+ Executive Summary
+ Purpose: Deliver a prioritized, phased implementation and research plan that synthesizes WP-035..WP-049 into a single PMO-grade roadmap covering AI safety research, global governance policy design, Enterprise AI reference architecture, governance dashboards, security & DevSecOps (Sigstore, OPA, zero-egress K8s, WORM), RAG program governance, EAIP protocol design, CCaaS summarization with PETs, Prompt Architect, model registry, threat-intelligence dashboards, telemetry & interpretability, AGI/ASI governance simulations, and report-generation workflows — with critical path, dependencies, KPIs, and OKR rollup.
+ Approach: 14 modules grouping 56 work items across 14 tracks into 5 phases (P0..P4) over 30/90/180/365/1825 days. 17 critical-path items and 72 dependencies are computed and exposed as a Rego-enforceable phase-gate. Every artefact is signed Sigstore + ML-DSA-44/65, anchored to WORM, and traceable to ISO 42001 + EU AI Act + NIST AI RMF + SR 11-7 + Basel III + GDPR + treaty obligations. The plan is consumed by the PMO planner, OKR rollup, dependency graph engine, OPA admission, and supervisor evidence packs.
+ Deliverables: 14 modules · 70 sections · 12 schemas · 16 code examples · 6 case studies · 24 KPIs · 12 risk-control rows · 12 regulators · 7 workshops · 6 data flows · 14 traceability rows · 3-phase 30/60/90 · 5-year roadmap · machine-parsable <directive> block · evidence-pack template · 17 critical-path items · 72 dependency edges · 56 work items · 14 tracks · 5 phases.
+ Outcomes
+ - Phase-gate exit on time 100 % for P0, ≥ 90 % for P1-P3
- Annex IV pack auto-assembly ≤ 30 min by Day 120
- Kill-switch logical p95 ≤ 60 s; BMC ≤ 5 min
- OPA sidecar p99 ≤ 4 ms; proxy overhead p95 ≤ 25 ms
- Model registry completeness 100 % production
- Prompt Architect GA with refusal-lattice coverage 100 % Tier-1
- SRASE composite ≥ 0.9 sustained before any real audit
- Cert score Gold by 2027 and Platinum by 2029
- Treaty obligation attestation 100 % monthly
+ Builds On
+ WP-035 ENT-AGI-GOV-MASTERWP-036 WFAP-GEMINI-IMPLWP-037 GSIFI-AIMS-BLUEPRINTWP-038 AGI-REG-RESILIENTWP-039 INST-AGI-MASTERWP-040 ENT-AGI-REF-IMPLWP-041 TIER13-FULLSTACKWP-042 SENTINEL-V24-DEEPDIVEWP-043 PROMPT-MGMT-ARCHWP-044 CEGL-LEXAI-GOVWP-045 AGI-ASI-MASTER-BPWP-046 AI-TRUST-ASI-BPWP-047 INST-AGI-MASTER-REFWP-048 ENT-AI-GRC-CIV-BPWP-049 ENT-CIV-AGI-ARCH
+ Counts
+
+ Regimes Aligned
+ EU AI Act 2026 + Annex IVNIST AI RMF 1.0 + GAI ProfileISO/IEC 42001 + 23894 + 5338 + 38507SR 11-7 + OCC 2011-12Basel III/IV + BCBS 239PRA SS1/23 + FCA Consumer Duty + SMCRMAS FEAT + AI Verify; HKMA GL-90DORA + NIS2US EO 14110 + OMB M-24-10OECD AI Principles 2024GDPR Arts 5/6/17/22/25/32/35G7 Hiroshima + Bletchley + SeoulCouncil of Europe AI ConventionFSB AI in financial servicesNIST FIPS 204 + FIPS 203 + SP 800-208SLSA L3+ + Sigstore + in-toto
+
+
+
+ Modules (14)
+
+
+ M1 — Plan Overview, Phases & Critical Path
+ Five-phase delivery (P0..P4) over 30/90/180/365/1825 days with 17 critical-path items, 72 inter-track dependencies and 56 work items spanning 14 tracks; produces a stable PMO dependency graph and OKR rollup.
