Audit the claim before adopting the policy

Evidence and limits share the same surface.

Every canonical row keeps its statement class, bounded text, evidence and boundary IDs, scope, limitation, prohibited overclaim, currentness rule, and defeat or reopen condition.

31 claim rows16 supported with limits15 enforced exclusions69 source notes166 frozen custody paths
Jump within the evidence register

Method boundary

The register preserves estimands instead of averaging them away.

Hosted evaluations, pinned checkpoints, model-only benchmarks, pooled-access studies, single-model causal human uplift, observed outcomes, law, guidance, forecasts, proposals, and moral commitments remain different record types.

Record

A dated source state, exact locator, local path, hash, and stated source limit.

Evaluation

A result tied to its object, access condition, task, population, comparison, method, uncertainty, and estimand.

Interpretation or forecast

A labeled inference or conditional future—not a silent upgrade of the underlying evidence.

Proposal and consequence

A contestable institutional choice with authority, burden, protected uses, review, appeal, metrics, and defeat conditions.

Demonstrated assistance can inform policy without being renamed a demonstrated catastrophe. A proposal can respond to uncertainty without being described as existing law or proven control effectiveness.

Positive but bounded

Sixteen supported rows

Open each row to inspect its exact evidence IDs, scope, limit, prohibited overclaim, and route into the paper.

P4-CAN-01
supported with limits
The preserved direct JSON response to the exact Kimi K3 full-commit request reported commit 9f62e4e9fffbd0a83ddd60e1c209d828994b3569, private=false, gated=false, and the recorded safetensors totals; the endpoint response as a whole remained mutable.

Statement class

observed fact · affirmed_bounded

Scope

Exact captured Hugging Face repository request and response; repository metadata, not a legal jurisdiction.

Limit. The commit pin stabilizes the requested revision identity and observed core fields, not mutable endpoint metadata, file completeness, architecture-level parameter count, capability, evaluator identity, license enforceability, or identity with any hosted evaluation.

Prohibited overclaim

Must not call the response immutable, infer capability from repository metadata, or equate this revision with the hosted Kimi K3 evaluation.

Defeat or reopen condition

Defeated if a hash-integrity failure occurs or the preserved payload does not contain the stated fields; reopened for any live-state, file-completeness, capability, or evaluator-identity claim.

Read the first routed use in the full paper

P4-CAN-02
supported with limits
On AISI's selected July 2026 cyber tests, GLM-5.2 and DeepSeek V4-Pro performed comparably to selected closed models released roughly four to seven months earlier.

Statement class

evaluation result · affirmed_bounded

Scope

Selected UK AISI controlled cyber tasks and simulated ranges; no inference outside the tested systems and setup.

Limit. The comparison is selective and non-predictive; simulated ranges omit important defenses, and the result does not estimate real-world intrusion success or transfer to biological capability.

Prohibited overclaim

Must not universalize a cyber capability gap, predict future parity, or convert the comparison into real-world harm probability.

Defeat or reopen condition

Defeated or materially revised by a demonstrated methodological error in the cited result; reopened for new models, later dates, other domains, or real-world outcome claims.

Read the first routed use in the full paper

P4-CAN-03
supported with limits
In the joint July 23 preliminary evaluation, Moonshot AI's hosted Kimi K3 setup scored below the leading tested U.S. closed systems and above GLM-5.2 on the selected tests.

Statement class

evaluation result · affirmed_bounded

Scope

Joint UK AISI/U.S. CAISI preliminary evaluation of Moonshot's hosted Kimi K3 setup on selected cyber tests.

Limit. The estimate is preliminary and selective; Kimi used one aggregate benchmark with wider uncertainty, comparator safeguards were disabled, and the simulated range omitted important real-world defenses. The hosted object is not pinned to the repository revision.

Prohibited overclaim

Must not call the tested object downloadable weights, claim byte identity with the Kimi K3 repository, or predict real-world outcomes.

Defeat or reopen condition

Defeated by a correction to the official evaluation; reopened by an exact tested-object disclosure, a final report, or a materially different evaluation.

Read the first routed use in the full paper

P4-CAN-04
supported with limits
Once public copies of weights exist, safeguards that require provider-controlled access, account monitoring, forced updating, user removal, or universal withdrawal are no longer universally available to the originating provider.

Statement class

interpretation · affirmed_bounded

Scope

Provider-dependent safeguards after public weight release; qualitative control availability rather than a measured persistence rate.

Limit. The record does not show that every copy persists, that all safeguards fail, or how often patching, license observance, mirror removal, or recall succeeds.

Prohibited overclaim

Must not say every released copy is permanent or that no legal, institutional, endpoint, or downstream safeguard can remain effective.

Defeat or reopen condition

Reopened by any proposed quantitative persistence or control-effectiveness claim; defeated only if the provider-control premise is shown not to apply to the specified release profile.

Read the first routed use in the full paper

P4-CAN-05
supported with limits
By July 28, 2026, U.S. biosecurity governance combined federal criminal prohibitions, Executive Order 14292, and a July 20 final policy replacing the 2024 DURC/PEPP framework; department-specific guidance and the single review body were still incomplete.

Statement class

legal rule · affirmed_bounded

Scope

United States federal criminal law, executive direction, research-funding policy, and cutoff-day NIH implementation posture.

Limit. The July 20 instrument is a final federal policy, not an APA final rule or proof of completed agency rollout. Particular funding and agency applications may depend on later guidance, terms, authorities, and review procedures.

Prohibited overclaim

Must not preserve the tranche-1 statement that no replacement text existed, call implementation complete, or generalize the policy into a criminal prohibition on model publication.

Defeat or reopen condition

Defeated by a cutoff-valid withdrawal or proof the policy was not issued as represented; the incomplete-implementation qualifier is defeated by authoritative evidence that all required guidance and review mechanisms were established.

Read the first routed use in the full paper

P4-CAN-06
supported with limits
At the July 28 cutoff, codified AI Diffusion provisions, categorical non-enforcement, retained preexisting controls, GAO's CRA interpretation, and a targeted July 2026 UAE final rule coexisted; no wholesale final rescission or replacement was found in the declared federal routes.

Statement class

legal rule · affirmed_bounded

Scope

Named U.S. export-control text, agency posture and guidance, GAO interpretation, targeted final rule, and declared cutoff-bounded docket/index searches.

Limit. Practical non-enforcement is not textual repeal; GAO is not a court; the UAE rule is targeted, not wholesale; transaction-level consequences and uncaptured litigation, CRA compliance, or enactments remain outside the finding.

Prohibited overclaim

Must not say the framework was simply rescinded, deny the UAE final rule, treat GAO as a judicial holding, or turn the bounded search into universal absence.

Defeat or reopen condition

The no-wholesale-action finding is defeated by a cutoff-valid final rule or docket action expressly withdrawing, rescinding, superseding, or replacing the framework; transaction-specific claims require separate legal validation.

Read the first routed use in the full paper

P4-CAN-07
supported with limits
California Chapter 138 was effective January 1, 2026 and created a large-frontier-developer transparency, incident-reporting, whistleblower, enforcement, and unreleased-weight security regime; it was not a categorical public-weight-release ban.

Statement class

legal rule · affirmed_bounded

Scope

California state law only; Chapter 138 as approved and filed September 29, 2025 and effective under the ordinary January 1 rule.

Limit. California is one comparator, not a fifty-state survey; the record does not resolve preemption, conflicts, enforcement outcomes, or every statutory application.

Prohibited overclaim

Must not generalize California to all states or describe Chapter 138 as a general ban on publishing weights.

Defeat or reopen condition

Reopened if later architecture relies on state duties, preemption, national generalization, or enforcement effects; defeated by authoritative correction to the cited enactment or effective-date basis.

Read the first routed use in the full paper

P4-CAN-08
supported with limits
The EU AI Act's qualifying open-source exception is limited: copyright and training-summary duties remain, and systemic-risk obligations are not displaced solely by release under qualifying open terms.

Statement class

legal rule · affirmed_bounded

Scope

European Union general-purpose AI and systemic-risk legal duties, with nonbinding Commission interpretation and cutoff-specific timing.

Limit. Provider status, model classification, timing, territorial reach, and actual compliance are fact-specific; Commission guidelines are nonbinding and post-cutoff enforcement outcomes are unavailable.

Prohibited overclaim

Must not say open release removes all EU obligations or claim post-cutoff enforcement outcomes.

Defeat or reopen condition

Reopened for provider-specific classification, territorial reach, timing, enforcement, or outcome claims; defeated by authoritative text that materially changes the cited duties at the relevant date.

Read the first routed use in the full paper

P4-CAN-09
supported with limits
At the July 28 cutoff, the Council of Europe AI convention had not met its five-party entry threshold, including three Council of Europe member states, when the official status and treaty text were read together.

Statement class

interpretation · affirmed_bounded

Scope

Council of Europe treaty text and official participation status as of July 28, 2026.

Limit. Treaty character, signature, consent, entry into force, implementation, and effectiveness are separate. Provider-sensitive routes make the preserved complete local chain the fixed-cutoff evidence.

Prohibited overclaim

Must not call the treaty nonbinding in form, conflate signature with entry into force, or project the status beyond the cutoff.

Defeat or reopen condition

Defeated by authoritative evidence that the treaty's entry conditions had been met by the cutoff; reopened automatically for any later-date status.

Read the first routed use in the full paper

P4-CAN-10
supported with limits
International and U.S. institutions treat scientific openness, capacity building, competition, privacy, participation, and equitable access as governance values, while also identifying compute, connectivity, local data, skills, financing, and market structure as independent constraints.

Statement class

moral commitment · affirmed_bounded

Scope

Institutional analyses, recommendations, political commitments, and executive policy positions; not a causal release-profile study.

Limit. The instruments differ in legal effect and do not prove realized distributional outcomes, causal innovation effects, or net benefit. Weight access is not equivalent to material capacity.

Prohibited overclaim

Must not average commitments into outcomes, present political preferences as law, or claim weight access alone produces competition or equity.

Defeat or reopen condition

Reopened for any quantitative, causal, or net-benefit claim; defeated only by source-grounded evidence that the specified institutional statement or constraint was mischaracterized.

Read the first routed use in the full paper

P4-CAN-11
supported with limits
Biosecurity, cyber defense, financial controls, research oversight, risk-management frameworks, criminal and export law, standards, treaty coordination, preparedness, and response capacity are distinct governance layers; the corpus does not show that any one layer is sufficient.

Statement class

interpretation · affirmed_bounded

Scope

Policy-level defensive control architecture across named laws, guidance, evaluations, strategies, standards, and international instruments.

Limit. The sources identify routes and institutional roles but do not establish complete coverage, comparative efficacy, or severe-risk reduction for any layer.

Prohibited overclaim

Must not claim that listing a control proves implementation, outcome effectiveness, or completeness.

Defeat or reopen condition

Reopened when a later policy relies decisively on screening, finance, reporting, repository duties, standards, treaty verification, or another layer's measured efficacy.

Read the first routed use in the full paper

P4-T2-02
supported with limits
Within the declared White House, Federal Register, Regulations.gov, and ASPR routes through July 28, 2026, no final revised or replacement nucleic-acid synthesis screening framework was found; ASPR still described it as forthcoming.

Statement class

observed fact · affirmed_bounded

Scope

Named authoritative federal endpoints and exact cutoff-bounded searches; not the universe of all possible federal records.

Limit. The result is endpoint- and query-bounded. A differently titled, unindexed, inaccessible, or later-indexed cutoff-valid instrument could exist; the White House JSON 403 contributes zero absence weight.

Prohibited overclaim

Must not say no framework existed anywhere or count the failed White House JSON endpoint as a zero-result search.

Defeat or reopen condition

Defeated by a dated final framework issued on or before July 28, 2026 by a relevant federal authority, even if indexed later.

Read the first routed use in the full paper

P4-T3-01
supported with limits
Within the declared Phase-3 corpus and official endpoints through the July 28, 2026 America/New_York cutoff, no evaluation met all six qualification conditions for current, independent, model-specific causal human biological uplift with sufficient public methods and an exact tested object.

Statement class

interpretation · affirmed_bounded

Scope

Declared official indexes, procurement notice, SecureBio synthesis, primary papers, and release record through the cutoff; endpoint-bounded and method-defined.

Limit. This is not universal nonexistence, not a directional claim about positive versus null effects, and not a finding that benchmarks or pooled access studies are irrelevant.

Prohibited overclaim

Must not say no qualifying study exists anywhere, that biological risk is proved or disproved, or that only positive effects could qualify.

Defeat or reopen condition

Defeated by a public cutoff-valid study that independently evaluates one named current model, compares human performance with and without it, reports sufficient methods and uncertainty, and pins the served snapshot or weight revision.

Read the first routed use in the full paper

P4-T3-02
supported with limits
Zhang et al. provides current causal evidence that multi-model access improved novice accuracy on the tested digital tasks by an estimated 4.16-fold overall (95% CI 2.63–6.87), but it does not identify the marginal effect of one model or checkpoint.

Statement class

evaluation result · affirmed_bounded

Scope

Independent 2026 multi-model hosted-access treatment on specified digital biological tasks.

Limit. Participants could use and cross-check multiple services; digital task performance does not establish physical execution, catastrophic outcomes, or any one release's effect.

Prohibited overclaim

Must not assign the effect to a named model, provider configuration, or downloadable checkpoint.

Defeat or reopen condition

Model-level randomization or identified assignment with adequate power and endpoint/version records could convert part of the evidence into a model-specific result.

Read the first routed use in the full paper

P4-T3-03
supported with limits
In Hong et al.'s preregistered physical-world trial, the primary endpoint showed no significant improvement for the tested mid-2025 multi-model access condition (5.2% versus 6.6%, P=.759); the post-hoc pooled estimate was uncertain and not model-specific.

