> For the complete documentation index, see [llms.txt](https://docs.therisk.global/organization/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.therisk.global/organization/organization/governance/bylaws/gcri-us/article-xviii.-definitions.md).

# ARTICLE XVIII. DEFINITIONS

### Section 504. Definitions Purpose and Scope

#### 504.1 Definitions Purpose.

504.1.1 Definitions under these Bylaws shall provide the Corporation’s authoritative interpretive framework for institutional identity, governance authority, public-benefit purpose, nonprofit character, participation, support, records, public authority interfaces, finance boundaries, certification and procurement boundaries, data / AI / cyber / privacy controls, public-safe publication, technical assets, Nexus coordination, safeguards, protected knowledge, validity-by-record, correctionability, dissolution, wind-up, and enforcement.

504.1.2 Definitions shall ensure that terms used by or for the Corporation are not used loosely, commercially, politically, technically, or rhetorically in a manner that creates unsupported authority, public authority confusion, finance reliance, certification implication, recognition implication, procurement advantage, provider preference, public warning confusion, emergency command confusion, public-good asset enclosure, data misuse, protected knowledge exposure, or Nexus role collapse.

504.1.3 Definitions shall be read as operative governance controls and not merely as drafting conveniences. Each defined term shall carry the restrictions, exclusions, conditions, record requirements, and boundary protections assigned to it by these Bylaws, applicable law, the certificate or articles, Board resolutions, policies, schedules, forms, registers, public-safe materials, technical asset records, and Nexus interface records.

#### 504.2 Definitions as Operative Terms.

504.2.1 Defined terms shall operate as binding interpretive terms throughout these Bylaws unless the context expressly and lawfully requires otherwise.

504.2.2 A defined term shall not be interpreted in isolation. Each defined term shall be read together with all related provisions governing authority, limits, records, approvals, public-safe status, correction, access, confidentiality, role separation, public authority boundaries, finance boundaries, certification and recognition boundaries, procurement neutrality, data / AI / cyber controls, safeguards, protected knowledge, and Nexus coordination.

504.2.3 Where a defined term appears in a policy, schedule, form, public material, repository notice, technical baseline, agreement, dashboard, map, publication, public authority notice, finance-boundary notice, or Nexus interface instrument, it shall carry the meaning assigned by these Bylaws unless a more restrictive approved definition is adopted for that instrument.

#### 504.3 Definitions as Controlled Vocabulary.

504.3.1 Definitions shall form part of the Corporation’s controlled vocabulary.

504.3.2 Terms with public meaning, technical meaning, legal meaning, finance meaning, public authority meaning, certification meaning, recognition meaning, procurement meaning, maturity meaning, Docket meaning, Grid meaning, Nexus-compatible meaning, or public-safe meaning shall be used only in accordance with these Bylaws and approved controlled vocabulary records.

504.3.3 Controlled vocabulary shall be used to prevent semantic drift, overclaim, informal authority creation, sponsor distortion, provider distortion, public authority confusion, public-safe misframing, and misuse of technical outputs.

504.3.4 Where a term becomes ambiguous through practice, public use, partner use, sponsor use, provider use, media use, AI-generated content, repository use, public authority reference, or Nexus interface usage, the Corporation shall clarify, restrict, correct, supersede, or withdraw the term as required.

#### 504.4 Definitions as Claims-Discipline Controls.

504.4.1 Definitions shall control public claims and institutional claims made by or about the Corporation.

504.4.2 No defined term shall be used in a public claim unless the claim is supported by competent records, source lineage, approval records, public-safe review where required, controlled vocabulary review where required, and boundary review where required.

504.4.3 Defined terms shall prevent the unsupported use of terms such as “official,” “approved,” “validated,” “verified,” “recognized,” “certified,” “compliant,” “conformant,” “finance-ready,” “insurance-ready,” “capital-readable,” “bankable,” “investable,” “Nexus-compatible,” “Docket-approved,” “Grid-approved,” “public authority approved,” “public warning,” “emergency command,” “provider-preferred,” and substantially similar terms unless competent authority exists.

#### 504.5 Definitions as Public Authority Boundary Controls.

504.5.1 Definitions shall preserve the Corporation’s public authority boundaries.

504.5.2 Terms concerning public authorities, public officials, public employees, public infrastructure operators, observers, regulator-listening participants, public finance readers, emergency-management participants, public health participants, public safety participants, public works participants, public authority data, public authority rooms, public grants, public records, procurement, public finance, regulatory participation, public warning, and emergency command shall be interpreted to prevent unauthorized public authority meaning.

504.5.3 No defined term shall create or imply public authority status, public authority delegation, official government decision-making, public procurement authority, public finance approval, regulatory approval, public warning authority, emergency command authority, public health order authority, safety command authority, sovereign obligation, or public-private partnership unless a competent public authority record and applicable law expressly provide such meaning.

#### 504.6 Definitions as Finance Boundary Controls.

504.6.1 Definitions shall preserve the Corporation’s finance, securities, insurance, lending, rating, public finance, and capital-reader boundaries.

504.6.2 Terms concerning finance-readiness, capital-readability, insurance-readiness, proof packs, diligence translation, RNFD, NFD, UNFSD, capital-reader rooms, public finance, investment, lending, insurance, ratings, guarantees, public credit, tax credits, grants, and regulated-perimeter matters shall be interpreted consistently with GRA role separation and the Corporation’s non-finance role.

504.6.3 No defined term shall create investment advice, securities offering, securities solicitation, broker-dealer activity, finder activity, placement activity, underwriting, lending, banking, insurance placement, insurance underwriting, claims handling, rating, credit opinion, public finance approval, public guarantee, public credit, or finance-readiness authority for the Corporation.

#### 504.7 Definitions as Certification and Procurement Boundary Controls.

504.7.1 Definitions shall preserve the Corporation’s certification, accreditation, conformance, compliance, procurement, approved-vendor, and provider-preference boundaries.

504.7.2 Terms concerning certification, accreditation, compliance, conformance, approval, procurement, approved vendor status, provider preference, technical baselines, public-good software, test harnesses, benchmarks, Nexus-compatible status, Docket, Grid, recognition, maturity, and standing shall be interpreted to prevent unauthorized approval meaning.

504.7.3 No defined term shall create certification, accreditation, legal compliance approval, procurement approval, approved vendor status, provider preference, GRF recognition, maturity standing, Docket approval, Grid guarantee, or Nexus-compatible status unless competent records from the proper authority provide such meaning.

#### 504.8 Definitions as Nexus Role-Separation Controls.

504.8.1 Definitions shall preserve role separation within the Nexus architecture.

504.8.2 Terms concerning GCRI US, GCRI Canada, other GCRI entities, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, protocol authorities, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, providers, hosts, sponsors, public authorities, and enterprise actors shall be interpreted to preserve legal separateness and functional distinction.

504.8.3 No defined term shall create merger, agency, partnership, joint venture, shared liability, authority to bind another entity, public authority delegation, finance-readiness transfer, recognition transfer, certification transfer, procurement approval, or enterprise execution authority.

#### 504.9 Definitions as Data / AI / Cyber / Privacy Controls.

504.9.1 Definitions shall preserve the Corporation’s data governance, AI governance, cybersecurity, privacy, verifiable compute, verifiable intelligence, proof receipt, repository security, and controlled-room controls.

504.9.2 Terms concerning data, datasets, personal information, rights-bearing data, health-sensitive data, public authority data, cyber-sensitive data, infrastructure-sensitive data, community-protected data, protected knowledge data, model registers, inference records, compute workload records, proof receipts, AI outputs, dashboards, maps, repositories, controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, and no-download rooms shall be interpreted according to their classification, authority record, access class, public-safe status, and correction path.

504.9.3 No AI output, automated output, dashboard output, map output, proof receipt, ledger entry, sensor signal, AI-RAN / O-RAN signal, DePIN record, DLT record, digital twin output, model output, or compute output shall be treated as authority merely because it exists or is technically generated.

#### 504.10 Definitions as Safeguards and Protected Knowledge Controls.

504.10.1 Definitions shall preserve civil rights, accessibility, community safeguards, Tribal / Indigenous protocols, local knowledge protections, territorial knowledge protections, cultural knowledge protections, environmental knowledge protections, protected knowledge controls, public-safe mapping controls, consent, non-consent, attribution, withdrawal, restriction, grievance, protected participation, and non-retaliation.

504.10.2 Terms concerning Tribal / Indigenous interfaces, Indigenous data, Indigenous knowledge, community-protected data, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, ecological knowledge, sacred knowledge, sensitive sites, public-safe mapping, vulnerable communities, and protected knowledge shall be interpreted according to the most protective lawful reading.

504.10.3 No defined term shall convert protected knowledge into public data, research material, AI training material, public dashboard content, map layer, sponsor asset, provider asset, finance-facing evidence, public authority evidence, or transferable technical asset without competent authority and safeguards review.

#### 504.11 Definitions as Validity-by-Record Controls.

504.11.1 Definitions shall implement the validity-by-record doctrine.

504.11.2 A defined status, authority, approval, role, access right, release status, evidence status, method status, public authority status, finance-boundary status, recognition status, certification status, procurement status, Docket status, Grid status, Nexus-compatible status, public-safe status, controlled-room status, technical asset status, or correction status exists only to the extent supported by an Authoritative Record.

504.11.3 Where a defined term is used without a required record, the term shall have no public meaning and shall be corrected, limited, withdrawn, or disregarded as appropriate.

#### 504.12 Definitions as Correctionability Controls.

504.12.1 Definitions shall support correctionability.

504.12.2 Where a defined term is inaccurate, obsolete, overbroad, misleading, boundary-defective, inconsistent with law, inconsistent with role separation, inconsistent with Nexus instruments, inconsistent with public authority records, inconsistent with finance-boundary records, inconsistent with safeguards records, or inconsistent with technical records, the Corporation shall correct, supersede, withdraw, restrict, clarify, or restate the term.

504.12.3 Correction of a defined term may require public-safe notice, controlled notice, repository correction, publication correction, technical asset correction, public authority correction, GRF notice, GRA notice, Nexus interface notice, or archive annotation.

#### 504.13 Definitions Apply Across Bylaw, Policies, Schedules, Forms, Records, Registers, Public Materials, Technical Assets, Agreements, and Nexus Interfaces Unless Otherwise Stated.

504.13.1 Definitions in these Bylaws shall apply across these Bylaws, policies, schedules, forms, records, registers, matrices, protocols, public materials, websites, repositories, publications, dashboards, maps, datasets, software, technical baselines, agreements, contracts, grants, sponsorships, public authority instruments, contributor terms, controlled-room instruments, public-safe notices, archive statements, Nexus interface instruments, and other Corporation instruments unless an instrument expressly adopts a narrower or more restrictive meaning.

504.13.2 A more permissive meaning shall not be inferred from context unless adopted by competent authority and lawful under applicable law, the certificate or articles, these Bylaws, Board resolution, or other competent record.

504.13.3 Translations, summaries, AI summaries, deck text, diagrams, public explainers, repository readme files, marketing materials, and public-facing narratives shall not alter defined terms.

#### 504.14 No Defined Term May Be Used to Expand Authority Beyond Law, Articles, Certificate, This Bylaw, Board Resolution, or Competent Record.

504.14.1 No defined term may be used to expand the Corporation’s authority beyond applicable law, the certificate or articles, these Bylaws, Board resolution, member approval where required, contract authority, public authority record, Nexus interface record, or other competent record.

504.14.2 No defined term may be used to create informal amendment, apparent authority, public authority status, finance authority, certification authority, recognition authority, procurement authority, provider preference, public warning authority, emergency command authority, enterprise execution authority, or authority to bind another entity.

504.14.3 If use of a defined term would create ambiguity about authority, the term shall be read narrowly, accompanied by limitation language where appropriate, or corrected.

#### 504.15 Definitions Records.

504.15.1 The Corporation shall maintain Definitions Records, including definitions purpose records, operative-term records, controlled vocabulary records, claims-discipline records, public authority boundary records, finance boundary records, certification and procurement boundary records, Nexus role-separation records, data / AI / cyber / privacy definition records, safeguards and protected knowledge definition records, validity-by-record definition records, correctionability definition records, cross-instrument application records, no-authority-expansion records, correction records, controlled vocabulary updates, Board interpretations, legal interpretations, and archive records.

***

### Section 505. Institutional Definitions

#### 505.1 “GCRI US.”

505.1.1 “GCRI US” means the United States legal entity of The Global Centre for Risk and Innovation operating under these Bylaws as a nonprofit, nonstock, non-share, non-distributing, non-executing, public-benefit, public-good technical institution.

505.1.2 GCRI US functions as an evidence steward, methods steward, observability methods steward, ontology steward, technical truth steward, public-benefit R\&D steward, public-good software steward, open technical baseline steward, verifiable compute and verifiable intelligence methods steward, Nexus Truth Engine methods steward, Nexus Observatory methods steward, and public authority learning support institution.

505.1.3 GCRI US does not by default function as a public authority, regulator, procurement authority, finance-readiness authority, certification body, recognition body, provider, operator, national company, Project SPV, fund, lender, insurer, broker, dealer, investment adviser, rating agency, public warning body, emergency command body, or enterprise execution vehicle.

#### 505.2 “The Global Centre for Risk and Innovation - United States.”

505.2.1 “The Global Centre for Risk and Innovation - United States” means the full institutional name or formal descriptive name of GCRI US, subject to the Corporation’s name-use rules, mark controls, legal status records, public-safe communications rules, and jurisdictional records.

505.2.2 Use of the full name shall not imply that GCRI US represents all GCRI entities, governs GCRI Canada, governs other GCRI entities, controls GRF, controls GRA, controls Nexus Network, or speaks for any public authority or Nexus participant unless competent records expressly provide such authority.

#### 505.3 “GCRI Function.”

505.3.1 “GCRI Function” means a public-good technical function associated with The Global Centre for Risk and Innovation family of institutions, including evidence, methods, observability, ontology, technical truth, public-benefit R\&D, public-good software, open technical baselines, verifiable compute methods, verifiable intelligence methods, public authority learning support, public-safe publication support, and correctionability.

505.3.2 A GCRI Function does not include GRF recognition functions, GRA finance-readiness functions, public authority functions, certification functions, procurement functions, enterprise execution functions, or regulated finance functions unless a competent record lawfully assigns such function and the assignment is consistent with these Bylaws.

#### 505.4 “GCRI Canada.”

505.4.1 “GCRI Canada” means a Canadian GCRI entity legally separate from GCRI US.

505.4.2 GCRI Canada may coordinate with GCRI US through recorded cross-border, North America, public-good, evidence, methods, observability, technical asset, public authority, data, protected knowledge, or Nexus interfaces.

505.4.3 GCRI Canada does not govern GCRI US, and GCRI US does not govern GCRI Canada, unless a specific lawful instrument creates a limited recorded coordination or authority.

#### 505.5 “Other GCRI Entity.”

505.5.1 “Other GCRI Entity” means any GCRI-affiliated, GCRI-aligned, or GCRI-named entity other than GCRI US or GCRI Canada, whether national, regional, sectoral, project-specific, or otherwise organized.

505.5.2 Other GCRI Entities shall be treated as legally separate unless competent records establish otherwise.

505.5.3 No Other GCRI Entity may bind GCRI US, and GCRI US may not bind any Other GCRI Entity, absent lawful authority and competent records.

#### 505.6 “The Global Risks Forum (GRF).”

505.6.1 “The Global Risks Forum (GRF)” means the separate Nexus public-good institution responsible, within its governing instruments, for public-good registry, recognition, maturity records, standing, claims discipline, stakeholder formation, public-safe reporting, and public-facing legitimacy stewardship.

505.6.2 GRF functions are legally and institutionally distinct from GCRI US technical evidence, methods, ontology, observability, public-good software, and technical truth functions.

505.6.3 No GCRI US record, publication, proof receipt, dashboard, map, technical baseline, software release, public authority learning material, or Nexus interface input shall create GRF recognition meaning without a competent GRF record.

#### 505.7 “The Global Risks Alliance (GRA).”

505.7.1 “The Global Risks Alliance (GRA)” means the separate Nexus institution responsible, within its governing instruments, for capital-readability, finance-readiness, proof packs, insurance-readiness, diligence translation, RNFD, NFD, UNFSD, capital-reader room discipline, and regulated-perimeter finance discipline.

505.7.2 GRA functions are legally and institutionally distinct from GCRI US technical evidence, methods, observability, ontology, public-good software, technical baseline, and public authority learning support functions.

505.7.3 No GCRI US record, publication, dashboard, map, proof receipt, technical baseline, software release, public authority learning material, or Nexus interface input shall create GRA finance-readiness, capital-readability, insurance-readiness, public finance, rating, investment, lending, or capital execution meaning without a competent GRA record and, where required, lawful regulated authority.

#### 505.8 “Nexus Network.”

505.8.1 “Nexus Network” means the permanent public-good infrastructure rail, coordination architecture, or institutional network through which Nexus-aligned public-good functions, evidence flows, methods flows, records, interfaces, observability, public authority learning support, technical assets, standards support, and ecosystem coordination may be structured.

505.8.2 Nexus Network does not mean a single merged legal entity, public authority, finance authority, certification authority, procurement authority, recognition authority, operator, or enterprise execution body.

505.8.3 Participation in Nexus Network shall not create agency, partnership, joint venture, shared liability, merger, or authority to bind another Nexus participant without competent records.

#### 505.9 “Nexus Public-Good Stack.”

505.9.1 “Nexus Public-Good Stack” means the set of Nexus-aligned institutions, roles, instruments, records, methods, public-safe publications, technical assets, observability functions, public authority learning functions, recognition functions, finance-readiness translation functions, standards-support functions, and safeguards functions that operate for public-benefit and public-good purposes without enterprise execution by default.

505.9.2 GCRI US is positioned in the Nexus Public-Good Stack as a technical evidence, methods, observability, ontology, technical truth, public-good software, and technical baseline steward.

505.9.3 The Nexus Public-Good Stack shall remain distinct from the Nexus Enterprise Stack.

#### 505.10 “Nexus Enterprise Stack.”

505.10.1 “Nexus Enterprise Stack” means the set of execution-side, investible, operational, commercial, project, provider, host, asset-owner, national company, state operating company, regional company, Project SPV, fund, lender, insurer, operator, contractor, or enterprise-facing actors and instruments that may implement, finance, operate, procure, or execute projects where lawfully structured.

505.10.2 GCRI US shall not be treated as a Nexus Enterprise Stack actor merely because its public-good outputs inform, support, or are used by enterprise stack actors.

505.10.3 Enterprise Stack participation shall not create GCRI US endorsement, certification, recognition, procurement approval, finance-readiness, provider preference, public authority adoption, public warning, or emergency command meaning.

#### 505.11 “Nexus Standards.”

505.11.1 “Nexus Standards” means Nexus-aligned standards, standards-support instruments, technical profiles, protocol specifications, reference frameworks, interoperability requirements, schemas, tests, baselines, or similar instruments adopted or maintained by a competent Nexus Standards body or protocol authority.

505.11.2 GCRI US may provide evidence, methods, technical baselines, reference implementations, test harnesses, schemas, profiles, benchmark support, and correction signals to Nexus Standards processes without becoming the standards authority by default.

505.11.3 Nexus Standards do not create certification, procurement approval, legal compliance approval, provider preference, public authority adoption, finance-readiness, recognition, rating, public warning, or emergency command by mere reference.

#### 505.12 “Protocol Authority.”

505.12.1 “Protocol Authority” means a competent body or recorded authority responsible for adopting, maintaining, interpreting, versioning, correcting, or retiring protocol specifications, role keys, smart licenses, ledger references, proof receipt profiles, interoperability profiles, or other protocol instruments within a defined scope.

505.12.2 GCRI US is not a Protocol Authority unless separately and lawfully designated by competent record.

505.12.3 A reference implementation, technical baseline, method, schema, API, SDK, or test harness prepared by GCRI US shall not itself create Protocol Authority.

#### 505.13 “Nexus Observatory.”

505.13.1 “Nexus Observatory” means the Nexus-aligned observability institution, framework, or operating architecture for structured sensing, evidence gathering, observability methods, nodes, hubs, clusters, hotspots, regional clusters, national dense Nexus cores, dashboards, maps, public-safe outputs, and degraded-mode awareness.

505.13.2 GCRI US may support Nexus Observatory methods, ontology, technical baselines, public-safe mapping methods, dashboard methods, and evidence records.

505.13.3 Nexus Observatory outputs shall not be public warnings, emergency commands, public authority decisions, finance-readiness determinations, certifications, procurement approvals, recognitions, ratings, or provider preferences unless competent external authority separately provides such meaning.

#### 505.14 “Nexus Universe.”

505.14.1 “Nexus Universe” means the annual or periodic Nexus operating arena, controlled build environment, live operation learning environment, simulation environment, benchmarking environment, Academy lab environment, public authority learning environment, and public-safe demonstration environment for Nexus-aligned work.

505.14.2 GCRI US may support Nexus Universe through evidence, methods, technical after-action review, public-good software, technical baselines, public-safe publication, public authority learning, and records.

505.14.3 Nexus Universe activities do not create public authority delegation, public warning, emergency command, procurement approval, finance-readiness, certification, recognition, provider preference, or enterprise execution by GCRI US.

#### 505.15 “Nexus Risk Management.”

505.15.1 “Nexus Risk Management” means the Nexus-aligned function or institution concerned with risk governance, risk registers, issue registers, control registers, systemic risk, resilience, safeguards, escalation, boundary controls, assurance, monitoring, evaluation, corrective action, and public-safe risk discipline.

505.15.2 GCRI US may provide evidence, methods, observability, technical records, public-good software, and correction signals to Nexus Risk Management interfaces without assuming enterprise risk transfer, insurance, rating, public authority, or command functions.

#### 505.16 “Nexus Rails.”

505.16.1 “Nexus Rails” means the Nexus-aligned rails, pathways, public-good-to-enterprise interfaces, finance translation interfaces, evidence-routing interfaces, proof-pack interfaces, public authority learning interfaces, capital-reader interfaces, or other structured pathways by which records, methods, technical assets, and public-good outputs may move across authorized interfaces.

505.16.2 Nexus Rails shall not be interpreted as regulated finance activity, securities activity, public finance approval, procurement approval, public authority decision, or enterprise execution by GCRI US.

#### 505.17 “Nexus Grid.”

505.17.1 “Nexus Grid” means a Nexus-aligned grid, maturity, routing, standing, eligibility, or coordination interface maintained by the proper Nexus authority.

505.17.2 GCRI US may provide technical evidence, methods, public-good software, technical baselines, observability records, and correction signals as inputs to Nexus Grid where authorized.

505.17.3 GCRI US does not itself create Grid approval, Grid guarantee, Grid routing, maturity standing, eligibility, procurement approval, recognition, finance-readiness, or public authority approval unless competent authority expressly provides otherwise.

#### 505.18 “Nexus Academy.”

505.18.1 “Nexus Academy” means the Nexus-aligned learning, training, workforce, fellowship, curriculum, lab, credential-support, or educational interface.

505.18.2 GCRI US may provide evidence, methods, technical baselines, public-good software, public authority learning materials, public-safe publication materials, and technical content to Nexus Academy.

505.18.3 GCRI US does not issue Nexus Academy credentials, professional licenses, public authority qualifications, certifications, procurement eligibility, or finance-readiness determinations unless separately and lawfully authorized.

#### 505.19 “Nexus Competence Cells.”

505.19.1 “Nexus Competence Cells” means specialized teams, cells, groups, or units organized around technical, sectoral, geographic, public authority, safeguards, data, AI, cyber, observability, software, standards-support, or public-good implementation support functions.

505.19.2 Nexus Competence Cells may interface with GCRI US through recorded authority, scope, role separation, confidentiality, data controls, public authority boundary controls, finance-boundary controls, safeguards, and correction paths.

505.19.3 Competence Cell participation does not create GCRI US enterprise execution, certification, recognition, finance-readiness, procurement approval, provider preference, public authority decision, public warning, or emergency command.

#### 505.20 “Nexus Docket.”

505.20.1 “Nexus Docket” means a record-based intake, routing, tracking, case, proof, issue, project, method, evidence, or maturity-related docket maintained by a competent Nexus authority or instrument.

505.20.2 GCRI US may provide evidence, methods, technical inputs, correction signals, public-good software records, technical baseline records, or observability records to the Nexus Docket where authorized.

505.20.3 Docket inclusion, Docket record creation, Docket input, or Docket reference does not create GCRI US approval, GRF recognition, GRA finance-readiness, certification, procurement approval, public authority approval, provider preference, public warning, or emergency command.

#### 505.21 “National Nexus Financing for Development (NFD).”

505.21.1 “National Nexus Financing for Development (NFD)” means a national-level Nexus finance-readiness, capital-readability, diligence translation, public-good-to-capital interface, or development-finance-related framework operated or stewarded by the appropriate GRA or Nexus finance authority.

505.21.2 GCRI US may support NFD through technical evidence, methods, observability, ontology, public-good software, technical baselines, public-safe records, and correction signals.

505.21.3 GCRI US does not make NFD finance-readiness determinations, investment decisions, lending decisions, insurance decisions, ratings, public finance approvals, or capital commitments.

#### 505.22 “Regional Nexus Financing for Development (RNFD).”

505.22.1 “Regional Nexus Financing for Development (RNFD)” means a regional-level Nexus finance-readiness, capital-readability, diligence translation, resilience-finance, public-good-to-capital, or development-finance-related framework operated or stewarded by the appropriate GRA or Nexus finance authority.

505.22.2 GCRI US may support RNFD only within its technical evidence and methods role.

505.22.3 RNFD references shall not imply GCRI US finance authority, public finance approval, investment advice, rating, or capital execution.

#### 505.23 “Universal Nexus Financing for Sustainable Development (UNFSD).”

505.23.1 “Universal Nexus Financing for Sustainable Development (UNFSD)” means a universal or global Nexus finance-readiness, sustainable development, capital-readability, diligence translation, public-good-to-capital, or development-finance-related framework operated or stewarded by the appropriate GRA or Nexus finance authority.

505.23.2 GCRI US may support UNFSD by providing technical evidence, methods, public-good software, technical baselines, and correction signals without entering regulated finance activity.

#### 505.24 “Global Nexus Consortium.”

505.24.1 “Global Nexus Consortium” means a global consortium, council, alliance, or coordination body structured for Nexus public-good coordination across countries, regions, sectors, institutions, public authorities, enterprise actors, universities, laboratories, communities, and civil society.

505.24.2 Participation in a Global Nexus Consortium shall not create merger, agency, partnership, joint venture, shared liability, public authority delegation, finance-readiness, certification, recognition, procurement approval, provider preference, or enterprise execution by GCRI US.

#### 505.25 “Regional Nexus Consortium.”

505.25.1 “Regional Nexus Consortium” means a regional Nexus coordination body, consortium, forum, or interface organized across a region, cross-border area, macro-region, or sectoral geography.

505.25.2 Regional Nexus Consortium interfaces shall preserve legal separateness, local law, cross-border data controls, public authority boundaries, protected knowledge controls, and public-good stack / enterprise stack separation.

#### 505.26 “National Nexus Consortium.”

505.26.1 “National Nexus Consortium” means a national Nexus public-good consortium, national coordination body, national public-good interface, or national stakeholder formation structure.

505.26.2 National Nexus Consortiums may interface with GCRI US for evidence, methods, observability, public authority learning, public-good software, technical baselines, and technical records.

505.26.3 National Nexus Consortium participation does not make GCRI US a national company, public authority, procurement authority, finance authority, or enterprise execution vehicle.

#### 505.27 “State Nexus Interface.”

505.27.1 “State Nexus Interface” means a state-level Nexus coordination, public authority, public-good, technical, observability, community, university, infrastructure, or implementation-support interface.

505.27.2 State Nexus Interfaces shall be governed by capacity classification, public authority boundary rules, state law localization, public records considerations, data controls, and public-safe publication controls.

#### 505.28 “Territorial Nexus Interface.”

505.28.1 “Territorial Nexus Interface” means a territorial-level Nexus coordination, public authority, public-good, technical, observability, community, infrastructure, disaster, climate, health, or public-safe interface.

505.28.2 Territorial Nexus Interfaces shall preserve local law, territorial public authority boundaries, language access, accessibility, protected knowledge, public-safe mapping, and data / AI / cyber controls.

#### 505.29 “Tribal / Indigenous Nexus Interface.”

505.29.1 “Tribal / Indigenous Nexus Interface” means a Nexus interface involving Tribal governments, Indigenous governments, Indigenous communities, Indigenous institutions, Indigenous data, Indigenous knowledge, local knowledge, cultural knowledge, environmental knowledge, sacred knowledge, sensitive sites, or related public authority and community protocols.

505.29.2 Tribal / Indigenous Nexus Interfaces require lawful and respectful structuring, safeguards review, permission records, consent or non-consent records where applicable, attribution or non-attribution records, public-safe mapping review, protected knowledge controls, and grievance pathways.

505.29.3 No Tribal / Indigenous Nexus Interface shall be inferred from attendance, public availability of information, informal discussion, third-party data, or technical accessibility.

#### 505.30 “Local Nexus Interface.”

505.30.1 “Local Nexus Interface” means a local, county, municipal, metropolitan, community, utility, port, public health, emergency management, public safety, public works, infrastructure, university, civil society, or place-based Nexus interface.

505.30.2 Local Nexus Interfaces shall preserve public authority boundary rules, public-safe mapping, community safeguards, accessibility, civil rights, local knowledge protections, and no public warning or emergency command authority by GCRI US.

#### 505.31 “National Company.”

505.31.1 “National Company” means a national-level enterprise stack entity, company, vehicle, implementation company, or execution-side organization structured to support or implement Nexus-aligned projects, operations, services, or investible activities where lawfully organized.

505.31.2 A National Company is legally distinct from GCRI US unless competent records expressly provide otherwise.

505.31.3 GCRI US does not become a National Company by providing technical evidence, methods, public-good software, public authority learning, or technical baseline support.

#### 505.32 “State Operating Company.”

505.32.1 “State Operating Company” means a state-level enterprise stack company or operating vehicle organized for implementation, service delivery, operations, asset support, project support, or other execution-side functions.

505.32.2 GCRI US shall remain legally and functionally distinct from any State Operating Company.

505.32.3 State Operating Company references shall not imply public authority adoption, procurement approval, provider preference, certification, recognition, finance-readiness, or GCRI US execution.

#### 505.33 “Regional Company.”

505.33.1 “Regional Company” means a regional enterprise stack company or operating vehicle organized for implementation, service delivery, operations, asset support, project support, or other execution-side functions across a region.

505.33.2 A Regional Company is not GCRI US and shall not be treated as holding GCRI US authority without competent record.

#### 505.34 “Project SPV.”

505.34.1 “Project SPV” means a special purpose vehicle, project company, project entity, implementation vehicle, finance vehicle, asset vehicle, or other enterprise stack entity organized for a specific project or set of projects.

505.34.2 Project SPVs may receive or use public-good evidence, methods, technical baselines, or proof-pack inputs through proper interfaces, but such use does not create GCRI US execution, endorsement, certification, recognition, procurement approval, public authority approval, finance-readiness, or provider preference.

505.34.3 GCRI US shall not be liable for a Project SPV merely because GCRI US provided public-good technical support, unless a lawful written instrument expressly creates an obligation.

#### 505.35 “Qualified Enterprise Provider.”

505.35.1 “Qualified Enterprise Provider” means a provider, vendor, operator, implementer, technology company, service provider, infrastructure provider, software provider, cloud provider, AI provider, cybersecurity provider, telecommunications provider, engineering provider, or other enterprise actor that meets criteria established by an appropriate enterprise stack, procurement, standards, or other competent authority.

505.35.2 GCRI US does not by default qualify, approve, certify, rank, prefer, recognize, or procure Qualified Enterprise Providers.

505.35.3 Any reference to a Qualified Enterprise Provider shall be subject to provider neutrality, public-safe claims, public authority boundaries, procurement neutrality, finance-boundary review, and records.

#### 505.36 “Host.”

505.36.1 “Host” means a person or entity that provides venue, infrastructure, data environment, cloud environment, compute environment, repository environment, public authority interface, event setting, controlled room, community setting, technical environment, or other hosting support.

505.36.2 Host status does not create control, endorsement, public authority approval, procurement advantage, certification, recognition, finance-readiness, provider preference, or authority to direct Corporation outputs.

505.36.3 Host relationships shall be recorded and reviewed for data, AI, cyber, privacy, public authority, safeguards, conflict, sponsorship, and public-safe publication implications.

#### 505.37 “Sponsor.”

505.37.1 “Sponsor” means a person or entity providing funding, support, sponsorship, in-kind resources, cloud credits, compute credits, software credits, event support, program support, technical support, or other resources to the Corporation or a Corporation-related activity.

505.37.2 Sponsor status does not create control over evidence, methods, findings, publications, corrections, public authority access, technical baselines, software, recognition-related inputs, finance-readiness inputs, certification meaning, provider status, procurement outcomes, or Nexus interface meaning.

505.37.3 Sponsor references shall be accurate, proportionate, recorded, public-safe, and subject to sponsor non-control.

#### 505.38 “Public Authority.”

505.38.1 “Public Authority” means any federal, state, District of Columbia, territorial, Tribal / Indigenous government where lawfully and respectfully engaged, local, county, municipal, metropolitan, public health, emergency management, public safety, public works, public infrastructure, utility, port, airport, transit, transportation, water, energy, food, telecom, cyber, environmental, housing, education, research, health-system, public finance, budget, treasury, grant, procurement, regulatory, inspector general, legislative, judicial, or oversight authority or public-sector body.

505.38.2 Public Authority includes public officials, public employees, public institutions, public infrastructure operators, public universities, public laboratories, regulators, public finance readers, emergency management personnel, public health personnel, public safety personnel, and public works personnel when acting within relevant public-sector contexts.

505.38.3 Public Authority participation in the Corporation’s activities shall be classified by capacity and shall not imply endorsement, adoption, funding approval, procurement approval, public finance approval, regulatory approval, public warning, emergency command, sovereign obligation, public-private partnership, or public authority decision unless competent records expressly provide such meaning.

#### 505.39 Institutional Definition Records.

505.39.1 The Corporation shall maintain Institutional Definition Records, including GCRI US definition records, The Global Centre for Risk and Innovation - United States definition records, GCRI Function records, GCRI Canada records, Other GCRI Entity records, GRF definition records, GRA definition records, Nexus Network records, Nexus Public-Good Stack records, Nexus Enterprise Stack records, Nexus Standards records, Protocol Authority records, Nexus Observatory records, Nexus Universe records, Nexus Risk Management records, Nexus Rails records, Nexus Grid records, Nexus Academy records, Nexus Competence Cells records, Nexus Docket records, NFD records, RNFD records, UNFSD records, Global Nexus Consortium records, Regional Nexus Consortium records, National Nexus Consortium records, State Nexus Interface records, Territorial Nexus Interface records, Tribal / Indigenous Nexus Interface records, Local Nexus Interface records, National Company records, State Operating Company records, Regional Company records, Project SPV records, Qualified Enterprise Provider records, Host records, Sponsor records, Public Authority records, correction records, controlled vocabulary records, and archive records.

***

### Section 506. Governance Definitions

#### 506.1 “Board.”

506.1.1 “Board” means the Board of Directors of the Corporation, as constituted under applicable law, the certificate or articles, these Bylaws, and competent governance records.

506.1.2 The Board is the Corporation’s governing body and holds the powers, duties, oversight responsibilities, reserved matters, fiduciary responsibilities, amendment authority, dissolution authority, and other authority assigned by law, the certificate or articles, and these Bylaws.

#### 506.2 “Director.”

506.2.1 “Director” means an individual lawfully elected, appointed, designated, or otherwise seated as a member of the Board according to applicable law, the certificate or articles, these Bylaws, and Board records.

506.2.2 A Director owes the duties required by law and these Bylaws and shall comply with conflicts, confidentiality, records, public authority boundary, finance-boundary, data / AI / cyber, safeguards, and non-retaliation obligations.

#### 506.3 “Officer.”

506.3.1 “Officer” means an individual appointed or elected to an officer role of the Corporation according to applicable law, the certificate or articles, these Bylaws, Board resolution, or competent authority record.

506.3.2 Officer authority exists only to the extent recorded and shall be subject to the Authority Matrix, Delegation records, Board oversight, reserved matters, conflicts rules, records duties, and legal limits.

#### 506.4 “Principal Officer.”

506.4.1 “Principal Officer” means the officer designated by the Board or applicable law as the primary executive, administrative, or accountable officer for the Corporation or for a legally required filing, record, notice, or operational function.

506.4.2 Principal Officer status does not create authority beyond the office, delegation, Board resolution, or legal requirement defining that status.

#### 506.5 “Executive Leadership.”

506.5.1 “Executive Leadership” means the officers, senior staff, executives, or other persons designated by the Board or Principal Officer to support management of the Corporation.

506.5.2 Executive Leadership may support implementation but shall not exercise Board reserved powers, amendment authority, dissolution authority, public authority status, finance-readiness authority, recognition authority, certification authority, procurement authority, or enterprise execution authority unless lawfully authorized.

#### 506.6 “Secretary.”

506.6.1 “Secretary” means the officer or designated person responsible for corporate records, minutes, notices, certifications, governance records, official repository coordination, and other duties assigned by law, the certificate or articles, these Bylaws, or Board resolution.

506.6.2 Secretary certification shall certify record status only within recorded authority and shall not create substantive authority, public authority meaning, finance-readiness, recognition, certification, procurement approval, or public warning meaning.

#### 506.7 “Treasurer.”

506.7.1 “Treasurer” means the officer or designated person responsible for financial records, budgets, accounts, fiscal controls, tax records, restricted fund records, grant financial records, financial reporting, and related duties assigned by law, the certificate or articles, these Bylaws, or Board resolution.

506.7.2 Treasurer authority shall be subject to financial controls, Board oversight, spending authority, conflicts rules, restricted fund rules, grant rules, and records requirements.

#### 506.8 “Chair.”

506.8.1 “Chair” means the Director or officer designated to chair the Board or another body according to these Bylaws, Board resolution, or charter.

506.8.2 Chair status does not create unilateral authority to amend Bylaws, dissolve the Corporation, approve reserved matters, bind the Corporation beyond delegated authority, or speak publicly beyond approved authority.

#### 506.9 “Vice-Chair.”

506.9.1 “Vice-Chair” means the Director or officer designated to support or substitute for the Chair within the scope authorized by these Bylaws, Board resolution, or charter.

506.9.2 Vice-Chair authority shall be limited to recorded authority.

#### 506.10 “President.”

506.10.1 “President” means an officer title that may be used for the Corporation’s executive, institutional, or administrative leadership role if adopted by Board record.

506.10.2 President authority shall be defined by Board resolution, officer appointment record, Authority Matrix, employment or service agreement where applicable, and these Bylaws.

#### 506.11 “Executive Director.”

506.11.1 “Executive Director” means an officer or senior executive role responsible for day-to-day management, implementation, public-benefit program coordination, staff supervision, external coordination, or other functions assigned by Board record.

506.11.2 Executive Director authority shall not include Board reserved matters unless expressly delegated and lawful.

#### 506.12 “Chief Executive Officer.”

506.12.1 “Chief Executive Officer” means an officer title that may be used where the Board designates a chief executive role.

506.12.2 Chief Executive Officer authority shall be recorded and shall not create public authority status, finance-readiness authority, certification authority, recognition authority, procurement authority, or enterprise execution authority.

#### 506.13 “Committee.”

506.13.1 “Committee” means a body created by the Board or other competent authority to perform governance, oversight, advisory, review, implementation, assurance, or other functions within a recorded scope.

506.13.2 Committee authority shall be defined by charter, Board resolution, these Bylaws, or applicable law and shall not exceed recorded authority.

#### 506.14 “Standing Committee.”

506.14.1 “Standing Committee” means a committee intended to continue for an ongoing governance or oversight function until dissolved, amended, or superseded.

506.14.2 Standing Committees may address governance, finance, audit, compliance, risk, research integrity, data / AI / cyber, safeguards, publication, technical assets, public authority boundaries, Nexus coordination, or other recurring matters.

#### 506.15 “Special Committee.”

506.15.1 “Special Committee” means a committee created for a limited purpose, time, matter, investigation, project, transaction, amendment, wind-up, assurance review, conflict review, or other defined task.

