Worklist — every open item as at v3.4

Superseded in part, 27 August 2026. The Act is now at v3.4.2statutory text, annotated. The defect this section was opened to track, that SEC. 6(a) could not be pleaded as drafted, is repaired; the section and subsection numbering is corrected throughout and the findings at SEC. 0 are renumbered and extended.

The three live pages in this section are keyed to v3.4 and have not been reconciled item by item against v3.4.2. Their counts — sixty-nine open items, twenty-three drafted amendments, none adopted — describe v3.4 and are no longer the state of the Act. They are left standing rather than quietly rewritten, because a revision record that edits itself is not a record. The current list of what is open is at the back of the annotated text: six questions, each marked in the statute at the provision it concerns.

Every open item on this Act, in one file. Each row says what is missing, which section it touches, and what it would take to close it.


What each row is missing

Five states. They escalate: each one holds everything the one before it holds, and lacks one thing more. A row cannot honestly sit at a higher level while a lower one beneath it is unresolved — a decision resting on an unpinned citation is a decision resting on nothing.

1 · Citation. The quotation is held and read in the source. What is missing is the page. The copy carries no reporter pagination, so the page number printed is the secondary source’s and cannot be confirmed from anything this project has. Needs a reporter print, Westlaw, Lexis, or a law library. No expertise. Nothing free closes it.

2 · Document. The citation is known and the quotation is not, because the text itself is not held. Nothing can be read, checked or characterized until somebody finds the file. Needs a search. No expertise.

3 · Reading. The document is held, the quotation is held, the citation is held. What is missing is that nobody has read it against the Act. Both texts are on the shelf and the comparison has not been made. Needs a careful reader with the repository open. No expertise — but the risk here is false confidence, because a row looks closed when someone has read about a document rather than the document.

4 · Counsel. The document is held, read, and compared, and the reading does not settle it. What is missing is professional judgment: what a court would do, what a legislature may enact, whether an offense can be charged as drafted. Needs a qualified lawyer. Nothing done inside this repository reduces this number.

5 · Decision. The document is held, read, compared, and advised on, and the question remains open because it is not a question about the world. What is missing is a choice about what this Act should be — how far it reaches, what it requires, what it is willing to cost. Needs the maintainer, and usually counsel first. A row waiting here for certainty waits forever.

Drafted text is a column, not a level. Replacement language exists for most amendments and for almost no objection, and it is recorded in its own column — because an amendment can have finished text and still be missing a citation, a reading, or a lawyer. AMD-8 is fully drafted and needs counsel; AMD-22 is fully drafted and blocked on a footnote nobody can reach. A row with no drafted text is one where even a lawyer would be starting from nothing, and that has been invisible until now.


The counts, 27 August 2026

  What is missing Rows
5 Decision 5
4 Counsel 30
3 Reading 21
2 Document 43
1 Citation 23

Every row carries a level. Nothing is unassigned.

Thirty rows are missing counsel, and no amount of reading reduces that number. It is the constraint this register exists to make visible. Sixty-three letters have gone out and four people replied; none of the four was a review.

Forty-three rows are missing a document — the largest level, and the cheapest to clear, because finding a file needs no expertise. Four of them are the participants’ own accounts of the 2026 incidents, which are the evidence base for this whole Act. Until those are read, that base rests on journalism about them.

Twenty-one rows need only a reading. Both texts are on the shelf and the comparison has not been made.


Responses

Name the item, state the conclusion, give the reasons. No review has been received. When one is, it is published verbatim — the reviewer’s own words, in full, under their own name or anonymously at their election, and the maintainer may reply beside it but may never edit or overrule it. A rejection is as publishable as an endorsement, and is worth more. FrontierAIAccountabilityProject@proton.me


5 · Decision missing

Held, read, compared and advised on. What remains is a choice about what this Act should be.

ID Kind Drafted text Item
★ DEC-5 Decision no SEC. 4(b) — the presumption that reaches the people this Act was written for stops at the criminal door. SEC. 4(b)(2) presumes a controlling person is anyone holding ownership, voting, contractual or governance rights sufficient to direct or replace management — the founder with supervoting shares, the holder through a trust. That presumption operates in civil proceedings only. In a criminal proceeding the same status is merely “evidence from which the trier of fact may infer,” and the prosecution keeps its burden on every element. So the person the Act exists to reach is presumed responsible where the penalty is money, and not presumed where the penalty is prison. That is the wrong way round for a statute whose entire purpose is that a fine gets absorbed and a sentence cannot be. The split was drafted on due-process grounds and has never been tested: whether a State may presume an element in a criminal proceeding, and on what conditions, is a constitutional question nobody here can settle. Level 5, and it is the first question this project would put to any criminal-law reader. A four-part proposal is drafted at _internal/PROPOSAL_DEC-5_criminal-tier-inference.md; its first part is a gate on DOC-29 and is not discharged
DEC-2 Decision no 2, 9 · Does the duty reach an evaluation run with safeguards deliberately disabled?
DEC-3 Decision no 4 · Third-party evaluators: does practical authority still run to the officer?
DEC-4 Decision no 2(a), 1(c) · The Act does not reach the conduct it was written after
Q-5 Open question no Whether act/bracketed-matter.md should discuss the citizen-suit question

4 · Counsel missing

Read and compared, and the reading does not settle it.

