For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE II. IDENTITY

24.1 Establishment of The Global Centre for Risk and Innovation - Canada. The Global Centre for Risk and Innovation - Canada, referred to in this Bylaw as the Corporation or GCRI Canada, is established and shall be maintained as a Canadian nonprofit, non-share, non-distributing, public-benefit, non-executing institution organized to steward upstream evidence, methods, observability, ontology, technical truth, public-good research and development, open technology, public-good software, open technical baselines, public authority learning, public-safe publication, and Nexus-compatible public-good coordination.

The Corporation shall exist as a public-benefit technical institution within Canada’s legal order and within the wider Nexus public-good architecture. Its establishment shall be interpreted as the formation of a lawful Canadian corporate body for evidence infrastructure, scientific-operational methods, observability systems, semantic interoperability, technical memory, public-good R&D, technical baselines, public-good software, and correctionable institutional learning across exponential, mission-critical, systemic-risk, resilience, infrastructure, and public-good domains.

For greater certainty, the Corporation’s establishment shall not be interpreted as the formation of:

a) a public authority, government body, regulator, treaty organization, sovereign standards body, emergency-management body, public-warning body, public finance authority, procurement authority, certification authority, accreditation body, recognition body, maturity-rating body, finance-readiness authority, insurer, lender, underwriter, broker, dealer, fund, market operator, clearing or settlement body, bank, payment intermediary, asset manager, investment adviser, national consortium company, Project SPV, enterprise delivery vehicle, provider platform, sponsor platform, or commercial execution vehicle;

b) a branch, office, division, alter ego, subsidiary, parent, agent, fiduciary delegate, common employer, shared treasury, common-liability platform, or execution arm of GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Observatory, Nexus Standards, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Consortium Companies, Project SPVs, qualified enterprise providers, sponsors, hosts, public authorities, universities, laboratories, communities, civil society bodies, or partners; or

c) an institution empowered to convert evidence into recognition, methods into certification, observability into public warning, technical baselines into procurement mandates, public authority participation into public authority action, finance-readiness inputs into finance-readiness determinations, public-good software into execution authority, AI outputs into final authority, blockchain or ledger entries into governance authority, DePIN records into public meaning, AI-RAN signals into operational command, or proof receipts into legal conclusions.

The Corporation’s establishment shall be evidenced, governed, and preserved through its Articles, this Bylaw, Board resolutions, statutory records, registered office records, corporate filings, minute books, registers, authoritative repository, Gazette or Gazette-equivalent notice stream where established, official name-use records, tax and nonprofit records, legal identity records, continuity records, and any other record required by applicable law or this Bylaw.

24.2 Corporation as a Distinct Legal Person. The Corporation shall be and remain a distinct legal person separate from its directors, officers, members where applicable, participants, supporters, subscribers, contributors, employees, contractors, volunteers, fellows, advisors, sponsors, donors, funders, hosts, vendors, providers, public authority participants, universities, laboratories, communities, civil society actors, media actors, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Observatory, Nexus Standards, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified enterprise providers, and any other Nexus-aligned or external person.

The Corporation’s distinct legal personality shall mean that:

a) the Corporation’s property, funds, grants, donations, sponsorships, subscriptions, fees, cost-recovery receipts, in-kind contributions, software assets, technical assets, records, rights, obligations, contracts, claims, proceedings, liabilities, authorities, permissions, registrations, filings, and lawful acts are those of the Corporation only where created, received, held, assumed, or approved by the Corporation in accordance with applicable law, the Articles, this Bylaw, and competent records;

b) no director, officer, member, participant, supporter, subscriber, donor, sponsor, funder, host, provider, public authority, partner, founder, contributor, technical maintainer, repository administrator, committee participant, council participant, advisor, fellow, staff member, contractor, GCRI entity, Nexus entity, consortium, national company, Project SPV, or external actor owns the Corporation’s legal identity, public-benefit purpose, institutional continuity, evidence function, methods function, observability function, ontology function, technical truth function, public-good software, technical baselines, public-safe publications, controlled vocabulary, records, or public-good stewardship role;

c) no participation, contribution, authorship, funding, sponsorship, donation, hosting, public authority attendance, provider contribution, technical access, repository permission, dashboard access, room access, shared doctrine, shared vocabulary, shared publication, shared event, shared software, shared visual identity, common public narrative, or Nexus-compatible relationship shall merge the Corporation with any other person;

d) no obligation, liability, debt, undertaking, warranty, guarantee, public representation, public authority meaning, finance-readiness meaning, recognition meaning, certification meaning, procurement meaning, rating meaning, emergency-command meaning, public-warning meaning, or execution responsibility shall bind or be attributed to the Corporation unless lawfully created, expressly accepted, properly authorized, and recorded in the Corporation’s official records;

e) no person shall bind the Corporation except through lawful authority, written or otherwise legally sufficient delegation, competent approval, and record discipline; and

f) no person shall bind GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), any Nexus entity, any consortium, any national company, any Project SPV, any provider, any sponsor, any host, any public authority, or any partner by reason of that person’s relationship with the Corporation.

The Corporation’s distinct legal personality shall be preserved in all contracts, memoranda of understanding, cooperation instruments, grant agreements, donation agreements, sponsorship agreements, subscription agreements, fee arrangements, in-kind contribution records, provider agreements, host agreements, public authority protocols, data-sharing agreements, software contribution agreements, controlled-room agreements, public authority room records, capital-reader room records, publication agreements, Nexus interface agreements, registers, repositories, dashboards, public-safe summaries, websites, presentations, reports, technical baselines, software releases, and public communications.

24.3 Continuity of Corporate Existence. The Corporation shall continue in existence notwithstanding any change in directors, officers, members where applicable, participants, supporters, subscribers, employees, contractors, volunteers, fellows, advisors, committees, councils, working groups, programs, projects, funding sources, sponsors, donors, funders, hosts, providers, vendors, public authority participants, universities, laboratories, communities, civil society participants, media participants, repositories, datasets, software assets, technical baselines, controlled rooms, data rooms, public authority rooms, capital-reader rooms, dashboards, publications, public-safe outputs, or Nexus interfaces.

Continuity of corporate existence shall preserve the Corporation’s legal identity, public-benefit purpose, nonprofit character, non-share character, non-distribution rule, non-charitable posture unless lawfully changed, mission lock, non-execution boundary, legal separateness, public-good stewardship duties, records obligations, correction obligations, data / AI / cyber obligations, research integrity obligations, public authority boundary discipline, finance-readiness boundary discipline, certification boundary discipline, procurement neutrality, provider neutrality, sponsor non-control, and Nexus role separation unless lawfully amended, superseded, continued, amalgamated, dissolved, wound up, or otherwise changed through a formal recorded legal act.

The Corporation’s continuity shall not depend upon any single founder, director, officer, member, donor, sponsor, funder, host, provider, public authority participant, university, laboratory, community, partner, event, platform, software repository, dataset, dashboard, technical baseline, observatory node, Nexus interface, or public narrative.

The Corporation shall maintain institutional-memory discipline sufficient to demonstrate continuity across time. Such discipline shall include official registers, minute books, Board records, officer records, member records where applicable, policy records, delegation records, program records, project records, evidence records, methods records, ontology records, observability records, software records, technical asset records, public-safe publication records, correction records, supersession records, withdrawal records, archival records, interface records, and continuity records.

24.4 Perpetual Succession Subject to Lawful Dissolution. The Corporation shall have perpetual succession to the fullest extent permitted by applicable law, subject only to lawful dissolution, wind-up, amalgamation, continuance, reorganization, or other corporate act approved and recorded in accordance with applicable law, the Articles, this Bylaw, Board reserved matters, member approval where required, and any required filings, consents, approvals, notices, or public-safe communications.

Perpetual succession shall mean that:

a) the Corporation’s existence shall not terminate by death, resignation, removal, incapacity, suspension, vacancy, term expiry, withdrawal, retirement, insolvency, dispute, replacement, or change of any director, officer, member, participant, supporter, employee, contractor, volunteer, fellow, advisor, sponsor, donor, funder, host, provider, public authority participant, partner, or external actor;

b) the Corporation’s rights, duties, records, obligations, contracts, assets, public-good assets, evidence artifacts, methods, ontologies, technical baselines, software assets, publications, controlled vocabulary, correction records, and institutional memory shall continue unless lawfully assigned, transferred, terminated, novated, superseded, extinguished, archived, sealed, disposed of, or otherwise altered by competent authority;

c) no project conclusion, program sunset, funding termination, sponsor withdrawal, provider withdrawal, host change, public authority change, repository migration, software fork, dataset retirement, publication supersession, data-room closure, controlled-room closeout, technical baseline supersession, or Nexus interface change shall terminate the Corporation’s existence; and

d) any dissolution, wind-up, asset disposition, public-good asset transfer, record disposition, repository preservation, software preservation, evidence archive, public-safe notice, successor access, or institutional closeout shall occur only through recorded lawful process.

Perpetual succession shall not be used to preserve error, unsafe records, unsupported claims, obsolete methods, stale data, misleading publications, invalid technical baselines, superseded software, sponsor-influenced conclusions, provider-influenced methods, public authority confusion, finance-readiness overclaims, certification overclaims, procurement overclaims, or records that require correction. Continuity shall coexist with correctionability.

24.5 Continuity Despite Changes in Directors, Officers, Members, Participants, Programs, Funders, Partners, or Nexus Interfaces. The Corporation’s existence, identity, authority, records, public-benefit purpose, non-execution boundary, legal separateness, and public-good stewardship duties shall continue despite changes in:

a) directors, including appointment, election, resignation, removal, suspension, incapacity, death, vacancy, recusal, term expiry, replacement, or succession;

b) officers, executive leadership, secretariat, central bureau, functional leads, staff, contractors, consultants, volunteers, fellows, advisors, seconded personnel, developers, maintainers, technical contributors, or operational teams;

c) statutory members where applicable, voting members where applicable, non-voting members, supporters, subscribers, institutional participants, delegates, observers, public authority participants, community participants, Indigenous participants, academic participants, civil society participants, media participants, enterprise participants, or technical participants;

d) programs, projects, laboratories, research streams, evidence streams, methods streams, observability environments, ontology projects, technical repositories, software assets, model registers, dataset registers, dashboards, controlled rooms, data rooms, evidence rooms, public authority rooms, capital-reader rooms, Academy activities, Nexus Universe activities, public-good testbeds, or technical baselines;

e) sponsors, donors, funders, grantors, hosts, providers, vendors, cloud providers, AI providers, data processors, universities, laboratories, public authorities, communities, national consortiums, regional consortiums, global consortiums, national companies, Project SPVs, or partners;

f) restricted funds, unrestricted funds, in-kind contributions, subscriptions, fees, cost-recovery arrangements, sponsorship arrangements, donation arrangements, grant arrangements, public authority support, host support, provider contributions, or enterprise participation;

g) Nexus interfaces, including interfaces with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified enterprise providers, sponsors, hosts, public authorities, and other Nexus-compatible actors; and

h) technology scope, technical methods, evidence classifications, controlled vocabulary, schemas, taxonomies, ontologies, data dictionaries, public-safe publication classes, access classes, repository systems, cybersecurity controls, AI governance controls, public authority protocols, finance-boundary controls, certification-boundary controls, procurement-neutrality controls, or governance procedures.

No such change shall be treated as creating a new legal person, dissolving the Corporation, transferring the Corporation’s duties, eliminating prior records, extinguishing correction obligations, authorizing uncontrolled rebranding, creating new governance authority, resetting institutional memory, or altering the Corporation’s legal status unless expressly and lawfully recorded.

24.6 Continuity of Records, Evidence Artifacts, Methods, Ontologies, Technical Baselines, Software Assets, Publications, and Public-Good Stewardship Duties. The Corporation shall preserve continuity of its records, evidence artifacts, methods, ontologies, technical baselines, public-good software, open technical assets, publications, public-safe summaries, controlled annexes, model records, dataset records, inference records, compute workload records, dashboards, source-lineage records, correction records, public authority learning records, and public-good stewardship duties.

Each material institutional asset shall have, where appropriate to its class, a recorded owner, custodian, steward, authority surface, version identifier, status, effective date, access class, publication class, data sensitivity class, security class, public authority sensitivity class, finance sensitivity class, safeguards flag, correction path, review cycle, supersession path, withdrawal path, retirement path, and archive path.

Continuity shall apply to:

a) corporate records, including Articles, bylaws, amendments, resolutions, minutes, registers, filings, notices, policies, charters, terms of reference, delegations, officer records, director records, member records where applicable, committee records, council records, authority matrices, official registers, Gazette entries, and governance instruments;

b) evidence artifacts, including evidence packs, assurance packs, source-lineage records, provenance records, confidence records, uncertainty records, challenge records, evidence classifications, public-safe evidence summaries, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, and correction records;

c) methods, including validation methods, confidence-scoring methods, uncertainty methods, source-lineage methods, sensor-fusion methods, AI output review methods, AI-RAN signal interpretation methods, O-RAN methods, DePIN validation methods, digital twin assumption review methods, geospatial evidence methods, cyber evidence methods, benchmarking methods, reproducibility methods, replication methods, public-safe publication methods, and correction methods;

d) observability assets, including Nexus Observatory methods, observatory node methods, hub methods, cluster methods, hotspot methods, national dense core methods, regional cluster methods, sensor methods, edge compute methods, sovereign compute methods, AI-RAN methods, O-RAN methods, DePIN methods, digital twin methods, simulation methods, cyber telemetry methods, geospatial methods, degraded-mode awareness methods, resilience indicators, mission-critical signal methods, and public-safe dashboard methods;

e) ontologies and semantic infrastructure, including taxonomies, controlled vocabularies, schemas, data dictionaries, risk ontologies, maturity concepts, evidence classifications, technology-family classifications, public authority capacity terms, finance-readiness boundary terms, recognition-boundary terms, certification-boundary terms, procurement-boundary terms, and AI-readable knowledge structures;

f) technical baselines and public-good software, including reference architectures, APIs, SDKs, schemas, dashboards, data tools, test harnesses, gold vectors, negative tests, model cards, dataset cards, system cards, benchmark cards, public-good repositories, secure build records, SBOM records, dependency records, vulnerability records, signing records, provenance records, release records, rollback records, deprecation records, and retirement records;

g) publications, including research publications, technical notes, methods notes, evidence notes, public-safe summaries, whitepapers, reports, website materials, public authority learning materials, Academy materials, visual materials, media materials, controlled annexes, errata, correction notices, withdrawal notices, retraction notices, and archival notices; and

h) interface records with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, communities, and partners.