506.15.2 A Special Committee shall terminate or be reviewed according to its charter or Board record.

#### 506.16 “Executive Committee.”

506.16.1 “Executive Committee” means a committee authorized by the Board, if permitted by law and these Bylaws, to act on specified matters between Board meetings.

506.16.2 Executive Committee authority shall be limited by law, Board reserved matters, these Bylaws, the committee charter, and records.

506.16.3 An Executive Committee shall not amend Bylaws, dissolve the Corporation, approve nondelegable matters, or act contrary to Board instructions unless lawfully authorized.

#### 506.17 “Council.”

506.17.1 “Council” means a governance-adjacent, advisory, coordination, technical, public-good, public authority learning, stakeholder, safeguards, or Nexus interface body created or recognized by competent record.

506.17.2 A Council shall have only the authority expressly assigned by its charter or record and shall not be presumed to govern the Corporation.

#### 506.18 “Leadership Council.”

506.18.1 “Leadership Council” means a Council composed of leaders, officers, directors, advisors, institutional representatives, technical experts, public-good representatives, or other persons designated to support strategy, coordination, review, or advisory functions.

506.18.2 Leadership Council participation does not create Board authority, officer authority, public authority approval, finance-readiness, recognition, certification, procurement approval, or provider preference.

#### 506.19 “Helix Council.”

506.19.1 “Helix Council” means a Nexus-aligned or Corporation-recognized council structured to support cross-functional coordination among public-good, technical, institutional, public authority, safeguards, finance-boundary, recognition-boundary, standards-support, and enterprise-interface considerations.

506.19.2 A Helix Council shall not override the Board, GCRI / GRF / GRA role separation, public authority boundaries, finance boundaries, certification boundaries, recognition boundaries, procurement neutrality, or legal separateness.

#### 506.20 “Advisory Forum.”

506.20.1 “Advisory Forum” means an advisory body, forum, roundtable, convening, or group formed to provide non-binding advice, expertise, perspective, review, or feedback.

506.20.2 Advisory Forum participation shall not create authority to bind the Corporation, endorse outputs, approve public authority meaning, approve finance meaning, certify, recognize, procure, or execute.

#### 506.21 “Working Group.”

506.21.1 “Working Group” means a time-limited or continuing group formed to perform drafting, research, technical, review, coordination, public-good, publication, safeguards, or interface work within a defined scope.

506.21.2 Working Group outputs are drafts or recommendations unless adopted by competent authority.

#### 506.22 “Expert Panel.”

506.22.1 “Expert Panel” means a group of persons with technical, legal, governance, sectoral, public authority, community, safeguards, data, AI, cyber, finance-boundary, or other expertise convened for review, advice, evaluation, or challenge.

506.22.2 Expert Panel conclusions shall not be treated as certification, public authority approval, finance-readiness, recognition, procurement approval, rating, public warning, or emergency command unless competent authority separately provides such meaning.

#### 506.23 “Peer Review Panel.”

506.23.1 “Peer Review Panel” means a panel convened to review research, evidence, methods, publications, datasets, technical baselines, software, dashboards, maps, or technical outputs for integrity, quality, limitations, and correction needs.

506.23.2 Peer review supports evidence integrity but does not itself create certification, recognition, finance-readiness, procurement approval, public authority approval, or legal compliance approval.

#### 506.24 “Model Review Panel.”

506.24.1 “Model Review Panel” means a review body convened to review AI systems, models, model cards, system cards, benchmark cards, evaluation harnesses, inference records, compute workload records, proof receipts, bias, safety, hallucination, drift, prompt injection, data leakage, privacy, cybersecurity, and public-safe output risks.

506.24.2 Model Review Panel findings shall be recorded and shall not create public authority decision, finance-readiness, certification, recognition, procurement approval, public warning, or emergency command.

#### 506.25 “Controlled-Room Review Group.”

506.25.1 “Controlled-Room Review Group” means a group assigned to review, approve, monitor, or close out controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, no-download rooms, regulator-listening rooms, public finance reader rooms, emergency learning rooms, or other restricted environments.

506.25.2 Controlled-Room Review Group authority shall be limited to its charter and shall preserve data, AI, cyber, privacy, public authority, finance, competition, protected knowledge, public-safe publication, and records controls.

#### 506.26 “Delegation.”

506.26.1 “Delegation” means a recorded grant of authority by the Board, an officer, a committee, or another competent authority to a person or role to perform specified actions within stated limits.

506.26.2 Delegation shall be interpreted narrowly and shall not include reserved matters, amendment authority, dissolution authority, finance-readiness authority, recognition authority, certification authority, procurement authority, public authority status, public warning authority, emergency command authority, or enterprise execution authority unless expressly and lawfully included.

#### 506.27 “Authority Matrix.”

506.27.1 “Authority Matrix” means the recorded instrument identifying who may approve, sign, release, publish, spend, contract, access, correct, restrict, hold, transfer, archive, or otherwise act for the Corporation by role, threshold, matter, risk class, and limitation.

506.27.2 The Authority Matrix implements but does not override these Bylaws.

#### 506.28 “Reserved Matter.”

506.28.1 “Reserved Matter” means a matter reserved to the Board, members where required, or another competent authority by law, the certificate or articles, these Bylaws, Board resolution, policy, contract, grant, or risk classification.

506.28.2 Reserved Matters include, at minimum where applicable, bylaw amendment, dissolution, major asset disposition, major restricted fund action, major public authority boundary issue, major finance-boundary issue, major technical asset disposition, major legal claim, indemnification decision where required, and other matters designated by the Board.

#### 506.29 “Quorum.”

506.29.1 “Quorum” means the minimum number or proportion of Directors, committee members, members where applicable, or other voting participants required to conduct business.

506.29.2 Quorum shall be determined under applicable law, the certificate or articles, these Bylaws, or the applicable charter.

#### 506.30 “Recusal.”

506.30.1 “Recusal” means abstaining from participation in deliberation, decision, vote, access, influence, or approval because of a conflict, related-party interest, legal requirement, confidentiality concern, public authority issue, finance-boundary issue, or other integrity concern.

506.30.2 Recusal shall be recorded where material.

#### 506.31 “Abstention.”

506.31.1 “Abstention” means a decision not to vote while remaining present or recorded for meeting purposes, subject to applicable law and governance rules.

506.31.2 Abstentions shall be recorded where required or material.

#### 506.32 “Written Consent.”

506.32.1 “Written Consent” means action taken without a meeting by written, electronic, or other legally permitted consent according to applicable law, the certificate or articles, these Bylaws, and governance records.

506.32.2 Written Consent shall identify action approved, date, consenting persons, required threshold, and effective date.

#### 506.33 “Emergency Decision.”

506.33.1 “Emergency Decision” means a time-sensitive decision made under emergency or urgent conditions according to authority granted by law, these Bylaws, Board resolution, policy, or recorded delegation.

506.33.2 Emergency Decisions shall be limited to what is necessary, recorded promptly, reviewed or ratified where required, and shall not create unauthorized public authority action, finance activity, certification, recognition, procurement approval, public warning, emergency command, or enterprise execution.

#### 506.34 “Break-Glass Authority.”

506.34.1 “Break-Glass Authority” means narrowly limited emergency authority to take immediate protective action to prevent or mitigate serious harm, legal violation, data breach, cybersecurity incident, public-safe risk, protected knowledge exposure, public authority confusion, finance-boundary violation, repository compromise, or record integrity failure.

506.34.2 Break-Glass Authority may include access restriction, system isolation, credential rotation, publication hold, repository hold, data hold, controlled-room hold, takedown, or escalation.

506.34.3 Break-Glass Authority shall be recorded, reviewed, sunsetted, and ratified where required.

#### 506.35 Governance Definition Records.

506.35.1 The Corporation shall maintain Governance Definition Records, including Board definition records, Director records, Officer records, Principal Officer records, Executive Leadership records, Secretary records, Treasurer records, Chair records, Vice-Chair records, President records, Executive Director records, Chief Executive Officer records, Committee records, Standing Committee records, Special Committee records, Executive Committee records, Council records, Leadership Council records, Helix Council records, Advisory Forum records, Working Group records, Expert Panel records, Peer Review Panel records, Model Review Panel records, Controlled-Room Review Group records, Delegation records, Authority Matrix records, Reserved Matter records, Quorum records, Recusal records, Abstention records, Written Consent records, Emergency Decision records, Break-Glass Authority records, correction records, and archive records.

***

### Section 507. Membership, Participation, and Support Definitions

#### 507.1 “Member.”

507.1.1 “Member” means a person or entity having membership status in the Corporation only if such status is created by applicable law, the certificate or articles, these Bylaws, Board resolution, or competent membership record.

507.1.2 Use of “member” in public materials, community materials, program materials, supporter materials, or participation materials shall not create statutory membership, voting rights, governance rights, fiduciary rights, equity rights, distribution rights, or authority to bind the Corporation unless competent records expressly provide such rights.

#### 507.2 “Statutory Member.”

507.2.1 “Statutory Member” means a member having rights under the governing nonprofit corporation statute, the certificate or articles, or these Bylaws.

507.2.2 Statutory Member rights shall exist only to the extent expressly created and recorded.

#### 507.3 “Voting Member.”

507.3.1 “Voting Member” means a member with voting rights on specified matters under applicable law, the certificate or articles, these Bylaws, or competent records.

507.3.2 Voting Member status shall not be inferred from donation, sponsorship, participation, subscription, affiliation, attendance, contribution, public authority status, or support.

#### 507.4 “Non-Voting Member.”

507.4.1 “Non-Voting Member” means a person or entity designated as a member without voting rights, if such class is lawfully created.

507.4.2 Non-Voting Member status shall not confer governance authority unless expressly granted by competent record.

#### 507.5 “Supporter.”

507.5.1 “Supporter” means a person or entity that provides encouragement, participation, contribution, donation, sponsorship, in-kind support, or other support without governance authority.

507.5.2 Supporter status does not confer membership, voting rights, endorsement authority, public authority meaning, finance-readiness, recognition, certification, procurement approval, provider preference, or right to use the Corporation’s name.

#### 507.6 “Subscriber.”

507.6.1 “Subscriber” means a person or entity receiving publications, updates, notices, newsletters, repository updates, public-safe summaries, or other communications from the Corporation.

507.6.2 Subscriber status does not confer membership, participation authority, governance rights, access rights, or endorsement.

#### 507.7 “Affiliate.”

507.7.1 “Affiliate” means a person or entity described as affiliated with the Corporation only where competent records define the relationship.

507.7.2 Affiliate status shall be construed narrowly and shall not create agency, partnership, joint venture, shared liability, authority to bind the Corporation, or institutional merger.

#### 507.8 “Participant.”

507.8.1 “Participant” means any person or entity participating in a program, meeting, room, committee, council, forum, working group, panel, event, research activity, public authority interface, technical activity, repository, training, Academy activity, Nexus interface, or other Corporation-related activity.

507.8.2 Participant status does not create authority to bind the Corporation, approve outputs, make public claims, certify, recognize, determine finance-readiness, approve procurement, issue public warnings, or issue emergency commands.

#### 507.9 “Public Authority Participant.”

507.9.1 “Public Authority Participant” means a Public Authority, public official, public employee, public infrastructure operator, public university representative, public laboratory representative, regulator, public finance reader, emergency-management participant, public health participant, public safety participant, public works participant, or other public-sector participant involved in a Corporation activity.

507.9.2 Public Authority Participant status shall be classified by capacity and shall not imply endorsement, adoption, approval, funding, procurement, regulatory approval, public finance approval, public warning, emergency command, or sovereign obligation.

#### 507.10 “Observer.”

507.10.1 “Observer” means a participant admitted for learning, awareness, listening, or observation without approval authority, adoption authority, endorsement authority, decision authority, public authority decision-making authority, finance authority, certification authority, recognition authority, or procurement authority.

507.10.2 Observer attendance shall not be used as endorsement, adoption, funding approval, procurement approval, regulatory approval, public finance approval, public warning, emergency command, or public authority decision.

#### 507.11 “Regulator-Listening Participant.”

507.11.1 “Regulator-Listening Participant” means a regulator or regulatory staff member participating in a listening, learning, awareness, or information-receiving capacity.

507.11.2 Regulator-Listening participation shall not constitute regulatory guidance, approval, safe harbor, permit, compliance determination, enforcement position, waiver, policy adoption, or public authority endorsement.

#### 507.12 “Public Finance Reader.”

507.12.1 “Public Finance Reader” means a public finance, budget, treasury, grant, public credit, development finance, or public funding participant reviewing materials for learning, literacy, diligence awareness, or public finance understanding.

507.12.2 Public Finance Reader status shall not create grant approval, budget allocation, appropriation, public finance approval, MDB / DFI approval, public guarantee, public credit, tax credit approval, sovereign obligation, capital commitment, investment advice, or GRA finance-readiness determination.

#### 507.13 “Emergency-Management Participant.”

507.13.1 “Emergency-Management Participant” means a public or authorized emergency management person participating in learning, scenario, simulation, tabletop, after-action, public-safe reporting, or resilience literacy activities.

507.13.2 Emergency-Management Participant status shall not create incident command, dispatch authority, evacuation authority, emergency alert authority, official public warning, public health order, safety command, or operational resource direction by the Corporation.

#### 507.14 “Public Infrastructure Operator Participant.”

507.14.1 “Public Infrastructure Operator Participant” means a person or entity operating, managing, or supporting public or publicly regulated infrastructure participating in a Corporation activity.

507.14.2 Such participation shall be subject to infrastructure-sensitive data controls, cyber-sensitive data controls, public authority boundary controls, procurement neutrality, and public-safe publication controls.

#### 507.15 “Controlled-Room Participant.”

507.15.1 “Controlled-Room Participant” means a person admitted to a controlled room, clean room, data room, evidence room, public authority room, no-download room, regulator-listening room, public finance reader room, emergency learning room, or other restricted environment.

507.15.2 Controlled-Room Participant status is limited by room charter, access records, capacity classification, confidentiality, data / AI / cyber restrictions, public authority boundaries, finance boundaries, protected knowledge restrictions, and no-overclaim rules.

#### 507.16 “Advisor.”

507.16.1 “Advisor” means a person appointed, retained, invited, or recognized to provide advice, expertise, perspective, review, or counsel to the Corporation.

507.16.2 Advisor status does not create authority to bind the Corporation or approve outputs unless expressly delegated by competent record.

#### 507.17 “Fellow.”

507.17.1 “Fellow” means a person participating in a fellowship, research, technical, policy, public-good, training, Academy, or Nexus-related program of the Corporation.

507.17.2 Fellow status shall be subject to role records, confidentiality, IP, data, AI, cyber, publication, safeguards, and public claims rules.

#### 507.18 “Volunteer.”

507.18.1 “Volunteer” means a person providing services without compensation or with limited reimbursement, according to applicable law and Corporation records.

507.18.2 Volunteer status does not create employment, officer status, agency, public authority status, or authority to bind the Corporation unless competent records provide otherwise.

#### 507.19 “Contributor.”

507.19.1 “Contributor” means a person or entity contributing content, code, data, documentation, review, research, methods, technical assets, public-safe materials, or other work product to the Corporation or its repositories.

507.19.2 Contributor rights and duties shall be governed by contributor terms, licenses, assignments, confidentiality rules, data restrictions, AI-use restrictions, public-safe claims rules, and records.

#### 507.20 “Technical Contributor.”

507.20.1 “Technical Contributor” means a Contributor contributing software, code, schemas, APIs, SDKs, profiles, datasets, models, test harnesses, benchmarks, documentation, infrastructure, cybersecurity materials, or technical methods.

507.20.2 Technical Contributors shall comply with secure development, repository governance, IP, license, data, AI, cyber, secrets, export-control, controlled technology, public-safe release, and no-overclaim requirements.

#### 507.21 “Developer.”

507.21.1 “Developer” means a person contributing to software, systems, code, repositories, APIs, SDKs, models, automation, infrastructure, or technical assets.

507.21.2 Developer status does not create maintainer authority, release authority, repository owner authority, publication authority, or institutional authority unless recorded.

#### 507.22 “Maintainer.”

507.22.1 “Maintainer” means a person authorized to maintain a repository, software project, dataset, technical baseline, schema, API, SDK, profile, documentation set, or technical asset.

507.22.2 Maintainer authority shall be defined by repository records and shall not include authority to alter institutional meaning, certify, recognize, determine finance-readiness, approve procurement, or issue public authority claims.

#### 507.23 “Reviewer.”

507.23.1 “Reviewer” means a person assigned to review records, research, evidence, methods, publications, public claims, data, AI systems, cybersecurity controls, technical assets, repositories, public authority references, finance-boundary statements, safeguards, or Nexus interface materials.

507.23.2 Reviewer findings are advisory or review records unless approval authority is separately recorded.

#### 507.24 “Public-Good Support.”

507.24.1 “Public-Good Support” means financial, in-kind, technical, infrastructure, data, cloud, compute, software, hosting, professional, volunteer, institutional, or other support provided to advance the Corporation’s public-benefit and public-good purposes.

507.24.2 Public-Good Support shall be support-without-control unless a lawful and recorded restriction applies.

#### 507.25 “Donation.”

507.25.1 “Donation” means a voluntary contribution to the Corporation without exchange for equivalent value, subject to applicable law, donor restrictions where accepted, tax rules, records, and public-benefit use.

507.25.2 Donation does not create control, membership, endorsement, recognition, finance-readiness, certification, procurement advantage, or public authority access.

#### 507.26 “Grant.”

507.26.1 “Grant” means a financial or in-kind award, contribution, cooperative agreement, subaward, public grant, private grant, research grant, or similar support subject to grant terms, restrictions, reporting, allowable use, and records.

507.26.2 Grant terms may define scope but shall not control evidence, methods, findings, corrections, public-safe publications, recognition, finance-readiness, certification, procurement neutrality, or provider status beyond lawful and recorded terms.

#### 507.27 “Sponsorship.”

507.27.1 “Sponsorship” means support provided in exchange for acknowledgment, participation, visibility, or other limited benefits consistent with law and the Corporation’s public-benefit purpose.

507.27.2 Sponsorship shall not create sponsor control, public authority access, provider preference, procurement advantage, finance-readiness, recognition, certification, or outcome purchase.

#### 507.28 “In-Kind Contribution.”

507.28.1 “In-Kind Contribution” means non-cash support, including services, equipment, cloud credits, compute credits, software credits, data access, venue support, professional support, technical support, repository support, or other non-monetary resources.

507.28.2 In-Kind Contributions shall be reviewed for value where required, restrictions, conflicts, data / AI / cyber risks, provider dependency, sponsor control, and public-benefit compatibility.

#### 507.29 “Restricted Fund.”

507.29.1 “Restricted Fund” means money or assets restricted by donor, grantor, law, public authority instrument, contract, Board designation, or other competent record for a specified purpose, time, program, project, geography, or use.

507.29.2 Restricted Funds shall be used, tracked, reported, reallocated, returned, or closed out according to applicable restrictions and law.

#### 507.30 “Unrestricted Support.”

507.30.1 “Unrestricted Support” means support received without donor, grantor, sponsor, contract, or legal restriction beyond general public-benefit use and applicable law.

507.30.2 Unrestricted Support remains subject to nonprofit purpose, private inurement prohibitions, private benefit restrictions, fiscal controls, and Board oversight.

#### 507.31 “Fee.”

507.31.1 “Fee” means an amount charged for lawful services, events, materials, training, access, participation, cost recovery, technical support, publication, or other activity consistent with the Corporation’s nonprofit purpose.

507.31.2 Fees shall not create equity, membership rights, public authority status, certification, recognition, finance-readiness, procurement approval, or provider preference unless competent records expressly provide a lawful limited meaning.

#### 507.32 “Cost Recovery.”

507.32.1 “Cost Recovery” means charges, reimbursements, fees, or contributions intended to recover reasonable costs of activities, programs, events, publications, technical assets, controlled rooms, data processing, public authority learning support, or other lawful functions.

507.32.2 Cost Recovery shall not be used to distribute profits, create private inurement, sell outcomes, or create sponsor or provider control.

#### 507.33 “Sponsored Seat.”

507.33.1 “Sponsored Seat” means participation support funded by a sponsor, donor, funder, host, public-good support provider, or other contributor for a participant, fellow, advisor, learner, public authority participant, community participant, or other person.

507.33.2 A Sponsored Seat shall not create sponsor control over participant views, evidence, methods, findings, publication, public authority access, recognition, finance-readiness, certification, procurement, or outcomes.

#### 507.34 “Support-Without-Control.”

507.34.1 “Support-Without-Control” means the principle that donations, grants, sponsorships, in-kind contributions, cloud credits, compute credits, software credits, hosted resources, public-good support, or other support may assist the Corporation’s public-benefit mission but shall not control institutional judgment, evidence, methods, findings, public-safe publication, correction, public authority access, technical baseline status, software status, provider status, recognition, finance-readiness, certification, procurement outcomes, or Nexus interface meaning.

507.34.2 Support-Without-Control is a mandatory interpretive principle for all support relationships.

#### 507.35 Membership, Participation, and Support Definition Records.

507.35.1 The Corporation shall maintain Membership, Participation, and Support Definition Records, including Member records, Statutory Member records, Voting Member records, Non-Voting Member records, Supporter records, Subscriber records, Affiliate records, Participant records, Public Authority Participant records, Observer records, Regulator-Listening Participant records, Public Finance Reader records, Emergency-Management Participant records, Public Infrastructure Operator Participant records, Controlled-Room Participant records, Advisor records, Fellow records, Volunteer records, Contributor records, Technical Contributor records, Developer records, Maintainer records, Reviewer records, Public-Good Support records, Donation records, Grant records, Sponsorship records, In-Kind Contribution records, Restricted Fund records, Unrestricted Support records, Fee records, Cost Recovery records, Sponsored Seat records, Support-Without-Control records, correction records, and archive records.

***

### Section 508. Public-Benefit and Nonprofit Definitions

#### 508.1 “Public-Benefit Purpose.”

508.1.1 “Public-Benefit Purpose” means the Corporation’s lawful purpose to advance public benefit through evidence, methods, observability, ontology, technical truth, public-good R\&D, public-good software, open technical baselines, verifiable compute and verifiable intelligence methods, public authority learning support, public-safe publication, safeguards, protected knowledge controls, correctionability, and Nexus public-good coordination.

508.1.2 Public-Benefit Purpose shall be interpreted to exclude private inurement, impermissible private benefit, sponsor capture, provider capture, enterprise capture, public authority capture, public-good asset enclosure, and unauthorized regulated activity.

#### 508.2 “Public-Good Purpose.”

508.2.1 “Public-Good Purpose” means a purpose directed toward shared public benefit, systemic risk literacy, resilience, public-safe evidence, public-good technical infrastructure, interoperable methods, public authority learning, community safeguards, open technical baselines, public-good software, and technical memory.

508.2.2 Public-Good Purpose does not mean unrestricted public disclosure of all materials. Public-good work may require controlled access, restricted rooms, confidentiality, privacy, cybersecurity protections, public authority restrictions, protected knowledge safeguards, or delayed publication.

#### 508.3 “Public-Good Technical Institution.”

508.3.1 “Public-Good Technical Institution” means a nonprofit or public-benefit institution that develops, stewards, documents, reviews, publishes, corrects, and maintains technical evidence, methods, software, baselines, ontologies, records, observability tools, and public-safe technical outputs for public-good purposes.

508.3.2 A Public-Good Technical Institution is not by that status a public authority, regulator, certifier, rating agency, procurement authority, finance authority, provider, operator, or enterprise execution vehicle.

#### 508.4 “Nonprofit Character.”

508.4.1 “Nonprofit Character” means the Corporation’s legal and institutional character as a nonstock, non-share, non-distributing organization organized and operated for public-benefit purposes rather than private ownership or profit distribution.

508.4.2 Nonprofit Character shall govern interpretation of revenue, fees, grants, donations, sponsorships, cost recovery, asset distribution, dissolution, compensation, contracts, and technical asset stewardship.

#### 508.5 “Non-Distribution Principle.”

508.5.1 “Non-Distribution Principle” means that the Corporation shall not distribute net earnings, surplus, assets, technical assets, IP value, or public-good value to private persons except through lawful payment of reasonable compensation, reimbursement, debts, obligations, contracts, indemnification, advancement, settlement, or other lawful amounts.

508.5.2 The Non-Distribution Principle shall survive dissolution and wind-up.

#### 508.6 “No Private Inurement.”

508.6.1 “No Private Inurement” means that no part of the Corporation’s net earnings, assets, restricted funds, public-good technical assets, IP, or institutional value shall inure to the benefit of directors, officers, insiders, founders, members, related parties, sponsors, donors, funders, providers, hosts, contractors, employees, or private persons except as lawfully permitted.

508.6.2 No Private Inurement is mandatory and shall not be waived by Board action, contract, sponsorship, donor preference, provider preference, or Nexus interface.

#### 508.7 “Impermissible Private Benefit.”

508.7.1 “Impermissible Private Benefit” means a non-incidental, unlawful, excessive, or mission-inconsistent benefit to a private person, related party, sponsor, provider, donor, funder, host, contractor, enterprise actor, or other private interest.

508.7.2 Impermissible Private Benefit includes public-good asset enclosure, provider preference, sponsor capture, procurement advantage, private control of evidence or methods, private control of public-safe publication, and restricted fund diversion where unlawful or inconsistent with mission.

#### 508.8 “Excess Benefit.”

508.8.1 “Excess Benefit” means a transaction or arrangement that provides economic benefit to a disqualified, related, insider, or covered person in excess of the value received by the Corporation or otherwise violates applicable tax or nonprofit rules.

508.8.2 Excess Benefit review shall be conducted where required by law, policy, or risk.

#### 508.9 “Tax-Exempt-Compatible.”

508.9.1 “Tax-Exempt-Compatible” means structured, interpreted, and operated in a manner intended to preserve compatibility with applicable tax-exempt or public-benefit tax requirements where the Corporation has, seeks, or maintains such status.

508.9.2 Tax-Exempt-Compatible shall not be used to represent that tax-exempt status has been granted, maintained, or approved unless competent tax records support the statement.

#### 508.10 “Charitable Purpose Where Applicable.”

508.10.1 “Charitable Purpose Where Applicable” means a purpose recognized as charitable under applicable law where the Corporation has adopted, seeks, or maintains charitable status or charitable-compatible activity.

508.10.2 Charitable purpose may include education, science, relief of burdens, community benefit, public-good technical infrastructure, or other lawful charitable purposes where applicable.

#### 508.11 “Scientific Purpose Where Applicable.”

508.11.1 “Scientific Purpose Where Applicable” means a purpose involving systematic research, evidence generation, methods development, technical inquiry, publication, replication where appropriate, public-benefit knowledge production, and public-good technical advancement.

508.11.2 Scientific purpose shall be pursued with research integrity, ethics review where required, evidence discipline, limitation disclosure, uncertainty disclosure, and correctionability.

#### 508.12 “Educational Purpose Where Applicable.”

508.12.1 “Educational Purpose Where Applicable” means a purpose involving public-benefit learning, public authority learning, evidence literacy, technical literacy, AI literacy, cyber literacy, resilience literacy, workforce learning, Academy support, training, public-safe publication, and dissemination of accurate, accessible, non-misleading information.

508.12.2 Educational purpose shall not be used to provide professional advice, public authority decision-making, public warning, emergency command, finance advice, certification, recognition, procurement approval, or legal compliance approval.

#### 508.13 “Public Trust.”

508.13.1 “Public Trust” means the confidence reasonably placed in the Corporation’s integrity, records, public-good mission, role separation, public-safe publication, correctionability, safeguards, and public-benefit stewardship.

508.13.2 Public Trust shall be protected through accuracy, transparency, limitation disclosure, independence, non-execution, sponsor non-control, provider neutrality, public authority boundary discipline, finance-boundary discipline, safeguards, and correction.

#### 508.14 “Public-Safe Transparency.”

508.14.1 “Public-Safe Transparency” means transparency that advances public understanding and accountability while protecting privacy, cybersecurity, infrastructure sensitivity, public authority confidentiality, privilege, protected knowledge, civil rights, community safety, and legal obligations.

508.14.2 Public-Safe Transparency is not unrestricted disclosure and shall not create certification, recognition, finance-readiness, procurement approval, rating, public authority endorsement, public warning, or emergency command.

#### 508.15 “Public-Good Firewall.”

508.15.1 “Public-Good Firewall” means the institutional, governance, records, conflict, funding, publication, role-separation, provider-neutrality, sponsor-non-control, public authority boundary, finance-boundary, data, AI, cyber, safeguards, and correction controls that prevent public-good functions from being captured by private, enterprise, sponsor, provider, public authority, finance, or political control.

508.15.2 The Public-Good Firewall protects evidence independence, methods independence, technical truth, public-safe publication, correctionability, and public trust.

#### 508.16 “Mission Lock.”

508.16.1 “Mission Lock” means the binding interpretation and governance principle that the Corporation’s assets, authority, programs, records, publications, technical assets, revenues, support, and wind-up actions shall remain aligned with public-benefit and public-good purposes.

508.16.2 Mission Lock prohibits drift into private-benefit operation, provider preference, sponsor capture, enterprise execution, public authority substitution, regulated finance activity, certification authority, recognition authority, or procurement authority without lawful and recorded authority.

#### 508.17 “Anti-Capture.”

508.17.1 “Anti-Capture” means the policy and governance principle that the Corporation shall not be controlled, distorted, directed, or functionally captured by sponsors, donors, funders, providers, hosts, enterprise actors, public authorities, political actors, capital actors, insiders, related parties, or any narrow interest inconsistent with public-benefit purpose.

508.17.2 Anti-Capture requires conflicts review, support-without-control, provider neutrality, public authority boundary discipline, finance-boundary discipline, procurement neutrality, public-safe publication, safeguards, independent records, and correctionability.

#### 508.18 “Provider Neutrality.”

508.18.1 “Provider Neutrality” means the principle that the Corporation shall not prefer, approve, certify, rank, endorse, select, procure, or create procurement advantage for providers unless a lawful, recorded, and appropriately authorized process expressly permits a limited action consistent with the Corporation’s role.

508.18.2 Provider Neutrality applies to software providers, AI providers, cloud providers, cybersecurity providers, telecom providers, infrastructure providers, consultants, contractors, hosts, vendors, enterprise providers, national companies, regional companies, Project SPVs, and other enterprise actors.

#### 508.19 “Sponsor Non-Control.”

508.19.1 “Sponsor Non-Control” means that sponsorship or sponsor support shall not control evidence, methods, findings, publication, corrections, public authority access, technical baselines, public-good software, provider status, recognition, finance-readiness, certification, procurement outcomes, public-safe summaries, or Nexus interface meaning.

508.19.2 Sponsor Non-Control shall apply regardless of sponsorship amount, visibility, strategic importance, in-kind contribution, technical dependency, or public authority relationship.

#### 508.20 “Donor Non-Control.”

508.20.1 “Donor Non-Control” means that donations shall not control governance, evidence, methods, findings, publications, corrections, technical assets, public authority access, provider status, recognition, finance-readiness, certification, procurement outcomes, or Nexus interface meaning except for lawful and accepted donor restrictions concerning use of donated assets.

508.20.2 Donor intent may restrict use of funds where lawfully accepted but shall not override the Corporation’s public-benefit purpose or integrity controls.

#### 508.21 “Funder Non-Control.”

508.21.1 “Funder Non-Control” means that funders, grantors, public grantors, cooperative agreement partners, public-good support providers, and other funding sources shall not control evidence, methods, findings, corrections, public-safe publications, public authority access, provider status, recognition, finance-readiness, certification, procurement outcomes, or Nexus interface meaning beyond lawful and recorded scope terms.

508.21.2 Funder reporting requirements shall not be interpreted as control over technical truth or institutional meaning.

#### 508.22 “Host Non-Control.”

508.22.1 “Host Non-Control” means that a host providing venue, infrastructure, cloud, compute, repository, data room, event space, public authority interface, technical environment, or other hosting support shall not control the Corporation’s governance, evidence, methods, findings, publications, corrections, access, technical baselines, public-good software, recognition, finance-readiness, certification, procurement outcomes, provider status, or Nexus interface meaning.

508.22.2 Host operational requirements may define safe use of hosted environments but shall not alter institutional authority.

#### 508.23 Public-Benefit and Nonprofit Definition Records.

508.23.1 The Corporation shall maintain Public-Benefit and Nonprofit Definition Records, including Public-Benefit Purpose records, Public-Good Purpose records, Public-Good Technical Institution records, Nonprofit Character records, Non-Distribution Principle records, No Private Inurement records, Impermissible Private Benefit records, Excess Benefit records, Tax-Exempt-Compatible records, Charitable Purpose records where applicable, Scientific Purpose records where applicable, Educational Purpose records where applicable, Public Trust records, Public-Safe Transparency records, Public-Good Firewall records, Mission Lock records, Anti-Capture records, Provider Neutrality records, Sponsor Non-Control records, Donor Non-Control records, Funder Non-Control records, Host Non-Control records, correction records, controlled vocabulary records, and archive records.

### Section 509. Non-Execution and Boundary Definitions

#### 509.1 “Non-Execution.”

509.1.1 “Non-Execution” means the Corporation’s binding institutional posture that GCRI US develops, stewards, reviews, records, publishes, corrects, and supports public-good evidence, methods, observability, ontology, technical truth, public-good software, open technical baselines, verifiable compute methods, verifiable intelligence methods, public authority learning, public-safe publication, safeguards, and Nexus coordination, without itself operating, commanding, financing, procuring, certifying, recognizing, rating, regulating, warning, underwriting, lending, insuring, executing, or delivering enterprise projects.

509.1.2 Non-Execution shall apply to all Corporation activities, including research, evidence generation, methods development, public-good software, technical baselines, dashboards, maps, controlled rooms, proof receipts, public authority learning materials, Nexus interface outputs, GRF interface inputs, GRA interface inputs, public-safe publications, Academy materials, repository releases, public claims, and technical asset disposition.

509.1.3 Non-Execution shall not prevent the Corporation from performing lawful nonprofit, administrative, research, technical, educational, public-good, convening, records, publication, repository, safeguarding, or support functions within its mission, provided such functions do not become execution, command, regulated finance, procurement, certification, recognition, public authority action, public warning, or enterprise operation.

#### 509.2 “Non-Executing Institution.”

509.2.1 “Non-Executing Institution” means an institution that supports public-benefit objectives through evidence, methods, records, public-good software, technical baselines, learning, observability, ontology, publication, safeguards, and coordination, while remaining outside the chain of operational command, procurement decision, finance execution, public authority action, certification, recognition, provider selection, project delivery, and asset operation.

509.2.2 GCRI US is a Non-Executing Institution. Its outputs may inform, support, or be read by public authorities, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, national companies, Project SPVs, providers, hosts, sponsors, communities, universities, laboratories, and capital readers, but such use shall not convert GCRI US into an executing body.

#### 509.3 “Emergency Command.”

509.3.1 “Emergency Command” means authority to direct, coordinate, order, control, or command emergency response, emergency operations, emergency resources, incident response operations, evacuation, dispatch, alerting, public safety action, public health orders, infrastructure shutdowns, restoration priorities, mutual aid, or emergency protective measures.

509.3.2 GCRI US does not exercise Emergency Command. No report, dashboard, map, observability output, simulation, public-safe summary, public authority learning material, AI output, sensor signal, AI-RAN / O-RAN signal, DePIN record, DLT record, digital twin output, proof receipt, or Nexus interface output shall be treated as Emergency Command.

#### 509.4 “Incident Command.”

509.4.1 “Incident Command” means formal or operational authority to direct an incident response structure, assign incident roles, allocate operational resources, control tactical response, set response objectives, manage field operations, or issue operational orders during an incident.

509.4.2 GCRI US may support incident learning, after-action review, scenario analysis, tabletop exercises, degraded-mode awareness, evidence literacy, and public-safe technical support, but shall not assume Incident Command.

#### 509.5 “Official Public Warning.”

509.5.1 “Official Public Warning” means a warning, alert, bulletin, instruction, advisory, evacuation notice, shelter notice, public health notice, public safety notice, cyber emergency notice, infrastructure warning, or similar communication issued by a competent public authority or other lawful authority to direct or warn the public.

509.5.2 GCRI US does not issue Official Public Warnings. Public-safe summaries, dashboards, maps, publications, observability outputs, technical notes, or evidence records shall not be described or relied upon as Official Public Warnings.

#### 509.6 “Emergency Alert.”

509.6.1 “Emergency Alert” means an official alert issued through a public warning, emergency management, public safety, public health, communications, utility, infrastructure, or other lawful alerting channel.

509.6.2 GCRI US shall not initiate, issue, transmit, authorize, or substitute for Emergency Alerts, except that GCRI US may provide non-command public-safe learning or technical support to competent authorities where lawfully structured.

#### 509.7 “Public Health Order.”

509.7.1 “Public Health Order” means a legally operative order, directive, restriction, mandate, quarantine, isolation requirement, closure order, inspection order, health emergency instruction, or similar act issued by a competent public health authority.

509.7.2 GCRI US does not issue Public Health Orders. Health-sensitive research, public health evidence, dashboards, maps, or technical outputs shall not be used to imply that GCRI US has public health command or order authority.

#### 509.8 “Safety Command.”

509.8.1 “Safety Command” means authority to direct safety operations, issue safety instructions, control field safety decisions, order shutdowns, require evacuations, assign safety resources, or command protective action.

509.8.2 GCRI US does not exercise Safety Command. Public-safe framing by GCRI US means non-command, evidence-disciplined, limitation-aware communication, not operational command.

#### 509.9 “Regulation.”

509.9.1 “Regulation” means governmental rulemaking, supervision, enforcement, licensing, permitting, compliance determination, sanctioning, binding guidance, adjudication, inspection, regulatory approval, or other exercise of public regulatory authority.

509.9.2 GCRI US is not a regulator. Its methods, evidence, technical baselines, public-good software, dashboards, maps, proof receipts, public authority learning materials, and Nexus interface outputs shall not be treated as Regulation.

#### 509.10 “Regulatory Approval.”

509.10.1 “Regulatory Approval” means an approval, authorization, clearance, license, permit, no-objection, safe harbor, compliance acceptance, waiver, enforcement position, or similar determination by a competent regulator.

509.10.2 GCRI US does not grant Regulatory Approval. No regulator attendance, regulator-listening participation, standards mapping, evidence review, proof receipt, technical baseline, dashboard, map, publication, or learning session shall be represented as Regulatory Approval.

#### 509.11 “Compliance Approval.”

509.11.1 “Compliance Approval” means a determination that a person, project, provider, system, product, public authority, process, dataset, model, software, infrastructure, or organization complies with applicable law, regulation, standard, contract, policy, procurement requirement, or professional requirement.

509.11.2 GCRI US does not provide Compliance Approval unless a separate lawful instrument expressly authorizes a limited non-regulatory review within the Corporation’s role. Standards mapping, evidence review, methods review, technical baselines, and public-good software shall not be treated as Compliance Approval.

#### 509.12 “Permit.”

509.12.1 “Permit” means a government-issued or authority-issued authorization to conduct an activity, build, operate, discharge, emit, deploy, use infrastructure, access restricted areas, perform regulated work, or otherwise engage in conduct requiring approval.

509.12.2 GCRI US does not issue Permits and shall not represent its outputs as satisfying, replacing, or guaranteeing Permit issuance.

#### 509.13 “Public Procurement.”

509.13.1 “Public Procurement” means the acquisition, purchasing, tendering, contracting, vendor selection, award, framework qualification, bid evaluation, public contract formation, or procurement-related decision process of a public authority or publicly regulated body.

509.13.2 GCRI US does not conduct Public Procurement for public authorities and does not select vendors, approve vendors, score bids, award contracts, create approved vendor lists, or confer procurement advantage.

#### 509.14 “Procurement Approval.”

509.14.1 “Procurement Approval” means approval, qualification, selection, scoring, eligibility, preferred status, award recommendation, approved vendor status, or procurement acceptance for a product, provider, project, service, technology, method, system, or organization.

509.14.2 No GCRI US evidence, technical baseline, software, proof receipt, dashboard, map, public-safe publication, repository release, room participation, sponsor status, provider status, Nexus interface, or public authority learning activity shall be treated as Procurement Approval.

