Skip to content

AIUC-1 registry names the wrong publisher, licence and URL #189

Description

@emmanuelgjr

What's wrong

The AIUC-1 framework registry attributes the standard to the wrong organisation:

Field On main (633c59a) Actual
publisher UK AI Safety Institute Artificial Intelligence Underwriting Company (AIUC). The site footer reads "Maintained by Artificial Intelligence Underwriting Company"
url / source https://www.ai-safety-institute.org/ (the domain doesn't resolve) https://www.aiuc-1.com/ (standard docs at standard.aiuc-1.com)
license Open Government Licence v3.0 (a UK Crown licence) not verified. AIUC-1 isn't a UK government publication, so OGL can't be right. The actual terms need checking on the AIUC-1 site
version 1.0 The standard is versioned quarterly. The site shows "Last Updated Q4: 2026" and has a changelog

The mapping file itself is correct: agentic-top10/Agentic_AIUC1.md links https://www.aiuc-1.com/. Only the registry metadata is wrong.

Where it appears

  • data/frameworks/aiuc-1.json: url, license, publisher, inventory_completeness.source
  • data/framework-sources.json: aiuc-1.source_url. Freshness was never checked (checked: null, current_version: null)
  • scripts/extract-registry.js lines 80–82, which is where the values come from, so fixing only the JSON would get overwritten
  • docs/ai-standards-crosswalk/index.html line 57: "AIUC-1 | UK AI Safety Institute". This is webapp content, so it needs C2 approval
  • docs/frameworks-registry.js: generated, and fixes itself on regenerate

Not affected: the "Inspect AI" rows in shared/TOOLS.md and docs/index.html, which correctly credit the UK AI Safety Institute.

Why it matters

The registry metadata feeds the exports and the webapp, so the error spreads to every consumer. It also matters for #186, which proposes verification methods for AIUC-1 controls. AIUC-1 publishes its own evidence for each requirement (standard.aiuc-1.com/evidence, e.g. "B001.1 Report: …"), and the crosswalk should point at that publisher accurately.

Fix (agent-safe apart from the two items marked)

  1. Correct publisher and url in extract-registry.js and aiuc-1.json, then regenerate.
  2. [HUMAN] Confirm the licence from AIUC-1's own terms. Until then, record "license": "not verified" rather than guess.
  3. Run a freshness check: record the current quarterly version and checked date. Re-mapping the rows to the new version is a separate question.
  4. [C2] Correct the webapp sub-page row.

Activity

  1. added a commit that references this issue on Oct 3, 2026
  2. added a commit that references this issue on Oct 3, 2026
    cc0a735
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions