For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE XIII. PUBLICATION

Section 315. Public-Safe Publication Purpose

315.1 Public-Safe Publication Purpose. GCRI Canada shall maintain public-safe publication discipline for reports, whitepapers, technical notes, research outputs, public-good software releases, technical baselines, schemas, dashboards, maps, websites, articles, speeches, decks, press releases, media responses, social media statements, datasets, public-safe summaries, controlled summaries, Observatory outputs, Truth Engine outputs, verifiable compute outputs, verifiable intelligence outputs, Nexus interface materials, Academy materials, public authority learning materials, and any other public or external communication. Public-safe publication shall ensure that GCRI Canada communicates in a manner that is accurate, evidence-supported, method-bound, role-separated, limitation-bearing, rights-respecting, safeguards-compliant, legally safe, cyber-safe, infrastructure-safe, public authority-safe, finance-boundary-safe, certification-boundary-safe, procurement-neutral, provider-neutral, sponsor-non-controlled, and correctionable.

315.2 Publication as Public-Benefit Communication. Publication by GCRI Canada shall be undertaken as public-benefit communication in furtherance of its nonprofit, non-share, non-distributing, public-benefit, non-executing institutional purposes. Publication shall support public understanding, evidence literacy, methods transparency, technical literacy, public authority learning, community-safe communication, research integrity, public-good software adoption, open technical baseline stewardship, Nexus-compatible interoperability, and disciplined correction. Publication shall not be used as marketing substitution for private actors, sponsor benefit, provider advantage, procurement influence, investor signalling, political endorsement, public authority approval implication, finance-readiness implication, recognition implication, maturity implication, certification implication, or execution instruction.

315.3 Publication as Evidence Communication. Publication may communicate evidence only where the relevant claims are supported by evidence records, source lineage, classification, confidence notes, limitation notes, public-safe review, and correction path. Evidence communication shall distinguish observed facts from inferred conclusions, modeled outputs, simulated scenarios, AI-assisted summaries, opinion, interpretation, uncertainty, disputed sources, stale information, and incomplete records. Publication shall not convert evidence into recognition, standing, maturity, finance-readiness, certification, procurement approval, public authority action, official warning, or public legitimacy unless a separate competent body and record lawfully provide that status.

315.4 Publication as Methods Communication. Publication may communicate methods, protocols, frameworks, taxonomies, schemas, baselines, profiles, test harnesses, evaluation methods, observability methods, Truth Engine methods, verifiable compute methods, AI governance methods, cybersecurity methods, public-safe publication methods, and interoperability methods. Methods communication shall describe purpose, scope, assumptions, applicability, exclusions, review status, version, dependencies, limitations, public-safe status, and correction path. Publication of a method shall not certify any implementation, approve any provider, mandate any procurement, create legal compliance, approve public authority use, determine finance-readiness, or warrant performance.

315.5 Publication as Research Communication. Publication may communicate research findings, working papers, discussion papers, literature reviews, field observations, technical analyses, scenario work, evidence syntheses, methods notes, public authority learning outputs, and public-good R&D outputs. Research communication shall preserve research integrity, source accuracy, intellectual honesty, conflict disclosure where material, data rights, privacy, protected knowledge safeguards, public authority boundaries, limitations, uncertainty, reproducibility where appropriate, and correctionability. Research communication shall not overstate certainty, novelty, consensus, causality, operational readiness, policy adoption, public authority endorsement, provider superiority, finance-readiness, certification, procurement suitability, or public warning status.

315.6 Publication as Technical Baseline Communication. Publication may communicate technical baselines, open technical baselines, reference baselines, evidence baselines, Observatory baselines, AI governance baselines, data governance baselines, cybersecurity baselines, interoperability baselines, and conformance-supporting baselines. Technical baseline communication shall include status, version, intended use, prohibited use, known limitations, dependencies, security status, license status, public-safe status, correction path, no-certification language, no-procurement language, no-finance-readiness language, no-public-authority-approval language, and no-provider-preference language where appropriate. Publication of a baseline shall not itself create mandatory compliance, accreditation, procurement requirement, public authority adoption, or finance approval.

315.7 Publication as Public-Good Software Communication. Publication may communicate public-good software releases, repository notices, release notes, software documentation, APIs, SDKs, schemas, technical packages, model cards, dataset cards, system cards, benchmark cards, test harnesses, reference implementations, vulnerability notices, and public-good licensing terms. Public-good software communication shall include license terms, attribution, limitations, security posture, known issues, dependency status, public-safe status, correction path, contribution terms, no-warranty language, no-certification language, no-procurement language, no-provider-endorsement language, and no-public-authority-approval language where required. Public-good software publication shall not make GCRI Canada an operator, managed service provider, certifier, procurement authority, or guarantor of third-party implementation.

315.8 Publication as Public Authority Learning Support. Publication may support public authority learning by providing educational, technical, evidence, methods, scenario, governance, data, AI, cyber, observability, public-safe publication, and capacity-formation materials for public authorities and public-sector readers. Such publication shall preserve public authority capacity classification and shall not imply that any public authority has approved, adopted, endorsed, funded, procured, regulated, certified, commanded, issued, or relied upon the publication unless expressly supported by competent public authority record. Public authority learning publications shall include non-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, and no-sovereign-obligation boundaries where material.

315.9 Publication as Community-Safe and Rights-Respecting Communication. Publication involving communities, Indigenous peoples, local or territorial knowledge, protected participants, youth, vulnerable persons, health-sensitive groups, remote communities, public-safe mapping risk, community vulnerability, lived experience, or protected knowledge shall be community-safe and rights-respecting. Such publication shall account for custodial authority, consent or authorization, context, attribution, non-extraction, confidentiality, re-identification risk, small-cell risk, geospatial sensitivity, retaliation risk, stigmatization, public authority sensitivity, withdrawal rights, correction rights, accessibility, and public-safe language. Publication shall not trade community safety or dignity for visibility, media effect, sponsor value, provider value, dashboard appeal, or institutional prestige.

315.10 Publication as Nexus-Compatible Public-Good Communication. Publication may communicate Nexus-compatible public-good concepts, architecture, methods, evidence, baselines, Observatory methods, Truth Engine methods, Risk Management methods, Rails technical evidence inputs, Grid evidence inputs, Academy learning materials, Competence Cell materials, consortium interface materials, national or regional compatibility notes, and public-safe summaries. Nexus-compatible communication shall preserve the one rail / two stacks discipline, non-execution, role separation among GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, National Consortium Companies, Project SPVs, providers, hosts, sponsors, public authorities, and communities. Publication shall not create merger, agency, shared treasury, shared liability, shared governance, public authority delegation, finance-readiness, certification, recognition, procurement approval, or execution authority.

315.11 Publication Subject to Evidence Records, Methods Records, Review, Classification, Redaction, Limitation, and Correction. Every material publication shall be subject to evidence records, methods records, review, classification, redaction, limitation, public-safe assessment, and correction requirements proportionate to risk. Publication review shall assess source support, method support, accuracy, uncertainty, public authority boundaries, protected knowledge, privacy, data / AI / cyber safety, infrastructure sensitivity, finance-boundary risk, certification-boundary risk, procurement implication, provider-neutrality risk, sponsor influence, licensing, export controls, sanctions, public-safe release, accessibility, and correction path. No publication shall be treated as complete, final, or safe merely because it is polished, internally approved in draft, AI-assisted, visually compelling, or previously circulated.

315.12 No Publication as Public Warning, Emergency Command, Regulation, Certification, Procurement Approval, Recognition, Finance-Readiness Determination, Insurance Approval, Investment Recommendation, Rating, or Execution Instruction. No publication by GCRI Canada shall constitute or be represented as a public warning, emergency command, emergency declaration, operational instruction, regulatory decision, legal compliance approval, certification, accreditation, conformity assessment, procurement approval, provider selection, provider preference, public authority approval, public authority adoption, recognition, standing, maturity determination, Nexus Grid guarantee, GRF recognition, finance-readiness determination, insurance-readiness determination, insurance approval, underwriting approval, lending approval, creditworthiness determination, rating, investment recommendation, securities recommendation, public finance approval, capital placement, investor matchmaking, or execution instruction. Where a publication could reasonably be misread in such manner, express limitation language shall be included.

315.13 Public-Safe Publication Records. GCRI Canada shall maintain public-safe publication records, including publication purpose records, public-benefit communication records, evidence communication records, methods communication records, research communication records, technical baseline communication records, public-good software communication records, public authority learning support records, community-safe and rights-respecting review records, Nexus-compatible communication records, evidence records, methods records, review records, classification records, redaction records, limitation records, public-safe approvals, boundary reviews, corrections, withdrawals, retractions, supersessions, public notices, controlled notices, and archives.


Section 316. Publication Authority and Approval Rights

316.1 Publication Authority. Publication authority shall be exercised only by the Board, an authorized officer, an authorized committee, or another person or function expressly delegated authority by competent record. Publication authority shall define who may approve, release, amend, correct, withdraw, retract, supersede, archive, or externally communicate a publication, and shall distinguish draft preparation, technical review, legal review, public-safe review, communications review, final approval, and release execution. No person shall infer publication authority from authorship, employment, fellowship, contributor status, advisory status, committee participation, council participation, working group participation, sponsorship, provider participation, public authority participation, repository access, communications access, or possession of draft materials.

316.2 Board Approval for Constitutional, High-Risk, or Material Publications. Board approval shall be required for constitutional, high-risk, institution-defining, legally sensitive, public authority-sensitive, finance-sensitive, certification-sensitive, procurement-sensitive, protected knowledge-sensitive, cyber-sensitive, infrastructure-sensitive, public controversy-sensitive, major public-safe, major Nexus interface, or materially reputational publications where policy or risk requires Board-level approval. Board approval may be required for major reports, public doctrinal statements, constitutional interpretations, public-good baseline releases of high significance, high-risk public authority materials, major controlled-to-public transformations, high-risk dashboards, high-risk maps, public statements concerning institutional boundaries, and publications that could materially affect public trust or legal exposure.

316.3 Officer Approval Within Delegation. An authorized officer may approve publications within the officer’s delegation, including routine public-safe materials, research summaries, technical notes, public-good software release notes, website updates, communications materials, Academy learning materials, public authority learning materials, event materials, media responses, and other outputs designated by policy. Officer approval shall remain subject to evidence review, legal review, public-safe review, data / AI / cyber review, safeguards review, public authority boundary review, finance-boundary review, certification-boundary review, procurement-boundary review, and Board escalation where risk exceeds delegation.

316.4 Committee Review Where Required. Committee review shall be required where publication falls within a committee’s mandate or risk lane, including audit, risk, governance, data / AI / cyber, research integrity, safeguards, public authority interface, finance-boundary, technical asset, publication, or other approved committee lanes. Committee review may recommend approval, conditional approval, revision, escalation, deferral, restriction, controlled release, public-safe redaction, withdrawal, or denial. Committee review shall not itself constitute publication approval unless the committee has delegated approval authority by competent record.

316.5 Legal Review Where Required. Legal review shall be required where publication involves legal interpretation, public authority claims, regulatory context, contractual obligations, data rights, privacy, intellectual property, licensing, export controls, sanctions, controlled technology, defamation risk, confidentiality, privilege, finance-sensitive language, certification-sensitive language, procurement-sensitive language, public authority references, third-party rights, contested matters, or material liability exposure. Legal review shall identify legal conditions, limitation language, required notices, required permissions, prohibited statements, and escalation needs.

316.6 Evidence and Methods Review Where Required. Evidence and methods review shall be required where publication makes material factual, technical, scientific, risk, observability, resilience, AI, cyber, geospatial, digital twin, public-good software, technical baseline, or Nexus interface claims. Review shall confirm source lineage, evidence sufficiency, method fit, uncertainty, confidence, limitation language, versioning, source classification, contradiction handling, stale-source handling, correction path, and public-safe suitability. Publications lacking adequate evidence or methods support shall be revised, limited, controlled, delayed, or denied.

316.7 Research Integrity Review Where Required. Research integrity review shall be required where publication presents research findings, analysis, studies, fieldwork, surveys, interviews, datasets, model results, benchmark results, literature syntheses, peer review outputs, or academic-style outputs. Review shall assess methodology, authorship, attribution, conflicts, ethics approvals, consent, data rights, privacy, statistical support, reproducibility where appropriate, limitations, publication review obligations, sponsor influence, provider influence, and correction or retraction pathway.

316.8 Data / AI / Cyber / Privacy Review Where Required. Data / AI / cyber / privacy review shall be required where publication includes, relies on, or is produced from data processing, AI assistance, model outputs, retrieval, embeddings, inference records, dashboards, maps, public authority data, personal information, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, finance-sensitive evidence, public repositories, technical packages, or security findings. Review shall confirm data rights, lawful basis, AI-use authority, human review, leakage risk, prompt injection risk, model limitations, cyber-safe language, privacy protection, public-safe classification, and incident response readiness.

316.9 Public Authority Boundary Review Where Required. Public authority boundary review shall be required where publication refers to public authorities, public authority personnel, ministries, municipalities, Crown entities, regulators, emergency management bodies, public finance bodies, public health bodies, public safety bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, public infrastructure operators, public authority data, public authority participation, public authority quotes, public authority logos, public authority photographs, public authority attendance, or public authority learning. Review shall confirm name-use authority, capacity classification, attribution permission, public reference permission, non-endorsement language, no-delegation boundaries, no-public-warning boundaries, no-emergency-command boundaries, no-regulatory-approval boundaries, no-procurement-approval boundaries, no-funding-approval boundaries, no-public-finance-approval boundaries, and no-sovereign-obligation boundaries.

316.10 Finance, Insurance, Investment, Procurement, Certification, Recognition, and Maturity Boundary Review Where Required. Boundary review shall be required where publication could be read to affect finance-readiness, insurance-readiness, investment suitability, bankability, creditworthiness, rating, underwriting, lending, public finance, capital placement, investor matchmaking, procurement, provider selection, certification, accreditation, compliance approval, recognition, standing, maturity, Nexus Grid status, GRF recognition, or public legitimacy. Review shall ensure that GCRI Canada does not provide regulated financial, securities, insurance, rating, lending, public finance, procurement, certification, accreditation, or recognition determinations unless separately and lawfully authorized by competent authority, and that limitation language prevents public overclaim.

316.11 Community Safeguards and Protected Knowledge Review Where Required. Community safeguards and protected knowledge review shall be required where publication involves Indigenous knowledge, local knowledge, territorial knowledge, community-protected data, cultural knowledge, environmental knowledge, sacred-site information, community vulnerability, remote community data, protected participants, youth, vulnerable persons, health-sensitive communities, public-safe mapping risk, or community-sensitive risk. Review shall confirm custodial authority, consent or authorization, attribution, non-extraction, access limits, AI-use limits, publication limits, withdrawal rights, correction rights, redaction, aggregation, geospatial generalization, community harm mitigation, and public-safe language.

316.12 Communications Review. Communications review shall be required for materials intended for public, media, website, social media, events, speeches, public decks, newsletters, public authority learning, sponsor-facing public materials, provider-facing public materials, or broad external audiences. Communications review shall ensure clarity, accuracy, consistency with approved institutional language, accessibility, controlled vocabulary, no-overclaim discipline, non-endorsement language, boundary language, reputational safety, public-safe tone, and correction path. Communications review shall not substitute for legal, evidence, methods, data / AI / cyber, public authority, finance-boundary, certification-boundary, procurement-boundary, or safeguards review where those are required.

316.13 Approval Matrix for Reports, Whitepapers, Datasets, Software Releases, Dashboards, Maps, Websites, Articles, Press Releases, Speeches, Decks, Social Media, Media Responses, and Public Statements. GCRI Canada may maintain a publication approval matrix identifying required approvals and reviews for reports, whitepapers, research papers, datasets, public-good software releases, technical packages, dashboards, maps, websites, articles, press releases, speeches, decks, social media, media responses, public statements, newsletters, Academy materials, public authority learning materials, public-safe summaries, controlled summaries, and Nexus interface materials. The matrix shall identify publication class, risk level, owner, reviewers, approver, required records, boundary reviews, limitation language, release channel, correction path, and archival requirements. The matrix shall be updated as risks, tools, publication forms, or institutional needs change.

316.14 No Publication by Unauthorized Person, Participant, Sponsor, Provider, Fellow, Advisor, Working Group, Council, Committee, Public Authority Participant, or Partner. No unauthorized person, participant, sponsor, provider, donor, funder, host, contractor, consultant, fellow, advisor, volunteer, contributor, working group, council, committee, public authority participant, university, laboratory, community participant, National Consortium Company, Project SPV, partner, or Nexus actor may publish, release, announce, cite as final, publicly attribute to GCRI Canada, use GCRI Canada name or marks, issue public statements on behalf of GCRI Canada, or represent draft materials as official GCRI Canada publications without competent authorization. Participation, contribution, attendance, sponsorship, data contribution, review, or possession of materials shall not create publication rights.

316.15 Publication Approval Records. GCRI Canada shall maintain publication approval records, including publication authority records, Board approval records, officer approval records, committee review records, legal review records, evidence and methods review records, research integrity review records, data / AI / cyber / privacy review records, public authority boundary review records, finance / insurance / investment / procurement / certification / recognition / maturity boundary review records, community safeguards and protected knowledge review records, communications review records, approval matrix records, unauthorized publication records, release records, corrections, withdrawals, retractions, supersessions, notices, and archives.


Section 317. Publication Classes, Access Classes, Handling Categories, Embargoes, Redactions, and Controlled Summaries

317.1 Publication Classification. GCRI Canada shall classify publications before release, circulation, external sharing, repository posting, dashboard display, map display, software release, dataset release, public statement, media response, or Nexus interface use. Publication classification shall identify publication class, access class, handling category, public-safe status, redaction requirements, embargo status, controlled summary requirements, data sensitivity, public authority sensitivity, protected knowledge status, cyber sensitivity, infrastructure sensitivity, finance sensitivity, commercial sensitivity, personal information status, licensing status, and correction path.

317.2 Public Publication Class. Public publication class means a publication approved for unrestricted public release after required review. Public publications may include public reports, whitepapers, websites, articles, public-safe dashboards, public-safe maps, public-good software releases, public technical baselines, public documentation, press releases, speeches, and social media materials. Public classification shall require confirmation that the publication is public-safe, rights-cleared, security-reviewed where required, limitation-bearing, non-overclaiming, accessible, versioned where appropriate, and correctionable.