#### 509.15 “Provider Preference.”

509.15.1 “Provider Preference” means express or implied preference, endorsement, ranking, selection advantage, procurement advantage, commercial advantage, official approval, approved-provider status, or favored status for a provider, vendor, host, sponsor, contractor, platform, technology, model, cloud, AI system, cybersecurity system, telecom system, infrastructure system, or enterprise actor.

509.15.2 GCRI US shall maintain Provider Neutrality. Provider participation, sponsorship, contribution, technical support, repository involvement, event participation, controlled-room participation, or Nexus interface participation shall not create Provider Preference.

#### 509.16 “Certification.”

509.16.1 “Certification” means a formal attestation, credential, approval, seal, certificate, mark, status, or determination that a person, organization, provider, product, project, system, model, dataset, technical asset, process, method, or infrastructure meets specified requirements.

509.16.2 GCRI US does not provide Certification by default. Public-good technical baselines, test harnesses, benchmarks, evidence records, proof receipts, public-safe publications, dashboards, maps, or software releases shall not be described as Certification unless competent authority expressly creates such status.

#### 509.17 “Accreditation.”

509.17.1 “Accreditation” means recognition that a body, person, provider, laboratory, assessor, certification body, educational body, process, or system is competent or authorized to perform a function.

509.17.2 GCRI US does not provide Accreditation by default and shall not imply Accreditation through training, Academy support, review panels, technical baselines, repository access, or Nexus participation.

#### 509.18 “Conformance.”

509.18.1 “Conformance” means alignment with, satisfaction of, or meeting of a standard, profile, protocol, test, baseline, schema, requirement, technical specification, or benchmark.

509.18.2 Conformance may be used only with precision, authority, scope, version, test record, limitation, and competent review. Passing a test harness, using a schema, implementing an API, referencing a baseline, or participating in Nexus shall not automatically create conformance status.

#### 509.19 “Nexus-Compatible.”

509.19.1 “Nexus-Compatible” means a compatibility status, claim, or relationship with Nexus instruments, protocols, technical profiles, interfaces, records, role keys, software, baselines, standards, or coordination architecture.

509.19.2 Nexus-Compatible status exists only if supported by the proper authority and competent records. No fork, integration, use, adoption, test pass, repository reference, public-good software use, technical baseline use, provider participation, sponsor status, public authority attendance, Docket input, or Grid input shall automatically create Nexus-Compatible status.

#### 509.20 “Recognition.”

509.20.1 “Recognition” means an official or institutional acknowledgment of standing, maturity, eligibility, public legitimacy, registry status, public-facing legitimacy, or other recognition-related status by the competent recognition authority.

509.20.2 Recognition is a GRF-related function unless otherwise lawfully assigned by competent records. GCRI US evidence, methods, technical baselines, observability outputs, software, publications, proof receipts, or public authority learning materials do not create Recognition.

#### 509.21 “Standing.”

509.21.1 “Standing” means an acknowledged position, status, registry posture, eligibility posture, maturity posture, or legitimacy posture assigned by a competent authority under a defined record system.

509.21.2 GCRI US does not assign public standing, market standing, maturity standing, finance standing, or procurement standing unless separately and lawfully authorized.

#### 509.22 “Maturity.”

509.22.1 “Maturity” means a staged, scored, classified, qualitative, or record-based assessment of development, readiness, governance, evidence, implementation, resilience, safeguards, technical status, or institutional capability.

509.22.2 Maturity meaning shall be controlled by the authority that creates it. GCRI US may provide technical evidence or methods inputs but does not create GRF maturity recognition, procurement maturity, finance maturity, or public authority maturity by default.

#### 509.23 “Docket Approval.”

509.23.1 “Docket Approval” means approval, acceptance, routing, eligibility, or official status within a Nexus Docket or comparable record system by the competent authority.

509.23.2 GCRI US may provide Docket inputs where authorized, but Docket input, evidence submission, method review, proof receipt, public authority learning record, or technical baseline record shall not create Docket Approval by GCRI US.

#### 509.24 “Grid Guarantee.”

509.24.1 “Grid Guarantee” means any express or implied guarantee, assurance, standing, eligibility, routing, maturity, adoption, or success claim arising from Nexus Grid or similar grid-related status.

509.24.2 GCRI US does not issue Grid Guarantees. No evidence record, software release, baseline, proof receipt, Docket input, dashboard, map, publication, or Nexus participation shall be treated as a Grid Guarantee.

#### 509.25 “Public Finance Approval.”

509.25.1 “Public Finance Approval” means approval, allocation, appropriation, budget authorization, grant approval, public credit approval, public guarantee, tax credit approval, MDB / DFI approval, sovereign obligation, public finance commitment, or other public finance decision by a competent authority.

509.25.2 GCRI US does not provide Public Finance Approval. Public finance reader participation, grant application support, public authority learning, evidence packs, proof packs, dashboards, maps, or technical baselines shall not be represented as Public Finance Approval.

#### 509.26 “Investment Advice.”

509.26.1 “Investment Advice” means advice, recommendation, analysis, opinion, or communication concerning the advisability of buying, selling, holding, financing, investing in, lending to, insuring, underwriting, rating, or otherwise transacting in securities, assets, projects, companies, funds, SPVs, instruments, or opportunities.

509.26.2 GCRI US does not provide Investment Advice. Evidence, methods, technical baselines, proof receipts, resilience analysis, public-safe reports, or GRA interface inputs shall not be used as Investment Advice.

#### 509.27 “Securities Solicitation.”

509.27.1 “Securities Solicitation” means solicitation, offering, promotion, placement, recommendation, marketing, subscription support, investor introduction, or other activity concerning securities or investment interests.

509.27.2 GCRI US shall not engage in Securities Solicitation. Nexus, GRA, proof-pack, finance-readiness, capital-reader, or public-good evidence interfaces shall be governed to prevent securities solicitation by GCRI US.

#### 509.28 “Broker-Dealer Activity.”

509.28.1 “Broker-Dealer Activity” means activity requiring broker, dealer, placement agent, underwriter, finder, investment adviser, or similar regulated status under applicable law.

509.28.2 GCRI US shall not conduct Broker-Dealer Activity and shall not receive compensation structured as transaction-based compensation for securities, capital raising, investment placement, lending placement, insurance placement, or similar regulated transactions unless lawful and separately authorized, which these Bylaws do not by themselves authorize.

#### 509.29 “Finder Activity.”

509.29.1 “Finder Activity” means identifying, introducing, soliciting, referring, arranging, or facilitating investors, lenders, insurers, underwriters, buyers, sellers, issuers, projects, providers, or capital actors in a manner that may be regulated or that creates transaction-based finance activity.

509.29.2 GCRI US shall not engage in Finder Activity. Public-good convening, public authority learning, evidence literacy, or Nexus coordination shall be structured to avoid finder status.

#### 509.30 “Lending.”

509.30.1 “Lending” means extending credit, arranging credit, approving credit, underwriting loans, guaranteeing repayment, servicing loans, making credit decisions, or otherwise acting as lender, bank, credit provider, loan broker, or credit intermediary.

509.30.2 GCRI US does not conduct Lending and shall not represent evidence, methods, public-safe reports, technical baselines, or Nexus interfaces as loan approval, credit approval, or repayment guarantee.

#### 509.31 “Insurance Placement.”

509.31.1 “Insurance Placement” means soliciting, arranging, binding, placing, brokering, underwriting, pricing, advising on, or selling insurance, reinsurance, risk transfer, or insurance-like products.

509.31.2 GCRI US does not conduct Insurance Placement. Insurance-readiness interface support, where any, shall remain within GRA role separation and shall not become insurance activity by GCRI US.

#### 509.32 “Underwriting.”

509.32.1 “Underwriting” means evaluating, assuming, pricing, approving, placing, guaranteeing, or committing risk, securities, loans, insurance, public finance, or other financial exposure.

509.32.2 GCRI US does not perform Underwriting. Technical evidence, observability, methods, resilience indicators, datasets, proof receipts, or public-safe materials shall not be represented as underwriting.

#### 509.33 “Rating.”

509.33.1 “Rating” means a score, grade, rank, opinion, classification, or determination that expresses creditworthiness, investment quality, resilience grade, insurance quality, financeability, bankability, public finance eligibility, provider quality, public authority approval, maturity, safety, or similar evaluative status.

509.33.2 GCRI US does not issue Ratings unless a competent, lawful, Board-approved and boundary-reviewed instrument expressly authorizes a limited non-regulated technical classification, and such classification is clearly distinguished from finance, insurance, public finance, procurement, recognition, certification, and public authority ratings.

#### 509.34 “Professional Advice.”

509.34.1 “Professional Advice” means advice requiring licensed or regulated professional status, including legal, tax, accounting, engineering, architectural, medical, public health, investment, insurance, lending, brokerage, rating, cybersecurity certification, or other professional advice.

509.34.2 GCRI US public-good materials are not Professional Advice unless expressly provided by a qualified professional under an authorized engagement and recorded scope. Public materials shall include limitation language where professional reliance risk exists.

#### 509.35 “Public Authority Decision.”

509.35.1 “Public Authority Decision” means a decision, approval, denial, permit, order, finding, enforcement action, funding award, procurement award, public finance commitment, public warning, emergency command, public health order, regulatory action, legislative action, judicial action, or official act by a competent public authority.

509.35.2 GCRI US does not make Public Authority Decisions. Public authority participants may learn from, review, or receive GCRI US materials, but such interaction does not transform GCRI US outputs into Public Authority Decisions.

#### 509.36 Boundary Definition Records.

509.36.1 The Corporation shall maintain Boundary Definition Records, including Non-Execution records, Non-Executing Institution records, Emergency Command records, Incident Command records, Official Public Warning records, Emergency Alert records, Public Health Order records, Safety Command records, Regulation records, Regulatory Approval records, Compliance Approval records, Permit records, Public Procurement records, Procurement Approval records, Provider Preference records, Certification records, Accreditation records, Conformance records, Nexus-Compatible records, Recognition records, Standing records, Maturity records, Docket Approval records, Grid Guarantee records, Public Finance Approval records, Investment Advice records, Securities Solicitation records, Broker-Dealer Activity records, Finder Activity records, Lending records, Insurance Placement records, Underwriting records, Rating records, Professional Advice records, Public Authority Decision records, correction records, public-safe limitation records, and archive records.

***

### Section 510. Evidence, Research, Methods, and Technical Truth Definitions

#### 510.1 “Research.”

510.1.1 “Research” means systematic, structured, or disciplined inquiry, investigation, study, analysis, testing, review, evidence generation, method development, observability review, dataset analysis, technical evaluation, or public-benefit knowledge work conducted by or for the Corporation.

510.1.2 Research may include qualitative, quantitative, mixed-method, technical, computational, legal-institutional, systems, resilience, public authority learning, community-informed, observability, data, AI, cyber, environmental, infrastructure, or technology-family research.

510.1.3 Research shall be subject to research integrity, ethics review where required or appropriate, evidence records, method records, limitation disclosure, uncertainty disclosure, safeguards, and correctionability.

#### 510.2 “Public-Benefit R\&D.”

510.2.1 “Public-Benefit R\&D” means research and development conducted for public-good, scientific, educational, evidence, methods, observability, ontology, technical baseline, public-good software, verifiable compute, verifiable intelligence, public authority learning, safeguards, resilience, and Nexus coordination purposes.

510.2.2 Public-Benefit R\&D shall not be used as a cover for private product development, provider preference, sponsor-controlled research, regulated finance activity, public authority substitution, certification, recognition, procurement approval, or enterprise execution.

#### 510.3 “Evidence.”

510.3.1 “Evidence” means record-supported information, observation, dataset, source, signal, document, measurement, review, computation, inference, proof receipt, corroboration, benchmark result, method output, or other material that supports or challenges a factual, technical, institutional, public-safe, or methodological claim.

510.3.2 Evidence is distinct from opinion, recognition, finance-readiness, certification, procurement approval, public authority decision, public warning, emergency command, and rating.

510.3.3 Evidence shall be classified by source, lineage, quality, confidence, uncertainty, limitations, public-safe status, access class, correction status, and authority record.

#### 510.4 “Evidence Record.”

510.4.1 “Evidence Record” means an Authoritative Record documenting evidence identity, source, lineage, custody, method, classification, confidence, uncertainty, limitations, reviewer notes, related records, public-safe status, access class, correction path, and retention status.

510.4.2 Evidence Records are necessary for material evidence claims, public-safe summaries, public authority learning materials, GRF inputs, GRA inputs, Docket inputs, Grid inputs, technical baselines, software claims, dashboards, maps, and Nexus interface outputs.

#### 510.5 “Evidence Doctrine.”

510.5.1 “Evidence Doctrine” means the Corporation’s doctrine that evidence is record-based technical support and not recognition, finance-readiness, certification, procurement approval, public authority action, public warning, emergency command, rating, or legal compliance approval.

510.5.2 Evidence Doctrine shall govern collection, review, publication, correction, challenge, and interface use of evidence.

#### 510.6 “Technical Truth.”

510.6.1 “Technical Truth” means the Corporation’s disciplined, record-based, method-supported, source-traceable, limitation-aware, uncertainty-aware, correctionable representation of technical facts, system states, evidence relationships, method outputs, and public-safe technical claims.

510.6.2 Technical Truth is not absolute certainty, public authority decision, finance determination, certification, recognition, or operational command.

510.6.3 Technical Truth requires records, methods, source lineage, confidence discipline, limitation disclosure, public-safe framing, and correctionability.

#### 510.7 “Method.”

510.7.1 “Method” means a documented process, protocol, workflow, analytical approach, computational procedure, evaluation approach, test approach, observability approach, ontology approach, mapping approach, benchmark procedure, model evaluation procedure, or evidence review approach used to produce or assess evidence or technical outputs.

510.7.2 Methods shall be versioned, documented, reviewed, classified, and corrected where appropriate.

#### 510.8 “Methods Stewardship.”

510.8.1 “Methods Stewardship” means the Corporation’s role in developing, documenting, reviewing, versioning, publishing where public-safe, maintaining, restricting where required, correcting, superseding, withdrawing, and archiving methods.

510.8.2 Methods Stewardship shall not be treated as certification, public authority approval, procurement approval, finance-readiness, recognition, or regulated professional approval.

#### 510.9 “Validation.”

510.9.1 “Validation” means a documented assessment that a method, model, dataset, system, software, technical baseline, dashboard, map, proof receipt, or output is fit for a stated purpose within a stated scope and limitations.

510.9.2 Validation is scope-limited and record-based. Validation shall not imply certification, legal compliance, public authority approval, finance-readiness, procurement approval, recognition, rating, or public warning status unless the competent authority expressly provides such meaning.

#### 510.10 “Verification.”

510.10.1 “Verification” means a documented assessment that a claim, result, record, process, computation, dataset, software release, technical asset, source, or output conforms to specified requirements, records, or expected conditions within a stated scope.

510.10.2 Verification shall identify what was checked, against what reference, by whom, using what method, on what date, with what limitations.

#### 510.11 “Corroboration.”

510.11.1 “Corroboration” means support for evidence or a claim through independent, partially independent, alternative, or additional sources, methods, signals, records, or reviewer assessments.

510.11.2 Corroboration strengthens but does not eliminate uncertainty and does not create authority beyond the corroborated scope.

#### 510.12 “Calibration.”

510.12.1 “Calibration” means documented adjustment, checking, benchmarking, alignment, or comparison of instruments, sensors, models, methods, dashboards, evaluation systems, or confidence estimates against references, standards, baseline data, or known conditions.

510.12.2 Calibration records shall identify reference, method, date, result, limitations, and correction implications.

#### 510.13 “Benchmark.”

510.13.1 “Benchmark” means a structured test, reference task, dataset, scenario, comparison, evaluation procedure, performance reference, or metric used to assess systems, models, methods, software, datasets, dashboards, maps, protocols, or technical baselines.

510.13.2 Benchmarks shall be documented with scope, version, limitations, suitability, known biases, data restrictions, and public-safe status.

510.13.3 A Benchmark result is not a rating, certification, recognition, procurement approval, finance-readiness, public authority approval, or provider preference unless a competent authority expressly provides such meaning.

#### 510.14 “Gold Vector.”

510.14.1 “Gold Vector” means a reference input, expected output, canonical case, test vector, verified example, or known-valid data point used to evaluate correctness, consistency, interoperability, or regression behavior.

510.14.2 Gold Vectors shall be versioned, sourced, documented, protected where sensitive, and corrected when defects are discovered.

#### 510.15 “Negative Test.”

510.15.1 “Negative Test” means a test designed to confirm that a system, method, model, software, interface, technical baseline, dashboard, map, or workflow rejects, flags, contains, limits, or fails safely under invalid, adversarial, unsafe, unauthorized, out-of-scope, or boundary-defective conditions.

510.15.2 Negative Tests may be restricted where disclosure could create security, misuse, protected knowledge, public authority, or public-safe risks.

#### 510.16 “Test Harness.”

510.16.1 “Test Harness” means software, scripts, tooling, datasets, scenarios, procedures, workflows, infrastructure, or interfaces used to run, measure, reproduce, evaluate, validate, verify, or challenge a technical system, method, model, dataset, protocol, baseline, API, SDK, dashboard, map, or output.

510.16.2 Test Harnesses shall be versioned, documented, licensed, secured, and accompanied by limitations.

#### 510.17 “Evaluation Set.”

510.17.1 “Evaluation Set” means a dataset, set of prompts, cases, tasks, signals, scenarios, examples, records, or inputs used to evaluate performance, safety, accuracy, bias, robustness, drift, hallucination, interoperability, or other properties.

510.17.2 Evaluation Sets shall be governed by data rights, privacy, protected knowledge, public authority restrictions, security, and publication controls.

#### 510.18 “Source Lineage.”

510.18.1 “Source Lineage” means the documented chain identifying where evidence, data, claims, records, signals, models, methods, outputs, or technical assets came from, how they were obtained, how they were transformed, and what records support them.

510.18.2 Source Lineage is required for material public claims, evidence records, datasets, dashboards, maps, technical baselines, software claims, GRF inputs, GRA inputs, and Nexus interface outputs.

#### 510.19 “Provenance.”

510.19.1 “Provenance” means documented origin, authorship, custody, transformation, version, processing history, source authority, and record history of data, software, technical assets, publications, evidence, models, compute outputs, and claims.

510.19.2 Provenance supports integrity, auditability, correctionability, and public-safe reliance limitations.

#### 510.20 “Custody.”

510.20.1 “Custody” means possession, control, stewardship, authorized access, storage, processing, or responsibility for records, data, evidence, technical assets, public authority materials, protected knowledge, or other materials.

510.20.2 Custody shall be documented for restricted, confidential, public authority, protected knowledge, cyber-sensitive, infrastructure-sensitive, health-sensitive, rights-bearing, and controlled-room materials.

#### 510.21 “Chain-of-Custody.”

510.21.1 “Chain-of-Custody” means the documented sequence of possession, transfer, access, handling, processing, review, storage, sealing, release, correction, archive, or disposal of evidence, data, records, technical assets, or restricted materials.

510.21.2 Chain-of-Custody records shall be maintained where integrity, legality, public authority restrictions, research integrity, security, protected knowledge, or dispute resolution requires traceability.

#### 510.22 “Confidence Score.”

510.22.1 “Confidence Score” means a qualitative, quantitative, categorical, probabilistic, or structured expression of confidence in evidence, method output, model output, observation, dashboard output, map output, or public-safe claim.

510.22.2 Confidence Scores shall be accompanied by method, scope, uncertainty, limitations, and source lineage. They shall not be represented as certification, rating, recognition, finance-readiness, procurement approval, public authority approval, public warning, or emergency command.

#### 510.23 “Uncertainty.”

510.23.1 “Uncertainty” means known or reasonably foreseeable limits, variability, ambiguity, incompleteness, error range, unknowns, model limitations, measurement limitations, sampling limitations, source limitations, method limitations, temporal limitations, or interpretation limits affecting evidence or outputs.

510.23.2 Material uncertainty shall be disclosed in public-safe and controlled outputs according to audience, classification, and risk.

#### 510.24 “Disputed Evidence.”

510.24.1 “Disputed Evidence” means evidence whose accuracy, source, method, interpretation, classification, completeness, authority, custody, public-safe status, or use has been challenged or is subject to unresolved disagreement.

510.24.2 Disputed Evidence shall be flagged, reviewed, restricted where necessary, and corrected, superseded, withdrawn, or retained with limitations as appropriate.

#### 510.25 “Failed Signal.”

510.25.1 “Failed Signal” means a signal, data point, sensor output, telemetry item, model output, observability output, proof receipt, inference, or evidence element that has failed validation, verification, quality review, calibration, source review, plausibility review, or public-safe review.

510.25.2 Failed Signals shall not support material public claims unless clearly labeled and used for failure analysis.

#### 510.26 “Spoofed Signal.”

510.26.1 “Spoofed Signal” means a signal, source, record, telemetry item, sensor output, digital identity, ledger entry, AI output, or observability record that is fabricated, manipulated, impersonated, adversarially generated, replayed, falsified, or otherwise made to appear authentic when it is not.

510.26.2 Spoofed Signals shall be handled as integrity, cybersecurity, evidence, or incident matters and shall not support public claims except as evidence of spoofing.

#### 510.27 “Stale Evidence.”

510.27.1 “Stale Evidence” means evidence whose age, update status, context, source status, environmental conditions, system conditions, legal status, public authority status, or technical status materially limits current use.

510.27.2 Stale Evidence may be used for historical context if labeled and shall not be used for current public claims without review.

#### 510.28 “Superseded Evidence.”

510.28.1 “Superseded Evidence” means evidence replaced by later, better, corrected, more authoritative, more complete, or more current evidence.

510.28.2 Superseded Evidence shall be retained for traceability where appropriate but shall not be used as current evidence unless context requires and limitations are disclosed.

#### 510.29 “Corrected Evidence.”

510.29.1 “Corrected Evidence” means evidence amended, clarified, limited, reclassified, recalculated, re-sourced, reinterpreted, or otherwise corrected through an authorized correction process.

510.29.2 Corrected Evidence shall include correction records, affected claims, downstream dependencies, and notice where required.

#### 510.30 “Research Integrity.”

510.30.1 “Research Integrity” means adherence to accuracy, honesty, transparency, reproducibility where appropriate, replicability where appropriate, method documentation, conflict management, sponsor and provider independence, peer review where appropriate, ethical review where required or appropriate, data and source integrity, limitation disclosure, uncertainty disclosure, public-safe framing, and correctionability.

#### 510.31 “Research Misconduct.”

510.31.1 “Research Misconduct” means fabrication, falsification, plagiarism, improper source omission, unsupported confidence claim, suppression of material limitation, misleading public-safe summary, misuse of GCRI US name or technical baseline, misuse of proof receipt or boundary terms, sponsor or provider distortion, AI-generated fabrication, or other material departure from research integrity requirements.

#### 510.32 “Peer Review.”

510.32.1 “Peer Review” means review by qualified persons of research, evidence, methods, publications, datasets, software, technical baselines, dashboards, maps, models, benchmarks, or other outputs to assess quality, accuracy, limitations, and correction needs.

510.32.2 Peer Review may be internal, external, blinded, open, controlled, technical, community-informed, public authority-informed, or safeguards-informed, as appropriate.

510.32.3 Peer Review does not create certification, finance-readiness, recognition, procurement approval, public authority approval, or rating by default.

#### 510.33 “Public-Safe Summary.”

510.33.1 “Public-Safe Summary” means a public-facing or broadly shareable summary that communicates accurate, limitation-aware, non-command, non-overclaim, non-sensitive information while protecting privacy, cybersecurity, infrastructure sensitivity, public authority restrictions, protected knowledge, and public safety.

510.33.2 Public-Safe Summaries shall not substitute for full evidence records, controlled annexes, legal advice, public authority decisions, public warnings, finance-readiness determinations, certifications, or recognition decisions.

#### 510.34 “Controlled Annex.”

510.34.1 “Controlled Annex” means a non-public, restricted, confidential, public authority, research-sensitive, finance-sensitive, cyber-sensitive, infrastructure-sensitive, protected knowledge, or otherwise controlled supplement to a public-safe publication, evidence pack, report, dataset, dashboard, map, or technical output.

510.34.2 Controlled Annexes shall be access-controlled, logged, classified, and subject to confidentiality, data, AI, cyber, privacy, public authority, protected knowledge, and retention requirements.

#### 510.35 Evidence, Research, Methods, and Technical Truth Definition Records.

510.35.1 The Corporation shall maintain Evidence, Research, Methods, and Technical Truth Definition Records, including Research records, Public-Benefit R\&D records, Evidence records, Evidence Record definitions, Evidence Doctrine records, Technical Truth records, Method records, Methods Stewardship records, Validation records, Verification records, Corroboration records, Calibration records, Benchmark records, Gold Vector records, Negative Test records, Test Harness records, Evaluation Set records, Source Lineage records, Provenance records, Custody records, Chain-of-Custody records, Confidence Score records, Uncertainty records, Disputed Evidence records, Failed Signal records, Spoofed Signal records, Stale Evidence records, Superseded Evidence records, Corrected Evidence records, Research Integrity records, Research Misconduct records, Peer Review records, Public-Safe Summary records, Controlled Annex records, correction records, and archive records.

***

### Section 511. Observability and Nexus Observatory Definitions

#### 511.1 “Observability.”

511.1.1 “Observability” means the disciplined ability to observe, record, structure, interpret, and communicate system states, signals, telemetry, conditions, events, dependencies, vulnerabilities, resilience indicators, and degraded-mode conditions through lawful, ethical, public-safe, and technically sound methods.

511.1.2 Observability may include sensors, telemetry, AI-RAN / O-RAN signals, DePIN records, DLT records, digital twins, cyber telemetry, geospatial evidence, Earth observation, edge compute, dashboards, maps, public-safe visualizations, and evidence records.

511.1.3 Observability shall not be treated as public warning, emergency command, surveillance authority, public authority decision, certification, recognition, finance-readiness, procurement approval, rating, or provider preference.

#### 511.2 “Observability Stewardship.”

511.2.1 “Observability Stewardship” means the Corporation’s role in developing, documenting, reviewing, versioning, correcting, and public-safely communicating observability methods, observability records, observability outputs, public-safe maps, dashboards, and related technical baselines.

511.2.2 Observability Stewardship shall be subject to data / AI / cyber / privacy controls, public authority boundaries, protected knowledge safeguards, infrastructure-sensitive restrictions, and public-safe publication rules.

#### 511.3 “Nexus Observatory Methods.”

511.3.1 “Nexus Observatory Methods” means the methods, protocols, workflows, ontologies, schemas, profiles, evidence records, dashboards, maps, quality controls, and public-safe publication controls used to support Nexus Observatory functions.

511.3.2 GCRI US may steward or support Nexus Observatory Methods within its non-executing technical role.

#### 511.4 “Observatory Node.”

511.4.1 “Observatory Node” means a structured point, unit, site, system, organization, technical environment, sensor environment, data environment, public authority learning environment, community interface, or observability function that contributes to or participates in observability.

511.4.2 Observatory Node status shall not create public authority status, certification, recognition, procurement approval, finance-readiness, operational command, or provider preference.

#### 511.5 “Nexus Hub.”

511.5.1 “Nexus Hub” means a Nexus-aligned hub through which observability, evidence, methods, public authority learning, technical assets, community safeguards, or Nexus coordination may be organized.

511.5.2 Nexus Hub status shall be record-based and shall not imply legal merger, public authority delegation, procurement approval, finance-readiness, certification, recognition, or enterprise execution by GCRI US.

#### 511.6 “Nexus Cluster.”

511.6.1 “Nexus Cluster” means a grouping of nodes, hubs, institutions, communities, public authorities, technical assets, infrastructure systems, or thematic functions organized for Nexus-aligned observability, evidence, methods, learning, or coordination.

511.6.2 Nexus Cluster status shall be subject to records, role separation, public-safe publication, data controls, and protected knowledge safeguards.

#### 511.7 “Nexus Hotspot.”

511.7.1 “Nexus Hotspot” means a place, system, sector, risk pattern, infrastructure dependency, technology concentration, vulnerability, opportunity, or public-good focus area identified for observability, learning, methods development, safeguards, or coordination.

511.7.2 A Nexus Hotspot designation shall not be treated as a public warning, emergency command, public authority determination, rating, recognition, finance-readiness, certification, procurement approval, or stigmatizing label.

#### 511.8 “Regional Cluster.”

511.8.1 “Regional Cluster” means a regional grouping of Nexus functions, observability nodes, public-good institutions, public authority learning interfaces, communities, infrastructure systems, universities, laboratories, providers, or enterprise actors.

511.8.2 Regional Cluster status shall preserve regional legal distinctions, public authority boundaries, cross-border data controls, protected knowledge safeguards, and Nexus role separation.

#### 511.9 “National Dense Nexus Core.”

511.9.1 “National Dense Nexus Core” means a concentrated national-level Nexus configuration, capacity, or interface involving public-good institutions, public authorities, observability functions, technical assets, evidence flows, methods, public authority learning, and ecosystem coordination.

511.9.2 National Dense Nexus Core status shall not create national public authority status, sovereign authority, public finance approval, procurement authority, emergency command, public warning, certification, recognition, or enterprise execution by GCRI US.

#### 511.10 “Sensor.”

511.10.1 “Sensor” means a device, system, process, signal source, software instrument, human-reported observation, automated feed, satellite source, edge device, network signal, cyber log, infrastructure telemetry source, or other means of detecting or recording information.

511.10.2 Sensor outputs require source lineage, quality review, calibration where appropriate, classification, and public-safe review before material use.

#### 511.11 “Reference Sensor.”

511.11.1 “Reference Sensor” means a sensor, signal source, benchmark source, calibration source, or trusted reference used to compare, validate, verify, calibrate, or corroborate other signals.

511.11.2 Reference Sensor status shall be documented and shall not guarantee accuracy beyond its scope and limitations.

#### 511.12 “Telemetry.”

511.12.1 “Telemetry” means remotely or automatically collected measurements, signals, logs, events, state data, operational data, network data, sensor data, infrastructure data, AI-RAN / O-RAN data, cyber data, or system data.

511.12.2 Telemetry shall be classified and handled according to privacy, public authority, cyber-sensitive, infrastructure-sensitive, commercial-sensitive, protected knowledge, and public-safe requirements.

#### 511.13 “Edge Compute.”

511.13.1 “Edge Compute” means computation, processing, inference, filtering, aggregation, storage, or analytics performed near sensors, devices, networks, infrastructure, facilities, field environments, or operational systems.

511.13.2 Edge Compute outputs shall not be treated as authoritative without records, review, classification, security controls, and correction path.

#### 511.14 “AI-RAN Signal.”

511.14.1 “AI-RAN Signal” means a signal, telemetry record, inference, control-plane indicator, performance indicator, security indicator, operational indicator, or observability output associated with AI-enabled radio access networks or related telecom infrastructure.

511.14.2 AI-RAN Signals may be cyber-sensitive or infrastructure-sensitive and shall not be publicized, mapped, or used for public claims without review.

511.14.3 AI-RAN Signals do not constitute public warnings, emergency commands, public authority decisions, certifications, procurement approvals, finance-readiness determinations, or provider preferences.

#### 511.15 “O-RAN Signal.”

511.15.1 “O-RAN Signal” means a signal, telemetry record, interface indicator, operational indicator, security indicator, performance indicator, or observability output associated with open radio access network architectures or components.

511.15.2 O-RAN Signals shall be subject to telecom, cyber, infrastructure, public authority, provider neutrality, and public-safe review controls.

#### 511.16 “DePIN Record.”

511.16.1 “DePIN Record” means a record, signal, telemetry item, proof, ledger-linked record, device record, infrastructure participation record, token-linked record, or decentralized physical infrastructure network record.

511.16.2 DePIN Records require source, integrity, spoofing, custody, privacy, cyber, infrastructure, finance-boundary, and public-safe review before material use.

#### 511.17 “DLT Record.”

511.17.1 “DLT Record” means a distributed ledger, blockchain, token, smart contract, hash, transaction, timestamp, proof, role-key, smart-license, or ledger-linked record.

511.17.2 A DLT Record is not authoritative merely because it is on a ledger. It requires authority, source lineage, lawful basis, interpretation, and review.

#### 511.18 “Digital Twin Output.”

511.18.1 “Digital Twin Output” means a modeled, simulated, estimated, visualized, or computed representation generated by or from a digital twin of a system, infrastructure, environment, asset, region, process, or risk pattern.

511.18.2 Digital Twin Outputs shall disclose model assumptions, data sources, limitations, uncertainty, update status, and public-safe constraints.

511.18.3 Digital Twin Outputs shall not be treated as public authority decisions, emergency commands, public warnings, certifications, finance-readiness, ratings, or procurement approvals.

#### 511.19 “Cyber Telemetry.”

511.19.1 “Cyber Telemetry” means logs, alerts, events, packet data, endpoint data, network data, vulnerability data, identity data, access data, threat intelligence, incident artifacts, or security observations.

511.19.2 Cyber Telemetry is presumptively sensitive unless classified otherwise and shall be protected from overdisclosure.

#### 511.20 “Geospatial Evidence.”

511.20.1 “Geospatial Evidence” means evidence with spatial, locational, geographic, mapping, coordinate, boundary, parcel, infrastructure, environmental, community, or place-based relevance.

511.20.2 Geospatial Evidence shall be reviewed for public-safe mapping, protected knowledge, infrastructure sensitivity, public authority restrictions, privacy, community safety, and risk of stigmatization.

#### 511.21 “Earth Observation Evidence.”

511.21.1 “Earth Observation Evidence” means evidence derived from satellites, aircraft, drones, remote sensing, imagery, radar, lidar, environmental sensors, climate data, land cover data, ocean data, atmospheric data, or other Earth observation sources.

511.21.2 Earth Observation Evidence shall be reviewed for source lineage, resolution, uncertainty, timeliness, licensing, public-safe mapping, protected knowledge, and infrastructure sensitivity.

#### 511.22 “Dashboard.”

511.22.1 “Dashboard” means a visual, interactive, static, public, controlled, internal, or restricted interface displaying data, evidence, indicators, signals, maps, charts, statuses, outputs, risks, or technical records.

511.22.2 Dashboards shall include source, timestamp, version, confidence, limitations, classification, update status, and non-reliance notices where appropriate.

#### 511.23 “Map.”

511.23.1 “Map” means a spatial representation, geospatial visualization, layer, digital twin view, public-safe visualization, dashboard map, risk map, observability map, infrastructure map, community map, or public authority map.

511.23.2 Maps shall be subject to public-safe mapping review, infrastructure-sensitive review, cyber-sensitive review, public authority data review, and protected knowledge review where applicable.

#### 511.24 “Public-Safe Map.”

511.24.1 “Public-Safe Map” means a map designed for public or broad sharing after review to reduce risk of harm, exposure, misinterpretation, stigmatization, public authority confusion, public warning confusion, infrastructure vulnerability, cyber misuse, privacy harm, or protected knowledge disclosure.

511.24.2 A Public-Safe Map is not an official public warning, public authority decision, emergency command, safety command, certification, recognition, finance-readiness, rating, or procurement approval.

#### 511.25 “Degraded-Mode Awareness.”

511.25.1 “Degraded-Mode Awareness” means awareness of reduced, impaired, uncertain, disrupted, compromised, partial, or unreliable system operation, data availability, infrastructure state, communications state, observability state, AI state, cyber posture, or public authority operating context.

511.25.2 Degraded-Mode Awareness supports learning and public-safe technical understanding and shall not be used as emergency command by GCRI US.

#### 511.26 “Resilience Indicator.”

511.26.1 “Resilience Indicator” means a qualitative or quantitative indicator used to understand capacity, exposure, vulnerability, redundancy, adaptability, recovery, robustness, continuity, or degraded-mode performance.

511.26.2 Resilience Indicators shall not be represented as ratings, finance-readiness, insurance-readiness, public authority approval, procurement approval, certification, or recognition without competent authority.

#### 511.27 “Observability Output.”

511.27.1 “Observability Output” means an evidence item, dashboard, map, signal interpretation, telemetry interpretation, public-safe summary, technical note, indicator, alert-like internal note, or method output derived from observability.

511.27.2 Observability Outputs shall be classified, versioned, limitation-aware, public-safe reviewed where shared, and correctionable.

#### 511.28 “Nexus Truth Engine.”

511.28.1 “Nexus Truth Engine” means a Nexus-aligned method, architecture, record system, computation system, ontology-supported reasoning system, evidence relationship system, or technical framework for structuring, testing, tracing, and correcting technical truth claims.

511.28.2 GCRI US may steward methods supporting Nexus Truth Engine functions, but Truth Engine methods do not create public authority decisions, finance-readiness, certification, recognition, procurement approval, public warning, or emergency command.

#### 511.29 “Truth Engine Output.”

511.29.1 “Truth Engine Output” means an output, inference, relationship, record, confidence statement, contradiction flag, evidence map, method result, or technical claim generated through Nexus Truth Engine methods or systems.

511.29.2 Truth Engine Outputs require human review, record support, limitation disclosure, public-safe classification, and correction path before material public or interface use.

#### 511.30 Observability Definition Records.

511.30.1 The Corporation shall maintain Observability Definition Records, including Observability records, Observability Stewardship records, Nexus Observatory Methods records, Observatory Node records, Nexus Hub records, Nexus Cluster records, Nexus Hotspot records, Regional Cluster records, National Dense Nexus Core records, Sensor records, Reference Sensor records, Telemetry records, Edge Compute records, AI-RAN Signal records, O-RAN Signal records, DePIN Record records, DLT Record records, Digital Twin Output records, Cyber Telemetry records, Geospatial Evidence records, Earth Observation Evidence records, Dashboard records, Map records, Public-Safe Map records, Degraded-Mode Awareness records, Resilience Indicator records, Observability Output records, Nexus Truth Engine records, Truth Engine Output records, correction records, and archive records.

***

### Section 512. Ontology, Semantic, and Controlled Vocabulary Definitions

#### 512.1 “Ontology.”

512.1.1 “Ontology” means a structured representation of concepts, relationships, classes, properties, terms, constraints, meanings, and semantic relationships used to organize evidence, methods, risks, technologies, public authority capacities, finance boundaries, certification boundaries, data classes, safeguards, public-safe terms, and Nexus interfaces.

512.1.2 Ontology supports semantic interoperability and controlled meaning. It does not create legal authority, certification, recognition, finance-readiness, procurement approval, public authority decision, public warning, or emergency command.

#### 512.2 “Taxonomy.”

512.2.1 “Taxonomy” means a structured classification system for organizing concepts, records, risks, evidence, methods, data, technologies, outputs, publications, incidents, assets, roles, or interfaces.

512.2.2 A Taxonomy shall be versioned, documented, and corrected when classifications become inaccurate or misleading.

#### 512.3 “Controlled Vocabulary.”

512.3.1 “Controlled Vocabulary” means the approved set of defined, restricted, reserved, prohibited, preferred, or context-specific terms governing institutional language, public claims, evidence status, technical claims, public authority references, finance-boundary statements, certification and recognition terms, Nexus interface terms, safeguards terms, and public-safe materials.

512.3.2 Controlled Vocabulary is mandatory for material public and institutional claims.

#### 512.4 “Schema.”

512.4.1 “Schema” means a structured specification defining data fields, types, relationships, constraints, formats, metadata, validation rules, interoperability requirements, or record structures.

512.4.2 Schemas support interoperability but do not by themselves create certification, conformance approval, procurement mandate, public authority adoption, finance-readiness, recognition, or legal compliance approval.

#### 512.5 “Data Dictionary.”

512.5.1 “Data Dictionary” means a documented set of data elements, definitions, fields, permissible values, formats, classifications, source notes, quality rules, sensitivity rules, access rules, and interpretation notes.

512.5.2 Data Dictionaries shall be aligned with the Corporation’s ontology, controlled vocabulary, data classification, and public-safe publication rules.

#### 512.6 “Semantic Interoperability.”

512.6.1 “Semantic Interoperability” means the ability of systems, records, datasets, methods, dashboards, maps, repositories, institutions, and Nexus interfaces to exchange and interpret information consistently according to shared meaning.

512.6.2 Semantic Interoperability does not mean legal equivalence, certification, public authority adoption, finance-readiness, recognition, procurement approval, or provider preference.

