From 3684991c277caeb4f5602bdd49f60c4117377bad Mon Sep 17 00:00:00 2001 From: Igor Holt Date: Fri, 10 Jul 2026 14:32:21 -0400 Subject: [PATCH 1/6] docs: answer EU AI Act GKE governance assessment controls --- .../eu_ai_act_driver_upgraded_assessment.yml | 359 ++++++++++++++++++ 1 file changed, 359 insertions(+) create mode 100644 docs/eu-ai-act-gke-governance/eu_ai_act_driver_upgraded_assessment.yml diff --git a/docs/eu-ai-act-gke-governance/eu_ai_act_driver_upgraded_assessment.yml b/docs/eu-ai-act-gke-governance/eu_ai_act_driver_upgraded_assessment.yml new file mode 100644 index 0000000..b701266 --- /dev/null +++ b/docs/eu-ai-act-gke-governance/eu_ai_act_driver_upgraded_assessment.yml @@ -0,0 +1,359 @@ +schema_version: 2.1.0 +assessment_id: gc-self-evolving-retrainer-gke-network-2026-07-10 +assessment_type: EU AI Act deployment-gate driver +status: blocked_pending_external_legal_and_production_remediation +last_updated: '2026-07-10' +owner: Igor Holt +legal_reviewer: UNASSIGNED — independent external legal/classification reviewer required +technical_owner: Igor Holt +system: + name: Self-Evolving Retrainer with GKE Pod Network Governance + organization: Genesis Conductor Ecosystem / Kovach Enterprises + repository: Genesis-Conductor-Engine/self-evolving-retrainer + intended_purpose: Optimize agent prompts and prepare read-only GKE pod-network audits, capacity plans, collision + reports, and human-reviewable change plans. + prohibited_execution_scope: + - No autonomous GKE CIDR mutation + - No self-approval of legal classification + - No on-chain publication without external authorization + deployment_mode: shadow + affected_persons: + - Genesis Conductor workspace operators and administrators + - Users who interact with the Botpress or agent conversational interface + - Downstream service users only if a future deployment uses recommendations to operate production infrastructure + data_categories: + - Prompt text, model responses, evaluation scores, and prompt-version metadata + - GKE cluster, subnet, secondary-range, pod-IP, service-IP, node-pool, and utilization metadata + - Operational logs, timestamps, request identifiers, decision hashes, approval identities, and incident records + - Operator identifiers such as name, business email, workspace user ID, and service-account identity + - Secrets are prohibited from prompts, evidence payloads, logs, and Notion/GitHub documentation + - Special-category personal data, biometric data, health data, employment decisions, education decisions, credit + decisions, law-enforcement data, and social-scoring data are out of scope + model_inventory: + - provider: OpenAI + role: Implemented runtime adapter for prompt mutation and judging + configured_model_identifiers: + - gpt-5.4-mini + - gpt-5.4-nano + status: configured_in_repository; live availability and contractual terms not independently verified + - provider: Notion AI / undisclosed underlying provider + role: Workspace-hosted Self-Evolving Retraining Agent interface + configured_model_identifiers: + - Apricot Sorbet (Medium) + status: active agent metadata; underlying provider/model card not available in the reviewed evidence + - provider: Multiple third-party providers + role: Planned or specification-level ensemble + configured_model_identifiers: + - Mistral Codestral 2501 + - Anthropic Claude Fable 5 + - Google Gemini 2.5 Pro + - OpenAI GPT-5-codex + status: specification only; not treated as verified production dependencies +classification: + prohibited_practice_screen: + status: provisionally_clear_for_documented_scope + determination: not_a_prohibited_practice_for_the_documented_intended_use + rationale: The approved scope is prompt optimization plus read-only GKE network evidence collection and human-reviewable + change planning. It does not perform manipulation, exploitation of vulnerabilities, social scoring, biometric + categorization, emotion recognition, predictive policing, facial-image scraping, or other Article 5 uses. + Any change of purpose into those domains is out of scope and NO_GO. + reviewer: Igor Holt — technical preliminary assessment; independent legal reviewer pending + evidence: + - 'EUR-Lex: Regulation (EU) 2024/1689, CELEX 32024R1689' + - EU AI Act Article 5 — prohibited AI practices + - 'Notion: Self-Evolving Agent Retraining Worker and Cross-Surface Integration Spec' + - botpress/agent-definition.md + high_risk_screen: + status: provisionally_not_high_risk_for_documented_scope + annex_or_use_case: No current Annex III natural-person decision use. Reclassification is mandatory if the system + becomes a safety component in the management or operation of critical digital infrastructure or materially + influences an Annex III decision. + determination: not_high_risk_for_current_shadow_read_only_internal_use + rationale: The current system prepares procedural audits and plans and cannot execute GKE mutations. It does + not profile natural persons. Annex III point 2 remains a conditional trigger for any future safety-component + deployment in critical digital infrastructure. + reviewer: Igor Holt — technical preliminary assessment; independent legal reviewer pending + evidence: + - EU AI Act Article 6 and Annex III — high-risk classification + - 'Notion: Self-Evolving Agent Retraining Worker and Cross-Surface Integration Spec' + - 'Notion/Skill: gke-pod-network-manager' + transparency_obligations: + status: applicable + determination: The Botpress/agent interface must clearly disclose that users are interacting with AI. Generated + content must be marked or otherwise identifiable where Article 50 applies. Infrastructure decision outputs + must state that they are recommendations/change plans, not executed changes. + rationale: The system directly interacts with natural persons through conversational interfaces and generates + text recommendations. + evidence: + - EU AI Act Article 50 — disclosure for direct interaction with natural persons + - botpress/agent-definition.md + general_purpose_ai_dependencies: + status: documented_with_provider_due_diligence_incomplete + providers: + - OpenAI + - Notion AI / undisclosed underlying provider + - 'planned: Mistral, Anthropic, Google' + model_cards: + - OpenAI model documentation and system cards — must be attached for the exact production model IDs + - Notion AI underlying model/provider disclosure — not available in the reviewed evidence + - Planned ensemble provider model cards — required before activation + contractual_evidence: + - Provider terms, data-processing terms, regional processing, retention, subprocessor, and model-version commitments + are not attached +controls: +- id: EU-AIA-01 + category: prohibited-use + question: Could the system be configured or repurposed for a prohibited practice? + answer: no_for_approved_scope + owner: Igor Holt + evidence: + - EU AI Act Article 5 — prohibited AI practices + - 'Notion: Self-Evolving Agent Retraining Worker and Cross-Surface Integration Spec' + - botpress/agent-definition.md + deployment_effect: block_all_if_yes; block_mutation_if_unanswered + rationale: Documented use is operational prompt/network governance, not an Article 5 prohibited use. Repurposing + is expressly out of scope and blocked. + residual_gap: Independent legal reviewer must confirm before EU market deployment. +- id: EU-AIA-02 + category: high-risk + question: Does any intended use fall within a high-risk use case or safety component? + answer: no_for_current_scope_conditional_reclassification_required + owner: Igor Holt + evidence: + - EU AI Act Article 6 and Annex III — high-risk classification + - 'Notion/Skill: gke-pod-network-manager' + deployment_effect: block_mutation_if_unanswered + rationale: Current shadow/read-only use is procedural and does not control critical-infrastructure safety or make + Annex III decisions about natural persons. + residual_gap: Treat as potentially high-risk if used as a safety component of critical digital infrastructure. +- id: EU-AIA-03 + category: human-oversight + question: Are named operators authorized to review, contest, and stop every mutation? + answer: yes_for_shadow_and_change_approval_scope + owner: Igor Holt + evidence: + - EU AI Act Articles 12, 14, and 15 — logging, human oversight, accuracy/robustness/cybersecurity + - EU AI Act Articles 26, 72, and 73 — deployer oversight, retention, monitoring, and incident reporting + - 'Notion: Project Instructions — Genesis Conductor Ecosystem (Igor Holt, Principal Investigator)' + - 'Notion: Self-Evolving Agent Retraining Worker and Cross-Surface Integration Spec' + deployment_effect: require_external_settle + rationale: Igor Holt is the named accountable operator, technical owner, SETTLE approver, and revocation authority. + Every mutation remains stoppable and requires evidence-bound human approval. + residual_gap: A second independent security/network reviewer is required before active production mutation. +- id: EU-AIA-04 + category: risk-management + question: Is there an approved risk-management file covering failure modes and foreseeable misuse? + answer: yes_engineering_risk_file_created_legal_review_pending + owner: Igor Holt + evidence: + - docs/risk-management-plan.md + - 'Notion: KEGCI Security Audit — 2026-04-05' + - 'Notion: Genesis Conductor — Claim Validation & Architecture Maturity Report (2026-07-10)' + deployment_effect: block_mutation_if_unanswered + rationale: A consolidated risk file now covers foreseeable misuse, CIDR collision, Autopilot constraints, evidence + tampering, model drift, security findings, and rollback. + residual_gap: Independent legal/classification approval is still required. +- id: EU-AIA-05 + category: data-governance + question: Are telemetry, prompt, cluster, and user-data sources inventoried with retention and access controls? + answer: partial_no_for_production + owner: Igor Holt + evidence: + - docs/data-governance-register.yml + - 'Notion: KEGCI Security Audit — 2026-04-05' + deployment_effect: block_mutation_if_unanswered + rationale: Data categories, retention, access roles, prohibited data, and deletion rules are now inventoried. + residual_gap: The April security audit recorded exposed secrets and incomplete access controls; remediation has + not been independently verified. +- id: EU-AIA-06 + category: technical-documentation + question: Can every decision be reproduced from versioned code, configuration, evidence, and model identifiers? + answer: partial_governance_decisions_reproducible_model_semantics_not_fully_replayable + owner: Igor Holt + evidence: + - 'GitHub: Genesis-Conductor-Engine/self-evolving-retrainer' + - reports/test-report.txt — 18 tests passed + - 'Notion: Genesis Conductor — Claim Validation & Architecture Maturity Report (2026-07-10)' + - docs/decision-reproduction-requirements.md + deployment_effect: signed_evidence_required + rationale: Canonical evidence, decision hashes, code, tests, and configuration can reproduce governance outcomes. + residual_gap: Exact LLM semantic replay still requires model/runtime digest, seed, retrieval snapshot, tool outputs, + and version-locked execution. +- id: EU-AIA-07 + category: logging + question: Are immutable logs, decision hashes, and rollback records retained for the approved period? + answer: partial_no_for_production + owner: Igor Holt + evidence: + - EU AI Act Articles 12, 14, and 15 — logging, human oversight, accuracy/robustness/cybersecurity + - EU AI Act Articles 26, 72, and 73 — deployer oversight, retention, monitoring, and incident reporting + - 'GitHub: Genesis-Conductor-Engine/self-evolving-retrainer' + - 'Notion: Genesis Conductor — Claim Validation & Architecture Maturity Report (2026-07-10)' + - docs/data-governance-register.yml + deployment_effect: signed_evidence_required + rationale: Decision hashes, D1/KV/queue records, Pareto snapshots, and rollback concepts exist, and a provisional + retention policy is defined. + residual_gap: Immutable/WORM or on-chain anchoring and enforcement of retention periods are not independently + verified. +- id: EU-AIA-08 + category: accuracy-robustness-cybersecurity + question: Are accuracy, collision detection, authentication, secret handling, and rollback controls tested? + answer: partial_no_for_production + owner: Igor Holt + evidence: + - reports/test-report.txt — 18 tests passed + - 'Notion: KEGCI Security Audit — 2026-04-05' + - 'Notion: Genesis Conductor — Claim Validation & Architecture Maturity Report (2026-07-10)' + deployment_effect: tests_and_security_review_required + rationale: Collision detection, invalid CIDR handling, shadow denial, Autopilot denial, tamper detection, and + SETTLE binding passed 18 tests. + residual_gap: Critical and high security-audit findings remain unverified as remediated; no penetration test or + live GKE deployment certification exists. +- id: EU-AIA-09 + category: incident-post-market-monitoring + question: Are incident reporting, drift monitoring, owner escalation, and corrective-action workflows assigned? + answer: yes_plan_and_owner_assigned_live_monitoring_pending + owner: Igor Holt + evidence: + - docs/incident-response-and-post-market-monitoring.md + - EU AI Act Articles 26, 72, and 73 — deployer oversight, retention, monitoring, and incident reporting + - 'Notion: KEGCI Security Audit — 2026-04-05' + deployment_effect: block_mutation_if_unanswered + rationale: Igor Holt is assigned incident owner; severity, suspension, escalation, evidence preservation, corrective + action, and review procedures are defined. + residual_gap: Alert integrations, drills, and evidence that the monitoring plan is operating continuously are + pending. +technical_controls: + shadow_mode_default: true + read_only_discovery_identity: dedicated least-privilege GCP service account + mutation_identity: separate operator-controlled identity + signed_evidence: + required: true + algorithm: HMAC-SHA256 + secret_reference: GKE_EVIDENCE_HMAC_SECRET + signer_identity: Dedicated service identity, separate from the retrainer + provisioning_status: not independently verified + human_settle: + required: true + fields: + - approved + - approver + - approved_at + - evidence_sha256 + accountable_operator: Igor Holt + settle_approver: Igor Holt + revocation_authority: Igor Holt + second_reviewer_for_active_mutation: UNASSIGNED — required before production activation + network_safety: + fleet_wide_collision_check_required: true + warning_utilization_pct: 80 + critical_utilization_pct: 90 + autopilot_range_mutation: deny + attestation: + target_network: Base + chain_id: 8453 + mode: prepare-only + publication_gate: Alchemy team access plus external SETTLE + data_minimization: + raw_prompt_retention_days: 30 + gke_operational_telemetry_retention_days: 180 + decision_evidence_and_approval_retention_days: 365 + incident_and_security_record_retention_days: 365 + internal_contest_window_days: 30 + legal_hold_override: true + status: provisional engineering policy; legal/privacy review pending + transparency: + ai_interaction_disclosure_required: true + recommendation_not_execution_notice_required: true + generated_content_marking_required_where_applicable: true +artifacts: + repository_branch: feat/eu-ai-act-gke-governance-20260710 + source_module: src/services/gke_governance.mjs + worker_routes: src/services/http_routes.mjs + evidence_runner: scripts/gke_evidence_runner.py + node_tests: tests/gke_governance.test.mjs + python_tests: tests/test_gke_evidence_runner.py + botpress_definition: botpress/agent-definition.md + alchemy_manifest: alchemy/app-manifest.yml + risk_management_plan: docs/risk-management-plan.md + data_governance_register: docs/data-governance-register.yml + incident_monitoring_plan: docs/incident-response-and-post-market-monitoring.md + reproduction_requirements: docs/decision-reproduction-requirements.md + answered_assessment_summary: reports/assessment-summary.json +deployment_gates: +- id: GATE-01 + name: Prohibited-practice clearance + condition: classification.prohibited_practice_screen.status == clear + failure_action: NO_GO +- id: GATE-02 + name: Owner answers complete + condition: all controls have owner, answer, and evidence or approved exception + failure_action: NO_GO for mutation; shadow read-only only +- id: GATE-03 + name: Fleet collision clearance + condition: collisions == [] + failure_action: NO_GO +- id: GATE-04 + name: Signed evidence + condition: HMAC signature valid and report hash immutable + failure_action: NO_GO +- id: GATE-05 + name: External human SETTLE + condition: approval binds to evidence_sha256 + failure_action: NO_GO +- id: GATE-06 + name: Production infrastructure ready + condition: Cloudflare resource IDs, GCP identities, Botpress secrets, and Alchemy team access configured + failure_action: NO_GO +open_questions: +- Who will serve as the independent qualified legal/classification reviewer? +- What are the verified GKE region, VPC, subnet, secondary ranges, and read-only/mutation service-account identities? +- Which security-audit findings have been remediated, and where are the independent retest results? +- What exact production model IDs, provider terms, data-processing terms, model cards, and region/retention commitments + are approved? +- What is the independently verified Base network contract address and bytecode hash for the canonical attestor? +- Which authorized Alchemy team/app and allowlists will be used for publication? +- Who is the second independent security/network reviewer required for active infrastructure mutation? +disclaimer: This file now contains an accountable-owner engineering assessment and operational policy decisions + for shadow/read-only use. It is not an independent legal opinion, conformity assessment, or authorization to activate + production mutation. All production_blockers are hard gates. +approval: + engineering_owner_decision: approved_for_shadow_read_only_and_change_planning_only + approved_by: Igor Holt + approved_on: '2026-07-10' + legal_classification_approval: pending + production_activation_approval: denied_until_all_blockers_close +production_blockers: +- id: BLOCK-LEGAL-01 + severity: hard_gate + blocker: No independent legal/classification reviewer exists in the connected workspace. + closure_evidence: Named qualified reviewer plus signed classification decision. +- id: BLOCK-SEC-01 + severity: hard_gate + blocker: KEGCI Security Audit reported six P0 and five P1 findings; closure is not independently verified. + closure_evidence: Rotations/remediations, least-privilege identities, secret scan, security-agent coverage, and + independent retest. +- id: BLOCK-GKE-01 + severity: hard_gate + blocker: Exact GKE region, VPC, subnet, secondary CIDRs, and read-only/mutation service accounts are not verified. + closure_evidence: Signed live inventory and fleet-wide collision report from project yenn-484707 or the formally + approved replacement project. +- id: BLOCK-REPRO-01 + severity: hard_gate + blocker: Model/runtime/retrieval semantic replay is not complete. + closure_evidence: Version-locked reproduction manifest with model digest, runtime digest, seed, retrieval snapshot, + tool results, and tolerance. +- id: BLOCK-LOG-01 + severity: hard_gate + blocker: Immutable log anchoring and retention enforcement are not independently verified. + closure_evidence: WORM or independently verifiable anchor, retention policy enforcement, restore test, and evidence + withdrawal procedure. +- id: BLOCK-CF-01 + severity: deployment_gate + blocker: Cloudflare D1/KV identifiers and production secrets remain unverified or placeholder-bound. + closure_evidence: Provisioned resource IDs, secret references, deployment receipt, and health checks. +- id: BLOCK-CHAIN-01 + severity: deployment_gate + blocker: Alchemy account/team/app access and canonical Base contract address are unavailable or unverified. + closure_evidence: Authorized Alchemy team/app, allowlists, independently verified contract address/bytecode, and + isolated signer. From 21c1bbe70ca8097ace14fc9dcba7549a61d45049 Mon Sep 17 00:00:00 2001 From: Igor Holt Date: Fri, 10 Jul 2026 14:33:38 -0400 Subject: [PATCH 2/6] docs: add EU AI Act GKE risk management plan --- .../risk-management-plan.md | 29 +++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 docs/eu-ai-act-gke-governance/risk-management-plan.md diff --git a/docs/eu-ai-act-gke-governance/risk-management-plan.md