Continuity of records and public-good assets shall not mean immutability. The Corporation shall preserve historical traceability while permitting correction, clarification, errata, supersession, withdrawal, retraction, downgrade, retirement, archival, sealing, secure disposal, deletion, or lawful successor access in accordance with this Bylaw.

24.7 No Fragmentation by Program, Project, Partnership, Platform, Repository, Dataset, or Funding Source. The Corporation shall not permit its legal identity, public-benefit purpose, mission lock, non-execution boundary, public-good stewardship role, records discipline, evidence integrity, methods integrity, observability integrity, ontology discipline, public authority boundary, finance-readiness boundary, certification boundary, procurement neutrality, sponsor non-control, provider neutrality, correctionability, or Nexus role separation to fragment by program, project, partnership, platform, repository, dataset, funding source, sponsor source, provider source, host site, event, room, interface, software asset, technical baseline, public authority relationship, national consortium relationship, national company relationship, Project SPV relationship, or Nexus interface.

No program, project, partnership, platform, repository, dataset, technical asset, funding source, or interface shall have independent constitutional authority unless separately and lawfully constituted. No such structure shall:

a) create a separate GCRI Canada legal identity;

b) override applicable law, the Articles, this Bylaw, Board authority, member approval where required, or official registers;

c) create autonomous governance authority outside the record;

d) create authority to bind the Corporation outside delegation;

e) create authority to bind GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), any Nexus entity, any consortium, any national company, any Project SPV, any provider, any sponsor, any host, any public authority, or any partner;

f) create public authority, recognition, finance-readiness, certification, procurement, standards, protocol, emergency-command, public-warning, regulated advice, or execution authority;

g) create sponsor, donor, funder, provider, host, investor, insurer, lender, national company, Project SPV, public authority, university, laboratory, community, or partner control over the Corporation;

h) isolate records from the authoritative repository, official register system, Gazette or notice stream, correction register, or Board oversight;

i) defeat conflict, recusal, related-party, competition, antitrust, data, AI, cyber, privacy, sanctions, export-control, research ethics, community safeguards, protected-knowledge, accessibility, public-safe publication, or correction controls; or

j) conceal obligations, liabilities, risks, errors, overclaims, public authority confusion, finance-readiness overclaims, certification overclaims, procurement overclaims, provider preference claims, sponsor-control implications, or role collapse.

Programs, projects, partnerships, platforms, repositories, datasets, funding sources, and Nexus interfaces may have operational records, project records, technical records, financial records, data records, evidence records, and closeout records, but such records shall remain subordinate to and interoperable with the Corporation’s official governance and records architecture.

Where fragmentation risk arises, the Corporation shall impose compatibility notes, divergence logs, repository reconciliation, access controls, classification controls, role clarification, correction records, Board review, or other controls necessary to preserve institutional unity.

24.8 No Interruption of Corporate Continuity Except by Formal Recorded Legal Act. The Corporation’s continuity shall not be interrupted, suspended, terminated, transferred, merged, divided, continued, amalgamated, wound up, dissolved, renamed, reconstituted, or materially transformed except by formal recorded legal act taken in accordance with applicable law, the Articles, this Bylaw, Board reserved matters, member approval where required, and any required filings, notices, consents, approvals, repository deposits, Gazette entries, or public-safe communications.

No interruption of corporate continuity shall occur by reason of:

a) informal agreement;

b) email, chat, call, meeting note, slide deck, public statement, website update, social media post, press statement, media description, repository comment, task-board entry, spreadsheet, informal memorandum, or unsigned draft;

c) operational practice, repeated behaviour, course of dealing, custom, convenience, urgency, ambiguity, or silence;

d) funding interruption, grant expiry, sponsor withdrawal, donor withdrawal, provider withdrawal, host withdrawal, or public authority change;

e) event cancellation, Nexus Universe change, observatory-node change, data-room closure, controlled-room closeout, capital-reader room closeout, repository migration, software fork, dataset retirement, dashboard deprecation, or technical baseline supersession;

f) leadership transition, resignation, removal, vacancy, member change where applicable, officer change, staff change, committee change, council change, advisor change, or fellowship change;

g) national, regional, or global Nexus interface change;

h) public narrative change, brand change, campaign change, publication correction, public-safe clarification, or visual identity update; or

i) emergency improvisation.

A formal recorded legal act affecting continuity shall include, where applicable:

a) the legal authority for the act;

b) the decision authority;

c) the text or instrument considered;

d) quorum and voting record;

e) conflict and recusal record;

f) member approval where required;

g) legal and compliance review;

h) tax, nonprofit, charitable-status, data, AI, cyber, privacy, sanctions, export-control, research ethics, public authority, sponsorship, provider, employment, records, insurance, and public-safe publication review where applicable;

i) asset, record, software, evidence, method, ontology, publication, technical baseline, data, model, dashboard, and public-good asset disposition;

j) successor access and archival plan where applicable;

k) correction, notice, and public description plan;

l) filing, repository deposit, Gazette, and notice-stream requirements; and

m) effective date, transition rules, and closeout records.

No person shall rely on uncertainty, transition, operational disruption, leadership change, funding pressure, sponsor pressure, provider pressure, public authority interest, or external narrative to treat the Corporation as dissolved, merged, suspended, rebranded, reconstituted, or transferred without the formal recorded legal act required by this Section.

24.9 Legal Identity Records. The Corporation shall maintain legal identity records sufficient to demonstrate its establishment, corporate form, governing law, registered office, Canadian seat, nonprofit status, non-share capital character, non-distribution rule, non-charitable posture unless lawfully changed, public-benefit purpose, authoritative name, approved short name, controlled naming protocol, official marks, public description, Board authority, officer authority, statutory registers, filings, legal separateness, and continuity.

Legal identity records shall include, as applicable:

a) Articles, articles of incorporation, certificates, notices, filings, letters patent if any, continuance records if any, and any constituting instrument;

b) this Bylaw and all adopted amendments, supersessions, withdrawals, archives, correction records, certified copies, repository records, and Gazette or notice-stream entries;

c) Board and member resolutions where applicable relating to establishment, name, status, registered office, governance seat, tax status, public-benefit purpose, powers, restrictions, continuity, dissolution, amalgamation, continuation, wind-up, or reorganization;

d) corporate registers, director registers, officer registers, member registers where applicable, registered office records, annual returns, statutory returns, minute books, filings, notices of change, certifications, and confirmations;

e) name-use records, mark-use records, seal records where applicable, logo and badge use records, public description approvals, website description records, unauthorized-use corrections, withdrawal records, takedown records, and clarification records;

f) tax, nonprofit, non-charitable, accounting, financial, audit, review engagement, grant, donation, sponsorship, subscription, fee, cost-recovery, and in-kind contribution records;

g) legal-separateness records distinguishing the Corporation from GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus entities, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, and partners;

h) public authority capacity records where the Corporation’s identity is referenced in public authority contexts;

i) public-safe publication records where the Corporation’s identity is described publicly;

j) repository, Gazette, notice-stream, authenticity, signature, hash, integrity, tamper-evident, or certification records where used; and

k) correction, clarification, withdrawal, retraction, takedown, supersession, archive, sealing, and successor-access records relating to legal identity.

Legal identity records shall be treated as governance-significant records and shall be retained, protected, accessed, corrected, archived, sealed, disclosed, or securely disposed of in accordance with applicable law, this Bylaw, confidentiality obligations, privilege requirements, privacy obligations, cybersecurity obligations, public authority restrictions, public-safe discipline, protected-knowledge controls, and records-retention requirements.

No legal identity record shall be silently edited. Any correction shall preserve historical traceability, identify the correction authority, state the correction reason, preserve the prior version where required, and identify the current authoritative record.

24.10 Continuity Records, Supersession Records, and Institutional Memory Records. The Corporation shall maintain continuity records, supersession records, and institutional memory records sufficient to preserve its legal, governance, technical, evidentiary, semantic, publication, public authority, Nexus-interface, and public-good stewardship continuity over time.

Continuity records shall include, as applicable:

a) records of establishment, registered office, corporate seat, governing law, Board composition, officer appointments, member structure where applicable, committee and council establishment, delegations, policies, registers, repositories, Gazette or notice-stream architecture, and core governance systems;

b) records of programs, projects, partnerships, platforms, repositories, datasets, technical baselines, software assets, evidence systems, observability environments, ontologies, controlled vocabularies, public-good assets, publications, controlled rooms, data rooms, evidence rooms, public authority rooms, capital-reader rooms, and Nexus interfaces;

c) records of continuity across leadership transitions, program transitions, repository migrations, technical migrations, funding changes, sponsor changes, provider changes, host changes, public authority changes, jurisdictional changes, localizations, software forks, dataset retirements, technical baseline supersessions, publication supersessions, and Nexus interface changes;

d) records of corrections, clarifications, errata, supersessions, suspensions, downgrades, withdrawals, retractions, reinstatements, retirements, archives, seals, secure disposals, deletions, and successor-access decisions;

e) records of divergence logs, compatibility notes, cross-entity mismatch detection, reconciliation, interface closeout, public description correction, public authority correction, finance-boundary correction, certification-boundary correction, procurement-neutrality correction, and sponsor or provider overclaim correction; and

f) records of institutional lessons, after-action reviews, research integrity corrections, evidence challenge outcomes, method retirements, software vulnerability lessons, AI incident lessons, cyber incident lessons, public-safe publication corrections, public authority boundary corrections, finance-boundary corrections, certification-boundary corrections, procurement-neutrality corrections, sponsor or provider capture corrections, safeguards corrections, and protected-knowledge corrections.

Supersession records shall identify:

a) the superseded record, asset, instrument, method, ontology, technical baseline, software release, dataset, model, benchmark, dashboard, publication, public-safe summary, interface, policy, decision, or public claim;

b) the superseding record or asset;

c) the reason for supersession;

d) the authority approving supersession;

e) the effective date;

f) the affected repositories, registers, rooms, publications, public authority materials, sponsor materials, provider materials, Nexus interfaces, downstream dependencies, and public descriptions;

g) required notice, correction, withdrawal, retraction, archive, access restriction, public-safe clarification, or controlled clarification;

h) access and publication classification after supersession; and

i) closeout requirements.

Institutional memory records shall be maintained so that future directors, officers, personnel, committees, councils, advisors, fellows, contributors, public authority participants, sponsors, providers, hosts, partners, and Nexus interface actors may understand the Corporation’s origins, legal identity, mission lock, public-benefit purpose, non-execution boundary, role separation, public-good stewardship duties, prior decisions, known risks, correction history, unresolved divergences, retired approaches, and reasons for institutional design choices.

Institutional memory shall not be used to perpetuate error, founder preference, informal custom, unsupported narrative, sponsor influence, provider influence, public authority confusion, finance-readiness overclaim, certification overclaim, procurement overclaim, obsolete technical assumptions, or uncorrected records. Institutional memory shall be disciplined by records, evidence, methods, review, lawful authority, public-safe publication, and correctionability.

This Section shall be interpreted as the Corporation’s legal-identity and continuity lock. It confirms that The Global Centre for Risk and Innovation - Canada is a distinct, continuing Canadian public-benefit legal person whose existence, records, evidence artifacts, methods, ontologies, technical baselines, software assets, publications, and public-good stewardship duties remain continuous, traceable, correctionable, non-executing, and legally bounded across changes in people, programs, funders, partners, technologies, repositories, jurisdictions, and Nexus interfaces.

25.1 Separate Legal Personality. The Corporation shall have and maintain separate legal personality in accordance with applicable law, the Articles, this Bylaw, and its lawful corporate status as a Canadian nonprofit corporation without share capital. The Corporation may act in its own name, hold rights and property in its own name, incur obligations in its own name, sue and be sued in its own name, contract in its own name, maintain records in its own name, and exercise lawful corporate powers in furtherance of its public-benefit purposes, subject always to the limits imposed by applicable law, the Articles, this Bylaw, Board authority, any required member approval, and the Corporation’s non-executing, non-distributing, public-good character.

The Corporation’s legal personality shall not be shared with, transferred to, merged into, or impliedly exercised by any director, officer, member where applicable, participant, supporter, subscriber, donor, sponsor, funder, provider, host, contractor, advisor, fellow, employee, volunteer, committee, council, working group, public authority participant, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Observatory, Nexus Standards, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortium, National Nexus Consortium, National Working Group, National Consortium Company, Project SPV, qualified enterprise provider, university, laboratory, community body, civil society body, media actor, or partner.

The Corporation’s legal personality shall be exercised only through lawful corporate acts, competent authority, proper delegation, accurate records, and compliance with the validity-by-record, correctionability, non-execution, public-good stack, and legal-separateness rules of this Bylaw.

25.2 Capacity to Contract. The Corporation shall have capacity to enter into contracts, memoranda of understanding, cooperation instruments, grant agreements, donation agreements, sponsorship agreements, subscription agreements, service agreements, cost-recovery arrangements, in-kind contribution agreements, employment agreements, contractor agreements, consultant agreements, fellowship agreements, advisor agreements, research collaboration agreements, university and laboratory agreements, host agreements, provider agreements, vendor agreements, software contribution agreements, data-sharing agreements, controlled-room agreements, public authority protocols, publication agreements, repository agreements, licensing agreements, confidentiality agreements, indemnity agreements, insurance agreements, and Nexus interface agreements, where such instruments are lawful, properly authorized, recorded, and consistent with the Corporation’s purposes and limits.