ID Kind Drafted text Item  
AMD-1 Amendment yes 1 · Sources “serious injury” from 18 U.S.C. § 1365(h)(3)–(4) instead of leaving it undefined — criminal. Relabeled 27 Aug: a wider injury definition widens a custodial offense, and the research being complete does not make that a drafting choice the maintainer can make. Maintainer decides after counsel advises  
AMD-2 Amendment yes 13(c) · Adds a review valve on the suspension order — administrative law  
AMD-4 Amendment yes 9(a) · Recasts two reporting triggers from characterizations into observable events — a prosecutor, on whether the events are provable  
AMD-6 Amendment yes 1(b)(1) · Adds the developer’s own designation as a third route into scope — whether self-designation can be gamed is policy  
★ AMD-8 Amendment yes 6 · Rebuilds the individual-liability offense — criminal. Unvalidated, drafted before E66  
AMD-9 Amendment yes 10(e) · Imports the access authority the Act omitted — enforcement. Moved 27 Aug: § 374 does not supply the model  
AMD-10 Amendment yes 3(c)(3) · Interim controls, so 5(b) is not dormant until year four — criminal. Relabeled 27 Aug: the repair works by writing four technical controls into the statute as offense elements, applied before any agency has ruled. Fair notice  
AMD-13 Amendment yes 1(b)(1)(B) · Says “sever” rather than “extend” — open-source implications are policy  
AMD-15 Amendment yes 3(c)(2) · A disclose-and-fix valve, because the text as written punishes candor — criminal. Relabeled 27 Aug: the 90-day shelter is renewable on a further nonconformity report and the text does not say whether that restarts the clock  
AMD-20 Amendment yes 3 · Conformity to a standard outside this Act credits nothing — too harsh on good-faith compliers?  
AMD-21 Amendment yes 8 · A certification register — facts public, contents protected — trade secret and public records  
AMD-23 Amendment yes 3(c)(4)(B) · Restores the publication the borrowed statutes require, on their redaction terms — regulatory; are the redaction terms workable  
★ AMD-24 Amendment yes 8 · The lower tier names recklessness; § 6(a) requires only negligence — criminal, on the fair-notice defect  
AMD-25 Amendment yes 10(d) · The FDCA remedies are cited and their protections are not taken — is taking the FDCA protections coherent  
DEC-2 Decision no 2, 9 · Does the duty reach an evaluation run with safeguards deliberately disabled? · Open — criminal. Relabeled 27 Aug: whether a configuration decision is a covered act. Maintainer decides after counsel advises  
DEC-3 Decision no 4 · Third-party evaluators: does practical authority still run to the officer? · Open — architecture, not a defect — criminal. Relabeled 27 Aug: whether practical authority reaches a person who commissioned an outside evaluation. Maintainer steer, 27 Aug: an independent evaluator such as AISI is not the concern; a company-commissioned evaluator is. Maintainer decides after counsel advises  
DEC-4 Decision no 2(a), 1(c) · The Act does not reach the conduct it was written after · Open — criminal and constitutional. Relabeled 27 Aug: whether a State may attach duties to conduct abroad on the basis of intended in-state effect. Maintainer owns the aim, not the answer  
OBJ-4 Objection yes — drafted Unaddressed; asserted rather than quantified — or an economist — asserted, never quantified · DRAFTED ANSWER. The marginal-supplier objection assumes the deterred party is the marginal supplier. Answer in two moves. First, concede the range: for capability already released open-weight, the Act deters nothing, and SEC. 1(b)(9) says so — duties on a release are limited to those performable before it. Second, note what the objection concedes: it is an argument about substitution, and substitution requires a substitute. For a training run above the compute line there are a handful of entities on earth, which is the fact the threshold was chosen to track. The drafted concession belongs on the objections page, in terms, rather than being met with assertion.
OBJ-5 Objection yes — drafted Unaddressed — legislative policy · DRAFTED ANSWER. Reversibility is answered by SEC. 13, which the objection does not appear to have read. SEC. 13(c) lets the Attorney General suspend any provision by published order where a federal enactment preempts it; SEC. 13(c)(3) bars conviction for conduct during a suspension; SEC. 13(d) makes revival prospective only. The Act is more amendable than an ordinary criminal statute, by design. What it lacks is a sunset, and the drafted answer is to say so and offer one as a bracketed adopting-state choice: [This Act expires on (date) unless re-enacted.]
OBJ-6 Objection yes — drafted Unaddressed — or an economist · DRAFTED ANSWER. Adverse selection — that criminal exposure filters for risk tolerance rather than care — is an empirical claim with a testable prior: the same was said of Sarbanes-Oxley § 302 certification in 2002, and the drafted answer is to say that and cite what happened to the officer pool. ⚠ That evidence is not held. Until it is, the honest drafted answer is the concession: the objection is unquantified in both directions, and the Act’s answer is that it prices the decision rather than the role.
OBJ-7 Objection yes — drafted Unaddressed — criminal theory · DRAFTED ANSWER. Moral luck is answered by the two-tier structure and the Act should say so. SEC. 6(a) attaches to the failure of due care and does not require that harm occurred — so the identical careless decision is the identical offense whether or not a user was hurt. Only the SEC. 10(c) harm tier turns on outcome, and it requires but-for and proximate cause plus a greater mental state. The Act already allocates moral luck to the sentencing tier and away from the offense. Drafted answer: state that on the objections page and cite SEC. 10(c)(2)(D).
