| Model artifacts in the release |
Files observed in the build: format, hash, size, identification strengthRecognised and hashed today; byte-level identification shipped in 0.4 as foundations |
Foundations shipped |
| Model & external-service inventory |
Declared models, deployment aliases, and external AI services, reconciled against what was observed |
In development |
| Datasets & provenance |
Dataset identity, provenance, licences, transformations, declared limitations |
Planned |
| Prompts & prompt bundles |
Prompt artifacts where they are genuine release artifacts, hashed and versioned |
Planned |
| Agents, tools & MCP dependencies |
Agent workflows, tools, and server dependencies with declared permissions and authority |
Planned |
| Frameworks, runtimes & supporting software |
The conventional software around the models — already first-class composition evidence |
Available today |
| Evaluation & test evidence |
Evaluation results, thresholds, and human acceptance recorded as evidence, never as verdicts |
Planned |
| AI-specific release drift |
Model, service, and prompt changes between releases, on the existing drift engine |
In development |
| Human review & AI-aware gates |
The live review queue, approvals, and explainable gates extended with AI-aware policies |
In development |
| Standards-based AI/ML BOM output |
Linked software SBOM plus CycloneDX ML-BOM and/or SPDX 3.0 AI & Dataset profile output |
Planned |
| Redacted AI evidence sharing |
A verifiable, redaction-audited AI evidence pack, following today's passport pattern |
Planned |