The capacity to contract shall be exercised only where the contract:

a) advances or supports the Corporation’s public-benefit purpose, evidence function, methods function, observability function, ontology function, technical truth function, public-good R&D function, public-good software function, open technical baseline function, public authority learning function, public-safe publication function, or Nexus-compatible public-good coordination function;

b) preserves the Corporation’s nonprofit, non-share, non-distributing, non-executing, non-charitable posture unless lawfully changed;

c) preserves legal separateness from GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus entities, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, and partners;

d) does not create agency, partnership, joint venture, alter ego status, shared treasury, shared employer, shared liability, public authority delegation, certification authority, recognition authority, finance-readiness authority, procurement authority, emergency-command authority, public-warning authority, or enterprise execution authority unless separately, lawfully, expressly, and narrowly authorized;

e) includes appropriate non-execution, no-reliance, no-endorsement, no-agency, role-separation, data, AI, cyber, privacy, confidentiality, IP, sanctions, export-control, competition, public authority, publication, claims-discipline, correction, and termination controls where applicable; and

f) is approved under the applicable authority matrix, reserved-matter rule, conflict process, financial control, and records procedure.

No contract shall be used to outsource the Corporation’s mission lock, surrender its correction authority, sell research conclusions, confer sponsor control, grant provider preference, purchase governance influence, create public authority access for money, imply finance-readiness, imply certification, imply procurement advantage, or bind the Corporation to prohibited functions.

25.3 Capacity to Acquire, Hold, Manage, License, Protect, Transfer, and Dispose of Property. The Corporation shall have capacity, subject to applicable law, the Articles, this Bylaw, and competent approval, to acquire, hold, manage, use, license, protect, transfer, assign, encumber where lawful, dispose of, retire, archive, or otherwise deal with property in furtherance of its purposes.

Property may include:

a) real property, leasehold interests, office facilities, laboratory space, event space, controlled-room facilities, equipment, hardware, sensors, telecommunications equipment, compute equipment, edge systems, servers, storage systems, devices, and other physical assets;

b) cash, grants, donations, sponsorships, subscriptions, fees, cost-recovery payments, restricted funds, unrestricted funds, receivables, reimbursements, insurance proceeds, and other lawful financial assets;

c) intellectual property, copyright, database rights, software, source code, documentation, schemas, APIs, SDKs, dashboards, technical libraries, test harnesses, model cards, dataset cards, system cards, benchmark cards, public-good software, open technical baselines, reference architectures, methods, ontologies, controlled vocabularies, taxonomies, data dictionaries, marks, logos, badges, designs, publications, visual materials, training materials, and other intangible assets;

d) data, datasets, metadata, evidence artifacts, evidence packs, assurance packs, source-lineage records, observability records, telemetry records, AI governance records, compute workload records, inference records, model records, and research records, subject to applicable data, privacy, AI, cyber, confidentiality, public authority, protected-knowledge, and safeguards restrictions; and

e) licenses, permissions, rights of use, access rights, repository rights, publication rights, contribution rights, and contractual rights.

The Corporation shall manage property as public-benefit property. No property shall be used for improper private benefit, private inurement, sponsor control, provider capture, public authority confusion, finance-readiness overclaim, certification implication, procurement advantage, or execution drift.

Any transfer, license, disposal, retirement, archive, open release, controlled release, or restriction of property of material significance shall be reviewed for public-benefit alignment, mission lock, non-distribution, non-execution, IP stewardship, public-good asset protection, anti-enclosure, data / AI / cyber risk, sanctions and export-control risk, public authority sensitivity, protected knowledge, downstream dependency, and correctionability.

25.4 Capacity to Receive Grants, Donations, Sponsorships, Subscriptions, In-Kind Contributions, Service Fees, Cost-Recovery Fees, and Other Lawful Support. The Corporation shall have capacity to receive grants, donations, sponsorships, subscriptions, supporter dues, membership fees where applicable, program fees, training fees, cost-recovery fees, service fees, restricted funds, unrestricted funds, in-kind contributions, equipment support, facility support, cloud support, compute support, software support, data contributions, technical contributions, professional services, fellowships support, research support, public-good infrastructure support, and other lawful support consistent with its purposes.

Support may be accepted only where it:

a) is lawful and properly recorded;

b) supports the Corporation’s public-benefit and public-good stewardship purposes;

c) does not create private inurement, improper private benefit, excess benefit, hidden extraction, disguised commercial participation, pay-to-play influence, access-for-money, or control-for-support;

d) does not purchase or influence research findings, evidence classifications, methods, technical baselines, publications, public authority access, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, Nexus-compatible claims, public-safe reports, correction decisions, or governance decisions;

e) does not create preferred provider status, sponsor control, donor control, funder control, host control, public authority endorsement, finance-readiness implication, certification implication, procurement advantage, recognition implication, or maturity implication;

f) is screened for conflicts, related-party concerns, sanctions, export-control, competition, reputational, public authority, data, AI, cyber, privacy, protected-knowledge, safeguards, and mission-drift risks where applicable; and

g) is subject to written terms, accounting records, restricted-fund records where applicable, acknowledgment controls, public-reference controls, and correction rights.

The Corporation shall not issue charitable tax receipts, represent itself as a registered charity, or imply charitable status unless such status is lawfully obtained and recorded. No payment, contribution, sponsorship, subscription, grant, donation, fee, or in-kind support shall confer governance control, voting rights, certification, recognition, finance-readiness, public authority access, procurement advantage, provider preference, or authority to bind the Corporation unless such right or status is separately lawful, expressly authorized, and recorded.

25.5 Capacity to Employ, Engage, Contract With, Appoint, or Retain Personnel, Fellows, Advisors, Contractors, Consultants, Researchers, Developers, Technical Contributors, and Service Providers. The Corporation shall have capacity to employ, engage, contract with, appoint, or retain personnel necessary or appropriate to carry out its purposes, including officers, employees, contractors, consultants, researchers, developers, technical contributors, maintainers, fellows, visiting fellows, technical fellows, Academy fellows, advisors, committee members, council participants, working group participants, volunteers, seconded personnel, service providers, professional advisers, auditors, legal counsel, accountants, security providers, data processors, cloud providers, AI providers, software providers, event providers, and other lawful contributors.

All such relationships shall be governed by written or otherwise legally sufficient terms appropriate to the role, including, where applicable:

a) role description, authority scope, reporting line, term, compensation or reimbursement terms, conflict obligations, confidentiality obligations, public statement limits, and offboarding obligations;

b) IP, moral rights where applicable, work product, contribution, licensing, attribution, repository, publication, and technical asset terms;

c) data, privacy, AI-use, cybersecurity, controlled-room, clean-room, no-download-room, public authority, protected knowledge, research ethics, safety, and safeguards obligations;

d) sanctions, export-control, controlled-technology, competition, anti-corruption, harassment, retaliation, accessibility, and human rights controls where applicable;

e) no apparent authority, no authority to bind, no public authority delegation, no finance-readiness authority, no certification authority, no procurement authority, no recognition authority, no protocol authority, and no execution authority clauses where appropriate; and

f) records, access, return, deletion, survival, correction, and cooperation obligations.

No title, expertise, authorship, technical access, repository permission, room access, sponsor relationship, public authority contact, speaking role, seniority, public prominence, or operational proximity shall create authority to bind the Corporation unless properly delegated and recorded.

25.6 Capacity to Establish Programs, Research Activities, Labs, Repositories, Publications, Technical Assets, Councils, Committees, Working Groups, Controlled Rooms, Data Rooms, and Participation Surfaces. The Corporation shall have capacity, subject to applicable law, Board authority, delegation, and this Bylaw, to establish, maintain, modify, suspend, retire, or close programs, research activities, public-benefit R&D activities, laboratories, public-good testbeds, observability environments, evidence systems, methods projects, ontology projects, technical repositories, software repositories, publication streams, public-safe reporting surfaces, dashboards, data rooms, controlled rooms, clean rooms, evidence rooms, public authority rooms, no-download rooms, councils, committees, working groups, advisory bodies, expert panels, peer-review panels, model-review panels, fellowships, Academy activities, Competence Cell activities, and other participation surfaces.

Such structures shall be created and governed only through appropriate records, charters, terms of reference, authority classifications, case IDs, registers, access controls, conflict controls, publication controls, and closeout pathways. Each material structure shall identify:

a) its purpose;

b) its authority source;

c) its public-good or enterprise-stack classification;

d) its owner, custodian, and steward;

e) its membership or participation rules;

f) its access, publication, data, AI, cyber, and security classes;

g) its public authority, finance, certification, procurement, recognition, and execution boundaries;

h) its sponsor, provider, donor, host, and public authority controls;

i) its records, correction, supersession, withdrawal, retirement, archive, and closeout pathway; and

j) its relationship, if any, to GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, and partners.

No program, lab, repository, publication stream, controlled room, data room, committee, council, working group, advisory body, or participation surface shall become a separate legal person, governance organ, public authority, certification body, recognition body, finance-readiness authority, procurement authority, emergency-command body, public-warning body, standards authority, protocol authority, or execution vehicle unless separately and lawfully constituted and expressly recorded. Within the Corporation, such structures shall remain subordinate to the Articles, this Bylaw, Board authority, applicable law, and the Corporation’s mission lock.

25.7 Capacity to Initiate, Defend, Settle, or Participate in Legal Proceedings. The Corporation shall have capacity to initiate, defend, settle, compromise, mediate, arbitrate, intervene in, respond to, or otherwise participate in legal, regulatory, administrative, investigative, compliance, enforcement, dispute-resolution, insurance, contractual, employment, IP, data, privacy, cybersecurity, research integrity, public authority, sanctions, export-control, competition, tax, governance, or other proceedings where lawful and in the Corporation’s interests.

The exercise of litigation or dispute capacity shall be subject to:

a) Board approval for material proceedings, settlements, admissions, waivers, releases, precedent-setting matters, constitutional matters, mission-significant matters, high-risk matters, or matters reserved by policy;

b) legal privilege, confidentiality, public-safe publication, protected-knowledge, data, AI, cyber, privacy, and public authority controls;

c) conflict, recusal, related-party, insurance, indemnification, financial exposure, reputational, mission-lock, and non-execution review;

d) preservation of the Corporation’s legal separateness and Nexus role separation;

e) correction, withdrawal, retraction, takedown, clarification, or public-safe notice where required; and

f) records sufficient to demonstrate authority, decision basis, legal advice where appropriate, settlement rationale, financial exposure, insurance treatment, corrective action, and closeout.

Settlement authority shall not be used to surrender the Corporation’s mission lock, non-execution boundary, correction authority, public-good asset stewardship, legal separateness, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, or records obligations except as lawfully approved by competent authority and consistent with this Bylaw.

25.8 Capacity to Maintain Insurance, Indemnification, Risk Controls, Compliance Systems, and Continuity Systems. The Corporation shall have capacity to obtain, maintain, renew, amend, terminate, and claim under insurance policies and risk-transfer arrangements lawful and appropriate for its operations, including directors’ and officers’ insurance, general liability insurance, cyber insurance, professional liability or errors and omissions insurance where appropriate, employment practices insurance, fiduciary insurance, event insurance, property insurance, crime or fraud coverage, travel insurance, volunteer coverage, controlled-room or data-room risk coverage where available, and other coverage approved by competent authority.

The Corporation shall have capacity to indemnify directors, officers, and other eligible persons to the extent permitted by law, the Articles, this Bylaw, and Board-approved indemnification instruments. Indemnification shall not authorize bad faith, fraud, knowing legal violation, willful misconduct, improper personal benefit, private inurement, misuse of data, cyber misconduct, protected-knowledge breach, sponsor or provider capture, public authority confusion, finance-readiness overclaim, certification overclaim, procurement overclaim, or prohibited execution.

The Corporation shall also have capacity to maintain risk controls, compliance systems, internal controls, incident-response systems, cybersecurity controls, data governance systems, AI governance systems, privacy systems, research integrity systems, public-safe publication systems, sanctions and export-control systems, competition-law controls, records systems, repository systems, continuity systems, backup systems, disaster recovery systems, succession systems, and institutional-memory systems.

Insurance, indemnification, risk, compliance, and continuity systems shall be recorded and periodically reviewed. No insurance coverage or indemnity shall be represented as a guarantee, warranty, certification, finance-readiness determination, public authority approval, or protection against breach of this Bylaw.

25.9 Capacity to Collaborate Internationally Within Lawful Boundaries. The Corporation shall have capacity to collaborate internationally with nonprofit bodies, public-benefit institutions, universities, laboratories, research networks, public authorities, communities, Indigenous and local knowledge holders where lawful and appropriate, civil society bodies, media actors, standards-support bodies, technical communities, open-source communities, providers, sponsors, hosts, funders, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, and other lawful actors.

International collaboration may include evidence sharing, methods development, research collaboration, observability methods, ontology alignment, semantic interoperability, public-good software coordination, open technical baseline development, public authority learning, public-safe publication, training, fellowships, controlled-room work, cross-border localization, Nexus Universe participation, Nexus Observatory support, technical benchmarking, after-action learning, and correction coordination.

International collaboration shall not create supranational status, foreign public authority status, treaty status, regulatory authority, emergency-command authority, public-warning authority, certification authority, recognition authority, finance-readiness authority, procurement authority, shared treasury, shared liability, agency, partnership, joint venture, or enterprise execution authority. It shall be conducted subject to local law, Canadian legal primacy for internal corporate acts, cross-border data controls, privacy controls, AI controls, cyber controls, sanctions and export-control controls, competition controls, public authority capacity controls, protected-knowledge safeguards, and records discipline.

Where international collaboration creates legal, technical, semantic, data, public authority, finance, certification, procurement, sponsor, provider, or role-separation ambiguity, the Corporation shall apply the most protective lawful posture pending review, and may use holds, quarantines, access restrictions, divergence logs, compatibility notes, interface agreements, re-scoping, externalization, or termination.

