{"message":"AI disclosure retrieved","code":200,"pageSize":0,"page":0,"totalCount":0,"nextCursor":null,"hasMore":false,"snapshotAt":null,"errorCode":null,"correlationId":null,"errors":null,"metadata":{},"data":{"policyVersion":"eu-ai-limited-risk-controls-v2","policyHash":"41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2","classificationStatus":"PRELIMINARY_PENDING_COUNSEL_REVIEW","counselReviewed":false,"generatedAt":"2026-09-24T04:55:43.836309061Z","aiActClassification":[{"systemKey":"deterministic_decision_kernel","displayName":"Deterministic risk-scoring kernel (DecisionKernel)","aiActRisk":"LIMITED","annexIIIReference":"n/a (not enumerated in Annex III; transparency obligations under Art. 50)","conformityRoute":"NOT_APPLICABLE","rationale":"Deterministic, replayable, no LLM in the decision path. Output informs but does not automate decisions affecting individuals' employment, credit, education, or essential services. No biometric or law-enforcement use. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"trajectory_pool","displayName":"Cross-tenant trajectory pool (aggregate-only)","aiActRisk":"LIMITED","annexIIIReference":"n/a — aggregated industry-level trajectories with explicit opt-in","conformityRoute":"NOT_APPLICABLE","rationale":"Aggregate-only contributions, k-anonymity ≥ 20 for every customer-affecting metric cell at both publication and read; there is no below-threshold fallback. Tenant administrative authorization defaults off; lawful-basis, DPIA/ROPA, and counsel review remain separate obligations. revocation triggers global rebuild excluding the revoked tenant. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"cross_lifecycle_cqi_kernel","displayName":"Cross-lifecycle CQI scoring formula (deterministic-recompute, tamper-evident)","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic internal GTM decision-support scoring across all five GTM lifecycle families for DEAL CQI","conformityRoute":"NOT_APPLICABLE","rationale":"The CQI score is produced by a deterministic formula and is tamper-evident via a hash-linked EvidenceManifest. CQI rows with a valid cqi_replay_snapshot are now byte-exact replay-verifiable end-to-end: a pure CqiScoringKernel + a re-feedable CqiInputSnapshotV1 persisted atomically with the score (same @Transactional, canonical-text source-of-truth column) feed CqiReplayService, which asserts byte-equality of both input and output hashes — same property the risk DecisionKernel and context-resolution paths carry. Marketing, sales, customer success, support, and product/engineering are stage-scored for DEAL CQI. Product/engineering stage attribution is deal-primary, derived from trusted mapped connector evidence, and surfaced to teams through existing deal-team rollups rather than a TEAM recompute subject. CONTACT subject CQI remains supported, but the Product/Engineering full CRTS lifecycle-stage claim is not made for CONTACT in V1. Unmapped provider AI insights stay advisory and outside the scoring path. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"peer_benchmark_flywheel","displayName":"Peer benchmark publication flywheel","aiActRisk":"LIMITED","annexIIIReference":"n/a — opt-in, k-anonymous aggregate benchmark publication","conformityRoute":"NOT_APPLICABLE","rationale":"Publication uses current benchmark generations only, tenant opt-in defaults off, k-anonymity is enforced at publish, and the tenant read surface exposes aggregate medians rather than raw rows. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"advisory_llm_outputs","displayName":"LLM-assisted advisory text (account briefs, suggested outreach, risk-dimension narrative/action drafts)","aiActRisk":"LIMITED","annexIIIReference":"Art. 50 transparency obligations apply (interaction with AI system)","conformityRoute":"NOT_APPLICABLE","rationale":"Advisory only; never on the decision path. UI labels every LLM-derived element. Risk-dimension enrichment is prose-only: the deterministic dimension, ranking, confidence, contribution profile, probability, and recommended action type cannot be changed by the model. Cached extractions ensure replay determinism without re-invoking the model. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"mcp_gtm_ingestion_gateway","displayName":"MCP GTM ingestion gateway (deterministic agent-originated data ingest)","aiActRisk":"LIMITED","annexIIIReference":"Art. 50 transparency obligations apply when agent-originated content is AI-generated; n/a for Annex III under the intended B2B GTM workflow","conformityRoute":"NOT_APPLICABLE","rationale":"The MCP GTM ingestion gateway accepts canonical envelopes from OAuth-registered agents into an immutable ledger and materializes them through deterministic, cluster-safe work queues. The ingest path does not invoke an LLM or make autonomous individual-impact decisions; provenance, content hashes, generated-content flags, scopes, tenant binding, quarantine, replay, and audit records preserve transparency and human oversight. Intended purpose is mandatory at connector creation; employment/rep evaluation and other high-risk or prohibited purposes are rejected unconditionally, and the legacy acknowledgement field cannot bypass that boundary. The connector also exposes FGA-gated, deterministic read tools (deals, contacts, signals, message activity, benchmarks) under per-resource OpenFGA authorization to a least-privilege service user; reads invoke no LLM. (counselReviewed remains false pending counsel sign-off before external GA.) Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"agentic_consequential_action_control_plane","displayName":"Tenant-governed consequential action control plane","aiActRisk":"LIMITED","annexIIIReference":"n/a under the pinned DEAL_ACCOUNT_REVENUE_OPERATIONS purpose; a tenant declaration of a high-risk purpose activates the stricter high-risk policy profile and requires counsel review","conformityRoute":"NOT_APPLICABLE","rationale":"BaseAPI, not an agent, derives the action descriptor and applies a non-bypassable platform floor before provider I/O. Tenants can deny or require approval for additional work and can pre-authorize only actions that the floor marks eligible. External, administrative, destructive, lifecycle, and high-risk actions remain human-approval-required. Every evaluated non-read action receives an append-only receipt binding minimized inputs, the frozen tenant policy, policy hash, decision hash, human-oversight requirement, and EU AI Act control references; replay re-runs the clock-free kernel against the frozen snapshot. Tenant activation validates intended purpose, prohibited-purpose screening, AI literacy ownership, record retention, human oversight, transparency, post-market monitoring, incident contact, and evidence references. This is a control-mapped technical posture, not a legal opinion or independent certification; counselReviewed remains false pending signed platform-level review. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"sentry_reliability_connector","displayName":"Sentry reliability connector (deterministic sanitized provider evidence)","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic B2B GTM decision-support evidence; Art. 50 transparency applies to any later AI-generated advisory text","conformityRoute":"NOT_APPLICABLE","rationale":"Sentry evidence is ingested from signed Integration Platform webhooks, reduced to sanitized issue/alert metadata, and mapped through tenant-owned tags or admin project/environment mapping before it can affect scoring. Raw stack frames, breadcrumbs, request headers, cookies, IPs, user emails, and exception bodies are not persisted by default. The connector does not make autonomous decisions; it feeds deterministic CQI, risk-dimension, trajectory explanation, and early-warning decision-support paths with provenance, redaction status, payload digests, and human-reviewable attribution. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"microsoft_teams_collaboration_connector","displayName":"Microsoft Teams collaboration connector (deterministic sanitized provider evidence)","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic B2B GTM decision-support evidence; Art. 50 transparency applies to any later AI-generated advisory text","conformityRoute":"NOT_APPLICABLE","rationale":"Teams evidence is ingested from Microsoft Graph sync and validated change notifications, reduced to redacted text, content hashes, resource metadata, participants, timestamps, and attribution state. It does not make autonomous decisions; it feeds deterministic deal context, CQI, risk-dimension, trajectory refresh, and advisory context with human-reviewable attribution and write-consent-gated outbound task routing. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"conversation_action_reconciliation","displayName":"Provider-independent action coverage detector (deterministic, proof-carrying)","aiActRisk":"LIMITED","annexIIIReference":"n/a — intended only for deal/account revenue operations; Annex III employment and worker-management uses are prohibited","conformityRoute":"NOT_APPLICABLE","rationale":"This subsystem is intended solely for DEAL_ACCOUNT_REVENUE_OPERATIONS. Deterministic rules extract action discussions and reconcile them against same-deal projected work-item metadata from optional Jira, Linear, GitHub, CRM, or future provider adapters; no LLM is invoked. Negative claims require fresh, exhaustive, error-free provider coverage receipts and otherwise remain explicitly unverified. Only minimized action summaries, salient tokens, hashes, provider references, and policy/provenance metadata are copied into action receipts; raw bodies remain solely in their governed source/evidence stores and are not duplicated into action signals or tasks. Provider sync and signal materialization create automatic audit logs. Worker monitoring, worker or sales-rep ranking, performance appraisal, hiring, compensation, discipline, termination, and every other employment decision are expressly prohibited. Automated assistance is disclosed as a workflow suggestion, human review is not a prerequisite, and human override and appeal remain available. The system may create an internal, dismissible unified task automatically. Reconciliation remains read-only and external work-item creation is never automatic (no automatic external writes). Policy-enabled urgent notifications may route through consent-gated Slack, Teams, email, or in-app delivery without changing customer, worker, employment, or revenue records. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"outlook_email_ingestion","displayName":"Outlook / Microsoft Graph email ingestion (deterministic sanitized provider evidence)","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic B2B GTM decision-support evidence; Art. 50 transparency applies to any later AI-generated advisory text","conformityRoute":"NOT_APPLICABLE","rationale":"Outlook mail is ingested via Microsoft Graph /me/messages/delta (plan A1) with per-channel deltaLink resume, full To/Cc/Bcc recipient capture (plan A2), per-contact consent gating (UserChannel.optOut + consentExpiryDate), HMAC-hashed email matching for contact resolution, and GDPR Art. 6 lawful-basis tagging on every emitted OptimizationSignal (plan F1, default LEGITIMATE_INTEREST for B2B sales). Signals feed the deterministic CQI, RiskDimension, and Trajectory kernels — no LLM on the decision path. Per-sync audit logging via AuditLoggingService with correlation IDs. Multi-node safety: DistributedTenantSyncScheduler holds a distributed lock with heartbeat + ThreeNodeExactlyOnceCertificationTest coverage (plan A3 / C3). Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"calendar_ingestion","displayName":"Google + Outlook calendar ingestion (deterministic sanitized provider evidence)","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic B2B GTM decision-support evidence; Art. 50 transparency applies to any later AI-generated advisory text","conformityRoute":"NOT_APPLICABLE","rationale":"Calendar events are ingested via Google /calendar/events with nextSyncToken and Microsoft Graph /me/calendarView/delta with deltaLink, both with 410-Gone re-bootstrap. Description PII (emails, phones, URLs) is redacted before any value enters the signal payload (content_redaction_level=STANDARD); raw description persists in calendar_events for tenant-scoped right-to-erasure only. Attendee emails are HMAC-hashed for contact resolution. Recurrence metadata (isRecurring, recurringEventId, recurrenceRule) feeds the deterministic MeetingCadenceDeltaDetector (plan D1). Every signal carries GDPR Art. 6 lawful basis (plan F1). Multi-node safety: CalendarSyncScheduler holds per-tenant DistributedLockService with heartbeat + ThreeNodeExactlyOnceCertificationTest coverage. No LLM on the decision path. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_dimension_synthesis_kernel","displayName":"RiskDimension synthesis kernel (deterministic scorecards)","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic internal GTM decision-support classification","conformityRoute":"NOT_APPLICABLE","rationale":"Risk dimensions are synthesized by deterministic, replayable scorecards from frozen signal snapshots. No LLM, clock, random source, or network call is on the decision path. The surface exposes the matched rule path and contribution percentages; calibrated probability is hidden unless a promoted weight-set artifact and display threshold are present. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"context_resolution_attribution","displayName":"AI-assisted context resolution and auto-multi deal attribution","aiActRisk":"LIMITED","annexIIIReference":"Art. 50 transparency obligations apply (AI-assisted decision support); n/a for Annex III","conformityRoute":"NOT_APPLICABLE","rationale":"Context gaps are labelled as AI-assisted decision support and route to Pending Cases for human RESOLVE_GAP or REJECT action. Auto-multi attribution is deterministic and allowed only when all candidates share the same non-null company and the same non-null product fingerprint under the tenant policy. The system creates traceable attribution links and evidence manifests; it does not perform an autonomous irreversible individual-impact decision. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"early_warning_alerts","displayName":"Early-warning alerts on at-risk deals","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal sales workflow tool, no individual-impact decision flow under Annex III","conformityRoute":"NOT_APPLICABLE","rationale":"Alerts surface to internal sales/CS users for review. No automated decision affecting an external individual's rights or services. Human oversight via RecommendedAction lifecycle. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_dimension_weights_promotion","displayName":"RiskDimension calibrated weight-set promotion","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model configuration, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"RiskDimension calibration emits exact-version ModelGenerationArtifact rows per supported dimension. Promotion uses the RISK_DIMENSION_WILSON_BASELINE_V3 proof profile against V4 trust-frozen snapshots and matrix 2.3. Strict readiness prevents an older promoted matrix from being used after a policy bump. Outputs remain deterministic by pinning the selected weightSetHash, trust verdicts, evidence-DAG version, and policy hash in the snapshot. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_dimension_calibration_readiness","displayName":"RiskDimension calibration readiness display","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model-readiness evidence, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"The calibration report is tenant-scoped and reads exact-version PROMOTED or ADVISORY_ONLY artifacts. Failed dimensions stay visible with blocked reasons rather than disappearing, and buyer-facing probabilities remain suppressed unless the strict promotion gate is live and display thresholds are met. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_dimension_task_generation","displayName":"RiskDimension auto-generated remediation tasks","aiActRisk":"LIMITED","annexIIIReference":"Art. 50 transparency obligations apply (AI-assisted decision support); n/a for Annex III — internal task recommendations require human review","conformityRoute":"NOT_APPLICABLE","rationale":"RiskDimension may create internal SalesSynq remediation tasks only from persisted, replayable decisions whose exact-version calibration readiness is LIVE_PROOF. Each task is labelled auto-generated decision support, requires human review, records audit/model/hash metadata, and exposes a feedback path. External routing to Slack, Jira, CRM, or similar providers remains opt-in through tenant write consent and task authorization. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"champion_inference","displayName":"Engagement-based champion inference (advisory, deterministic)","aiActRisk":"LIMITED","annexIIIReference":"Art. 50 transparency obligations apply (AI-assisted decision support); n/a for Annex III — advisory stakeholder hint, no individual-impact decision","conformityRoute":"NOT_APPLICABLE","rationale":"Fills the 'who is the champion' gap only when no CRM-declared buying role exists. The output is labelled INFERRED (AI_DERIVED) and is never presented as a declared fact; a CRM-declared role always outranks it. The inference abstains rather than guess when the engagement evidence is ambiguous. It is a pure, deterministic function of frozen engagement features — no LLM, clock, or RNG — and is byte-replayable with hashes stable across nodes. Advisory only; never the sole basis of an automated decision affecting an individual. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"cqi_synthesis_kernel","displayName":"CQI composite-score deterministic scoring kernel","aiActRisk":"LIMITED","annexIIIReference":"n/a — deterministic internal GTM decision-support score","conformityRoute":"NOT_APPLICABLE","rationale":"Deal Quality Index composite + 9 sub-scores produced by a pure, deterministic kernel (CqiScoringKernel). No LLM, clock, RNG, or network on the decision path; kernel purity is source-scanned by CqiScoringKernelDeterminismTest and cross-process determinism is asserted by CqiHashStabilityAcrossNodesTest (3-JVM fork against pinned hashes). Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"cqi_weights_promotion","displayName":"CQI calibrated weight-set promotion (AUROC-lift)","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model configuration, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"CqiPromotionRunner emits exact-version ModelGenerationArtifact under the CQI_AUROC_LIFT_V3 proof profile, asserting correctly oriented loss-risk AUROC of the CQI composite score exceeds the naive-health baseline (lower CI bound clears zero). Promotion uses ModelPromotionGateService.assessStrict — no fallback to older promoted weight versions. Below-threshold corpus persists as ADVISORY_ONLY with the blocked_reason intact (audit visible). Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"cqi_calibration_readiness","displayName":"CQI calibration readiness display","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model-readiness evidence, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"Calibration readiness for cqi-composite-score is tenant-scoped and reads exact-version PROMOTED or ADVISORY_ONLY artifacts. Buyer-facing AUROC-lift claims are suppressed unless the strict gate is LIVE_PROOF; advisory artifacts retain their blocked reasons rather than disappearing. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_likelihood_synthesis_kernel","displayName":"Risk-likelihood decision kernel (deterministic, per-outcome Wilson)","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal sales decision support, no individual-impact decision under Annex III","conformityRoute":"NOT_APPLICABLE","rationale":"Risk case decision via DecisionKernel.compute(DecisionSnapshotV1) — pure function, no clock/RNG/IO inside the kernel; the assembler resolves now and freezes decisionTs into the snapshot. Purity guarded by DecisionKernelPurityTest; byte-identity guarded by Ws3bRiskReplayByteIdentityRegressionTest with pinned hashes; multi-node parity asserted by RiskCaseHashStabilityAcrossNodesTest. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_likelihood_weights_promotion","displayName":"Risk-likelihood per-outcome calibrated weight-set promotion","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model configuration, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"PredictionEvaluationService emits one ModelGenerationArtifact per outcome (LOSS_30D, CLOSE_DATE_SLIPPAGE, MISSED_CLOSE, CHURN_RISK) under the RISK_LIKELIHOOD_WILSON_BASELINE_V2 proof profile. Each promotion uses strict exact-version semantics, a recomputable chronological paired-Brier e-process certificate with a fixed four-outcome family-wise error budget, and an exact frozen-label stability certificate. There is no fallback to older promoted versions. The bare risk-likelihood modelKey is retired in favour of the per-outcome keys. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"risk_likelihood_calibration_readiness","displayName":"Risk-likelihood per-outcome calibration readiness display","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model-readiness evidence, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"Per-outcome calibration readiness rows are surfaced via ModelPromotionGateService.assessStrict for each risk-likelihood-<OUTCOME> key. Calibrated loss probabilities are hidden unless every outcome's gate is LIVE_PROOF; advisory artifacts retain blocked_reason. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"trajectory_synthesis_kernel","displayName":"Trajectory path-distance kernel (interquartile-range normalised, deterministic)","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal buyer-state motion analysis, no individual-impact decision","conformityRoute":"NOT_APPLICABLE","rationale":"TrajectoryKernel.compute(TrajectoryInputSnapshotV1) is a pure function: interquartile-range normalised position vs the won/lost trajectory pool, velocity gap, acceleration gap, quadratic motion fit. No clock/RNG/IO inside the kernel; the assembler freezes all profile statistics + score history into the snapshot. Purity guarded by TrajectoryKernelPurityTest; multi-node parity asserted by TrajectoryHashStabilityAcrossNodesTest (3-JVM fork) and TrajectoryReplayMultiNodeCertificationTest (NODES=3 × K=20 fixtures). Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"trajectory_weights_promotion","displayName":"Trajectory calibrated weight-set promotion (Wilson)","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model configuration, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"TrajectoryPromotionRunner emits exact-version ModelGenerationArtifact under the TRAJECTORY_WILSON_BASELINE_V3 proof profile over prospectively persisted production input snapshots and pre-outcome decisions, asserting that P(loss | trajectory verdict = HIGH_RISK) exceeds the corpus baseline (Wilson 95% CI lower bound clears baseline_loss_rate). Strict exact-version semantics; no fallback to older versions. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"trajectory_calibration_readiness","displayName":"Trajectory calibration readiness display","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model-readiness evidence, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"Trajectory calibration readiness is tenant-scoped and reads exact-version PROMOTED or ADVISORY_ONLY artifacts. Calibrated loss probabilities are hidden unless the strict gate is LIVE_PROOF; advisory artifacts retain blocked_reason. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"self_learning_synthesis_kernel","displayName":"Self-learning weight derivation kernel (deterministic, train/validation split)","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model configuration, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"SelfLearningKernel derives new warning-weight candidates via a deterministic grid search on a 70/30 train/validation split sorted by UUID, then computes the paired AUROC LIFT bootstrap CI on the validation set only. Pinned SplittableRandom seed; purity guarded by SelfLearningKernelPurityTest; multi-node parity asserted by SelfLearningHashStabilityAcrossNodesTest (3-JVM fork) and SelfLearningReplayMultiNodeCertificationTest. Replaces the previous self_learning_weights_promotion placeholder which had no producer. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"self_learning_weights_promotion","displayName":"Self-learning weight-set promotion (AUROC-lift with audit hashes)","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model configuration, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"SelfLearningPromotionRunner emits exact-version ModelGenerationArtifact under the SELF_LEARNING_AUROC_LIFT_V2 proof profile. Only immutable-link-time, terminal WON/LOST-family labels enter the estimator; triage judgments carry zero outcome weight. The lift claim carries prior_weights_hash + new_weights_hash + split_hash so the audit trail can prove 'these specific NEW weights beat THESE specific PRIOR weights on THIS split'. Volume gate: n ≥ 100, validation_n ≥ 30, positives ≥ 10, negatives ≥ 10. Lift gate: bootstrap CI lower bound > 0. Below-threshold corpus persists as ADVISORY_ONLY with blocked_reason intact. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false},{"systemKey":"self_learning_calibration_readiness","displayName":"Self-learning calibration readiness display","aiActRisk":"LIMITED","annexIIIReference":"n/a — internal model-readiness evidence, no individual-impact flow","conformityRoute":"NOT_APPLICABLE","rationale":"Self-learning calibration readiness is tenant-scoped and reads exact-version PROMOTED or ADVISORY_ONLY artifacts via assessStrict. First production runs WILL fail INSUFFICIENT_SAMPLE until enough labelled feedback accumulates (≥ 100 rows in the 7-90d label-latency window) — this is correct fail-closed behaviour, not a bug. Classification status: PRELIMINARY_PENDING_COUNSEL_REVIEW; executable policy eu-ai-limited-risk-controls-v2 / 41164c778debdc3b8629918fb77e3a8b7a52a459d27a09007362bb32e273b2a2.","counselReviewed":false}]},"items":[],"dataList":[],"requestId":"5f3efe29-cde4-4cec-b100-ae7b1f82d88e"}