b/docs/eu-ai-act-gke-governance/risk-management-plan.md new file mode 100644 index 0000000..c39c0b1 --- /dev/null +++ b/docs/eu-ai-act-gke-governance/risk-management-plan.md @@ -0,0 +1,29 @@ +# Risk Management Plan — Self-Evolving Retrainer with GKE Pod Network Governance + +**Owner:** Igor Holt +**Engineering approval:** Shadow/read-only and change-planning use only, 2026-07-10 +**Legal/classification approval:** Pending independent review +**Production mutation:** NO_GO until every hard gate closes + +## Scope and safety boundary + +The system may optimize prompts, collect read-only GKE network evidence, detect CIDR collisions, report utilization, and prepare human-reviewable change plans. It may not autonomously mutate GKE, approve its own assessment, sign its own evidence, or publish an on-chain attestation. + +## Material risks and controls + +| Risk | Preventive control | Detection | Response / rollback | Current state | +|---|---|---|---|---| +| Article 5 prohibited-purpose repurposing | Fixed intended purpose, denied data/use categories, prompt and route guard | Assessment and request screening | Stop, reject, preserve evidence, legal review | Controlled for documented scope | +| High-risk critical-infrastructure use | Conditional Annex III reclassification gate | Deployment-context review | Keep shadow; require conformity program | Not activated | +| CIDR overlap or route collision | Fleet-wide enumeration and overlap test | Signed collision report | NO_GO; choose non-overlapping range | Tested | +| Pod-IP exhaustion | 80% warning / 90% critical thresholds | Utilization report and trend | Capacity plan; no autonomous expansion | Tested | +| Autopilot immutable-range misuse | Explicit action denial | Cluster-type validation | Replacement/migration plan | Tested | +| Evidence tampering | Canonical JSON, SHA-256, HMAC-SHA256, evidence-bound SETTLE | Signature verification | Reject and rotate signer if compromise suspected | Tested; signer provisioning unverified | +| Prompt/model drift | Pareto snapshots, queue-safe evaluation, rollback guard | Quality/latency/cost regression metrics | Revert active prompt version | Implemented concept; live evidence required | +| Secret leakage / excessive access | Secret Manager/worker secrets, redaction, least privilege, separate identities | Secret scans and audit logs | Revoke, rotate, incident response | Blocked by open security-audit findings | +| Overclaiming proof or determinism | Claim-maturity labels and refusal-over-fabrication policy | Evidence registry review | Downgrade claim; publish correction | Documented | +| Monitoring failure | Scheduled health/queue/log checks and incident owner | Alerting and periodic review | Suspend service and open incident | Plan created; live operation unverified | + +## Release decision + +Active mutation is prohibited until an independent legal reviewer, second security/network reviewer, verified GKE identities, closed security findings, immutable evidence retention, provider due diligence, Cloudflare resources, and Alchemy/Base publication controls are documented. From 0c505cf30e0fe635232c42fc05214626317b292f Mon Sep 17 00:00:00 2001 From: Igor Holt Date: Fri, 10 Jul 2026 14:34:42 -0400 Subject: [PATCH 3/6] docs: add GKE governance data register --- .../data-governance-register.yml | 71 +++++++++++++++++++ 1 file changed, 71 insertions(+) create mode 100644 docs/eu-ai-act-gke-governance/data-governance-register.yml diff --git a/docs/eu-ai-act-gke-governance/data-governance-register.yml b/docs/eu-ai-act-gke-governance/data-governance-register.yml new file mode 100644 index 0000000..e95688e --- /dev/null +++ b/docs/eu-ai-act-gke-governance/data-governance-register.yml @@ -0,0 +1,71 @@ +schema_version: 1.0.0 +owner: Igor Holt +status: provisional_engineering_policy_legal_privacy_review_pending +systems: +- source: Self-Evolving Retrainer + data: + - prompts + - model outputs + - judge scores + - prompt versions + - cost and latency metrics + purpose: bounded prompt optimization and regression evaluation + retention_days: + raw_content: 30 + decision_metadata: 365 + access: + - Igor Holt + - dedicated worker service identity +- source: GKE Pod Network Manager + data: + - cluster names + - regions + - subnets + - secondary CIDRs + - pod/service IPs + - node pools + - utilization + purpose: network audit, collision detection, capacity planning, and change-plan preparation + retention_days: 180 + access: + - Igor Holt + - read-only GCP discovery service account +- source: Governance and incident plane + data: + - decision hashes + - evidence signatures + - approver identity + - timestamps + - incident records + - corrective actions + purpose: auditability, contestability, rollback, incident response, and compliance evidence + retention_days: 365 + access: + - Igor Holt + - evidence signer identity + - independent reviewer when appointed +personal_data: +- business name +- business email +- workspace user ID +- approver/reviewer identity +- user prompt content if supplied +prohibited_data: +- secrets and private keys +- special-category personal data +- biometric data +- health records +- employment, education, credit, insurance, law-enforcement, immigration, or social-scoring decision data +controls: +- data minimization and purpose limitation +- redaction before logging +- least-privilege service identities +- separate read-only and mutation identities +- Secret Manager/worker secret storage +- deletion at retention expiry +- legal hold only when documented +- 30-day internal contest window +known_gaps: +- April 2026 security audit remediation is not independently verified +- provider data-processing and subprocessor terms are not attached +- retention enforcement and deletion tests are not evidenced From 8e9215ce12f349385188ff761600632c7f654ef3 Mon Sep 17 00:00:00 2001 From: Igor Holt Date: Fri, 10 Jul 2026 14:35:50 -0400 Subject: [PATCH 4/6] docs: add incident and post-market monitoring plan --- ...ent-response-and-post-market-monitoring.md | 32 +++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 docs/eu-ai-act-gke-governance/incident-response-and-post-market-monitoring.md diff --git a/docs/eu-ai-act-gke-governance/incident-response-and-post-market-monitoring.md b/docs/eu-ai-act-gke-governance/incident-response-and-post-market-monitoring.md new file mode 100644 index 0000000..885fbd7 --- /dev/null +++ b/docs/eu-ai-act-gke-governance/incident-response-and-post-market-monitoring.md @@ -0,0 +1,32 @@ +# Incident Response and Post-Market Monitoring Plan + +**Incident owner:** Igor Holt +**Scope:** Self-Evolving Retrainer, GKE governance worker, evidence signer, Botpress interface, Cloudflare resources, and Base/Alchemy publication path. + +## Monitoring inputs + +- Cloudflare Worker health, queue failures, D1/KV errors, budget alerts, and dead-letter queue. +- GCP Cloud Logging, IAM changes, Secret Manager access, GKE audit logs, pod scheduling failures, and IP-utilization thresholds. +- GitHub CI, dependency/security alerts, branch-protection events, and release hashes. +- Evidence-signature failures, decision/SETTLE mismatches, CIDR collisions, model-quality drift, and unexpected model/provider changes. + +## Severity and response + +| Severity | Trigger | Required action | +|---|---|---| +| P0 | Secret/key exposure, unauthorized mutation, signer compromise, prohibited-use activation, material evidence tampering | Immediately suspend mutation/publication, revoke credentials, preserve logs, notify owner, start root-cause analysis | +| P1 | CIDR collision, critical IP exhaustion, repeated auth failures, critical dependency outage | Suspend affected workflow, open incident, create corrective plan within 24 hours | +| P2 | Degraded quality/latency, incomplete evidence, monitoring gap | Keep shadow, remediate within five business days | +| P3 | Documentation or low-risk operational defect | Backlog with owner and due date | + +## Post-market / operational review + +- Continuous automated health and signature checks where deployed. +- Weekly review of active alerts, failures, model/provider changes, and unresolved controls. +- Monthly review of drift, cost, latency, prompt rollback, GKE