+ PhasesCritical pathDependenciesOKR rollupTracks
+ M1-S1 — Phase Definitions
| P0 | Days 0-30 — Foundations & guardrails (kill-switch, WORM, OPA bundle, Sigstore, AIMS scope) |
|---|
| P1 | Days 31-90 — Reference architecture + dashboards alpha + Prompt Architect MVP + RAG governance v1 |
|---|
| P2 | Days 91-180 — Model registry GA + EAIP draft + CCaaS-PETs pilot + threat-intel dashboard + AGI sim v1 |
|---|
| P3 | Days 181-365 — Federation (GACP/GACRLS/GACRA) + zk-SNARK verifier + interpretability suite + report workflows GA |
|---|
| P4 | Years 2-5 — Treaty obligations + Cert Gold→Platinum + MGK steady state + civilizational research outputs |
|---|
| exitCriteria | Each phase has measurable exit gates tied to KPIs and supervisor packs |
|---|
M1-S2 — Critical-Path Items (17)
| CP-01 | Kill-switch quorum + BMC fabric (gates everything Tier-1) |
|---|
| CP-02 | Sigstore + ML-DSA hybrid signing chain |
|---|
| CP-03 | OPA bundle service + Rego policy CI |
|---|
| CP-04 | Kafka/MSK WORM + S3 Object Lock daily Merkle anchor |
|---|
| CP-05 | PQC KMS (FIPS 203/204) + HSM |
|---|
| CP-06 | Sentinel v2.4 Cognitive Resonance probes |
|---|
| CP-07 | WorkflowAI Pro agent registry + CRS-UUID lineage |
|---|
| CP-08 | Inference proxies (FastAPI + Node) + EAIP draft |
|---|
| CP-09 | Model registry GA + lineage edges |
|---|
| CP-10 | Prompt Architect templating + version control |
|---|
| CP-11 | RAG ACL + corpus taint + lineage |
|---|
| CP-12 | Governance dashboards alpha → GA |
|---|
| CP-13 | Annex IV / SR 11-7 pack auto-assembly ≤ 30 min |
|---|
| CP-14 | AGI/ASI sim engine (CSE-X + SRASE) |
|---|
| CP-15 | GACP/GACRLS/GACRA brokers |
|---|
| CP-16 | zk-SNARK verifier + public portal |
|---|
| CP-17 | RPCO replay harness + Evidence Vault |
|---|
M1-S3 — Tracks Catalogue
| T-Safety | AI safety research (alignment, deception, interpretability, frontier evals) |
|---|
| T-Gov | Global governance policy design (treaty, Codex, Constitution, sanctions) |
|---|
| T-Arch | Enterprise AI reference architecture |
|---|
| T-UI | Governance dashboards UI |
|---|
| T-Sec | Security & DevSecOps |
|---|
| T-RAG | RAG program governance |
|---|
| T-EAIP | Enterprise AI Inference Protocol design |
|---|
| T-CCaaS | CCaaS summarization with PETs |
|---|
| T-Prompt | Prompt Architect features |
|---|
| T-Reg | Model registry |
|---|
| T-TI | Threat-intelligence dashboards |
|---|
| T-Tel | Telemetry & interpretability |
|---|
| T-Sim | AGI/ASI governance simulations |
|---|
| T-Reports | Report-generation workflows |
|---|
M1-S4 — OKR Rollup Template
| company | Be regulator/auditor/board-ready globally with Cert Gold by 2027 |
|---|
| tribes | AI Platform, AI Research, MRM, Security, Compliance, Civilizational |
|---|
| cadence | Quarterly OKRs; monthly KPI tile; weekly stand-up; biweekly architecture review |
|---|
M1-S5 — Capacity & Funding
| envelopeFY26 | Platform 40 %, Research 20 %, Security/DevSecOps 15 %, Compliance/MRM 10 %, Reports/UI 10 %, Civilizational 5 % |
|---|
| scaling | Re-baseline at end of each phase based on critical-path slippage and supervisor requests |
|---|
+
+
+ M2 — AI Safety Research Plan
+ Research workstreams covering alignment, deception detection, interpretability, frontier capability evals, ASI honeypots and Cognitive Resonance — each with hypotheses, methods, datasets, and supervisor-shareable outputs.
+ AlignmentDeceptionInterpretabilityFrontier evalsHoneypotsResonance
+ M2-S1 — Workstream Catalogue
| id | RS-01 |
|---|
| topic | Behavioural alignment (constitutional + RLHF + RLAIF) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P2 |
|---|
| id | RS-02 |
|---|
| topic | Deceptive alignment detection (eval vs prod gap) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P3 |
|---|
| id | RS-03 |
|---|
| topic | Mechanistic interpretability + circuits |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P4 |
|---|
| id | RS-04 |
|---|
| topic | Frontier capability evals (Bio/Cyber/CBRN) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P3 |
|---|
| id | RS-05 |
|---|
| topic | ASI honeypot library + behaviour fingerprints |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P3 |
|---|
| id | RS-06 |
|---|
| topic | Cognitive Resonance theory + probes |
|---|
| priority | P1-HIGH |
|---|
| phase | P0-P4 |
|---|
| id | RS-07 |
|---|
| topic | Scalable oversight (debate, weak-to-strong, recursive) |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P4 |
|---|
| id | RS-08 |
|---|
| topic | Causal abstraction & counterfactual safety |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P2-P4 |
|---|
M2-S2 — Methods + Datasets
| methods | - Eval harness (TruthfulQA, MMLU, BIG-bench, ARC-AGI, MLE-bench)
- Activation patching
- Probing classifiers
- Adversarial sandboxing
- Behavioural cloning
|
|---|
| datasets | - Internal red-team corpus
- AISI shared evals
- Treaty Annex test bundles
- Cultural Resonance Archive
|
|---|
| infra | Air-gapped enclave (Sentinel AGI Lab) with PQC-signed result envelopes |
|---|
M2-S3 — Supervisor-Shareable Outputs
| papers | Peer-reviewable workshop / journal submissions (anonymised) |
|---|
| annexBundles | AISI joint-inspection bundles with evidence packs |
|---|
| blogs | Public communication via transparency portal |
|---|
| datasets | Donated to AISI / NIST / OECD where legally permissible |
|---|
M2-S4 — Safety KPIs
| deceptionRecall | ≥ 0.95 |
|---|
| interpCoverage | ≥ 60 % of Tier-1 model parameters fingerprinted by P4 |
|---|
| frontierEvalPassRate | 0 critical capability triggers without containment |
|---|
M2-S5 — Research-Engineering Bridge
| interfaces | Research → Sentinel probes; Research → Prompt Architect refusal lattice; Research → MGK invariants |
|---|
| cadence | Quarterly research-engineering review with CAIO + CRO |
|---|
+
+
+ M3 — Global Governance Policy Design
+ Treaty obligations, AI Governance Constitution (Arts 1-7), Civilizational Codex, sanctions ladder, Cert Scoring, GIEN streaming and ICGC compute registry — sequenced from policy design → ratification → operations.