OBJ-8 Objection yes — drafted The literature is held; nothing anticipates the coalition — criminal policy · DRAFTED ANSWER. The mens rea reform coalition opposes strict liability and default-mens-rea gaps. This Act is not their target and its own text is the evidence. SEC. 6(c) is a culpability floor — no custodial sentence absent proof of the failure of due care. SEC. 1(a) classifies the offenses as public welfare offenses within the Morissette limits and says so. Amendment 12 restores scienter to SEC. 5(d). Drafted answer: a section on the objections page addressed to that coalition by argument, listing every place the Act declines strict liability, and conceding the one place it does not — entity liability under SEC. 10(a).
★ OBJ-9 Objection yes — drafted Named as unanswered on the objections page · DRAFTED FIX, and it is a text change. SEC. 8 requires “statements of fact within the certifying person’s knowledge after reasonable inquiry” and never defines reasonable inquiry, which is why the safety-team defense is open. Draft: Reasonable inquiry requires that the certifying person have obtained and considered the findings of those responsible for the matters certified, provided them reasonable access to relevant information, and recorded any material disagreement. Reliance on the report of another is evidence bearing on due care; it is not a defense where the certifying person knew, or consciously avoided knowing, of a material nonconformity. That is Amendment 7 Operation 4’s auditor-reliance conditions, applied to the certification.
★ OBJ-10 Objection yes — drafted Raised from outside; answer incomplete · DRAFTED FIX — see DEC-5 and _internal/PROPOSAL_DEC-5_criminal-tier-inference.md. Three parts: a SEC. 0 finding supplying the rational connection; Amendment 8 Operation 4 restoring Park’s production burden; and Amendment 7 Operation 3 severed and landed on its own, so the org chart is a record before anyone needs it. Part 1 is gated on DOC-29.
★ OBJ-13 Objection yes — drafted Takings. X.AI LLC v. Bonta, No. 2:25-cv-12295 (C.D. Cal.) pleads per se takings and regulatory takings before it reaches speech — compelled training-data disclosure as destruction of a trade secret. This repository returns zero on Takings Clause, regulatory taking, per se taking and Penn Central ·constitutional. Lifted from standing watch 27 Aug 2026 · DRAFTED ANSWER, and Amendment 23 is half of it. The takings count turns on compelled publication destroying a trade secret. This Act compels transmission to a regulator and seals it — SEC. 8, SEC. 9(c) and SEC. 12 each say so on their face, which under Ruckelshaus defeats the investment-backed-expectation limb. Amendment 23 then restores publication on the donor statute’s own redaction terms, so nothing secret is surrendered. What is not drafted is an answer to the per se limb, which may not care whether the State prints it. That half needs counsel.
★ OBJ-14 Objection yes — drafted The apex-witness problem. Every SEC. 6 offense turns on what a natural person knew or could have prevented, and American courts shield senior executives from depositions absent unique non-duplicative knowledge. Can the State get that person into a chair? One data point cuts our way — Concord Music Group v. Anthropic, No. 5:24-cv-03811 (N.D. Cal.), 19 Dec 2025, Amodei ordered to sit — ⚠ the order has not been retrieved and both sources are secondary — enforcement. Lifted from the internal review 27 Aug 2026 · DRAFTED FIX. The apex-witness problem is a discovery doctrine, and the Act’s answer is to make the testimony unnecessary. Amendment 7 Operation 3 requires advance designation in a record of every person holding authority over each covered function; SEC. 12 requires it retained. A State that can read the designation does not need the deposition. Draft: sever Operation 3 from Amendment 7 and land it against SEC. 4 alone. See DEC-5 part 4.
★ OBJ-15 Objection yes — drafted The doctrine will not bear the felony tier. Lyness, 64 B.C. L. Rev. 253, 297–98, would revive the state RCO doctrine for civil liability only: Dotterweich and Park are misdemeanor authority from a time when collateral consequences were different. The base tier answers it; SEC. 6(b) may not, and no argument that the same authority reaches it exists anywhere here — criminal. The scholar whose survey this project cites for its comparative claims · DRAFTED ANSWER. The objection is that Dotterweich and Park are misdemeanor authority and cannot carry a felony tier. The Act’s answer is already in its structure and is not stated anywhere: SEC. 6(a), the negligence tier, is the misdemeanor and rests on Park directly. SEC. 6(b), the felony tier, does not rest on Park at all — it requires knowledge or willfulness proved by ordinary means. Drafted answer: state that division in terms on the objections page, so the felony tier stops being defended on authority that does not reach it.
OBJ-3 Objection yes — drafted Prior to every legal question on this page, and unaddressed · Neither — an evaluations researcher, not a lawyer · DRAFTED ANSWER. The measurability objection is answered by the Act’s own rule-gating pattern, not by argument: SEC. 5(b) commences only when controls are prescribed, and Amendment 4 Operation 2 already provides that an evaluation result triggers no reporting duty until a threshold is prescribed by rule. Extend that pattern in terms — no offense under this Act turns on an evaluation result unless a threshold for that evaluation has been prescribed by rule and the result is reproduced on re-run under the same protocol — and the Act stops criminalizing an unmeasurable standard by construction rather than by promise. Needs an evaluations researcher, not a lawyer.
★ Q-1 Open question no Whether 8 Del. C. § 102(b)(7) exculpation reaches a duty imposed by a statute outside the DGCL. “We have found no case deciding it” · commentary/objections.md 1097  
Q-3 Open question no Whether the Act’s answer to Lyness on remediable and insurable harm holds — “asserted here, not proven” · commentary/other-jurisdictions.md 369  

3 · Reading missing

Document, quotation and citation are all held. Nobody has read it against the Act.

ID Kind Drafted text Item  
AMD-3 Amendment yes regulations · Conforms the draft regulations to the current Act — three changes never cascaded — compare act/rules.md against the Act; three anchors  
AMD-5 Amendment yes 8 · Punctuation only — SEC. 8 has a comma where a period belongs, mid-sentence before “A certification disclosing” — adopt  
AMD-SC Amendment end of file · The statute ends with two stray characters, )(, after “Steal it.” Present in the tagged v3.4 text and in the-act.txt; absent from the reviewer’s clean copy, so it was introduced or preserved in one and not the other. Found 26 Aug 2026 — delete two characters and re-checksum, or carry to v3.5  
AMD-7 Amendment yes 1 · Extends scope to the covered frontier enterprise — ecosystem scope, functional duty — held pending enforcement and security review  
AMD-11 Amendment yes 5, 9(b) · Names who owes the duty; rewrites it in the active voice — read it; does SEC. 5 now name the obligor  
AMD-14 Amendment yes 9(b) · A detection clock that cannot be gamed by certifying less monitoring — read it; can the clock still be gamed  
AMD-26 Amendment yes 3(c)(4) · Repairs the disapplication list against a full read of the three adopted standards — check the repair against the three standards, already read  
FACT-10 Fact yes — drafted Resolution; the individual-signature reading stands meanwhile — a disposition · DRAFTED RULING: a signature on those letters is the individual’s and not the employer’s, and the counts are cited on that basis. Nothing in the record shows employer authorization, and the dossier has held that reading since 17 August.
FACT-13 Fact yes — drafted Pin it, or strike the sentence. The incident timeline does not carry it — pin or strike · DONE 27 Aug — both sentences struck from commentary/the-case.md. Close the row, and correct it: it says “front page” and they were on the case page.
FACT-14 Fact yes — drafted A re-sweep: did OpenAI and Anthropic answer? Silence is itself the SEC. 9 argument — a re-sweep · DRAFTED DISPOSITION: record that the re-sweep was not performed, on what date it was attempted, and what was searched. Silence nobody checked for is not evidence of silence.
PUB-2 Published defect yes — drafted commentary/questions.md 163, 247, 253, 363, 371, 384, 393, 407 · commentary/objections.md 44, 316, 493, 658, 715, 808 · commentary/other-jurisdictions.md 244, 372, 380 · Seventeen passages address reviewers, seats and a council as existing parties — “the enforcement reviewer’s core question, and the reviewer exists because it is”; “identifiable privately to reviewers before they sign”; “any completed expert reviews”. No reviewer exists and no review has been received. objections.md line 10 now says so, and fourteen later passages on the same page contradict it · FIX: rewrite each of the seventeen passages to name the work rather than a person — “this needs a criminal lawyer,” not “the criminal-law reviewer should say so.” Keep every question; delete only the implied party.
PUB-3 Published defect yes — drafted commentary/objections.md 706, 850 · commentary/the-case.md 501 · Three references to a docs/ directory that no longer existsdocs/safe_harbors_and_affirmative_defenses.md (now commentary/half-statutes.md), docs/03-whats-in-the-act.md, and a GitHub permalink pinned to commit 6f48eff under the vanished tree · FIX: repoint docs/safe_harbors_and_affirmative_defenses.md to commentary/half-statutes.md, docs/03-whats-in-the-act.md to commentary/the-case.md, and replace the 6f48eff permalink with the current path or strike the sentence.
PUB-5 Published defect yes — drafted commentary/already-a-crime.md 34 · commentary/what-frontier-means.md 33, 50, 113, 129 · commentary/half-statutes.md 138 · “CURE 6”, “CURE 7”, “CURE 20” — this file numbers them Amendment n, and three other commentary pages already use that. Two naming schemes for the same rows in one directory · FIX: “CURE n” becomes “Amendment n” on four pages. Read each sentence after changing it — the same replacement produced “THIS Amendment LANDS” in proposals.md.
PUB-6 Published defect yes — drafted commentary/objections.md 317, commentary/questions.md 393 · Two links promise something the target is not — “the reviewer page” and “the enforcement reviewer’s” both resolve to this file, which has no per-topic errata and is not a person · FIX: both links resolve to the worklist. Change the link text to “the worklist” so the sentence promises what the target is.
PUB-7 Published defect yes — drafted commentary/objections.md 862 · Cites model_act_v3_4.txt; the file is act/model-act.txt · FIX: model_act_v3_4.txt becomes act/model-act.txt.
PUB-8 Published defect yes — drafted commentary/the-case.md 466 · Corrupted sentence — “unless that model is itself offered as a Comments.” A bad paste; the sentence about Pennsylvania SB 1090 § 4 does not parse · FIX: the sentence about Pennsylvania SB 1090 § 4 does not parse. Recover it from git history at the commit before the paste, or strike it.
PUB-9 Published defect yes — drafted commentary/other-jurisdictions.md 380 · commentary/the-same-conduct.md 193, 376 · commentary/objections.md 15 · commentary/why-a-signature-works.md 12 · Self-awarded grades, contrary to the no-superlatives rule: “the strongest doctrinal objection in the scholarship this project relies on”; “the most useful one in the file”; “the strongest version of it”; “the strongest form of pre-resistance”; “This file is the answer · FIX: five self-awarded grades. Delete the grading clause and keep the claim — “the strongest doctrinal objection in the scholarship” becomes “an objection in the scholarship this project relies on.”
PUB-10 Published defect yes — drafted commentary/half-statutes.md 165 · commentary/objections.md 707 · commentary/questions.md 150, 290, 373, 435 · commentary/the-same-conduct.md 41 · commentary/other-jurisdictions.md 303 · British spelling in project prose — armoured, harbours, trialled, weaponise, criminalising, authorisation, misdemeanours. check_spelling.py does not catch these, which is itself a finding: see the criminalise item in the carried-forward block · FIX: armoured→armored, harbours→harbors, trialled→trialed, weaponise→weaponize, criminalising→criminalizing, authorisation→authorization, misdemeanours→misdemeanors. Leave every quoted statute alone. And record why check_spelling.py misses all of them — the checker defect matters more than the words.
Q-2 Open question yes — drafted No public page states that the negligence tier is the operating regime and the felony tier the exception. A reader cannot tell which the Act is · commentary/objections.md 849 · FIX: no public page states that the negligence tier is the operating regime and the felony tier the exception. Draft a section for commentary/the-case.md saying so, with SEC. 6(a) and SEC. 6(b) set beside each other and Hanousek for the negligence floor.
Q-4 Open question yes — drafted Whether H.R. 9917’s testing carve-out would exclude the studied incidents. Not checked, not asserted · commentary/the-same-conduct.md 285 · FIX: read H.R. 9917’s testing carve-out against each of the six 2026 incidents, one at a time, and record which are excluded. The bill text is held.
Q-6 Open question yes — drafted The Lyness four-goal mapping correction, marked “candidate erratum, maintainer to number” — belongs in G · commentary/other-jurisdictions.md 341 · FIX: assign the Lyness four-goal mapping correction an erratum number and enter it. It has been waiting for a number since it was found.
DOC-23 Document no UK AISI incident report INC-2026-07-28-01, now held. Read § 4 (events) and § 5 (contributing factors) against SEC. 5(b), SEC. 9(a) and Amendment 10. The Act’s interim controls were written from press accounts of this document  
DOC-24 Report no AISI, Loss of Oversight (Taylor, Heitmann et al., 82pp, now held) — 25 expert interviews on whether AI systems can be audited, monitored and investigated at all. Bears directly on OBJ-3, which says the Act criminalizes a standard nobody can measure, and OBJ-3 currently has no answer  
DOC-25 Standard no International Network for Advanced AI Measurement, Automated Evaluation of LLMs: Best Practice (20pp, now held). SEC. 3 presupposes evaluation standards exist; this is one, from a body the Act does not cite  
DOC-26 Capture no METR, Recent Frontier Models Are Reward Hacking (Von Arx, Chan, Barnes, 5 June 2025) — held as an HTML capture. Models optimizing the measure rather than the goal is the mechanism behind Amendment 4’s divergence trigger, and this project cites METR’s inventory without having read this  
DOC-27 Capture no UKGovernmentBEIS/aisi-sandboxing — the AI Security Institute’s own open-source sandboxing toolkit for agentic evaluations, held as a repository-page capture. Amendment 10 writes four interim containment controls into the statute; the institute publishes a working implementation and this project has never looked at it  
DOC-28 Capture no Detecting Safety Violations Across Many Agent Traces, arXiv:2604.11806 (Stein, Brown, Hassani, Naik, Wong, 13 Apr 2026) — abstract page only; the paper itself is not held. Bears on OBJ-3, which says the Act criminalizes a standard nobody can measure  
★ DOC-29 Document no County Court of Ulster County v. Allen, 442 U.S. 140 (1979) — carried in the table of authorities with no read-status, cited nowhere in the statute or Comments. It is the gate on DEC-5: whether a permissive inference on an element of a criminal offense survives on a rational connection, and where that line actually sits. Until it is read, the proposal at _internal/PROPOSAL_DEC-5_criminal-tier-inference.md cannot be drafted into operative text  

2 · Document missing

The text is not held. Nothing can be read or checked until somebody finds it.

ID Kind Drafted text Item  
OBJ-11 Objection no Reported, not read. Her work is not in the source library — then readable by the maintainer · No drafted answer is possible until the work is read. The affirmative case — that personal liability cannot be insured, indemnified or booked as a cost — is the answer to most of section 4, and it is unread. See DOC-11.
OBJ-12 Objection no The largest hole. The central analogy is a legal argument wearing an empirical one’s clothes — then readable by the maintainer · No drafted answer is possible. Whether officer liability measurably reduced adulteration or pollution rates is an empirical question and nobody has looked. It cannot be drafted around.
FACT-1 Fact no A first-party or filing source  
FACT-2 Fact no A source  
FACT-3 Fact no A dated source  
FACT-4 Fact no The S-1 read directly. Currently held through secondary reads — the S-1  
FACT-5 Fact no The roster reconciled against the seat count  
FACT-6 Fact no Published? Watch — watch  
FACT-7 Fact no Any sourced figure  
FACT-8 Fact no Pins; flagged in the incidents appendix  
FACT-9 Fact no Both currently rest on an AI summary — first-party or strike — or strike  
FACT-11 Fact no All three still unpinned  
FACT-12 Fact no A pin  
DOC-1 Document no Hugging Face’s incident post, 16 July 2026 · One of four primaries behind the 2026 incident cluster  
DOC-2 Document no OpenAI’s statement on the same incident · Same  
DOC-3 Document no The Black Hat presentation by two OpenAI staff · Same  
DOC-4 Document no Anthropic’s disclosure of its own April evaluations · Same. Three of the four remain at reporting strength; AISI’s is now held  
DOC-23 Document no HELD as of 27 Aug 2026 — the UK AI Security Institute’s own incident report, INC-2026-07-28-01, published 4 Aug 2026, 35pp, in the library. Nobody has read it against the Act. Its § 5 names five contributing factors — internet access, no provider cyber classifiers, no synchronous monitoring, prompt misconfiguration, unclear exercise scope — which is the list Amendment 10’s four interim controls were drafted against without the primary in hand. Moves to level 3  
DOC-5 Document no The June 2026 executive order founding the federal review framework · Distinct from EO 14365 of 11 Dec 2025. Not held  
DOC-6 Document no The order in X.AI LLC v. Weiser constraining the Colorado Attorney General · The first judicial constraint on a state AI enforcer in this record  
DOC-7 Document no Apollo Global Management’s own breach notification · Nothing hardens on the security side until it is read  
DOC-8 Document no Rep. Trahan’s post of ~22 August 2026, in full · Held as a truncated paste; nothing may cite it beyond the watch  
DOC-9 Document no Connecticut’s enacted 2026 act — public act number and section numbering · Blocks DEC-1 and FACT-15  
DOC-10 Document no Concord Music Group v. Anthropic, No. 5:24-cv-03811 (N.D. Cal.), the 19 Dec 2025 deposition order · Public on CourtListener. The only court finding that a frontier chief executive holds unique personal knowledge of model training. Blocks OBJ-14  
★ DOC-11 Document no Lyness, 64 B.C. L. Rev. 253, in the original · Cited throughout for comparative claims and read only in extract. Blocks OBJ-15  
DOC-12 Document no Government Functional Standard 007: Security and Managing Public Money — the primary sources for the Accounting Officer duty · commentary/why-a-signature-works.md 223  
DOC-13 Document no Whether any UK Accounting Officer has been personally sanctioned over cyber risk. The page says if none has, “that is a finding against this section” · commentary/why-a-signature-works.md 226  