317.3 Public-Safe Summary Class. Public-safe summary class means a summary derived from controlled, restricted, sensitive, or internal materials that has been transformed for public release by redaction, aggregation, generalization, de-identification, limitation, controlled vocabulary, public authority boundary review, safeguards review, data / AI / cyber review, and public-safe approval. A public-safe summary shall communicate meaningful public-benefit information without exposing restricted data, protected knowledge, public authority-sensitive details, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, personal information, confidential information, or unsafe operational details.

317.4 Controlled Publication Class. Controlled publication class means a publication approved for a defined audience, room, data room, public authority room, Board context, committee context, council context, partner context, research context, capital-reader context, technical review context, or Nexus interface context, but not approved for unrestricted public release. Controlled publications shall identify recipients, permitted use, prohibited use, confidentiality, redistribution limits, AI-use restrictions, no-download status where applicable, retention, deletion, correction path, and public-safe summary rules.

317.5 Restricted Publication Class. Restricted publication class means a publication, document, dashboard, map, dataset, technical asset, report, note, annex, or communication that may be accessed only by authorized persons under heightened controls due to public authority sensitivity, protected knowledge, cyber sensitivity, infrastructure sensitivity, health sensitivity, finance sensitivity, legal sensitivity, commercial sensitivity, export-control restriction, sanctions sensitivity, personal information, or public-safe risk. Restricted publications shall not be forwarded, summarized, excerpted, uploaded, indexed, embedded, trained on, or externally shared without authority.

317.6 Internal-Only Publication Class. Internal-only publication class means a publication or material approved only for internal GCRI Canada use or governance use. Internal-only materials may include draft reports, Board materials, committee materials, internal analyses, working notes, issue records, incident records, research drafts, legal reviews, public-safe review notes, and internal guidance. Internal-only status shall not authorize public circulation, public authority circulation, sponsor circulation, provider circulation, media disclosure, repository posting, or Nexus interface use without reclassification and approval.

317.7 Embargoed Publication Class. Embargoed publication class means a publication approved or conditionally approved for release only after a specified time, event, notice, partner clearance, public authority clearance, legal review, publication date, research integrity condition, vulnerability disclosure condition, public-safe condition, or Board condition. Embargoed materials shall be access-controlled and shall not be previewed, leaked, cited, posted, summarized publicly, or used for sponsor, provider, finance, procurement, or media advantage before release authority permits.

317.8 Access Classes. Access classes shall identify who may access publication materials, drafts, controlled summaries, annexes, source records, datasets, dashboards, maps, repository materials, software packages, review notes, or release records. Access classes may include public, public-safe, internal, controlled, restricted, confidential, privileged, no-download, room-only, public authority-limited, safeguards-limited, cyber-limited, infrastructure-limited, finance-boundary-limited, Board-only, committee-only, council-only, reviewer-only, and archive-only. Access class shall be enforceable through permissions, records, and review.

317.9 Handling Categories. Handling categories shall identify special treatment required for publication materials. Handling categories may include public authority handling, cyber-sensitive handling, infrastructure-sensitive handling, finance-sensitive handling, commercially sensitive handling, personal information handling, community-protected and Indigenous / local / territorial knowledge handling, export-control handling, sanctions-sensitive handling, legal privilege handling, research integrity handling, vulnerability disclosure handling, and media-sensitive handling. Handling category shall travel with drafts, summaries, annexes, outputs, and dependent records.

317.10 Public Authority Handling Category. Public authority handling shall apply where materials include public authority names, logos, titles, agencies, quotes, attendance, data contributions, public authority communications, public finance reader materials, regulator-listening materials, emergency-management materials, public infrastructure operator materials, public health materials, public safety materials, or public-sector sensitive records. Such materials shall require capacity classification, reference permission, non-endorsement language, no-public-warning language where material, and no-public-authority-approval language where material.

317.11 Cyber-Sensitive Handling Category. Cyber-sensitive handling shall apply where materials include vulnerabilities, exploits, threat intelligence, incident records, access controls, credentials, security architecture, logs, repository security details, SBOMs, dependency risks, prompt injection tests, model attack records, or cyber telemetry. Such materials shall be restricted or public-safe transformed to prevent exploit amplification, credential exposure, system targeting, or unsafe disclosure.

317.12 Infrastructure-Sensitive Handling Category. Infrastructure-sensitive handling shall apply where materials include telecom, AI-RAN, O-RAN, DePIN, compute, energy, water, food, health, port, transport, public works, emergency management, cyber-physical systems, digital twins, degraded-mode indicators, geospatial layers, dependency maps, or mission-critical infrastructure information. Publication shall be reviewed for targeting risk, operational security, public authority terms, public-safe mapping risk, and non-command language.

317.13 Finance-Sensitive Handling Category. Finance-sensitive handling shall apply where materials include finance-boundary notes, capital-readability materials, public finance reader materials, investor-facing evidence, insurance-sensitive evidence, lender-sensitive evidence, project finance materials, revenue assumptions, sponsor materials, public-private finance context, guarantee-related records, underwriting-adjacent records, rating-adjacent records, Nexus Rails inputs, National Consortium Company materials, or Project SPV materials. Publication shall include no-investment-advice, no-insurance-advice, no-underwriting, no-rating, no-lending, no-public-finance-approval, and no-finance-readiness language where material.

317.14 Commercially Sensitive Handling Category. Commercially sensitive handling shall apply where materials include confidential provider information, sponsor information, donor information, funder information, pricing, costs, bids, roadmaps, capacity, supplier terms, customer information, product plans, proprietary systems, provider comparisons, vendor performance records, or competition-sensitive information. Publication shall avoid unlawful information exchange, market coordination, provider preference, procurement distortion, sponsor control, improper private benefit, and confidential disclosure.

317.15 Personal Information Handling Category. Personal information handling shall apply where materials include personal information, sensitive personal information, health information, participant information, contributor information, public authority personnel information, community participant information, youth data, vulnerable person data, whistleblower data, complainant data, witness data, location data, or rights-bearing data. Publication shall require privacy review, minimization, redaction, de-identification or aggregation where appropriate, re-identification risk review, and correction path.

317.16 Community-Protected and Indigenous / Local / Territorial Knowledge Handling Category. Community-protected and Indigenous / local / territorial knowledge handling shall apply where materials include Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, community vulnerability, remote community data, protected participant information, public-safe mapping risk, or community-sensitive evidence. Publication shall require safeguards review, custodial authority where applicable, consent or authorization, non-extraction, attribution controls, public-safe transformation, withdrawal rights, correction rights, and harm-prevention measures.

317.17 Redaction Standards. Redaction for publication shall remove or obscure information sufficient to protect privacy, protected knowledge, public authority-sensitive information, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, commercial sensitivity, legal privilege, confidential information, and public-safe integrity. Redaction shall address direct identifiers, indirect identifiers, metadata, tracked changes, comments, hidden layers, screenshots, file properties, geospatial precision, timestamps, small-cell data, source links, access paths, credentials, prompts, logs, and embedded data. Redaction shall not distort meaning, conceal material limitations, or create misleading confidence.

317.18 Controlled Summaries. Controlled summaries may be prepared for audiences requiring more detail than public materials but less access than full restricted records. Controlled summaries shall identify source class, audience, purpose, permitted use, prohibited use, sensitivity, redactions, limitations, boundary language, redistribution limits, AI-use restrictions, retention, correction path, and whether a public-safe version may be created. Controlled summaries shall not be used to bypass access controls, public authority terms, protected knowledge safeguards, finance-boundary controls, or cyber restrictions.

317.19 Declassification, Reclassification, and Public-Safe Release. Publication materials may be declassified, reclassified, or released in public-safe form only after review confirms that the proposed class is lawful, accurate, safe, rights-respecting, public authority-safe, cyber-safe, infrastructure-safe, finance-boundary-safe, certification-boundary-safe, procurement-neutral, provider-neutral, and correctionable. Reclassification shall preserve audit trail and shall identify what changed, why it changed, who approved it, whether source permissions changed, whether redactions are sufficient, whether dependency review is required, and whether prior recipients require notice.

317.20 Publication Classification Records. GCRI Canada shall maintain publication classification records, including publication classification records, public publication records, public-safe summary records, controlled publication records, restricted publication records, internal-only publication records, embargoed publication records, access class records, handling category records, public authority handling records, cyber-sensitive handling records, infrastructure-sensitive handling records, finance-sensitive handling records, commercially sensitive handling records, personal information handling records, community-protected and Indigenous / local / territorial knowledge handling records, redaction records, controlled summary records, declassification records, reclassification records, public-safe release records, corrections, notices, and archives.


Section 318. Claims Substantiation, Evidence Records, Methods Records, Controlled Vocabulary, and Public-Safe Review

318.1 Claims Substantiation Requirement. Every material claim in a GCRI Canada publication shall be substantiated before release. A material claim includes any factual, technical, scientific, legal-adjacent, public authority, evidence, methods, observability, risk, resilience, AI, cyber, geospatial, digital twin, software, baseline, finance-boundary, certification-boundary, procurement-boundary, recognition-boundary, maturity-boundary, public-good impact, institutional authority, sponsor, provider, community, or Nexus-compatible claim that may affect public meaning or reliance. Claims shall be supported by evidence records, methods records, source lineage, confidence notes, limitation notes, controlled vocabulary, public-safe review, and correction path proportionate to materiality.

318.2 Evidence Record Support. Claims requiring evidence shall be supported by evidence records identifying source, provenance, custody, timestamp, jurisdiction, permission, classification, reliability, confidence, limitations, dispute status, public authority capacity where applicable, protected knowledge status where applicable, data rights, and correction path. Evidence record support shall distinguish direct evidence, indirect evidence, inferred evidence, model-supported evidence, AI-assisted evidence, simulated evidence, anecdotal evidence, and illustrative material. Unsupported claims shall be removed, limited, qualified, or converted into questions or hypotheses.

318.3 Methods Record Support. Claims requiring methodological support shall be supported by methods records identifying method, version, purpose, scope, assumptions, applicability, exclusions, limitations, reviewer, source requirements, uncertainty treatment, public-safe status, and correction path. Methods record support shall be required for risk analysis, observability outputs, AI model outputs, digital twin results, geospatial outputs, benchmark results, public-good software claims, technical baseline claims, Truth Engine outputs, verifiable compute claims, and public-safe intelligence outputs. Method absence shall trigger limitation, delay, controlled release, or denial.

318.4 Source Lineage Support. Claims shall preserve source lineage sufficient to identify where the claim came from, how it was transformed, who reviewed it, what method applied, what version was used, and what limitations attach. Source lineage may include source records, dataset records, model records, inference records, compute workload records, repository records, dashboard records, map records, legal review notes, public authority terms, protected knowledge permissions, and publication review records. Public versions may summarize lineage where full disclosure would be unsafe or unlawful.

318.5 Confidence and Uncertainty Support. Claims involving uncertain, probabilistic, modelled, simulated, forecast, inferred, incomplete, disputed, or dynamic matters shall include confidence and uncertainty support. Confidence and uncertainty support shall identify source quality, corroboration, contradiction, missing data, stale data, model limitations, method limitations, reviewer judgment, confidence band where used, non-use conditions, and triggers for correction. Confidence language shall not be overread as guarantee, rating, certification, maturity, finance-readiness, public authority approval, or public warning.

318.6 Limitation Disclosure. Publications shall disclose limitations proportionate to claim materiality and audience. Limitations may address source limitations, scope limits, temporal limits, jurisdictional limits, method limits, data limits, model limits, AI limits, public authority limits, protected knowledge limits, privacy limits, cyber limits, infrastructure limits, finance-boundary limits, certification-boundary limits, procurement-boundary limits, provider-neutrality limits, sponsor-related limits, and unsupported uses. Limitation disclosure shall be clear enough to prevent reasonable misreliance.

318.7 Controlled Vocabulary Requirement. Publications shall use GCRI Canada controlled vocabulary and Nexus-compatible terms where material to prevent ambiguity, role collapse, overclaim, public authority confusion, finance implication, certification implication, procurement implication, recognition implication, maturity implication, or provider preference. Terms such as validated, verified, certified, approved, recognized, endorsed, official, compliant, finance-ready, procurement-ready, mature, safe, sovereign, public warning, emergency, authority, guarantee, readiness, rating, standard, protocol, and Nexus-compatible shall be used only with the meaning supported by competent records.

318.8 Prohibited Overstatement. GCRI Canada shall not publish overstatements of certainty, evidence, method validity, research conclusions, public benefit, public authority participation, public authority support, sponsor support, provider participation, software capability, dashboard completeness, map accuracy, AI reliability, cyber security, infrastructure resilience, finance-readiness, certification, procurement suitability, recognition, maturity, or Nexus compatibility. Overstatement includes excessive confidence, omitted limitations, misleading titles, exaggerated executive summaries, unsupported graphics, promotional language, and selective source presentation.

318.9 Prohibited Ambiguity Where Public Meaning Could Be Misread. GCRI Canada shall not use ambiguous language where public meaning could reasonably be misread as public authority approval, official warning, emergency command, certification, accreditation, compliance approval, procurement approval, provider preference, finance-readiness, insurance approval, investment recommendation, rating, recognition, maturity status, Nexus Grid status, GRF recognition, legal advice, engineering opinion, clinical opinion, or regulated professional opinion. Ambiguous language shall be corrected through precise controlled vocabulary and express limitation language.

318.10 Prohibited Role Collapse. Publications shall not collapse the roles of GCRI Canada, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, public authorities, hosts, sponsors, providers, universities, laboratories, communities, capital readers, insurers, lenders, or media. Each publication shall preserve legal separateness, institutional boundaries, non-execution, and authority limits.

318.11 Prohibited Sponsor, Provider, Public Authority, Finance, Certification, Procurement, Recognition, or Maturity Overclaim. No publication shall overclaim sponsor participation, provider participation, public authority participation, public finance reader participation, regulator-listening participation, emergency-management participation, public infrastructure operator participation, finance-readiness, insurance-readiness, investment suitability, bankability, rating, underwriting approval, lending approval, certification, accreditation, compliance approval, procurement approval, provider preference, recognition, standing, maturity, Nexus Grid status, GRF recognition, or public legitimacy. Where any such risk exists, claims shall be narrowed, disclaimed, moved to controlled records, or removed.

318.12 Public-Safe Review. Public-safe review shall assess whether a publication may be released externally without exposing personal information, protected knowledge, public authority-sensitive information, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, commercial sensitivity, confidential information, legal privilege, unsafe operational details, misleading public authority meaning, finance overclaim, certification overclaim, procurement implication, provider preference, sponsor benefit, public warning confusion, or public-safe harm. Public-safe review may require redaction, aggregation, generalization, delay, controlled summary, denial, correction, or escalation.

318.13 Claims Review for Technical Accuracy. Technical accuracy review shall assess whether publication claims concerning software, schemas, APIs, dashboards, maps, models, datasets, AI, AI-RAN, O-RAN, DePIN, cyber, geospatial, digital twins, sensors, sovereign compute, public-good baselines, test harnesses, benchmarks, observability methods, Truth Engine methods, or verifiable compute outputs are accurate, versioned, reproducible where appropriate, limitation-bearing, source-supported, and not misleading. Technical accuracy review shall include known issues, dependency status, security status, and correction path where material.

318.14 Claims Review for Legal Safety. Legal safety review shall assess whether claims create legal exposure, misstate legal obligations, imply legal compliance, overstate institutional authority, disclose confidential information, infringe rights, violate licenses, breach contracts, misrepresent public authority participation, create finance or investment implications, create certification or procurement implications, or provide regulated professional advice. Legal safety review shall identify required revisions, limitations, approvals, or prohibitions.

318.15 Claims Review for Public Authority Safety. Public authority safety review shall assess whether claims involving public authorities are accurate, authorized, capacity-classified, non-endorsement-compliant, public-safe, and boundary-protected. Review shall prevent misdescription of names, titles, offices, logos, quotes, attendance, data contributions, public authority comments, public finance participation, regulator listening, emergency management context, public infrastructure operator participation, procurement involvement, funding involvement, regulatory involvement, or public authority adoption.

318.16 Claims Review for Community and Protected Knowledge Safety. Community and protected knowledge safety review shall assess whether publication claims respect custodial authority, consent or authorization, context, attribution, non-extraction, confidentiality, protected participant safety, remote community risk, Indigenous / local / territorial knowledge protocols, small-cell risk, geospatial sensitivity, community dignity, public-safe mapping risk, withdrawal rights, and correction rights. Claims that expose, appropriate, decontextualize, stigmatize, or overgeneralize community knowledge shall be revised, restricted, or denied.

318.17 Claims Review for Data / AI / Cyber Safety. Data / AI / cyber safety review shall assess whether claims involve data rights, AI use, model outputs, embeddings, retrieval, inference, cyber vulnerabilities, security controls, infrastructure-sensitive details, public repository exposure, model limitations, prompt injection risk, data leakage risk, AI hallucination risk, model drift, benchmark limitations, or unsafe technical disclosure. Claims shall be revised or controlled where public release could increase risk, mislead users, disclose sensitive details, or overstate reliability.

318.18 Claims Substantiation Records. GCRI Canada shall maintain claims substantiation records, including claim inventories where appropriate, evidence record support, methods record support, source lineage records, confidence and uncertainty records, limitation disclosures, controlled vocabulary reviews, overstatement reviews, ambiguity reviews, role-collapse reviews, sponsor / provider / public authority / finance / certification / procurement / recognition / maturity overclaim reviews, public-safe reviews, technical accuracy reviews, legal safety reviews, public authority safety reviews, community and protected knowledge safety reviews, data / AI / cyber safety reviews, corrections, approvals, withdrawals, retractions, and archives.


Section 319. Technical Claims and No Certification, No Procurement Approval, No Grid Guarantee, No Finance Approval, and No Public Authority Endorsement

319.1 Technical Claim Definition. A technical claim means any publication statement, dashboard output, map output, software release note, benchmark statement, model card statement, dataset card statement, system card statement, technical baseline statement, schema statement, API statement, methods statement, observability statement, Truth Engine statement, verifiable compute statement, AI output statement, cybersecurity statement, infrastructure statement, geospatial statement, digital twin statement, sensor statement, sovereign compute statement, public-good software statement, or Nexus interface statement that describes technical status, technical performance, technical structure, technical suitability, technical interoperability, technical evidence, technical reliability, technical limitation, or technical meaning. Technical claims shall be evidence-supported, method-bound, versioned where appropriate, limitation-bearing, public-safe-reviewed, and correctionable.

319.2 Evidence-Based Technical Claims. Evidence-based technical claims shall be supported by evidence records, source lineage, confidence notes, uncertainty notes, classification, public-safe review, and correction path. Such claims may describe what a source, dataset, log, telemetry record, software test, benchmark, dashboard, map, model output, or evidence pack indicates, but shall not overstate evidence as final proof, official truth, legal compliance, safety guarantee, certification, procurement approval, finance-readiness, maturity, recognition, or public authority endorsement.