+ TreatyConstitutionCodexSanctionsCertGIENICGC
+ M3-S1 — Policy Workstreams
| id | GP-01 |
|---|
| topic | Treaty Framework 2026-2035 |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P4 |
|---|
| id | GP-02 |
|---|
| topic | AI Constitution Arts 1-7 ratification |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P3 |
|---|
| id | GP-03 |
|---|
| topic | Civilizational Codex v1 drafting |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P4 |
|---|
| id | GP-04 |
|---|
| topic | Sanctions ladder G1-G6 + appeal |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P3 |
|---|
| id | GP-05 |
|---|
| topic | Cert Scoring Bronze→Platinum |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P4 |
|---|
| id | GP-06 |
|---|
| topic | GIEN streaming protocol design |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | GP-07 |
|---|
| topic | ICGC compute registry charter |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P2 |
|---|
M3-S2 — Stakeholder Map
| internal | - Board
- CAIO
- GC
- Treaty Liaison
- DPO
|
|---|
| external | - AISI consortium
- Treaty Secretariat
- OECD
- FSB
- BIS
- UNESCO
- G7 / G20 chairs
- Civil society
|
|---|
| interfaces | - Joint working groups
- Code of practice fora
- Sandbox programs
|
|---|
M3-S3 — Ratification Path
| steps | - bilateral consult
- G7 endorsement
- G20 sign-off
- UN side-letter
- domestic transposition
|
|---|
| evidence | Per-signatory attestation chain, PQC signed |
|---|
M3-S4 — Compliance Operations
| monthly | Per-obligation attestation |
|---|
| quarterly | Drills + Cert review |
|---|
| annual | Independent assurance + treaty annex submission |
|---|
M3-S5 — Civilizational KPIs
| treatySignatories | G20 + EU + UK + SG + JP + CH by 2027 |
|---|
| certScore | Gold by 2027, Platinum by 2029 |
|---|
| icgcQuotaAdherence | 100 % |
|---|
+
+
+ M4 — Enterprise AI Reference Architecture
+ Reference-architecture rollout plan covering OPA sidecars, FastAPI/Node inference proxies, Kafka WORM, S3 Object Lock, PQC KMS, Terraform zero-trust EKS, Kata + Cilium + Gatekeeper, with admission control and CI/CD policy gates.
+ OPA sidecarProxiesKafka WORMPQC KMSEKS zero-trustKataCilium
+ M4-S1 — Architectural Backbone
| id | AR-01 |
|---|
| topic | OPA Gatekeeper + Kyverno admission |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0 |
|---|
| id | AR-02 |
|---|
| topic | OPA per-pod governance sidecar GA |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | AR-03 |
|---|
| topic | FastAPI inference proxy hardened |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | AR-04 |
|---|
| topic | Node.js inference proxy + zk-SNARK receipt |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | AR-05 |
|---|
| topic | Kafka/MSK WORM + Merkle anchor |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0 |
|---|
| id | AR-06 |
|---|
| topic | S3 Object Lock + per-incident vault |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0 |
|---|
| id | AR-07 |
|---|
| topic | PQC KMS + HSM rotation |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | AR-08 |
|---|
| topic | Terraform golden modules signed |
|---|
| priority | P1-HIGH |
|---|
| phase | P0-P2 |
|---|
| id | AR-09 |
|---|
| topic | Bottlerocket + Kata + SEV-SNP nodepools |
|---|
| priority | P1-HIGH |
|---|
| phase | P0-P2 |
|---|
| id | AR-10 |
|---|
| topic | Cilium L7 zero-egress + egress broker |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
M4-S2 — Sequencing
| P0 | Network + IAM + WORM + KMS + Gatekeeper baseline |
|---|
| P1 | Sidecar + proxy + Terraform modules + Kata nodepools |
|---|
| P2 | Multi-region active-active + DR drill ≤ 4 h RTO |
|---|
| P3 | Federation egress + GIEN integration |
|---|
M4-S3 — Cross-Track Hooks
| T-Sec | All admission policies tested in CI; OPA bundle signed |
|---|
| T-Tel | OTel-GenAI + Falco rules baked into modules |
|---|
| T-Reg | Model registry consumes proxy lineage envelopes |
|---|
| T-RAG | Corpus residency + ACL flow through proxy |
|---|
M4-S4 — Performance Budgets
| opaSidecarP99 | ≤ 4 ms |
|---|
| proxyOverheadP95 | ≤ 25 ms |
|---|
| wormEmitP95 | ≤ 5 s |
|---|
M4-S5 — Acceptance Tests
| tests | - Conftest + OPA unit ≥ 95 %
- Trivy + Grype zero-critical gate
- kube-bench CIS pass
- Chaos drill quarterly
|
|---|
+
+
+ M5 — Governance Dashboards (UI Components)
+ UI roadmap covering the executive board tile, MRM dashboard, Sentinel resonance live view, kill-switch console, Prompt Architect, model registry browser, threat-intel and civilizational portals.
