Reference
Hazard placards
A certification discloses hazard categories using placards, the same idea as a HAZMAT placard on a truck: a quick visual signal for the public and first responders. This list is open-ended. Propose a new placard by opening a pull request, the same way a certification gets added to the registry.
Data & Training Bias
lowTraining data or sourcing may skew outcomes for some groups or cases.
Agentic Decision-Making
moderateModel takes decisions on its own, without a human confirming each one.
Multi-Agent Interaction
highModel or agent coordinates with other agents, where their combined behavior can differ from any one acting alone.
Human-in-the-Loop Oversight
moderateDiscloses the ratio of human overseers to AI agents, within the charter’s 1:8 to 1:15 range.
Unintended Consequences
highModel has caused, or could cause, effects nobody intended or predicted.
Autonomous Operation
highModel runs and acts continuously, without a human present to supervise it.
Public Infrastructure Control
criticalModel controls shared infrastructure, such as power, water, or traffic systems.
Nuclear & Strategic Systems Control
criticalModel controls, or assists in controlling, nuclear or other strategic defense systems.
Battlefield Use
criticalModel, agent, or autonomous bot that operates in, is used within, handles, or is capable of a battlefield or combat environment.
Parental Guidance Suggested
lowOutput may include themes better reviewed by a parent or guardian before a minor sees them.
Mature Content (18+)
moderateModel can generate content intended for adult audiences only, unsuitable for minors.
NSFW / Explicit Content
highModel can generate sexually explicit, graphic, or otherwise not-safe-for-work content.
Analytical Thinking Loss
moderateOver-reliance on the model risks eroding users’ own critical thinking and analytical skills.
Child Safe
lowModel has been reviewed and filtered for content safe for minors, with no adult or explicit material.
Data-handling & compliance
A certification can also disclose which sensitive data classes and regulations a model or agent is certified to handle safely. These signal competence with a data regime, the way a placard signals a category of risk. The list covers currently active standards and is open-ended.
PII Handling
Handles personally identifiable information under recognized data-protection practice.
Sensitive PII
Handles sensitive personal data such as government IDs, biometrics, or precise location.
HIPAA (PHI)
Handles US protected health information under HIPAA safeguards.
GDPR
Processes EU/EEA personal data under the General Data Protection Regulation.
CCPA / CPRA
Handles California consumer personal data under CCPA/CPRA.
PCI DSS
Handles cardholder and payment data under PCI DSS.
Classified / SECRET
Cleared to handle classified or SECRET-level government data under the relevant national scheme.
SOC 2
Operated under a SOC 2 report for security, availability, and confidentiality controls.
ISO/IEC 27001
Information-security management certified to ISO/IEC 27001.
FedRAMP
Authorized to handle US federal government cloud data under FedRAMP.
DPDP Act (India)
Processes personal data under India’s Digital Personal Data Protection Act.
PIPL (China)
Processes personal data under China’s Personal Information Protection Law.
LGPD (Brazil)
Processes personal data under Brazil’s Lei Geral de Proteção de Dados.
PIPEDA (Canada)
Processes personal data under Canada’s PIPEDA.
POPIA (South Africa)
Processes personal data under South Africa’s Protection of Personal Information Act.
Approved operating regions
A certification can state where a model or agent is cleared to operate. Regions are coarse, not a full country list, and are open-ended.
Global
Cleared to operate worldwide, subject to local law.
North America (NA)
United States, Canada, and Mexico.
Latin America (LATAM)
Central and South America and the Caribbean.
European Union (EU/EEA)
EU and European Economic Area member states.
United Kingdom (UK)
United Kingdom.
Middle East & North Africa (MENA)
Middle East and North Africa.
Sub-Saharan Africa (SSA)
Sub-Saharan Africa.
Asia-Pacific (APAC)
East, Southeast, and South Asia and Oceania.
EU AI Act risk tier
A certification can self-classify under the EU AI Act risk tiers, so a reader can place it against a framework many operators already use.
Unacceptable risk
Banned use under the EU AI Act, such as social scoring. Should not be deployed.
High risk
Regulated high-risk use under the EU AI Act, such as hiring, credit, or critical infrastructure.
Limited risk
Transparency obligations apply, such as telling users they interact with AI.
Minimal risk
Little to no regulatory obligation under the EU AI Act.
NIST AI RMF functions
A certification can map to the NIST AI Risk Management Framework core functions, so it crosswalks to that voluntary standard without extra work.
- Govern
- Map
- Measure
- Manage