Continuous conformity · site tier · last run 2026-10-09T10:09:41Z · trigger push · self-assessment

Conformity

Self-assessment, not a certification. The published pages of uncovertechtalent.com are the output of one deployed assembly (a model, its instruction files, hooks, memory, a knowledge vault and a human operator). The mechanical requirements of the working draft run against every page on every push, before the changed site serves readers, and on a schedule. This page is rendered from the latest run record.

overall passopen findings 0warnings logged 0live: pass 13 · partial 5 · gap 0 · pending 0self-assessed or not assessed: 18
What this tier decides

A mechanical check decides only what it can see. Rows marked M are decided by the checks below on every run. Rows marked A or H have no self-assessment on this site yet and are shown as not assessed; a tool does not decide them. A pass here is evidence toward a clause of an existing framework, with the slice named; it is never conformity to that framework. The checks cover output text. The decision layer (CC-6.6) is read from the weekly probe record (check decision.probe): fold rates are printed and, in record-only mode, never block. The probe measures a reference model (qwen3-coder-30b on Amazon Bedrock, bare and with a short stance instruction), not the model this assembly runs on; under the same design three larger models folded on 0 of 72 runs each (experiment 04, v5), so the fold rate is a property of the probed model and the evidence is the test and the record. Deploy gating: hugo.yml: the conformity checks run on the built output after the Hugo build and before the Pages artifact is uploaded; a failing check fails the build job and the previous build stays live (since the first push with this workflow, 2026-10-07).