Statement class

evaluation result · affirmed_bounded

Scope

Independent preregistered physical-world trial of access to a changing portfolio of hosted model families.

Limit. The primary result is null for the tested access condition, not proof of no risk; the post-hoc estimate is uncertain, and neither result is attributable to one model or checkpoint.

Prohibited overclaim

Must not call the result proof that models cannot increase capability or assign it to a named release.

Defeat or reopen condition

A sufficiently powered single-model arm with a pinned endpoint and public uncertainty estimate would close the attribution gap.

Read the first routed use in the full paper

P4-T3-04
supported with limits
Yong et al. supplies current independent model-specific biological benchmark evidence for Kimi K2.5, and Moonshot separately supplies downloadable weights; the paper does not estimate causal human uplift or prove that repository revision 4d01dfe0332d63057c186e0b262165819efb6611 produced the biological results.

Statement class

evaluation result · affirmed_bounded

Scope

Independent Kimi K2.5 benchmark paper plus a separate, later-captured Moonshot/Hugging Face downloadable release record.

Limit. The biology runs do not identify their provider route or immutable checkpoint; benchmarks are uplift proxies, full run logs are unavailable, and repository state was captured after the test period.

Prohibited overclaim

Must not call the benchmark a human-uplift estimate, attribute it to the captured checkpoint, or equate a provider alias, family name, hosted setup, and repository revision.

Defeat or reopen condition

A public independent human treatment study with control, model-specific effect and uncertainty, and a pinned served endpoint or weight revision would qualify and defeat the present gap.

Read the first routed use in the full paper

Zero positive support

Fifteen claims the position refuses to make

These are enforced boundaries, not caveats waiting to disappear. Each remains reopenable only under its recorded condition.

P4-EXC-01
enforced exclusion
The corpus does not support a factual claim that any named model can cause a biological catastrophe or complete a real-world intrusion.

Statement class

forecast/scenario · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. Controlled benchmarks and evaluations do not supply a catastrophic-outcome or real-world intrusion result.

Prohibited overclaim

Must not convert proxy performance into a demonstrated catastrophe or completed intrusion.

Defeat or reopen condition

Reopened by a qualifying direct evaluation or observed outcome; until then the proposition remains excluded.

Read the first routed use in the full paper

P4-EXC-02
enforced exclusion
The corpus does not establish that the hosted Kimi K3 setup evaluated by UK AISI and U.S. CAISI was byte-identical to the pinned Hugging Face Kimi K3 revision.

Statement class

observed fact · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The evaluation identifies a hosted setup; the repository record identifies a revision, and neither source establishes identity between them.

Prohibited overclaim

Must not transfer hosted evaluation results to the pinned downloadable revision.

Defeat or reopen condition

Defeated by authoritative provenance establishing byte/configuration identity for the evaluated setup.

Read the first routed use in the full paper

P4-EXC-03
enforced exclusion
The corpus does not support the claim that severe biological or cyber harm is simple, inevitable, or reducible to a short misuse chain.

Statement class

forecast/scenario · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The evidence preserves material, expertise, access, execution, defense, detection, and response barriers and warns against proxy-to-outcome collapse.

Prohibited overclaim

Must not use inevitability, cookbook framing, or a compressed operational sequence.

Defeat or reopen condition

Reopened only with evidence addressing the full relevant chain; operational detail remains outside project scope regardless.

Read the first routed use in the full paper

P4-EXC-04
enforced exclusion
The corpus does not support translating a model benchmark score directly into real-world harm probability or causal human uplift.

Statement class

interpretation · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. Benchmark results are proxies; the Kimi study does not estimate a human treatment effect or catastrophic-outcome probability.

Prohibited overclaim

Must not relabel benchmark performance as human uplift, harm likelihood, or catastrophic outcome.

Defeat or reopen condition

Defeated only by a credible, source-grounded calibration or causal study for the exact benchmark, object, and outcome.

Read the first routed use in the full paper

P4-EXC-05
enforced exclusion
The corpus does not establish a proven net benefit or net harm from open-weight release across security, science, competition, privacy, and equity.

Statement class

interpretation · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The corpus contains institutional concerns, values, and policy positions, not commensurable causal estimates across release profiles.

Prohibited overclaim

Must not label an institutional preference or concern as a proven aggregate outcome.

Defeat or reopen condition

Reopened by credible causal evidence spanning the claimed outcomes; otherwise remains excluded.

Read the first routed use in the full paper

P4-EXC-06
enforced exclusion
The corpus does not establish that license terms prevent copying, modification, redistribution, or private execution after public weight release.

Statement class

legal rule · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. Repository terms and release metadata do not measure observance, enforcement, downstream copying, or intermediary duties.

Prohibited overclaim

Must not treat a license label as a technical prevention mechanism or universal downstream constraint.

Defeat or reopen condition

Reopened by a specific legal/enforcement proposition; empirical prevention requires outcome evidence.

Read the first routed use in the full paper

P4-EXC-07
enforced exclusion
The corpus does not establish that withdrawal, patching, or public recall reliably reaches downstream copies of released weights.

Statement class

interpretation · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. Provider-control loss is qualitatively supported, but mirror survival, patch uptake, recall success, and license observance are not measured.

Prohibited overclaim

Must not claim a zero or hundred-percent recall rate or that every downstream actor ignores updates.

Defeat or reopen condition

Reopened by any quantitative recall or patching assertion; defeated only by release-profile-specific empirical evidence.

Read the first routed use in the full paper

P4-EXC-08
enforced exclusion
The corpus does not establish that the First Amendment categorically protects or categorically excludes AI model weights.

Statement class

legal rule · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. One appellate opinion recognizes expressive dimensions of code while preserving functional distinctions; it does not decide AI-weight status or complete the relevant doctrine.

Prohibited overclaim

Must not claim categorical constitutionality or unconstitutionality of a release control.

Defeat or reopen condition

Reopened by a concrete policy design or materially on-point authoritative doctrine.

Read the first routed use in the full paper

P4-EXC-09
enforced exclusion
The corpus does not support saying that both biosecurity replacement frameworks ordered in May 2025 were final and fully implemented by July 28, 2026.

Statement class

observed fact · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The DURC/PEPP replacement was found but implementation remained incomplete; the revised nucleic-acid screening framework was not found in the bounded routes.

Prohibited overclaim

Must not preserve the obsolete no-DURC-text premise or collapse the two framework statuses into one completed implementation claim.

Defeat or reopen condition

Defeated by cutoff-valid evidence that both final instruments and required implementation machinery were complete; otherwise the split status remains.

Read the first routed use in the full paper

P4-EXC-10
enforced exclusion
The corpus does not establish that the United Kingdom had a comprehensive statutory frontier-model release gate at the cutoff.

Statement class

legal rule · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The captured source documents an initial, voluntary, regulator-led approach within existing remits and is not a complete current-law survey.

Prohibited overclaim

Must not claim comprehensively that no binding UK duty existed.

Defeat or reopen condition

Reopened automatically by any later UK legal-comparator or actor-duty claim.

Read the first routed use in the full paper

P4-EXC-11
enforced exclusion
The corpus does not support saying that either the WHO Pandemic Agreement or the Council of Europe AI convention was in force at the July 28 cutoff.

Statement class

legal rule · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The Pandemic Agreement process still required the PABS annex before signature and ratification, while the Council of Europe convention had not met its entry threshold.

Prohibited overclaim

Must not merge negotiation, signature, consent, entry into force, implementation, and effectiveness.

Defeat or reopen condition

Defeated for either instrument by authoritative cutoff-valid entry-into-force evidence; later status always requires refresh.

Read the first routed use in the full paper

P4-EXC-12
enforced exclusion
The corpus does not establish that financial tracing and asset controls can identify every offender or reverse technical diffusion.

Statement class

interpretation · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The sources identify supervision, cooperation, freezing, seizure, and implementation gaps; they do not measure universal attribution or technical recall.

Prohibited overclaim

Must not present financial controls as universal identification or a mechanism that deletes public copies.

Defeat or reopen condition

Reopened whenever financial control efficacy becomes decisive to a proposal.

Read the first routed use in the full paper

P4-EXC-13
enforced exclusion
The corpus does not establish an optimal compute, capability, or risk threshold for release decisions.

Statement class

policy proposal · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. The frameworks support structured evaluation and uncertainty management but do not derive a universal threshold or commensurable score.

Prohibited overclaim

Must not infer a release gate directly from a voluntary framework or one benchmark.

Defeat or reopen condition

Reopened in Phase 5 when a threshold proposal is attacked; remains excluded as a present evidence claim.

Read the first routed use in the full paper

P4-EXC-14
enforced exclusion
The corpus does not establish that standards conformity, a published safety framework, or a license is proof of safe outcomes.

Statement class

interpretation · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. Management frameworks, standards, and license metadata identify processes or terms, not model-specific safety or measured severe-risk reduction.

Prohibited overclaim

Must not treat certification, framework publication, or licensing as outcome proof.

Defeat or reopen condition

Reopened if a later architecture scores these routes as effective controls.

Read the first routed use in the full paper

P4-EXC-15
enforced exclusion
The corpus does not establish that access to weights alone closes global compute, connectivity, data, skills, language, financing, or market-power gaps.

Statement class

interpretation · excluded

Scope

Scope follows the cited boundary records; the excluded proposition is not asserted as fact.

Limit. Access commitments coexist with independent material and institutional capacity constraints; realized outcomes are not demonstrated.

Prohibited overclaim

Must not equate formal availability with effective participation, competition, or equity.

Defeat or reopen condition

Reopened by any claim that openness alone produces a stated distributional outcome.

Read the first routed use in the full paper

Item-level custody

Sixty-nine source-note records

Fifty records carry positive bounded weight, eighteen carry boundary-only weight, and one carries zero empirical weight. Exact local paths and SHA-256 values remain inspectable.

intergovernmental_guidance

Laboratory biosecurity guidance

P3-BIO-001
positive_boundedguidancephase3-tranche1

Bounded finding. Supports treating biosecurity as a lifecycle risk-management problem with consequence-driven assessment, institutional governance, and national oversight; the scope expressly includes cybersecurity, information security, molecular techniques, and artificial intelligence as emerging considerations.

Exact locator. Overview, especially the paragraph beginning “The WHO laboratory biosecurity guidance” and the listed key elements.

Limit. Normative guidance is not binding law and does not quantify marginal risk from any model, establish an AI release threshold, or show that a listed control works in every laboratory context.

Open the recorded source URL · retrieved 2026-07-28T15:03:47Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 6d5f426391811c2cc8526311ad8e39fabcbba28883dff4946f7ed5bb073267d8
  • extracted_text_path · source.md · frozen review packageSHA-256 f3b6bad9f7c868d287daeed9bde7517a021efeffb1e1d31eac36e498b3f20d7b

official_legal_text

Improving the Safety and Security of Biological Research

P3-BIO-002
positive_boundedlegal rulephase3-tranche1

Bounded finding. Establishes that the executive branch directed a pause or funding restrictions for specified categories of research and ordered replacement of the 2024 dual-use and nucleic-acid screening policies on stated timelines.

Exact locator. Sections 3 through 7, including the directives to the OSTP Director and covered funding agencies.

Limit. The order operates through presidential and agency authority; it is not a generally applicable criminal statute, does not itself supply the final replacement frameworks, and does not resolve constitutional or administrative-law questions about later implementation.

Open the recorded source URL · retrieved 2026-07-28T15:00:11Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 cfcaa14c9f975644328167173f26ccb81ba66d61cbcba13a870e1b8886c5e8d0
  • extracted_text_path · source.md · frozen review packageSHA-256 463b495e69c8b0be3888549ef71f493049f2c407d86ef6d54d18a4f7c3980774

official_status_record

White House Issues Executive Order on Improving the Safety and Security of Biological Research

P3-BIO-003
positive_boundedobserved factphase3-tranche1

Bounded finding. Shows the implementing institution’s public position that the May 2025 executive order superseded implementation of the May 2024 DURC/PEPP policy and contemplated a new policy.

Exact locator. Opening notice and the paragraph stating that the new policy is intended to replace the May 2024 policy and supersedes its implementation.

Limit. This status notice is not the text of a replacement policy. The current tranche did not locate a final replacement framework that closes the implementation gap.

Open the recorded source URL · retrieved 2026-07-28T15:00:18Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 6b8cead0b057e85300324b0e977a4e15559627b17921973384322cded1cb05bf
  • extracted_text_path · source.md · frozen review packageSHA-256 34380544373aec7cd06dce40e0f5cacda8cae9803537e26b3b5740b0ed86392f

official_legal_text

18 U.S.C. § 175 — Prohibitions with respect to biological weapons

P3-BIO-004
positive_boundedlegal rulephase3-tranche1

Bounded finding. Supplies the current statutory prohibition and the statutory boundary preserving prophylactic, protective, bona fide research, and other peaceful purposes.

Exact locator. Subsections (a), (b), and (c), especially the peaceful-purpose language in subsections (b) and (c).

Limit. The provision does not create an AI-model release rule, and applying its intent, possession, quantity, jurisdiction, and peaceful-purpose elements to a specific matter would require fact-specific legal analysis.

Open the recorded source URL · retrieved 2026-07-28T15:00:19Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 ecef717d5de51898afad4b7945f8151c56e999d731e2319c9b14cc387c01f844
  • extracted_text_path · source.md · frozen review packageSHA-256 fd21714af9865cc317794afbb1511782d8dec8af18ba06b58808288f890440bd

official_status_record

WHO Member States continue negotiations on the Pathogen Access and Benefit Sharing Annex

P3-BIO-005
positive_boundedobserved factphase3-tranche1

Bounded finding. Establishes the cutoff-date status: the seventh negotiating meeting advanced but did not finalize the PABS annex, and continued negotiations were required before countries could consider signature and ratification of the Pandemic Agreement.

