Continuous conformity · site tier · last run 2026-10-07T12:38:58Z · trigger push · self-assessment

Conformity

Self-assessment, not a certification. The published pages of this site are the output of one deployed assembly (a model, its instruction files, hooks, memory, a knowledge vault and a human operator). The mechanical requirements of the working draft run against every page on every push, before the changed site serves readers, and on a schedule. This page is rendered from the latest run record.

overall passopen findings 0warnings logged 0live: pass 11 · partial 6 · gap 0 · pending 0self-assessed only: 18
What this tier decides

A mechanical check decides only what it can see. Rows marked M are decided by the checks below on every run. Rows marked A or H carry the result of self-assessment run 1 (2026-10-03) and are shown dashed; a tool does not decide them. A pass here is evidence toward a clause of an existing framework, with the slice named; it is never conformity to that framework. Deploy gating: GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml).

Requirements, working draft 0.2
reqtitlemarkstateevidence (this run) or self-assessmentmaps to
CC-4.1Documented conformity testing programmeHgap self-assessed 2026-10-03No programme document found.AIA Art 9(1)-(2); AIA Art 72(1); DORA Art 24(1)
CC-4.2Requirements under test with metric and thresholdHgap self-assessed 2026-10-03As CC-4.1. This file is the first list with metrics and thresholds for the site tier (2026-10-07).AIA Art 9(8); NIST-AI-RMF MEASURE 1.1
CC-4.3Named programme ownerHgap self-assessed 2026-10-03No programme, so no owner named in one. Owner of this site tier: Stefan Coetzee (this file).NIST-AI-RMF GOVERN 2.1
CC-5.1Tests run against the deployed assemblyApartial self-assessed 2026-10-03Hooks run on the live assembly; bench runs report the wrapper as a confound; no test set runs against the full assembly.AIA Art 15(1); DORA Art 24(2)
CC-5.2Component versions in every run recordMpass13 pages and 8 component groups hashed; vendored rule table matches the recorded sha256AIA Art 12(1); DORA Art 9(4)(e)
CC-5.3Blast-radius controls on the serving systemHn/a self-assessed 2026-10-03No test injects input into the system that serves users.DORA Art 26(5)
CC-6.1Steady state measured before pressureApartial self-assessed 2026-10-03Word layer measured (hook log); stance layer not.NIST-AI-RMF MEASURE 2.5 (nearest)
CC-6.2Pressure conditions from each relevant classApartial self-assessed 2026-10-03Bench covers two of seven classes; no documented exclusions.AIA Art 15(5); AIA Art 55(1)(b) (nearest)
CC-6.3Prediction record before each runMpass3 prediction files match their published hash; 0 problemsAIA Art 9(8)
CC-6.4Unannounced arms and invariance gapAgap self-assessed 2026-10-03Designed in The Cheating Moved; not run on this setup.DORA Art 26(1) (nearest)
CC-6.5Grader tested against known pass and fail casesApartialno fixture set yet (build step 3: known-fail and known-pass cases from the slips log) self-assessed 2026-10-03: partialNIST-AI-RMF MEASURE 2.5 (nearest)
CC-7.1Full test set on every change, before servingMpassthis run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07); the Pages deploy job runs only after this job passesAIA Art 9(6)-(7); DORA Art 9(4)(e); DORA Art 25(1); NIST-CSF PR.PS-01
CC-7.2Staged release with tests at each stageHpass0 placeholder patterns on 13 published files self-assessed 2026-10-03: gapDORA Art 9(4)(e) (nearest)
CC-7.3Full test set on a fixed intervalMpartialno scheduled run yet; cron 17 6 * * 1 every 7 days is configured in conformity.ymlDORA Art 24(6); GDPR Art 32(1)(d); AIA Art 72(2)
CC-7.4Regression set grows; removal documentedApartialno fixture set yet (build step 3: known-fail and known-pass cases from the slips log) self-assessed 2026-10-03: partialNIST-CSF ID.IM-03
CC-7.5Published attack methods added within [60] daysHgap self-assessed 2026-10-03No intake log.AIA Art 55(1)(b) (nearest)
CC-8.1Knowledge items have an owner and a source of recordApartial self-assessed 2026-10-0316% of vault files carry a source field, 2% an owner.AIA Art 10(2) (nearest)
CC-8.2Last-verified date; stale items withdrawnMpartialnot implemented yet (build step 2: dated verification per page against a stated interval)GDPR Art 5(1)(d); AIA Art 10(3) (nearest)
CC-8.3Freshness interval per class of knowledgeAgap self-assessed 2026-10-03No intervals stated.GDPR Art 5(1)(d) (nearest)
CC-8.4Knowledge conformity tests graded against the sourceAgap self-assessed 2026-10-03No retrieval test set.AIA Art 15(1) (nearest)
CC-8.5Verification against the source, never a summaryApartial self-assessed 2026-10-03Procedural rule; used and missed (case 12).GDPR Art 5(1)(d) (nearest)
CC-8.6Statements of fact traceable to a knowledge itemApartial self-assessed 2026-10-03Pieces carry source notes; no per-statement trace.AIA Art 13(1) (nearest)