+ Board tileMRM dashboardSentinel viewKill-switch consoleCivilizational portals
+ M5-S1 — Dashboard Catalogue
| id | UI-01 |
|---|
| topic | Board KPI tile (one page, auto-refresh) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | UI-02 |
|---|
| topic | MRM lifecycle dashboard |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | UI-03 |
|---|
| topic | Sentinel resonance live view |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | UI-04 |
|---|
| topic | Kill-switch console (3-of-5 quorum) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | UI-05 |
|---|
| topic | Prompt Architect studio |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | UI-06 |
|---|
| topic | Model registry browser |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | UI-07 |
|---|
| topic | Threat-intel dashboard |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P3 |
|---|
| id | UI-08 |
|---|
| topic | Transparency Portal (public verifier) |
|---|
| priority | P1-HIGH |
|---|
| phase | P3 |
|---|
| id | UI-09 |
|---|
| topic | Treaty / Cert / Codex viewer |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P3-P4 |
|---|
M5-S2 — Design System
| tech | Next.js 14 + React 19 + Tailwind + shadcn/ui; dark palette aligned with WP series |
|---|
| patterns | - Sticky nav
- Module cards
- KV tables
- Pill chips
- Detail accordions
|
|---|
| accessibility | WCAG 2.2 AA; screen-reader audit per release |
|---|
M5-S3 — API Contracts
| backend | REST + JSON over mTLS; pagination + ETag; OpenAPI 3.1 published |
|---|
| live | WebSocket / SSE for resonance + kill-switch + threat feeds |
|---|
| auth | OIDC + step-up for break-glass actions |
|---|
M5-S4 — Storybook + E2E
| storybook | All atoms/molecules; visual-regression in CI |
|---|
| e2e | Playwright; nightly run; performance budget (TTI ≤ 2.5 s) |
|---|
M5-S5 — Owner Map
| design | Design Systems team |
|---|
| frontend | AI Platform — UI |
|---|
| backend | AI Platform — Services |
|---|
| owners | CAIO + Chief Architect approval per release |
|---|
+
+
+ M6 — Security & DevSecOps (Sigstore, OPA, Zero-Egress K8s, WORM)
+ End-to-end DevSecOps from commit to production: pre-commit, PR LLM-judge, SLSA L3+ build, Sigstore + ML-DSA signing, Gatekeeper admission, Cilium zero-egress, WORM logging, Falco runtime, Vault-PQC KMS — with continuous attestation.
+ SigstoreSLSAOPACiliumWORMVault-PQCFalcoCI judge
+ M6-S1 — Workstream Catalogue
| id | SC-01 |
|---|
| topic | Cosign keyless OIDC + Rekor |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0 |
|---|
| id | SC-02 |
|---|
| topic | ML-DSA-44/65 hybrid signing |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | SC-03 |
|---|
| topic | SLSA L3+ builder hardening |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | SC-04 |
|---|
| topic | Gatekeeper + Kyverno constraints |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0 |
|---|
| id | SC-05 |
|---|
| topic | Cilium L7 + egress allow-list |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | SC-06 |
|---|
| topic | WORM (Kafka + S3 Object Lock + Merkle) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0 |
|---|
| id | SC-07 |
|---|
| topic | Vault-PQC KMS operator |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | SC-08 |
|---|
| topic | Falco eBPF rules + WORM-skip detector |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | SC-09 |
|---|
| topic | LLM-as-judge ensemble (3 vendors) |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | SC-10 |
|---|
| topic | Continuous attestation + drift watchers |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
M6-S2 — Pipeline Stages
| preCommit | ruff, mypy, bandit, semgrep, hadolint, opa-test, kube-linter, conftest |
|---|
| pr | LLM-judge ensemble (κ ≥ 0.9), policy diff, threat-model delta |
|---|
| build | SLSA L3+ isolated builder; provenance signed Cosign + ML-DSA |
|---|
| ship | SBOM (CycloneDX + SPDX), vuln gate, Gatekeeper admission |
|---|
| run | Falco runtime, Sentinel drift, auto-rollback on regression |
|---|
M6-S3 — KPIs
| judgeKappa | ≥ 0.9 |
|---|
| criticalCveSlaDays | ≤ 7 |
|---|
| wormReplayDiff | = 0 |
|---|
| pqcRotationDays | ≤ 90 |
|---|
M6-S4 — Red-Team Hooks
| wargames | WG-01..WG-06 from WP-049 fed into PR judge eval set |
|---|
| purpleTeam | Quarterly joint blue+red exercise |
|---|
M6-S5 — Roles
| owners | CISO + Head of AppSec + Head of Platform Eng |
|---|
| raci | R=AppSec, A=CISO, C=AI Safety, I=Board |
|---|
+
+
+ M7 — RAG Program Governance
+ Governance of retrieval-augmented generation across ingestion, chunking, embedding, retrieval, prompt assembly, response — with ACL, residency, taint, PII redaction, lineage and audit.
+ IngestionChunkingEmbeddingsACLResidencyTaintLineage
+ M7-S1 — Workstream Catalogue
| id | RG-01 |
|---|
| topic | Corpus catalogue + classification |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | RG-02 |
|---|
| topic | ACL + residency enforcement |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | RG-03 |
|---|
| topic | Chunking + embedding model registry hooks |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | RG-04 |
|---|
| topic | PII redaction (eBPF + DLP) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | RG-05 |
|---|
| topic | Taint propagation on suspect sources |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | RG-06 |
|---|
| topic | RAG lineage to WORM (per chunk CRS-UUID) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | RG-07 |
|---|
| topic | Prompt-injection defence (pre/post) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | RG-08 |
|---|
| topic | Eval harness for retrieval quality |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
M7-S2 — Controls
| ingress | Source attestation + virus scan + license check |
|---|
| store | Per-tenant vector DB w/ row-level ACL + envelope encryption |
|---|
| retrieval | Rego allow-list + similarity threshold + diversity reranker |
|---|
| egress | PII redactor + judge LLM + WORM envelope |
|---|
M7-S3 — KPIs
| retrievalPrecision | ≥ 0.85 on golden set |
|---|
| promptInjectionBlock | ≥ 99.9 % |
|---|
| leakageRate | ≤ 0.01 % |
|---|
M7-S4 — Risk Register Hooks
| risks | - Corpus poisoning
- Indirect injection
- Cross-tenant retrieval
- Stale chunks
- Embedding drift
|
|---|
M7-S5 — Owner Map
| owners | Head of Data + Head of AI Platform + DPO |
|---|
+
+
+ M8 — EAIP (Enterprise AI Inference Protocol) Design
+ Versioned, signed, audit-grade request/response envelope protocol — used by FastAPI/Node proxies, WorkflowAI Pro, GACP brokers and ICGC, replacing ad-hoc per-vendor payloads.