25.10 Capacity Subject to Articles, This Bylaw, Applicable Law, Public-Benefit Purpose, Non-Distribution, Mission Lock, and Non-Execution Boundary. Every power and capacity of the Corporation shall be subject to applicable law, the Articles, this Bylaw, Board authority, member approval where required, fiduciary duties, corporate records, nonprofit status, non-share character, non-distribution rule, public-benefit purpose, mission lock, anti-capture discipline, public-good stewardship burden, non-execution boundary, public authority boundary, finance-readiness boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, data / AI / cyber controls, research integrity, public-safe publication, protected-knowledge safeguards, validity-by-record, and correctionability.

No corporate power shall be interpreted in isolation. Each power shall be read narrowly where necessary to prevent:

a) private inurement or improper private benefit;

b) sponsor, donor, funder, host, provider, investor, insurer, lender, national company, Project SPV, public authority, or partner capture;

c) role collapse between GCRI Canada, GCRI US, GRF, GRA, Nexus Standards, Nexus entities, consortiums, national companies, Project SPVs, providers, sponsors, hosts, and public authorities;

d) conversion of evidence into recognition;

e) conversion of methods into certification;

f) conversion of technical baselines into procurement requirements;

g) conversion of public authority participation into public authority action;

h) conversion of finance-readiness inputs into finance-readiness determinations;

i) conversion of AI, dashboards, digital twins, DePIN records, AI-RAN signals, blockchain or ledger entries, compute attestations, or proof receipts into final authority; or

j) conversion of stewardship into operation, control, execution, regulation, command, warning, underwriting, lending, rating, brokerage, placement, procurement, certification, or public finance approval.

Where a power can be read in both a lawful public-benefit, non-executing manner and an authority-inflating or execution-facing manner, the lawful public-benefit, non-executing reading shall prevail unless a more specific provision, lawful authority, and competent record require otherwise.

25.11 No Capacity to Exercise Prohibited Functions. The Corporation shall have no capacity, power, authority, mandate, implied function, apparent function, or incidental power to exercise any prohibited function identified in this Bylaw. Without limiting the generality of the foregoing, the Corporation shall not exercise capacity to:

a) act as a public authority, regulator, enforcement body, permitting body, inspection authority, emergency-management body, incident-command body, dispatch authority, evacuation authority, official public-warning body, public health order body, procurement authority, public finance authority, or sovereign body;

b) act as a certification body, accreditation body, standards authority, protocol authority, conformance approval body, maturity-rating body, recognition body, standing body, registry authority, or public-facing legitimacy authority except where a separate lawful program and Board-approved instrument expressly and narrowly authorizes a function within law and this Bylaw;

c) act as an investment adviser, securities dealer, broker, finder, placement agent, underwriter, lender, bank, deposit-taker, payment intermediary, custodian, clearing body, settlement body, insurer, reinsurer, guarantor, rating agency, asset manager, fund, market operator, capital router, investor matcher where regulated, public finance approver, MDB approver, DFI approver, grant approver for public funds, budget approver, or sovereign finance approver;

d) select vendors for public authorities, award public contracts, create procurement preference, create provider preference, mandate providers, create exclusive provider status, or create procurement advantage by participation, sponsorship, compatibility, technical contribution, or publication;

e) bind GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Observatory, Nexus Standards, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, providers, sponsors, hosts, public authorities, or partners unless expressly, lawfully, narrowly, and separately authorized by all affected competent authorities; or

f) conduct enterprise-stack execution, own or operate project assets by default, control Project SPVs, control National Consortium Companies, execute regulated transactions, place capital, underwrite risk, bind insurance, lend money as a lending business, guarantee debt or performance, issue official warnings, command emergency response, or substitute for public authority decisions.

Any act purporting to exercise a prohibited function shall be unauthorized, subject to hold, quarantine, correction, withdrawal, retraction, takedown, re-scoping, externalization, termination, or legal response, and incapable of gaining authority through repetition, funding, urgency, public authority interest, technical integration, sponsor pressure, provider pressure, or public narrative.

25.12 No Implied Expansion of Capacity by Funding, Technology, Urgency, Partnership, Public Authority Participation, Sponsor Pressure, or Institutional Convenience. The Corporation’s capacity shall not expand by implication, custom, practice, urgency, funding availability, sponsor expectation, donor expectation, provider expectation, host expectation, public authority attention, public authority attendance, investor interest, insurer interest, lender interest, national company demand, Project SPV demand, technical opportunity, AI capability, dashboard functionality, blockchain or ledger integration, DePIN record, AI-RAN signal, proof receipt, compute attestation, controlled-room workflow, public narrative, media attention, emergency context, institutional convenience, or desire for speed.

For greater certainty:

a) funding shall not create powers;

b) sponsorship shall not create powers;

c) donation shall not create powers;

d) subscription shall not create powers;

e) public authority participation shall not create powers;

f) provider contribution shall not create powers;

g) technical access shall not create powers;

h) repository permission shall not create powers;

i) event operation shall not create powers;

j) Nexus alignment shall not create powers;

k) public-good urgency shall not create powers;

l) AI capability shall not create powers;

m) dashboard capability shall not create powers;

n) blockchain or ledger capability shall not create powers;

o) DePIN, sensor, AI-RAN, O-RAN, digital twin, geospatial, cyber telemetry, or compute capability shall not create powers; and

p) repeated practice shall not create powers.

Where a proposed act depends on implied authority, the act shall be held pending authority mapping. If authority cannot be identified in applicable law, the Articles, this Bylaw, Board resolution, member approval where required, written delegation, contract, policy, or other competent record, the proposed act shall not proceed.

25.13 Power-Use Records and Authority Records. The Corporation shall maintain records sufficient to demonstrate the source, scope, limits, exercise, review, and correction of its powers and capacities. Power-use and authority records shall include, where applicable:

a) the legal authority for the act;

b) the Article, Bylaw section, policy, Board resolution, member resolution where required, delegation, contract, or other authority source relied upon;

c) the decision authority and approving person or body;

d) the purpose of the act;

e) the public-benefit rationale;

f) the mission-lock analysis;

g) the non-distribution and private-benefit review where applicable;

h) the non-execution analysis;

i) the Nexus role-separation analysis;

j) the public authority boundary review;

k) the finance, insurance, securities, lending, underwriting, rating, capital placement, public finance, certification, procurement, and regulated-perimeter review where applicable;

l) the sponsor, donor, funder, provider, host, national company, Project SPV, investor, insurer, lender, contractor, and related-party review where applicable;

m) the data, AI, cyber, privacy, confidentiality, IP, sanctions, export-control, controlled-technology, competition, accessibility, research ethics, community safeguards, Indigenous / local / territorial knowledge, protected knowledge, and public-safe publication review where applicable;

n) the contract, instrument, publication, technical asset, software release, controlled-room, data-room, public authority interface, or Nexus interface affected;

o) the access, publication, security, data sensitivity, public authority sensitivity, finance sensitivity, and protected-knowledge classifications;

p) the signatures, approvals, consents, recusals, abstentions, notices, filings, repository deposits, Gazette entries, and register entries required;

q) the correction path, supersession path, withdrawal path, retraction path, archive path, and closeout requirements; and

r) the final disposition of the act.

No material exercise of corporate power shall be treated as valid for internal governance purposes unless supported by an authority record sufficient to demonstrate that the Corporation acted within its lawful capacity and within the limits of this Bylaw. Where a power-use record is incomplete, inaccurate, unsupported, overbroad, unsafe, outdated, or inconsistent with the Corporation’s limits, the Corporation shall correct, restrict, ratify where lawful, re-scope, withdraw, terminate, or otherwise remediate the act in accordance with this Bylaw.

This Section shall be interpreted as the Corporation’s capacity-and-limits rule. It confirms that The Global Centre for Risk and Innovation - Canada has the lawful capacities necessary to act as a Canadian public-benefit, non-executing, upstream evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, and technical-baseline steward, while denying any implied capacity to become a public authority, recognition authority, finance-readiness authority, certification authority, procurement authority, regulated intermediary, sponsor-controlled platform, provider-preference mechanism, or enterprise execution vehicle.

Section 26. Registered Office, Corporate Seat, Canadian Jurisdictional Anchor, and International Reach

26.1 Registered Office in Canada. The registered office of The Global Centre for Risk and Innovation - Canada, referred to in this Bylaw as the Corporation or GCRI Canada, shall be situated in Canada at the location designated in the Corporation’s Articles, statutory filings, Board records, or other governing records required or permitted by applicable law.

The registered office shall function as the Corporation’s formal Canadian corporate address for service, statutory notices, corporate filings, official records, registered-office obligations, and such other lawful purposes as may be required under applicable Canadian federal, provincial, territorial, or municipal law. The registered office shall not by itself define the entire geographic scope of the Corporation’s public-benefit work, research activities, technical stewardship, public-good software work, open technical baseline work, public authority learning, public-safe publication, or Nexus-compatible coordination.

The registered office shall be maintained in a manner that preserves:

a) the Corporation’s Canadian legal identity;

b) the Corporation’s legal separateness from GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Observatory, Nexus Standards, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, communities, civil society bodies, media actors, and partners;

c) the integrity of statutory records and official notice channels;

d) the Corporation’s nonprofit, non-share, non-distributing, public-benefit, non-executing character;

e) the Corporation’s mission lock, non-execution boundary, validity-by-record discipline, correctionability, public authority boundary, finance-readiness boundary, certification boundary, procurement neutrality, provider neutrality, and sponsor non-control; and

f) the Corporation’s ability to maintain authoritative governance records in accordance with this Bylaw.

No change in operational address, mailing address, virtual office, hosting site, event venue, data room, controlled room, repository location, cloud region, project site, laboratory site, observatory node, Nexus hub, Nexus cluster, Nexus Universe site, sponsor facility, host facility, university facility, public authority facility, or partner facility shall constitute a change of registered office unless lawfully approved and recorded as such.

26.2 Board Authority to Change Registered Office Where Lawful. The Board may change the Corporation’s registered office where permitted by applicable law, the Articles, this Bylaw, and any required filing, notice, member approval, or statutory process. Any change of registered office shall be treated as a governance-significant act and shall be supported by a written record sufficient to demonstrate lawful authority, decision process, effective date, filing requirements, notice requirements, repository update requirements, public description updates, and continuity of records.

A decision to change the registered office shall include, where applicable:

a) the current registered office;

b) the proposed registered office;

c) the legal authority for the change;

d) confirmation that the change is permitted under the Corporation’s Articles and applicable law;

e) any required director, officer, member, filing, or regulatory approval;

f) assessment of effects on service of process, statutory notices, minute books, corporate records, tax records, registered-office obligations, governance seat discipline, public descriptions, public authority interfaces, contracts, grants, donations, sponsorships, subscriptions, provider agreements, host agreements, repository metadata, and Nexus interface materials;

g) confirmation that the change does not alter the Corporation’s public-benefit purpose, nonprofit character, non-distribution rule, non-execution boundary, Canadian legal identity, or legal separateness;

h) a transition plan for mail, notices, filings, records, statutory books, access credentials, registered agent or office service arrangements where applicable, and public-facing materials;

i) required filings, certificates, confirmations, notices, or repository deposits;

j) correction or clarification actions where prior materials identify an outdated registered office; and

k) a closeout record confirming completion.

No officer, employee, contractor, advisor, fellow, sponsor, donor, funder, host, provider, public authority participant, committee, council, working group, partner, or informal leadership group shall change or represent a change in the Corporation’s registered office without competent authority and official record.

26.3 Canada as Corporate Seat. Canada shall be the Corporation’s corporate seat for purposes of internal corporate governance, legal identity, Board authority, bylaw interpretation, statutory corporate records, governance continuity, and authoritative corporate meaning. The Corporation’s corporate seat shall anchor the Corporation as a Canadian public-benefit, nonprofit, non-share, non-distributing, non-executing institution organized to steward upstream evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical baselines, public authority learning, public-safe publication, and Nexus-compatible public-good coordination.

The Canadian corporate seat shall mean that the Corporation’s internal corporate acts are to be understood, authorized, recorded, and interpreted through the Corporation’s Canadian legal identity, subject to applicable law, the Articles, this Bylaw, Board authority, member approval where required, and official records. The Canadian corporate seat shall not be displaced by:

a) cross-border programs;

b) foreign participants;

c) foreign sponsors, donors, funders, hosts, providers, universities, laboratories, public authorities, communities, or partners;

d) international working groups, councils, committees, controlled rooms, public authority rooms, capital-reader rooms, or Nexus interface rooms;

e) use of cloud infrastructure, repositories, collaboration tools, AI systems, data rooms, dashboards, model registers, or technical systems located outside Canada;

f) participation in Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Universe, Nexus Observatory, Nexus Network, Nexus Grid, Nexus Rails, Nexus Academy, Nexus Competence Cells, National Consortium Companies, or Project SPVs;

g) public-facing use of a global narrative, common Nexus vocabulary, common public-good rail, common visual identity, or common technical architecture; or

h) operational convenience, funding source, public authority interest, sponsor expectation, provider expectation, or emergency context.

The Canadian corporate seat shall not confer Canadian public authority status, sovereign authority, public finance authority, regulatory authority, procurement authority, certification authority, recognition authority, emergency-command authority, public-warning authority, finance-readiness authority, or enterprise execution authority on the Corporation.

26.4 Canada as Primary Governance Jurisdiction. Canada shall be the primary governance jurisdiction for the Corporation’s internal corporate acts. The Corporation’s Board decisions, officer appointments, delegations, bylaws, policies, registers, minute books, member records where applicable, governance instruments, official repository records, official notices, and corporate authority records shall be interpreted through the Corporation’s Canadian legal status and applicable Canadian law.