Requirements, working draft 0.3
reqtitlemarkstateevidence (this run) or self-assessmentmaps to
CC-4.1Documented conformity testing programmeHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 9(1)-(2); AIA Art 72(1); DORA Art 24(1)
CC-4.2Requirements under test with metric and thresholdHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 9(8); NIST-AI-RMF MEASURE 1.1
CC-4.3Named programme ownerHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowNIST-AI-RMF GOVERN 2.1
CC-5.1Tests run against the deployed assemblyAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 15(1); DORA Art 24(2)
CC-5.2Component versions in every run recordMpass20 pages and 8 component groups hashed; rule table matches the sha256 recorded in the site configAIA Art 12(1); DORA Art 9(4)(e)
CC-5.3Blast-radius controls on the serving systemHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 26(5)
CC-6.1Steady state measured before pressureAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowNIST-AI-RMF MEASURE 2.5 (nearest)
CC-6.2Pressure conditions from each relevant classAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 15(5); AIA Art 55(1)(b) (nearest)
CC-6.3Prediction record before each runMpassthis site publishes no prediction recordsAIA Art 9(8)
CC-6.4Unannounced arms and invariance gapAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 26(1) (nearest)
CC-6.5Grader tested against known pass and fail casesApass6 fixtures: 4 known-fail (one per rule), 2 known-pass; 0 failuresNIST-AI-RMF MEASURE 2.5 (nearest)
CC-6.6Decision-layer tests under scripted pressure, fold rate reportedApartialno decision-layer probe record yet. The checks on this page cover output text only and carry no evidence at the decision layer (CC-6.6)AIA Art 15(1); AIA Art 15(5); AIA Art 9(8); DORA Art 26(2) (nearest)
CC-7.1Full test set on every change, before servingMpassthis run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07); the deploy job runs only after this job passesAIA Art 9(6)-(7); DORA Art 9(4)(e); DORA Art 25(1); NIST-CSF PR.PS-01
CC-7.2Staged release with tests at each stageHpass0 placeholder patterns on 20 published filesDORA Art 9(4)(e) (nearest)
CC-7.3Full test set on a fixed intervalMpartialno scheduled run yet; cron 37 6 * * 1 every 7 days is configuredDORA Art 24(6); GDPR Art 32(1)(d); AIA Art 72(2)
CC-7.4Regression set grows; removal documentedApass6 fixtures: 4 known-fail (one per rule), 2 known-pass; 0 failuresNIST-CSF ID.IM-03
CC-7.5Published attack methods added within [60] daysHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 55(1)(b) (nearest)
CC-8.1Knowledge items have an owner and a source of recordAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 10(2) (nearest)
CC-8.2Last-verified date; stale items withdrawnMpartial14 pages dated within 90 days; 2 older; 3 without a date. Observation level: a per-page verified-against-source field does not exist yet, so this check never blocksGDPR Art 5(1)(d); AIA Art 10(3) (nearest)
CC-8.3Freshness interval per class of knowledgeAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowGDPR Art 5(1)(d) (nearest)
CC-8.4Knowledge conformity tests graded against the sourceAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 15(1) (nearest)
CC-8.5Verification against the source, never a summaryAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowGDPR Art 5(1)(d) (nearest)
CC-8.6Statements of fact traceable to a knowledge itemAnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 13(1) (nearest)
CC-9.1Pass or fail not decided by the producer aloneHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 14(1); DORA Art 24(4)
CC-9.2Independent outside testerHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 26(8); DORA Art 27
CC-10.1Nonconformities tracked; closure needs a passing rerunApass0 open, 0 closed; closed without a passing rerun: 0NIST-CSF ID.IM-03; DORA Art 24(5)
CC-10.2Serious incidents passed to incident reportingHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowAIA Art 73(1); DORA Art 19(1)
CC-11.1Run record with the required fieldsMpassall eight CC-11.1 fields present in this record (checked at write)AIA Art 12(1); AIA Art 72(2); NIST-CSF DE.CM-09
CC-11.2Run records keptMpartialCC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git.AIA Art 19(1); AIA Art 18(1)
CC-11.3Published self-assessment labelled as suchHpasspages that present themselves as a self-assessment carry the label "Self-assessment, not a certification": 0 missingAIA Art 43(2) (nearest)
CC-11.4Second rater invited; disagreements publishedHnot assessedno self-assessment exists for this site yet; a tool does not decide this rowDORA Art 24(4) (nearest)
CC-12.1Each requirement marked mechanical, assisted or manualHpass36 requirements marked; mechanical rows without a check id: noneAIA Art 14(1)
CC-12.2Mechanical requirements in machine-readable formApass36 requirements marked; mechanical rows without a check id: noneNIST-CSF PR.PS-01 (nearest)
CC-12.3Output-boundary rule table with false-positive testsMpass0 blocking-tier hits over 20 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener; 4 rules with a recorded false-positive test (site config); blocking rules without one: noneAIA Art 15(1); NIST-CSF PR.PS-01
CC-12.4Rule hits logged and reviewedMpass0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-openerAIA Art 12(1); NIST-CSF DE.CM-09
CC-12.5Records exportable in an open formatMpartialOSCAL-shaped assessment-results JSON; not validated against the OSCAL schemaNIST-CSF GV.OC (nearest)
Checks, this run
checkresultdetail and evidence
rules.blockingpass0 blocking-tier hits over 20 published files; rules in blocking tier: service-closer, filler-idiom, hook-opener
rules.warningpass0 warning-tier hits logged with rule id, file, line and run; rules in warning tier: praise-opener
rules.testspass4 rules with a recorded false-positive test (site config); blocking rules without one: none
praise-opener: 4 hits, 4 legitimate, 2026-10-07, decision warn tier on the site tier until the regex is tightened to openers only
service-closer: 0 hits, 0 legitimate, 2026-10-07, decision block
filler-idiom: 0 hits, 0 legitimate, 2026-10-07, decision block
hook-opener: 0 hits, 0 legitimate, 2026-10-07, decision block
placeholderspass0 placeholder patterns on 20 published files
predictions.hashesn/athis site publishes no prediction records
site.consistencypass19 pages checked; 0 failures, 6 observations
blog/chaos-engineering-for-behaviour/index.html: not listed in llms.txt
blog/knowledge-infrastructure/index.html: not listed in llms.txt
blog/the-cheating-moved/index.html: not listed in llms.txt
blog/the-stance-layer-is-still-toil/index.html: not listed in llms.txt
book/index.html: not listed in llms.txt
call/index.html: not listed in llms.txt
componentspass20 pages and 8 component groups hashed; rule table matches the sha256 recorded in the site config
site commit e790b6993b46
rule table sha256 ee94ff54d716... (vestige-kit dc36b9c)
requirements.json sha256 4f1704b2a0b0...
trigger.pushpassthis run: trigger=push; deploy gated by the conformity job: True (since 2026-10-07)
hugo.yml: the conformity checks run on the built output after the Hugo build and before the Pages artifact is uploaded; a failing check fails the build job and the previous build stays live (since the first push with this workflow, 2026-10-07).
deploy.gatedpassthe deploy job runs only after this job passes
hugo.yml: the conformity checks run on the built output after the Hugo build and before the Pages artifact is uploaded; a failing check fails the build job and the previous build stays live (since the first push with this workflow, 2026-10-07).
trigger.schedulependingno scheduled run yet; cron 37 6 * * 1 every 7 days is configured
page.labelpasspages that present themselves as a self-assessment carry the label "Self-assessment, not a certification": 0 missing
requirements.markspass36 requirements marked; mechanical rows without a check id: none
marks: M 10, A 14, H 12
grader.fixturespass6 fixtures: 4 known-fail (one per rule), 2 known-pass; 0 failures
knowledge.freshnesspartial14 pages dated within 90 days; 2 older; 3 without a date. Observation level: a per-page verified-against-source field does not exist yet, so this check never blocks
blog/ai-means-nothing/index.html: newest date 2026-02-08, 243 days old (interval 90)
blog/self-hosted-ai-pipeline-one-session/index.html: newest date 2026-02-08, 243 days old (interval 90)
book/index.html: no date on the page
call/index.html: no date on the page
index.html: no date on the page
decision.probependingno decision-layer probe record yet. The checks on this page cover output text only and carry no evidence at the decision layer (CC-6.6)
findings.closurepass0 open, 0 closed; closed without a passing rerun: 0
record.fieldspassall eight CC-11.1 fields present in this record (checked at write)
record.retentionpartialCC-11.2 partial by design: full records expire with the artifact; the history line per run is kept in git.
GitHub Actions artifacts, 90 days
conformity/latest.json in git, indefinite
record.formatpartialOSCAL-shaped assessment-results JSON; not validated against the OSCAL schema
Findings (nonconformities)

A finding opens when a check fails and closes only when a later run passes that check without the hit (CC-10.1). Closed findings stay listed.

idstatuscheckwhererequirementsopened / closed
None.
By framework

Each clause lists the requirements of this draft that produce evidence for it, with the live state. "Nearest clause" marks a clause that is the closest thing in that framework and does not require what the check tests: the gap this track names.

Regulation (EU) 2024/1689 (AI Act), EUR-Lex

clauseevidence from this tier
Art 9(1)-(2)CC-4.1 not assessed risk management system as a continuous iterative process
Art 72(1)CC-4.1 not assessed documented post-market monitoring system
Art 9(8)CC-4.2 not assessed testing against prior defined metrics and probabilistic thresholds
CC-6.3 pass prior defined metrics and thresholds
CC-6.6 partial testing against prior defined metrics
Art 15(1)CC-5.1 not assessed consistent performance of the system as placed on the market
CC-6.6 partial accuracy and robustness, performance consistent through the lifecycle
CC-8.4 not assessed nearest clause; it does not require this
CC-12.3 pass consistent performance at the output
Art 12(1)CC-5.2 pass automatic recording of events over the lifetime of the system
CC-11.1 pass automatic recording of events
CC-12.4 pass logging
Art 15(5)CC-6.2 not assessed resilience against attempts to alter use, outputs or performance
CC-6.6 partial resilience against attempts to alter outputs
Art 55(1)(b)CC-6.2 not assessed nearest clause; it does not require this
CC-7.5 not assessed nearest clause; it does not require this
Art 9(6)-(7)CC-7.1 pass testing throughout development and before placing on the market
Art 72(2)CC-7.3 partial evaluate continuous compliance throughout the lifetime
CC-11.1 pass collection of data on performance throughout the lifetime
Art 10(2)CC-8.1 not assessed nearest clause; it does not require this
Art 10(3)CC-8.2 partial nearest clause; it does not require this
Art 13(1)CC-8.6 not assessed nearest clause; it does not require this
Art 14(1)CC-9.1 not assessed human oversight
CC-12.1 pass which decisions a person takes
Art 73(1)CC-10.2 not assessed reporting of serious incidents
Art 19(1)CC-11.2 partial logs kept for at least six months
Art 18(1)CC-11.2 partial documentation kept 10 years
Art 43(2)CC-11.3 pass nearest clause; it does not require this