319.3 Methods-Based Technical Claims. Methods-based technical claims shall be supported by methods records identifying method version, assumptions, scope, applicability, exclusions, limitations, public-safe status, reviewer, and correction path. Methods-based claims may describe how GCRI Canada analyzes, classifies, compares, models, maps, tests, or communicates technical matters. Publication of a method shall not mean that any implementation using the method is approved, certified, compliant, secure, procurement-ready, finance-ready, public-authority-approved, or preferred.

319.4 Baseline Claims. Baseline claims shall state the status, version, intended use, scope, limitations, known issues, licensing, public-safe status, and correction path of a public-good baseline, open technical baseline, reference baseline, evidence baseline, Observatory baseline, AI governance baseline, data governance baseline, cybersecurity baseline, interoperability baseline, or conformance-supporting baseline. Baseline claims shall not imply certification, accreditation, compliance approval, procurement mandate, provider approval, public authority adoption, finance-readiness, insurance-readiness, performance guarantee, or legal equivalence.

319.5 Observatory Claims. Observatory claims shall describe observability methods, telemetry structures, sensing methods, dashboard logic, map layers, digital twin methods, degraded-mode awareness, resilience indicators, AI-RAN or O-RAN signal methods, DePIN telemetry methods, cyber telemetry structures, geospatial evidence, public-safe observability outputs, or Nexus Observatory interface support only within the limits of source records, method records, and public-safe review. Observatory claims shall not constitute public warning, emergency command, public authority decision, operational control, infrastructure guarantee, Observatory certification, maturity determination, finance-readiness, procurement approval, or provider preference.

319.6 Truth Engine Claims. Truth Engine claims shall describe source comparison, corroboration, contradiction detection, confidence support, dispute marking, spoof detection, tamper detection, stale-source handling, missing-source handling, retrieval review, AI-assisted comparison, or verifiable intelligence methods only as evidence and methods outputs. Truth Engine claims shall not be represented as absolute truth, official truth, legal truth, public authority truth, certified truth, finance truth, procurement truth, maturity truth, or final institutional authority. Truth Engine claims shall include confidence, limitations, source support, review status, and correction path where material.

319.7 Verifiable Compute Claims. Verifiable compute claims shall describe compute workload records, model records, dataset records, execution environment records, hashes, logs, provenance, reproducibility, output classification, inference records, human review, and correction paths only within the actual recorded scope. Verifiable compute claims shall not imply that a computation is universally correct, public authority-approved, certified, legally compliant, secure, finance-ready, procurement-ready, operationally safe, or immune from error. Verifiable compute means traceability and reviewability, not infallibility.

319.8 AI, AI-RAN, O-RAN, DePIN, Cyber, Geospatial, Digital Twin, Sensor, Sovereign Compute, and Public-Good Software Claims. Claims concerning AI, AI-RAN, O-RAN, DePIN, cyber, geospatial systems, Earth observation, digital twins, sensors, sovereign compute, public-good software, technical packages, APIs, SDKs, dashboards, maps, test harnesses, and reference implementations shall be specific, versioned where appropriate, evidence-supported, limitation-bearing, and public-safe-reviewed. Such claims shall identify whether outputs are experimental, draft, internal, controlled, restricted, public-safe, public, adopted, active, superseded, deprecated, or retired. Such claims shall not overstate safety, security, readiness, resilience, performance, interoperability, public authority support, provider neutrality, finance suitability, certification status, procurement status, or maturity.

319.9 No Certification by Technical Claim. No technical claim by GCRI Canada shall constitute certification, conformity assessment, accredited certification, compliance certification, safety certification, cybersecurity certification, AI certification, software certification, product certification, infrastructure certification, provider certification, Observatory certification, Grid certification, or Nexus certification. Use of GCRI Canada technical materials, baselines, methods, software, dashboards, maps, profiles, test harnesses, or public-good assets shall not create certification unless a separate competent certification authority and record expressly provide it.

319.10 No Accreditation by Technical Claim. No technical claim shall constitute accreditation of any person, provider, host, sponsor, public authority, university, laboratory, consortium, National Consortium Company, Project SPV, software, dataset, model, dashboard, map, method, technical asset, or implementation. Accreditation may arise only through a separate competent accreditation body and record, if any. GCRI Canada technical statements shall not be marketed as accreditation substitutes.

319.11 No Compliance Approval by Technical Claim. No technical claim shall constitute legal, regulatory, statutory, contractual, cybersecurity, privacy, AI, environmental, telecom, public procurement, public finance, insurance, public authority, or other compliance approval. Compliance determinations require competent legal, regulatory, professional, public authority, or formal assessment process as applicable. GCRI Canada may publish technical evidence or methods support but shall not imply compliance approval by technical claim.

319.12 No Procurement Approval by Technical Claim. No technical claim shall constitute procurement approval, tender qualification, vendor selection, preferred provider designation, purchasing recommendation, public-sector eligibility standard, contract award condition, or procurement mandate. Public authorities and procuring bodies may make their own lawful procurement decisions, but GCRI Canada technical publications shall not create procurement meaning unless a competent procuring body separately and lawfully adopts a requirement, and GCRI Canada’s publication shall remain non-procurement in character.

319.13 No Provider Preference by Technical Claim. No technical claim shall prefer, endorse, rank, select, approve, recommend, certify, or promote any provider, vendor, host, contractor, consultant, AI provider, cloud provider, telecom provider, AI-RAN provider, O-RAN provider, DePIN provider, cybersecurity provider, software provider, data provider, National Consortium Company, Project SPV, or commercial actor unless a competent record expressly authorizes narrowly defined reference for a lawful purpose. Technical comparison shall be controlled to avoid provider preference, procurement distortion, market signalling, sponsor benefit, or private capture.

319.14 No Grid Guarantee by Technical Claim. No technical claim shall guarantee Nexus Grid status, maturity, capability, infrastructure readiness, host readiness, participation standing, public legitimacy, recognition, or performance. GCRI Canada may provide evidence inputs, methods inputs, observability inputs, research inputs, and correction signals where authorized, but it shall not determine Grid maturity, guarantee Grid status, or represent Grid-related evidence as certification, finance-readiness, insurance-readiness, procurement approval, public authority approval, or performance warranty.

319.15 No Finance Approval by Technical Claim. No technical claim shall constitute finance-readiness, insurance-readiness, investment suitability, bankability, creditworthiness, rating, underwriting approval, lending approval, public finance approval, capital recommendation, investor matchmaking, capital placement, guarantee approval, or insurance placement. GCRI Canada technical publications may support technical evidence literacy and capital-readability inputs where authorized, but shall not provide regulated financial, securities, insurance, rating, underwriting, lending, or investment determinations.

319.16 No Public Authority Endorsement by Technical Claim. No technical claim shall imply public authority endorsement, approval, adoption, funding approval, procurement approval, regulation, public warning, emergency command, public finance approval, sovereign obligation, or official public-sector status. Public authority participation, attendance, data contribution, comments, learning participation, regulator listening, public finance reading, emergency-management participation, or infrastructure-operator participation shall not be represented as endorsement unless a competent public authority record expressly authorizes the precise language.

319.17 Required Limitation Language. Technical claims shall include limitation language proportionate to risk. Limitation language may state that the claim is evidence-based, method-bound, version-specific, source-dependent, review-limited, uncertainty-bearing, public-safe, not certification, not accreditation, not compliance approval, not procurement approval, not provider preference, not Grid guarantee, not finance approval, not insurance approval, not investment recommendation, not rating, not public authority endorsement, not public warning, not emergency command, and subject to correction. Required limitation language shall be clear and not buried in a manner likely to be missed by intended readers.

319.18 Technical Claim Records. GCRI Canada shall maintain technical claim records, including technical claim inventories where appropriate, evidence-based claim records, methods-based claim records, baseline claim records, Observatory claim records, Truth Engine claim records, verifiable compute claim records, AI / AI-RAN / O-RAN / DePIN / cyber / geospatial / digital twin / sensor / sovereign compute / public-good software claim records, no-certification reviews, no-accreditation reviews, no-compliance-approval reviews, no-procurement-approval reviews, provider-neutrality reviews, Grid guarantee boundary records, finance approval boundary records, public authority endorsement boundary records, required limitation language, corrections, withdrawals, retractions, supersessions, and archives.


Section 320. Public Authority Names, Logos, Titles, Agencies, Quotes, Attendance, Photographs, Data Contributions, and Reference Approvals

320.1 Public Authority Reference Purpose. GCRI Canada shall govern references to public authorities, public authority personnel, agencies, departments, ministries, municipalities, Crown entities, regulators, public finance bodies, emergency management bodies, public health bodies, public safety bodies, public infrastructure operators, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, and other public-sector actors to preserve accuracy, lawful attribution, public trust, public authority boundaries, non-endorsement, capacity classification, and public-safe communication. Public authority references shall be used only where supported by record and shall not be used to imply approval, adoption, funding, procurement, regulation, public warning, emergency command, public finance approval, endorsement, or sovereign obligation.

320.2 Public Authority Name Use. Use of a public authority name in a publication, website, report, deck, dashboard, map, press release, social media post, media response, event material, sponsor material, provider material, technical baseline, or Nexus interface material shall require review for accuracy, authority, context, capacity, public-safe meaning, and permission where required. Public authority name use shall identify whether the authority participated, attended, received materials, provided data, commented, observed, listened, learned, reviewed, funded, procured, adopted, or approved, and shall not collapse those distinct meanings.

320.3 Public Authority Logo Use. Public authority logos, seals, crests, emblems, flags, marks, visual identifiers, official branding, or department marks shall not be used without express permission or other lawful authority. Logo use shall be limited to the approved context, format, duration, placement, and language. Logo use shall not imply endorsement, co-branding, approval, adoption, sponsorship, funding, procurement, public authority partnership, public warning, emergency command, or sovereign obligation unless the public authority expressly authorizes such meaning.

320.4 Public Authority Title Use. Titles of public authority personnel shall be used accurately and only with appropriate context. A person’s title shall not be used to imply that the person’s views are official, that the public authority has approved a publication, that the public authority has delegated authority to GCRI Canada, or that GCRI Canada has public-sector status. Where necessary, publications shall distinguish personal-capacity participation, observer participation, regulator-listening participation, public finance reader participation, public authority learning participation, official-capacity participation, and institutional approval.

320.5 Public Authority Agency or Department Reference. References to agencies, departments, ministries, municipalities, Crown entities, regulators, public finance bodies, emergency management bodies, public health bodies, public safety bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, or public infrastructure operators shall be precise and record-supported. Such references shall not imply that the entire public authority, government, ministry, department, agency, or jurisdiction endorses or adopts GCRI Canada materials merely because one office, employee, unit, participant, or observer engaged with GCRI Canada.

320.6 Jurisdiction Reference. Jurisdiction references shall be used carefully to identify geographic, legal, regulatory, public authority, regional, national, local, Indigenous, territorial, or operational context. A statement about a jurisdiction shall not imply governmental endorsement, official public policy, regulatory approval, procurement approval, funding approval, public finance approval, emergency command, public warning, sovereign obligation, or official status unless supported by competent public authority record. Jurisdiction references shall distinguish where GCRI Canada is discussing location, law, public authority context, data residency, localization, risk context, or Nexus regional / national compatibility.

320.7 Public Authority Quote. A quote from a public authority official, employee, representative, participant, or advisor shall not be published unless the quote is accurate, authorized where required, attributed correctly, capacity-classified, context-preserving, and reviewed for public-safe meaning. Quote approval shall identify whether the quote is personal, official, institutional, event-based, learning-based, advisory, or limited. Public authority quotes shall not be edited in a way that creates endorsement, adoption, funding approval, procurement approval, public finance approval, regulatory approval, public warning, emergency command, or approval of GCRI Canada’s work beyond the authorized statement.

320.8 Public Authority Attendance Reference. Reference to public authority attendance at meetings, workshops, briefings, Academy sessions, consultations, listening sessions, demonstrations, controlled rooms, public authority rooms, public finance reader rooms, regulator-listening sessions, emergency-management learning sessions, or Nexus interface sessions shall be accurate, capacity-classified, and non-overclaiming. Attendance shall not imply endorsement, approval, adoption, partnership, funding, procurement, public finance approval, regulation, public warning, emergency command, data approval, official position, or public authority delegation. Attendance references may require approval where the public authority’s identity or role is not already public or where sensitivity exists.

320.9 Public Authority Photograph or Image Use. Photographs, screenshots, video stills, event images, meeting images, public authority facilities, public authority personnel, public authority logos, badges, uniforms, room displays, public authority documents, public dashboards, or public infrastructure settings shall not be published without review and permission where required. Image use shall address privacy, security, public authority sensitivity, infrastructure sensitivity, metadata, background information, protected knowledge, confidentiality, public-safe meaning, and non-endorsement. Images shall not be used to manufacture legitimacy or imply public authority approval.

320.10 Public Authority Data Contribution Reference. Reference to public authority data contribution shall require review of data-sharing terms, confidentiality, capacity classification, publication permission, attribution permission, public-safe status, public authority sensitivity, derived output rules, and correction obligations. A public authority data contribution shall not imply that the authority approves GCRI Canada’s analysis, endorses conclusions, authorizes public warning, adopts a dashboard, approves a map, validates a model, funds a project, approves procurement, approves finance-readiness, or assumes sovereign obligation.

320.11 Official Capacity Verification. Before publication represents public authority participation as official, GCRI Canada shall verify official capacity through a competent record. Official capacity verification may include written confirmation, agreement, public authority communication, approved quote, approved logo use, data-sharing agreement, meeting record, public authority authorization, or other reliable record. Where official capacity is not verified, publication shall use narrower language such as observer, participant, attendee, learner, reader, contributor, or other accurate capacity, and shall include non-endorsement language where necessary.

320.12 Attribution Permission. Attribution of public authority names, offices, titles, quotes, data contributions, photographs, logos, or attendance shall require permission where law, policy, agreement, confidentiality, context, or public-safe review requires it. Attribution permission shall identify approved wording, approved name, approved title, approved organization, approved context, approval date, duration, limitations, revocation rights where any, and correction path. Permission for one use shall not imply permission for another use, channel, publication, translation, derivative, sponsor material, provider material, media response, or Nexus interface.

320.13 Approved Public Language. GCRI Canada may require approved public language for references to public authorities. Approved public language shall be precise, limited, capacity-classified, non-endorsement-compliant, and aligned with public authority permissions. Approved language may state, for example, that a public authority participated in a learning session, attended as an observer, provided data under defined terms, received a briefing, contributed comments, or engaged in regulator-listening capacity, but shall not imply approval, adoption, funding, procurement, public finance approval, regulation, public warning, emergency command, or sovereign obligation unless expressly authorized.

320.14 Non-Endorsement Statement. Public authority references shall include a non-endorsement statement where necessary to prevent misinterpretation. The statement may clarify that reference to a public authority, official, attendance, data contribution, quote, or learning participation does not imply endorsement, approval, adoption, funding, procurement, regulation, public warning, emergency command, public finance approval, public-private partnership, sovereign obligation, or official position. Non-endorsement language shall be clear, proximate, and proportionate to the risk of misreading.

320.15 No Public Authority Approval, Adoption, Procurement, Funding, Regulation, Public Warning, or Sovereign Obligation by Reference. No reference to a public authority name, logo, title, agency, department, jurisdiction, quote, attendance, photograph, image, data contribution, review, comment, receipt of materials, learning participation, regulator-listening participation, public finance reader participation, emergency-management participation, infrastructure-operator participation, or public authority communication shall constitute or imply public authority approval, adoption, procurement, funding, regulation, public warning, emergency command, public finance approval, sovereign obligation, public authority delegation, official policy, public-private partnership, or endorsement unless a competent public authority record expressly authorizes that precise statement.

320.16 Correction of Misdescribed Public Authority Participation. Where GCRI Canada identifies that public authority participation, name use, logo use, title use, agency reference, quote, attendance, photograph, data contribution, jurisdiction reference, or approval status has been misdescribed, overstated, ambiguously stated, copied into sponsor or provider materials, used in media materials, or interpreted as endorsement, GCRI Canada shall correct the misdescription. Correction may include publication revision, public-safe clarification, removal of logo or quote, amended caption, amended attribution, direct notice, controlled notice, website update, social media correction, media correction, partner correction, sponsor correction, provider correction, dashboard note, map note, or withdrawal where necessary.

320.17 Public Authority Reference Records. GCRI Canada shall maintain public authority reference records, including public authority reference purpose records, name-use records, logo-use permissions, title-use records, agency or department reference records, jurisdiction reference records, quote approval records, attendance reference records, photograph and image-use records, data contribution reference records, official capacity verification records, attribution permission records, approved public language records, non-endorsement statement records, no-approval / no-adoption / no-procurement / no-funding / no-regulation / no-public-warning / no-sovereign-obligation records, correction records, notices, withdrawals, and archives.

Section 321. Finance-Readiness References, Non-Reliance, No Solicitation, No Capital Commitment, No Underwriting, No Insurance Approval, No Rating, and No Public Finance Approval

321.1 Finance-Readiness Reference Purpose. GCRI Canada may refer to finance-readiness, capital-readability, insurance-readiness-adjacent, public finance reader, proof pack, GRA interface, Nexus Rails, RNFD, NFD, UNFSD, or related financing-for-development concepts only for the limited purpose of describing technical evidence inputs, methods support, observability inputs, documentation structures, public-good learning, non-executing interface records, and boundary-controlled institutional coordination. Any such reference shall be framed as an evidence, methods, governance, or public-benefit communication and shall not be framed as regulated financial activity, investment promotion, securities offering, insurance placement, underwriting, rating, lending, guarantee, bankability determination, public finance approval, capital commitment, or solicitation. Finance-readiness references shall preserve GCRI Canada’s non-executing role, nonprofit character, public-benefit purpose, role separation from The Global Risks Alliance (GRA), Nexus Rails, capital readers, insurers, lenders, investors, public finance institutions, National Consortium Companies, Project SPVs, sponsors, providers, and public authorities, and shall remain subject to non-reliance and regulated-perimeter language.

321.2 Technical Evidence Input References. GCRI Canada may state that it contributes, maintains, reviews, or supports technical evidence inputs relevant to finance-readiness or capital-readability processes where such inputs are limited to evidence records, methods records, observability records, technical baselines, public-safe summaries, compute records, verifiable intelligence records, source lineage, confidence notes, limitation notes, and correction records. Technical evidence input references shall specify that GCRI Canada does not decide whether any project, asset, company, provider, host, consortium, National Consortium Company, Project SPV, infrastructure system, or technology is finance-ready, investable, bankable, insurable, underwritable, lendable, publicly financeable, rated, guaranteed, or suitable for capital allocation. Technical evidence shall be treated as one possible input to separate competent processes and shall not be represented as a capital decision.