This primary governance jurisdiction rule shall apply to:

a) adoption, amendment, repeal, supersession, withdrawal, archival, and interpretation of this Bylaw;

b) Board authority, director duties, Board meetings, Board resolutions, Board committees, reserved matters, conflicts, recusals, indemnification, insurance, and Board records;

c) officer appointments, executive authority, delegations, signature authority, spending authority, contracting authority, program authority, publication authority, and authority surfaces;

d) membership or memberless governance structure, member rights where applicable, participation categories, supporter categories, subscription arrangements, and stakeholder participation records;

e) corporate filings, registered office, statutory registers, minute books, annual returns, tax records, financial records, audit or review engagement records, and compliance records;

f) legal separateness from GCRI US, GRF, GRA, Nexus entities, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, and partners;

g) validity-by-record, correctionability, official registers, Gazette or notice-stream discipline, repository discipline, and no-silent-edit rules; and

h) public descriptions of the Corporation’s identity, status, authority, limits, and Nexus role.

Primary governance jurisdiction shall not mean that Canadian law is the only law that may apply to the Corporation’s activities. Where the Corporation acts, collaborates, receives support, processes data, uses technology, publishes materials, hosts rooms, works with public authorities, engages participants, or maintains systems in other jurisdictions, the Corporation shall respect applicable foreign local law, contractual obligations, data sovereignty requirements, community protocols, host requirements, sanctions, export controls, privacy rules, cybersecurity obligations, competition rules, research ethics requirements, public authority boundaries, and other lawful obligations.

26.5 Canada as Legal Anchor for Internal Corporate Acts. Canada shall be the legal anchor for the Corporation’s internal corporate acts, including acts concerning its existence, name, registered office, governance seat, Articles, Bylaw, Board, officers, members where applicable, committees, councils, delegations, records, public-benefit purpose, nonprofit character, non-distribution rule, legal separateness, mission lock, and internal authority.

For purposes of this Section, internal corporate acts shall include:

a) incorporation, continuance, amendment of Articles, amendment of Bylaw, amalgamation, reorganization, wind-up, dissolution, or other structural corporate act;

b) adoption, amendment, repeal, supersession, withdrawal, correction, or archival of governance instruments;

c) appointment, election, removal, resignation, suspension, replacement, or succession of directors, officers, members where applicable, committee members, council members, and other governance-significant roles;

d) approval of annual plans, budgets, major policies, major agreements, restricted funds, sponsorship frameworks, public authority protocols, Nexus interface agreements, and reserved matters;

e) creation, modification, suspension, retirement, or closure of official registers, repositories, Gazette or notice streams, records systems, controlled rooms, data rooms, public authority rooms, and other governance-operating systems;

f) internal conflict, recusal, related-party, independence, fiduciary, indemnification, insurance, risk, compliance, and correction decisions; and

g) authority determinations, power-use records, legal-capacity records, and perimeter decisions under this Bylaw.

No foreign office, foreign host, foreign funder, foreign public authority, foreign consortium, foreign partner, regional body, international participant, Nexus interface, technical repository, on-chain record, AI system, dashboard, digital twin, DePIN record, AI-RAN signal, proof receipt, controlled room, or operational platform shall override the Canadian legal anchor for internal corporate acts.

Where an internal corporate act has cross-border consequences, the Corporation shall record both the Canadian authority basis and the applicable foreign-law, data, public authority, community, contractual, operational, or Nexus-interface considerations.

26.6 Canada as Anchor for Corporate Records, Minute Books, Board Records, Member Records Where Applicable, and Authoritative Governance Instruments. Canada shall serve as the anchor jurisdiction for the Corporation’s corporate records, minute books, Board records, member records where applicable, statutory registers, officer records, committee records, council records, governance instruments, official repository records, Gazette or notice-stream records, adoption records, amendment records, supersession records, correction records, withdrawal records, archival records, and other authoritative governance records.

The Corporation shall maintain or ensure lawful access to such records in accordance with applicable law and this Bylaw. Records may be created, stored, mirrored, backed up, encrypted, sealed, archived, or made accessible through digital systems, cloud environments, repositories, ledgers, record-management platforms, data rooms, or controlled rooms, provided that such arrangements preserve:

a) Canadian legal access and custody requirements;

b) authenticity, integrity, completeness, versioning, audit trail, and chain-of-custody where required;

c) record ownership, custodian, steward, authority surface, publication class, access class, data sensitivity class, security class, public authority sensitivity class, finance sensitivity class, and protected-knowledge classification;

d) confidentiality, privilege, privacy, cybersecurity, data residency, data sovereignty, cross-border transfer, sanctions, export-control, research ethics, community safeguards, Indigenous / local / territorial knowledge, and protected-knowledge controls where applicable;

e) no-silent-edit discipline, historical traceability, correctionability, supersession, withdrawal, retraction, retirement, archival, legal hold, secure disposal, and successor-access rules;

f) continuity during repository failure, cloud-provider change, cyber incident, staff transition, host transition, sponsor withdrawal, public authority change, or Nexus interface change; and

g) legal separateness from other GCRI, GRF, GRA, Nexus, consortium, national company, Project SPV, provider, sponsor, host, or partner records unless interoperable or shared records are lawfully established and clearly classified.

Authoritative governance instruments shall not be displaced by unofficial copies, summaries, extracts, slide decks, translations, redlines, working drafts, email attachments, chat posts, repository comments, dashboards, AI-generated summaries, visual materials, public statements, media descriptions, event materials, or operational practice.

26.7 International Activities Permitted Within Lawful Scope. The Corporation may conduct, support, participate in, or coordinate international activities where such activities are lawful, properly authorized, recorded, public-benefit aligned, non-executing, and consistent with the Articles, this Bylaw, Canadian legal primacy for internal corporate acts, local law, and applicable cross-border obligations.

International activities may include:

a) research collaboration;

b) evidence-methods development;

c) observability methods and Nexus Observatory support;

d) ontology, controlled vocabulary, schema, taxonomy, data dictionary, and semantic interoperability work;

e) public-good software development, open technical baseline development, reference architecture work, APIs, SDKs, dashboards, test harnesses, model cards, dataset cards, system cards, benchmark cards, and technical libraries;

f) Nexus Truth Engine methods, verifiable compute methods, verifiable intelligence methods, AI governance methods, model governance methods, inference-record methods, compute workload-record methods, and secure computing methods;

g) public authority learning, evidence literacy, technical literacy, AI literacy, cyber literacy, observatory literacy, and public-safe publication literacy;

h) controlled-room, clean-room, evidence-room, data-room, public authority room, or no-download-room activities;

i) Nexus Universe build, test, benchmark, Academy, after-action, correction, and public-safe learning activities;

j) Nexus Network, Nexus Observatory, Nexus Grid, Nexus Rails, Nexus Standards, Nexus Academy, Nexus Competence Cell, Global Nexus Consortium, Regional Nexus Consortium, National Nexus Consortium, National Working Group, National Consortium Company, and Project SPV interface support where lawful and non-executing;

k) community, Indigenous, local, territorial, environmental, cultural, and protected-knowledge safeguards work where lawful, appropriate, and consent-aligned;

l) publications, public-safe summaries, controlled annexes, technical notes, methods notes, evidence notes, research outputs, visual materials, and learning materials;

m) fellowships, visiting researcher arrangements, technical contributor arrangements, open-source contribution arrangements, and capacity-formation activities; and

n) correction, supersession, divergence logging, compatibility notes, and cross-border interface reconciliation.

International activities shall not convert the Corporation into a foreign corporation for internal governance purposes unless lawfully registered or recognized as such, nor shall they create foreign public authority status, treaty status, sovereign authority, public finance authority, regulatory authority, certification authority, recognition authority, finance-readiness authority, procurement authority, emergency-command authority, public-warning authority, provider-selection authority, investment authority, insurance authority, lending authority, underwriting authority, rating authority, or enterprise execution authority.

26.8 No Supranational Status by International Reach. The Corporation’s international reach, global partnerships, Nexus alignment, participation in global-to-regional-to-national architectures, collaboration with public authorities, involvement in cross-border public-good systems, use of common rail infrastructure, operation of international controlled rooms, participation in Nexus Universe, support for Nexus Observatory, or contribution to Nexus Network shall not create supranational status.

The Corporation shall not represent itself, and no participant shall represent the Corporation, as:

a) a treaty body;

b) an intergovernmental organization;

c) a multilateral development bank;

d) a development finance institution;

e) a sovereign institution;

f) a United Nations body;

g) a public international organization;

h) a public authority;

i) a regulator;

j) a public finance authority;

k) a sovereign standards body;

l) a global certification authority;

m) a global recognition authority;

n) a global emergency-command authority;

o) a global public-warning authority; or

p) a global execution platform,

unless such status is separately, lawfully, expressly, and formally created under applicable law and adopted through the Corporation’s competent authority, which shall not be presumed from collaboration, participation, public authority attendance, public-benefit language, international use, or Nexus architecture.

Any public description, report, deck, website, media statement, controlled-room material, public authority material, sponsor material, provider material, capital-reader material, procurement-facing material, or Nexus interface material that implies supranational status shall be corrected, clarified, withdrawn, restricted, reissued, or subject to takedown as appropriate.

26.9 No Foreign Public Authority Status by Collaboration. The Corporation’s collaboration with a foreign public authority, regulator, ministry, agency, municipality, public infrastructure operator, public university, public laboratory, public finance institution, emergency-management organization, health authority, utility, port authority, telecom authority, energy authority, water authority, food authority, cyber authority, standards body, Indigenous government, community authority, or other public or quasi-public body shall not make the Corporation a foreign public authority, delegate of a foreign public authority, agent of a foreign public authority, substitute for a foreign public authority, public-private partnership by implication, or holder of foreign public powers.

Foreign public authority collaboration may occur only within a capacity classification and record that identifies, where applicable:

a) the public authority entity;

b) the public authority participant’s capacity;

c) whether participation is official, observer, regulator-listening, public finance reader, emergency-management participant, public infrastructure operator, technical participant, learning participant, or another recorded class;

d) the legal basis or participation basis;

e) the purpose and limits of the collaboration;

f) the data, AI, cyber, privacy, confidentiality, public-safe publication, protected-knowledge, and safeguards controls;

g) any restrictions on public references, logos, titles, quotes, photographs, attendance descriptions, and public authority statements;

h) whether the Corporation is providing evidence, methods, observability, ontology, technical baselines, public-good software, public authority learning, public-safe publication, or other non-executing support;

i) confirmation that the Corporation is not issuing public warnings, orders, permits, approvals, procurement decisions, public finance decisions, certification decisions, recognition decisions, legal compliance decisions, funding decisions, emergency commands, or regulated determinations; and

j) correction and notice pathways.

No public authority participation, attendance, review, contribution, data sharing, co-publication, facility hosting, funding, procurement interest, or controlled-room access shall be used to imply endorsement, approval, delegation, public authority status, sovereign backing, finance-readiness, certification, procurement advantage, recognition, or public legitimacy beyond the record.

26.10 No Extraterritorial Regulatory or Sovereign Claim. The Corporation shall not claim, imply, exercise, or permit others to claim, imply, or exercise on its behalf any extraterritorial regulatory, sovereign, public authority, emergency-command, public-warning, public finance, procurement, certification, recognition, standards, protocol, enforcement, inspection, permit, compliance-approval, legal-equivalence, finance-readiness, insurance-readiness, investment, lending, underwriting, rating, or execution power.

The Corporation may develop evidence, methods, ontologies, observability systems, public-good software, open technical baselines, technical notes, public-safe summaries, controlled annexes, reference architectures, dashboards, test harnesses, schemas, data tools, and learning materials for use across jurisdictions, but such materials shall not:

a) override local law;

b) bind public authorities;

c) replace public authority decisions;

d) create legal compliance approval;

e) create safe harbor;

f) create procurement requirements;

g) create certification by default;

h) create recognition by default;

i) create finance-readiness determinations;

j) create insurance-readiness determinations;

k) create investment recommendations;

l) create public warning;

m) create emergency command;

n) create provider preference; or

o) create enterprise execution authority.

Where public-good materials are used outside Canada, the Corporation shall ensure that appropriate limitation language, localization notes, compatibility notes, divergence logs, access controls, translation controls, public-safe classification, public authority capacity records, and correction paths are used where needed.

26.11 Respect for Foreign Local Law, Public Authorities, Data Sovereignty, Community Protocols, and Host Requirements. Where the Corporation conducts or supports activities outside Canada, or where its activities involve foreign participants, foreign data, foreign systems, foreign public authorities, foreign communities, foreign hosts, foreign providers, foreign sponsors, foreign laboratories, foreign universities, foreign infrastructure, foreign controlled rooms, or foreign Nexus interfaces, the Corporation shall respect applicable foreign local law, public authority structures, data sovereignty requirements, community protocols, host requirements, contractual obligations, and safeguards.

Such respect shall include, where applicable:

a) compliance with local corporate registration, qualification, tax, employment, contractor, volunteer, grant, donation, sponsorship, procurement, public authority, privacy, data protection, AI, cybersecurity, telecommunications, critical infrastructure, research ethics, health, safety, environmental, sanctions, export-control, import-control, and controlled-technology requirements;

b) appropriate treatment of sovereign data, Indigenous data, local data, territorial data, community data, health-sensitive data, environmental data, infrastructure-sensitive data, cyber-sensitive data, commercially sensitive data, rights-bearing data, and protected knowledge;

c) consent, non-consent, attribution, withdrawal, correction, community review, protected participation, non-retaliation, and do-no-harm pathways where appropriate;

d) respect for public authority decision lanes and avoidance of public authority substitution;

e) respect for host facility rules, security rules, data rules, safety rules, publication rules, access rules, and community rules;

f) cross-border data transfer review, localization review, compute-to-data review, secure computing review, and access-control review;

g) sanctions, export-control, controlled-technology, restricted-party, and dual-use review;

h) competition-law and market-conduct controls, including clean-room or clean-team structures where appropriate;

i) controlled-room, evidence-room, data-room, public authority room, capital-reader room, and no-download-room restrictions where needed;

j) public-safe publication review, redaction, delayed publication, controlled release, or non-public treatment where required; and

k) records sufficient to show authority, compliance, classification, safeguards, review, and correction.

