For the complete documentation index, see llms.txt. This page is also available as Markdown.

II. IDENTITY

2.1 Constitutional Establishment and Identity of GCRI Canada

2.1.1 Establishment of The Global Centre for Risk and Innovation - Canada as a Canadian Public-Benefit Institution. 2.1.1(a) The Global Centre for Risk and Innovation - Canada (“GCRI Canada”) is established as a Canadian public-benefit institution for the disciplined stewardship of evidence, methods, observability, ontology, technical truth, public-good research and development, public-good software, open technical baselines, verifiable compute methods, verifiable intelligence methods, public authority learning, community safeguards, protected knowledge discipline, public-safe publication, and systemic de-risking across exponential, mission-critical, infrastructure-relevant, and public-benefit technologies. 2.1.1(b) GCRI Canada shall be understood as a durable institutional public-good anchor and not as a temporary project, advocacy campaign, consulting vehicle, event brand, vendor platform, public authority proxy, finance vehicle, grant-delivery wrapper, research-only association, deployment company, market actor, or execution enterprise. 2.1.1(c) The establishment of GCRI Canada shall be interpreted as a commitment to Canadian public-benefit capacity capable of receiving, structuring, testing, preserving, translating, publishing where public-safe, correcting, and stewarding evidence and methods in forms that are institutionally usable without converting such evidence or methods into downstream authority by implication. 2.1.1(d) GCRI Canada’s constitutional identity shall be grounded in continuity, bounded authority, lawful stewardship, semantic discipline, evidence integrity, technical credibility, public trust, correctionability, and non-execution. 2.1.1(e) GCRI Canada’s identity shall not be weakened, expanded, or distorted by the novelty of the technologies it studies, the scale of the risks it addresses, the urgency of public-interest contexts, the importance of public authorities or partners with which it interacts, the sophistication of its technical assets, the visibility of its publications, the value of its evidence to downstream actors, or the public reliance that may attach to its work. 2.1.1(f) GCRI Canada shall maintain its establishment as a Canadian public-benefit institution across all forms of activity, including research, observability, ontology, technical architecture, public-good software, AI-assisted analysis, public authority learning, community engagement, publications, controlled rooms, data rooms, repositories, dashboards, Academy materials, Nexus interfaces, sponsorship arrangements, grant-funded programs, and public communications. 2.1.1(g) No activity shall be treated as outside this constitutional establishment merely because it is experimental, technical, digital, cross-border, partner-supported, public authority-facing, sponsor-supported, AI-assisted, software-based, field-based, time-sensitive, or described as a pilot. 2.1.1(h) GCRI Canada’s establishment shall be read to preserve the institution as an upstream public-good truth, evidence, methods, observability, ontology, public-good R&D, public-good software, and technical-stewardship institution whose outputs support lawful decision-making by others without making GCRI Canada the downstream decision-maker.

2.1.2 GCRI Canada as a Nonprofit, Non-Share, Non-Distributing, Non-Executing Public-Good Steward. 2.1.2(a) GCRI Canada shall be governed and operated as a nonprofit, non-share or equivalent non-equity, non-distributing, non-executing public-good steward. 2.1.2(b) No director, officer, member, participant, sponsor, donor, funder, provider, host, contractor, fellow, advisor, founder, public authority participant, capital reader, related party, contributor, technical maintainer, institutional partner, or private person shall acquire any ownership interest in GCRI Canada’s mission, institutional identity, evidence records, methods, ontology, software, repositories, public-good technical core, technical baselines, public authority interfaces, public-safe outputs, correction records, institutional goodwill, records authority, public meaning, or Nexus-compatible stewardship function. 2.1.2(c) GCRI Canada’s assets shall be used to advance its public-benefit purposes and shall not be distributed, pledged, enclosed, licensed, transferred, marketed, assigned, encumbered, captured, or deployed in a manner that creates improper private benefit, private inurement, excess benefit, hidden extraction, provider advantage, sponsor control, public authority access purchase, procurement preference, finance-readiness purchase, public-good enclosure, technical dependency capture, or execution leverage. 2.1.2(d) The non-distribution principle shall apply not only to money and property, but also to intangible public-good value, including evidence access, data access, public authority proximity, community access, protected knowledge, technical baselines, controlled vocabulary, public-safe publication surfaces, institutional goodwill, Nexus-compatible language, and public meaning. 2.1.2(e) Reasonable compensation, reimbursement, contractor payment, fellow support, expert honoraria, institutional procurement, lawful cost recovery, and mission-compatible program revenue may occur only where properly authorized, documented, conflict-managed, proportionate, reasonable, and subordinate to GCRI Canada’s public-benefit, non-distribution, non-execution, anti-capture, and anti-enclosure obligations. 2.1.2(f) GCRI Canada shall not issue shares, equity rights, dividend rights, profit participations, beneficial ownership claims, mission ownership rights, technical-core ownership rights, or other instruments that confer proprietary interest in the institution or its public-good assets. 2.1.2(g) No funding arrangement, sponsorship, grant, donation, subscription, membership, training fee, in-kind contribution, cloud credit, data contribution, technical contribution, hosting arrangement, public authority participation, or provider support shall be interpreted as purchasing authority, preferred status, evidence outcome, publication control, correction suppression, public authority access, provider advantage, finance-readiness implication, recognition implication, procurement implication, or public-good legitimacy. 2.1.2(h) GCRI Canada’s non-executing character shall be treated as a constitutional protection and not as a temporary operating preference. It exists to preserve independence, public trust, evidence integrity, methods discipline, public authority safety, finance-boundary safety, provider neutrality, sponsor non-control, and separation between public-good stewardship and downstream execution.

2.1.3 GCRI Canada as a Non-Charitable Institution Unless and Until Lawfully Changed. 2.1.3(a) Unless and until GCRI Canada lawfully obtains, adopts, or is recognized as holding charitable status under applicable Canadian law, and such status is properly recorded, publicly described, governance-integrated, tax-compliant, and operationally implemented, GCRI Canada shall not represent itself as a registered charity or imply charitable status, charitable receipting authority, charity-law privileges, charity-law registration, or charity-specific public representations. 2.1.3(b) GCRI Canada’s public-benefit mandate shall be real, binding, and substantive regardless of charitable registration. Public-benefit character shall not be reduced to a tax label, fundraising category, communications posture, or symbolic public-interest claim. 2.1.3(c) Public-benefit character shall govern governance, mission, fiduciary decision-making, funding, sponsorship, grants, donations, research integrity, methods integrity, public-safe publication, anti-capture discipline, anti-enclosure discipline, public authority boundaries, finance boundaries, data rights, cybersecurity, AI governance, protected knowledge, Indigenous and community safeguards, accessibility, competition safety, records integrity, correctionability, and legal separateness. 2.1.3(d) If charitable status is later pursued, obtained, rejected, withdrawn, modified, suspended, revoked, or replaced by another lawful status, such change shall not dilute GCRI Canada’s non-execution, legal separateness, Public-Good Stack and Enterprise Stack separation, sponsor non-control, provider neutrality, finance-boundary discipline, public authority boundary discipline, privacy obligations, cybersecurity obligations, Indigenous and protected knowledge safeguards, public-safe publication discipline, or correctionability. 2.1.3(e) Any change in charitable or tax status shall be adopted only through lawful process, competent authority, proper records, public-safe description where appropriate, and review of implications for mission lock, funding terms, public representations, receipting, governance, reporting, contracts, data handling, sponsorship, and public claims. 2.1.3(f) No director, officer, staff member, sponsor, donor, funder, advisor, participant, public authority participant, provider, partner, or external actor shall describe GCRI Canada in a manner that implies charitable status, charitable receipt eligibility, charitable tax treatment, or charity-law privilege unless such representation is accurate, current, authorized, and records-valid. 2.1.3(g) Misstatements regarding charitable status, charitable receipting, or charity-law authority shall be corrected promptly through proportionate internal correction, public-safe clarification, partner notification, sponsor correction, donor communication, website update, document revision, or other suitable corrective action.

2.1.4 GCRI Canada as a Distinct Legal Person Within the Wider GCRI and Nexus Architecture. 2.1.4(a) GCRI Canada is a distinct legal person within the wider GCRI and Nexus architecture. 2.1.4(b) GCRI Canada may coordinate with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, any applicable Nexus Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, laboratories, public authorities, communities, Indigenous institutions, civil society actors, media actors, capital readers, and other Nexus-compatible public-good or enterprise actors. 2.1.4(c) Such coordination shall not create merger, agency, partnership, joint venture, parent-subsidiary status, alter ego, shared treasury, shared employer status, shared liability, substituted fiduciary duty, substituted tax status, delegated public authority, finance authority, protocol authority, recognition authority, procurement authority, certification authority, execution authority, or implied control. 2.1.4(d) Shared mission, shared language, shared ontology, shared doctrine, shared software, shared records, shared events, shared directors where lawful, shared participants, shared public-good objectives, shared technical baselines, shared publication surfaces, common branding elements, or shared Nexus-compatible public identity shall not override GCRI Canada’s separate legal personality. 2.1.4(e) Each interface shall preserve the distinction between alignment and legal fusion, cooperation and control, interoperability and substitution, support and authority, contribution and ownership, participation and endorsement, public-good coordination and shared liability, and shared public-benefit purpose and shared legal responsibility. 2.1.4(f) GCRI Canada shall not bind any other Nexus institution, and no other Nexus institution shall bind GCRI Canada, except through an express, lawful, authorized, records-valid instrument within proper scope. 2.1.4(g) GCRI Canada shall preserve separate records, separate approvals, separate authority surfaces, separate liability perimeters, separate fiscal records, separate public claims, separate public authority interfaces, separate data stewardship obligations, and separate correction responsibilities unless a lawful and express instrument provides otherwise within defined limits. 2.1.4(h) Where a joint or coordinated output involves GCRI Canada and another institution, the output shall identify, where material, each institution’s contribution, authority surface, role, scope, limitations, public-safe status, and correction responsibility sufficient to prevent confusion regarding legal identity, institutional authority, reliance, and liability. 2.1.4(i) No person shall describe GCRI Canada as the parent, agent, controller, representative, guarantor, issuer, certifier, finance authority, public authority proxy, protocol authority, recognition authority, procurement gate, or execution arm of another Nexus institution unless such role is expressly created by lawful instrument and remains consistent with this Charter.

2.1.5 GCRI Canada as the Canadian Anchor for Evidence, Methods, Observability, Ontology, Technical Truth, Public-Good R&D, Public-Good Software, and Open Technical Baselines. 2.1.5(a) GCRI Canada shall serve as the Canadian anchor for the GCRI function of evidence, methods, observability, ontology, technical truth, public-good research and development, public-good software, and open technical baselines. 2.1.5(b) This anchor function includes Canadian-localized capacity to steward evidence records, method libraries, method notes, method profiles, data-to-evidence rules, observability methods, systems-intelligence methods, Nexus Truth Engine methods, verifiable compute methods, verifiable intelligence methods, model registers, dataset cards, system cards, benchmark cards, inference records, technical reference architectures, controlled vocabulary, taxonomies, schemas, data dictionaries, public-safe dashboards, public-good repositories, secure release systems, correction registers, provenance records, and public authority learning materials. 2.1.5(c) The Canadian anchor role shall be exercised with respect for Canadian federal, provincial, territorial, Indigenous, local, community, academic, research, public authority, privacy, cybersecurity, sanctions, export-control, tax, nonprofit, employment, accessibility, competition, language, and public-benefit contexts while maintaining global interoperability and Nexus-compatible structure. 2.1.5(d) GCRI Canada shall not treat anchoring as centralization for its own sake. The anchor function exists to preserve lawful stewardship, semantic coherence, records continuity, evidence integrity, public-good technical integrity, public-safe publication discipline, correctionability, and Canada-compatible institutional trust. 2.1.5(e) The anchor function shall not confer ownership of all GCRI activity, control over all Nexus actors, authority over all public-good systems, authority over all technical baselines, authority over all public authority interfaces, or authority over downstream recognition, finance-readiness, protocol, procurement, public authority, or execution functions. 2.1.5(f) The anchor function shall require GCRI Canada to maintain records, repositories, methods, governance controls, technical stewardship practices, secure collaboration environments, controlled vocabulary, versioning, public-safe release pathways, and correction mechanisms sufficient to support long-horizon public-good use. 2.1.5(g) GCRI Canada may localize global methods, adapt technical baselines, translate evidence structures, support Canadian public authority learning, contribute Canada-relevant observability methods, and provide Canada-to-global and global-to-Canada evidence translation, provided that such activity remains lawful, public-benefit, records-valid, public-safe, sovereignty-respecting, and non-executing. 2.1.5(h) The Canadian anchor function shall extend across exponential and mission-critical technologies, including artificial intelligence, agentic AI, AI-RAN, O-RAN, private wireless, telecommunications, sovereign compute, edge compute, cloud compute, high-performance compute, verifiable compute, verifiable intelligence, blockchain, distributed ledger technology, DePIN, cyber-physical systems, robotics, drones, digital twins, sensing systems, satellite and geospatial systems, cybersecurity systems, critical infrastructure systems, energy systems, climate and disaster systems, water, food, health, biodiversity, industrial systems, biotechnology-adjacent systems where relevant, quantum-adjacent systems where relevant, and other emerging technologies designated under an applicable Nexus instrument.

2.1.6 GCRI Canada as an Upstream Truth Institution Rather Than a Downstream Recognition, Finance, Protocol, Procurement, Public Authority, or Execution Institution. 2.1.6(a) GCRI Canada is an upstream truth institution. Its role is to help determine what is known, how it is known, what is uncertain, what is disputed, what is stale, what is corrected, what is public-safe, what is restricted, what is method-supported, what is confidence-supported, what is outside the record, and what must not be publicly overstated. 2.1.6(b) GCRI Canada is not a downstream recognition institution, finance-readiness institution, capital-readiness institution, protocol authority, procurement body, public authority, regulator, certifier by default, execution vehicle, deployment company, infrastructure operator, public warning body, emergency command body, market actor, fund, insurer, broker, lender, underwriter, rating agency, investment adviser, public finance approver, capital-formation actor, or transaction platform. 2.1.6(c) GCRI Canada may support downstream functions by others, including GRF recognition or maturity work, GRA finance-readiness work, protocol-authority work, public authority learning, enterprise diligence, standards-aligned interpretation, Academy learning, Nexus interface review, and Project SPV or National Consortium Company evidence support, but it shall not convert its upstream inputs into downstream authority by its own act. 2.1.6(d) The production of evidence, methods, public-good software, observability outputs, public-safe reports, confidence logic, technical baselines, model registers, dataset cards, system cards, benchmark cards, proof templates, dashboards, maps, public authority learning materials, or correction records shall not by itself constitute recognition, maturity status, finance-readiness, insurance-readiness, investment suitability, public finance approval, procurement approval, protocol entitlement, legal certification, regulatory approval, public warning, public authority action, or execution authority. 2.1.6(e) GCRI Canada shall preserve the distinction between evidence and recognition, methods and certification, observability and surveillance, learning and delegated public authority, public-safe publication and public warning, finance-readiness input and investment advice, technical baseline and protocol entitlement, support and control, technical integration and execution, and Nexus compatibility and legal merger. 2.1.6(f) The stronger, more useful, more visible, more technically sophisticated, or more relied-upon an upstream output becomes, the more carefully GCRI Canada shall preserve the boundary between evidence support and downstream decision authority. 2.1.6(g) Where downstream actors rely on GCRI Canada outputs, such reliance shall increase the need for accurate limitations, source-lining where appropriate, confidence treatment, public-safe status, correction pathways, and boundary language; it shall not alter GCRI Canada’s constitutional role. 2.1.6(h) GCRI Canada shall not permit public materials, dashboards, labels, badges, metadata, user interfaces, technical documentation, public authority references, sponsor references, provider references, capital-reader references, or media statements to imply downstream authority inconsistent with this Charter. 2.1.6(i) Where a proposed activity risks transforming GCRI Canada from upstream truth steward into downstream decision-maker, GCRI Canada shall narrow, redesign, refer, segregate, suspend, or refuse the activity unless a separate lawful authority exists and the activity remains consistent with this Charter.

2.1.7 GCRI Canada as a Canadian Entity With International Public-Good Reach and No Supranational Status by Default. 2.1.7(a) GCRI Canada may conduct research, publish public-safe materials, develop technical baselines, maintain public-good software, support public authority learning, participate in international projects, coordinate with global Nexus entities, contribute to interoperable methods, and collaborate with universities, laboratories, public authorities, public-good partners, providers, communities, Indigenous institutions, standards bodies, research networks, civil society actors, and technical networks outside Canada. 2.1.7(b) Such international public-good reach shall not create supranational, treaty, sovereign, diplomatic, intergovernmental, public-law, regulatory, public authority, international organization, public finance, procurement, certification, protocol-authority, or execution status by default. 2.1.7(c) GCRI Canada’s international work shall be lawful, records-valid, Canadian-localized, sovereignty-respecting, conflict-of-law-aware, privacy-preserving, cybersecurity-controlled, export-control-aware, sanctions-screened where required, public-safe, and protected against role inflation. 2.1.7(d) International coordination shall be structured through appropriate records, instruments, safeguards, public-safe descriptions, data-handling controls, IP and licensing terms, correction responsibilities, and boundary language so that GCRI Canada’s public-good presence is legible without being mistaken for state authority, treaty authority, delegated regulation, public procurement authority, market infrastructure, capital authority, protocol authority, or execution power. 2.1.7(e) GCRI Canada may align with global Nexus doctrine, contribute to shared ontology, support interoperable technical baselines, participate in coordinated public-good methods, and provide evidence inputs to international public-good systems, provided that such alignment does not create legal fusion, shared liability, shared treasury, agency, partnership, joint venture, parent-subsidiary status, public authority delegation, finance authority, or execution authority. 2.1.7(f) GCRI Canada shall respect local law, public authority structures, Indigenous protocols, community safeguards, data localization requirements, protected knowledge limits, privacy rules, cybersecurity obligations, sanctions, export controls, and conflict-of-law constraints in international work. 2.1.7(g) Global interoperability shall not erase Canadian legal identity or local context. GCRI Canada shall use controlled vocabulary, equivalence notes, divergence logs, localization notes, public-safe summaries, and jurisdiction-aware records to support international comparability without flattening law, sovereignty, culture, community meaning, or institutional role. 2.1.7(h) No international partner, platform, funder, sponsor, provider, public authority, media actor, or Nexus actor shall describe GCRI Canada as a supranational authority, global regulator, treaty organization, international public authority, global certifier, public finance authority, procurement authority, protocol authority, or execution body unless such status is lawfully created, records-valid, and consistent with this Charter.

2.1.8 GCRI Canada as a Public-Benefit Steward of Long-Horizon Institutional Memory and Technical Continuity. 2.1.8(a) GCRI Canada shall steward long-horizon institutional memory and technical continuity through records, registers, repositories, method libraries, ontology records, evidence records, model registers, dataset records, system cards, benchmark cards, software release records, public-safe publication records, public authority learning records, sponsorship and funding records, data-handling records, AI-use records, correction chains, supersession histories, withdrawal records, retraction records, deprecation records, archival records, final closeout records, and continuity plans. 2.1.8(b) GCRI Canada’s institutional memory shall not depend on individual recollection, founder knowledge, leadership memory, email trails, chat history, informal consensus, slide decks, public claims, media coverage, sponsor narratives, provider documentation, personal accounts, undocumented scripts, platform defaults, or ungoverned storage. 2.1.8(c) Long-horizon memory is a constitutional asset because systemic de-risking requires continuity beyond funding cycles, leadership changes, technology cycles, platform changes, public attention, temporary programs, crisis periods, political cycles, market conditions, sponsor priorities, provider relationships, and institutional growth. 2.1.8(d) GCRI Canada shall maintain memory in a form that is traceable, auditable, versioned, portable where appropriate, secure, classification-aware, privacy-preserving, public-safe where released, correctionable, and capable of distinguishing operative records from drafts, proposals, prototypes, superseded materials, public summaries, informal commentary, AI-generated summaries, and historical artifacts. 2.1.8(e) Technical continuity shall include stewardship of public-good software, repositories, APIs, dashboards, schemas, ontologies, data dictionaries, controlled vocabulary, model registers, dataset cards, system cards, technical baselines, reference architectures, secure release systems, dependency records, vulnerability records, licensing records, contribution records, and deprecation records. 2.1.8(f) GCRI Canada shall not permit mission-critical memory or technical assets to depend on one individual, one vendor, one sponsor, one cloud provider, one model provider, one repository account, one platform, one public authority relationship, one undocumented workflow, or one fragile technical dependency without review and mitigation. 2.1.8(g) Where a record, method, repository, dataset, model, dashboard, technical baseline, or public-good software asset can no longer be responsibly maintained, GCRI Canada shall classify, correct, supersede, deprecate, archive, transfer where lawful, restrict, or retire the asset in a records-valid manner. 2.1.8(h) GCRI Canada shall treat continuity failures, repository loss, uncontrolled edits, undocumented migrations, untraceable claims, lost evidence lineage, unsupported software, uncorrectable dashboards, insecure releases, and unclear status labels as institutional risks requiring corrective action.

2.1.9 GCRI Canada’s Identity as an Institution of Stewardship, Not Ownership of Nexus. 2.1.9(a) GCRI Canada shall be understood as a steward within Nexus and not the owner of Nexus. 2.1.9(b) GCRI Canada does not own the entire Nexus Network, determine all Nexus legitimacy, control all Nexus infrastructure, decide all Nexus finance-readiness, issue all Nexus maturity records, govern all Nexus protocols, control all Nexus enterprise activity, bind all Nexus actors, operate all Nexus systems, control all Nexus public authority interfaces, or substitute for public authorities, enterprise actors, capital actors, protocol authorities, recognition bodies, standards bodies, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, communities, Indigenous institutions, or capital readers. 2.1.9(c) GCRI Canada’s stewardship is powerful because it is bounded. It supplies upstream evidence, methods, observability, ontology, technical baselines, public-good software, public-safe publication discipline, technical truth infrastructure, and correction signals while preserving the distinct functions of GRF, GRA, protocol authority, public authorities, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, communities, Indigenous institutions, and capital readers. 2.1.9(d) Stewardship shall mean duty-bearing custody, disciplined maintenance, public-benefit protection, reviewability, public-safe release where appropriate, correctionability, and continuity. It shall not mean ownership of institutional meaning, monopoly over truth, control over downstream decisions, or authority to absorb the roles of other Nexus institutions. 2.1.9(e) GCRI Canada may steward public-good assets, evidence infrastructures, methods, ontologies, technical baselines, repositories, and public-safe outputs that are essential to Nexus-compatible operations, but such stewardship shall not create unilateral authority over Nexus identity, Nexus legitimacy, Nexus recognition, Nexus finance-readiness, Nexus protocol effect, Nexus procurement, Nexus execution, or Nexus enterprise activity. 2.1.9(f) No institutional narrative, public claim, website, deck, report, dashboard, map, software repository, public authority reference, sponsor reference, provider reference, Academy material, media statement, or Nexus interface record shall describe GCRI Canada as the whole of Nexus, the controller of Nexus, the single legitimacy source for Nexus, the public authority face of Nexus, the finance-readiness authority of Nexus, the protocol authority of Nexus, or the execution vehicle of Nexus merely because it stewards critical upstream truth infrastructure. 2.1.9(g) Where GCRI Canada’s technical assets become widely used by Nexus actors, such use shall be governed through records, licensing, public-safe descriptions, contribution rules, interoperability terms, correction pathways, and boundary language sufficient to prevent stewardship from being mistaken for ownership or control. 2.1.9(h) GCRI Canada shall preserve the integrity of Nexus by refusing role inflation. It shall support, inform, structure, and correct within its own constitutional role, and shall route downstream matters to the competent institution or actor rather than absorb them by convenience.

2.1.10 Constitutional Identity as a Binding Interpretive Rule Across the Charter, Bylaw, Policies, Programs, Publications, and Public Statements. 2.1.10(a) The constitutional identity of GCRI Canada shall bind interpretation across this Charter, the GCRI Canada Bylaw, articles and governing instruments where applicable, board resolutions, policies, procedures, program charters, committee charters, council terms, terms of reference, public authority protocols, sponsorship instruments, grant instruments, donation instruments, provider agreements, data-sharing instruments, public materials, websites, reports, dashboards, maps, datasets, software repositories, Academy materials, public statements, media statements, and Nexus interface records. 2.1.10(b) No document, public statement, title, room, event, technical release, sponsor reference, provider reference, public authority reference, capital-reader reference, funding arrangement, AI output, dashboard, map, proof receipt, evidence pack, method note, public-safe report, controlled annex, learning material, software release, repository label, metadata field, visual badge, or shared record shall be interpreted in a manner inconsistent with GCRI Canada’s constitutional identity. 2.1.10(c) Where an instrument, communication, system output, interface, or public claim is capable of more than one interpretation, the interpretation that preserves GCRI Canada as a Canadian public-benefit, nonprofit, non-share or equivalent non-equity, non-distributing, non-executing, upstream truth, evidence, methods, observability, ontology, public-good research and development, public-good software, and technical-stewardship institution shall prevail unless applicable law requires otherwise. 2.1.10(d) The constitutional identity of GCRI Canada shall operate as a mission-lock, public-benefit, non-execution, validity-by-record, correctionability, public authority boundary, finance boundary, provider-neutrality, sponsor-non-control, privacy, cybersecurity, protected knowledge, public-safe publication, anti-capture, anti-enclosure, anti-drift, and legal-separateness rule. 2.1.10(e) Subordinate instruments shall be drafted, interpreted, implemented, amended, corrected, superseded, withdrawn, or retired in a manner consistent with this constitutional identity. A subordinate instrument that cannot be reconciled with this constitutional identity shall be corrected, suspended, superseded, withdrawn, or referred to the competent governance authority for amendment. 2.1.10(f) No informal practice, repeated usage, public narrative, sponsor expectation, provider expectation, public authority attendance, media repetition, technical dependency, AI-generated summary, repository convention, dashboard design, event language, or partner statement shall amend GCRI Canada’s constitutional identity. 2.1.10(g) No waiver of constitutional identity shall be implied from silence, custom, urgency, operational convenience, funding need, institutional visibility, public authority interest, technical centrality, ecosystem expectation, or past error. 2.1.10(h) Where public materials or external statements misstate, inflate, narrow, or distort GCRI Canada’s constitutional identity, GCRI Canada shall take proportionate corrective action, including clarification, relabeling, amendment, public-safe correction, partner notice, sponsor notice, provider correction, withdrawal, supersession, retraction, or other suitable remedy. 2.1.10(i) The constitutional identity of GCRI Canada shall survive leadership changes, funding cycles, host changes, platform changes, technology shifts, public visibility, international expansion, Nexus growth, public authority engagement, sponsor support, provider participation, and ecosystem complexity. 2.1.10(j) The Board, officers, committees, councils, staff, fellows, advisors, contractors, contributors, sponsors, providers, hosts, members where applicable, public authority participants, and partners shall act consistently with this constitutional identity in all GCRI Canada-related roles and shall not use association with GCRI Canada to imply authority, endorsement, recognition, finance-readiness, certification, procurement preference, public authority approval, protocol entitlement, Nexus legitimacy, or execution power beyond the relevant record and competent authority.

2.2 Charter Status and Constitutional Function

2.2.1 The Charter as the Constitutional Identity Instrument of GCRI Canada. 2.2.1(a) This Charter is the constitutional identity instrument of GCRI Canada. It states what GCRI Canada is, what GCRI Canada exists to protect, what functions GCRI Canada may perform, what functions GCRI Canada shall not perform, how GCRI Canada preserves Canadian public-benefit character, how GCRI Canada fits within the wider GCRI and Nexus architecture, and how GCRI Canada’s authority remains bounded by law, role, record, public-safe language, legal separateness, non-execution, and correctionability. 2.2.1(b) This Charter shall define the institutional identity, public-benefit posture, stewardship mandate, authority perimeter, doctrinal commitments, public-good role, technical-stewardship function, and interpretive rules of GCRI Canada. 2.2.1(c) This Charter shall not be treated as decorative institutional prose, promotional language, a public-relations document, a concept note, a strategy memorandum, a donor narrative, a technical whitepaper alone, or a non-binding expression of aspiration. It is the interpretive foundation for governance, mission, policy, programs, technical stewardship, public claims, boundary discipline, public authority interfaces, sponsor conduct, provider neutrality, data handling, cybersecurity, AI use, public-safe publication, and records validity. 2.2.1(d) This Charter shall be read as a constitutional-operational instrument: constitutional because it defines identity, purpose, limits, role, authority, and non-negotiable institutional commitments; operational because its principles shall be converted into procedures, forms, controls, records, registers, reviews, publication rules, technical-release gates, data-handling requirements, correction pathways, and public-safe communication practices. 2.2.1(e) The Charter shall establish GCRI Canada as a Canadian public-benefit, nonprofit, non-share or equivalent non-equity, non-distributing, non-executing, upstream truth, evidence, methods, observability, ontology, public-good R&D, public-good software, open technical baseline, verifiable compute, verifiable intelligence, public authority learning, protected knowledge, and public-safe publication steward. 2.2.1(f) The Charter shall preserve GCRI Canada’s institutional identity across changes in directors, officers, staff, members where applicable, funding sources, sponsors, providers, hosts, public authority participants, technical platforms, repositories, programs, publications, public visibility, and Nexus interfaces. 2.2.1(g) The Charter shall be used to test whether a proposed act, program, claim, partnership, funding pathway, sponsorship, technical release, public authority interface, data practice, AI workflow, repository structure, public-safe report, dashboard, map, Academy material, or Nexus interface is consistent with GCRI Canada’s constitutional role. 2.2.1(h) No person shall interpret the Charter to expand GCRI Canada into a downstream recognition body, finance-readiness body, investment adviser, insurer, underwriter, lender, broker, rating agency, public authority, regulator, procurement authority, certification body by default, protocol authority, emergency command body, public warning body, infrastructure operator, vendor platform, or execution vehicle. 2.2.1(i) Where the Charter is used in interpretation, implementation, communication, system design, governance review, public authority engagement, sponsor negotiation, provider interface, data-sharing arrangement, public-facing material, or Nexus coordination, it shall be read to preserve GCRI Canada’s upstream truth role and non-executing public-good identity.

2.2.2 The Charter as Mission, Doctrine, Role, Boundary, Stewardship, and Public-Good Alignment Instrument. 2.2.2(a) This Charter shall operate as GCRI Canada’s mission, doctrine, role-separation, boundary-setting, stewardship, public-good alignment, validity-by-record, correctionability, non-execution, public authority boundary, finance-readiness boundary, anti-capture, anti-enclosure, anti-drift, anti-repurposing, public-safe publication, data-rights, cybersecurity, AI-governance, public-good technical-core, and technical-stewardship instrument. 2.2.2(b) The Charter shall guide how GCRI Canada structures programs, accepts support, governs funds, manages sponsorship, publishes claims, collaborates with public authorities, maintains technical assets, develops public-good software, governs AI use, protects data, releases software, manages repositories, operates controlled rooms, participates in Nexus interfaces, and corrects errors. 2.2.2(c) The Charter shall align GCRI Canada with the wider Nexus architecture while preserving its separate legal personality, Canadian public-benefit status, upstream truth function, public-good technical stewardship, non-execution boundary, and institutional role distinct from GRF, GRA, protocol authority, public authorities, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, communities, Indigenous institutions, and capital readers. 2.2.2(d) No program, partnership, funding arrangement, sponsorship, donation, grant, public statement, platform design, software release, repository structure, technical baseline, Academy material, public authority room, controlled room, data-sharing arrangement, AI-assisted workflow, observability output, or public-safe publication shall be considered properly formed unless it is capable of being interpreted consistently with this Charter. 2.2.2(e) Charter alignment shall be an active governance control and not a symbolic reference. GCRI Canada shall maintain policies, templates, review pathways, records systems, public claims review, sponsorship review, provider-interface review, technical-release gates, data-classification rules, public-safe publication procedures, and correction processes sufficient to implement Charter alignment. 2.2.2(f) The Charter shall require GCRI Canada to preserve the distinction between evidence and recognition, method and certification, observability and surveillance, learning and delegated public authority, public-safe publication and official public warning, finance-readiness input and investment advice, technical baseline and protocol entitlement, sponsorship and control, provider participation and endorsement, interoperability and legal merger, and support and execution. 2.2.2(g) The Charter shall govern not only formal governance instruments but also systems that create public meaning, including websites, dashboards, maps, public repositories, dataset labels, software package descriptions, model registers, badges, metadata fields, event titles, public authority references, sponsor acknowledgments, provider references, and AI-generated summaries. 2.2.2(h) Where a GCRI Canada activity appears mission-aligned in substance but creates risk of role confusion, public overclaim, capture, enclosure, data misuse, public authority ambiguity, finance-boundary ambiguity, provider preference, procurement implication, certification implication, protocol implication, or execution implication, the Charter shall require narrowing, redesign, review, correction, or refusal before institutional effect is created.

2.2.3 The Charter as Distinct From the GCRI Canada Bylaw. 2.2.3(a) This Charter is distinct from the GCRI Canada Bylaw. 2.2.3(b) The GCRI Canada Bylaw shall govern corporate mechanics, including directors, officers, members where applicable, meetings, quorum, voting, notices, committees, fiscal powers, banking, signing authority, indemnification, amendment, dissolution, books and records, corporate acts, and other corporate matters to the extent provided therein and required by applicable law. 2.2.3(c) This Charter shall govern constitutional meaning, public-benefit mission, role boundaries, mission lock, technical stewardship, Public-Good Stack discipline, public authority boundaries, finance boundaries, anti-capture safeguards, anti-enclosure safeguards, anti-drift safeguards, public-safe publication, evidence integrity, methods integrity, ontology discipline, correctionability, and interpretive commitments. 2.2.3(d) The Charter shall not be used to bypass Bylaw procedure, director duties, member rights where applicable, statutory requirements, filing obligations, board approval requirements, fiscal controls, or corporate formalities. 2.2.3(e) The Bylaw shall not be implemented in a manner that defeats Charter mission where lawful interpretive alternatives exist. Corporate powers shall be exercised only within GCRI Canada’s Charter-consistent public-benefit, non-executing, upstream truth, evidence, methods, observability, ontology, public-good R&D, public-good software, and technical-stewardship role. 2.2.3(f) Legal capacity under the Bylaw or applicable corporate law shall not be treated as mission permission under this Charter. A power that GCRI Canada may possess as a legal person shall not be exercised in a manner inconsistent with mission lock, non-execution, public-good role separation, sponsor non-control, provider neutrality, public authority boundaries, finance boundaries, privacy, cybersecurity, protected knowledge, public-safe publication, and correctionability. 2.2.3(g) Where Charter principles and Bylaw mechanics interact, the proper approach shall be alignment: corporate acts shall be validly adopted under the Bylaw and interpreted, implemented, recorded, communicated, published, and corrected consistently with this Charter. 2.2.3(h) Where a conflict appears to exist between this Charter and the Bylaw, GCRI Canada shall identify the conflict, preserve compliance with applicable law, apply the interpretation that best preserves legality and public-benefit mission, and refer the matter to the competent governance authority for clarification, correction, amendment, or supersession. 2.2.3(i) No informal interpretation of the Bylaw, repeated corporate practice, board custom, officer practice, committee habit, sponsor expectation, provider workflow, public authority engagement, or technical implementation shall amend the Charter or override its constitutional identity rules.

2.2.4 The Charter as Superior Interpretive Context for Policies, Program Charters, Council Terms, Public Materials, and Strategic Plans, Subject to Law and the Bylaw. 2.2.4(a) Subject always to applicable law, articles or governing instruments, and the GCRI Canada Bylaw, this Charter shall provide superior interpretive context for policies, procedures, program charters, committee charters, council terms, terms of reference, strategic plans, public materials, technical releases, public authority protocols, sponsorship arrangements, provider interfaces, grant terms, donation terms, membership terms where applicable, Academy materials, data-sharing instruments, controlled-room procedures, AI-use protocols, software-release practices, repository rules, and Nexus coordination instruments. 2.2.4(b) Any ambiguity in a subordinate instrument shall be resolved to preserve public-benefit purpose, mission lock, non-execution, evidence integrity, methods integrity, ontology discipline, records validity, correctionability, public authority boundaries, finance boundaries, legal separateness, provider neutrality, sponsor non-control, privacy, cybersecurity, protected knowledge, community safeguards, Indigenous knowledge safeguards, accessibility, competition safety, public-safe publication, and public trust. 2.2.4(c) Policies shall implement the Charter and shall not narrow, waive, dilute, or reverse the Charter’s constitutional commitments unless the Charter itself is lawfully amended through competent authority and proper records. 2.2.4(d) Program charters shall identify their Charter basis, public-benefit purpose, permitted functions, prohibited functions, authority surface, output types, records requirements, public-safe status, data-handling requirements, sponsor and provider boundaries, public authority boundaries, finance boundaries, correction path, and lifecycle controls. 2.2.4(e) Council terms and committee terms shall preserve GCRI Canada’s non-executing role and shall not allow councils or committees to issue recognition, finance-readiness, public authority decisions, procurement preferences, certification, protocol entitlements, public warnings, or execution instructions unless separately and lawfully authorized by the competent institution and consistent with this Charter. 2.2.4(f) Public materials and strategic plans shall be interpreted and drafted in a manner that distinguishes adopted reality from aspiration, proposed work from operational work, pilots from mature systems, learning from public authority action, evidence support from downstream decision authority, and technical baseline from certification or protocol effect. 2.2.4(g) A subordinate instrument that cannot be reconciled with this Charter shall be corrected, suspended, superseded, withdrawn, restricted, or referred to the competent governance authority for amendment. 2.2.4(h) Where a subordinate instrument has already created public meaning inconsistent with this Charter, GCRI Canada shall assess reliance risk and take proportionate corrective action, including internal correction, public-safe clarification, partner notice, sponsor notice, provider correction, public authority clarification, withdrawal, retraction, or supersession. 2.2.4(i) The Charter shall apply to all subordinate instruments regardless of format, including legal documents, policy manuals, web pages, dashboards, diagrams, maps, slide decks, repository files, code documentation, dataset descriptions, AI-generated summaries, event descriptions, funding materials, and public-facing visuals.

2.2.5 The Charter as a Public-Benefit Compass Rather Than a Regulated Offering, Public Authority Delegation, Certification Scheme, Financial Instrument, or Procurement Framework. 2.2.5(a) This Charter is a public-benefit compass. It is not a securities offering document, investment memorandum, prospectus, financial promotion, credit instrument, insurance instrument, underwriting instrument, public finance approval document, procurement framework, tender document, certification scheme, public authority delegation, emergency response protocol, official public warning system, regulatory approval mechanism, market infrastructure instrument, professional advice instrument, or execution mandate. 2.2.5(b) No person shall use this Charter to imply that GCRI Canada grants investment suitability, finance-readiness, capital-readiness, insurance-readiness, public approval, public authority adoption, vendor award, procurement preference, maturity status, certification, recognition, insurance approval, legal compliance, regulatory approval, technical performance guarantee, emergency command authority, public warning authority, protocol entitlement, or regulated-market consequence. 2.2.5(c) The Charter may guide evidence, methods, observability, ontology, technical stewardship, public authority learning, public-safe publication, public-good software, open technical baselines, and correctionability, but it shall not itself create downstream approval, downstream entitlement, market status, legal certification, public authority action, procurement eligibility, capital allocation, insurance underwriting, or execution authority. 2.2.5(d) Any use of this Charter in fundraising, sponsorship, grants, donations, public authority engagement, procurement-adjacent discussion, capital-reader engagement, provider communications, Academy materials, public-facing materials, or Nexus interface materials shall include role-bounded language sufficient to prevent misinterpretation. 2.2.5(e) No investor, lender, insurer, underwriter, broker, rating agency, public finance body, procurement office, regulator, public authority, provider, sponsor, host, Project SPV, National Consortium Company, or capital reader shall treat this Charter as a substitute for its own legal, fiduciary, professional, technical, procurement, investment, insurance, underwriting, public finance, or regulatory analysis. 2.2.5(f) The Charter shall not authorize GCRI Canada to receive transaction-based compensation, arrange capital, solicit securities, underwrite insurance, approve credit, rate financial instruments, issue professional opinions, certify legal compliance, award vendors, recommend procurement, or command public response. 2.2.5(g) Where public materials, partner statements, sponsor language, provider references, public authority references, or capital-reader materials use this Charter in a manner that implies regulated offering, delegated authority, certification, procurement effect, finance-readiness, or execution, GCRI Canada shall require correction, restriction, withdrawal, or clarification as appropriate. 2.2.5(h) The public-benefit compass function of this Charter shall be implemented through mission-faithful interpretation, governance discipline, records-valid action, public-safe communication, and correctionability, not through unauthorized creation of legal, financial, procurement, certification, regulatory, or public authority effect.

2.2.6 The Charter as a Boundary-Setting Instrument for Directors, Officers, Councils, Members, Fellows, Advisors, Participants, Sponsors, Providers, Public Authorities, and Partners. 2.2.6(a) This Charter shall bind and guide directors, officers, staff, committees, councils, members where applicable, fellows, advisors, contractors, contributors, participants, sponsors, donors, funders, providers, hosts, public authorities, universities, communities, Indigenous institutions, media actors, capital readers, and partners in their GCRI Canada-related roles. 2.2.6(b) Each actor shall be understood by role and capacity, not by prestige, title, contribution size, funding importance, public visibility, sponsor status, provider centrality, technical indispensability, public authority position, academic status, institutional prominence, founder proximity, capital influence, or media profile. 2.2.6(c) Participation creates duties, not authority by default. No participant shall use association with GCRI Canada to imply endorsement, preferred status, public authority approval, finance-readiness, technical certification, procurement advantage, protocol entitlement, Nexus legitimacy, legal compliance, maturity status, recognition, or execution authority unless the relevant status has been separately authorized by the competent institution and recorded within proper scope. 2.2.6(d) Directors shall oversee Charter compliance, mission lock, public-benefit purpose, non-execution, legal separateness, sponsor non-control, provider neutrality, public authority boundaries, finance boundaries, public-safe publication, records validity, correctionability, anti-capture, anti-enclosure, anti-drift, privacy, cybersecurity, and protected knowledge safeguards. 2.2.6(e) Officers shall implement the Charter through operating controls, authority matrices, forms-first governance, records-first governance, public claims review, data access controls, AI-use controls, technical-release discipline, sponsorship review, provider-interface review, public authority capacity records, and correction pathways. 2.2.6(f) Councils and committees shall operate only within recorded mandates and shall not expand their own authority, output types, public meaning, public claims, public authority status, finance implications, certification implications, protocol implications, or execution implications by custom, urgency, technical importance, or participant expectation. 2.2.6(g) Fellows, advisors, experts, and contributors shall support evidence, methods, observability, technical baselines, public-good software, public authority learning, or other Charter-consistent functions within their recorded roles and shall not use title, expertise, authorship, or proximity to imply institutional authority beyond scope. 2.2.6(h) Sponsors, donors, funders, providers, hosts, and partners shall accept support-without-control as a condition of participation. They shall not control evidence selection, method design, publication timing, public-safe language, correction, public authority access, provider status, technical baseline meaning, repository design, or public claims. 2.2.6(i) Public authorities may learn, observe, contribute, collaborate, or participate within capacity-classified records, but their participation shall not imply delegated public authority, official adoption, regulatory approval, procurement approval, funding approval, public finance approval, public warning, emergency command, or sovereign obligation. 2.2.6(j) Any person who becomes aware of a boundary breach, role confusion, public overclaim, sponsor control, provider preference, public authority ambiguity, finance overclaim, procurement implication, certification implication, protocol implication, data misuse, AI misuse, cyber risk, protected knowledge risk, or correction need shall route the matter through the appropriate review or escalation pathway.