321.3 GRA Interface References. References to The Global Risks Alliance (GRA) shall preserve institutional separateness and role separation. GCRI Canada may describe GRA-facing technical evidence inputs, documentation support, non-executing records, public-good baselines, interface notes, or correction signals where authorized, but shall not imply that GCRI Canada controls GRA, acts as GRA, makes GRA determinations, places capital, manages investor relationships, arranges insurance, approves underwriting, structures transactions, executes financing, or guarantees outcomes. GRA interface references shall state, where material, that GRA-related financing, alliance, capital, insurance, or public-private finance functions are separately governed and that GCRI Canada’s role remains evidence, methods, observability, ontology, technical baseline, public-good software, and correction support only.

321.4 Proof Pack References. GCRI Canada may refer to proof packs, assurance packs, evidence packs, technical packs, source packs, observability packs, compute packs, or public-safe proof artifacts only as organized records of evidence, methods, sources, limitations, confidence, review, classification, and correction. A proof pack shall not be described as conclusive proof, certification, accreditation, rating, investment memorandum, offering document, underwriting file, insurance approval, lender approval, public finance approval, procurement approval, recognition record, maturity determination, or guarantee. Proof pack references shall identify scope, version, limitations, permitted audience, public-safe status, dependency, correction path, and non-reliance language where material.

321.5 Insurance-Readiness Reference Controls. Insurance-readiness references shall be limited to technical evidence inputs, risk evidence structures, observability records, methods documentation, public-safe summaries, and boundary-controlled learning materials. GCRI Canada shall not state or imply that it approves insurance, places insurance, acts as broker, acts as agent, underwrites, prices risk, determines insurability, assesses coverage adequacy, issues loss estimates for underwriting reliance, recommends insurers, recommends insurance products, provides actuarial opinion, provides regulated insurance advice, or determines insurance-readiness. Any insurance-related reference shall include limitation language where reasonable readers could confuse technical evidence support with insurance approval or placement.

321.6 Capital-Reader Room Reference Controls. References to capital-reader rooms, finance reader rooms, investor reader rooms, public finance reader rooms, insurer reader rooms, lender reader rooms, or controlled finance-sensitive rooms shall specify that such rooms are controlled-access information environments, not solicitation forums, offering rooms, investment roadshows, securities distribution systems, broker-dealer rooms, insurance placement rooms, rating rooms, underwriting rooms, lending approval rooms, or public finance approval rooms. GCRI Canada may support technical evidence organization and public-benefit documentation in such rooms only within authorized boundaries, classification rules, access controls, non-reliance terms, confidentiality terms, finance-sensitive handling rules, and correction paths.

321.7 RNFD, NFD, and UNFSD Reference Controls. References to Regional Nexus Financing for Development, National Financing for Development, United Nations Financing for Sustainable Development, or any similarly named RNFD, NFD, UNFSD, blended finance, development finance, public finance, philanthropic finance, guarantee, concessional finance, or capital coordination concept shall be framed as public-good finance-readiness architecture where separately governed and not as GCRI Canada financing execution. GCRI Canada may contribute technical evidence inputs, public-good methods, observability records, public authority learning materials, and correction signals to such concepts where authorized, but shall not approve funding, allocate public finance, commit capital, endorse projects, certify eligibility, make investment recommendations, arrange transactions, or bind any public authority, funder, lender, insurer, investor, sponsor, or finance institution.

321.8 No Investment Advice. GCRI Canada shall not provide investment advice, securities advice, portfolio advice, asset allocation advice, investment suitability advice, buy / sell / hold recommendations, investor recommendations, capital allocation recommendations, valuation advice, return forecasts, investment ranking, investment diligence opinion, or regulated financial advice through any publication, proof pack, dashboard, map, report, dataset, technical baseline, public-safe summary, capital-reader room, GRA interface, Nexus Rails interface, RNFD / NFD / UNFSD reference, public authority learning material, or private communication. Any technical, evidence, risk, observability, or methods information that may be read by investors shall include non-reliance language proportionate to risk.

321.9 No Solicitation. No GCRI Canada publication, communication, report, proof pack, dataset, dashboard, map, website, deck, speech, press release, social media post, capital-reader room, public authority material, sponsor material, provider material, or Nexus interface material shall constitute or be used as a solicitation, offer, invitation, inducement, marketing of securities, fundraising solicitation, insurance solicitation, lending solicitation, capital placement, investor matchmaking, public finance request, guarantee request, or transaction promotion. GCRI Canada shall not allow its evidence or methods work to be repurposed as solicitation language by sponsors, providers, partners, National Consortium Companies, Project SPVs, or external actors without correction where identified.

321.10 No Securities Offering. No reference to finance-readiness, capital-readability, proof packs, Nexus Rails, GRA, RNFD, NFD, UNFSD, National Consortium Companies, Project SPVs, infrastructure projects, public-good assets, technical baselines, observability records, dashboards, or evidence packs shall constitute a securities offering, private placement memorandum, prospectus, offering circular, subscription document, token offering, investment contract, debt offering, equity offering, fund interest offering, or securities marketing material by GCRI Canada. Any securities-related activity, where separately lawful and undertaken by a separate competent entity, shall be separately governed and shall not be implied from GCRI Canada technical publications.

321.11 No Capital Commitment. GCRI Canada shall not state or imply that any investor, insurer, lender, public finance institution, donor, sponsor, funder, public authority, GRA actor, Nexus Rails actor, National Consortium Company, Project SPV, philanthropic institution, development finance institution, or capital reader has committed capital, agreed to finance, approved funding, endorsed finance-readiness, guaranteed financing, or accepted risk unless a competent record from the relevant actor expressly authorizes the precise statement. Attendance, review, data room access, reader-room participation, public finance reader participation, technical evidence review, or receipt of materials shall not constitute capital commitment.

321.12 No Underwriting. GCRI Canada shall not underwrite, approve underwriting, recommend underwriting, price underwriting risk, validate underwriting assumptions, approve underwriting files, represent insurability, determine creditworthiness, approve lender diligence, or act as underwriter, broker, agent, arranger, insurer, reinsurer, guarantor, lender, or rating analyst. Technical evidence may be made available to separate competent actors only with boundary language clarifying that GCRI Canada’s records are not underwriting decisions and shall not be relied upon as underwriting approval.

321.13 No Lending or Guarantee. GCRI Canada shall not make loans, approve loans, arrange loans, recommend loans, determine creditworthiness, issue guarantees, approve guarantees, recommend guarantees, commit public finance, approve concessional finance, bind lenders, bind guarantors, bind public finance institutions, or represent that any project, institution, provider, host, National Consortium Company, or Project SPV is eligible for lending or guarantee support. Any reference to lending or guarantee context shall be limited to public-good technical evidence inputs or finance-boundary literacy and shall include non-reliance language where material.

321.14 No Insurance Approval or Placement. GCRI Canada shall not approve insurance, place insurance, broker insurance, recommend insurance products, recommend insurers, bind coverage, determine premiums, issue coverage opinions, provide actuarial certification, determine insurability, or represent insurance-readiness as an approval. Insurance-related materials shall be treated as finance-sensitive evidence or public-good learning materials and shall be reviewed for insurance boundary language, non-reliance, confidentiality, data rights, protected knowledge, public authority terms, and correction path.

321.15 No Rating. GCRI Canada shall not issue credit ratings, insurance ratings, risk ratings for regulated reliance, investment ratings, project ratings, provider ratings, issuer ratings, public finance ratings, bond ratings, ESG ratings, maturity ratings, resilience ratings, safety ratings, security ratings, or any rating intended or reasonably likely to be used as regulated investment, lending, insurance, procurement, certification, public finance, or public authority approval. GCRI Canada may publish confidence notes, evidence classifications, method limitations, or maturity inputs only with clear language that such outputs are not ratings, guarantees, or regulated determinations.

321.16 No Public Finance Approval. GCRI Canada shall not approve public finance, public funding, public grants, public guarantees, public-private partnerships, concessions, public procurement, public authority budget commitments, sovereign obligations, municipal obligations, Crown entity obligations, development finance commitments, or public finance reader conclusions. Public finance references shall distinguish public authority learning, public finance reader participation, technical evidence review, and public-benefit discussion from any official public finance decision. No public authority shall be represented as approving finance by attending, reading, receiving, commenting on, or participating in GCRI Canada materials.

321.17 No Bankability or Investability Determination by GCRI Canada. GCRI Canada shall not determine that any project, asset, technology, host, provider, National Consortium Company, Project SPV, public-good infrastructure, digital infrastructure, AI-RAN / O-RAN deployment, DePIN system, observability node, sovereign compute facility, data trust, platform, climate or resilience project, or Nexus interface is bankable, investable, finance-ready, insurance-ready, public-finance-ready, underwritable, lendable, guaranteed, or capital-ready. Any such determination must be made, if at all, by a separate competent actor under separate authority and record. GCRI Canada may only identify technical evidence inputs and limitations.

321.18 Required Non-Reliance and Regulated-Perimeter Language. Finance-sensitive publications, proof packs, public-safe summaries, dashboards, maps, reader-room materials, GRA interface notes, Nexus Rails interface notes, RNFD / NFD / UNFSD references, sponsor-facing materials, provider-facing materials, public authority-facing materials, and capital-reader materials shall include non-reliance and regulated-perimeter language proportionate to risk. Such language shall state, where appropriate, that GCRI Canada does not provide investment advice, securities advice, insurance advice, underwriting approval, lending approval, public finance approval, rating, capital placement, investor matchmaking, solicitation, securities offering, bankability determination, finance-readiness determination, insurance-readiness determination, procurement approval, provider preference, public authority endorsement, or execution instruction, and that users must obtain their own legal, financial, insurance, tax, public finance, technical, and professional advice where applicable.

321.19 Finance-Readiness Reference Records. GCRI Canada shall maintain finance-readiness reference records, including finance-readiness purpose records, technical evidence input reference records, GRA interface reference records, proof pack records, insurance-readiness reference review records, capital-reader room records, RNFD / NFD / UNFSD reference records, no-investment-advice records, no-solicitation records, no-securities-offering records, no-capital-commitment records, no-underwriting records, no-lending-or-guarantee records, no-insurance-approval-or-placement records, no-rating records, no-public-finance-approval records, no-bankability-or-investability-determination records, required non-reliance language, regulated-perimeter language, corrections, withdrawals, clarifications, dependency reviews, and archives.


Section 322. Sponsor Acknowledgments, Provider References, Host References, and Partner References

322.1 Sponsor Acknowledgment Purpose. Sponsor acknowledgments may be used to recognize lawful support, funding, in-kind contribution, facility support, convening support, technical support, learning support, public-good support, or other recorded contribution to GCRI Canada’s public-benefit activities. Sponsor acknowledgments shall be accurate, proportionate, non-promotional where required, non-controlling, non-exclusive unless lawfully recorded, and shall not imply sponsor control, sponsor endorsement, research outcome purchase, public authority access purchase, recognition purchase, certification influence, finance-readiness influence, procurement advantage, provider preference, or institutional authority. Sponsor acknowledgment shall support transparency and public-benefit accountability, not private legitimacy transfer.

322.2 Provider Reference Purpose. Provider references may be used only to identify a provider’s factual role, technical contribution, service, tool, software, infrastructure, data, platform, cloud, AI, cyber, telecom, AI-RAN, O-RAN, DePIN, sensing, compute, dashboard, repository, professional service, or other contribution where such reference is accurate, authorized where required, and necessary for transparency, documentation, attribution, technical reproducibility, conflict disclosure, or public-good recordkeeping. Provider references shall not imply preference, certification, procurement approval, selection, ranking, endorsement, suitability, finance-readiness, public authority approval, or Nexus-approved status unless expressly supported by competent record and lawful authority.

322.3 Host Reference Purpose. Host references may identify institutions, facilities, universities, laboratories, public authorities, community organizations, infrastructure sites, data room hosts, controlled-room hosts, Observatory-supporting environments, Academy hosts, research hosts, public authority learning hosts, or technical testing hosts where such reference is accurate, authorized where required, public-safe, and consistent with host terms. Host references shall not imply that the host endorses GCRI Canada conclusions, grants public authority authority, approves procurement, selects providers, certifies systems, transfers assets, assumes liability, controls governance, or validates finance-readiness unless expressly authorized by competent record.

322.4 Partner Reference Purpose. Partner references may describe factual collaboration with universities, laboratories, public authorities, communities, sponsors, providers, hosts, consortiums, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, National Consortium Companies, Project SPVs, civil society organizations, or other actors where such collaboration is lawfully recorded and accurately described. Partner references shall preserve legal separateness, no agency, no merger, no shared treasury, no shared liability, no public authority delegation, no finance authority, no certification authority, no procurement authority, and no execution authority unless a separate lawful instrument expressly provides otherwise.

322.5 Contribution Record Requirement. No sponsor acknowledgment, provider reference, host reference, or partner reference shall be published unless a contribution record, engagement record, contract, agreement, meeting record, permission, correspondence, docket entry, or other competent record supports the factual statement. The contribution record shall identify contributor identity, capacity, contribution type, value or non-value description where appropriate, restrictions, benefits, approved language, conflicts, public authority involvement, data rights, IP rights, confidentiality, publication limits, and correction path. Informal goodwill, expectation, attendance, offer, draft discussion, or public association shall not substitute for contribution record.

322.6 Benefit Schedule Requirement Where Applicable. Where sponsors, donors, funders, providers, hosts, or partners receive acknowledgments, access rights, event visibility, logo placement, public mention, learning access, controlled material access, data room access, advisory participation, technical review participation, or other benefits, GCRI Canada shall maintain a benefit schedule where applicable. The benefit schedule shall define permitted benefits, prohibited benefits, value boundaries, public wording, non-control language, non-endorsement language, access limits, conflict controls, public authority limits, provider-neutrality protections, finance-boundary protections, certification-boundary protections, procurement-boundary protections, and correction rights.

322.7 Approved Acknowledgment Language. Sponsor, donor, funder, provider, host, and partner acknowledgments shall use approved language. Approved language shall be accurate, limited, non-misleading, non-promotional where required, role-specific, capacity-specific, public-safe, and consistent with contribution records, benefit schedules, contracts, public authority terms, protected knowledge safeguards, confidentiality, and conflict controls. Approved acknowledgment language may identify support, contribution, participation, hosting, collaboration, or learning role, but shall avoid words such as approved, certified, selected, preferred, endorsed, official, finance-ready, procurement-ready, recognized, validated, guaranteed, sovereign, public authority-approved, or Nexus-certified unless competent record expressly authorizes the precise use.

322.8 No Sponsor Control Implication. No sponsor acknowledgment shall imply that a sponsor controls, directs, approves, vetoes, suppresses, shapes, purchases, or owns GCRI Canada research, evidence, methods, public-good software, ontology, observability, technical baselines, publications, corrections, Board decisions, committee decisions, public authority interfaces, public-safe outputs, or Nexus interface records. Sponsor support shall be support-without-control. Any publication that may be read as sponsor-controlled shall include clarifying language and shall be corrected if misleading.

322.9 No Donor or Funder Control Implication. No donor or funder reference shall imply that a donor or funder controls governance, research conclusions, methods, evidence records, public-safe publication, public authority access, provider references, recognition, finance-readiness, certification, procurement, or Nexus interface meaning. Donor and funder restrictions may be honoured only to the extent lawful and consistent with GCRI Canada’s public-benefit purpose, nonprofit character, independence, public-safe obligations, correctionability, and anti-capture controls.

322.10 No Provider Preference Implication. No provider reference shall imply that a provider is preferred, selected, approved, certified, procurement-ready, finance-ready, public authority-ready, Nexus-compatible, Observatory-compatible, Grid-recognized, technically superior, safer, more secure, more resilient, or otherwise endorsed by GCRI Canada unless a separate competent record and lawful process expressly supports such limited statement. Provider references shall be factual, non-exclusive where appropriate, conflict-reviewed, and neutral. GCRI Canada shall not permit its publications to become provider marketing collateral through implication.

322.11 No Host Public Authority Endorsement Implication. Where a host is a public authority, public institution, university, laboratory, infrastructure operator, public facility, community body, or public-sector-adjacent institution, host references shall not imply public authority approval, public authority adoption, public funding approval, procurement approval, regulatory approval, public warning authority, emergency command, public finance approval, sovereign obligation, or official endorsement. Host references shall distinguish hosting, attendance, facility support, learning support, data contribution, and official approval.

322.12 No Partner Agency, Joint Venture, Partnership, or Shared Liability Implication. No partner reference shall imply legal partnership, agency, joint venture, merger, shared treasury, shared liability, fiduciary relationship, employer relationship, franchise, mandate, public authority delegation, execution vehicle, investment vehicle, procurement body, certification body, recognition authority, or finance authority unless a written legal instrument expressly creates such relationship and the publication accurately states its limits. The word “partner” shall be used carefully and, where needed, replaced with collaborator, participant, supporter, host, contributor, funder, technical contributor, observer, or other precise capacity term.

322.13 No Recognition Purchase, Finance-Readiness Influence, Procurement Advantage, Certification Influence, Public Authority Access, or Research Outcome Purchase. No sponsor, donor, funder, provider, host, or partner shall receive or be represented as receiving recognition, standing, maturity status, finance-readiness, insurance-readiness, investment suitability, bankability, public finance approval, procurement advantage, provider preference, certification influence, research conclusion influence, publication influence, public authority access, public authority endorsement, Nexus interface status, or GCRI Canada authority in exchange for money, in-kind support, services, data, technology, hosting, publicity, or participation. Any benefit that could be misread in such manner shall be rejected, narrowed, disclosed, or corrected.

322.14 Sponsor and Provider Claims Review. Sponsor and provider claims shall be reviewed before publication where they describe sponsor support, donor support, funder support, provider contribution, technical capability, host support, partner role, public authority adjacency, finance relevance, procurement relevance, certification relevance, recognition relevance, maturity relevance, Nexus compatibility, Observatory compatibility, Grid relevance, or public-good contribution. Review shall assess accuracy, contribution records, conflicts, benefit schedules, public authority risks, provider-neutrality risks, sponsor-control risks, finance-boundary risks, certification-boundary risks, procurement-boundary risks, public-safe language, and correction path.