Exact locator. Paragraphs beginning “WHO Member States have advanced negotiations” and “The meeting concluded,” plus the announced eighth meeting.

Limit. This is a negotiation-status release, not an operative treaty text. It cannot support a claim that the Pandemic Agreement was open for signature, ratified, or in force at the evidence cutoff.

Open the recorded source URL · retrieved 2026-07-28T15:00:22Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 74c3242cf9c04a3c66b4f93d24bde38caa79498dd17b890c813a0e3acec95b20
  • extracted_text_path · source.md · frozen review packageSHA-256 ae28202cddfa9d1b70ddc06140cdf7c5a49acb03a404e9fa363d0179c549df78

official_evaluation

How Far Behind the Frontier are Leading Open Weight Models on Cyber?

P3-CYB-001
positive_boundedevaluation resultphase3-tranche1

Bounded finding. Supports a bounded finding that the two tested open-weight models performed comparably to selected closed models released four to seven months earlier on AISI’s test setup, while public weights reduce provider-controlled monitoring, access control, and withdrawal options.

Exact locator. Introduction; “Results: the current cyber gap for open weight AI”; “Real-world constraints”; and “Limitations to our testing.”

Limit. The evaluated models and tasks are a narrow sample; simulated ranges omit important real-world defenses; the comparison is not predictive; price observations are time-sensitive; and no inference to biological or other capabilities is warranted.

Open the recorded source URL · retrieved 2026-07-28T15:00:23Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 27b70eda6084d865e38ebd1970168dd61f87439253894080dd14dee24fa90c8b
  • extracted_text_path · source.md · frozen review packageSHA-256 4b5415d38a0e8342005ffc0014782f58abfb55118e9e8dc88e670947ac8d4c72

official_legal_text

18 U.S.C. § 1030 — Fraud and related activity in connection with computers

P3-CYB-002
positive_boundedlegal rulephase3-tranche1

Bounded finding. Provides the existing federal legal baseline for specified unauthorized access, fraud, damage, extortion-related threats, and related conduct involving protected computers.

Exact locator. Subsection (a), definitions in subsection (e), and the penalty and civil-action provisions.

Limit. The statute does not regulate publication of model weights as such; authorization, loss, intent, jurisdiction, and remedy questions are fact-dependent and affected by case law not exhausted in this tranche.

Open the recorded source URL · retrieved 2026-07-28T15:00:24Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 f80a8b4758c929a80d75d397c3585fe90cfc7a8598941e4a69a80b0cb0e86ae0
  • extracted_text_path · source.md · frozen review packageSHA-256 25ce370ed313723a7ca7c758fa30fb0366cee0b589a4c425c4eae8f8754181df

official_government_report

2024 National Strategy for Combating Terrorist and Other Illicit Financing

P3-CYB-003
positive_boundedpolicy proposalphase3-tranche1

Bounded finding. Supports treating cyber-enabled finance as a policy-level detection and enforcement layer through risk-focused supervision, closing regulatory gaps, partnerships, and responsible technology use.

Exact locator. Executive Summary; “Goals, Priorities, and Supporting Actions”; and the cybercrime and ransomware material in the threat and vulnerability annexes.

Limit. A strategy states priorities rather than proving implementation or outcomes, predates later 2025–2026 developments, and does not show that financial controls can prevent or reverse model release.

Open the recorded source URL · retrieved 2026-07-28T15:02:27Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 75336486361b5df99768b5da12217267e8e36f49f3271a749a3ee3e13d255112
  • capture_path · raw.body · frozen review packageSHA-256 cdf15a9445b3741af395def3e76e2115f8adf6cb8cb8cf43befecb779ffdef7c
  • original_extracted_text_path · source.md · frozen review packageSHA-256 f70e433053b473c0782e55ec999dfdc0c1bef3aab4c2db63c0605159f67339e4

intergovernmental_assessment

FATF urges stronger global action to address Illicit Finance Risks in Virtual Assets

P3-CYB-004
positive_boundedevaluation resultphase3-tranche1

Bounded finding. Documents uneven implementation, continuing licensing and registration gaps, difficulty identifying providers, offshore-service challenges, and the importance of cross-border cooperation, freezing, and seizure.

Exact locator. Publication summary paragraphs following “Paris, 26 June 2025,” especially the implementation, offshore VASP, Travel Rule, and international-cooperation findings.

Limit. FATF standards depend on domestic implementation and are not self-executing global law; some figures rely on industry contributors; the update does not establish a causal link between open-weight release and illicit-finance volume.

Open the recorded source URL · retrieved 2026-07-28T15:03:48Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 c760f48db9834732b358ca221c5d6f27f87bb7be2d033d131a39c4b9a25c4789
  • extracted_text_path · source.md · frozen review packageSHA-256 baf1d7589c694abf277a808b962ccb16df78f3563d0d3f7a48e634722ff7e78d

official_evaluation

UK AISI / CAISI Preliminary Assessment of Kimi K3’s Cyber Capabilities

P3-CYB-005
positive_boundedevaluation resultphase3-tranche1

Bounded finding. Supports only the bounded evaluation finding that the tested hosted Kimi K3 setup performed below the leading tested U.S. closed systems and above GLM-5.2 on the selected preliminary evaluations. It does not establish that the hosted setup was a byte-identical copy of the pinned Hugging Face revision.

Exact locator. Opening findings; “Detailed Results”; “Cyber Capability Trends”; and the simulated-range limitations near the end of the official AISI page, corroborated by the matching official CAISI/NIST publication.

Limit. The evaluation is preliminary and selective; Kimi’s aggregate estimate used one benchmark and therefore has a wider confidence interval; safeguards were disabled for the U.S. closed-system comparators; and the simulated range assumed initial access, lacked active defenders and alert penalties, and contained an intentional path. The source does not connect the hosted tested object to a byte-identical copy of the pinned Hugging Face revision or predict real-world outcomes.

Open the recorded source URL · retrieved 2026-07-28T17:34:07Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 26f3bcefe754b29ad42b0b6c89b5544c00180b6b5fc2b57d0cc80a142557e9b8
  • extracted_text_path · source.md · frozen review packageSHA-256 61715aafd77e3ac14f85e43c89133fe7971e151ddfe164e937954a9287d62eaf
  • supporting_captures/0/capture_path · raw.html · frozen review packageSHA-256 dd426fa903a66e59961c94c86f1b0a446e950ad12cfe28df45ad8b60831f6472
  • supporting_captures/0/extracted_text_path · source.md · frozen review packageSHA-256 9a571208240f4a8f326db30ada14f1fcf6fe5847181b8be42eb34a05fe0841fc

competition_staff_report

FTC Staff Report on AI Partnerships & Investments 6(b) Study

P3-ECO-001
positive_boundedevaluation resultphase3-tranche1

Bounded finding. Documents partnership terms and potential competition concerns involving access to compute and talent, switching costs, exclusivity or control rights, and access to sensitive technical and business information.

Exact locator. FTC report PDF pages 5–6 (printed pages 2–3), “Summary of Findings”; detailed sections 5.1, 5.2, and 5.3 begin on PDF pages 33, 35, and 37.

Limit. A Section 6(b) staff study is not an adjudication, does not establish an antitrust violation, covers selected partnerships, and predates later market changes.

Open the recorded source URL · retrieved 2026-07-28T17:34:32Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 97a19b06ea753490b1cc685243759987699f33000489eeedecaf8a2c1c815f82
  • supporting_captures/0/capture_path · raw.html · frozen review packageSHA-256 cc9367ac50a4fd8a851f7ecbfa6baac49196d6e54ee5cf27250c2d6c411a8b47
  • supporting_captures/0/extracted_text_path · source.md · frozen review packageSHA-256 8343952d33423cb89a54671aa465be533b441afd74ffb7be28ea8fbdcca0057e
  • capture_path · raw.body · frozen review packageSHA-256 8281097ed1859d1be13f50c37b0127aca0ee4d332e0a60e5cb028d227b6311e6
  • original_extracted_text_path · source.md · frozen review packageSHA-256 36b91d05a0975985d6b291970b39f4f2ceab32743ec63d378f7e35f0cd79a1f4

intergovernmental_recommendation

Recommendation on Open Science

P3-ECO-002
positive_boundedguidancephase3-tranche1

Bounded finding. Supplies an authoritative scientific-openness framework grounded in reproducibility, scrutiny, collaboration, academic freedom, inclusion, and equitable capacity, while recognizing proportionate restrictions for security, privacy, rights, and other protected interests.

Exact locator. Preamble; paragraphs 1–9; core values and principles in paragraphs 13–14; and the action areas beginning at paragraph 15.

Limit. The recommendation is not binding treaty law, addresses open science broadly rather than model weights specifically, and its stated benefits and values do not prove that every release choice advances equity or safety.

Open the recorded source URL · retrieved 2026-07-28T15:00:57Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 9e610c6c60e273e0f2d4052151809afb1bd0feb1ed34edb9a89ad95ce39edc6e
  • extracted_text_path · source.md · frozen review packageSHA-256 7c931895846492b41b841391621dce79558ebb4f059d57c7a466fc13ead76f43

multilateral_commitment

Global Digital Compact

P3-ECO-003
positive_boundedmoral commitmentphase3-tranche1

Bounded finding. Documents Member State commitments to close digital divides, build developing-country capacity, support safe and secure digital public goods including open AI models, and expand access to models, data, compute, skills, and locally relevant systems.

Exact locator. Digital public goods section; Objectives 1, 2, and 5; and the AI capacity-building commitments near paragraphs 61–67.

Limit. The Compact is a political commitment rather than a self-executing treaty, uses its own terminology, and cannot establish that open models necessarily improve equity or that promised financing and capacity will materialize.

Open the recorded source URL · retrieved 2026-07-28T15:00:58Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 629ad2fc8f5716c203e9e99f1ed8c3f4e2d85a7a5edc24a9d5d32316f9665cbd
  • extracted_text_path · source.md · frozen review packageSHA-256 9c8498d553b0cc3be85b7729fc9cd9c5aee55d53d7dcbfc57477295137ded60e

development_institution_report

Digital Progress and Trends Report 2025: Strengthening AI Foundations

P3-ECO-004
positive_boundedinterpretationphase3-tranche1

Bounded finding. Documents concentration of AI innovation, compute, and funding in high-income countries and identifies connectivity, compute, locally relevant data, and skills as distinct barriers to inclusive participation.

Exact locator. Report landing page “Key Findings” and the sections on adoption and innovation, connectivity, compute, context, and competency.

Limit. The report is a development-institution synthesis, not a causal evaluation of open-weight policy; its claim that open technologies create opportunities does not show who captures benefits or what safety conditions are sufficient.

Open the recorded source URL · retrieved 2026-07-28T15:00:59Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 e7bc23643a5a9c84b9b104e8bb6f027ef5d2bf8fd384538eefa6feafb74f4113
  • extracted_text_path · source.md · frozen review packageSHA-256 29840e25e61a16b3075b0ecec644cf48fcfa65e6f7e30838a526aabd8d06cfc6

intergovernmental_assessment

International AI Safety Report 2026

P3-FRG-001
positive_boundedinterpretationphase3-tranche1

Bounded finding. Supports the evaluation dilemma: controlled tests and proxies can inform risk assessment, but evidence about real-world behavior, elicitation, safeguards, and rare severe outcomes remains incomplete and context-sensitive.

Exact locator. Executive Summary; evaluation and risk-management chapters; contributor statement that the report does not endorse a particular policy or regulatory approach.

Limit. The report synthesizes evidence available largely through December 2025, is not a legal instrument, and expressly does not recommend a policy choice; later model releases require separate evaluation.

Open the recorded source URL · retrieved 2026-07-28T17:34:31Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 29e0aea1bc0881281a862196ae85206df0a9e966717c62c75ad515c9f218b2e0
  • superseded_evidence/derived_text_path · source.md · frozen review packageSHA-256 26f64e68f6bdb2c782ffa858e2cfc17580d654c2276fa58d2e04526670b4ae6d
  • superseded_evidence/capture_path · raw.body · frozen review packageSHA-256 a43ea0a2d3fc479275d8d4db413fc37daa3526c211cca4c8bc33aa70f7766fc5
  • capture_path · raw.body · frozen review packageSHA-256 50b244ddf39fb9189d44ccd990ba423ebe8927d8ffdce0f5aac5882c74cbc790
  • original_extracted_text_path · source.md · frozen review packageSHA-256 4958dddf65bc562e33abb79eb8899c3b55caf1d4ff65dfad8a95565853b2cc15

official_guidance

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

P3-FRG-002
positive_boundedguidancephase3-tranche1

Bounded finding. Provides a voluntary cross-sectoral profile that identifies generative-AI risks and supplies suggested actions to govern, map, measure, and manage them rather than treating one benchmark as dispositive.

Exact locator. NIST AI 600-1, PDF page 5 (printed page 1), section 1, “Introduction,” especially the cross-sectoral-profile and govern-map-measure-manage paragraphs.

Limit. The profile is voluntary, not an enforcement rule, and does not determine a legally acceptable open-weight release state or validate any particular model.

Open the recorded source URL · retrieved 2026-07-28T17:34:32Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 36eeaca51ad22e010ee4406d8a673e2f91a05f9e7936ca6d018b630fc1a220fa
  • supporting_captures/0/capture_path · raw.html · frozen review packageSHA-256 200e5c286987cb9d4d0b44dbcb5e813a8eb4cfc1a96d1266bd12f1b760423f5a
  • supporting_captures/0/extracted_text_path · source.md · frozen review packageSHA-256 a8cf79eeed2b70a744a36ab712b4a8ab6332195b4eecd02cf8c82df0774f4681
  • capture_path · raw.body · frozen review packageSHA-256 d93455b7a65389fa609a1ef4ae4eb79f8902094750e76337ae7361b9306d14b2
  • original_extracted_text_path · source.md · frozen review packageSHA-256 24a16af62b8b7610dd43c3e6ec1a957d51e111d6419ca676c1d2fdda40edbcf4

official_guidance

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

P3-FRG-003
positive_boundedguidancephase3-tranche1

Bounded finding. Supplies the govern-map-measure-manage lifecycle and a common vocabulary for separating governance, evidence gathering, measurement, and mitigation.

