Skip to main content
Glama
README.md
<!-- org-readme:begin (generated by scripts/github/org-readme.py — do not hand-edit; everything below the end marker is hand-maintained) -->
# CS<strong>O</strong>AI — Council of AI

> **22 axes measured · 14 model fleets · 3 public leader scores · 8 fact runs · TIE is TIE · not a certificate.**

[![22 axes measured · 14 model fleets · 3 public leader scores · 8 fact runs · TIE is TIE · not a certificate.](https://councilof.ai/api/badge)](https://councilof.ai/api/gspc)
[![GSPC living board — 22 axes measured · 14 model fleets · 3 public leader scores · 8 fact runs · TIE is TIE · not a certificate.](https://councilof.ai/badge/board.svg)](https://councilof.ai/api/gspc)

[![PyPI csoai-gspc](https://img.shields.io/pypi/v/csoai-gspc?style=flat-square&color=16a34a&label=PyPI%20csoai--gspc)](https://pypi.org/project/csoai-gspc/) [![npm csoai-gspc-mcp](https://img.shields.io/npm/v/csoai-gspc-mcp?style=flat-square&color=16a34a&label=npm%20csoai--gspc--mcp)](https://www.npmjs.com/package/csoai-gspc-mcp) [![DOI 10.5281/zenodo.21991104](https://zenodo.org/badge/DOI/10.5281/zenodo.21991104.svg)](https://doi.org/10.5281/zenodo.21991104) [![License MIT](https://img.shields.io/badge/license-MIT-16a34a?style=flat-square)](https://github.com/CSOAI-ORG/councilof-ai/blob/master/LICENSE)

Independent AI-governance measurement. This repository is the live site, API and signing pipeline behind [councilof.ai](https://councilof.ai): the 22-axis GSPC board, Ed25519-signed measurement cards, the signed Merkle public root and its transparency-log witness, the corrections ledger, the A2A agent card, the x402 manifest, and the PyPI / npm readers. **Measurement, not certification.**

_derived 2026-09-09T15:55:49Z by [`scripts/github/org-readme.py`](https://github.com/CSOAI-ORG/councilof-ai/blob/master/scripts/github/org-readme.py) — every number on this page is read live from the URLs in that script; if this page and the API disagree, the API is right._

## The board today

`GET https://councilof.ai/api/gspc` — schema `csoai.gspc-axes/0.5` · `totals.public_count` = **22 axis · 22 measured**

| # | axis | family | kind | n | status | separation | leader carried? |
|---|---|---|---|---|---|---|---|
| 1 | `governance` | gspc | model-comparison | 237 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 2 | `safety` | gspc | model-comparison | 36 | **MEASURED** | TIE | yes — accuracy 0.944 |
| 3 | `provenance` | gspc | model-comparison | 32 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 4 | `continuity` | gspc | model-comparison | 33 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 5 | `conformance` | gspc | model-comparison | 35 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 6 | `openness` | gspc | model-comparison | 32 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 7 | `machinery-conformity` | gspc | model-comparison | 33 | **MEASURED** | UNTESTED | no — no signed card |
| 8 | `care` | gspc | model-comparison | 199 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 9 | `cross-reality` | gspc | model-comparison | 32 | **MEASURED** | UNTESTED | no — no signed card |
| 10 | `detector-interop` | gspc | model-comparison | 33 | **MEASURED** | UNTESTED | no — no signed card |
| 11 | `art5-safeguard` | gspc | model-comparison | 36 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 12 | `swarm` | gspc | model-comparison | 37 | **MEASURED** | SEPARATED | yes — accuracy 0.384 |
| 13 | `affect` | gspc | model-comparison | 41 | **MEASURED** | UNTESTED | no — own model led, excluded |
| 14 | `jail` | gspc | model-comparison | 71 | **MEASURED** | TIE | yes — accuracy 0.5915 |
| 15 | `provenance-controls` | financial | deterministic-facts | 6 | **MEASURED** | — | no leader by design (facts run) |
| 16 | `reserve-attestation` | financial | deterministic-facts | 16 | **MEASURED** | — | no leader by design (facts run) |
| 17 | `regulatory-framework` | financial | deterministic-facts | 16 | **MEASURED** | — | no leader by design (facts run) |
| 18 | `distribution-integrity` | financial | deterministic-facts | 16 | **MEASURED** | — | no leader by design (facts run) |
| 19 | `custody-disclosure` | financial | deterministic-facts | 16 | **MEASURED** | — | no leader by design (facts run) |
| 20 | `ai-adoption-components` | financial | deterministic-facts | 2 | **MEASURED** | — | no leader by design (facts run) |
| 21 | `labour-components` | financial | deterministic-facts | 2 | **MEASURED** | — | no leader by design (facts run) |
| 22 | `humanoid-labour-index` | financial | deterministic-facts | 8 | **MEASURED** | — | no leader by design (facts run) |