Respect for foreign local law shall not permit weakening of the Corporation’s mission lock, public-benefit purpose, non-distribution rule, legal separateness, non-execution boundary, records discipline, controlled vocabulary, public authority boundary, finance-readiness boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, data / AI / cyber controls, research integrity, protected-knowledge safeguards, validity-by-record, or correctionability. If foreign local requirements or host requirements conflict with such core protections, the Corporation shall escalate, hold, quarantine, narrow, compartmentalize, localize, route through compliant structures, decline, suspend, or terminate the activity as appropriate.

26.12 Canadian Seat and Cross-Border Conflict Management Records. The Corporation shall maintain Canadian seat and cross-border conflict management records sufficient to demonstrate its registered office, corporate seat, Canadian governance jurisdiction, legal anchor for internal corporate acts, records custody, international activities, foreign local-law review, data sovereignty review, public authority capacity classification, community and protected-knowledge safeguards, host requirements, and conflict-of-law handling.

Such records shall include, where applicable:

a) registered office records;

b) corporate seat records;

c) statutory filings and confirmations;

d) minute book and corporate register custody records;

e) Board and officer authority records;

f) Canadian legal basis records for internal corporate acts;

g) cross-border activity records;

h) foreign local-law review records;

i) foreign registration, qualification, tax, employment, contractor, research ethics, privacy, data protection, AI, cybersecurity, telecommunications, critical infrastructure, sanctions, export-control, and controlled-technology review records;

j) data residency, data sovereignty, localization, compute-to-data, secure computing, cross-border transfer, and data-processing records;

k) public authority capacity records, public authority reference approvals, and public authority non-endorsement records;

l) host requirement records, facility access records, security records, safety records, and controlled-room records;

m) community, Indigenous, local, territorial, environmental, cultural, protected-knowledge, consent, non-consent, attribution, withdrawal, correction, grievance, remedy, and non-retaliation records where applicable;

n) sponsor, donor, funder, provider, host, university, laboratory, partner, national company, Project SPV, consortium, and Nexus interface conflict records;

o) compatibility notes, equivalence notes, divergence logs, localization records, and conflict-of-law escalation records;

p) public-safe publication and controlled-publication records for cross-border outputs;

q) correction, clarification, withdrawal, retraction, takedown, supersession, and archive records; and

r) closeout records.

Where a cross-border conflict arises between Canadian corporate governance requirements, foreign local law, public authority expectations, data sovereignty requirements, host requirements, community protocols, sponsor expectations, provider expectations, Nexus interface requirements, or operational demands, the Corporation shall record the conflict, classify the risk, identify the affected authority surfaces, apply the most protective lawful interim posture, and escalate to competent authority. Pending resolution, the Corporation may hold, stop, quarantine, restrict access, freeze publication, suspend implementation, compartmentalize data, localize processing, re-scope activity, externalize the function to a lawful actor, or terminate the activity.

This Section shall be interpreted as the Corporation’s Canadian-seat and international-reach rule. It confirms that The Global Centre for Risk and Innovation - Canada may act internationally as a Canadian public-benefit, non-executing, upstream evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, and technical-baseline steward, while preserving Canada as the Corporation’s corporate seat, primary governance jurisdiction, legal anchor for internal corporate acts, and authoritative records anchor, and while denying any supranational, foreign public authority, extraterritorial regulatory, sovereign, procurement, certification, recognition, finance-readiness, public-warning, emergency-command, or execution status by international reach.

Section 27. Public-Benefit and Public-Good Stewardship Identity

27.1 Public-Benefit Identity. The Global Centre for Risk and Innovation - Canada, referred to in this Bylaw as the Corporation or GCRI Canada, shall be constituted, governed, interpreted, operated, funded, represented, and corrected as a Canadian public-benefit institution. Its public-benefit identity shall be substantive and operative, not merely descriptive, promotional, aspirational, or reputational.

The Corporation’s public-benefit identity shall mean that the Corporation exists to advance shared institutional, scientific, technical, evidentiary, public-good, and systemic-resilience purposes through upstream stewardship of evidence, methods, observability, ontology, technical truth, public-good research and development, open technology, public-good software, open technical baselines, public authority learning, public-safe publication, and Nexus-compatible public-good coordination.

The Corporation’s public-benefit identity shall apply across all technology, risk, resilience, infrastructure, and public-good domains within its lawful remit, including artificial intelligence, agentic AI, AI-RAN, O-RAN, private wireless, telecommunications, edge compute, sovereign compute, high-performance compute, verifiable compute, verifiable intelligence, blockchain, distributed ledger technology, Web3-relevant systems, DePIN, cyber and cyber-physical systems, robotics, drones, autonomous systems, sensors, Earth observation, satellite, geospatial and remote-sensing systems, digital twins, simulation systems, climate, nature, biodiversity, disaster, wildfire, flood, water, energy, food, health, biosecurity-relevant systems, quantum-adjacent systems, post-quantum-relevant systems, advanced manufacturing, semiconductors, industrial systems, ports, utilities, critical infrastructure, supply chains, and other emerging, exponential, mission-critical, or public-good-relevant technologies designated in accordance with this Bylaw.

The Corporation’s public-benefit identity shall not be reduced to brand, convening power, sponsorship, consulting, advocacy, technology promotion, public relations, event delivery, research publishing alone, software publication alone, commercial enablement alone, project acceleration alone, capital-readiness narrative, public authority proximity, or institutional prestige. The Corporation’s public-benefit identity shall be measured by whether its records, acts, outputs, technical assets, publications, rooms, interfaces, and relationships preserve public-good integrity, evidence discipline, correctionability, openness where lawful, controlled disclosure where necessary, and institutional trust.

27.2 Public-Good Stewardship Burden. The Corporation shall bear a public-good stewardship burden with respect to the assets, methods, evidence systems, records, software, baselines, ontologies, publications, participation surfaces, and Nexus interfaces that it creates, holds, maintains, supports, or authorizes. Public-good stewardship shall impose a higher institutional standard than ordinary operational convenience, sponsor preference, provider preference, transaction speed, event success, publication momentum, public narrative, or short-term funding interest.

The public-good stewardship burden shall require the Corporation to:

a) preserve the public-benefit purpose of its activities and outputs;

b) maintain evidence integrity, method integrity, research integrity, data integrity, software integrity, ontology integrity, and public-safe publication integrity;

c) protect the non-execution boundary and prevent evidence, methods, dashboards, models, digital twins, AI outputs, DePIN records, AI-RAN signals, blockchain or ledger entries, proof receipts, or technical baselines from being misread as authority;

d) preserve the separation between GCRI Canada’s upstream evidence and methods function, The Global Risks Forum (GRF)’s public-good registry, recognition, maturity-records, standing, claims-discipline, stakeholder-formation, public-safe reporting, and public-facing legitimacy function, and The Global Risks Alliance (GRA)’s finance-readiness, capital-readability, investor-literacy, insurance-readiness, diligence-translation, and common-business-interest function;

e) protect public-good assets against enclosure, capture, suppression, misleading reuse, sponsor control, provider control, unauthorized privatization, improper dependency lock-in, and hidden commercial extraction;

f) maintain controlled vocabulary, semantic discipline, versioning, review cycles, correction paths, and no-silent-edit controls;

g) ensure that public authority participation remains capacity-classified, non-controlling, non-delegating, non-endorsement-based, and non-executing;

h) preserve procurement neutrality, provider neutrality, sponsor support-without-control, donor support-without-control, funder support-without-control, and host support-without-control;

i) protect data, AI, cybersecurity, privacy, community, Indigenous, local, territorial, environmental, cultural, health-sensitive, infrastructure-sensitive, cyber-sensitive, commercially sensitive, and protected-knowledge interests;

j) ensure that public-safe publication does not become public warning, emergency command, public authority decision, certification, recognition, finance-readiness determination, procurement approval, rating, underwriting, lending, insurance approval, investment recommendation, or execution instruction; and

k) maintain records sufficient to demonstrate all of the foregoing.

The Corporation shall not treat the public-good stewardship burden as satisfied by general mission statements, informal assurances, public-good branding, event participation, sponsor language, open-source labels, high-level disclaimers, or informal alignment with Nexus architecture. Stewardship shall be demonstrated by recorded governance, recorded evidence, recorded methods, recorded limits, recorded corrections, recorded interfaces, recorded classifications, and recorded accountability.

27.3 Stewardship of Shared Evidence Infrastructure. The Corporation shall steward shared evidence infrastructure as a public-good function. Shared evidence infrastructure shall include the systems, records, methods, classifications, repositories, schemas, registers, rooms, workflows, and artifacts by which data, telemetry, observations, claims, research outputs, model outputs, technical signals, public authority inputs, community inputs, operator inputs, provider system outputs, and other source materials are transformed into evidence records capable of review, challenge, correction, public-safe interpretation, and lawful reuse.

The Corporation’s stewardship of shared evidence infrastructure may include:

a) evidence doctrine, evidence classifications, source-lineage rules, provenance rules, custody rules, reliability rules, confidence-scoring rules, uncertainty rules, limitation disclosure rules, dispute rules, correction rules, and evidence lifecycle rules;

b) evidence registers, assurance packs, evidence packs, public-safe evidence summaries, controlled evidence annexes, observability evidence records, Nexus Docket inputs, Nexus Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, and Nexus Observatory inputs;

c) transformation methods for raw data, telemetry, sensor readings, AI-RAN signals, O-RAN signals, DePIN records, blockchain or ledger records, cyber logs, digital twin outputs, simulation outputs, geospatial data, Earth observation data, public authority inputs, community inputs, operator observations, provider system outputs, research data, derived data, and inferred data;

d) evidence-quality review for completeness, accuracy, timeliness, relevance, reproducibility, calibration, method integrity, source integrity, data integrity, model integrity, public-safe fitness, and fitness for stated purpose;

e) evidence challenge procedures, correction procedures, reclassification procedures, confidence-adjustment procedures, supersession procedures, withdrawal procedures, retraction procedures, archival procedures, and downstream dependency review; and

f) public-safe translation of evidence without converting evidence into final authority, recognition, finance-readiness, certification, procurement approval, public warning, emergency command, or execution instruction.

Shared evidence infrastructure shall be stewarded for common institutional trust and systemic legibility. It shall not be designed, maintained, funded, or represented to privilege a sponsor, provider, host, donor, funder, public authority, investor, insurer, lender, national company, Project SPV, technology vendor, platform, or commercial offering.

27.4 Stewardship of Scientific-Operational Methods. The Corporation shall steward scientific-operational methods as public-good institutional infrastructure. Scientific-operational methods shall include the repeatable, reviewable, versioned, documented, challengeable, and correctionable procedures by which the Corporation supports evidence collection, validation, corroboration, benchmarking, observability, modeling, public-safe interpretation, technical baseline development, and decision-support translation without substituting itself for public authorities, regulated actors, certification bodies, recognition bodies, finance-readiness authorities, procurement authorities, or enterprise execution vehicles.

Scientific-operational methods may include:

a) validation methods;

b) corroboration methods;

c) confidence-scoring methods;

d) uncertainty methods;

e) source-lineage methods;

f) sensor-fusion methods;

g) AI output review methods;

h) agentic AI control methods;

i) AI-RAN and O-RAN signal interpretation methods;

j) DePIN validation methods;

k) blockchain, distributed ledger, proof-receipt, and compute-attestation interpretation methods;

l) digital twin assumption review methods;

m) geospatial, Earth observation, satellite, and remote-sensing evidence methods;

n) cyber evidence and cyber-physical evidence methods;

o) scenario, simulation, resilience, degraded-mode awareness, and mission-critical signal methods;

p) benchmarking, reproducibility, replication, calibration, and peer-review methods;

q) public-safe publication methods; and

r) correction, withdrawal, supersession, retirement, and archival methods.

Each material method shall have an identified owner, custodian, steward, purpose, scope, applicability conditions, exclusion conditions, dependencies, limitations, version identifier, effective date, review cycle, public-safe status, controlled annex status where applicable, correction path, supersession path, withdrawal path, and retirement path.

Scientific-operational methods shall not be treated as immutable, self-executing, self-validating, or authority-conferring. A method may support evidence and public-good technical learning, but it shall not itself confer recognition, standing, maturity status, finance-readiness, insurance-readiness, certification, accreditation, procurement approval, public authority approval, public warning, emergency command, regulated advice, or execution authority.

27.5 Stewardship of Observability Systems and Evidence Environments. The Corporation shall steward observability systems and evidence environments as public-good infrastructure for lawful, public-benefit, method-governed, correctionable understanding of complex systems. Observability stewardship shall include the design, review, support, documentation, and correction of methods by which physical, digital, cyber-physical, human-machine, natural, institutional, infrastructure, and mission-critical systems may be observed, interpreted, and translated into evidence records or public-safe outputs.

The Corporation’s observability stewardship may include methods and evidence environments for:

a) Nexus Observatory nodes, hubs, clusters, hotspots, national dense cores, regional clusters, sensors, edge compute environments, sovereign compute environments, AI-RAN systems, O-RAN systems, DePIN systems, digital twins, cyber telemetry, geospatial systems, Earth observation systems, dashboards, public-safe maps, and degraded-mode awareness surfaces;

b) climate, nature, biodiversity, disaster, wildfire, flood, water, energy, food, health, biosecurity-relevant, telecom, port, utility, logistics, supply-chain, industrial, public infrastructure, cyber, AI, robotics, drone, autonomous system, and critical infrastructure contexts;

c) public authority learning environments, public-safe reporting environments, Academy environments, Nexus Universe test and benchmark environments, controlled rooms, evidence rooms, data rooms, public authority rooms, and no-download rooms;

d) public-good telemetry interpretation, signal reliability review, spoofing and failure review, missing-data handling, stale-data handling, confidence adjustment, and public-safe limitation statements; and

e) observability-to-evidence, observability-to-Docket, observability-to-Grid, observability-to-GRF, observability-to-GRA, observability-to-Nexus Standards, and observability-to-public-safe-publication interfaces.

Observability systems and evidence environments shall not be used or represented as emergency-command systems, official public-warning systems, public authority decision systems, certification systems, recognition systems, finance-readiness systems, procurement systems, rating systems, underwriting systems, investment systems, or execution systems.