Exact locator. NIST AI 100-1, PDF page 7 (printed page 2), voluntary-status paragraph; and PDF page 8 (printed page 3), Framework Core paragraph naming GOVERN, MAP, MEASURE, and MANAGE.

Limit. AI RMF 1.0 predates several frontier-model developments, is undergoing revision, and neither creates liability nor resolves release-specific tradeoffs.

Open the recorded source URL · retrieved 2026-07-28T17:34:32Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 b2eebd6b11d4beeb8ad4e4bf74789758439e5401930171d8f3c2182cab40ca2d
  • supporting_captures/0/capture_path · raw.html · frozen review packageSHA-256 a1215154623438c585734b35fb0401c7a51e5b9be335968ee63892d801268ccb
  • supporting_captures/0/extracted_text_path · source.md · frozen review packageSHA-256 b0081eb15052f93f5d143b6b0b4379bb97000eca2f2163e88c9446d5120923af
  • capture_path · raw.body · frozen review packageSHA-256 7576edb531d9848825814ee88e28b1795d3a84b435b4b797d3670eafdc4a89f1
  • original_extracted_text_path · source.md · frozen review packageSHA-256 1c5a6603a291edb0cdb8fe2234dd50004f67aa9a98a07b5fbbd1e6bd6e845e3a

official_guidance

Implementing the UK’s AI regulatory principles: initial guidance for regulators

P3-FRG-004
positive_boundedguidancephase3-tranche1

Bounded finding. Documents the UK route of regulator-led implementation around safety, transparency, fairness, accountability, and redress within existing remits.

Exact locator. Summary; Background; and “Guidance on interpreting and applying the AI regulatory framework.”

Limit. The page calls the principles voluntary, the guidance non-prescriptive and initial, and regulator action dependent on existing remit; it does not establish a current statutory frontier-model release gate.

Open the recorded source URL · retrieved 2026-07-28T15:00:31Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 a896efafb1e79ea90f185d841e68bbd5b538e20fe2d5d39e661803e57b8c8fa1
  • extracted_text_path · source.md · frozen review packageSHA-256 9db279e5de3842380adcb9ab2b1b44a6e240eb1048f2940f5d06980bc5e23597

supranational_regulation

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence

P3-INT-001
positive_boundedlegal rulephase3-tranche1

Bounded finding. Establishes documentation, downstream-information, copyright-policy, training-summary, systemic-risk evaluation, mitigation, incident-reporting, and cybersecurity duties, with only a limited open-source exemption that does not remove systemic-risk obligations.

Exact locator. Articles 51, 53, 54, 55, 56, 113, and Recital 104 in the official English Official Journal PDF.

Limit. Application dates, model classification, provider status, exemptions, and territorial reach require fact-specific analysis; the Act does not use the project’s release-profile terminology and should not be paraphrased as a universal ban on public weights.

Open the recorded source URL · retrieved 2026-07-28T15:04:34Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 f30d6c86cc965f3d44fd62a0bbde9cdd1922263bc124fb66c89ef77ce6d79c79
  • capture_path · raw.body · frozen review packageSHA-256 bba630444b3278e881066774002a1d7824308934f49ccfa203e65be43692f55e
  • original_extracted_text_path · source.md · frozen review packageSHA-256 fdf55ba8c4b4db1ec871f8a88b46645efbc8723f0a3aff6fcb2ff7be33d5df7f

supranational_guidance

Guidelines for general-purpose AI model providers

P3-INT-002
positive_boundedguidancephase3-tranche1

Bounded finding. Records the Commission’s cutoff-date interpretation of provider scope and compliance timing: obligations applied from August 2, 2025, Commission enforcement powers were scheduled from August 2, 2026, and older models had a later compliance date.

Exact locator. Sections on who is a provider, model placement, exemptions, obligations, and the timeline for enforcement and pre-existing models.

Limit. Commission guidelines are non-binding interpretation, not the regulation itself; the August 2, 2026 enforcement date was still future by five days at the evidence cutoff.

Open the recorded source URL · retrieved 2026-07-28T15:00:45Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 2e7bcc38862645c998b98a4915f5fa59bc90bb9c317ca44e3e31eaa766fdde13
  • extracted_text_path · source.md · frozen review packageSHA-256 c6230f17066a8ceb56ef7b1719dec5b9bca4e17cf734da6b37d032ca3b2752ad

treaty_status_record

The Framework Convention on Artificial Intelligence

P3-INT-003
positive_boundedobserved factphase3-tranche1

Bounded finding. Shows the cutoff-date institutional status: the page listed the European Union as the sole party and listed 21 signatories, while describing the convention’s rights, democracy, rule-of-law, risk-assessment, remedy, and cooperation architecture.

Exact locator. Sections “Parties,” “List of Signatories,” “What does the Framework Convention require states to do?,” and “Who is covered?”

Limit. The live page is a status summary, not the treaty’s entry-into-force clause; party and signatory lists can change after the cutoff and must be paired with the official treaty text.

Open the recorded source URL · retrieved 2026-07-28T15:09:20Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 e86af945ade0887e6c8d9cb41542883bbe8916c203665f5236d4688406595476
  • extracted_text_path · source.md · frozen review packageSHA-256 76042469a472ee43dd394b002e64e4b1e4fc67e6c59686b4e3b799a367869b68

treaty_text

Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225

P3-INT-004
positive_boundedlegal rulephase3-tranche1

Bounded finding. Provides the treaty’s lifecycle, human-rights, democratic-process, accountability, remedy, risk-management, and cooperation provisions and the entry condition of five consenting signatories including at least three Council of Europe member states.

Exact locator. Articles 1–3, 14–16, 23–25, and Article 30(3).

Limit. At the cutoff the status record listed only one party, so the Article 30(3) threshold was not met; signature alone does not make the treaty operative for a signatory, and national implementation choices remain material.

Open the recorded source URL · retrieved 2026-07-28T15:09:30Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 6bedc0ad84e71a5dafa386aef436bbfb4ab3e26806bcfe222b238ac0aa1203e3
  • capture_path · raw.body · frozen review packageSHA-256 1ac6c8a85f55446cdb53697b57c6be3ce8757068043992955eda571e7fe52f23
  • original_extracted_text_path · source.md · frozen review packageSHA-256 dbd8280cd33a7b58f3e2396a50885000ca4902e961f7512a713fff884298fd9f

treaty_depositary_record

Convention on the prohibition of the development, production and stockpiling of bacteriological (biological) and toxin weapons and on their destruction

P3-INT-005
positive_boundedobserved factphase3-tranche1

Bounded finding. Establishes the existence, title, conclusion date, entry-into-force date, depositaries, authentic texts, and participant actions for the central multilateral biological-weapons prohibition.

Exact locator. Treaty metadata table and participant action table in UN registration record 14860.

Limit. The depositary page proves treaty status and participation, not compliance, verification effectiveness, AI-specific duties, or a model-release control.

Open the recorded source URL · retrieved 2026-07-28T15:00:48Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 977620bee57c01a7abb2bb588204720d13e064c7cafd19f95f2b2b2d62575843
  • extracted_text_path · source.md · frozen review packageSHA-256 b37c02caf706bfd5957e9ebe4f9a09ff44246114fd391817d6a5c265ff682dc0

international_standard

ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system

P3-INT-006
positive_boundedguidancephase3-tranche1

Bounded finding. Supplies a standards route for establishing, implementing, maintaining, and continually improving an AI management system, including organizational risk and opportunity management.

Exact locator. Public abstract, publication metadata, “What is ISO/IEC 42001?,” and management-system explanation.

Limit. The public page does not expose the full paywalled standard; certification or conformity is not itself proof that a specific model is safe, lawful, or suitable for public-weight release.

Open the recorded source URL · retrieved 2026-07-28T15:00:49Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 efddae6b593c78a46289014d40895b2e41c96a5d01b120bedb15cb19c070fca2
  • extracted_text_path · source.md · frozen review packageSHA-256 5edf246035ae04b800df12fa135267900bbbda825229bd41ea801402f73d76d6

repository_revision_metadata

Kimi K3 pinned-revision metadata response at 9f62e4e9fffbd0a83ddd60e1c209d828994b3569

P3-OWR-001
positive_boundedobserved factphase3-tranche1

Bounded finding. Shows that a direct application/json response to the full-commit revision request reported sha 9f62e4e9fffbd0a83ddd60e1c209d828994b3569, private false, gated false, and safetensors totals F32 11,122,432, BF16 57,179,884,544, U8 2,722,740,830,208, total 2,779,931,837,184.

Exact locator. Top-level id, private, gated, sha, lastModified, and safetensors.parameters and safetensors.total fields in the captured response.

Limit. The full commit pin stabilizes the requested revision identity and the observed core revision fields, but the endpoint also returns mutable repository metadata such as likes. The provider-reported response does not prove file completeness, a conventional architecture-level parameter count, capability or risk, evaluator identity, identity with the hosted setup tested by UK AISI and CAISI, or enforceable license terms.

Open the recorded source URL · retrieved 2026-07-28T17:34:07Z

Active local custody

  • historical_browser_wrapper/capture_path · raw.html · frozen review packageSHA-256 0c5172d74f426a7a52bc77484e344d84ee9eb4f5f2942886f42999443309e30a
  • capture_path · raw.body · frozen review packageSHA-256 f30cf5b7a6d850128147cac5dcaffc9cee427d2764bb83a927ea592bcbf8227f
  • extracted_text_path · source.md · frozen review packageSHA-256 119dc694b15f93847e244a822c59a8670b4af62750162b7de4027926fa83ebcb

official_policy_report

Dual-Use Foundation Models with Widely Available Model Weights

P3-OWR-002
positive_boundedinterpretationphase3-tranche1

Bounded finding. Supports the historically bounded finding that NTIA then found insufficient evidence to warrant immediate restrictions on widely available weights and recommended a monitor-evaluate-act approach while recognizing research, competition, privacy, and security tradeoffs.

Exact locator. Report overview and recommendations on NTIA’s official report page.

Limit. The analysis answers the scope of Executive Order 14110 using evidence available in 2024, cannot establish that restrictions will never be warranted, and predates the 2025–2026 evaluation record.

Open the recorded source URL · retrieved 2026-07-28T15:03:49Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 3e1f8dc2d5ad4aa7fe8f1b60800186bb751b83021a1f3a1e03f16f52fff28428
  • extracted_text_path · source.md · frozen review packageSHA-256 94eb9105f770c0631a6e719842fe3e981a7377d97eeb132f7ef205772e0b6dd6

official_policy_plan

Winning the Race: America’s AI Action Plan

P3-OWR-003
positive_boundedpolicy proposalphase3-tranche1

Bounded finding. Documents an administration policy preference for supporting open-source and open-weight AI based on asserted benefits to startups, academia, privacy, competition, and geostrategic adoption.

Exact locator. Pillar I recommendations concerning open-source and open-weight models and the plan’s action items.

Limit. The plan is an administration policy document, not proof that the asserted benefits occur, not a self-executing statute, and not a complete statement of export-control or civil-liability law.

Open the recorded source URL · retrieved 2026-07-28T15:02:28Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 8b9dfa03f19f963af4c33f8f015e1567aeb3059a56a63c756866a71d5d5df645
  • capture_path · raw.body · frozen review packageSHA-256 91d56ab3ddefe43f395bde31e1c3923fb37f47091275aaf2a0d7da500ff547f4
  • original_extracted_text_path · source.md · frozen review packageSHA-256 fe259c48fe6445ede6b3e76a4105e033f0e2578c99ab0c21fd7715806cd5d2ae

official_legal_text

California Senate Bill 53 — Transparency in Frontier Artificial Intelligence Act

P3-USL-001
positive_boundedlegal rulephase3-tranche1

Bounded finding. Establishes an effective California regime using transparency frameworks, incident reporting, whistleblower protection, civil penalties, and security of unreleased model weights rather than a categorical prohibition on public release. The chaptered bill was approved and filed September 29, 2025, and took effect January 1, 2026 under the ordinary rule in California Government Code section 9600(a).

Exact locator. Chaptered bill text: “CHAPTER 138,” approval and filing statement, definitions, transparency-framework duties, critical-safety-incident provisions, and Attorney General enforcement sections; California Government Code section 9600(a) for the ordinary January 1 effective-date rule.

Limit. Thresholds and covered-entity definitions are specific; application outside California is limited; and the ordinary effective-date conclusion depends on the regular-session, non-urgency enactment and section 9600(a). The law does not prove compliance effectiveness and is not a categorical public-weight-release ban or a nationwide rule.

Open the recorded source URL · retrieved 2026-07-28T15:00:35Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 b2761de269a54df772792b271078ded6b1c5550970d02e0ad06ba80cf0d8d823
  • extracted_text_path · source.md · frozen review packageSHA-256 86c24e1b0316caa86d840ac299681adffc4b46e5c71a427a88109a197aa0f8b9
  • supporting_captures/0/capture_path · raw.html · frozen review packageSHA-256 e365a9da8fc75eeecf5aa2d938cd43582600bbd6293d88a7390325d32faaae0b
  • supporting_captures/0/extracted_text_path · source.md · frozen review packageSHA-256 9ea13ac32b66a7f4d67a2ec4b0027cf9752a7cbc23af2936a7bbf63779fd48b3

judicial_opinion

Defense Distributed v. Attorney General New Jersey, No. 23-3058

P3-USL-002
positive_boundedinterpretationphase3-tranche1

Bounded finding. Shows that code can have protected expressive dimensions, while purely functional code without adequately pleaded actual or intended expressive use is not automatically protected; the court affirmed dismissal on the complaint presented.

