Skip to content

Add mapping packs so evidence can cite frameworks beyond SIMM 5305-F #46

Description

@ChelseaKR

What

src/gauntlet/mapping.py hard-codes SIMM 5305-F, SAM 4986.2, and SAM 4986.9. Vendors selling the same feature also answer NIST AI RMF and its Generative AI Profile (NIST AI 600-1), ISO/IEC 42001 clauses, Colorado SB 24-205, and the EU AI Act. The harness cannot cite any of them today, and it should not without reading them.

Add a mapping-pack format: a YAML file naming the framework, its edition and date, how_read, read_on, per-gate items with identifiers, and an unverified list with why_omitted. gauntlet report --mapping PATH (repeatable) renders one cross-reference section per pack. The California mapping becomes the built-in pack. Ship one more pack, NIST AI 600-1, only after reading the public PDF line by line, the way M1 read SIMM 5305-F.

Why it matters

The mapping's discipline is the product: "informs" is not "satisfies", only identifiers that were read are cited, a gate that maps to nothing verified says so. A pack mechanism extends that discipline instead of forking it. A test that fails when a pack cites an identifier absent from its own read list makes the rule enforced rather than promised.

Scope

  • Pack schema and loader; built-in CA pack extracted from mapping.py with byte-identical output.
  • --mapping flag; per-pack section in both forms; unmapped gates named per pack.
  • A NIST AI 600-1 pack with a dated read record.
  • An ISO/IEC 42001 skeleton with every identifier in unverified, because the text is not freely readable.

Out of scope

  • Any "compliant with" or "approved by" language.
  • Automated fetching of framework text.

Done when

  • --mapping twice renders two sections in a fixed order.
  • A pack citing an identifier not in its read list fails the loader and the test.
  • Default output without the flag is byte-identical to today.
  • docs/california-mapping.md is unchanged.

Pointers

  • src/gauntlet/mapping.py, src/gauntlet/report.py, docs/california-mapping.md, SCOPE.md "Claim rules"

Proposed with AI assistance.

Activity

  1. ChelseaKR commented on Sep 7, 2026

    @ChelseaKR
    OwnerAuthor

    Triage against origin/main (8ae3fa2): unbuilt, premise intact — and it splits into one automatable half and one that is not.

    Verified: src/gauntlet/mapping.py hard-codes SIMM 5305-F, SAM 4986.2 and SAM 4986.9 as module constants; gauntlet report has no --mapping flag. ✔

    Automatable: the pack format, the loader, extracting the California mapping into a built-in pack with byte-identical output, the repeatable --mapping flag, per-pack sections in both output forms, the ISO/IEC 42001 skeleton with every identifier in unverified, and — importantly — the test that fails when a pack cites an identifier absent from its own read list. That test is the whole discipline made mechanical and it is pure code.

    Not automatable, and this is the part to protect: "Ship one more pack, NIST AI 600-1, only after reading the public PDF line by line, the way M1 read SIMM 5305-F." An agent cannot honestly attest to having read a document. The entire value of SCOPE.md's claim rules is that a cited identifier was read by someone who can answer for it; a machine-generated NIST pack would be the first entry in this repository that says "read on " without that being true, and identifiers_not_verified exists precisely so unread material has somewhere honest to go.

    Recommended split: build the pack mechanism and the California extraction (mechanical, byte-identical output provable); file the NIST AI 600-1 pack as its own issue requiring the owner's read record. Whoever does the first half should ship the NIST pack empty with every identifier in unverified, not populated.

    Left open, unstarted.

    Triaged with AI assistance; premises checked against origin/main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestfeatureMajor new capability proposal

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions