What's wrong
The AIUC-1 framework registry attributes the standard to the wrong organisation:
| Field |
On main (633c59a) |
Actual |
publisher |
UK AI Safety Institute |
Artificial Intelligence Underwriting Company (AIUC). The site footer reads "Maintained by Artificial Intelligence Underwriting Company" |
url / source |
https://www.ai-safety-institute.org/ (the domain doesn't resolve) |
https://www.aiuc-1.com/ (standard docs at standard.aiuc-1.com) |
license |
Open Government Licence v3.0 (a UK Crown licence) |
not verified. AIUC-1 isn't a UK government publication, so OGL can't be right. The actual terms need checking on the AIUC-1 site |
version |
1.0 |
The standard is versioned quarterly. The site shows "Last Updated Q4: 2026" and has a changelog |
The mapping file itself is correct: agentic-top10/Agentic_AIUC1.md links https://www.aiuc-1.com/. Only the registry metadata is wrong.
Where it appears
data/frameworks/aiuc-1.json: url, license, publisher, inventory_completeness.source
data/framework-sources.json: aiuc-1.source_url. Freshness was never checked (checked: null, current_version: null)
scripts/extract-registry.js lines 80–82, which is where the values come from, so fixing only the JSON would get overwritten
docs/ai-standards-crosswalk/index.html line 57: "AIUC-1 | UK AI Safety Institute". This is webapp content, so it needs C2 approval
docs/frameworks-registry.js: generated, and fixes itself on regenerate
Not affected: the "Inspect AI" rows in shared/TOOLS.md and docs/index.html, which correctly credit the UK AI Safety Institute.
Why it matters
The registry metadata feeds the exports and the webapp, so the error spreads to every consumer. It also matters for #186, which proposes verification methods for AIUC-1 controls. AIUC-1 publishes its own evidence for each requirement (standard.aiuc-1.com/evidence, e.g. "B001.1 Report: …"), and the crosswalk should point at that publisher accurately.
Fix (agent-safe apart from the two items marked)
- Correct
publisher and url in extract-registry.js and aiuc-1.json, then regenerate.
- [HUMAN] Confirm the licence from AIUC-1's own terms. Until then, record
"license": "not verified" rather than guess.
- Run a freshness check: record the current quarterly version and
checked date. Re-mapping the rows to the new version is a separate question.
- [C2] Correct the webapp sub-page row.
What's wrong
The AIUC-1 framework registry attributes the standard to the wrong organisation:
main(633c59a)publisherurl/sourcehttps://www.ai-safety-institute.org/(the domain doesn't resolve)https://www.aiuc-1.com/(standard docs atstandard.aiuc-1.com)licenseversion1.0The mapping file itself is correct:
agentic-top10/Agentic_AIUC1.mdlinkshttps://www.aiuc-1.com/. Only the registry metadata is wrong.Where it appears
data/frameworks/aiuc-1.json:url,license,publisher,inventory_completeness.sourcedata/framework-sources.json:aiuc-1.source_url. Freshness was never checked (checked: null,current_version: null)scripts/extract-registry.jslines 80–82, which is where the values come from, so fixing only the JSON would get overwrittendocs/ai-standards-crosswalk/index.htmlline 57: "AIUC-1 | UK AI Safety Institute". This is webapp content, so it needs C2 approvaldocs/frameworks-registry.js: generated, and fixes itself on regenerateNot affected: the "Inspect AI" rows in
shared/TOOLS.mdanddocs/index.html, which correctly credit the UK AI Safety Institute.Why it matters
The registry metadata feeds the exports and the webapp, so the error spreads to every consumer. It also matters for #186, which proposes verification methods for AIUC-1 controls. AIUC-1 publishes its own evidence for each requirement (
standard.aiuc-1.com/evidence, e.g. "B001.1 Report: …"), and the crosswalk should point at that publisher accurately.Fix (agent-safe apart from the two items marked)
publisherandurlinextract-registry.jsandaiuc-1.json, then regenerate."license": "not verified"rather than guess.checkeddate. Re-mapping the rows to the new version is a separate question.