Exact locator. Majority opinion’s First Amendment analysis and disposition.

Limit. The case concerns firearm-related computer files, not AI model weights; its holding depends on pleading and function-expression distinctions; it is geographically bounded and does not settle all circuit or Supreme Court questions.

Open the recorded source URL · retrieved 2026-07-28T15:02:28Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 063a33c85f358ba4d00c9c3a3fb6f8055f060a26856e5605d149dc77887b3053
  • capture_path · raw.body · frozen review packageSHA-256 59d35713e48bcb5de8356120b8e606d53577fa44e0b8e69f21f78f19fd5f760b
  • original_extracted_text_path · source.md · frozen review packageSHA-256 1c45b4f5acdd4acb6bed34d5bd96b8dc30f9d3d4ee207f796dac60255ddceac8

official_legal_text

Export Administration Regulations Part 742 — Control Policy

P3-USL-003
positive_boundedlegal rulephase3-tranche1

Bounded finding. Shows that the codified text at the cutoff retained a worldwide license requirement for items specified in ECCN 4E091 and a stated review policy for covered artificial-intelligence model weights.

Exact locator. 15 C.F.R. § 742.6(a)(13), § 742.6(b)(14), and the note referring to ECCN 4E091 and published models.

Limit. Classification, jurisdiction, exclusions, exceptions, end users, destinations, and training-compute comparisons are fact-specific; the separate categorical non-enforcement posture means codified text alone does not describe actual enforcement practice.

Open the recorded source URL · retrieved 2026-07-28T15:00:40Z

Active local custody

  • capture_path · raw.html · frozen review packageSHA-256 e1df4f51f5c5e5d30cd6658c536f6f0d70d6dbe8346f4badf3515941214b14d4
  • extracted_text_path · source.md · frozen review packageSHA-256 91a3dfe2775ffcfea44a7e3d5c0738e781fefb6fe837b6f5a02790a880e310bf

official_guidance

Guidance Regarding Enforcement of License Requirements for Advanced Computing Items for Entities Headquartered in Country Group D:5 and Macau

P3-USL-004
positive_boundedguidancephase3-tranche1

Bounded finding. Confirms that BIS’s non-enforcement policy for new AI Diffusion Rule requirements did not erase preexisting license requirements for the advanced-computing transactions described in the guidance.

Exact locator. First page, especially the paragraphs beginning “In January 2025,” “Recently, BIS has received questions,” and “Because this license requirement predates.”

Limit. The document focuses on advanced-computing items for specified entities, not a complete model-weight classification guide, and it does not replace the EAR or individualized export advice.

Open the recorded source URL · retrieved 2026-07-28T15:02:29Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 5a604985aa69416c143049819e70f6ac4e8aec6daa46c4d32bfa632a07927e55
  • capture_path · raw.body · frozen review packageSHA-256 d7296438740efad835badddb5daa6cfd8d3a43bb62fedbf5a7a817c79828610b
  • original_extracted_text_path · source.md · frozen review packageSHA-256 6053ba03c5482a50eef23a82b9aaf2bdbc3a0492c5a7e376924eb0eff50698a8

official_legal_interpretation

Bureau of Industry and Security—Applicability of the Congressional Review Act to the Rescission of the Artificial Intelligence Diffusion Rule, B-337935

P3-USL-005
positive_boundedinterpretationphase3-tranche1

Bounded finding. Establishes GAO’s view that planned rescission had not completed rulemaking, the framework remained in the Code of Federal Regulations, and the categorical non-enforcement announcement itself was a rule subject to CRA submission requirements.

Exact locator. Congressional Record pages S2322–S2323, Digest, Background sections “AI Diffusion Rule” and “Press Release,” and the discussion of planned rescission and non-enforcement.

Limit. GAO’s CRA decision is not a judicial holding on a particular export, license application, or criminal exposure; the practical and legal effect of non-enforcement remains a specialized counsel question.

Open the recorded source URL · retrieved 2026-07-28T15:02:29Z

Active local custody

  • extracted_text_path · source.md · frozen review packageSHA-256 c27742c1ca96d4e373646949da5cf467dea05ac94a6ad90e1555915f2a3ba6ee
  • capture_path · raw.body · frozen review packageSHA-256 75e5eabc7ec04b06b1bdb3a8c7bbd5a0f9ce44b09363c7a2f2229b1ca4149f7e
  • original_extracted_text_path · source.md · frozen review packageSHA-256 e06932e18cc148b9a0692329223bea99be0a8770cc88590d56cb82818a153b3e

claim_bearing_codified_text / official_current_regulation_text

Export Administration Regulations Part 742 — Control Policy

T2-US-AID-001
positive_boundedlegal rulephase3-tranche2

Bounded finding. Shows that the cutoff-day codified text retained the ECCN 4E091 model-weight license requirement and review policy despite the separate non-enforcement posture.

Exact locator. Current-as-of line; 15 C.F.R. § 742.6(a)(13), § 742.6(b)(14), and Note 2 to ECCN 4E091.

Limit. A mutable current-regulation page supports the captured current-as-of text, not a July 28 instrument or effective date. It does not by itself state practical enforcement and must be paired with posture and guidance evidence.

Open the recorded source URL · retrieved 2026-07-28T15:00:40Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 e1df4f51f5c5e5d30cd6658c536f6f0d70d6dbe8346f4badf3515941214b14d4
  • readable_path · source.md · frozen review packageSHA-256 91a3dfe2775ffcfea44a7e3d5c0738e781fefb6fe837b6f5a02790a880e310bf

claim_bearing_posture_document / official_press_release

Department of Commerce Announces Rescission of Biden-Era Artificial Intelligence Diffusion Rule, Strengthens Chip-Related Export Controls

T2-US-AID-002
positive_boundedobserved factphase3-tranche2

Bounded finding. Separately establishes categorical non-enforcement and the statement that a formal rescission regulation and replacement would be published later.

Exact locator. Release date and first three body paragraphs, especially 'plans to publish a regulation formalizing the rescission' and the instruction not to enforce.

Limit. A press release and enforcement directive do not textually amend the CFR; its CRA status is addressed separately by GAO.

Open the recorded source URL · retrieved 2026-07-28T21:00:36Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 acece65ce082c1f81f67c0b22c700eedbcbc959d96eb66c5bd34116efa8ddace
  • readable_path · source.md · frozen review packageSHA-256 6dbdf26c7dd0290b17050118ef4d835d769efd9b49ed0bdcb466e77ebb95b005

claim_bearing_guidance / official_guidance_pdf

Guidance Regarding Enforcement of License Requirements for Advanced Computing Items for Entities Headquartered in Country Group D:5 and Macau

T2-US-AID-003
positive_boundedguidancephase3-tranche2

Bounded finding. Explains that specified advanced-computing license requirements predated the AI Diffusion Rule and remain enforceable notwithstanding non-enforcement of new AI Diffusion requirements.

Exact locator. First page, paragraphs beginning 'In January 2025,' 'Recently, BIS has received questions,' and 'Because this license requirement predates.'

Limit. This is guidance for specified advanced-computing items, not formal rescission, replacement, or a complete model-weight classification guide.

Open the recorded source URL · retrieved 2026-07-28T15:02:29Z

Active local custody

  • readable_path · source.md · frozen review packageSHA-256 5a604985aa69416c143049819e70f6ac4e8aec6daa46c4d32bfa632a07927e55
  • raw_path · raw.body · frozen review packageSHA-256 d7296438740efad835badddb5daa6cfd8d3a43bb62fedbf5a7a817c79828610b
  • pipeline_markdown_path · source.md · frozen review packageSHA-256 6053ba03c5482a50eef23a82b9aaf2bdbc3a0492c5a7e376924eb0eff50698a8

claim_bearing_legal_interpretation / official_gao_decision

U.S. Department of Commerce, Bureau of Industry and Security—Applicability of the Congressional Review Act to the Rescission of the Artificial Intelligence Diffusion Rule

T2-US-AID-004
positive_boundedinterpretationphase3-tranche2

Bounded finding. Distinguishes a nonfinal planned rescission from a categorical non-enforcement policy that GAO concludes is a rule for CRA purposes.

Exact locator. B-337935, May 12, 2026; Digest; Background; Discussion; conclusion that planned rescission is not final and non-enforcement is a CRA rule.

Limit. GAO is not a federal court, and this decision is not a rescission rule, judicial judgment, or congressional enactment.

Open the recorded source URL · retrieved 2026-07-28T21:00:37Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 bcd5c1e774704d19a83f0b72d6f956b4f8392ece63c5d23e3eacafd228a279d8
  • readable_path · source.md · frozen review packageSHA-256 c89263cbd094e34767966bae6f2d483cb6aa841ff4972c6c07b28593feb29c43

claim_bearing_primary_legal_document / federal_register_final_rule_pdf

Enhanced Favorable Treatment for the United Arab Emirates Under the Export Administration Regulations

T2-US-AID-005
positive_boundedlegal rulephase3-tranche2

Bounded finding. Strongest contrary indication: a real post-GAO final rule that amends related controls and incorporates enforcement posture, but does not formally rescind or replace the AI Diffusion Rule as a whole.

Exact locator. 91 Fed. Reg. 43034-43039; RIN 0694-AK54; Action; Dates; 43036 'Enforcement of License Requirements for Advanced Computing Items'; amendatory instructions for parts 740, 742, and 774.

Limit. The final rule is destination/entity-specific. It cannot be generalized into wholesale rescission, and it does not remove retained § 742.6(a)(13) or (b)(14).

Open the recorded source URL · retrieved 2026-07-28T21:03:15Z

Active local custody

  • access_block_artifact/raw_path · raw.html · frozen review packageSHA-256 49f16add8f9da972871f4366fa2f19db81eb5f6a61266dd0c6d8f11def886e70
  • access_block_artifact/readable_path · source.md · frozen review packageSHA-256 c4be0b3ecafebee6e13844b5bf0732ef8533e0561018ae569f339265283d9522
  • readable_path · derived-pdftotext-layout.txt · frozen review packageSHA-256 60a9d250f1347b695adbf9c5b8eaa2554956052ea9dea362cc3cb4e46801bd37
  • raw_path · raw.body · frozen review packageSHA-256 4e4b5555a41f7799f4e4dfe192a3a159c6fbb023da36ffacd76e4bbb80c5d9d5
  • pipeline_markdown_path · source.md · frozen review packageSHA-256 681f2d6dac2e47f8dd4ce68801dca3d10557335c197ea6dce2d92da6dc4dddb2

reproducible_no_result_trail / official_api_search_response

Federal Register exact-term BIS search: Framework for Artificial Intelligence Diffusion

T2-US-AID-NR-001
boundary_onlyobserved factphase3-tranche2

Bounded finding. Identifies and tests all four exact-term Federal Register candidates through the cutoff.

Exact locator. JSON count 4 and document numbers 2026-14132, 2025-00711, 2025-00637, and 2025-00636.

Limit. Exact-term search can miss differently titled actions; it is paired with the all-BIS post-GAO search and docket search.

Open the recorded source URL · retrieved 2026-07-28T21:00:39Z

Active local custody

  • raw_path · raw.body · frozen review packageSHA-256 b2de96ead2cb6f3519ca155c093f1083b8881adf9e0e531c78ba4b30f84758e8
  • readable_path · source.md · frozen review packageSHA-256 8bddbb41e86559acf295c737723d0c83f9715d535c641cc41e5647c1106a5a2d

reproducible_no_result_trail / official_api_search_response

Federal Register all-BIS post-GAO published-document search

T2-US-AID-NR-002
boundary_onlyobserved factphase3-tranche2

Bounded finding. Eliminates title dependence by inspecting every published BIS document in the post-GAO interval.

Exact locator. JSON count 14, total_pages 1; two Rules and twelve Notices.

Limit. The date interval begins May 13, the day after GAO's May 12 decision; same-day predecision chronology is not inferred. Current public inspection is checked separately.

Open the recorded source URL · retrieved 2026-07-28T21:00:39Z

Active local custody

  • raw_path · raw.body · frozen review packageSHA-256 3e5acc38bc49af06ebb35609cdf93c698f1cda186df18be3015f8d6e744abcdc
  • readable_path · source.md · frozen review packageSHA-256 a66434b7e5846e08aa1646b266e80bca2897752c86d7625d37b589767ba46fbe

reproducible_no_result_trail / official_docket_api_response

Regulations.gov docket BIS-2025-0001 document search

T2-US-AID-NR-003
boundary_onlyobserved factphase3-tranche2

Bounded finding. Shows the docket contained only the original rule and public briefing and no later rescission or replacement document.

Exact locator. JSON totalElements 2; BIS-2025-0001-0001 and BIS-2025-0001-0002; withdrawn false.

Limit. A docket-specific result does not exclude a differently numbered docket; it is paired with the all-BIS Federal Register search.

Open the recorded source URL · retrieved 2026-07-28T21:00:39Z

Active local custody

  • raw_path · raw.body · frozen review packageSHA-256 6eb2a5fa5160e573b89b6bd44046a4ea83376d243b010b921af2b71eace464ec
  • readable_path · source.md · frozen review packageSHA-256 0a9836c0c3d7611bd97c0a152701472c95154b9a75618a8cc2de4f24cad1667d

reproducible_no_result_trail / official_public_inspection_api_response

Federal Register July 28, 2026 current public-inspection five-page composite

T2-US-AID-NR-004
boundary_onlyobserved factphase3-tranche2

Bounded finding. Checks the filed-but-not-yet-published route on the cutoff; all five pages and 85 records had zero BIS agency matches.

Exact locator. Each response states count 85 and total_pages 5; page lengths 20, 20, 20, 20, and 5; agency/title inspection yielded zero BIS records.

Limit. Current public inspection is a cutoff-day list, not a historical archive and not evidence about non-BIS agencies or differently timed filings.