2.2.7 The Charter as the Record of GCRI Canada’s Public-Good Stewardship Posture. 2.2.7(a) This Charter records GCRI Canada’s public-good stewardship posture: evidence before assertion; methods before interpretation; records before effect; correction before reliance; public benefit before visibility; support without control; participation without implied authority; open where appropriate, controlled where required, correctionable always; public meaning only through proper role and record. 2.2.7(b) This posture shall guide internal governance, external communications, technical design, data handling, AI use, public authority learning, sponsor engagement, provider engagement, community engagement, Indigenous and protected knowledge handling, repository governance, software release, public-safe publication, and Nexus coordination. 2.2.7(c) The posture shall guide the design of systems, repositories, dashboards, maps, AI workflows, public-safe publications, public authority learning materials, Academy resources, data rooms, controlled rooms, clean rooms, model registers, dataset records, software packages, technical baselines, and correction registers. 2.2.7(d) The posture shall be preserved in form as well as substance. Documents shall be versioned; claims shall be bounded; public materials shall not overstate maturity; technical releases shall identify status and limitations; public authority references shall identify capacity; sponsor acknowledgments shall avoid endorsement; provider references shall avoid preference; and institutional language shall distinguish evidence, recognition, readiness, adoption, certification, protocol effect, procurement, and execution. 2.2.7(e) GCRI Canada shall maintain public-good stewardship through custody, maintenance, security, review, limitation disclosure, public-safe release, controlled access where required, correction, supersession, withdrawal, archival, and closeout. 2.2.7(f) GCRI Canada shall not treat public-good stewardship as passive custody. Stewardship is an active duty to protect evidence integrity, methods quality, semantic clarity, public-safe publication, technical continuity, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, community safeguards, protected knowledge, and correctionability. 2.2.7(g) The Charter shall preserve the principle that public-good infrastructure must remain trustworthy because it is traceable, challengeable, bounded, secure, correctionable, and protected against capture, not because the institution asserts trust. 2.2.7(h) Where conduct, language, architecture, publication, funding, sponsorship, provider involvement, public authority participation, or technical dependency is inconsistent with this public-good stewardship posture, GCRI Canada shall narrow, correct, redesign, restrict, terminate, withdraw, or supersede the relevant activity or material.

2.2.8 The Charter as a Correctable, Versioned, Records-Valid Instrument. 2.2.8(a) This Charter shall be versioned, dated, custodially assigned, reviewable, correctable, supersession-aware, withdrawal-aware, archival-aware, and records-valid. 2.2.8(b) Amendments, interpretations, controlled annexes, public-safe summaries, plain-language summaries, technical summaries, supersession notices, withdrawal notices, correction notices, translation notes, compatibility notes, divergence notes, localization notes, and governance notes shall be maintained in authoritative records. 2.2.8(c) No silent amendment, informal reinterpretation, unrecorded waiver, public materials drift, uncontrolled copy, outdated website text, unofficial deck, AI-generated summary, unapproved translation, partner excerpt, sponsor summary, provider description, or public authority briefing shall alter the constitutional meaning of this Charter. 2.2.8(d) The operative version of this Charter shall be the authenticated version recorded in the authoritative repository or equivalent official records system designated by GCRI Canada. 2.2.8(e) Drafts, excerpts, summaries, translations, briefing slides, web pages, AI-generated restatements, public-facing explainers, and partner materials shall not override the operative text and shall not be cited as operative authority unless expressly designated as such by competent authority. 2.2.8(f) Where a non-authoritative copy or summary misstates Charter meaning, GCRI Canada shall correct, withdraw, supersede, qualify, restrict, or replace the material to prevent public reliance, internal confusion, partner misuse, sponsor overclaim, provider overclaim, public authority ambiguity, finance overclaim, or downstream misuse. 2.2.8(g) The Charter’s correction system shall distinguish clerical correction, formatting correction, translation correction, substantive correction, limitation clarification, interpretive clarification, material amendment, supersession, withdrawal, retraction, and archival. 2.2.8(h) Any material amendment to this Charter shall be adopted only by competent authority, under applicable law, with proper records, version identification, effective date, change classification, transition provisions where needed, and public-safe notice where reliance risk exists. 2.2.8(i) Where Charter interpretation becomes disputed, unclear, stale, operationally inconsistent, or misused, GCRI Canada shall route the matter through an appropriate interpretation, correction, amendment, or supersession process rather than allowing informal practice to settle constitutional meaning. 2.2.8(j) The Charter shall remain correctionable because public-good stewardship requires the ability to repair errors, update terms, clarify boundaries, and preserve trust without pretending that prior wording was infallible.

2.2.9 The Charter as a Nexus-Compatible Instrument Without Creating Legal Merger or Shared Liability. 2.2.9(a) This Charter is Nexus-compatible but shall not create legal merger, shared liability, shared treasury, agency, partnership, joint venture, parent-subsidiary status, alter ego, shared employer status, substituted fiduciary duty, public authority delegation, financial-services authority, protocol authority, recognition authority, procurement authority, certification authority, execution authority, or international organization status by implication. 2.2.9(b) Nexus compatibility means interoperability of role, method, record, vocabulary, evidence logic, observability logic, technical baseline, correction signal, public-good doctrine, public-safe publication discipline, and institutional interface. It does not mean legal fusion. 2.2.9(c) GCRI Canada may align with Nexus doctrine, participate in Nexus systems, contribute to Nexus public-good baselines, provide evidence inputs to Nexus institutions, support Nexus Observatory methods, support Nexus Academy learning, support Nexus Grid maturity inputs where appropriate, support Nexus Rails evidence logic where appropriate, and support Nexus interfaces, but each such act shall preserve GCRI Canada’s own authority surface, legal personality, liability perimeter, records custody, public-facing role description, and correction responsibility. 2.2.9(d) GCRI Canada shall remain distinct from GCRI US, GRF, GRA, Nexus Standards, any applicable Nexus Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, public authorities, communities, Indigenous institutions, media actors, and capital readers. 2.2.9(e) Common doctrine, common vocabulary, common technical baselines, common public-good rail, shared records, shared software, shared events, shared public-safe materials, shared participants, shared directors where lawful, shared repositories, or shared interoperability shall not create common control, common treasury, common liability, common employment, common tax status, common public authority status, common finance status, or common execution responsibility. 2.2.9(f) Any inter-institutional relationship involving GCRI Canada shall be governed by written or records-valid instruments where material, including role, purpose, authority, data rights, public-safe status, publication responsibility, IP and licensing terms, public claims rules, confidentiality, correction responsibility, and termination or supersession where appropriate. 2.2.9(g) Where a Nexus-compatible output is jointly developed, GCRI Canada’s contribution shall be identified according to its upstream truth, evidence, methods, observability, ontology, public-good software, technical baseline, or correction role. Downstream effects shall be attributed only to the competent institution that lawfully creates them. 2.2.9(h) No use of this Charter shall imply that GCRI Canada controls Nexus, owns Nexus, issues all Nexus legitimacy, decides all Nexus finance-readiness, grants all Nexus protocol effect, binds all Nexus actors, or operates all Nexus enterprise execution. 2.2.9(i) Where legal merger, shared liability, agency, partnership, public authority delegation, finance authority, protocol authority, certification authority, procurement authority, or execution authority is alleged, the presumption shall be against such effect unless an express lawful instrument, competent authority, and records-valid designation establish it within proper scope.

2.2.10 Charter Interpretation as Public-Benefit, Non-Execution, Validity-by-Record, Correctionability, and Role-Separation Interpretation. 2.2.10(a) Charter interpretation shall favor public-benefit purpose, mission lock, non-execution, validity-by-record, correctionability, role separation, legal separateness, privacy, cybersecurity, community safeguards, Indigenous and protected knowledge safeguards, public authority safety, finance-boundary safety, provider neutrality, sponsor non-control, anti-capture, anti-enclosure, anti-drift, anti-repurposing, competition safety, public-safe publication, sovereignty respect, localization without fragmentation, and institutional trust. 2.2.10(b) Where ambiguity exists, the more protective, more role-bounded, more public-good-preserving, more records-valid, more correctionable, and more non-executing interpretation shall prevail unless contrary to applicable law. 2.2.10(c) Interpretive discretion shall not be used to expand authority by convenience, urgency, emergency relevance, funding need, sponsor expectation, provider pressure, public visibility, technical centrality, public authority participation, capital-reader interest, media attention, ecosystem demand, or perceived strategic importance. 2.2.10(d) No interpretation shall convert this Charter into an execution instrument, public authority delegation, finance-readiness instrument, investment instrument, insurance instrument, procurement framework, certification scheme, protocol authority instrument, public warning system, emergency response instrument, or regulated offering. 2.2.10(e) The Charter shall be interpreted to preserve the distinct roles of GCRI Canada, GRF, GRA, protocol authority, public authorities, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, communities, Indigenous institutions, and capital readers. 2.2.10(f) The Charter shall be interpreted to preserve the Public-Good Stack and Enterprise Stack separation. Public-good evidence, methods, observability, ontology, technical baselines, public-safe publication, maturity inputs, learning, and correction shall remain distinct from commercial execution, asset operation, procurement, finance, investment, insurance, deployment, and regulated market activity. 2.2.10(g) The Charter shall be interpreted according to validity-by-record. No institutional meaning, authority, public claim, public authority status, finance implication, provider status, sponsor role, technical release status, correction status, or Nexus interface consequence shall arise solely from memory, informal consensus, repeated practice, public narrative, title, attendance, funding, proximity, technical access, or AI-generated text. 2.2.10(h) The Charter shall be interpreted according to correctionability. Any material record, publication, claim, method, dashboard, map, technical baseline, software release, public authority material, Academy material, sponsor reference, provider reference, or Nexus interface record that is wrong, stale, misleading, unsafe, incomplete, overbroad, or inconsistent with the Charter shall be capable of correction, supersession, withdrawal, retraction, downgrade, restriction, or archival. 2.2.10(i) The Charter shall be interpreted according to public-safe communication. Accuracy shall include not only factual correctness but also correct public meaning, bounded reliance, appropriate limitation disclosure, proper status labels, and prevention of misleading authority signals. 2.2.10(j) Where an interpretation would permit GCRI Canada to do indirectly what the Charter prohibits directly, that interpretation shall be rejected. 2.2.10(k) Where an interpretation would allow sponsor control, provider preference, public authority overclaim, finance overclaim, certification drift, protocol drift, procurement implication, execution by stealth, public-good enclosure, data misuse, AI-generated authority, or public-safe publication failure, that interpretation shall be rejected unless applicable law requires otherwise and appropriate safeguards are recorded. 2.2.10(l) Charter interpretation shall remain durable across leadership changes, funding cycles, platform changes, public visibility, technical evolution, public authority engagement, sponsor support, provider participation, international alignment, and Nexus growth. The constitutional identity of GCRI Canada shall not drift by circumstance.

2.3 Mission Statement

2.3.1 Mission to Steward Public-Benefit Evidence Infrastructure. 2.3.1(a) GCRI Canada’s mission is to steward public-benefit evidence infrastructure that allows systemic risk, resilience, innovation, technology, infrastructure, community, public authority, research, and Nexus-relevant information to become usable, comparable, source-lined, confidence-aware, limitation-aware, public-safe, and correctionable. 2.3.1(b) Evidence infrastructure shall include records, evidence packs, datasets, dashboards, maps, public-safe summaries, controlled annexes, observability outputs, technical baselines, model records, dataset records, system records, benchmark records, public authority learning materials, correction chains, provenance records, and public-good repositories. 2.3.1(c) GCRI Canada shall steward evidence infrastructure as a durable public-good asset requiring lawful basis, custody, provenance, versioning, classification, access control, retention discipline, public-safe publication review, challenge pathways, correction mechanisms, and archival continuity. 2.3.1(d) Evidence infrastructure shall be designed to support lawful downstream decisions by competent actors without making GCRI Canada the decision-maker, public authority, certifier, procurement body, finance authority, insurer, underwriter, rating agency, protocol authority, or execution actor. 2.3.1(e) GCRI Canada shall distinguish data from evidence, evidence from interpretation, interpretation from recognition, recognition from adoption, adoption from protocol effect, protocol effect from execution, and evidence support from downstream decision authority. 2.3.1(f) Evidence infrastructure shall not be treated as a sponsor deliverable, provider proof, marketing asset, public authority endorsement, finance-readiness conclusion, procurement signal, public warning, or execution instruction merely because it is useful, visible, technical, public, relied upon, or operationally relevant. 2.3.1(g) GCRI Canada shall maintain evidence infrastructure in a form capable of supporting review by authorized persons, public-safe explanation to appropriate audiences, and correction where evidence changes, methods are superseded, public-safe status changes, errors are discovered, or public meaning exceeds the record. 2.3.1(h) Where evidence infrastructure includes personal information, rights-bearing data, sovereign-sensitive material, protected knowledge, community-linked data, public authority restricted information, cyber-sensitive information, infrastructure-sensitive information, or finance-sensitive information, GCRI Canada shall apply heightened classification, privacy, cybersecurity, localization, controlled-room, redaction, and public-safe publication controls. 2.3.1(i) The mission to steward evidence infrastructure shall extend across exponential and mission-critical technologies and shall be interpreted to support cross-domain public-good understanding rather than fragmented issue-by-issue treatment.

2.3.2 Mission to Steward Scientific-Operational Methods. 2.3.2(a) GCRI Canada’s mission is to steward scientific-operational methods that connect research rigor with institutional usability. 2.3.2(b) Scientific-operational methods may include validation, corroboration, calibration, source comparison, confidence scoring, uncertainty treatment, disputed evidence handling, missing-data treatment, stale-data treatment, spoof-risk assessment, reproducibility where appropriate, limitation disclosure, challenge procedures, public-safe review, and correction triggers. 2.3.2(c) Methods shall not be treated as institutionally valid because they are prestigious, familiar, vendor-supplied, sponsor-funded, embedded in software, AI-generated, publicly repeated, operationally convenient, or informally adopted. 2.3.2(d) Methods shall be valid only within recorded scope, purpose, assumptions, input requirements, evidence basis, review status, limitations, maturity, public-safe status, and correction path. 2.3.2(e) GCRI Canada shall maintain method libraries, method notes, method profiles, method review records, method retirement procedures, supersession records, and correction records sufficient to show which method applies, when, for what purpose, with what authority, with what limits, and subject to what review. 2.3.2(f) GCRI Canada shall preserve the distinction between method support and certification. A method may structure evidence, test a claim, support comparison, or reveal limitations, but it shall not by itself create recognition, maturity status, legal compliance, procurement approval, public authority adoption, finance-readiness, insurance-readiness, protocol entitlement, or execution authority. 2.3.2(g) Scientific-operational methods shall be selected and applied because they are fit for purpose, reviewable, proportionate, records-valid, rights-respecting, public-safe where released, and capable of correction. 2.3.2(h) GCRI Canada shall reject or restrict methods that are opaque, unsuitable for context, unsafe for rights-bearing data, sponsor-shaped, provider-dependent without adequate transparency, incapable of correction, likely to create false precision, or likely to generate public meaning beyond their source record. 2.3.2(i) Where a method is experimental, exploratory, provisional, context-limited, AI-assisted, model-dependent, dataset-limited, or subject to known uncertainty, that status shall be recorded and communicated where material to reliance. 2.3.2(j) GCRI Canada shall treat methodological challenge, replication, peer review, community correction, public authority clarification, technical dispute, and evidence correction as features of institutional seriousness and not as threats to institutional authority.

2.3.3 Mission to Steward Observability Architecture and Systems-Intelligence Methods. 2.3.3(a) GCRI Canada’s mission is to steward observability architecture and systems-intelligence methods for Nexus Observatory Nodes, hubs, clusters, hotspots, regional clusters, national dense cores, sensors, AI-RAN, O-RAN, private wireless, telecommunications, edge compute, sovereign compute, cloud compute, high-performance compute, cyber-physical systems, digital twins, geospatial systems, Earth observation systems, distributed ledger systems, DePIN systems, robotics, drones, energy systems, climate and disaster systems, critical infrastructure systems, public authority systems, and other exponential and mission-critical technologies. 2.3.3(b) Observability stewardship shall include the design, testing, documentation, review, classification, and correction of methods by which signals, telemetry, indicators, reports, field observations, model outputs, benchmark results, geospatial layers, infrastructure states, incident records, public authority inputs, community inputs, and technical traces may be collected, structured, validated, contextualized, compared, limited, and translated into public-benefit evidence. 2.3.3(c) Systems-intelligence methods shall support cross-domain interpretation where AI, cyber, telecommunications, compute, climate, water, energy, food, health, biodiversity, infrastructure, geospatial systems, digital twins, robotics, drones, biosecurity, supply chains, finance-sensitive systems, public authority systems, and community systems interact. 2.3.3(d) GCRI Canada shall distinguish observation from inference, inference from assessment, assessment from recommendation, recommendation from recognition, recognition from adoption, and adoption from execution. 2.3.3(e) No observability output shall be represented as emergency command, official public warning, regulatory decision, public authority action, procurement determination, finance-readiness conclusion, insurance underwriting conclusion, certification, maturity record, provider endorsement, or final safety determination merely because it is technically sophisticated, visual, automated, geospatial, real-time, public-facing, or operationally useful. 2.3.3(f) GCRI Canada shall ensure that observability systems preserve source lineage, temporal context, uncertainty, confidence level where appropriate, limitation notes, data quality indicators, classification status, access restrictions, public-safe status, and correction history. 2.3.3(g) Observability architecture shall be public-good disciplined. It shall support better public authority learning, community safeguards, resilience planning, research quality, infrastructure awareness, technical literacy, systems-risk interpretation, and Nexus interoperability without creating surveillance excess, rights-bearing data misuse, uncontrolled metadata exposure, public authority substitution, provider preference, finance overclaim, or execution by stealth. 2.3.3(h) Where observability systems involve personal information, rights-bearing data, sovereign-sensitive data, protected knowledge, community-sensitive knowledge, Indigenous knowledge, restricted infrastructure information, cybersecurity-sensitive information, market-sensitive information, or operationally sensitive public authority material, GCRI Canada shall apply appropriate privacy, security, localization, controlled-room, redaction, consent-alignment where applicable, public-safe publication, and retention controls. 2.3.3(i) GCRI Canada shall treat observability as a means of disciplined institutional awareness and not as a license for total visibility. The purpose of observability is to improve lawful, bounded, correctionable understanding of systems, not to maximize collection, centralize control, intensify exposure, or convert public-good intelligence into commercial, political, surveillance, or operational dominance.

2.3.4 Mission to Steward Ontology, Controlled Vocabulary, Taxonomies, Schemas, and Semantic Interoperability. 2.3.4(a) GCRI Canada’s mission is to steward ontology, controlled vocabulary, taxonomies, schemas, data dictionaries, semantic mappings, evidence classes, maturity concepts, proof concepts, public-safe language, finance-boundary language, protocol-adjacent language, public authority capacity language, and interoperability terms necessary to preserve meaning across legal, technical, public authority, community, academic, enterprise, and Nexus contexts. 2.3.4(b) Controlled vocabulary shall prevent semantic drift, public overclaim, institutional ambiguity, public authority confusion, finance overclaim, provider preference, sponsor inflation, certification implication, protocol implication, procurement implication, and execution implication. 2.3.4(c) Terms such as “verified,” “validated,” “recognized,” “certified,” “mature,” “finance-ready,” “public-safe,” “approved,” “adopted,” “official,” “operational,” “decision-grade,” “proof,” “truth,” “confidence,” “Nexus-compatible,” “readiness,” “standing,” and “authority” shall be defined and used only within recorded scope and competent authority. 2.3.4(d) GCRI Canada shall not allow words, labels, badges, metadata fields, UI elements, dashboard captions, repository tags, public authority references, sponsor acknowledgments, provider references, or AI-generated summaries to create authority, recognition, certification, maturity, finance-readiness, public authority approval, procurement preference, protocol effect, or execution implication not supported by records. 2.3.4(e) Schemas and data dictionaries shall support machine-readable and human-readable interoperability while preserving source, classification, confidence, limitations, lawful basis, permissions, public-safe status, retention status, and correction fields where material. 2.3.4(f) Semantic design shall not strip context merely to simplify systems integration. Interoperability shall be achieved through disciplined translation, equivalence notes, divergence logs, localization notes, controlled vocabulary, and public-safe summaries rather than semantic flattening. 2.3.4(g) GCRI Canada shall preserve local truth while supporting global comparability. Indigenous knowledge, local knowledge, territorial knowledge, community context, jurisdictional meaning, public authority context, linguistic meaning, and infrastructure reality shall not be erased to fit generic global categories. 2.3.4(h) Where terminology diverges across jurisdictions, institutions, technologies, communities, or public authority contexts, GCRI Canada shall maintain equivalence notes, divergence logs, compatibility notes, localization notes, or interpretive records sufficient to prevent false equivalence. 2.3.4(i) Misuse of controlled vocabulary shall trigger correction where material. Correction may include relabeling, public-safe clarification, metadata update, dashboard revision, repository correction, policy update, partner notice, sponsor correction, provider correction, or withdrawal where necessary. 2.3.4(j) Ontology stewardship shall remain upstream and public-good in character. It shall support evidence integrity, semantic coherence, interoperability, and correctionability, but shall not become protocol authority, recognition authority, certification authority, procurement authority, finance authority, or execution authority by default.

2.3.5 Mission to Steward Technical Truth and Decision-Grade Evidence Architecture. 2.3.5(a) GCRI Canada’s mission is to steward technical truth and decision-grade evidence architecture for public-benefit use. 2.3.5(b) Technical truth means disciplined, source-lined, method-supported, confidence-aware, limitation-aware, classification-aware, public-safe, and correctionable institutional truthfulness concerning technologies, systems, risks, dependencies, capabilities, failures, safeguards, maturity, and evidence gaps. 2.3.5(c) Decision-grade evidence architecture means evidence infrastructure sufficiently structured to support lawful downstream decisions by competent actors, while preserving the distinction between decision support and decision-making. 2.3.5(d) GCRI Canada shall identify what is known, what is probable, what is uncertain, what is disputed, what is stale, what is missing, what is inferred, what is restricted, what is unsafe for public release, what is outside the record, and what must not be publicly overstated. 2.3.5(e) GCRI Canada shall reject false certainty, unsupported claims, public narrative inflation, sponsor-driven conclusions, provider-driven proof, AI-generated authority, dashboard authority, benchmark overclaim, and public authority implication not grounded in records. 2.3.5(f) Decision-grade evidence shall not mean final decision authority. It shall mean that evidence is structured, source-lined where appropriate, method-supported, classification-aware, limitation-aware, and correctionable enough to be responsibly used by actors who possess their own lawful authority, duties, and accountability. 2.3.5(g) GCRI Canada may produce evidence packs, technical notes, public-safe reports, confidence summaries, observability outputs, method notes, public authority learning materials, model records, dataset records, benchmark records, and correction signals, but such outputs shall not decide, approve, procure, fund, warn, regulate, certify, rate, underwrite, guarantee, insure, lend, invest, or execute. 2.3.5(h) Technical truth shall remain challengeable. GCRI Canada shall maintain pathways for internal review, expert challenge, participant challenge, community challenge where appropriate, public authority clarification, technical dispute, data correction, and method reconsideration. 2.3.5(i) Where technical truth is communicated to non-expert audiences, GCRI Canada shall use especially clear boundary language to prevent overreliance, public authority confusion, finance overclaim, provider preference, certification implication, or execution implication. 2.3.5(j) The mission to steward technical truth shall require courage to preserve uncertainty, disclose limitations, correct errors, retract overclaims, and resist pressure from sponsors, providers, funders, public authorities, media, capital readers, or internal leadership where such pressure would distort the record.

2.3.6 Mission to Conduct and Support Public-Good R&D Across Exponential and Mission-Critical Technologies. 2.3.6(a) GCRI Canada’s mission is to conduct and support public-good research and development across exponential and mission-critical technologies. 2.3.6(b) This mission includes artificial intelligence, machine learning, foundation models, agentic AI, cyber, cybersecurity, cyber-physical systems, climate, disaster, wildfire, flood, drought, energy, water, food, health, biodiversity, telecommunications, compute, sovereign compute, edge compute, cloud compute, confidential compute, high-performance compute, semiconductors, supply chains, infrastructure, geospatial systems, Earth observation, robotics, drones, digital twins, biosecurity, AI-RAN, O-RAN, private wireless, DePIN, distributed ledger technology, blockchain, quantum-relevant systems, industrial systems, critical infrastructure systems, and emerging exponential and mission-critical technologies. 2.3.6(c) GCRI Canada shall treat these domains as interconnected systems requiring evidence discipline and not as isolated verticals. Climate risk may affect energy, water, food, health, connectivity, insurance, public finance, logistics, and community safety. AI may affect cyber, public authority learning, infrastructure operations, misinformation, scientific evidence, procurement, and workforce readiness. Telecommunications, sensing, compute, and geospatial systems may affect observability, sovereignty, data rights, emergency awareness, and public-safe publication. 2.3.6(d) Public-good R&D shall support durable evidence capacity, methods quality, public-good technical baselines, safe interoperability, verifiable compute, verifiable intelligence, public authority literacy, community safeguards, data governance, cybersecurity discipline, and clear separation between upstream truth and downstream execution. 2.3.6(e) Public-good R&D shall not be structured as private product development, sponsor-owned research, provider marketing, procurement support, finance-readiness production, certification business, regulated advisory service, or execution support unless such activity remains within GCRI Canada’s lawful non-executing role and public-benefit mission. 2.3.6(f) Research outputs shall distinguish findings, assumptions, methods, limitations, confidence, open questions, public-safe status, and correction pathways. 2.3.6(g) GCRI Canada shall apply heightened safeguards to R&D involving high-consequence, dual-use, safety-critical, cyber-sensitive, rights-bearing, public authority-facing, infrastructure-relevant, Indigenous or protected knowledge, community-impacting, sovereign-sensitive, sanctions-sensitive, export-control-sensitive, or finance-sensitive materials. 2.3.6(h) Public-good R&D may be open where appropriate and controlled where required. Openness shall not justify exposure of personal data, sensitive infrastructure information, protected knowledge, cyber vulnerabilities, sovereign data, commercial secrets, public authority restricted information, or unsafe implementation details. 2.3.6(i) GCRI Canada shall not allow research prestige, publication incentives, sponsor expectations, public visibility, technical ambition, or innovation pressure to override public-safe publication, data rights, cybersecurity, community safeguards, protected knowledge, correctionability, or non-execution.

2.3.7 Mission to Build, Maintain, and Govern Public-Good Software, Open Technical Baselines, Reference Architectures, APIs, Data Tools, and Conformance-Supporting Instruments. 2.3.7(a) GCRI Canada’s mission is to build, maintain, and govern public-good software, open technical baselines, reference architectures, APIs, dashboards, data tools, test harnesses, evaluation harnesses, templates, scripts, repository assets, workflow components, documentation, and conformance-supporting instruments that support evidence quality, observability, semantic interoperability, public-safe publication, and correctionability. 2.3.7(b) Public-good software shall be governed through secure development, repository discipline, licensing, contribution review, dependency management, vulnerability management, access control, release controls, public-safe documentation, versioning, deprecation, and correction. 2.3.7(c) GCRI Canada shall not release software, APIs, dashboards, datasets, models, schemas, or technical baselines as public-good infrastructure where it cannot reasonably maintain, correct, secure, explain, classify, or retire the asset in relation to its intended use and public reliance. 2.3.7(d) Technical baselines shall describe public-good expectations, design structures, evidence requirements, interoperability requirements, security practices, documentation requirements, data-handling requirements, AI-governance expectations, or public-safe release requirements. 2.3.7(e) Technical baselines may help competent actors build better systems or assess readiness for further review, but they shall not by themselves certify compliance, approve technology, recognize maturity, grant procurement preference, create protocol entitlement, establish finance-readiness, or guarantee technical performance. 2.3.7(f) Reference architectures shall support coherent design across Nexus Observatory Nodes, hubs, clusters, hotspots, national dense cores, public authority learning environments, data rooms, controlled rooms, dashboards, repositories, APIs, and public-good software. They shall preserve role separation and shall not become execution blueprints for GCRI Canada to operate downstream systems. 2.3.7(g) APIs, dashboards, data tools, and reference implementations shall preserve source, scope, classification, confidence, limitation, public-safe status, access control, correction, and lifecycle status where material. 2.3.7(h) User interfaces shall not imply authority beyond the record. A dashboard shall not appear to issue public warnings. An API shall not appear to grant protocol entitlement. A test harness shall not appear to certify a provider. A reference implementation shall not appear to mandate a vendor. 2.3.7(i) Conformance-supporting instruments may help gather evidence, test structure, identify gaps, or support later review by competent actors, but their use shall not be described as certification, recognition, procurement approval, public authority approval, finance-readiness, insurance-readiness, or protocol effect unless a separate lawful program exists. 2.3.7(j) GCRI Canada shall protect public-good technical assets against enclosure, vendor chokepoints, sponsor capture, proprietary dependency, hidden control surfaces, insecure release, uncontrolled forks, license confusion, and unsupported compatibility claims.

2.3.8 Mission to Develop and Govern Verifiable Compute, Verifiable Intelligence, Nexus Truth Engine Methods, and Nexus Observatory Methods. 2.3.8(a) GCRI Canada’s mission is to develop and govern verifiable compute methods, verifiable intelligence methods, Nexus Truth Engine methods, Nexus Observatory methods, compute-to-evidence structures, workload records, model registers, dataset cards, model cards, system cards, benchmark cards, inference records, evaluation records, and AI-use records. 2.3.8(b) Verifiable compute methods shall preserve the conditions under which compute-assisted, AI-assisted, model-assisted, simulation-assisted, benchmark-assisted, and telemetry-assisted outputs may be reviewed, reproduced where appropriate, challenged, limited, secured, and corrected. 2.3.8(c) Verifiable intelligence methods shall ensure that intelligence outputs remain source-lined, provenance-bearing, confidence-aware, limitation-aware, classification-aware, public-safe, and correctionable where material. 2.3.8(d) Nexus Truth Engine methods shall help structure the conditions under which institutional claims are made, challenged, corrected, withheld, superseded, withdrawn, or published as public-safe. 2.3.8(e) Nexus Truth Engine methods shall not be represented as producing absolute truth, machine authority, public warning, certification, recognition, finance-readiness, protocol entitlement, procurement approval, public authority action, or execution authority by themselves. 2.3.8(f) Confidence logic shall help distinguish high-confidence conclusions, low-confidence signals, preliminary findings, disputed evidence, stale evidence, missing evidence, model-dependent outputs, public-safe summaries, and non-public evidence. GCRI Canada shall not allow confidence scores to create false precision or automated authority. 2.3.8(g) Model registers shall identify relevant models, versions where available, intended uses, limitations, evaluation status, data restrictions, access controls, risks, public-safe status, and correction pathways. 2.3.8(h) Dataset cards shall identify dataset origin, scope, lawful basis, permissions, sensitivity, limitations, bias considerations where relevant, update status, retention posture, public-safe constraints, and correction paths. 2.3.8(i) System cards shall describe system context, dependencies, controls, intended use, prohibited use, known risks, security posture, data posture, review status, and correction pathways. 2.3.8(j) Inference records shall be maintained where AI or model outputs materially contribute to evidence, publication, observability, public authority learning, technical baselines, or public-safe reporting. Such records shall preserve enough information to allow authorized review without exposing protected materials. 2.3.8(k) AI-assisted work shall not become unverifiable institutional assertion. AI systems may assist classification, retrieval, summarization, anomaly detection, comparison, translation, routing, and analysis, but they shall not become the authority for truth, recognition, public warning, finance-readiness, certification, procurement, public authority decision, or publication without review. 2.3.8(l) GCRI Canada shall govern AI and compute methods against model hallucination, bias, overconfidence, data leakage, hidden training use, prompt injection, insecure integration, vendor capture, cross-border transfer, unreviewed automation, and AI-generated public authority or finance implication.

2.3.9 Mission to Strengthen Public Authority Learning, Technical Literacy, Evidence Literacy, AI Literacy, Cyber Literacy, and Public-Safe Interpretation. 2.3.9(a) GCRI Canada’s mission is to strengthen public authority learning, technical literacy, evidence literacy, AI literacy, cyber literacy, observability literacy, data literacy, public-safe interpretation, and systems-risk understanding. 2.3.9(b) Public authority learning may include briefings, workshops, scenario exercises, technical literacy programs, AI literacy, cyber literacy, observability interpretation, evidence literacy, controlled-room review, public-safe summaries, and system-risk explanation. 2.3.9(c) Public authority learning shall remain non-delegated, non-regulatory, non-procurement, non-funding, non-public-warning, non-emergency-command, non-public-finance, and non-sovereign-obligation. Public authorities retain their own legal powers, duties, accountabilities, decision procedures, procurement rules, public finance authorities, emergency authorities, regulatory powers, and public communication responsibilities. 2.3.9(d) GCRI Canada may help public authorities understand technical claims, evidence limitations, AI risks, cyber dependencies, observability outputs, data governance, public-safe publication, community safeguards, and systemic risk interactions, but it shall not speak as the public authority, decide for the public authority, issue official guidance on behalf of the public authority, or imply that public authority participation constitutes adoption. 2.3.9(e) Public authority interfaces shall be structured through capacity classification, agenda discipline, records, public-safe language, confidentiality where required, competition safety, procurement neutrality, privacy, cybersecurity, and conflict-of-law awareness. 2.3.9(f) Participation by public officials, agencies, departments, regulators, emergency-management actors, public finance bodies, public health actors, infrastructure authorities, or other public-sector participants shall be recorded in a manner that avoids ambiguity regarding capacity, authority, endorsement, reliance, procurement, finance, public warning, and sovereign obligation. 2.3.9(g) Evidence literacy materials shall help audiences distinguish data, evidence, method, confidence, uncertainty, limitation, recognition, adoption, certification, finance-readiness, public authority action, and execution. 2.3.9(h) AI literacy and cyber literacy materials shall support safe understanding of model outputs, automated systems, cyber dependencies, vulnerabilities, secure collaboration, data protection, public-safe release, and the risks of AI-generated or cyber-derived authority. 2.3.9(i) Academy and training materials shall develop competence and literacy without creating regulated credentials, professional licensure, public authority qualification, provider preference, procurement advantage, certification effect, recognition effect, finance-readiness, or public authority endorsement by default. 2.3.9(j) Where public authority learning materials are published, shared, or referenced externally, GCRI Canada shall ensure that such materials do not imply delegated public authority, official warning, public procurement approval, regulatory approval, funding approval, public finance approval, or sovereign obligation.

2.3.10 Mission to Preserve Privacy, Data Rights, Sovereign Data, Cybersecurity, Community Safeguards, Protected Knowledge, and Do-No-Harm Principles. 2.3.10(a) GCRI Canada’s mission is to preserve privacy, data rights, sovereign data, cybersecurity, community safeguards, protected knowledge, Indigenous and local knowledge respect, protected participation, accessibility, and do-no-harm principles across all GCRI Canada activities. 2.3.10(b) Privacy shall include protection against unnecessary collection, unjustified access, overlinkage, re-identification, profiling, coercive visibility, contextual misuse, function creep, unsafe secondary use, uncontrolled metadata exposure, and excessive retention. 2.3.10(c) Data shall be processed only within lawful, purpose-bound, proportionate, classification-aware, and public-benefit-aligned conditions. GCRI Canada shall not collect, retain, infer, link, publish, or reuse data merely because it is technically available, analytically interesting, inexpensive to store, useful for future research, convenient for dashboards, or attractive to sponsors, providers, public authorities, or capital readers. 2.3.10(d) Rights-bearing data shall be identified by effect and context, not only by formal classification. Aggregated data, geospatial layers, community indicators, infrastructure data, model outputs, inferred attributes, public authority datasets, and linked records may create risk through re-identification, profiling, exposure, or contextual misuse. 2.3.10(e) Sovereign data shall be handled through localization, sovereign data zones, compute-to-data, cross-border review, public authority controls, Indigenous data considerations, conflict-of-law review, and jurisdictional respect where applicable. Data shall not move merely because technology permits movement. 2.3.10(f) Cybersecurity shall protect repositories, controlled rooms, data rooms, public-good software, technical baselines, keys, secrets, credentials, dashboards, public authority materials, protected knowledge, participant data, AI workflows, and public-safe outputs. 2.3.10(g) Community safeguards shall apply before, during, and after evidence work. They shall inform project design, data intake, consent alignment where applicable, classification, controlled-room handling, publication review, public-safe mapping, attribution, redaction, retention, withdrawal where applicable, grievance, remedy, and correction. 2.3.10(h) Indigenous and local knowledge shall be handled with respect for applicable law, governance expectations, protocols, cultural sensitivity, territorial context, restrictions on disclosure or reuse, and community authority. 2.3.10(i) GCRI Canada shall not publish, model, map, summarize, train on, or integrate protected knowledge in a manner that strips context, violates expectation, exposes sensitive locations, discloses protected practices, or converts protected knowledge into public-good assets without proper authority and safeguards. 2.3.10(j) Do-no-harm shall require anticipatory review of foreseeable harms, including privacy harm, dignity harm, cultural harm, community exposure, infrastructure risk, cyber risk, public authority confusion, finance overclaim, public warning confusion, procurement implication, protected knowledge misuse, AI-mediated distortion, retaliation risk, and downstream reliance. 2.3.10(k) Where privacy, data rights, sovereign data, cybersecurity, community safeguards, protected knowledge, or do-no-harm concerns conflict with openness, speed, visibility, sponsor interest, provider interest, public authority interest, technical ambition, or analytical usefulness, GCRI Canada shall apply the more protective lawful approach pending proper review.

2.3.11 Mission to Maintain Public-Good Continuity, Correctionability, Auditability, and Public-Safe Publication. 2.3.11(a) GCRI Canada’s mission is to maintain public-good continuity, correctionability, auditability, traceability, custody, institutional memory, public-safe publication, and final archival discipline. 2.3.11(b) Public-good continuity shall require GCRI Canada to preserve records, repositories, software, methods, technical baselines, public-safe publications, evidence infrastructure, public authority learning materials, data-handling records, AI-use records, correction chains, and technical memory beyond funding cycles, leadership changes, technology changes, platform changes, public attention, sponsor priorities, provider relationships, and institutional growth. 2.3.11(c) Correctionability shall apply to evidence records, methods, ontologies, controlled vocabulary, public-safe publications, dashboards, maps, datasets, software releases, technical baselines, model registers, dataset cards, system cards, benchmark cards, Academy materials, public authority materials, sponsorship references, provider references, and Nexus interface records. 2.3.11(d) Correctionability shall include intake, triage, review, authority assignment, records update, public-safe notice where required, downstream notice where required, supersession, withdrawal, retraction, downgrade, reinstatement, archival, and closeout. 2.3.11(e) GCRI Canada shall not publish, release, or rely on material outputs in a manner that makes correction impracticable where reliance exists. Systems shall be designed for correction. Public materials shall allow updates. Repositories shall preserve history. Dashboards shall show status where material. Technical baselines shall be versioned. 2.3.11(f) Auditability shall require records sufficient to show who authorized material actions, what evidence supported them, what methods were applied, what review occurred, what classification applied, what limitations were known, what public-safe status applied, and what correction path exists. 2.3.11(g) Traceability shall apply to evidence, methods, datasets, models, software releases, public-safe publications, public authority materials, sponsorship records, provider references, public claims, and Nexus interface records. GCRI Canada shall not rely on untraceable claims, uncontrolled copies, private memory, or undocumented technical changes for material institutional acts. 2.3.11(h) Public-safe publication shall protect privacy, cybersecurity, infrastructure sensitivity, public authority limits, finance sensitivity, commercial sensitivity, community safeguards, Indigenous and protected knowledge, vulnerable communities, public safety, protected participation, and lawful confidentiality. Evidence may be true yet not public-safe. 2.3.11(i) Where full public release is unsafe, GCRI Canada may use redaction, aggregation, delayed publication, controlled annexes, restricted rooms, private correction notices, public-safe summaries, synthetic examples, or non-public archival. 2.3.11(j) Public-safe publication shall include language discipline. Titles, headings, summaries, visualizations, dashboards, maps, captions, labels, tags, metadata, public authority references, sponsor acknowledgments, provider references, and public statements shall be reviewed for public-safe meaning. 2.3.11(k) Correction shall not be treated as reputational failure. It is a constitutional duty and a condition of public trust. GCRI Canada shall maintain the capacity to correct because the institution that cannot correct cannot steward truth.

2.3.12 Mission to Support Lawful Downstream Action by Others Without Becoming the Downstream Actor. 2.3.12(a) GCRI Canada’s mission includes supporting lawful downstream action by competent actors without becoming the downstream actor. 2.3.12(b) GCRI Canada may support downstream action by producing evidence, methods, observability outputs, technical baselines, public-good software, public-safe reports, model records, dataset records, benchmark records, public authority learning materials, confidence summaries, correction signals, and evidence inputs that help competent actors make better decisions under their own authority. 2.3.12(c) Downstream actors may include GRF, GRA, protocol authorities, public authorities, universities, communities, Indigenous institutions, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, investors, insurers, lenders, public finance actors, operators, standards bodies, and implementation partners, each acting within its own lawful authority, duties, procedures, and accountability. 2.3.12(d) GCRI Canada shall not become GRF merely because its evidence supports recognition, maturity, standing, claims-discipline, stakeholder formation, public-safe reporting, or public-facing legitimacy work. 2.3.12(e) GCRI Canada shall not become GRA merely because its evidence supports finance-readiness interpretation, capital-readability, investor literacy, insurance-readiness, diligence translation, or common-business-interest work. 2.3.12(f) GCRI Canada shall not become protocol authority merely because its methods, schemas, APIs, software, technical baselines, proof templates, or observability methods support protocol-adjacent work. 2.3.12(g) GCRI Canada shall not become a public authority merely because public authorities learn from, contribute to, attend, request, discuss, or rely upon its evidence, methods, learning materials, public-safe summaries, observability outputs, or technical baselines. 2.3.12(h) GCRI Canada shall not become a procurement body, certifier, finance actor, insurer, lender, underwriter, rating agency, broker, investment adviser, public warning authority, emergency commander, infrastructure operator, deployment company, National Consortium Company, Project SPV, or vendor platform by producing upstream support. 2.3.12(i) Where GCRI Canada outputs are handed off to downstream actors, such handoff shall be records-valid and shall identify, where material, source, status, scope, limitations, review level, public-safe classification, intended receiving function, and correction path. 2.3.12(j) GCRI Canada shall preserve the agency and accountability of downstream actors. Public authorities shall make public decisions. Boards shall make governance decisions. GRF shall make recognition and maturity determinations where authorized. GRA shall handle finance-readiness translation within its boundary. Protocol authority shall determine protocol effect where competent. Enterprise actors and Project SPVs shall execute their lawful operations. 2.3.12(k) The fact that downstream actors rely on GCRI Canada’s upstream truth shall not alter GCRI Canada’s role. Reliance by others may increase the need for careful limitations, correction notices, public-safe language, and records discipline, but it shall not convert GCRI Canada into the downstream actor. 2.3.12(l) Where an activity, output, public claim, dashboard, map, technical baseline, sponsor reference, provider reference, public authority reference, or finance-adjacent material creates credible risk that GCRI Canada is being perceived as the downstream actor, GCRI Canada shall narrow, correct, reclassify, withdraw, redesign, route, or refuse the activity as required to preserve this Charter.

2.4 Public-Benefit Mandate

2.4.1 Public-Benefit Mandate as the Controlling Purpose of GCRI Canada. 2.4.1(a) The public-benefit mandate is the controlling purpose of GCRI Canada. It shall govern GCRI Canada’s assets, governance, fiduciary decisions, programs, staffing, fundraising, sponsorships, grants, donations, technical architecture, publications, public authority interfaces, data practices, AI use, cybersecurity practices, research activities, software releases, Nexus interfaces, and public claims. 2.4.1(b) No revenue opportunity, sponsor relationship, provider contribution, public authority interest, media opportunity, institutional partnership, technology opportunity, data-access opportunity, funding pathway, policy-window opportunity, strategic visibility opportunity, or ecosystem expansion opportunity shall override the public-benefit mandate. 2.4.1(c) Where a proposed activity is attractive, funded, urgent, influential, technically compelling, reputationally valuable, publicly visible, or strategically important but inconsistent with public-benefit stewardship, GCRI Canada shall narrow, redesign, defer, decline, transfer, suspend, or terminate the activity. 2.4.1(d) The public-benefit mandate shall be interpreted as an active duty to preserve public-good infrastructure, evidence integrity, methods discipline, semantic precision, safe publication, privacy, cybersecurity, protected knowledge, lawful collaboration, role separation, anti-capture protections, anti-enclosure protections, anti-drift discipline, and correctionability. 2.4.1(e) The public-benefit mandate shall not be satisfied by mere statements of public purpose, public-facing language, social value claims, broad institutional aspiration, public-interest branding, sponsor-supported visibility, public authority attendance, or generalized mission language. 2.4.1(f) The public-benefit mandate shall operate as a constraint on discretion. Directors, officers, councils, committees, staff, fellows, advisors, participants, sponsors, providers, hosts, donors, funders, contractors, contributors, public authority participants, and partners shall not treat flexibility, innovation, urgency, experimentation, technical ambition, fundraising pressure, or ecosystem-building as permission to dilute the mandate. 2.4.1(g) Every material institutional act shall be capable of being explained as mission-faithful, law-compatible, records-valid, role-bounded, public-safe, correctionable, and public-benefit preserving. 2.4.1(h) Public-benefit purpose shall prevail over institutional convenience, speed, scale, publicity, sponsor preference, provider interest, donor expectation, public authority ambiguity, capital-reader attention, technical dependency, platform design, or narrative advantage. 2.4.1(i) GCRI Canada shall maintain policies, procedures, records, review pathways, funding controls, public claims discipline, data controls, technical-release controls, and correction mechanisms sufficient to demonstrate that the public-benefit mandate governs institutional conduct in practice and not merely in statement.

2.4.2 Public-Benefit Mandate in Risk, Resilience, Innovation, Evidence, Intelligence, Technical Governance, and Systemic De-Risking. 2.4.2(a) GCRI Canada’s public-benefit mandate includes systemic risk evidence, resilience intelligence, innovation governance, technical evidence, public-safe observability, institutional learning, technical truth, data-to-evidence translation, evidence-to-decision translation, and systemic de-risking. 2.4.2(b) The purpose of this mandate is not merely to produce reports, convene events, issue commentary, publish dashboards, maintain public visibility, or support institutional branding, but to create durable public-good infrastructure for trust, learning, correction, public-safe interpretation, and safe action by others. 2.4.2(c) Systemic de-risking shall be understood as the disciplined improvement of evidence, methods, observability, interpretation, safeguards, semantic coherence, institutional memory, technical baselines, public authority learning, and correction capacity across interdependent systems. 2.4.2(d) Systemic de-risking shall not be represented as a guarantee of safety, elimination of risk, regulatory approval, insurance suitability, investment suitability, public authority adoption, public finance approval, procurement approval, operational control, or execution authority. 2.4.2(e) GCRI Canada may reduce uncertainty, improve readiness, reveal gaps, structure evidence, clarify limitations, support learning, strengthen observability, and preserve correction pathways, but it shall not claim to remove all risk or decide acceptable risk for competent downstream actors. 2.4.2(f) Innovation governance under this mandate shall not mean slowing innovation for its own sake or accelerating innovation without safeguards. It shall mean enabling better innovation through evidence quality, public-good technical baselines, safe interoperability, correctionable methods, public authority literacy, community safeguards, data governance, cybersecurity discipline, technical truth, and clear separation between upstream truth and downstream execution. 2.4.2(g) GCRI Canada shall treat resilience as both technical and institutional. Resilience includes infrastructure continuity, data integrity, cyber resilience, community protection, governance continuity, public authority learning, supply-chain awareness, degraded-mode understanding, public-safe communication, continuity of records, and the ability to correct errors before they compound into public harm or institutional overclaim. 2.4.2(h) Technical governance shall include lawful, records-valid, public-benefit stewardship of methods, ontologies, controlled vocabulary, technical baselines, observability architecture, public-good software, secure repositories, AI-use records, model registers, dataset records, benchmark records, system cards, and correction chains. 2.4.2(i) Intelligence under this mandate shall remain evidence-supporting and decision-supporting. It shall not become public authority command, public warning, finance-readiness determination, procurement direction, certification, market rating, protocol entitlement, or execution instruction by default. 2.4.2(j) Public-benefit de-risking shall be measured by improved evidence quality, improved methods, improved public-safe interpretation, improved safeguards, improved correctionability, improved institutional memory, improved public authority learning, and improved role clarity, not by public narrative, sponsor satisfaction, provider advantage, capital-reader interest, or institutional visibility.

2.4.3 Public-Benefit Mandate in AI, Cyber, Climate, Disaster, Energy, Water, Food, Health, Biodiversity, Telecommunications, Compute, Infrastructure, and Exponential Technologies. 2.4.3(a) GCRI Canada’s public-benefit mandate includes artificial intelligence, machine learning, foundation models, agentic AI, cyber, cybersecurity, cyber-physical systems, climate, disaster, wildfire, flood, drought, energy, water, food, health, biodiversity, telecommunications, compute, sovereign compute, edge compute, cloud compute, confidential compute, high-performance compute, semiconductors, supply chains, infrastructure, geospatial systems, Earth observation, robotics, drones, digital twins, biosecurity, AI-RAN, O-RAN, private wireless, DePIN, distributed ledger technology, blockchain, quantum-relevant systems, industrial systems, critical infrastructure systems, and other emerging exponential and mission-critical technologies. 2.4.3(b) GCRI Canada shall treat these domains as interconnected systems requiring evidence discipline and not as isolated verticals. Climate risk may affect energy, water, food, health, connectivity, insurance, public finance, logistics, public safety, biodiversity, infrastructure, and community resilience. AI may affect cyber, public authority learning, infrastructure operations, misinformation, scientific evidence, procurement, workforce readiness, data rights, and public trust. Telecommunications, sensing, compute, and geospatial systems may affect observability, sovereignty, data rights, emergency awareness, public-safe publication, and critical infrastructure resilience. 2.4.3(c) The inclusion of a technology domain within GCRI Canada’s mandate shall not create authority to regulate, certify, approve, procure, finance, deploy, operate, insure, underwrite, rate, command, or endorse that technology. 2.4.3(d) The mandate authorizes evidence stewardship, methods development, observability, ontology, public-good R&D, public-good software, public-safe publication, literacy, technical baselines, verifiable compute methods, verifiable intelligence methods, and correctionable knowledge infrastructure within GCRI Canada’s non-executing role. 2.4.3(e) Where technologies are high-consequence, dual-use, safety-critical, cyber-sensitive, rights-bearing, public authority-facing, infrastructure-relevant, community-impacting, sovereign-sensitive, sanctions-sensitive, export-control-sensitive, or finance-sensitive, GCRI Canada shall apply heightened safeguards. 2.4.3(f) Heightened safeguards may include controlled-room handling, clean-room handling, public-safe redaction, restricted publication, secure development review, lawful-basis review, privacy impact review, export-control awareness, sanctions screening, protected knowledge controls, Indigenous and community safeguards, model governance, independent challenge, enhanced cybersecurity, and public claims review. 2.4.3(g) GCRI Canada shall not allow technological novelty, urgency, hype, strategic relevance, investor attention, public authority interest, provider pressure, sponsor expectations, or market excitement to weaken evidence discipline, public-benefit purpose, privacy, cybersecurity, protected knowledge safeguards, public authority boundaries, finance boundaries, or non-execution. 2.4.3(h) Public-benefit treatment of technology shall require that claims about capabilities, risks, maturity, reliability, safety, readiness, interoperability, public authority relevance, finance relevance, or deployment relevance remain tied to records, methods, limitations, public-safe status, and correction pathways. 2.4.3(i) GCRI Canada shall maintain cross-domain evidence architecture so that interactions among technologies, infrastructure, communities, public authorities, ecosystems, markets, and environment can be studied without collapsing institutional roles or creating unsupported downstream consequences.

2.4.4 Public-Benefit Mandate in Research, Education, Technical Stewardship, Public-Good Software, and Open Technical Baselines. 2.4.4(a) GCRI Canada’s public-benefit mandate includes public-benefit research, education, technical stewardship, public-good software, open technical baselines, public-safe reference architectures, evidence tools, datasets, APIs, dashboards, Academy materials, workforce learning, public authority learning, and institutional capacity-building. 2.4.4(b) These activities shall be conducted to improve evidence quality, public-interest literacy, technical accountability, interoperability, safeguards, public-safe interpretation, correctionability, and lawful downstream use by competent actors. 2.4.4(c) Research shall be conducted and supported in a manner that preserves independence, method integrity, source discipline, limitation disclosure, public-safe publication, correctionability, privacy, data rights, cybersecurity, protected knowledge, Indigenous and community safeguards, and freedom from sponsor, provider, political, media, or finance-driven distortion. 2.4.4(d) Education shall develop competence and literacy without creating regulated credentials, professional licensure, public authority qualification, provider preference, procurement advantage, certification effect, recognition effect, finance-readiness, public authority endorsement, or guaranteed competence by default. 2.4.4(e) GCRI Canada may issue participation records, learning records, completion records, knowledge materials, public-safe training outputs, and evidence literacy materials, but such outputs shall be role-bounded and shall not be represented as professional licenses, legal qualifications, regulated certifications, procurement qualifications, finance-readiness, or public authority approvals unless separately and lawfully authorized. 2.4.4(f) Technical stewardship shall include maintenance, documentation, security, review, versioning, licensing, contribution governance, vulnerability management, correction, deprecation, supersession, archival, and retirement of public-good technical assets. 2.4.4(g) GCRI Canada shall not treat research outputs, software, baselines, dashboards, APIs, datasets, models, technical notes, or Academy materials as disposable project artifacts where they carry public-good reliance. Public-good technical stewardship requires lifecycle responsibility. 2.4.4(h) Open technical baselines shall be open where appropriate and controlled where required. Openness shall not justify exposure of personal data, sensitive infrastructure information, protected knowledge, cyber vulnerabilities, sovereign data, commercial secrets, public authority restricted information, finance-sensitive information, or unsafe implementation details. 2.4.4(i) GCRI Canada’s mandate is governed openness, not uncontrolled release. Public-good assets shall be reusable where lawful, governed where required, secure by design, privacy-preserving, versioned, documented, and correctionable. 2.4.4(j) Technical stewardship shall not create vendor preference, procurement approval, certification, recognition, finance-readiness, public authority adoption, protocol entitlement, or execution authority by default. Technical assets may support downstream review by others, but they shall remain within GCRI Canada’s upstream public-good role.

2.4.5 Public-Benefit Mandate in Public Authority Learning Without Delegated Public Authority. 2.4.5(a) GCRI Canada may support public authority learning, evidence literacy, AI literacy, cyber literacy, observability literacy, public-safe interpretation, technical scenario understanding, systems-risk awareness, and capacity-building for public institutions. 2.4.5(b) Such learning shall remain non-delegated, non-regulatory, non-procurement, non-funding, non-public-warning, non-emergency-command, non-public-finance, non-enforcement, and non-sovereign-obligation. 2.4.5(c) Public authorities retain their own legal powers, duties, accountabilities, decision procedures, procurement rules, public finance authorities, emergency authorities, regulatory powers, enforcement powers, public communication responsibilities, and legal obligations. 2.4.5(d) Public authority learning shall be capacity-building, not authority transfer. GCRI Canada may help public authorities understand technical claims, evidence limitations, AI risks, cyber dependencies, observability outputs, data governance, public-safe publication, community safeguards, protected knowledge issues, and systemic risk interactions, but it shall not speak as the public authority, decide for the public authority, issue official guidance on behalf of the public authority, or imply that public authority participation constitutes adoption. 2.4.5(e) Public authority interfaces shall be structured through capacity classification, agenda discipline, records, public-safe language, confidentiality where required, competition safety, procurement neutrality, privacy controls, cybersecurity controls, data-handling rules, and conflict-of-law awareness. 2.4.5(f) Participation by public officials, agencies, departments, regulators, emergency-management actors, public finance bodies, public health actors, infrastructure authorities, Indigenous governments or institutions, municipalities, or other public-sector participants shall be recorded in a manner that avoids ambiguity regarding capacity, authority, endorsement, adoption, reliance, procurement, finance, public warning, and sovereign obligation. 2.4.5(g) Where public authority learning materials are published, shared, referenced externally, used in public rooms, or included in Academy materials, GCRI Canada shall ensure that such materials do not imply delegated public authority, official warning, public procurement approval, regulatory approval, funding approval, public finance approval, official public guidance, public-private partnership, or sovereign obligation. 2.4.5(h) Public authority logos, names, quotes, images, attendance, data contributions, comments, requests, or participation shall not be used in a manner that implies approval, adoption, funding, procurement, regulation, warning, enforcement, or endorsement unless such implication is expressly authorized, lawful, and records-valid. 2.4.5(i) Where public authority ambiguity arises, GCRI Canada shall adopt the most protective interpretation and issue clarification where material. Public authority proximity shall not become public authority status.

2.4.6 Public-Benefit Mandate in Community Safeguards, Indigenous and Local Knowledge Respect, Protected Participation, and Public-Safe Mapping. 2.4.6(a) GCRI Canada shall protect community participation, Indigenous knowledge, local knowledge, territorial knowledge, protected knowledge, culturally sensitive knowledge, environmental knowledge, vulnerable communities, remote communities, at-risk participants, public-safe mapping, and protected participation. 2.4.6(b) Evidence work shall not become extraction, exposure, mapping harm, AI training misuse, narrative appropriation, public simplification, sponsor-enabled access, provider-enabled access, public authority overexposure, or technical processing that damages communities. 2.4.6(c) Community safeguards shall apply before, during, and after evidence work. They shall inform project design, data intake, consent alignment where applicable, classification, controlled-room handling, clean-room handling, publication review, public-safe mapping, attribution, redaction, retention, withdrawal where applicable, grievance, remedy, and correction. 2.4.6(d) GCRI Canada shall not treat community-linked information as raw material merely because it is available, useful, public, geospatially visible, donated, inferable, model-readable, or technically processable. 2.4.6(e) Indigenous and local knowledge shall be handled with respect for applicable law, Indigenous governance protocols, local governance expectations, cultural sensitivity, territorial context, restrictions on disclosure or reuse, and community authority. 2.4.6(f) GCRI Canada shall not publish, model, map, summarize, train on, commercialize, route, integrate, or translate Indigenous, local, territorial, cultural, environmental, or protected knowledge in a manner that strips context, violates expectation, exposes sensitive locations, discloses protected practices, weakens community authority, or converts protected knowledge into public-good assets without proper authority and safeguards. 2.4.6(g) Protected participation shall allow persons and communities to contribute, challenge, correct, or raise concerns without retaliation, exposure, coercion, reputational harm, loss of access, sponsor pressure, provider pressure, public authority pressure, or misuse of their participation. 2.4.6(h) Public-safe mapping shall receive heightened discipline. Maps, dashboards, geospatial layers, digital twins, observability outputs, infrastructure overlays, community risk profiles, environmental intelligence, and public authority-facing visualizations shall be reviewed for potential harm. 2.4.6(i) Public-safe mapping review shall consider exposure of vulnerable communities, protected sites, critical infrastructure, evacuation routes, cyber-sensitive assets, ecological sensitivity, culturally significant areas, contested territorial information, small-group re-identification, stigmatization, retaliation, exploitation, or misuse. 2.4.6(j) Where full publication, precise mapping, or granular disclosure creates harm risk, GCRI Canada shall use aggregation, redaction, generalization, delayed publication, controlled annexes, restricted rooms, synthetic examples, non-public archival, or refusal to publish. 2.4.6(k) Community safeguards and protected knowledge obligations shall not be waived by sponsor interest, public authority interest, research convenience, public visibility, data availability, technical feasibility, or public-good rhetoric.

2.4.7 Public-Benefit Mandate in Data, AI, Cybersecurity, Secure Collaboration, and Sovereign Data Handling. 2.4.7(a) GCRI Canada shall treat data governance, AI governance, cybersecurity, secure collaboration, sovereign data handling, compute-to-data, cross-border transfer review, restricted rooms, clean rooms, controlled repositories, model registers, inference records, secure release, identity and access management, vulnerability handling, and incident response as mission infrastructure. 2.4.7(b) These controls shall be designed for public trust, institutional integrity, evidence quality, protected participation, public authority confidence, and public-good continuity, not merely for technical compliance or administrative risk management. 2.4.7(c) Data shall be processed only within lawful, purpose-bound, proportionate, classification-aware, rights-respecting, and public-benefit-aligned conditions. 2.4.7(d) GCRI Canada shall not collect, retain, infer, link, publish, export, train on, or reuse data merely because it is technically available, analytically interesting, inexpensive to store, useful for future research, convenient for dashboards, attractive to sponsors, valuable to providers, requested by public authorities, or useful to capital readers. 2.4.7(e) AI use shall remain evidence-supporting and human-governed where material. AI systems may assist classification, retrieval, summarization, anomaly detection, comparison, translation, routing, pattern identification, evidence gap identification, and analysis, but shall not become the authority for truth, recognition, public warning, finance-readiness, certification, procurement, public authority decision, or publication without review. 2.4.7(f) AI outputs shall be traceable, bounded, evaluated, classified, public-safe reviewed, human-reviewed where material, and correctable. GCRI Canada shall distinguish AI-assisted workflow from AI-authorized result. 2.4.7(g) GCRI Canada shall not ingest restricted, rights-bearing, sovereign-sensitive, public authority restricted, protected knowledge, community-sensitive, confidential, or cyber-sensitive materials into AI systems unless lawful, authorized, secure, purpose-bound, classification-compliant, and consistent with data rights, sovereignty, and public-safe publication rules. 2.4.7(h) Cybersecurity and secure collaboration shall protect repositories, controlled rooms, data rooms, public-good software, technical baselines, keys, secrets, credentials, dashboards, public authority materials, protected knowledge, community data, model records, dataset records, and correction systems. 2.4.7(i) GCRI Canada shall treat weak security as a public-interest risk because compromised systems can distort evidence, expose participants, corrupt public-good assets, compromise public authority confidence, enable misinformation, and undermine institutional trust. 2.4.7(j) Sovereign data handling shall include localization, sovereign data zones, compute-to-data, cross-border transfer review, conflict-of-law review, public authority data controls, Indigenous data considerations, community data safeguards, and jurisdictional respect. Data shall not move merely because technology permits movement. 2.4.7(k) Secure collaboration tools, repositories, model providers, cloud environments, AI systems, communications platforms, and release channels shall be reviewed for access control, logging, privacy, security, data residency, vendor control, dependency risk, export behavior, retention, deletion, and correction capability before use for protected or mission-critical work.

2.4.8 Public-Benefit Mandate in Evidence Quality, Methodological Integrity, Transparency Minima, and Lawful Redaction. 2.4.8(a) GCRI Canada’s public-benefit mandate includes evidence quality, methodological integrity, transparency minima, lawful redaction, lawful confidentiality, public-safe summaries, controlled annexes, limitation disclosure, source protection, correction, and public-safe publication. 2.4.8(b) Transparency shall be pursued without exposing personal data, rights-bearing data, cyber-sensitive material, infrastructure vulnerabilities, public authority restrictions, finance-sensitive information, commercial sensitivity, community-protected data, culturally sensitive information, Indigenous knowledge, local protected knowledge, or protected knowledge. 2.4.8(c) Evidence quality shall require source discipline, provenance, method clarity, confidence treatment, limitation disclosure, uncertainty handling, review status, challenge pathways, public-safe status, and correction. 2.4.8(d) GCRI Canada shall not permit public claims, technical claims, sponsor claims, provider claims, public authority references, impact claims, finance-adjacent language, procurement-adjacent language, certification-adjacent language, or Nexus-compatible language to exceed the evidence record. 2.4.8(e) Methodological integrity shall require independence from sponsor pressure, provider preference, political convenience, public authority expectation, media simplicity, finance narrative, procurement pressure, institutional ambition, and public visibility. 2.4.8(f) Methods shall be selected because they are appropriate, explainable, reviewable, records-valid, proportionate, context-sensitive, rights-respecting, public-safe where released, and correctable, not because they produce preferred outcomes or support predetermined narratives. 2.4.8(g) Transparency minima shall require that GCRI Canada explain enough about an output for relevant audiences to understand its purpose, scope, authority, limitations, public-safe status, review status, and correction path. 2.4.8(h) Where full transparency is unsafe, unlawful, contractually restricted, privacy-infringing, cyber-risky, public authority-restricted, community-harming, finance-sensitive, commercially sensitive, or protected-knowledge-infringing, GCRI Canada shall use controlled annexes, redacted summaries, classification notes, public-safe explanations, restricted rooms, or non-public archival to preserve accountability without causing harm. 2.4.8(i) Redaction shall be lawful, proportionate, reviewable, and records-valid. Redaction shall not be used to conceal error, avoid accountability, shield sponsor influence, hide provider preference, avoid correction, or preserve institutional reputation. 2.4.8(j) GCRI Canada shall preserve source protection where disclosure would expose protected participants, vulnerable communities, confidential sources, Indigenous or protected knowledge, public authority restricted information, cybersecurity-sensitive materials, personal data, or lawful confidentiality interests. 2.4.8(k) Lawful redaction and transparency minima shall operate together. GCRI Canada shall be open enough to sustain public trust and controlled enough to prevent harm.

2.4.9 Public-Benefit Mandate in Anti-Capture, Anti-Enclosure, Anti-Fragmentation, and Anti-Drift. 2.4.9(a) GCRI Canada shall protect against capture, enclosure, fragmentation, drift, role collapse, sponsor influence, provider preference, public authority confusion, finance overclaim, certification drift, protocol drift, procurement implication, narrative inflation, technical dependency capture, public-good asset enclosure, informal authority, and execution by stealth. 2.4.9(b) Public-benefit purpose is not only what GCRI Canada does; it is also what GCRI Canada refuses to become. 2.4.9(c) Anti-capture discipline shall prevent sponsors, donors, funders, providers, hosts, platforms, public authorities, capital readers, media actors, founders, technical contributors, or internal leaders from controlling evidence, methods, publication timing, public claims, correction, access, public authority interfaces, technical baselines, repository design, or public meaning. 2.4.9(d) Influence may be subtle and may arise through dependency, visibility, access, priority-setting, funding conditions, data control, cloud control, model dependency, technical control, staffing support, media attention, public authority proximity, or narrative power. It need not take the form of formal ownership or written veto rights. 2.4.9(e) Anti-enclosure discipline shall prevent public-good assets from becoming proprietary chokepoints, vendor-controlled infrastructure, sponsor-branded inventory, exclusive market advantage, privately controlled semantics, proprietary dependency, public authority access channel, or execution infrastructure. 2.4.9(f) Public-good technical assets shall remain governed for public benefit, with appropriate openness, licensing, portability, documentation, security, access controls, contribution rules, lifecycle management, and correction. 2.4.9(g) Anti-fragmentation discipline shall preserve coherent institutional meaning across programs, public materials, systems, repositories, national interfaces, public authority interfaces, technical baselines, and Nexus-compatible instruments. 2.4.9(h) GCRI Canada shall localize and adapt responsibly without allowing inconsistent terminology, uncontrolled forks, jurisdictional confusion, program-specific exceptions, or repeated practice to silently rewrite its constitutional role. 2.4.9(i) Anti-drift discipline shall prevent GCRI Canada from becoming a consultancy, event company, vendor, finance actor, certification body by default, procurement gate, public authority proxy, protocol authority, emergency command body, public warning body, infrastructure operator, or execution actor by repetition, visibility, funding, urgency, public authority participation, technical centrality, or ecosystem expectation. 2.4.9(j) Where capture, enclosure, fragmentation, or drift risk arises, GCRI Canada shall impose safeguards, ring-fence the activity, revise terms, restrict access, diversify support, require independent review, disclose conflicts where appropriate, redesign the structure, correct public claims, or refuse the arrangement. 2.4.9(k) Anti-capture, anti-enclosure, anti-fragmentation, and anti-drift controls shall be implemented through funding review, sponsorship controls, provider-neutral rules, public authority capacity classification, contract clauses, repository governance, dependency mapping, controlled vocabulary, public claims review, correction pathways, and board oversight.

2.4.10 Public-Benefit Mandate as a Constraint on Revenue, Sponsorship, Partnerships, Programs, Public Claims, and Technical Architecture. 2.4.10(a) Revenue, sponsorship, donations, grants, memberships, subscriptions, training fees, fellowships, in-kind contributions, provider tools, cloud credits, AI model access, data access, facilities, public authority rooms, public claims, software architecture, repository structure, technical dependencies, AI systems, dashboards, data rooms, public-safe reports, and Nexus interfaces shall be designed under public-benefit constraint. 2.4.10(b) Sustainability shall never become capture. Scale shall never become drift. Visibility shall never become authority. Technical centrality shall never become control. Public authority proximity shall never become public authority status. Sponsorship shall never become public-good ownership. Provider participation shall never become procurement preference. 2.4.10(c) Each support pathway shall be reviewed for compatibility with mission lock, non-execution, public-benefit purpose, sponsor non-control, provider neutrality, privacy, cybersecurity, protected knowledge, community safeguards, public authority boundaries, finance boundaries, competition safety, public-safe publication, correctionability, and legal separateness. 2.4.10(d) Support that requires GCRI Canada to distort evidence, suppress correction, privilege a provider, imply public authority approval, accelerate stage truth, overstate maturity, grant procurement advantage, create finance-readiness implication, enclose public-good assets, or weaken safeguards shall be refused, narrowed, renegotiated, segregated, returned, or terminated. 2.4.10(e) Programs shall be designed to serve mission rather than revenue architecture. A program may generate cost recovery, membership value, training revenue, sponsored support, or public-good sustainability only where its substance remains public-benefit, role-bounded, records-valid, safeguarded, and correctionable. 2.4.10(f) Program economics shall not determine evidence results, method selection, public claims, participant access to authority, technical baseline status, public authority participation, provider prominence, correction timing, publication timing, or Nexus interface consequence. 2.4.10(g) Public claims shall be accurate, record-supported, limitation-aware, current, public-safe, non-misleading, role-bounded, and correctionable. Claims shall not be written to maximize influence at the expense of precision. 2.4.10(h) Technical architecture shall remain mission-bound. GCRI Canada shall not adopt architectures that create hidden dependency, vendor chokepoints, public-good enclosure, uncontrolled data flow, insecure release, AI opacity, cross-border transfer risk, uncorrectable outputs, provider control, sponsor control, or public authority confusion merely because such systems are efficient, subsidized, popular, technically attractive, or offered by a strategic partner. 2.4.10(i) Public-benefit constraints shall apply to architecture as much as to legal text. A dashboard, API, model workflow, repository structure, data room, metadata field, badge, map, or interface may create public meaning and shall therefore be governed under this Charter. 2.4.10(j) Where revenue, sponsorship, partnership, program design, public claim, or technical architecture creates credible public-benefit risk, GCRI Canada shall apply perimeter review and may pause, narrow, reclassify, redesign, correct, withdraw, terminate, or route the matter to the competent authority.

2.5 Mission Lock

2.5.1 Mission Lock as a Constitutional Constraint. 2.5.1(a) Mission lock is a constitutional constraint that prevents GCRI Canada from becoming what its public-good role exists to distinguish. GCRI Canada shall not interpret opportunity, funding, urgency, visibility, public authority interest, sponsor interest, provider contribution, technical centrality, media attention, Nexus proximity, ecosystem demand, crisis conditions, or institutional growth as permission to depart from its public-benefit, evidence-centered, non-executing role. 2.5.1(b) Mission lock shall apply in quiet operations as much as in public-facing work. It shall govern internal decisions, budgets, hiring, staffing, procurement, partnerships, research agendas, repository design, data access, AI workflows, public authority engagement, sponsorship arrangements, public materials, Academy programs, technical baselines, observability outputs, publications, and correction decisions. 2.5.1(c) Mission lock is not activated only when a problem becomes public. It is a standing condition of institutional validity, public trust, lawful stewardship, records discipline, and public-benefit continuity. 2.5.1(d) Mission lock shall preserve the distinction between evidence and recognition, methods and certification, observability and surveillance, learning and delegated authority, public-safe publication and public warning, finance-readiness input and investment advice, technical baseline and protocol entitlement, support and control, technical integration and execution, and Nexus compatibility and legal merger. 2.5.1(e) These distinctions shall not be waived, diluted, bypassed, or amended by practice, convenience, urgency, repeated use, sponsor expectation, provider expectation, public authority participation, public visibility, or technical architecture. 2.5.1(f) Where a proposed act appears mission-adjacent but risks role confusion, GCRI Canada shall apply perimeter review before proceeding. The institution shall ask whether the act is lawful, public-benefit, evidence-centered, non-executing, records-valid, public-safe, correctionable, and capable of being explained without overclaim. 2.5.1(g) Mission lock shall prevent GCRI Canada from using the importance of its work, the seriousness of systemic risk, the novelty of technology, or the value of evidence to others as a basis for expanding into roles reserved to public authorities, GRF, GRA, protocol authorities, standards bodies, procurement actors, finance actors, insurers, Project SPVs, National Consortium Companies, qualified providers, or execution actors. 2.5.1(h) Mission lock shall be interpreted as both a negative prohibition and a positive duty. It prohibits role conversion, capture, enclosure, and execution drift, and it requires active stewardship of evidence, methods, observability, ontology, public-good software, public-safe publication, public authority learning, data rights, cybersecurity, protected knowledge, and correctionability. 2.5.1(i) No institutional ambition, donor expectation, sponsor condition, provider integration, public authority request, capital-reader interest, media narrative, technical dependency, or crisis condition shall be treated as superior to mission lock.

2.5.2 Mission Lock as Binding on Directors, Officers, Staff, Committees, Councils, Fellows, Advisors, Members, Participants, Contractors, Contributors, and Authorized Representatives. 2.5.2(a) Mission lock binds all persons and bodies acting in relation to GCRI Canada. Directors shall oversee it; officers shall implement it; committees shall review it; councils shall respect it; staff shall operationalize it; fellows and advisors shall communicate consistently with it; contractors and contributors shall perform within it; members where applicable shall comply with it; sponsors and providers shall accept it as a condition of participation; public authority participants shall not be described inconsistently with it; and authorized representatives shall act only within it. 2.5.2(b) No person shall rely on title, seniority, expertise, founding role, public visibility, technical indispensability, funding relationship, public authority status, academic prestige, provider centrality, sponsor contribution, institutional proximity, media prominence, capital influence, or access to systems to bypass mission lock. 2.5.2(c) Authority to act for GCRI Canada shall arise only from lawful role, proper delegation, proper record, proper scope, and proper boundary. Mission lock shall apply even where a person has technical access, communications access, meeting access, repository access, public authority access, donor access, sponsor access, or operational influence. 2.5.2(d) Directors and officers shall ensure that mission lock is reflected in governance instruments, board materials, committee mandates, council terms, staff instructions, contracting practices, sponsorship controls, public materials review, technical release procedures, risk registers, public authority interface controls, data access procedures, AI-use procedures, cybersecurity controls, and correction procedures. 2.5.2(e) Mission lock shall be capable of being tested and evidenced. GCRI Canada shall not rely on generalized culture, informal leadership commitment, verbal assurance, personal judgment, or institutional memory as a substitute for mission-lock controls. 2.5.2(f) Participants, advisors, fellows, contractors, contributors, providers, sponsors, hosts, and public authority participants shall not use association with GCRI Canada to imply powers that GCRI Canada itself does not possess. 2.5.2(g) Where external actors make inaccurate claims regarding GCRI Canada’s authority, endorsement, recognition, certification, public authority role, procurement effect, finance-readiness, protocol effect, or execution capacity, GCRI Canada shall require correction or take other appropriate action to protect mission lock. 2.5.2(h) Mission lock shall apply to formal acts and informal conduct. A person may breach mission lock through public statements, meeting descriptions, emails, decks, dashboards, website text, social media posts, sponsor claims, provider references, public authority references, repository labels, AI-generated summaries, or visual materials that create misleading public meaning. 2.5.2(i) Any person who becomes aware of a credible mission-lock risk shall escalate, record, correct, or route the concern through the appropriate governance, legal, compliance, technical, public-safe, or correction pathway.

2.5.3 Mission Lock as Applicable to Purpose, Assets, Funding, Programs, Publications, Systems, Partnerships, and Public Communications. 2.5.3(a) Mission lock applies to all purposes, assets, funding structures, sponsorships, grants, donations, contracts, memberships where applicable, subscriptions, training fees, fellowships, in-kind contributions, programs, research agendas, publications, dashboards, maps, datasets, AI systems, model registers, repositories, technical baselines, software releases, public authority materials, provider references, sponsor acknowledgments, Academy materials, Nexus interface records, and public communications. 2.5.3(b) No area of institutional activity is exempt from mission lock because it is technical, informal, internal, experimental, urgent, sponsor-supported, partner-led, provider-enabled, public authority-facing, AI-assisted, low visibility, early-stage, described as a pilot, or framed as operational convenience. 2.5.3(c) Mission lock shall govern both content and architecture. A publication may breach mission lock through overclaim; a dashboard may breach mission lock through implied authority; a contract may breach mission lock through sponsor control; a repository may breach mission lock through private dependency; a program may breach mission lock through provider preference; a public authority room may breach mission lock through implied delegation; an AI workflow may breach mission lock by allowing machine output to appear authoritative. 2.5.3(d) Mission lock shall also apply to derivative materials, including summaries, excerpts, translations, slide decks, websites, social media, press materials, event descriptions, partner communications, sponsor acknowledgments, provider claims, public authority references, capital-reader materials, diagrams, visualizations, and AI-generated summaries. 2.5.3(e) Simplification shall not create misstatement. Public accessibility shall not justify public inaccuracy. Visual clarity shall not justify authority inflation. Public-safe summary shall not erase limitations. 2.5.3(f) Where mission lock concerns arise in a system already in operation, GCRI Canada shall not rely on sunk cost, public launch, sponsor expectation, provider investment, public authority participation, user reliance, media visibility, repository adoption, or technical complexity as a reason to continue uncorrected. 2.5.3(g) GCRI Canada shall narrow, quarantine, correct, suspend, redesign, restrict, withdraw, supersede, or retire any activity, system, publication, partnership, funding structure, or communication that materially violates or threatens mission lock. 2.5.3(h) Funding shall not purchase mission interpretation. Assets shall not be used to create private authority. Programs shall not be designed around revenue at the expense of role. Publications shall not be shaped to satisfy sponsor, provider, public authority, media, or capital-reader expectations. Systems shall not be architected to create hidden execution, hidden authority, hidden data movement, or unreviewed public meaning. 2.5.3(i) Mission lock shall require that every material purpose, asset, funding pathway, program, publication, system, partnership, and communication be capable of being traced to lawful authority, public-benefit purpose, appropriate review, records-valid status, public-safe treatment, and correction pathway.

2.5.4 Mission Lock as Protection Against Consultancy Drift, Event Drift, Vendor Drift, Finance Drift, Standards Drift, Execution Drift, and Public Authority Drift. 2.5.4(a) Mission lock protects GCRI Canada from consultancy drift, event drift, vendor drift, finance drift, standards drift, certification drift, protocol-authority drift, procurement drift, public authority drift, emergency command drift, public warning drift, and execution drift. 2.5.4(b) GCRI Canada may advise through public-benefit evidence, convene through controlled roles, develop technical baselines, support finance-readiness inputs, support public authority learning, and interact with providers, but it shall not become a consultancy, event company, vendor, financial intermediary, standards authority by default, procurement gatekeeper, public authority, emergency actor, public warning body, or deployment actor. 2.5.4(c) Consultancy drift occurs where GCRI Canada’s evidence, methods, learning, or technical work becomes client-directed advisory service outside its public-benefit role, especially where outputs are tailored to a private actor’s preferred outcome, commercial objective, regulatory objective, procurement interest, finance narrative, or public authority influence strategy. 2.5.4(d) Event drift occurs where convening becomes the institution’s identity rather than a tool for evidence and public-good stewardship. Convening shall remain subordinate to evidence quality, public-safe participation, records discipline, competition safety, role clarity, and correctionability. 2.5.4(e) Vendor drift occurs where tools, software, integrations, dashboards, technical baselines, implementation support, or reference architectures become commercial delivery offerings, preferred-provider channels, procurement signals, or provider-marketing surfaces. 2.5.4(f) Finance drift occurs where evidence inputs are framed as investment advice, capital-readiness, bankability, insurance-readiness, rating, underwriting, guarantee, lending support, public finance approval, or transaction recommendation. 2.5.4(g) Standards drift occurs where technical baselines, methods, schemas, test harnesses, APIs, or public-good software are described as formal certification, legal conformance, external approval, or binding standard-setting authority without competent authorization. 2.5.4(h) Protocol-authority drift occurs where GCRI Canada technical assets are treated as role keys, smart licenses, entitlement states, proof-receipt legal effect, or protocol-effective instruments without proper protocol authority. 2.5.4(i) Public authority drift occurs where learning, attendance, data-sharing, scenario work, public authority rooms, technical briefings, or public materials are represented as official adoption, regulatory approval, procurement support, funding approval, public finance approval, emergency instruction, public warning, or sovereign obligation. 2.5.4(j) Execution drift occurs where upstream support begins to direct, operate, deploy, procure, finance, insure, command, settle, route, or execute downstream action. 2.5.4(k) Mission lock shall require active monitoring for these forms of drift. GCRI Canada shall train personnel, review public materials, control naming, structure contracts, maintain role labels, classify participation capacity, govern technical interfaces, and use correction mechanisms to prevent role expansion by narrative, convenience, architecture, or repetition.

2.5.5 Mission Lock as Anti-Capture, Anti-Enclosure, Anti-Substitution, and Anti-Structural-Drift Rule. 2.5.5(a) Mission lock is an anti-capture, anti-enclosure, anti-substitution, and anti-structural-drift rule. 2.5.5(b) Mission lock prohibits arrangements that convert public-good evidence into sponsor benefit, public-good software into proprietary control, technical baselines into vendor gatekeeping, public authority learning into public authority endorsement, finance-readiness inputs into investment advice, provider participation into procurement advantage, records into marketing claims, controlled vocabulary into private semantics, or observability into execution authority. 2.5.5(c) Anti-capture requires that no sponsor, donor, funder, provider, public authority, host, capital reader, platform, founder, media actor, technical contributor, or internal leader may control evidence, method, interpretation, publication, correction, access, public authority interface, technical baseline status, repository design, or public meaning. 2.5.5(d) Influence shall be evaluated not only by formal rights but by practical dependency, public prominence, resource control, data control, technical control, access control, funding concentration, publication channels, reviewer selection, public authority proximity, and narrative power. 2.5.5(e) Anti-enclosure requires that public-good assets remain governed for public benefit and not converted into exclusive private inventory, closed dependency, proprietary chokepoint, sponsor-controlled asset, provider-controlled asset, vendor funnel, or private control surface. 2.5.5(f) Anti-substitution requires that GCRI Canada not be used as a substitute for GRF, GRA, protocol authority, public authorities, regulated professionals, enterprise actors, National Consortium Companies, Project SPVs, qualified providers, procurement actors, finance actors, insurers, operators, or execution actors. 2.5.5(g) Anti-structural-drift requires that repeated workarounds, informal exceptions, emergency practices, sponsor-specific adaptations, provider-specific integrations, public authority habits, technical dependencies, or repeated public claims not become new constitutional identity. 2.5.5(h) Where an arrangement creates capture, enclosure, substitution, or structural drift risk, GCRI Canada shall impose safeguards, ring-fence the activity, revise terms, restrict access, require independent review, disclose conflicts where appropriate, redesign the structure, correct public claims, or refuse the arrangement. 2.5.5(i) Where capture, enclosure, substitution, or structural drift has already occurred or appears to have occurred, GCRI Canada shall investigate, document, correct, narrow, suspend, terminate, withdraw, reclassify, or supersede the affected relationship, output, system, claim, or instrument. 2.5.5(j) Mission lock shall be applied by practical effect. A structure shall not be considered safe merely because it uses public-benefit language, nonprofit form, non-binding labels, disclaimers, or indirect contractual pathways if its practical effect defeats GCRI Canada’s public-benefit, non-executing, role-bounded identity.