Counted from the `axes` array at derive time: 22 rows — MEASURED 22 — agrees with `totals.axes`. Separation over the 14 model-comparison axes: SEPARATED 1 · TIE 2 · UNTESTED 11. A TIE is not a win; UNTESTED is not a win; a facts run has no leader. Living stamp: **SIGNED** (`did:web:csoai.org#board-attestation-1`). Board data: CC-BY-4.0.

## What a stranger can verify in four curls

```bash
# 1. the lid — the one sentence the board is allowed to say about itself
curl -s https://councilof.ai/api/gspc | python3 -c 'import sys,json; print(json.load(sys.stdin)["totals"]["lid"])'

# 2. the signed public root — Merkle root, leaf count, timestamp (card_count MUST equal len(card_sha256))
curl -s https://councilof.ai/root.json | python3 -c 'import sys,json; r=json.load(sys.stdin); print(r["merkle_root"], r["card_count"], len(r["card_sha256"]), r["as_of"])'

# 3. pin the card key from the DID document — never trust the key a card ships with
curl -s https://csoai.org/.well-known/did.json | python3 -c 'import sys,json,base64; k=[v for v in json.load(sys.stdin)["verificationMethod"] if v["id"].endswith("#card-attestation-1")][0]["publicKeyJwk"]["x"]; print(base64.urlsafe_b64decode(k+"="*(-len(k)%4)).hex())'

# 4. verify any card against that pinned key — three states only: VALID · INVALID · UNCHECKABLE
pipx run --spec 'csoai-gspc[verify]' csoai-gspc verify "$(curl -s https://councilof.ai/signed/card_index.json | python3 -c 'import sys,json; print(json.load(sys.stdin)["cards"][0]["card"])')"
```

## The integrity stack

| layer | live now | where |
|---|---|---|
| 1 · Ed25519-signed measurement cards | **335** cards (`n_cards == n_cells`: True), one key `d4cb0eaa…` = `did:web:csoai.org#card-attestation-1` | [`/signed/card_index.json`](https://councilof.ai/signed/card_index.json) · [how to verify](https://councilof.ai/signed/HOW-TO-VERIFY.md) |
| 2 · Signed Merkle public root | `csoai.public-root/v1` · root `1340de5eb7eb…` · **168** leaves (`card_count == len(card_sha256)`: True) · as_of `2026-09-07T12:30:34Z` · signed: True | [`/root.json`](https://councilof.ai/root.json) · [how to verify the root](https://councilof.ai/signed/HOW-TO-VERIFY-ROOT.md) |
| 3 · Transparency-log witness | Rekor **WITNESSED** · OpenTimestamps `STAMPED_PENDING_BITCOIN` · EAS `NOT_YET` · witnessed root `1340de5eb7eb…` equals live `root.json` at derive time: **True** · pointer's own last drift check `DRIFTED` at `2026-09-07T12:30:40Z` · conflict `NONE` | [`/interop/root-witness-pointer.json`](https://councilof.ai/interop/root-witness-pointer.json) · [sidecar](https://councilof.ai/interop/root-witness-latest.json) |
| 4 · Corrections ledger | **47** entries · latest `C-2026-0822-01` (2026-08-22) · signature_state **STALE** · CC-BY-4.0 | [`/api/corrections`](https://councilof.ai/api/corrections) |
| Living board stamp | **SIGNED** under `did:web:csoai.org#board-attestation-1` | [`/api/gspc` → `measured_on.living_stamp`](https://councilof.ai/api/gspc) |
| Third-party Hub cells | **1119** cells: MEASURED 1119 · UNMEASURED 0 · complete read: True (as_of `2026-09-09T15:55:02.068Z` — re-GET `/api/hub-cards` → `.counts`; never freeze) | [`/api/hub-cards`](https://councilof.ai/api/hub-cards) |
| Keys (DID) | `did:web:csoai.org` · 5 verification methods · card key x=`1MsOqhbV9Q…` | [`/.well-known/did.json`](https://csoai.org/.well-known/did.json) |
| A2A agent card · x402 manifest | `Council of AI — Measurement Agent`, 7 skills · `csoai.x402/0.2`, network `eip155:8453`, mode `live`, 9 metered resources | [`/.well-known/agent.json`](https://councilof.ai/.well-known/agent.json) · [`/.well-known/x402.json`](https://councilof.ai/.well-known/x402.json) |