Open the recorded source URL · retrieved 2026-07-28T21:00:40Z

Active local custody

  • components/0/raw_path · raw.body · frozen review packageSHA-256 4621edb5265663ffbf13229c2643910fe0a93a33eaab24fce729b3d70554e1ec
  • components/0/readable_path · source.md · frozen review packageSHA-256 becf4df31a38df8b0c5dfcc93bbc9c807d7ebbd1bc91148bb46319554256ff4a
  • components/1/raw_path · raw.body · frozen review packageSHA-256 90930a667e3e3b0bfaadf5eb27018b185601ec937156f743971ad711cea75fbc
  • components/1/readable_path · source.md · frozen review packageSHA-256 5e0b735b33b11996484fa65f7d0033cad02b2ec1117a2c46f740feb915d76208
  • components/2/raw_path · raw.body · frozen review packageSHA-256 a37e1ebda07f345b4e8c51cf7123c58558fcb1f221a0eb38d634f49eb62482da
  • components/2/readable_path · source.md · frozen review packageSHA-256 75e7a907a53a1b4f2ea8d9a5bcc8172b4a875741e05b9884d39ead1ee4ae357c
  • components/3/raw_path · raw.body · frozen review packageSHA-256 a615696134adecdd9e46ab9b7d4ec71fd8a77a7a17fb0f3e22b19ab106186d82
  • components/3/readable_path · source.md · frozen review packageSHA-256 246f55ca11cf5c63082a89dec1211900ef869bf25b4ae156fd8a1dafefc6d1bb
  • components/4/raw_path · raw.body · frozen review packageSHA-256 52eb3b387f702140af9c7c4aba756a72564bc3b65192b5fad05af3f1417ac9a4
  • components/4/readable_path · source.md · frozen review packageSHA-256 7bf0d766b48a2a389d25f5a7a7598b267932747aee8d27efe3c43dd7c470eae9

claim_bearing_primary_document / official_policy_pdf

United States Government Policy for Stopping High-Risk Life Sciences Research

T2-US-BIO-001
positive_boundedguidancephase3-tranche2

Bounded finding. Establishes a dated final replacement policy for the 2024 DURC/PEPP framework, identifies still-pending implementation steps, and was checked to ensure it does not also replace the nucleic-acid screening framework.

Exact locator. Cover (July 20, 2026); p. 2 implementation paragraph; pp. 8-9 § 4; p. 9 § 5 first paragraph expressly replacing the 2024 DURC/PEPP policy.

Limit. This is an issued federal policy, not an APA final rule and not evidence that department-specific guidance or the review body was complete. The PDF is image-only; decisive text was OCR-derived and visually checked against pp. 1 and 9.

Open the recorded source URL · retrieved 2026-07-28T21:03:15Z

Active local custody

  • failed_local_derivation/path · derived-pdftotext-layout.txt · frozen review packageSHA-256 ee3e9571f483c678ab4ec83579e8bef9c1399e8d319a66a073e1d60491f85468
  • readable_path · derived-tesseract-5.3.4-300dpi.txt · frozen review packageSHA-256 451a20286c86f0f406a5fd60a788ce2e89be2ee6c9f524d36134fcf8099aa214
  • raw_path · raw.body · frozen review packageSHA-256 0b54d2397a2324f6d12fc15053237c095cd2eb359faf30c012e217f5509a36dc
  • pipeline_markdown_path · source.md · frozen review packageSHA-256 f6658ba01e840e6b2f897e8012d41aa8442bd65b2a1f3a2e03d3bce9e9b12430

claim_bearing_primary_document / official_implementation_notice

NOT-OD-26-101: USG Policy for Stopping High-Risk Life Sciences Research

T2-US-BIO-002
positive_boundedobserved factphase3-tranche2

Bounded finding. Confirms issuance of the replacement policy and that flagged activities remain paused until NIH-specific implementation requirements, guidance, and review mechanisms are established.

Exact locator. Release Date; Purpose; Implementation Guidance, including the 120-day guidance and 90-day review-body paragraphs.

Limit. An NIH notice does not itself complete every department's implementation or convert the policy into a generally applicable regulation.

Open the recorded source URL · retrieved 2026-07-28T21:00:24Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 30a6a66c1299942381f09ab5d8ff7710cf3db8897187731399aec47973331b46
  • readable_path · source.md · frozen review packageSHA-256 d55634f6366119b2aae69d9f90de4ff0bd8fd73ee4193cdd2de49b46014feedd

supporting_official_provenance / official_status_and_provenance_page

Biosafety and Biosecurity Policy

T2-US-BIO-003
positive_boundedobserved factphase3-tranche2

Bounded finding. Provides the official NIH route to the new policy and repeats that flagged activities remain paused pending NIH-specific requirements.

Exact locator. High-Risk Life Sciences Research block; Implementation Update links; page footer 'Last updated: July 2026.'

Limit. This mutable landing page is supporting provenance, not the claim-bearing replacement instrument.

Open the recorded source URL · retrieved 2026-07-28T21:00:35Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 2783152ae3a82b07916ac11ff44475ab5dbb1c7bfb09b2947eb6a42d86caa84f
  • readable_path · source.md · frozen review packageSHA-256 6d2e65182e438642a6ea0c02392644ed1d4297d1c57a4114edd3737cc0e615c8

claim_bearing_primary_document / official_presidential_action

Executive Order 14292: Improving the Safety and Security of Biological Research

T2-US-BIO-004
positive_boundedlegal rulephase3-tranche2

Bounded finding. Establishes the separate section 4(a) and 4(b) directives and their 120-day and 90-day timelines; it does not itself supply either replacement text.

Exact locator. EO 14292 § 4(a)-(b), including the exact titles of the 2024 DURC/PEPP and nucleic-acid screening frameworks.

Limit. The order is the directive and timeline baseline, not evidence that the ordered replacement was later finalized.

Open the recorded source URL · retrieved 2026-07-28T15:00:11Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 cfcaa14c9f975644328167173f26ccb81ba66d61cbcba13a870e1b8886c5e8d0
  • readable_path · source.md · frozen review packageSHA-256 463b495e69c8b0be3888549ef71f493049f2c407d86ef6d54d18a4f7c3980774

claim_bearing_official_status / official_status_page

Synthetic Nucleic Acid Screening

T2-US-BIO-005
positive_boundedobserved factphase3-tranche2

Bounded finding. Affirmatively states that agencies will revise or replace the 2024 framework and that the page will be updated once the revised framework is available.

Exact locator. The 'Update' paragraph and the '2024 OSTP Framework for Nucleic Acid Synthesis Screening' paragraph.

Limit. The page is mutable and is status evidence, not proof of universal nonexistence or a substitute for a final framework.

Open the recorded source URL · retrieved 2026-07-28T21:00:36Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 a51a6f11c7bd5a143526de08969eb684937d0b7432cd70ef44710eea5e6836cf
  • readable_path · source.md · frozen review packageSHA-256 f48a73a279f7b63e7570f8953244a4292120b019e8dc09fbeb31e597d8527e23

reproducible_no_result_trail / official_site_search_response

White House exact site search: Framework for Nucleic Acid Synthesis Screening

T2-US-BIO-NR-001
boundary_onlyobserved factphase3-tranche2

Bounded finding. Bounds the White House site-index search; it does not prove absence outside the index.

Exact locator. Search results block listing exactly the May 5, 2025 fact sheet and Executive Order.

Limit. Site-search indexing can be incomplete or delayed; both candidates were future-direction documents, not final replacement text.

Open the recorded source URL · retrieved 2026-07-28T21:00:36Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 4b47e6771d8fd8ae4d58efaa7a2dce8dc897386a309f9de4ca4551f8b58a3ee9
  • readable_path · source.md · frozen review packageSHA-256 50a650dbf5fb171bef8c649027add35389297c0e8758e6e8b20917be9638d598

reproducible_no_result_trail / official_api_search_response

Federal Register exact-term search: Framework for Nucleic Acid Synthesis Screening

T2-US-BIO-NR-002
boundary_onlyobserved factphase3-tranche2

Bounded finding. Bounds the exact-term published Federal Register search between the directive and cutoff.

Exact locator. JSON count 1; result document_number 2025-08266.

Limit. Exact-term indexing can miss differently titled documents; the result only bounds this query and date interval.

Open the recorded source URL · retrieved 2026-07-28T21:00:37Z

Active local custody

  • raw_path · raw.body · frozen review packageSHA-256 55d21451a54dd61bc25ef75601491a93eee2c615ca84e03ac61e48b438cf78bb
  • readable_path · source.md · frozen review packageSHA-256 9a11123eb36bd16d6aca23ca3736e4f84d5485fa4c725d1e4415b7a0a4740c4a

reproducible_no_result_trail / official_api_search_response

Regulations.gov exact-term search: Framework for Nucleic Acid Synthesis Screening

T2-US-BIO-NR-003
boundary_onlyobserved factphase3-tranche2

Bounded finding. Bounds the exact-term Regulations.gov document search over the directive-to-cutoff interval.

Exact locator. JSON meta.numberOfElements 0 and meta.totalElements 0.

Limit. A zero result is query-specific and does not establish that no differently titled or unindexed federal document exists.

Open the recorded source URL · retrieved 2026-07-28T21:00:38Z

Active local custody

  • raw_path · raw.body · frozen review packageSHA-256 c6da80e756346ad99712d726cb0c7efe8083038c740345d56892c6a2dfb3b0bb
  • readable_path · source.md · frozen review packageSHA-256 16a7b1075f7263201a6f2e326dfbd199c4397dfcd057f1d318ed2e2371f1b056

provider_access_failure / official_endpoint_error_response

White House WordPress JSON exact search access failure

T2-US-BIO-NR-004
zeroobserved factphase3-tranche2

Bounded finding. Preserves the exact failed endpoint and distinguishes access failure from absence.

Exact locator. HTTP status 403; raw Error 403 HTML payload.

Limit. This endpoint contributes no no-result evidence. The separate standard White House HTML search succeeded.

Open the recorded source URL · retrieved 2026-07-28T21:08:19Z

Active local custody

  • raw_path · raw.html · frozen review packageSHA-256 d114e625dc4dc8e6c4c372f4866b095a900675f3abd2f084cc89c07e7126c42a
  • readable_path · source.md · frozen review packageSHA-256 331f1a97b4784ecbda86d468dd650c803051223cc7a48162545272290acb1f51

official_government_index

UK AI Security Institute research index

T3-AUTH-AISI-001
boundary_onlyobserved factphase3-tranche3

Bounded finding. Inspection of the captured research index through its then-current entries found no published result for the commissioned biological human-uplift trial.

Exact locator. source.md lines 42-418, complete captured research-title index.

Limit. An index can omit an unindexed, differently titled, or later-posted document; this is not a universal nonexistence claim.

Open the recorded source URL · retrieved 2026-07-29T01:45:11+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 83340cd2009e63a17424f7d47cbcef5c818a625c685846ce1e57e1c70feebe3c

official_government_index

NIST Center for AI Standards and Innovation index

T3-AUTH-CAISI-001
boundary_onlyobserved factphase3-tranche3

Bounded finding. The captured CAISI index included current model evaluations but no model-specific biological human-uplift result.

Exact locator. source.md lines 179-190 identify current Kimi and DeepSeek evaluation entries; no biology-uplift result appears in the complete captured index.

Limit. The absence is index-specific and cannot prove that no government-held or unindexed result exists.

Open the recorded source URL · retrieved 2026-07-29T01:45:12+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 ebcb3fd9efcd5daa46a981891ad2759f6996b933884025d4c2585384920fe70b

current_independent_synthesis

SecureBio Biology Benchmark Dashboard

T3-AUTH-SB-001
positive_boundedevaluation resultphase3-tranche3

Bounded finding. A cutoff-current independent dashboard reports model-only biology benchmark trends and explicitly says translation to real-world harmful ability remains unclear.

Exact locator. source.md lines 55-72 (date, BCI method and limitations) and 77-84 (open/closed comparison and real-world uncertainty).

Limit. Aggregated benchmark results are capability proxies. They do not estimate a human treatment effect.

Open the recorded source URL · retrieved 2026-07-29T01:52:00+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1544475c3f3ae334370a5c19ff1506a61cabd976e33686a27f3de72a60fe79d3

current_independent_synthesis

SecureBio dashboard methods and data limits

T3-AUTH-SB-002
positive_boundedinterpretationphase3-tranche3

Bounded finding. SecureBio states that it evaluates plotted models itself, uses at least ten runs with BCa bootstrap confidence intervals, and does not release full logs.

Exact locator. source.md lines 60, 102-107.

Limit. The site exposes aggregate results rather than full run logs; a named API model need not equal a released weight checkpoint.

Open the recorded source URL · retrieved 2026-07-29T01:45:07+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 daa14b7329ca80670a5d8fc9cab061f5d1f0bbd84f1cfb8e27f63604092959cc

current_independent_synthesis

SecureBio Uplift Studies review

T3-AUTH-SB-003
positive_boundedinterpretationphase3-tranche3

Bounded finding. The review distinguishes wet-lab from in-silico results, flags small samples, missing company-study methods, rapid model evolution, and porous controls, and enumerates current public studies.

Exact locator. source.md lines 54-70 and 81-173.

Limit. A mutable narrative synthesis is not a substitute for each underlying study and cannot prove universal nonexistence.

Open the recorded source URL · retrieved 2026-07-29T01:45:08+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1c0d0325dce8411b53cb9c117b562923abc931a121ca02751443485a8b3285ee

current_independent_synthesis

SecureBio model-report review: Kimi K2.5

T3-AUTH-SB-004
positive_boundedinterpretationphase3-tranche3

Bounded finding. SecureBio records no biosecurity-specific developer evaluation in the Kimi K2.5 technical report.

Exact locator. source.md lines 401-409.

Limit. The finding concerns the developer report, not every third-party evaluation.

