XII. RESEARCH
12.1 Research Integrity Purpose
12.1.1 Research Integrity as a Constitutional Mission Requirement of GCRI Canada. 12.1.1(a) Research integrity shall be a constitutional mission requirement of GCRI Canada and shall govern all research, public-benefit R&D, technical inquiry, evidence development, method development, observability work, ontology work, public-good software development, Open Technical Baseline development, public-safe publication, and research-facing Nexus interface activity conducted by or through GCRI Canada.
12.1.1(b) Research integrity shall be treated as a public-benefit duty, not merely an academic convention, publication standard, grant condition, reputational practice, or discretionary professional norm. It shall be a condition of GCRI Canada’s legitimacy as a Canadian public-benefit evidence, methods, observability, ontology, technical-truth, public-good R&D, public-good software, and open technical baseline steward.
12.1.1(c) Research integrity shall require that GCRI Canada’s research activities be accurate, honest, methodologically disciplined, source-lineage-aware, conflict-managed, classification-aware, public-safe, legally bounded, reproducible where appropriate, challengeable where appropriate, and correctionable always.
12.1.1(d) Research integrity shall apply before publication, during research, after publication, during public-safe communication, during technical release, during evidence pack creation, during dashboard or map preparation, during AI-assisted work, during Observatory or Truth Engine work, and during any downstream interface where research meaning may be relied upon.
12.1.1(e) The controlling rule shall be that GCRI Canada’s research integrity exists to protect public-good truth from distortion by informality, speed, prestige, sponsorship, provider influence, public authority ambiguity, finance narrative, media compression, AI output, or execution pressure.
12.1.2 Research Integrity as Accuracy, Honesty, Methodological Discipline, Source Lineage, Transparency With Lawful Protection, Conflict Management, Reproducibility Where Appropriate, and Correctionability. 12.1.2(a) Research integrity shall include accuracy, honesty, methodological discipline, source lineage, transparency with lawful protection, conflict management, reproducibility where appropriate, replication where appropriate, challengeability where appropriate, public-safe communication, and correctionability.
12.1.2(b) Accuracy shall require that research claims, evidence summaries, technical findings, dashboards, maps, model outputs, AI-assisted outputs, public-safe summaries, and technical baselines be supported by records, source lineage, methods, limitations, uncertainty treatment, and review appropriate to their use.
12.1.2(c) Honesty shall require that GCRI Canada not suppress negative results, omit material limitations, conceal uncertainty, overstate maturity, inflate confidence, disguise sponsor or provider influence, misstate public authority involvement, or present preliminary findings as established conclusions.
12.1.2(d) Methodological discipline shall require recorded research questions, methods, assumptions, scope, exclusions, limitations, sampling logic, data quality treatment, model treatment, evaluation logic, reproducibility treatment, and correction pathways.
12.1.2(e) Source lineage shall require that research outputs identify, preserve, classify, and protect the provenance, custody, permissions, limitations, confidence, uncertainty, and public-safe status of evidence sources.
12.1.2(f) Transparency with lawful protection shall require that GCRI Canada be as open as public-safe, lawful, rights-respecting, cybersecurity-safe, public-authority-safe, protected-knowledge-safe, and mission-compatible conditions permit.
12.1.2(g) Conflict management shall require disclosure, review, mitigation, recusal, boundary language, or refusal where sponsors, providers, hosts, public authorities, funders, donors, capital readers, researchers, contributors, or other actors may influence or appear to influence research meaning.
12.1.2(h) Correctionability shall require that research records, findings, methods, outputs, publications, dashboards, maps, datasets, model records, AI outputs, public-safe summaries, and technical assets be correctable, supersedable, withdrawable, retractable, archivable, and publicly or controlledly noticed where required.
12.1.2(i) The controlling rule shall be that research integrity is not satisfied by good intent; it requires record-valid disciplines that make truth reviewable and correction possible.
12.1.3 Research Integrity as Distinct From Advocacy, Marketing, Sponsor Narrative, Provider Claim, Public Authority Position, Capital Narrative, or Media Framing. 12.1.3(a) GCRI Canada research shall remain distinct from advocacy, marketing, sponsor narrative, provider claim, public authority position, capital narrative, media framing, event messaging, fundraising language, project promotion, procurement narrative, or public relations positioning.
12.1.3(b) Research outputs shall not be drafted, framed, edited, suppressed, accelerated, delayed, labeled, visualized, translated, mapped, dashboarded, summarized, or released for the purpose of serving sponsor visibility, provider preference, public authority optics, finance momentum, media simplicity, political convenience, event timing, or institutional self-promotion.
12.1.3(c) GCRI Canada may communicate research in public-safe, accessible, policy-relevant, technically useful, or decision-supportive formats, provided that such communication does not convert research into advocacy, official public authority position, finance recommendation, certification, recognition, procurement preference, provider endorsement, sponsor validation, public warning, emergency command, or execution instruction.
12.1.3(d) Where research findings are relevant to public policy, public authority learning, finance-readiness evidence inputs, provider participation, sponsor support, community safeguards, or Nexus interfaces, GCRI Canada shall preserve the boundary between evidence and downstream authority.
12.1.3(e) Research communications shall identify limitations, uncertainty, conflicts, sponsor and provider roles where material, public authority capacity where material, finance-boundary language where material, and correction path.
12.1.3(f) The controlling rule shall be that research may inform public-good understanding, but it shall not become advocacy, marketing, public authority position, finance signal, or execution mandate by framing.
12.1.4 Research Integrity as Applicable to Public-Benefit R&D, Technical Prototyping, Evidence Packs, Decision Packs, Public-Good Software, Dashboards, Maps, Model Outputs, AI-Assisted Research, Observatory Outputs, Truth Engine Outputs, and Public-Safe Publications. 12.1.4(a) Research integrity shall apply to all public-benefit R&D, technical prototyping, evidence packs, decision packs, public-good software, Open Technical Baselines, reference architectures, dashboards, maps, model outputs, AI-assisted research, Observatory outputs, Truth Engine outputs, datasets, benchmarks, evaluation harnesses, public-safe publications, controlled annexes, restricted annexes, and technical notes.
12.1.4(b) Technical prototypes shall be treated as research and method-supporting artifacts unless separately approved for another status. A prototype shall not be represented as a product, managed service, operational system, certification tool, procurement tool, market infrastructure, public authority system, or execution platform by default.
12.1.4(c) Evidence packs and decision packs shall preserve source lineage, method basis, assumptions, limitations, confidence, uncertainty, classification, public-safe status, boundary language, and correction path. A decision pack shall not make GCRI Canada the decision-maker unless a separate lawful authority expressly provides otherwise.
12.1.4(d) Public-good software and technical baselines shall be developed and released under research integrity, secure release, IP, licensing, cybersecurity, repository, public-safe publication, and anti-enclosure controls.
12.1.4(e) Dashboards, maps, Observatory outputs, Truth Engine outputs, model outputs, and AI-assisted outputs shall not be treated as authority merely because they are visual, automated, computational, real-time, cryptographically anchored, or technically sophisticated.
12.1.4(f) Public-safe publications shall reflect the underlying research record and shall not amplify confidence, hide limits, expose restricted information, or imply downstream authority beyond the record.
12.1.4(g) The controlling rule shall be that research integrity follows the output wherever research becomes a record, tool, visualization, model, publication, or interface.
12.1.5 Research Integrity as Protection Against Hype, Capture, False Maturity, False Precision, Selective Evidence, Publication Suppression, and Uncorrected Error. 12.1.5(a) Research integrity shall protect GCRI Canada against hype, capture, false maturity, false precision, selective evidence, publication suppression, correction avoidance, and institutional drift.
12.1.5(b) Hype shall include overstating readiness, impact, reliability, maturity, scalability, public authority relevance, finance relevance, provider capability, sponsor contribution, AI capability, digital twin fidelity, dashboard completeness, proof receipt meaning, or Nexus compatibility beyond the record.
12.1.5(c) Capture shall include sponsor, donor, funder, provider, host, public authority, capital-reader, media, political, founder, platform, vendor, or institutional pressure that shapes research questions, methods, evidence selection, findings, publication timing, public-safe summaries, corrections, technical baselines, or public claims contrary to research integrity.
12.1.5(d) False maturity shall include presenting pilots, prototypes, early evidence, partial baselines, dashboard displays, limited benchmarks, provider demonstrations, or public authority participation as readiness, recognition, finance-readiness, certification, public authority approval, procurement approval, or execution capacity.
12.1.5(e) False precision shall include presenting uncertain, incomplete, model-derived, AI-generated, simulated, estimated, low-confidence, or context-limited findings as more exact, reliable, universal, or actionable than the record supports.
12.1.5(f) Selective evidence shall include omitting contrary evidence, failed tests, negative results, source limitations, disputed evidence, community objections, public authority limits, sponsor roles, provider roles, data gaps, model limitations, or uncertainty in order to strengthen a preferred narrative.
12.1.5(g) Publication suppression shall include delaying, weakening, withholding, or altering research outputs or corrections because of sponsor concern, provider concern, public authority discomfort, finance timing, media optics, institutional embarrassment, or event scheduling.
12.1.5(h) The controlling rule shall be that research integrity shall protect GCRI Canada not only from falsehood, but from polished overstatement that functions as falsehood.
12.1.6 Research Integrity as Applicable Across All Exponential and Mission-Critical Technology Domains. 12.1.6(a) Research integrity shall apply across all exponential, mission-critical, public-benefit, resilience-relevant, and systemic-risk-relevant technology domains within GCRI Canada’s scope.
12.1.6(b) Such domains include artificial intelligence, machine learning, foundation models, agentic AI, AI governance, AI assurance, AI safety, AI-RAN, O-RAN, private wireless, telecommunications, DePIN, blockchain, distributed ledger technology, Web3, proof infrastructure, sovereign compute, edge compute, cloud compute, high-performance computing, confidential computing, cybersecurity, cyber-physical systems, operational technology, digital twins, simulation, sensors, Earth observation, satellite systems, geospatial systems, robotics, drones, autonomous systems, quantum-relevant systems, cryptography, biosecurity, health-sensitive systems, climate, nature, biodiversity, disaster, wildfire, flood, water, energy, food, WEFH systems, semiconductors, advanced manufacturing, supply chains, ports, corridors, remote communities, Arctic and Northern contexts, and strategic infrastructure.
12.1.6(c) Research integrity shall be technology-neutral in its constitutional requirements and technology-specific in its safeguards, methods, classifications, and public-safe controls.
12.1.6(d) Emerging technologies shall be brought within research integrity controls by analogy where no specific policy yet exists, applying the most protective and mission-compatible interpretation until a specific method, baseline, policy, or safeguard profile is adopted.
12.1.6(e) The controlling rule shall be that no technology domain is too novel, urgent, complex, strategic, or commercially attractive to be exempt from research integrity.
12.1.7 Research Integrity as Compatible With Public Authority Learning but Not Public Authority Substitution. 12.1.7(a) GCRI Canada research may support public authority learning, evidence literacy, technical literacy, AI literacy, cyber literacy, risk literacy, public-safe interpretation, and capacity-classified public authority review.
12.1.7(b) Research integrity requires that public authority participation, attendance, data contribution, listening, review, comment, or learning be classified and described accurately and not be represented as endorsement, adoption, approval, regulation, procurement approval, funding approval, public finance approval, official guidance, public warning, emergency command, public safety order, public health order, sovereign obligation, or public-law status.
12.1.7(c) GCRI Canada shall not substitute its research for lawful public authority decision-making, public warning, emergency management, procurement, regulation, funding, enforcement, permitting, licensing, public finance, or sovereign action.
12.1.7(d) Research outputs shared with public authorities shall include public authority boundary language, capacity classification, limitations, public-safe status, and correction path where material.
12.1.7(e) The controlling rule shall be that research may help public authorities learn, but shall not become public authority action by proximity.
12.1.8 Research Integrity as Compatible With Finance-Readiness Evidence Inputs but Not Financial Advice or Capital Execution. 12.1.8(a) GCRI Canada research may support finance-readiness evidence inputs, GRA proof-pack discipline, capital readability, diligence gap identification, risk evidence, public finance reader learning, and capital-reader understanding where properly classified, bounded, and recorded.
12.1.8(b) Research integrity requires that finance-facing evidence inputs be distinguished from investment advice, securities solicitation, brokerage, underwriting, lending, insurance placement, rating, guarantee, public finance approval, capital commitment, finance-readiness determination, project approval, or financial execution.
12.1.8(c) Research outputs used in finance-facing contexts shall include finance-boundary language, classification, source lineage, assumptions, limitations, confidence, uncertainty, sponsor and provider role disclosures where material, public-safe status, and correction path.
12.1.8(d) GCRI Canada shall not alter research questions, methods, evidence selection, findings, public-safe summaries, or correction decisions to satisfy investor expectations, lender requirements, insurance narratives, sponsor timelines, capital-reader preferences, or project finance narratives.
12.1.8(e) The controlling rule shall be that finance-readable research may inform capital readers, but GCRI Canada shall not become a capital actor.
12.1.9 Research Integrity as Compatible With Open Technical Baselines but Not Certification by Default. 12.1.9(a) GCRI Canada research may support Open Technical Baselines, reference architectures, interoperability profiles, technical notes, evaluation harnesses, benchmark methods, schemas, APIs, data contracts, public-good software, secure release methods, and public-good technical assets.
12.1.9(b) Research integrity requires that Open Technical Baselines and related technical outputs be described as public-good reference points, evidence-quality instruments, interoperability supports, or methods supports, not as certification, conformance approval, procurement preference, provider ranking, public authority approval, finance-readiness, protocol effect, operational clearance, infrastructure operation, or execution authority by default.
12.1.9(c) Technical baseline research shall disclose scope, assumptions, dependencies, exclusions, limitations, external standards mapping where appropriate, public-safe status, version, review status, known issues, and correction path.
12.1.9(d) Benchmarking and evaluation research shall distinguish comparability from ranking, test performance from certification, benchmark success from procurement advantage, and technical demonstration from market or public authority approval.
12.1.9(e) The controlling rule shall be that research may produce strong technical baselines without creating certification unless a separate competent authority creates certification.
12.1.10 Research Integrity as Subject to Board, Committee, Officer, and Research-Leadership Oversight. 12.1.10(a) Research integrity shall be subject to oversight by the Board, applicable committees, officers, research leadership, technical stewards, public-safe publication authorities, data governance authorities, cybersecurity authorities, safeguards authorities, and other authorized roles according to the Charter, bylaws, policies, delegations, and approved records.
12.1.10(b) Oversight shall include approval of research agenda where required, protocol approval where required, conflict review, sponsor and provider influence review, public authority boundary review, finance-boundary review, data and AI review, cybersecurity review, ethics or community review where applicable, public-safe publication review, correction review, and assurance.
12.1.10(c) Research leadership shall preserve methodological independence and shall escalate material integrity risks, boundary risks, public-safe risks, sponsor or provider influence risks, public authority risks, finance risks, AI risks, data risks, cybersecurity risks, protected knowledge risks, and correction failures.
12.1.10(d) Board and committee oversight shall not convert directors or committees into authors, researchers, public authorities, finance actors, certification bodies, or execution actors unless a separate lawful record expressly creates a role within permitted boundaries.
12.1.10(e) The controlling rule shall be that research integrity requires accountable oversight without political, sponsor, provider, finance, or public authority control over truth.
12.2 Research Agenda and Public-Benefit R&D Priorities
12.2.1 Research Agenda as Public-Benefit, Evidence, Methods, Observability, Ontology, Technical Truth, and Systemic De-Risking Agenda. 12.2.1(a) GCRI Canada may maintain a Research Agenda as a public-benefit, evidence, methods, observability, ontology, technical truth, public-good software, Open Technical Baseline, verifiable compute, verifiable intelligence, public-safe publication, and systemic de-risking agenda.
12.2.1(b) The Research Agenda shall identify priority questions, research domains, methods-development needs, evidence gaps, observability gaps, ontology gaps, technical baseline needs, public-good software needs, data governance needs, AI governance needs, cybersecurity needs, public-safe publication needs, community safeguard needs, public authority learning needs, and Nexus interface needs.
12.2.1(c) The Research Agenda shall not be a marketing plan, sponsor-deliverables plan, provider roadmap, political platform, public authority program, finance pipeline, procurement strategy, media calendar, or execution plan.
12.2.1(d) The Research Agenda shall be designed to strengthen institutional evidence before claims, methods before interpretation, records before effect, and correction before reliance.
12.2.1(e) The controlling rule shall be that the Research Agenda shall organize public-good inquiry without becoming a downstream authority or market agenda.
12.2.2 Research Priorities Across AI, AI-RAN, O-RAN, DePIN, Cyber, Sovereign Compute, Digital Twins, Sensors, Geospatial Systems, Climate, WEFH, Biosecurity, Energy, Supply Chains, Infrastructure, Public Trust, and Exponential Technologies. 12.2.2(a) GCRI Canada’s Research Agenda may include priorities across artificial intelligence, agentic AI, AI governance, AI assurance, AI safety, AI-RAN, O-RAN, private wireless, DePIN, blockchain, distributed ledger technology, Web3, cyber, cyber-physical systems, operational technology, sovereign compute, edge compute, confidential computing, digital twins, simulation, sensors, Earth observation, satellite systems, geospatial systems, robotics, drones, autonomous systems, climate, nature, biodiversity, wildfire, flood, disaster, water, energy, food, health, WEFH systems, biosecurity, semiconductors, advanced manufacturing, supply chains, ports, corridors, remote communities, Arctic and Northern systems, strategic infrastructure, public trust, public-safe communication, and other exponential technologies.
12.2.2(b) Research priorities shall be selected for public-benefit relevance, systemic-risk relevance, evidence gap significance, method-development value, observability value, ontology value, technical baseline value, public authority learning value, community safeguard relevance, Nexus interoperability relevance, and correctionability.
