What
src/gauntlet/mapping.py hard-codes SIMM 5305-F, SAM 4986.2, and SAM 4986.9. Vendors selling the same feature also answer NIST AI RMF and its Generative AI Profile (NIST AI 600-1), ISO/IEC 42001 clauses, Colorado SB 24-205, and the EU AI Act. The harness cannot cite any of them today, and it should not without reading them.
Add a mapping-pack format: a YAML file naming the framework, its edition and date, how_read, read_on, per-gate items with identifiers, and an unverified list with why_omitted. gauntlet report --mapping PATH (repeatable) renders one cross-reference section per pack. The California mapping becomes the built-in pack. Ship one more pack, NIST AI 600-1, only after reading the public PDF line by line, the way M1 read SIMM 5305-F.
Why it matters
The mapping's discipline is the product: "informs" is not "satisfies", only identifiers that were read are cited, a gate that maps to nothing verified says so. A pack mechanism extends that discipline instead of forking it. A test that fails when a pack cites an identifier absent from its own read list makes the rule enforced rather than promised.
Scope
- Pack schema and loader; built-in CA pack extracted from
mapping.py with byte-identical output.
--mapping flag; per-pack section in both forms; unmapped gates named per pack.
- A NIST AI 600-1 pack with a dated read record.
- An ISO/IEC 42001 skeleton with every identifier in
unverified, because the text is not freely readable.
Out of scope
- Any "compliant with" or "approved by" language.
- Automated fetching of framework text.
Done when
--mapping twice renders two sections in a fixed order.
- A pack citing an identifier not in its read list fails the loader and the test.
- Default output without the flag is byte-identical to today.
docs/california-mapping.md is unchanged.
Pointers
src/gauntlet/mapping.py, src/gauntlet/report.py, docs/california-mapping.md, SCOPE.md "Claim rules"
Proposed with AI assistance.
What
src/gauntlet/mapping.pyhard-codes SIMM 5305-F, SAM 4986.2, and SAM 4986.9. Vendors selling the same feature also answer NIST AI RMF and its Generative AI Profile (NIST AI 600-1), ISO/IEC 42001 clauses, Colorado SB 24-205, and the EU AI Act. The harness cannot cite any of them today, and it should not without reading them.Add a mapping-pack format: a YAML file naming the framework, its edition and date,
how_read,read_on, per-gate items with identifiers, and anunverifiedlist withwhy_omitted.gauntlet report --mapping PATH(repeatable) renders one cross-reference section per pack. The California mapping becomes the built-in pack. Ship one more pack, NIST AI 600-1, only after reading the public PDF line by line, the way M1 read SIMM 5305-F.Why it matters
The mapping's discipline is the product: "informs" is not "satisfies", only identifiers that were read are cited, a gate that maps to nothing verified says so. A pack mechanism extends that discipline instead of forking it. A test that fails when a pack cites an identifier absent from its own read list makes the rule enforced rather than promised.
Scope
mapping.pywith byte-identical output.--mappingflag; per-pack section in both forms; unmapped gates named per pack.unverified, because the text is not freely readable.Out of scope
Done when
--mappingtwice renders two sections in a fixed order.docs/california-mapping.mdis unchanged.Pointers
src/gauntlet/mapping.py,src/gauntlet/report.py,docs/california-mapping.md,SCOPE.md"Claim rules"Proposed with AI assistance.