322.15 Misuse Correction, Withdrawal, or Clarification. Where a sponsor, donor, funder, provider, host, partner, public authority, National Consortium Company, Project SPV, or external actor misuses a GCRI Canada reference, acknowledgment, logo, publication, technical claim, public authority reference, finance-readiness reference, certification-boundary statement, procurement-boundary statement, Nexus-compatible claim, or public-good asset, GCRI Canada may require correction, withdrawal, clarification, takedown, public-safe notice, controlled notice, license enforcement, trademark enforcement, access revocation, benefit suspension, contract review, or termination. Misuse correction shall be proportionate and recorded.

322.16 Sponsor, Provider, Host, and Partner Reference Records. GCRI Canada shall maintain sponsor, provider, host, and partner reference records, including sponsor acknowledgment records, provider reference records, host reference records, partner reference records, contribution records, benefit schedules, approved acknowledgment language, sponsor non-control reviews, donor and funder non-control reviews, provider-preference reviews, host public authority endorsement reviews, partner agency / joint venture / shared liability reviews, recognition purchase / finance-readiness influence / procurement advantage / certification influence / public authority access / research outcome purchase reviews, sponsor and provider claims reviews, misuse correction records, withdrawal records, clarification records, notices, takedowns, and archives.


Section 323. Public-Safe Maps, Geospatial Outputs, Infrastructure Sensitivity, Protected Knowledge, Vulnerable Communities, Cultural Sites, and Environmental Information

323.1 Public-Safe Mapping Purpose. GCRI Canada shall govern public-safe maps, geospatial outputs, spatial dashboards, Earth observation outputs, remote-sensing outputs, digital twin views, location-linked evidence, hazard maps, resilience maps, infrastructure maps, public authority maps, community maps, protected knowledge maps, environmental maps, AI-RAN / O-RAN / DePIN observability maps, sensor maps, and Nexus Observatory-related map products to ensure that geospatial communication advances public benefit without exposing persons, communities, protected knowledge, cultural sites, critical infrastructure, public authority-sensitive materials, cyber-physical dependencies, vulnerable locations, or unsafe operational details. Public-safe mapping shall be evidence-supported, method-bound, classified, redacted, limitation-bearing, public authority-safe, safeguards-safe, cyber-safe, infrastructure-safe, privacy-safe, finance-boundary-safe, and correctionable.

323.2 Geospatial Output Review. Geospatial outputs shall be reviewed before publication or external sharing. Review shall assess source, license, resolution, precision, date, update status, method, confidence, uncertainty, completeness, geocoding accuracy, location sensitivity, re-identification risk, small-cell risk, public authority terms, protected knowledge, infrastructure sensitivity, cyber-physical exposure, environmental sensitivity, community harm, health and safety risk, public-safe status, and correction path. Geospatial outputs shall not be released merely because source imagery, coordinates, or map layers are publicly available.

323.3 Infrastructure Sensitivity Review. Infrastructure sensitivity review shall be required where maps or geospatial outputs concern telecom systems, AI-RAN, O-RAN, DePIN, compute facilities, data centres, energy systems, water systems, food systems, health systems, ports, transport, public works, emergency management, cyber-physical systems, utilities, supply chains, digital twins, degraded-mode indicators, resilience gaps, dependencies, vulnerabilities, or mission-critical assets. Review shall identify whether aggregation, masking, delay, controlled access, or non-public treatment is required to reduce targeting, exploitation, disruption, or public authority confusion.

323.4 Critical Location Protection. GCRI Canada shall protect critical locations, including sensitive public facilities, critical infrastructure sites, community-protected sites, cultural sites, sacred sites, health facilities, shelters, emergency facilities, vulnerable community locations, telecom nodes, energy assets, water assets, ports, transport nodes, cyber facilities, compute facilities, sensors, AI-RAN / O-RAN assets, DePIN nodes, and other locations where disclosure could increase harm. Critical location protection may require removing coordinates, reducing precision, aggregating, generalizing, delaying publication, controlling access, or withholding publication.

323.5 Dependency and Vulnerability Protection. Maps and geospatial outputs shall not expose dependencies, vulnerabilities, weak points, degraded-mode conditions, cascading failure pathways, cyber-physical linkages, emergency response gaps, public authority sensitivities, infrastructure fragilities, or community vulnerabilities in a manner that materially increases risk. Where dependency or vulnerability information serves public-benefit learning, it shall be communicated through public-safe summaries, controlled annexes, aggregated views, or restricted rooms as appropriate.

323.6 Cyber-Physical Exposure Review. Cyber-physical exposure review shall be required where geospatial outputs combine cyber, telecom, sensor, AI-RAN, O-RAN, DePIN, digital twin, compute, infrastructure, public authority, or operational data in ways that reveal attack surfaces, network paths, device locations, telemetry patterns, control dependencies, physical access points, or disruption opportunities. Outputs with cyber-physical exposure shall be restricted or public-safe transformed before release.

323.7 Protected Knowledge Review. Protected knowledge review shall be required where maps or geospatial outputs involve Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, community-held knowledge, place-based knowledge, protected participation, or community-sensitive data. Such outputs shall respect custodial authority, consent or authorization, non-extraction, attribution limits, public-safe transformation, AI-use limits, publication limits, withdrawal rights, and correction rights.

323.8 Indigenous / Local / Territorial Knowledge Review. Indigenous / local / territorial knowledge review shall assess whether mapped information relates to lands, waters, territories, cultural resources, sacred sites, ecological knowledge, harvesting areas, linguistic knowledge, community routes, environmental stewardship, traditional use, local hazard memory, or territorial governance. Review shall determine whether publication is prohibited, restricted, generalized, delayed, anonymized, attributed, co-reviewed, or governed by a community or custodial protocol. GCRI Canada shall not convert place-based knowledge into open geospatial data without authority.

323.9 Cultural Site Protection. Cultural sites, sacred sites, heritage sites, burial sites, ceremonial sites, language-sensitive sites, archaeological sites, community gathering places, and other culturally sensitive locations shall not be mapped, named, precisely located, photographed, linked, inferred, or publicly described where disclosure may cause harm, appropriation, targeting, tourism pressure, desecration, extraction, stigmatization, or breach of custodial obligations. Cultural site protection shall override publication convenience and dashboard appeal.

323.10 Environmental Knowledge Protection. Environmental knowledge, including sensitive species locations, habitat information, water sources, ecological refugia, restoration areas, climate vulnerability, environmental hazards, resource-use locations, and community environmental observations, shall be reviewed before publication. Environmental knowledge protection shall prevent ecological harm, community harm, extraction, targeting, misinterpretation, protected knowledge exposure, public authority confusion, and false precision. Environmental maps shall include uncertainty and limitation language where material.

323.11 Vulnerable and Remote Community Protection. Maps and geospatial outputs involving vulnerable or remote communities shall be reviewed for small-population risk, re-identification, stigmatization, targeting, service access sensitivity, health sensitivity, public authority sensitivity, infrastructure fragility, cultural context, community autonomy, and public-safe mapping risk. GCRI Canada shall use aggregation, generalization, masking, delayed publication, controlled access, or non-public treatment where needed to prevent harm. Community vulnerability shall not be displayed for spectacle, fundraising optics, provider advantage, or sponsor value.

323.12 Health, Safety, and Security Review. Health, safety, and security review shall be required for maps involving health-sensitive locations, public health data, emergency management, public safety, shelters, vulnerable populations, hazardous sites, critical dependencies, cyber-physical systems, infrastructure exposure, environmental hazards, or public movement patterns. Review shall determine whether public release could cause panic, unsafe reliance, targeting, retaliation, misinformation, public authority confusion, or operational disruption.

323.13 Aggregation, Generalization, Masking, Obfuscation, or Redaction. GCRI Canada may require aggregation, generalization, masking, obfuscation, redaction, geospatial jittering, scale reduction, delayed publication, small-cell suppression, layer removal, metadata stripping, screenshot control, no-download treatment, or controlled access to make maps public-safe or externally shareable. Such transformations shall preserve meaningful public-benefit communication without creating false precision, false confidence, hidden bias, or misleading absence of risk. The transformation method shall be recorded where material.

323.14 Public Authority Boundary Review. Maps involving public authority data, public authority facilities, public authority personnel, emergency management, public health, public safety, public works, public infrastructure, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, or public-sector operational contexts shall undergo public authority boundary review. Review shall confirm that the map does not imply public authority approval, official map status, public warning, evacuation instruction, emergency command, regulatory decision, procurement approval, funding approval, public finance approval, or sovereign obligation unless expressly authorized by competent public authority record.

323.15 No Public-Safe Map as Official Warning, Evacuation Instruction, Emergency Command, Public Authority Decision, Procurement Approval, or Finance-Readiness Determination. No public-safe map, geospatial output, dashboard map, digital twin view, Observatory map, resilience map, degraded-mode awareness map, hazard map, infrastructure map, environmental map, community map, public authority learning map, or Nexus interface map published by GCRI Canada shall constitute or be represented as an official warning, evacuation instruction, emergency command, emergency declaration, public authority decision, regulatory action, public safety instruction, public health order, procurement approval, provider selection, certification, recognition, maturity determination, finance-readiness determination, insurance approval, investment recommendation, rating, public finance approval, or execution instruction. Required limitation language shall be included where needed.

323.16 Public-Safe Map Correction and Withdrawal. Where a public-safe map or geospatial output is inaccurate, stale, unsafe, over-precise, re-identifying, protected-knowledge-exposing, infrastructure-sensitive, cyber-sensitive, public authority-misdescribing, finance-overclaiming, certification-implying, procurement-implying, provider-favouring, community-harming, or otherwise inconsistent with public-safe publication rules, GCRI Canada shall correct, suppress, withdraw, reclassify, revise, generalize, mask, restrict, deprecate, or archive the map. Correction may include public-safe notice, controlled notice, dashboard note, map layer removal, metadata correction, source correction, limitation update, and downstream dependency review.

323.17 Public-Safe Map Records. GCRI Canada shall maintain public-safe map records, including mapping purpose records, geospatial output review records, infrastructure sensitivity review records, critical location protection records, dependency and vulnerability protection records, cyber-physical exposure review records, protected knowledge review records, Indigenous / local / territorial knowledge review records, cultural site protection records, environmental knowledge protection records, vulnerable and remote community protection records, health / safety / security review records, aggregation / generalization / masking / obfuscation / redaction records, public authority boundary review records, no-warning / no-command / no-public-authority-decision / no-procurement / no-finance-readiness records, correction records, withdrawal records, notices, and archives.


Section 324. Dashboards, Update Status, Data Sources, Limitations, Classification, Access Controls, Public-Safe Status, and Correction Path

324.1 Dashboard Governance Purpose. GCRI Canada shall govern dashboards, portals, observability displays, public-safe displays, controlled displays, map dashboards, technical status dashboards, evidence dashboards, public authority learning dashboards, AI-supported dashboards, Truth Engine dashboards, Nexus Observatory dashboards, Nexus Rails technical evidence dashboards, Nexus Grid input dashboards, and internal governance dashboards to ensure that displayed information is source-supported, method-bound, classified, limitation-bearing, secure, rights-respecting, public authority-safe, finance-boundary-safe, certification-boundary-safe, procurement-neutral, provider-neutral, sponsor-non-controlled, and correctionable. Dashboard governance shall prevent public misreliance, stale data reliance, false precision, hidden uncertainty, public authority confusion, cyber-sensitive disclosure, infrastructure-sensitive disclosure, protected knowledge exposure, and finance or certification overclaim.

324.2 Dashboard Classification. Each material dashboard shall be classified before use, release, or external sharing. Classification shall identify whether the dashboard is public, public-safe, controlled, restricted, internal, experimental, public authority-limited, safeguards-limited, cyber-limited, infrastructure-limited, finance-boundary-limited, no-download, room-only, archive-only, or another approved class. Dashboard classification shall determine data sources, access controls, refresh rules, publication status, output limits, permitted audience, prohibited use, limitation language, and correction path.

324.3 Public Dashboard. A public dashboard is a dashboard approved for unrestricted public access after public-safe, privacy, data / AI / cyber, public authority, safeguards, infrastructure, finance-boundary, certification-boundary, procurement-boundary, and legal review where required. Public dashboards shall display source summaries, update status, limitations, confidence or uncertainty indicators where material, public-safe language, correction path, and boundary language. Public dashboards shall not display restricted records, personal information, protected knowledge, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, or unsupported public authority references.

324.4 Controlled Dashboard. A controlled dashboard is a dashboard approved for a defined audience, room, data room, public authority room, capital-reader room, Board room, committee room, council room, research room, safeguards room, or technical review room. Controlled dashboards shall identify recipients, permitted use, prohibited use, access limits, redistribution limits, AI-use restrictions, download restrictions where applicable, update status, classification, limitations, correction path, and closeout obligations. Controlled dashboard access shall not authorize publication, external redistribution, public authority action, finance reliance, certification reliance, or procurement use beyond recorded authority.

324.5 Internal Dashboard. An internal dashboard is a dashboard approved only for internal governance, research, evidence review, technical development, security, privacy, operations, publication review, incident response, or administrative purposes. Internal dashboards shall not be treated as public-safe, public authority-facing, capital-reader-facing, sponsor-facing, provider-facing, or Nexus interface outputs unless reclassified and approved. Internal dashboard access shall remain role-based and purpose-bound.

324.6 Experimental Dashboard. An experimental dashboard is a prototype, sandbox, test, pilot, research, exploratory, model-evaluation, methods-evaluation, or proof-of-concept dashboard not approved for operational reliance or public meaning. Experimental dashboards shall be clearly labelled, access-controlled, limitation-bearing, and separated from public or production environments. Experimental dashboards shall use synthetic, dummy, de-identified, minimized, or approved test data where possible and shall not be shown externally as authoritative.

324.7 Dashboard Owner. Each material dashboard shall have a dashboard owner responsible for purpose, classification, public-safe status, source support, method support, update status, access posture, limitation language, boundary language, correction path, approval status, review cycle, deprecation, retirement, and archival. Dashboard ownership shall not itself authorize public release or external sharing without required approvals.

324.8 Dashboard Custodian. Each material dashboard may have a dashboard custodian responsible for configuration, access controls, data connections, refresh schedules, logging, technical maintenance, security, incident response support, backups, deactivation, and archival. Custodianship is technical stewardship and shall not create authority to alter public meaning, publish dashboards, approve public authority references, approve finance-boundary language, or release restricted data.

324.9 Dashboard Data Sources. Dashboard data sources shall be identified, classified, permissioned, and reviewed. Source records shall identify source owner, provenance, date, update cadence, license, permission, lawful basis, public authority terms, protected knowledge restrictions, data rights, AI-use restrictions, transformation steps, confidence, limitations, and correction path. Dashboards shall not combine sources in a manner that defeats source restrictions, creates re-identification, exposes protected knowledge, or implies unsupported conclusions.

324.10 Dashboard Update Status. Each material dashboard shall display or otherwise record update status, including current, delayed, stale, paused, experimental, superseded, deprecated, retired, unavailable, under review, incident-affected, or archive-only status where relevant. Update status shall be visible to users or recorded in controlled dashboard metadata. Stale or paused dashboards shall not be represented as current.

324.11 Dashboard Refresh Cadence. Each material dashboard shall identify refresh cadence, including real-time, near-real-time, daily, weekly, monthly, event-driven, manual, paused, historical, or irregular. Refresh cadence shall not be overstated. Where data is delayed, sampled, incomplete, manually updated, source-dependent, or subject to review, the dashboard shall disclose the limitation. Refresh cadence shall not imply emergency monitoring, public warning, operational control, or public authority duty.

324.12 Dashboard Limitations. Dashboard limitations shall identify source limitations, method limitations, data limitations, AI limitations, model limitations, transformation limitations, update limitations, geospatial limitations, confidence limitations, public authority limitations, protected knowledge limitations, privacy limitations, cyber limitations, infrastructure limitations, finance-boundary limitations, certification-boundary limitations, procurement-boundary limitations, and unsupported uses. Limitations shall be clear and proximate where users may rely on dashboard outputs.

324.13 Dashboard Confidence and Uncertainty Display. Dashboards shall display confidence and uncertainty where material to interpretation. Confidence and uncertainty display may include bands, flags, source quality notes, stale-data indicators, missing-data indicators, disputed-source indicators, model limitation notes, warning labels, review status, and not-for-reliance labels. Confidence indicators shall not be presented as ratings, guarantees, certifications, maturity status, finance-readiness, public authority approval, public warning, or procurement approval.

324.14 Dashboard Access Controls. Dashboard access shall be controlled according to classification and purpose. Controls may include role-based access, attribute-based access, named-user access, MFA, room-only access, no-download rules, watermarking, access logging, export limits, screenshot limits, query limits, API limits, time-limited access, public authority capacity rules, protected knowledge restrictions, finance-sensitive restrictions, and offboarding. Public dashboards shall be segregated from controlled and restricted dashboards.

324.15 Dashboard Public-Safe Status. Each dashboard shall identify public-safe status, including public-safe, public-safe after redaction, public-safe after aggregation, public-safe after delay, controlled only, restricted, internal-only, public authority-limited, safeguards-limited, cyber-limited, infrastructure-limited, finance-boundary-limited, experimental, or not suitable for external release. Public-safe status shall be reviewed when sources, methods, data, audience, refresh cadence, map layers, public authority references, AI components, or output meaning change.

324.16 Dashboard Correction Path. Each material dashboard shall include or record a correction path for errors, stale data, missing data, source changes, public authority corrections, protected knowledge concerns, privacy concerns, cyber-sensitive exposure, infrastructure-sensitive exposure, finance-boundary overclaim, certification-boundary overclaim, procurement implication, provider preference, sponsor influence, public-safe failure, AI hallucination, model drift, retrieval failure, or incident. Correction may include source update, refresh pause, dashboard note, layer suppression, access restriction, reclassification, withdrawal, public-safe notice, or archive.

324.17 Dashboard Incident Response. Dashboard incidents shall trigger response where a dashboard displays restricted information, personal information, protected knowledge, public authority-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, inaccurate claims, stale critical information, unsupported public authority references, finance overclaims, certification overclaims, procurement implications, provider preference, public warning confusion, or unsafe maps. Response may include containment, access restriction, dashboard disabling, layer removal, source review, public-safe review, notification review, correction, withdrawal, and post-incident review.

324.18 No Dashboard as Public Warning, Public Authority Decision, Finance-Readiness Determination, Certification, Procurement Approval, Recognition, or Maturity Guarantee. No dashboard produced, maintained, supported, referenced, or published by GCRI Canada shall constitute or be represented as public warning, emergency command, evacuation instruction, public authority decision, regulatory action, public health order, public safety instruction, procurement approval, provider selection, certification, accreditation, compliance approval, recognition, standing, maturity determination, Nexus Grid guarantee, finance-readiness determination, insurance approval, investment recommendation, underwriting approval, rating, public finance approval, or execution instruction. Dashboard outputs shall include limitation language where material.