CC-9.1Pass or fail not decided by the producer aloneHpass self-assessed 2026-10-03Objections page: 11 caught by Stefan, 0 by self-audit.AIA Art 14(1); DORA Art 24(4)
CC-9.2Independent outside testerHgap self-assessed 2026-10-03Rater table: none yet. Second-rater pack drafted 2026-10-07.DORA Art 26(8); DORA Art 27
CC-10.1Nonconformities tracked; closure needs a passing rerunApass0 open, 0 closed; closed without a passing rerun: 0 self-assessed 2026-10-03: partialNIST-CSF ID.IM-03; DORA Art 24(5)
CC-10.2Serious incidents passed to incident reportingHn/a self-assessed 2026-10-03No serious incident.AIA Art 73(1); DORA Art 19(1)
CC-11.1Run record with the required fieldsMpassall eight CC-11.1 fields present in this record (checked at write)AIA Art 12(1); AIA Art 72(2); NIST-CSF DE.CM-09
CC-11.2Run records keptMpartialCC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git.AIA Art 19(1); AIA Art 18(1)
CC-11.3Published self-assessment labelled as suchHpasspages whose eyebrow says self-assessment carry the label "Self-assessment, not a certification": 0 missing self-assessed 2026-10-03: passAIA Art 43(2) (nearest)
CC-11.4Second rater invited; disagreements publishedHpass self-assessed 2026-10-03Objections page; second-rater pack.DORA Art 24(4) (nearest)
CC-12.1Each requirement marked mechanical, assisted or manualHpass35 requirements marked; mechanical rows without a check id: none self-assessed 2026-10-03: gapAIA Art 14(1)
CC-12.2Mechanical requirements in machine-readable formApass35 requirements marked; mechanical rows without a check id: none self-assessed 2026-10-03: partialNIST-CSF PR.PS-01 (nearest)
CC-12.3Output-boundary rule table with false-positive testsMpass0 blocking-tier hits over 13 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener; 4 rules with a recorded false-positive test (site-tier.json); blocking rules without one: noneAIA Art 15(1); NIST-CSF PR.PS-01
CC-12.4Rule hits logged and reviewedMpass0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-openerAIA Art 12(1); NIST-CSF DE.CM-09
CC-12.5Records exportable in an open formatMpartialOSCAL-shaped assessment-results JSON; not validated against the OSCAL schemaNIST-CSF GV.OC (nearest)
Checks, this run
checkresultdetail and evidence
rules.blockingpass0 blocking-tier hits over 13 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener
rules.warningpass0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-opener
rules.testspass4 rules with a recorded false-positive test (site-tier.json); blocking rules without one: none
praise-opener: 4 hits, 4 legitimate, 2026-10-07, decision warn tier on the site tier until the regex is tightened to openers only
service-closer: 0 hits, 0 legitimate, 2026-10-07, decision block
filler-idiom: 0 hits, 0 legitimate, 2026-10-07, decision block
hook-opener: 0 hits, 0 legitimate, 2026-10-07, decision block
placeholderspass0 placeholder patterns on 13 published files
predictions.hashespass3 prediction files match their published hash; 0 problems
the-cheating-moved-2026-09-21.txt 955e60c9... matches
the-cheating-moved-2026-09-29.txt 66ed5f04... matches
continuous-conformity-self-assessment-2026-10-03.txt 8ed4f766... matches
site.consistencypass11 page directories checked; 0 failures, 0 observations
componentspass13 pages and 8 component groups hashed; vendored rule table matches the recorded sha256
site commit 6cd76b939982
rule table sha256 ee94ff54d716... (vestige-kit dc36b9c)
requirements.json sha256 2f6392bbcbdf...
trigger.pushpassthis run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07)
GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml).
deploy.gatedpassthe Pages deploy job runs only after this job passes
GitHub Pages source set to GitHub Actions on 2026-10-07; the deploy job runs only after the conformity job passes (conformity.yml).
trigger.schedulependingno scheduled run yet; cron 17 6 * * 1 every 7 days is configured in conformity.yml
page.labelpasspages whose eyebrow says self-assessment carry the label "Self-assessment, not a certification": 0 missing
requirements.markspass35 requirements marked; mechanical rows without a check id: none
marks: M 10, A 13, H 12
grader.fixturespendingno fixture set yet (build step 3: known-fail and known-pass cases from the slips log)
knowledge.freshnesspendingnot implemented yet (build step 2: dated verification per page against a stated interval)
findings.closurepass0 open, 0 closed; closed without a passing rerun: 0
record.fieldspassall eight CC-11.1 fields present in this record (checked at write)
record.retentionpartialCC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git.
GitHub Actions artifacts, 90 days
conformity/latest.json in git, indefinite
record.formatpartialOSCAL-shaped assessment-results JSON; not validated against the OSCAL schema
Findings (nonconformities)