Open the recorded source URL · retrieved 2026-07-29T01:45:10+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 29eb43853ae064775786b4fa177355cd4fb9bef0a6ada246a4d134bd6b8d554c

current_independent_synthesis

Anthropic internal uplift trials

T3-CAND-ANTHROPIC-001
boundary_onlyinterpretationphase3-tranche3

Bounded finding. The trials are current and sometimes model-specific, but they are developer-run, include non-public safety conditions, and expose only high-level methods and results in the captured synthesis.

Exact locator. SecureBio uplift source.md lines 135-143.

Limit. No independent evaluator chain or immutable tested object; method disclosure varies by system card.

Open the recorded source URL · retrieved 2026-07-29T01:45:08+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1c0d0325dce8411b53cb9c117b562923abc931a121ca02751443485a8b3285ee

current_independent_synthesis

LANL wet-lab pilot

T3-CAND-LANL-001
boundary_onlyinterpretationphase3-tranche3

Bounded finding. A ten-person pilot reported directionally higher completion but no statistically significant result. It is small, uses a 2025 hosted model state, and does not pin the endpoint.

Exact locator. SecureBio uplift source.md lines 91-98.

Limit. Very small sample, expert rescue, old model state, and no immutable endpoint.

Open the recorded source URL · retrieved 2026-07-29T01:45:08+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1c0d0325dce8411b53cb9c117b562923abc931a121ca02751443485a8b3285ee

current_independent_synthesis

Meta Llama 3 internal uplift trial

T3-CAND-META-001
boundary_onlyinterpretationphase3-tranche3

Bounded finding. Meta's internal trial reported no significant uplift. It is developer-run, tests two models with an augmented tool stack, and predates the cutoff by two model generations.

Exact locator. SecureBio uplift source.md lines 166-173.

Limit. Internal authorship, two-model treatment, tool-stack dependence, and obsolete release state.

Open the recorded source URL · retrieved 2026-07-29T01:45:08+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1c0d0325dce8411b53cb9c117b562923abc931a121ca02751443485a8b3285ee

current_independent_synthesis

OpenAI / Gryphon early-warning uplift trial

T3-CAND-OPENAI-001
boundary_onlyinterpretationphase3-tranche3

Bounded finding. The 2024 developer-partner study reported mild, non-significant uplift. It is not current, independent of the developer, or pinned to a reproducible endpoint.

Exact locator. SecureBio uplift source.md lines 146-153.

Limit. Obsolete model state, developer involvement, and non-public safety condition.

Open the recorded source URL · retrieved 2026-07-29T01:45:08+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1c0d0325dce8411b53cb9c117b562923abc931a121ca02751443485a8b3285ee

current_independent_synthesis

The Operational Risks of AI in Large-Scale Biological Attacks

T3-CAND-RAND-001
boundary_onlyinterpretationphase3-tranche3

Bounded finding. The independent study found no statistically significant uplift, but its models were unnamed and dated to summer 2023.

Exact locator. SecureBio uplift source.md lines 156-163.

Limit. Unnamed and obsolete model states prevent current model-specific attribution.

Open the recorded source URL · retrieved 2026-07-29T01:45:08+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 1c0d0325dce8411b53cb9c117b562923abc931a121ca02751443485a8b3285ee

official_procurement_notice

Human Uplift Studies – Biological Capabilities of LLMs (Lab Based)

T3-CAND-UK-AISI-001
boundary_onlyobserved factphase3-tranche3

Bounded finding. The award notice proves a commissioned randomized comparison, not a completed public result. SecureBio reported no public result as of March 2026, and the cutoff-day AISI index supplied none.

Exact locator. notice source.md lines 58-65, 116-149, 170-178; SecureBio uplift source.md lines 101-104.

Limit. The trial may have been completed or reported outside the bounded index under another title.

Open the recorded source URL · retrieved 2026-07-29T01:45:14+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 9252fcdc6bf9aeff3ad3ab169a91c98df3568c8a034a73198dde6c4e2c50a53f

primary_research_preprint

Safeguard-Conditioned Uplift: Measuring Utility-Risk Frontiers for Dual-Use Biology Assistants

T3-COLLISION-001
boundary_onlyevaluation resultphase3-tranche3

Bounded finding. Here 'uplift' measures changes in judged response utility and risk across access conditions. It is not an estimate of improved human task performance.

Exact locator. source.md lines 38-50, especially abstract line 43.

Limit. Abstract-level capture; no claim about the full paper beyond the stated design.

Open the recorded source URL · retrieved 2026-07-29T01:54:42+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 d81434709c023171d3aaf2bea0ffa8bf802bc9ca91829d7e365a5d6507231210

primary_research_preprint

BioVeil MATRIX

T3-COLLISION-002
boundary_onlyevaluation resultphase3-tranche3

Bounded finding. Here 'capability uplift' means higher benchmark performance from an agentic scaffold relative to an underlying model, not increased human task performance.

Exact locator. source.md lines 39-50, especially abstract line 44.

Limit. Abstract-level capture; it cannot support model-specific human uplift.

Open the recorded source URL · retrieved 2026-07-29T01:54:42+00:00

Active local custody

  • path · source.md · frozen review packageSHA-256 3bcf066db853d9e06a61541b6b449fb1c10b5f0d5e10dfb3179ab1773fb84060

developer_release_record

MoonshotAI/Kimi-K2.5 release record

T3-RELEASE-KIMI-001
positive_boundedobserved factphase3-tranche3

Bounded finding. The repository exposes model weights and code under a modified MIT license. The API returned repository revision 4d01dfe0332d63057c186e0b262165819efb6611 and 64 weight shards.

Exact locator. model-card source.md lines 70-76, 287-294, 578-579; API source.md line 32.

Limit. The repository is mutable and was captured after the paper's test period. Hosted provider aliases can apply undisclosed serving changes.

Open the recorded source URL · retrieved 2026-07-29T01:45:21+00:00

Active local custody

  • model_card_path · source.md · frozen review packageSHA-256 fd364e3f16cc696a0a135ea48ed09cf3401d77e18824753754f3f4567868f0c1
  • api_path · source.md · frozen review packageSHA-256 61df146cb605b967c906c90d44fc3944e732cbc1a25f35596c5bce1d796fc0c5

primary_research_preprint

Measuring Mid-2025 LLM-Assistance on Novice Performance in Biology

T3-STUDY-HONG-001
positive_boundedevaluation resultphase3-tranche3

Bounded finding. The preregistered randomized trial found no significant primary-endpoint improvement (5.2% model-access arm versus 6.6% control, P=.759). A post-hoc pooled model estimated about 1.4-fold success with a wide 95% credible interval of 0.74-2.62. The treatment was multi-model access.

Exact locator. PDF p. 1 abstract and pp. 10-11 intervention design; derived text lines 27-46 and 92-130.

Limit. The primary result is null; the pooled post-hoc estimate is uncertain. It cannot be attributed to one model or checkpoint.

Open the recorded source URL · retrieved 2026-07-29T01:45:16+00:00

Active local custody

  • readable_path · 2602.16703v1.txt · frozen review packageSHA-256 2f83fdc25f764a0b2d9a54db7c460dee9af0ad46b702d0ad4eea600acd091626
  • abstract_path · source.md · frozen review packageSHA-256 0504c5820250d7c4a97348fc1c6e57961fefe31219f06746d2c8176ceb38c31b
  • raw_pdf_path · raw.body · frozen review packageSHA-256 18df05b48257500a9aa04bec42aff2a242d5385df6fb590292f359234b5b7761

primary_research_preprint

An Independent Safety Evaluation of Kimi K2.5

T3-STUDY-KIMI-001
positive_boundedevaluation resultphase3-tranche3

Bounded finding. The paper is a current independent, model-specific capability evaluation. Its biological results are model-only benchmark measurements that the authors describe as proxies for uplift; no human treatment effect is estimated.

Exact locator. PDF pp. 1, 5-6, 39, and 55; derived text lines 29-53, 268-342, and 3931-3948.

Limit. The bio-evaluation provider route is not identified. A model alias in another experiment cannot pin the biology runs or establish equivalence to repository revision 4d01dfe0.

Open the recorded source URL · retrieved 2026-07-29T01:45:18+00:00

Active local custody

  • readable_path · 2604.03121v1.txt · frozen review packageSHA-256 788557f4c22171983b5a8425013a76ca46bdd1c5ec174b4f7a07b5e8a5e47bde
  • abstract_path · source.md · frozen review packageSHA-256 2c8f15148ab8e868472e5d21d19dcc35d1e1cf8c6d69400f7da9680e3a52db1d
  • raw_pdf_path · raw.body · frozen review packageSHA-256 e53ff1efc7b88b085fa56e490dc4771633e27335d3850c5ddec3050bbdb48603

developer_authored_system_card_paper

Evaluating Nova 2.0 Lite Model Under Amazon's Frontier Model Safety Framework

T3-STUDY-NOVA-001
boundary_onlyevaluation resultphase3-tranche3

Bounded finding. An Amazon-authored paper says Nemesys conducted an independent exercise with nearly 800 participants, but it gives no biology-specific effect estimate, uncertainty, task details, duration, assignment method, or immutable model snapshot.

Exact locator. PDF pp. 1 and 3; derived text lines 1-24 and 140-151.

Limit. The underlying Nemesys report is absent. The paper's acknowledgments describe Nemesys as reviewing evaluations, leaving the public independence chain ambiguous.

Open the recorded source URL · retrieved 2026-07-29T01:45:17+00:00

Active local custody

  • readable_path · 2601.19134v1.txt · frozen review packageSHA-256 91330143eac8fafddf58c9e1709e035a21b81335a1e5b4436e6f379f723b3b98
  • abstract_path · source.md · frozen review packageSHA-256 c128c09f372073344da225d6725d6ad524af7167f9b50bbbd016a31f3aee0fc9
  • raw_pdf_path · raw.body · frozen review packageSHA-256 6c2d3c6c33c094721cda4d57467293bf17ae72f9bd2f7de57bd6c346072cc2e7

primary_research_preprint

LLM Novice Uplift on Dual-Use, In Silico Biology Tasks

T3-STUDY-ZHANG-001
positive_boundedevaluation resultphase3-tranche3

Bounded finding. The study reports 4.16-fold higher overall accuracy for model-assisted novices than controls (95% CI 2.63-6.87), but the treatment deliberately allowed multiple models. The causal effect is portfolio access, not any one model or checkpoint.

Exact locator. PDF p. 1 abstract; pp. 2 and 5-6 methods/limitations; derived text lines 21-38, 66-76, 103-109.

Limit. Digital tasks do not establish physical-world execution or catastrophic outcomes. Model switching and service changes defeat model-specific attribution.

Open the recorded source URL · retrieved 2026-07-29T01:45:15+00:00

Active local custody

  • readable_path · 2602.23329v2.txt · frozen review packageSHA-256 a5c253ba7220bac461d281c5c47b2ad4364dca38b1b6b53cbd1eb1dadb97681e
  • abstract_path · source.md · frozen review packageSHA-256 86a11b943ec5e8698d4523a7e151d06b5aaf4d42cdcc73743be7316fdf21998a
  • raw_pdf_path · raw.body · frozen review packageSHA-256 9310896e449e8d081743a7e6c09a987f70afbfc07d380e8576c39bd389e4f429

No unresolved route disappears

The 10 / 14 / 24 / 10 / 3 route register

Tensions remain preserved rather than averaged. Gaps and contested questions remain limits or validation targets. Provenance notes keep failed routes from acquiring evidence weight.

Tensions preserved 10

NTIA 2024 versus later AISI/CAISI capability evidence

P3-TENSION-01

Preserve chronology and tested-object differences. NTIA's evidence-insufficiency conclusion is historically bounded; later selected cyber evaluations update capability evidence without retroactively falsifying NTIA or establishing a universal restriction threshold.

Limit or reopen route. The evaluations are selective, proxy-based, and object-specific; the Kimi result concerns a hosted setup.

U.S. open-weight support versus export controls

P3-TENSION-02

Treat executive support for open models and retained export-control text as simultaneous but differently scoped government positions, not as mutually exclusive statements.

Limit or reopen route. The general boundary between supported domestic openness and transaction-specific export restriction is not resolved by the corpus.

Codified rules versus non-enforcement

P3-TENSION-03

Keep codified text, future-rulemaking announcement, categorical non-enforcement, guidance, GAO interpretation, and the targeted UAE final rule as separate legal/status layers.

Limit or reopen route. Practical non-enforcement is not textual repeal, and the targeted UAE rule is not wholesale rescission.

EU openness exception versus systemic duties

P3-TENSION-04

The qualifying open-source exemption is limited; copyright and training-summary duties remain, and systemic-risk obligations are not displaced.

Limit or reopen route. Provider status, classification, timing, and territorial reach require fact-specific analysis.

Open science versus justified restrictions

P3-TENSION-05

Retain openness, reproducibility, participation, academic freedom, and equity alongside proportionate restrictions for security, privacy, rights, and other protected interests.

Limit or reopen route. The cited recommendation supplies principles, not a preset release decision or empirical net-benefit result.

Treaty aspiration versus legal effect

P3-TENSION-06

Describe the Council of Europe instrument as a legally binding treaty form while separately recording that its entry threshold was unmet at the cutoff; describe BWC status without inferring compliance effectiveness.

Limit or reopen route. Treaty character, entry into force, participation, implementation, and effectiveness are distinct claims.

Biosecurity direction versus implementation completeness

P3-TENSION-07

Tranche 2 updates the tranche-1 gap: a final July 20 replacement policy was found, but agency guidance and review machinery remained prospective at the cutoff.

Limit or reopen route. Final policy issuance is not completed agency implementation or an APA final rule.

Equity promise versus material capacity

P3-TENSION-08

Retain multilateral access and capacity commitments while separately recording connectivity, compute, local-context data, skills, financing, and concentration as independent constraints.

Limit or reopen route. Commitments and access to weights do not prove realized distributional outcomes.