324.19 Dashboard Records. GCRI Canada shall maintain dashboard records, including dashboard governance purpose records, dashboard classification records, public dashboard records, controlled dashboard records, internal dashboard records, experimental dashboard records, dashboard owner records, dashboard custodian records, dashboard data source records, update status records, refresh cadence records, limitation records, confidence and uncertainty display records, access control records, public-safe status records, correction path records, dashboard incident response records, no-warning / no-public-authority-decision / no-finance-readiness / no-certification / no-procurement / no-recognition / no-maturity-guarantee records, corrections, withdrawals, suppressions, deprecations, retirements, and archives.


Section 325. AI-Generated and AI-Assisted External Content

325.1 AI-Generated Content Purpose. GCRI Canada may use AI-generated content only where such use supports public-benefit communication, evidence literacy, methods communication, drafting support, translation support, accessibility, technical documentation, public-safe summarization, software documentation, research assistance, learning materials, or other approved purposes consistent with GCRI Canada’s public-benefit purpose, non-execution boundary, data / AI / cyber controls, privacy obligations, protected knowledge safeguards, public authority boundaries, finance-boundary discipline, certification-boundary discipline, procurement neutrality, provider neutrality, sponsor support-without-control, and correctionability. AI-generated content shall not be treated as institutionally authoritative merely because it is fluent, polished, efficient, or plausible.

325.2 AI-Assisted Content Purpose. AI-assisted content may include content drafted, summarized, translated, edited, formatted, classified, checked, compared, searched, cited, structured, visualized, coded, or otherwise supported by AI systems. AI assistance may improve speed, accessibility, consistency, and technical organization, but shall not replace human accountability, evidence verification, methods review, public-safe review, legal review, public authority boundary review, safeguards review, data / AI / cyber review, finance-boundary review, certification-boundary review, procurement-boundary review, or final publication approval where required. AI assistance shall be governed as a tool, not as an authority.

325.3 Human Accountability Requirement. Every external AI-generated or AI-assisted publication, statement, response, report, article, deck, website text, public authority material, public-safe summary, dashboard text, map note, software documentation, technical baseline, public-good software release note, press release, media response, social media post, or Nexus interface communication shall have a human owner accountable for its accuracy, evidence support, public-safe status, limitation language, boundary language, confidentiality, rights compliance, and correction path. Human accountability shall not be displaced by provider terms, model outputs, automation, agentic workflows, or AI confidence indicators.

325.4 Human Review Requirement. External AI-generated or AI-assisted content shall undergo human review proportionate to risk before release. Human review shall assess factual accuracy, source support, method support, citation integrity, hallucination risk, public authority references, sponsor references, provider references, finance implications, certification implications, procurement implications, recognition implications, maturity implications, privacy, protected knowledge, cyber sensitivity, infrastructure sensitivity, tone, accessibility, controlled vocabulary, limitation language, and correction path. High-risk content shall receive heightened review and may require Board, officer, committee, legal, data / AI / cyber, public authority, finance-boundary, or safeguards review.

325.5 Evidence Verification Requirement. AI-generated or AI-assisted content that makes factual, technical, scientific, legal-adjacent, public authority, finance-boundary, certification-boundary, procurement-boundary, recognition-boundary, maturity-boundary, research, evidence, methods, observability, AI, cyber, geospatial, public-good software, or Nexus-compatible claims shall be verified against competent evidence records before release. AI output shall not be accepted as evidence, source, method, citation, authority, or record merely because it provides a confident answer. Unsupported AI-generated claims shall be removed, qualified, corrected, or converted into internal questions for review.

325.6 Citation and Source Verification Requirement Where Applicable. Where AI-generated or AI-assisted content includes citations, quotations, links, references, case names, statutes, regulations, public authority statements, research sources, technical documentation, repository references, model cards, dataset cards, system cards, standards, public-good baseline references, or Nexus interface references, each source shall be verified for existence, accuracy, relevance, version, date, permission, quotation accuracy, and public-safe suitability where applicable. Fabricated, stale, misquoted, misattributed, irrelevant, or unsupported citations shall be treated as AI incidents or publication incidents where material.

325.7 Fabrication and Hallucination Review. AI-generated or AI-assisted content shall be reviewed for fabrication and hallucination, including invented facts, invented citations, invented public authority positions, invented sponsor or provider roles, invented legal requirements, invented finance-readiness status, invented certification status, invented procurement status, invented recognition status, invented maturity status, invented technical capabilities, invented benchmark results, invented model performance, invented source lineage, invented public warning status, or invented Nexus compatibility. Fabrication and hallucination shall trigger correction, source review, reviewer notice where appropriate, incident classification where material, and downstream dependency review.

325.8 Confidentiality Review. AI-generated or AI-assisted external content shall be reviewed to ensure it does not disclose confidential information, Board materials, committee materials, council materials, public authority-sensitive information, protected knowledge, personal information, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive evidence, legal privilege, commercial sensitivity, controlled-room materials, no-download-room materials, sponsor confidential information, provider confidential information, host confidential information, or partner confidential information. Confidentiality review shall include review of prompts, retrieved context, outputs, citations, examples, metadata, attachments, screenshots, and hidden content where relevant.

325.9 Data Leakage Review. AI-generated or AI-assisted external content shall be reviewed for data leakage, including leakage through summaries, examples, citations, source names, metadata, embeddings, retrieval traces, prompt residue, internal instructions, hidden context, personal information, protected knowledge, public authority records, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, controlled-room content, no-download-room content, repository paths, credentials, secrets, or model-generated reconstruction. Data leakage shall trigger containment, correction, publication hold, incident review, and notification review where required.

325.10 Public Authority Reference Review. AI-generated or AI-assisted content that mentions public authorities, public authority personnel, titles, agencies, departments, municipalities, ministries, Crown entities, regulators, emergency management bodies, public finance bodies, public infrastructure operators, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, public authority data, public authority quotes, attendance, photographs, or public authority participation shall undergo public authority reference review. Review shall verify capacity, permission, attribution, non-endorsement, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, and no-sovereign-obligation language.

325.11 Finance, Certification, Procurement, Recognition, and Public Warning Boundary Review. AI-generated or AI-assisted content shall undergo boundary review where it could imply finance-readiness, insurance-readiness, investment suitability, bankability, underwriting approval, lending approval, public finance approval, rating, capital placement, investor matchmaking, certification, accreditation, compliance approval, procurement approval, provider preference, recognition, standing, maturity, Nexus Grid status, GRF recognition, public warning, emergency command, public authority decision, or execution instruction. Boundary review shall add limitation language, revise claims, remove claims, or prevent release where necessary.

325.12 Protected Knowledge and Community Safeguards Review. AI-generated or AI-assisted content involving communities, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred sites, remote communities, vulnerable communities, protected participants, youth, health-sensitive communities, community vulnerability, public-safe mapping, or protected knowledge shall undergo safeguards review. Review shall assess consent or authorization, custodial authority, attribution, non-extraction, withdrawal rights, correction rights, re-identification risk, geospatial sensitivity, decontextualization, stigmatization, AI-generated distortion, and public-safe language.

325.13 Disclosure of AI Use Where Required or Appropriate. GCRI Canada shall disclose AI use where required by law, public authority terms, research integrity, publication policy, ethics review, funder requirements, platform rules, professional norms, or where disclosure is appropriate to preserve trust, transparency, accountability, or public-safe meaning. Disclosure may state that AI tools assisted with drafting, editing, translation, summarization, coding, formatting, or accessibility, while confirming that human review, evidence verification, and publication approval remain GCRI Canada responsibilities. Disclosure shall not overstate AI capability or imply AI authority.

325.14 No External Publication Directly From Unreviewed AI Output. No AI output shall be published externally, sent to public authorities, posted publicly, placed in a repository, included in a report, added to a dashboard, displayed on a map, distributed to sponsors, distributed to providers, used in capital-reader rooms, used in Academy materials, or issued as a public statement without required human review, evidence verification, confidentiality review, public-safe review, boundary review, and publication approval. Automated publication from AI systems shall be prohibited unless a separately approved workflow includes controls sufficient for the publication class and risk.

325.15 No AI-Generated Legal, Finance, Insurance, Engineering, Clinical, Rating, Public Authority, or Emergency Instruction by Default. AI-generated or AI-assisted content shall not be represented as legal advice, financial advice, securities advice, investment advice, insurance advice, underwriting advice, lending advice, accounting advice, tax advice, engineering opinion, clinical opinion, rating, public authority decision, public warning, emergency command, emergency instruction, procurement approval, certification, regulatory approval, compliance approval, or execution instruction by default. Any content touching these domains shall be framed as general information, evidence support, methods support, public-good learning, or draft material unless separately reviewed and authorized by competent professionals or authorities where lawful.

325.16 AI-Assisted Content Records. GCRI Canada shall maintain AI-assisted content records, including AI-generated content purpose records, AI-assisted content purpose records, human accountability records, human review records, evidence verification records, citation and source verification records, fabrication and hallucination review records, confidentiality review records, data leakage review records, public authority reference review records, finance / certification / procurement / recognition / public warning boundary review records, protected knowledge and community safeguards review records, AI-use disclosure records, unreviewed AI output prevention records, regulated-professional and emergency-instruction boundary records, corrections, publication holds, withdrawals, retractions, incident records, and archives.

Section 326. Websites, Articles, Social Media, Speeches, Media Responses, Decks, Public Reports, Whitepapers, Datasets, Software Releases, and Public Dashboards

326.1 Website Governance. GCRI Canada shall govern websites, webpages, landing pages, public microsites, publication pages, repository pages, dashboard pages, Academy pages, event pages, public authority learning pages, sponsor acknowledgment pages, provider reference pages, public-good software pages, technical baseline pages, public-safe map pages, and Nexus interface pages as official or semi-official publication environments according to their classification, purpose, audience, evidence support, approval status, security posture, accessibility, versioning, public-safe status, and correction path. Website materials shall be maintained in a manner that preserves public-benefit purpose, controlled vocabulary, non-execution, role separation, public authority boundary language, finance-boundary language, certification-boundary language, procurement-neutrality language, provider-neutrality language, sponsor non-control language, privacy, data / AI / cyber safety, protected knowledge safeguards, and correctionability. Website publication shall not be treated as informal merely because it is easy to update or presented in short form.

326.2 Article Governance. Articles, essays, public notes, thought pieces, technical explainers, opinion-adjacent materials, public authority learning pieces, research summaries, Academy articles, Nexus-compatible explainers, and public-good commentary issued by or attributed to GCRI Canada shall be reviewed for accuracy, evidence support, methods support, controlled vocabulary, role separation, limitations, public-safe content, sponsor and provider neutrality, public authority references, finance and certification boundaries, and correction path. Articles shall clearly distinguish institutional position, author view, research interpretation, evidence summary, educational explanation, discussion draft, and public-safe summary. No article shall be used to imply public authority approval, emergency guidance, finance-readiness, certification, procurement approval, provider preference, recognition, maturity, or execution authority unless a competent record separately and lawfully supports the precise statement.

326.3 Social Media Governance. Social media posts, short-form updates, reposts, replies, comments, captions, threads, public acknowledgments, event notices, publication announcements, public-safe summaries, image cards, video clips, and other platform-native communications shall be treated as public publications of GCRI Canada when issued through official channels or by authorized persons in an official capacity. Social media governance shall require concise accuracy, source alignment, approved language for institutional claims, avoidance of overstatement, public authority reference controls, sponsor and provider reference controls, no-regulated-advice language where appropriate, accessibility where feasible, and rapid correction procedures. Social media shall not be used to bypass publication approval, legal review, public-safe review, public authority review, protected knowledge review, or finance / certification / procurement boundary review.

326.4 Speech and Presentation Governance. Speeches, remarks, keynote materials, panel remarks, training presentations, Academy presentations, public authority learning presentations, consortium presentations, community-facing presentations, sponsor-facing presentations, provider-facing presentations, and Nexus interface presentations shall be governed as publications where they communicate GCRI Canada positions, evidence, methods, baselines, public authority references, finance-boundary concepts, technical claims, or public-safe outputs. Speech and presentation materials shall be reviewed according to audience, sensitivity, recording status, distribution status, public authority presence, media presence, sponsor or provider presence, public-safe risk, and whether slides or transcripts will be distributed. Oral remarks shall not expand beyond approved institutional meaning where high-risk matters are involved.

326.5 Media Response Governance. Media responses, journalist statements, background briefings, attributed quotes, unattributed briefings, written responses, fact sheets, Q&A documents, interviews, podcasts, video appearances, broadcast appearances, and rapid responses shall be governed through authorized spokesperson and publication controls. Media responses shall be accurate, limited to approved scope, public-safe, evidence-supported, and boundary-protected. GCRI Canada shall avoid speculation, unsupported attribution, public authority misdescription, finance overclaim, certification implication, procurement implication, provider preference, sponsor control implication, protected knowledge exposure, cyber-sensitive disclosure, infrastructure-sensitive disclosure, or emergency-command language in media contexts.

326.6 Public Deck Governance. Public decks, slide presentations, speaker decks, briefing decks, Academy decks, public authority learning decks, sponsor-facing decks, provider-facing decks, conference decks, webinar decks, and Nexus-compatible explanatory decks shall be classified, versioned, reviewed, and approved before external use. Deck governance shall address titles, graphics, icons, maps, dashboard screenshots, public authority logos, sponsor logos, provider references, technical claims, evidence summaries, finance-boundary language, certification-boundary language, procurement-boundary language, limitations, citations where appropriate, export-control issues, redactions, and correction path. A deck shall not become an offering document, public warning, procurement document, certification package, finance-readiness document, or public authority decision merely by format or audience.

326.7 Public Report Governance. Public reports shall be governed as high-reliance publications where they communicate institutional findings, evidence synthesis, methods, risk evidence, observability outputs, public-good baselines, public authority learning, Nexus interface analysis, or public-safe intelligence. Public reports shall require appropriate evidence records, methods records, source lineage, reviewer notes, public-safe classification, legal review where required, data / AI / cyber / privacy review where required, public authority boundary review where required, safeguards review where required, finance / certification / procurement / recognition / public warning boundary review where required, approval records, publication date, version, limitations, and correction path. Public reports shall be written to prevent reasonable misreliance.

326.8 Whitepaper Governance. Whitepapers shall be governed as institutional or technical publications that may shape public understanding, public authority learning, market interpretation, technical implementation, public-good baselines, or Nexus-compatible architecture. Whitepaper governance shall require clear status language, including whether the document is a discussion paper, consultation draft, technical note, methods note, public-good baseline, public-safe summary, final publication, superseded output, or controlled summary. Whitepapers shall include appropriate limitations, non-reliance language, evidence support, methods support, public authority boundary language, finance-boundary language, certification-boundary language, procurement-boundary language, provider-neutrality language, sponsor non-control language, and correction path.

326.9 Dataset Release Governance. Public or external dataset releases shall require data rights review, privacy review, public-safe review, protected knowledge review, public authority review where applicable, license review, metadata review, de-identification or aggregation review where applicable, re-identification risk review, documentation, dataset card, versioning, retention and deletion language, permitted-use terms, prohibited-use terms, AI-use terms, model-training restrictions where applicable, citation guidance, limitation language, and correction path. Dataset release shall not imply completeness, accuracy guarantee, public authority approval, research conclusion, certification, finance-readiness, procurement approval, provider preference, or public warning status.

326.10 Software Release Governance. Software releases, public-good software packages, scripts, APIs, SDKs, schemas, reference implementations, technical tools, dashboards, test harnesses, benchmark tools, public-safe publication tools, Observatory-supporting tools, Truth Engine-supporting tools, and verifiable compute tools shall be governed by release authorization, repository controls, licensing, dependency review, security review, secrets scanning, SBOM where appropriate, documentation, known issues, public-safe review, versioning, release notes, no-warranty language, no-certification language, no-procurement language, no-finance-readiness language, no-public-authority-approval language, contribution rules, vulnerability disclosure path, and correction path. Software release shall not make GCRI Canada an operator, managed service provider, certifier, procurement authority, public authority, or guarantor.

326.11 Public Dashboard Governance. Public dashboards shall be governed as public-safe publication environments requiring source records, method records, classification, public-safe status, update status, refresh cadence, confidence and uncertainty display where material, limitations, accessibility, privacy review, protected knowledge review, public authority review where applicable, cyber and infrastructure review where applicable, finance-boundary review where applicable, and correction path. Public dashboards shall be designed to prevent false precision, stale-data reliance, public authority confusion, emergency-command confusion, public warning confusion, finance-readiness overclaim, certification implication, procurement implication, provider preference, sponsor benefit, or unsupported public meaning.

326.12 Public Repository Governance. Public repositories shall be governed as public disclosure environments. Before material is placed in a public repository, GCRI Canada shall review for PII, protected knowledge, public authority-sensitive information, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, credentials, secrets, confidential information, license conflicts, export-control issues, sanctions-sensitive materials, public-safe status, documentation accuracy, contribution terms, issue templates, security policy, and correction path. Public repositories shall not contain controlled-room materials, no-download-room materials, restricted datasets, unreviewed AI outputs, internal deliberations, or materials whose public release would undermine GCRI Canada’s public-benefit purpose or safeguards obligations.

326.13 Public Event Material Governance. Public event materials, including agendas, speaker lists, biographies, programs, badges, recordings, transcripts, slides, handouts, event pages, promotional materials, photographs, videos, sponsor acknowledgments, public authority references, provider references, host references, and post-event summaries, shall be reviewed according to public-safe publication rules. Event materials shall distinguish attendance, speaking, sponsorship, hosting, learning participation, public authority participation, provider participation, advisory participation, and institutional approval. Public event materials shall not imply endorsement, procurement approval, finance-readiness, certification, recognition, maturity, public authority adoption, or public-private partnership unless a competent record supports the precise statement.

326.14 Public Authority-Facing Material Governance. Materials prepared for public authorities, regulators, ministries, municipalities, Crown entities, emergency management bodies, public finance readers, public infrastructure operators, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, or public-sector learning audiences shall be classified and reviewed for public authority boundaries. Such materials shall make clear that GCRI Canada provides public-good evidence, methods, learning, observability, ontology, technical baseline, software, or correction support only, and does not issue public warnings, emergency commands, regulatory approvals, procurement approvals, funding approvals, public finance approvals, sovereign obligations, or public authority decisions. Public authority-facing materials may be controlled even where derived from public information.