DOC-14 Document no The ASRS immunity design — the aviation objection’s whole empirical premise · commentary/objections.md 663, 715  
DOC-15 Document no Lee’s written answers to Sen. Klobuchar, S. Hrg. 119-202 pp. 87–92 — read only by OCR, and the page says they are owed a proper reading before quotation · commentary/objections.md 1313  
DOC-16 Document no Anthropic, Detecting and Preventing Distillation Attacks, 23 Feb 2026 · commentary/objections.md 208  
DOC-17 Document no The bioRxiv preprint of 16 July 2026 (Ioannidis; 317 unicorn AI firms) · commentary/objections.md 419  
DOC-18 Document no CRS, Enforcement of Federal Pollution Control Laws — unread in the original, and Amendment 22 leans on it · commentary/objections.md 536  
DOC-19 Document no Primary texts: TRAIGA, SB 24-205 and its delay amendment, the SANDBOX Act, the Utah AI Policy Act, the TRUMP AMERICA AI Act, the GAAIA draft · commentary/half-statutes.md 62, 249  
DOC-20 Document no The Copenhagen dispatch, findable in Foreign Relations of the United States · commentary/other-jurisdictions.md 416  
DOC-21 Document no Gawande, The Checklist Manifesto — pincites unpinned, and the page says they must be pinned before publication · commentary/why-a-signature-works.md 323  
DOC-22 Document no Senate statements unread: fourteen senators and Kratsios’s prepared statement (S. Hrg. 119-284), the Commerce hearing of 3 Mar 2026, Muro’s Brookings statement. Blackburn and Cantwell bear on preemption · commentary/objections.md 1408, 1479  
★ AMD-12 Amendment yes 5(d) · Restores the mental state the borrowed provision requires · Alvarez is not held. Once it is, level 4 — criminal  
AMD-16 Amendment yes 1(b)(7) · A deception limb, because Van Buren excludes what actually happened · Van Buren is not held. Once it is, level 4 — CFAA  
DEC-1 Decision no 3(c)(4) · Does Connecticut become a fourth adopted standard? · Parked until the act is read in full · The enacted act is not held. Once it is, level 3  
OBJ-1 Objection no Neither case is held or cited. This is the constitutional objection that most often kills a bill in committee · Neither Lambert nor Johnson is held. Once they are, level 4  
OBJ-2 Objection no Not held, not cited · Bernstein is not held. Once it is, level 4  
FACT-15 Fact no A published page cites a bill that never became law. commentary/half-statutes.md argues Connecticut inverts the anti-inoculation pattern and cites section numbers taken from 2025 SB 2, which died in chamber — tabled 16 May 2025, never voted, confirmed against the General Assembly’s own bill history. A successor was enacted in 2026 and is not held. Nothing there may be called Connecticut law until the enacted act is read · The enacted act is not held. Once it is, level 3. Flagged 24 Aug 2026 on standing watch, never entered here  
PUB-1 Published defect no commentary/half-statutes.md 128–135 · Asserts Connecticut P.A. 26-15 “read in full” with pincites § 33(e) and § 13(b)(1). FACT-15 and DOC-9 record that the enacted act is not held and the section numbers came from 2025 SB 2, which died in chamber. The register has already ruled this impermissible and it is still published. Also hedges the bill’s death as “inferred” where this file has it confirmed against the General Assembly’s own history  
PUB-4 Published defect no commentary/objections.md 236 vs commentary/half-statutes.md 116 · Two different numbers for the same executive order — E.O. 14409 on one page, EO 14365 of 11 Dec 2025 on the other. DOC-5 records the founding order as not held  

1 · Citation missing

The quotation is held and read. The page cannot be confirmed from any copy this project has.