#### 512.7 “AI-Readable Knowledge Structure.”

512.7.1 “AI-Readable Knowledge Structure” means an ontology, schema, data dictionary, structured record, embedding-supported structure, graph, taxonomy, prompt-safe corpus, or other structured resource designed to be read, used, retrieved, or reasoned over by AI systems.

512.7.2 AI-Readable Knowledge Structures shall be governed by AI-use restrictions, data rights, protected knowledge controls, privacy, cybersecurity, source lineage, and correctionability.

#### 512.8 “Risk Category.”

512.8.1 “Risk Category” means a defined category used to classify risk, including systemic, technological, cyber, AI, infrastructure, public authority, finance, procurement, public-safe publication, civil rights, accessibility, community, protected knowledge, legal, compliance, reputational, operational, and Nexus coordination risks.

512.8.2 Risk Categories support governance and do not by themselves create ratings or public warnings.

#### 512.9 “Evidence Class.”

512.9.1 “Evidence Class” means a classification of evidence by type, source, quality, confidence, uncertainty, public-safe status, access class, legal sensitivity, technical sensitivity, public authority status, protected knowledge status, or correction status.

512.9.2 Evidence Class shall be recorded and updated when evidence is corrected, superseded, disputed, stale, or withdrawn.

#### 512.10 “Technology Family.”

512.10.1 “Technology Family” means a class of technologies covered by the Corporation’s work, including AI, AI-RAN, O-RAN, private wireless, telecommunications, blockchain, DLT, Web3, quantum-relevant systems, HPC, sovereign compute, cyber, robotics, drones, sensing, Earth observation, geospatial systems, digital twins, biosecurity, climate, nature, WEFH systems, energy, advanced manufacturing, semiconductors, and related exponential technologies.

512.10.2 Technology Family classification shall not imply provider preference, certification, procurement approval, public authority adoption, finance-readiness, recognition, or rating.

#### 512.11 “Maturity Concept.”

512.11.1 “Maturity Concept” means a conceptual stage, level, category, or descriptor used to discuss development, governance, resilience, evidence quality, implementation readiness, technical capability, safeguards, or institutional capacity.

512.11.2 Maturity Concepts used by GCRI US are technical or conceptual unless competent GRF, GRA, Nexus Grid, or other authority gives them formal status.

#### 512.12 “Public Authority Capacity Concept.”

512.12.1 “Public Authority Capacity Concept” means a controlled term describing the capacity in which a public authority or public-sector person participates, including official participant, observer, regulator-listening participant, public finance reader, emergency-management participant, public infrastructure operator participant, public health participant, public safety participant, public works participant, personal-capacity participant, non-attributable participant, data provider, reviewer, or simulation participant.

512.12.2 Public Authority Capacity Concepts prevent public authority overclaim and shall be recorded.

#### 512.13 “Finance Boundary Concept.”

512.13.1 “Finance Boundary Concept” means a controlled term or classification used to distinguish technical evidence, public-good records, proof-pack inputs, capital-reader learning, finance-readiness meaning, investment advice, securities activity, lending, insurance, rating, public finance approval, and capital execution.

512.13.2 Finance Boundary Concepts shall preserve GRA role separation and GCRI US non-finance status.

#### 512.14 “Certification Boundary Concept.”

512.14.1 “Certification Boundary Concept” means a controlled term or classification used to distinguish technical baselines, conformance tests, benchmarks, evidence reviews, validation, verification, certification, accreditation, procurement approval, compliance approval, recognition, Nexus-compatible status, Docket status, and Grid status.

512.14.2 Certification Boundary Concepts shall prevent unsupported certification, recognition, procurement, and public authority meaning.

#### 512.15 “Public-Safe Term.”

512.15.1 “Public-Safe Term” means a term approved for public or broad use because it is accurate, limitation-aware, non-command, non-overclaim, non-sensitive, accessible, and unlikely to create public authority, finance, certification, recognition, procurement, public warning, emergency command, protected knowledge, or public safety confusion.

#### 512.16 “Restricted Term.”

512.16.1 “Restricted Term” means a term that may be used only with approval, context, limitation language, record support, or controlled audience because it carries legal, public authority, finance, certification, recognition, procurement, security, protected knowledge, or public-safe risk.

#### 512.17 “Reserved Term.”

512.17.1 “Reserved Term” means a term reserved to the Board, a proper Nexus authority, GRF, GRA, Nexus Standards, protocol authority, public authority, or other competent body.

512.17.2 Reserved Terms shall not be used by GCRI US without authority from the proper source and record support.

#### 512.18 “Semantic Drift.”

512.18.1 “Semantic Drift” means gradual, informal, public, internal, technical, AI-generated, sponsor-driven, provider-driven, public authority-driven, or media-driven change in the meaning or perceived meaning of a term away from its approved meaning.

512.18.2 Semantic Drift shall trigger review, correction, controlled vocabulary update, public-safe clarification, or restriction where material.

#### 512.19 “Equivalence Note.”

512.19.1 “Equivalence Note” means a record explaining whether and how one term, classification, standard, method, profile, jurisdictional concept, public authority capacity, finance-boundary concept, or Nexus interface term is equivalent or not equivalent to another.

512.19.2 Equivalence Notes do not create legal equivalence, certification, recognition, finance-readiness, procurement approval, or public authority approval unless competent authority expressly provides such meaning.

#### 512.20 “Compatibility Note.”

512.20.1 “Compatibility Note” means a record describing technical, semantic, procedural, policy, data, AI, cyber, public authority, finance-boundary, safeguards, or Nexus compatibility between systems, records, methods, institutions, standards, baselines, or interfaces.

512.20.2 Compatibility Notes shall not create Nexus-Compatible status unless issued by competent authority for that purpose.

#### 512.21 “Divergence Log.”

512.21.1 “Divergence Log” means a record documenting differences, conflicts, deviations, localizations, exceptions, unresolved issues, or controlled departures among terms, instruments, methods, baselines, policies, jurisdictions, Nexus interfaces, or technical assets.

512.21.2 Divergence Logs support transparency and correctionability without creating approval or waiver by default.

#### 512.22 “Localization Note.”

512.22.1 “Localization Note” means a record explaining how a term, policy, method, protocol, public authority language, data rule, safeguard, technical asset, publication, or Nexus interface is adapted for a jurisdiction, community, public authority, sector, language, cultural context, or legal context.

512.22.2 Localization Notes shall not weaken mandatory Bylaw protections.

#### 512.23 “Interface Map.”

512.23.1 “Interface Map” means a structured record showing relationships, roles, dependencies, handoffs, boundaries, records, data flows, public authority interfaces, finance interfaces, technical interfaces, Nexus interfaces, or safeguards interfaces among persons, institutions, systems, or instruments.

512.23.2 Interface Maps are explanatory and operational tools and shall not create authority beyond competent records.

#### 512.24 Ontology and Semantic Definition Records.

512.24.1 The Corporation shall maintain Ontology and Semantic Definition Records, including Ontology records, Taxonomy records, Controlled Vocabulary records, Schema records, Data Dictionary records, Semantic Interoperability records, AI-Readable Knowledge Structure records, Risk Category records, Evidence Class records, Technology Family records, Maturity Concept records, Public Authority Capacity Concept records, Finance Boundary Concept records, Certification Boundary Concept records, Public-Safe Term records, Restricted Term records, Reserved Term records, Semantic Drift records, Equivalence Note records, Compatibility Note records, Divergence Log records, Localization Note records, Interface Map records, correction records, and archive records.

***

### Section 513. Data, AI, Cybersecurity, Privacy, and Compute Definitions

#### 513.1 “Data.”

513.1.1 “Data” means recorded information, observations, measurements, signals, text, images, audio, video, metadata, telemetry, logs, structured records, unstructured records, derived records, synthetic records, model inputs, model outputs, embeddings, vector records, geospatial information, public authority materials, protected knowledge materials, or other machine-readable or human-readable information.

513.1.2 Data shall be governed by classification, source authority, lawful basis, permissions, privacy, cybersecurity, public authority restrictions, protected knowledge restrictions, retention, access, and correction requirements.

#### 513.2 “Dataset.”

513.2.1 “Dataset” means a collection, file, database, table, corpus, repository, stream, archive, benchmark set, evaluation set, training set, validation set, test set, map layer, telemetry set, or other organized grouping of data.

513.2.2 Dataset status shall be recorded with owner, custodian, source lineage, license, restrictions, classification, public-safe status, AI-use restrictions, correction path, and retention class.

#### 513.3 “Raw Data.”

513.3.1 “Raw Data” means data as originally collected, received, observed, measured, obtained, imported, or contributed before substantive transformation, aggregation, labeling, cleaning, enrichment, modeling, or analysis.

513.3.2 Raw Data may still contain sensitive, personal, public authority, cyber-sensitive, infrastructure-sensitive, protected knowledge, or restricted information and shall be classified accordingly.

#### 513.4 “Derived Data.”

513.4.1 “Derived Data” means data produced, inferred, calculated, transformed, cleaned, enriched, aggregated, labeled, modeled, summarized, embedded, or otherwise created from other data.

513.4.2 Derived Data may retain restrictions from source data and shall not be treated as unrestricted merely because it has been transformed.

#### 513.5 “Synthetic Data.”

513.5.1 “Synthetic Data” means artificially generated data designed to resemble, simulate, augment, replace, or model real data, whether produced by statistical methods, simulation, AI systems, digital twins, generative models, or other means.

513.5.2 Synthetic Data shall be reviewed for privacy leakage, re-identification risk, source restrictions, bias, public-safe risk, protected knowledge inference, cyber misuse, and misleading representation.

#### 513.6 “Embedding.”

513.6.1 “Embedding” means a numerical, vector, latent, semantic, or machine-generated representation of data, text, images, records, code, documents, prompts, outputs, or other materials.

513.6.2 Embeddings may carry sensitive, personal, confidential, public authority, protected knowledge, or restricted information and shall be governed by source restrictions, access controls, deletion controls, and AI-use restrictions.

#### 513.7 “Vector Store.”

513.7.1 “Vector Store” means a database, index, repository, service, or technical environment storing embeddings or vector representations for retrieval, search, reasoning, AI use, or analytics.

513.7.2 Vector Stores shall be access-controlled, classified, logged, secured, and subject to deletion and restriction pathways where required.

#### 513.8 “Personal Information.”

513.8.1 “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable natural person, household, device, or rights-bearing person, as applicable under governing law.

513.8.2 Personal Information shall be governed by privacy, lawful basis, notice, consent where required, rights handling, minimization, access control, retention, deletion, and security requirements.

#### 513.9 “Rights-Bearing Data.”

513.9.1 “Rights-Bearing Data” means data connected to persons, communities, groups, Tribal / Indigenous peoples, protected classes, vulnerable populations, youth, workers, participants, data subjects, or other rights-bearing persons or entities such that legal, ethical, civil rights, accessibility, consent, attribution, withdrawal, correction, grievance, or safeguards obligations may apply.

513.9.2 Rights-Bearing Data shall be treated with heightened review where public-safe publication, AI use, mapping, transfer, or analysis may affect rights or interests.

#### 513.10 “Sensitive Personal Information.”

513.10.1 “Sensitive Personal Information” means Personal Information requiring heightened protection under law, policy, ethics, contract, consent, or risk, including health, biometric, genetic, precise geolocation, financial, government identifier, children’s data, protected class, authentication, account access, communications, employment, education, or similarly sensitive information.

513.10.2 Sensitive Personal Information shall be restricted, minimized, secured, and not used for unauthorized AI training, publication, mapping, transfer, or external sharing.

#### 513.11 “Health-Sensitive Data.”

513.11.1 “Health-Sensitive Data” means data concerning health, public health, healthcare, mental health, disability, disease, exposure, vulnerability, treatment, health systems, health facilities, health status, health risks, public health operations, or community health conditions.

513.11.2 Health-Sensitive Data shall be governed by applicable health privacy, research ethics, public health, consent, public authority, public-safe publication, and safeguards controls.

#### 513.12 “Public Authority Data.”

513.12.1 “Public Authority Data” means data received from, contributed by, generated with, derived from, or subject to restrictions of a Public Authority or public-sector interface.

513.12.2 Public Authority Data shall be governed by authority records, capacity records, data contribution agreements, confidentiality, public records considerations, public authority restrictions, AI-use restrictions, publication restrictions, transfer restrictions, retention, deletion, and security requirements.

#### 513.13 “Cyber-Sensitive Data.”

513.13.1 “Cyber-Sensitive Data” means data that could expose, enable, increase, or explain cybersecurity risk, including vulnerabilities, exploits, configurations, credentials, logs, threat intelligence, incident details, security architecture, authentication records, access records, repository security data, or cyber telemetry.

513.13.2 Cyber-Sensitive Data shall be restricted and shall not be publicly disclosed except through authorized public-safe or coordinated vulnerability disclosure processes.

#### 513.14 “Infrastructure-Sensitive Data.”

513.14.1 “Infrastructure-Sensitive Data” means data concerning critical infrastructure, public infrastructure, utilities, ports, airports, transportation, telecom, energy, water, food, public health, public safety, cyber-physical systems, operational technology, supply chains, facilities, locations, vulnerabilities, dependencies, or operational states that could create risk if disclosed.

513.14.2 Infrastructure-Sensitive Data shall be handled under heightened access, mapping, publication, transfer, and security controls.

#### 513.15 “Finance-Sensitive Data.”

513.15.1 “Finance-Sensitive Data” means non-public or sensitive data concerning finances, budgets, capital, grants, lending, insurance, investment, proof packs, diligence, public finance, tax credits, guarantees, underwriting, ratings, pricing, projections, financial models, funders, sponsors, or capital-reader materials.

513.15.2 Finance-Sensitive Data shall be handled to preserve confidentiality, finance boundaries, GRA role separation, non-reliance, and regulated-perimeter discipline.

#### 513.16 “Commercially Sensitive Data.”

513.16.1 “Commercially Sensitive Data” means non-public business, commercial, provider, sponsor, vendor, contract, pricing, trade secret, proprietary, market, product, customer, strategy, or technical data whose disclosure could harm legitimate interests or create unfair advantage.

513.16.2 Commercially Sensitive Data shall be protected while preserving provider neutrality, sponsor non-control, procurement neutrality, public-benefit purpose, and legal obligations.

#### 513.17 “Community-Protected Data.”

513.17.1 “Community-Protected Data” means data provided by, about, or concerning communities, vulnerable communities, local groups, affected populations, civil society, neighborhoods, local institutions, or community knowledge holders that is subject to community expectation, consent, non-consent, attribution, restriction, public-safe mapping, grievance, or do-no-harm controls.

513.17.2 Community-Protected Data shall not be treated as unrestricted public data without safeguards review.

#### 513.18 “Protected Knowledge Data.”

513.18.1 “Protected Knowledge Data” means data containing or derived from Tribal / Indigenous knowledge, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, ecological knowledge, sacred knowledge, sensitive site information, community-protected knowledge, or other knowledge requiring protection.

513.18.2 Protected Knowledge Data shall be governed by consent, non-consent, attribution, withdrawal, restriction, public-safe mapping, AI-use restriction, transfer restriction, and grievance records.

#### 513.19 “Lawful Basis.”

513.19.1 “Lawful Basis” means the legal, contractual, consent-based, public authority, research, organizational, or other recognized basis authorizing collection, processing, access, use, retention, transfer, publication, deletion, or disposition of data.

513.19.2 Lawful Basis shall be recorded where required and shall not be inferred from possession alone.

#### 513.20 “Permission Record.”

513.20.1 “Permission Record” means a record documenting permission, authority, scope, restrictions, source, approver, term, withdrawal conditions, permitted uses, prohibited uses, transfer limits, publication limits, AI-use limits, and correction path for access to or use of data, records, materials, technical assets, public authority materials, or protected knowledge.

#### 513.21 “Consent Record.”

513.21.1 “Consent Record” means a record documenting consent from a person, participant, data subject, community, Tribal / Indigenous authority or representative where applicable, knowledge holder, public authority, or other competent source.

513.21.2 Consent Records shall identify scope, purpose, duration, withdrawal pathway, attribution rules, non-attribution rules, restrictions, publication permissions, AI-use permissions, transfer permissions, and correction pathways.

#### 513.22 “Data Steward.”

513.22.1 “Data Steward” means a person or role responsible for implementing data governance controls, classification, quality, metadata, access, use limitation, retention, correction, and compliance for specified data.

513.22.2 Data Stewardship does not by itself confer ownership, public authority, publication, AI-use, or transfer authority.

#### 513.23 “Data Owner.”

513.23.1 “Data Owner” means the person, role, entity, or authority responsible for approving or controlling use of a dataset or data class within the scope of applicable law, contract, permission, or organizational authority.

513.23.2 Data Owner status shall be recorded and shall not override law, consent, public authority restrictions, protected knowledge restrictions, or privacy rights.

#### 513.24 “Data Custodian.”

513.24.1 “Data Custodian” means the person, role, system, repository, provider, processor, or entity responsible for holding, securing, storing, administering, backing up, transferring, archiving, deleting, or disposing of data.

513.24.2 Data Custodians shall comply with access, security, privacy, retention, legal hold, and correction obligations.

#### 513.25 “Data Processor.”

513.25.1 “Data Processor” means a person or entity that processes data on behalf of the Corporation or another data owner, subject to contract, data processing terms, public authority terms, privacy requirements, cybersecurity requirements, and restrictions.

513.25.2 Data Processors shall not use data for unauthorized AI training, model improvement, external sharing, publication, provider development, sponsor benefit, or other prohibited purposes.

#### 513.26 “AI System.”

513.26.1 “AI System” means a machine-based system, model, software, tool, workflow, agent, automation, classifier, generator, recommender, predictor, optimizer, reasoning system, retrieval system, or decision-support system that produces outputs such as predictions, content, recommendations, classifications, inferences, scores, summaries, code, actions, or analyses.

513.26.2 AI Systems used by or for the Corporation shall be inventoried, classified, reviewed, monitored, and governed by human review, data restrictions, public-safe controls, and incident controls.

#### 513.27 “Model.”

513.27.1 “Model” means a statistical, machine learning, AI, simulation, optimization, digital twin, analytical, rules-based, computational, or hybrid model used to generate outputs, inferences, classifications, predictions, summaries, recommendations, or analyses.

513.27.2 Models shall be registered where material and governed by version, provider, purpose, permitted uses, prohibited uses, risk class, data access, evaluation, limitations, incident history, and retirement status.

#### 513.28 “Model Register.”

513.28.1 “Model Register” means the structured record of material AI systems, models, model versions, providers, owners, custodians, purposes, permitted uses, prohibited uses, risk classes, data access, evaluations, limitations, incidents, and retirement status.

#### 513.29 “Inference Record.”

513.29.1 “Inference Record” means a record documenting material AI or model use, including input, authority, environment, model, code, tool, workflow, execution, output, reviewer, confidence, limitations, classification, and correction path.

513.29.2 Inference Records support technical traceability and shall not be treated as public authority decisions, certifications, recognition, finance-readiness, procurement approvals, ratings, public warnings, or emergency commands.

#### 513.30 “Compute Workload Record.”

513.30.1 “Compute Workload Record” means a record documenting material compute activity, including workload identity, purpose, authority, data, environment, code, model, tool, compute resource, execution, output, reviewer, security status, limitation, and correction path.

#### 513.31 “Verifiable Compute.”

513.31.1 “Verifiable Compute” means compute whose execution, environment, code, input, output, identity, timestamp, integrity, or other material properties are documented, reproducible, attestable, auditable, or otherwise verifiable within a defined scope.

513.31.2 Verifiable Compute supports evidence integrity but does not by itself create certification, public authority approval, finance-readiness, recognition, procurement approval, rating, public warning, or emergency command.

#### 513.32 “Verifiable Intelligence.”

513.32.1 “Verifiable Intelligence” means intelligence, inference, analysis, or output whose sources, methods, computation, model, review, limitations, confidence, and correction path are documented sufficiently to support traceability and review.

513.32.2 Verifiable Intelligence is not official truth without records and review and is not a public authority decision, certification, finance-readiness, recognition, procurement approval, rating, public warning, or emergency command.

#### 513.33 “Proof Receipt.”

513.33.1 “Proof Receipt” means a record, attestation, hash, timestamp, ledger reference, execution receipt, compute receipt, validation receipt, verification receipt, or similar technical record indicating that a defined action, computation, submission, event, record, or output occurred or was recorded within a defined scope.

513.33.2 Proof Receipts are technical traceability instruments. They shall not be represented as public authority decisions, certifications, recognition, finance-readiness, procurement approvals, ratings, public warnings, emergency commands, or legal compliance determinations.

#### 513.34 “Agentic AI.”

513.34.1 “Agentic AI” means an AI system, workflow, automation, or tool-enabled system capable of taking actions, using tools, calling APIs, accessing systems, modifying records, sending communications, initiating workflows, making recommendations for action, or otherwise operating with autonomy or semi-autonomy.

513.34.2 Agentic AI shall be subject to permission controls, logging, approval gates, prohibited action rules, kill switches, human review, and boundary controls.

#### 513.35 “Human Review.”

513.35.1 “Human Review” means review by a qualified human reviewer of AI outputs, model outputs, evidence outputs, publication outputs, public authority materials, finance-boundary materials, technical claims, public-safe summaries, or other material outputs.

513.35.2 Human Review shall be meaningful, recorded where material, and sufficient for the risk, use, audience, and reliance context.

#### 513.36 “Model Card.”

513.36.1 “Model Card” means a structured documentation record describing a model’s identity, version, provider, purpose, training or source context where available, intended uses, prohibited uses, evaluation results, limitations, risk class, data access, bias considerations, safety considerations, incident history, and retirement status.

#### 513.37 “System Card.”

513.37.1 “System Card” means a structured documentation record describing an AI system or technical system, including components, models, tools, data flows, interfaces, controls, human review, limitations, risks, evaluation, monitoring, incidents, and public-safe restrictions.

#### 513.38 “Dataset Card.”

513.38.1 “Dataset Card” means a structured documentation record describing a dataset’s source, purpose, contents, collection method, lawful basis, license, permissions, restrictions, classifications, quality, limitations, biases, public-safe status, AI-use restrictions, retention, and correction path.

#### 513.39 “Benchmark Card.”

513.39.1 “Benchmark Card” means a structured documentation record describing a benchmark, evaluation set, test harness, gold vector set, negative test suite, or evaluation framework, including purpose, scope, version, method, known limitations, data restrictions, suitability, bias, and interpretation limits.

#### 513.40 “Cybersecurity Incident.”

513.40.1 “Cybersecurity Incident” means an actual or suspected event that compromises or threatens confidentiality, integrity, availability, authentication, authorization, systems, networks, repositories, data, secrets, keys, tokens, credentials, software, cloud services, AI systems, controlled rooms, or technical assets.

513.40.2 Cybersecurity Incidents include unauthorized access, malware, phishing, credential compromise, secret exposure, vulnerability exploitation, denial of service, supply-chain compromise, repository compromise, cloud compromise, and service disruption.

#### 513.41 “Data Incident.”

513.41.1 “Data Incident” means an actual or suspected event involving unauthorized access, use, disclosure, alteration, loss, deletion, corruption, transfer, publication, AI use, embedding, training, retention, destruction, or compromise of data.

513.41.2 Data Incidents include privacy incidents, public authority data incidents, health-sensitive data incidents, cyber-sensitive data incidents, infrastructure-sensitive data incidents, protected knowledge incidents, and data leakage incidents.

#### 513.42 “AI Incident.”

513.42.1 “AI Incident” means an actual or suspected event involving unsafe, unauthorized, erroneous, biased, hallucinated, leaking, manipulated, adversarial, agentic, privacy-defective, public authority-confusing, finance-confusing, certification-confusing, recognition-confusing, procurement-confusing, protected-knowledge-defective, or public-safe-defective AI system behavior or output.

513.42.2 AI Incidents include hallucination incidents, unsafe output incidents, bias or civil rights incidents, data leakage incidents, unauthorized agentic action incidents, prompt injection incidents, model drift incidents, and misuse of AI outputs in public claims.

#### 513.43 Data, AI, Cybersecurity, Privacy, and Compute Definition Records.

513.43.1 The Corporation shall maintain Data, AI, Cybersecurity, Privacy, and Compute Definition Records, including Data records, Dataset records, Raw Data records, Derived Data records, Synthetic Data records, Embedding records, Vector Store records, Personal Information records, Rights-Bearing Data records, Sensitive Personal Information records, Health-Sensitive Data records, Public Authority Data records, Cyber-Sensitive Data records, Infrastructure-Sensitive Data records, Finance-Sensitive Data records, Commercially Sensitive Data records, Community-Protected Data records, Protected Knowledge Data records, Lawful Basis records, Permission Record definitions, Consent Record definitions, Data Steward records, Data Owner records, Data Custodian records, Data Processor records, AI System records, Model records, Model Register records, Inference Record definitions, Compute Workload Record definitions, Verifiable Compute records, Verifiable Intelligence records, Proof Receipt records, Agentic AI records, Human Review records, Model Card records, System Card records, Dataset Card records, Benchmark Card records, Cybersecurity Incident records, Data Incident records, AI Incident records, correction records, and archive records.

### Section 514. Public-Good Software, Technical Asset, Repository, and IP Definitions

#### 514.1 “Public-Good Software.”

514.1.1 “Public-Good Software” means software, code, scripts, libraries, applications, dashboards, APIs, SDKs, tools, reference implementations, automation, workflows, inference tooling, verification tooling, public-safe visualization tooling, observability tooling, repository tooling, documentation, and related technical materials developed, maintained, contributed to, released, or stewarded by or for the Corporation for public-benefit, public-good, research, evidence, methods, observability, ontology, technical truth, public authority learning, interoperability, safeguards, or Nexus coordination purposes.

514.1.2 Public-Good Software may be open, controlled, restricted, internal, archived, experimental, reference-only, or successor-stewarded depending on its license, security posture, data content, public-safe status, maturity, dependency status, vulnerability status, release status, and Technical Asset Records.

514.1.3 Public-Good Software shall not be construed as certification, accreditation, procurement approval, public authority adoption, legal compliance approval, provider preference, finance-readiness, capital-readability, insurance-readiness, recognition, rating, public warning, emergency command, public health order, safety command, warranty, guarantee, or operational approval.

#### 514.2 “Public-Good Technical Asset.”

514.2.1 “Public-Good Technical Asset” means any software, dataset, schema, API, SDK, technical profile, reference architecture, open technical baseline, ontology, controlled vocabulary, data dictionary, benchmark, evaluation harness, test harness, gold vector, negative test, model card, system card, dataset card, benchmark card, dashboard, map, public-safe visualization, proof receipt profile, repository, documentation, method, or technical record stewarded for public-good purposes.

514.2.2 Public-Good Technical Assets shall be governed by asset identity, ownership, stewardship, version, license, access class, public-safe status, confidentiality status, security status, dependency status, vulnerability status, data / AI / cyber / privacy status, protected knowledge status, Nexus interface status, correction path, deprecation path, and retirement path.

514.2.3 Public-Good Technical Asset status shall not create public authority approval, certification, recognition, finance-readiness, procurement approval, provider preference, or enterprise execution authority.

#### 514.3 “Open Technical Baseline.”

514.3.1 “Open Technical Baseline” means a public-good reference baseline, technical framework, methods baseline, interoperability baseline, evidence baseline, data governance baseline, AI governance baseline, cybersecurity baseline, observability baseline, proof receipt baseline, public authority learning baseline, or other technical baseline released or stewarded for public-good reference use.

514.3.2 An Open Technical Baseline may support interoperability, evidence quality, technical literacy, public authority learning, Nexus alignment, and public-good software development.

514.3.3 An Open Technical Baseline is not certification, accreditation, legal compliance approval, procurement mandate, public authority adoption, provider preference, finance-readiness, recognition, rating, public warning, emergency command, or professional advice.

#### 514.4 “Reference Architecture.”

514.4.1 “Reference Architecture” means a non-executing technical design, model, pattern, diagram, specification, interface structure, systems map, workflow, or architecture intended to support understanding, interoperability, public-good design, methods development, public authority learning, technical baseline development, or Nexus coordination.

514.4.2 Reference Architectures may address AI, AI-RAN, O-RAN, DePIN, DLT, digital twins, cyber telemetry, geospatial systems, sensor networks, edge compute, public authority learning systems, controlled rooms, proof receipts, public-safe dashboards, observability nodes, Nexus hubs, Nexus clusters, and other exponential-technology systems.

514.4.3 Reference Architectures do not authorize deployment, procurement, certification, public authority adoption, finance-readiness, provider preference, emergency command, public warning, or operational execution.

#### 514.5 “Technical Profile.”

514.5.1 “Technical Profile” means a defined specification, metadata profile, interface profile, evidence profile, method profile, ontology profile, dataset profile, model register profile, inference record profile, compute workload profile, proof receipt profile, observability profile, dashboard profile, map profile, federation profile, or Nexus interface profile.

514.5.2 Technical Profiles shall be versioned, documented, validated where appropriate, classified, and corrected when incomplete, outdated, unsafe, or misleading.

514.5.3 Use of a Technical Profile does not by itself create conformance approval, certification, procurement approval, public authority adoption, finance-readiness, recognition, rating, provider preference, or Nexus-compatible status.

#### 514.6 “API.”

514.6.1 “API” means an application programming interface, endpoint, interface specification, service interface, data exchange interface, query interface, inference interface, repository interface, dashboard interface, proof receipt interface, or system-to-system communication interface.

514.6.2 APIs shall be governed by access controls, documentation, versioning, authentication, authorization, logging, data classification, security controls, rate limits where appropriate, license terms, public-safe restrictions, and deprecation rules.

514.6.3 API access shall not be treated as endorsement, certification, provider preference, public authority access, finance-readiness, recognition, procurement approval, or operational authority.

#### 514.7 “SDK.”

514.7.1 “SDK” means a software development kit, library, package, toolkit, code sample, developer tool, reference implementation, integration kit, command-line tool, or documentation package supporting interaction with Corporation or Nexus-aligned technical assets.

514.7.2 SDKs shall be governed by license, documentation, release status, security status, version, known limitations, vulnerability records, dependency records, and public-safe use guidance.

514.7.3 Use of an SDK shall not create certification, conformance approval, procurement approval, public authority adoption, finance-readiness, recognition, provider preference, or Nexus-compatible status without competent records.

#### 514.8 “Repository.”

514.8.1 “Repository” means a system, platform, folder, code repository, data repository, model repository, evidence repository, publication repository, documentation repository, technical baseline repository, archive, registry, storage environment, or controlled file space used to store, version, access, publish, review, maintain, or archive records or technical assets.

514.8.2 Repositories may be public, public-safe, internal, confidential, restricted, controlled, no-download, archived, successor-stewarded, or otherwise classified.

514.8.3 Repository access shall be governed by identity, least privilege, access class, branch protection where applicable, required review where applicable, commit signing where appropriate, logging, monitoring, secrets controls, and retention rules.

#### 514.9 “Official Repository.”

514.9.1 “Official Repository” means the repository designated by the Board, Secretary, repository custodian, or other competent authority as the authoritative location for specified records, Bylaws, policies, schedules, technical assets, releases, public-safe materials, notices, or archives.

514.9.2 Official Repository status shall be recorded with custodian, scope, access rules, versioning rules, certification-of-record rules, integrity controls, backup rules, migration rules, failure recovery rules, and correction path.

514.9.3 Unofficial copies, drafts, redlines, slides, summaries, AI summaries, translations, extracts, screenshots, or mirrored materials shall not override the Official Repository.

#### 514.10 “Release.”

514.10.1 “Release” means a versioned publication, distribution, deployment, posting, transfer, archive, controlled availability, repository tag, package publication, dataset publication, software release, baseline release, documentation release, dashboard release, map release, API release, SDK release, or technical asset availability event.

514.10.2 A Release shall identify status, version, date, authority, owner, custodian, license, known issues, known limitations, public-safe status, security status, access class, deprecation path, rollback path where applicable, and correction path.

#### 514.11 “Secure Release.”

514.11.1 “Secure Release” means a Release that has undergone appropriate secure development, vulnerability review, dependency review, license review, secrets review, access review, public-safe review, data / AI / cyber / privacy review, and approval according to its risk class.

514.11.2 Secure Release does not mean risk-free, vulnerability-free, certified, compliant, public authority-approved, procurement-approved, finance-ready, recognized, or warranted.

#### 514.12 “Version.”

514.12.1 “Version” means a unique, recorded state, edition, release, build, revision, tag, commit, model, dataset, baseline, document, schema, method, or technical asset identifier.

514.12.2 Version records shall support traceability, comparison, supersession, rollback, correction, archive, and reliance limitation.

#### 514.13 “Changelog.”

514.13.1 “Changelog” means a structured record describing changes between versions, including additions, removals, corrections, security changes, breaking changes, dependency changes, licensing changes, public-safe changes, and known limitations.

514.13.2 Changelogs shall not omit material changes that affect reliance, security, public-safe status, data use, AI use, public authority references, finance-boundary references, certification or recognition boundary references, or Nexus interface status.

#### 514.14 “Release Notes.”

514.14.1 “Release Notes” means explanatory notes accompanying a Release, including purpose, scope, changes, installation or use guidance where applicable, known issues, known limitations, migration notes, security notes, public-safe limitations, license notes, and correction path.

514.14.2 Release Notes shall include boundary language where reliance risk exists.

#### 514.15 “Known Issues.”

514.15.1 “Known Issues” means identified defects, limitations, bugs, gaps, vulnerabilities, unresolved questions, compatibility problems, data quality concerns, model limitations, public-safe concerns, documentation gaps, or other issues known at the time of release or subsequently discovered.

514.15.2 Known Issues shall be recorded, tracked, classified, mitigated, corrected, superseded, or disclosed according to risk and access class.

#### 514.16 “Known Limitations.”

514.16.1 “Known Limitations” means limits on purpose, scope, method, data, model, system, benchmark, dashboard, map, software, technical baseline, public-safe summary, or output that affect interpretation or use.

514.16.2 Known Limitations shall be disclosed where material and shall include uncertainty, unsupported contexts, excluded uses, data restrictions, public authority limits, finance-boundary limits, certification and recognition boundary limits, security limits, and safeguards limits.

#### 514.17 “Deprecation.”

514.17.1 “Deprecation” means a recorded status indicating that a technical asset, version, method, API, SDK, schema, baseline, dataset, model, dashboard, map, repository, feature, term, or public material remains available but is no longer preferred, may be replaced, may be unsupported, or is scheduled for retirement.

514.17.2 Deprecation shall include notice, effective date, replacement where applicable, migration guidance where appropriate, support limits, public-safe limitations, and correction path.

#### 514.18 “Retirement.”

514.18.1 “Retirement” means a recorded status indicating that a technical asset, version, method, API, SDK, schema, baseline, dataset, model, dashboard, map, repository, feature, term, or public material is no longer maintained, supported, approved for use, or current.

514.18.2 Retirement shall not eliminate legal holds, retention duties, archive duties, correction duties, license obligations, or vulnerability disclosure obligations where applicable.

#### 514.19 “Archive.”

514.19.1 “Archive” means the preserved state of a record, technical asset, publication, repository, dataset, software, baseline, dashboard, map, method, version, notice, or other material retained for historical, legal, audit, technical memory, public-safe, correction, or continuity purposes.

514.19.2 Archive status shall distinguish historical availability from current authority.

514.19.3 Archived materials shall not be treated as current unless competent records expressly restore or re-enter them.

#### 514.20 “Contributor License Agreement.”

514.20.1 “Contributor License Agreement” or “CLA” means a written, electronic, repository-based, click-through, signed, or otherwise enforceable contributor agreement granting rights, licenses, permissions, representations, warranties, assignments where applicable, patent rights where applicable, attribution terms, and contribution conditions for contributions to the Corporation or its repositories.

514.20.2 A CLA shall not create employment, membership, governance authority, maintainer authority, release authority, endorsement, certification, recognition, finance-readiness, or procurement approval.

#### 514.21 “Assignment.”

514.21.1 “Assignment” means a transfer of ownership or rights in intellectual property, data rights, work product, software, documentation, technical assets, inventions, copyrights, patents, model artifacts, datasets, or other rights from one person or entity to another.

514.21.2 Assignments shall be recorded, lawful, within authority, and consistent with public-benefit purpose, contributor rights, grant terms, sponsor terms, public authority restrictions, protected knowledge restrictions, and anti-enclosure controls.

#### 514.22 “Open License.”

514.22.1 “Open License” means a license permitting public or broad use, copying, modification, distribution, performance, display, implementation, or reuse of software, data, documentation, technical assets, or other materials under stated conditions.

514.22.2 Open License status shall not override privacy, public authority restrictions, protected knowledge restrictions, export controls, sanctions, controlled technology controls, trademark restrictions, or public-safe limitations unless lawfully and expressly addressed.

#### 514.23 “Public-Good License.”

514.23.1 “Public-Good License” means a license or license strategy designed to preserve public-benefit use, interoperability, anti-enclosure, attribution, public-safe limitations, role-separation clarity, and responsible reuse of technical assets.

514.23.2 Public-Good Licenses may be open, restricted, dual, community-protective, standards-supportive, research-oriented, or mission-limited, depending on the asset and legal requirements.

#### 514.24 “Restricted License.”

514.24.1 “Restricted License” means a license limiting access, use, modification, redistribution, commercial use, AI training, model improvement, publication, transfer, export, public authority use, protected knowledge use, security-sensitive use, or other activity.

514.24.2 Restricted Licenses shall be used where open release would conflict with law, contract, privacy, public authority restrictions, protected knowledge safeguards, security, controlled technology, export-control, sanctions, or public-safe obligations.

#### 514.25 “Dual License.”

514.25.1 “Dual License” means licensing the same or substantially similar asset under two or more licensing paths, such as open and commercial, public-good and restricted, research and enterprise, or community and institutional licenses.

514.25.2 Dual Licensing shall be reviewed for mission compatibility, anti-enclosure, private benefit, sponsor or provider advantage, license compatibility, contributor rights, and public-safe interpretation.

#### 514.26 “Fork.”

514.26.1 “Fork” means a copy, branch, derivative codebase, repository split, independent development line, or externally maintained version of software, documentation, data, baseline, schema, API, SDK, profile, or other technical asset.

514.26.2 A Fork may be permitted by license, but a Fork shall not create compatibility, certification, recognition, finance-readiness, procurement approval, public authority adoption, provider preference, or authority to use the Corporation’s marks beyond applicable terms.

#### 514.27 “Derivative Use.”

514.27.1 “Derivative Use” means use, adaptation, modification, transformation, integration, extension, model training, fine-tuning, embedding, translation, compilation, packaging, commercialization, or deployment derived from Corporation technical assets.

514.27.2 Derivative Use shall be subject to license terms, attribution, restrictions, data rights, protected knowledge controls, AI-use restrictions, public-safe limitations, and no-overclaim rules.

#### 514.28 “Compatibility Claim.”

514.28.1 “Compatibility Claim” means a claim that a system, project, product, provider, dataset, model, repository, method, technical asset, software release, protocol, schema, API, SDK, baseline, or implementation is compatible with GCRI US, Nexus, Nexus Standards, a technical profile, an interface, a baseline, or a public-good asset.

514.28.2 Compatibility Claims require record support, scope, version, testing basis where applicable, limitations, and authority.

514.28.3 Compatibility Claims shall not be treated as certification, procurement approval, public authority adoption, finance-readiness, recognition, provider preference, rating, or Nexus-compatible status unless competent authority expressly provides that meaning.

#### 514.29 “Anti-Enclosure.”

514.29.1 “Anti-Enclosure” means the principle that public-good software, open technical baselines, schemas, ontologies, controlled vocabularies, methods, public-safe tools, documentation, and technical memory shall not be captured, monopolized, privatized, misappropriated, restricted, or commercially enclosed in a manner inconsistent with public-benefit purpose, lawful restrictions, license terms, or public-good stewardship.

514.29.2 Anti-Enclosure shall be implemented through license selection, trademark restrictions, no-endorsement clauses, provider-neutrality controls, sponsor non-control, public-good successor stewardship, repository preservation, correctionability, and technical memory controls.

#### 514.30 “SBOM.”

514.30.1 “SBOM” means a software bill of materials or equivalent structured record identifying software components, dependencies, versions, licenses, suppliers, provenance, vulnerability information where appropriate, and related security information.