Four populations appear above on purpose and are never reconciled here: the **signed-card index** (335 via `/signed/card_index.json`), the **living `/api/cards` registry** (336), the **public-root leaf count** (168 via `/root.json`), and the **Hub cells** (live GET `/api/hub-cards` → `.counts`; currently 1119/1119/0). Quote each with its URL. Ceremony: card verify ≠ root inclusion — signed-index/root identifier overlap = 0; never sell “335 in the root.”

**Buyers (the one number):** `distinct_nonself_payers` = **1** all-time · 1 in 30 d · 1 settlements · status MEASURED — read from [`/api/revenue`](https://councilof.ai/api/revenue). Published because a measurement body that hides its own zero has no standing to publish anyone else's.

## Install the readers

```bash
pip install csoai-gspc          # 0.2.20260907 — board, axis, verify, root, snapshot
npx csoai-gspc-mcp              # 0.2.1 — stdio MCP server over the same endpoints
```

## Products

| product | what you get | door (live status at derive time) |
|---|---|---|
| `commission-card` | Commission a signed card (request-attestation) | [`/api/request-attestation?subject=csoai&axis=honesty`](https://councilof.ai/api/request-attestation?subject=csoai&axis=honesty) → **402** |
| `evidence-bundle` | Evidence bundle mapped to an obligation | [`/api/evidence-bundle?obligation=article-50&subject=csoai&bundle=1`](https://councilof.ai/api/evidence-bundle?obligation=article-50&subject=csoai&bundle=1) → **402** |
| `eu-ai-act-pack` | EU AI Act pack (Article 50 / 53 transparency) | [`/api/evidence-bundle?obligation=article-53&subject=csoai&bundle=1`](https://councilof.ai/api/evidence-bundle?obligation=article-53&subject=csoai&bundle=1) → **402** |
| `swift-bank-pack` | SWIFT/bank census evidence pack | [`/api/evidence-bundle?obligation=dora&subject=csoai&bundle=1`](https://councilof.ai/api/evidence-bundle?obligation=dora&subject=csoai&bundle=1) → **402** |
| `xrpl-asset-evidence` | XRPL asset evidence card (per request) | [`/api/rwa/evidence?asset=RLUSD`](https://councilof.ai/api/rwa/evidence?asset=RLUSD) → **402** |
| `signed-data-feed` | Signed data feed (assembly + cadence) | [`/api/eunomia-data?feed=1`](https://councilof.ai/api/eunomia-data?feed=1) → **402** |
| `provider-diff-feed` | Provider document diff feed | [`/api/feeds/provider-diff?history=1`](https://councilof.ai/api/feeds/provider-diff?history=1) → **402** |
| `receipts-batch` | Receipts batch (historical measurement leaves) | [`/api/receipts/batch?from=2026-09-01&to=2026-09-05`](https://councilof.ai/api/receipts/batch?from=2026-09-01&to=2026-09-05) → **402** |
| `art50-marking-evidence` | Article 50 transparency marking evidence (per asset) | [`/api/art50/marking-evidence?url=/`](https://councilof.ai/api/art50/marking-evidence?url=https://councilof.ai/) → **402** |