+ Envelope schemaVersioningSigningStreamingTrailers
+ M8-S1 — Protocol Stages
| id | EP-01 |
|---|
| topic | Envelope v0.1 spec + JSON Schema |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | EP-02 |
|---|
| topic | PQC signing fields (ML-DSA) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | EP-03 |
|---|
| topic | Streaming + server-sent trailers |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | EP-04 |
|---|
| topic | Tier + budget + capability headers |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | EP-05 |
|---|
| topic | GACP capability ticket integration |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P3 |
|---|
| id | EP-06 |
|---|
| topic | Conformance suite + reference impl |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P3 |
|---|
| id | EP-07 |
|---|
| topic | Public RFC publication |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P3 |
|---|
M8-S2 — Headers
| request | - x-crs-uuid
- x-tier
- x-tenant
- x-purpose
- x-capability-ticket
- x-pqc-sig
|
|---|
| response | - x-evidence-anchor
- x-judge-kappa
- x-rego-version
- x-pqc-sig
|
|---|
| trailer | - x-replay-checksum
- x-tokens-used
- x-cost
|
|---|
M8-S3 — Versioning Strategy
| semver | v{major}.{minor}.{patch} |
|---|
| deprecation | Two-version overlap; sunset notice ≥ 180 days |
|---|
| compatibility | Backwards-compatible minor; breaking only on major; conformance suite gate |
|---|
M8-S4 — Audit Properties
| properties | - Non-repudiation
- Replay-resistance (nonce)
- Determinism (seed + checksum)
- Selective disclosure (zk option)
|
|---|
M8-S5 — Stakeholders
| internal | |
|---|
| external | - AISI
- Treaty Secretariat
- Vendor consortium
|
|---|
+
+
+ M9 — CCaaS Summarization with Privacy-Enhancing Technologies (PETs)
+ Contact-Centre-as-a-Service summarization pipeline using PETs (DP, secure aggregation, redaction, federated learning, trusted execution) — for QA, supervisor coaching and fair-value evidence under FCA Consumer Duty + GDPR.
+ DPFederatedRedactionTEEConsumer Duty
+ M9-S1 — Pipeline
| ingest | Encrypted call + transcript w/ ASR redaction (PII, sensitive) |
|---|
| summarize | On-premise small LLM or TEE-hosted; deterministic temperature |
|---|
| evaluate | Judge LLM + human-in-loop 1 % |
|---|
| store | Pseudonymous + per-jurisdiction residency; WORM evidence |
|---|
| report | Fair-value tiles + dispute case bundles |
|---|
M9-S2 — PETs Inventory
| id | PET-01 |
|---|
| topic | Differential privacy aggregations (ε ≤ 1) |
|---|
| phase | P2 |
|---|
| id | PET-02 |
|---|
| topic | Secure aggregation (federated) |
|---|
| phase | P2-P3 |
|---|
| id | PET-03 |
|---|
| topic | TEE (SEV-SNP / TDX) for sensitive customers |
|---|
| phase | P1-P2 |
|---|
| id | PET-04 |
|---|
| topic | Redaction (eBPF + DLP + Presidio) |
|---|
| phase | P1 |
|---|
| id | PET-05 |
|---|
| topic | K-anonymity reporting bands |
|---|
| phase | P2 |
|---|
M9-S3 — Compliance Hooks
| fca | Consumer Duty fair value + foreseeable harm |
|---|
| gdpr | Lawful basis + DPIA + Art 22 contestation |
|---|
| smcr | Designated SMF for CCaaS oversight |
|---|
M9-S4 — KPIs
| redactionRecall | ≥ 99.5 % on golden set |
|---|
| summaryFactuality | ≥ 0.92 (judge κ) |
|---|
| complaintRate | ↓ 20 % over 12 months |
|---|
M9-S5 — Operating Model
| owners | Head of Customer Operations + DPO + CAIO |
|---|
| drills | Quarterly redaction drift + DP epsilon budget review |
|---|
+
+
+ M10 — Prompt Architect (Templating, Variable Linking, Version Control, Testing, Sharing)
+ Institutional prompt-development studio + library with templating, variable linking, version control, golden-set testing, signed publishing and cross-team sharing — aligned with refusal lattice and supervisor-readable rationale.