2.5.6 Mission Lock as Duty to Preserve Public-Good Technical Assets, Evidence Infrastructure, Methods, Ontologies, Repositories, and Records. 2.5.6(a) Mission lock requires GCRI Canada to preserve its public-good technical assets, evidence infrastructure, methods, ontologies, controlled vocabulary, taxonomies, schemas, data dictionaries, repositories, model registers, dataset records, system cards, benchmark cards, public-good software, public-safe publication systems, correction chains, and archival records. 2.5.6(b) These assets shall be maintained, secured, documented, versioned, reviewed, portable where appropriate, public-safe where released, classification-aware, privacy-preserving, and protected from enclosure, abandonment, dependency capture, hidden control, unsupportable release, corruption, semantic drift, and silent alteration. 2.5.6(c) Preservation shall include technical, legal, semantic, and institutional preservation. 2.5.6(d) Technical preservation includes repository security, dependency management, release integrity, vulnerability handling, access control, portability, backup, continuity, secure decommissioning, and maintainability. 2.5.6(e) Legal preservation includes licensing, ownership clarity, contribution terms, privacy compliance, protected knowledge restrictions, public authority restrictions, lawful-basis records, data-sharing controls, and contractual boundaries. 2.5.6(f) Semantic preservation includes controlled vocabulary, ontology maintenance, equivalence notes, divergence logs, localization notes, term-use rules, status labels, and correction of misuse. 2.5.6(g) Institutional preservation includes records custody, approval history, authority mapping, supersession chains, correction records, withdrawal records, archival discipline, and final closeout records. 2.5.6(h) GCRI Canada shall not allow mission-critical assets to depend on one individual, one vendor, one cloud platform, one AI model provider, one repository account, one sponsor, one host, one public authority relationship, one undocumented process, or one fragile technical dependency without review and mitigation. 2.5.6(i) Fragility in public-good technical assets is a mission risk. Unsupported software, stale datasets, unversioned methods, untraceable dashboards, undocumented repositories, insecure APIs, uncorrectable publications, and uncontrolled vocabulary drift shall be treated as mission-lock concerns. 2.5.6(j) Where assets can no longer be maintained responsibly, GCRI Canada shall classify, deprecate, archive, transfer where lawful, supersede, withdraw, restrict, or retire them in a records-valid manner. Abandonment without notice or correction shall be inconsistent with mission lock where public reliance exists.

2.5.7 Mission Lock as Narrow-Reading Rule Where Ambiguity Creates Role Confusion or Harm Risk. 2.5.7(a) Where ambiguity creates role confusion, public harm risk, data risk, AI risk, cyber risk, public authority confusion, finance-boundary risk, protected knowledge risk, community harm risk, sponsor influence, provider preference, procurement implication, public warning implication, certification implication, protocol-authority implication, execution implication, legal ambiguity, or public-safe publication risk, GCRI Canada shall adopt the narrower, safer, more public-good-preserving interpretation. 2.5.7(b) The burden shall rest on the actor seeking broader authority to show proper law, proper record, proper role, proper review, proper safeguards, and proper boundary. 2.5.7(c) The narrow-reading rule shall apply to communications, contracts, public materials, technical releases, dashboards, maps, AI outputs, sponsorships, public authority rooms, data-sharing arrangements, provider integrations, program names, Academy materials, Nexus interface records, controlled vocabulary, repository labels, metadata fields, and public-safe reports. 2.5.7(d) Ambiguity shall not be resolved in favor of institutional expansion merely because expansion appears useful, efficient, fundable, technically attractive, publicly valuable, requested by public authorities, supported by sponsors, desired by providers, or expected by the ecosystem. 2.5.7(e) Where a broader interpretation is legally available but creates public confusion, unsafe reliance, capture risk, enclosure risk, public authority ambiguity, finance overclaim, certification drift, protocol drift, procurement implication, or mission drift, GCRI Canada shall select the narrower interpretation unless the competent governance authority records a lawful, safeguarded, public-benefit reason for the broader path. 2.5.7(f) Any recorded reason for a broader interpretation shall identify the legal basis, public-benefit basis, authority surface, scope, limits, safeguards, affected actors, public-safe status, review date, and correction path. 2.5.7(g) The narrow-reading rule shall not prevent innovation, collaboration, or technical development. It shall ensure that innovation occurs inside lawful, transparent, records-valid, role-bounded, public-safe, and correctable conditions. 2.5.7(h) Where ambiguity concerns public authority, finance, procurement, certification, protocol effect, public warning, emergency response, protected knowledge, personal data, sovereign data, cybersecurity, or execution, GCRI Canada shall apply the most protective lawful interpretation pending review. 2.5.7(i) No disclaimer shall cure an ambiguous structure if the structure itself reasonably communicates authority, endorsement, recognition, certification, procurement preference, finance-readiness, public authority action, or execution power beyond GCRI Canada’s role.

2.5.8 Mission Lock as Survival Rule Across Leadership Changes, Funding Cycles, Host Changes, Platform Changes, Public Visibility, and Ecosystem Growth. 2.5.8(a) Mission lock shall survive leadership changes, board changes, officer changes, founder transitions, staffing changes, funding cycles, donor changes, sponsor changes, provider changes, host changes, platform changes, repository migrations, technology shifts, public visibility, media attention, public authority participation, institutional expansion, Nexus growth, and ecosystem complexity. 2.5.8(b) No change in institutional circumstance shall silently amend mission lock. No new leader, funder, sponsor, provider, host, partner, public authority participant, platform, technology, or public narrative shall acquire authority to reinterpret GCRI Canada’s mission by circumstance. 2.5.8(c) Mission lock shall also survive success. Increased demand, public recognition, sponsor interest, public authority engagement, provider participation, capital-reader attention, technical adoption, international collaboration, or widespread use of GCRI Canada outputs shall not convert GCRI Canada into an execution, finance, procurement, certification, public authority, public warning, or protocol institution. 2.5.8(d) Institutional growth shall require stronger boundaries, not weaker ones. The greater the reliance on GCRI Canada outputs, the stronger the need for records, limitation disclosure, public-safe publication, source discipline, correction pathways, sponsor non-control, provider neutrality, and role separation. 2.5.8(e) Mission lock shall survive crisis. Emergencies, disasters, cyber incidents, climate events, public health events, infrastructure failures, AI incidents, geopolitical shocks, or public pressure may create demand for rapid interpretation, but GCRI Canada shall not become a public warning authority, emergency commander, official response body, regulator, procurement actor, finance actor, or sovereign actor by urgency. 2.5.8(f) During crisis or urgency, GCRI Canada may support evidence, methods, public authority learning, technical interpretation, public-safe summaries, and correction within lawful limits. It shall preserve stage truth, source limitations, public-safe review, authority boundaries, and non-execution. 2.5.8(g) Mission lock shall be embedded in onboarding, board education, staff training, committee mandates, council terms, contracts, repository governance, public claims review, sponsorship review, provider-interface review, public authority protocols, data governance, AI governance, technical-release controls, and continuity planning so that it is not dependent on institutional memory alone. 2.5.8(h) Leadership change shall not cause constitutional drift. GCRI Canada’s identity shall be held by law, Charter, Bylaw, records, policies, procedures, systems, repositories, controlled vocabulary, and correction paths rather than personal authority. 2.5.8(i) Where growth, visibility, or public reliance creates pressure to reinterpret GCRI Canada’s role, the presumption shall favor the mission-locked interpretation unless a lawful, records-valid amendment or properly authorized instrument provides otherwise within the limits of this Charter.

2.5.9 Mission Lock as Board-Level Duty and Officer-Level Operating Constraint. 2.5.9(a) Mission lock is a board-level duty and an officer-level operating constraint. 2.5.9(b) Directors shall ensure that strategy, budget, partnerships, funding, sponsorship, technical architecture, public materials, risk appetite, public authority interfaces, data practices, AI practices, cybersecurity practices, repository governance, public-safe publication, correction systems, and institutional growth remain mission-locked. 2.5.9(c) Officers shall ensure that operations, public communications, technical releases, data access, AI use, public authority interfaces, sponsorships, programs, repositories, controlled rooms, procurement, staff instructions, provider interfaces, and correction processes remain within mission lock. 2.5.9(d) Committees and councils shall test mission lock through assurance, review, challenge, correction, and escalation. No committee or council shall treat its subject-matter importance as authority to enlarge GCRI Canada’s role. 2.5.9(e) The Board shall receive sufficient information to detect mission-lock risks, including risks arising from funding dependence, sponsor concentration, provider dependency, public authority ambiguity, technical architecture, publication pressure, repository control, AI-system reliance, data sensitivity, public claims, protected knowledge, community safeguards, public-safe mapping, and Nexus interface complexity. 2.5.9(f) Mission lock shall be part of governance oversight, not only legal review. The Board shall treat mission-lock risk as constitutional, strategic, operational, legal, technical, reputational, and public-trust risk. 2.5.9(g) Officers shall implement mission lock through practical controls, including intake forms, authority matrices, approval workflows, public-safe review, records requirements, contract clauses, claims review, access controls, classification, privacy review, AI-use review, secure development discipline, technical release discipline, and correction pathways. 2.5.9(h) Operational convenience shall not be treated as an excuse for missing mission-lock controls. Where controls are burdensome or ineffective, GCRI Canada shall improve the controls rather than abandon mission-lock discipline. 2.5.9(i) Where committees, councils, or delegated bodies operate under GCRI Canada, their mandates shall include mission-lock obligations. A council or committee shall not expand its own role, output type, public claims, public authority status, finance implications, certification implications, protocol implications, procurement implications, or execution implications beyond the Charter merely because it convenes important actors or addresses important topics. 2.5.9(j) Board and officer duties under mission lock shall include corrective courage. Where public materials, programs, funding structures, partnerships, systems, or claims drift from mission, GCRI Canada shall correct even where correction is reputationally inconvenient, commercially uncomfortable, or contrary to external expectations.

2.5.10 Mission Lock as Corrective Trigger Where Public Materials, Contracts, Programs, or Partnerships Overstate GCRI Canada’s Role. 2.5.10(a) Any mission lock breach or credible mission lock risk shall trigger review, correction, narrowing, reclassification, withdrawal, retraction, redesign, handoff, access restriction, public-safe clarification, legal review, technical review, committee review, officer action, or board action as appropriate. 2.5.10(b) Corrective action may be required for public materials, contracts, sponsorships, grants, donations, provider references, public authority references, dashboards, maps, repositories, software releases, datasets, model registers, Academy materials, public claims, media statements, event materials, funding decks, partner statements, Nexus interface records, and AI-generated summaries. 2.5.10(c) Corrective action shall not be delayed merely because the material is already public, the event has occurred, the sponsor has expectations, the provider has invested resources, the public authority has participated, the public narrative has formed, the dashboard is in use, the repository has been adopted, or correction may be reputationally inconvenient. 2.5.10(d) The integrity of GCRI Canada depends on the capacity to correct overstatement. Correction shall be treated as a public-benefit duty and not as a reputational admission to be avoided. 2.5.10(e) Corrections shall be proportionate to the risk and public meaning of the overstatement. Minor internal ambiguity may require clarification. Public-facing overclaim may require public-safe correction. Misuse by a sponsor, provider, partner, public authority participant, or external actor may require contractual cure, public clarification, access restriction, or termination. Persistent or material role distortion may require board-level intervention. 2.5.10(f) Where an overstatement creates downstream reliance risk, GCRI Canada shall assess whether notice is required to affected audiences, public authorities, partners, participants, sponsors, providers, Nexus institutions, communities, capital readers, or the public. 2.5.10(g) Reliance risk shall be evaluated by the likely interpretation of the audience, not only by the intention of the drafter. A statement, dashboard, badge, map, title, logo placement, public authority reference, sponsor acknowledgment, or provider reference may be misleading even if individual words are technically accurate. 2.5.10(h) GCRI Canada shall maintain correction records sufficient to show the source of the mission-lock concern, the nature of the overstatement, the affected materials or relationships, the corrective authority, the corrective action taken, the public-safe notice decision, and any downstream notice required. 2.5.10(i) Where public materials, contracts, programs, or partnerships repeatedly create mission-lock risk, GCRI Canada shall address root causes through template revision, training, contract reform, claims review, technical redesign, sponsorship policy change, provider-interface controls, public authority protocol revision, or governance amendment. 2.5.10(j) No mission-lock correction shall itself create overclaim. Corrective language shall remain accurate, public-safe, role-bounded, records-valid, and proportionate.

2.6 Stewardship Posture

2.6.1 GCRI Canada as Steward Rather Than Owner of Public-Good Meaning. 2.6.1(a) GCRI Canada shall act as steward rather than owner of public-good meaning. It safeguards the conditions under which evidence, methods, observability, ontology, technical baselines, public-good software, public authority learning, public-safe publications, and correction systems can be trusted, interpreted, reviewed, maintained, and corrected. 2.6.1(b) Stewardship shall not be interpreted as ownership of truth, ownership of Nexus, monopoly over public legitimacy, control over downstream decisions, or authority to absorb functions reserved to other institutions, public authorities, enterprise actors, capital actors, protocol authorities, recognition bodies, procurement actors, or execution actors. 2.6.1(c) GCRI Canada’s authority to steward public-good meaning shall arise from lawful governance, public-benefit purpose, technical discipline, records validity, methods integrity, public-safe conduct, controlled vocabulary, correctionability, and institutional trust. It shall not arise from branding, public visibility, founder identity, sponsor support, provider contribution, public authority attention, technical centrality, media repetition, or repeated reference by others. 2.6.1(d) As steward, GCRI Canada may structure, preserve, contextualize, publish where public-safe, restrict where required, and correct public-good evidence and technical assets. It may maintain vocabulary, methods, repositories, observability structures, technical baselines, public-good software, public-safe materials, and evidence infrastructure. It may support other actors in understanding evidence and methods. It shall not use stewardship to claim ownership of all interpretations, downstream decisions, public legitimacy, public authority action, finance-readiness, procurement outcomes, protocol effect, certification status, or execution activity. 2.6.1(e) Stewardship shall remain humble, disciplined, reviewable, and accountable. GCRI Canada shall recognize that public-good meaning is built through evidence, participation, review, law, context, public safety, community safeguards, protected knowledge discipline, public authority clarity, and correction, not unilateral institutional assertion. 2.6.1(f) GCRI Canada shall not describe itself, or permit itself to be described, as the owner, controller, single source, gatekeeper, final authority, public authority proxy, finance authority, procurement authority, certification authority, protocol authority, execution authority, or exclusive legitimacy source for Nexus or any public-good field merely because it stewards upstream evidence and technical truth infrastructure. 2.6.1(g) Where public materials, dashboards, maps, repositories, public authority references, sponsor references, provider references, Academy materials, media materials, or Nexus interface records create an impression that GCRI Canada owns or controls public-good meaning beyond its role, GCRI Canada shall correct, narrow, clarify, withdraw, or supersede the material. 2.6.1(h) Stewardship shall be interpreted as a fiduciary-like public-benefit discipline within GCRI Canada’s lawful role, not as proprietary entitlement, institutional dominance, commercial leverage, or authority over downstream actors.

2.6.2 Stewardship as Active Custodianship, Not Passive Observation. 2.6.2(a) Stewardship by GCRI Canada is active custodianship, not passive observation. GCRI Canada shall not merely watch, comment, convene, archive, or publicize; it shall maintain the conditions under which public-good evidence, methods, observability, ontology, technical baselines, software, and publications remain trustworthy, bounded, secure, usable, reviewable, and correctionable. 2.6.2(b) Active custodianship shall include intake discipline, classification, lawful-basis review, source-lining, provenance preservation, method selection, methodological review, controlled vocabulary, versioning, access control, public-safe publication, cybersecurity, data-rights protection, correction, supersession, withdrawal, archival, and final closeout. 2.6.2(c) GCRI Canada shall not treat stewardship as satisfied by creating an output once. A report, map, dataset, dashboard, API, method, model record, technical baseline, repository, public-good software release, or Academy material that carries public-good reliance shall require lifecycle discipline appropriate to its risk, sensitivity, reliance, public-safe status, and correction needs. 2.6.2(d) Active custodianship shall require GCRI Canada to act when evidence is stale, methods are superseded, datasets are flawed, software is insecure, dashboards are misleading, controlled vocabulary is misused, public claims exceed records, public authority references create ambiguity, sponsor or provider claims overstate meaning, or public-safe status changes. 2.6.2(e) GCRI Canada shall not remain passive where public-good assets under its stewardship are captured, enclosed, misrepresented, technically compromised, semantically distorted, unsafe for publication, used for finance overclaim, used for procurement implication, used for public authority overclaim, or used to imply execution authority. 2.6.2(f) Active custodianship shall include refusal as well as production. GCRI Canada may refuse data, refuse publication, refuse sponsorship, refuse provider integration, refuse public authority framing, refuse finance-adjacent misuse, refuse unsafe mapping, refuse AI ingestion, refuse unsupported claims, and refuse technical release where public-benefit stewardship requires restraint. 2.6.2(g) Stewardship shall be carried out through records, not memory; through systems, not slogans; through controls, not assumptions; and through correction, not reputation management. 2.6.2(h) GCRI Canada shall maintain sufficient institutional capacity, technical competence, governance controls, and public-safe review mechanisms to make stewardship operational rather than symbolic.

2.6.3 Stewardship of Evidence Systems, Methods, Ontologies, Technical Baselines, Public-Good Software, and Observability Environments. 2.6.3(a) GCRI Canada shall steward evidence systems, methods, ontologies, taxonomies, schemas, controlled vocabularies, data dictionaries, semantic mappings, technical baselines, reference architectures, public-good software, APIs, dashboards, data tools, test harnesses, evaluation harnesses, model registers, dataset records, system cards, benchmark cards, observability environments, and public-safe intelligence structures. 2.6.3(b) Evidence systems shall be stewarded to preserve source, provenance, custody, classification, lawful basis, permissions, confidence, limitations, review status, public-safe status, correction path, and retention discipline. Evidence systems shall not be treated as ungoverned data stores, sponsor deliverables, provider proof channels, public authority endorsement mechanisms, finance-readiness engines, or execution systems. 2.6.3(c) Methods shall be stewarded through versioning, documentation, scope definition, assumptions, input requirements, maturity status, limitations, review history, challenge procedures, supersession, and correction. A method shall not migrate across contexts merely because it is convenient, familiar, technically available, sponsor-preferred, provider-embedded, or AI-assisted. 2.6.3(d) Ontologies, taxonomies, schemas, data dictionaries, and controlled vocabularies shall be stewarded to preserve meaning across legal, technical, public authority, community, academic, enterprise, and Nexus contexts. GCRI Canada shall prevent semantic drift where language could imply recognition, certification, finance-readiness, public authority approval, procurement preference, protocol entitlement, or execution authority beyond the record. 2.6.3(e) Technical baselines and reference architectures shall be stewarded as public-good design infrastructure. They may support interoperability, evidence quality, secure implementation, public authority learning, and downstream review by competent actors, but shall not by themselves create certification, recognition, procurement approval, public authority approval, finance-readiness, protocol effect, or execution authority. 2.6.3(f) Public-good software, APIs, dashboards, data tools, test harnesses, and reference implementations shall be governed through secure development, repository discipline, contribution review, dependency management, vulnerability handling, licensing clarity, release control, public-safe documentation, deprecation, and correction. 2.6.3(g) Observability environments shall be stewarded to support disciplined awareness of systems, risks, dependencies, infrastructure conditions, technical signals, public authority context, and community context without becoming surveillance, emergency command, public warning, operational control, market intelligence for private advantage, or public authority substitution. 2.6.3(h) GCRI Canada shall ensure that technical usability does not override legal meaning, semantic precision, privacy, cybersecurity, sovereignty, protected knowledge, community safeguards, public authority boundaries, finance boundaries, or non-execution. 2.6.3(i) Where evidence systems, methods, ontologies, baselines, software, or observability environments are integrated with external systems, GCRI Canada shall preserve role boundaries, data rights, licensing clarity, access controls, public-safe status, dependency records, correction pathways, and exit readiness.

2.6.4 Stewardship of Research Integrity, Technical Memory, Controlled Vocabulary, and Correction Chains. 2.6.4(a) GCRI Canada shall steward research integrity, technical memory, controlled vocabulary, semantic discipline, correction chains, supersession chains, withdrawal records, retraction records, deprecation records, archive records, and public-safe clarification records. 2.6.4(b) Research integrity shall require independence from sponsor pressure, provider preference, political convenience, public authority expectation, media simplicity, finance narrative, procurement pressure, institutional ambition, and public visibility. Findings, methods, limitations, public-safe status, and corrections shall not be shaped to satisfy predetermined narratives. 2.6.4(c) GCRI Canada shall preserve technical memory through records of design decisions, source choices, dependency changes, release histories, repository actions, vulnerability handling, licensing decisions, contribution provenance, model use, dataset use, benchmark design, AI-use records, deprecation events, unresolved risks, and correction decisions. 2.6.4(d) Technical memory shall not depend on individual maintainers, founders, private inboxes, chat histories, personal accounts, undocumented scripts, informal calls, platform defaults, or unversioned files. Mission-critical memory shall be institutional, traceable, secure, and portable where appropriate. 2.6.4(e) Controlled vocabulary shall be treated as a constitutional control surface. Terms carrying institutional consequence shall be defined, used within scope, reviewed, corrected where misused, and protected against rhetorical inflation, sponsor distortion, provider overclaim, public authority ambiguity, finance overclaim, and public-facing misunderstanding. 2.6.4(f) Correction chains shall preserve the history and effect of corrections, including the item corrected, correction type, authority, date, reason where appropriate, affected records, public-safe status, downstream notice decision, and remaining limitations. 2.6.4(g) Supersession chains shall identify what replaces what, what remains valid, what is deprecated, what is withdrawn, what is archived, and what shall no longer be relied upon. Silent replacement, orphaned outputs, uncontrolled copies, and unmarked obsolete materials shall be inconsistent with stewardship where reliance risk exists. 2.6.4(h) GCRI Canada shall treat correction as an institutional strength and a condition of public trust. Correction shall not be delayed or suppressed because an output is public, sponsor-supported, widely cited, technically complex, reputationally important, or difficult to amend. 2.6.4(i) Where public meaning has been distorted by error, stale information, ambiguous language, misleading visuals, public authority overclaim, sponsor overclaim, provider overclaim, finance overclaim, certification implication, protocol implication, or procurement implication, GCRI Canada shall use correction chains to restore bounded meaning.

2.6.5 Stewardship of Data Rights, Privacy, Cybersecurity, Sovereign Data, and Secure Release. 2.6.5(a) GCRI Canada shall steward data rights, privacy, cybersecurity, sovereign data, secure collaboration, secure repositories, secure development, identity and access management, controlled rooms, clean rooms, data rooms, AI-use controls, model governance, cross-border transfer review, compute-to-data, and secure release as public-good infrastructure. 2.6.5(b) Privacy shall be treated as a core institutional and safeguards obligation. GCRI Canada shall protect against unnecessary collection, unjustified access, overlinkage, re-identification, profiling, coercive visibility, contextual misuse, function creep, unsafe secondary use, uncontrolled metadata exposure, excessive retention, and internal overexposure. 2.6.5(c) Data rights shall include lawful basis, purpose limitation, minimization, classification, access control, retention discipline, correction where applicable, deletion or restriction where appropriate, rights-response procedures, and public-safe publication review. 2.6.5(d) Rights-bearing data shall be identified by effect and context, not only by formal category. Aggregated data, geospatial layers, community indicators, infrastructure data, model outputs, inferred attributes, public authority datasets, and linked records may create risk through re-identification, targeting, profiling, exposure, or contextual misuse. 2.6.5(e) Sovereign data stewardship shall include localization, sovereign data zones, compute-to-data, cross-border transfer review, conflict-of-law assessment, public authority data controls, Indigenous data considerations, community data safeguards, and jurisdictional respect. Data shall not move merely because technology permits movement. 2.6.5(f) Cybersecurity shall protect the integrity, confidentiality, and availability of evidence, methods, repositories, software, datasets, dashboards, APIs, model records, public authority materials, protected knowledge, participant data, public-safe outputs, correction chains, credentials, keys, secrets, and release systems. 2.6.5(g) GCRI Canada shall treat cyber weakness as a public-interest risk because compromised systems can distort evidence, expose participants, corrupt public-good assets, compromise public authority confidence, enable misinformation, and undermine institutional trust. 2.6.5(h) Secure release shall require review of content, code, data, metadata, dependencies, credentials, embedded files, logs, test fixtures, examples, geospatial clues, public authority references, sponsor references, provider references, and public-safe meaning before publication or distribution. 2.6.5(i) GCRI Canada shall prohibit personal information, sensitive rights-bearing data, protected-source information, protected knowledge, cyber-sensitive information, or re-identifiable materials in public repositories, open releases, public technical packages, public documentation, or on-chain artifacts unless expressly lawful, public-safe, authorized, and consistent with this Charter. 2.6.5(j) Where a privacy, data, cyber, sovereign data, or secure-release incident occurs or is credibly suspected, GCRI Canada shall contain, assess, record, correct, notify where required, preserve evidence, and conduct post-incident review appropriate to the risk and public-benefit impact.

2.6.6 Stewardship of Public-Safe Publications, Dashboards, Maps, Reports, Datasets, and Technical Outputs. 2.6.6(a) GCRI Canada shall steward public-safe publications, dashboards, maps, reports, datasets, APIs, software releases, technical notes, whitepapers, controlled annexes, Academy materials, public authority learning materials, model records, benchmark records, system cards, and other technical outputs through public-safe review, limitation disclosure, records validity, versioning, correction, and lifecycle control. 2.6.6(b) Public-safe publication shall require protection of privacy, cybersecurity, infrastructure sensitivity, public authority limits, finance sensitivity, commercial sensitivity, community safeguards, Indigenous and protected knowledge, vulnerable communities, protected participation, source protection, and lawful confidentiality. 2.6.6(c) Evidence may be true yet not public-safe. The fact that information is accurate, technically available, publicly sourced, geospatially visible, partner-provided, or analytically useful shall not determine whether it may be released. 2.6.6(d) Reports and public-safe summaries shall distinguish findings, assumptions, methods, limitations, confidence, public-safe status, review status, and correction pathways. They shall not imply recognition, certification, finance-readiness, public authority approval, procurement preference, protocol entitlement, official warning, or execution instruction where none exists. 2.6.6(e) Dashboards, maps, digital twins, geospatial layers, and visual outputs shall be reviewed for public meaning and misuse risk. Visual design, color, labels, badges, pins, overlays, alerts, scores, rankings, and public authority references can create authority signals and shall be governed accordingly. 2.6.6(f) Datasets and data tools shall preserve source, scope, lawful basis, permissions, classification, limitations, retention posture, public-safe status, and correction pathways where material. Dataset publication shall not expose personal information, protected knowledge, small-group identity, sensitive infrastructure, cyber-sensitive details, or sovereign data without proper authority and safeguards. 2.6.6(g) Technical outputs shall carry status labels, version identifiers, scope statements, limitation statements, dependency notes, maturity status where relevant, permitted-use terms, prohibited-use terms where required, and correction pathways. 2.6.6(h) Where full public release is unsafe, GCRI Canada may use redaction, aggregation, delayed publication, controlled annexes, restricted rooms, private correction notices, public-safe summaries, synthetic examples, or non-public archival. 2.6.6(i) GCRI Canada shall not use public-safe publication as a branding exercise. Public-safe publication exists to preserve public-benefit learning, transparency minima, lawful protection, accurate reliance, and correctionability. 2.6.6(j) Where a publication, dashboard, map, dataset, or technical output becomes stale, misleading, unsafe, insecure, superseded, overclaimed, or misused, GCRI Canada shall correct, update, restrict, deprecate, withdraw, reclassify, or archive it as appropriate.

2.6.7 Stewardship of Public Authority Learning Without Public Authority Substitution. 2.6.7(a) GCRI Canada shall steward public authority learning without public authority substitution. It may support technical literacy, evidence literacy, AI literacy, cyber literacy, observability literacy, scenario understanding, public-safe interpretation, and systems-risk learning for public authorities while preserving the authority, duties, procedures, and accountability of those public authorities. 2.6.7(b) Public authority learning shall not become public authority delegation, official guidance, regulatory approval, procurement approval, funding approval, public finance approval, emergency command, public warning, public health order, enforcement action, permit decision, sovereign obligation, or public-private partnership by implication. 2.6.7(c) GCRI Canada may help public authorities understand technical claims, evidence limitations, AI risks, cyber dependencies, data governance, observability outputs, community safeguards, protected knowledge issues, public-safe publication, and systemic risk interactions, but it shall not speak as the public authority, decide for the public authority, issue official guidance on behalf of the public authority, or imply adoption by public authority participation. 2.6.7(d) Public authority interfaces shall be structured through capacity classification, agenda discipline, records, public-safe language, confidentiality where required, competition safety, procurement neutrality, privacy controls, cybersecurity controls, data-handling controls, and conflict-of-law awareness. 2.6.7(e) Participation by public officials, regulators, emergency-management actors, public finance bodies, public health actors, infrastructure authorities, agencies, departments, municipalities, Indigenous governments or institutions, or public-sector participants shall be recorded in a manner that avoids ambiguity regarding capacity, authority, endorsement, adoption, reliance, procurement, finance, public warning, and sovereign obligation. 2.6.7(f) Public authority logos, names, quotes, photographs, meeting attendance, data contributions, comments, requests, or participation shall not be used in public materials unless authorized within scope and reviewed for public meaning. 2.6.7(g) Public authority rooms, briefings, controlled rooms, scenario exercises, learning sessions, workshops, and Academy materials shall not become unrecorded governance environments. Attendance, agenda, capacity, confidentiality, output type, and public-safe status shall be recorded where material. 2.6.7(h) Where public authority ambiguity arises, GCRI Canada shall adopt the most protective interpretation, clarify the record, and correct public materials where necessary. 2.6.7(i) GCRI Canada shall protect public authorities from misdescription and shall protect itself from authority inflation. Public trust requires that GCRI Canada not appear to exercise powers it does not hold.

2.6.8 Stewardship of Community Safeguards, Protected Participation, Indigenous and Local Knowledge, and Do-No-Harm Controls. 2.6.8(a) GCRI Canada shall steward community safeguards, protected participation, Indigenous knowledge, local knowledge, territorial knowledge, culturally sensitive knowledge, environmental knowledge, protected knowledge, public-safe mapping, accessibility, grievance, remedy, non-retaliation, and do-no-harm controls. 2.6.8(b) Community safeguards shall apply across research, evidence intake, observability, data handling, AI use, mapping, publication, public authority learning, technical baselines, controlled rooms, Academy materials, Nexus interfaces, correction, and closeout. 2.6.8(c) Protected participation shall allow persons and communities to contribute, challenge, correct, or raise concerns without retaliation, exposure, coercion, reputational harm, loss of access, sponsor pressure, provider pressure, public authority pressure, or misuse of their participation. 2.6.8(d) GCRI Canada shall provide safe channels proportionate to risk, including confidential reporting, controlled-room reporting, community grievance pathways, public-safe correction pathways, or independent review where appropriate. 2.6.8(e) Indigenous and local knowledge shall be handled with respect for applicable law, Indigenous governance protocols, local governance expectations, cultural sensitivity, territorial context, restrictions on disclosure or reuse, community authority, and public-safe limitations. 2.6.8(f) GCRI Canada shall not publish, model, map, summarize, train on, commercialize, route, integrate, or translate Indigenous, local, territorial, cultural, environmental, or protected knowledge in a manner that strips context, violates expectation, exposes sensitive locations, discloses protected practices, weakens community authority, or converts protected knowledge into public-good assets without proper authority and safeguards. 2.6.8(g) Public-safe mapping shall be governed by heightened review. Maps, dashboards, geospatial layers, digital twins, observability outputs, infrastructure overlays, community risk profiles, environmental intelligence, and public authority-facing visualizations shall be reviewed for potential harm, including vulnerable community exposure, protected site disclosure, critical infrastructure targeting, cyber-sensitive asset exposure, ecological sensitivity, culturally significant area exposure, contested territorial information, stigma, retaliation, and exploitation. 2.6.8(h) Do-no-harm shall include privacy harm, dignity harm, cultural harm, community exposure, infrastructure risk, cyber risk, public authority confusion, finance overclaim, public warning confusion, procurement implication, protected knowledge misuse, AI-mediated distortion, retaliation risk, and downstream reliance. 2.6.8(i) Where harm risk exists, GCRI Canada shall narrow, aggregate, redact, delay, restrict, generalize, use synthetic examples, create controlled annexes, withhold publication, or refuse the activity. 2.6.8(j) Community safeguards, protected participation, Indigenous and local knowledge protection, and do-no-harm controls shall not be waived by sponsor interest, provider interest, public authority interest, research convenience, data availability, technical feasibility, public visibility, or public-good rhetoric. 2.6.8(k) GCRI Canada shall treat communities and knowledge holders as rights-bearing participants and context-bearing sources of knowledge, not as raw data sources, mapping objects, narrative assets, AI training material, or public legitimacy tokens.

2.6.9 Stewardship of Open and Governed Public-Good Assets Without Private Capture. 2.6.9(a) GCRI Canada shall steward open and governed public-good assets without private capture, sponsor control, provider control, vendor chokepoints, proprietary dependency, hidden control surfaces, enclosure, or improper private benefit. 2.6.9(b) Public-good assets may include evidence methods, ontologies, controlled vocabularies, schemas, data dictionaries, public-good software, open technical baselines, reference architectures, correction chains, public-safe knowledge, model registers, dataset templates, observability methods, dashboards, repositories, APIs, documentation, and Academy materials. 2.6.9(c) Open shall mean open where lawful, safe, mission-compatible, and public-benefit enhancing. Open shall not mean uncontrolled disclosure of personal data, rights-bearing data, protected knowledge, sensitive infrastructure information, public authority restricted materials, cyber vulnerabilities, sovereign data, trade secrets, finance-sensitive information, or unsafe implementation details. 2.6.9(d) Governed shall mean subject to licensing, contribution rules, version control, access classification, security, documentation, maintenance responsibility, public-safe release status, permitted-use terms, prohibited-use terms where required, correction pathways, and lifecycle discipline. 2.6.9(e) GCRI Canada shall not confuse publication with stewardship. A released public-good asset remains a governance responsibility where public reliance exists. 2.6.9(f) No sponsor, donor, funder, provider, host, platform, model provider, technical contributor, public authority participant, capital reader, or partner shall acquire control over public-good assets by funding, hosting, contributing, maintaining, integrating, publicizing, or relying upon them. 2.6.9(g) Public-good assets shall not be enclosed through ownership transfer, exclusive licensing, restrictive contracts, proprietary dependencies, technical lock-in, sponsor branding, vendor control, data concentration, closed formats, paywalling, platform dependence, hidden APIs, restrictive patents, undocumented workflows, or practical inability to use or maintain the asset without a private actor. 2.6.9(h) Where proprietary components are used to implement public-good methods or baselines, GCRI Canada shall preserve a clear distinction between the public-good canonical layer and the proprietary implementation layer. Public-good meaning shall remain portable, explainable, and not dependent on proprietary interpretation. 2.6.9(i) GCRI Canada shall use public-good licensing, open licensing, restricted licensing, defensive publication, contributor agreements, trademark controls, repository terms, portability requirements, and anti-enclosure IP strategies to preserve public-good availability and safety. 2.6.9(j) Where capture, enclosure, dependency, vendor chokepoint, sponsor control, or hidden control risk arises, GCRI Canada shall impose safeguards, diversify dependencies, amend contracts, migrate repositories, restrict claims, require independent review, redesign architecture, terminate the arrangement, or issue public-safe clarification as appropriate.

2.6.10 Stewardship as Measured by Integrity, Durability, Interoperability, Usability, Correctionability, and Public Trust, Not Transaction Volume, Market Share, Sponsor Value, or Media Visibility. 2.6.10(a) GCRI Canada’s stewardship shall be measured by integrity, durability, interoperability, usability, correctionability, evidence quality, methods quality, public-safe publication, safeguard strength, technical continuity, records validity, semantic coherence, public authority clarity, community protection, and public trust. 2.6.10(b) Stewardship shall not be measured by transaction volume, market share, sponsor value, provider value, media visibility, public attention, event attendance, capital-reader interest, public authority proximity, number of partnerships, number of logos, size of datasets, number of dashboards, number of downloads, repository stars, social media reach, or apparent ecosystem centrality. 2.6.10(c) Integrity shall require that GCRI Canada say what it knows, what it does not know, what is uncertain, what is disputed, what is stale, what is restricted, what is public-safe, what has been corrected, and what lies outside its authority. 2.6.10(d) Durability shall require that public-good assets, records, methods, repositories, software, datasets, dashboards, ontologies, correction chains, and technical baselines survive leadership changes, funding cycles, platform changes, sponsor changes, provider changes, technology changes, and public attention cycles. 2.6.10(e) Interoperability shall require disciplined compatibility across systems, jurisdictions, public-good institutions, technical environments, evidence practices, and controlled vocabularies without uncontrolled data sharing, semantic flattening, legal merger, public authority delegation, provider preference, or loss of local context. 2.6.10(f) Usability shall require that public-good assets be understandable and usable by intended audiences within proper scope, limitations, access class, public-safe status, and correction path. Usability shall not be achieved by simplifying away legal boundaries, uncertainty, protected knowledge, data rights, public authority limits, finance boundaries, or role separation. 2.6.10(g) Correctionability shall require that errors, changed evidence, superseded methods, public-safe concerns, data rights issues, model failures, cyber issues, software vulnerabilities, semantic drift, and public claim overreach can be addressed through records-valid correction, supersession, withdrawal, retraction, restriction, or archival. 2.6.10(h) Public trust shall arise from disciplined restraint as well as production. GCRI Canada shall be trusted because it refuses overclaim, corrects errors, protects communities, secures systems, preserves records, controls vocabulary, respects public authority boundaries, avoids finance overclaim, prevents sponsor control, maintains provider neutrality, and separates public-good stewardship from execution. 2.6.10(i) GCRI Canada shall not pursue growth metrics that weaken stewardship quality. A smaller, accurate, secure, correctionable, public-benefit output shall be preferred over a larger, visible, sponsor-attractive, provider-attractive, or media-friendly output that is unsafe, overbroad, unmaintainable, uncorrectable, or role-confusing. 2.6.10(j) The Board and officers shall periodically assess whether institutional incentives, funding models, public communications, technical architecture, public authority interfaces, provider relationships, sponsor relationships, and Nexus coordination practices are measuring success by stewardship integrity rather than visibility, revenue, transactionality, or dominance.

2.7 Public-Good Technical Core

2.7.1 Definition of the Public-Good Technical Core. 2.7.1(a) The public-good technical core means the evidence, method, software, ontology, technical baseline, reference architecture, observability, record, repository, model, dataset, dashboard, API, conformance-supporting, secure release, public-safe intelligence, and correction assets stewarded by GCRI Canada for public-benefit purposes. 2.7.1(b) The public-good technical core is constitutional infrastructure because it makes evidence durable, interoperable, verifiable, reviewable, reusable, secure, public-safe where released, and correctionable across time, jurisdictions, institutions, technologies, and public-good use contexts. 2.7.1(c) The public-good technical core shall include both human-governance artifacts and machine-readable or system-operational artifacts. It may include controlled vocabulary, taxonomies, schemas, data dictionaries, model registers, dataset cards, benchmark cards, system cards, inference records, observability methods, evidence-pack structures, proof templates, public-safe publication templates, secure repository structures, release metadata, API specifications, method libraries, software packages, workflow tools, public authority learning assets, Academy materials, and documentation necessary to preserve institutional meaning. 2.7.1(d) The public-good technical core shall be governed as an institutional asset and not merely as software inventory, research output, data inventory, sponsor deliverable, provider contribution, technical convenience, or communications surface. 2.7.1(e) The value of the public-good technical core lies in the ability to preserve public-good meaning, evidence integrity, semantic coherence, security, portability, public-safe release, controlled access where required, and correctionability. 2.7.1(f) A technical asset that cannot be traced, maintained, reviewed, corrected, secured, classified, versioned, lawfully used, or interpreted within role boundaries shall not be treated as mature public-good technical-core infrastructure. 2.7.1(g) GCRI Canada shall maintain the public-good technical core for public-benefit purposes and shall not allow it to become a private product line, sponsor-controlled asset, vendor-controlled chokepoint, proprietary dependency, procurement gate, protocol entitlement, finance-readiness engine, market infrastructure, execution system, or public authority substitute by default. 2.7.1(h) The public-good technical core shall support evidence stewardship, methods discipline, observability, ontology, technical truth, public-good R&D, public-good software, public-safe publication, public authority learning, interoperability, and correctionability. It shall not silently become downstream authority. 2.7.1(i) No actor shall acquire ownership of the public-good technical core or authority over its meaning by reason of funding, sponsorship, technical contribution, hosting, implementation, integration, public authority participation, provider support, academic participation, capital-reader interest, media visibility, or repeated public reference. 2.7.1(j) The public-good technical core shall be read together with GCRI Canada’s mission lock, non-execution boundary, public-benefit mandate, validity-by-record doctrine, correctionability doctrine, anti-capture doctrine, anti-enclosure doctrine, public authority boundary, finance boundary, provider-neutrality rule, sponsor-non-control rule, and public-safe publication obligations.