326.15 Sponsor-Facing and Provider-Facing Material Governance. Sponsor-facing and provider-facing materials shall be reviewed to prevent sponsor control implication, provider preference, improper private benefit, research outcome purchase, public authority access purchase, finance-readiness influence, certification influence, procurement advantage, recognition purchase, maturity implication, or Nexus-compatible overclaim. Such materials may describe public-benefit purpose, contribution opportunities, lawful support terms, technical collaboration scope, public-good asset stewardship, non-control requirements, conflicts, permitted acknowledgments, and prohibited benefits. Sponsor-facing and provider-facing materials shall not promise outcomes, access, status, recognition, procurement positioning, finance-readiness, certification, public authority influence, or favourable publication treatment.

326.16 Investor-Facing or Capital-Reader Material Boundary Review. Investor-facing, insurer-facing, lender-facing, public finance reader-facing, capital-reader, guarantee-reader, development finance, philanthropic finance, blended finance, Nexus Rails, GRA interface, RNFD, NFD, UNFSD, National Consortium Company, or Project SPV-adjacent materials shall undergo regulated-perimeter boundary review. Such materials shall include non-reliance language, no-investment-advice language, no-solicitation language, no-securities-offering language, no-capital-commitment language, no-underwriting language, no-lending-or-guarantee language, no-insurance-approval language, no-rating language, no-public-finance-approval language, and no-bankability-determination language where material. GCRI Canada may provide technical evidence inputs and methods support only within recorded authority.

326.17 Publication Calendar, Embargo, Approval, and Release Controls. GCRI Canada may maintain a publication calendar and release control process for websites, articles, social media, speeches, media responses, decks, public reports, whitepapers, datasets, software releases, dashboards, repositories, public event materials, public authority-facing materials, sponsor-facing materials, provider-facing materials, and capital-reader materials. Release controls shall identify owner, reviewers, approver, intended audience, publication class, embargo, release date, channel, required disclaimers, version, archive copy, public-safe status, dependency review, and correction path. Embargoes and release schedules shall not be used to manipulate public authority meaning, finance markets, procurement processes, provider advantage, sponsor value, or public interpretation.

326.18 Output-Specific Records. GCRI Canada shall maintain output-specific records, including website governance records, article records, social media records, speech and presentation records, media response records, public deck records, public report records, whitepaper records, dataset release records, software release records, public dashboard records, public repository records, public event material records, public authority-facing material records, sponsor-facing and provider-facing material records, investor-facing and capital-reader boundary review records, publication calendar records, embargo records, approval records, release records, versions, corrections, withdrawals, supersessions, retractions, clarifications, and archives.


Section 327. Required Disclaimers and Boundary Language

327.1 Disclaimer Purpose. GCRI Canada shall use disclaimers and boundary language to prevent misunderstanding of its public-benefit, nonprofit, non-executing, evidence, methods, observability, ontology, public-good software, open technical baseline, public-safe publication, and Nexus-compatible support role. Disclaimers shall be clear, proximate, proportionate to risk, audience-appropriate, and consistent with the substance of the publication. Disclaimers shall not be used to excuse inaccurate claims, unsupported claims, unsafe publication, privacy breaches, protected knowledge misuse, public authority misdescription, finance overclaim, certification overclaim, procurement implication, provider preference, sponsor control, or deficient review.

327.2 Non-Execution Disclaimer. Where material, GCRI Canada publications shall state that GCRI Canada is a non-executing public-benefit institution and does not operate, manage, command, deploy, procure, finance, insure, underwrite, certify, accredit, regulate, control, or implement projects, infrastructure systems, emergency responses, public authority functions, providers, National Consortium Companies, Project SPVs, or Nexus execution vehicles. Non-execution language shall be included where readers could confuse evidence, methods, observability, dashboards, maps, technical baselines, software, or interface records with execution instructions or operational responsibility.

327.3 Non-Public-Warning Disclaimer. Where publications, dashboards, maps, observability outputs, degraded-mode indicators, resilience indicators, risk summaries, public-safe intelligence outputs, or public authority learning materials could be mistaken for public warnings, GCRI Canada shall state that the material is not an official public warning, public alert, public safety instruction, public health order, evacuation notice, emergency bulletin, or public authority notice. Such language shall not prevent GCRI Canada from issuing public-safe corrections or public-benefit educational materials, but it shall prevent misreliance as an official warning system.

327.4 Non-Emergency-Command Disclaimer. Where materials concern hazards, resilience, observability, degraded-mode awareness, emergency management, public safety, public health, infrastructure disruption, cyber incidents, environmental conditions, or crisis communication, GCRI Canada shall state, where material, that it does not exercise emergency command, incident command, public safety command, public health command, infrastructure command, public authority command, dispatch authority, operational control, or responder direction. Materials shall direct readers to competent public authorities for official emergency instructions where appropriate.

327.5 Non-Regulatory Disclaimer. Where materials discuss laws, regulations, public authority concepts, compliance frameworks, standards, public procurement, public safety, public health, cyber rules, telecom rules, environmental rules, finance rules, insurance rules, or governance concepts, GCRI Canada shall state where material that the material is not regulatory approval, legal compliance determination, public authority interpretation, legal advice, enforcement action, official guidance, or substitute for competent professional or public authority advice. GCRI Canada may provide technical, educational, and methods-oriented materials without assuming regulatory authority.

327.6 Non-Certification Disclaimer. Where materials describe baselines, methods, software, dashboards, maps, technical profiles, test harnesses, benchmark results, evidence packs, Observatory methods, Truth Engine outputs, verifiable compute outputs, AI governance, cybersecurity, data governance, or interoperability, GCRI Canada shall state where material that the material does not constitute certification, accreditation, conformity assessment, compliance approval, product approval, provider approval, system approval, safety approval, cybersecurity certification, AI certification, Observatory certification, Nexus certification, or performance assurance. Use of GCRI Canada materials shall not create certification.

327.7 Non-Procurement Disclaimer. Where publications could be read as influencing procurement, vendor selection, tender eligibility, preferred provider status, purchasing, public-sector eligibility, or contract award, GCRI Canada shall state that the material is not procurement approval, procurement advice, tender requirement, vendor qualification, provider selection, preferred provider designation, purchasing recommendation, or public-sector contract condition. Public authorities and other purchasers remain solely responsible for their own lawful procurement processes.

327.8 Non-Finance Disclaimer. Where materials could be read as finance-readiness, capital-readability, insurance-readiness, bankability, investability, underwriting, lending, guarantee, rating, public finance, or capital placement material, GCRI Canada shall state that it does not determine finance-readiness, insurance-readiness, bankability, investability, creditworthiness, lendability, public finance eligibility, capital readiness, or transaction suitability. Any technical evidence input shall be non-executing, non-reliance, and subject to separate review by competent actors.

327.9 Non-Investment-Advice Disclaimer. Where materials may be read by investors, funders, lenders, insurers, sponsors, public finance readers, capital readers, or transaction participants, GCRI Canada shall state that the material is not investment advice, securities advice, financial advice, tax advice, accounting advice, portfolio advice, buy / sell / hold recommendation, valuation opinion, offering document, solicitation, or investment recommendation. Readers shall be directed, where appropriate, to obtain their own professional advice and conduct their own diligence.

327.10 Non-Insurance Disclaimer. Where materials discuss insurance, risk transfer, risk evidence, resilience, loss, exposure, insurability, insurance-readiness, underwriting-adjacent evidence, or insurer reader rooms, GCRI Canada shall state that the material is not insurance advice, insurance placement, brokerage, underwriting approval, coverage advice, premium determination, actuarial opinion, insurance recommendation, or confirmation of insurability. Technical evidence support shall not be treated as insurance approval.

327.11 Non-Rating Disclaimer. Where materials include confidence bands, evidence classifications, risk categories, maturity inputs, benchmark outputs, resilience indicators, dashboard indicators, provider-neutral comparisons, or public-good technical assessments, GCRI Canada shall state where material that such outputs are not ratings, credit ratings, investment ratings, insurance ratings, issuer ratings, project ratings, provider ratings, resilience ratings for regulated reliance, public finance ratings, or performance guarantees.

327.12 Non-Public-Finance-Approval Disclaimer. Where materials concern public finance, development finance, blended finance, philanthropic finance, guarantees, public finance readers, RNFD, NFD, UNFSD, GRA interfaces, Nexus Rails interfaces, National Consortium Companies, or Project SPVs, GCRI Canada shall state that the material is not public finance approval, grant approval, government funding approval, guarantee approval, concession approval, public-private partnership approval, budget commitment, sovereign obligation, municipal obligation, Crown entity obligation, development finance commitment, or public authority funding decision.

327.13 Public Authority Non-Endorsement Disclaimer. Where public authority names, titles, logos, attendance, data contributions, comments, photographs, quotes, or participation appear, GCRI Canada shall state where material that such reference does not imply endorsement, approval, adoption, funding, procurement, regulation, public warning, emergency command, public finance approval, official position, public-private partnership, sovereign obligation, or delegation of public authority unless expressly stated by competent public authority record.

327.14 Sponsor and Provider Non-Control Disclaimer. Where sponsors, donors, funders, providers, hosts, or partners are acknowledged or referenced, GCRI Canada shall state where material that support, contribution, participation, hosting, or collaboration does not confer control over governance, research conclusions, evidence, methods, publications, public authority access, certification, recognition, procurement, finance-readiness, provider preference, or Nexus interface status. Sponsor support shall remain support-without-control and provider participation shall remain provider-neutral.

327.15 AI Limitation Disclaimer. Where materials rely on, include, summarize, or disclose AI-generated or AI-assisted content, model outputs, retrieval outputs, inference outputs, automated classification, embeddings, agentic workflows, or AI-supported dashboards, GCRI Canada shall include AI limitation language where material. Such language may state that AI outputs are subject to error, hallucination, bias, drift, source limitations, retrieval failure, model limitations, and human review requirements, and that AI outputs do not constitute official authority, professional advice, certification, public warning, finance-readiness, public authority decision, or execution instruction.

327.16 Digital Twin Limitation Disclaimer. Where digital twins, simulations, models, synthetic environments, scenario tools, geospatial models, infrastructure models, climate models, risk models, or system models are referenced, GCRI Canada shall state where material that such outputs are simplified, assumption-dependent, data-dependent, uncertainty-bearing, version-specific, and not identical to the real world. Digital twin outputs shall not be represented as operational instructions, public authority decisions, engineering approvals, emergency commands, finance-readiness determinations, insurance approvals, procurement approvals, or performance guarantees.

327.17 Dashboard and Map Limitation Disclaimer. Dashboards and maps shall include limitation language where material, including data source limits, update cadence, stale data, missing data, confidence, uncertainty, aggregation, redaction, geospatial generalization, public-safe transformation, public authority boundaries, protected knowledge limits, cyber and infrastructure sensitivity, and correction path. Dashboard and map limitation language shall state where appropriate that the output is not an official warning, emergency command, public authority decision, procurement approval, certification, finance-readiness determination, recognition, maturity guarantee, or operational instruction.

327.18 Observatory and Truth Engine Limitation Disclaimer. Where Nexus Observatory, observability outputs, Truth Engine outputs, source comparison, confidence scoring, verifiable intelligence, telemetry, sensor evidence, degraded-mode awareness, or resilience indicators are referenced, GCRI Canada shall state where material that such outputs are evidence and methods artifacts, not absolute truth, official public warning, emergency command, public authority decision, certification, procurement approval, finance-readiness, recognition, maturity guarantee, or execution instruction. Observatory and Truth Engine outputs remain source-dependent, method-dependent, confidence-limited, and correctionable.

327.19 Evidence, Methods, Confidence, and Uncertainty Disclaimer. Where publications present evidence, methods, confidence, uncertainty, scenarios, forecasts, simulations, models, benchmarks, risk summaries, observability outputs, or technical baselines, GCRI Canada shall include language explaining that such materials are based on identified sources, methods, assumptions, limitations, review status, and confidence levels, and remain subject to correction, supersession, withdrawal, and further review. Evidence and methods language shall be designed to prevent overreliance and false certainty.

327.20 Disclaimer Records. GCRI Canada shall maintain disclaimer records, including disclaimer purpose records, non-execution disclaimer records, non-public-warning disclaimer records, non-emergency-command disclaimer records, non-regulatory disclaimer records, non-certification disclaimer records, non-procurement disclaimer records, non-finance disclaimer records, non-investment-advice disclaimer records, non-insurance disclaimer records, non-rating disclaimer records, non-public-finance-approval disclaimer records, public authority non-endorsement disclaimer records, sponsor and provider non-control disclaimer records, AI limitation disclaimer records, digital twin limitation disclaimer records, dashboard and map limitation disclaimer records, Observatory and Truth Engine limitation disclaimer records, evidence / methods / confidence / uncertainty disclaimer records, approved language, deviations, corrections, and archives.


Section 328. Media Protocol, Spokesperson Authority, Crisis Communications, and Emergency Communications Discipline

328.1 Media Protocol Purpose. GCRI Canada shall maintain media protocol, spokesperson authority, crisis communications, and emergency communications discipline to ensure that public statements are accurate, authorized, evidence-supported, public-safe, legally reviewed where required, role-separated, boundary-protected, and correctionable. Media protocol shall preserve GCRI Canada’s public-benefit purpose, non-execution boundary, public authority boundaries, finance-boundary discipline, certification-boundary discipline, procurement neutrality, provider neutrality, sponsor non-control, data / AI / cyber safety, protected knowledge safeguards, and institutional trust.

328.2 Authorized Spokespersons. Only persons designated by the Board, an authorized officer, or competent record may speak on behalf of GCRI Canada to media, at public events, in public statements, on social media, in crisis communications, or in other official external communications. Authorized spokespersons shall act within their delegation, use approved language, preserve confidentiality, avoid unsupported claims, observe boundary language, and escalate matters beyond authority. Spokesperson authority shall be recorded and may be limited by topic, audience, time, channel, geography, or publication class.

328.3 Spokesperson Delegation. Spokesperson delegation shall identify the person, role, scope, permitted topics, prohibited topics, approval requirements, quote approval rules, crisis communications authority, social media authority, public authority reference limits, finance-boundary limits, certification-boundary limits, procurement-boundary limits, sponsor and provider reference limits, and revocation path. Delegation may be temporary, event-specific, topic-specific, publication-specific, or emergency-specific. Delegation shall not create authority to bind GCRI Canada contractually or operationally unless separately authorized.

328.4 Media Inquiry Intake. Media inquiries shall be routed through approved intake channels. Intake shall record journalist identity, outlet, topic, deadline, proposed framing, requested materials, public authority references, sponsor or provider references, finance relevance, public safety relevance, crisis relevance, protected knowledge issues, cyber or infrastructure sensitivity, requested quote, and required review. High-risk inquiries shall be escalated before response. No person shall respond to high-risk media inquiries in an official capacity without authorization.

328.5 Interview Approval. Interviews shall be approved before participation where the interview concerns GCRI Canada institutional positions, public authority matters, finance-related matters, certification or procurement matters, sponsor or provider matters, protected knowledge, cyber-sensitive matters, infrastructure-sensitive matters, public safety, crises, allegations, incidents, disputes, or Nexus interface matters. Interview approval shall identify spokesperson, topic boundaries, approved messages, prohibited statements, limitation language, confidentiality restrictions, recording status, publication status, and correction path.

328.6 Quote Approval. Attributed quotes shall be reviewed and approved before release where practicable. Quote approval shall ensure accuracy, role separation, boundary language, public authority reference accuracy, finance-boundary accuracy, certification-boundary accuracy, procurement-boundary accuracy, sponsor and provider neutrality, public-safe language, and avoidance of overclaim. Quotes shall not be edited by others in ways that create endorsement, public authority approval, finance-readiness, certification, procurement approval, provider preference, public warning, emergency command, or execution meaning.

328.7 Press Release Approval. Press releases shall require publication approval according to risk. Approval shall include review of titles, subtitles, quotes, public authority references, sponsor references, provider references, host references, partner references, claims, evidence support, limitations, disclaimers, public-safe status, media contacts, release date, embargo, distribution list, and correction path. Press releases shall not announce public authority approval, funding, procurement, finance-readiness, certification, recognition, maturity, capital commitment, insurance approval, provider preference, or official Nexus status without competent record.

328.8 Crisis Communications. Crisis communications shall be used where a situation may materially affect GCRI Canada’s public trust, legal position, public-safe outputs, data / AI / cyber posture, privacy, protected knowledge, public authority relationships, sponsor or provider relationships, publications, repositories, dashboards, maps, incidents, or Nexus interface meaning. Crisis communications shall be factual, restrained, public-safe, legally reviewed where required, and updated as facts change. Crisis communications shall not speculate, blame prematurely, disclose sensitive details, misdescribe public authorities, or overstate institutional authority.

328.9 Emergency Communications Discipline. Emergency communications discipline shall apply where communications concern hazards, disasters, cyber incidents, public safety, public health, infrastructure disruption, degraded-mode awareness, public authority emergencies, or urgent public risk. GCRI Canada shall avoid language that could be read as official emergency command, public warning, evacuation instruction, public safety order, public health order, infrastructure operating instruction, or public authority directive. Where appropriate, communications shall refer readers to competent public authorities for official instructions.

328.10 Public Authority Coordination Where Appropriate. Where a media or crisis communication involves public authority data, public authority participation, public authority names, public authority-sensitive materials, emergency management, public health, public safety, public finance, infrastructure operators, regulators, or public-sector context, GCRI Canada shall coordinate with the relevant public authority where lawful, appropriate, and consistent with GCRI Canada’s role. Coordination shall not create public authority delegation, public warning authority, emergency command, procurement approval, funding approval, public finance approval, or sovereign obligation.

328.11 Public Warning Boundary in Crisis Communications. Crisis communications shall include public warning boundary language where there is a risk that GCRI Canada statements could be treated as official warnings, alerts, emergency instructions, public health orders, public safety directions, evacuation guidance, or operational commands. GCRI Canada may correct its own materials and inform audiences of limitations, but it shall not assume public warning or emergency command functions.

328.12 Public Authority Reference Boundary in Crisis Communications. Crisis communications involving public authorities shall avoid implying endorsement, adoption, approval, official position, funding, procurement, regulation, public finance approval, emergency command, public warning, public-private partnership, or sovereign obligation without competent record. Public authority names, logos, quotes, or roles shall be used only with accuracy and permission where required.

328.13 Finance, Procurement, Certification, Recognition, and Provider Claim Boundary in Crisis Communications. Crisis communications shall not be used to create or defend unsupported claims about finance-readiness, insurance-readiness, investment suitability, bankability, rating, underwriting, lending, public finance approval, procurement approval, certification, accreditation, compliance approval, recognition, maturity, Nexus Grid status, provider preference, sponsor control, or public authority endorsement. Where such claims are part of a crisis, communications shall correct overclaims with precision and without amplifying misinformation.