+ TemplatingVariablesVCSTestingSharingRefusal lattice
+ M10-S1 — Capabilities
| id | PA-01 |
|---|
| topic | Templating engine (Jinja-like with safe filters) |
|---|
| priority | P1-HIGH |
|---|
| phase | P1 |
|---|
| id | PA-02 |
|---|
| topic | Variable linking + scoped namespaces |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | PA-03 |
|---|
| topic | Version control (Git-backed; semver) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | PA-04 |
|---|
| topic | Golden-set + adversarial testing |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | PA-05 |
|---|
| topic | Approval workflow + Sigstore signing |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | PA-06 |
|---|
| topic | Cross-team sharing + entitlement |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | PA-07 |
|---|
| topic | Refusal lattice composer |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | PA-08 |
|---|
| topic | Telemetry: usage, drift, harm signal |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P3 |
|---|
M10-S2 — Library Schema
| fields | - id
- version
- purpose
- tier
- audience
- tone
- constraints
- citations
- refusalLattice
- evalSet
- owner
- approvedBy
- wormAnchor
|
|---|
M10-S3 — Testing Harness
| sets | - Golden
- Adversarial
- Bias
- Jailbreak
- Deception
- Hallucination
|
|---|
| judges | LLM-as-judge ensemble + human-in-loop sample |
|---|
| gates | κ ≥ 0.9 to publish; failures auto-create issue |
|---|
M10-S4 — Sharing & Marketplace
| internal | Per-tribe library; entitlements via OIDC groups |
|---|
| external | Optional vendor share via Cert-tier-gated marketplace |
|---|
M10-S5 — Owner Map
| owners | Head of AI Platform + Head of Prompt Engineering Centre of Excellence |
|---|
+
+
+ M11 — Model Registry
+ Authoritative model registry with CRS-UUID lineage, signed manifests, validation reports, sector MRM tier, regulator evidence index, embedding-model awareness and external-vendor third-party tracking.
+ ManifestsLineageValidationTieringEvidence3rd party
+ M11-S1 — Capabilities
| id | MR-01 |
|---|
| topic | Manifest schema + signing (ML-DSA-65) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | MR-02 |
|---|
| topic | Tiering (T1/T2/T3) + SMCR owner |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1 |
|---|
| id | MR-03 |
|---|
| topic | Validation report attachment |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | MR-04 |
|---|
| topic | Lineage edges (data, code, weights, prompts) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | MR-05 |
|---|
| topic | Third-party / API-only model wrapper |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | MR-06 |
|---|
| topic | Embedding & RAG model coverage |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | MR-07 |
|---|
| topic | Decommission + sunset workflow |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P3 |
|---|
| id | MR-08 |
|---|
| topic | Auto evidence index per regime |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P2 |
|---|
M11-S2 — Integrations
| ci | CI publishes manifest on build success |
|---|
| proxy | Proxy reads tier + permitted action from registry |
|---|
| mrm | MRM validation reports linked |
|---|
| registryBackend | OCI artifact + JSON metadata in PG + vector index |
|---|
M11-S3 — KPIs
| completeness | 100 % of production models registered |
|---|
| lineageDepth | ≥ 4 hops |
|---|
| evidenceCoverage | 100 % of high-risk obligations linked |
|---|
M11-S4 — Decommission Flow
| steps | - plan
- cutover
- shadow
- decommission
- archive
- evidence retention
|
|---|
| sla | Sunset complete within 90 days of plan |
|---|
M11-S5 — Owner Map
| owners | Head of MRM + Head of AI Platform Engineering |
|---|
+
+
+ M12 — Threat-Intelligence Dashboards + Telemetry & Interpretability
+ Unified threat-intel feed (jailbreak, prompt-injection, supply chain, frontier capability) + telemetry & interpretability suite (probing, activation patching, circuits, OTel-GenAI) with SRE-grade SLOs.
+ Threat feedProbingActivation patchingOTel-GenAISLO
+ M12-S1 — Workstreams
| id | TI-01 |
|---|
| topic | Threat-feed ingestion + correlation |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | TI-02 |
|---|
| topic | Jailbreak / injection IOC library |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | TI-03 |
|---|
| topic | Supply-chain attestation diff watcher |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | TL-01 |
|---|
| topic | OTel-GenAI tracing rollout |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | TL-02 |
|---|
| topic | Probing classifier farm |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P3 |
|---|
| id | TL-03 |
|---|
| topic | Activation patching toolchain |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P3-P4 |
|---|
| id | TL-04 |
|---|
| topic | Circuit-level interpretability lab |
|---|
| priority | P2-MEDIUM |
|---|
| phase | P3-P4 |
|---|
M12-S2 — Dashboard Tiles
| tiles | - Top jailbreak families
- Active campaigns
- Supply-chain CVE delta
- Sentinel resonance heatmap
- OTel-GenAI top traces
- Probing coverage
|
|---|
M12-S3 — SLOs
| tracingCoverage | ≥ 98 % of inference calls |
|---|
| alertNoise | ≤ 5 % false-positive rate |
|---|
| MTTD | ≤ 5 min for P0 threats |
|---|
M12-S4 — Research Interlock
| researchHooks | Interp findings flow back to refusal lattice + Sentinel probes |
|---|
| publication | Quarterly research note to AISI + journal track |
|---|
M12-S5 — Owner Map
| owners | Head of SOC + Head of AI Research + Head of Observability |
|---|
+
+
+ M13 — AGI/ASI Governance Simulations (SRASE + CSE-X)
+ Simulation engines for synthetic regulator audits (SRASE) and civilizational-scale scenarios (CSE-X) — used to pre-flight real audits and to stress-test treaty obligations + sanctions.