2.7.2 Reference Architectures, Open Technical Assets, Technical Baselines, Schemas, APIs, Dashboards, Data Tools, Ontologies, and Conformance-Supporting Instruments. 2.7.2(a) The public-good technical core includes reference architectures, open technical assets, technical baselines, schemas, APIs, dashboards, data tools, ontologies, controlled vocabularies, data dictionaries, conformance-supporting instruments, proof templates, model cards, dataset cards, system cards, benchmark cards, public-safe documentation, interoperability mappings, technical profiles, and public authority learning profiles. 2.7.2(b) These assets may support conformance work, evidence quality, systems interoperability, public authority learning, technical literacy, public-safe interpretation, Nexus-compatible coordination, and downstream review by competent actors, but they shall not become certification, recognition, procurement preference, protocol authority, public authority approval, finance-readiness, insurance-readiness, or execution authorization by default. 2.7.2(c) Reference architectures shall be treated as structured guidance and public-good design infrastructure. They may describe how systems, repositories, observability surfaces, data pipelines, AI workflows, secure rooms, controlled rooms, clean rooms, dashboards, APIs, evidence rails, or public-safe publication systems should be organized, but they shall not mandate a vendor, platform, procurement pathway, public authority action, finance pathway, or execution model unless a separate competent authority lawfully and expressly attaches such effect. 2.7.2(d) Technical baselines shall be maintained to support common understanding, interoperability, security, evidence quality, data governance, AI governance, public-safe publication, and disciplined implementation by others. 2.7.2(e) Technical baselines shall carry appropriate versioning, scope statements, assumptions, limitations, maturity status, dependency records, release notes, permitted-use terms, prohibited-use terms where required, and correction paths. 2.7.2(f) A technical baseline shall not be represented as proof of safety, legal compliance, financeability, insurability, procurement readiness, public authority adoption, certification, recognition, protocol effect, or technical guarantee unless such status is separately authorized by competent authority and properly recorded. 2.7.2(g) Schemas, APIs, dashboards, data tools, and conformance-supporting instruments shall be designed to preserve controlled vocabulary, source traceability, lawful basis, access control, classification, confidence, limitations, public-safe release, error handling, and correction. 2.7.2(h) Technical usability shall not override semantic precision. System convenience shall not override legal meaning. Interoperability shall not collapse institutional boundaries. Dashboard visibility shall not create public warning authority. API availability shall not create protocol entitlement. Test completion shall not create certification by default. 2.7.2(i) Ontologies and controlled vocabulary shall be integrated into technical assets so that terms carrying institutional consequence are used only within recorded scope. Terms such as “verified,” “validated,” “recognized,” “certified,” “mature,” “finance-ready,” “public-safe,” “approved,” “adopted,” “official,” “operational,” “proof,” “truth,” “standing,” and “Nexus-compatible” shall not be embedded in systems, metadata, badges, labels, or interfaces in a manner that creates unsupported authority. 2.7.2(j) Conformance-supporting instruments may assist evidence collection, gap identification, technical comparison, structured review, or later assessment by competent actors, but their use shall not be described as conformance determination with external force unless a separate lawful authority has attached such effect. 2.7.2(k) GCRI Canada shall maintain documentation sufficient to allow authorized users to understand what each technical asset is, what it is not, what it supports, what it does not determine, what assumptions it uses, what data it requires, what limitations apply, what risks are known, and how correction occurs.

2.7.3 Evidence Infrastructure, Observability Systems, Model Registers, Dataset Records, Method Libraries, and Public-Safe Intelligence Structures. 2.7.3(a) The public-good technical core includes evidence infrastructure, observability systems, model registers, dataset records, method libraries, confidence logic, corroboration methods, dispute logic, missing-data logic, stale-data logic, spoof-risk logic, correction triggers, public-safe intelligence structures, controlled annexes, secure evidence rooms, clean-room processes, restricted publication pathways, and public authority learning records. 2.7.3(b) These assets shall be structured so that source, method, confidence, limitation, review, classification, public-safe status, lawful basis, permission, access class, and correction status remain visible to authorized users. 2.7.3(c) Evidence infrastructure shall support data-to-evidence conversion without hiding provenance or uncertainty. It shall distinguish raw data, derived data, model outputs, AI-assisted outputs, human observations, public authority inputs, provider attestations, community inputs, Indigenous or protected knowledge, geospatial signals, cyber logs, telemetry, research evidence, benchmark evidence, and interpreted conclusions. 2.7.3(d) No evidence infrastructure shall be designed in a manner that obscures the difference between input, inference, validation, interpretation, publication, recommendation, recognition, certification, protocol effect, public authority action, finance-readiness, procurement, and execution. 2.7.3(e) Observability systems shall support structured awareness of systems, risks, dependencies, infrastructure states, technology conditions, environmental signals, community context, and public authority context without becoming surveillance, emergency command, public warning, operational control, market intelligence for private advantage, procurement direction, finance signal, or public authority substitution. 2.7.3(f) Observability assets shall be classified, access-controlled, and public-safe reviewed according to sensitivity, identifiability, infrastructure exposure, cyber risk, community harm risk, protected knowledge risk, public authority context, data rights, and downstream reliance risk. 2.7.3(g) Model registers, dataset records, method libraries, and intelligence structures shall be designed to prevent false precision and unsupported authority. Each material model, dataset, benchmark, system card, inference record, method profile, or intelligence artifact shall preserve sufficient information to understand purpose, source, scope, limitations, evaluation status, known risks, permitted uses, prohibited uses, review date, and correction status. 2.7.3(h) Public-safe intelligence shall remain decision-supporting, not decision-making. It may inform public authority learning, GRF inputs, GRA inputs, protocol-adjacent technical work, enterprise diligence, community safeguards, research, and technical literacy, but it shall not become public authority command, public warning, finance-readiness, investment advice, procurement approval, certification, protocol entitlement, or execution instruction by default. 2.7.3(i) Dataset records shall preserve origin, lawful basis, permissions, consent alignment where applicable, sensitivity, classification, update status, limitations, bias considerations where relevant, data quality, retention posture, public-safe constraints, and correction pathways. 2.7.3(j) Model registers shall preserve model identity, model version where available, intended use, prohibited use, data restrictions, evaluation status, limitations, known risks, human review requirements, security considerations, privacy considerations, and correction pathways. 2.7.3(k) Method libraries shall preserve purpose, scope, assumptions, input requirements, context limits, review status, maturity, public-safe status, prohibited uses, supersession status, and correction path for each method. 2.7.3(l) GCRI Canada shall not permit evidence infrastructure, observability systems, model registers, dataset records, method libraries, or intelligence structures to be shaped by sponsor pressure, provider preference, public authority expectation, finance narrative, procurement interest, media simplicity, or institutional ambition in a manner inconsistent with public-benefit purpose and evidence integrity.

2.7.4 Secure Repositories, Release Systems, Package Channels, Documentation, and Technical Memory. 2.7.4(a) The public-good technical core includes secure repositories, release systems, package channels, documentation, contribution records, dependency records, software bills of materials where appropriate, signing mechanisms, key management, vulnerability records, release notes, changelogs, deprecation notices, maintenance plans, archival records, backup records, technical memory, and final closeout records. 2.7.4(b) Repository discipline shall prevent silent changes, dependency capture, insecure release, license confusion, uncontrolled forks, unsupported compatibility claims, false reliance on obsolete or experimental materials, unreviewed publication, credential exposure, and hidden control surfaces. 2.7.4(c) Secure repositories shall be governed as public-good control surfaces. Access shall be role-based, least-privilege, logged where material, reviewed periodically, and compatible with classification, privacy, cybersecurity, public authority restrictions, protected knowledge, and public-safe publication requirements. 2.7.4(d) Maintainer privileges shall be controlled. Review gates shall be proportionate to risk. Release authority shall not be confused with ordinary contribution authority. Technical permission to commit, merge, publish, deploy, package, or tag shall not by itself constitute governance authority. 2.7.4(e) Release systems and package channels shall preserve authenticity, integrity, versioning, provenance, rollback capability, public-safe status, dependency awareness, vulnerability response, and correction pathways. 2.7.4(f) Where software, schemas, APIs, dashboards, datasets, models, technical baselines, documentation, or public-safe materials are released for public or controlled use, GCRI Canada shall preserve records sufficient to show what was released, when, under what authority, with what dependencies, under what license, with what known limitations, for what permitted uses, subject to what prohibited uses where applicable, and through what correction pathway. 2.7.4(g) Technical memory shall include the history required to maintain trust in public-good assets over time. GCRI Canada shall maintain records of design decisions, evidence-source decisions, method decisions, dependency changes, vulnerability handling, licensing choices, contribution provenance, release approvals, deprecation events, supersession events, unresolved risks, and public-safe review decisions. 2.7.4(h) Technical memory shall not depend on individual maintainers, founder recollection, informal chat histories, private accounts, undocumented scripts, unversioned notebooks, platform defaults, oral explanations, or uncontrolled folders. 2.7.4(i) Documentation shall be treated as a public-good asset. It shall explain scope, setup, dependencies, assumptions, limitations, data restrictions, security requirements, public-safe status, correction pathways, and role boundaries sufficient to prevent misuse and overclaim. 2.7.4(j) Release documentation shall not use language, badges, labels, or metadata that implies certification, recognition, public authority approval, procurement preference, finance-readiness, protocol entitlement, or execution authority where none exists. 2.7.4(k) Where repository compromise, release error, dependency vulnerability, credential exposure, license conflict, data exposure, hidden telemetry, model-provider risk, or public-safe release error occurs or is suspected, GCRI Canada shall apply incident handling, containment, correction, notice where required, and post-incident review proportionate to the risk.

2.7.5 Public-Good Technical Core as Interoperable, Reviewable, Portable, Versioned, and Correctionable. 2.7.5(a) The public-good technical core shall be interoperable, reviewable, portable where appropriate, versioned, secure, auditable, maintainable, public-safe where released, and correctionable. 2.7.5(b) Technical design shall preserve substitutability, exit readiness, controlled access, lifecycle discipline, records validity, public-good continuity, lawful localization, semantic precision, and public-safe publication. 2.7.5(c) A technical asset that cannot be corrected, retired, replaced, explained, secured, localized, recontextualized, or lawfully maintained shall not be treated as mature public-good infrastructure. 2.7.5(d) Interoperability shall mean disciplined compatibility across systems, jurisdictions, public-good institutions, technical environments, evidence practices, controlled vocabularies, public authority contexts, community contexts, and Nexus-compatible interfaces. 2.7.5(e) Interoperability shall not mean uncontrolled data sharing, semantic flattening, public-good merger, legal fusion, vendor preference, public authority delegation, finance implication, protocol entitlement, or loss of local context. Interoperability shall preserve difference while enabling responsible connection. 2.7.5(f) Reviewability shall require that material technical assets preserve enough source, method, authority, classification, version, dependency, limitation, and public-safe information to allow meaningful assessment by authorized reviewers. Where full public disclosure is unsafe or unlawful, reviewability shall be preserved through controlled access, redacted records, restricted annexes, or independent review. 2.7.5(g) Portability shall include practical ability to migrate, replicate where lawful, archive, redeploy, replace, or substitute mission-critical assets without losing record custody, evidence integrity, semantic meaning, licensing clarity, security posture, public-safe status, or correction history. 2.7.5(h) Portability shall be especially important where cloud services, model providers, proprietary APIs, identity systems, repository platforms, observability vendors, data providers, cybersecurity vendors, or sponsor-supported infrastructure are used. 2.7.5(i) Versioning shall distinguish drafts, prototypes, pilots, adopted releases, public releases, controlled releases, deprecated assets, superseded assets, withdrawn assets, archived assets, and retired assets. Public-facing technical assets shall not hide lifecycle status where reliance risk exists. 2.7.5(j) Correctionability shall apply to technical assets as much as to legal or publication records. Software may require patching, baselines may require supersession, dashboards may require data correction, ontologies may require term revision, APIs may require deprecation, datasets may require withdrawal, and model records may require limitation updates. 2.7.5(k) GCRI Canada shall maintain pathways for reporting, triaging, reviewing, correcting, superseding, withdrawing, deprecating, archiving, and notifying affected users of material technical-core issues. 2.7.5(l) The technical core shall be designed so that correction is practical, visible where appropriate, records-valid, and proportionate to reliance risk.

2.7.6 Public-Good Technical Core as Separate From Proprietary Commercial Inventory. 2.7.6(a) The public-good technical core is separate from proprietary commercial inventory, vendor products, sponsor assets, provider systems, execution tools, National Consortium Company assets, Project SPV assets, private delivery tooling, market infrastructure, and commercial implementation environments unless expressly and lawfully licensed, contributed, integrated, or referenced under mission-compatible terms. 2.7.6(b) GCRI Canada shall not allow public-good technical assets to be rebranded as private commercial inventory, treated as exclusive vendor advantage, embedded in a commercial offering in a manner that misstates ownership or control, or used as a sponsor-controlled legitimacy asset. 2.7.6(c) Where GCRI Canada interfaces with proprietary tools or commercial systems, the interface shall be governed by written terms, records, role boundaries, security requirements, data restrictions, licensing clarity, public-safe publication controls, public claims controls, correction rights, and exit planning. 2.7.6(d) Integration shall not imply endorsement. Compatibility shall not imply preference. Contribution shall not imply control. Technical dependence shall not imply ownership of public-good meaning. Use in a commercial environment shall not convert public-good assets into commercial inventory. 2.7.6(e) GCRI Canada may receive tools, infrastructure, data access, cloud credits, model access, technical contributions, implementation support, facilities, or other in-kind resources from private actors only where such support is mission-compatible, conflict-reviewed, sponsor-neutral, provider-neutral, cybersecurity-reviewed, data-rights-compliant, records-valid, and protected against capture. 2.7.6(f) Such support shall not purchase privileged control over methods, repositories, public releases, public authority access, public claims, technical baseline status, correction, publication timing, or institutional meaning. 2.7.6(g) If a public-good technical asset is combined with proprietary components, the boundary between public-good asset, proprietary component, licensed dependency, restricted dataset, provider system, and execution system shall be recorded and communicated where material. 2.7.6(h) No hybrid asset shall be described in a manner that hides private control surfaces, vendor dependencies, sponsor influence, proprietary restrictions, public-good limitations, data-rights limits, or correction constraints. 2.7.6(i) GCRI Canada shall protect public-good licensing, contribution terms, repository terms, trademark terms, documentation, and public claims from commercial reinterpretation that would create exclusivity, implied certification, procurement preference, finance-readiness, market ranking, or public authority approval. 2.7.6(j) Where a private actor misuses the public-good technical core as commercial inventory, GCRI Canada may require correction, removal of claims, license enforcement, mark-use restriction, access restriction, public-safe clarification, termination, or other remedies appropriate to the breach.

2.7.7 Public-Good Technical Core as Separate From Protocol Authority Unless Separately Designated. 2.7.7(a) The public-good technical core is separate from protocol authority unless separately designated by competent Nexus protocol governance and recorded within lawful scope. 2.7.7(b) Technical baselines, APIs, schemas, proof templates, software tools, model registers, dataset cards, observability methods, test harnesses, conformance-supporting instruments, and public-good releases may inform protocol authority but shall not create protocol effect, role keys, smart licenses, entitlement states, proof-receipt legal effect, public registry status, or external conformance states by default. 2.7.7(c) GCRI Canada may design technical inputs that are useful to protocol authority, but design contribution shall not equal protocol governance. A method may be technically sound without being protocol-binding. A schema may be widely adopted without becoming a role key. A proof template may support evidence without creating legal effect. A public-good release may be Nexus-compatible without becoming mandatory protocol infrastructure. 2.7.7(d) Where a GCRI Canada asset is proposed for protocol-authority use, the transition from technical asset to protocol-effective instrument shall require separate review, authority mapping, records, role designation, version identification, public-safe language, correction logic, dependency review, legal review where required, and boundary terms. 2.7.7(e) GCRI Canada shall not allow informal use, public repetition, technical dependency, ecosystem expectation, dashboard design, repository labeling, proof-receipt language, token design, smart-contract integration, API use, or metadata fields to attach protocol effect silently. 2.7.7(f) Any protocol-adjacent output of GCRI Canada shall include language sufficient to distinguish evidence support, method support, technical baseline support, conformance support, public-good software support, or interoperability support from protocol entitlement, protocol authority, or binding conformance status. 2.7.7(g) This distinction shall be preserved in documentation, dashboards, repositories, user interfaces, public materials, partner communications, Academy materials, and machine-readable outputs. 2.7.7(h) Where a protocol authority later adopts, incorporates, references, or relies upon a GCRI Canada output, such adoption shall be separately recorded, scoped, versioned, governed, and corrected through the competent authority. GCRI Canada’s original role shall remain upstream technical and evidence support unless expressly and lawfully changed. 2.7.7(i) GCRI Canada shall not issue, administer, revoke, or validate protocol role keys, smart licenses, protocol entitlements, proof-receipt legal effect, or externally binding conformance states by default. 2.7.7(j) Any public or technical claim implying protocol effect from a GCRI Canada asset without competent designation shall be corrected, restricted, withdrawn, or clarified.

2.7.8 Public-Good Technical Core as Separate From Vendor Products, Provider Implementations, National Companies, Project SPVs, and Execution Systems. 2.7.8(a) The public-good technical core is separate from vendor products, provider implementations, National Consortium Companies, Project SPVs, asset operations, deployment systems, market infrastructure, regulated execution systems, and commercial delivery systems. 2.7.8(b) GCRI Canada may interface with such systems, test them, receive data from them, develop methods relevant to them, produce public-safe baselines, structure evidence concerning them, or support learning about them, but such interface shall not create ownership, operation, endorsement, procurement preference, public authority approval, finance-readiness, certification, protocol entitlement, or execution authority. 2.7.8(c) Provider systems may be evidence sources, test environments, integration targets, or implementation contexts, but they shall not control GCRI Canada’s public-good technical core, public claims, methods, publication timing, correction pathways, public authority access, or institutional meaning. 2.7.8(d) National Consortium Companies and Project SPVs may use evidence, methods, baselines, public-good software, public-safe materials, or technical tools within lawful boundaries, but their execution decisions, contracts, assets, liabilities, providers, investors, insurers, revenues, governance, operations, and market-facing obligations shall remain outside GCRI Canada’s legal and institutional role. 2.7.8(e) Where GCRI Canada tests, evaluates, documents, benchmarks, integrates with, observes, or receives outputs from a vendor or provider system, the resulting output shall be described in role-bounded language. It shall not be represented as endorsement, procurement recommendation, legal certification, market rating, public authority approval, insurance suitability, investment suitability, operational approval, or guarantee of performance. 2.7.8(f) Execution systems shall remain separate in architecture and governance. GCRI Canada shall not design its public-good technical core so that it becomes indispensable to operational command, dispatch, asset control, settlement, payments, trading, procurement execution, emergency response, infrastructure operation, project governance, or regulated market activity unless a separate lawful instrument defines a different role consistent with this Charter. 2.7.8(g) GCRI Canada shall maintain boundary language, records, access controls, technical separation, data-use rules, licensing terms, public claims restrictions, and correction responsibility where its technical core interfaces with execution-capable systems. 2.7.8(h) A vendor, provider, National Consortium Company, Project SPV, or execution actor shall not use compatibility with, contribution to, integration with, or reference to GCRI Canada technical assets as proof of preferred status, public authority approval, procurement advantage, finance-readiness, recognition, certification, protocol entitlement, or Nexus legitimacy unless such status has been separately granted by competent authority and properly recorded. 2.7.8(i) Where provider implementation or execution-system use creates public confusion regarding GCRI Canada’s role, GCRI Canada shall require corrective language, restrict use, revise documentation, issue public-safe clarification, or terminate access where appropriate. 2.7.8(j) GCRI Canada shall preserve the Public-Good Stack and Enterprise Stack distinction in the design, licensing, release, documentation, and public description of all technical-core interfaces.

2.7.9 Public-Good Technical Core as Protected Against Enclosure, Dependency Lock-In, Sponsor Capture, Vendor Chokepoints, and Hidden Control Surfaces. 2.7.9(a) The public-good technical core shall be protected against enclosure, dependency lock-in, sponsor capture, vendor chokepoints, cloud chokepoints, model-provider capture, repository capture, data capture, licensing traps, single-maintainer fragility, proprietary format dependency, hidden telemetry, unmanaged AI dependencies, undocumented automation, opaque identity layers, hidden administrative control, and hidden control surfaces. 2.7.9(b) Where dependencies are unavoidable, they shall be recorded, reviewed, mitigated, monitored, and subject to exit planning proportionate to risk and criticality. 2.7.9(c) Enclosure may occur through legal rights, technical architecture, access control, data concentration, licensing restrictions, cloud dependency, model dependency, proprietary formats, platform lock-in, contributor dominance, funding conditions, public authority dependency, sponsor control, or practical inability to maintain assets without a private actor. GCRI Canada shall identify enclosure risk based on practical control, not merely formal ownership. 2.7.9(d) Dependency management shall include review of vendors, platforms, APIs, repositories, cloud environments, AI models, model providers, data providers, security tools, identity systems, observability tools, release systems, storage systems, package channels, and collaboration tools. 2.7.9(e) The institution shall assess whether a dependency creates unacceptable risk to continuity, public-good availability, data sovereignty, cybersecurity, privacy, correctionability, portability, public-safe publication, licensing clarity, institutional independence, or public trust. 2.7.9(f) Hidden control surfaces shall be treated as governance risks. Systems that allow unreviewed changes, invisible data flows, undisclosed telemetry, non-transparent model behavior, privileged vendor access, unmanaged administrative rights, undocumented automation, opaque ranking logic, or unrecorded external dependencies shall not be used for mission-critical technical-core functions without review, controls, and documented justification. 2.7.9(g) Sponsor capture of the technical core may occur where sponsor support shapes repository priority, feature design, method design, public authority access, publication timing, release order, dashboard framing, public claims, correction handling, or dependency selection. Such capture is prohibited. 2.7.9(h) Vendor chokepoint risk may occur where GCRI Canada cannot maintain, explain, correct, migrate, audit, publish, secure, or reuse a public-good asset without a vendor’s permission or practical cooperation. Vendor convenience shall not override public-good resilience. 2.7.9(i) GCRI Canada shall require, where appropriate, exportable data, documented APIs, backup access, license clarity, administrative control, termination rights, transition assistance, security documentation, audit rights, escrow or backup arrangements where appropriate, and continuity plans. 2.7.9(j) AI dependencies shall receive heightened review. Proprietary models, opaque embeddings, external inference services, vendor-hosted agents, automated classification tools, and AI copilots may create data leakage, hallucination, hidden training, cross-border transfer, public-safe risk, or unreviewed authority. AI tools shall not control institutional truth. 2.7.9(k) Where public claims imply openness, independence, neutrality, portability, or public-good control, but material dependencies limit those qualities, GCRI Canada shall disclose or qualify the claim internally or publicly as appropriate to prevent misleading reliance. 2.7.9(l) Where enclosure, dependency lock-in, sponsor capture, vendor chokepoint, or hidden control risk becomes material, GCRI Canada shall redesign, diversify, migrate, restrict, renegotiate, disclose where appropriate, suspend, terminate, or correct the affected asset or relationship.

2.7.10 Board-Level and Technical-Stewardship Duties for Public-Good Technical Core Integrity. 2.7.10(a) The Board and delegated technical stewards shall protect the integrity, security, licensing, portability, public-good alignment, correctionability, maintainability, reviewability, lifecycle discipline, and continuity of the public-good technical core. 2.7.10(b) Material changes to mission-critical technical assets shall require record support, review, versioning, authority confirmation, risk assessment, dependency assessment, public-safe assessment, and notice where reliance risk exists. 2.7.10(c) Board-level duties shall include oversight of technical-core strategy, funding, risk appetite, anti-capture controls, anti-enclosure controls, major dependencies, licensing posture, cybersecurity posture, privacy posture, data-rights posture, AI-governance posture, public-good continuity, and alignment with GCRI Canada’s constitutional role. 2.7.10(d) The Board shall not need to perform technical work directly, but it shall ensure that appropriate expertise, delegated authority, review bodies, controls, records, escalation pathways, and correction mechanisms exist. 2.7.10(e) Technical stewards shall maintain asset inventories, ownership records, contribution records, licensing records, release records, vulnerability records, correction records, dependency records, deprecation plans, portability plans, continuity plans, public-safe status records, and archival records for mission-critical technical assets. 2.7.10(f) Technical stewards shall ensure that technical changes do not silently alter public meaning, role boundaries, controlled vocabulary, data handling, privacy posture, public-safe status, licensing posture, security posture, or institutional authority. 2.7.10(g) Technical stewards shall distinguish contribution authority from release authority, release authority from governance authority, technical compatibility from endorsement, public-good baseline from certification, and tool output from institutional determination. 2.7.10(h) The Board and technical stewards shall ensure that repositories, dashboards, APIs, datasets, software releases, methods, ontologies, model registers, dataset cards, benchmark cards, and technical baselines carry appropriate status, scope, limitations, dependency notes, permitted-use terms, prohibited-use terms where required, correction pathways, and public-safe language. 2.7.10(i) Where the technical core is threatened by compromise, dependency failure, loss of maintainers, licensing dispute, security incident, data exposure, repository corruption, model failure, sponsor pressure, provider control, public misunderstanding, semantic drift, or public overclaim, the Board or delegated authority shall take corrective measures. 2.7.10(j) Corrective measures may include freezing releases, revoking access, rotating credentials, migrating systems, issuing correction notices, superseding assets, withdrawing materials, deprecating releases, commissioning independent review, restructuring technical governance, terminating dependencies, or restricting public claims. 2.7.10(k) The Board shall periodically review whether the public-good technical core remains aligned with public-benefit purpose, non-execution, role separation, provider neutrality, sponsor non-control, public authority boundaries, finance boundaries, privacy, cybersecurity, protected knowledge, public-safe publication, and correctionability. 2.7.10(l) Public-good technical core integrity shall be treated as a constitutional obligation of GCRI Canada and not as an optional technical preference, administrative matter, or ordinary project-management concern.

2.8 Upstream Truth Mandate

2.8.1 Upstream Truth as GCRI Canada’s Constitutional Function. 2.8.1(a) Upstream truth is GCRI Canada’s constitutional function. It means the disciplined production, stewardship, review, preservation, publication where public-safe, and correction of evidence, methods, observability, ontology, technical baselines, public-good software, verifiable compute methods, verifiable intelligence methods, and public-good technical assets before public claims, recognition, finance-readiness, protocol effect, procurement, public authority action, or execution. 2.8.1(b) Upstream truth is not absolute certainty, institutional infallibility, machine authority, sponsor-approved narrative, provider proof, public authority approval, finance signal, certification, or execution instruction. It is method-supported institutional truthfulness under records, limitations, uncertainty, classification, public-safe treatment, review, and correction. 2.8.1(c) The upstream truth mandate shall require GCRI Canada to distinguish what is known, what is probable, what is disputed, what is uncertain, what is stale, what is missing, what is inferred, what is restricted, what is unsafe for public release, what is outside the record, and what must not be publicly overstated. 2.8.1(d) GCRI Canada shall reject false certainty, unsupported claims, public narrative inflation, sponsor-driven conclusions, provider-driven proof, political convenience, media simplification, public authority implication, finance overclaim, procurement implication, certification drift, protocol drift, dashboard authority, and AI-generated authority. 2.8.1(e) Upstream truth shall be prior to downstream action but not superior to all downstream actors. It informs; it does not command. It supports recognition by The Global Risks Forum (GRF), finance-readiness interpretation by The Global Risks Alliance (GRA), protocol work by competent protocol authority, public authority learning, enterprise diligence, community understanding, and public-safe institutional learning, but it shall not become those functions by implication. 2.8.1(f) Because upstream truth shapes later reliance, GCRI Canada shall apply high discipline to source records, method selection, confidence treatment, limitations, classification, public-safe status, public claims, technical interfaces, and correction. 2.8.1(g) The upstream position is not weaker because it is non-executing. It is foundational because downstream systems depend on disciplined inputs, bounded meaning, and correctionable evidence. 2.8.1(h) GCRI Canada shall not use the importance of upstream truth to claim downstream supremacy. Evidence seriousness does not confer recognition authority, finance authority, public authority, protocol authority, procurement authority, certification authority, or execution authority. 2.8.1(i) The upstream truth mandate shall bind all GCRI Canada programs, publications, repositories, data systems, dashboards, maps, AI workflows, public authority materials, Academy materials, sponsorship arrangements, provider interfaces, and Nexus coordination instruments.

2.8.2 Upstream Truth as Evidence, Methods, Observability, Ontology, Technical Baselines, Research Integrity, and Public-Good Technical Assets. 2.8.2(a) Upstream truth includes evidence, methods, observability, ontology, controlled vocabulary, taxonomies, schemas, data dictionaries, semantic mappings, technical baselines, research integrity, public-good software, model records, dataset records, benchmark records, system cards, public-safe outputs, correction chains, technical memory, secure repositories, and governed release systems. 2.8.2(b) Upstream truth is an architecture of disciplined knowing, not a single report, statement, dashboard, model output, publication, technical release, score, proof receipt, or public claim. 2.8.2(c) Evidence contributes facts, signals, observations, records, and source materials. Methods explain how evidence is selected, tested, compared, weighted, limited, and interpreted. Observability structures system awareness. Ontology and controlled vocabulary preserve meaning. Technical baselines support interoperability. Research integrity protects independence. Public-good software and repositories operationalize evidence architecture. Correction chains preserve trust over time. 2.8.2(d) GCRI Canada shall not allow any one component of upstream truth to dominate the others in a manner that creates blind spots. Data without methods is insufficient. Methods without records are insufficient. Observability without public-safe governance is unsafe. Ontology without correction creates semantic rigidity. Software without governance becomes hidden authority. AI outputs without review become unreliable or misleading. 2.8.2(e) The upstream truth architecture shall be designed to support cross-domain systemic understanding. It shall integrate technological, legal, social, public authority, community, environmental, cyber, data, infrastructure, and institutional contexts where relevant, while preserving classification, locality, sovereignty, privacy, protected knowledge, and role boundaries. 2.8.2(f) Technical baselines and public-good software shall be upstream truth assets only within their recorded scope. They may structure evidence, support interoperability, improve public-good implementation, and assist downstream review by others, but they shall not create certification, public authority approval, procurement readiness, finance-readiness, protocol entitlement, or execution authority by default. 2.8.2(g) Research integrity shall require that upstream truth remain independent of sponsor pressure, provider preference, public authority expectation, political convenience, media simplicity, finance narrative, procurement interest, institutional ambition, or public visibility. 2.8.2(h) GCRI Canada shall maintain upstream truth through records, repositories, method libraries, technical baselines, ontologies, controlled vocabularies, software releases, model registers, dataset records, public-safe publications, and correction systems that are traceable, reviewable, secure, and correctionable. 2.8.2(i) Upstream truth assets shall be protected against enclosure, capture, dependency lock-in, hidden control surfaces, unreviewed AI authority, uncontrolled public claims, and semantic drift.

2.8.3 Upstream Truth as Prior to Recognition, Finance-Readiness, Protocol Effect, Procurement, Public Authority Action, and Execution. 2.8.3(a) Upstream truth is prior to recognition, finance-readiness, protocol effect, procurement, public authority action, enterprise adoption, market action, public warning, insurance interpretation, public finance interpretation, and execution. 2.8.3(b) No downstream function shall be treated as valid merely because GCRI Canada produced evidence, methods, observability outputs, technical baselines, public-good software, public-safe summaries, or correction signals relevant to it. Each downstream function requires its own competent actor, proper record, review, authority, legal basis, and boundary. 2.8.3(c) Evidence relevant to recognition may be routed to The Global Risks Forum (GRF), but GCRI Canada shall not issue GRF recognition, standing, maturity records, registry status, claims determinations, stakeholder legitimacy, or public-facing legitimacy by default. 2.8.3(d) Evidence relevant to finance-readiness may be routed to The Global Risks Alliance (GRA) or competent capital-facing actors, but GCRI Canada shall not provide investment advice, insurance approval, credit opinion, rating, underwriting conclusion, public finance approval, capital commitment, transaction recommendation, or finance-readiness determination. 2.8.3(e) Technical baselines relevant to protocol work may be routed to competent protocol authority, but GCRI Canada shall not create protocol entitlements, role keys, smart licenses, proof-receipt legal effect, public registry status, or externally binding conformance states by default. 2.8.3(f) Evidence relevant to procurement, public authority decisions, emergency management, public health, infrastructure operation, public finance, or execution shall be treated with particular boundary discipline. GCRI Canada may support understanding and provide evidence records, but the lawful decision-maker shall remain outside GCRI Canada unless a separate lawful authority exists and is records-valid. 2.8.3(g) The fact that downstream actors rely on GCRI Canada’s upstream truth shall not alter GCRI Canada’s role. Reliance by others may increase the need for careful limitations, correction notices, public-safe language, source discipline, and status labels, but it shall not convert GCRI Canada into the downstream actor. 2.8.3(h) GCRI Canada shall not design documents, dashboards, maps, APIs, badges, public reports, technical baselines, repository labels, public authority rooms, provider materials, sponsor acknowledgments, or capital-reader materials in a manner that collapses upstream truth into downstream authority. 2.8.3(i) Where upstream materials are handed off to downstream actors, GCRI Canada shall preserve records identifying the source, scope, status, limitations, review level, public-safe classification, receiving function, and correction path where material. 2.8.3(j) Where downstream actors misuse upstream truth to imply recognition, finance-readiness, protocol effect, procurement approval, public authority action, certification, or execution authority, GCRI Canada shall require correction, clarify the record, restrict use, or take other appropriate action.

2.8.4 Upstream Truth as Decision-Supporting but Not Decision-Making. 2.8.4(a) Upstream truth may support decisions but shall not make GCRI Canada the decision-maker. 2.8.4(b) GCRI Canada may produce evidence packs, technical notes, public-safe reports, confidence summaries, public authority learning materials, finance-readiness inputs, observability outputs, method notes, model records, dataset records, benchmark records, technical baselines, public-good software, and correction signals, but those outputs shall not decide, approve, procure, fund, warn, regulate, certify, rate, underwrite, guarantee, insure, lend, invest, or execute. 2.8.4(c) Decision-supporting outputs shall identify their scope, intended use, limitations, source base, method base, confidence level where appropriate, public-safe status, review status, classification, and correction path. 2.8.4(d) Decision-supporting outputs shall not be drafted, designed, titled, visualized, labeled, scored, badged, or distributed in a manner that implies stronger legal, technical, financial, public authority, procurement, certification, protocol, or execution effect than they possess. 2.8.4(e) GCRI Canada shall preserve the agency and accountability of downstream actors. Public authorities shall make public decisions. Boards shall make governance decisions. GRF shall make recognition and maturity determinations where authorized. GRA shall handle finance-readiness translation within its boundary. Protocol authority shall determine protocol effect where competent. Enterprise actors, National Consortium Companies, Project SPVs, qualified providers, and operators shall execute their lawful operations. 2.8.4(f) Decision-supporting status shall apply to dashboards, maps, observability outputs, public-safe reports, technical baselines, model summaries, dataset summaries, benchmark cards, risk indicators, confidence logic, and AI-assisted summaries unless a separate competent authority has lawfully attached a different effect. 2.8.4(g) Where decision-supporting materials are likely to be relied upon by non-expert audiences, GCRI Canada shall use especially clear language to prevent overreliance. A public-safe summary may be accessible without being simplistic. A technical report may be useful without being decisive. A dashboard may be informative without being authoritative. 2.8.4(h) GCRI Canada shall not allow decision-supporting work to become unrecorded advisory service, professional opinion, investment advice, procurement recommendation, public authority instruction, public warning, certification, protocol entitlement, or execution command by repeated practice or public perception. 2.8.4(i) Any material ambiguity between decision support and decision-making shall be resolved in favor of the narrower, non-executing, public-good-preserving interpretation unless applicable law and competent authority expressly provide otherwise.

2.8.5 Upstream Truth as Challengeable, Confidence-Aware, Limitation-Aware, and Correctionable. 2.8.5(a) Upstream truth shall be challengeable, confidence-aware, limitation-aware, uncertainty-aware, disputed-evidence-aware, stale-data-aware, missing-data-aware, model-limit-aware, bias-aware where relevant, context-aware, public-safe-aware, and correctionable. 2.8.5(b) A claim that cannot be challenged, traced, reviewed, limited, corrected, superseded, restricted, withdrawn, or recontextualized shall not be treated as upstream truth. 2.8.5(c) Challengeability shall require pathways for internal review, expert challenge, participant challenge, community challenge where appropriate, Indigenous or local knowledge clarification where applicable, public authority clarification, technical dispute, data correction, method reconsideration, and public-safe review. 2.8.5(d) GCRI Canada shall not treat challenge as hostility where challenge is offered in good faith and within appropriate process. Challenge, dissent, uncertainty, and correction shall be treated as features of institutional seriousness. 2.8.5(e) Confidence awareness shall require that evidence strength be communicated in proportion to the record. High-confidence claims, low-confidence claims, disputed claims, preliminary findings, exploratory signals, stale records, inferred conclusions, AI-assisted outputs, public-safe summaries, and restricted evidence shall not be presented as equivalent. 2.8.5(f) Where precision is unavailable, GCRI Canada shall preserve uncertainty rather than fabricate certainty. Where evidence is incomplete, GCRI Canada shall state incompleteness rather than substitute narrative. Where methods are provisional, GCRI Canada shall state provisional status rather than imply maturity. 2.8.5(g) Limitation awareness shall require that assumptions, scope limits, data gaps, method limits, context limits, model limits, public-safe restrictions, classification limits, and prohibited uses be recorded and communicated where material. 2.8.5(h) Correctionability shall require that errors, changed evidence, superseded methods, public-safe concerns, data rights issues, model failures, cyber issues, public claim overreach, sponsor misuse, provider misuse, public authority ambiguity, and finance overclaim can be addressed. 2.8.5(i) Upstream truth matures through correction; it does not become less legitimate because it is corrected. GCRI Canada shall treat correction as a public-good duty and a condition of trust. 2.8.5(j) Correction pathways shall include intake, triage, review, authority assignment, records update, public-safe notice where required, downstream notice where required, supersession, withdrawal, retraction, downgrade, reinstatement, archival, and closeout. 2.8.5(k) The more widely an upstream truth output is used, cited, integrated, or relied upon, the stronger the duty to maintain confidence treatment, limitation disclosure, and correctionability.

2.8.6 Upstream Truth as Source-Lined, Provenance-Bearing, Classification-Aware, and Records-Valid. 2.8.6(a) Upstream truth shall be source-lined, provenance-bearing, classification-aware, permission-aware, custody-aware, lawful-basis-aware, access-controlled where required, and records-valid. 2.8.6(b) Each material output shall be capable of showing what sources support it, what methods were applied, what assumptions exist, what limits apply, what review occurred, what classification governs it, what public-safe status applies, what authority supports release, and how correction may occur. 2.8.6(c) Source-lining shall include sufficient linkage between claims and underlying evidence to permit review by authorized persons. It shall not require public disclosure of protected sources, personal information, cyber-sensitive records, public authority restricted materials, confidential data, commercial secrets, Indigenous knowledge, protected knowledge, or other restricted substrata. Source discipline and public release are distinct questions. 2.8.6(d) Provenance shall include the origin, custody, transformation, review, and use history of material evidence where appropriate. Evidence transformed through AI, modeling, aggregation, geospatial processing, anonymization, redaction, summarization, translation, or statistical treatment shall preserve records sufficient to understand the transformation and its limits. 2.8.6(e) Classification awareness shall prevent inappropriate public release, internal overexposure, cross-border transfer, AI ingestion, sponsor access, provider access, public authority ambiguity, or reuse beyond purpose. 2.8.6(f) GCRI Canada shall not treat information as unrestricted merely because it appears in a repository, dataset, dashboard, model output, public authority room, partner system, cloud environment, public website, or third-party database. 2.8.6(g) Records-valid upstream truth shall require records sufficient to establish the act, source, method, authority, date, status, classification, limitations, review, public-safe treatment, and correction path where material. 2.8.6(h) No record means no public meaning. Informal consensus, meeting attendance, public authority interest, sponsor funding, provider contribution, technical access, dashboard visibility, social media repetition, or AI-generated text shall not create upstream truth validity without proper records. 2.8.6(i) Where source records are incomplete, contested, missing, restricted, or unsafe to disclose, GCRI Canada shall record the limitation and restrict, qualify, withhold, or correct the output as appropriate. 2.8.6(j) Source-lining, provenance, classification, and records validity shall apply to human-authored and AI-assisted outputs alike.

2.8.7 Upstream Truth as Public-Safe Before Public Release. 2.8.7(a) Upstream truth shall be public-safe before public release. 2.8.7(b) Public-safe review shall protect privacy, cybersecurity, infrastructure sensitivity, public authority limits, finance sensitivity, commercial sensitivity, community safeguards, Indigenous and protected knowledge, vulnerable communities, public safety, protected participation, source protection, lawful confidentiality, and institutional role clarity. 2.8.7(c) Evidence may be true yet not public-safe. Public-safe publication shall determine what can be released, not what exists. 2.8.7(d) Public-safe review shall consider direct harm, indirect harm, re-identification, geospatial exposure, operational misuse, cyber exploitation, infrastructure targeting, retaliation risk, community vulnerability, protected knowledge exposure, market sensitivity, procurement sensitivity, public authority confusion, finance overclaim, provider preference, sponsor overclaim, and execution implication. 2.8.7(e) Public-safe release shall not be reduced to legal disclaimer. It shall include review of content, context, audience, timing, format, metadata, labels, charts, maps, dashboards, badges, captions, repository tags, AI summaries, and likely public meaning. 2.8.7(f) Where full public release is unsafe, GCRI Canada may use redaction, aggregation, delayed publication, controlled annexes, restricted rooms, clean rooms, private correction notices, public-safe summaries, synthetic examples, or non-public archival. 2.8.7(g) The choice among public release, controlled release, restricted release, delayed release, redacted release, or non-release shall be based on law, risk, public-benefit purpose, privacy, cybersecurity, public authority restrictions, protected knowledge, community safeguards, and institutional responsibility. 2.8.7(h) Public-safe publication shall include language discipline. Even where content is safe to release, the way it is described may create unsafe reliance or false authority. GCRI Canada shall review titles, captions, summaries, visualizations, dashboards, maps, claims, tags, metadata, public authority references, sponsor acknowledgments, provider references, and public statements for public-safe meaning. 2.8.7(i) No publication shall imply official public warning, emergency command, regulatory approval, procurement approval, public finance approval, investment suitability, insurance readiness, certification, protocol effect, or execution authority unless such effect is separately lawful, authorized, and records-valid. 2.8.7(j) Where a released output becomes unsafe, misleading, stale, overbroad, misused, or incorrect, GCRI Canada shall correct, restrict, supersede, withdraw, retract, downgrade, or clarify the output as appropriate.

2.8.8 Upstream Truth as AI-Assisted Only Under Human Review, Model Governance, and Evidence Records Where Material. 2.8.8(a) Upstream truth may be AI-assisted only under model governance, retrieval controls, embedding controls, inference records, evaluation records, access limits, human review where material, public-safe review, security controls, privacy controls, and correction paths. 2.8.8(b) AI systems may help classify, summarize, detect anomalies, compare sources, translate, route evidence, identify missing information, support draft analysis, assist technical review, and improve retrieval, but AI outputs shall not become authority, truth, warning, finance-readiness, certification, recognition, public authority action, procurement approval, protocol entitlement, or public claim by themselves. 2.8.8(c) GCRI Canada shall distinguish AI-assisted workflow from AI-authorized result. A model may assist evidence processing, but the institution shall remain responsible for review, limitation disclosure, public-safe treatment, and correction where the output is material. 2.8.8(d) AI-generated content shall not bypass source-lining, provenance, method review, public-safe review, controlled vocabulary, classification, records validity, or human accountability where material. 2.8.8(e) AI use shall be records-valid where material. Records may include model identity, model version where available, task class, prompt or retrieval class where appropriate, retrieval sources, evaluation status, human reviewer, data classification, access controls, limitations, public-safe status, and correction status. 2.8.8(f) GCRI Canada shall not ingest restricted, rights-bearing, public authority restricted, sovereign-sensitive, confidential, cyber-sensitive, Indigenous, community-sensitive, or protected knowledge materials into AI systems unless lawful, authorized, secure, purpose-bound, classification-compliant, and consistent with data rights, public-safe obligations, and this Charter. 2.8.8(g) AI governance shall protect against model hallucination, bias, overconfidence, hidden training use, data leakage, prompt injection, insecure integration, vendor capture, model-provider lock-in, cross-border transfer, unreviewed automation, and public meaning beyond the evidence record. 2.8.8(h) AI-assisted outputs shall carry appropriate limitation treatment where material, especially where they summarize sensitive evidence, classify risks, generate public-facing language, assist observability, support public authority learning, produce maps, compare providers, or support finance-adjacent understanding. 2.8.8(i) GCRI Canada shall not allow AI fluency, speed, or apparent confidence to substitute for source discipline, method discipline, public-safe review, human judgment, and correctionability. 2.8.8(j) Where AI-assisted outputs are wrong, misleading, untraceable, biased, unsafe, overconfident, stale, improperly sourced, or inconsistent with controlled vocabulary, GCRI Canada shall correct the record, adjust workflows, and restrict or withdraw outputs where necessary.

2.8.9 Upstream Truth as Sovereignty-Compatible and Context-Respecting. 2.8.9(a) Upstream truth shall be sovereignty-compatible, context-respecting, jurisdictionally aware, local-knowledge-aware, Indigenous-protocol-aware, community-safeguard-aware, language-aware where appropriate, and public authority-aware. 2.8.9(b) Global interoperability shall not erase local meaning, override local law, flatten Indigenous protocols, disregard community context, or transfer data beyond lawful and safeguarded conditions. 2.8.9(c) Sovereignty-compatible truth shall respect jurisdictional authority, public authority structures, data localization requirements, sovereign data zones, conflict-of-law issues, public-sector sensitivities, sanctions and export-control constraints, Indigenous data considerations, and lawful restrictions on disclosure or transfer. 2.8.9(d) GCRI Canada shall not treat global public-good interest, technical convenience, research usefulness, sponsor interest, provider access, public authority attention, or Nexus interoperability as permission to disregard sovereignty, law, public authority capacity, Indigenous protocols, protected knowledge, or local context. 2.8.9(e) Context-respecting truth shall preserve the setting in which evidence arises. A risk signal in a northern community, Indigenous territory, urban infrastructure system, public health setting, cyber environment, energy grid, water system, telecommunications network, remote connectivity context, climate-vulnerable region, or contested territory may have meanings that cannot be accurately interpreted through generic global categories alone. 2.8.9(f) Interoperability shall be achieved through semantic mapping, equivalence notes, divergence logs, localization notes, public-safe summaries, controlled vocabulary, jurisdictional tags, and context records, not through erasure of difference. 2.8.9(g) GCRI Canada shall preserve local truth while supporting global comparability. Where local evidence cannot be safely generalized, the limitation shall be preserved. Where global categories do not fit local evidence, GCRI Canada shall create appropriate mappings rather than distort the evidence. 2.8.9(h) Public authority context shall be preserved. Participation, data contribution, comment, attendance, review, or learning by a public authority shall not be interpreted as adoption, approval, funding, procurement, regulatory decision, public warning, or sovereign obligation unless separately authorized and records-valid. 2.8.9(i) Where cross-border work creates conflict-of-law, data transfer, public authority, protected knowledge, cyber, sanctions, export-control, or sovereignty risk, GCRI Canada shall apply the most protective lawful approach pending review. 2.8.9(j) GCRI Canada shall maintain Canada-to-global and global-to-Canada translation mechanisms that preserve local law, local meaning, controlled vocabulary, public-safe status, role boundaries, and correction pathways.

2.8.10 Upstream Truth as a Public-Good Asset That Cannot Be Bought, Owned, Suppressed, or Inflated by Sponsors, Providers, Funders, or Public Authorities. 2.8.10(a) Upstream truth is a public-good asset that cannot be bought, owned, suppressed, inflated, distorted, privately controlled, publicly overstated, or converted into private legitimacy by sponsors, providers, funders, donors, public authorities, capital readers, vendors, platforms, media actors, founders, internal leadership, or technical contributors. 2.8.10(b) Support may fund the conditions for truth; it may not purchase truth. Funding may support research capacity; it may not predetermine findings. Sponsorship may support public-good infrastructure; it may not control methods, publications, corrections, public authority access, or public meaning. Provider contribution may support tools or evidence; it may not create preferred status, certification, procurement advantage, or technical legitimacy beyond the record. 2.8.10(c) No sponsor, donor, funder, provider, host, capital reader, public authority participant, or partner shall receive control over evidence selection, method design, confidence scoring, publication timing, public-safe interpretation, correction, withdrawal, retraction, reviewer choice, public claims, repository design, dashboard framing, or technical baseline status unless such involvement is lawful, role-bounded, recorded, and consistent with public-benefit purpose. Even then, involvement shall not become control. 2.8.10(d) Suppression may occur through explicit veto, informal pressure, funding threat, access withdrawal, data control, reputational pressure, legal intimidation, public authority sensitivity, sponsor discomfort, provider concern, media strategy, or internal avoidance. GCRI Canada shall maintain procedures to identify and respond to suppression risk while respecting lawful confidentiality, privacy, public authority limits, legal privilege, cybersecurity, protected knowledge, and public-safe obligations. 2.8.10(e) Inflation may occur where uncertain evidence is framed as certainty, preliminary work as operational maturity, public authority learning as endorsement, technical baseline as certification, finance input as investment advice, public-safe report as public warning, provider participation as procurement preference, sponsor support as legitimacy, or AI output as truth. GCRI Canada shall correct inflation as a matter of public-good integrity. 2.8.10(f) No public authority shall acquire control over GCRI Canada’s upstream truth merely by attending, requesting, funding, commenting, contributing data, providing facilities, participating in controlled rooms, or relying on outputs. Public authorities retain their own authority; GCRI Canada retains its upstream public-good role. 2.8.10(g) No funder, sponsor, or donor shall use restricted funding, grant deliverables, sponsorship recognition, publication review, confidentiality language, access terms, branding rights, or milestone pressure to distort evidence, suppress correction, shape public-safe meaning, or create public authority, finance, procurement, certification, protocol, or execution implication. 2.8.10(h) No provider shall use technical contribution, integration, benchmarking, tool support, cloud credits, model access, data access, or repository contribution to claim endorsement, certification, preferred status, procurement advantage, public authority approval, finance-readiness, or Nexus legitimacy unless such status is separately authorized by competent authority and records-valid. 2.8.10(i) Where upstream truth is subject to attempted purchase, ownership claim, suppression, distortion, or inflation, GCRI Canada shall apply anti-capture, anti-enclosure, public claims, conflict, legal, technical, and correction controls. Corrective action may include refusal, narrowing, ring-fencing, independent review, disclosure where appropriate, contractual correction, public-safe clarification, withdrawal, termination, or board-level review. 2.8.10(j) The integrity of upstream truth shall be protected even where doing so reduces funding, delays publication, disappoints sponsors, weakens provider marketing, complicates public authority relationships, reduces media appeal, or limits institutional visibility. Public-good truth shall remain more important than institutional advantage.

2.9 Evidence, Methods, Observability, and Ontology as Constitutional Assets

2.9.1 Evidence as a Constitutional Asset. 2.9.1(a) Evidence is a constitutional asset of GCRI Canada and shall be stewarded through provenance, custody, classification, lawful basis, permissions, source limits, confidence, uncertainty, public-safe status, review status, correction path, and retention discipline.

2.9.1(b) Evidence shall not be treated as ordinary content, marketing material, sponsor deliverable, provider proof, public authority endorsement, finance-readiness signal, procurement signal, public warning, media asset, advocacy material, or ungoverned data.

2.9.1(c) Evidence may include documents, datasets, field observations, telemetry, sensor outputs, geospatial materials, satellite and Earth observation data, cyber logs, public authority inputs, community submissions, Indigenous and local knowledge where lawfully and properly handled, provider attestations, academic research, model outputs, benchmark results, interviews, public records, controlled-room materials, clean-room outputs, incident records, supply-chain records, infrastructure records, AI-use records, and derived analyses.

2.9.1(d) Each evidence type shall be handled according to its source, sensitivity, rights implications, lawful basis, reliability, classification, intended use, public-safe status, and correction pathway. Evidence shall not be elevated, downgraded, published, restricted, summarized, mapped, scored, visualized, or routed without regard to the conditions under which it was obtained and the harms that may arise from its use.

2.9.1(e) GCRI Canada shall preserve the distinction between evidence and claim. Evidence may support a claim, weaken a claim, qualify a claim, contradict a claim, or remain insufficient for a claim. Public claims, technical claims, public authority references, finance-adjacent references, procurement-adjacent references, provider references, sponsor references, maturity language, and Nexus-compatible statements shall not exceed the evidence record.

2.9.1(f) Where evidence is incomplete, disputed, stale, uncertain, inferred, restricted, unverifiable, AI-assisted, context-limited, public-safe-limited, or unsafe for release, the output shall reflect that condition. GCRI Canada shall preserve uncertainty rather than fabricate certainty, preserve limitation rather than imply maturity, and preserve classification rather than expose restricted substrata.

2.9.1(g) Evidence stewardship shall require both protection and usability. Evidence locked away without method, metadata, custody, access pathway, review pathway, or correction logic may lose public-good value; evidence released without safeguards may cause harm. GCRI Canada shall steward evidence so that it remains usable by authorized persons while protected from misuse, exposure, overclaim, and distortion.

2.9.1(h) GCRI Canada shall balance public-benefit use with privacy, cybersecurity, sovereignty, public authority limits, protected participation, community safeguards, Indigenous and protected knowledge, lawful confidentiality, competition safety, finance sensitivity, commercial sensitivity, and correctionability.

2.9.1(i) Evidence shall not be selected, omitted, sequenced, framed, scored, summarized, mapped, or published to satisfy sponsor preference, provider preference, public authority expectation, finance narrative, procurement interest, media simplicity, institutional ambition, or public visibility.

2.9.1(j) Evidence shall remain challengeable. GCRI Canada shall maintain pathways for evidence correction, evidence challenge, evidence supplementation, evidence downgrade, evidence withdrawal, evidence reclassification, evidence restriction, and evidence supersession where material.

2.9.1(k) Evidence that cannot be traced, classified, reviewed, limited, secured, or corrected shall not carry constitutional weight within GCRI Canada except as a clearly marked, limited, unresolved, non-reliance, exploratory, or historical record.

2.9.1(l) Evidence shall not create recognition, finance-readiness, protocol effect, procurement effect, public authority action, certification, public warning, emergency instruction, provider endorsement, market ranking, or execution authority by its mere existence, rigor, public release, dashboard display, technical sophistication, or downstream relevance.

2.9.2 Methods as a Constitutional Asset. 2.9.2(a) Methods are constitutional assets because they determine how evidence becomes institutionally usable. Methods shall be versioned, documented, reviewed, challenged, secured, public-safe where released, reproduced where appropriate, superseded where necessary, and protected from sponsor, provider, public authority, political, media, procurement, or finance-driven distortion.

2.9.2(b) A method shall not be considered institutionally valid merely because it is familiar, prestigious, technically elegant, AI-assisted, widely used, sponsor-funded, provider-supplied, embedded in software, repeated in public materials, or convenient for operational purposes.

2.9.2(c) Methods shall be valid only within recorded scope, purpose, assumptions, evidence basis, input requirements, domain limits, review status, maturity status, public-safe status, known limitations, and correction path.

2.9.2(d) Methods may include validation methods, corroboration methods, calibration methods, source comparison methods, confidence logic, uncertainty treatment, dispute logic, stale-data logic, missing-data logic, spoof-risk methods, bias assessment where relevant, public-safe review methods, redaction methods, sensitivity-classification methods, observability methods, benchmarking methods, model-evaluation methods, and correction triggers.

2.9.2(e) GCRI Canada shall maintain method libraries, method notes, method profiles, method review histories, method retirement procedures, supersession records, and correction records sufficient to identify which method applies, where it applies, when it applies, why it applies, what it assumes, what it excludes, what evidence it requires, what public-safe limits apply, and how it may be challenged or corrected.

2.9.2(f) Methods shall not migrate across domains, communities, jurisdictions, datasets, technologies, public authority contexts, or public-safe settings merely by convenience. A method suitable for one risk domain, data type, community context, technical system, or jurisdiction shall not be presumed suitable for another without review.

2.9.2(g) Methods shall preserve the distinction between evidence support and downstream authority. A validation method may test a claim; it does not certify. A confidence method may express uncertainty; it does not guarantee truth. A conformance-supporting method may structure review; it does not create conformance status with external force by default.

2.9.2(h) Methods shall remain challengeable and correctable. Where new evidence, methodological critique, technical failure, public-safe concern, data-rights issue, model failure, cyber issue, protected-knowledge concern, or community challenge reveals a method’s weakness, GCRI Canada shall review, correct, restrict, supersede, or retire the method as appropriate.

2.9.2(i) Methods shall be protected against hidden authority. A method embedded in a dashboard, API, AI workflow, test harness, repository, data tool, or benchmark shall not silently create recognition, finance-readiness, procurement preference, certification, public authority action, protocol entitlement, or execution implication.

2.9.2(j) The Board, officers, and delegated technical stewards shall ensure that mission-critical methods are maintained as institutional assets and not left to undocumented practice, individual memory, sponsor preference, provider tooling, public authority expectation, or unreviewed automation.

2.9.3 Observability as a Constitutional Asset. 2.9.3(a) Observability is a constitutional asset because it structures how GCRI Canada and authorized users perceive systems, signals, risks, dependencies, infrastructure conditions, environmental changes, technology states, public authority contexts, and community conditions.

2.9.3(b) Observability shall be stewarded to support disciplined awareness, evidence quality, resilience learning, public authority literacy, community safeguards, and systems-intelligence methods. It shall not become surveillance, emergency command, public warning, operational control, procurement direction, finance signal, market intelligence for private advantage, public authority substitution, or execution authority.

2.9.3(c) Observability assets may include node methods, hub methods, cluster methods, hotspot methods, regional cluster methods, national dense core methods, observatory methods, sensor methods, telemetry methods, dashboard methods, degraded-mode awareness methods, incident awareness structures, geospatial layers, Earth observation methods, AI-RAN and O-RAN observability methods, cyber observability structures, digital twin inputs, environmental signals, infrastructure indicators, and public-safe intelligence summaries.

2.9.3(d) Observability systems shall preserve the distinction between observation, signal, inference, assessment, recommendation, recognition, public authority action, finance-readiness, procurement decision, certification, protocol effect, and execution. No observability output shall be allowed to collapse these categories by visual design, automated scoring, public-facing labels, dashboard colors, alerts, maps, rankings, or public authority references.

2.9.3(e) Observability shall be governed by source lineage, temporal context, confidence level where appropriate, data quality indicators, uncertainty, limitation notes, classification, access restrictions, public-safe status, data-rights controls, cybersecurity controls, and correction history.

2.9.3(f) GCRI Canada shall not maximize collection for its own sake. Observability shall be purpose-bound, proportionate, lawful, public-benefit aligned, privacy-preserving, and sensitive to public authority, community, Indigenous, infrastructure, cyber, and sovereign data contexts.

2.9.3(g) Public-safe observability shall be distinguished from controlled observability. Some observability outputs may be appropriate for public release, while others may require restricted rooms, controlled annexes, aggregation, redaction, delay, or non-public archival.

2.9.3(h) Observability environments shall be reviewed for direct harm, indirect harm, re-identification, geospatial exposure, infrastructure targeting, cyber exploitation, public authority confusion, market sensitivity, community vulnerability, protected knowledge exposure, and downstream misuse.

2.9.3(i) Observability systems shall not create implied public authority status merely because public authorities participate, provide data, review outputs, request analysis, or rely on summaries. Public authority participation shall remain capacity-classified and records-valid.

2.9.3(j) Where observability outputs are used by downstream actors, GCRI Canada shall preserve boundary language, limitations, review status, public-safe classification, and correction pathways sufficient to prevent overreliance or role conversion.

2.9.4 Ontology and Controlled Vocabulary as Constitutional Assets. 2.9.4(a) Ontology and controlled vocabulary are constitutional assets because they determine the meaning of GCRI Canada’s evidence, methods, technical baselines, public-safe publications, public authority materials, Nexus interfaces, dashboards, maps, repositories, APIs, metadata, and institutional claims.

2.9.4(b) GCRI Canada shall steward ontologies, taxonomies, schemas, data dictionaries, semantic mappings, equivalence notes, divergence logs, localization notes, evidence classes, maturity concepts, proof concepts, public-safe language, finance-boundary language, protocol-adjacent language, public authority capacity language, and interoperability terms as public-good constitutional infrastructure.

2.9.4(c) Controlled vocabulary shall prevent misuse of terms that carry institutional consequence. Terms such as “verified,” “validated,” “recognized,” “certified,” “mature,” “finance-ready,” “public-safe,” “approved,” “adopted,” “official,” “operational,” “decision-grade,” “proof,” “truth,” “confidence,” “standing,” “recognized,” “Nexus-compatible,” “authority,” “readiness,” and “compliance” shall be used only within recorded scope and competent authority.

2.9.4(d) GCRI Canada shall not allow public-facing language, internal labels, dashboards, maps, repository tags, metadata fields, badges, APIs, data schemas, AI-generated summaries, sponsor acknowledgments, provider references, public authority references, or Academy materials to create authority by ambiguity.

2.9.4(e) Ontology shall preserve meaning across legal, technical, public authority, community, academic, enterprise, and Nexus contexts. It shall not flatten local meaning, erase jurisdictional distinctions, override Indigenous protocols, disregard community context, or collapse public-good and enterprise-stack meanings.

2.9.4(f) Controlled vocabulary shall preserve the distinctions between evidence, method, interpretation, validation, verification, recognition, maturity, standing, finance-readiness, certification, public authority action, procurement, protocol effect, and execution.

2.9.4(g) Semantic interoperability shall be achieved through disciplined translation, not forced uniformity. Where meanings diverge across jurisdictions, communities, public authorities, technologies, or Nexus institutions, GCRI Canada shall record divergence rather than conceal it.

2.9.4(h) GCRI Canada shall maintain controlled vocabulary governance, including term definitions, usage rules, prohibited uses, conditional uses, localization notes, equivalence mappings, change records, version histories, and correction pathways.

2.9.4(i) Misuse of controlled vocabulary shall be treated as an institutional risk. Where terms are used in a manner that creates recognition implication, finance implication, public authority implication, procurement implication, certification implication, protocol implication, provider preference, sponsor overclaim, or execution implication, GCRI Canada shall correct, relabel, clarify, withdraw, or supersede the relevant material.

2.9.4(j) Ontology and controlled vocabulary shall not be enclosed by a sponsor, provider, platform, vendor, funder, or private actor. Control over language is control over meaning, and control over meaning may become control over public-good authority.

2.9.5 Technical Baselines and Reference Architectures as Constitutional Assets. 2.9.5(a) Technical baselines and reference architectures are constitutional assets because they structure how public-good evidence, observability, software, data, AI systems, repositories, dashboards, APIs, controlled rooms, secure release systems, and Nexus-compatible interfaces may be designed, interpreted, reviewed, and corrected.

2.9.5(b) Technical baselines may define public-good expectations, evidence requirements, interoperability structures, security practices, privacy controls, documentation requirements, data-handling profiles, AI-governance expectations, public-safe release requirements, and correction pathways.

2.9.5(c) Reference architectures may describe how systems, repositories, observability surfaces, data pipelines, AI workflows, secure rooms, controlled rooms, clean rooms, dashboards, APIs, public-good software, or evidence rails should be organized.

2.9.5(d) Technical baselines and reference architectures shall not by themselves certify compliance, approve technology, recognize maturity, grant procurement preference, create protocol entitlement, establish finance-readiness, imply public authority adoption, or guarantee technical performance.

2.9.5(e) Each mission-critical technical baseline or reference architecture shall include, where material, scope, purpose, status, assumptions, limitations, dependency records, implementation notes, public-safe status, intended users, prohibited interpretations, version history, and correction pathway.

2.9.5(f) GCRI Canada shall maintain technical baselines and reference architectures to support common understanding, evidence quality, public-safe implementation, interoperability, public authority learning, technical literacy, and lawful downstream review by competent actors.

2.9.5(g) Technical baselines shall remain vendor-neutral and sponsor-neutral. They shall not be shaped to privilege a provider, create a procurement funnel, embed hidden commercial advantage, or convert a public-good asset into market leverage.

2.9.5(h) Reference architectures shall preserve separation between public-good stewardship and enterprise execution. They may describe patterns useful to execution actors, but they shall not make GCRI Canada the operator, deployer, procurement actor, project governor, infrastructure owner, or execution authority.

2.9.5(i) Where technical baselines or reference architectures are used by GRF, GRA, protocol authority, public authorities, National Consortium Companies, Project SPVs, providers, sponsors, or other actors, GCRI Canada’s role shall remain upstream unless a separate lawful instrument provides otherwise.

2.9.5(j) Technical baselines and reference architectures shall be versioned, reviewable, public-safe where released, and correctionable. Stale, insecure, superseded, misleading, or overclaimed baselines shall be corrected, restricted, superseded, deprecated, withdrawn, or archived.

2.9.6 Public-Good Software and Open Technical Tools as Constitutional Assets. 2.9.6(a) Public-good software and open technical tools are constitutional assets where they operationalize evidence integrity, observability, semantic interoperability, public-safe publication, technical baselines, verifiable compute, verifiable intelligence, correctionability, or public authority learning.

2.9.6(b) Public-good software may include APIs, dashboards, data tools, scripts, libraries, reference implementations, test harnesses, evaluation harnesses, templates, schemas, repository assets, workflow tools, public-safe publication tools, AI-governance tools, and secure release utilities.

2.9.6(c) Public-good software shall be governed through secure development, repository discipline, contribution review, dependency management, vulnerability handling, licensing clarity, release controls, access controls, public-safe documentation, versioning, deprecation, and correction.

2.9.6(d) GCRI Canada shall not release software as public-good infrastructure where it cannot reasonably maintain, secure, correct, explain, classify, or retire the asset in relation to its intended use and expected reliance.

2.9.6(e) Open technical tools shall be open where lawful, safe, mission-compatible, and public-benefit enhancing. Openness shall not justify exposure of personal data, rights-bearing data, protected knowledge, cyber vulnerabilities, sensitive infrastructure information, public authority restricted materials, sovereign data, trade secrets, finance-sensitive information, or unsafe implementation details.

2.9.6(f) Public-good software shall not become a vendor product, provider implementation, sponsor-controlled asset, procurement gate, certification mechanism, finance-readiness engine, protocol entitlement, market infrastructure, or execution system by default.

2.9.6(g) Technical tools shall carry boundary language sufficient to prevent false reliance. A dashboard shall not imply public warning. A test harness shall not imply certification. An API shall not imply protocol effect. A data tool shall not imply finance-readiness. A reference implementation shall not imply vendor preference.

2.9.6(h) GCRI Canada shall preserve contribution provenance, licensing records, dependency records, release histories, changelogs, vulnerability records, and correction records for mission-critical public-good software.

2.9.6(i) Public-good software and open technical tools shall be protected against enclosure, hidden telemetry, unmanaged AI dependencies, proprietary lock-in, sponsor capture, provider control, single-maintainer fragility, license traps, and unreviewed external dependencies.

2.9.6(j) Where public-good software becomes insecure, stale, unsupported, misleading, captured, or uncorrectable, GCRI Canada shall patch, restrict, deprecate, supersede, withdraw, archive, or terminate the asset as appropriate.

2.9.7 Model Registers, Dataset Cards, System Cards, Benchmark Cards, and Inference Records as Constitutional Assets. 2.9.7(a) Model registers, dataset cards, system cards, benchmark cards, inference records, evaluation records, AI-use records, compute workload records, and verifiable intelligence records are constitutional assets where they preserve the conditions under which AI-assisted, model-assisted, simulation-assisted, benchmark-assisted, compute-assisted, and intelligence-assisted outputs may be reviewed and corrected.

2.9.7(b) Model registers shall identify relevant models, versions where available, intended uses, prohibited uses, limitations, evaluation status, training or input data restrictions where known and relevant, access controls, security considerations, privacy considerations, public-safe status, and correction pathways.

2.9.7(c) Dataset cards shall identify dataset origin, lawful basis, permissions, sensitivity, classification, scope, limitations, bias considerations where relevant, update status, retention posture, public-safe constraints, and correction paths.

2.9.7(d) System cards shall describe system context, dependencies, controls, intended use, prohibited use, known risks, security posture, privacy posture, data posture, public authority relevance, public-safe status, and correction pathways.

2.9.7(e) Benchmark cards shall identify test design, evidence base, data sources, assumptions, limitations, context relevance, scoring logic, known weaknesses, public-safe status, and prohibited interpretations. Benchmark outputs shall not become provider marketing claims, procurement signals, finance signals, certification, public authority endorsements, or market rankings beyond their recorded scope.

2.9.7(f) Inference records shall be maintained where AI or model outputs materially contribute to evidence, publication, observability, public authority learning, technical baselines, public-safe reporting, or Nexus interface records. Such records shall preserve enough information to allow authorized review without exposing protected materials.

2.9.7(g) AI-assisted work shall not become unverifiable institutional assertion. GCRI Canada shall preserve task class, model identity where appropriate, retrieval sources, evaluation status, human reviewer where material, data classification, limitations, public-safe status, and correction status where needed for review.

2.9.7(h) Model, dataset, system, benchmark, and inference records shall prevent AI-generated authority, false precision, hidden bias, unreviewed automation, model-provider capture, cross-border transfer risk, prompt-injection risk, hallucination risk, and public claim overreach.

2.9.7(i) GCRI Canada shall not use or release model outputs, benchmark results, dataset summaries, system cards, or AI-generated analyses in a manner that implies truth, recognition, certification, finance-readiness, public authority action, procurement approval, protocol entitlement, or execution authority without competent authority and proper records.

2.9.7(j) Where models, datasets, systems, benchmarks, or inference records are corrected, superseded, withdrawn, downgraded, or restricted, GCRI Canada shall preserve version histories, correction notices, downstream notice decisions where required, and affected-output linkages.

2.9.8 Records, Repositories, Gazette Entries, Correction Chains, and Version Histories as Constitutional Assets. 2.9.8(a) Records, repositories, Gazette entries, correction chains, supersession records, withdrawal records, retraction records, downgrade records, reinstatement records, archive records, version histories, changelogs, release notes, authority records, and final closeout records are constitutional assets of GCRI Canada.

2.9.8(b) Institutional meaning shall arise through records and not informal status, reputation, proximity, meeting attendance, public authority presence, sponsor support, provider contribution, technical centrality, media repetition, verbal assurance, chat exchange, slide deck, dashboard appearance, or unapproved summary.

2.9.8(c) Records shall identify, where material, the act, authority, date, scope, status, classification, evidence basis, method basis, limitations, public-safe status, responsible function, affected assets, and correction path.

2.9.8(d) Repositories shall be governed as institutional control surfaces. Repository access, contribution, merge, release, publication, tagging, package distribution, and archival authority shall be role-based, recorded, reviewable, secure, and distinct from ordinary technical access.

2.9.8(e) Gazette entries or equivalent official publication records shall identify operative institutional acts, public-safe releases, corrections, supersessions, withdrawals, notices, adoption events, amendments, and status changes where such publication is required by policy, governance, reliance risk, or public-benefit discipline.

2.9.8(f) Correction chains shall preserve the history of error identification, review, decision, correction, public-safe notice, downstream notice, supersession, withdrawal, retraction, downgrade, reinstatement, or archival.

2.9.8(g) Version histories shall prevent silent edit, hidden correction, untraceable release, public confusion, and reliance on obsolete materials. Material edits shall be recorded and noticed publicly or controlledly where reliance risk exists.

2.9.8(h) GCRI Canada shall not rely on private inboxes, personal accounts, individual memory, undocumented folders, chat history, platform defaults, or uncontrolled repositories as the authoritative record for material institutional acts.

2.9.8(i) Records may be public, controlled, confidential, restricted, or sealed according to law, safety, privacy, cybersecurity, public authority limits, protected knowledge, community safeguards, commercial sensitivity, finance sensitivity, and public-safe publication rules. Restricted status shall not mean absence of record.

2.9.8(j) Records, repositories, Gazette entries, correction chains, and version histories shall be protected against tampering, loss, unauthorized access, hidden edits, improper deletion, uncontrolled export, repository capture, platform dependency, and sponsor or provider influence.

2.9.8(k) Where authoritative records are missing, defective, conflicting, corrupted, or unclear, GCRI Canada shall correct the record deficiency rather than rely on informal validity.

2.9.9 Privacy, Data Rights, Sovereign Data, Cybersecurity, and Secure Release Controls as Constitutional Safeguards. 2.9.9(a) Privacy, data rights, sovereign data, cybersecurity, secure collaboration, secure development, controlled-room operations, clean-room operations, cross-border review, AI-use controls, identity and access management, and secure release controls are constitutional safeguards of GCRI Canada.

2.9.9(b) These safeguards protect the integrity, confidentiality, availability, legality, legitimacy, and public trust of GCRI Canada’s evidence, methods, observability, ontology, technical baselines, public-good software, public-safe publications, public authority materials, protected knowledge, and correction systems.

2.9.9(c) Privacy safeguards shall include lawful basis, minimization, purpose limitation, access restriction, retention discipline, correction where applicable, deletion or restriction where appropriate, protection against re-identification, profiling, coercive visibility, overlinkage, contextual misuse, and unsafe secondary use.

2.9.9(d) Data rights safeguards shall apply to collection, ingestion, storage, analysis, AI use, publication, sharing, retention, disposal, correction, and cross-border transfer. Data shall not be reused for AI training, sponsor reporting, provider testing, public authority sharing, public dashboards, capital-reader materials, or unrelated research without lawful and mission-compatible authority.

2.9.9(e) Sovereign data safeguards shall include localization, sovereign data zones, compute-to-data, jurisdictional tagging, cross-border transfer review, conflict-of-law review, public authority data controls, Indigenous data considerations, community data safeguards, sanctions awareness, export-control awareness, and public-safe translation.

2.9.9(f) Cybersecurity safeguards shall protect repositories, software, APIs, datasets, dashboards, model records, inference records, public authority materials, credentials, keys, secrets, release systems, logs, backups, controlled rooms, and public-good technical assets.

2.9.9(g) Secure release controls shall require review of code, content, data, metadata, embedded materials, credentials, logs, examples, dependencies, geospatial signals, public authority references, sponsor references, provider references, model outputs, and public-safe meaning before release.

2.9.9(h) No personal information, rights-bearing data, protected knowledge, cyber-sensitive material, sensitive infrastructure information, public authority restricted material, sovereign-sensitive data, commercial secret, finance-sensitive material, or re-identifiable data shall be released publicly unless expressly lawful, public-safe, authorized, and consistent with this Charter.

2.9.9(i) Secure collaboration shall require that tools used for document creation, code development, data analysis, AI processing, public authority engagement, controlled rooms, and external collaboration be appropriate to classification and risk. Consumer convenience shall not justify unsafe channels for sensitive or mission-critical work.

2.9.9(j) A failure of privacy, data rights, sovereign data handling, cybersecurity, or secure release shall be treated not merely as a technical incident but as a potential constitutional safeguard failure requiring containment, assessment, correction, notice where required, and institutional learning.

2.9.10 No Alienation, Enclosure, Pledge, Exclusive Control, or Hidden Dependency Over Mission-Critical Constitutional Assets Without Heightened Review and Public-Benefit Justification. 2.9.10(a) Mission-critical constitutional assets of GCRI Canada shall not be alienated, enclosed, pledged, exclusively controlled, commercially captured, sponsor-controlled, provider-controlled, vendor-locked, privately appropriated, or made dependent on hidden control surfaces without heightened review and public-benefit justification.

2.9.10(b) Mission-critical constitutional assets include evidence systems, method libraries, observability environments, ontologies, controlled vocabularies, taxonomies, schemas, data dictionaries, technical baselines, reference architectures, public-good software, APIs, dashboards, model registers, dataset cards, system cards, benchmark cards, inference records, repositories, Gazette entries, correction chains, version histories, secure release systems, and public-safe publication systems.

2.9.10(c) Alienation includes sale, assignment, exclusive license, restrictive transfer, pledge, encumbrance, outsourcing, repository transfer, data transfer, IP transfer, platform migration, dependency conversion, or contractual arrangement that materially impairs GCRI Canada’s ability to steward, maintain, correct, secure, publish where public-safe, restrict where required, or preserve public-good meaning.

2.9.10(d) Enclosure may occur through ownership transfer, exclusive licensing, restrictive contracts, proprietary dependencies, technical lock-in, sponsor branding, vendor control, data concentration, closed formats, paywalls, platform dependence, hidden APIs, restrictive patents, undocumented workflows, model-provider dependency, cloud lock-in, identity-layer control, or practical inability to use or maintain the asset without a private actor.

2.9.10(e) Exclusive control over mission-critical constitutional assets shall be prohibited except for narrow, lawful, time-bound where appropriate, safety-justified, public-benefit-justified, board-approved exceptions with conflict review, exit rights, continuity planning, correction rights, licensing clarity, and public-safe documentation where appropriate.

2.9.10(f) GCRI Canada shall not pledge mission-critical constitutional assets as collateral, commercial leverage, sponsor security, transaction support, investment inducement, debt support, or private benefit where such pledge would impair public-benefit stewardship, non-distribution, mission lock, correctionability, public-good availability, or institutional independence.

2.9.10(g) Hidden dependency shall be treated as a constitutional risk. Systems that allow unreviewed changes, invisible data flows, undisclosed telemetry, non-transparent model behavior, privileged vendor access, unmanaged administrative rights, undocumented automation, unrecorded external dependencies, or practical control by a sponsor or provider shall not be used for mission-critical constitutional assets without review, controls, and documented justification.

2.9.10(h) Heightened review shall consider public-benefit purpose, legal authority, asset criticality, ownership, licensing, access control, dependency, portability, cybersecurity, privacy, sovereign data, protected knowledge, public authority restrictions, correctionability, interoperability, anti-capture, anti-enclosure, sponsor influence, provider preference, vendor lock-in, public claims, downstream reliance, and exit readiness.

2.9.10(i) Any approved exception shall identify the affected asset, scope, duration, rationale, public-benefit basis, restrictions, safeguards, affected parties, public-safe status, review date, termination rights, post-exclusivity treatment, and correction pathway.

2.9.10(j) Indefinite exclusivity, hidden veto rights, broad field-of-use restrictions, public-good dependency without exit, sponsor approval rights over correction, provider control over public meaning, or vendor control over canonical semantics shall be prohibited.

2.9.10(k) Where alienation, enclosure, pledge, exclusive control, or hidden dependency is identified after the fact, GCRI Canada shall assess the risk, preserve records, mitigate harm, renegotiate terms, migrate systems, restrict use, correct claims, terminate the arrangement, recover assets where possible, or issue public-safe clarification where reliance risk exists.

2.9.10(l) The Board shall retain ultimate oversight over mission-critical constitutional assets and shall ensure that GCRI Canada’s public-good evidence infrastructure, methods, observability, ontology, technical baselines, public-good software, records, and correction systems remain protected for public benefit across time.

2.10 Values of GCRI Canada

2.10.1 Integrity. 2.10.1(a) GCRI Canada shall act with institutional integrity, truthfulness, consistency, independence, reliability, and fidelity to its public-benefit mission.

2.10.1(b) Integrity requires that private expectations, sponsor narratives, provider claims, political pressure, public authority ambiguity, public visibility, financial opportunity, institutional urgency, media attention, technical enthusiasm, ecosystem expectation, or strategic convenience do not alter evidence, methods, records, public-safe meaning, correction duties, role boundaries, or constitutional identity.

2.10.1(c) Integrity shall require GCRI Canada to say what it knows, what it does not know, what remains uncertain, what is contested, what is stale, what is restricted, what is public-safe, what has been corrected, what has been superseded, what has been withdrawn, and what lies outside its authority.

2.10.1(d) GCRI Canada shall not inflate confidence, compress uncertainty, omit limitations, obscure source weakness, overstate maturity, imply public authority approval, imply finance-readiness, imply procurement preference, imply certification, imply protocol effect, imply provider endorsement, or imply execution authority in order to attract support, satisfy partners, influence public perception, accelerate adoption, simplify communication, or increase visibility.

2.10.1(e) Institutional integrity shall require consistency between internal governance and external representation. GCRI Canada shall not maintain careful internal boundaries while allowing public-facing materials, sponsor statements, provider references, public authority references, media narratives, event materials, dashboards, maps, repositories, or partner communications to imply broader authority.

2.10.1(f) Integrity requires alignment among records, public claims, technical systems, legal instruments, public-safe publications, funding arrangements, sponsorship language, provider interfaces, data practices, AI workflows, and institutional conduct.

2.10.1(g) Where integrity requires correction, withdrawal, downgrade, limitation disclosure, public-safe clarification, restriction, supersession, or retraction, GCRI Canada shall act even where correction is inconvenient, reputationally uncomfortable, technically difficult, financially unattractive, or contrary to sponsor, provider, public authority, media, capital-reader, or internal expectations.

2.10.1(h) Integrity shall be measured by GCRI Canada’s willingness to preserve truth under pressure, not by the ease of its public narrative, scale of its partnerships, sponsor value, public authority proximity, technical sophistication, or visibility.

2.10.1(i) No director, officer, staff member, council member, fellow, advisor, member where applicable, contractor, contributor, sponsor, provider, host, public authority participant, or partner shall use association with GCRI Canada to create public meaning inconsistent with institutional integrity.

2.10.1(j) Integrity shall survive urgency, crisis, uncertainty, public pressure, funding need, and ecosystem growth. GCRI Canada shall not become less truthful because circumstances become more important.

2.10.2 Scientific and Methodological Discipline. 2.10.2(a) GCRI Canada shall maintain scientific, technical, and methodological discipline while remaining challengeable, humble, context-aware, public-safe, and correctionable.

2.10.2(b) Scientific discipline shall be paired with institutional discipline: method, source, limitation, review, confidence, uncertainty, classification, public-safe status, and correction must be visible enough to sustain trust by authorized reviewers and understandable enough to support lawful downstream use by competent actors.

2.10.2(c) Scientific and methodological discipline shall require that conclusions be proportionate to evidence, methods be appropriate to purpose, assumptions be documented, limitations be disclosed, uncertainty be preserved, and dissent or conflicting evidence be handled through records rather than suppressed by narrative.

2.10.2(d) GCRI Canada shall not use prestige, institutional confidence, public urgency, sponsor funding, provider contribution, public authority attention, media visibility, AI-generated fluency, technical complexity, or repeated use as a substitute for method.

2.10.2(e) Methods shall be selected and applied because they are fit for purpose, reviewable, records-valid, proportionate, context-sensitive, privacy-preserving, public-safe where released, and capable of correction.

2.10.2(f) GCRI Canada shall reject or restrict methods that are opaque, sponsor-shaped, vendor-dependent without transparency, unsuitable for context, unsafe for rights-bearing data, unsafe for protected knowledge, incapable of correction, likely to create false precision, or likely to create authority beyond the record.

2.10.2(g) Where methods are experimental, exploratory, provisional, AI-assisted, model-dependent, dataset-limited, jurisdiction-limited, community-limited, or context-limited, that status shall be recorded and communicated where material.

2.10.2(h) GCRI Canada shall preserve methodological challenge. Challenge, replication, peer review, community correction, public authority clarification, technical dispute, data correction, and evidence correction shall be understood as features of institutional seriousness.

2.10.2(i) Methodological confidence shall not become institutional infallibility. A strong method may still have limits; a public-safe output may still require correction; a confidence score may still be misunderstood; and a benchmark may still be context-limited.

2.10.2(j) GCRI Canada shall ensure that scientific and methodological discipline applies equally to publications, dashboards, maps, datasets, software releases, technical baselines, AI workflows, public authority materials, Academy materials, sponsor-supported work, provider-supported work, and Nexus interface records.

2.10.3 Public-Benefit Orientation. 2.10.3(a) GCRI Canada shall orient all activities toward public benefit rather than private advantage, sponsor influence, provider preference, political convenience, market positioning, institutional visibility, reputational accumulation, public authority proximity, finance narrative, media appeal, or ecosystem dominance.

2.10.3(b) Public benefit shall be a constraint, not a slogan. It shall determine what GCRI Canada builds, publishes, withholds, corrects, funds, accepts, declines, restricts, terminates, and permits others to say about its work.

2.10.3(c) Public-benefit orientation shall require that programs, partnerships, public authority interfaces, technical baselines, public-good software, data practices, AI workflows, events, publications, Academy materials, repositories, dashboards, maps, and Nexus interfaces be designed to advance durable public-good capacity.

2.10.3(d) GCRI Canada shall avoid activities that provide only reputational value, sponsor value, provider value, market visibility, public authority optics, media value, or symbolic legitimacy without genuine public-benefit substance.

2.10.3(e) Public benefit shall not require uncontrolled openness, universal release, or maximum visibility. In some circumstances, public benefit requires confidentiality, redaction, aggregation, delay, controlled-room handling, protection of communities, restricted access, secure publication, or non-public correction.

2.10.3(f) GCRI Canada shall distinguish public-benefit stewardship from performative transparency. Public release shall be governed by public-safe discipline, not by public relations value.

2.10.3(g) GCRI Canada shall distinguish public benefit from institutional growth. Growth may support public benefit where it strengthens evidence capacity, technical continuity, safeguards, public authority learning, public-good software, and correctionability; it shall be resisted where it creates capture, drift, overclaim, dependency, public authority confusion, finance overclaim, or inability to maintain quality.

2.10.3(h) Public-benefit orientation shall require attention to persons, communities, institutions, infrastructure, ecosystems, public authorities, and future users who may be affected by evidence, data, maps, dashboards, AI outputs, technical baselines, or public claims.

2.10.3(i) GCRI Canada shall not subordinate public benefit to the interests of directors, officers, members where applicable, sponsors, donors, funders, providers, hosts, partners, capital readers, public authorities, media actors, or founders.

2.10.3(j) Public-benefit orientation shall be evidenced through records, not merely stated in mission language.

2.10.4 Evidence Before Assertion. 2.10.4(a) Evidence shall precede assertion. Public claims, technical claims, impact claims, public authority claims, sponsor claims, provider claims, finance-readiness references, Nexus-compatible statements, maturity statements, public-safe statements, operational-status statements, and public-benefit claims shall not exceed records.

2.10.4(b) GCRI Canada shall not permit assertion to create the appearance of evidence where the record is incomplete, disputed, preliminary, stale, restricted, inferred, AI-assisted without review, or absent.

2.10.4(c) Evidence-before-assertion shall apply to internal governance as well as external communication. A board paper, program proposal, funding submission, technical release, public authority briefing, sponsor deck, Academy material, dashboard, map, public report, website, media statement, or social media post shall not treat aspirational plans, intended partnerships, informal conversations, anticipated funding, proposed systems, or future capabilities as current facts.

2.10.4(d) Where evidence is incomplete but a public-benefit reason exists to communicate, GCRI Canada shall use appropriate stage labels, uncertainty language, limitation disclosure, public-safe status, and correction pathways.

2.10.4(e) GCRI Canada may describe planned, pilot, exploratory, draft, proposed, controlled, limited, under-development, or prototype work, but it shall not describe such work as adopted, operational, supported, mature, recognized, finance-ready, certified, official, public-authority-approved, protocol-effective, or execution-ready unless the record supports that status.

2.10.4(f) Evidence-before-assertion shall constrain AI-assisted communication. AI-generated summaries, translations, drafts, or analyses shall not be treated as evidence. They may assist drafting or analysis, but the source record, method record, human review, public-safe status, and correction record shall determine what may be asserted.

2.10.4(g) Evidence-before-assertion shall also constrain visual and technical outputs. A dashboard, map, badge, score, API response, repository label, model output, confidence value, benchmark result, or proof receipt shall not assert more than the underlying evidence supports.

2.10.4(h) Where a claim has been made before adequate evidence exists, GCRI Canada shall correct, qualify, withdraw, reclassify, or supersede the claim.

2.10.4(i) GCRI Canada shall prefer a narrower truthful claim over a broader claim that creates false authority, unsafe reliance, sponsor value, provider advantage, public authority implication, or finance overclaim.

2.10.4(j) No person acting in relation to GCRI Canada shall use repetition, confidence, branding, design, public authority attendance, sponsor visibility, or media amplification to convert assertion into evidence.

2.10.5 Record Before Effect. 2.10.5(a) Institutional meaning shall arise through records, not informal status, reputation, proximity, meeting attendance, sponsor support, public authority presence, provider contribution, technical centrality, social media repetition, public narrative, verbal assurance, chat exchange, draft slide, dashboard appearance, repository label, AI-generated summary, or unapproved text.

2.10.5(b) Record before effect means that public meaning, authority, access, publication, technical release, correction, sponsorship status, public authority capacity, provider role, data access, AI-use authorization, Nexus interface consequence, and institutional status require proper records.

2.10.5(c) No person shall rely on memory, custom, urgency, seniority, founder preference, donor importance, public authority interest, provider readiness, technical convenience, or ecosystem expectation to create institutional effect outside records.

2.10.5(d) Where a material act is not recorded, GCRI Canada shall treat it as lacking public meaning until properly documented, reviewed, approved, classified, and given status under authority.

2.10.5(e) Records shall be structured enough to support accountability. They shall identify the act, authority, date, scope, status, classification, evidence basis, method basis, limitations, public-safe status, responsible function, and correction path where material.

2.10.5(f) Informal communications may support deliberation, but they shall not replace records for material institutional effect. Email, chat, slides, verbal discussions, collaborative comments, and social media shall not become governance unless converted into proper records under authority.

2.10.5(g) Record-before-effect shall protect GCRI Canada against drift, capture, misquotation, public overclaim, disputed authority, sponsor misuse, provider misuse, public authority ambiguity, finance overclaim, and downstream misuse.

2.10.5(h) Record-before-effect shall protect participants and downstream actors by making clear what GCRI Canada has actually done, what it has not done, and what may be relied upon only within bounded terms.

2.10.5(i) Where public meaning appears to have arisen without records, GCRI Canada shall correct the record, clarify status, restrict reliance, withdraw the claim, or formally adopt a lawful and Charter-consistent record if appropriate.

2.10.5(j) No record shall be created merely to rationalize an overclaim after the fact. Records shall truthfully reflect authority, evidence, limits, review, and timing.

2.10.6 Correctionability and Reviewability. 2.10.6(a) Outputs shall be reviewable and correctionable as a condition of trust.

2.10.6(b) GCRI Canada shall treat correction as institutional maturity, not embarrassment. Evidence, methods, publications, dashboards, maps, software releases, technical baselines, public authority materials, Academy materials, model registers, dataset cards, system cards, benchmark cards, public-safe summaries, sponsor references, provider references, and Nexus interface records shall be capable of review, challenge, correction, supersession, withdrawal, restriction, downgrade, reinstatement, archival, or retirement where appropriate.

2.10.6(c) Reviewability shall require that material outputs preserve enough source, method, authority, classification, version, limitation, public-safe status, and correction information to allow meaningful assessment.

2.10.6(d) GCRI Canada shall not publish, release, or rely upon outputs whose basis cannot be reconstructed by authorized reviewers. Where full source disclosure is unsafe or unlawful, reviewability shall be preserved through controlled access, redacted records, restricted annexes, independent review, or public-safe explanations.

2.10.6(e) Correctionability shall include procedures for intake of corrections, triage, review, authority assignment, records update, public-safe notice, downstream notification where required, supersession, withdrawal, retraction, downgrade, reinstatement, archive, and closeout.

2.10.6(f) Corrections shall distinguish clerical correction, formatting correction, metadata correction, translation correction, substantive correction, limitation clarification, public-safe clarification, status correction, supersession, withdrawal, retraction, downgrade, reinstatement, restriction, and archival.

2.10.6(g) GCRI Canada shall not treat correction as optional merely because an output is popular, sponsor-supported, provider-supported, widely cited, publicly visible, technically complex, or difficult to amend.

2.10.6(h) The more relied upon an output becomes, the stronger the duty to maintain reviewability and correctionability.

2.10.6(i) Correctionability shall apply to systems as well as documents. Dashboards, APIs, models, datasets, repositories, maps, release packages, metadata fields, and AI workflows shall be designed so that errors can be corrected, status can be displayed, and supersession can be traced.

2.10.6(j) Where correction is impracticable for a material output, GCRI Canada shall not release or rely on that output as public-good infrastructure unless the limitation is recorded, justified, public-safe, and subject to risk controls.

2.10.6(k) GCRI Canada shall maintain correction records sufficient to preserve institutional memory and prevent repeated reliance on obsolete, unsafe, withdrawn, or superseded materials.

2.10.7 Transparency With Lawful Protection. 2.10.7(a) GCRI Canada shall favor transparency while protecting confidential, personal, public authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, community-protected, culturally sensitive, Indigenous, local, territorial, and protected knowledge materials.

2.10.7(b) Transparency shall be disciplined by law, safety, rights, public-benefit purpose, classification, public-safe review, and correctionability.

2.10.7(c) Transparency shall require that GCRI Canada explain its role, scope, authority, limitations, methods, public-safe status, correction pathways, and boundary conditions where public meaning exists.

2.10.7(d) Transparency shall not require disclosure of protected sources, personal information, controlled-room substrata, security details, privileged materials, sensitive infrastructure data, protected knowledge, public authority restricted information, confidential commercial information, finance-sensitive information, or information that would create avoidable harm.

2.10.7(e) Lawful protection shall not become secrecy for convenience, reputational protection, sponsor shielding, provider preference, public authority appeasement, finance narrative protection, or avoidance of accountability.

2.10.7(f) Where information is withheld or redacted for valid reasons, GCRI Canada shall, where appropriate, preserve an internal or controlled record of the basis, scope, authority, classification, and review status of the withholding or redaction.

2.10.7(g) Transparency and protection shall operate together. GCRI Canada shall be open enough to sustain public trust and controlled enough to prevent harm. Neither uncontrolled disclosure nor unjustified opacity shall satisfy the public-benefit mandate.

2.10.7(h) Public-safe summaries, controlled annexes, redacted reports, classification notes, and restricted records may be used to preserve accountability while protecting sensitive substrata.

2.10.7(i) GCRI Canada shall not use broad confidentiality labels, sponsor review rights, provider concerns, public authority sensitivity, or internal discomfort to suppress correction, obscure limitations, or hide overclaim.

2.10.7(j) Where transparency itself creates public authority confusion, finance overclaim, procurement implication, cyber risk, community harm, or protected knowledge exposure, GCRI Canada shall use bounded, public-safe, records-valid transparency rather than unrestricted disclosure.

2.10.8 Privacy, Dignity, Contextual Integrity, and Rights-Bearing Data Protection. 2.10.8(a) GCRI Canada shall protect privacy, dignity, contextual integrity, and rights-bearing data.

2.10.8(b) Data shall not be treated as free raw material merely because it is accessible, technically processable, public, donated, scraped, inferred, generated, purchased, aggregated, visualized, or useful.

2.10.8(c) Privacy shall include protection against unnecessary collection, unjustified access, overlinkage, re-identification, profiling, coercive visibility, contextual misuse, function creep, unsafe secondary use, uncontrolled metadata exposure, and excessive retention.

2.10.8(d) Dignity shall require that people and communities are not reduced to data points, risk categories, dashboards, maps, AI training material, public narratives, investment signals, public authority targets, or sponsor-facing legitimacy assets without context and safeguards.

2.10.8(e) GCRI Canada shall handle personal, community, geospatial, health, public authority, participation, employment, infrastructure-adjacent, and protected knowledge data with care proportionate to potential harm.

2.10.8(f) Contextual integrity shall require that data be used consistently with the circumstances under which it was collected, shared, inferred, observed, or entrusted. Data collected for one public-benefit purpose shall not automatically become available for research, AI training, publication, sponsor reporting, provider testing, public authority sharing, finance-facing use, or dashboard display.

2.10.8(g) Purpose expansion shall require review. Reuse shall be lawful, mission-compatible, classification-aware, public-safe, and records-valid.

2.10.8(h) Rights-bearing data protection shall include lawful basis, minimization, classification, access control, retention discipline, correction where applicable, deletion or restriction where appropriate, cross-border review, AI-use controls, and public-safe publication review.

2.10.8(i) GCRI Canada shall preserve the rights and expectations of affected persons and communities as constitutional safeguards.

2.10.8(j) Aggregated data, geospatial layers, community indicators, infrastructure data, model outputs, inferred attributes, public authority datasets, and linked records may create rights-bearing risk through re-identification, profiling, targeting, stigma, exposure, or contextual misuse. Such risk shall be assessed by effect, not only by formal data category.

2.10.8(k) Where privacy, dignity, contextual integrity, or rights-bearing data protection conflicts with openness, analytical usefulness, sponsor interest, provider interest, public authority interest, media interest, or technical convenience, GCRI Canada shall adopt the more protective lawful approach pending proper review.

2.10.9 Sovereignty Respect and Localization Without Fragmentation. 2.10.9(a) GCRI Canada shall respect sovereignty and localization while avoiding fragmentation through controlled vocabulary, equivalence notes, divergence logs, interoperable records, public-safe summaries, jurisdiction-aware methods, localization notes, and context-preserving translation.

2.10.9(b) Sovereignty respect shall apply to Canadian federal, provincial, territorial, Indigenous, local, cross-border, and international contexts.

2.10.9(c) Localization shall not mean constitutional drift. GCRI Canada may adapt procedures, publication language, public authority interfaces, data handling, safeguards, technical profiles, learning materials, or observability methods to local law and context, but such adaptation shall not undermine mission lock, non-execution, role separation, public-good stewardship, validity-by-record, correctionability, provider neutrality, sponsor non-control, or public-safe publication.

2.10.9(d) Sovereignty respect shall include data localization, sovereign data zones, compute-to-data, public authority capacity classification, Indigenous protocols, community safeguards, conflict-of-law review, sanctions awareness, export-control awareness, cross-border transfer review, and respect for lawful restrictions on disclosure or transfer.

2.10.9(e) GCRI Canada shall not treat global interoperability as a reason to override local obligations, local truth, public authority structures, Indigenous knowledge protocols, community context, privacy rules, or lawful restrictions.

2.10.9(f) Localization without fragmentation shall require records that explain where local variants exist, why they exist, how they differ, what legal or public-safe basis supports them, and how they remain compatible with common public-good meaning.

2.10.9(g) Divergence shall be recorded rather than hidden. Interoperability shall be maintained through disciplined translation, not forced uniformity.

2.10.9(h) GCRI Canada shall preserve local truth while supporting global comparability. Evidence arising from a particular jurisdiction, community, territory, public authority system, infrastructure system, or cultural context shall not be flattened into generic categories that distort meaning.

2.10.9(i) Where local law, sovereign data obligations, public authority restrictions, Indigenous protocols, protected knowledge, or community safeguards require a narrower approach, GCRI Canada shall apply that narrower approach unless competent authority and lawful review support otherwise.

2.10.9(j) International alignment, Nexus compatibility, shared ontology, or common technical baselines shall not create legal fusion, shared liability, supranational status, or public authority delegation.

2.10.10 Support Without Control. 2.10.10(a) Sponsors, donors, funders, providers, hosts, universities, public authorities, communities, technical contributors, and partners may support GCRI Canada’s mission, but they shall not control evidence, methods, publications, technical baselines, public authority access, public claims, correction, repository design, public-safe language, or institutional meaning.

2.10.10(b) Support shall be welcomed only where it remains subordinate to mission, law, public-benefit purpose, independence, safeguards, role boundaries, provider neutrality, sponsor non-control, public authority clarity, finance boundaries, and correctionability.

2.10.10(c) Support without control shall apply to money, in-kind contributions, cloud credits, data access, tools, facilities, expertise, hosting, public authority participation, media access, technical integrations, AI model access, software licenses, personnel contributions, and infrastructure support.

2.10.10(d) No form of support shall purchase priority treatment, preferred-provider status, public authority access, publication veto, method control, evidence selection, finance-readiness implication, procurement advantage, certification implication, recognition implication, protocol entitlement, or correction suppression.

2.10.10(e) GCRI Canada may acknowledge support in accurate, public-safe, role-bounded terms. Acknowledgment shall not imply endorsement, control, ownership, certification, recognition, adoption, public authority approval, finance-readiness, procurement preference, technical superiority, or Nexus legitimacy.

2.10.10(f) Sponsor and provider references shall be reviewed for claims discipline. Logos, quotes, case studies, photographs, event language, dashboard labels, repository references, and public authority proximity shall not create false public meaning.

2.10.10(g) Where support creates dependency, concentration risk, conflict risk, public perception risk, technical control risk, public authority confusion, finance overclaim, provider advantage, or public-safe risk, GCRI Canada shall impose mitigation measures.

2.10.10(h) Mitigation measures may include diversification, recusal, ring-fencing, independent review, access limits, contract clauses, publication-independence clauses, public-safe disclosure, provider-neutral language, sponsor acknowledgment limits, repository controls, or refusal.

2.10.10(i) Support that cannot be separated from control shall be refused, narrowed, returned, terminated, or publicly clarified as appropriate.

2.10.10(j) GCRI Canada shall preserve the principle that support may enable public-good truth but may not purchase, own, suppress, inflate, or direct it.

2.10.11 Independence, Neutrality, Non-Capture, and Provider Neutrality. 2.10.11(a) GCRI Canada shall preserve independence, neutrality, non-capture, provider neutrality, sponsor non-control, competition safety, and public authority boundary discipline.

2.10.11(b) Neutrality shall mean disciplined role integrity, not false equivalence between strong evidence and unsupported claims. GCRI Canada shall be neutral as to improper private advantage, not neutral as to evidence quality.

2.10.11(c) Independence shall require that evidence, methods, public-safe publication, correction, technical baselines, public authority learning, and technical stewardship remain free from improper influence.

2.10.11(d) GCRI Canada may engage with providers, sponsors, public authorities, universities, communities, capital readers, and technical contributors, but such engagement shall not determine conclusions, priorities, methods, public claims, access, publication timing, or correction in a manner inconsistent with public-benefit purpose.

2.10.11(e) Provider neutrality shall require that participation by a provider, contribution of technology, integration with a system, use of public-good software, attendance at a GCRI Canada event, or inclusion in evidence work does not create preferred-provider status, procurement advantage, certification implication, public authority endorsement, market allocation, or technical superiority claim.

2.10.11(f) GCRI Canada shall not allow public-good platforms, dashboards, technical baselines, reference architectures, public authority learning rooms, Academy materials, public reports, or public repositories to become vendor-marketing surfaces.

2.10.11(g) Non-capture shall require GCRI Canada to identify, mitigate, disclose where appropriate, ring-fence, correct, or refuse influence risks arising from funding, data access, technical dependency, public authority proximity, reviewer selection, publication timing, sponsor visibility, provider integration, media framing, or leadership pressure.

2.10.11(h) Competition safety shall require that convening and technical collaboration do not become collusion, market allocation, bid coordination, provider exclusion, procurement steering, unlawful information exchange, or coordinated commercial conduct.

2.10.11(i) Public-good collaboration shall remain compatible with lawful market conduct. Agendas, minutes, participation, data sharing, benchmarking, provider comparisons, and public claims shall be controlled where market-conduct risk exists.

2.10.11(j) Where independence, neutrality, non-capture, provider neutrality, or competition safety is threatened, GCRI Canada shall pause, narrow, reclassify, restrict, correct, or terminate the activity as appropriate.

2.10.12 Community Safeguards, Protected Participation, Accessibility, and Do-No-Harm. 2.10.12(a) GCRI Canada shall protect community safeguards, protected participation, accessibility, grievance, remedy, non-retaliation, Indigenous and local knowledge protocols, public-safe mapping, dignity, contextual integrity, and do-no-harm.

2.10.12(b) These values shall apply across research, evidence intake, observability, data handling, publication, AI use, public authority learning, technical baselines, Academy materials, controlled rooms, repositories, dashboards, maps, and Nexus interfaces.

2.10.12(c) Protected participation shall allow persons and communities to contribute, challenge, correct, or raise concerns without retaliation, exposure, coercion, reputational harm, loss of access, funding consequence, sponsor pressure, provider pressure, public authority pressure, or informal exclusion.

2.10.12(d) GCRI Canada shall provide safe channels proportionate to risk and shall preserve confidentiality where required.

2.10.12(e) Accessibility shall require that public-facing and participant-facing materials be reasonably legible, usable, and inclusive while preserving legal precision, controlled vocabulary, and public-safe meaning.

2.10.12(f) Plain-language summaries may support understanding, but they shall not override operative records, weaken binding boundaries, erase limitations, or create simplified overclaim.

2.10.12(g) Do-no-harm shall require anticipatory review of foreseeable harms, including privacy harm, dignity harm, community exposure, cultural harm, infrastructure risk, cyber risk, public authority confusion, finance overclaim, public warning confusion, procurement implication, protected knowledge misuse, AI-mediated distortion, retaliation risk, stigmatization, and downstream misuse.

2.10.12(h) Harm prevention shall be built into design, not added after release. GCRI Canada shall address harm risk at intake, classification, analysis, mapping, AI use, publication, sharing, correction, and closeout.

2.10.12(i) Indigenous knowledge, local knowledge, territorial knowledge, culturally sensitive knowledge, environmental knowledge, and protected knowledge shall be handled with context, respect, lawful authority, appropriate protocols, controlled access, public-safe review, and correction.

2.10.12(j) Where public-good work risks extraction, exposure, appropriation, harmful mapping, coercive visibility, public simplification, or unsafe AI use, GCRI Canada shall narrow, restrict, redesign, withhold, or refuse the activity.

2.10.13 Open, Governed, Reusable, and Secure Public-Good Assets. 2.10.13(a) GCRI Canada shall favor public-good assets that are open where appropriate, governed where required, reusable where lawful, secure by design, privacy-preserving, public-safe, versioned, and correctionable always.

2.10.13(b) Openness shall be pursued to support public-benefit learning, interoperability, review, capacity-building, transparency, reuse, public authority literacy, technical literacy, and institutional trust.

2.10.13(c) Openness shall not defeat privacy, cybersecurity, protected knowledge, lawful confidentiality, public authority restrictions, sovereign data obligations, community safeguards, sanctions, export controls, or public-safe publication rules.

2.10.13(d) Governed public-good assets shall include licensing terms, access classifications, contribution rules, version control, maintenance responsibility, public-safe release status, security controls, dependency records, permitted-use terms, prohibited-use terms where appropriate, and correction pathways.

2.10.13(e) GCRI Canada shall not confuse publication with stewardship. A released asset remains a governance responsibility where public reliance exists.

2.10.13(f) Reuse shall be encouraged where lawful and mission-compatible, but reuse shall not imply endorsement, certification, recognition, public authority approval, procurement preference, finance-readiness, protocol entitlement, or technical guarantee.

2.10.13(g) Public-good reuse shall be accompanied by boundary language, licensing clarity, limitation disclosure, status labels, correction notices, and version information where appropriate.

2.10.13(h) Secure-by-design shall apply to repositories, software, APIs, datasets, dashboards, controlled rooms, model registers, inference records, public authority materials, technical baselines, and public-safe publication systems.

2.10.13(i) Public-good assets that are insecure, unmaintained, unversioned, unlicensed, untraceable, or uncorrectable can undermine public trust and shall be corrected, restricted, deprecated, superseded, withdrawn, or archived.

2.10.13(j) GCRI Canada shall protect public-good assets against enclosure, vendor lock-in, sponsor control, provider capture, hidden telemetry, license traps, dependency fragility, and public meaning beyond the record.

2.10.14 Auditability, Traceability, Tamper-Evidence, and Institutional Memory. 2.10.14(a) GCRI Canada shall preserve auditability, traceability, custody, version history, tamper-evidence where appropriate, institutional memory, and final archival discipline.

2.10.14(b) These values shall ensure that institutional meaning can be reconstructed, challenged, corrected, superseded, withdrawn, and trusted over time.

2.10.14(c) Auditability shall require records sufficient to show who authorized material actions, what evidence supported them, what methods were applied, what review occurred, what classification applied, what limitations were known, what public-safe status applied, and what correction path exists.

2.10.14(d) Auditability may be internal, controlled, restricted, or public depending on classification, safety, law, privacy, cybersecurity, public authority limits, protected knowledge, and public-safe publication rules.

2.10.14(e) Traceability shall apply to evidence, methods, datasets, models, software releases, public-safe publications, public authority materials, sponsorship records, provider references, public claims, technical baselines, AI-use records, and Nexus interface records.

2.10.14(f) GCRI Canada shall not rely on untraceable claims, uncontrolled copies, private memory, undocumented technical changes, personal accounts, hidden scripts, or platform defaults for material institutional acts.

2.10.14(g) Tamper-evidence may include version control, hashes, signatures, logs, immutable records, controlled repositories, access records, release records, archival snapshots, and equivalent controls where appropriate.

2.10.14(h) The institution shall select tamper-evident controls proportionate to risk, public reliance, security needs, legal context, and public-good importance.

2.10.14(i) Institutional memory shall preserve not only final outputs but also authority, review, limitations, correction, supersession, withdrawal, dependency, and context necessary to understand those outputs over time.

2.10.14(j) Where institutional memory is threatened by platform migration, staff change, repository loss, sponsor dependency, provider dependency, corrupted records, or uncontrolled copies, GCRI Canada shall take corrective measures to preserve continuity.

2.10.15 Competition Safety and Market-Conduct Discipline. 2.10.15(a) GCRI Canada shall maintain competition safety and market-conduct discipline.

2.10.15(b) Public-good convening shall not become collusion, market allocation, bid influence, provider exclusion, procurement steering, unlawful information exchange, coordinated commercial conduct, or improper use of competitively sensitive information.

2.10.15(c) Evidence cooperation shall remain distinct from market coordination. Public-benefit purpose shall not excuse unlawful or unsafe market conduct.

2.10.15(d) Competition safety shall apply to councils, working groups, public authority rooms, provider sessions, benchmarking activity, technical comparison, data sharing, Academy sessions, sponsor events, controlled rooms, and Nexus interfaces.

2.10.15(e) GCRI Canada shall control agendas, minutes, participation, data aggregation, clean-room procedures, public claims, benchmarking language, and sensitive topics where competition or market-conduct risk exists.

2.10.15(f) Market-conduct discipline shall also apply to public claims. GCRI Canada shall not publish provider comparisons, benchmark outputs, readiness references, technical baselines, dashboards, or public-safe reports in a manner that unfairly implies procurement direction, market ranking, preferred-provider status, investment suitability, public authority endorsement, or exclusion unless the output is lawfully structured, evidence-supported, role-bounded, and public-safe.

2.10.15(g) Provider participation shall not create provider preference. Sponsor support shall not create market advantage. Technical compatibility shall not create procurement endorsement. Public authority attendance shall not create public-sector approval.

2.10.15(h) Where competition or market-conduct risk arises, GCRI Canada may pause discussion, remove topics, restrict materials, aggregate data, use independent review, seek legal review, reclassify information, modify public claims, or terminate the activity.

2.10.15(i) Competition safety shall be integrated into convening design, data-sharing design, benchmarking design, provider-interface design, public authority interface design, and public communications.

2.10.15(j) GCRI Canada shall not allow public-good language to mask market conduct inconsistent with law, fairness, provider neutrality, public authority boundaries, or public trust.

2.10.16 Public-Safe Communication and Bounded Reliance. 2.10.16(a) GCRI Canada shall communicate in a public-safe manner with bounded reliance, controlled vocabulary, limitation disclosure, public authority clarity, finance-safe language, sponsor neutrality, provider neutrality, evidence traceability, public-safe status, and correction pathways.

2.10.16(b) Public communication shall be designed to inform without overstating authority, maturity, certainty, scope, legal effect, technical effect, finance effect, public authority effect, procurement effect, certification effect, protocol effect, or execution effect.

2.10.16(c) Bounded reliance shall require that outputs identify, where material, their purpose, scope, status, limitations, intended audience, public-safe classification, review status, source basis, method basis, and correction path.

2.10.16(d) GCRI Canada shall not allow readers to reasonably infer investment advice, insurance approval, procurement direction, regulatory approval, public authority endorsement, official public warning, emergency command, certification, recognition, protocol entitlement, provider preference, or execution authority where none exists.

2.10.16(e) Public-safe communication shall include careful use of titles, headings, charts, maps, dashboards, badges, logos, labels, metadata, scores, ranks, public authority references, sponsor acknowledgments, provider references, colors, icons, calls to action, and Nexus-compatible terminology.

2.10.16(f) Visual design and naming can create authority as much as legal text; both shall be governed.

2.10.16(g) Where communication is likely to reach broad public audiences, media audiences, public authorities, capital readers, providers, sponsors, communities, Indigenous institutions, or vulnerable participants, GCRI Canada shall apply heightened review.

2.10.16(h) Accuracy shall include not only factual correctness but also correct public meaning. A statement may be misleading even where each sentence is literally true if its likely interpretation exceeds the record or GCRI Canada’s authority.

2.10.16(i) Public-safe communication shall not conceal limitations merely to be accessible. Plain-language communication shall remain legally precise, role-bounded, and correctionable.

2.10.16(j) Where GCRI Canada communications create public confusion, overreliance, public authority ambiguity, finance overclaim, provider preference, sponsor overclaim, certification implication, protocol implication, procurement implication, or execution implication, GCRI Canada shall correct, clarify, restrict, withdraw, supersede, or reissue the communication as appropriate.

2.11 Operating Principles

2.11.1 Forms-First Governance. 2.11.1(a) GCRI Canada shall conduct material institutional acts through forms-first governance. Material actions shall use approved forms, templates, decision packs, registers, committee records, council records, public-safe review forms, data access forms, AI-use records, sponsorship review forms, public authority capacity records, provider-interface forms, technical release forms, correction forms, controlled-room records, repository release records, conflict records, or equivalent structured artifacts.

2.11.1(b) Forms-first governance shall reduce ambiguity, prevent informal authority, preserve institutional memory, and make institutional action auditable, reviewable, public-safe, and correctionable.

2.11.1(c) Forms-first governance shall not be treated as bureaucracy for its own sake. It is a public-good control surface that ensures that purpose, authority, risk, classification, evidence, method, safeguards, role boundaries, conflicts, approvals, public-safe status, and correction paths are captured before institutional effect is created.

2.11.1(d) Forms shall be designed to improve judgment, not replace it. A completed form shall not validate an activity whose substance violates this Charter, applicable law, public-benefit purpose, non-execution, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, privacy, cybersecurity, protected knowledge, public-safe publication, or correctionability.

2.11.1(e) A material act shall not proceed merely because participants agree informally, a senior person approves verbally, a sponsor expects action, a public authority requests speed, a provider is ready, a dashboard can be launched, a repository can be published, or a technical system can be deployed. Where a form or structured record is required, the absence of the form shall be treated as a governance deficiency.

2.11.1(f) Forms-first governance shall apply to the initiation, approval, release, amendment, correction, restriction, supersession, withdrawal, and closeout of material programs, publications, technical assets, data access, AI use, public authority interfaces, sponsor arrangements, provider integrations, controlled rooms, public claims, Academy materials, and Nexus interface records.

2.11.1(g) Forms shall identify, where material, the requesting actor, responsible authority, purpose, legal basis, Charter basis, evidence basis, method basis, data categories, public-safe status, classification, affected parties, risks, safeguards, conflicts, public authority capacity, finance-boundary implications, sponsor or provider involvement, review history, approval, conditions, limitations, version, and correction pathway.

2.11.1(h) Forms shall be maintained, improved, versioned, and aligned with this Charter. Where recurring workarounds indicate that forms are inadequate, GCRI Canada shall correct the forms rather than abandon forms-first discipline.

2.11.1(i) No form, template, checklist, or automated workflow shall be designed in a manner that silently creates recognition, finance-readiness, certification, procurement approval, public authority action, protocol effect, provider preference, sponsor control, or execution authority.

2.11.1(j) GCRI Canada shall preserve completed forms and related decision artifacts as institutional records according to classification, retention, privacy, cybersecurity, public authority, protected knowledge, and public-safe publication requirements.

2.11.2 Records-First Governance. 2.11.2(a) GCRI Canada shall operate under records-first governance. Records shall precede institutional effect where public meaning, authority, access, publication, data use, AI use, technical release, funding, sponsorship, public authority reference, provider reference, finance-readiness reference, correction, or Nexus interface consequence exists.

2.11.2(b) No record means no public meaning. No material institutional act shall be treated as valid for public meaning merely because it was discussed, expected, funded, attended, technically implemented, publicly repeated, verbally approved, or embedded in a system.

2.11.2(c) Records-first governance shall require that material institutional acts be traceable to authority, scope, purpose, classification, approval, evidence, method, limitations, public-safe status, affected assets, affected actors, and correction path.

2.11.2(d) A record may be public, controlled, confidential, restricted, sealed, or archival, but it must exist where material effect is claimed. Restricted status shall not mean absence of record.

2.11.2(e) GCRI Canada shall reject governance by memory, proximity, chat, informal meeting notes, slide decks, social media, dashboard appearance, repository convention, public narrative, AI-generated summary, or repeated statement. Such communications may support work, but they shall not create institutional validity unless converted into proper records under authority.

2.11.2(f) Records-first governance shall apply to board actions, officer actions, committee actions, council actions, public-safe publications, technical releases, repository releases, data access, AI-use authorizations, sponsorship acceptance, grant acceptance, donation acceptance, provider designations, public authority capacity classifications, corrections, withdrawals, supersessions, controlled-room access, and Nexus interface claims.

2.11.2(g) Records shall distinguish draft, proposed, exploratory, pilot, controlled, adopted, active, public-facing, public-safe, superseded, deprecated, withdrawn, archived, and retired status.

2.11.2(h) Records-first governance shall protect GCRI Canada from disputes, drift, overclaim, capture, misquotation, public confusion, sponsor misuse, provider misuse, public authority ambiguity, finance overclaim, procurement implication, certification implication, protocol implication, and downstream misuse.

2.11.2(i) Records-first governance shall also protect public authorities, communities, sponsors, providers, partners, Nexus institutions, capital readers, and the public by clarifying what GCRI Canada has done, what it has not done, what it has authorized, and what may be relied upon only within bounded terms.

2.11.2(j) Where a record is missing, defective, inconsistent, corrupted, ambiguous, or outdated, GCRI Canada shall correct the record deficiency rather than rely on informal validity.

2.11.3 No-Email-Governance Rule for Material Acts. 2.11.3(a) Email, chat, messaging threads, slides, verbal discussions, informal minutes, shared-drive drafts, collaborative comments, text messages, social media posts, AI-generated summaries, or platform notifications shall not constitute governance for material acts unless converted into proper records under authority.

2.11.3(b) Informal communication may support work; it shall not itself create institutional validity, public meaning, authority, release status, correction status, public authority capacity, provider status, sponsor status, finance-readiness implication, procurement implication, certification implication, protocol implication, or execution authority.

2.11.3(c) Material acts include, without limitation, adoption of Charter interpretations, Bylaw-relevant decisions, public-safe publication, technical release, repository release, data access, AI-use approval, sponsorship acceptance, grant acceptance, donation acceptance, provider designation, public authority capacity classification, correction, withdrawal, supersession, repository authority, controlled-room access, public claims, and Nexus interface claims.

2.11.3(d) Where email, chat, slides, or other informal channels contain a material instruction, approval, concern, dissent, correction request, classification decision, publication decision, or public claim, the responsible person shall ensure that the matter is captured in the appropriate record system.

2.11.3(e) Private inboxes, personal accounts, messaging applications, cloud comments, and ad hoc folders shall not be treated as authoritative repositories for material institutional acts.

2.11.3(f) The no-email-governance rule shall not prevent efficient communication. It shall ensure that efficiency does not erase authority, classification, safeguards, review, correction, legal separateness, public authority boundaries, finance boundaries, or institutional memory.

2.11.3(g) Speed shall be compatible with records; it shall not replace them. Where urgency requires rapid action, the minimum necessary record shall be created contemporaneously or as soon as practicable, with later completion, review, and correction where required.

2.11.3(h) No person shall use informal channels to create plausible deniability, avoid review, bypass public-safe controls, satisfy sponsor expectations, accelerate provider claims, imply public authority approval, create finance-readiness language, or evade correction.

2.11.3(i) Where material action has occurred through informal channels without proper records, GCRI Canada shall reconstruct, classify, review, correct, and record the action, and shall determine whether corrective notice, restriction, withdrawal, or supersession is required.

2.11.3(j) Repeated failure to convert informal decisions into records shall be treated as a governance risk requiring training, controls, workflow redesign, or disciplinary or corrective action where appropriate.

2.11.4 No Silent Edit. 2.11.4(a) Material edits to records, publications, dashboards, maps, datasets, software releases, APIs, methods, baselines, ontologies, controlled vocabulary, public authority references, sponsor references, provider references, public claims, technical documentation, Academy materials, and Nexus interface materials shall be versioned, recorded, and publicly or controlledly noticed where reliance risk exists.

2.11.4(b) Silent editing is prohibited where it obscures institutional meaning, correction, supersession, reliance, public-safe status, source basis, method basis, authority, or limitations.

2.11.4(c) A silent edit may include altering a claim, changing a date, replacing a file, modifying a dataset, changing dashboard logic, updating a map layer, revising a method, changing a software package, altering public authority language, modifying sponsor acknowledgment, modifying provider reference, changing a technical baseline, removing limitations, changing a status label, or revising metadata without adequate record.

2.11.4(d) Materiality shall be assessed by effect, not by file size, word count, technical complexity, or the appearance of the edit. A small change may materially alter public meaning.

2.11.4(e) Where an edit corrects an error, GCRI Canada shall determine whether a correction note, supersession notice, version history, changelog, public-safe notice, controlled notice, downstream notification, or archival note is required.

2.11.4(f) Clerical, typographical, formatting, or non-substantive fixes may be handled proportionately, but substantive changes shall remain traceable.

2.11.4(g) No silent edit shall be used to avoid embarrassment, conceal error, remove inconvenient limitations, satisfy sponsor preference, reduce provider criticism, obscure public authority ambiguity, soften finance-boundary language, avoid procurement concerns, or alter public meaning without accountability.

2.11.4(h) Version histories shall preserve enough information to identify what changed, when it changed, who authorized the change, why the change was made, what records were affected, what public-safe status applies, and whether downstream notice was required.

2.11.4(i) Public-facing systems shall display version, status, date, correction, supersession, or withdrawal information where reliance risk requires it.

2.11.4(j) Where silent editing has occurred or is suspected, GCRI Canada shall reconstruct the change history, assess reliance risk, correct the record, and issue public-safe or controlled notice where appropriate.

2.11.5 No Informal Validity. 2.11.5(a) Informal consensus, prestige, urgency, funding, attendance, public authority interest, sponsor importance, provider centrality, founder preference, media repetition, technical convenience, ecosystem expectation, AI-generated fluency, or operational reliance shall not create validity.

2.11.5(b) Validity requires lawful authority, proper scope, proper record, required review, and compliance with Charter boundaries.

2.11.5(c) No meeting shall create institutional effect merely because important people attended. No dashboard shall become authoritative merely because it is widely viewed. No method shall become adopted merely because it is repeatedly used. No provider shall become preferred merely because it is technically central. No public authority engagement shall become approval merely because officials participated. No sponsor shall become controlling merely because support is substantial.

2.11.5(d) Informal validity risks shall be especially controlled in early-stage programs, high-visibility events, pilot projects, public authority sessions, sponsor-supported activities, provider demonstrations, technical integrations, capital-reader discussions, public dashboards, and Nexus interface work.

2.11.5(e) These settings often produce public meaning before formal records mature; GCRI Canada shall prevent that public meaning from exceeding the record.

2.11.5(f) Informal validity shall not arise through titles, badges, logos, maps, dashboard labels, repository tags, agenda language, public authority attendance, sponsor acknowledgment, provider listing, press statements, or repeated partner language.

2.11.5(g) Where informal validity appears to have arisen, GCRI Canada shall correct the record. Correction may include clarification, reclassification, public-safe notice, updated documentation, disclaimer, withdrawal, restriction, supersession, or formal adoption through proper process if lawful and Charter-consistent.

2.11.5(h) GCRI Canada shall not allow informal practices to become constitutional identity by repetition. Where recurring practices suggest a need for formal authority, GCRI Canada shall either formalize them through proper records and safeguards or discontinue them.

2.11.5(i) No actor shall rely on informal validity to claim recognition, finance-readiness, certification, procurement approval, public authority approval, protocol effect, provider endorsement, sponsor control, or execution authority.

2.11.5(j) The absence of correction shall not be interpreted as approval where the underlying record does not support the claimed meaning.

2.11.6 No Authority by Title, Proximity, Visibility, Sponsorship, Funding, Technical Centrality, or Public Attendance. 2.11.6(a) No person or actor shall acquire authority by title, proximity, visibility, sponsorship, funding, technical centrality, public authority attendance, media profile, contribution size, founder relationship, academic prestige, provider role, platform control, repository access, or ecosystem prominence.

2.11.6(b) Authority requires lawful source, proper delegation, proper record, proper scope, and proper boundary.

2.11.6(c) Titles shall be interpreted according to their recorded mandate. A fellow, advisor, chair, sponsor, provider, host, contributor, public authority participant, capital reader, technical lead, maintainer, reviewer, committee participant, council member, or partner shall not possess authority beyond the role recorded for that person or entity.

2.11.6(d) Public-facing titles shall be controlled to prevent apparent authority. Titles shall not imply certification power, public authority status, finance authority, procurement influence, protocol authority, recognition authority, institutional control, or execution authority unless such authority is lawful, records-valid, and Charter-consistent.

2.11.6(e) Technical centrality shall be especially guarded. A person or provider who controls a repository, cloud system, model, dataset, dashboard, integration, identity layer, API, sensor network, or critical tool shall not thereby acquire governance authority over GCRI Canada’s mission, methods, publications, public authority interfaces, correction, technical baselines, public claims, or institutional meaning.

2.11.6(f) Technical access shall be separated from institutional authority. Commit, merge, release, deploy, admin, model, data, dashboard, or repository rights shall not imply governance power unless separately recorded.

2.11.6(g) Public attendance or participation shall not create authority. A public official attending a meeting, a sponsor funding a program, a provider demonstrating a tool, a university hosting an event, a capital reader joining a room, or a media actor covering a session shall not acquire decision rights or confer approval by presence.

2.11.6(h) GCRI Canada shall maintain records and public language that preserve the distinction between attendance and approval, support and control, expertise and authority, contribution and ownership, access and governance, technical compatibility and endorsement, and public authority participation and public authority action.

2.11.6(i) Where apparent authority is created by title, proximity, visibility, sponsorship, funding, technical centrality, or public attendance, GCRI Canada shall correct, relabel, restrict, clarify, withdraw, or supersede the relevant claim, material, or role.

2.11.6(j) No external actor shall use GCRI Canada association to imply authority beyond the relevant record, and GCRI Canada shall reserve the right to correct or restrict such misuse.

2.11.7 Controlled Vocabulary and Semantic Precision. 2.11.7(a) Controlled vocabulary and semantic precision shall govern institutional meaning, public claims, technical terms, public authority references, finance-readiness references, maturity language, recognition language, certification language, protocol-adjacent language, Nexus-compatible language, and public-safe communication.

2.11.7(b) Words shall be treated as control surfaces. Labels, badges, metadata fields, dashboard captions, repository tags, API fields, public authority references, sponsor acknowledgments, provider references, event titles, Academy materials, and AI-generated summaries may create institutional effect and shall be governed accordingly.

2.11.7(c) GCRI Canada shall use terms such as “verified,” “validated,” “recognized,” “certified,” “mature,” “finance-ready,” “public-safe,” “approved,” “adopted,” “official,” “operational,” “decision-grade,” “proof,” “truth,” “standing,” “readiness,” “Nexus-compatible,” “compliant,” and “authority” only within recorded scope and competent authority.

2.11.7(d) Such terms shall not be used for rhetorical force where they create authority, maturity, market, public authority, finance, procurement, certification, protocol, or reliance implications not supported by records.

2.11.7(e) Semantic precision shall apply to documents, dashboards, maps, user interfaces, metadata, dataset fields, API responses, repository tags, public statements, Academy materials, sponsor acknowledgments, public authority references, provider references, media materials, and AI-generated outputs.

2.11.7(f) A misleading label in a system may create as much risk as misleading prose in a report. Technical fields, visual design, automated labels, scores, status tags, and machine-readable outputs shall be reviewed for semantic accuracy.

2.11.7(g) Controlled vocabulary shall preserve distinctions between data, evidence, method, inference, interpretation, validation, verification, recognition, maturity, standing, certification, finance-readiness, public authority action, procurement, protocol effect, execution, and correction.