514.30.2 SBOMs support supply-chain assurance and do not themselves create certification, compliance approval, security guarantee, procurement approval, or public authority approval.

#### 514.31 “Artifact Signing.”

514.31.1 “Artifact Signing” means cryptographic, digital, or equivalent signing of software, packages, releases, documents, datasets, containers, build artifacts, proof receipts, or other technical assets to support authenticity, integrity, provenance, and tamper evidence.

514.31.2 Artifact Signing does not guarantee absence of defects, vulnerabilities, malicious dependencies, unsafe outputs, legal compliance, certification, procurement approval, public authority approval, finance-readiness, or recognition.

#### 514.32 “Provenance Record.”

514.32.1 “Provenance Record” means a record documenting origin, authorship, source, build process, data source, transformation, custody, dependency, version, signature, timestamp, approval, or chain-of-custody for a technical asset, release, dataset, model, record, or output.

514.32.2 Provenance Records support traceability, integrity, correctionability, and public-safe interpretation.

#### 514.33 “Vulnerability.”

514.33.1 “Vulnerability” means a weakness, flaw, defect, misconfiguration, exposed secret, dependency issue, design weakness, access control gap, data leakage path, AI misuse risk, prompt injection susceptibility, model leakage path, repository weakness, or other condition that may compromise confidentiality, integrity, availability, safety, privacy, security, or public-safe operation.

514.33.2 Vulnerabilities shall be classified, triaged, remediated, disclosed, restricted, embargoed, or corrected according to risk and coordinated disclosure rules.

#### 514.34 “Coordinated Vulnerability Disclosure.”

514.34.1 “Coordinated Vulnerability Disclosure” means a process for receiving, validating, triaging, mitigating, notifying, embargoing, and publicly or privately disclosing vulnerabilities in a manner that reduces harm and supports remediation.

514.34.2 Coordinated Vulnerability Disclosure shall protect sensitive exploit details, public authority data, infrastructure-sensitive information, protected knowledge, personal information, and ongoing investigations.

#### 514.35 “Secret.”

514.35.1 “Secret” means any password, private key, API key, token, credential, signing material, recovery code, certificate, access string, environment variable, configuration value, encryption material, or other sensitive information that can enable access, authentication, authorization, decryption, signing, control, or misuse.

514.35.2 Secrets shall not be stored in public repositories, exposed in logs, embedded in public artifacts, retained by unauthorized persons, or transferred without recorded authority and secure controls.

#### 514.36 “Key.”

514.36.1 “Key” means cryptographic key material, signing key, encryption key, decryption key, API key, access key, SSH key, private key, public key where relevant, recovery key, or other key-like material used for authentication, authorization, integrity, confidentiality, or signing.

514.36.2 Keys shall be inventoried, protected, rotated, revoked, transferred, escrowed, or destroyed according to policy and risk.

#### 514.37 “Token.”

514.37.1 “Token” means a bearer token, access token, refresh token, session token, API token, repository token, cloud token, model-access token, identity token, service token, or other technical credential enabling access or action.

514.37.2 Tokens shall be limited, logged where appropriate, revoked when no longer required, and protected as secrets.

#### 514.38 “Credential.”

514.38.1 “Credential” means any password, token, certificate, key, account, identity assertion, authentication factor, authorization grant, recovery code, service account, privileged account, or other mechanism enabling access to systems, repositories, data, cloud environments, AI systems, controlled rooms, or technical assets.

514.38.2 Credentials shall be governed by identity and access management, least privilege, logging, rotation, revocation, break-glass controls, and closeout procedures.

#### 514.39 Technical Asset and IP Definition Records.

514.39.1 The Corporation shall maintain Technical Asset and IP Definition Records, including Public-Good Software records, Public-Good Technical Asset records, Open Technical Baseline records, Reference Architecture records, Technical Profile records, API records, SDK records, Repository records, Official Repository records, Release records, Secure Release records, Version records, Changelog records, Release Notes records, Known Issues records, Known Limitations records, Deprecation records, Retirement records, Archive records, Contributor License Agreement records, Assignment records, Open License records, Public-Good License records, Restricted License records, Dual License records, Fork records, Derivative Use records, Compatibility Claim records, Anti-Enclosure records, SBOM records, Artifact Signing records, Provenance Record records, Vulnerability records, Coordinated Vulnerability Disclosure records, Secret records, Key records, Token records, Credential records, correction records, and archive records.

***

### Section 515. Public Authority and Government Interface Definitions

#### 515.1 “Federal Public Authority.”

515.1.1 “Federal Public Authority” means any agency, department, office, instrumentality, regulator, commission, board, legislative body, judicial body, inspector general, grantor, procurement body, public finance body, public health body, emergency management body, public safety body, infrastructure body, research body, laboratory, or other body of the United States federal government.

515.1.2 Federal Public Authority participation, funding, attendance, data contribution, or reference shall not imply federal endorsement, adoption, procurement approval, regulatory approval, public finance approval, public warning, emergency command, sovereign obligation, or public-private partnership unless competent federal records expressly provide such meaning.

#### 515.2 “State Public Authority.”

515.2.1 “State Public Authority” means any agency, department, office, instrumentality, regulator, commission, board, legislative body, judicial body, inspector general, grantor, procurement body, public finance body, public health body, emergency management body, public safety body, infrastructure body, research body, university, laboratory, or other public-sector body of a United States state.

515.2.2 State Public Authority interfaces shall be subject to state law, public records considerations, procurement neutrality, public authority capacity classification, and public-safe reference controls.

#### 515.3 “District of Columbia Public Authority.”

515.3.1 “District of Columbia Public Authority” means any agency, office, instrumentality, regulator, commission, board, legislative body, judicial body, grantor, procurement body, public finance body, emergency management body, public health body, public safety body, public works body, infrastructure body, university, or public-sector body of the District of Columbia.

515.3.2 District of Columbia Public Authority references shall not imply approval, adoption, procurement, funding, regulation, public finance, public warning, or emergency command by the District absent competent record.

#### 515.4 “Territorial Public Authority.”

515.4.1 “Territorial Public Authority” means any public authority, agency, department, office, regulator, commission, board, legislature, court, public health body, emergency management body, public safety body, public works body, infrastructure body, utility body, port body, university, laboratory, grantor, or procurement body of a United States territory or other relevant territorial public-sector context.

515.4.2 Territorial Public Authority interfaces shall account for territorial law, federal law, public authority capacity, public records constraints, language access, accessibility, protected knowledge, public-safe mapping, disaster risk, climate risk, public health sensitivity, and infrastructure sensitivity.

#### 515.5 “Tribal Government.”

515.5.1 “Tribal Government” means a federally recognized Tribal government, state-recognized Tribal government where applicable, Indigenous governing authority, Native nation government, Tribal council, Tribal department, Tribal enterprise acting in governmental capacity, or other Tribal governmental body where lawfully and respectfully engaged.

515.5.2 Tribal Government engagement shall respect Tribal sovereignty, government-to-government considerations where applicable, consent, non-consent, data sovereignty, protected knowledge, public-safe mapping, attribution, withdrawal, restriction, and grievance pathways.

#### 515.6 “Indigenous Government Interface.”

515.6.1 “Indigenous Government Interface” means an interface involving Indigenous governments, Indigenous governance bodies, Indigenous representatives, Indigenous institutions, Indigenous knowledge authorities, Indigenous data stewards, Indigenous public authorities, or Indigenous community governance structures.

515.6.2 Indigenous Government Interfaces shall be structured according to applicable law, respectful protocol, safeguards review, protected knowledge controls, data sovereignty, consent, restriction, and public-safe publication rules.

#### 515.7 “Local Public Authority.”

515.7.1 “Local Public Authority” means a county, city, municipality, parish, borough, township, metropolitan authority, regional authority, utility authority, port authority, transit authority, public health district, school district, public safety authority, public works body, housing authority, environmental authority, or other local public-sector body.

515.7.2 Local Public Authority engagement shall preserve local law, public records constraints, procurement neutrality, public-safe mapping, public warning boundaries, emergency command boundaries, and public authority capacity records.

#### 515.8 “Public Infrastructure Operator.”

515.8.1 “Public Infrastructure Operator” means a public, publicly regulated, publicly owned, publicly supported, or public-service operator of infrastructure, including utilities, ports, airports, transit systems, transportation systems, telecom systems, energy systems, water systems, food systems, public health systems, cyber systems, emergency systems, public works systems, or other infrastructure systems.

515.8.2 Public Infrastructure Operator participation shall be subject to infrastructure-sensitive data controls, cyber-sensitive data controls, public-safe mapping review, public authority boundary controls, procurement neutrality, and confidentiality requirements.

#### 515.9 “Public Health Authority.”

515.9.1 “Public Health Authority” means a public-sector body or official with legal authority concerning public health, disease control, health surveillance, health orders, public health emergency response, health system coordination, population health, or health-sensitive data.

515.9.2 Public Health Authority engagement shall not make GCRI US a public health authority or permit GCRI US to issue public health orders.

#### 515.10 “Emergency Management Authority.”

515.10.1 “Emergency Management Authority” means a public-sector body or official responsible for emergency preparedness, mitigation, response, recovery, incident coordination, disaster management, public alerts, evacuation coordination, emergency operations, or related functions.

515.10.2 Emergency Management Authority engagement shall not give GCRI US emergency command, incident command, dispatch, evacuation, alerting, public warning, or operational resource direction authority.

#### 515.11 “Public Safety Authority.”

515.11.1 “Public Safety Authority” means a law enforcement, fire, emergency medical, public safety, emergency communications, public protection, or related public-sector body or official.

515.11.2 Public Safety Authority interfaces shall preserve public safety sensitivity, privacy, civil rights, public authority boundaries, public-safe publication, and no-command rules.

#### 515.12 “Public Works Authority.”

515.12.1 “Public Works Authority” means a public-sector body responsible for public works, infrastructure maintenance, roads, bridges, utilities, water, wastewater, sanitation, facilities, public construction, public operations, or related services.

515.12.2 Public Works Authority interfaces shall preserve procurement neutrality, infrastructure sensitivity, public authority capacity classification, and no operational command by GCRI US.

#### 515.13 “Public Finance Body.”

515.13.1 “Public Finance Body” means a public budget, treasury, grant, public credit, bond, tax credit, development finance, public bank, public guarantee, appropriation, fiscal, or finance-related body or official.

515.13.2 Public Finance Body engagement shall not create public finance approval, grant approval, budget allocation, public credit, public guarantee, tax credit approval, sovereign obligation, capital commitment, finance-readiness, or investment advice by GCRI US.

#### 515.14 “Regulator.”

515.14.1 “Regulator” means a public authority with legal authority to issue rules, enforce laws, grant approvals, issue permits, conduct inspections, provide binding guidance, take enforcement action, or determine compliance.

515.14.2 Regulator attendance, listening, participation, or review shall not create regulatory approval, safe harbor, compliance determination, permit, waiver, enforcement position, policy adoption, or public authority endorsement.

#### 515.15 “Official Capacity.”

515.15.1 “Official Capacity” means participation, communication, approval, contribution, reference, or action by a public authority participant within the scope of that person’s official authority and supported by competent records.

515.15.2 Official Capacity shall not be inferred from title, email domain, attendance, verbal statement, informal participation, or public employment without appropriate authority record where material.

#### 515.16 “Observer Status.”

515.16.1 “Observer Status” means participation by a person or public authority for observation, learning, awareness, or listening only, without endorsement, approval, adoption, funding approval, procurement approval, regulatory approval, public finance approval, public warning, emergency command, or decision authority.

#### 515.17 “Regulator-Listening Status.”

515.17.1 “Regulator-Listening Status” means participation by a regulator or regulatory staff in a listening, learning, or awareness capacity only.

515.17.2 Regulator-Listening Status does not create regulatory guidance, approval, safe harbor, permit, waiver, compliance determination, enforcement position, policy adoption, or endorsement.

#### 515.18 “Public Finance Reader Status.”

515.18.1 “Public Finance Reader Status” means participation by a public finance, budget, treasury, grant, development finance, public credit, or related public-sector participant for literacy, learning, diligence awareness, or review without approval authority.

515.18.2 Public Finance Reader Status does not create grant approval, appropriation, public finance approval, public credit, public guarantee, tax credit approval, sovereign obligation, capital commitment, finance-readiness, or investment advice.

#### 515.19 “Emergency-Management Participation.”

515.19.1 “Emergency-Management Participation” means participation by emergency management personnel in learning, scenario, simulation, tabletop, after-action, public-safe reporting, resilience literacy, or technical awareness activities.

515.19.2 Emergency-Management Participation shall not create incident command, dispatch authority, evacuation authority, emergency alert authority, official public warning, public health order, safety command, or operational resource direction by GCRI US.

#### 515.20 “Simulation Participant.”

515.20.1 “Simulation Participant” means a person or entity participating in a simulated, hypothetical, training, scenario, tabletop, exercise, model, digital twin, or controlled learning environment.

515.20.2 Simulation Participant status shall not imply real-world operational authority, emergency command, public authority approval, procurement approval, finance-readiness, certification, recognition, or provider preference.

#### 515.21 “Tabletop Participant.”

515.21.1 “Tabletop Participant” means a participant in a discussion-based exercise, scenario, planning session, learning session, or after-action-preparation exercise.

515.21.2 Tabletop Participant status is for learning and does not create operational command, public authority adoption, public warning, procurement approval, or finance meaning.

#### 515.22 “After-Action Participant.”

515.22.1 “After-Action Participant” means a person or entity participating in a post-event, post-exercise, post-incident, or post-simulation review designed to identify lessons, evidence gaps, methods gaps, safeguards issues, public authority boundary issues, and improvement actions.

515.22.2 After-Action Participation shall not imply admission, liability, endorsement, public authority decision, certification, recognition, finance-readiness, procurement approval, or public warning unless expressly stated by competent authority.

#### 515.23 “Public Authority Room.”

515.23.1 “Public Authority Room” means a controlled room, data room, evidence room, clean room, no-download room, regulator-listening room, public finance reader room, emergency learning room, or other restricted environment involving public authority participants or public authority materials.

515.23.2 Public Authority Rooms shall be governed by room charter, capacity classification, confidentiality, public records considerations, data / AI / cyber / privacy controls, competition controls, public authority boundary controls, finance and procurement boundary controls, and public-safe publication controls.

#### 515.24 “Public Records.”

515.24.1 “Public Records” means records that may be subject to public records laws, FOIA, open records laws, sunshine laws, open meetings laws, public authority retention laws, public grant laws, or other public-sector disclosure regimes.

515.24.2 GCRI US records are not Public Records merely because GCRI US engages with public authorities, unless law, contract, public authority possession, grant terms, or other legal conditions make them subject to disclosure.

#### 515.25 “FOIA.”

515.25.1 “FOIA” means the United States Freedom of Information Act or analogous freedom of information, access to information, open records, or public disclosure laws, as applicable.

515.25.2 FOIA considerations shall be reviewed where Corporation materials are provided to or held by public authorities or otherwise become subject to public-sector disclosure.

#### 515.26 “Sunshine Law.”

515.26.1 “Sunshine Law” means any law requiring openness, notice, access, disclosure, meeting transparency, or public accountability for public bodies or public-sector proceedings.

515.26.2 Sunshine Law considerations shall be reviewed where public authority participation, meetings, rooms, or records may trigger public-sector requirements.

#### 515.27 “Open Meetings.”

515.27.1 “Open Meetings” means public-sector meeting laws or requirements governing meetings of public bodies, public authorities, committees, commissions, boards, councils, or other public entities.

515.27.2 GCRI US meetings are not Open Meetings merely because public authority participants attend, unless law or competent record requires otherwise.

#### 515.28 “Government Ethics.”

515.28.1 “Government Ethics” means laws, rules, policies, or standards governing public officials, public employees, conflicts, gifts, honoraria, travel, sponsored attendance, procurement integrity, revolving-door restrictions, outside activity, use of title, use of resources, and public-sector conduct.

515.28.2 GCRI US shall structure public official interactions to avoid violating Government Ethics requirements.

#### 515.29 “Procurement Integrity.”

515.29.1 “Procurement Integrity” means rules, duties, and controls designed to protect public procurement fairness, confidentiality, competition, impartiality, no improper influence, no unfair advantage, no improper disclosure, and no conflict of interest.

515.29.2 Procurement Integrity shall govern public authority interfaces, provider participation, sponsor references, technical baseline use, and public materials where procurement risk exists.

#### 515.30 “Public Grant.”

515.30.1 “Public Grant” means funding, award, contribution, cooperative support, subaward, public-good support, or other assistance from a public authority or public-sector funder.

515.30.2 Public Grant acceptance shall not create public authority delegation, procurement approval, public finance approval, endorsement, regulatory approval, recognition, certification, provider preference, or public warning authority.

#### 515.31 “Cooperative Agreement.”

515.31.1 “Cooperative Agreement” means a public or private funding, support, research, technical assistance, or program agreement involving substantial coordination or participation by the grantor or counterparty, where lawful.

515.31.2 Cooperative Agreement terms shall not override nonprofit purpose, research integrity, public authority boundaries, finance boundaries, sponsor non-control, provider neutrality, public-safe publication, safeguards, or correctionability unless lawfully required and recorded.

#### 515.32 “Public Authority Reference.”

515.32.1 “Public Authority Reference” means any use of a public authority name, logo, title, quote, attendance reference, photograph, recording, data contribution statement, grant reference, room reference, observer reference, regulator-listening reference, public finance reader reference, emergency-learning reference, or public infrastructure operator reference.

515.32.2 Public Authority References require approval, capacity classification, attribution permission, public-safe review, and non-endorsement language where material.

#### 515.33 Public Authority Definition Records.

515.33.1 The Corporation shall maintain Public Authority Definition Records, including Federal Public Authority records, State Public Authority records, District of Columbia Public Authority records, Territorial Public Authority records, Tribal Government records, Indigenous Government Interface records, Local Public Authority records, Public Infrastructure Operator records, Public Health Authority records, Emergency Management Authority records, Public Safety Authority records, Public Works Authority records, Public Finance Body records, Regulator records, Official Capacity records, Observer Status records, Regulator-Listening Status records, Public Finance Reader Status records, Emergency-Management Participation records, Simulation Participant records, Tabletop Participant records, After-Action Participant records, Public Authority Room records, Public Records records, FOIA records, Sunshine Law records, Open Meetings records, Government Ethics records, Procurement Integrity records, Public Grant records, Cooperative Agreement records, Public Authority Reference records, correction records, and archive records.

***

### Section 516. Community, Tribal / Indigenous, Civil Rights, Accessibility, and Safeguards Definitions

#### 516.1 “Community.”

516.1.1 “Community” means a group of persons, households, organizations, local institutions, rights-bearing groups, place-based groups, cultural groups, Tribal / Indigenous peoples, civil society groups, vulnerable populations, affected populations, or other collective stakeholders connected by geography, identity, risk, infrastructure, experience, knowledge, public authority interface, or shared interest.

516.1.2 Community status shall not be used to erase internal diversity, substitute one voice for all affected persons, bypass consent, or weaken civil rights, accessibility, protected knowledge, or safeguards obligations.

#### 516.2 “Community Safeguards.”

516.2.1 “Community Safeguards” means the policies, procedures, reviews, records, protections, participation pathways, grievance pathways, consent rules, public-safe mapping rules, do-no-harm review, protected knowledge controls, accessibility practices, civil rights controls, and non-retaliation obligations intended to prevent harm to communities.

516.2.2 Community Safeguards shall apply to research, evidence, observability, dashboards, maps, datasets, AI systems, publications, public authority interfaces, protected knowledge, public-good software, technical baselines, and Nexus coordination.

#### 516.3 “Tribal Sovereignty.”

516.3.1 “Tribal Sovereignty” means the inherent sovereignty, self-government, legal authority, and governance dignity of Tribal governments and Tribal peoples, as recognized under applicable law and respected by the Corporation in relevant interfaces.

516.3.2 Tribal Sovereignty requires lawful and respectful engagement, government-to-government awareness where applicable, permission records, consent or non-consent records where applicable, data sovereignty review, protected knowledge controls, public-safe mapping review, and correction pathways.

#### 516.4 “Indigenous Data Safeguards.”

516.4.1 “Indigenous Data Safeguards” means controls governing Indigenous data, Indigenous knowledge, Tribal data, community data, cultural knowledge, ecological knowledge, sacred knowledge, sensitive sites, language materials, and other Indigenous-related materials.

516.4.2 Indigenous Data Safeguards may include consent, non-consent, attribution, non-attribution, withdrawal, restriction, return, deletion, sealing, local stewardship, Indigenous governance review, public-safe mapping review, AI-use limits, transfer limits, and grievance pathways.

#### 516.5 “Indigenous Knowledge.”

516.5.1 “Indigenous Knowledge” means knowledge, practices, observations, traditions, language, cultural expressions, ecological knowledge, place-based knowledge, sacred knowledge, governance knowledge, environmental knowledge, or other knowledge held by Indigenous peoples, communities, governments, or knowledge holders.

516.5.2 Indigenous Knowledge shall not be treated as public data, research material, AI training material, map layer, dashboard content, sponsor asset, provider asset, public authority asset, or transferable technical asset without competent authority and safeguards review.

#### 516.6 “Local Knowledge.”

516.6.1 “Local Knowledge” means place-based knowledge, lived experience, local observations, infrastructure awareness, community history, risk knowledge, environmental knowledge, operational knowledge, or social knowledge held by local persons, institutions, or communities.

516.6.2 Local Knowledge may be protected, restricted, sensitive, or public-safe depending on context and shall be reviewed before publication, mapping, transfer, or AI use.

#### 516.7 “Territorial Knowledge.”

516.7.1 “Territorial Knowledge” means knowledge connected to a territory, island, region, jurisdiction, public authority, community, environment, infrastructure, disaster context, climate context, cultural context, or geographic setting.

516.7.2 Territorial Knowledge shall be reviewed for local law, territorial public authority boundaries, language access, public-safe mapping, environmental sensitivity, cultural sensitivity, disaster vulnerability, and protected knowledge controls.

#### 516.8 “Cultural Knowledge.”

516.8.1 “Cultural Knowledge” means knowledge, practices, expressions, customs, sites, narratives, histories, language, symbols, rituals, or other cultural materials held by communities, Tribal / Indigenous peoples, local groups, or cultural institutions.

516.8.2 Cultural Knowledge may require consent, attribution, restriction, non-attribution, protected knowledge handling, public-safe publication review, and grievance pathways.

#### 516.9 “Environmental Knowledge.”

516.9.1 “Environmental Knowledge” means knowledge concerning ecosystems, nature, climate, water, land, biodiversity, species, habitats, environmental risk, resource systems, local ecology, Earth observation, or environmental stewardship.

516.9.2 Environmental Knowledge shall be reviewed for protected species, sensitive sites, community vulnerability, Tribal / Indigenous knowledge, public-safe mapping, and misuse risks.

#### 516.10 “Protected Knowledge.”

516.10.1 “Protected Knowledge” means knowledge, data, records, materials, observations, maps, locations, narratives, practices, signals, or other information requiring protection due to Tribal / Indigenous, community, local, territorial, cultural, environmental, ecological, sacred, sensitive site, civil rights, privacy, public safety, public authority, or do-no-harm considerations.

516.10.2 Protected Knowledge may be restricted even when technically accessible, publicly observable, previously published, or held by third parties.

#### 516.11 “Community-Protected Materials.”

516.11.1 “Community-Protected Materials” means data, records, documents, observations, maps, images, audio, video, narratives, local knowledge, environmental knowledge, cultural knowledge, or other materials provided by or about communities and subject to safeguards, restriction, consent, attribution, withdrawal, grievance, or do-no-harm controls.

516.11.2 Community-Protected Materials shall not be used for unauthorized AI training, publication, mapping, transfer, finance-facing evidence, provider development, sponsor benefit, or public authority action without appropriate authority.

#### 516.12 “Consent.”

516.12.1 “Consent” means recorded permission by a competent person, participant, data subject, community representative, Tribal / Indigenous authority or knowledge holder where applicable, public authority, or other authorized source for a defined use.

516.12.2 Consent shall identify scope, purpose, duration, conditions, attribution, withdrawal pathway, publication permission, AI-use permission, transfer permission, restrictions, and correction path where applicable.

#### 516.13 “Non-Consent.”

516.13.1 “Non-Consent” means refusal, absence, withdrawal, denial, limitation, or restriction of permission for a proposed use, publication, mapping, AI use, transfer, attribution, or disclosure.

516.13.2 Non-Consent shall be respected unless law expressly permits otherwise and the Corporation has recorded legal authority and safeguards review.

#### 516.14 “Attribution.”

516.14.1 “Attribution” means naming, crediting, identifying, referencing, acknowledging, or otherwise associating a person, community, source, public authority, contributor, knowledge holder, or institution with materials, ideas, data, knowledge, statements, or participation.

516.14.2 Attribution shall be accurate, authorized, context-appropriate, public-safe, and subject to non-attribution, anonymity, confidentiality, protected knowledge, and public authority restrictions.

#### 516.15 “Withdrawal.”

516.15.1 “Withdrawal” means revocation, removal, limitation, or request to stop participation, use, attribution, publication, data processing, mapping, AI use, transfer, or further engagement where permitted by law, consent terms, policy, ethics, or safeguards records.

516.15.2 Withdrawal shall be reviewed and implemented according to legal, technical, archival, record-retention, public-safe, and correction requirements.

#### 516.16 “Restriction.”

516.16.1 “Restriction” means a limitation on access, use, publication, transfer, AI training, embedding, mapping, attribution, disclosure, retention, deletion, archive, derivative use, or public reference.

516.16.2 Restrictions may arise from law, contract, consent, non-consent, public authority terms, community safeguards, Tribal / Indigenous protocols, protected knowledge records, grant terms, license terms, or Board action.

#### 516.17 “Correction Pathway.”

516.17.1 “Correction Pathway” means the process by which a person, community, public authority, reviewer, participant, contributor, knowledge holder, or affected party may request, trigger, or support correction, supersession, withdrawal, retraction, takedown, restriction, archive annotation, or public-safe clarification.

516.17.2 Correction Pathways shall be accessible, non-retaliatory, recorded, and appropriate to the nature of the affected material.

#### 516.18 “Grievance.”

516.18.1 “Grievance” means a complaint, concern, challenge, objection, harm report, safeguards concern, civil rights concern, accessibility concern, protected knowledge concern, community concern, Tribal / Indigenous concern, public-safe mapping concern, or non-retaliation concern.

516.18.2 Grievances shall be received, recorded, reviewed, classified, addressed, corrected, referred, or closed according to policy and risk.

#### 516.19 “Remedy.”

516.19.1 “Remedy” means corrective, restorative, protective, procedural, public-safe, controlled, legal, technical, access, publication, data, repository, grievance, or other action taken to address a violation, harm, risk, or defect.

516.19.2 Remedy may include correction, apology where appropriate, retraction, takedown, restriction, deletion, sealing, access change, policy change, training, role restriction, referral, or other action.

#### 516.20 “Protected Participation.”

516.20.1 “Protected Participation” means good-faith participation in reporting, challenge, correction, grievance, whistleblowing, safeguards review, public authority boundary concern, finance-boundary concern, protected knowledge concern, civil rights concern, accessibility concern, or investigation.

516.20.2 Protected Participation shall be safeguarded against retaliation.

#### 516.21 “Non-Retaliation.”

516.21.1 “Non-Retaliation” means the prohibition on adverse action, intimidation, exclusion, harassment, defamation, access denial, funding threat, work interference, public misstatement, repository retaliation, legal threat made in bad faith, or other penalty against a person or community for Protected Participation.

516.21.2 Non-Retaliation duties survive role end, contract end, dissolution, and wind-up where applicable.

#### 516.22 “Do-No-Harm Review.”

516.22.1 “Do-No-Harm Review” means review intended to identify, prevent, mitigate, or correct foreseeable harm from research, evidence, data use, AI use, observability, dashboards, maps, public-safe publication, public authority reference, technical asset release, protected knowledge handling, or Nexus interface activity.

516.22.2 Do-No-Harm Review may address privacy, civil rights, accessibility, community harm, stigmatization, public authority confusion, public warning confusion, infrastructure exposure, cyber risk, protected knowledge exposure, and misuse.

#### 516.23 “Accessibility.”

516.23.1 “Accessibility” means the design, communication, formatting, publication, participation, event, digital, physical, language, disability, and usability practices that enable persons with disabilities and other access needs to participate in or understand Corporation materials and activities.

516.23.2 Accessibility shall be integrated into public-safe publications, websites, dashboards, maps, meetings, events, training, forms, grievance pathways, and records where applicable.

#### 516.24 “Civil Rights.”

516.24.1 “Civil Rights” means legal and public-benefit protections concerning equality, non-discrimination, accessibility, protected classes, language access, disability access, due process where applicable, privacy, participation, and freedom from unlawful discrimination or retaliation.

516.24.2 Civil Rights review shall apply where Corporation activities may affect persons, communities, public authority interfaces, AI systems, datasets, maps, dashboards, publications, or technical assets.

#### 516.25 “Non-Discrimination.”

516.25.1 “Non-Discrimination” means the prohibition against unlawful discrimination, exclusion, denial of benefit, harassment, retaliation, or unequal treatment based on protected characteristics, disability, language, community status, or other protected status under applicable law or policy.

516.25.2 Non-Discrimination shall guide participation, employment, access, publication, AI governance, public-safe mapping, and safeguards.

#### 516.26 “Vulnerable Community.”

516.26.1 “Vulnerable Community” means a community facing heightened exposure, sensitivity, marginalization, risk, limited resources, legal vulnerability, health vulnerability, climate vulnerability, infrastructure vulnerability, digital vulnerability, language access barriers, disability access barriers, public safety risk, or other conditions requiring safeguards.

516.26.2 Vulnerable Community status shall not be used to stigmatize, rank, label, expose, or disadvantage a community.

#### 516.27 “Remote Community.”

516.27.1 “Remote Community” means a community with geographic, infrastructure, communications, transportation, service access, climate, disaster, language, cultural, or institutional remoteness affecting participation, observability, public authority access, technical support, or public-safe communication.

516.27.2 Remote Community engagement shall consider accessibility, local knowledge, connectivity, public-safe mapping, infrastructure sensitivity, and safeguards.

#### 516.28 “Public-Safe Mapping.”

516.28.1 “Public-Safe Mapping” means mapping, geospatial publication, dashboard visualization, layer release, digital twin display, hotspot display, Earth observation output, infrastructure visualization, or community map publication designed to reduce harm, avoid overdisclosure, protect sensitive locations, preserve public authority boundaries, prevent public warning confusion, and protect communities and protected knowledge.

516.28.2 Public-Safe Mapping shall not be treated as public warning, emergency command, public authority decision, certification, finance-readiness, rating, recognition, procurement approval, or provider preference.

#### 516.29 Safeguards Definition Records.

516.29.1 The Corporation shall maintain Safeguards Definition Records, including Community records, Community Safeguards records, Tribal Sovereignty records, Indigenous Data Safeguards records, Indigenous Knowledge records, Local Knowledge records, Territorial Knowledge records, Cultural Knowledge records, Environmental Knowledge records, Protected Knowledge records, Community-Protected Materials records, Consent records, Non-Consent records, Attribution records, Withdrawal records, Restriction records, Correction Pathway records, Grievance records, Remedy records, Protected Participation records, Non-Retaliation records, Do-No-Harm Review records, Accessibility records, Civil Rights records, Non-Discrimination records, Vulnerable Community records, Remote Community records, Public-Safe Mapping records, correction records, and archive records.

***

### Section 517. Finance, Capital, Insurance, Public Finance, and GRA Boundary Definitions

#### 517.1 “Finance-Readiness.”

517.1.1 “Finance-Readiness” means a GRA-stewarded or otherwise competent finance-interface status, record, determination, or structured indication that specified materials, projects, systems, portfolios, or proof packs have been prepared for finance-facing diligence within a defined scope.

517.1.2 Finance-Readiness is not determined by GCRI US. GCRI US may provide technical evidence, methods, observability records, technical baselines, public-good software, and correction signals as inputs, but such inputs do not create Finance-Readiness.

517.1.3 Finance-Readiness shall not be represented as investment advice, securities offering, credit approval, insurance approval, rating, public finance approval, guarantee, procurement approval, certification, recognition, or public authority approval.

#### 517.2 “Capital Readability.”

517.2.1 “Capital Readability” means the structured ability of public-good, project, infrastructure, resilience, technical, evidence, risk, governance, or proof-pack materials to be read by capital-facing, diligence-facing, insurance-facing, lending-facing, public finance-facing, or finance-literacy audiences within a GRA or competent finance-boundary framework.

517.2.2 Capital Readability does not mean investability, bankability, insurability, creditworthiness, public finance approval, investment suitability, rating, guarantee, or capital commitment.

#### 517.3 “Proof Pack.”

517.3.1 “Proof Pack” means a structured collection of evidence, records, methods, technical materials, governance records, public authority records, risk records, safeguards records, data records, technical asset records, finance-boundary records, and limitations prepared for diligence translation or finance-facing review within an authorized framework.

517.3.2 A Proof Pack may include GCRI US technical inputs, but the existence of a Proof Pack shall not create finance-readiness, investment advice, certification, recognition, procurement approval, rating, public finance approval, public authority approval, public warning, or emergency command.

#### 517.4 “Insurance-Readiness.”

517.4.1 “Insurance-Readiness” means a GRA-stewarded or otherwise competent insurance-interface status, record, or structured indication that specified materials may be organized for insurance-facing diligence within a defined scope.

517.4.2 Insurance-Readiness is not insurance placement, underwriting, pricing, binding, claims handling, rating, insurability determination, or insurance approval.

517.4.3 GCRI US does not determine Insurance-Readiness by providing evidence, methods, observability records, dashboards, maps, proof receipts, technical baselines, or public-good software.

#### 517.5 “Diligence Translation.”

517.5.1 “Diligence Translation” means the structured translation of technical evidence, methods, public-good records, risk records, governance records, safeguards records, and public authority learning materials into formats intelligible to finance, capital, insurance, public finance, grant, or diligence readers.

517.5.2 Diligence Translation shall not alter evidence, suppress limitations, overstate confidence, create ratings, provide investment advice, certify projects, determine finance-readiness, or imply public authority approval.

#### 517.6 “Capital-Reader Room.”

517.6.1 “Capital-Reader Room” means a controlled room, data room, evidence room, no-download room, or other restricted environment in which capital readers, public finance readers, insurers, lenders, grantors, diligence readers, or related participants may review authorized materials under defined conditions.

517.6.2 Capital-Reader Rooms shall be governed by room charter, confidentiality, access controls, finance-boundary controls, public authority boundary controls, competition controls, data / AI / cyber / privacy controls, protected knowledge controls, non-reliance language, and no-solicitation rules.

517.6.3 Capital-Reader Room participation shall not create investment advice, securities solicitation, finance-readiness, insurance-readiness, public finance approval, rating, procurement approval, certification, recognition, or capital commitment by GCRI US.

#### 517.7 “Capital Reader.”

517.7.1 “Capital Reader” means a person or entity reviewing materials for finance literacy, diligence understanding, capital-readability, insurance-readiness, lending awareness, grant awareness, public finance awareness, or investment context.

517.7.2 Capital Reader status shall not create investor status, securities solicitation, investment advice, lending commitment, insurance placement, rating, finance-readiness, or public finance approval.

#### 517.8 “Investor.”

517.8.1 “Investor” means a person or entity that invests or may invest capital in securities, companies, projects, funds, SPVs, infrastructure, assets, or other investment opportunities.

517.8.2 Investor participation in a Corporation activity shall not convert the activity into securities solicitation, investment advice, finance-readiness, rating, or capital raising by GCRI US.

#### 517.9 “Insurer.”

517.9.1 “Insurer” means a regulated or authorized entity that underwrites, issues, prices, binds, or administers insurance or risk-transfer products.

517.9.2 Insurer participation in a Corporation activity shall not create insurance placement, underwriting, pricing, binding, claims handling, insurance-readiness, rating, or insurability determination by GCRI US.

#### 517.10 “Reinsurer.”

517.10.1 “Reinsurer” means an entity that provides reinsurance or risk transfer to insurers or other risk-bearing entities.

517.10.2 Reinsurer participation shall be governed by finance-boundary, insurance-boundary, confidentiality, and non-reliance controls.

#### 517.11 “Lender.”

517.11.1 “Lender” means a bank, credit institution, fund, public finance body, development finance institution, private lender, or other person or entity that extends or may extend credit.

517.11.2 Lender participation shall not create lending, credit approval, guarantee, finance-readiness, public finance approval, or investment advice by GCRI US.

#### 517.12 “Underwriter.”

517.12.1 “Underwriter” means a person or entity that evaluates, prices, assumes, distributes, places, guarantees, or commits risk, securities, loans, insurance, public finance, or other financial exposure.

517.12.2 Underwriter participation shall not make GCRI US an underwriter or create underwriting by GCRI US.

#### 517.13 “Bank.”

517.13.1 “Bank” means a regulated bank, financial institution, public bank, development bank, credit institution, or banking-related entity.

517.13.2 Bank participation in a Corporation activity shall not create banking, lending, credit approval, deposit-taking, finance-readiness, or public finance approval by GCRI US.

#### 517.14 “Public Finance Actor.”

517.14.1 “Public Finance Actor” means a public finance body, treasury, budget office, grant body, public bank, development finance body, public credit body, guarantee authority, tax credit authority, bond authority, MDB, DFI, or similar actor involved in public finance.

517.14.2 Public Finance Actor participation shall not create public finance approval, appropriation, grant approval, budget allocation, public guarantee, public credit, sovereign obligation, capital commitment, or finance-readiness by GCRI US.

#### 517.15 “MDB / DFI.”

517.15.1 “MDB / DFI” means a multilateral development bank, development finance institution, public development bank, international financial institution, or similar public or quasi-public development finance body.

517.15.2 MDB / DFI participation, observation, review, or receipt of materials shall not create approval, financing, guarantee, public finance approval, sovereign obligation, investment advice, rating, or finance-readiness by GCRI US.

#### 517.16 “Public Guarantee.”

517.16.1 “Public Guarantee” means a guarantee, assurance, credit support, risk support, repayment support, sovereign guarantee, public credit enhancement, or similar obligation issued or backed by a public authority or public finance actor.

517.16.2 GCRI US does not issue Public Guarantees and shall not imply that its evidence, methods, proof packs, dashboards, maps, or technical baselines create a Public Guarantee.

#### 517.17 “Public Credit.”

517.17.1 “Public Credit” means credit, credit support, financing, guarantee, loan, bond support, grant-related financing, public finance instrument, or credit enhancement provided by or through a public authority or public finance actor.

517.17.2 GCRI US does not approve, issue, arrange, guarantee, or determine Public Credit.

#### 517.18 “Sovereign Obligation.”

517.18.1 “Sovereign Obligation” means a binding obligation, guarantee, debt, treaty commitment, public finance obligation, budget obligation, sovereign commitment, or other legally binding act of a sovereign or public authority.

517.18.2 No Corporation material, public authority participation, Nexus interface, public finance reader room, proof pack, or evidence output shall imply a Sovereign Obligation without competent sovereign authority.

#### 517.19 “Investment Suitability.”

517.19.1 “Investment Suitability” means a determination or recommendation that an investment is suitable for a person, entity, portfolio, mandate, fund, investor, lender, insurer, or capital actor.

517.19.2 GCRI US does not determine Investment Suitability.

#### 517.20 “Bankability.”

517.20.1 “Bankability” means a finance-facing view that a project, entity, asset, or opportunity may satisfy lender or finance requirements.

517.20.2 Bankability is not determined by GCRI US. Technical evidence, public-good records, resilience indicators, proof receipts, or public-safe publications shall not be represented as Bankability.

#### 517.21 “Insurability.”

517.21.1 “Insurability” means an insurance-facing view that a risk, project, asset, system, entity, or activity may be suitable for insurance, reinsurance, underwriting, pricing, or risk transfer.

517.21.2 GCRI US does not determine Insurability and does not underwrite, place, bind, price, sell, or approve insurance.

#### 517.22 “Rating.”

517.22.1 “Rating,” for purposes of finance and capital boundaries, means a credit rating, resilience rating, insurability rating, bankability rating, financeability rating, investment grade opinion, provider rating, public finance rating, or similar evaluative grade, score, opinion, or rank used for finance, insurance, lending, investment, public finance, or procurement decisions.