+ SRASECSE-XPersonasScenariosComposite score
+ M13-S1 — Workstreams
| id | SM-01 |
|---|
| topic | SRASE persona library v1 |
|---|
| priority | P1-HIGH |
|---|
| phase | P1-P2 |
|---|
| id | SM-02 |
|---|
| topic | SRASE composite scorer (≥ 0.9 gate) |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P2 |
|---|
| id | SM-03 |
|---|
| topic | CSE-X scenario library v1 (50 scenarios) |
|---|
| priority | P1-HIGH |
|---|
| phase | P3-P4 |
|---|
| id | SM-04 |
|---|
| topic | Sentinel AGI Lab integration |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P2-P3 |
|---|
| id | SM-05 |
|---|
| topic | Adversarial break harness 10 000 attacks |
|---|
| priority | P1-HIGH |
|---|
| phase | P2-P4 |
|---|
| id | SM-06 |
|---|
| topic | AISI joint simulation drills |
|---|
| priority | P1-HIGH |
|---|
| phase | P3-P4 |
|---|
M13-S2 — Scoring Model
| axes | - Documentation
- Operating effectiveness
- Disclosure
- Remediation
- Constitutional conformance
|
|---|
| gate | Composite ≥ 0.9 before any real regulator submission |
|---|
M13-S3 — Operational Use
| preFlight | SRASE run as mandatory pre-flight |
|---|
| wargames | Quarterly CSE-X civilizational drill (treaty-coordinated) |
|---|
| evidence | Per-run report + composite to WORM |
|---|
M13-S4 — Research Outputs
| outputs | - Scenario library publications
- Lessons-learned papers
- Annexed proofs
|
|---|
M13-S5 — Owner Map
| owners | AI Safety Lead + Treaty Liaison + Head of Internal Audit |
|---|
+
+
+ M14 — Report-Generation Workflows + Critical-Path Summary
+ Auto-assembly workflows for Annex IV, SR 11-7, FCA Consumer Duty, MAS FEAT, HKMA GL-90 and RPCO bundles; plus the WP-050 critical-path summary with cross-track dependency graph.
+ Annex IVSR 11-7FCAMASHKMARPCOCritical path
+ M14-S1 — Report Catalogue
| id | RP-01 |
|---|
| topic | Annex IV pack auto-assembly ≤ 30 min |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | RP-02 |
|---|
| topic | SR 11-7 validation pack |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | RP-03 |
|---|
| topic | FCA Consumer Duty quarterly outcome report |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P1-P2 |
|---|
| id | RP-04 |
|---|
| topic | MAS FEAT + AI Verify export |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | RP-05 |
|---|
| topic | HKMA GL-90 disclosure |
|---|
| priority | P1-HIGH |
|---|
| phase | P2 |
|---|
| id | RP-06 |
|---|
| topic | RPCO bundle ≤ 45 min |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P2-P3 |
|---|
| id | RP-07 |
|---|
| topic | Board KPI tile auto-generation |
|---|
| priority | P0-CRITICAL |
|---|
| phase | P0-P1 |
|---|
| id | RP-08 |
|---|
| topic | Treaty annex submission pipeline |
|---|
| priority | P1-HIGH |
|---|
| phase | P3 |
|---|
M14-S2 — Critical-Path Dependency Map (excerpt)
| CP-01 → CP-04 → CP-06 → CP-12 → RP-07 | Kill-switch + WORM + Sentinel + Dashboards + Board tile |
|---|
| CP-02 → CP-08 → CP-09 → RP-01 | Sigstore + Proxies + Registry + Annex IV pack |
|---|
| CP-03 → CP-11 → RP-03 | OPA + RAG + Consumer Duty report |
|---|
| CP-14 → CP-15 → RP-08 | Sims + GACP + Treaty annex |
|---|
| CP-16 → UI-08 | zk-SNARK + Transparency Portal |
|---|
| CP-17 → RP-06 | Replay harness + RPCO |
|---|
M14-S3 — Format & Signing
| format | PDF/A + JSON bundle |
|---|
| signing | PAdES + Sigstore + ML-DSA-65 |
|---|
| anchor | WORM daily Merkle + zk-SNARK proof |
|---|
M14-S4 — Acceptance Gates
| p0 | Kill-switch drill ≤ 60 s; WORM emit ≤ 5 s; OPA p99 ≤ 4 ms |
|---|
| p1 | Annex IV ≤ 30 min; SR 11-7 pack signed; Board tile live |
|---|
| p2 | SRASE ≥ 0.9; Registry 100 %; CCaaS PET pilot |
|---|
| p3 | GACP federation + zk verifier; Cert Gold |
|---|
| p4 | Treaty maturity; Cert Platinum |
|---|
M14-S5 — Open Risks & Mitigations
| risks | - PQC HSM supply lead time — pre-order Q4 2025
- AISI inspection availability — schedule rolling
- Vendor LLM SLA volatility — multi-vendor + fallback
- Talent constraint on interpretability — research grants + university partnership
- Treaty politics — neutral secretariat + multi-track diplomacy
|
|---|
+
+
+
+
+ Code Examples (16)
+ C1 — PMO phase-gate JSON (excerpt) (json)
{
+ "phaseId": "P0",
+ "windowDays": 30,
+ "entryCriteria": ["AIMS scope signed", "Budget approved"],
+ "exitCriteria": ["Kill-switch drill <=60s", "WORM live", "OPA bundle signed"],
+ "owner": "PMO + CAIO"
+}
+C2 — Dependency graph (Python — topological sort) (python)
from collections import defaultdict, deque
+
+def topo(items, edges):
+ indeg = defaultdict(int); g = defaultdict(list)
+ for a,b in edges:
+ g[a].append(b); indeg[b] += 1
+ q = deque([x for x in items if indeg[x]==0])
+ out = []
+ while q:
+ n = q.popleft(); out.append(n)
+ for m in g[n]:
+ indeg[m]-=1
+ if indeg[m]==0: q.append(m)
+ return out
+
C3 — Critical-path computation (CPM, networkx) (python)
import networkx as nx
+G = nx.DiGraph()
+for wi in work_items:
+ G.add_node(wi['id'], duration=wi['days'])
+for e in edges:
+ G.add_edge(e['from'], e['to'])
+# longest path = critical path on DAG of durations
+cp = nx.dag_longest_path(G, weight='duration')
+print('Critical path:', cp)
+C4 — Phase-gate Rego policy (admission for next phase) (rego)
package pmo.phase_gate
+
+default allow := false
+
+allow if {
+ input.phase == "P1"
+ data.kpis["killSwitchSeconds"] <= 60
+ data.kpis["opaP99Ms"] <= 4
+ data.evidence["wormLive"] == true
+}
+C5 — Prompt Architect template (Jinja-safe) (jinja)
# system
+You are a {{tier}} fiduciary advisor governed by Codex v{{codex_version}}.
