Developers should share as much as possible of the following with downstream deployers, while protecting commercially sensitive information and complying with law: (a) technical details such as architecture, data description and components; (b) test methods, use cases and results; (c) known limitations, risks and mitigations, such as potential bias and corrective actions, and external audit findings; (d) data management for training and testing data, including quality, metadata and provenance; (e) privacy and cybersecurity practices and conformance to standards; (f) transparency mechanisms for AI-generated content, interactions and decisions; (g) for general-purpose AI, training data sources with privacy, intellectual property and copyright compliance details, and model and system cards including evaluations of dangerous and emerging capabilities in the deployment and tool-access context; and (h) restricted, managed access to model weights and associated artefacts.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.