utilization, and access logs. +- Quarterly tabletop exercise for secret compromise, unauthorized mutation, and evidence withdrawal. +- Every incident records detection time, scope, affected systems/persons, evidence hash, actions, root cause, corrective action, owner, closure criteria, and closure date. + +## Contest and suspension + +Users and operators may contest a governance decision within 30 days. Igor Holt may override, reverse, or stop any recommendation or mutation. Active use remains suspended when evidence is missing, signatures fail, legal classification changes, or a serious incident is open. From 6eaaaa44dc2cd59b9b3845877704bf8a5fd05279 Mon Sep 17 00:00:00 2001 From: Igor Holt Date: Fri, 10 Jul 2026 14:36:18 -0400 Subject: [PATCH 5/6] docs: define governance decision reproduction requirements --- .../decision-reproduction-requirements.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 docs/eu-ai-act-gke-governance/decision-reproduction-requirements.md diff --git a/docs/eu-ai-act-gke-governance/decision-reproduction-requirements.md b/docs/eu-ai-act-gke-governance/decision-reproduction-requirements.md new file mode 100644 index 0000000..4b2deb7 --- /dev/null +++ b/docs/eu-ai-act-gke-governance/decision-reproduction-requirements.md @@ -0,0 +1,15 @@ +# Decision Reproduction Requirements + +A governance decision is reproducible only when its evidence bundle contains: + +- repository, commit SHA, branch, dirty-state indicator, and artifact SHA-256 values; +- assessment version and hash; +- complete canonical request and evidence payload; +- configuration values with secrets replaced by stable secret-reference IDs; +- model provider, exact model identifier/version, system prompt hash, sampling parameters, seed when supported, and model response ID; +- retrieval corpus/snapshot identifiers and hashes; +- tool inputs, tool outputs, timestamps, and external resource versions; +- runtime/container image digest, dependency lockfile hash, region, and execution identity; +- decision hash, evidence signature, human SETTLE record, rollback target, and acceptance tolerance. + +Current status: deterministic governance hashing and tests are available. Exact semantic replay of probabilistic model output is not yet established and remains a production blocker. From cc65d5ee28d128a674b82549db41fdacaf47c02f Mon Sep 17 00:00:00 2001 From: Igor Holt Date: Fri, 10 Jul 2026 14:37:22 -0400 Subject: [PATCH 6/6] docs: add answered EU AI Act assessment summary --- .../assessment-summary.json | 35 +++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 docs/eu-ai-act-gke-governance/assessment-summary.json diff --git a/docs/eu-ai-act-gke-governance/assessment-summary.json b/docs/eu-ai-act-gke-governance/assessment-summary.json new file mode 100644 index 0000000..f6d8724 --- /dev/null +++ b/docs/eu-ai-act-gke-governance/assessment-summary.json @@ -0,0 +1,35 @@ +{ + "schema_version": "2.1.0", + "status": "blocked_pending_external_legal_and_production_remediation", + "control_count": 9, + "answered_control_count": 9, + "unanswered_control_count": 0, + "unanswered_controls": [], + "control_answers": { + "EU-AIA-01": "no_for_approved_scope", + "EU-AIA-02": "no_for_current_scope_conditional_reclassification_required", + "EU-AIA-03": "yes_for_shadow_and_change_approval_scope", + "EU-AIA-04": "yes_engineering_risk_file_created_legal_review_pending", + "EU-AIA-05": "partial_no_for_production", + "EU-AIA-06": "partial_governance_decisions_reproducible_model_semantics_not_fully_replayable", + "EU-AIA-07": "partial_no_for_production", + "EU-AIA-08": "partial_no_for_production", + "EU-AIA-09": "yes_plan_and_owner_assigned_live_monitoring_pending" + }, + "deployment_mode": "shadow", + "production_ready": false, + "production_blocker_count": 7, + "production_blockers": [ + "BLOCK-LEGAL-01", + "BLOCK-SEC-01", + "BLOCK-GKE-01", + "BLOCK-REPRO-01", + "BLOCK-LOG-01", + "BLOCK-CF-01", + "BLOCK-CHAIN-01" + ], + "legal_reviewer_assigned": false, + "accountable_owner": "Igor Holt ", + "technical_owner": "Igor Holt ", + "settle_approver": "Igor Holt" +}