12.2.2(c) Research priorities shall not be selected merely because they are commercially attractive, sponsor-preferred, provider-promoted, politically visible, media-friendly, finance-facing, event-aligned, or technology-hyped.
12.2.2(d) Each priority domain shall be subject to appropriate data, AI, cyber, privacy, sovereign data, public authority, export-control, sanctions, controlled-technology, community safeguard, protected knowledge, public-safe publication, and non-execution review.
12.2.2(e) The controlling rule shall be that GCRI Canada may research frontier and mission-critical technologies, but shall do so through public-benefit evidence discipline rather than hype cycles.
12.2.3 Research Agenda Approval Through Records-Valid Process. 12.2.3(a) The Research Agenda shall be approved, amended, renewed, suspended, superseded, withdrawn, or archived through a records-valid process.
12.2.3(b) Research Agenda approval records shall identify approving authority, version, effective date, scope, priorities, excluded areas, limitations, public-safe summary status, sponsor and provider independence review, public authority boundary review, finance-boundary review, data and AI review, cybersecurity review, safeguards review, and correction path.
12.2.3(c) Email, chat, verbal agreement, slides, event plans, sponsor discussions, provider proposals, public authority interest, media requests, or capital-reader interest shall not constitute approval of the Research Agenda unless incorporated into an approved record.
12.2.3(d) Material changes to the Research Agenda shall be versioned and shall identify prior version, successor version, reason for change, public-safe implications, affected research protocols, affected partnerships, affected technical assets, and correction path.
12.2.3(e) The controlling rule shall be that research priorities become institutional priorities only by record.
12.2.4 Research Agenda Alignment With Charter, Bylaw, Mission Lock, Non-Execution, Public-Good Stack Discipline, and Canadian Public-Benefit Purpose. 12.2.4(a) The Research Agenda shall align with GCRI Canada’s Charter, bylaws, mission lock, public-benefit purpose, non-execution posture, public-good stack discipline, legal separateness, Canadian jurisdictional context, and Nexus role separation.
12.2.4(b) No Research Agenda priority shall be adopted where its primary purpose would convert GCRI Canada into a consultancy, vendor, operator, deployment company, fund, broker, underwriter, lender, insurer, rating agency, certifier, recognizer, regulator, procurement body, public authority, public warning authority, emergency command actor, Protocol Authority by default, National Company, Project SPV, provider, market actor, or execution vehicle.
12.2.4(c) Research priorities shall preserve evidence distinct from recognition, technical evidence distinct from finance-readiness, technical baselines distinct from certification, public authority learning distinct from public authority action, sponsor support distinct from sponsor control, provider participation distinct from provider preference, and research outputs distinct from execution.
12.2.4(d) Where a proposed research priority creates execution ambiguity, GCRI Canada shall narrow, redesign, reclassify, route, partner, refuse, quarantine, or hand off the activity through a role-appropriate record.
12.2.4(e) The controlling rule shall be that the Research Agenda must serve the Charter, not expand beyond it.
12.2.5 Research Agenda Independence From Sponsors, Donors, Funders, Providers, Hosts, Public Authorities, Capital Readers, Media, or Political Pressure. 12.2.5(a) The Research Agenda shall remain independent from sponsors, donors, funders, providers, hosts, public authorities, capital readers, media actors, political actors, founders, vendors, platforms, or other external pressure.
12.2.5(b) Support relationships may inform public-benefit needs, evidence gaps, technical realities, community needs, public authority learning needs, or implementation contexts, but shall not control research questions, evidence selection, method selection, findings, publication timing, corrections, technical baselines, public-safe summaries, or public claims.
12.2.5(c) Any sponsor, donor, funder, provider, host, public authority, capital-reader, media, or political interest affecting or appearing to affect a Research Agenda priority shall be disclosed, reviewed, and managed through conflict, independence, public-safe publication, sponsor non-control, provider neutrality, public authority boundary, and finance-boundary controls.
12.2.5(d) GCRI Canada shall not sell, trade, promise, suppress, or tailor research agenda status in exchange for funding, access, equipment, data, compute, public authority participation, media coverage, finance interest, or provider participation.
12.2.5(e) The controlling rule shall be that support may enable research, but shall not own the research agenda.
12.2.6 Research Agenda Treatment of Urgent, Emerging, Frontier, Contested, and High-Risk Topics. 12.2.6(a) The Research Agenda may address urgent, emerging, frontier, contested, and high-risk topics where public-benefit evidence, method development, observability, ontology, public-safe communication, or technical baseline work is needed.
12.2.6(b) Urgency shall not eliminate research integrity. Frontier status shall not eliminate method discipline. Public pressure shall not eliminate public-safe review. Strategic importance shall not eliminate legal, data, AI, cyber, public authority, finance, export-control, sanctions, controlled-technology, community safeguard, or protected knowledge review.
12.2.6(c) Contested topics shall require explicit treatment of uncertainty, competing evidence, source limitations, assumptions, conflicts, community implications, public authority boundaries, finance boundaries, and correction pathways.
12.2.6(d) High-risk topics may require controlled protocols, restricted rooms, staged publication, public-safe summaries, external expert review, Board or committee review, legal review, cybersecurity review, safeguards review, or refusal where safe research cannot be conducted.
12.2.6(e) The controlling rule shall be that urgent and frontier topics require stronger discipline, not weaker discipline.
12.2.7 Research Agenda Review for Privacy, Data Rights, Cybersecurity, Public Authority Boundaries, Export Controls, Sanctions, Controlled Technology, Community Safeguards, and Protected Knowledge. 12.2.7(a) Research Agenda priorities shall be reviewed for privacy, data rights, cybersecurity, public authority boundaries, export controls, sanctions, controlled technology, community safeguards, Indigenous knowledge where applicable, local knowledge, territorial knowledge, health-sensitive data, rights-bearing data, public-safe mapping, and protected knowledge.
12.2.7(b) Review shall identify whether a priority requires data minimization, compute-to-data, sovereign data zones, cross-border transfer controls, no-download rooms, controlled rooms, clean rooms, public authority classification, export-control review, sanctions review, controlled technology review, cybersecurity review, ethics review, community review, or protected knowledge restrictions.
12.2.7(c) Research priorities shall not proceed in a form that would foreseeably expose protected persons, sensitive locations, public authority restricted information, infrastructure vulnerabilities, cyber-sensitive details, finance-sensitive materials, protected knowledge, confidential sources, or rights-bearing data without proper safeguards.
12.2.7(d) Where safeguards cannot be achieved, the priority shall be narrowed, redesigned, deferred, routed to a competent actor, or refused.
12.2.7(e) The controlling rule shall be that research priority selection must consider harms before research begins, not only before publication.
12.2.8 Research Agenda Relationship to Nexus Universe, Nexus Observatory, Nexus Truth Engine, Nexus Risk Management, Nexus Rails, Nexus Grid, and Nexus Academy. 12.2.8(a) The Research Agenda may interface with Nexus Universe, Nexus Observatory, Nexus Truth Engine, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, GRF, GRA, Protocol Authority, National Consortiums, National Companies, Project SPVs, providers, hosts, sponsors, public authorities, universities, and communities.
12.2.8(b) Research Agenda interfaces shall distinguish GCRI Canada research, evidence, methods, observability, ontology, technical baselines, and public-good software from GRF recognition, GRA finance-readiness, Protocol Authority effect, Nexus Network operations, Nexus Universe convening, Nexus Rails finance routing, Nexus Grid maturity records, Nexus Academy certification or credentials, National Company execution, Project SPV execution, provider delivery, sponsor support, public authority action, and community consent.
12.2.8(c) Research priorities may support Nexus Observatory methods without making GCRI Canada an infrastructure operator, emergency command actor, public warning authority, or asset owner.
12.2.8(d) Research priorities may support Nexus Rails evidence inputs without making GCRI Canada a financial intermediary, investment adviser, broker, underwriter, lender, insurer, rating agency, guarantor, or capital platform.
12.2.8(e) Research priorities may support Nexus Grid or Academy inputs without creating maturity records, professional certification, licensure, public authority qualification, market credential, or employment credential by default.
12.2.8(f) The controlling rule shall be that Nexus interfaces may shape research relevance, but shall not collapse GCRI Canada’s research role into downstream Nexus functions.
12.2.9 Research Agenda Versioning, Publication, Public-Safe Summary, Supersession, and Correction. 12.2.9(a) The Research Agenda shall be versioned, reviewed, amended, superseded, withdrawn, corrected, or archived through records-valid procedures.
12.2.9(b) Public or public-safe summaries of the Research Agenda may be issued where appropriate and shall identify scope, priorities, limitations, public-benefit rationale, boundary language, sponsor and provider independence language, public authority boundary language, finance-boundary language, public-safe status, and correction path.
12.2.9(c) Research Agenda publication shall not disclose sensitive research topics, public authority restricted interests, cybersecurity-sensitive work, infrastructure vulnerabilities, protected knowledge, community-sensitive topics, finance-sensitive matters, controlled technology, export-control-sensitive topics, sanctions-sensitive matters, or confidential partner information where disclosure would create harm.
12.2.9(d) Supersession shall identify prior agenda version, successor version, effective date, affected research protocols, affected public-safe summaries, affected technical assets, affected partnerships, affected public authority interfaces, affected finance-facing interfaces, and correction path.
12.2.9(e) The controlling rule shall be that the Research Agenda shall be transparent where safe, controlled where necessary, and correctable always.
12.2.10 Research Agenda Records and Annual Renewal. 12.2.10(a) GCRI Canada shall maintain Research Agenda records sufficient to support approval, versioning, independence, public-benefit alignment, risk review, public-safe publication, correction, and assurance.
12.2.10(b) Research Agenda records shall identify agenda version, approval authority, priorities, exclusions, rationale, review records, sponsor and provider independence review, public authority boundary review, finance-boundary review, data and AI review, cybersecurity review, safeguards review, public-safe status, affected protocols, annual review date, and correction path.
12.2.10(c) The Research Agenda should be reviewed annually or on another recorded periodic cycle appropriate to institutional maturity, risk, funding conditions, public-benefit needs, and technology change.
12.2.10(d) Annual renewal shall assess whether priorities remain current, whether emerging risks require new priorities, whether old priorities should be retired, whether safeguards remain adequate, whether public-safe summaries require correction, and whether agenda independence has been preserved.
12.2.10(e) The controlling rule shall be that GCRI Canada’s Research Agenda shall remain living, public-benefit-aligned, and record-valid.
12.3 Research Protocols
12.3.1 Research Protocol Requirement for Material Research Activities. 12.3.1(a) GCRI Canada shall require a research protocol for material research activities, including activities involving significant evidence collection, public-benefit R&D, human or community participation, public authority data, protected knowledge, sensitive data, AI use, cybersecurity-sensitive work, technical prototyping, dashboards, maps, datasets, models, benchmarks, Observatory outputs, Truth Engine outputs, public-good software, Open Technical Baselines, controlled rooms, public-safe publications, or Nexus interfaces.
12.3.1(b) The protocol requirement shall apply before material research begins unless an emergency or urgent research record permits limited preliminary action subject to prompt protocol completion.
12.3.1(c) A research protocol shall not be a mere administrative form. It shall be the record that defines the research question, purpose, scope, methods, data sources, evidence sources, roles, safeguards, reviews, outputs, publication plan, correction plan, and closeout path.
12.3.1(d) Research conducted without a required protocol shall be subject to suspension, restriction, correction, withdrawal, reclassification, ethics review, public-safe review, or refusal of publication.
12.3.1(e) The controlling rule shall be that material research shall not rely on informal intent where protocol discipline is required.
12.3.2 Research Question, Purpose, Scope, Public-Benefit Rationale, Methods, Data Sources, Evidence Sources, Models, Tools, Outputs, and Limitations. 12.3.2(a) A research protocol shall identify the research question, purpose, scope, public-benefit rationale, methods, data sources, evidence sources, models, tools, systems, repositories, compute environments, AI systems, anticipated outputs, limitations, assumptions, exclusions, and correction path.
12.3.2(b) The research question shall be specific enough to guide method selection and evidence review, and bounded enough to prevent overclaim, public authority confusion, finance overclaim, provider preference, sponsor validation, certification implication, protocol implication, or execution implication.
12.3.2(c) The public-benefit rationale shall identify how the research supports evidence quality, methods, observability, ontology, technical truth, public-good software, technical baselines, public-safe publication, public authority learning, community safeguards, systemic de-risking, or Nexus public-good stack interoperability.
12.3.2(d) Methods shall be described with sufficient detail to permit review, challenge, replication where appropriate, public-safe summary where appropriate, and correction. Data and evidence sources shall be classified and linked to source-lineage records.
12.3.2(e) Models and tools shall be identified by version, provider or source where applicable, permitted use, data restrictions, AI-use restrictions, known limitations, cybersecurity considerations, and correction path.
12.3.2(f) Anticipated outputs shall identify whether the research may produce internal records, controlled annexes, restricted annexes, public-safe summaries, technical notes, public reports, dashboards, maps, datasets, software releases, APIs, schemas, technical baselines, evidence packs, decision packs, Academy materials, GRF inputs, GRA inputs, Protocol Authority inputs, or Nexus interface materials.
12.3.2(g) The controlling rule shall be that a research protocol must define the work before the work defines itself through outputs.
12.3.3 Research Roles, Principal Leads, Contributors, Reviewers, Fellows, Advisors, Universities, Providers, Sponsors, Public Authorities, Communities, and Partners. 12.3.3(a) A research protocol shall identify research roles, including principal leads, investigators, contributors, reviewers, fellows, advisors, technical maintainers, data custodians, public-safe reviewers, safeguards reviewers, cybersecurity reviewers, legal reviewers, publication authorities, universities, laboratories, providers, sponsors, public authorities, communities, hosts, partners, GRF interfaces, GRA interfaces, Protocol Authority interfaces, and Nexus interfaces where applicable.
12.3.3(b) Each role shall identify authority, scope, duties, access, confidentiality, conflicts, contribution type, publication rights where any, IP treatment, data access, AI-use permissions, public claims limits, correction duties, and closeout obligations.
12.3.3(c) Sponsor, donor, funder, provider, host, public authority, capital-reader, or media involvement shall be described accurately and shall not be allowed to imply control over research questions, methods, findings, publication, correction, or public-safe summaries.
12.3.3(d) Public authority roles shall be capacity-classified and shall distinguish learning, data contribution, regulator-listening, public finance reading, emergency-management participation, or other roles from approval, endorsement, adoption, procurement, public warning, public finance approval, or sovereign obligation.
12.3.3(e) Community and Indigenous or protected knowledge roles shall include safeguards, consent or non-consent treatment where applicable, attribution or non-attribution, withdrawal, grievance, remedy, and correction pathways.
12.3.3(f) The controlling rule shall be that research roles confer duties and bounded access, not institutional authority by proximity.
12.3.4 Research Ethics, Human-Subjects, Community Review, Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Health-Sensitive Data, and Protected Knowledge Assessment. 12.3.4(a) A research protocol shall assess whether research ethics, human-subjects review, community review, Indigenous knowledge review, local knowledge review, territorial knowledge review, health-sensitive data review, vulnerable population review, protected knowledge review, or other safeguards review is required.
12.3.4(b) The assessment shall consider whether the research involves individuals, communities, protected persons, vulnerable groups, public officials in sensitive roles, confidential sources, whistleblowers, youth, health-sensitive data, rights-bearing data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, sensitive locations, public-safe mapping, or community-protected information.
12.3.4(c) Where review is required by law, policy, university agreement, grant condition, partner requirement, community protocol, Board or committee determination, or risk profile, the research shall not proceed beyond permitted preliminary steps until review conditions are satisfied.
12.3.4(d) The protocol shall identify consent, non-consent, withdrawal, grievance, remedy, challenge, correction, attribution, non-attribution, data minimization, accessibility, and do-no-harm requirements where applicable.
12.3.4(e) The controlling rule shall be that research affecting persons, communities, and protected knowledge must be governed before it is conducted, not merely redacted before publication.
12.3.5 Data Governance, Privacy, AI Use, Cybersecurity, Sovereign Data, Cross-Border Transfer, and Secure Collaboration Assessment. 12.3.5(a) A research protocol shall assess data governance, privacy, AI use, cybersecurity, sovereign data, cross-border transfer, compute-to-data, secure collaboration, repository, access, retention, deletion, and publication requirements.
12.3.5(b) The assessment shall identify data classes, lawful or approval basis where applicable, source permissions, purpose limitations, retention, transfer, localization, sovereign data zones, compute environments, AI-use permissions, embedding restrictions, retrieval restrictions, model-use rules, dashboard restrictions, map restrictions, public-safe transformation, and correction path.
12.3.5(c) Cybersecurity assessment shall identify threat model, secure collaboration tools, access controls, encryption where appropriate, repository security, key and token handling, secrets prohibition, vulnerability considerations, secure release controls, incident path, and legal hold implications.
12.3.5(d) Cross-border transfer shall be reviewed for law, classification, public authority restrictions, privacy, cybersecurity, sovereign data, protected knowledge, contractual limits, export controls, sanctions, controlled technology, and conflict-of-law risk.
12.3.5(e) The controlling rule shall be that research data and tools must be governed from intake to archive, not only at publication.
12.3.6 Conflict, Sponsor, Provider, Host, Public Authority, Capital-Reader, and Publication-Independence Assessment. 12.3.6(a) A research protocol shall include conflict, sponsor, provider, host, public authority, capital-reader, media, and publication-independence assessment.
12.3.6(b) The assessment shall identify financial interests, institutional interests, sponsor or donor support, provider contributions, host contributions, equipment, data, compute, platform access, public authority involvement, capital-reader interest, political sensitivity, media interest, personal relationships, prior commitments, and any pressure affecting the research.
12.3.6(c) Conflict management may include disclosure, recusal, independent review, methodology lock, data access controls, publication independence terms, sponsor non-control language, provider-neutrality language, public authority capacity language, finance-boundary language, or refusal.
