Press

Press contact: Nicholas Templeman, founder — press@councilof.ai

For deadline queries, include PRESS URGENT in the subject.

Corrections feed (RSS) — every correction is published here first.

Measurement, never certification. Verification is free and needs no account. Every line below carries the command that checks it.

Window 2026-09-17 → 2026-09-23. The 7 days ending at the newest date any committed artifact carries. NOT the clock: two requests any interval apart return the same window.

curl -s https://councilof.ai/api/press.json | jq .window

Corrections issued in this window — 7 of 63 total

Entries are things we got wrong about ourselves, how they were caught, and the fix. Publishing them is the credibility engine: the body that publishes the number also publishes when it was wrong.

C-2026-0923-02 2026-09-23

What was wrong. totals carries axes, measured_axes, unmeasured_axes, quotable_axes and the count line '23 axis · 23 measured', and no aggregate of the separation field at all. The same payload's limitations[0] states the measured position plainly: of the 14 model-comparison axes, 2 TIE, 12 UNTESTED. The count line is the line every other surface quotes, so the figure that travels is the one that cannot carry the negative.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0923-02")'

C-2026-0923-01 2026-09-23

What was wrong. Two surfaces this organisation publishes and signs give different answers to the same question about the same axis. GET /api/gspc reports swarm separation UNTESTED with leader 'qwen2.5:7b (base model)' over n=37. /signals/swarm.signed.json reports elo_separation SEPARATED with elo_leader 'nemotron-3-nano:30b' over 18 decided arena games. A reader asking whether we can tell two models apart on swarm gets two answers and two different model names, both carrying the board signature.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0923-01")'

C-2026-0922-02 2026-09-22

What was wrong. 32 signed measurement cards for the jail axis under /interop/mill-cards-signed/ published an accuracy for jailbreak-escape detection that was never measured. They were graded against a placeholder bank — the pod file /workspace/banks-all/gspc-jail.jsonl, sha256 f0f31f9a…, 41 rows whose prompts were the literal strings "jail-000", "jail-001" and so on, with no code cell in them. Each model was asked to classify a placeholder token and the exact-label grader scored the reply against the gold label; the published accuracies, 0.0 to 0.9487, are an artifact of which label a model happens to prefer. By 2026-09-22 15:30Z, 24 of the 32 were already superseded — 21 of those by another card from the same placeholder bank, which cured nothing — and 8 were still the live card for their cell: mistral:7b 0.9487 (n=39), phi3.5:3.8b 0.25 (n=40), qwen2.5:1.5b 0.0732 (n=41), mistral-nemo:12b and qwen2.5:0.5b-instruct 0.0488 (n=41), gemma3:4b 0.0256 (n=39), qwen2.5:7b 0.0244 (n=41), qwen3:4b 0 (n=41). All 32 carried status MEASURED and all 32 verify under did:web:csoai.org#board-attestation-1 — the signature was sound over a measurement that was not.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0922-02")'

C-2026-0922-01 2026-09-18

What was wrong. The 17 September note on the public root's odd-node duplication (corrections/merkle-count-binding-2026-09-17.md in the csoai/councilof-ai-mirror dataset) said that RFC 6962 domain-separation prefixes are the general fix for the padding collision it demonstrated, and that moving the public root to domain separation would close it by construction. Prefixing 0x00 before leaves and 0x01 before nodes while keeping odd-node duplication leaves the collision intact: the forged 306-leaf set and the honest 305-leaf set still hash to one root, because the substitution pairs a leaf with a leaf.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0922-01")'

C-2026-0920-01 2026-09-20

What was wrong. The site_attestation on GET /api/gspc did not verify under its own published preimage rule. excludeOwnLeader() and dropUncardedLeader() in functions/api/gspc.ts returned leader: undefined as an own property on the 11 axes whose leader is excluded or uncarded; the edge signer's canonical() emits an own undefined property as the literal text "leader":undefined, while JSON.stringify — which produces the served bytes — drops the key entirely. The signed bytes were therefore unreconstructable from the served bytes by anyone. An outside reconciliation on 2026-09-20 tried 11 preimage variants across two independent implementations (Node with the signer's exact canonical(); Python ensure_ascii both ways); none verified, while the same payload's living_stamp verified under the same pinned key.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0920-01")'

C-2026-0917-01 2026-09-17

What was wrong. public/interop/ots/manifest.json claimed 566 OpenTimestamps proofs, every row asserting state PENDING_BITCOIN_CONFIRMATION. Checked by deserialising each file it named, NONE of the 566 was a proof: each was a calendar response fragment saved under the .ots extension. A row asserting that a stamp exists and awaits Bitcoin confirmation, for bytes that are not a stamp, is a false claim about evidence. The same defect recurred four times across 16 and 17 September, reaching 1,915 claimed proofs at its largest, and a later sample of 40 from one branch again contained zero real proofs.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0917-01")'

C-2026-0917-02 2026-09-17

What was wrong. Every public surface councilof.ai serves answers HTTP 403 to a plain standard-library HTTP client while answering normally to a browser. Measured 17 September 2026: 21 of 21 published URLs, including /.well-known/did.json, /.well-known/agent-card.json, /.well-known/x402.json, robots.txt and llms.txt. Those five exist only for machines. We have told correspondents, standards bodies and regulators in writing that they can fetch our evidence and verify it without our cooperation. For anyone using a standard client, that was not true.

How it was caught.

Fix.

curl -s https://councilof.ai/api/corrections | jq '.corrections[]|select(.id=="C-2026-0917-02")'

The public root

merkle_root
40ce3833118fab76a98c55429a5b06c7c3051915780893f3ab60a25cb31ac0a4
leaves
305
as_of
2026-09-22T08:54:02Z
signature
SIGNED

A valid OpenTimestamps proof over root.json covers root.json BYTES ONLY. It does not anchor the signed-card index and it does not anchor GSPC.

curl -s https://councilof.ai/root.json | jq '{merkle_root,card_count,as_of}'

Signed measurement cards

335 indexed, 0 added in this window. This is the SIGNED CARD INDEX. It shares no members with the public-root leaf set or the on-disk wrapper count — three corpora, zero identifier overlap.

curl -s https://councilof.ai/signed/verify-card.mjs  # the same verifier we run

Distribution surfaces

NO surface is confirmed live. The spray log records drafted and queued rows only, every one owner-gated. A drafted row is not a published surface, and this field stays null rather than 0 so the gap is legible rather than counted as an achievement.

jq '[.[].status]|group_by(.)|map({(.[0]):length})|add' scripts/badger/_spray-log-v2.json

Commercial evidence

Revenue: the live settlement ledger records 1 outside settlement from 1 distinct non-self payer, totalling 0.02 USDC (20000 atomic units, 6 dp, on Base). This is a project-reported ledger: every record names its settlement transaction, so the chain is the check. Owner-controlled and zero-value settlements are excluded.

curl -s https://councilof.ai/api/revenue | jq '{settled_usdc,one_number}'

Questions we are actually asked

The questions are ours. Every answer is computed from the ledger, the board or the root at request time, so an answer cannot be edited into something the artifacts do not support.

Do you certify AI systems?

No. We measure, and we do not certify: no conformity marks, no accreditation, no conformity assessments. A grade is never sold, and verification is free and needs no account, permanently.

How many corrections have you issued about your own published figures?

63 to date, 7 in the 2026-09-17 to 2026-09-23 window. Each records what was wrong, how it was caught — usually by our own instrument — and the fix. The full ledger is at /api/corrections and the feed is /feeds/corrections.xml.

What is the most recent thing you got wrong?

C-2026-0923-01 (2026-09-23). Two surfaces this organisation publishes and signs give different answers to the same question about the same axis. GET /api/gspc reports swarm separation UNTESTED with leader 'qwen2.5:7b (base model)' over n=37. /signals/swarm.signed.json reports elo_separation SEPARATED with elo_leader 'nemotron-3-nano:30b' over 18 decided arena games. A reader asking whether we can tell two models apart on swarm gets two answers and two different model names, both carrying the board signature. It was caught: undefined The fix: undefined

What have you NOT measured?

Revenue: the live settlement ledger records 1 outside settlement from 1 distinct non-self payer, totalling 0.02 USDC (20000 atomic units, 6 dp, on Base). This is a project-reported ledger: every record names its settlement transaction, so the chain is the check. Owner-controlled and zero-value settlements are excluded. Distribution: no surface is confirmed live in the committed spray log; drafted and queued rows are not counted as placements. The board publishes its own unmeasured slots rather than hiding them: quote totals.unmeasured_axes from /api/gspc.

Can I verify one of your measurements myself, without an account?

Yes, and without asking us. Each signed card carries an Ed25519 signature over a canonical body whose id is the sha-256 of those bytes. Fetch the card, recompute the id, and check the signature against the key published at did:web:csoai.org using the same verifier we run: https://councilof.ai/signed/verify-card.mjs. A signature is an integrity claim, not a truth claim — it says these are the bytes that were signed, not that the measurement inside them is correct.

What does your public root actually prove?

It commits to its own leaf list — 305 leaves under merkle_root 40ce3833118fab76… as of 2026-09-22T08:54:02Z. Stranger inclusion means membership in that list. Its OpenTimestamps proof covers root.json bytes only: it does not anchor the signed-card index, and it does not anchor GSPC. Those are separate corpora with zero identifier overlap.

Claims we refuse to overstate

Measured gaps and unavailable sources remain visible. Each item includes the command that checks its state.

N sites live — NOT HAPPENED

The spray log carries drafted and queued rows and no live ones. Announcing a number of live surfaces would be counting drafts as placements.

jq '[.[]|select(.status=="live")]|length' scripts/badger/_spray-log-v2.json