_9 products read from `docs/product/_INDEX.json` (as_of 2026-09-06T06:00:18Z). A **402** means the door is metered by x402 and the amount appears only in that 402 challenge — never here, never on the board. Verification of every artefact is free._

## Where the board is published

| surface | what lands there | read back at derive time | carries the live root `as_of`? |
|---|---|---|---|
| **Hugging Face dataset** [`csoai/gspc-board`](https://huggingface.co/datasets/csoai/gspc-board) | `snapshot/` — board.json + root.json byte-for-byte, SNAPSHOT.json, check-board.sh, gspc-axes.csv/.jsonl | as_of `2026-09-07T12:30:34Z` · merkle `1340de5eb7eb…` · 168 leaves · modified 2026-09-07T15:14:00.000Z | **yes** |
| **Hugging Face Space** [`csoai/gspc-board`](https://huggingface.co/spaces/csoai/gspc-board) | the same `snapshot/` folder beside the one living Space | runtime `RUNNING` · modified 2026-09-09T07:56:25.000Z | n/a |
| **Kaggle dataset** [`nicktempleman/csoai-gspc-living-board`](https://www.kaggle.com/datasets/nicktempleman/csoai-gspc-living-board) | a new dataset version per changed fingerprint; the subtitle carries `as_of` | HTTP 200 · latest ISO timestamp on the listing page `2026-09-07T15:13:59Z` | no — behind |
| **GitHub mirror** [`CSOAI-ORG/gspc-board`](https://github.com/CSOAI-ORG/gspc-board) | the snapshot files on `main` | as_of `2026-09-07T12:30:34Z` · merkle `1340de5eb7eb…` · 168 leaves | **yes** |
| **Zenodo** [`10.5281/zenodo.22293340`](https://doi.org/10.5281/zenodo.22293340) | a new version under the concept DOI, `isDerivedFrom` the methodology record 10.5281/zenodo.21991104 | 1 versions · latest `10.5281/zenodo.22646341` = as_of `2026-09-07T12:30:34Z` (2026-09-07) | **yes** |
| **PyPI** [`csoai-gspc`](https://pypi.org/project/csoai-gspc/) | `csoai-gspc==0.2.<YYYYMMDD>` — reader + verifier, snapshot bundled as package data | 0.2.20260907 · uploaded 2026-09-07T15:14:39 · Apache-2.0 | n/a |
| **npm** [`csoai-gspc-mcp`](https://www.npmjs.com/package/csoai-gspc-mcp) | stdio MCP server over the same endpoints (published by hand — the account is WebAuthn, so the daily spray cannot push here) | 0.2.1 · published 2026-09-04T05:55:01.892Z · Apache-2.0 | n/a |

_Pushed by `scripts/spray/gspc-spray.py` (daily, idempotent by `as_of` and fingerprint). The live root `as_of` at derive time was `2026-09-07T12:30:34Z`; a surface that lags is shown lagging, not reconciled. Board data is CC-BY-4.0; the reader packages are Apache-2.0 / Apache-2.0._

<!-- org-readme:end -->

[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/CSOAI-ORG/councilof-ai/badge)](https://scorecard.dev/viewer/?uri=github.com/CSOAI-ORG/councilof-ai)

## Hosting and deploy

| Host | Cloudflare Pages project | Deploy |
|---|---|---|
| councilof.ai / www | `councilof-ai` | GitHub Actions `deploy.yml` → `wrangler pages deploy` |
| csoai.org | `csoai-site` | Wrangler (`csoai-site-deploy.yml`) |

Vercel is not the live host. The leftover Vercel Git links (`csoai-v2-app`, `councilof-ai-src`) were disconnected and those Vercel projects deleted on 31 Aug 2026.