12.3.6(d) No sponsor, donor, funder, provider, host, public authority, capital reader, media actor, or political actor may receive authority to approve findings, suppress publication, control correction, determine methods, select evidence, veto limitations, or purchase public claims.
12.3.6(e) The controlling rule shall be that research independence must be assessed before influence becomes embedded in the work.
12.3.7 Public-Safe Publication Plan and Controlled Annex Plan. 12.3.7(a) A research protocol shall include a public-safe publication plan and, where appropriate, a controlled annex or restricted annex plan.
12.3.7(b) The public-safe publication plan shall identify anticipated public materials, intended audience, public-safe transformation, review requirements, source-lineage treatment, limitations, uncertainty, sponsor and provider disclosures, public authority reference controls, finance-boundary language, protected knowledge controls, dashboard or map controls, AI-output controls, and correction path.
12.3.7(c) The controlled annex plan shall identify materials that may require restricted or controlled disclosure, including detailed evidence, methods, data, cyber-sensitive information, infrastructure-sensitive information, public authority information, finance-sensitive information, provider or sponsor information, community-protected information, Indigenous or protected knowledge, confidential sources, or legal materials.
12.3.7(d) No research output shall be made public merely because the research protocol anticipated public release. Public release shall still require public-safe review and publication approval.
12.3.7(e) The controlling rule shall be that public-safe publication must be designed before findings are translated into public meaning.
12.3.8 Research Correction Plan, Withdrawal Plan, Retraction Plan, and Archive Plan. 12.3.8(a) A research protocol shall include a correction plan, withdrawal plan, retraction plan, supersession plan where appropriate, dependency plan where appropriate, and archive plan.
12.3.8(b) The correction plan shall identify how factual errors, method errors, source errors, data errors, model errors, AI errors, public-safe defects, public authority misdescription, finance overclaim, provider or sponsor overclaim, protected knowledge issues, cybersecurity issues, or legal boundary issues will be received, reviewed, corrected, noticed, and closed.
12.3.8(c) The withdrawal and retraction plan shall identify conditions requiring immediate hold, suspension, withdrawal, retraction, public-safe notice, controlled notice, dashboard or map removal, dataset restriction, software release quarantine, or public claim correction.
12.3.8(d) The archive plan shall identify retention, archive status, sealed materials, restricted materials, public-safe outputs, legal hold treatment, repository location, and correction path.
12.3.8(e) The controlling rule shall be that research is not complete unless its errors can be found, corrected, and remembered.
12.3.9 Research Protocol Approval, Versioning, Amendment, Suspension, and Closeout. 12.3.9(a) Research protocols shall be approved by the authority appropriate to risk, scope, data class, public authority involvement, finance-facing implications, sponsor or provider involvement, community safeguards, protected knowledge, cybersecurity, technical assets, public-safe publication, and Nexus interfaces.
12.3.9(b) Protocols shall be versioned, and material amendments shall identify changed research questions, methods, sources, data, models, tools, roles, safeguards, conflicts, outputs, publication plans, correction plans, or archive plans.
12.3.9(c) Research shall be suspended where protocol conditions are materially breached, required review is missing, safeguards fail, data use exceeds authorization, public authority boundaries are unclear, sponsor or provider influence compromises independence, cybersecurity risk emerges, protected knowledge risk emerges, or public-safe publication risk becomes material.
12.3.9(d) Closeout shall identify outputs produced, records created, data disposition, publications, public-safe summaries, controlled annexes, restricted annexes, corrections, unresolved issues, archive status, retention, legal hold status, and lessons learned.
12.3.9(e) The controlling rule shall be that research protocols must remain active records throughout research, amendment, suspension, and closeout.
12.3.10 Research Protocol Register. 12.3.10(a) GCRI Canada shall maintain a Research Protocol Register for material research activities.
12.3.10(b) The Research Protocol Register shall identify protocol ID, Case ID, title, research lead, owner, custodian, approval authority, version, status, scope, domain, data classes, AI-use status, public authority involvement, sponsor or provider involvement, ethics or community review status, public-safe publication status, correction plan, withdrawal plan, retraction plan, archive status, and closeout status.
12.3.10(c) The Register shall identify whether a protocol is proposed, approved, active, amended, suspended, completed, closed, withdrawn, archived, sealed, or under legal hold.
12.3.10(d) The Register shall be access-controlled according to classification and may support public-safe summaries where appropriate.
12.3.10(e) The controlling rule shall be that material research shall be findable by protocol record, not dependent on memory or informal files.
12.4 Research Ethics and Human-Subjects / Community Review
12.4.1 Research Ethics as Required Where Research Involves Individuals, Communities, Health-Sensitive Data, Vulnerable Populations, Indigenous or Local Knowledge, Protected Knowledge, Public Authority Data, or High-Risk Contexts. 12.4.1(a) Research ethics review shall be required where research involves individuals, communities, health-sensitive data, rights-bearing data, vulnerable populations, protected persons, Indigenous knowledge where applicable, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, protected knowledge, public authority data, confidential sources, whistleblowers, or high-risk contexts.
12.4.1(b) Research ethics review may be required by law, policy, university agreement, grant condition, partner requirement, community protocol, Board determination, committee determination, funder condition, data agreement, public authority condition, or risk assessment.
12.4.1(c) Ethics review shall assess dignity, consent or non-consent, withdrawal, privacy, data minimization, proportionality, contextual integrity, accessibility, non-retaliation, do-no-harm, community safeguards, public-safe mapping, AI use, publication risk, and correction pathways.
12.4.1(d) Research shall not proceed in a manner that exposes persons, communities, public authority data, protected knowledge, sensitive locations, or vulnerable groups to avoidable harm.
12.4.1(e) The controlling rule shall be that research ethics applies wherever research can affect persons, communities, rights, protected knowledge, or safety.
12.4.2 Human-Subjects Review Where Required by Law, Policy, University Agreement, Grant Condition, Research Partner Requirement, or Board / Committee Determination. 12.4.2(a) Human-subjects review shall be obtained where required by law, policy, university agreement, research partner requirement, grant condition, funder requirement, data agreement, public authority requirement, Board determination, committee determination, or research risk profile.
12.4.2(b) Human-subjects review shall apply to research involving direct participation, interviews, surveys, observation, personal information, health-sensitive data, rights-bearing data, behavioral data, community data, AI-mediated interaction, sensor-derived personal data, geospatial personal risk, or other human-related evidence.
12.4.2(c) Review shall address consent, non-consent where applicable, withdrawal, confidentiality, privacy, data protection, risk minimization, vulnerable participants, accessibility, compensation where any, conflicts, publication, AI use, public-safe outputs, and correction.
12.4.2(d) Where GCRI Canada works with universities, laboratories, public authorities, providers, communities, or other research partners, the protocol shall identify which ethics body or process applies and how GCRI Canada’s own safeguards remain applicable.
12.4.2(e) The controlling rule shall be that human-subjects review shall not be bypassed by re-labeling research as technical work, dashboarding, data analysis, AI evaluation, observability, or public-benefit prototyping.
12.4.3 Community Review Where Research Affects Communities, Indigenous Knowledge, Territorial Knowledge, Cultural Sites, Environmental Knowledge, Protected Knowledge, or Vulnerable Groups. 12.4.3(a) Community review shall be required where research affects communities, Indigenous knowledge where applicable, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, vulnerable groups, remote communities, at-risk communities, sensitive locations, or community-protected information.
12.4.3(b) Community review shall assess consent or non-consent treatment where applicable, withdrawal, grievance, remedy, attribution, non-attribution, public-safe mapping, data governance, AI use, publication, benefit sharing where applicable, contextual integrity, and correction.
12.4.3(c) Community review shall not be reduced to symbolic consultation, public relations, event attendance, or post-hoc approval. It shall be designed to protect safety, dignity, context, and self-determined limits where applicable.
12.4.3(d) Where community review identifies unacceptable harm or non-consent, GCRI Canada shall narrow, redesign, refuse, restrict, seal, withdraw, or refrain from publication as appropriate.
12.4.3(e) The controlling rule shall be that community-facing research must respect community context before it produces institutional evidence.
12.4.4 Consent, Non-Consent, Withdrawal, Grievance, Remedy, and Correction Pathways Where Applicable. 12.4.4(a) Research involving persons, communities, protected knowledge, sensitive data, public authority data, or high-risk contexts shall identify consent, non-consent, withdrawal, grievance, remedy, and correction pathways where applicable.
12.4.4(b) Consent shall be informed, role-appropriate, purpose-specific, documented where required, and subject to limitations, withdrawal conditions, data treatment, publication treatment, AI-use treatment, and correction path.
12.4.4(c) Non-consent, refusal, restriction, or withdrawal shall be respected according to law, ethics, community protocols, data rights, research integrity, and public-safe obligations.
12.4.4(d) Grievance and remedy pathways shall allow affected participants or communities to raise concerns regarding misuse, misdescription, exposure, lack of consent, unsafe mapping, protected knowledge handling, data misuse, publication harm, AI misuse, or correction failure.
12.4.4(e) Correction pathways shall be accessible, non-retaliatory, classified where necessary, public-safe where public meaning is affected, and controlled where sensitive information is involved.
12.4.4(f) The controlling rule shall be that participation in research shall not extinguish the right to challenge unsafe or inaccurate use.
12.4.5 Data Minimization, Proportionality, Contextual Integrity, Dignity, Accessibility, Non-Retaliation, and Do-No-Harm. 12.4.5(a) Research ethics shall require data minimization, proportionality, contextual integrity, dignity, accessibility, non-retaliation, and do-no-harm.
12.4.5(b) Data minimization shall require GCRI Canada to collect, receive, generate, process, retain, publish, map, dashboard, or route only the data reasonably necessary for the recorded public-benefit research purpose.
12.4.5(c) Proportionality shall require that research benefits, evidence value, technical value, public authority learning value, or Nexus interoperability value be balanced against privacy, safety, community, public authority, cybersecurity, protected knowledge, legal, and public harm risks.
12.4.5(d) Contextual integrity shall require that information be used consistently with the context in which it was provided or lawfully obtained, including community expectations, public authority restrictions, participant expectations, data agreements, and safeguards.
12.4.5(e) Dignity shall require respectful treatment of persons and communities and shall prohibit exploitative, stigmatizing, extractive, sensationalized, or decontextualized research framing.
12.4.5(f) Accessibility shall require that research processes and public-safe outputs be accessible where appropriate and not exclude affected persons or communities from understanding, challenge, or correction pathways.
12.4.5(g) Non-retaliation shall protect good-faith participants, communities, researchers, contributors, staff, fellows, advisors, and external actors who raise research integrity concerns.
12.4.5(h) The controlling rule shall be that research must be useful without being extractive, accurate without being harmful, and public-benefit without overriding rights.
12.4.6 Review of Public-Safe Mapping, Geospatial Outputs, Dashboards, AI Outputs, and Public Reports for Harm Risk. 12.4.6(a) Public-safe mapping, geospatial outputs, dashboards, AI outputs, and public reports shall be reviewed for harm risk before release.
12.4.6(b) Harm risk review shall consider re-identification, sensitive-location exposure, infrastructure vulnerability exposure, protected knowledge exposure, community stigma, public authority confusion, public warning confusion, finance overclaim, provider or sponsor overclaim, model error, dashboard misinterpretation, map misuse, AI hallucination, and unsafe public reliance.
12.4.6(c) Public-safe mapping and geospatial outputs shall avoid exposing protected persons, sensitive sites, infrastructure vulnerabilities, community-protected information, Indigenous or protected knowledge, confidential sources, or public authority restricted information.
12.4.6(d) Dashboards shall include limitations, update status, source status, public-safe status, public warning boundary, public authority boundary, confidence, uncertainty, and correction path where material.
12.4.6(e) AI outputs shall be human-reviewed where required and shall not be published as institutional findings unless supported by records, classification, public-safe review, and approval.
12.4.6(f) The controlling rule shall be that visual, automated, and public-facing research outputs require harm review because presentation can create reliance faster than text.
12.4.7 Research Ethics Records, Approvals, Conditions, Amendments, Deviations, Incidents, and Closeout. 12.4.7(a) GCRI Canada shall maintain research ethics records, approvals, conditions, amendments, deviations, incidents, corrective actions, and closeout records where ethics or safeguards review applies.
12.4.7(b) Ethics records shall identify protocol, review authority, review date, scope, conditions, approved materials, participant treatment, community treatment, data treatment, AI-use treatment, public-safe publication treatment, withdrawal treatment, grievance path, correction path, and closeout conditions.
12.4.7(c) Deviations from approved ethics or safeguards conditions shall be recorded, reviewed, corrected, and reported where required.
12.4.7(d) Ethics incidents may require suspension, public-safe notice, controlled notice, withdrawal, retraction, deletion where lawful and required, sealing, grievance response, remedy, or Board or committee reporting.
12.4.7(e) The controlling rule shall be that ethics approval is not a one-time shield; ethics conditions must be recorded, followed, amended, and closed out.
12.4.8 External REB / IRB / Ethics Review Interface Where Applicable. 12.4.8(a) Where research requires or uses external Research Ethics Board, Institutional Review Board, university ethics committee, public authority ethics process, community review process, Indigenous review process where applicable, funder ethics process, or partner review process, GCRI Canada shall record the interface and conditions.
12.4.8(b) External ethics review shall not displace GCRI Canada’s own Charter duties, public-safe publication controls, non-execution boundaries, data governance, AI governance, cybersecurity, public authority boundary discipline, finance-boundary discipline, protected knowledge safeguards, or correctionability unless expressly and lawfully integrated by record.
12.4.8(c) The protocol shall identify which body reviewed what, what conditions apply, what GCRI Canada remains responsible for, what partner is responsible for, what conflicts exist, what publication controls apply, and how corrections are handled.
12.4.8(d) Where external review is absent, incomplete, delayed, or inconsistent with GCRI Canada safeguards, the research shall not proceed beyond permitted scope until the gap is resolved or the activity is redesigned.
12.4.8(e) The controlling rule shall be that external ethics review may support integrity, but GCRI Canada remains responsible for its own public-benefit research discipline.
12.4.9 No Research Publication Where Required Ethics Review Is Missing or Materially Breached. 12.4.9(a) GCRI Canada shall not publish research where required ethics review is missing, materially incomplete, materially breached, expired, exceeded, or contradicted by actual research conduct.
12.4.9(b) Publication shall include public reports, technical notes, research publications, dashboards, maps, datasets, software releases where research-derived, AI outputs, public-safe summaries, controlled annexes, restricted annexes, evidence packs, decision packs, Academy materials, media materials, and Nexus interface materials.
12.4.9(c) Where ethics review is missing or materially breached after publication, GCRI Canada shall consider suspension, correction, withdrawal, retraction, public-safe notice, controlled notice, sealing, deletion where lawful and required, grievance response, remedy, and downstream dependency review.
12.4.9(d) Publication shall not proceed because of sponsor deadlines, provider commitments, public authority interest, event timing, finance timelines, media requests, grant deadlines, or institutional pressure where ethics review is required and unresolved.
12.4.9(e) The controlling rule shall be that ethics review failure blocks publication where publication would convert ethical defect into public meaning.
12.4.10 Correction, Suspension, Withdrawal, or Retraction for Ethics Failures. 12.4.10(a) Ethics failures shall trigger correction, suspension, withdrawal, retraction, restriction, sealing, deletion where lawful and required, grievance response, remedy, public-safe notice, controlled notice, or Board or committee review as appropriate.
12.4.10(b) Ethics failures may include missing review, breached consent, failure to honor withdrawal, unsafe publication, protected knowledge exposure, public-safe mapping failure, inadequate data protection, AI misuse, public authority data misuse, vulnerable participant harm, community misrepresentation, or inadequate grievance handling.
12.4.10(c) Correction shall address both the research record and affected outputs, including publications, dashboards, maps, datasets, models, public-safe summaries, evidence packs, technical baselines, Academy materials, public authority materials, finance-facing materials, provider materials, sponsor materials, and Nexus interfaces.
12.4.10(d) Remedies shall be proportionate to the affected persons, communities, knowledge holders, public authorities, or other stakeholders and may include apology, correction, withdrawal, access restriction, deletion where lawful, revised safeguards, participant notice, community notice, or process redesign.
12.4.10(e) The controlling rule shall be that ethics failures must be repaired in records, outputs, relationships, and safeguards.
12.5 Methodological Integrity
12.5.1 Methodological Integrity as Required for Research, Evidence, Technical Baselines, Dashboards, Maps, AI Outputs, and Public-Safe Communications. 12.5.1(a) Methodological integrity shall be required for research, evidence records, evidence packs, decision packs, public-good software, Open Technical Baselines, reference architectures, evaluation harnesses, benchmark harnesses, dashboards, maps, datasets, models, AI outputs, Observatory outputs, Truth Engine outputs, technical notes, public reports, public-safe summaries, controlled annexes, restricted annexes, and public-safe communications.
12.5.1(b) Methodological integrity shall require that methods be fit for purpose, recorded, versioned, reviewable, challengeable where appropriate, reproducible where appropriate, bounded by assumptions, limited by source quality, classified, public-safe, and correctionable.
12.5.1(c) Methods shall not be selected, altered, weighted, interpreted, visualized, or summarized to achieve sponsor-preferred, provider-preferred, public authority-preferred, finance-preferred, media-preferred, political, or institutional reputation outcomes.
12.5.1(d) Methodological integrity shall distinguish method support from certification, benchmark from ranking, dashboard from public warning, model output from institutional truth, technical baseline from approval, and evidence pack from downstream decision.
12.5.1(e) The controlling rule shall be that research outputs are only as trustworthy as the methods that produced them and the records that bound them.
12.5.2 Method Selection Records. 12.5.2(a) GCRI Canada shall maintain method selection records for material research activities and outputs.