328.14 Social Media Rapid Response. Social media rapid response may be used to correct misinformation, clarify official position, direct readers to accurate materials, acknowledge incidents, or provide public-safe updates. Rapid response shall remain authorized, factual, limited, and boundary-protected. Rapid response shall not bypass legal, public-safe, public authority, data / AI / cyber, protected knowledge, finance-boundary, certification-boundary, procurement-boundary, or spokesperson controls where risk is material.

328.15 Rumor, Misinformation, or Misuse Response. Where rumors, misinformation, misquotes, fake documents, forged statements, misleading sponsor claims, provider overclaims, public authority misdescription, finance-readiness overclaims, certification claims, procurement implications, public warning confusion, or Nexus-compatible misrepresentations arise, GCRI Canada may issue correction, clarification, takedown request, public-safe notice, controlled notice, website update, media statement, social media response, or direct communication. Responses shall be proportionate, evidence-supported, and designed to reduce confusion without spreading unsafe details.

328.16 No Spokesperson Authority by Seniority, Participation, Expertise, Public Authority Relationship, Sponsor Relationship, or Media Contact Alone. No person shall have spokesperson authority merely because of seniority, expertise, Board service, officer title outside delegation, employment, fellowship, advisory status, public authority relationship, sponsor relationship, provider relationship, host relationship, academic reputation, technical knowledge, working group participation, council participation, media contact, or public recognition. Spokesperson authority exists only by competent record and within defined scope.

328.17 Media and Crisis Communications Records. GCRI Canada shall maintain media and crisis communications records, including media protocol records, authorized spokesperson records, delegation records, media inquiry intake records, interview approvals, quote approvals, press release approvals, crisis communications records, emergency communications discipline records, public authority coordination records, public warning boundary records, public authority reference boundary records, finance / procurement / certification / recognition / provider claim boundary records, social media rapid response records, rumor / misinformation / misuse response records, unauthorized spokesperson records, corrections, clarifications, withdrawals, takedowns, and archives.


Section 329. Corrections, Supersessions, Withdrawals, Retractions, Public Clarifications, and Archive Status

329.1 Publication Correction Purpose. GCRI Canada shall maintain correction, supersession, withdrawal, retraction, public clarification, and archive-status procedures for publications, public-safe summaries, reports, whitepapers, articles, websites, social media, decks, speeches, media responses, datasets, software releases, dashboards, maps, repositories, technical baselines, public authority-facing materials, sponsor-facing materials, provider-facing materials, capital-reader materials, and Nexus interface outputs. These procedures shall preserve truthfulness, public trust, evidence integrity, methods integrity, public authority boundaries, finance-boundary discipline, certification-boundary discipline, procurement neutrality, protected knowledge safeguards, data / AI / cyber safety, public-safe publication, historical traceability, and correctionability.

329.2 Correction Trigger. A correction shall be triggered where a publication contains an error, omission, ambiguity, stale statement, unsupported claim, citation error, source error, method error, limitation omission, public authority misdescription, sponsor or provider misdescription, finance overclaim, certification implication, procurement implication, recognition or maturity overclaim, AI hallucination, data leakage, privacy issue, protected knowledge issue, cyber-sensitive disclosure, infrastructure-sensitive disclosure, dashboard error, map error, software release error, dataset error, or public-safe issue that can be remedied while preserving the publication’s general status. Corrections shall be proportionate and recorded.

329.3 Supersession Trigger. Supersession shall be triggered where a publication, dataset, software release, dashboard, map, technical baseline, method note, evidence note, public-safe summary, or Nexus interface output is replaced by a later version, updated method, corrected source, improved evidence, changed law, changed public authority term, changed data status, changed AI model, changed security posture, changed public-safe classification, or changed institutional position. Supersession shall identify the successor version, effective date, prior version, reliance rule, migration path, and archive status.

329.4 Withdrawal Trigger. Withdrawal shall be triggered where a publication or output should no longer be available for active reliance because of error, unresolved source issue, rights issue, privacy issue, protected knowledge concern, public authority concern, cyber risk, infrastructure risk, finance-boundary risk, certification-boundary risk, procurement-boundary risk, legal risk, sponsor or provider misuse, public-safe risk, or unresolved review. Withdrawal may occur without a finding of research misconduct and may be temporary or permanent.

329.5 Retraction Trigger. Retraction shall be triggered where a publication contains material error, unreliable evidence, fabricated source, fabricated citation, serious methods failure, serious research integrity issue, unauthorized data use, protected knowledge breach, public authority misdescription of high consequence, public-safe failure, legal defect, AI hallucination of material significance, or other defect that materially undermines the publication’s validity. Retraction shall be clear, recorded, and accompanied by appropriate explanation consistent with legal, privacy, safeguards, and public-safe constraints.

329.6 Public Clarification Trigger. Public clarification shall be triggered where a publication is accurate in part but is being misread, misused, taken out of context, copied into sponsor or provider marketing, misrepresented as public authority approval, treated as finance-readiness, treated as certification, treated as procurement approval, treated as public warning, treated as emergency command, or otherwise creating public confusion. Clarification may be issued through website notice, social media, direct notice, press statement, dashboard note, map note, repository notice, updated disclaimer, or controlled communication.

329.7 Archive Status Trigger. Archive status shall be triggered where a publication, dataset, dashboard, map, software release, technical baseline, report, article, whitepaper, deck, or public-safe output is no longer current but should be preserved for historical traceability, research integrity, legal records, correctionability, public-benefit memory, or institutional continuity. Archive status shall identify whether the material is superseded, withdrawn, retracted, retired, obsolete, historical, no-longer-maintained, or retained for record only.

329.8 Error Severity Classification. Publication errors shall be classified by severity. Severity shall consider public exposure, reliance risk, public authority impact, finance implication, certification implication, procurement implication, recognition or maturity implication, protected knowledge exposure, privacy risk, cyber risk, infrastructure risk, community harm, legal exposure, sponsor or provider misuse, AI hallucination, source failure, method failure, and downstream dependency. Severity may determine whether correction is silent, noted, public, controlled, urgent, escalated, withdrawn, or retracted. Material changes shall preserve traceability.

329.9 Public Authority Misdescription Correction. Where public authority names, titles, logos, attendance, quotes, photographs, data contributions, official capacity, approval status, funding status, procurement status, public finance status, regulatory status, emergency-management status, public warning status, or sovereign obligation have been misdescribed, GCRI Canada shall correct the misdescription promptly and proportionately. Correction may include revised wording, logo removal, quote removal, attribution correction, capacity clarification, non-endorsement statement, direct public authority notice where appropriate, public-safe notice, controlled notice, or withdrawal.

329.10 Finance, Investment, Insurance, Procurement, Certification, Recognition, Maturity, Provider Preference, Sponsor Control, or Public Warning Overclaim Correction. Where a publication overclaims or is misused to imply finance-readiness, investment suitability, insurance-readiness, underwriting approval, lending approval, public finance approval, rating, capital commitment, solicitation, procurement approval, provider preference, certification, accreditation, compliance approval, recognition, standing, maturity, Nexus Grid status, sponsor control, provider endorsement, public warning, emergency command, or execution authority, GCRI Canada shall correct the overclaim. Correction may require revised disclaimers, withdrawal of materials, sponsor or provider notice, public clarification, data room correction, dashboard note, map note, repository notice, or legal review.

329.11 Data, AI, Cyber, Privacy, Community, Protected Knowledge, Infrastructure, or Public-Safety Correction. Where a publication creates data, AI, cyber, privacy, community, protected knowledge, infrastructure, public safety, health, geospatial, dashboard, map, software, dataset, or public-safe risk, GCRI Canada shall correct, suppress, redact, aggregate, generalize, restrict, withdraw, reclassify, take down, disable, or retract the material as appropriate. Such correction shall include incident review where required, notification review where required, safeguards review where required, public authority review where required, and downstream dependency review where material.

329.12 Public-Safe Correction Notice. A public-safe correction notice shall be issued where public audiences need to know that a material has changed, contains limitations, has been corrected, has been superseded, has been withdrawn, has been retracted, or should no longer be relied upon. Public-safe correction notices shall be accurate, concise, non-alarming, limitation-bearing, and shall avoid disclosing restricted details, protected knowledge, personal information, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive materials, or privileged information.

329.13 Controlled Correction Notice. A controlled correction notice may be issued to defined recipients, reviewers, public authorities, partners, sponsors, providers, capital readers, Board members, committees, councils, working groups, repository users, dashboard users, dataset recipients, software users, or Nexus interface actors where the correction concerns materials not suitable for public disclosure. Controlled correction notices shall identify permitted use, confidentiality, redistribution limits, public-safe handling, correction action, and dependency implications.

329.14 Downstream Dependency Notification. Where a publication correction, supersession, withdrawal, retraction, or clarification affects downstream materials, dashboards, maps, datasets, repositories, public authority materials, sponsor materials, provider materials, capital-reader materials, technical baselines, software releases, Academy materials, Nexus interface records, or public-safe outputs, GCRI Canada shall provide downstream dependency notification where appropriate. Dependency notification shall identify affected materials, required action, replacement version, limitation language, and closeout.

329.15 Replacement Publication. Where appropriate, GCRI Canada may issue a replacement publication after correction, supersession, withdrawal, or retraction. Replacement publication shall identify prior publication, successor status, material changes, correction basis where appropriate, updated evidence, updated methods, updated limitations, updated disclaimers, updated public-safe status, and archive status of the replaced material. Replacement publication shall not conceal material prior error.

329.16 Archive Copy and Historical Traceability. GCRI Canada shall preserve archive copies of material publications and related correction records according to law, policy, research integrity, public authority terms, privacy, protected knowledge obligations, cyber security, infrastructure sensitivity, finance sensitivity, public-safe publication needs, and institutional memory. Archive copies shall identify operative status, access class, public-safe status, supersession status, withdrawal status, retraction status, correction history, and reliance limitations. Archive copies may be sealed, restricted, or redacted where required.

329.17 Corrections, Supersessions, Withdrawals, Retractions, Clarifications, and Archive Records. GCRI Canada shall maintain correction and archive records, including publication correction purpose records, correction triggers, supersession triggers, withdrawal triggers, retraction triggers, public clarification triggers, archive status triggers, error severity classifications, public authority misdescription corrections, finance / investment / insurance / procurement / certification / recognition / maturity / provider preference / sponsor control / public warning overclaim corrections, data / AI / cyber / privacy / community / protected knowledge / infrastructure / public-safety corrections, public-safe correction notices, controlled correction notices, downstream dependency notifications, replacement publications, archive copies, historical traceability records, and archives.


Section 330. Publication Records, Drafts, Approvals, Source Records, Reviewer Notes, Public-Safe Reviews, Publication Dates, Versions, Corrections, and Retention

330.1 Publication Record Requirement. GCRI Canada shall maintain publication records for material websites, articles, social media statements, speeches, media responses, decks, public reports, whitepapers, datasets, software releases, dashboards, maps, repositories, public authority-facing materials, sponsor-facing materials, provider-facing materials, capital-reader materials, Academy materials, public-safe summaries, controlled summaries, and Nexus interface outputs. Publication records shall preserve source support, methods support, approval authority, classification, public-safe review, boundary review, versioning, release date, correction path, retention, and institutional traceability.

330.2 Draft Records. Draft records shall be maintained where material to publication approval, review, legal compliance, research integrity, public authority boundaries, sponsor or provider review, protected knowledge safeguards, finance-boundary review, certification-boundary review, procurement-boundary review, or correctionability. Draft records shall identify draft status, author, contributors, reviewers, date, version, classification, circulation, comments, unresolved issues, public-safe status, and whether the draft is internal-only, controlled, restricted, or approved for external review. Drafts shall not be represented as final.

330.3 Source Records. Source records shall identify the materials relied upon in a publication, including documents, datasets, interviews, public authority records, community inputs, protected knowledge records, technical records, repository records, model records, dashboard records, map layers, legal materials, research sources, public sources, controlled annexes, and evidence packs. Source records shall identify provenance, custody, permission, classification, reliability, date, version, public-safe status, limitations, and correction path. Public versions may summarize source lineage where full disclosure is unsafe.

330.4 Evidence Records. Evidence records supporting publication claims shall include source lineage, evidence classification, confidence, uncertainty, method linkage, reviewer status, dispute status, stale-data status, missing-data status, public authority capacity where applicable, protected knowledge status where applicable, data rights, limitations, and correction path. Evidence records shall be sufficient to reconstruct the basis for material claims and to correct or supersede them where necessary.

330.5 Methods Records. Methods records shall identify the methods used to generate, interpret, summarize, classify, map, model, simulate, benchmark, compare, or communicate publication content. Methods records shall include method name, version, purpose, assumptions, exclusions, limitations, data requirements, review status, public-safe status, applicable audience, and correction path. Methods records shall be retained where publications rely on technical, research, AI, cyber, geospatial, Observatory, Truth Engine, verifiable compute, or Nexus-compatible methods.

330.6 Reviewer Notes. Reviewer notes shall document material comments, approvals, objections, conditions, unresolved issues, corrections, limitation requirements, public-safe concerns, legal concerns, public authority concerns, protected knowledge concerns, data / AI / cyber concerns, finance-boundary concerns, certification-boundary concerns, procurement-boundary concerns, sponsor or provider concerns, conflict concerns, and release conditions. Reviewer notes may be classified, privileged, restricted, or sealed where required. Reviewer notes shall not be publicly released unless approved.

330.7 Approval Records. Approval records shall identify approving authority, approval date, publication class, version approved, release channel, required disclaimers, required redactions, conditions, embargoes, public-safe status, reviewer sign-offs, delegated authority, Board approval where applicable, officer approval where applicable, committee review where applicable, legal review where applicable, and any limits on use. Approval records shall distinguish approval to draft, approval to circulate, approval for controlled release, approval for public release, and approval for final publication.

330.8 Conflict Review Records. Conflict review records shall identify conflicts affecting authors, reviewers, contributors, sponsors, providers, donors, funders, public authorities, partners, hosts, universities, laboratories, National Consortium Companies, Project SPVs, or other actors involved in publication. Conflict records shall identify disclosure, review, recusal, mitigation, independent review, limitation language, rejection, or approval conditions. Publications shall not conceal conflicts that materially affect public interpretation.

330.9 Public Authority Review Records. Public authority review records shall document review of public authority names, titles, logos, agencies, jurisdictions, quotes, attendance, photographs, data contributions, capacity classification, public reference permissions, official-capacity verification, non-endorsement language, no-delegation language, no-public-warning language, no-emergency-command language, no-regulatory-approval language, no-procurement-approval language, no-funding-approval language, no-public-finance-approval language, and no-sovereign-obligation language.

330.10 Data / AI / Cyber / Privacy Review Records. Data / AI / cyber / privacy review records shall document review of data rights, lawful basis, personal information, rights-bearing data, AI use, model outputs, retrieval systems, embeddings, prompts, inference records, cyber-sensitive details, infrastructure-sensitive details, public repository hygiene, privacy risks, data leakage risks, prompt injection risks, public-safe status, retention, deletion, and incident response readiness. Such records shall identify conditions, redactions, restrictions, approvals, denials, and correction path.

330.11 Community Safeguards and Protected Knowledge Review Records. Community safeguards and protected knowledge review records shall document review of Indigenous knowledge, local knowledge, territorial knowledge, community-protected data, cultural knowledge, environmental knowledge, sacred-site information, protected participants, youth, vulnerable persons, remote communities, public-safe mapping risk, consent or authorization, custodial authority, attribution, non-extraction, AI-use restrictions, publication limits, withdrawal rights, correction rights, redaction, aggregation, generalization, and harm-prevention measures.

330.12 Finance, Certification, Procurement, Recognition, and Public Warning Boundary Review Records. Boundary review records shall document review of finance-readiness, insurance-readiness, investment suitability, bankability, underwriting, lending, public finance approval, rating, capital placement, solicitation, certification, accreditation, compliance approval, procurement approval, provider preference, recognition, standing, maturity, Nexus Grid status, GRF recognition, public warning, emergency command, public authority decision, and execution instruction risks. Records shall identify limitation language, non-reliance language, claim revisions, claim removals, escalation, and approval or denial.

330.13 Publication Date Records. Publication date records shall identify original publication date, release time where relevant, embargo date, update date, correction date, supersession date, withdrawal date, retraction date, archive date, effective date where applicable, and channel. Publication date records shall prevent confusion between drafts, prior versions, corrected versions, superseded versions, archived versions, and current operative publications.

330.14 Version Records. Version records shall identify version number, version label, change log, prior version, successor version, release authority, material changes, redactions, limitations, corrected claims, superseded claims, data source changes, method changes, public authority reference changes, boundary language changes, dashboard changes, map changes, software changes, dataset changes, and archive location. Version records shall preserve no-silent-edit discipline for material publications.

330.15 Correction Records. Correction records shall identify error, omission, overclaim, misdescription, stale statement, source issue, method issue, AI issue, public authority issue, sponsor issue, provider issue, finance issue, certification issue, procurement issue, protected knowledge issue, privacy issue, cyber issue, infrastructure issue, public-safe issue, correction authority, correction date, affected materials, dependency review, notice, and closeout. Correction records shall distinguish minor editorial correction from material correction.

330.16 Supersession, Withdrawal, Retraction, Clarification, and Archive Records. GCRI Canada shall maintain records for supersessions, withdrawals, retractions, clarifications, archive status, replacement publications, public-safe correction notices, controlled correction notices, dependency notifications, access restrictions, sealed copies, public access changes, public dashboard changes, repository changes, dataset changes, software release changes, and historical traceability. These records shall identify reason, authority, date, affected audience, successor material, reliance limitation, and correction path.

330.17 Retention Periods. Publication records shall be retained according to law, corporate governance requirements, research integrity, public authority terms, privacy obligations, protected knowledge obligations, cybersecurity needs, intellectual property needs, contractual obligations, donor or grant terms, publication risk, public-safe needs, correctionability, and institutional memory. Retention periods shall distinguish drafts, final publications, source records, reviewer notes, approval records, public authority review records, data / AI / cyber review records, safeguards records, boundary review records, correction records, and archive copies.

330.18 Publication Record Access, Sealing, and Secure Disposal. Publication records shall be accessed only by authorized persons according to classification, role, purpose, and need to know. Records may be sealed, restricted, privileged, redacted, or controlled where they contain legal advice, confidential information, personal information, protected knowledge, public authority-sensitive materials, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive evidence, reviewer deliberations, or incident information. Secure disposal shall occur only where lawful, consistent with retention schedules, public authority terms, protected knowledge obligations, legal holds, research integrity, and correctionability.

Last updated

Was this helpful?