ID Kind Drafted text Item
Citation United States v. MacDonald & Watson Waste Oil Co., 933 F.2d 35 (1st Cir. 1991) · Footnote 15, read in a reporter print. Amendment 22 depends on whether the court approved the willful-blindness instruction or merely recited it  
Citation United States v. Johnson & Towers, 741 F.2d 662 (3d Cir. 1984) · 669  
Citation United States v. Bank of New England, 821 F.2d 844 (1st Cir. 1987) · 856  
Citation United States v. Jewell, 532 F.2d 697 (9th Cir. 1976) (en banc) · 704  
Citation United States v. Cincotta, 689 F.2d 238 (1st Cir. 1982) · 243 (note 2 is confirmed)  
Citation United States v. Iverson, 162 F.3d 1015 (9th Cir. 1998) · 1024, 1026  
Citation United States v. Ahmad, 101 F.3d 386 (5th Cir. 1996) · any  
Citation United States v. Philip Morris USA, 566 F.3d 1095 (D.C. Cir. 2009) · any  
Citation Veeck v. Southern Building Code Congress, 293 F.3d 791 (5th Cir. 2002) (en banc) · any  
Citation Cedar Point Nursery v. Hassid, 594 U.S. 139 (2021) · 150  
Citation Liu v. SEC, 591 U.S. 71 (2020) · any  
Citation National Pork Producers v. Ross, 598 U.S. 356 (2023) · any  
Citation Sveen v. Melin, 584 U.S. 811 (2018) · any beyond 811  
Citation Trump v. Slaughter, No. 25-332 (2026) · any  
Citation SEC v. Jensen, 835 F.3d 1100 (9th Cir. 2016) · any  
Citation Lambert v. California, 355 U.S. 225 (1957) · any  
Citation Johnson v. United States, 576 U.S. 591 (2015) · any  
Citation United States v. Freed, 401 U.S. 601 (1971) · any  
Citation Bernstein v. U.S. Dep’t of Justice, 176 F.3d 1132 (9th Cir. 1999) · any  
Citation Soto v. Bushmaster Firearms, 331 Conn. 53 (2019) · any  
Citation Ontario Provincial Council of Carpenters v. Walton, C.A. 2021-0827-JTL (Del. Ch. 2023) · Which of two opinions is reported at 294 A.3d 65 — the laches opinion of 12 April or the demand-futility opinion of 26 April. One look at the Atlantic Reporter settles it  
ERR-1 Erratum no xAI LLC v. Bonta, No. 26-1591 (9th Cir.) — the argument date of 16 July 2026 · The Ninth Circuit docket was read 25 Aug 2026 and carries no entry for argument, submission or opinion; the snapshot ends 15 May 2026. An amicus filed 22 July into “briefing ongoing” is hard to reconcile with argument on 16 July. The current wording is correct and must not be strengthened. Confirming it needs PACER.
★ AMD-22 Amendment yes 6(b) · The felony tier’s knowledge element, and one word that is not American English · Blocked on MacDonald & Watson n.15, which needs a reporter print. Once read, level 4

Closed

ID Kind Drafted text Item
AMD-17–19 Amendment yes Never drafted, not lost. Numbers and titles were allocated in the index at commit d775601 (23 Aug) — 17 SEC. 11(d), remedies for a reporter outside employment; 18 SEC. 9(b), an immediate notice tier; 19 SEC. 0(a), the personhood finding — and no entry was ever written for any of them. Ruled out: proposals-adopted-v3-4.md (absent), the git history of proposals.md (no heading ever existed), and the inline index, which was replaced on 26 Aug. Closed 27 Aug: the gap is explained. The three subjects remain undrafted and may be renumbered if taken up

Nothing was lost in the reorganization

27 August 2026. 119 rows before, 122 after — the three added are the four decisions and the citizen-suit question, which existed in prose and had never been rows. The sections were A B C D F G H I J E, with E stranded at the end because two insertions used its anchor. They are now the five levels, ordered 5 to 1, plus Closed. No row was dropped, merged, or renumbered, and every row carries a level — the twenty-four that carried none were assigned by what each is blocked on first.


Back to top

This page was built . The repository is the authoritative record; if this page and the repository differ, the repository is right.

Visits are counted with GoatCounter: no cookies, no personal data, nothing shared. The count is private to the maintainer.

This site uses Just the Docs, a documentation theme for Jekyll.