517.22.2 GCRI US does not issue finance Ratings. Any technical classification by GCRI US shall be clearly distinguished from a finance, credit, insurance, public finance, procurement, recognition, certification, or public authority rating.

#### 517.23 “Credit Opinion.”

517.23.1 “Credit Opinion” means an opinion regarding creditworthiness, repayment capacity, default risk, debt quality, bond quality, issuer quality, project credit, public credit, or similar credit matters.

517.23.2 GCRI US does not provide Credit Opinions.

#### 517.24 “Securities Offering.”

517.24.1 “Securities Offering” means an offer, sale, subscription, placement, issuance, marketing, promotion, or distribution of securities or investment interests.

517.24.2 GCRI US shall not conduct Securities Offerings. Its public-good records, evidence packs, proof packs, Nexus materials, and technical outputs shall not be used as offering materials by or for GCRI US.

#### 517.25 “Securities Solicitation.”

517.25.1 “Securities Solicitation” means solicitation, recommendation, introduction, marketing, promotion, communication, or activity intended to induce investment in securities or investment interests.

517.25.2 GCRI US shall not engage in Securities Solicitation and shall structure capital-reader interfaces to avoid solicitation meaning.

#### 517.26 “Brokerage.”

517.26.1 “Brokerage” means broker, dealer, placement, transaction facilitation, securities intermediation, investment intermediation, or similar regulated activity.

517.26.2 GCRI US does not conduct Brokerage.

#### 517.27 “Placement.”

517.27.1 “Placement” means arranging, facilitating, soliciting, intermediating, or supporting placement of securities, investment interests, loans, insurance, or capital commitments.

517.27.2 GCRI US does not conduct Placement.

#### 517.28 “Finder.”

517.28.1 “Finder” means a person or entity that introduces, refers, or connects parties for investment, securities, lending, insurance, capital, acquisition, or transaction purposes in a manner that may create regulated activity or transaction-based compensation.

517.28.2 GCRI US shall not act as a Finder.

#### 517.29 “Guarantee.”

517.29.1 “Guarantee” means a promise, assurance, support, indemnity, credit support, repayment support, performance support, risk support, or other commitment to answer for the debt, performance, risk, or obligation of another.

517.29.2 GCRI US does not issue Guarantees through evidence, methods, proof receipts, dashboards, maps, publications, technical baselines, public authority learning, or Nexus coordination.

#### 517.30 “Public Finance Approval.”

517.30.1 “Public Finance Approval” means approval, allocation, appropriation, authorization, grant award, public credit approval, tax credit approval, public guarantee, MDB / DFI approval, public financing commitment, sovereign obligation, or similar public finance decision.

517.30.2 GCRI US does not provide Public Finance Approval, and public finance reader participation does not create Public Finance Approval.

#### 517.31 “GRA Boundary.”

517.31.1 “GRA Boundary” means the role-separation boundary preserving The Global Risks Alliance (GRA) as the appropriate Nexus steward for finance-readiness, capital-readability, insurance-readiness, proof packs, diligence translation, RNFD, NFD, UNFSD, capital-reader room discipline, and regulated-perimeter finance discipline, while preserving GCRI US as a non-executing public-good technical evidence and methods institution.

517.31.2 GRA Boundary controls shall prevent GCRI US from being represented as making finance-readiness determinations, capital-readability determinations, insurance-readiness determinations, investment recommendations, lending decisions, insurance placements, ratings, public finance approvals, securities solicitations, broker-dealer actions, underwriting actions, or capital execution decisions.

#### 517.32 Finance and Capital Definition Records.

517.32.1 The Corporation shall maintain Finance and Capital Definition Records, including Finance-Readiness records, Capital Readability records, Proof Pack records, Insurance-Readiness records, Diligence Translation records, Capital-Reader Room records, Capital Reader records, Investor records, Insurer records, Reinsurer records, Lender records, Underwriter records, Bank records, Public Finance Actor records, MDB / DFI records, Public Guarantee records, Public Credit records, Sovereign Obligation records, Investment Suitability records, Bankability records, Insurability records, Rating records, Credit Opinion records, Securities Offering records, Securities Solicitation records, Brokerage records, Placement records, Finder records, Guarantee records, Public Finance Approval records, GRA Boundary records, correction records, public-safe limitation records, non-reliance records, and archive records.

### Section 518. GRF, Recognition, Registry, Maturity, Claims Discipline, and Public Legitimacy Definitions

#### 518.1 “Registry.”

518.1.1 “Registry” means a structured, record-based, governed list, register, ledger, catalogue, docket, maturity record, standing record, recognition record, public-good record, or other organized record system maintained by a competent authority for defined institutional, public-good, recognition, maturity, public-facing legitimacy, claims-discipline, stakeholder-formation, or Nexus coordination purposes.

518.1.2 A Registry may identify entities, projects, technical assets, public-good outputs, evidence packages, maturity records, standing records, public-safe summaries, Docket entries, Grid records, or other items within a defined scope.

518.1.3 Registry inclusion shall not by itself create certification, procurement approval, public authority adoption, finance-readiness, insurance-readiness, investment suitability, rating, public warning, emergency command, legal compliance approval, provider preference, or enterprise execution authority.

518.1.4 A Registry has only the meaning assigned by the competent authority maintaining it and the Authoritative Records supporting the relevant entry.

#### 518.2 “Recognition.”

518.2.1 “Recognition” means a formal, record-based acknowledgment, public-good standing, public-facing legitimacy status, maturity acknowledgment, stakeholder formation status, registry status, or other recognition-related determination made by the competent recognition authority within a defined scope.

518.2.2 Recognition is a GRF-related function unless another competent authority is expressly and lawfully assigned recognition responsibility by Authoritative Record.

518.2.3 GCRI US does not create Recognition by issuing evidence, methods, proof receipts, public-good software, technical baselines, dashboards, maps, public-safe summaries, public authority learning materials, Nexus interface inputs, Docket inputs, Grid inputs, or technical records.

518.2.4 Recognition shall not be represented as certification, accreditation, procurement approval, public authority approval, finance-readiness, insurance-readiness, rating, investment suitability, legal compliance approval, public warning, emergency command, or provider preference.

#### 518.3 “Public-Facing Legitimacy.”

518.3.1 “Public-Facing Legitimacy” means a record-based public-good status, public-safe acknowledgment, registry posture, recognition posture, maturity posture, standing posture, or claims-disciplined public representation that enables external audiences to understand the status, role, limitations, and public-good meaning of an entity, project, initiative, record, technical asset, or Nexus interface.

518.3.2 Public-Facing Legitimacy shall be grounded in Authoritative Records, controlled vocabulary, public-safe language, claims substantiation, boundary discipline, and correctionability.

518.3.3 Public-Facing Legitimacy shall not imply public authority endorsement, public authority adoption, certification, procurement approval, finance-readiness, insurance-readiness, rating, investment suitability, public warning, emergency command, or legal compliance approval unless competent external authority separately provides such meaning.

#### 518.4 “Standing.”

518.4.1 “Standing” means a record-based status, posture, eligibility, maturity position, registry position, recognition position, or public-good position assigned within a defined framework by the competent authority.

518.4.2 Standing may be public, public-safe, controlled, provisional, conditional, suspended, superseded, withdrawn, archived, or otherwise classified according to the applicable records.

518.4.3 GCRI US may provide technical evidence, methods, observability records, public-good technical assets, or correction signals that inform Standing, but GCRI US does not assign GRF Standing by default.

518.4.4 Standing shall not be represented as certification, procurement approval, finance-readiness, public authority approval, rating, guarantee, or operational authority.

#### 518.5 “Maturity Record.”

518.5.1 “Maturity Record” means an Authoritative Record documenting a maturity-related status, assessment, stage, level, condition, posture, progression, limitation, dependency, review date, scope, evidence basis, responsible authority, and correction path.

518.5.2 A Maturity Record may concern institutional maturity, project maturity, technical asset maturity, governance maturity, evidence maturity, safeguards maturity, public authority interface maturity, public-safe publication maturity, or Nexus interface maturity.

518.5.3 A Maturity Record shall be interpreted only within its defined scope and shall not be treated as certification, legal compliance approval, procurement approval, finance-readiness, insurance-readiness, rating, public authority approval, or public warning.

#### 518.6 “Claims Discipline.”

518.6.1 “Claims Discipline” means the governance discipline requiring public claims, technical claims, recognition claims, maturity claims, standing claims, finance-boundary claims, public authority references, certification-boundary references, procurement-boundary references, Nexus-compatible claims, Docket references, Grid references, sponsor references, provider references, and public-safe summaries to be accurate, records-based, controlled-vocabulary-compliant, limitation-aware, and correctionable.

518.6.2 Claims Discipline includes substantiation, source lineage, authority review, public-safe review, conflict review, sponsor and provider independence review, public authority boundary review, finance-boundary review, certification and recognition boundary review, safeguards review, protected knowledge review, and correction pathway.

518.6.3 Claims Discipline shall apply equally to formal publications, decks, websites, repositories, social media, dashboards, maps, datasets, grant applications, sponsor materials, public authority materials, media statements, archive statements, and informal materials likely to create public meaning.

#### 518.7 “Stakeholder Formation.”

518.7.1 “Stakeholder Formation” means the structured identification, convening, classification, orientation, role clarification, boundary setting, safeguards review, and records-based participation of stakeholders within GRF, GCRI US, GRA, Nexus, public authority, community, technical, public-good, finance-boundary, or enterprise-interface contexts.

518.7.2 Stakeholder Formation may include public authorities, communities, Tribal / Indigenous bodies, universities, laboratories, civil society, sponsors, donors, funders, providers, hosts, enterprise actors, national companies, Project SPVs, capital readers, insurers, lenders, public finance readers, media, and other participants.

518.7.3 Stakeholder Formation shall not create endorsement, membership, governance authority, public authority approval, finance-readiness, certification, recognition, procurement approval, provider preference, or enterprise execution authority unless competent records expressly provide such status.

#### 518.8 “Public-Safe Reporting.”

518.8.1 “Public-Safe Reporting” means reporting designed to inform public, stakeholder, public authority, community, technical, or Nexus audiences while protecting privacy, cybersecurity, infrastructure sensitivity, public authority confidentiality, protected knowledge, civil rights, accessibility, community safety, public safety, legal obligations, and public-good role separation.

518.8.2 Public-Safe Reporting may include public-safe summaries, public reports, dashboards, maps, datasets, archive statements, technical notes, recognition summaries, maturity summaries, public legitimacy statements, public authority learning materials, and public-good technical asset notices.

518.8.3 Public-Safe Reporting is not public warning, emergency command, public authority decision, finance-readiness, certification, procurement approval, recognition by GCRI US, rating, legal advice, investment advice, insurance advice, or professional advice.

#### 518.9 “GRF Record.”

518.9.1 “GRF Record” means an Authoritative Record created, maintained, approved, or recognized by The Global Risks Forum (GRF) within its governing authority.

518.9.2 GRF Records may include registry records, recognition records, maturity records, standing records, claims-discipline records, stakeholder-formation records, public-safe reporting records, correction records, suspension records, withdrawal records, archive records, and public legitimacy records.

518.9.3 A GRF Record shall not be created by GCRI US unless GRF has lawfully delegated or accepted a defined record input, and such input shall not itself become a GRF Record until accepted or recognized by GRF according to its rules.

#### 518.10 “GRF Recognition Record.”

518.10.1 “GRF Recognition Record” means a GRF Record documenting Recognition, including scope, subject, authority, evidence basis, maturity relationship where applicable, standing relationship where applicable, conditions, limitations, effective date, review cycle, public-safe status, correction path, suspension path, withdrawal path, and archive status.

518.10.2 A GRF Recognition Record shall be interpreted only within its stated scope and shall not create finance-readiness, certification, procurement approval, public authority adoption, rating, public warning, emergency command, or provider preference.

#### 518.11 “GRF Maturity Record.”

518.11.1 “GRF Maturity Record” means a GRF Record documenting maturity status, maturity stage, maturity evidence, maturity limitations, maturity conditions, maturity review, maturity correction path, or maturity public summary.

518.11.2 A GRF Maturity Record may rely on GCRI US technical evidence or methods inputs where accepted by GRF, but GCRI US does not issue the GRF Maturity Record unless expressly authorized by GRF.

#### 518.12 “GRF Public Summary.”

518.12.1 “GRF Public Summary” means a public-safe summary issued or authorized by GRF concerning registry status, recognition, maturity, standing, claims discipline, stakeholder formation, public-facing legitimacy, or related public-good status.

518.12.2 A GRF Public Summary shall be public-safe, limitation-aware, records-based, and controlled-vocabulary-compliant.

518.12.3 A GRF Public Summary shall not be represented as finance-readiness, certification, procurement approval, public authority approval, rating, public warning, emergency command, or legal compliance approval.

#### 518.13 “Docket Entry.”

518.13.1 “Docket Entry” means a record, case entry, intake entry, routing entry, evidence entry, issue entry, technical input, public authority interface entry, maturity-related entry, Grid-related entry, or Nexus coordination entry in a competent Docket.

518.13.2 Docket Entry status shall be limited to the Docket’s stated purpose and shall not by itself create approval, recognition, finance-readiness, certification, procurement approval, public authority approval, provider preference, public warning, or emergency command.

518.13.3 GCRI US may create or provide technical inputs to a Docket Entry where authorized, but such input remains subject to the Docket authority’s rules.

#### 518.14 “Grid Record.”

518.14.1 “Grid Record” means an Authoritative Record maintained by a competent Nexus Grid or related authority concerning routing, maturity, eligibility, standing, interface status, coordination status, or other Grid-related matter.

518.14.2 Grid Records shall be interpreted according to scope, authority, status, conditions, limitations, correction path, and effective date.

518.14.3 GCRI US technical evidence or methods may support a Grid Record only as an input and shall not itself create Grid authority.

#### 518.15 “Grid Maturity.”

518.15.1 “Grid Maturity” means maturity-related status or classification within a competent Nexus Grid framework.

518.15.2 Grid Maturity is not issued by GCRI US by default and shall not be inferred from GCRI US evidence, methods, technical baselines, public-good software, observability outputs, dashboards, maps, proof receipts, public authority learning, or Nexus interface inputs.

518.15.3 Grid Maturity shall not be treated as certification, finance-readiness, procurement approval, public authority approval, rating, recognition by GCRI US, or public warning.

#### 518.16 “Recognition Claim.”

518.16.1 “Recognition Claim” means any claim that an entity, project, technical asset, record, organization, public-good output, provider, interface, initiative, or person has been recognized, acknowledged, accepted, listed, validated for legitimacy, granted standing, or given public-facing legitimacy by GRF or another recognition authority.

518.16.2 Recognition Claims require competent recognition records, scope, effective date, limitations, public-safe language, and correction path.

518.16.3 Recognition Claims shall not be made by or for GCRI US without confirming the competent recognition record and proper authority.

#### 518.17 “Maturity Claim.”

518.17.1 “Maturity Claim” means any claim concerning maturity stage, maturity level, maturity status, development stage, readiness stage, governance maturity, evidence maturity, technical maturity, implementation maturity, safeguards maturity, public authority interface maturity, or Nexus maturity.

518.17.2 Maturity Claims require record support, scope, authority, methodology or framework, limitations, effective date, and correction path.

518.17.3 A Maturity Claim shall not be used as finance-readiness, certification, procurement approval, public authority approval, rating, recognition, or provider preference unless the competent authority expressly provides such meaning.

#### 518.18 “Standing Claim.”

518.18.1 “Standing Claim” means any claim that a person, entity, project, technical asset, initiative, public-good output, or Nexus interface has standing within a registry, recognition framework, maturity framework, public-good framework, or Nexus coordination framework.

518.18.2 Standing Claims require competent records and shall be limited by scope, authority, conditions, limitations, and effective date.

#### 518.19 “Public Legitimacy Claim.”

518.19.1 “Public Legitimacy Claim” means any public-facing statement that an entity, project, technical asset, public-good output, stakeholder formation, registry entry, maturity posture, recognition status, or Nexus interface has legitimacy, public-good status, institutional standing, or public-facing acceptance.

518.19.2 Public Legitimacy Claims shall be grounded in GRF Records or other competent records and shall be reviewed for public-safe framing, claims discipline, role separation, sponsor non-control, provider neutrality, public authority boundaries, finance boundaries, certification boundaries, and correctionability.

#### 518.20 “GRF Boundary.”

518.20.1 “GRF Boundary” means the role-separation boundary preserving The Global Risks Forum (GRF) as the public-good registry, recognition, maturity-records, standing, claims-discipline, stakeholder-formation, public-safe reporting, and public-facing legitimacy steward within the Nexus public-good stack, while preserving GCRI US as a non-executing public-good technical evidence, methods, observability, ontology, technical truth, public-good software, and open technical baseline institution.

518.20.2 The GRF Boundary prevents GCRI US from being represented as issuing GRF Recognition, GRF Standing, GRF Maturity, public-facing legitimacy determinations, registry status, claims-discipline determinations, or stakeholder-formation determinations unless expressly and lawfully authorized by competent GRF record.

518.20.3 The GRF Boundary also prevents GRF records from being represented as finance-readiness, certification, procurement approval, public authority adoption, public warning, emergency command, investment advice, rating, or technical guarantee.

#### 518.21 GRF and Public Legitimacy Definition Records.

518.21.1 The Corporation shall maintain GRF and Public Legitimacy Definition Records, including Registry records, Recognition records, Public-Facing Legitimacy records, Standing records, Maturity Record definitions, Claims Discipline records, Stakeholder Formation records, Public-Safe Reporting records, GRF Record definitions, GRF Recognition Record definitions, GRF Maturity Record definitions, GRF Public Summary records, Docket Entry records, Grid Record records, Grid Maturity records, Recognition Claim records, Maturity Claim records, Standing Claim records, Public Legitimacy Claim records, GRF Boundary records, correction records, controlled vocabulary records, public-safe limitation records, and archive records.

***

### Section 519. Nexus Coordination, Federation, and Interoperability Definitions

#### 519.1 “Nexus Coordination.”

519.1.1 “Nexus Coordination” means records-based coordination among GCRI US, GCRI Canada, other GCRI entities, GRF, GRA, Nexus Network, Nexus Standards, protocol authorities, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, public authorities, universities, laboratories, communities, sponsors, providers, hosts, national companies, Project SPVs, capital readers, civil society, and other lawful participants.

519.1.2 Nexus Coordination may involve evidence flows, methods support, observability methods, ontology alignment, public-good software, open technical baselines, public authority learning, public-safe publication, technical asset sharing, shared records, shared rooms, Docket routing, Grid inputs, correction signals, safeguards, and interoperability.

519.1.3 Nexus Coordination does not create merger, agency, partnership, joint venture, shared liability, public authority delegation, finance-readiness, recognition, certification, procurement approval, provider preference, public warning, emergency command, or enterprise execution unless competent records expressly provide otherwise.

#### 519.2 “Federation.”

519.2.1 “Federation” means a structured relationship among legally separate persons, institutions, systems, repositories, records, authorities, technical assets, or interfaces that enables coordination, interoperability, shared rules, shared records, shared technical assets, or aligned action without merging legal identity or collapsing roles.

519.2.2 Federation preserves separateness, local authority, role boundaries, jurisdictional constraints, access controls, data controls, public authority boundaries, finance boundaries, safeguards, and correctionability.

519.2.3 Federation shall not be interpreted as agency, partnership, joint venture, public authority delegation, shared liability, common control, procurement approval, finance-readiness, certification, recognition, or authority to bind another federated participant.

#### 519.3 “Interoperability.”

519.3.1 “Interoperability” means the ability of systems, records, datasets, schemas, APIs, SDKs, repositories, technical assets, methods, institutions, public authority interfaces, and Nexus interfaces to exchange, understand, validate, or use information or functionality within defined standards, profiles, permissions, and limitations.

519.3.2 Interoperability may be technical, semantic, legal, organizational, procedural, operational, public-safe, or records-based.

519.3.3 Interoperability shall not be represented as certification, Nexus-compatible status, procurement approval, public authority adoption, finance-readiness, recognition, rating, public warning, emergency command, or legal compliance approval without competent authority.

#### 519.4 “Interface.”

519.4.1 “Interface” means a structured relationship, connection, handoff, protocol, access point, data exchange, public authority contact, technical connection, governance connection, room, repository, publication, shared record, shared asset, or other point of interaction between persons, institutions, systems, or records.

519.4.2 Interfaces shall be governed by scope, authority, access, classification, records, data controls, security, public authority boundaries, finance boundaries, protected knowledge controls, public-safe publication controls, and correction paths.

#### 519.5 “Interface Agreement.”

519.5.1 “Interface Agreement” means a written, electronic, or otherwise recorded agreement governing an Interface, including scope, roles, authority, access, records, confidentiality, data controls, AI-use restrictions, security, IP, public authority boundaries, finance boundaries, publication, correction, termination, and dispute handling.

519.5.2 Interface Agreements shall preserve legal separateness and shall not create agency, partnership, joint venture, public authority delegation, finance-readiness, certification, recognition, procurement approval, or enterprise execution unless expressly and lawfully stated.

#### 519.6 “Memorandum of Understanding.”

519.6.1 “Memorandum of Understanding” or “MoU” means a written instrument describing non-binding or binding understandings, roles, coordination principles, interfaces, public-good purposes, records, confidentiality, support, limitations, and boundaries between the Corporation and another person or entity.

519.6.2 An MoU shall be interpreted according to its text and authority records and shall not create legal obligations, agency, partnership, joint venture, public authority delegation, finance-readiness, recognition, certification, procurement approval, public warning, or emergency command unless expressly and lawfully provided.

#### 519.7 “Shared Record.”

519.7.1 “Shared Record” means a record created, maintained, accessed, relied upon, or synchronized by more than one authorized person, institution, repository, system, Nexus interface, public authority interface, or controlled room.

519.7.2 Shared Records shall identify owner, custodian, authority, access class, classification, source lineage, version, public-safe status, correction path, retention class, and participating institutions.

519.7.3 Shared Record status does not create shared liability, merger, agency, public authority approval, finance-readiness, recognition, certification, or procurement approval.

#### 519.8 “Shared Repository.”

519.8.1 “Shared Repository” means a repository used, accessed, maintained, or governed by more than one authorized person, institution, Nexus interface, public authority interface, or technical asset steward.

519.8.2 Shared Repositories shall be governed by access controls, repository ownership, repository custody, branch protection, review rules, security, logging, data controls, protected knowledge controls, release controls, and correction paths.

#### 519.9 “Shared Room.”

519.9.1 “Shared Room” means a controlled room, data room, clean room, evidence room, public authority room, no-download room, capital-reader room, regulator-listening room, emergency learning room, or other restricted environment involving more than one institution, role, or participant class.

519.9.2 Shared Rooms shall require a room charter, access criteria, capacity classification, confidentiality terms, data / AI / cyber / privacy controls, public authority boundary controls, finance-boundary controls, competition controls, safeguards controls, protected knowledge controls, public-safe publication controls, logging, and closeout.

#### 519.10 “Shared Publication.”

519.10.1 “Shared Publication” means a report, summary, technical note, public-safe publication, dashboard, map, dataset, software notice, technical baseline, whitepaper, deck, article, media statement, public authority learning material, or other output jointly authored, co-branded, jointly approved, cross-referenced, or issued by more than one person or institution.

519.10.2 Shared Publications shall define authorship, approval authority, name use, public authority references, sponsor references, provider references, data rights, IP rights, confidentiality, public-safe status, correction path, and role-separation language.

#### 519.11 “Shared Technical Asset.”

519.11.1 “Shared Technical Asset” means a technical asset developed, maintained, used, licensed, transferred, accessed, or stewarded by more than one authorized institution, repository, contributor, or Nexus interface.

519.11.2 Shared Technical Assets shall be governed by ownership, license, contributor terms, repository control, security, vulnerability handling, dependency management, data controls, public-safe release, anti-enclosure protections, and correctionability.

#### 519.12 “Routing.”

519.12.1 “Routing” means the records-based movement, referral, classification, assignment, escalation, handoff, or interface direction of a case, record, issue, evidence package, Docket entry, Grid input, public authority matter, finance-boundary matter, safeguards matter, technical asset matter, incident, or correction matter.

519.12.2 Routing shall not create approval, recognition, finance-readiness, certification, procurement approval, public authority decision, provider preference, public warning, or emergency command unless competent authority separately provides such meaning.

#### 519.13 “Case ID.”

519.13.1 “Case ID” means a unique identifier assigned to a case, matter, issue, challenge, incident, correction, Docket entry, Grid record, public authority interface, controlled-room matter, research matter, evidence matter, technical asset matter, or enforcement matter.

519.13.2 Case IDs support traceability, custody, auditability, routing, correctionability, and records management.

#### 519.14 “Mismatch.”

519.14.1 “Mismatch” means an inconsistency, conflict, divergence, error, ambiguity, misalignment, unsupported claim, authority gap, record gap, data gap, version conflict, public authority confusion, finance-boundary conflict, recognition-boundary conflict, certification-boundary conflict, or safeguards conflict between records, systems, institutions, terms, outputs, or interfaces.

519.14.2 Mismatches shall be classified, triaged, reconciled, corrected, superseded, restricted, or escalated as appropriate.

#### 519.15 “Reconciliation.”

519.15.1 “Reconciliation” means the process of reviewing, comparing, aligning, correcting, or documenting differences among records, claims, datasets, methods, technical assets, public authority references, finance-boundary statements, recognition records, certification references, Nexus interfaces, or institutional positions.

519.15.2 Reconciliation may result in correction, supersession, withdrawal, retraction, takedown, divergence log, equivalence note, compatibility note, localization note, or no-change decision.

#### 519.16 “Cure.”

519.16.1 “Cure” means action taken to remedy a defect, violation, mismatch, missing record, defective authority, public-safe problem, technical defect, data defect, publication defect, boundary violation, safeguards issue, or governance failure.

519.16.2 Cure may include record creation where lawful, ratification where lawful, correction, supersession, withdrawal, retraction, takedown, access restriction, notice, training, policy update, contract remedy, technical fix, or referral.

#### 519.17 “Joint Incident Review.”

519.17.1 “Joint Incident Review” means a review conducted by or involving more than one authorized institution, role, public authority, Nexus interface, room participant, repository custodian, technical asset steward, or safeguards representative concerning an incident, mismatch, boundary violation, data incident, AI incident, cybersecurity incident, public authority confusion, finance-boundary issue, technical asset issue, protected knowledge issue, or public-safe publication issue.

519.17.2 Joint Incident Review shall preserve confidentiality, privilege, public authority restrictions, data controls, protected knowledge, legal separateness, role separation, and no-admission language where appropriate.

#### 519.18 “Nexus Identity Object.”

519.18.1 “Nexus Identity Object” means a record, credential, token, identifier, profile, role key, digital object, or identity reference used to identify a person, entity, system, technical asset, repository, public authority interface, room participant, or Nexus participant within a defined Nexus context.

519.18.2 Nexus Identity Objects shall be governed by identity verification, access control, privacy, security, role separation, revocation, correction, and authority records.

#### 519.19 “Role Object.”

519.19.1 “Role Object” means a structured record or digital object defining a role, capacity, permission, authority, limitation, delegation, access class, public authority capacity, finance-boundary status, contributor status, maintainer status, reviewer status, or Nexus interface role.

519.19.2 Role Objects shall not create authority beyond the recorded scope and competent approval.

#### 519.20 “Credential Object.”

519.20.1 “Credential Object” means a structured credential, certificate, token, identity assertion, access credential, role credential, proof credential, public authority capacity credential, or other digital or documentary credential used to evidence identity, role, access, permission, or authority.

519.20.2 Credential Objects shall be revocable, auditable, scope-limited, and subject to correction, expiration, suspension, and access controls.

#### 519.21 “Access Object.”

519.21.1 “Access Object” means a structured record, permission, token, policy, role, entitlement, key, credential, access grant, or configuration enabling or documenting access to records, systems, rooms, repositories, datasets, dashboards, maps, AI systems, technical assets, or Nexus interfaces.

519.21.2 Access Objects shall be governed by least privilege, logging, expiration, revocation, classification, and security controls.

#### 519.22 “Proof Object.”

519.22.1 “Proof Object” means a structured record, proof receipt, hash, timestamp, signature, attestation, ledger entry, evidence object, verification object, validation object, compute receipt, or other technical object used to support traceability, integrity, or verification of a record, event, computation, submission, or output.

519.22.2 Proof Objects are technical traceability instruments and shall not be treated as public authority decisions, certifications, recognition, finance-readiness, procurement approvals, ratings, public warnings, or emergency commands.

#### 519.23 “Public-Good Ledger.”

519.23.1 “Public-Good Ledger” means a ledger, registry, record system, DLT system, hash-linked record system, or tamper-evident system used for public-good traceability, records integrity, technical memory, proof receipts, shared records, or Nexus coordination.

519.23.2 Public-Good Ledger entries shall require interpretation, authority, scope, and records support. A ledger entry is not authoritative merely because it exists.

#### 519.24 “Tamper-Evident Record.”

519.24.1 “Tamper-Evident Record” means a record protected by hash, signature, timestamp, immutable log, ledger entry, access log, version control, chain-of-custody, or other control designed to reveal alteration.

519.24.2 Tamper-evidence supports integrity but does not itself establish truth, authority, certification, recognition, finance-readiness, public authority approval, or legal compliance.

#### 519.25 “Verifiable Claim.”

519.25.1 “Verifiable Claim” means a claim supported by records, source lineage, proof objects, signatures, hashes, evidence records, method records, or other verification mechanisms sufficient to permit review within a defined scope.

519.25.2 Verifiable Claims shall still require authority, context, limitations, and public-safe review. Verifiability does not create recognition, certification, finance-readiness, procurement approval, public authority decision, rating, public warning, or emergency command.

#### 519.26 “Smart License.”

519.26.1 “Smart License” means a license, permission, access rule, use rule, restriction, or obligation expressed or supported through code, smart contract, digital credential, ledger entry, automated policy, or machine-readable instrument.

519.26.2 Smart Licenses shall be governed by legal enforceability, human-readable terms, authority records, access controls, correctionability, and public-safe interpretation.

519.26.3 Smart License automation shall not override law, consent, protected knowledge safeguards, public authority restrictions, or Board authority.

#### 519.27 “DLT.”

519.27.1 “DLT” means distributed ledger technology, including systems that maintain replicated, shared, cryptographically supported, append-only, consensus-based, or tamper-evident records across participants or nodes.

519.27.2 DLT shall not be treated as self-validating authority. DLT records require authority, source lineage, interpretation, access controls, public-safe review, and correction pathways.

#### 519.28 “Blockchain.”

519.28.1 “Blockchain” means a type of DLT that structures records in blocks linked by cryptographic references or comparable mechanisms.

519.28.2 Blockchain entries, tokens, smart contracts, and hashes shall not be treated as public authority decisions, finance-readiness, recognition, certification, procurement approval, ratings, public warnings, emergency commands, or legal compliance approvals without competent authority.

#### 519.29 “Ledger Entry.”

519.29.1 “Ledger Entry” means a record, transaction, hash, timestamp, proof, token movement, smart contract state, attestation, or other entry in a ledger, DLT system, blockchain, or public-good ledger.

519.29.2 A Ledger Entry is evidence of a recorded event within the ledger’s scope, not proof of truth, legality, public authority approval, finance-readiness, recognition, certification, procurement approval, or public warning.

#### 519.30 “Federation KPI.”

519.30.1 “Federation KPI” means a key performance indicator or measure used to assess coordination, interoperability, record quality, interface health, routing timeliness, correction performance, public-safe publication, safeguards performance, public authority interface discipline, finance-boundary discipline, technical asset stewardship, or Nexus federation performance.

519.30.2 Federation KPIs are internal or public-safe improvement metrics and shall not be represented as ratings, certification, recognition, finance-readiness, procurement approval, public authority approval, or provider ranking unless competent authority separately authorizes such use.

#### 519.31 Nexus Coordination and Federation Definition Records.

519.31.1 The Corporation shall maintain Nexus Coordination and Federation Definition Records, including Nexus Coordination records, Federation records, Interoperability records, Interface records, Interface Agreement records, Memorandum of Understanding records, Shared Record records, Shared Repository records, Shared Room records, Shared Publication records, Shared Technical Asset records, Routing records, Case ID records, Mismatch records, Reconciliation records, Cure records, Joint Incident Review records, Nexus Identity Object records, Role Object records, Credential Object records, Access Object records, Proof Object records, Public-Good Ledger records, Tamper-Evident Record records, Verifiable Claim records, Smart License records, DLT records, Blockchain records, Ledger Entry records, Federation KPI records, correction records, divergence logs, equivalence notes, compatibility notes, localization notes, and archive records.

***

### Section 520. Exponential Technology Definitions

#### 520.1 “Exponential Technology.”

520.1.1 “Exponential Technology” means any technology, technical system, platform, infrastructure, scientific domain, computational capability, engineered system, digital system, cyber-physical system, biological system, environmental intelligence system, or convergent technology whose capabilities, adoption, systemic effects, risks, governance needs, or infrastructure dependencies may scale rapidly, interact across sectors, or materially affect public benefit, resilience, safety, security, rights, economies, public authorities, communities, or critical systems.

520.1.2 Exponential Technology includes artificial intelligence, machine learning, generative AI, agentic AI, AI-RAN, O-RAN, private wireless, mission-critical connectivity, DePIN, blockchain, distributed ledger technology, Web3, tokenized records, quantum-relevant systems, post-quantum readiness, sovereign compute, high-performance computing, secure enclaves, confidential computing, cyber-physical systems, robotics, drones, autonomous systems, sensor systems, geospatial systems, Earth observation, remote sensing, satellite systems, digital twins, simulation systems, biosecurity systems, climate systems, nature systems, biodiversity systems, water systems, food systems, energy systems, WEFH systems, critical infrastructure, advanced manufacturing, semiconductor systems, and mission-critical infrastructure.

520.1.3 Inclusion of a technology within the Corporation’s scope does not create certification, public authority approval, procurement approval, finance-readiness, recognition, rating, provider preference, public warning, emergency command, or enterprise execution.

#### 520.2 “Artificial Intelligence.”

520.2.1 “Artificial Intelligence” means machine-based systems that, for explicit or implicit objectives, generate outputs such as predictions, recommendations, classifications, content, decisions, actions, code, summaries, reasoning traces, plans, analyses, or inferences from inputs, data, prompts, rules, models, or environments.

520.2.2 Artificial Intelligence includes machine learning, generative AI, agentic AI, foundation models, language models, computer vision, speech systems, recommender systems, decision-support systems, optimization systems, autonomous systems, simulation systems, AI-enabled networks, and hybrid systems.

520.2.3 AI outputs require governance, record support, human review where material, limitation disclosure, bias review, safety review, data controls, and correctionability.

#### 520.3 “Machine Learning.”

520.3.1 “Machine Learning” means AI methods that use data, examples, optimization, statistical learning, representation learning, reinforcement learning, self-supervision, supervision, unsupervised methods, or other computational processes to produce models or outputs.

520.3.2 Machine Learning systems shall be governed by dataset records, model records, evaluation records, bias review, drift review, privacy controls, security controls, and public-safe limitations.

#### 520.4 “Generative AI.”

520.4.1 “Generative AI” means AI systems that generate text, code, images, audio, video, synthetic data, simulations, designs, analyses, summaries, or other content.

520.4.2 Generative AI outputs shall be reviewed for hallucination, fabrication, bias, data leakage, IP issues, protected knowledge exposure, public authority boundary issues, finance-boundary issues, public-safe publication risks, and correction needs.

#### 520.5 “Agentic AI.”

520.5.1 “Agentic AI” means AI systems capable of performing tasks, using tools, initiating actions, accessing systems, calling APIs, modifying records, interacting with repositories, sending communications, executing workflows, or operating with autonomy or semi-autonomy.

520.5.2 Agentic AI shall be governed by permission controls, approval gates, logs, prohibited actions, human review, kill switches, incident controls, and non-execution boundaries.

#### 520.6 “AI-RAN.”

520.6.1 “AI-RAN” means AI-enabled radio access network systems, architectures, components, orchestration, optimization, telemetry, inference, edge compute, automation, or observability functions involving AI and radio access networks.

520.6.2 AI-RAN systems may involve telecom, cyber, infrastructure, public safety, public authority, privacy, spectrum, resilience, provider, and public-safe publication sensitivities.

520.6.3 AI-RAN references by GCRI US shall not create provider preference, procurement approval, public authority adoption, certification, finance-readiness, recognition, public warning, or emergency command.

#### 520.7 “O-RAN.”

520.7.1 “O-RAN” means open radio access network architectures, interfaces, components, standards, profiles, software, telemetry, orchestration, and interoperability systems.

520.7.2 O-RAN work shall be governed by telecom, cyber, infrastructure, standards-support, interoperability, provider-neutrality, and public-safe publication controls.

#### 520.8 “Private Wireless.”

520.8.1 “Private Wireless” means wireless networks, spectrum-enabled systems, local cellular networks, private 5G, private LTE, industrial wireless, campus wireless, mission-critical wireless, or similar networks operated for enterprise, public authority, infrastructure, facility, community, or controlled environments.

520.8.2 Private Wireless materials may implicate cybersecurity, infrastructure sensitivity, public authority data, procurement neutrality, provider neutrality, and operational safety.

#### 520.9 “Mission-Critical Connectivity.”

520.9.1 “Mission-Critical Connectivity” means communications connectivity supporting safety, emergency, infrastructure, public authority, healthcare, utility, industrial, defense-adjacent, public works, public safety, transportation, energy, water, food, telecom, or other critical functions.

520.9.2 Mission-Critical Connectivity materials shall not be used by GCRI US as emergency command, public warning, operational direction, or public authority decision.

#### 520.10 “DePIN.”

520.10.1 “DePIN” means decentralized physical infrastructure networks or systems combining physical infrastructure, devices, sensors, connectivity, compute, tokens, ledgers, decentralized coordination, or distributed participation.

520.10.2 DePIN work shall be reviewed for telemetry integrity, spoofing, public-safe mapping, tokenization, finance-boundary issues, cybersecurity, infrastructure sensitivity, and public authority boundaries.

#### 520.11 “Blockchain.”

520.11.1 “Blockchain” means a DLT system using cryptographically linked blocks or comparable structures to maintain records across participants or nodes.

520.11.2 Blockchain outputs, ledger entries, tokens, smart contracts, and proof receipts shall not be treated as self-validating authority.

#### 520.12 “Distributed Ledger Technology.”

520.12.1 “Distributed Ledger Technology” means technology that records, replicates, synchronizes, validates, or shares data across distributed participants, ledgers, nodes, or systems using cryptographic, consensus, or tamper-evident mechanisms.

520.12.2 DLT may support traceability, proof receipts, public-good ledgers, role objects, smart licenses, and technical memory, subject to governance and interpretation.

#### 520.13 “Web3.”

520.13.1 “Web3” means decentralized, tokenized, blockchain-linked, wallet-based, smart-contract-based, identity-linked, distributed, or cryptographically mediated digital systems or applications.

520.13.2 Web3 materials shall be reviewed for finance-boundary, token, securities, privacy, cybersecurity, identity, governance, public authority, and public-safe risks.

#### 520.14 “Tokenized Record.”

520.14.1 “Tokenized Record” means a record represented by, linked to, referenced by, or controlled through a token, digital asset, smart contract, ledger entry, credential, or blockchain-related object.

520.14.2 A Tokenized Record does not create ownership, authority, legality, public authority approval, finance-readiness, recognition, certification, or procurement approval merely because it is tokenized.

#### 520.15 “Quantum-Relevant System.”

520.15.1 “Quantum-Relevant System” means a system, technology, cryptographic method, compute environment, security architecture, sensing system, communications system, simulation system, or infrastructure whose risk, resilience, computation, encryption, or future posture may be materially affected by quantum computing, quantum sensing, quantum communications, or quantum-adjacent developments.

520.15.2 Quantum-Relevant Systems shall be reviewed for security, post-quantum readiness, critical infrastructure exposure, public authority implications, and technical uncertainty.

