Sources

1. The Article 12 assembly: unanimous CANNOT_CONCLUDE, escalated anyway — https://miscsubjects.com/receipt/inv_ivezpvux57
2. The human-review row whose BLINDED field fails closed — https://miscsubjects.com/api/directory/ADJUDICATE_HUMAN_REVIEW
3. The anchor packet: cryptographic anteriority, no legal presumption — https://miscsubjects.com/api/anchor/3be5071eb3035ca29093c6713646bbe21bdca6cce262fc7f7eb64080c04e61fe