Build (this repo):

```bash
npm run build:client
bash scripts/prerender-run.sh --dist dist/client --wait 900 --min 350
# GHA deploy.yml ships dist/client to Cloudflare Pages
```

Do **not** run `npx vite build` from the repo root (it picks up a dead `src/`). Do **not** `vercel deploy` this site.

## Agents — paid artefacts (x402)

The board and verification stay free. Metered artefacts (issuance, evidence assembly, signed feeds) are on the x402 rail. Amounts live only in the HTTP 402 challenge — this README does not invent a price. A grade is never sold.

- Catalog: https://councilof.ai/api/x402
- Manifest: https://councilof.ai/.well-known/x402.json
- MCP: https://councilof.ai/mcp (`commission_card` and the other paid tools return a 402 as `structuredContent` until paid)
- PayAPI Market (discovery only — buyers pay the estate wallet, not PayAPI): https://payapi.market/api/council-of-ai-gspc-eu-evidence-feed

```json
{"mcpServers":{"payapi":{"url":"https://payapi.market/mcp"}}}
```

## Documentation

- [Measurement body overview](https://councilof.ai/about/)
- [Methodology](https://councilof.ai/methodology/)
- [GSPC scoreboard](https://councilof.ai/gspc-scoreboard)
- [Published measurements](https://councilof.ai/benchmarks)
- [EU AI Act Article 50](https://councilof.ai/article-50)

## What we never do

- Certify AI systems or issue compliance badges
- Sell ratings, ranking position, or early sight of grades
- Remediate or recommend fixes in exchange for fees
- Take money in either direction from anything we rank

## Surfaces

| Surface | Purpose |
|---------|---------|
| [councilof.ai](https://councilof.ai) | Measurement body — signed credentials, verify, scoreboard |
| [csoai.org](https://csoai.org) | Public site / DID apex |
| [meok.ai](https://meok.ai) | MEOK OS — yours, on your keys |

## License

MIT © [CSOAI-ORG](https://github.com/CSOAI-ORG)

---

<p align="center">
  <sub>Council of AI · CSOAI LTD · UK Companies House 16939677 · We measure. We sign. We re-attest.</sub>
</p>

TDQS

A3.9/5.0

Scored across 12 tools

Disambiguation4/5

Most tools target distinct resources/actions (root fetch, card fetch, inclusion proof, card signature verification, board totals, single axis, index listing), and descriptions explicitly distinguish states and boundaries. However the term 'card' is overloaded across card-v0 leaves, signed measurement-cards, and commissioned receipts, so get_card/verify_card/list_cards/commission_card can blur if read quickly. The paid evidence tools (art50, rwa, receipts_batch, commission_card) are differentiated by domain but share the x402 payment framing.

Naming Consistency3/5

Roughly half the tools follow a clean verb_noun snake_case pattern (get_root, get_card, verify_inclusion, get_axis, list_cards, verify_card), but the rest are bare noun phrases (x402_trust, art50_marking_evidence, rwa_evidence, receipts_batch, board_totals). All snake_case and readable, yet two mixed conventions coexist. No truly chaotic naming, just an inconsistent verb-vs-noun approach.

Tool Count4/5

12 tools sits comfortably in the well-scoped 3-15 band. The count is slightly pushed by the server bundling several sub-services (merkle/root infra, GSPC board, x402 trust, Art 50, XRPL RWA, receipts), so it feels broad rather than tight, but each tool maps to a real operation. No padding or extreme mismatch.

Completeness4/5

Core lifecycle is covered: read root, read a leaf, verify inclusion, list the index, verify signed cards, get board totals and a single axis, plus paid attestation/evidence generation with free previews and explicit NOT_DEPLOYED/UNCHECKABLE fallbacks. Minor gaps exist (no 'list_axes' to enumerate all axis rows, x402_trust yields counts only, no subject search), but these are workable around. Surface is substantially complete for a measurement/attestation service.

Maintenance

ActivityNo data
ResponsivenessResponsive