#### 520.16 “Post-Quantum Readiness.”

520.16.1 “Post-Quantum Readiness” means the preparedness of systems, records, cryptographic materials, technical assets, infrastructure, identity systems, signatures, ledgers, repositories, and communications to manage risks from quantum-capable adversaries or quantum-relevant changes.

520.16.2 Post-Quantum Readiness claims require scope, evidence, method, limitations, and correction path and shall not be treated as certification or security guarantee.

#### 520.17 “Sovereign Compute.”

520.17.1 “Sovereign Compute” means compute infrastructure, cloud, data center, AI infrastructure, HPC, edge compute, or compute governance structured for jurisdictional control, public authority requirements, national interest, data localization, public-good use, resilience, security, or strategic autonomy.

520.17.2 Sovereign Compute references shall not imply sovereign authority, public finance approval, public authority adoption, procurement approval, certification, finance-readiness, or public warning.

#### 520.18 “High-Performance Computing.”

520.18.1 “High-Performance Computing” or “HPC” means advanced computing systems, clusters, accelerators, supercomputers, distributed compute, scientific compute, AI compute, or high-capacity compute infrastructure used for intensive workloads.

520.18.2 HPC work shall be governed by compute workload records, data controls, security controls, export-control review, model governance, and public-good purpose.

#### 520.19 “Secure Enclave.”

520.19.1 “Secure Enclave” means a protected hardware, software, cloud, compute, identity, or execution environment designed to isolate processing, protect secrets, preserve confidentiality, or support trusted execution.

520.19.2 Secure Enclave use shall be documented and shall not guarantee security, compliance, certification, or public authority approval.

#### 520.20 “Confidential Computing.”

520.20.1 “Confidential Computing” means computing techniques designed to protect data in use through trusted execution environments, secure enclaves, cryptographic protections, hardware isolation, attestation, or similar methods.

520.20.2 Confidential Computing supports data protection but does not eliminate privacy, security, public authority, protected knowledge, or legal obligations.

#### 520.21 “Cyber-Physical System.”

520.21.1 “Cyber-Physical System” means a system integrating computation, networks, sensors, software, control, automation, physical processes, infrastructure, devices, or operational technology.

520.21.2 Cyber-Physical Systems may be mission-critical and shall be reviewed for safety, cybersecurity, infrastructure sensitivity, public authority boundaries, and public-safe publication.

#### 520.22 “Robotics.”

520.22.1 “Robotics” means technologies involving programmable machines, autonomous or semi-autonomous devices, sensors, actuators, control systems, physical automation, human-machine interaction, or robotic platforms.

520.22.2 Robotics materials shall be reviewed for safety, autonomy, public authority boundaries, civil rights, accessibility, cybersecurity, and operational risk.

#### 520.23 “Drone.”

520.23.1 “Drone” means an unmanned aircraft system, unmanned aerial vehicle, remotely piloted aircraft, autonomous aerial system, or related platform, including sensors, payloads, communications, data, maps, and control systems.

520.23.2 Drone-related materials shall be reviewed for aviation law, public safety, privacy, public-safe mapping, infrastructure sensitivity, public authority use, and protected knowledge.

#### 520.24 “Autonomous System.”

520.24.1 “Autonomous System” means a system capable of performing functions, navigating, sensing, deciding, acting, controlling, recommending, or operating with limited or no human intervention.

520.24.2 Autonomous Systems shall be governed by safety review, human oversight, incident controls, public authority boundaries, civil rights, accessibility, and non-execution limitations.

#### 520.25 “Sensor System.”

520.25.1 “Sensor System” means one or more sensors, telemetry sources, devices, networks, platforms, data pipelines, edge compute systems, dashboards, or observability systems used to collect or transmit observations.

520.25.2 Sensor Systems shall be reviewed for data quality, calibration, spoofing, privacy, cyber, infrastructure sensitivity, public authority restrictions, and public-safe publication.

#### 520.26 “Geospatial System.”

520.26.1 “Geospatial System” means a system for collecting, processing, analyzing, visualizing, mapping, storing, or sharing spatial, location, Earth observation, remote sensing, infrastructure, environmental, or place-based data.

520.26.2 Geospatial Systems shall be governed by public-safe mapping, protected knowledge, infrastructure sensitivity, public authority data, privacy, and community safeguards.

#### 520.27 “Earth Observation.”

520.27.1 “Earth Observation” means observation of Earth systems through satellites, aircraft, drones, remote sensors, ground sensors, radar, lidar, imagery, environmental monitoring, climate data, ocean data, atmospheric data, or related systems.

520.27.2 Earth Observation materials shall be reviewed for resolution, source lineage, uncertainty, licensing, public-safe mapping, protected knowledge, environmental sensitivity, infrastructure sensitivity, and public authority restrictions.

#### 520.28 “Remote Sensing.”

520.28.1 “Remote Sensing” means collecting information about objects, places, infrastructure, environments, or systems without direct physical contact, including satellite, aerial, drone, radar, lidar, optical, thermal, hyperspectral, acoustic, radio, or other sensing methods.

520.28.2 Remote Sensing outputs shall be reviewed before public or controlled use according to data, privacy, public-safe mapping, public authority, and protected knowledge controls.

#### 520.29 “Satellite System.”

520.29.1 “Satellite System” means satellites, constellations, ground stations, data products, imagery, telemetry, communications, navigation, Earth observation, remote sensing, or space-based systems.

520.29.2 Satellite System materials may implicate national security sensitivity, export controls, infrastructure sensitivity, public authority restrictions, privacy, protected knowledge, and public-safe mapping.

#### 520.30 “Digital Twin.”

520.30.1 “Digital Twin” means a digital representation, model, simulation, data-linked system, dynamic model, or computational representation of a physical, environmental, infrastructure, social, operational, or cyber-physical system.

520.30.2 Digital Twins shall disclose assumptions, source data, model limitations, uncertainty, version, update status, and public-safe limitations.

#### 520.31 “Simulation System.”

520.31.1 “Simulation System” means a computational, mathematical, scenario-based, digital twin, tabletop, synthetic, or model-based system used to represent, test, evaluate, forecast, or explore conditions, risks, operations, policies, or system behavior.

520.31.2 Simulation Systems shall not be treated as predictions, public authority decisions, emergency commands, public warnings, finance-readiness, ratings, certifications, or procurement approvals without competent authority.

#### 520.32 “Biosecurity System.”

520.32.1 “Biosecurity System” means systems, data, methods, policies, infrastructure, surveillance, diagnostics, laboratory practices, public health interfaces, environmental monitoring, supply chains, or technologies concerning biological risk, biosafety, disease, pathogens, synthetic biology, biotechnology, agriculture, food systems, or health security.

520.32.2 Biosecurity System work shall be governed by safety, security, public health, public authority, privacy, protected knowledge, dual-use, controlled technology, and public-safe publication controls.

#### 520.33 “Climate System.”

520.33.1 “Climate System” means climate-related physical, environmental, social, infrastructure, economic, technological, data, model, observation, mitigation, adaptation, resilience, transition, or risk systems.

520.33.2 Climate System work shall be governed by evidence quality, uncertainty, public-safe mapping, community safeguards, public authority boundaries, finance boundaries, and correctionability.

#### 520.34 “Nature System.”

520.34.1 “Nature System” means ecological, environmental, land, water, ocean, biodiversity, habitat, ecosystem service, conservation, restoration, or nature-related systems.

520.34.2 Nature System materials shall be reviewed for protected species, sensitive sites, Indigenous knowledge, environmental knowledge, community safeguards, public-safe mapping, and public authority restrictions.

#### 520.35 “Biodiversity System.”

520.35.1 “Biodiversity System” means systems concerning species, habitats, ecosystems, genetic diversity, ecological networks, conservation, restoration, monitoring, biodiversity data, environmental DNA, or related evidence.

520.35.2 Biodiversity System outputs may require protected location handling, public-safe mapping, protected knowledge review, and environmental safeguards.

#### 520.36 “Water System.”

520.36.1 “Water System” means drinking water, wastewater, stormwater, groundwater, watersheds, hydrology, water infrastructure, water quality, water security, water utilities, flood systems, drought systems, coastal systems, and related data or governance systems.

520.36.2 Water System work shall be reviewed for public health, infrastructure sensitivity, public authority boundaries, community safeguards, climate risk, and public-safe publication.

#### 520.37 “Food System.”

520.37.1 “Food System” means agriculture, food production, processing, distribution, storage, logistics, safety, security, nutrition, supply chains, markets, land systems, water dependencies, energy dependencies, and related infrastructure or data systems.

520.37.2 Food System work shall be reviewed for biosecurity, public health, supply-chain sensitivity, community safeguards, public authority boundaries, and finance-boundary overclaims.

#### 520.38 “Energy System.”

520.38.1 “Energy System” means electricity, fuels, grids, generation, transmission, distribution, storage, hydrogen, renewables, nuclear-adjacent systems, critical minerals, energy markets, energy infrastructure, utilities, and related cyber-physical systems.

520.38.2 Energy System work shall be reviewed for infrastructure sensitivity, cybersecurity, public authority boundaries, public-safe mapping, public finance boundaries, procurement neutrality, and mission-critical continuity.

#### 520.39 “WEFH System.”

520.39.1 “WEFH System” means the integrated water-energy-food-health system or related nexus systems that connect water, energy, food, health, climate, nature, infrastructure, public authority, community, and resilience considerations.

520.39.2 WEFH System work shall be governed by systems methods, public-safe publication, public authority boundaries, community safeguards, protected knowledge, data controls, and correctionability.

#### 520.40 “Critical Infrastructure.”

520.40.1 “Critical Infrastructure” means systems, assets, networks, facilities, services, or resources whose incapacity, degradation, compromise, disruption, or destruction may materially affect public safety, public health, economic security, national security, community resilience, public authority functions, or essential services.

520.40.2 Critical Infrastructure materials shall be treated as potentially infrastructure-sensitive and cyber-sensitive and shall be reviewed before publication, mapping, transfer, or AI use.

#### 520.41 “Advanced Manufacturing.”

520.41.1 “Advanced Manufacturing” means technologically advanced production, automation, robotics, additive manufacturing, precision manufacturing, cyber-physical manufacturing, semiconductor manufacturing, bio-manufacturing, materials manufacturing, AI-enabled manufacturing, or related industrial systems.

520.41.2 Advanced Manufacturing materials may implicate trade secrets, export controls, controlled technology, cybersecurity, workforce, safety, public authority, and supply-chain sensitivity.

#### 520.42 “Semiconductor System.”

520.42.1 “Semiconductor System” means systems concerning semiconductor design, fabrication, packaging, supply chains, equipment, materials, chips, compute hardware, accelerators, telecom components, AI infrastructure, and related industrial or strategic infrastructure.

520.42.2 Semiconductor System work shall be reviewed for export controls, sanctions, controlled technology, supply-chain sensitivity, public authority boundaries, national security sensitivity, and public-good technical asset restrictions.

#### 520.43 “Mission-Critical Infrastructure.”

520.43.1 “Mission-Critical Infrastructure” means infrastructure whose operation, continuity, security, or resilience is essential to public safety, public health, emergency management, public authority functions, critical infrastructure, utilities, telecom, energy, water, food, transportation, cyber systems, health systems, or other essential services.

520.43.2 Mission-Critical Infrastructure materials shall not be published, mapped, modeled, or transferred without infrastructure-sensitive, cyber-sensitive, public authority, and public-safe review.

#### 520.44 Exponential Technology Definition Records.

520.44.1 The Corporation shall maintain Exponential Technology Definition Records, including Exponential Technology records, Artificial Intelligence records, Machine Learning records, Generative AI records, Agentic AI records, AI-RAN records, O-RAN records, Private Wireless records, Mission-Critical Connectivity records, DePIN records, Blockchain records, Distributed Ledger Technology records, Web3 records, Tokenized Record records, Quantum-Relevant System records, Post-Quantum Readiness records, Sovereign Compute records, High-Performance Computing records, Secure Enclave records, Confidential Computing records, Cyber-Physical System records, Robotics records, Drone records, Autonomous System records, Sensor System records, Geospatial System records, Earth Observation records, Remote Sensing records, Satellite System records, Digital Twin records, Simulation System records, Biosecurity System records, Climate System records, Nature System records, Biodiversity System records, Water System records, Food System records, Energy System records, WEFH System records, Critical Infrastructure records, Advanced Manufacturing records, Semiconductor System records, Mission-Critical Infrastructure records, correction records, controlled vocabulary records, public-safe limitation records, and archive records.

***

### Section 521. Records, Registers, Validity, Correction, and Assurance Definitions

#### 521.1 “Record.”

521.1.1 “Record” means any written, electronic, digital, audio, visual, code-based, repository-based, ledger-based, metadata-based, structured, unstructured, or otherwise preserved information created, received, maintained, approved, used, relied upon, archived, or controlled by or for the Corporation.

521.1.2 Records include governance records, corporate records, Board records, officer records, committee records, fiscal records, conflict records, research records, evidence records, method records, ontology records, data records, AI records, cyber records, privacy records, technical asset records, public authority records, publication records, Nexus records, safeguards records, incident records, assurance records, correction records, and wind-up records.

#### 521.2 “Authoritative Record.”

521.2.1 “Authoritative Record” means a Record designated, approved, maintained, or recognized as controlling for a defined purpose by competent authority.

521.2.2 Authoritative Records establish the Corporation’s valid institutional meaning, authority, status, approval, version, public-safe status, access class, correction path, and reliance limitations within their defined scope.

521.2.3 No draft, unofficial copy, AI summary, translation, extract, slide, informal note, public statement, screenshot, email excerpt, or third-party description shall override an Authoritative Record.

#### 521.3 “Public Record.”

521.3.1 “Public Record,” for Corporation record-classification purposes, means a Record approved for public access or required to be public by law.

521.3.2 “Public Record” shall not be confused with public-sector public records law. The Corporation’s Record is not subject to public records law merely because it is called public, unless applicable law or public authority custody creates that status.

#### 521.4 “Internal Record.”

521.4.1 “Internal Record” means a Record intended for internal Corporation access or internal authorized Nexus, governance, technical, research, administrative, or operational use.

521.4.2 Internal Records may not be externally shared without authority, classification review, public-safe review where applicable, and confidentiality review.

#### 521.5 “Controlled Record.”

521.5.1 “Controlled Record” means a Record subject to controlled access, defined audience, logging, use limitations, confidentiality terms, public authority restrictions, finance-boundary restrictions, data / AI / cyber controls, protected knowledge controls, or controlled-room rules.

521.5.2 Controlled Records may be shared only according to access records and applicable restrictions.

#### 521.6 “Confidential Record.”

521.6.1 “Confidential Record” means a Record containing confidential, non-public, proprietary, privileged, personal, sensitive, public authority restricted, finance-sensitive, commercially sensitive, research-sensitive, technical, security, or other protected information.

521.6.2 Confidential Records shall be protected against unauthorized disclosure and shall not be publicized, summarized, or transferred without review.

#### 521.7 “Restricted Record.”

521.7.1 “Restricted Record” means a Record requiring heightened access limits due to legal, contractual, privacy, cybersecurity, public authority, health-sensitive, infrastructure-sensitive, protected knowledge, export-control, sanctions, controlled technology, privilege, investigation, legal hold, or public-safe risk.

521.7.2 Restricted Records shall be accessed only by authorized persons with recorded purpose and appropriate controls.

#### 521.8 “Register.”

521.8.1 “Register” means a structured set of Records maintained for a defined category, including corporate, Board, member, officer, director, delegation, committee, conflict, related-party, fiscal, grant, contract, procurement, research, evidence, method, ontology, data, processing, model, inference, compute, incident, technical asset, repository, publication, public authority, Nexus interface, compliance, risk, correction, safeguards, and protected knowledge registers.

521.8.2 Registers support validity-by-record, traceability, oversight, correctionability, assurance, and institutional memory.

#### 521.9 “Record Owner.”

521.9.1 “Record Owner” means the person, role, body, or authority responsible for the substantive accuracy, authority, scope, review, approval, status, and correction of a Record.

521.9.2 Record Owner status shall be documented and does not necessarily include custody, access administration, or publication authority unless separately assigned.

#### 521.10 “Record Custodian.”

521.10.1 “Record Custodian” means the person, role, system, repository, provider, archive, officer, or entity responsible for maintaining, storing, securing, versioning, preserving, migrating, archiving, producing, deleting, or disposing of a Record.

521.10.2 Record Custodians shall follow retention, access, confidentiality, legal hold, security, and correction requirements.

#### 521.11 “Record Identifier.”

521.11.1 “Record Identifier” means a unique identifier, code, number, hash, case ID, URI, repository path, ledger reference, file identifier, docket number, version tag, or other reference used to identify a Record.

521.11.2 Record Identifiers shall support retrieval, traceability, citation, access control, correction, supersession, and archive.

#### 521.12 “Version.”

521.12.1 “Version” means the specific state, edition, release, revision, commit, tag, build, publication, record state, or form of a Record or technical asset at a given time.

521.12.2 Versioning shall preserve lineage, changes, effective dates, supersession paths, correction paths, and archive status.

#### 521.13 “Effective Date.”

521.13.1 “Effective Date” means the date and, where material, time on which a Record, policy, Bylaw, resolution, release, delegation, authority, permission, classification, correction, supersession, withdrawal, retraction, takedown, suspension, re-entry, archive, or status becomes operative.

521.13.2 Effective Date shall be distinguished from creation date, approval date, publication date, filing date, notice date, and archive date where material.

#### 521.14 “Authority.”

521.14.1 “Authority” means the lawful and recorded basis for action, approval, access, publication, amendment, correction, transfer, release, use, retention, disposition, public claim, public authority reference, finance-boundary statement, certification-boundary statement, recognition-boundary statement, or Nexus interface output.

521.14.2 Authority may arise from law, certificate or articles, these Bylaws, Board resolution, officer delegation, committee charter, contract, consent, permission, public authority record, GRF record, GRA record, Nexus authority record, license, or other competent record.

#### 521.15 “Scope.”

521.15.1 “Scope” means the defined boundaries of a Record, authority, review, claim, method, evidence item, dataset, model, technical asset, publication, public authority reference, finance-boundary statement, recognition status, certification-related statement, or Nexus interface.

521.15.2 Scope shall be interpreted narrowly where overclaim, reliance, public authority confusion, finance confusion, recognition confusion, certification confusion, procurement implication, data misuse, or protected knowledge risk exists.

#### 521.16 “Classification.”

521.16.1 “Classification” means the assigned status of a Record, data item, technical asset, publication, output, room, access, incident, claim, or material according to sensitivity, access, confidentiality, public-safe status, public authority status, finance status, protected knowledge status, cybersecurity status, infrastructure status, retention, and disclosure rules.

521.16.2 Classification shall be reviewed and updated when facts, law, risk, public-safe status, or authority changes.

#### 521.17 “Public-Safe Status.”

521.17.1 “Public-Safe Status” means the classification determining whether and how a Record, publication, dashboard, map, dataset, software, technical asset, public authority reference, protected knowledge material, or public claim may be shared publicly or broadly without creating foreseeable harm, overclaim, public authority confusion, finance confusion, certification confusion, recognition confusion, procurement implication, public warning confusion, or emergency command confusion.

521.17.2 Public-Safe Status may be public-safe, controlled, restricted, confidential, internal, public authority only, community-protected, archived, withdrawn, retracted, or other approved status.

#### 521.18 “Limitation.”

521.18.1 “Limitation” means a disclosed or recorded constraint, uncertainty, exclusion, assumption, data gap, method gap, source gap, temporal limit, jurisdictional limit, authority limit, technical limit, public-safe limit, access limit, finance-boundary limit, recognition-boundary limit, certification-boundary limit, procurement-boundary limit, public authority limit, or safeguards limit affecting interpretation or use.

521.18.2 Material Limitations shall be disclosed in public-safe or controlled outputs as appropriate.

#### 521.19 “Retention Class.”

521.19.1 “Retention Class” means the assigned category determining how long a Record must be retained, whether it may be archived, sealed, deleted, securely disposed of, transferred, returned, or held.

521.19.2 Retention Class shall account for law, tax, corporate records, grants, contracts, research integrity, evidence integrity, public authority obligations, data protection, legal holds, protected knowledge, technical memory, and correctionability.

#### 521.20 “Access Class.”

521.20.1 “Access Class” means the assigned category determining who may access a Record, dataset, room, repository, technical asset, dashboard, map, publication, model, proof receipt, or other material and under what conditions.

521.20.2 Access Class may include public, public-safe, internal, controlled, confidential, restricted, public authority, research, clean-room, data-room, evidence-room, no-download, community-protected, protected knowledge, cyber-sensitive, infrastructure-sensitive, finance-sensitive, archived, sealed, or legal-hold access.

#### 521.21 “Validity-by-Record.”

521.21.1 “Validity-by-Record” means the doctrine that institutional authority, public meaning, evidence status, method status, public claim status, public authority reference status, technical baseline status, software release status, data access status, AI-use status, controlled-room access status, finance-boundary status, safeguards status, Nexus interface status, correction status, and other material meanings exist only to the extent supported by competent Authoritative Records.

521.21.2 Validity-by-Record shall govern interpretation of all Corporation outputs and interfaces.

#### 521.22 “No Record / No Public Meaning.”

521.22.1 “No Record / No Public Meaning” means the rule that, absent a competent Authoritative Record, no public claim, public authority reference, official capacity, evidence status, method status, software release status, technical baseline status, Nexus-compatible claim, Docket meaning, Grid meaning, GRF recognition meaning, GRA finance-readiness meaning, certification meaning, procurement approval, public finance approval, rating, public warning, emergency command, or public authority decision shall be recognized as valid.

521.22.2 Unsupported public meaning shall be corrected, limited, withdrawn, disregarded, or referred as appropriate.

#### 521.23 “Correction.”

521.23.1 “Correction” means a recorded action to amend, clarify, limit, qualify, update, repair, correct, reclassify, annotate, or otherwise address an error, omission, overclaim, outdated statement, boundary defect, data defect, public-safe defect, technical defect, or unsupported meaning.

521.23.2 Correction may be public-safe, controlled, internal, repository-based, record-based, downstream, or direct to affected parties.

521.23.3 Correction may be made without admission where appropriate, but non-admission shall not prevent accurate correction.

#### 521.24 “Supersession.”

521.24.1 “Supersession” means replacement of a Record, publication, policy, version, method, technical asset, software release, technical baseline, dataset, model, dashboard, map, public claim, public authority reference, or other material with a later or more authoritative version.

521.24.2 Superseded materials shall be marked, archived, restricted, or withdrawn as appropriate to prevent reliance confusion.

#### 521.25 “Withdrawal.”

521.25.1 “Withdrawal” means removal of current status, current use, current authority, current public-safe approval, or current availability of a Record, publication, claim, technical asset, dataset, software, method, dashboard, map, public authority reference, or other material.

521.25.2 Withdrawal may occur because of error, uncertainty, legal issue, public-safe issue, data issue, security issue, protected knowledge issue, authority defect, or changed circumstances.

#### 521.26 “Retraction.”

521.26.1 “Retraction” means a formal removal or invalidation of a publication, claim, evidence statement, method statement, public-safe summary, technical claim, recognition-related reference, finance-boundary statement, public authority reference, or other output because it is materially inaccurate, unsupported, misleading, unsafe, or defective.

521.26.2 Retraction shall be recorded and accompanied by notice where required or appropriate.

#### 521.27 “Takedown.”

521.27.1 “Takedown” means removal, disabling, restriction, or suppression of public or external access to a website item, repository item, dataset, dashboard, map, software release, technical baseline, publication, social media post, public notice, media statement, file, or other material.

521.27.2 Takedown may be required for legal, privacy, cybersecurity, protected knowledge, public authority, public-safe, IP, defamation, misinformation, or boundary reasons.

#### 521.28 “Suspension.”

521.28.1 “Suspension” means temporary pause, hold, restriction, access limitation, publication limitation, release limitation, use limitation, authority limitation, repository hold, data hold, model hold, room hold, or public claim hold pending review, correction, investigation, or resolution.

521.28.2 Suspension shall be recorded with trigger, scope, owner, review date, conditions, and re-entry path.

#### 521.29 “Re-Entry.”

521.29.1 “Re-Entry” means the recorded restoration of a Record, technical asset, dataset, model, publication, dashboard, map, room, access, public claim, method, software release, technical baseline, or authority after suspension, hold, withdrawal, restriction, correction, or review.

521.29.2 Re-Entry requires competent authority, corrective action where required, public-safe review where required, and updated records.

#### 521.30 “Archive.”

521.30.1 “Archive” means retention of a Record, technical asset, publication, software release, dataset, model, dashboard, map, policy, Bylaw version, public claim, or other material for legal, historical, technical memory, evidence, audit, public-safe, or correctionability purposes.

521.30.2 Archive status shall distinguish historical preservation from current authority and shall include access, retention, classification, and correction metadata.

#### 521.31 “Assurance.”

521.31.1 “Assurance” means structured review, testing, control assessment, audit, verification, monitoring, evaluation, evidence review, governance review, compliance review, technical review, or public-safe review intended to provide confidence within a defined scope.

521.31.2 Assurance may be internal, external, Board-directed, committee-directed, funder-required, public authority-facing, technical, privacy, AI, cyber, research integrity, safeguards, publication, or Nexus-focused.

521.31.3 Assurance shall not be represented as certification, legal compliance approval, finance-readiness, public authority approval, rating, procurement approval, recognition, or guarantee unless competent authority separately provides such meaning.

#### 521.32 “Monitoring.”

521.32.1 “Monitoring” means ongoing or periodic observation, review, measurement, logging, assessment, or tracking of records, controls, access, models, data quality, cybersecurity, privacy, public authority interfaces, protected knowledge, vendors, technical assets, publications, Nexus interfaces, KPIs, KRIs, incidents, corrections, or compliance.

521.32.2 Monitoring supports improvement and does not create public warning, emergency command, regulatory approval, finance-readiness, certification, recognition, or rating.

#### 521.33 “Evaluation.”

521.33.1 “Evaluation” means structured assessment of effectiveness, quality, integrity, impact, performance, controls, methods, evidence, outputs, programs, technical assets, safeguards, public authority interfaces, data governance, AI governance, cybersecurity, public-safe publication, or Nexus coordination.

521.33.2 Evaluation shall be record-based, limitation-aware, and correctionable.

521.33.3 Evaluation findings shall not be represented as certification, procurement approval, public authority approval, finance-readiness, rating, recognition, or public warning unless competent authority expressly provides otherwise.

#### 521.34 “Impact Claim.”

521.34.1 “Impact Claim” means a claim that the Corporation, a program, publication, technical asset, method, public authority learning activity, Nexus interface, evidence output, dashboard, map, software release, technical baseline, grant, sponsor support, public-good activity, or other activity produced, contributed to, caused, enabled, improved, reduced, prevented, accelerated, or otherwise affected an outcome.

521.34.2 Impact Claims require evidence, limitations, attribution caution, contribution rather than sole-causation language where appropriate, sponsor and funder review where material, public authority review where material, community review where material, safeguards review where material, and boundary review.

521.34.3 Impact Claims shall not be represented as ratings, public authority approvals, finance-readiness, certifications, recognition, procurement approvals, provider preferences, public warnings, or emergency commands.

#### 521.35 “Renewal.”

521.35.1 “Renewal” means the process of updating, reaffirming, revising, extending, replacing, reauthorizing, retraining, revalidating, re-reviewing, correcting, or retiring a Record, authority, policy, method, technical asset, public-safe publication, register, model, dataset, access, room, public authority interface, safeguard, or Nexus interface.

521.35.2 Renewal shall be based on monitoring, evaluation, assurance, incident review, correction records, legal changes, technology changes, public authority changes, data changes, safeguards changes, and Board or officer direction.

#### 521.36 Records, Validity, and Assurance Definition Records.

521.36.1 The Corporation shall maintain Records, Validity, and Assurance Definition Records, including Record records, Authoritative Record records, Public Record records, Internal Record records, Controlled Record records, Confidential Record records, Restricted Record records, Register records, Record Owner records, Record Custodian records, Record Identifier records, Version records, Effective Date records, Authority records, Scope records, Classification records, Public-Safe Status records, Limitation records, Retention Class records, Access Class records, Validity-by-Record records, No Record / No Public Meaning records, Correction records, Supersession records, Withdrawal records, Retraction records, Takedown records, Suspension records, Re-Entry records, Archive records, Assurance records, Monitoring records, Evaluation records, Impact Claim records, Renewal records, correction records, assurance records, and archive records.

### Section 522. Risk, Compliance, Incident, Enforcement, and Stop-the-Line Definitions

#### 522.1 “Risk.”

522.1.1 “Risk” means the possibility that an event, condition, act, omission, ambiguity, dependency, defect, weakness, misuse, misrepresentation, overclaim, boundary failure, data failure, technical failure, governance failure, public authority confusion, finance-boundary confusion, certification-boundary confusion, recognition-boundary confusion, procurement implication, provider preference, protected knowledge exposure, public-safe publication defect, cybersecurity compromise, privacy harm, legal noncompliance, fiduciary failure, public-good asset enclosure, sponsor capture, provider capture, or Nexus role collapse may adversely affect the Corporation, its public-benefit purpose, its records, its outputs, affected persons, public authorities, communities, Nexus interfaces, technical assets, or public trust.

522.1.2 Risk includes legal, governance, fiduciary, fiscal, tax, nonprofit, research integrity, evidence integrity, methods integrity, ontology, data, AI, cybersecurity, privacy, public authority, public records, public finance, procurement, finance, insurance, rating, certification, recognition, Docket, Grid, Nexus-compatible, provider-neutrality, sponsor-non-control, civil rights, accessibility, community safeguards, Tribal / Indigenous, protected knowledge, public-safe mapping, publication, media, technical asset, repository, supply-chain, IP, licensing, sanctions, export-control, controlled technology, national security sensitivity, operational, reputational, assurance, dissolution, wind-up, and archival risks.

522.1.3 Risk classification shall not be used as a public rating, finance-readiness determination, recognition determination, certification, procurement approval, public authority decision, public warning, emergency command, or provider preference unless a competent external authority separately provides such meaning.

#### 522.2 “Risk Register.”

522.2.1 “Risk Register” means the structured record or set of records identifying material risks, risk owners, risk descriptions, causes, consequences, likelihood, severity, controls, mitigations, escalation status, review dates, corrective actions, residual risk, related incidents, related records, and closure status.

522.2.2 The Risk Register may include risks concerning corporate governance, fiscal stewardship, research integrity, evidence integrity, methods, data, AI, cybersecurity, privacy, public authority boundaries, finance boundaries, certification and recognition boundaries, procurement neutrality, public-good software, repositories, technical assets, protected knowledge, public-safe publication, Nexus coordination, grants, sponsorships, vendors, conflicts, legal holds, and wind-up.

522.2.3 The Risk Register is a governance and assurance instrument and shall not be represented as a public rating, public warning, finance-readiness instrument, procurement instrument, recognition instrument, certification instrument, or public authority determination.

#### 522.3 “Issue Register.”

522.3.1 “Issue Register” means the structured record or set of records identifying active, emerging, unresolved, disputed, defective, escalated, or corrective issues requiring review, decision, mitigation, correction, hold, referral, or closeout.

522.3.2 The Issue Register may include governance issues, record defects, research issues, evidence issues, method issues, data quality issues, AI incidents, cybersecurity issues, privacy issues, publication issues, public authority reference issues, finance-boundary issues, certification or recognition overclaims, protected knowledge issues, repository issues, technical asset issues, public-safe mapping issues, Nexus interface mismatches, and enforcement matters.

522.3.3 Issue Register entries shall identify issue owner, severity, source, related records, interim measures, corrective actions, due dates, status, and closeout record.

#### 522.4 “Control Register.”

522.4.1 “Control Register” means the structured record or set of records identifying governance, legal, fiscal, research, evidence, methods, data, AI, cybersecurity, privacy, technical asset, publication, public authority, finance-boundary, certification-boundary, recognition-boundary, procurement-neutrality, safeguards, protected knowledge, Nexus coordination, vendor, repository, and assurance controls.

522.4.2 The Control Register shall identify control owner, control purpose, control frequency, control evidence, control status, tested status, failures, corrective actions, exceptions, residual risk, and review date.

522.4.3 Control Register status shall not be represented as certification, compliance approval, public authority approval, procurement approval, finance-readiness, recognition, rating, guarantee, public warning, or emergency command.

#### 522.5 “KPI.”

522.5.1 “KPI” means a key performance indicator used to monitor performance, timeliness, quality, completeness, participation, publication, correction, recordkeeping, technical asset stewardship, public authority learning support, public-safe publication, Nexus coordination, training, or other mission-related performance.

522.5.2 KPIs shall be used for internal or public-safe improvement and accountability and shall not be represented as ratings, certification, recognition, finance-readiness, procurement approval, public authority approval, provider ranking, or public warning unless competent authority separately provides such meaning.

#### 522.6 “KRI.”

522.6.1 “KRI” means a key risk indicator used to monitor risk exposure, risk trend, control weakness, boundary risk, incident likelihood, evidence defect, data quality concern, AI risk, cybersecurity risk, privacy risk, public authority confusion risk, finance-boundary risk, certification-boundary risk, recognition-boundary risk, procurement implication, protected knowledge risk, public-safe publication risk, or Nexus interface risk.

522.6.2 KRIs support governance, monitoring, escalation, and corrective action and shall not be used as public warnings, ratings, finance-readiness determinations, recognition determinations, certifications, procurement approvals, or public authority decisions.

#### 522.7 “Corrective Action.”

522.7.1 “Corrective Action” means a recorded action taken to address a defect, incident, risk, issue, violation, overclaim, unsupported public meaning, data error, AI misuse, cybersecurity weakness, privacy failure, publication error, protected knowledge exposure, public authority confusion, finance-boundary issue, certification or recognition boundary issue, procurement implication, technical asset defect, repository defect, control failure, or governance failure.

522.7.2 Corrective Action may include correction, supersession, withdrawal, retraction, takedown, access restriction, data hold, AI hold, publication hold, repository hold, controlled-room hold, credential rotation, system isolation, policy update, training, role restriction, contract remedy, grantor notice, funder notice, public authority notice, community notice, Tribal / Indigenous notice where appropriate, legal review, regulator referral, law enforcement referral, or Board action.

522.7.3 Corrective Action may be public, controlled, internal, technical, legal, procedural, remedial, restorative, disciplinary, contractual, or referral-based depending on the matter.

#### 522.8 “Compliance.”

522.8.1 “Compliance” means adherence to applicable law, the certificate or articles, these Bylaws, Board resolutions, policies, contracts, grants, donor restrictions, public authority terms, data protection requirements, privacy requirements, AI governance requirements, cybersecurity requirements, research ethics requirements, employment requirements, civil rights requirements, accessibility requirements, sanctions and export-control requirements, tax and nonprofit requirements, IP and licensing requirements, records requirements, public-safe publication rules, and Nexus interface requirements.

522.8.2 Compliance, as used internally by the Corporation, shall not mean legal compliance approval, regulatory approval, certification, public authority approval, procurement approval, finance-readiness, recognition, rating, or safe harbor unless competent authority expressly provides such meaning.

#### 522.9 “Legal Hold.”

522.9.1 “Legal Hold” means a required or prudent preservation instruction, restriction, suspension of deletion, or records-preservation status issued because of litigation, anticipated litigation, investigation, audit, public authority request, regulatory matter, funder matter, grantor matter, cybersecurity incident, data incident, research integrity matter, publication challenge, protected knowledge issue, technical asset issue, insurance claim, indemnification matter, or other preservation need.

522.9.2 Legal Hold may apply to corporate records, communications, emails, chats, repositories, datasets, logs, AI records, model records, inference records, compute workload records, proof receipts, public authority records, protected knowledge records, technical assets, publications, dashboards, maps, contracts, fiscal records, and backups.

522.9.3 Legal Hold suspends deletion, destruction, overwriting, alteration, disposal, or uncontrolled transfer of covered materials until released by competent authority.

#### 522.10 “Incident.”

522.10.1 “Incident” means an actual or suspected event, condition, act, omission, failure, violation, breach, exposure, defect, overclaim, misuse, misrouting, unauthorized access, unauthorized disclosure, unauthorized action, public-safe publication failure, public authority boundary failure, finance-boundary failure, certification or recognition boundary failure, procurement implication, data incident, AI incident, cybersecurity incident, privacy incident, protected knowledge incident, technical asset incident, repository incident, governance incident, fiscal incident, legal incident, or safeguards incident requiring intake, triage, classification, investigation, correction, remediation, referral, or closeout.

522.10.2 Incidents shall be assigned a case identifier where material and shall be handled through the Corporation’s incident, investigation, enforcement, corrective action, and stop-the-line framework.

#### 522.11 “Boundary Incident.”

522.11.1 “Boundary Incident” means an Incident involving actual or suspected breach, confusion, misuse, overclaim, reliance, role collapse, or unauthorized expansion of any institutional boundary established by these Bylaws.

522.11.2 Boundary Incidents include public authority boundary incidents, finance boundary incidents, certification boundary incidents, procurement boundary incidents, recognition boundary incidents, Docket or Grid meaning incidents, Nexus-compatible claim incidents, provider-preference incidents, public warning incidents, emergency command incidents, and role-collapse incidents.

522.11.3 Boundary Incidents require prompt classification, limitation, correction, and escalation where reliance risk exists.

#### 522.12 “Public Authority Boundary Incident.”

522.12.1 “Public Authority Boundary Incident” means an Incident in which Corporation materials, participants, outputs, rooms, events, public claims, dashboards, maps, publications, public authority references, public authority data, public authority learning materials, or Nexus interfaces are used or understood to imply public authority endorsement, adoption, funding approval, procurement approval, regulatory approval, public finance approval, sovereign obligation, public-private partnership, official public warning, emergency command, public health order, safety command, or public authority decision without competent public authority record.

522.12.2 Public Authority Boundary Incidents may require immediate public-safe correction, controlled correction, public authority notice, publication hold, dashboard or map hold, room hold, data hold, legal review, or referral.

#### 522.13 “Finance Boundary Incident.”

522.13.1 “Finance Boundary Incident” means an Incident in which Corporation evidence, methods, proof receipts, dashboards, maps, publications, technical baselines, public-good software, public authority learning materials, Nexus interfaces, rooms, sponsor references, provider references, or public claims are used or understood to imply finance-readiness, capital-readability, insurance-readiness, investment advice, securities solicitation, brokerage, finder activity, placement, underwriting, lending, insurance placement, rating, credit opinion, public finance approval, public guarantee, public credit, sovereign obligation, bankability, insurability, investability, or capital commitment by GCRI US without competent authority.

522.13.2 Finance Boundary Incidents shall preserve GRA role separation and may require immediate correction, room restriction, non-reliance notice, public-safe notice, funder notice, GRA notice, legal review, or referral.

#### 522.14 “Role-Collapse Incident.”

522.14.1 “Role-Collapse Incident” means an Incident in which the distinct roles of GCRI US, GCRI Canada, other GCRI entities, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, protocol authorities, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, public authorities, providers, sponsors, hosts, national companies, Project SPVs, or enterprise actors are confused, merged, substituted, or misrepresented.

522.14.2 Role-Collapse Incidents may arise through public materials, MoUs, decks, press statements, event participation, public authority references, finance materials, repository notices, shared rooms, shared publications, public claims, or AI-generated content.

522.14.3 Role-Collapse Incidents require correction of institutional meaning, legal separateness, non-execution, public-good stack / enterprise stack separation, and competent authority.

#### 522.15 “Interface Misuse.”

522.15.1 “Interface Misuse” means unauthorized, misleading, unsafe, unlawful, overbroad, or boundary-defective use of an institutional, technical, public authority, finance, Nexus, repository, data, AI, controlled-room, publication, or stakeholder interface.

522.15.2 Interface Misuse includes using an interface to bypass approvals, access restricted records, imply endorsement, imply finance-readiness, imply recognition, imply certification, imply procurement approval, create provider preference, disclose protected knowledge, misuse public authority data, misroute records, or generate unsupported public meaning.

#### 522.16 “Cybersecurity Incident.”

522.16.1 “Cybersecurity Incident” means an actual or suspected compromise, unauthorized access, unauthorized use, unauthorized disclosure, malware, phishing, credential compromise, secret exposure, key exposure, token exposure, repository compromise, vulnerability exploitation, service disruption, supply-chain compromise, cloud compromise, AI system compromise, controlled-room compromise, denial of service, logging failure, integrity compromise, or other event affecting confidentiality, integrity, availability, authentication, authorization, or technical security.