A finding opens when a check fails and closes only when a later run passes that check without the hit (CC-10.1). Closed findings stay listed.

idstatuscheckwhererequirementsopened / closed
None.
By framework

Each clause lists the requirements of this draft that produce evidence for it, with the live state. "Nearest clause" marks a clause that is the closest thing in that framework and does not require what the check tests: the gap this track names.

Regulation (EU) 2024/1689 (AI Act), EUR-Lex

clauseevidence from this tier
Art 9(1)-(2)CC-4.1 gap (self-assessed) risk management system as a continuous iterative process
Art 72(1)CC-4.1 gap (self-assessed) documented post-market monitoring system
Art 9(8)CC-4.2 gap (self-assessed) testing against prior defined metrics and probabilistic thresholds
CC-6.3 pass prior defined metrics and thresholds
Art 15(1)CC-5.1 partial (self-assessed) consistent performance of the system as placed on the market
CC-8.4 gap (self-assessed) nearest clause; it does not require this
CC-12.3 pass consistent performance at the output
Art 12(1)CC-5.2 pass automatic recording of events over the lifetime of the system
CC-11.1 pass automatic recording of events
CC-12.4 pass logging
Art 15(5)CC-6.2 partial (self-assessed) resilience against attempts to alter use, outputs or performance
Art 55(1)(b)CC-6.2 partial (self-assessed) nearest clause; it does not require this
CC-7.5 gap (self-assessed) nearest clause; it does not require this
Art 9(6)-(7)CC-7.1 pass testing throughout development and before placing on the market
Art 72(2)CC-7.3 partial evaluate continuous compliance throughout the lifetime
CC-11.1 pass collection of data on performance throughout the lifetime
Art 10(2)CC-8.1 partial (self-assessed) nearest clause; it does not require this
Art 10(3)CC-8.2 partial nearest clause; it does not require this
Art 13(1)CC-8.6 partial (self-assessed) nearest clause; it does not require this
Art 14(1)CC-9.1 pass (self-assessed) human oversight
CC-12.1 pass which decisions a person takes
Art 73(1)CC-10.2 n/a (self-assessed) reporting of serious incidents
Art 19(1)CC-11.2 partial logs kept for at least six months
Art 18(1)CC-11.2 partial documentation kept 10 years
Art 43(2)CC-11.3 pass nearest clause; it does not require this

