Today: the five AI headlines of the day → and the AI Wiki

Crosswalk 1.0.0 · 8 pinned namespaces

Governance without false equivalence.

Risk frameworks, incident methods, law and vulnerability systems remain separately versioned. A mapping explains a relationship; it never manufactures conformity.

Registry, not certification.

This registry documents source namespaces and mapping rules. It contains no claim that Metatron, a system, an incident or a control conforms with any listed framework.

Inspect registry JSON →Validate registry →Incident & hazard contract →
NIST_AI_RMF · 1.0

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Voluntary AI risk-management outcomes across GOVERN, MAP, MEASURE and MANAGE.

Boundary: A mapping is not proof that a control is adequate, implemented or compliant; version 1.0 was under revision at the research cut-off.

Official source ↗
NIST_AI_600_1 · 1.0

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

Generative-AI risk actions including logging, incident documentation, near-misses, response and after-action learning.

Boundary: A voluntary profile, not a reporting law or exhaustive incident taxonomy.

Official source ↗
OECD_AI_INCIDENT_REPORTING · 2025-02-28

Towards a common reporting framework for AI incidents

A common, tailorable reporting format with incident criteria and dimensions.

Boundary: A reporting framework is not a finding that an incident occurred and is not a binding duty.

Official source ↗
OECD_AIM · methodology-since-2024-11

Overview and methodology of the AI Incidents and Hazards Monitor

Separates incidents involving actual harm from hazards involving plausible harm and documents a media/model-assisted discovery pipeline.

Boundary: Discovery and clustering do not independently verify accuracy, completeness or validity.

Official source ↗
EU_AI_ACT · Regulation-EU-2024-1689-consolidated-2026-07-27

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence

Namespaced legal concepts including serious incident in Article 3(49) and the Article 73 reporting pathway.

Boundary: Legal applicability is never inferred by the wiki; it requires jurisdiction-, actor- and system-specific qualified review.

Official source ↗
ISO_IEC_42001 · 2023

ISO/IEC 42001:2023 — Artificial intelligence management system

Public abstract supports an organisational AI management system and continual improvement.

Boundary: Public abstract only; no clause-level mapping, certification or conformity claim is permitted without authorised normative text.

Official source ↗
CISA_VDP · BOD-20-01

BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy

Process precedent for an authorised reporting channel, scope, expectations, tracking and coordinated remediation.

Boundary: Its binding scope is U.S. federal civilian agencies and cybersecurity vulnerabilities, not general AI intelligence contributions.

Official source ↗
CVE_RECORD_FORMAT · 5.2.0

CVE Record Format

Technical precedent for stable IDs, versioned schemas, controlled states, publisher metadata, timestamps, revisions and source containers.

Boundary: CVE models public cybersecurity vulnerabilities; CVE IDs and states must never be fabricated or repurposed for AI incidents.

Official source ↗

Mapping contract

  1. Pin every source and target version.
  2. Map exact elements, not document names or topical similarity.
  3. State direction and cardinality; never assume a bidirectional mapping.
  4. Publish a rationale and the omitted-content limitation.
  5. Keep framework-mapping confidence separate from event-evidence confidence and legal applicability.
  6. Preserve conflicts and none relations instead of forcing equivalence.
  7. An upstream version change marks affected mappings review_due; it never changes an editorial conclusion automatically.
  8. ISO clause and conformity mappings require authorised clause-level evidence.