2.11.7(h) Where controlled vocabulary is misused, GCRI Canada shall correct the misuse and, where necessary, update templates, systems, documentation, training, dashboards, repositories, public materials, or review controls to prevent recurrence.

2.11.7(i) Semantic drift shall be treated as an institutional risk and not as a stylistic issue.

2.11.7(j) No sponsor, provider, funder, public authority, partner, media actor, AI system, or technical contributor shall define GCRI Canada’s constitutional terms by use, repetition, public visibility, or technical implementation.

2.11.8 Minimum Truthfulness in Public Claims. 2.11.8(a) Public claims shall be accurate, record-supported, limitation-aware, current, public-safe, non-misleading, role-bounded, and correctionable.

2.11.8(b) Claims shall not be written to maximize influence at the expense of precision. GCRI Canada shall prefer a narrower truthful claim over a broader claim that creates false authority, false maturity, public authority confusion, finance overclaim, provider preference, sponsor advantage, procurement implication, certification implication, protocol implication, or execution implication.

2.11.8(c) Minimum truthfulness shall apply to all public-facing and external-facing materials, including websites, reports, slide decks, press statements, grant materials, sponsorship materials, public authority materials, Academy materials, social media, event descriptions, dashboards, maps, repository descriptions, technical documentation, public-safe summaries, and partner communications.

2.11.8(d) Minimum truthfulness shall also apply to internal materials likely to be shared externally or relied upon by external actors, including board materials, funding decks, concept notes, diagrams, prototypes, and planning materials.

2.11.8(e) A claim may be misleading even if each sentence is literally true. GCRI Canada shall consider the likely interpretation by the intended audience and by foreseeable secondary audiences.

2.11.8(f) If a reasonable reader may infer recognition, certification, finance-readiness, public authority approval, procurement preference, operational maturity, protocol effect, provider endorsement, sponsor control, or execution authority where none exists, the claim shall be revised.

2.11.8(g) Public claims shall be reviewed against the record. Claims concerning partnerships, public authority participation, technical maturity, geographic reach, operational status, funding, provider participation, community participation, public-safe outputs, Nexus compatibility, software readiness, and program status shall be especially controlled.

2.11.8(h) Claims shall distinguish proposed, exploratory, pilot, prototype, controlled, limited, active, operational, mature, public-facing, public-safe, adopted, superseded, withdrawn, and archived status.

2.11.8(i) Public-safe communication shall not soften or omit boundaries merely to improve public appeal. Legal precision, public authority clarity, finance-safe language, provider neutrality, sponsor non-control, and correctionability shall remain visible where material.

2.11.8(j) Where a public claim becomes stale, misleading, overbroad, or inconsistent with the record, GCRI Canada shall correct, qualify, withdraw, supersede, or update it.

2.11.9 Proportionality, Necessity, and Least-Exposure Publication Rule. 2.11.9(a) Publication shall be proportionate, necessary, and least-exposure where public safety, privacy, cybersecurity, infrastructure sensitivity, public authority confidentiality, commercial sensitivity, finance sensitivity, community safeguards, Indigenous protocols, protected knowledge, vulnerable persons, or lawful restrictions require restraint.

2.11.9(b) GCRI Canada shall publish enough to serve public benefit and accountability, but not so much as to create avoidable harm.

2.11.9(c) Proportionality shall require that the detail, timing, audience, format, granularity, permanence, and dissemination of publication match the public-benefit purpose and risk profile.

2.11.9(d) Necessity shall require that publication serve a defined public-benefit purpose rather than mere visibility, sponsor value, media interest, public attention, institutional promotion, provider marketing, or strategic signaling.

2.11.9(e) Least exposure shall require that sensitive details be minimized, aggregated, generalized, redacted, delayed, controlled, or withheld where full public release is not required for the public-benefit purpose.

2.11.9(f) The least-exposure rule shall apply to maps, dashboards, datasets, public authority materials, vulnerability information, infrastructure data, geospatial layers, community-linked evidence, protected knowledge, AI outputs, model records, benchmark results, and technical implementation details.

2.11.9(g) GCRI Canada shall not publish high-risk information merely because it is accurate, publicly sourced, technically available, visually compelling, sponsor-relevant, provider-relevant, media-friendly, or analytically useful.

2.11.9(h) Where publication is restricted, GCRI Canada shall consider whether a public-safe summary, controlled annex, private notice, stakeholder briefing, synthetic example, delayed release, aggregated release, or archival record can preserve accountability without causing harm.

2.11.9(i) Non-public handling shall be recorded and justified where material.

2.11.9(j) Least-exposure publication shall not be used to hide error, suppress correction, protect reputation, conceal sponsor influence, shield provider preference, or avoid accountability. It exists to prevent harm while preserving lawful and public-benefit transparency.

2.11.10 Lifecycle Discipline From Creation Through Review, Release, Maintenance, Challenge, Correction, Supersession, Retirement, and Archival. 2.11.10(a) Records, software, datasets, methods, baselines, maps, dashboards, models, publications, Academy materials, public authority materials, AI workflows, controlled vocabulary, public claims, repositories, technical tools, and Nexus interface records shall follow lifecycle discipline from creation through review, approval, release, maintenance, challenge, correction, supersession, retirement, archival, and closeout.

2.11.10(b) Lifecycle discipline shall prevent GCRI Canada from treating outputs as one-time artifacts. Public-good infrastructure requires maintenance. A dataset may become stale; a method may become outdated; a dashboard may become misleading; software may become insecure; a public authority material may require clarification; a public claim may require correction; a baseline may require supersession.

2.11.10(c) Each material asset shall have an appropriate lifecycle status. Draft, proposed, exploratory, pilot, prototype, controlled, adopted, in force, public-facing, public-safe, limited, deprecated, superseded, withdrawn, archived, retired, and final states shall be distinguished.

2.11.10(d) Public-facing materials shall not hide lifecycle status where reliance risk exists.

2.11.10(e) Lifecycle records shall identify responsible owner or steward, review schedule, dependency status, public-safe status, access classification, maintenance obligations, correction pathway, and retirement conditions where material.

2.11.10(f) Maintenance shall include review for accuracy, security, privacy, public-safe status, licensing, dependency risk, controlled vocabulary, public authority language, finance-safe language, provider neutrality, sponsor non-control, and correctionability.

2.11.10(g) Challenge shall be part of lifecycle discipline. GCRI Canada shall provide pathways for appropriate challenge of evidence, methods, datasets, dashboards, maps, software, technical baselines, public-safe reports, public authority materials, and public claims.

2.11.10(h) Closeout shall be treated as a governance act. When a program, repository, dataset, model, dashboard, method, publication, public authority interface, controlled room, or technical baseline is ended, GCRI Canada shall preserve records, handle data properly, issue notices where required, transfer or archive assets where appropriate, and prevent obsolete materials from being mistaken for current authority.

2.11.10(i) Lifecycle discipline shall apply even where the asset is experimental, open-source, sponsor-supported, provider-contributed, AI-assisted, or publicly popular.

2.11.10(j) GCRI Canada shall not allow abandoned, unsupported, stale, insecure, or superseded assets to continue circulating as current public-good infrastructure.

2.11.11 Auditability, Traceability, Custody, and Tamper-Evident Stewardship. 2.11.11(a) GCRI Canada shall preserve auditability, traceability, custody, and tamper-evident stewardship where appropriate through version control, logs, access records, source records, signed releases, hashes where appropriate, repository discipline, correction registers, approval records, archival records, and equivalent controls.

2.11.11(b) The level of control shall be proportionate to risk, sensitivity, public reliance, legal context, public authority relevance, privacy impact, cybersecurity importance, protected knowledge sensitivity, and public-good significance.

2.11.11(c) Auditability shall allow authorized reviewers to reconstruct material decisions, releases, publications, corrections, access grants, data uses, AI uses, sponsorship decisions, public authority references, provider references, technical baseline changes, repository changes, and Nexus interface actions.

2.11.11(d) Traceability shall link outputs to sources, methods, approvals, versions, classifications, limitations, public-safe status, and correction records.

2.11.11(e) Custody shall preserve who held, altered, transferred, accessed, approved, released, corrected, superseded, or archived material assets where relevant.

2.11.11(f) Tamper-evident stewardship shall be applied where alteration could damage public trust, evidence integrity, technical security, public authority confidence, finance-boundary safety, community safeguards, protected knowledge controls, or public-good continuity.

2.11.11(g) Tamper-evidence may include cryptographic signatures, hash records, immutable logs, signed releases, controlled repositories, access records, release attestations, archival snapshots, or equivalent controls.

2.11.11(h) Auditability and traceability shall not require public exposure of restricted materials. GCRI Canada may preserve internal or controlled audit paths where public disclosure would create privacy, cybersecurity, protected knowledge, public authority, finance, commercial, or safety risks.

2.11.11(i) Custody failures, uncontrolled access, broken provenance, missing logs, repository compromise, untraceable releases, or unexplained changes shall be treated as governance risks requiring review and correction.

2.11.11(j) Auditability, traceability, custody, and tamper-evident stewardship shall apply to both human-governed and AI-assisted systems.

2.11.12 Most-Restrictive Rule Where Risk, Harm, Role Confusion, Perimeter Breach, or Legal Ambiguity Exists. 2.11.12(a) Where risk, harm, role confusion, perimeter breach, legal ambiguity, public authority ambiguity, finance ambiguity, data risk, AI risk, cyber risk, protected knowledge risk, public safety risk, community harm risk, competition risk, procurement implication, certification implication, protocol-authority implication, public warning implication, or execution implication exists, the most protective lawful interpretation shall prevail until proper review resolves the matter.

2.11.12(b) The most-restrictive rule shall apply to authority, publication, access, data sharing, AI use, public authority references, sponsor references, provider references, finance-adjacent language, technical releases, public claims, controlled-room access, public-safe mapping, and Nexus interfaces.

2.11.12(c) The most-restrictive rule shall prevent GCRI Canada from proceeding under ambiguity where ambiguity itself creates risk.

2.11.12(d) Most-restrictive treatment may include delay, narrowing, redaction, aggregation, controlled-room handling, legal review, safeguards review, public-safe review, board review, independent review, access restriction, reclassification, publication hold, release freeze, or refusal to proceed.

2.11.12(e) Restriction shall be proportionate but shall not be avoided merely because it is inconvenient, reputationally uncomfortable, sponsor-disfavored, provider-disfavored, public authority-sensitive, technically burdensome, or time-consuming.

2.11.12(f) Once proper review resolves the ambiguity, GCRI Canada may proceed under the approved interpretation, provided that the record explains the basis, scope, controls, limitations, public-safe status, review date, and correction path.

2.11.12(g) Where ambiguity concerns personal data, protected knowledge, cyber-sensitive information, sensitive infrastructure, public authority materials, finance-sensitive information, public warning effect, procurement effect, certification effect, protocol effect, or execution effect, GCRI Canada shall not rely on broad disclaimers alone. Structural controls shall be applied.

2.11.12(h) The most-restrictive rule shall not be used to suppress correction, hide error, avoid accountability, or deny access where lawful public-benefit access is required. It is a risk-control principle, not a secrecy principle.

2.11.12(i) The burden shall rest on the actor seeking broader interpretation, wider release, broader access, or stronger public claim to establish lawful basis, public-benefit purpose, records validity, safeguards, and correction pathway.

2.11.12(j) Where the risk cannot be reduced to a Charter-consistent level, GCRI Canada shall refuse, terminate, withdraw, or reroute the activity.

2.11.13 Public-Safe by Design. 2.11.13(a) Systems, publications, dashboards, maps, repositories, data rooms, controlled rooms, AI workflows, Academy materials, public authority materials, technical releases, software tools, observability outputs, APIs, datasets, model records, technical baselines, and Nexus interfaces shall be public-safe by design, not merely reviewed after creation.

2.11.13(b) Public-safe design shall embed safeguards into structure, metadata, access controls, terminology, review stages, output formats, user interfaces, release workflows, correction links, status labels, and documentation.

2.11.13(c) Public-safe by design shall require early identification of privacy risk, cyber risk, infrastructure sensitivity, public authority constraints, finance-boundary risks, provider preference risk, sponsor overclaim risk, community harm, Indigenous and protected knowledge, public warning implication, procurement implication, certification implication, protocol implication, execution implication, and AI-output risk.

2.11.13(d) These issues shall not be left for final-stage communications review where redesign may be difficult or public reliance may already have formed.

2.11.13(e) Public-safe design shall include default minimization, role-bounded labels, controlled vocabulary, classification fields, limitation displays, access controls, redaction capability, aggregation capability, correction links, stage-truth indicators, public authority capacity fields, and finance-safe language where appropriate.

2.11.13(f) Technical systems shall be designed so that unsafe publication is harder, not easier. Default settings shall not favor overexposure, uncontrolled sharing, ambiguous status, missing limitations, or public authority overclaim.

2.11.13(g) Public-safe design shall consider likely audiences and foreseeable secondary audiences, including public authorities, communities, sponsors, providers, capital readers, media, technical users, policymakers, and the general public.

2.11.13(h) Where a system or material cannot be made public-safe, it shall be restricted, redesigned, summarized, controlled, delayed, archived, or withheld.

2.11.13(i) The desire for public visibility shall not override public-safe design.

2.11.13(j) Public-safe design failures shall be corrected through redesign, relabeling, access control, public-safe clarification, restriction, withdrawal, or supersession where appropriate.

2.11.14 Secure, Privacy-Preserving, and Sovereignty-Compatible by Design. 2.11.14(a) GCRI Canada systems shall be secure, privacy-preserving, and sovereignty-compatible by design.

2.11.14(b) Cross-border transfer, cloud use, AI use, public release, repository access, data sharing, model inference, observability, public authority materials, controlled-room collaboration, technical releases, and external collaboration shall be controlled by law, classification, purpose, permissions, safeguards, and risk.

2.11.14(c) Secure by design shall require identity and access management, least privilege, secure configuration, encryption where appropriate, vulnerability management, logging, incident response, backup, continuity, secure development, secure release, secrets control, dependency review, and secure decommissioning.

2.11.14(d) Privacy-preserving by design shall require minimization, purpose limitation, access restriction, retention discipline, de-identification or aggregation where appropriate, avoidance of unnecessary linkage, public-safe review, and prevention of unsafe secondary use.

2.11.14(e) Sovereignty-compatible by design shall require attention to jurisdiction, localization, sovereign data zones, compute-to-data, public authority controls, Indigenous protocols, cross-border transfer review, sanctions awareness, export-control awareness, and conflict-of-law issues.

2.11.14(f) Systems shall not be architected in ways that require unlawful, unnecessary, or trust-damaging data movement by default.

2.11.14(g) Design choices shall be documented where material. GCRI Canada shall not adopt tools, platforms, AI systems, repositories, collaboration environments, cloud services, or model providers for protected or mission-critical work unless they can support the required security, privacy, sovereignty, public-safe, and correction controls.

2.11.14(h) Vendor convenience, sponsor-funded access, provider preference, public authority urgency, technical popularity, cost savings, or speed shall not justify tools that create unacceptable privacy, cybersecurity, sovereign data, protected knowledge, or correction risk.

2.11.14(i) Where a tool or architecture creates material dependency, lock-in, hidden telemetry, cross-border exposure, model-provider control, opaque automation, or insecure release risk, GCRI Canada shall mitigate, redesign, restrict, replace, or refuse the tool or architecture.

2.11.14(j) Secure, privacy-preserving, and sovereignty-compatible design shall be treated as a constitutional safeguard, not an optional technical enhancement.

2.11.15 Open Where Appropriate, Controlled Where Required, Correctable Always. 2.11.15(a) GCRI Canada shall be open where appropriate, controlled where required, and correctionable always.

2.11.15(b) Openness shall not defeat safety; control shall not become secrecy for convenience; correction shall not be optional.

2.11.15(c) Open where appropriate means that public-good methods, technical baselines, software, schemas, summaries, educational materials, public-safe reports, learning materials, evidence outputs, and public-good tools should be made available where lawful, safe, mission-compatible, and useful for public benefit.

2.11.15(d) Controlled where required means that sensitive data, protected knowledge, public authority materials, cyber-sensitive details, infrastructure-sensitive information, rights-bearing data, confidential materials, preliminary evidence, finance-sensitive information, and restricted records shall be handled under appropriate controls.

2.11.15(e) Correctionable always means that every material output shall have a pathway for review, challenge, revision, supersession, withdrawal, restriction, clarification, downgrade, reinstatement, archival, or closeout.

2.11.15(f) GCRI Canada shall not publish, deploy, or rely upon materials in a manner that makes correction practically impossible where reliance exists.

2.11.15(g) This operating principle shall be used as a simple interpretive test across the institution. When designing a system, publication, program, repository, partnership, public authority interface, AI workflow, data room, controlled room, or technical release, GCRI Canada shall ask: what can be open, what must be controlled, and how will it be corrected.

2.11.15(h) Openness shall be accompanied by licensing clarity, limitation disclosure, versioning, status labels, public-safe review, security review where appropriate, and correction pathways.

2.11.15(i) Control shall be accompanied by records, access rules, classification, retention, review, public-safe rationale where appropriate, and correction pathways.

2.11.15(j) Correction shall be accompanied by authority, version history, affected-record identification, public-safe notice where required, downstream notice where required, and archival discipline.

2.11.15(k) Where openness, control, and correctionability conflict, GCRI Canada shall apply the Charter-consistent, public-benefit, lawful, public-safe, and most protective interpretation until proper review resolves the matter.

2.12 Doctrinal Anchors

2.12.1 One Rail / Two Stacks Doctrine. 2.12.1(a) GCRI Canada shall observe the One Rail / Two Stacks Doctrine, preserving a common Nexus public-good rail while maintaining a strict separation between the Public-Good Stack and the Enterprise Stack.

2.12.1(b) The common rail may carry shared vocabulary, evidence structures, methods, observability logic, ontologies, technical baselines, public-good software, public-safe publication practices, correction signals, interoperability records, public authority learning inputs, and Nexus-compatible coordination methods.

2.12.1(c) The existence of one rail shall not mean that all actors on the rail possess the same authority, legal character, liability, public role, economic function, governance rights, public authority status, finance role, protocol role, or execution role.

2.12.1(d) The Public-Good Stack shall preserve evidence, methods, observability, ontology, technical baselines, public-good software, public-safe publication, public authority learning, safeguards, correctionability, and public-benefit stewardship.

2.12.1(e) The Enterprise Stack shall preserve implementation, delivery, commercial contracting, project economics, finance execution, procurement participation, asset ownership, infrastructure operation, service provision, regulated activity where applicable, Project SPV governance, National Consortium Company activity, provider implementation, and market-facing responsibility.

2.12.1(f) The two stacks may interface, but they shall not be collapsed. Public-good evidence may support enterprise action; it shall not become enterprise execution. Enterprise activity may use public-good tools; it shall not acquire control over public-good meaning.

2.12.1(g) GCRI Canada shall remain within the Public-Good Stack unless a lawful and Charter-consistent instrument expressly provides otherwise for a narrowly defined function that does not compromise mission lock, non-execution, legal separateness, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, or correctionability.

2.12.1(h) The common rail shall support interoperability without legal fusion, alignment without control, shared methods without shared liability, shared vocabulary without shared authority, and shared public-good purpose without shared execution.

2.12.1(i) Any activity that uses the common rail to blur the Public-Good Stack and Enterprise Stack shall be corrected, narrowed, restricted, rerouted, or refused.

2.12.1(j) The One Rail / Two Stacks Doctrine shall govern GCRI Canada’s relationship with GRF, GRA, protocol authorities, public authorities, National Consortium Companies, Project SPVs, qualified providers, sponsors, hosts, universities, communities, Indigenous institutions, capital readers, and other Nexus-compatible actors.

2.12.2 Public-Good Stack Distinctness. 2.12.2(a) The Public-Good Stack is distinct from enterprise execution, finance execution, procurement execution, public authority action, certification by default, regulated professional opinion, protocol authority, and market operation.

2.12.2(b) GCRI Canada’s place within the Public-Good Stack shall include upstream truth, evidence infrastructure, scientific-operational methods, observability architecture, ontology, controlled vocabulary, public-good R&D, public-good software, open technical baselines, public authority learning, public-safe publication, safeguards, and correctionability.

2.12.2(c) Public-Good Stack distinctness shall preserve independence, public-benefit purpose, role clarity, public authority safety, finance-boundary safety, provider neutrality, sponsor non-control, data rights, cybersecurity, protected knowledge, and institutional trust.

2.12.2(d) Public-Good Stack assets shall not be treated as commercial inventory, vendor preference, sponsor property, finance-readiness engine, procurement gate, certification mechanism, public authority delegation, protocol entitlement, or execution infrastructure by default.

2.12.2(e) Public-Good Stack outputs may be useful, technical, public, relied upon, and foundational, but they shall remain bounded by source, method, scope, review, public-safe status, limitations, and correction path.

2.12.2(f) The Public-Good Stack shall be open where appropriate, controlled where required, and correctionable always.

2.12.2(g) Public-Good Stack distinctness shall require GCRI Canada to protect public-good assets against private capture, public-good enclosure, semantic drift, public authority overclaim, finance overclaim, procurement implication, certification drift, protocol drift, execution drift, and AI-generated authority.

2.12.2(h) Participation in the Public-Good Stack shall not confer ownership, control, endorsement, recognition, maturity status, finance-readiness, procurement preference, public authority approval, protocol effect, or execution authority unless such status is separately and lawfully created by competent authority and properly recorded.

2.12.2(i) Where public-good language is used to mask private advantage, GCRI Canada shall correct the record and preserve Public-Good Stack distinctness.

2.12.3 Enterprise Stack Separation. 2.12.3(a) The Enterprise Stack is separate from GCRI Canada’s public-good technical, evidence, methods, observability, ontology, and learning functions.

2.12.3(b) The Enterprise Stack may include commercial implementation, project finance, procurement participation, vendor delivery, regulated execution, insurance placement, lending, underwriting, rating, investment, asset operation, project governance, National Consortium Company activity, Project SPV activity, qualified provider services, infrastructure deployment, and market-facing obligations.

2.12.3(c) GCRI Canada may provide upstream evidence, methods, baselines, observability outputs, public-safe reports, public-good software, public authority learning materials, and correction signals that support Enterprise Stack actors, but it shall not become those actors.

2.12.3(d) Enterprise Stack actors shall remain responsible for their own governance, lawfulness, contracts, financing, procurement, deployment, operations, professional duties, regulated obligations, insurance, public claims, risk acceptance, and execution.

2.12.3(e) Use of GCRI Canada outputs by Enterprise Stack actors shall not imply endorsement, recognition, certification, finance-readiness, procurement approval, public authority approval, protocol entitlement, technical guarantee, or Nexus legitimacy unless separately authorized by competent authority and records-valid.

2.12.3(f) Enterprise Stack revenue, execution, contracts, asset ownership, investor relationships, insurance arrangements, public authority procurement, and project delivery shall not be attributed to GCRI Canada by implication.

2.12.3(g) GCRI Canada shall not hold itself out as the operator, provider, broker, lender, insurer, underwriter, rating agency, public finance approver, procurement authority, vendor manager, Project SPV governor, National Consortium Company governor, deployment manager, or commercial execution body of the Enterprise Stack.

2.12.3(h) Interfaces with the Enterprise Stack shall be governed by written or records-valid instruments that preserve legal separateness, role boundaries, public claims limits, data rights, cybersecurity, protected knowledge, sponsor non-control, provider neutrality, finance-safe language, and correction rights.

2.12.3(i) Where Enterprise Stack actors misuse GCRI Canada materials to imply authority beyond the record, GCRI Canada shall require correction, restrict use, withdraw permission, issue public-safe clarification, or take other appropriate action.

2.12.4 Evidence Distinct From Recognition. 2.12.4(a) Evidence is distinct from recognition. GCRI Canada may produce evidence, evidence packs, evidence summaries, observability outputs, method notes, technical baselines, public-safe reports, confidence logic, correction records, and evidence inputs relevant to recognition, but it shall not produce recognition by default.

2.12.4(b) Recognition may include public-facing legitimacy, standing, maturity records, registry status, claims determinations, stakeholder legitimacy, or equivalent recognition outputs issued by a competent recognition institution, including The Global Risks Forum (GRF) where applicable.

2.12.4(c) A GCRI Canada evidence output shall not be represented as GRF recognition, registry status, maturity record, standing, claims determination, public legitimacy, adoption, certification, approval, finance-readiness, procurement readiness, protocol effect, or execution authority.

2.12.4(d) Evidence may be strong, public, technical, rigorous, widely used, and relied upon, but strength of evidence does not itself create recognition.

2.12.4(e) Recognition requires competent authority, proper process, proper scope, proper record, public-safe language, correction path, and issuing institution.

2.12.4(f) GCRI Canada shall structure handoffs to recognition bodies so that the receiving institution can understand what evidence has been provided, what it supports, what it does not support, what limitations apply, what public-safe status applies, and how corrections shall be communicated.

2.12.4(g) Terms such as “recognized,” “standing,” “maturity,” “accepted,” “listed,” “verified by registry,” “public legitimacy,” or equivalent status language shall not be used by GCRI Canada unless such status has been lawfully and records-validly granted by the competent institution.

2.12.4(h) Where an external actor treats GCRI Canada evidence as recognition, GCRI Canada shall correct or clarify the misuse where material.

2.12.4(i) The evidence-recognition distinction shall protect both GCRI Canada and the recognition institution by ensuring that upstream truth and public-facing legitimacy remain separately governed.

2.12.5 Recognition Distinct From Adoption. 2.12.5(a) Recognition is distinct from adoption. A recognized, listed, mature, evidence-supported, or public-facing legitimate status shall not by itself constitute adoption by a public authority, enterprise actor, standards body, protocol authority, funder, insurer, lender, procurement office, community, host, sponsor, provider, National Consortium Company, Project SPV, or other downstream actor.

2.12.5(b) Adoption requires the competent adopting actor to act under its own authority, procedures, records, legal obligations, approvals, contracts, procurement rules, governance rules, or operational controls.

2.12.5(c) Recognition may inform adoption, but it shall not substitute for adoption.

2.12.5(d) GCRI Canada shall not allow evidence inputs, public-safe reports, observability outputs, technical baselines, Academy materials, public authority learning materials, or Nexus-compatible language to imply that a recognized matter has been adopted unless adoption has been separately and properly recorded by the competent adopting actor.

2.12.5(e) Public authority participation, provider participation, sponsor support, capital-reader interest, GRF recognition, technical compatibility, or public visibility shall not create adoption by implication.

2.12.5(f) Where adoption status is referenced, the reference shall identify the adopting actor, scope, date, instrument, limitations, public-safe status, and correction pathway where material.

2.12.5(g) GCRI Canada shall preserve the distinction between evidence support, recognition, adoption, implementation, operation, and execution in all public materials and technical systems.

2.12.5(h) Where adoption is ambiguous, GCRI Canada shall apply the most protective interpretation and avoid language suggesting adoption until the record supports it.

2.12.5(i) Recognition-adoption discipline shall prevent public authority confusion, procurement distortion, finance overclaim, provider advantage, sponsor overclaim, and public reliance beyond the record.

2.12.6 Adoption Distinct From Protocol Authority. 2.12.6(a) Adoption is distinct from protocol authority. A public authority, enterprise actor, provider, sponsor, project, consortium, or institution may adopt a method, technical baseline, schema, software tool, dashboard, public-safe report, or evidence practice without thereby creating protocol effect.

2.12.6(b) Protocol authority requires competent protocol governance, proper designation, version control, scope definition, role mapping, technical effect, legal or institutional effect where applicable, correction logic, and records-valid adoption by the protocol authority.

2.12.6(c) GCRI Canada shall not treat use, reference, implementation, compatibility, or adoption of its technical assets as protocol authority by default.

2.12.6(d) Adoption by a downstream actor may show use, reliance, alignment, or implementation, but it shall not create role keys, smart licenses, protocol entitlements, proof-receipt legal effect, externally binding conformance states, mandatory interoperability status, or protocol recognition unless the competent protocol authority expressly attaches such effect.

2.12.6(e) GCRI Canada may produce protocol-supporting inputs, including schemas, evidence logic, public-good software, method notes, technical baselines, observability structures, model records, proof templates, and conformance-supporting tools, but such inputs shall remain upstream technical and evidence support unless lawfully designated otherwise.

2.12.6(f) Protocol-adjacent outputs shall carry boundary language distinguishing technical support from protocol effect.

2.12.6(g) Dashboards, repositories, badges, tokens, metadata fields, receipts, API responses, hashes, smart-contract references, and machine-readable outputs shall not be designed in a manner that implies protocol effect without competent authority.

2.12.6(h) Where a GCRI Canada asset is proposed for protocol effect, the change in status shall require a separate records-valid process identifying scope, version, authority, effect, limitations, correction logic, public-safe status, and affected actors.

2.12.6(i) Any misuse of adoption language to imply protocol authority shall be corrected.

2.12.7 Protocol Authority Distinct From Execution. 2.12.7(a) Protocol authority is distinct from execution. Protocol authority may define rules, roles, technical states, proofs, interoperability logic, conformance states, or system relationships, but it shall not by itself cause GCRI Canada to operate assets, deploy infrastructure, command actions, deliver services, procure vendors, arrange finance, insure risks, execute transactions, or govern Project SPVs.

2.12.7(b) Execution requires separate actors, separate authority, separate contracts, separate liability, separate governance, and separate operational responsibility.

2.12.7(c) GCRI Canada shall not become an execution actor merely because its evidence, methods, schemas, public-good software, technical baselines, or observability outputs are incorporated into protocol-adjacent systems or relied upon by execution actors.

2.12.7(d) Protocol effect, where lawfully attached by competent authority, shall not erase the distinction between upstream truth, protocol governance, and operational execution.

2.12.7(e) GCRI Canada shall not issue dispatch instructions, operational commands, procurement awards, deployment approvals, asset ownership decisions, project governance instructions, public warning instructions, market execution instructions, or regulated execution decisions through protocol-adjacent tools.

2.12.7(f) Where protocol systems interface with execution systems, boundary controls shall identify the responsible execution actor, operational authority, liability perimeter, data responsibilities, public claims limits, cybersecurity responsibilities, and correction pathways.

2.12.7(g) Machine-readable protocol outputs shall not be designed to create operational control by ambiguity. A proof receipt may evidence process; it shall not command execution. A role key may identify status; it shall not authorize GCRI Canada to operate assets. A conformance state may support interpretation; it shall not substitute for execution governance.

2.12.7(h) Where public materials or technical systems imply that GCRI Canada executes because it supports protocol-adjacent work, GCRI Canada shall correct, restrict, redesign, or withdraw the relevant materials or interface.

2.12.7(i) Protocol-execution separation shall protect public-good neutrality, legal separateness, liability boundaries, public authority clarity, finance boundaries, provider neutrality, sponsor non-control, and public trust.

2.12.8 Routeability Distinct From Finance Execution. 2.12.8(a) Routeability is distinct from finance execution. Evidence may make a project, technology, institution, asset, or program more understandable to finance actors, insurers, public finance bodies, capital readers, or diligence reviewers, but such routeability shall not constitute financing, investment advice, insurance approval, underwriting, lending, rating, brokerage, placement, guarantee, public finance approval, or capital commitment.

2.12.8(b) GCRI Canada may produce evidence, technical risk notes, diligence gap maps, observability outputs, methods, public-safe reports, technical baselines, confidence summaries, and correction signals that help others understand risks, gaps, maturity, dependencies, safeguards, and evidence quality.

2.12.8(c) Such outputs shall remain evidence support and shall not be framed as investability, bankability, insurability, finance-readiness, creditworthiness, underwriting approval, investment suitability, rating, public finance approval, guarantee, capital allocation, or transaction recommendation.

2.12.8(d) Finance execution belongs to competent finance actors acting under their own legal, fiduciary, professional, regulatory, investment, insurance, credit, public finance, and governance obligations.

2.12.8(e) GCRI Canada shall not receive transaction-based compensation, arrange capital, solicit securities, introduce investors for compensation, broker deals, approve credit, place insurance, underwrite risks, rate instruments, guarantee outcomes, or commit capital.

2.12.8(f) Where GCRI Canada materials are used in finance-adjacent contexts, they shall carry finance-safe language and shall identify their evidentiary and non-financial character.

2.12.8(g) Capital readers shall not obtain preferred access to public authority rooms, project information, provider relationships, or evidence records in a manner that implies finance privilege, investment allocation, public endorsement, or market advantage.

2.12.8(h) Where a project, SPV, provider, sponsor, public authority, or capital reader seeks to use GCRI Canada materials in finance materials, GCRI Canada may review the proposed use of its name, outputs, marks, records, or public-good assets to prevent misleading finance implication.

2.12.8(i) Misuse of routeability to imply finance execution shall be corrected, refused, restricted, or clarified.

2.12.9 Public Authority Learning Distinct From Public Authority Delegation. 2.12.9(a) Public authority learning is distinct from public authority delegation. GCRI Canada may support public authority learning, technical literacy, evidence literacy, AI literacy, cyber literacy, observability interpretation, controlled-room review, scenario understanding, and public-safe explanation, but it shall not thereby receive public authority powers.

2.12.9(b) Public authorities retain their own statutory powers, procedures, duties, accountabilities, procurement rules, funding rules, public finance powers, emergency powers, regulatory powers, enforcement powers, public health powers, and public communication responsibilities.

2.12.9(c) Public authority participation in GCRI Canada activities shall be capacity-classified and role-bounded. Participation may be informational, observational, technical, advisory, learning-focused, consultative, evidence-contributing, or otherwise limited, but shall not be treated as adoption, approval, procurement, funding, public finance approval, regulation, public warning, enforcement, or sovereign obligation unless separately and lawfully recorded by the public authority.

2.12.9(d) Public authority logos, names, quotes, photographs, attendance, comments, data contributions, requests, or room participation shall not be used to imply approval, adoption, public-private partnership, procurement, funding, regulation, warning, or official guidance beyond the record.

2.12.9(e) GCRI Canada shall not issue official public warnings, emergency orders, evacuation instructions, public health orders, regulatory approvals, permits, enforcement actions, public procurement approvals, public finance approvals, or sovereign obligations.

2.12.9(f) Public authority learning materials shall be designed to inform without appearing to command. Dashboards, maps, reports, briefings, scenario materials, and Academy materials shall not mimic official alerts, official directions, regulatory notices, procurement determinations, or public authority decisions.

2.12.9(g) Where public authority ambiguity arises, GCRI Canada shall adopt the most protective interpretation and clarify the record.

2.12.9(h) Public authority learning distinctness shall protect public authorities from misdescription and protect GCRI Canada from authority inflation.

2.12.9(i) No urgency, crisis, emergency relevance, public attention, or public authority request shall convert GCRI Canada into a delegated public authority absent lawful authority and records-valid designation consistent with this Charter.

2.12.10 Support Distinct From Control. 2.12.10(a) Support is distinct from control. Sponsors, donors, funders, providers, hosts, universities, public authorities, communities, technical contributors, platforms, model providers, media actors, and partners may support GCRI Canada’s mission, but support shall not confer control over evidence, methods, publications, public authority access, public claims, correction, repositories, technical baselines, public-safe language, or institutional meaning.

2.12.10(b) Support may include money, in-kind contributions, cloud credits, software access, AI model access, data access, tools, facilities, expertise, hosting, technical integrations, public authority participation, event support, media access, and personnel contributions.

2.12.10(c) No support shall purchase priority treatment, preferred-provider status, public authority access, publication veto, method control, evidence selection, reviewer selection, finance-readiness implication, procurement advantage, certification implication, recognition implication, protocol entitlement, correction suppression, or public-good ownership.

2.12.10(d) GCRI Canada may acknowledge support in accurate, public-safe, role-bounded terms, but acknowledgment shall not imply endorsement, ownership, certification, recognition, adoption, public authority approval, finance-readiness, procurement preference, technical superiority, or control.

2.12.10(e) Sponsor and provider references shall be reviewed for public meaning. Logos, quotes, case studies, event materials, repository references, public authority proximity, dashboard references, and Academy materials shall not create false authority.

2.12.10(f) Support arrangements shall preserve publication independence, correction independence, data rights, public-safe publication, provider neutrality, sponsor non-control, public authority clarity, finance boundaries, competition safety, and legal separateness.

2.12.10(g) Where support creates dependency, concentration risk, public perception risk, technical control risk, sponsor influence, provider advantage, public authority confusion, finance overclaim, or capture risk, GCRI Canada shall impose safeguards or refuse the support.

2.12.10(h) Support that cannot be separated from control shall be refused, narrowed, returned, terminated, or publicly clarified as appropriate.

2.12.10(i) GCRI Canada shall preserve the principle that public-good truth may be supported but not bought.

2.12.11 Local Truth Distinct From Global Abstraction. 2.12.11(a) Local truth is distinct from global abstraction. GCRI Canada shall preserve local law, local evidence, Indigenous knowledge, local knowledge, territorial knowledge, community context, public authority practice, infrastructure reality, linguistic meaning, environmental context, cultural context, and historical vulnerability while supporting global interoperability.

2.12.11(b) Global categories, shared ontology, technical baselines, public-good rails, and Nexus-compatible terms shall not flatten or erase local meaning.

2.12.11(c) Local truth may be essential to accurate interpretation. A risk signal, infrastructure dependency, public authority practice, community safeguard, Indigenous protocol, data restriction, or environmental condition may have meaning that cannot be safely generalized.

2.12.11(d) GCRI Canada shall use controlled vocabulary, equivalence notes, divergence logs, localization notes, jurisdictional tags, context records, and public-safe summaries to preserve local truth while enabling responsible comparison and interoperability.

2.12.11(e) Where global categories do not fit local evidence, GCRI Canada shall create appropriate mappings rather than distort the evidence.

2.12.11(f) Where local evidence cannot be publicized safely, GCRI Canada shall preserve public-benefit accountability through controlled records, public-safe summaries, redaction, aggregation, restricted access, or non-public archival.

2.12.11(g) Localization shall not become fragmentation. Local adaptation shall remain connected to the common rail through records, controlled vocabulary, and compatibility notes.

2.12.11(h) Global interoperability shall not justify unlawful transfer, unsafe disclosure, public authority overclaim, Indigenous protocol violation, community exposure, or protected knowledge misuse.

2.12.11(i) GCRI Canada shall preserve Canada-to-global and global-to-Canada evidence translation in a manner that respects sovereignty, law, context, safeguards, and correctionability.

2.12.12 Public-Good Software Distinct From Vendor Preference. 2.12.12(a) Public-good software is distinct from vendor preference. GCRI Canada may develop, maintain, release, adapt, or govern software, APIs, dashboards, data tools, reference implementations, test harnesses, evaluation harnesses, scripts, schemas, and workflow tools for public-benefit purposes, but such software shall not create preferred-provider status by default.

2.12.12(b) Use of, contribution to, compatibility with, integration into, or visibility within GCRI Canada public-good software shall not imply endorsement, procurement preference, certification, public authority approval, finance-readiness, market ranking, or technical superiority.

2.12.12(c) Public-good software shall be provider-neutral, sponsor-neutral, secure, versioned, licensed, documented, maintained where relied upon, and correctionable.

2.12.12(d) GCRI Canada shall not permit public-good software to become a vendor funnel, sponsor-branded product, hidden commercial channel, procurement filter, or provider-marketing surface.

2.12.12(e) Reference implementations shall be described as reference implementations, not mandatory products or preferred vendor routes.

2.12.12(f) Test harnesses and evaluation tools shall identify what they test, what they do not test, what assumptions they use, what data they require, and what conclusions may or may not be drawn. Passing a test shall not create certification, recognition, public authority approval, procurement approval, finance-readiness, protocol effect, or provider endorsement by default.

2.12.12(g) Where public-good software relies on third-party tools, models, APIs, cloud environments, libraries, or platforms, GCRI Canada shall preserve dependency records, licensing clarity, security review, public claims limits, and exit readiness.

2.12.12(h) Provider references in software documentation, release notes, examples, integrations, screenshots, or public materials shall be reviewed to prevent implied preference.

2.12.12(i) Misuse of public-good software to claim vendor preference shall be corrected, restricted, or refused.

2.12.13 Technical Baselines Distinct From Certification by Default. 2.12.13(a) Technical baselines are distinct from certification by default. GCRI Canada may produce technical baselines, reference architectures, method profiles, evidence-quality baselines, interoperability profiles, secure release patterns, AI-governance patterns, observability patterns, data-handling profiles, and public-safe implementation guidance, but such outputs shall not certify compliance unless a separate lawful certification program is created by competent authority and records-valid process.

2.12.13(b) A technical baseline may describe expectations, good practices, public-good architecture, evidence requirements, security controls, documentation requirements, or interoperability structures, but it shall not by itself approve technology, certify an actor, recognize maturity, create procurement preference, establish finance-readiness, confer public authority approval, or create protocol entitlement.

2.12.13(c) Technical baselines shall carry status, scope, version, assumptions, limitations, intended users, prohibited interpretations, public-safe status, dependency notes, and correction pathways where material.

2.12.13(d) Public materials shall not use baseline language in a manner that implies certification. Terms such as “certified,” “approved,” “compliant,” “authorized,” “recognized,” “mature,” “official,” or equivalent status language shall be used only where competent authority has attached such effect.

2.12.13(e) Conformance-supporting instruments may support later review by competent actors, but shall not themselves create conformance status with external force by default.

2.12.13(f) Where a baseline is adopted by another institution or authority, that adoption shall be separately recorded, scoped, versioned, and governed by the adopting actor.

2.12.13(g) GCRI Canada shall correct any use of technical baselines that implies certification, public authority approval, procurement preference, finance-readiness, provider endorsement, protocol effect, or execution authority beyond the record.

2.12.13(h) Technical-baseline discipline shall preserve the value of open public-good guidance while preventing false reliance.

2.12.14 AI Outputs Distinct From Authority. 2.12.14(a) AI outputs are distinct from authority. AI-generated summaries, classifications, recommendations, scores, rankings, translations, anomaly detections, risk flags, confidence estimates, dashboards, maps, model outputs, or draft analyses shall not constitute institutional authority by themselves.

2.12.14(b) AI may assist GCRI Canada in evidence processing, retrieval, summarization, translation, classification, anomaly detection, model comparison, gap identification, and drafting, but AI shall not decide truth, recognition, maturity, finance-readiness, certification, procurement, public authority action, protocol effect, public warning, or execution.

2.12.14(c) AI-assisted outputs shall be subject to human review, source discipline, model governance, inference records where material, classification rules, public-safe review, privacy controls, cybersecurity controls, controlled vocabulary, limitation disclosure, and correction pathways.

2.12.14(d) AI fluency, confidence, speed, or apparent precision shall not substitute for evidence, method, record, or competent authority.