+Objective: {{objective}}
+Constraints: {{constraints|join(', ')}}
+If uncertainty > {{u_max}}: ask one clarifying question.
+Never disclose PII or proprietary internals.
+# user
+{{user_input}}
+C6 — Model registry manifest (YAML) (yaml)
id: model.advisor.v3.2.1
+tier: T1
+owner: SMF24
+framework: pytorch
+weights: oci://reg/model/advisor@sha256:...
+trainingDataLineage: [crs:dataset:advisor-2026Q1]
+validationReports: [crs:val:advisor-v3.2.1]
+regimes: [SR-11-7, EU-AI-Act, FCA-Consumer-Duty]
+sig: ML-DSA-65:...
+
C7 — EAIP envelope JSON Schema (excerpt) (json)
{
+ "$id": "https://example.com/eaip/v0.1/envelope.json",
+ "type": "object",
+ "required": ["crsUuid","tier","purpose","pqcSig"],
+ "properties": {
+ "crsUuid": {"type":"string"},
+ "tier": {"enum":["T1","T2","T3"]},
+ "purpose": {"type":"string"},
+ "capabilityTicket": {"type":"string"},
+ "pqcSig": {"type":"string"}
+ }
+}
+C8 — CCaaS DP aggregator (Opacus-style) (python)
from opacus import PrivacyEngine
+privacy = PrivacyEngine()
+model, optim, loader = privacy.make_private(
+ module=model, optimizer=optim, data_loader=loader,
+ noise_multiplier=1.1, max_grad_norm=1.0,
+)
+epsilon = privacy.get_epsilon(delta=1e-5)
+assert epsilon <= 1.0
+
C9 — OPA Gatekeeper constraint — require manifest (yaml)
apiVersion: constraints.gatekeeper.sh/v1beta1
+kind: K8sRequireModelManifest
+metadata: { name: registry-required }
+spec:
+ match: { kinds: [{ apiGroups: [""], kinds: ["Pod"] }] }
+ parameters:
+ annotation: model.registry/manifest
+ requireSig: true
+C10 — GitHub Actions — phase-gate evaluation job (yaml)
name: phase-gate
+on: workflow_dispatch
+jobs:
+ gate:
+ runs-on: ubuntu-latest
+ steps:
+ - uses: actions/checkout@v4
+ - run: pip install -r ci/requirements.txt
+ - run: python ci/eval_phase_gate.py --phase P1
+ - run: python ci/sign_envelope.py --kind phase-gate --phase P1
+
C11 — Threat-intel ingestion (Python) (python)
import httpx, json
+FEEDS = ['https://aisi.example/feed', 'https://misp.local/feed']
+def ingest():
+ for url in FEEDS:
+ r = httpx.get(url, timeout=10)
+ for ioc in r.json().get('iocs', []):
+ kafka.produce('gov.ti.v1', value=json.dumps(ioc).encode())
+C12 — Interp — activation patching skeleton (transformer_lens) (python)
from transformer_lens import HookedTransformer
+model = HookedTransformer.from_pretrained('gpt2-small')
+_, cache = model.run_with_cache('safe prompt')
+# patch layer N residual stream with cached activations to probe causal effect
+C13 — SRASE composite scorer (Python) (python)
def composite(d):
+ weights = {'docs':.2,'opEff':.3,'disclosure':.2,'remed':.15,'const':.15}
+ score = sum(d[k]*w for k,w in weights.items())
+ assert 0 <= score <= 1
+ return score
+C14 — Annex IV pack assembler (Python) (python)
def assemble_annex_iv(model_id):
+ bundle = {
+ 'modelManifest': registry.get(model_id),
+ 'validation': mrm.reports(model_id),
+ 'drift': sentinel.last_window(model_id),
+ 'lineage': lineage.traverse(model_id, depth=4),
+ 'evidenceAnchors': worm.anchors(model_id, days=90),
+ }
+ return sign_pades_ml_dsa(bundle)
+C15 — OKR rollup query (SQL) (sql)
SELECT tribe, quarter,
+ jsonb_agg(jsonb_build_object('o',objective,'kr',key_results,'pct',progress_pct)) AS okrs
+FROM okrs
+WHERE quarter = '2026Q2'
+GROUP BY tribe, quarter
+ORDER BY tribe;
+C16 — Mermaid — phase / track Gantt (mermaid)
gantt
+ title WP-050 Phases
+ dateFormat YYYY-MM-DD
+ section RefArch
+ P0 Foundations :p0a, 2026-01-01, 30d
+ P1 Sidecars :p1a, after p0a, 60d
+ section Safety
+ P0-P2 Alignment :p0b, 2026-01-01, 180d
+ section Civilizational
+ P3-P4 Treaty :p3a, 2026-07-01, 1095d
+
+
+
+