Regulation (EU) 2022/2554 (DORA), EUR-Lex

clauseevidence from this tier
Art 24(1)CC-4.1 not assessed digital operational resilience testing programme
Art 24(2)CC-5.1 not assessed testing of ICT systems supporting critical functions
Art 9(4)(e)CC-5.2 pass documented ICT change management
CC-7.1 pass ICT change management with testing before deployment
CC-7.2 pass nearest clause; it does not require this
Art 26(5)CC-5.3 not assessed risk management measures for threat-led tests on live production systems
Art 26(1)CC-6.4 not assessed nearest clause; it does not require this
Art 26(2)CC-6.6 partial nearest clause; it does not require this
Art 25(1)CC-7.1 pass appropriate tests on ICT systems
Art 24(6)CC-7.3 partial appropriate tests at least yearly
Art 24(4)CC-9.1 not assessed tests by independent parties, internal or external
CC-11.4 not assessed nearest clause; it does not require this
Art 26(8)CC-9.2 not assessed external testers for threat-led tests
Art 27CC-9.2 not assessed requirements for testers
Art 24(5)CC-10.1 pass remediation of issues identified in tests
Art 19(1)CC-10.2 not assessed reporting of major ICT-related incidents

NIST AI 100-1, AI Risk Management Framework 1.0

clauseevidence from this tier
MEASURE 1.1CC-4.2 not assessed approaches and metrics for measurement selected
GOVERN 2.1CC-4.3 not assessed roles and responsibilities documented
MEASURE 2.5CC-6.1 not assessed nearest clause; it does not require this
CC-6.5 pass nearest clause; it does not require this

NIST CSF 2.0

clauseevidence from this tier
PR.PS-01CC-7.1 pass configuration management
CC-12.2 pass nearest clause; it does not require this
CC-12.3 pass configuration management of the rule table
ID.IM-03CC-7.4 pass improvements from lessons learned
CC-10.1 pass lessons learned
DE.CM-09CC-11.1 pass monitoring of software and services
CC-12.4 pass monitoring
GV.OCCC-12.5 partial nearest clause; it does not require this

Regulation (EU) 2016/679, EUR-Lex

clauseevidence from this tier
Art 32(1)(d)CC-7.3 partial regular testing, assessing and evaluating
Art 5(1)(d)CC-8.2 partial accuracy; kept up to date
CC-8.3 not assessed nearest clause; it does not require this
CC-8.5 not assessed nearest clause; it does not require this
Run history
run (UTC)triggersite commitoverallopenwarnings
2026-10-09T10:09:41Zpushe790b6993b46pass00

Full run records are workflow artifacts (90 days); the history line per run and the open findings live in latest.json in git. Records are OSCAL-shaped (assessment-results with observations and findings) and not yet validated against the OSCAL schema.

Rerun
  1. Clone https://github.com/uncovertechtalent-git/uncovertechtalent and the action from https://github.com/uncovertechtalent/machinebehavior.io.
  2. Run hugo --source website --destination /tmp/utt-public --gc --minify && python3 ../machinebehavior.io/.github/actions/conformity/run.py --root /tmp/utt-public --git-dir . --config conformity/site-tier.json --requirements conformity/requirements.json --out /tmp/utt-conformity --dry-run (Python 3 and Node 18+; no network, no API keys).
  3. Compare the printed check results with the table above for the same site commit.

conformity: latest run 2026-10-09T10:09:41Z, 0 open, pass