The Corporation shall preserve strict distinction between observing, evidencing, learning, modeling, simulating, and publishing public-safe technical information, on the one hand, and commanding, warning, approving, certifying, recognizing, financing, procuring, underwriting, insuring, rating, lending, investing, operating, or executing, on the other hand.

27.6 Stewardship of Ontologies, Schemas, Taxonomies, Data Dictionaries, and Controlled Vocabulary. The Corporation shall steward ontologies, schemas, taxonomies, data dictionaries, and controlled vocabulary as public-good semantic infrastructure. Such semantic infrastructure shall support evidence integrity, interoperability, public-safe claims discipline, machine readability, AI-readable knowledge structures, Nexus-compatible records, public authority learning, technical baseline alignment, and correctionable institutional memory.

The Corporation’s semantic stewardship shall include:

a) controlled terms for evidence, verified, validated, public-safe, recognized, Nexus-compatible, finance-ready, insurance-ready, Docket, Grid, proof receipt, public authority, certification, conformance, maturity, routeability, readiness, observatory, node, hub, cluster, hotspot, dense core, reference implementation, public-good software, open technical baseline, public-good technical asset, public-safe summary, controlled annex, and related terms;

b) risk ontologies, maturity concepts, evidence classifications, technology-family classifications, mission-critical system categories, public authority capacity terms, finance-readiness boundary terms, recognition and standing boundary terms, certification and conformance boundary terms, procurement-boundary terms, data-sensitivity terms, security terms, safeguards terms, and publication classes;

c) machine-readable metadata, schemas, APIs, data dictionaries, data tools, semantic versioning, semantic correction, localization notes, equivalence notes, compatibility notes, and divergence logs;

d) semantic interoperability across GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, qualified enterprise providers, public authorities, universities, laboratories, communities, sponsors, hosts, donors, funders, and partners; and

e) public-safe vocabulary controls to prevent promotional redefinition, sponsor-driven meaning shift, provider-driven meaning shift, public authority confusion, finance-readiness overclaim, recognition overclaim, certification overclaim, procurement overclaim, or technical authority inflation.

No program, publication lead, technology vendor, sponsor, provider, donor, funder, host, partner, public authority participant, council, working group, committee, repository maintainer, AI system, dashboard, model, or informal team shall silently redefine a controlled term. Any material change in semantic infrastructure shall be recorded, classified, reviewed, versioned, and corrected where needed.

27.7 Stewardship of Public-Good Software, Open Technical Baselines, and Reference Architectures. The Corporation shall steward public-good software, open technical baselines, reference architectures, and related technical assets as public-benefit infrastructure. Such assets shall be developed, maintained, released, licensed, secured, reviewed, corrected, superseded, retired, or archived in a manner that supports interoperability, auditability, reusability, portability, lawful public-good adoption, technical learning, evidence integrity, and Nexus-compatible coordination.

The Corporation’s stewardship may include:

a) public-good software repositories;

b) open reference implementations;

c) APIs, SDKs, schemas, data tools, dashboards, test harnesses, model cards, dataset cards, system cards, benchmark cards, gold vectors, negative tests, technical libraries, and public-safe visualization tools;

d) reference architectures for observability systems, evidence infrastructure, verifiable compute, verifiable intelligence, AI governance, cyber governance, public-good software, AI-RAN, O-RAN, DePIN, digital twins, sovereign compute, edge compute, secure computing, data rooms, controlled rooms, public authority learning environments, and Nexus-compatible interfaces;

e) interoperability profiles and conformance-supporting tools, without certification effect by default;

f) secure build records, signing records, provenance records, dependency records, SBOM records, vulnerability records, license records, contribution records, release records, rollback records, deprecation records, retirement records, and archive records; and

g) public-good asset registers, ownership records, stewardship records, contributor records, license records, IP records, anti-enclosure records, and correction records.

Public-good software, open technical baselines, and reference architectures shall not be used or represented as certification, accreditation, compliance approval, legal equivalence, procurement mandate, provider preference, public authority approval, finance-readiness determination, insurance-readiness determination, investment recommendation, emergency command, public warning, or execution instruction by default.

The Corporation shall protect such assets against enclosure, dependency lock-in, sponsor control, provider capture, hidden proprietary conversion, contractual overreach, unauthorized sublicensing, license laundering, security degradation, unreviewed forks, misleading compatibility claims, and false Nexus-compatible claims.

27.8 Stewardship of Technical Memory, Correction Records, and Public-Good Institutional Continuity. The Corporation shall steward technical memory, correction records, and public-good institutional continuity as core public-benefit functions. Technical memory shall include the recorded history of methods, evidence, assumptions, limitations, errors, corrections, supersessions, withdrawn claims, retired approaches, technical baselines, software releases, model records, dataset records, benchmark records, ontology changes, observability methods, public-safe publication decisions, public authority boundary decisions, finance-boundary decisions, sponsor and provider conflict decisions, and Nexus interface decisions.

The Corporation shall maintain technical memory so that future directors, officers, personnel, committees, councils, fellows, advisors, contributors, public authority participants, sponsors, providers, hosts, partners, communities, and Nexus interface actors may understand:

a) why a method was adopted, limited, corrected, superseded, withdrawn, retired, or archived;

b) why an evidence artifact was accepted, rejected, restricted, reclassified, challenged, corrected, superseded, withdrawn, or retired;

c) why a technical baseline, software release, schema, ontology, model, dataset, benchmark, dashboard, or public-safe output was created, changed, limited, deprecated, or retired;

d) what assumptions, limitations, dependencies, uncertainties, confidence levels, failure conditions, and known exclusions were recorded;

e) what public authority, finance-readiness, certification, procurement, provider, sponsor, data, AI, cyber, community, Indigenous, protected-knowledge, and public-safe publication boundaries applied; and

f) what lessons should govern future work.

Correction records shall not be treated as reputational liabilities to be concealed. They shall be treated as institutional assets that preserve trust, accuracy, humility, learning, and correctionability. Technical memory shall not be used to perpetuate obsolete assumptions, founder preferences, sponsor influence, provider influence, uncorrected errors, public authority confusion, finance-readiness overclaims, certification overclaims, procurement overclaims, unsafe practices, or unsupported narratives.

27.9 Public-Good Stewardship as Active Custodianship, Not Passive Observation. Public-good stewardship by the Corporation shall be active custodianship, not passive observation. The Corporation shall not discharge its public-good responsibilities merely by receiving information, attending meetings, publishing materials, hosting repositories, organizing events, maintaining dashboards, convening stakeholders, or allowing others to use its name.

Active custodianship shall require the Corporation to:

a) define the purpose, scope, authority surface, access class, publication class, data sensitivity class, security class, public authority sensitivity class, finance sensitivity class, safeguards status, and correction path for material activities and outputs;

b) apply forms-first intake, case IDs, decision packs, registers, repository discipline, Gazette or notice-stream discipline where applicable, versioning, no-silent-edit rules, authenticity controls, and correction pathways;

c) review evidence, methods, research, software, ontologies, observability outputs, public-safe materials, public authority references, sponsor references, provider references, finance-readiness references, certification references, procurement references, and Nexus-compatible claims before they receive institutional meaning;

d) challenge, correct, withdraw, retract, takedown, supersede, retire, archive, restrict, or reclassify outputs where inaccurate, unsupported, unsafe, outdated, overbroad, misleading, unauthorized, sponsor-influenced, provider-influenced, public authority-confusing, finance-overclaiming, certification-implying, procurement-implying, or role-collapsing;

e) maintain lawful openness where openness is appropriate and controlled protection where openness would create legal, safety, privacy, cybersecurity, infrastructure, public authority, community, Indigenous, protected-knowledge, competition, sanctions, export-control, or other material risk;

f) protect the Corporation’s public-good assets from capture, misuse, enclosure, dependency lock-in, unauthorized commercialization, and public meaning inflation; and

g) preserve role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, communities, civil society bodies, media actors, and partners.

Where the Corporation cannot actively steward an activity, output, asset, interface, publication, room, repository, dataset, model, dashboard, or public claim within lawful and public-benefit limits, it shall not represent that activity or output as within its authoritative public-good stewardship.

27.10 Public Benefit Through Openness, Auditability, Interoperability, Reusability, Correctionability, and Institutional Trust. The Corporation shall pursue public benefit through openness, auditability, interoperability, reusability, correctionability, and institutional trust, subject to lawful restrictions and public-safe controls.

Openness shall mean that, where lawful and appropriate, the Corporation may make public-good methods, public-safe summaries, open technical baselines, public-good software, schemas, APIs, SDKs, data tools, dashboards, reference architectures, educational materials, evidence summaries, technical notes, methods notes, and research outputs available for public-benefit use. Openness shall not require disclosure of confidential, privileged, personal, rights-bearing, community-protected, Indigenous, local, territorial, cultural, health-sensitive, cyber-sensitive, infrastructure-sensitive, commercially sensitive, public authority-sensitive, controlled-technology, export-controlled, security-sensitive, or otherwise protected materials.

Auditability shall mean that material acts, outputs, technical assets, evidence artifacts, methods, publications, software releases, controlled rooms, public authority references, sponsor references, provider references, and Nexus interface claims shall be traceable to authority records, source records, method records, classification records, version records, review records, correction records, and closeout records.

Interoperability shall mean that the Corporation shall support semantic, technical, evidence, record, software, and institutional compatibility across Nexus-compatible public-good systems without creating merger, shared liability, shared treasury, agency, partnership, parent-subsidiary status, protocol authority, standards authority, recognition authority, finance-readiness authority, public authority delegation, certification authority, procurement authority, or execution authority by default.

Reusability shall mean that public-good assets should, where lawful and safe, be structured, licensed, documented, versioned, and maintained so they can be responsibly reused, localized, extended, audited, corrected, and retired without sponsor control, provider lock-in, hidden extraction, or improper dependency.

Correctionability shall mean that the Corporation’s outputs and records shall remain open to challenge, review, correction, clarification, errata, supersession, withdrawal, retraction, downgrade, retirement, archival, and public-safe notice where required.

Institutional trust shall mean that the Corporation shall preserve confidence not by claiming perfection, finality, authority, or supremacy, but by maintaining discipline, transparency within lawful limits, humility about uncertainty, clear role boundaries, correction records, and public-good accountability.

27.11 No Public-Benefit Reduction to Branding, Events, Sponsorship, Advocacy, Consultancy, or Transactional Services. The Corporation’s public-benefit identity shall not be reduced to branding, event production, sponsorship management, fundraising, advocacy, media activity, consulting, advisory services, report writing, training delivery, platform operation, transaction preparation, commercial introductions, project acceleration, capital-readiness storytelling, procurement support, technology promotion, public relations, market-building, or other transactional services.

The Corporation may lawfully convene, publish, train, collaborate, receive support, maintain subscriptions, operate programs, host rooms, develop software, develop methods, support events, participate in Nexus Universe, support public authority learning, and provide technical evidence inputs, but such activities shall remain subordinate to the Corporation’s public-benefit purpose, public-good stewardship burden, non-execution boundary, evidence integrity, methods integrity, research integrity, public-safe publication discipline, public authority boundary, finance-readiness boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, legal separateness, and role-separation duties.

For greater certainty:

a) an event shall not become the Corporation’s purpose;

b) a sponsor shall not become the Corporation’s beneficiary-control point;

c) a provider shall not become the Corporation’s technical authority by contribution;

d) a public authority participant shall not convert public authority learning into public authority action by the Corporation;

e) a report shall not convert evidence into recognition, certification, finance-readiness, procurement approval, public authority approval, or execution instruction;

f) a dashboard shall not become a public warning or emergency command surface;

g) a technical baseline shall not become a procurement mandate;

h) an open-source release shall not become certification;

i) a proof receipt shall not become final authority;

j) a controlled room shall not become a regulated transaction room by institutional convenience;

k) a Nexus-compatible claim shall not become standing, maturity, recognition, finance-readiness, certification, or provider preference without lawful authority and record; and

l) a public-good narrative shall not override this Bylaw.

Where branding, events, sponsorship, advocacy, consultancy, or transactional framing risks mischaracterizing the Corporation’s public-benefit identity, the Corporation shall re-scope, correct, clarify, restrict, withdraw, or terminate the framing.

27.12 Public-Benefit Interpretation in Case of Doubt. Where any provision of this Bylaw, any policy, protocol, schedule, annex, register, form, template, contract, grant agreement, donation agreement, sponsorship agreement, provider agreement, host agreement, public authority protocol, publication, technical baseline, software release, dashboard, room record, public claim, or Nexus interface instrument is capable of more than one interpretation, the interpretation that best preserves the Corporation’s public-benefit identity and public-good stewardship burden shall prevail, unless mandatory applicable law requires otherwise.

In applying this public-benefit interpretation rule, the Corporation shall prefer the interpretation that:

a) preserves nonprofit, non-share, non-distributing, non-charitable posture unless lawfully changed;

b) avoids private inurement and improper private benefit;

c) preserves public-good stewardship, evidence integrity, methods integrity, research integrity, observability integrity, ontology integrity, public-good software integrity, and open technical baseline integrity;

d) preserves non-execution, public authority boundaries, finance-readiness boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, anti-capture, anti-enclosure, and legal separateness;

e) preserves role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, sponsors, hosts, public authorities, universities, laboratories, communities, civil society bodies, media actors, and partners;

f) avoids converting evidence into recognition, methods into certification, observability into public warning, technical baselines into procurement mandates, public authority participation into public authority action, finance-readiness inputs into finance-readiness determinations, AI outputs into final authority, dashboards into authority, digital twins into authority, DePIN records into authority, AI-RAN signals into authority, blockchain or ledger entries into authority, or proof receipts into authority;

g) protects data, AI, cyber, privacy, human rights, accessibility, community safeguards, Indigenous / local / territorial knowledge, protected knowledge, public safety, and public trust;

h) preserves validity-by-record, no-record/no-public-meaning discipline, no-silent-edit discipline, correctionability, and historical traceability; and

i) applies the most restrictive lawful interpretation where ambiguity, role confusion, legal risk, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, sponsor capture, provider capture, data risk, AI risk, cyber risk, community harm, protected-knowledge risk, or public-safety risk exists.