522.16.2 Cybersecurity Incidents shall be handled through containment, investigation, credential or key rotation, system isolation, vulnerability remediation, notification assessment, legal review, public-safe communication, and closeout as appropriate.

#### 522.17 “Privacy Incident.”

522.17.1 “Privacy Incident” means an actual or suspected unauthorized access, use, disclosure, loss, alteration, retention, transfer, publication, AI use, embedding, training, destruction, or compromise of Personal Information, Sensitive Personal Information, Rights-Bearing Data, Health-Sensitive Data, data subject records, participant records, or privacy-restricted materials.

522.17.2 Privacy Incidents shall be reviewed for breach notification, data subject rights, regulatory notice, public authority notice, public-safe communication, legal hold, correction, deletion, restriction, and remediation.

#### 522.18 “Protected Knowledge Incident.”

522.18.1 “Protected Knowledge Incident” means an actual or suspected unauthorized access, use, disclosure, publication, mapping, transfer, AI training, embedding, modeling, attribution, non-attribution failure, withdrawal failure, restriction failure, archive failure, or exposure of Protected Knowledge, Indigenous Knowledge, Indigenous Data, Community-Protected Materials, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, sacred knowledge, sensitive site information, or other safeguards-protected materials.

522.18.2 Protected Knowledge Incidents may require immediate stop-the-line action, takedown, access restriction, community notice, Tribal / Indigenous notice where appropriate, public-safe mapping correction, deletion where lawful, sealing, grievance review, remedy, or referral.

#### 522.19 “Public-Safe Publication Incident.”

522.19.1 “Public-Safe Publication Incident” means an actual or suspected publication, release, statement, website update, repository notice, dataset release, dashboard display, map display, social media post, media statement, public authority reference, sponsor reference, provider reference, public-safe summary, archive statement, or external communication that is inaccurate, unsupported, overclaimed, unsafe, misleading, boundary-defective, inaccessible, privacy-defective, cyber-sensitive, infrastructure-sensitive, protected-knowledge-defective, or otherwise inconsistent with public-safe publication requirements.

522.19.2 Public-Safe Publication Incidents may require publication hold, takedown, correction, supersession, withdrawal, retraction, controlled notice, public notice, public authority notice, safeguards review, or legal review.

#### 522.20 “Misrepresentation.”

522.20.1 “Misrepresentation” means a false, misleading, incomplete, unsupported, overstated, outdated, ambiguous, or materially defective statement, omission, implication, label, title, claim, public authority reference, finance-boundary reference, recognition claim, certification claim, procurement claim, Nexus-compatible claim, Docket claim, Grid claim, technical claim, evidence claim, public-safe statement, or institutional description.

522.20.2 Misrepresentation may occur through words, graphics, marks, logos, badges, seals, decks, websites, repositories, dashboards, maps, datasets, AI outputs, public authority references, sponsor references, provider references, media statements, archive statements, or silence where a limitation is required.

#### 522.21 “Overclaim.”

522.21.1 “Overclaim” means a claim that exceeds the authority, evidence, method, record, scope, public-safe status, technical status, public authority status, finance-boundary status, recognition status, certification status, procurement status, Nexus-compatible status, Docket status, Grid status, or institutional role that actually exists.

522.21.2 Overclaims include unsupported use of “official,” “approved,” “certified,” “validated,” “verified,” “recognized,” “mature,” “standing,” “finance-ready,” “insurance-ready,” “bankable,” “investable,” “rated,” “public authority approved,” “public warning,” “emergency ready,” “procurement-ready,” “preferred provider,” “Nexus-compatible,” or equivalent terms without competent records.

522.21.3 Overclaim shall be corrected according to severity, reliance risk, public-safe risk, and affected parties.

#### 522.22 “Investigation.”

522.22.1 “Investigation” means a structured review, inquiry, fact-finding process, evidence review, records review, technical review, legal review, compliance review, incident review, boundary review, safeguards review, research integrity review, or enforcement review conducted to determine facts, classification, responsibility, impact, corrective action, referral, or closeout.

522.22.2 Investigations shall preserve confidentiality, privilege, non-retaliation, impartiality where required, evidence preservation, access controls, public authority restrictions, protected knowledge, and due process where applicable.

#### 522.23 “Interim Measure.”

522.23.1 “Interim Measure” means temporary protective action taken before final determination to preserve evidence, prevent harm, limit reliance, protect records, restrict access, pause publication, isolate systems, protect data, prevent public authority confusion, prevent finance-boundary misuse, prevent protected knowledge exposure, or preserve legal rights.

522.23.2 Interim Measures may include stop-the-line, hold, quarantine, suspension, access restriction, publication hold, repository hold, data hold, model hold, controlled-room hold, credential rotation, takedown, public-safe notice, controlled notice, or escalation.

522.23.3 Interim Measures shall be recorded, reviewed, and lifted, extended, modified, or converted to final corrective action as appropriate.

#### 522.24 “Enforcement.”

522.24.1 “Enforcement” means the Corporation’s process for reviewing, addressing, correcting, remedying, restricting, escalating, referring, or otherwise responding to violations, incidents, defects, risks, misconduct, overclaims, unauthorized actions, unsupported public meanings, record failures, boundary failures, data / AI / cyber failures, safeguards failures, or Bylaw violations.

522.24.2 Enforcement may involve Board action, officer action, committee review, legal review, investigation, corrective action, role restriction, access restriction, suspension, termination, contract remedy, public or controlled correction, referral, recovery action, or other lawful remedy.

522.24.3 Enforcement shall be proportionate, records-based, non-retaliatory, confidentiality-aware, privilege-aware, public-safe, and consistent with applicable law and these Bylaws.

#### 522.25 “Remedy.”

522.25.1 “Remedy” means an action taken to repair, mitigate, reverse, prevent, compensate where lawful, correct, restore, restrict, discipline, refer, disclose, or otherwise address harm, risk, violation, defect, overclaim, unsupported meaning, data misuse, protected knowledge exposure, public authority confusion, finance-boundary misuse, technical asset misuse, or governance failure.

522.25.2 Remedies may include correction, supersession, withdrawal, retraction, takedown, apology where appropriate, access restriction, deletion where lawful, sealing, return, secure destruction, contract remedy, training, policy revision, technical fix, repository fix, public authority notice, community remedy, Tribal / Indigenous remedy where appropriate, funder notice, legal referral, or enforcement action.

#### 522.26 “Referral.”

522.26.1 “Referral” means transmission, escalation, notice, report, or direction of a matter to counsel, auditor, insurer, regulator, public authority, funder, grantor, donor, Attorney General, court, law enforcement, data protection authority, cybersecurity authority, sanctions authority, export-control authority, public health authority, emergency management authority, Tribal / Indigenous authority where appropriate, community process, GRF, GRA, Nexus authority, or other competent body.

522.26.2 Referral shall be made where required by law, contract, grant, public authority terms, insurance terms, safeguards obligations, legal advice, Board decision, or risk severity.

522.26.3 Referral shall preserve confidentiality, privilege, privacy, protected knowledge, public-safe communication, and role separation.

#### 522.27 “Stop-the-Line.”

522.27.1 “Stop-the-Line” means immediate authority or obligation to pause, stop, hold, restrict, isolate, suspend, withdraw, take down, re-scope, quarantine, escalate, or prevent continuation of an activity, output, release, publication, access, room, repository, dataset, model, system, technical asset, public authority interface, finance-boundary interface, public claim, or Nexus interface where continuation may create material risk, violation, harm, unsupported public meaning, public authority confusion, finance misuse, data misuse, AI misuse, cybersecurity risk, privacy harm, protected knowledge exposure, civil rights harm, research integrity failure, evidence integrity failure, public-safe publication defect, sponsor capture, provider capture, sanctions risk, export-control risk, controlled technology risk, legal deadline failure, or public-good asset enclosure.

522.27.2 Stop-the-Line may be invoked by persons authorized by policy, delegation, incident protocol, officer authority, Board authority, controlled-room charter, repository governance, data governance, public-safe publication rules, or emergency protective authority.

522.27.3 Stop-the-Line action shall be recorded, triaged, reviewed, ratified where required, sunsetted, and closed or converted into corrective action.

#### 522.28 “Hold.”

522.28.1 “Hold” means a temporary or continuing restriction placed on a record, dataset, system, model, repository, publication, technical asset, release, room, access, claim, interface, contract, distribution, transfer, deletion, or action pending review, investigation, correction, approval, legal hold, or closeout.

522.28.2 Holds may include legal holds, data holds, AI holds, repository holds, publication holds, controlled-room holds, model holds, technical asset holds, public authority reference holds, finance-boundary holds, distribution holds, transfer holds, and wind-up holds.

#### 522.29 “Quarantine.”

522.29.1 “Quarantine” means isolation or segregation of a system, repository, dataset, file, model, output, record, credential, user, device, artifact, publication, technical asset, or environment to prevent further access, spread, reliance, misuse, contamination, corruption, exposure, or harm.

522.29.2 Quarantine may be used for cybersecurity incidents, data contamination, AI output defects, repository compromise, malware, secrets exposure, evidence integrity concerns, protected knowledge exposure, publication defects, or boundary incidents.

#### 522.30 “Re-Scope.”

522.30.1 “Re-Scope” means narrowing, revising, limiting, reframing, separating, segmenting, reclassifying, or redefining an activity, record, output, publication, dataset, model, room, repository, technical asset, public authority interface, finance interface, sponsor relationship, provider relationship, Nexus interface, or public claim to align with authority, risk, safeguards, public-safe status, or records.

522.30.2 Re-Scope may be required where original scope would create overclaim, public authority confusion, finance-boundary misuse, certification or recognition confusion, procurement implication, data misuse, protected knowledge exposure, or public-safe risk.

#### 522.31 “Suspension.”

522.31.1 “Suspension,” for purposes of risk, compliance, incident, enforcement, and stop-the-line definitions, means temporary removal, pause, restriction, deactivation, hold, or non-current status applied to a person, role, access, room, repository, dataset, model, technical asset, release, publication, claim, interface, authority, permission, or activity pending review, correction, investigation, or final decision.

522.31.2 Suspension shall identify scope, effective date, owner, trigger, conditions, review date, permitted exceptions, and re-entry process.

#### 522.32 “Termination.”

522.32.1 “Termination” means final ending of a role, employment, contract, participation, access, license, room, repository, interface, authority, delegation, publication status, technical asset support, sponsorship, grant, agreement, or activity according to law, contract, policy, Board action, officer action, enforcement action, or closeout record.

522.32.2 Termination shall not extinguish surviving duties concerning confidentiality, records, legal holds, IP, data / AI / cyber / privacy, public authority boundaries, finance boundaries, certification and recognition boundaries, protected knowledge, non-retaliation, indemnification, advancement, insurance, correction, or archive custody where such duties survive by law, contract, policy, or these Bylaws.

#### 522.33 Risk, Incident, and Enforcement Definition Records.

522.33.1 The Corporation shall maintain Risk, Incident, and Enforcement Definition Records, including Risk records, Risk Register records, Issue Register records, Control Register records, KPI records, KRI records, Corrective Action records, Compliance records, Legal Hold records, Incident records, Boundary Incident records, Public Authority Boundary Incident records, Finance Boundary Incident records, Role-Collapse Incident records, Interface Misuse records, Cybersecurity Incident records, Privacy Incident records, Protected Knowledge Incident records, Public-Safe Publication Incident records, Misrepresentation records, Overclaim records, Investigation records, Interim Measure records, Enforcement records, Remedy records, Referral records, Stop-the-Line records, Hold records, Quarantine records, Re-Scope records, Suspension records, Termination records, correction records, referral records, and archive records.

***

### Section 523. Reserved Terms Requiring Competent Record Before Use

#### 523.1 Reserved Term Purpose.

523.1.1 Reserved Terms Requiring Competent Record Before Use shall protect the Corporation’s public-benefit mission, public trust, public-good stack integrity, public authority boundaries, finance boundaries, certification boundaries, recognition boundaries, procurement neutrality, provider neutrality, sponsor non-control, technical truth, public-safe publication, Nexus role separation, and validity-by-record doctrine.

523.1.2 A Reserved Term shall not be used in public materials, publications, websites, repositories, dashboards, maps, datasets, software notices, technical baselines, grant applications, proposals, media statements, social media, event materials, public authority communications, sponsor materials, provider materials, Nexus materials, archive statements, or AI-generated content unless supported by a competent Authoritative Record, reviewed under the applicable controlled vocabulary rules, and limited to the approved scope.

523.1.3 Use of a Reserved Term without competent record shall have no public meaning and shall be corrected, withdrawn, retracted, taken down, clarified, or otherwise remedied where material.

#### 523.2 “Official.”

523.2.1 “Official” is a Reserved Term when used to imply legal authority, public authority authority, institutional authority, final status, Board approval, officer approval, public authority approval, Nexus authority, GRF authority, GRA authority, certification, recognition, procurement approval, or public warning.

523.2.2 “Official” may be used only where an Authoritative Record identifies the source of official status, scope, effective date, owner, custodian, and limitations.

523.2.3 The word “official” shall not be used to describe drafts, informal summaries, AI summaries, slides, working materials, public authority attendance, sponsor support, provider participation, or Nexus participation unless competent authority supports that use.

#### 523.3 “Approved.”

523.3.1 “Approved” is a Reserved Term when used to imply approval by the Board, officer, committee, public authority, regulator, procurement authority, finance authority, certification body, recognition authority, Nexus authority, GRF, GRA, or other competent authority.

523.3.2 “Approved” shall identify who approved, what was approved, for what purpose, on what date, within what scope, and subject to what limitations.

523.3.3 “Approved” shall not be used to imply legal compliance, public authority endorsement, finance-readiness, insurance-readiness, procurement approval, certification, recognition, provider preference, public warning, emergency command, or operational approval unless competent record expressly provides such meaning.

#### 523.4 “Certified.”

523.4.1 “Certified” is a Reserved Term requiring a competent certification program, certification authority, certification record, scope, criteria, method, limitations, effective date, and status.

523.4.2 GCRI US shall not be described as certifying persons, providers, products, projects, systems, models, datasets, technical assets, public authorities, public-good outputs, or Nexus interfaces unless a lawful and authorized certification program exists and the specific certification record supports the claim.

523.4.3 Public-good technical baselines, evidence records, verification records, validation records, proof receipts, benchmarks, test harnesses, dashboards, maps, software releases, or public-safe publications shall not be called “certified” by default.

#### 523.5 “Accredited.”

523.5.1 “Accredited” is a Reserved Term requiring competent accreditation authority, accreditation criteria, accreditation record, scope, effective date, and limitations.

523.5.2 GCRI US shall not represent any body, provider, reviewer, laboratory, training, Academy activity, model, system, process, or technical asset as accredited unless competent accreditation authority supports the statement.

#### 523.6 “Compliant.”

523.6.1 “Compliant” is a Reserved Term when used to imply legal, regulatory, contractual, technical, standards, procurement, data, AI, cybersecurity, privacy, public authority, finance, or professional compliance.

523.6.2 “Compliant” shall not be used unless the relevant requirement, review method, reviewer authority, scope, date, limitations, and record support are identified.

523.6.3 A standards mapping, evidence review, technical baseline, proof receipt, dashboard, map, software release, or method note shall not be described as establishing compliance unless competent authority expressly provides such meaning.

#### 523.7 “Conformant.”

523.7.1 “Conformant” is a Reserved Term when used to imply that a system, product, provider, technical asset, dataset, model, API, SDK, schema, baseline, or implementation satisfies a specified standard, profile, test, protocol, or benchmark.

523.7.2 “Conformant” shall identify the standard or profile, version, test basis, scope, reviewer, date, limitations, and authority.

523.7.3 Conformance shall not imply certification, procurement approval, public authority adoption, finance-readiness, recognition, rating, or Nexus-compatible status unless competent authority separately provides that meaning.

#### 523.8 “Verified.”

523.8.1 “Verified” is a Reserved Term when used to imply that a claim, record, source, dataset, model, output, proof receipt, computation, technical asset, public authority reference, finance-boundary statement, or public claim has been checked and confirmed.

523.8.2 “Verified” shall identify what was verified, by whom, against what reference, using what method, on what date, within what scope, and subject to what limitations.

523.8.3 Verification shall not imply certification, recognition, finance-readiness, procurement approval, public authority approval, rating, public warning, or emergency command.

#### 523.9 “Validated.”

523.9.1 “Validated” is a Reserved Term when used to imply that a method, model, dataset, system, software, technical baseline, dashboard, map, proof receipt, or output has been assessed as fit for a stated purpose.

523.9.2 “Validated” shall identify purpose, scope, validation method, reviewer, date, evidence basis, limitations, and correction path.

523.9.3 Validation shall not imply general approval, certification, legal compliance, public authority approval, finance-readiness, recognition, procurement approval, rating, public warning, or emergency command.

#### 523.10 “Recognized.”

523.10.1 “Recognized” is a Reserved Term requiring competent recognition authority, recognition record, scope, effective date, conditions, limitations, and public-safe language.

523.10.2 Recognition is presumptively a GRF-related function within the Nexus public-good stack unless another competent record provides otherwise.

523.10.3 GCRI US evidence, methods, publications, dashboards, maps, proof receipts, technical baselines, software releases, public authority learning materials, or Nexus inputs shall not be described as recognizing an entity, project, provider, system, technical asset, public authority, or initiative without competent recognition record.

#### 523.11 “Mature.”

523.11.1 “Mature” is a Reserved Term when used to imply maturity status, maturity level, maturity recognition, readiness stage, Grid maturity, implementation maturity, technical maturity, public authority maturity, safeguards maturity, or finance maturity.

523.11.2 “Mature” shall identify the maturity framework, authority, evidence basis, method, scope, date, limitations, and correction path.

523.11.3 “Mature” shall not imply certification, finance-readiness, procurement approval, public authority approval, rating, recognition, provider preference, or operational readiness unless competent authority expressly provides such meaning.

#### 523.12 “Standing.”

523.12.1 “Standing” is a Reserved Term when used to imply registry status, recognition status, public legitimacy, maturity posture, eligibility, acceptance, Docket posture, Grid posture, public-good status, or institutional legitimacy.

523.12.2 Standing shall require competent record, authority, scope, conditions, limitations, effective date, and correction path.

523.12.3 GCRI US shall not create GRF Standing by default.

#### 523.13 “Nexus-Compatible.”

523.13.1 “Nexus-Compatible” is a Reserved Term requiring competent Nexus authority, compatibility record, scope, version, applicable profile, test basis where applicable, limitations, and effective date.

523.13.2 Use, fork, integration, API connection, schema adoption, technical baseline implementation, public-good software use, Docket input, Grid input, public authority participation, provider participation, or sponsor support shall not automatically create Nexus-Compatible status.

#### 523.14 “Finance-Ready.”

523.14.1 “Finance-Ready” is a Reserved Term requiring competent GRA or finance-boundary authority, finance-readiness record, scope, limitations, effective date, and non-reliance language.

523.14.2 GCRI US shall not describe its outputs as Finance-Ready by default.

523.14.3 “Finance-Ready” shall not be used to imply investment advice, securities offering, lending approval, insurance approval, rating, public finance approval, public guarantee, procurement approval, recognition, or certification.

#### 523.15 “Insurance-Ready.”

523.15.1 “Insurance-Ready” is a Reserved Term requiring competent GRA or insurance-boundary authority, insurance-readiness record, scope, limitations, and non-reliance language.

523.15.2 “Insurance-Ready” shall not imply insurance placement, binding, underwriting, pricing, claims handling, approval, guarantee, rating, or insurability determination by GCRI US.

#### 523.16 “Bankable.”

523.16.1 “Bankable” is a Reserved Term when used to imply financeability, lender acceptance, creditworthiness, project finance suitability, capital commitment, investment quality, or public finance viability.

523.16.2 “Bankable” shall not be used in GCRI US public materials unless reviewed under finance-boundary controls and supported by competent non-GCRI US authority.

#### 523.17 “Investable.”

523.17.1 “Investable” is a Reserved Term when used to imply investment suitability, investment quality, capital readiness, investor acceptance, securities readiness, or financeability.

523.17.2 GCRI US shall not use “Investable” to describe projects, providers, companies, SPVs, assets, funds, portfolios, or opportunities unless competent finance authority supports the statement and the statement is not investment advice or securities solicitation.

#### 523.18 “Capital-Readable.”

523.18.1 “Capital-Readable” is a Reserved Term requiring competent GRA or finance-boundary authority, capital-readability record, scope, limitations, and non-reliance language.

523.18.2 Capital-readable status shall not imply investability, bankability, finance-readiness, lending approval, insurance approval, rating, public finance approval, or capital commitment.

#### 523.19 “Rated.”

523.19.1 “Rated” is a Reserved Term when used to imply a grade, score, rating, credit opinion, resilience rating, financeability rating, insurability rating, public finance rating, procurement score, provider ranking, maturity rating, or public authority rating.

523.19.2 GCRI US shall not use “Rated” unless the rating authority, methodology, scope, limitations, and lawful authority are clear and the term does not imply regulated rating activity by GCRI US.

#### 523.20 “Guaranteed.”

523.20.1 “Guaranteed” is a Reserved Term requiring express legal authority to make a guarantee, scope, obligations, party, conditions, and approval.

523.20.2 GCRI US evidence, methods, proof receipts, dashboards, maps, datasets, software, technical baselines, publications, Nexus interfaces, public authority participation, or GRA / GRF references shall not be described as guaranteeing accuracy, safety, finance-readiness, public authority approval, procurement approval, recognition, certification, performance, repayment, insurability, or outcomes.

#### 523.21 “Public-Safe.”

523.21.1 “Public-Safe” is a Reserved Term requiring public-safe review, classification, limitations, scope, and record support when used to describe a publication, dataset, map, dashboard, summary, technical asset, software release, public authority reference, archive statement, or public claim.

523.21.2 “Public-Safe” shall not imply risk-free, harm-free, fully accurate, public authority-approved, emergency-ready, certified, finance-ready, recognition-ready, procurement-approved, or legally compliant.

#### 523.22 “Official Public Authority.”

523.22.1 “Official Public Authority” is a Reserved Term requiring competent public authority record, official capacity record, public authority authorization, scope, and approved language.

523.22.2 GCRI US shall not describe itself, its events, rooms, outputs, dashboards, maps, publications, public authority learning materials, or Nexus interfaces as Official Public Authority unless law and competent public authority records expressly provide such status.

#### 523.23 “Public Authority Endorsed.”

523.23.1 “Public Authority Endorsed” is a Reserved Term requiring express public authority approval or endorsement record, approved language, scope, date, and limitations.

523.23.2 Public authority attendance, observation, data contribution, grant support, public finance reader participation, regulator-listening participation, emergency-management participation, or room participation shall not be described as Public Authority Endorsed.

#### 523.24 “Public Authority Approved.”

523.24.1 “Public Authority Approved” is a Reserved Term requiring competent public authority approval record, legal authority, approved language, scope, effective date, and limitations.

523.24.2 GCRI US outputs shall not be described as Public Authority Approved merely because a public authority participated, reviewed, received, funded, observed, or discussed them.

#### 523.25 “Public Warning.”

523.25.1 “Public Warning” is a Reserved Term reserved to competent public authority or other lawful warning authority.

523.25.2 GCRI US shall not describe its outputs, dashboards, maps, observability outputs, reports, AI outputs, proof receipts, public-safe summaries, or Nexus interface materials as Public Warnings.

#### 523.26 “Emergency Ready.”

523.26.1 “Emergency Ready” is a Reserved Term when used to imply readiness for emergency operations, public warning, incident command, public safety command, public health order, dispatch, evacuation, operational resource direction, or emergency deployment.

523.26.2 GCRI US shall not use “Emergency Ready” for its tools, methods, dashboards, maps, technical baselines, software, simulations, or publications unless competent authority supports a defined and non-command meaning.

#### 523.27 “Operationally Approved.”

523.27.1 “Operationally Approved” is a Reserved Term requiring competent operational authority, scope, conditions, effective date, and limitations.

523.27.2 GCRI US does not operationally approve projects, providers, public authorities, technologies, technical assets, emergency systems, infrastructure systems, AI systems, or enterprise implementations by default.

#### 523.28 “Procurement-Ready.”

523.28.1 “Procurement-Ready” is a Reserved Term when used to imply eligibility, preference, qualification, tender readiness, approved vendor status, bid advantage, specification compliance, or procurement approval.

523.28.2 GCRI US shall not use “Procurement-Ready” unless competent procurement authority or authorized procurement framework supports the statement, and GCRI US has confirmed that the statement does not create procurement authority or provider preference by GCRI US.

#### 523.29 “Preferred Provider.”

523.29.1 “Preferred Provider” is a Reserved Term when used to imply that a vendor, provider, host, sponsor, contractor, technology, platform, software, model, AI provider, cloud provider, cybersecurity provider, telecom provider, infrastructure provider, or enterprise actor is preferred, endorsed, ranked, selected, or advantaged.

523.29.2 GCRI US shall not designate Preferred Providers by default and shall correct any use of provider participation, sponsorship, support, contribution, technical integration, or public-good collaboration that implies Preferred Provider status without authority.

#### 523.30 “Strategic Partner” Where It May Imply Authority or Preference.

523.30.1 “Strategic Partner” is a Reserved Term where it may imply governance authority, public authority status, provider preference, sponsor control, procurement advantage, finance-readiness, recognition, certification, public authority approval, authority to bind GCRI US, or Nexus authority.

523.30.2 “Strategic Partner” may be used only where the relationship is recorded, scope-limited, approved, public-safe, and accompanied by no-endorsement, no-control, no-authority, and role-separation language where appropriate.

#### 523.31 “North America Anchor” Where It May Imply Sovereign or Public Authority Status.

523.31.1 “North America Anchor” is a Reserved Term when used to describe GCRI US or its role in North America coordination, public authority learning, technical evidence, methods, observability, ontology, public-good software, technical baselines, or Nexus interfaces.

523.31.2 “North America Anchor” shall not imply sovereign authority, treaty authority, intergovernmental authority, public authority status, Canadian authority, Mexican authority, Caribbean authority, Arctic authority, public finance approval, public warning, emergency command, procurement authority, recognition authority, finance authority, certification authority, or enterprise execution.

523.31.3 Use of “North America Anchor” shall be accompanied by scope and role-separation language where public confusion risk exists.

#### 523.32 “GCRI-Approved” Where It May Imply Certification.

523.32.1 “GCRI-Approved” is a Reserved Term where it may imply certification, procurement approval, public authority approval, finance-readiness, recognition, provider preference, compliance approval, operational approval, public warning, or emergency command.

523.32.2 “GCRI-Approved” shall not be used in public claims unless a competent GCRI US record expressly identifies the approval, approving authority, scope, limitations, effective date, and boundaries.

523.32.3 Approval of internal use, publication, repository release, technical review, or public-safe classification shall not be described as GCRI-Approved in a way that implies external certification or approval.

#### 523.33 Reserved Term Records.

523.33.1 The Corporation shall maintain Reserved Term Records, including Reserved Term Purpose records, Official records, Approved records, Certified records, Accredited records, Compliant records, Conformant records, Verified records, Validated records, Recognized records, Mature records, Standing records, Nexus-Compatible records, Finance-Ready records, Insurance-Ready records, Bankable records, Investable records, Capital-Readable records, Rated records, Guaranteed records, Public-Safe records, Official Public Authority records, Public Authority Endorsed records, Public Authority Approved records, Public Warning records, Emergency Ready records, Operationally Approved records, Procurement-Ready records, Preferred Provider records, Strategic Partner records where it may imply authority or preference, North America Anchor records where it may imply sovereign or public authority status, GCRI-Approved records where it may imply certification, competent authority records, controlled vocabulary review records, public-safe review records, correction records, and archive records.

***

### Section 524. Prohibited Public Uses Without Express Authority

#### 524.1 Prohibited Public Use Purpose.

524.1.1 Prohibited Public Uses Without Express Authority shall prevent public confusion, unsupported public meaning, public authority overclaim, finance-boundary overclaim, certification overclaim, recognition overclaim, procurement implication, provider preference, public warning confusion, emergency command confusion, sponsor distortion, provider distortion, Nexus role collapse, public-good asset enclosure, and misuse of GCRI US evidence, methods, public-good software, technical baselines, dashboards, maps, datasets, proof receipts, repositories, publications, and Nexus interface outputs.

524.1.2 The prohibitions in this Section apply to directors, officers, employees, contractors, fellows, advisors, volunteers, contributors, maintainers, reviewers, committees, councils, working groups, panels, sponsors, donors, funders, providers, hosts, partners, public authority participants, capital readers, universities, laboratories, communities, media, successor stewards, repository custodians, and any person using Corporation names, marks, materials, records, outputs, or references.

524.1.3 A prohibited public use may occur through oral statements, written statements, websites, decks, proposals, grant applications, sponsor materials, provider materials, public authority materials, media statements, social media, dashboards, maps, datasets, repository readme files, software documentation, technical baseline notices, public-safe summaries, AI-generated content, archive statements, logos, seals, badges, labels, citations, or implied associations.

#### 524.2 No Use of “Certified by GCRI US” Without Authorized Certification Program.

524.2.1 No person shall use “Certified by GCRI US,” “GCRI-certified,” “certified under GCRI,” “certified by The Global Centre for Risk and Innovation,” or equivalent language unless the Corporation has lawfully adopted an authorized certification program, the specific certification has been granted under that program, and the applicable Authoritative Record supports the use.

524.2.2 No evidence review, method review, verification, validation, proof receipt, benchmark result, software release, technical baseline, public authority learning session, public-good publication, dashboard, map, Docket input, Grid input, GRF input, GRA input, Nexus interface, or controlled-room participation shall be described as certification by GCRI US.

#### 524.3 No Use of “Approved by GCRI US” to Imply Legal, Public Authority, Procurement, Finance, Insurance, Investment, or Operational Approval.

524.3.1 No person shall use “Approved by GCRI US,” “GCRI US approved,” “approved by The Global Centre for Risk and Innovation,” or equivalent language to imply legal compliance approval, public authority approval, regulatory approval, procurement approval, provider approval, finance-readiness, insurance approval, investment approval, lending approval, rating, public finance approval, operational approval, safety approval, public warning, emergency command, or public health order.

524.3.2 Where “approved” is used for internal administrative purposes, the statement shall identify the limited internal approval, approving authority, scope, and limitations and shall not be used externally in a misleading way.

#### 524.4 No Use of “Recognized by GCRI US” to Imply GRF Recognition.

524.4.1 No person shall use “Recognized by GCRI US,” “GCRI-recognized,” “recognized under GCRI,” or equivalent language to imply GRF recognition, public-facing legitimacy, registry status, standing, maturity status, stakeholder-formation status, or public legitimacy unless competent recognition authority and Authoritative Records expressly support the statement.

524.4.2 GCRI US evidence, methods, public-good software, technical baselines, proof receipts, dashboards, maps, public-safe summaries, public authority learning materials, or Nexus inputs shall not be described as recognition unless the term is narrowly used within a recorded technical context that cannot reasonably be confused with GRF recognition.

#### 524.5 No Use of “Finance-Ready by GCRI US” to Imply GRA Finance-Readiness.

524.5.1 No person shall use “Finance-Ready by GCRI US,” “GCRI finance-ready,” “capital-ready through GCRI,” “GCRI-approved for finance,” or equivalent language to imply GRA finance-readiness, capital-readability, investment suitability, bankability, financeability, lending approval, public finance approval, insurance approval, rating, guarantee, securities suitability, or capital commitment.

524.5.2 GCRI US technical evidence, methods, proof receipts, observability records, dashboards, maps, public-good software, technical baselines, and Nexus interface inputs may support GRA processes only as technical inputs and shall not be represented as finance-readiness determinations by GCRI US.

#### 524.6 No Use of “Insurance-Ready by GCRI US” to Imply Insurance Approval.

524.6.1 No person shall use “Insurance-Ready by GCRI US,” “GCRI insurance-ready,” “insured by GCRI,” “underwritten by GCRI,” “GCRI-approved for insurance,” or equivalent language to imply insurance placement, underwriting, pricing, binding, claims handling, insurance approval, insurability, reinsurance approval, risk transfer approval, or guarantee.

524.6.2 GCRI US shall not be represented as an insurer, reinsurer, insurance broker, insurance adviser, underwriter, claims handler, insurance rating body, or insurance approval authority.

#### 524.7 No Use of “Public Authority Endorsed” Without Public Authority Record.

524.7.1 No person shall use “Public Authority Endorsed,” “government-endorsed,” “agency-endorsed,” “regulator-endorsed,” “public authority supported,” “officially backed,” or equivalent language unless a competent public authority record expressly authorizes the specific statement.

524.7.2 Public authority attendance, observer status, regulator-listening status, public finance reader status, emergency-management participation, public grant support, public authority data contribution, room participation, event attendance, or receipt of materials shall not be represented as endorsement.

524.7.3 Public authority references shall use capacity classification and non-endorsement language where material.

#### 524.8 No Use of “Emergency Warning” or “Public Warning” for GCRI US Outputs.

524.8.1 No person shall describe GCRI US reports, dashboards, maps, observability outputs, AI outputs, digital twin outputs, sensor signals, AI-RAN signals, O-RAN signals, DePIN records, DLT records, proof receipts, public-safe summaries, technical notes, datasets, or publications as “Emergency Warning,” “Public Warning,” “official warning,” “alert,” “evacuation notice,” “public health order,” “safety command,” or equivalent language.

524.8.2 GCRI US outputs may be public-safe, evidence-based, limitation-aware, and non-command, but shall not be used as official public warnings, emergency alerts, incident command, dispatch, evacuation instruction, public health order, safety command, or operational resource direction.

#### 524.9 No Use of “Procurement Approved” or “Preferred Vendor” Based on GCRI US Participation.

524.9.1 No person shall use “Procurement Approved,” “approved vendor,” “preferred vendor,” “preferred provider,” “GCRI-approved provider,” “Nexus-approved vendor,” “public procurement ready,” “shortlisted by GCRI,” or equivalent language based on GCRI US participation, evidence review, technical baseline use, software use, event participation, sponsorship, provider support, controlled-room participation, public authority attendance, or Nexus interface participation.

524.9.2 Provider participation in GCRI US activities shall not create procurement advantage, preferred status, procurement eligibility, approved vendor status, certification, recognition, finance-readiness, public authority approval, or public tender advantage.

#### 524.10 No Use of “Official Nexus Authority” Without Competent Nexus Record.

524.10.1 No person shall use “Official Nexus Authority,” “Nexus authority,” “authorized by Nexus,” “Nexus-approved,” “official Nexus,” “Nexus-mandated,” or equivalent language unless a competent Nexus record identifies the authority, scope, effective date, limitations, and approving body.

524.10.2 GCRI US participation in Nexus coordination, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Standards support, public authority learning, public-good software, or technical baselines shall not make GCRI US the official authority for all Nexus functions.

524.10.3 Use of Nexus names shall preserve legal separateness, one rail / two stacks discipline, GCRI / GRF / GRA role separation, public-good stack and enterprise stack distinction, and no-authority-to-bind rules.

#### 524.11 No Use of “Sovereign,” “Mandated,” “Government-Approved,” or Equivalent Terms Without Competent Public Authority Record.

524.11.1 No person shall use “sovereign,” “sovereign-backed,” “government-mandated,” “government-approved,” “state-approved,” “federally approved,” “publicly mandated,” “official mandate,” “nationally mandated,” “treaty-backed,” “intergovernmental,” “public-private partnership,” or equivalent language for GCRI US, its outputs, Nexus interfaces, technical assets, public authority learning materials, or public-good activities unless competent public authority record and legal authority expressly support the statement.

524.11.2 “North America Anchor,” “United States Anchor,” “state interface,” “territorial interface,” “Tribal interface,” or similar terms shall not be used to imply sovereign authority, treaty authority, public authority delegation, government mandate, public finance approval, public warning, emergency command, procurement authority, or regulatory authority.

#### 524.12 No Use of “Rating,” “Grade,” or “Score” Where It Implies Regulated Rating, Finance, Insurance, Procurement, Recognition, or Public Authority Determination.

524.12.1 No person shall use “rating,” “grade,” “score,” “investment grade,” “credit grade,” “resilience rating,” “insurability rating,” “bankability score,” “financeability rating,” “procurement score,” “provider score,” “public authority score,” “risk grade,” or equivalent language where it implies regulated rating, finance, insurance, lending, public finance, procurement, recognition, public authority determination, certification, or provider preference without competent authority.

524.12.2 Internal technical metrics, confidence scores, KPIs, KRIs, benchmark results, maturity concepts, or quality indicators shall be labeled and limited to their actual scope and shall not be converted into public ratings or procurement scores by implication.

#### 524.13 No Use of AI, Dashboard, Map, Proof Receipt, Ledger, Sensor, AI-RAN, DePIN, Digital Twin, or Model Output as Authority Without Record and Review.

524.13.1 No person shall use or describe an AI output, dashboard output, map output, proof receipt, ledger entry, sensor signal, AI-RAN signal, O-RAN signal, DePIN record, DLT record, blockchain record, digital twin output, model output, inference record, compute workload record, observability output, Truth Engine output, benchmark output, or automated output as authority unless an Authoritative Record, qualified review, classification, public-safe status, scope, limitations, and correction path support the use.

524.13.2 Such outputs shall not be treated as self-validating, self-executing, self-certifying, self-recognizing, finance-ready, public authority-approved, procurement-approved, rated, guaranteed, public warning, emergency command, or legal compliance determination merely because they exist, were generated, were signed, were timestamped, were recorded on a ledger, were produced by a model, or were displayed in a dashboard.

524.13.3 Material use of such outputs shall require source lineage, method record, authority record, human review where required, data / AI / cyber / privacy review where required, public authority review where required, safeguards review where required, and public-safe review where required.

#### 524.14 Prohibited Public Use Correction.

524.14.1 Any prohibited public use, unsupported reserved term, overclaim, misrepresentation, boundary-defective statement, public authority overclaim, finance-boundary overclaim, certification overclaim, recognition overclaim, procurement implication, provider-preference implication, public warning implication, emergency command implication, or unauthorized Nexus authority claim shall be corrected.

524.14.2 Correction may include direct correction, public-safe correction, controlled correction, website update, repository notice, publication correction, dashboard or map notice, dataset notice, software notice, technical baseline notice, archive annotation, social media correction, media correction, grant or proposal correction, sponsor material correction, provider material correction, public authority notice, GRF notice, GRA notice, Nexus interface notice, takedown, supersession, withdrawal, retraction, access restriction, contract remedy, enforcement action, legal referral, public authority referral, funder referral, grantor referral, regulator referral, or law enforcement referral where required or appropriate.

524.14.3 Correction shall be proportionate to severity, reliance risk, public-safe risk, legal risk, public authority risk, finance risk, recognition risk, certification risk, procurement risk, protected knowledge risk, and Nexus coordination risk.

524.14.4 Correction may be made without admission where appropriate, provided that the corrected public meaning is accurate, record-supported, and public-safe.

#### 524.15 Prohibited Public Use Records.

524.15.1 The Corporation shall maintain Prohibited Public Use Records, including Prohibited Public Use Purpose records, prohibited “Certified by GCRI US” use records, prohibited “Approved by GCRI US” use records, prohibited “Recognized by GCRI US” use records, prohibited “Finance-Ready by GCRI US” use records, prohibited “Insurance-Ready by GCRI US” use records, prohibited “Public Authority Endorsed” use records, prohibited “Emergency Warning” or “Public Warning” use records, prohibited “Procurement Approved” or “Preferred Vendor” use records, prohibited “Official Nexus Authority” use records, prohibited “Sovereign,” “Mandated,” “Government-Approved,” or equivalent use records, prohibited “Rating,” “Grade,” or “Score” use records, prohibited AI / dashboard / map / proof receipt / ledger / sensor / AI-RAN / DePIN / digital twin / model output authority-use records, correction records, takedown records, supersession records, withdrawal records, retraction records, public authority notice records, GRF notice records, GRA notice records, Nexus notice records, enforcement records, referral records, and archive records.

<br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.therisk.global/organization/organization/governance/bylaws/gcri-us/article-xviii.-definitions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