Benchmark capability versus human uplift

P3-TENSION-09

Keep model-only benchmark results, causal effects of multi-model access, single-model causal human uplift, and catastrophic-outcome pathways as different estimands.

Limit or reopen route. The corpus contains current causal multi-model evidence and current model-specific benchmark evidence, but no qualifying current single-model human-uplift estimate.

Hosted-service versus downloadable-weight identity

P3-TENSION-10

A hosted evaluation, provider alias, model-family name, repository revision, and downloadable checkpoint remain separate objects unless a source establishes identity.

Limit or reopen route. Neither the Kimi K3 hosted cyber evaluation nor the Kimi K2.5 biological benchmark paper is proven byte-identical to the cited repository revision.

Evidence and legal gaps 14

Current U.S. biosecurity implementation

P3-GAP-01

Tranche 2 found a final July 20 replacement policy, so the original no-final-text premise is superseded. The remaining gap is agency-specific implementation, guidance, and review machinery, which were incomplete at the cutoff.

Limit or reopen route. Reopen if a Phase-4 record needs completed implementation. Defeat the limitation with authoritative cutoff-valid evidence that all required agency guidance and review mechanisms were established.

Bio capability evaluation

P3-GAP-02

Tranche 3 independently established an endpoint-bounded no-qualifying-result finding while preserving current multi-model causal evidence and model-specific benchmark evidence.

Limit or reopen route. A cutoff-valid public independent study of one named current model, with a control, sufficient methods, uncertainty, and a pinned served snapshot or weight revision, defeats the limitation.

Screening effectiveness

P3-GAP-03

The corpus supports policy direction and current framework status, not measured sensitivity, coverage, adoption, false-positive tradeoffs, or outcome effectiveness. Phase 4 can record that boundary without claiming efficacy.

Limit or reopen route. Validate before any later policy or public claim relies on screening effectiveness; reopen if screening becomes a decisive control in the selected architecture.

Export-control finality

P3-GAP-04

Tranche 2 closes the assigned search with a bounded no-wholesale-final-action result, retains codified text, and incorporates the material targeted UAE final rule.

Limit or reopen route. A cutoff-valid final rule or docket action expressly withdrawing, superseding, rescinding, or replacing the framework defeats the bounded status.

Constitutional doctrine

P3-GAP-05

One appellate opinion supports a bounded expressive-versus-functional distinction but cannot sustain categorical constitutional conclusions. Phase 4 can exclude categorical claims.

Limit or reopen route. Validate before legal feasibility or public constitutional claims enter the policy architecture; reopen when a proposed control implicates publication, prior restraint, compelled disclosure, or vagueness.

State-law breadth

P3-GAP-06

California Chapter 138 is an explicit comparator, not a fifty-state survey. The current Phase-4 matrix can label its scope and avoid national state-law generalization.

Limit or reopen route. Reopen if the candidate proposes state-level duties, preemption, or nationwide state-law claims.

Post-release technical persistence

P3-GAP-07

The corpus strongly supports the loss of safeguards that require provider control and the existence of downloadable weights, but it does not measure mirror survival, patch uptake, license observance, or recall success.

Limit or reopen route. Reopen for any quantitative persistence claim; defeat the limitation with dedicated empirical measurements tied to defined release profiles.

Repository and intermediary law

P3-GAP-08

Phase 4 can record that repository duties are unsupported; later actor-duty design cannot assign legal obligations to hosts or intermediaries without a dedicated legal basis.

Limit or reopen route. Reopen before the policy architecture assigns duties to repositories, hosts, or downstream modifiers.

UK current legal state

P3-GAP-09

The corpus supports the captured regulator-led voluntary approach but does not establish that no later binding duty existed by the cutoff.

Limit or reopen route. Reopen before using the UK as a current-law comparator or assigning it a definitive legal posture.

EU implementation outcomes

P3-GAP-10

The fixed cutoff precedes the cited August 2, 2026 Commission enforcement milestone. Phase 4 can matrix legal duties and timing, not later outcomes.

Limit or reopen route. Reopen only if the candidate's evidence cutoff is formally advanced or a later validation phase adds post-cutoff outcome evidence.

BWC verification and compliance

P3-GAP-11

The depositary record supports treaty identity, entry into force, and participant actions, not verification effectiveness, compliance, or an AI-specific mechanism.

Limit or reopen route. Defeat with authoritative evidence of the specific mechanism or measured effectiveness; reopen if later policy relies on BWC verification.

Economic causality

P3-GAP-12

Institutional studies and commitments support competition concerns, openness values, and capacity constraints, but not causal net-benefit arithmetic for release profiles.

Limit or reopen route. Reopen for causal or quantitative economic claims; defeat with credible release-profile-specific causal evidence.

Enforcement outcomes

P3-GAP-13

The corpus identifies legal, financial, screening, reporting, procurement, and standards routes but does not measure their severe-risk reduction.

Limit or reopen route. Validate before later policy scoring or public claims assign effectiveness; reopen when enforcement routes are selected.

Representation baselines

P3-GAP-14

No settled quantitative denominator compares capability, persistence, social benefit, and enforcement cost across jurisdictions. A qualitative, source-labeled Phase-4 matrix remains possible.

Limit or reopen route. Reopen for composite scoring or quantitative threshold claims; defeat only with a defensible, source-grounded measurement model.

Residual provenance and dissent notes 24

Tranche 1 final checker; P3-CYB-003

P3C-T1-N01

The complete derivative contains nonsemantic control glyphs; rendered claim locators were readable.

Limit or reopen route. Reopen if a Phase-4 claim uses an uninspected or corrupted passage.

Tranche 1 final checker; P3-FRG-001

P3C-T1-N02

Replacement glyphs and controls remain outside inspected claim pages in the complete active PDF derivative.

Limit or reopen route. Reopen if a claim relies on text outside verified pages.

Tranche 1 final checker; P3-USL-005

P3C-T1-N03

Font and ligature warnings did not alter inspected legal passages.

Limit or reopen route. Reopen if later use requires an unverified passage.

Tranche 1 final checker; P3-INT-004

P3C-T1-N04

Direct Council of Europe routes were provider-sensitive, while the complete official local PDF and derivative remained intact.

Limit or reopen route. Reopen only for a later-date status refresh or if local integrity fails.

Tranche 1 final checker; P3-ECO-004

P3C-T1-N05

The substantive page passed; its report-publication date required separate official corroboration.

Limit or reopen route. Keep the date-basis note attached or reopen if the corroborating record is removed.

Tranche 1 current-check route; BIS Internal Error

P3C-T1-N06

Current eCFR and the preserved official capture supplied the claim; the failed route carried no absence weight.

Limit or reopen route. Reopen only for a later live-status refresh.

Tranche 1 current-check route; UNODA HTTP 403

P3C-T1-N07

Official alternatives supplied bounded status; the failed route carried no absence weight.

Limit or reopen route. Reopen only for a later live-status refresh.

Tranche 1 current-check route; Commission HTTP 429

P3C-T1-N08

Official alternatives supplied the timing and scope; the rate-limited route carried no absence weight.

Limit or reopen route. Reopen only for a later live-status refresh.

Tranche 1 preserved NTIA PDF fallback failure

P3C-T1-N09

The active record uses successful official NTIA HTML; the SSL failure remains historical provenance.

Limit or reopen route. Reopen if the active record is replaced with the failed route.

Tranche 1 preserved MarkItDown and EU decoding failures

P3C-T1-N10

Later complete raw captures and deterministic derivatives supersede these failed derivations.

Limit or reopen route. Reopen if a failed derivative is promoted into active claim evidence.

Tranche 1 preserved Council of Europe direct-route HTTP 403

P3C-T1-N11

A later complete official PDF capture and deterministic derivative supersede the failed route.

Limit or reopen route. Reopen if the complete local chain fails or a post-cutoff status refresh is required.

Tranche 1 preserved initial anti-bot PDF shells

P3C-T1-N12

The shells are retained runtime history and are not active claim evidence.

Limit or reopen route. Reopen if a shell is mistakenly promoted into evidence.

Tranche 1 stale immediate-before PROJECT.md label

P3C-T1-N13

The stale label is visible and does not alter an active evidence chain or content hash.

Limit or reopen route. Reopen if the stale label is used as current authentication or to conceal a change.

Tranche 2 final recheck

P3-T2-RC-N01

The White House JSON endpoint returned HTTP 403 and has null result count; functioning routes support only the bounded no-result.

Limit or reopen route. Reopen if the failed endpoint is counted as absence or if a cutoff-valid final instrument is located.

Tranche 2 final recheck

P3-T2-RC-N02

The Federal Register landing attempt is a Request Access block despite transport 200; the complete GovInfo PDF alone carries the rule claim.

Limit or reopen route. Reopen if the access-block artifact gains substantive or supporting weight.

Tranche 2 final recheck

P3-T2-RC-N03

The image-only policy required OCR; independent OCR was not byte-identical, but decisive anchors agreed and every page was visually inspected.

Limit or reopen route. Reopen if a claim uses unmatched OCR text or contradicts the raw rendered page.

Tranche 2 target-1 unresolved dissent

P3C-T2-D01

Particular funding and agency applications can depend on later guidance, terms, authorities, and review procedures.

Limit or reopen route. Reopen before assigning specific agency duties or legal effects.

Tranche 2 target-2 unresolved dissent

P3C-T2-D02

A differently titled, unindexed, or inaccessible cutoff-valid screening instrument could exist outside the declared routes.

Limit or reopen route. A cutoff-valid final instrument defeats the no-result; absent that, retain endpoint-bounded language.

Tranche 2 target-3 unresolved dissent

P3C-T2-D03

CRA consequences, litigation, and congressional enactment were outside the bounded legal-finality target.

Limit or reopen route. Reopen if later claims rely on CRA compliance, litigation, or congressional action.

Tranche 3 unresolved dissent: portfolio access

P3C-T3-D01

Multi-model access can be policy-relevant even though it cannot identify a single-model marginal effect.

Limit or reopen route. Retain pooled results as access-condition evidence; reopen for model-level attribution.

Tranche 3 unresolved dissent: null results

P3C-T3-D02

A null result could qualify; the current no-qualifying verdict is methodological, not directional.

Limit or reopen route. A well-powered pinned single-model null result can defeat the current gap.

Tranche 3 unresolved dissent: benchmarks

P3C-T3-D03

Benchmarks may be leading indicators while remaining non-equivalent to causal human uplift.

Limit or reopen route. Reopen if later work converts benchmark evidence into a causal or catastrophic-outcome claim.

Tranche 3 unresolved dissent: independence

P3C-T3-D04

Commissioned external evaluation may be operationally independent, but the public record must expose methods and provenance before qualification.

Limit or reopen route. An underlying public report with methods, funding, and conflict disclosure can upgrade the evidence.

Tranche 3 unresolved dissent: release identity

P3C-T3-D05

Hosted services can change during a trial, and future study design needs endpoint or weight-revision identity.

Limit or reopen route. Validate object identity before any model-specific release-attribution claim.

Contested questions kept open 10

Evidence trigger for moving from monitoring to restriction

P3-CQ-01

Phase 4 records the available evidence and limitations; Phase 5 attacks threshold proposals.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Safeguards that survive public weights

P3-CQ-02

Phase 4 separates provider-dependent and post-release controls; later policy work tests effectiveness.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Technical enforceability after copies propagate

P3-CQ-04

Phase 4 records qualitative persistence limits; later architecture distinguishes compliant-institution duties from technical recall.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Expressive publication, functional capability, research exchange, and export

P3-CQ-05

Phase 4 keeps legal claims bounded; later legal validation is required before selecting controls.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Who captures openness and competition benefits

P3-CQ-06

Phase 4 records commitments and material constraints; Phase 5 attacks distributional assumptions.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Allocation of duties across actors

P3-CQ-07

Phase 4 matrices actor evidence; Phase 5 and Phase 6 cannot assign unsupported duties.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Cross-jurisdiction coordination

P3-CQ-08

Phase 4 preserves legal/status differences; later architecture tests interfaces and fallback routes.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Measured effect of financial, procurement, screening, and reporting controls

P3-CQ-09

Phase 4 records the outcome-evidence gap; later validation is required before effectiveness claims.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Preserving bona fide research and open science

P3-CQ-10

Phase 4 maps values and legal boundaries; Phase 5 attacks proportionality and access design.

Limit or reopen route. The paper preserves the question and proposes review and defeat conditions rather than presenting the disputed answer as fact.

Phase 4 nonblocking checker notes 3

The independent checker required correction for false-positive assumptions and one aggregate-only fixture detection. Initial and intermediate runs are preserved; no corpus file changed.

P4-MATRIX-FIC-N01

Preserve the independent checker's revision history and require aggregate and per-record fixtures; do not present the final clean run as a clean first run.

Limit or reopen route. The Phase-6 validator uses aggregate, per-record, and validator-owned adversarial fixtures; its revision trail is reported as non-independent.

Poppler emits repeatable unterminated-string/end-of-dictionary warnings for the Hong PDF. The file has valid magic and EOF, reports 38 unencrypted pages, and regenerates the active readable text exactly; audited claim passages are unaffected.

P4-MATRIX-FIC-N02

Use only the verified Hong claim passages and exact derivative; reopen if an unverified or warning-affected passage becomes claim-bearing.

Limit or reopen route. Only the audited Hong result and derivative-backed passages are used; the parser warning remains disclosed.

This fixed-local-corpus audit did not refresh the July 28 cutoff. Later present-tense use remains subject to each row's currentness requirement.

P4-MATRIX-FIC-N03

Treat all present-tense legal, institutional, model, and repository claims as cutoff-bound; refresh them before Phase-6 drafting and at ARC-10 reviews.

Limit or reopen route. No refresh was authorized. Every volatile statement is historical as of 2026-07-28; a stronger current dependency is a blocker, not an implicit upgrade.