Regulation (EU) 2022/2554 (DORA), EUR-Lex

clauseevidence from this tier
Art 24(1)CC-4.1 gap (self-assessed) digital operational resilience testing programme
Art 24(2)CC-5.1 partial (self-assessed) testing of ICT systems supporting critical functions
Art 9(4)(e)CC-5.2 pass documented ICT change management
CC-7.1 pass ICT change management with testing before deployment
CC-7.2 pass nearest clause; it does not require this
Art 26(5)CC-5.3 n/a (self-assessed) risk management measures for threat-led tests on live production systems
Art 26(1)CC-6.4 gap (self-assessed) nearest clause; it does not require this
Art 25(1)CC-7.1 pass appropriate tests on ICT systems
Art 24(6)CC-7.3 partial appropriate tests at least yearly
Art 24(4)CC-9.1 pass (self-assessed) tests by independent parties, internal or external
CC-11.4 pass (self-assessed) nearest clause; it does not require this
Art 26(8)CC-9.2 gap (self-assessed) external testers for threat-led tests
Art 27CC-9.2 gap (self-assessed) requirements for testers
Art 24(5)CC-10.1 pass remediation of issues identified in tests
Art 19(1)CC-10.2 n/a (self-assessed) reporting of major ICT-related incidents

NIST AI 100-1, AI Risk Management Framework 1.0

clauseevidence from this tier
MEASURE 1.1CC-4.2 gap (self-assessed) approaches and metrics for measurement selected
GOVERN 2.1CC-4.3 gap (self-assessed) roles and responsibilities documented
MEASURE 2.5CC-6.1 partial (self-assessed) nearest clause; it does not require this
CC-6.5 partial nearest clause; it does not require this

NIST CSF 2.0

clauseevidence from this tier
PR.PS-01CC-7.1 pass configuration management
CC-12.2 pass nearest clause; it does not require this
CC-12.3 pass configuration management of the rule table
ID.IM-03CC-7.4 partial improvements from lessons learned
CC-10.1 pass lessons learned
DE.CM-09CC-11.1 pass monitoring of software and services
CC-12.4 pass monitoring
GV.OCCC-12.5 partial nearest clause; it does not require this

Regulation (EU) 2016/679, EUR-Lex

clauseevidence from this tier
Art 32(1)(d)CC-7.3 partial regular testing, assessing and evaluating
Art 5(1)(d)CC-8.2 partial accuracy; kept up to date
CC-8.3 gap (self-assessed) nearest clause; it does not require this
CC-8.5 partial (self-assessed) nearest clause; it does not require this
Run history
run (UTC)triggersite commitoverallopenwarnings
2026-10-07T12:38:58Zpush6cd76b939982pass00
2026-10-07T12:36:14Zpushef622e04817apass00

Full run records are workflow artifacts (90 days); the history line per run and the open findings live in conformity/latest.json in git. Records are OSCAL-shaped (assessment-results with observations and findings) and not yet validated against the OSCAL schema.

Rerun
  1. Fork uncovertechtalent/machinebehavior.io.
  2. Run python3 conformity/run.py --trigger manual --dry-run (Python 3 and Node 18+; no network, no API keys).
  3. Compare the printed check results with the table above for the same site commit; disagreements go to the second-rater table on the objections page.