12.5.2(b) Method selection records shall identify the method chosen, purpose, scope, research question, alternatives considered, reason for selection, assumptions, limitations, required data, required evidence, required expertise, validation status, public-safe implications, known failure modes, and correction path.
12.5.2(c) Where a method is experimental, adapted, localized, AI-assisted, model-based, simulation-based, provider-supported, sponsor-supported, public authority-supplied, or derived from external standards, the record shall identify status, provenance, modifications, dependencies, and limits.
12.5.2(d) Method selection shall be reviewed for suitability to the research question and shall not be based solely on convenience, available tools, sponsor preference, provider preference, public authority interest, platform availability, or speed.
12.5.2(e) The controlling rule shall be that methods must be chosen by fit and recorded by reason.
12.5.3 Source Selection Records. 12.5.3(a) GCRI Canada shall maintain source selection records where sources materially affect research findings, evidence packs, dashboards, maps, datasets, models, technical baselines, public-safe summaries, or public claims.
12.5.3(b) Source selection records shall identify source type, source origin, authority, custody, permissions, classification, relevance, reliability, completeness, timeliness, bias, limitations, conflicts, public-safe status, and correction path.
12.5.3(c) Source selection shall include treatment of missing sources, contradictory sources, disputed sources, stale sources, community sources, public authority sources, provider sources, sponsor sources, media sources, AI-generated sources, and model-derived sources where applicable.
12.5.3(d) GCRI Canada shall not select sources to confirm a preferred narrative, sponsor claim, provider claim, public authority position, finance narrative, media framing, or institutional claim.
12.5.3(e) The controlling rule shall be that source selection must be defensible before source interpretation can be trusted.
12.5.4 Sampling, Measurement, Calibration, Validation, Benchmark, and Evaluation Records. 12.5.4(a) GCRI Canada shall maintain sampling, measurement, calibration, validation, benchmark, and evaluation records where material to research outputs.
12.5.4(b) Sampling records shall identify population, frame, inclusion criteria, exclusion criteria, representativeness, limitations, bias risks, missing data, and contextual constraints.
12.5.4(c) Measurement records shall identify variables, instruments, sensors, metrics, units, collection conditions, measurement limits, error ranges, quality controls, and correction path.
12.5.4(d) Calibration and validation records shall identify calibration method, validation set, validation conditions, known limitations, failure modes, drift risks, and review status.
12.5.4(e) Benchmark and evaluation records shall identify benchmark purpose, conditions, test data, metrics, gold vectors, negative tests, adversarial tests, edge cases, limitations, reproducibility, provider participation, sponsor participation, and public-safe interpretation.
12.5.4(f) Benchmarking shall not be represented as ranking, certification, procurement preference, provider endorsement, finance-readiness, public authority approval, protocol effect, or execution authority by default.
12.5.4(g) The controlling rule shall be that measurement and evaluation must be recorded before results become public-good evidence.
12.5.5 Assumption, Limitation, Uncertainty, and Confidence Records. 12.5.5(a) GCRI Canada shall maintain assumption, limitation, uncertainty, and confidence records for material research findings, evidence packs, dashboards, maps, datasets, models, public-safe summaries, technical baselines, and publications.
12.5.5(b) Assumption records shall identify material premises, scope conditions, dependencies, context requirements, exclusions, and conditions under which findings may not hold.
12.5.5(c) Limitation records shall identify data gaps, source gaps, method limitations, model limitations, sampling limits, measurement limits, jurisdictional limits, temporal limits, public-safe restrictions, and publication limits.
12.5.5(d) Uncertainty records shall identify unknowns, confidence ranges where appropriate, competing interpretations, contradictory evidence, sensitivity to assumptions, and unresolved questions.
12.5.5(e) Confidence records shall identify basis for confidence, evidence quality, method strength, source corroboration, reproducibility where applicable, review status, and conditions for downgrade or correction.
12.5.5(f) GCRI Canada shall not remove limitations, uncertainty, or confidence boundaries to make research more persuasive, fundable, media-friendly, sponsor-friendly, provider-friendly, or public authority-friendly.
12.5.5(g) The controlling rule shall be that uncertainty and limitation are integrity features, not communication defects.
12.5.6 Reproducibility and Replication Records Where Appropriate. 12.5.6(a) GCRI Canada shall maintain reproducibility and replication records where appropriate to the research method, data class, public-safe status, technical domain, publication class, and public reliance.
12.5.6(b) Reproducibility records may include data provenance, code version, repository reference, environment specification, dependency versions, model version, prompt or retrieval configuration where material, compute workload, parameters, random seeds where applicable, scripts, evaluation harnesses, benchmark conditions, and public-safe limitations.
12.5.6(c) Replication records may include independent review, repeated runs, alternative methods, external validation, peer review, challenge review, failed replication, partial replication, or non-replicability explanation.
12.5.6(d) Reproducibility shall not require disclosure of restricted data, protected knowledge, public authority restricted information, cyber-sensitive details, infrastructure vulnerabilities, personal data, confidential sources, or controlled technology. Where full reproducibility is unsafe, GCRI Canada may provide controlled reproducibility, synthetic data, aggregate methods, public-safe summaries, or restricted review.
12.5.6(e) The controlling rule shall be that reproducibility shall be pursued where appropriate and bounded where protection requires it.
12.5.7 Negative Results, Failed Inputs, Contradictory Evidence, Missing Data, and Disputed Evidence Treatment. 12.5.7(a) GCRI Canada shall record negative results, failed inputs, contradictory evidence, missing data, disputed evidence, abandoned hypotheses, failed benchmarks, failed model outputs, failed technical tests, and rejected interpretations where material to research integrity.
12.5.7(b) Negative results and failed inputs shall not be suppressed because they weaken sponsor narratives, provider claims, public authority enthusiasm, finance-facing interpretation, event messaging, media simplicity, or internal expectations.
12.5.7(c) Contradictory evidence shall be reviewed, classified, and explained where material, including whether contradiction arises from source error, method difference, temporal change, jurisdictional difference, translation divergence, model limitation, data quality issue, or genuine uncertainty.
12.5.7(d) Missing data shall be identified as a limitation and shall not be silently filled, inferred, synthesized, or AI-generated without disclosure, method record, and review.
12.5.7(e) Disputed evidence shall be treated through challenge records, dissent records where appropriate, confidence treatment, uncertainty treatment, and correction path.
12.5.7(f) The controlling rule shall be that research integrity requires recording what did not work and what remains uncertain, not only what supports the final output.
12.5.8 Sponsor, Provider, Host, Public Authority, and Capital-Reader Influence Review. 12.5.8(a) GCRI Canada shall review sponsor, provider, host, public authority, and capital-reader influence where such actors contribute funding, data, equipment, compute, facilities, access, expertise, public authority participation, finance-facing interest, media visibility, or other support to research.
12.5.8(b) Influence review shall identify whether any actor may affect research question selection, method selection, source selection, data access, evidence weighting, interpretation, publication timing, public-safe summary, technical baseline framing, dashboard design, map design, correction decisions, or public claims.
12.5.8(c) Influence risks shall be mitigated through disclosure, independence controls, recusal, review separation, publication independence terms, sponsor non-control language, provider-neutrality language, public authority capacity language, finance-boundary language, and correction safeguards.
12.5.8(d) GCRI Canada shall not permit sponsor or provider contribution to become method control, evidence control, publication veto, correction veto, public authority access purchase, finance-readiness purchase, recognition purchase, certification implication, or provider preference.
12.5.8(e) The controlling rule shall be that influence must be identified and bounded before it becomes capture.
12.5.9 Method Drift, Model Drift, Dataset Drift, and Version Drift Controls. 12.5.9(a) GCRI Canada shall maintain controls for method drift, model drift, dataset drift, and version drift affecting research outputs, evidence packs, dashboards, maps, datasets, models, technical baselines, AI outputs, public-safe summaries, and Nexus interface materials.
12.5.9(b) Method drift shall include undocumented changes to method assumptions, weighting, metrics, source selection, review criteria, confidence treatment, uncertainty treatment, public-safe transformation, or interpretation.
12.5.9(c) Model drift shall include changes in model behavior, performance, calibration, bias, failure modes, retrieval behavior, prompt behavior, embedding behavior, or output reliability over time.
12.5.9(d) Dataset drift shall include changes in source coverage, data quality, distribution, definitions, labels, missingness, bias, freshness, permissions, or public-safe status.
12.5.9(e) Version drift shall include mismatches among research protocols, methods, datasets, models, software, dashboards, maps, publications, public-safe summaries, technical baselines, repositories, and public claims.
12.5.9(f) Drift controls may include versioning, periodic review, benchmark reruns, recalibration, data quality review, model evaluation, dashboard review, dependency review, public-safe review, correction, supersession, downgrade, withdrawal, or retraction.
12.5.9(g) The controlling rule shall be that research integrity must continue after first release because methods, models, datasets, and versions change over time.
12.5.10 Methodological Correction, Supersession, Withdrawal, and Retraction. 12.5.10(a) GCRI Canada shall correct, supersede, withdraw, or retract methodological records and affected outputs where methods are erroneous, stale, unsupported, misapplied, unsafe, overbroad, unauthorized, misleading, misclassified, affected by drift, or no longer fit for purpose.
12.5.10(b) Methodological correction may require revision of method records, research protocols, evidence packs, public-safe summaries, technical baselines, datasets, models, dashboards, maps, publications, public claims, Academy materials, GRF inputs, GRA inputs, Protocol Authority inputs, and Nexus interface materials.
12.5.10(c) Supersession shall identify predecessor method, successor method, reason, effective date, continuing validity, affected outputs, dependency implications, and correction path.
12.5.10(d) Withdrawal or retraction shall be used where the method defect undermines reliance, creates public-safe risk, public authority confusion, finance overclaim, provider or sponsor overclaim, protected knowledge risk, cybersecurity risk, legal risk, or material research integrity risk.
12.5.10(e) Public-safe or controlled notice shall be issued where affected materials have entered public, external, public authority, finance-facing, provider, sponsor, community, GRF, GRA, Protocol Authority, or Nexus reliance.
12.5.10(f) The controlling rule shall be that when a method changes or fails, all meanings produced by that method must be reviewed for correction.
12.6 Peer Review and Expert Review
12.6.1 Peer Review as Appropriate to Research Risk, Public Impact, Technical Complexity, and Publication Class. 12.6.1(a) GCRI Canada shall require peer review or expert review proportionate to the risk, public impact, technical complexity, public-safe significance, publication class, data sensitivity, public authority relevance, finance-facing relevance, community safeguard relevance, protected knowledge relevance, cybersecurity relevance, and Nexus interface significance of the research activity or output.
12.6.1(b) Peer review may be internal, external, technical, methodological, legal-boundary, public-safe, safeguards, public authority context, finance-boundary, cybersecurity, data governance, community, or mixed review, depending on the nature of the research.
12.6.1(c) Research outputs requiring higher review may include public reports, technical notes, research publications, evidence packs, decision packs, public-safe summaries, dashboards, maps, datasets, model outputs, benchmark results, AI-assisted findings, Observatory outputs, Truth Engine outputs, Open Technical Baselines, public-good software releases, public authority-facing materials, finance-facing materials, GRF inputs, GRA inputs, Protocol Authority inputs, and Nexus interface materials.
12.6.1(d) Peer review shall not convert research into certification, recognition, finance-readiness, public authority approval, procurement approval, provider endorsement, sponsor validation, protocol effect, public warning, emergency command, infrastructure operation, operational clearance, or execution authority by default.
12.6.1(e) The controlling rule shall be that research review must be strong enough for the risk and bounded enough not to become downstream authority.
12.6.2 Internal Peer Review. 12.6.2(a) Internal peer review shall be used where GCRI Canada personnel, fellows, advisors, researchers, technical stewards, method stewards, data stewards, cybersecurity stewards, public-safe reviewers, safeguards reviewers, or other authorized internal reviewers assess research quality, methodological discipline, source lineage, evidence treatment, limitations, public-safe status, conflicts, and correctionability.
12.6.2(b) Internal peer review shall assess whether the research question, methods, sources, assumptions, uncertainty, confidence, data treatment, AI use, model use, technical tools, public-safe treatment, and publication class are appropriate to the stated purpose.
12.6.2(c) Internal peer review shall identify unresolved issues, required amendments, conditions for publication, required corrections, required boundary language, public-safe limitations, dependency concerns, and archive or retention requirements.
12.6.2(d) Internal peer reviewers shall be sufficiently independent from the research preparation where risk warrants independence. Where full independence is not practicable, reviewer involvement and limitations shall be recorded.
12.6.2(e) The controlling rule shall be that internal peer review shall improve institutional reliability without becoming informal approval outside the records system.
12.6.3 External Peer Review. 12.6.3(a) External peer review may be used where research risk, public impact, technical complexity, contested evidence, public authority relevance, finance-facing relevance, community impact, protected knowledge risk, or publication class warrants review beyond GCRI Canada.
12.6.3(b) External reviewers may include academic experts, technical experts, domain experts, safeguards experts, community reviewers, legal or regulatory context experts, cybersecurity experts, data governance experts, public-safe communication experts, standards experts, or other qualified reviewers.
12.6.3(c) External peer review shall be governed by confidentiality, conflict disclosure, data handling, AI-use limits, protected knowledge safeguards, public authority restrictions, IP terms, publication limits, and correction obligations.
12.6.3(d) External peer review shall not give the reviewer or reviewer institution control over research findings, publication, correction, technical baselines, public-safe summaries, public claims, sponsor acknowledgments, provider references, public authority references, or Nexus interface materials unless a separate lawful record grants a bounded role.
12.6.3(e) The controlling rule shall be that external peer review may strengthen research credibility, but shall not transfer GCRI Canada’s institutional responsibility or authority.
12.6.4 Expert Technical Review. 12.6.4(a) Expert technical review shall be required where research involves complex, high-risk, safety-relevant, cybersecurity-relevant, infrastructure-relevant, AI-relevant, data-intensive, model-dependent, benchmark-dependent, software-dependent, geospatial, AI-RAN, O-RAN, DePIN, sovereign compute, digital twin, simulation, sensor, or technical baseline matters requiring specialized competence.
12.6.4(b) Expert technical review shall assess architecture, assumptions, methods, implementation, interoperability, dependency, security, benchmark design, model behavior, data quality, measurement quality, reproducibility, failure modes, known limitations, public-safe implications, and correction path.
12.6.4(c) Expert technical review of public-good software, technical baselines, APIs, schemas, datasets, models, dashboards, maps, repositories, and releases shall include secure release, repository integrity, dependency, SBOM where material, vulnerability, IP, license, public-safe, and anti-enclosure considerations.
12.6.4(d) Technical review shall distinguish technical sufficiency within scope from certification, conformance, public authority approval, finance-readiness, provider preference, sponsor validation, protocol effect, operational clearance, infrastructure operation, or execution authority.
12.6.4(e) The controlling rule shall be that expert technical review may validate method and technical soundness within scope, but shall not create status beyond the reviewed record.
12.6.5 Community Review. 12.6.5(a) Community review shall be required where research affects communities, Indigenous knowledge where applicable, local knowledge, territorial knowledge, cultural sites, environmental knowledge, vulnerable groups, remote communities, at-risk communities, public-safe mapping, protected knowledge, community-protected information, or community-facing public meaning.
12.6.5(b) Community review shall assess contextual integrity, dignity, consent or non-consent treatment where applicable, withdrawal, grievance, remedy, attribution, non-attribution, public-safe mapping, data governance, AI use, dashboard treatment, publication risk, and correction pathways.
12.6.5(c) Community review shall not be symbolic consultation, media participation, event attendance, post-hoc validation, or extraction of legitimacy. It shall be a safeguards process designed to identify harm, misdescription, exposure, and correction needs.
12.6.5(d) Where community review identifies unacceptable risk, non-consent, unsafe mapping, protected knowledge exposure, or misrepresentation, GCRI Canada shall narrow, redesign, restrict, seal, withdraw, reclassify, or refrain from publication as appropriate.
12.6.5(e) The controlling rule shall be that community review protects persons, places, knowledge, and context before research becomes public-good evidence.
12.6.6 Public Authority Context Review Where Appropriate. 12.6.6(a) Public authority context review may be used where research concerns public authority data, public authority participation, regulator-listening, public finance reader participation, emergency-management learning, public infrastructure learning, public health learning, public safety learning, public authority references, or public authority-facing outputs.
12.6.6(b) Public authority context review shall assess capacity classification, data contribution status, reference permissions, public-safe status, confidentiality, public authority duties, public warning boundaries, emergency command boundaries, procurement boundaries, funding boundaries, public finance boundaries, and no-delegation language.
12.6.6(c) Public authority context review shall not create public authority endorsement, adoption, approval, official guidance, regulatory determination, procurement approval, funding approval, public finance approval, public warning, emergency command, sovereign obligation, or public-law status.
12.6.6(d) Where public authority context review identifies misdescription or overclaim, the research output shall be corrected, narrowed, relabeled, restricted, or accompanied by boundary language.
12.6.6(e) The controlling rule shall be that public authority context review clarifies context without converting research into public authority action.
12.6.7 Legal, Privacy, Cybersecurity, Public-Safe, Finance-Boundary, Public Authority Boundary, and Safeguards Review. 12.6.7(a) Research shall undergo legal, privacy, cybersecurity, public-safe, finance-boundary, public authority boundary, and safeguards review where required by risk, law, policy, protocol, publication class, data class, public authority involvement, finance-facing relevance, protected knowledge, or Nexus interface.
12.6.7(b) Legal review shall assess corporate authority, nonprofit status, non-execution, professional boundaries, regulated perimeter, IP, licensing, contracts, liability, sanctions, export controls, controlled technology, public claims, and role separation.
12.6.7(c) Privacy and data governance review shall assess lawful or approval basis where applicable, purpose limitation, minimization, classification, retention, transfer, AI use, publication, deletion, sealing, archive, and correction.
12.6.7(d) Cybersecurity review shall assess secure collaboration, repository security, access controls, secrets handling, vulnerability exposure, infrastructure-sensitive information, secure release, incident response, and public-safe technical disclosure.
12.6.7(e) Finance-boundary review shall prevent research outputs from being treated as investment advice, securities solicitation, brokerage, underwriting, lending, insurance, rating, guarantee, public finance approval, capital commitment, finance-readiness, or financial execution.
12.6.7(f) Public authority boundary review shall prevent public authority attendance, review, comment, data contribution, or learning from being misdescribed as endorsement, adoption, approval, procurement approval, public warning, emergency command, official guidance, or sovereign obligation.
12.6.7(g) Safeguards review shall protect communities, protected persons, sensitive locations, Indigenous or protected knowledge, local knowledge, territorial knowledge, vulnerable groups, confidential sources, whistleblowers, dignity, accessibility, grievance, remedy, withdrawal, and correction.
12.6.7(h) The controlling rule shall be that research review must examine not only whether findings are correct, but whether publication and reliance would be lawful, safe, bounded, and correctionable.
12.6.8 Reviewer Qualifications, Independence, Conflicts, Confidentiality, and Recusal. 12.6.8(a) Reviewers shall be selected based on qualifications, independence, subject-matter competence, methodological competence, safeguards competence, technical competence, legal or contextual competence where applicable, and ability to review within classification and confidentiality requirements.
12.6.8(b) Reviewer qualifications shall be proportionate to the research risk and may include academic expertise, technical expertise, field experience, community knowledge, public authority context knowledge, cybersecurity competence, data governance competence, AI competence, legal-boundary competence, or public-safe communication competence.
12.6.8(c) Reviewers shall disclose conflicts, including financial, institutional, sponsor, provider, host, public authority, capital-reader, publication, professional, personal, political, competitive, or reputational conflicts.
12.6.8(d) Reviewers shall be recused, restricted, paired with independent reviewers, or subject to mitigation where conflicts may affect independence or appearance of independence.
12.6.8(e) Reviewers shall comply with confidentiality, classification, no-download, AI-use, public claims, IP, data, cybersecurity, protected knowledge, and public-safe restrictions.
12.6.8(f) The controlling rule shall be that reviewer competence and independence must be recorded because review quality depends on who reviewed and under what constraints.
12.6.9 Minority Views, Dissent Notes, Reviewer Conditions, and Unresolved Disputes. 12.6.9(a) GCRI Canada shall record material minority views, dissent notes, reviewer conditions, unresolved disputes, unresolved uncertainty, methodological disagreement, source disagreement, public-safe disagreement, safeguards disagreement, technical disagreement, public authority boundary disagreement, finance-boundary disagreement, and legal-boundary disagreement where such matters affect reliance.
12.6.9(b) Minority views and dissent notes shall not be suppressed merely because they complicate publication, weaken sponsor narratives, challenge provider claims, delay finance-facing materials, complicate public authority engagement, reduce media clarity, or create internal discomfort.
12.6.9(c) Reviewer conditions shall be tracked and resolved, accepted with limitations, escalated, or recorded as unresolved before publication or release.
12.6.9(d) Where unresolved disputes materially affect public meaning, GCRI Canada shall disclose uncertainty at a public-safe level, narrow conclusions, downgrade confidence, delay publication, issue controlled annexes, or refrain from release.
12.6.9(e) The controlling rule shall be that disagreement is part of research integrity when it is recorded, bounded, and carried into reliance decisions.
12.6.10 Peer Review Records, Reviewer Notes, Review Outcomes, and Publication Conditions. 12.6.10(a) GCRI Canada shall maintain peer review records, reviewer notes where appropriate, review outcomes, reviewer conditions, conflict disclosures, recusal records, publication conditions, and closeout records.
12.6.10(b) Peer review records shall identify research output, version reviewed, reviewers, reviewer qualifications, conflicts, scope of review, materials reviewed, findings, required changes, unresolved issues, conditions, approval or non-approval status, publication class, public-safe status, and correction path.
12.6.10(c) Reviewer notes may be retained as internal, confidential, restricted, sealed, or public-safe records according to classification, confidentiality, legal, safeguards, and publication needs.
12.6.10(d) Publication conditions shall be implemented before release unless a recorded authority expressly permits release with unresolved conditions and appropriate limitations.
12.6.10(e) The controlling rule shall be that peer review must leave a record sufficient to show what was reviewed, by whom, with what conditions, and with what effect.
12.7 Reproducibility, Replication, and Auditability
12.7.1 Reproducibility as Required Where Appropriate and Lawful. 12.7.1(a) GCRI Canada shall support reproducibility where appropriate and lawful, taking into account research method, data class, public-safe status, technical domain, publication class, public reliance, legal duties, privacy, cybersecurity, public authority restrictions, protected knowledge, IP, licensing, sanctions, export controls, and controlled technology.
12.7.1(b) Reproducibility may require records sufficient to permit an authorized reviewer to understand, rerun, inspect, compare, validate, or challenge the research process, subject to classification and access controls.
12.7.1(c) Reproducibility shall not require unrestricted public release of sensitive data, protected knowledge, public authority data, cyber-sensitive information, infrastructure-sensitive information, personal information, health-sensitive data, confidential sources, or controlled technology.
12.7.1(d) Where full public reproducibility is unsafe or unlawful, GCRI Canada may provide controlled reproducibility, clean-room reproducibility, synthetic data, redacted data, public-safe methods summaries, restricted annexes, or authorized audit access.
12.7.1(e) The controlling rule shall be that reproducibility is a research integrity value, but it must operate within lawful protection.
12.7.2 Replication as Encouraged Where Appropriate, Proportionate, and Public-Benefit Aligned. 12.7.2(a) GCRI Canada shall encourage replication where appropriate, proportionate, and public-benefit aligned, especially for research outputs likely to affect public-safe understanding, technical baselines, public authority learning, finance-facing evidence inputs, GRF inputs, GRA inputs, Protocol Authority inputs, dashboards, maps, datasets, models, or Nexus interface materials.
12.7.2(b) Replication may be internal, external, independent, partial, controlled, clean-room, synthetic, public-safe, or restricted according to classification and risk.
12.7.2(c) Replication planning shall consider cost, feasibility, data access, source availability, protected knowledge, public authority restrictions, cybersecurity, IP, community safeguards, and public benefit.
12.7.2(d) Replication failures, partial replications, inconsistent results, or inability to replicate shall be recorded and assessed for correction, method update, confidence downgrade, public-safe notice, controlled notice, supersession, withdrawal, or retraction.
12.7.2(e) The controlling rule shall be that replication strengthens trust when feasible, and non-replication must be understood rather than ignored.
12.7.3 Reproducibility Without Disclosure of Sensitive, Protected, Public Authority, Cyber-Sensitive, Infrastructure-Sensitive, Personal, Health-Sensitive, Community-Protected, or Controlled Technology Materials. 12.7.3(a) GCRI Canada shall design reproducibility practices to avoid disclosure of sensitive, protected, public authority, cyber-sensitive, infrastructure-sensitive, personal, health-sensitive, finance-sensitive, commercially sensitive, community-protected, Indigenous or protected knowledge, confidential source, whistleblower, export-control-sensitive, sanctions-sensitive, controlled technology, or privileged materials.
12.7.3(b) Reproducibility may be supported through redaction, aggregation, synthetic data, derived public-safe data, public-safe code, public-safe methods descriptions, controlled annexes, secure enclaves, compute-to-data, clean rooms, data rooms, no-download rooms, authorized audit rooms, or trusted reviewer access.
12.7.3(c) Metadata released for reproducibility shall be reviewed for re-identification risk, mosaic risk, public authority risk, cyber risk, infrastructure risk, finance risk, protected knowledge risk, and public-safe risk.
12.7.3(d) A reproducibility package shall not be released where release would expose protected persons, sensitive sites, vulnerabilities, restricted public authority data, protected knowledge, or controlled technology beyond lawful and public-safe bounds.
12.7.3(e) The controlling rule shall be that reproducibility shall prove method integrity without exposing protected materials.
12.7.4 Reproducibility Packages, Public-Safe Data, Synthetic Data, Redacted Data, Code, Methods, Environment Notes, and Dependency Notes. 12.7.4(a) Where appropriate, GCRI Canada may create reproducibility packages containing public-safe data, synthetic data, redacted data, code, methods, environment notes, dependency notes, configuration notes, model notes, prompt or retrieval notes where material, evaluation harnesses, benchmark conditions, and verification instructions.
12.7.4(b) Reproducibility packages shall identify version, scope, purpose, included materials, excluded materials, limitations, public-safe transformations, license, IP status, dependency status, security status, data rights, permitted uses, prohibited uses, and correction path.
12.7.4(c) Synthetic data shall be labeled as synthetic and shall not be represented as original data. Redacted data shall identify redaction approach at a public-safe level. Public-safe data shall identify limitations and remaining restrictions.
12.7.4(d) Code and environment notes shall be reviewed for secrets, credentials, tokens, keys, vulnerability exposure, unsafe dependencies, license issues, and public-safe status before release.
12.7.4(e) The controlling rule shall be that reproducibility packages must be useful enough to support review and safe enough not to create exposure.
12.7.5 Reproducibility Limits and Non-Reproducible Evidence Handling. 12.7.5(a) GCRI Canada shall record reproducibility limits where evidence, methods, outputs, observations, field conditions, public authority restrictions, protected knowledge, data rights, safety conditions, proprietary constraints, cybersecurity controls, or time-sensitive contexts prevent full reproducibility.
12.7.5(b) Non-reproducible evidence may include one-time observations, confidential interviews, emergency-context evidence, public authority restricted records, sensitive community testimony, protected knowledge, field telemetry, transient sensor signals, proprietary logs, cyber incident data, or sensitive geospatial evidence.
12.7.5(c) Non-reproducible evidence shall be handled through source lineage, custody records, reviewer access where appropriate, confidence limits, uncertainty treatment, corroboration where possible, public-safe summaries, controlled annexes, and correction paths.
12.7.5(d) Non-reproducibility shall be disclosed at a level appropriate to publication class and shall not be hidden where it affects confidence or reliance.
12.7.5(e) The controlling rule shall be that evidence that cannot be reproduced may still be usable, but only when its limits are recorded and carried into meaning.
12.7.6 Audit Trails for Data, Models, Compute, Methods, Review, Publication, and Correction. 12.7.6(a) GCRI Canada shall maintain audit trails for data, models, compute workloads, methods, source selection, review, publication, technical release, public-safe transformation, correction, supersession, withdrawal, retraction, and archive where material to research integrity.
12.7.6(b) Audit trails may include access logs, change logs, repository history, dataset versioning, model versioning, prompt or retrieval records where material, compute workload records, inference records, method records, reviewer records, publication approval records, correction records, proof receipts, hashes, signatures, timestamps, and Gazette entries.
12.7.6(c) Audit trails shall be classified, protected, retained, and accessible to authorized reviewers according to record class, sensitivity, legal requirements, public authority restrictions, cybersecurity, protected knowledge, finance sensitivity, and public-safe rules.
12.7.6(d) Audit trails shall not be silently edited, deleted, backdated, or altered to improve appearances, protect sponsors, protect providers, avoid public authority discomfort, preserve finance narratives, or conceal error.
12.7.6(e) The controlling rule shall be that auditability makes research meaning accountable after the moment of publication.
12.7.7 Research Artifact Registers. 12.7.7(a) GCRI Canada shall maintain or link to research artifact registers for material research artifacts, including protocols, datasets, models, code, scripts, evaluation harnesses, benchmark harnesses, dashboards, maps, evidence packs, decision packs, technical baselines, public-good software, reproducibility packages, public-safe summaries, controlled annexes, restricted annexes, and publications.
12.7.7(b) Research artifact registers shall identify artifact ID, Case ID, title, version, owner, custodian, repository, classification, access class, data class, IP status, license status, source lineage, review status, public-safe status, dependency status, correction path, supersession status, withdrawal status, retraction status, archive status, and legal hold status where applicable.
12.7.7(c) Artifact registers shall support reproducibility, replication, auditability, dependency management, correction, retention, and public-safe publication.
12.7.7(d) Public versions of artifact registers may be issued only where public-safe and shall not expose restricted materials or imply certification, recognition, finance-readiness, public authority approval, provider preference, sponsor validation, protocol effect, or execution.
12.7.7(e) The controlling rule shall be that research artifacts must be registered so research can be found, reviewed, corrected, and preserved.
12.7.8 Replication Failure, Reanalysis, Method Update, Correction, Supersession, Withdrawal, and Retraction. 12.7.8(a) Replication failure shall be recorded and reviewed to determine whether it results from source differences, data differences, method differences, model drift, environment differences, version differences, public-safe transformation, implementation error, genuine uncertainty, or original error.
12.7.8(b) Reanalysis shall be conducted where replication failure materially affects findings, public-safe summaries, dashboards, maps, technical baselines, evidence packs, public claims, public authority materials, finance-facing materials, GRF inputs, GRA inputs, Protocol Authority inputs, or Nexus interfaces.
12.7.8(c) Method updates shall be recorded and versioned where replication reveals method limitations, calibration defects, benchmark issues, model drift, dataset drift, or evaluation weakness.
12.7.8(d) Replication failure may require correction, confidence downgrade, public-safe notice, controlled notice, supersession, withdrawal, retraction, archive marking, or additional review.
12.7.8(e) Replication failure shall not be suppressed because it undermines a preferred narrative, sponsor expectation, provider claim, public authority interest, finance-facing timeline, or publication prestige.
12.7.8(f) The controlling rule shall be that replication failure is an integrity signal to be reviewed, not a reputational problem to be hidden.
12.7.9 Public-Safe Reproducibility Summaries. 12.7.9(a) GCRI Canada may issue public-safe reproducibility summaries to explain what can be reproduced, what cannot be reproduced, what materials are available, what materials are restricted, what assumptions apply, what limitations exist, and how correction may be requested.
12.7.9(b) Public-safe reproducibility summaries shall identify version, scope, reproducibility status, data availability status, code availability status, method availability status, environment notes at a safe level, limitations, public-safe restrictions, license terms where applicable, and correction path.
12.7.9(c) Such summaries shall not disclose sensitive data, protected knowledge, public authority restricted information, cyber-sensitive details, infrastructure vulnerabilities, personal information, confidential sources, controlled technology, or unsafe metadata.
12.7.9(d) Public-safe reproducibility summaries shall not imply certification, recognition, finance-readiness, public authority approval, provider preference, sponsor validation, protocol effect, or execution.
12.7.9(e) The controlling rule shall be that public audiences should understand reproducibility status without receiving unsafe materials.
12.7.10 Reproducibility and Auditability Assurance. 12.7.10(a) GCRI Canada shall conduct reproducibility and auditability assurance proportionate to research risk, publication class, technical significance, public-safe significance, public authority relevance, finance-facing relevance, cybersecurity relevance, protected knowledge relevance, and Nexus interface reliance.
12.7.10(b) Assurance may review whether protocols, data, models, code, methods, environments, dependencies, reviewer records, public-safe summaries, audit trails, artifact registers, correction paths, and archive records support appropriate reproducibility and auditability.
12.7.10(c) Assurance shall identify missing artifacts, incomplete audit trails, unregistered datasets, untracked model versions, missing method records, missing dependency notes, broken repository links, unreviewed public-safe reproducibility claims, and unsupported reproducibility statements.
12.7.10(d) Assurance findings shall result in corrective action plans, artifact registration, method updates, repository updates, public-safe notices, controlled notices, training, or Board or committee reporting where material.
12.7.10(e) The controlling rule shall be that reproducibility and auditability must themselves be periodically tested.
12.8 Research Conflicts and Independence
12.8.1 Research Conflicts of Interest. 12.8.1(a) Research conflicts of interest shall include any financial, institutional, personal, professional, political, sponsor, donor, funder, provider, host, public authority, university, capital-reader, media, partner, technical, publication, or reputational interest that may affect or appear to affect research questions, methods, source selection, data selection, benchmark design, model evaluation, interpretation, publication, correction, or public-safe communication.
12.8.1(b) Conflicts may be actual, potential, perceived, direct, indirect, individual, institutional, project-specific, programmatic, technical, financial, or relational.
12.8.1(c) Research conflicts shall be disclosed, recorded, classified, reviewed, managed, mitigated, monitored, and corrected where necessary.
12.8.1(d) The presence of a conflict shall not automatically disqualify research participation where mitigation is sufficient, but unmanaged conflict shall not be permitted to shape research meaning.
12.8.1(e) The controlling rule shall be that conflicts must be recorded before they become invisible influence.
12.8.2 Financial Conflicts. 12.8.2(a) Financial conflicts shall include funding, sponsorship, donations, grants, contracts, consulting fees, equity, options, tokens, royalties, IP interests, licensing interests, employment, board roles, advisory roles, investment interests, lender interests, insurer interests, vendor interests, provider interests, or other financial relationships that may affect research independence.
12.8.2(b) Financial conflicts may involve GCRI Canada, directors, officers, staff, fellows, advisors, reviewers, contributors, committees, councils, universities, partners, sponsors, providers, hosts, funders, donors, capital readers, or related parties.
12.8.2(c) Financial conflicts shall be disclosed and reviewed before research design, data access, publication, or correction decisions where material.
12.8.2(d) Financial conflicts shall be managed through disclosure, recusal, independent review, firewalls, funding independence clauses, public-safe disclosure where appropriate, restricted access, or refusal.
12.8.2(e) The controlling rule shall be that financial support shall never purchase research meaning.
12.8.3 Institutional Conflicts. 12.8.3(a) Institutional conflicts shall include organizational interests, partnerships, public authority relationships, sponsor relationships, provider relationships, host relationships, university relationships, Nexus relationships, public visibility, grant dependence, program continuation, media strategy, or reputational interest that may affect research independence.
12.8.3(b) Institutional conflicts may arise where GCRI Canada benefits from a particular research outcome, partnership continuation, sponsor satisfaction, provider participation, public authority relationship, finance-facing interest, or public narrative.
12.8.3(c) Institutional conflicts shall be disclosed in internal records and public-safe materials where material to reliance and safe to disclose.
12.8.3(d) Institutional conflict mitigation may include independent review, committee review, Board review, publication independence protection, separation of fundraising from research decisions, separation of provider relations from methods decisions, separation of public authority engagement from findings, and correction oversight.
12.8.3(e) The controlling rule shall be that GCRI Canada shall not allow its own institutional interests to distort public-benefit truth.
12.8.4 Sponsor, Donor, Funder, Provider, Host, Public Authority, University, Capital-Reader, and Partner Conflicts. 12.8.4(a) Conflicts involving sponsors, donors, funders, providers, hosts, public authorities, universities, capital readers, and partners shall be disclosed and reviewed where such actors fund, support, provide data, provide equipment, provide compute, provide facilities, provide access, provide expertise, participate in review, request publication, request suppression, request correction, or benefit from research outputs.
12.8.4(b) Sponsor and donor conflicts shall be managed to prevent control over research agenda, methods, source selection, findings, public-safe summaries, corrections, or publication timing.
12.8.4(c) Provider and host conflicts shall be managed to prevent provider preference, procurement advantage, benchmark manipulation, technical baseline capture, data selection capture, or public claim inflation.
12.8.4(d) Public authority conflicts shall be managed to prevent public authority participation from being misdescribed as endorsement, adoption, approval, procurement, public warning, emergency command, official guidance, or sovereign obligation.
12.8.4(e) Capital-reader conflicts shall be managed to prevent technical research from becoming investment advice, securities solicitation, underwriting, lending, insurance, rating, guarantee, finance-readiness, capital commitment, or financial execution.
12.8.4(f) The controlling rule shall be that research may involve powerful actors only when their influence is bounded by record.
12.8.5 Researcher, Fellow, Advisor, Reviewer, Committee, Council, and Technical Contributor Conflicts. 12.8.5(a) Researchers, fellows, advisors, reviewers, committee members, council participants, technical contributors, maintainers, contractors, and staff shall disclose conflicts that may affect research design, evidence selection, methods, model evaluation, code review, benchmark design, interpretation, publication, public claims, or correction.
12.8.5(b) Conflicts may include employment, consulting, funding, grants, IP interests, equity, tokens, professional rivalry, publication incentives, public authority roles, provider relationships, sponsor relationships, media roles, advocacy positions, political roles, or personal relationships.
12.8.5(c) Conflicted persons may be recused from specific decisions, limited to technical input, paired with independent reviewers, excluded from publication approval, restricted from data access, or removed from review where appropriate.
12.8.5(d) Reviewer conflicts shall be recorded before review outcome is relied upon. Undisclosed conflicts discovered later shall trigger review of affected outputs.
12.8.5(e) The controlling rule shall be that expertise does not cure conflict; conflict must be disclosed and managed.
12.8.6 Conflicts in Research Design, Data Selection, Method Selection, Benchmark Design, Model Evaluation, Interpretation, Publication, and Correction. 12.8.6(a) Conflict review shall apply to research design, data selection, source selection, method selection, benchmark design, model evaluation, technical testing, dashboard design, map design, interpretation, publication, public-safe summary, technical baseline framing, public claims, correction, withdrawal, retraction, and archive decisions.
12.8.6(b) Conflicts in design may shape research questions toward preferred outcomes. Conflicts in data selection may shape evidence. Conflicts in method selection may shape findings. Conflicts in benchmark design may shape comparability. Conflicts in model evaluation may shape perceived performance. Conflicts in publication may shape public meaning. Conflicts in correction may preserve error.
12.8.6(c) Where conflicts affect any stage, GCRI Canada shall record mitigation, including independent review, method lock, data selection review, reviewer independence, public-safe disclosure, recusal, boundary language, or refusal.
12.8.6(d) Conflicts shall be reassessed when research scope, funding, providers, public authority involvement, data sources, models, publication plans, or correction issues change.
12.8.6(e) The controlling rule shall be that conflict controls must follow the research lifecycle from question to correction.
12.8.7 Disclosure, Mitigation, Recusal, Independent Review, Firewalls, Restricted Access, and Public Disclosure Where Appropriate. 12.8.7(a) GCRI Canada shall use disclosure, mitigation, recusal, independent review, firewalls, restricted access, public-safe disclosure, controlled disclosure, refusal, or termination of participation where necessary to protect research independence.
12.8.7(b) Disclosure shall identify the conflict, affected person or entity, affected research, potential influence, mitigation, and residual risk.
12.8.7(c) Recusal shall apply where a conflicted person should not participate in decisions, reviews, approvals, publication determinations, correction decisions, or access to particular materials.
12.8.7(d) Independent review shall be used where research findings, public-safe outputs, sponsor or provider involvement, public authority references, finance-facing materials, or technical baselines require review insulated from conflict.
12.8.7(e) Firewalls and restricted access shall separate fundraising, sponsorship, provider relations, public authority relations, capital-reader relations, business development, or communications from research decisions where needed.
12.8.7(f) Public disclosure shall be provided where safe and material to public reliance, but shall not disclose sensitive information beyond public-safe limits.
12.8.7(g) The controlling rule shall be that conflict management shall be practical, recorded, proportionate, and strong enough to preserve trust.
12.8.8 No Sponsor or Provider Control Over Research Findings. 12.8.8(a) No sponsor, donor, funder, provider, host, vendor, platform, capital reader, or other external support actor shall control GCRI Canada research findings, methods, evidence selection, data selection, benchmark design, model evaluation, interpretation, publication, public-safe summary, correction, supersession, withdrawal, retraction, or archive.
12.8.8(b) Sponsors and providers may provide data, tools, equipment, compute, funding, facilities, expertise, field context, factual correction, or technical comments where recorded, but such contributions shall not create control over conclusions.
12.8.8(c) Sponsor or provider factual review may be permitted for accuracy of the sponsor’s or provider’s own information, subject to no-veto, no-suppression, no-method-control, no-finding-control, and correctionability rules.
12.8.8(d) Any agreement purporting to give sponsors or providers control over research findings shall be void or ineffective within GCRI Canada governance to the maximum extent permitted by law and shall be corrected or refused.
12.8.8(e) The controlling rule shall be that research findings belong to the record, not to the party that supports the work.
12.8.9 No Publication Suppression or Veto Rights Except Lawful, Narrow, Recorded, Safety-Justified, Confidentiality-Justified, or Rights-Protective Restrictions. 12.8.9(a) No sponsor, donor, funder, provider, host, public authority, capital reader, media actor, partner, reviewer, or participant shall receive publication suppression or veto rights over GCRI Canada research except where a lawful, narrow, recorded, safety-justified, confidentiality-justified, rights-protective, public authority-restricted, protected-knowledge-protective, cybersecurity-protective, export-control-protective, sanctions-compliant, controlled-technology-protective, or legal-hold restriction applies.
12.8.9(b) Lawful restrictions may delay, redact, aggregate, public-safe transform, control, restrict, seal, or withhold materials, but shall not be used to suppress inconvenient findings, negative results, provider defects, sponsor limitations, public authority ambiguity, finance risk, or research corrections.
12.8.9(c) Any publication restriction shall identify scope, reason, authority, duration, affected materials, review date, public-safe alternative where appropriate, and correction path.
12.8.9(d) Where restrictions affect public reliance, GCRI Canada may issue public-safe explanation without exposing restricted details.
12.8.9(e) The controlling rule shall be that safety and rights may limit disclosure, but interests shall not veto truth.
12.8.10 Conflict Records and Research Independence Assurance. 12.8.10(a) GCRI Canada shall maintain conflict records and research independence assurance for material research activities.
12.8.10(b) Conflict records shall identify disclosed conflicts, affected research, affected persons or entities, mitigation, recusals, independent reviews, firewalls, public-safe disclosures, residual risk, and closeout.
12.8.10(c) Research independence assurance shall review whether conflicts were disclosed, mitigated, updated, and respected throughout research design, evidence selection, data selection, methods, review, publication, correction, and archive.
12.8.10(d) Assurance findings may result in correction, additional disclosure, independent re-review, publication amendment, confidence downgrade, withdrawal, retraction, training, agreement amendment, access restriction, or Board or committee reporting.
12.8.10(e) The controlling rule shall be that independence must be capable of audit, not merely asserted.
12.9 Sponsor, Donor, Funder, Provider, and Host Roles in Research
12.9.1 Support Without Control. 12.9.1(a) Sponsors, donors, funders, providers, and hosts may support GCRI Canada research through lawful, mission-compatible funding, grants, donations, in-kind contributions, facilities, equipment, data, compute, access, expertise, convening support, field context, or technical input, provided that support does not create control over research meaning.
12.9.1(b) Support shall not create sponsor control, provider preference, host control, donor influence, funder veto, outcome purchase, method capture, data selection capture, reviewer selection capture, publication suppression, correction suppression, recognition purchase, finance-readiness purchase, certification implication, public authority access purchase, or public claim purchase.
12.9.1(c) Support relationships shall be documented, conflict-reviewed, public-safe where disclosed, bounded by independence clauses where appropriate, and correctionable.
12.9.1(d) Research support shall be accepted only where compatible with GCRI Canada’s mission lock, non-execution, public-benefit purpose, public-good stack discipline, provider neutrality, sponsor non-control, anti-capture, anti-enclosure, and correctionability.
12.9.1(e) The controlling rule shall be that sponsors, donors, funders, providers, and hosts may support research infrastructure, but shall not own institutional truth.
12.9.2 Funding Disclosure. 12.9.2(a) Research funding shall be disclosed in internal records and, where material to public reliance and public-safe, in public-safe publications, technical notes, research reports, dashboards, maps, evidence packs, public-safe summaries, and related outputs.
12.9.2(b) Funding disclosure shall identify the funder, sponsor, donor, grantor, or support source at an appropriate level; the nature of support; restrictions where any; independence protections; and whether the funder had any role in research design, data selection, method selection, review, publication, or correction.
12.9.2(c) Where full disclosure would expose confidential, personal, public authority-sensitive, security-sensitive, protected knowledge, or legally restricted information, GCRI Canada may provide public-safe funding disclosure and retain controlled records.
12.9.2(d) Funding disclosure shall not be framed as sponsor endorsement, funder approval, public authority approval, finance-readiness, provider preference, or research validation.
12.9.2(e) The controlling rule shall be that funding transparency supports trust, but funding shall not become control or endorsement.
12.9.3 Sponsor Role Disclosure. 12.9.3(a) Sponsor role disclosure shall identify whether a sponsor provided financial support, in-kind support, facilities, convening, data, equipment, compute, expertise, field access, communications support, or other assistance to research.
12.9.3(b) Sponsor role disclosure shall identify whether the sponsor had no role, limited factual review, technical input, data contribution, field context contribution, or other recorded role in the research.
12.9.3(c) Sponsor role disclosure shall include boundary language where necessary stating that sponsor support did not confer control over research questions, methods, evidence selection, findings, publication, correction, public claims, recognition, finance-readiness, certification, public authority meaning, provider status, or Nexus status.
12.9.3(d) Sponsor role disclosure shall be corrected where sponsor materials, media materials, event materials, public claims, or third-party materials overstate the sponsor’s role.
12.9.3(e) The controlling rule shall be that sponsor support must be visible enough for trust and bounded enough to prevent capture.
12.9.4 Provider Role Disclosure. 12.9.4(a) Provider role disclosure shall identify whether a provider supplied tools, systems, equipment, software, data, compute, AI-RAN, O-RAN, sensors, dashboards, cybersecurity support, integration support, expertise, test environments, demonstrations, or services used in research.
12.9.4(b) Provider role disclosure shall distinguish provider contribution from provider endorsement, provider preference, procurement advantage, certification, compatibility status, public authority approval, finance-readiness, protocol effect, or market entitlement.
12.9.4(c) Where provider tools or data materially affect findings, the research record shall identify dependencies, limitations, validation status, conflicts, public-safe status, and correction path.
12.9.4(d) Provider factual or technical review shall not allow provider control over methods, findings, publication, correction, benchmark design, model evaluation, or public claims.
12.9.4(e) The controlling rule shall be that provider contributions shall be disclosed without converting contribution into preference.
12.9.5 Host Role Disclosure. 12.9.5(a) Host role disclosure shall identify whether a host provided facilities, infrastructure, field site access, data, operational context, public authority context, community context, convening support, equipment, connectivity, compute, testing environment, or other support to research.
12.9.5(b) Host role disclosure shall distinguish host support from host control, public authority approval, infrastructure ownership by GCRI Canada, operational responsibility by GCRI Canada, public warning authority, emergency command, procurement approval, finance-readiness, provider preference, sponsor validation, or execution.
12.9.5(c) Where host environments affect research findings, the record shall identify site conditions, limitations, permissions, safety controls, public authority context, community safeguards, data rights, and public-safe status.
12.9.5(d) Hosts shall not receive authority to suppress findings, approve public-safe summaries, control corrections, or claim endorsement beyond recorded role.
12.9.5(e) The controlling rule shall be that host context may make research possible, but it shall not control research meaning.
12.9.6 In-Kind Contribution Disclosure Where Material. 12.9.6(a) In-kind contributions shall be disclosed where material to research independence, method selection, data access, technical capability, public-safe output, public authority context, finance-facing interpretation, provider neutrality, sponsor non-control, or public trust.
12.9.6(b) In-kind contributions may include equipment, software, cloud credits, compute, datasets, sensors, telecommunications access, AI systems, cybersecurity services, facilities, staff time, technical expertise, travel, convening, media support, or field access.
12.9.6(c) Disclosure shall identify contributor, nature of contribution, estimated value where appropriate, restrictions, IP implications, data implications, security implications, conflicts, and independence controls.
12.9.6(d) In-kind contributions shall not create method capture, provider preference, sponsor control, public authority meaning, finance-readiness, procurement advantage, or technical endorsement.
12.9.6(e) The controlling rule shall be that non-cash support can influence research and therefore must be recorded where material.
12.9.7 No Outcome Purchase. 12.9.7(a) No sponsor, donor, funder, provider, host, public authority, capital reader, university, partner, or other actor may purchase, condition, require, or secure a predetermined research outcome, finding, public-safe summary, dashboard result, map result, benchmark result, model evaluation, technical baseline, correction decision, publication decision, or public claim.
12.9.7(b) Agreements, side letters, informal assurances, emails, chats, event commitments, grant narratives, sponsor decks, provider proposals, or public authority interest shall not create outcome commitments unless lawful and consistent with research integrity, and no such commitment may override truth, methods, public-safe publication, or correctionability.
12.9.7(c) Where a support relationship creates actual or perceived outcome purchase risk, GCRI Canada shall reject, restructure, disclose, mitigate, firewall, or terminate the relationship.
12.9.7(d) Research outputs shall not be modified to satisfy support expectations.
12.9.7(e) The controlling rule shall be that research outcomes must be earned by evidence and method, not bought by support.
12.9.8 No Method Capture. 12.9.8(a) No sponsor, donor, funder, provider, host, public authority, capital reader, university, partner, or other actor may control GCRI Canada’s research methods, evaluation logic, benchmark design, model evaluation, source weighting, confidence treatment, uncertainty treatment, public-safe transformation, or correction method.
12.9.8(b) External actors may provide technical input, factual context, data explanations, field constraints, public authority context, community context, or standards references where recorded and reviewed, but method selection shall remain subject to GCRI Canada research integrity.
12.9.8(c) Method capture risk shall be reviewed where methods depend on proprietary tools, provider data, sponsor-supplied evaluation conditions, host-controlled environments, public authority restrictions, capital-reader metrics, or external standards.
12.9.8(d) Captured or potentially captured methods shall be corrected, independently reviewed, supplemented, disclosed, restricted, or refused.
12.9.8(e) The controlling rule shall be that methods must serve the research question and public-benefit truth, not the preferences of support actors.
12.9.9 No Data Selection Capture. 12.9.9(a) No sponsor, donor, funder, provider, host, public authority, capital reader, university, partner, or other actor may control research data selection, source inclusion, source exclusion, evidence weighting, negative result suppression, contradictory evidence handling, missing data treatment, or dataset framing in a manner that distorts findings.
12.9.9(b) External data contributions shall be classified, source-lineage-recorded, reviewed for completeness, bias, limitations, permissions, public-safe status, conflicts, and correction path.
12.9.9(c) Data selection shall not be limited to sponsor-favorable, provider-favorable, host-favorable, public authority-favorable, finance-favorable, media-favorable, or institutionally favorable data where material contradictory or missing data exists.
12.9.9(d) Where data access is constrained by lawful confidentiality, privacy, public authority restrictions, protected knowledge, cybersecurity, or contract limits, the limitation shall be recorded and carried into findings.
12.9.9(e) The controlling rule shall be that data selection must be defensible by record, not shaped by the actor most interested in the result.
12.9.10 No Reviewer Selection Capture. 12.9.10(a) No sponsor, donor, funder, provider, host, public authority, capital reader, university, partner, or other actor may control reviewer selection in a manner that compromises independence, credibility, safeguards, public-safe review, finance-boundary review, public authority boundary review, or technical integrity.
12.9.10(b) External actors may suggest reviewers where appropriate, but reviewer selection shall remain subject to GCRI Canada authority, conflict review, qualification review, confidentiality controls, and independence requirements.
12.9.10(c) Reviewer selection shall avoid stacking review panels with sponsor-friendly, provider-friendly, finance-friendly, public authority-friendly, politically convenient, reputationally aligned, or technically dependent reviewers where independence is required.
12.9.10(d) Reviewer conflicts shall be disclosed, mitigated, recused, or balanced with independent review.
12.9.10(e) The controlling rule shall be that review must be selected for integrity, not comfort.
12.9.11 No Publication Suppression. 12.9.11(a) No sponsor, donor, funder, provider, host, public authority, capital reader, university, partner, media actor, or other participant may suppress GCRI Canada research publication, public-safe correction, supersession, withdrawal, retraction, limitation disclosure, negative result, contrary evidence, or public-safe clarification except through lawful, narrow, recorded, safety-justified, confidentiality-justified, rights-protective, public authority-restricted, cybersecurity-protective, protected-knowledge-protective, export-control-compliant, sanctions-compliant, controlled-technology-protective, or legal-hold restrictions.
12.9.11(b) Publication delay may be permitted for factual review, safety review, coordinated vulnerability disclosure, public authority restriction, protected knowledge review, legal review, privacy review, IP review, or public-safe transformation, but not to avoid embarrassment or protect a preferred narrative.
12.9.11(c) Any publication restriction shall be recorded with authority, reason, scope, duration, affected materials, review date, and correction path.
12.9.11(d) Where publication restriction affects public reliance, GCRI Canada shall consider public-safe notice or controlled notice.
12.9.11(e) The controlling rule shall be that research publication may be lawfully protected, but not improperly suppressed.
12.9.12 Research Agreements, Independence Clauses, Public-Safe Acknowledgments, and Correction Rights. 12.9.12(a) Research agreements with sponsors, donors, funders, providers, hosts, universities, public authorities, partners, communities, or other actors shall include research independence clauses, publication controls, public-safe publication rules, data governance rules, IP rules, confidentiality rules, conflict rules, sponsor non-control language, provider-neutrality language, correction rights, withdrawal rights, retraction rights, and archive obligations where appropriate.
12.9.12(b) Independence clauses shall state that GCRI Canada retains control over research questions, methods, evidence interpretation, findings, public-safe summaries, corrections, supersessions, withdrawals, retractions, and public claims within its role and applicable law.
12.9.12(c) Public-safe acknowledgments shall accurately describe support without implying endorsement, control, outcome purchase, provider preference, public authority approval, finance-readiness, certification, recognition, protocol effect, or execution authority.
12.9.12(d) Correction rights shall permit GCRI Canada to correct, supersede, withdraw, retract, clarify, or publicly-safe notice research outputs where required by evidence, methods, law, safety, public authority boundaries, finance boundaries, protected knowledge, cybersecurity, or public trust.
12.9.12(e) The controlling rule shall be that research agreements must protect independence before support begins.
12.10 Research Data Governance
12.10.1 Research Data Lawful Basis. 12.10.1(a) GCRI Canada shall identify the lawful basis, approval basis, contractual basis, consent basis, public-benefit basis, research basis, public authority basis, community basis, or other permitted basis for research data collection, receipt, generation, access, use, processing, transfer, publication, retention, deletion, sealing, archive, and correction where applicable.
12.10.1(b) Research data shall not be used merely because it is available, technically accessible, sponsor-provided, provider-provided, public authority-provided, publicly scraped, AI-generated, dashboard-accessible, repository-accessible, or commercially obtainable.
12.10.1(c) The lawful or approval basis shall be recorded with purpose, scope, data class, source, permissions, restrictions, retention, transfer, AI-use permission, publication status, public-safe status, and correction path.
12.10.1(d) Where the lawful or approval basis is uncertain, research data use shall be paused, narrowed, restricted, reviewed, or refused until the basis is established.
12.10.1(e) The controlling rule shall be that research data must have a lawful or approved path into the research record.
12.10.2 Purpose Limitation. 12.10.2(a) Research data shall be collected, received, generated, accessed, processed, transformed, linked, published, or retained only for recorded purposes compatible with the approved research protocol, lawful or approval basis, data classification, public-safe status, and participant or source expectations where applicable.
12.10.2(b) Purpose limitation shall apply to raw data, derived data, synthetic data, aggregated data, de-identified data, embeddings, feature stores, retrieval indexes, model inputs, model outputs, dashboard data, map layers, benchmark sets, evaluation sets, and public-safe summaries.
12.10.2(c) Research data collected for one purpose shall not be repurposed for AI training, model evaluation, dashboarding, mapping, public authority materials, finance-facing materials, provider materials, sponsor materials, public claims, GRF inputs, GRA inputs, Protocol Authority inputs, or Nexus interfaces unless permitted by record and review.
12.10.2(d) Purpose expansion shall require review for law, privacy, public authority restrictions, cybersecurity, protected knowledge, community safeguards, finance sensitivity, IP, public-safe status, and correction path.
12.10.2(e) The controlling rule shall be that research data shall not drift into new uses by convenience or technical possibility.
12.10.3 Data Minimization. 12.10.3(a) GCRI Canada shall minimize research data collection, access, processing, retention, publication, mapping, dashboarding, AI use, and transfer to what is reasonably necessary and proportionate for the recorded research purpose.
12.10.3(b) Data minimization shall require evaluation of whether the research can be conducted using less sensitive data, aggregated data, synthetic data, redacted data, de-identified data, public-safe data, compute-to-data, controlled rooms, clean rooms, or no-download rooms.
12.10.3(c) GCRI Canada shall not collect or retain personal, health-sensitive, public authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercial, community-protected, Indigenous or protected knowledge, confidential source, or controlled technology data where less sensitive alternatives are adequate.
12.10.3(d) Data minimization shall also apply to metadata, logs, embeddings, prompts, retrieval stores, copies, exports, backups, screenshots, notes, and derived materials.
12.10.3(e) The controlling rule shall be that the safest research data is often the data GCRI Canada does not collect, copy, or retain.
12.10.4 Data Classification. 12.10.4(a) Research data shall be classified at intake, before use, before transfer, before AI use, before public-safe transformation, before dashboarding, before mapping, before publication, before archive, and whenever conditions materially change.
12.10.4(b) Data classification shall identify data type, source, owner or contributor, lawful or approval basis where applicable, permissions, restrictions, sensitivity, public-safe status, access class, handling class, retention class, transfer class, AI-use status, publication status, and correction path.
12.10.4(c) Research data may be classified as public, public-safe, internal, confidential, restricted, personal, health-sensitive, rights-bearing, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, community-protected, Indigenous or protected knowledge, export-control-sensitive, sanctions-sensitive, controlled-technology-sensitive, privileged, sealed, or legal-hold.
12.10.4(d) Where classification is uncertain, GCRI Canada shall apply the more protective classification until review supports downgrade.
12.10.4(e) The controlling rule shall be that research data classification governs every subsequent use.
12.10.5 Sensitive Research Data. 12.10.5(a) Sensitive research data shall include data that may create legal, privacy, cybersecurity, public authority, finance, commercial, community, protected knowledge, safety, dignity, rights, or public trust risk if improperly accessed, used, linked, published, transferred, or retained.
12.10.5(b) Sensitive research data may include personal information, health-sensitive information, rights-bearing data, public authority data, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, commercially sensitive information, community-protected information, Indigenous knowledge, local knowledge, territorial knowledge, environmental knowledge, cultural knowledge, protected knowledge, confidential source information, whistleblower information, credentials, keys, tokens, secrets, controlled technology, export-control-sensitive information, sanctions-sensitive information, and privileged information.
12.10.5(c) Sensitive research data shall be handled under least-privilege access, classification, encryption where appropriate, logging where material, controlled rooms or clean rooms where appropriate, no-download rules where appropriate, AI-use restrictions, public-safe review, retention limits, correction path, and incident response.
12.10.5(d) Sensitive research data shall not be placed in public repositories, public dashboards, public maps, public datasets, uncontrolled AI tools, email attachments, chat threads, personal storage, unmanaged folders, or public materials unless lawfully transformed and approved.
12.10.5(e) The controlling rule shall be that sensitive data requires governance before analysis, not merely before publication.
12.10.6 Public Authority Research Data. 12.10.6(a) Public authority research data shall include data received from, generated with, derived from, referring to, or materially involving public authorities, public programs, public infrastructure, public finance, emergency management, public health, public safety, public procurement, regulatory activity, public authority participation, or public authority learning.
12.10.6(b) Public authority research data shall be capacity-classified and shall identify source, authority or approval basis where applicable, permitted use, prohibited use, confidentiality, publication permission, AI-use limits, retention, transfer, public-safe status, reference approval, and correction path.
12.10.6(c) Public authority research data shall not be used to imply public authority endorsement, adoption, regulation, procurement approval, funding approval, public finance approval, official guidance, public warning, emergency command, sovereign obligation, or public-law status.
12.10.6(d) Public authority research data shall not be published, mapped, dashboarded, included in public-safe summaries, used in finance-facing materials, routed to GRF, routed to GRA, routed to Protocol Authority, or reused in Nexus interfaces beyond its recorded permissions and public-safe review.
12.10.6(e) The controlling rule shall be that public authority data carries public power risks and must be handled without borrowing public authority.
12.10.7 Health-Sensitive Research Data. 12.10.7(a) Health-sensitive research data shall include personal health information, public health data, epidemiological data, health system data, biosurveillance data, biosecurity data, clinical data, mental health data, disability-related data, community health data, health-related geospatial data, and other data that may affect health privacy, dignity, rights, stigma, or safety.
12.10.7(b) Health-sensitive research data shall require heightened lawful or approval basis review, ethics review where applicable, data minimization, de-identification or aggregation where appropriate, access controls, AI-use restrictions, publication review, public-safe transformation, retention limits, and correction path.
12.10.7(c) Health-sensitive research data shall not be used in public dashboards, maps, AI systems, public reports, media materials, sponsor materials, provider materials, finance-facing materials, or Nexus interfaces where such use may expose persons, vulnerable groups, communities, health conditions, sensitive locations, or public health vulnerabilities.
12.10.7(d) Where health-sensitive data is combined with geospatial, public authority, community, AI, or infrastructure data, GCRI Canada shall review mosaic and re-identification risk.
12.10.7(e) The controlling rule shall be that health-sensitive data shall be governed as rights-bearing data, not merely research input.
12.10.8 Cyber-Sensitive Research Data. 12.10.8(a) Cyber-sensitive research data shall include vulnerability information, exploit information, threat intelligence, incident records, logs, credentials, keys, tokens, secrets, system configurations, network diagrams, attack paths, detection rules, security telemetry, malware samples, repository security data, dependency vulnerabilities, and other data that may increase cybersecurity risk if mishandled.
12.10.8(b) Cyber-sensitive research data shall be handled under cybersecurity classification, need-to-know access, secure repositories, no-public-repository rules, controlled disclosure, coordinated vulnerability disclosure where applicable, AI-use restrictions, secure collaboration, retention controls, and incident response.
12.10.8(c) Public-safe publication of cyber-sensitive research shall remove or control details that would enable exploitation, unauthorized access, credential abuse, infrastructure harm, or operational compromise.
12.10.8(d) Cyber-sensitive data shall not be entered into unauthorized AI tools, public issue trackers, public repositories, public dashboards, public maps, public datasets, chat, email, or uncontrolled collaboration systems.
12.10.8(e) The controlling rule shall be that cyber research shall help reduce vulnerability without publishing a roadmap to harm.
12.10.9 Infrastructure-Sensitive Research Data. 12.10.9(a) Infrastructure-sensitive research data shall include information about critical infrastructure, mission-critical infrastructure, public infrastructure, energy systems, water systems, food systems, transportation systems, ports, corridors, telecommunications, AI-RAN, O-RAN, private wireless, DePIN, sensors, cyber-physical systems, operational technology, public safety systems, emergency management systems, digital twins, and sensitive geospatial locations.
12.10.9(b) Infrastructure-sensitive research data shall be reviewed for public-safe mapping, geospatial exposure, cyber-physical risk, public authority restrictions, community safeguards, provider or host confidentiality, national security sensitivity, export-control sensitivity, controlled technology, and operational risk.
12.10.9(c) Infrastructure-sensitive data shall not be released in a manner that exposes vulnerabilities, exact sensitive locations, system dependencies, failure modes, operational weaknesses, emergency response gaps, or attack pathways.
12.10.9(d) Public-safe summaries may use aggregation, generalization, redaction, delayed disclosure, controlled annexes, or non-public technical details to preserve public understanding without increasing risk.
12.10.9(e) The controlling rule shall be that infrastructure research must make resilience more intelligible without making infrastructure more vulnerable.
12.10.10 Community-Protected and Protected Knowledge Research Data. 12.10.10(a) Community-protected and protected knowledge research data shall include Indigenous knowledge where applicable, local knowledge, territorial knowledge, environmental knowledge, cultural knowledge, community context, sensitive sites, protected locations, vulnerable community information, confidential community testimony, protected persons, community-protected data, and other knowledge subject to safeguards, consent, non-consent, attribution, non-attribution, withdrawal, grievance, remedy, or restricted use.
12.10.10(b) Such data shall be governed by safeguards, consent or non-consent treatment where applicable, community review where appropriate, contextual integrity, purpose limitation, access control, AI-use restrictions, mapping restrictions, publication limits, retention controls, withdrawal pathways, grievance pathways, remedy pathways, and correction paths.
12.10.10(c) Community-protected and protected knowledge research data shall not be treated as open data, ordinary evidence, public authority material, sponsor material, provider material, finance-facing material, AI training material, dashboard content, map layer, public repository content, or media material without recorded safeguards and approval.
12.10.10(d) Derivatives, summaries, translations, embeddings, retrieval indexes, model outputs, maps, dashboards, public-safe summaries, reports, technical baselines, Academy materials, GRF inputs, GRA inputs, Protocol Authority inputs, and Nexus interfaces shall inherit protective restrictions unless reviewed and lawfully transformed.
12.10.10(e) The controlling rule shall be that protected knowledge remains protected even when transformed into research data.
12.10.11 Cross-Border Research Data and Sovereign Data Zones. 12.10.11(a) Cross-border research data use shall be reviewed before data is transferred, accessed, processed, stored, backed up, mirrored, indexed, embedded, used in AI systems, placed in cloud systems, shared through repositories, or made available outside its approved jurisdictional or sovereign data context.
12.10.11(b) Review shall address law, privacy, public authority restrictions, data localization, sovereign data zones, compute-to-data options, contractual restrictions, conflict-of-law risk, cybersecurity, protected knowledge, public-safe status, sanctions, export controls, controlled technology, and retention.
12.10.11(c) Sovereign data zones may be used to preserve jurisdictional, public authority, community, Indigenous, local, territorial, or institutional control over data access, processing, storage, and use.
12.10.11(d) Compute-to-data shall be preferred where research value can be achieved without transferring sensitive data.
12.10.11(e) Cross-border transfer shall not occur where legal, public authority, privacy, cybersecurity, protected knowledge, sanctions, export-control, controlled-technology, or public-safe risks cannot be adequately controlled.
12.10.11(f) The controlling rule shall be that research interoperability shall not override sovereign data discipline.
12.10.12 Research Data Access, Retention, Deletion, Sealing, Archive, and Legal Hold. 12.10.12(a) Research data access, retention, deletion, sealing, archive, and legal hold shall be governed by data classification, research protocol, lawful or approval basis, public-safe status, ethics or community conditions, public authority restrictions, cybersecurity requirements, IP rights, contractual obligations, retention schedule, correction needs, and legal hold requirements.
12.10.12(b) Research data access shall be role-based, least-privilege, purpose-limited, time-limited where appropriate, logged where material, revocable, and subject to AI-use, download, export, and onward disclosure restrictions.
12.10.12(c) Retention shall preserve data long enough to support law, audit, research integrity, reproducibility where appropriate, correctionability, public-safe accountability, legal hold, and institutional memory, while avoiding unnecessary over-retention of sensitive data.
12.10.12(d) Deletion shall occur where lawful, required, authorized, and consistent with retention, legal hold, correction, ethics, community safeguards, public authority restrictions, and protected knowledge obligations.
12.10.12(e) Sealing shall be used where data must be preserved but access restricted due to legal, safety, public authority, cybersecurity, protected knowledge, confidential source, whistleblower, privilege, or public-safe reasons.
12.10.12(f) Archive shall preserve research data and metadata according to classification, public-safe status, source lineage, correction path, and access limits.
12.10.12(g) Legal hold shall suspend ordinary deletion, alteration, or disposal where actual or anticipated legal, regulatory, audit, investigation, dispute, litigation, public authority request, incident response, or Board-directed preservation need exists.
12.10.12(h) The controlling rule shall be that research data remains governed throughout its lifecycle, from access to deletion or archive.
12.11 AI-Assisted Research and Publication
12.11.1 AI Assistance in Research as Governed Tool Use, Not Research Authority. 12.11.1(a) Artificial intelligence may be used by GCRI Canada as a governed tool for research assistance, drafting assistance, summarization, translation, coding, analysis, classification support, visualization support, retrieval support, quality review, comparison, pattern identification, and workflow support, provided that such use remains subordinate to human responsibility, research protocol, source lineage, method discipline, data governance, public-safe publication controls, and correctionability.
12.11.1(b) AI assistance shall not constitute research authority, institutional authority, evidentiary authority, public authority, finance authority, certification authority, recognition authority, protocol authority, publication authority, legal authority, professional authority, public warning authority, emergency command authority, or execution authority.
12.11.1(c) AI outputs shall not be treated as facts, findings, citations, legal conclusions, technical conclusions, evidence records, method records, public-safe outputs, public authority materials, finance-facing materials, provider assessments, sponsor assessments, public claims, or Nexus interface materials unless reviewed, supported by records, classified, approved, and corrected where necessary.
12.11.1(d) AI use shall remain governed by approved systems, approved purposes, permitted data classes, access controls, logging where material, human review, bias controls, hallucination controls, public-safe controls, privacy controls, cybersecurity controls, protected knowledge safeguards, and publication controls.
12.11.1(e) The controlling rule shall be that AI may assist research, but shall not authoritatively determine institutional truth.
12.11.2 AI Use Disclosure Where Material. 12.11.2(a) GCRI Canada shall disclose AI use where material to research integrity, publication meaning, public-safe interpretation, reproducibility, auditability, authorship, translation, analysis, coding, visualization, model evaluation, public authority use, finance-facing use, public claims, or correction.