No person shall rely on ambiguity to expand the Corporation’s authority, weaken its boundaries, create a commercial entitlement, create sponsor or provider control, imply public authority approval, imply finance-readiness, imply certification, imply recognition, imply procurement advantage, or avoid correction.

27.13 Public-Good Stewardship Records. The Corporation shall maintain public-good stewardship records sufficient to demonstrate the source, scope, exercise, limits, review, correction, and continuity of its public-benefit identity and public-good stewardship burden.

Public-good stewardship records shall include, where applicable:

a) public-benefit purpose records;

b) mission-lock records;

c) public-good stewardship assessments;

d) evidence stewardship records;

e) methods stewardship records;

f) observability stewardship records;

g) ontology, schema, taxonomy, data dictionary, and controlled vocabulary records;

h) public-good software, open technical baseline, reference architecture, API, SDK, dashboard, test harness, gold vector, negative test, model card, dataset card, system card, benchmark card, technical library, SBOM, dependency, vulnerability, signing, provenance, release, rollback, deprecation, and retirement records;

i) technical memory records;

j) correction records, errata records, supersession records, withdrawal records, retraction records, retirement records, archive records, and downstream dependency records;

k) public-safe publication records;

l) controlled annex records;

m) public authority capacity records, public authority reference records, public authority non-endorsement records, and public authority correction records;

n) finance-readiness boundary records, capital-reader room boundary records, insurance-readiness boundary records, investment boundary records, lending boundary records, underwriting boundary records, rating boundary records, public finance boundary records, and GRA interface records;

o) recognition boundary records, standing boundary records, maturity-record boundary records, claims-discipline records, and GRF interface records;

p) certification boundary records, conformance-supporting tool records, standards-support records, protocol-interface records, proof-receipt boundary records, and Nexus Standards interface records;

q) procurement-neutrality records, provider-neutrality records, sponsor non-control records, donor non-control records, funder non-control records, host non-control records, and enterprise actor boundary records;

r) data, AI, cyber, privacy, secure computing, controlled-room, clean-room, data-room, evidence-room, public authority room, no-download-room, model register, inference record, compute workload, and incident records;

s) community safeguard, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, protected-knowledge, accessibility, consent, non-consent, attribution, withdrawal, grievance, remedy, protected participation, non-retaliation, and do-no-harm records;

t) Nexus interface records with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified enterprise providers, sponsors, hosts, public authorities, universities, laboratories, communities, and partners;

u) compatibility notes, equivalence notes, divergence logs, mismatch records, reconciliation records, localization records, and cross-border stewardship records; and

v) Board, committee, council, officer, secretariat, repository, Gazette, register, case ID, decision pack, classification, review, approval, refusal, hold, stop, quarantine, re-scope, externalization, termination, and closeout records.

No material public-good stewardship act shall be treated as valid for internal governance purposes unless supported by records sufficient to demonstrate lawful authority, public-benefit alignment, non-execution compliance, role-separation compliance, classification, review, and correction path. Where public-good stewardship records are incomplete, inaccurate, unsupported, outdated, unsafe, overbroad, misleading, or inconsistent with this Bylaw, the Corporation shall correct, clarify, restrict, ratify where lawful, re-scope, withdraw, supersede, retire, archive, or otherwise remediate the record or related act.

This Section shall be interpreted as the Corporation’s public-benefit and public-good stewardship identity rule. It confirms that The Global Centre for Risk and Innovation - Canada exists as a Canadian public-benefit, non-executing, upstream evidence, methods, observability, ontology, technical truth, public-good R&D, public-good software, open technical-baseline, and public-safe institutional steward, and that its public-good function is active, recorded, correctionable, non-capturable, legally bounded, and distinct from branding, events, sponsorship, advocacy, consultancy, finance-readiness determination, recognition, certification, procurement, public authority action, or enterprise execution.

Section 28. GCRI Canada as Evidence, Methods, Observability, Ontology, Technical Truth, Open Technology, and Public-Good R&D Steward

28.1 Evidence Stewardship Function. The Global Centre for Risk and Innovation - Canada, referred to in this Bylaw as the Corporation or GCRI Canada, shall serve as an upstream evidence steward within its Canadian public-benefit, nonprofit, non-share, non-distributing, non-executing, public-good institutional mandate. Evidence stewardship shall be a core institutional function of the Corporation and shall be exercised for the purpose of developing, maintaining, reviewing, improving, challenging, correcting, and preserving shared evidence infrastructure across systemic risk, resilience, infrastructure, public authority learning, exponential technology, public-good R&D, observability, and Nexus-compatible coordination contexts.

The Corporation’s evidence stewardship function shall include, without limitation, the authority and duty, within lawful and non-executing boundaries, to develop, maintain, support, and correct:

a) evidence doctrine, evidence classifications, evidence-quality criteria, evidence-intake methods, evidence-chain rules, source-lineage requirements, provenance requirements, custody requirements, permission requirements, confidence-scoring rules, uncertainty rules, limitation-disclosure rules, challenge rules, correction rules, supersession rules, withdrawal rules, retraction rules, archival rules, and public-safe evidence publication methods;

b) evidence records, evidence registers, assurance packs, evidence packs, public-safe evidence summaries, controlled evidence annexes, decision-support evidence inputs, Nexus Docket inputs, Nexus Grid inputs, Nexus Observatory inputs, Nexus Standards inputs, The Global Risks Forum (GRF) inputs, The Global Risks Alliance (GRA) inputs, and other Nexus-compatible evidence artifacts;

c) methods for converting raw data, telemetry, sensor outputs, AI-RAN signals, O-RAN signals, DePIN records, blockchain or distributed ledger records, cyber logs, model outputs, digital twin outputs, simulation outputs, geospatial data, Earth observation data, public authority inputs, community inputs, operator observations, provider system outputs, research data, derived data, and inferred data into evidence records capable of review and correction;

d) evidence review processes for completeness, accuracy, timeliness, relevance, reproducibility, calibration, method integrity, source integrity, data integrity, model integrity, public-safe fitness, and fitness for stated purpose; and

e) evidence challenge, dispute, correction, reclassification, confidence adjustment, dependency review, downstream notice, and institutional learning processes.

The Corporation shall distinguish evidence from raw data, opinion, advocacy, branding, sponsorship claims, provider claims, marketing claims, public authority decisions, recognition, maturity status, finance-readiness, insurance-readiness, certification, procurement approval, public warning, emergency command, regulated advice, and execution instruction.

No evidence artifact, evidence record, assurance pack, evidence pack, public-safe evidence summary, controlled evidence annex, dashboard evidence layer, observatory output, proof receipt, compute receipt, AI output, AI-RAN signal, DePIN record, blockchain entry, ledger entry, model output, or technical note shall be represented as final authority merely because it is created, reviewed, hosted, cited, published, or supported by the Corporation.

28.2 Methods Stewardship Function. The Corporation shall serve as a methods steward for scientific-operational, evidence, observability, ontology, technical, public-good software, public-safe publication, and Nexus-compatible coordination methods. Methods stewardship shall mean the documented, reviewable, versioned, challengeable, reproducible where appropriate, and correctionable development and maintenance of procedures by which the Corporation supports evidence integrity, technical learning, public authority literacy, public-good R&D, open technical baselines, and lawful decision-support translation without decision substitution.

The Corporation’s methods stewardship function may include:

a) validation methods;

b) corroboration methods;

c) source-lineage methods;

d) provenance methods;

e) confidence-scoring methods;

f) uncertainty methods;

g) calibration methods;

h) sensor-fusion methods;

i) AI output review methods;

j) agentic AI control methods;

k) AI-RAN and O-RAN signal interpretation methods;

l) DePIN validation methods;

m) blockchain, distributed ledger, proof-receipt, and compute-attestation interpretation methods;

n) cyber evidence methods;

o) cyber-physical evidence methods;

p) geospatial, satellite, Earth observation, and remote-sensing evidence methods;

q) digital twin assumption review methods;

r) scenario, simulation, resilience, degraded-mode awareness, and mission-critical signal methods;

s) benchmarking, reproducibility, replication, peer-review, model-review, and evaluation methods;

t) public-safe publication methods; and

u) correction, withdrawal, retraction, supersession, retirement, archival, and downstream dependency management methods.

Each material method shall identify its purpose, scope, owner, custodian, steward, authority surface, version identifier, effective date, applicability conditions, exclusion conditions, dependencies, limitations, public-safe status, controlled-annex status where applicable, review cycle, correction path, supersession path, withdrawal path, and retirement path.

Methods shall remain support infrastructure. No method shall, by adoption, publication, use, citation, technical sophistication, sponsor support, provider contribution, public authority participation, Nexus compatibility, software implementation, dashboard integration, or repeated application, become recognition, finance-readiness, certification, procurement approval, public authority approval, legal compliance approval, professional advice, emergency command, public warning, or enterprise execution authority.

28.3 Observability Stewardship Function. The Corporation shall serve as an observability steward for public-benefit, non-executing, evidence-generating, method-governed, public-safe, and correctionable observability systems and evidence environments. Observability stewardship shall include the design, review, documentation, support, classification, interpretation, limitation, and correction of methods by which physical, digital, cyber-physical, environmental, social, institutional, infrastructure, and mission-critical systems may be observed and translated into evidence records or public-safe outputs.

The Corporation’s observability stewardship function may extend to:

a) Nexus Observatory methods;

b) observatory node methods;

c) Nexus hub, cluster, hotspot, national dense core, and regional cluster methods;

d) sensor, telemetry, reference-sensor, edge-compute, sovereign-compute, AI-RAN, O-RAN, DePIN, digital twin, cyber telemetry, geospatial, satellite, Earth observation, and remote-sensing methods;

e) public-safe dashboard, public-safe map, degraded-mode awareness, resilience indicator, and mission-critical signal interpretation methods;

f) observability environments used for climate, nature, biodiversity, disaster, wildfire, flood, water, energy, food, health, public health, biosecurity-relevant, telecom, port, utility, logistics, industrial, supply-chain, cyber, AI, robotics, drone, autonomous system, public infrastructure, and critical infrastructure contexts;

g) Nexus Universe test, build, benchmark, after-action, and public authority learning environments;

h) controlled rooms, evidence rooms, data rooms, public authority rooms, clean rooms, and no-download rooms used for observability-related review; and

i) observability-to-evidence, observability-to-Docket, observability-to-Grid, observability-to-GRF, observability-to-GRA, observability-to-Nexus Standards, and observability-to-public-safe-publication interfaces.

Observability stewardship shall not include emergency command, official public warning, public authority decision-making, certification, recognition, procurement approval, finance-readiness determination, insurance-readiness determination, rating, underwriting, lending, investment recommendation, provider selection, asset operation, or enterprise execution.

The Corporation shall ensure that observability outputs remain classified, contextual, reviewed, limited, challengeable, and correctable. No dashboard, map, model, digital twin, AI output, AI-RAN signal, O-RAN signal, DePIN record, sensor output, cyber telemetry stream, compute receipt, proof receipt, or observatory signal shall be treated as public warning, emergency instruction, public authority decision, certification, recognition, finance-readiness determination, procurement approval, or final authority.

28.4 Ontology Stewardship Function. The Corporation shall serve as an ontology steward for the semantic infrastructure required to make evidence, methods, observability, public-good software, technical baselines, public-safe outputs, public authority learning, and Nexus-compatible coordination coherent, interoperable, machine-readable, institutionally traceable, and correctionable.

The ontology stewardship function shall include the development, maintenance, review, publication where public-safe, controlled release where necessary, localization, alignment, versioning, and correction of:

a) ontologies;

b) taxonomies;

c) controlled vocabularies;

d) schemas;

e) data dictionaries;

f) risk categories;

g) evidence classifications;

h) maturity concepts;

i) technology-family classifications;

j) mission-critical system categories;

k) public authority capacity terms;

l) finance-readiness boundary terms;

m) recognition and standing boundary terms;

n) certification, conformance, and protocol-boundary terms;

o) procurement-boundary terms;

p) data, AI, cyber, privacy, security, safeguards, protected-knowledge, access, handling, and publication classes;

q) machine-readable metadata;

r) AI-readable knowledge structures; and

s) semantic interoperability mappings across Nexus institutions and interfaces.

The Corporation shall preserve semantic discipline across GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Universe, Nexus Academy, Nexus Competence Cells, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, qualified enterprise providers, sponsors, donors, funders, hosts, public authorities, universities, laboratories, communities, civil society bodies, media actors, and partners.

No controlled term shall be silently redefined. No sponsor, provider, donor, funder, host, public authority participant, technology vendor, program team, council, working group, committee, repository maintainer, publication lead, AI system, dashboard, model, or informal team shall alter the meaning of an ontology, schema, taxonomy, controlled term, data dictionary, classification, public-safe label, Nexus-compatible claim, finance-readiness term, recognition term, maturity term, certification term, procurement term, or public authority capacity term without competent authority and record.

Ontology stewardship shall not confer standards authority, protocol authority, certification authority, recognition authority, finance-readiness authority, public authority authority, procurement authority, or legal equivalence by mapping. Shared vocabulary shall not mean shared authority.

28.5 Technical Truth Stewardship Function. The Corporation shall serve as a technical truth steward within its bounded, public-benefit, non-executing, evidence-and-methods remit. Technical truth stewardship shall mean the disciplined production, review, limitation, publication, correction, and preservation of evidence-supported, method-governed, technically reasoned, public-safe, and challengeable outputs concerning complex systems, technologies, infrastructures, risks, capabilities, baselines, and observability environments.

Technical truth stewardship shall require the Corporation to prefer:

a) truthfulness before speed;

b) evidence sufficiency before narrative convenience;

c) provenance before rhetorical force;

d) method integrity before institutional prestige;

e) uncertainty disclosure before overclaim;

f) limitation disclosure before reliance;

g) challengeability before opacity;