12.11.2(b) AI use disclosure may be internal, controlled, restricted, public-safe, or public, depending on publication class, data class, system class, sensitivity, public-safe status, and reliance risk.
12.11.2(c) Disclosure shall identify, where material and safe, the AI system or model class used, purpose of use, output type, human review performed, data restrictions, limitations, known risks, and correction path.
12.11.2(d) Public-safe AI use disclosure shall not expose sensitive prompts, protected knowledge, public authority data, cyber-sensitive information, infrastructure-sensitive information, personal information, confidential sources, credentials, system vulnerabilities, or restricted methods.
12.11.2(e) Failure to disclose material AI use where required shall constitute a research integrity and publication correction trigger.
12.11.2(f) The controlling rule shall be that AI use shall be visible enough for integrity and bounded enough for safety.
12.11.3 Model Register Requirements for Material AI Use. 12.11.3(a) GCRI Canada shall maintain model register records for material AI use in research, publication, evidence processing, public-safe transformation, coding, visualization, translation, summarization, retrieval, classification, inference, dashboarding, mapping, technical asset development, or Nexus interface preparation.
12.11.3(b) Model register records shall identify model or system name, version where known, provider or source, deployment context, permitted use, prohibited use, data classes permitted, data classes prohibited, access controls, logging status, retention treatment, evaluation status, known limitations, bias risks, hallucination risks, cybersecurity risks, public-safe status, and correction path.
12.11.3(c) Model register records shall identify whether the system is approved for internal use, controlled use, restricted use, public-safe output assistance, coding assistance, translation assistance, publication assistance, research analysis assistance, sensitive data use, or prohibited use.
12.11.3(d) Material AI systems shall be reviewed for privacy, cybersecurity, data retention, model training or improvement practices, cross-border processing, contractual terms, IP, confidentiality, public authority restrictions, protected knowledge safeguards, and public-safe publication implications.
12.11.3(e) The controlling rule shall be that material AI use must be traceable to a registered system and permitted purpose.
12.11.4 Inference Records for Material AI Outputs. 12.11.4(a) GCRI Canada shall maintain inference records for material AI outputs where such outputs affect research findings, evidence records, public-safe summaries, dashboards, maps, datasets, code, technical baselines, public authority-facing materials, finance-facing materials, public claims, or Nexus interface materials.
12.11.4(b) Inference records may identify Case ID, research protocol, model or system used, version where known, date and time, user or process, purpose, input class, output class, retrieval context where material, prompt or instruction record where material and safe, data sources, human reviewer, review outcome, limitations, public-safe status, and correction path.
12.11.4(c) Inference records shall be classified and shall not disclose sensitive prompts, personal information, public authority restricted data, protected knowledge, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, credentials, keys, tokens, secrets, or privileged material beyond authorized access.
12.11.4(d) Inference records shall support auditability, challengeability, reproducibility where appropriate, publication review, hallucination review, bias review, and correction.
12.11.4(e) The controlling rule shall be that material AI outputs must leave enough record to be reviewed, challenged, and corrected.
12.11.5 Human Review for AI-Assisted Research Claims. 12.11.5(a) AI-assisted research claims shall require human review before they are incorporated into research outputs, public-safe summaries, publications, dashboards, maps, datasets, technical baselines, Academy materials, public authority-facing materials, finance-facing materials, provider materials, sponsor materials, public claims, or Nexus interface materials.
12.11.5(b) Human review shall assess factual accuracy, source support, method fit, context, limitations, uncertainty, bias, hallucination risk, public-safe status, legal boundaries, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, protected knowledge, cybersecurity, and correction path.
12.11.5(c) Human reviewers shall not rely on AI fluency, confidence, formatting, citation style, apparent precision, or technical language as evidence of correctness.
12.11.5(d) Higher-risk AI-assisted outputs shall require subject-matter review, technical review, legal-boundary review, public-safe review, safeguards review, cybersecurity review, data review, or independent review as appropriate.
12.11.5(e) The controlling rule shall be that AI-assisted claims become institutional claims only after human review and record support.
12.11.6 No Sensitive Data in Unauthorized AI Systems. 12.11.6(a) GCRI Canada shall prohibit entry, upload, transmission, embedding, retrieval indexing, summarization, translation, analysis, code generation, or other use of sensitive data in unauthorized AI systems.
12.11.6(b) Sensitive data includes personal information, health-sensitive information, rights-bearing data, public authority restricted data, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, commercially sensitive information, community-protected information, Indigenous or protected knowledge, confidential source information, whistleblower information, credentials, keys, tokens, secrets, privileged information, export-control-sensitive information, sanctions-sensitive information, controlled technology, and restricted research data.
12.11.6(c) Authorized AI use involving sensitive data shall require explicit approval, classification, data governance review, privacy review, cybersecurity review, public authority review where applicable, protected knowledge review where applicable, contractual review, retention review, logging where material, and correction path.
12.11.6(d) Where sensitive data is entered into an unauthorized AI system, GCRI Canada shall treat the matter as a data incident, AI incident, research integrity incident, cybersecurity incident, public-safe publication incident, or protected knowledge incident as applicable.
12.11.6(e) The controlling rule shall be that AI convenience shall never override data protection, public authority restrictions, cybersecurity, or protected knowledge safeguards.
12.11.7 No Unauthorized Training, Fine-Tuning, Embedding, Retrieval, or Model Improvement. 12.11.7(a) GCRI Canada shall prohibit unauthorized use of research data, evidence records, public authority data, protected knowledge, sensitive data, confidential materials, publications, technical assets, code, datasets, models, prompts, retrieval stores, embeddings, or controlled annexes for model training, fine-tuning, embedding, retrieval, indexing, model improvement, evaluation, or synthetic data generation.
12.11.7(b) Any authorized training, fine-tuning, embedding, retrieval, or model-improvement use shall require recorded purpose, lawful or approval basis, data classification, source permissions, public-safe status, privacy review, cybersecurity review, IP review, public authority review where applicable, protected knowledge review where applicable, retention controls, deletion or removal path, and correction path.
12.11.7(c) Embeddings and retrieval indexes shall be treated as governed derivative records and shall inherit restrictions from source materials unless reviewed and lawfully transformed.
12.11.7(d) Unauthorized AI training, fine-tuning, embedding, retrieval, or model improvement shall trigger containment, deletion where lawful and required, model or index remediation, notice where appropriate, correction, suspension, withdrawal, or incident response.
12.11.7(e) The controlling rule shall be that research materials shall not silently become AI training or retrieval infrastructure.
12.11.8 AI Hallucination, Source Fabrication, False Citation, Bias, Drift, and Public Overclaim Controls. 12.11.8(a) GCRI Canada shall maintain controls for AI hallucination, source fabrication, false citation, inaccurate quotation, unsupported synthesis, bias, model drift, retrieval drift, prompt drift, embedding drift, stale output, and public overclaim.
12.11.8(b) Hallucination controls shall include source verification, citation verification, record cross-checking, human review, uncertainty labeling, limitation language, and refusal to rely on unsupported AI output.
12.11.8(c) Bias controls shall include review for discriminatory, stigmatizing, culturally unsafe, community-harmful, rights-affecting, public authority-distorting, finance-distorting, provider-favoring, sponsor-favoring, or technologically overconfident outputs.
12.11.8(d) Drift controls shall include review of model changes, retrieval changes, dataset changes, prompt changes, system changes, evaluation changes, output changes, and dependency changes over time.
12.11.8(e) Public overclaim controls shall prevent AI outputs from being represented as evidence, findings, public warnings, public authority statements, finance-readiness, certification, recognition, provider assessments, sponsor validation, or execution guidance.
12.11.8(f) The controlling rule shall be that AI outputs must be assumed fallible until verified by records and reviewed within scope.
12.11.9 AI-Assisted Writing, Summarization, Translation, Coding, Analysis, Visualization, and Review Controls. 12.11.9(a) AI-assisted writing shall be reviewed for accuracy, source support, tone, boundary language, public-safe status, overclaim, omission of limitations, conflicts, public authority meaning, finance meaning, provider or sponsor meaning, and correction path.
12.11.9(b) AI-assisted summarization shall be reviewed against source materials and shall not omit limitations, uncertainty, dissent, restrictions, public-safe controls, protected knowledge, public authority capacity, finance-boundary language, sponsor or provider roles, or correction status where material.
12.11.9(c) AI-assisted translation shall be reviewed for legal meaning, technical meaning, public authority meaning, finance meaning, safeguards meaning, cultural meaning, controlled vocabulary consistency, localization status, and divergence risk.
12.11.9(d) AI-assisted coding shall be reviewed for security, dependencies, licensing, secrets, vulnerabilities, correctness, maintainability, IP, data handling, public-safe release, and secure development controls.
12.11.9(e) AI-assisted analysis and visualization shall be reviewed for method fit, data quality, assumptions, statistical validity, model limitations, visualization distortion, public-safe interpretation, and unsupported precision.
12.11.9(f) AI-assisted review shall not substitute for required peer review, expert review, legal review, public-safe review, cybersecurity review, safeguards review, or publication approval.
12.11.9(g) The controlling rule shall be that AI assistance may accelerate work but shall not weaken review gates.
12.11.10 Correction, Withdrawal, or Retraction for AI-Related Publication Failures. 12.11.10(a) AI-related publication failures shall trigger correction, clarification, downgrade, suspension, withdrawal, retraction, public-safe notice, controlled notice, model or inference record review, data review, training update, and process remediation as appropriate.
12.11.10(b) AI-related publication failures may include hallucinated claims, fabricated sources, false citations, inaccurate translation, biased output, unsafe summarization, unsupported public authority implication, finance overclaim, provider or sponsor overclaim, protected knowledge exposure, personal data exposure, cyber-sensitive exposure, false technical output, unreviewed AI-generated code, or unauthorized AI use.
12.11.10(c) Correction shall address both the published material and the AI-use process that produced or contributed to the failure, including model register, inference record, prompt or retrieval controls where material, human review, publication approval, and training.
12.11.10(d) Where AI-related failure affects downstream materials, GCRI Canada shall conduct dependency review and issue public-safe or controlled notices where required.
12.11.10(e) The controlling rule shall be that AI-related publication failures must be corrected as system failures, not merely wording errors.
12.12 Publication Authority
12.12.1 Publication Authority as Records-Valid Delegation. 12.12.1(a) Publication authority shall exist only through records-valid delegation, Board authority, officer authority, committee authority, policy authority, protocol authority, technical release authority, public-safe publication authority, or other approved record.
12.12.1(b) Publication authority shall identify who may approve which publication class, under what review gates, for what audience, with what classification, public-safe status, boundary language, versioning, distribution channels, correction path, and archive requirements.
12.12.1(c) Email, chat, verbal agreement, meeting discussion, event planning, sponsor approval, provider approval, public authority interest, media request, researcher assumption, draft circulation, or prior similar publication shall not constitute publication authority unless incorporated into an approved record.
12.12.1(d) Publication authority shall be role-based, scope-limited, revocable, reviewable, and correctionable.
12.12.1(e) The controlling rule shall be that publication occurs by recorded authority, not by momentum.
12.12.2 Board-Reserved Publications. 12.12.2(a) The Board may reserve approval authority over publications that materially affect GCRI Canada’s Charter, bylaws, mission lock, public-benefit identity, legal separateness, public-good stack position, major public authority relationships, major finance-facing interfaces, major sponsor or provider controversies, significant corrections, major retractions, high-risk public-safe matters, or institutional reputation where reputation is tied to mission integrity.
12.12.2(b) Board-reserved publications may include constitutional statements, annual public-safe reports, major research reports, major policy positions, major public authority interface statements, major finance-boundary statements, major sponsor or provider correction statements, high-risk technical baseline releases, major public-safe correction notices, and material retractions.
12.12.2(c) Board review shall not convert the Board into a research author, public authority, finance actor, certification body, recognition body, protocol authority, or execution actor.
12.12.2(d) Board-reserved publication records shall identify Board authority, materials reviewed, review gates satisfied, conflicts and recusals, publication scope, public-safe status, boundary language, and correction path.
12.12.2(e) The controlling rule shall be that Board reservation protects institutional meaning without politicizing research findings.
12.12.3 Officer-Approved Publications. 12.12.3(a) Officers may approve publications within delegated authority, including public-safe summaries, technical notes, research communications, website materials, program materials, non-material corrections, controlled notices, internal materials, and other publication classes assigned by policy or delegation.
12.12.3(b) Officer approval shall be conditioned on satisfaction of required research, public-safe, legal, data, AI, cybersecurity, public authority, finance-boundary, provider-neutrality, sponsor non-control, safeguards, and technical review gates.
12.12.3(c) Officers shall escalate publications that exceed their delegation, create boundary risk, involve public authority sensitivity, finance sensitivity, protected knowledge, cybersecurity risk, major sponsor or provider implications, or material public reliance.
12.12.3(d) Officer approval records shall identify approving officer, delegated authority, publication class, version, review gates, public-safe status, publication date, distribution channel, and correction path.
12.12.3(e) The controlling rule shall be that officer approval is valid only within recorded delegation and review.
12.12.4 Committee-Reviewed Publications. 12.12.4(a) Committees may review publications within their mandate, including research integrity, public-safe publication, technical asset, data governance, cybersecurity, safeguards, public authority, finance-boundary, conflict, audit, or records matters.
12.12.4(b) Committee review may be advisory, approval-based, condition-setting, escalation-based, or assurance-based depending on the committee’s recorded authority.
12.12.4(c) Committee-reviewed publication records shall identify committee role, materials reviewed, conditions, unresolved issues, dissent where material, approval status where applicable, public-safe status, and escalation requirements.
12.12.4(d) Committee review shall not create publication authority where the committee has no delegated approval authority, nor shall it create public authority approval, finance-readiness, certification, recognition, provider endorsement, sponsor validation, protocol effect, or execution authority.
12.12.4(e) The controlling rule shall be that committee review improves governance only within its recorded mandate.
12.12.5 Research-Lead Publications. 12.12.5(a) Research leads may prepare and recommend publications within their approved research protocol, subject to review gates, publication authority, public-safe review, conflict controls, data governance, AI-use rules, cybersecurity, safeguards, and correctionability.
12.12.5(b) Research leads shall ensure that publication materials accurately reflect research protocol, methods, sources, assumptions, limitations, uncertainty, confidence, review status, conflicts, sponsor and provider roles where material, public authority capacity where material, finance-boundary language where material, and correction path.
12.12.5(c) Research leads shall not independently publish GCRI Canada research outputs unless delegated publication authority exists and all review gates are satisfied.
12.12.5(d) Research-lead publication records shall identify protocol, research output, version, reviewers, review conditions, approvals, public-safe status, and archive path.
12.12.5(e) The controlling rule shall be that research leads carry responsibility for research integrity but publication authority remains record-bound.
12.12.6 Technical-Release Publications. 12.12.6(a) Technical-release publications shall include public-good software releases, technical baseline releases, API releases, schema releases, data contract releases, dataset releases, model releases, benchmark releases, evaluation harness releases, dashboard releases, map releases, repository releases, SBOM-related notices, vulnerability advisories, and release notes.
12.12.6(b) Technical-release publications shall require secure release review, repository review, license review, IP review, dependency review, vulnerability review, secrets review, public-safe review, export-control review where applicable, sanctions review where applicable, controlled technology review where applicable, data review, AI-use review where applicable, and correction path.
12.12.6(c) Technical releases shall include version, scope, intended use, prohibited use, known limitations, security status, public-safe status, compatibility status, boundary language, dependency notes, and correction path where material.
12.12.6(d) Technical releases shall not imply certification, conformance, public authority approval, procurement preference, finance-readiness, provider endorsement, sponsor validation, protocol effect, operational clearance, infrastructure operation, managed service status, warranty, guarantee, or execution authority.
12.12.6(e) The controlling rule shall be that technical release publication must protect security, rights, and boundaries before utility.
12.12.7 Public Authority Materials. 12.12.7(a) Public authority materials shall include any publication, briefing, dashboard, map, report, technical note, evidence pack, decision-support material, public-safe summary, room material, data contribution summary, public authority reference, or learning material intended for, involving, or referencing a public authority.
12.12.7(b) Public authority materials shall require capacity classification, public authority reference approval where applicable, public-safe review, confidentiality review, data permission review, no-delegation language, no-endorsement language, no-public-warning language, no-emergency-command language, no-procurement language, no-public-finance language, and correction path.
12.12.7(c) Public authority materials shall not state or imply that GCRI Canada is acting as a regulator, public authority, public warning authority, emergency command actor, procurement body, public finance approver, official guidance issuer, or sovereign actor.
12.12.7(d) Public authority names, logos, titles, quotes, photos, agency references, jurisdiction references, and data contributions shall not be used in publication without required approval and boundary language.
12.12.7(e) The controlling rule shall be that public authority publications must support learning without borrowing public authority.
12.12.8 Sponsor, Donor, Funder, Provider, Host, or Partner-Referenced Publications. 12.12.8(a) Publications referencing sponsors, donors, funders, providers, hosts, universities, partners, contributors, equipment suppliers, data contributors, compute contributors, field sites, or in-kind support shall be reviewed for accuracy, conflict disclosure, public-safe status, sponsor non-control, provider neutrality, host boundary, funding disclosure, IP, confidentiality, public claims, and correction path.
12.12.8(b) Such publications shall not imply sponsor control, provider preference, procurement advantage, certification, recognition, finance-readiness, public authority approval, protocol effect, outcome purchase, publication veto, or public-good asset ownership.
12.12.8(c) Public acknowledgments shall be factual, proportionate, non-promotional, public-safe, and bounded by role records.
12.12.8(d) Sponsors, donors, funders, providers, hosts, or partners may review references to themselves for factual accuracy where permitted, but shall not control findings, methods, conclusions, limitations, correction, or publication decision.
12.12.8(e) The controlling rule shall be that acknowledgments may recognize support without transforming support into authority.