Sign In

publedge

Package Overview
Dependencies
Maintainers
1
Versions
4
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

publedge - npm Package Compare versions

Comparing version
0.1.2
to
0.1.3
+36
data/examples/obligations/admt-60-day-cure-period.md
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Permission"
id: admt-60-day-cure-period
name: ADMT Sixty-Day Cure Period Before Enforcement
group: permission
status: draft
lifecycle_status: operative
last_verified: 2026-07-24
search_terms:
- admt
- cure period
- attorney general
- deceptive trade practice
- colorado
- sb26-189
---
## Summary
Violations of the Colorado ADMT Act are enforced by the Attorney General as deceptive trade practices, with no private right of action. A regulated party may cure an alleged violation within 60 days of notice; the cure route is available through January 1, 2030.
## What Counts
- Curing the alleged violation within 60 days of receiving notice from the Attorney General
- Curing on or before January 1, 2030, while the cure route remains available
- Remedying the underlying conduct, not only the documentation of it
## What Does Not Count
- Asserting cure after the 60-day window has closed
- Relying on the cure route for conduct noticed after the January 1, 2030 sunset
- Treating the cure period as a defense to a claim brought by a private plaintiff, which the Act does not authorize in the first place
## Statute Anchors
- C.R.S. §6-1-1706 — Attorney General enforcement; 60-day cure period; deceptive trade practices (as enacted by Colorado SB 26-189)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: admt-correction-and-human-review
name: ADMT Data Correction And Human Review Of Adverse Outcomes
group: requirement
status: draft
lifecycle_status: operative
last_verified: 2026-07-24
search_terms:
- admt
- human review
- data correction
- reconsideration
- colorado
- sb26-189
---
## Summary
Consumers subject to an adverse consequential decision made using covered automated decision-making technology may correct inaccurate personal data used in that decision and may request meaningful human review and reconsideration of the outcome. The deployer must provide both paths.
## What Counts
- A working route for the consumer to submit corrections to personal data used in the decision
- Reconsideration of the decision once corrected data is supplied
- Review by a human with authority to change the outcome
- Communicating the result of the reconsideration to the consumer
## What Does Not Count
- Human review by a reviewer who cannot overturn the automated outcome
- Re-running the same model on the same data and reporting the same result as "review"
- Accepting a correction into a customer record without reconsidering the decision
- Conditioning review on the consumer waiving other rights
## Statute Anchors
- C.R.S. §6-1-1705 — Consumer rights; data correction; human review and reconsideration (as enacted by Colorado SB 26-189)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: admt-deployer-3-year-record-retention
name: ADMT Deployer Three-Year Record Retention
group: requirement
status: draft
lifecycle_status: operative
last_verified: 2026-07-24
search_terms:
- admt
- record keeping
- retention
- three years
- colorado
- sb26-189
---
## Summary
A deployer of covered automated decision-making technology must retain its compliance documentation for at least three years. The retention floor is what makes the notice, explanation, and review duties auditable by the Attorney General after the fact.
## What Counts
- Retaining the consumer notices, explanations, and human-review records generated under the Act
- A retention period of three years or longer measured from the record's creation
- Records held in a form that can be produced on request
## What Does Not Count
- Purging compliance records on a shorter operational retention schedule
- Retaining only aggregate statistics rather than the underlying compliance records
- Relying on a vendor's retention without an enforceable route to the records
## Statute Anchors
- C.R.S. §6-1-1703 — Deployer record-keeping; three-year retention (as enacted by Colorado SB 26-189)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: admt-deployer-pre-decision-notice
name: ADMT Deployer Notice Before Consequential Decision
group: requirement
status: draft
lifecycle_status: operative
last_verified: 2026-07-24
search_terms:
- admt
- consumer notice
- consequential decision
- deployer
- colorado
- sb26-189
---
## Summary
Before a consequential decision is made using covered automated decision-making technology, the deployer must notify the consumer that an automated system is in use and disclose the purpose and nature of the decision. The notice is pre-decision; a post-hoc disclosure does not satisfy it.
## What Counts
- Notice delivered at or before the point the ADMT is used in the consequential decision
- Plain statement that an automated decision-making technology is involved
- Description of what the decision is for and what it determines
## What Does Not Count
- Notice issued only after an adverse outcome is communicated
- Disclosure buried in terms of service or a privacy policy the consumer is not shown
- A generic statement that the company "uses technology" without identifying automated decision-making
- Notice given to a third-party intermediary rather than to the consumer
## Statute Anchors
- C.R.S. §6-1-1704 — Deployer consumer-notice obligation; consequential decisions (as enacted by Colorado SB 26-189)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: admt-developer-documentation-to-deployer
name: ADMT Developer Documentation To Deployer
group: requirement
status: draft
lifecycle_status: operative
last_verified: 2026-07-24
search_terms:
- admt
- developer documentation
- training data
- known limitations
- colorado
- sb26-189
---
## Summary
A developer of covered automated decision-making technology must disclose to deployers the technology's intended uses, the categories of data used to train it, its known limitations, and instructions for meaningful human review. The duty runs developer-to-deployer, not developer-to-consumer.
## What Counts
- Documentation naming the intended uses the developer supports for the ADMT
- Description of training-data categories at a level that lets a deployer assess fit
- Statement of known limitations, including populations or inputs where performance is unreliable
- Instructions sufficient for a deployer to conduct meaningful human review of an output
## What Does Not Count
- A marketing datasheet with capability claims but no limitations
- Documentation available only to consumers rather than to the deploying entity
- A generic model card that omits intended uses or human-review instructions
- Deferring the disclosure until after the deployer has placed the ADMT in service
## Statute Anchors
- C.R.S. §6-1-1702 — Developer documentation duties (as enacted by Colorado SB 26-189)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: admt-post-adverse-explanation-30-days
name: ADMT Post-Adverse Explanation Within 30 Days
group: requirement
status: draft
lifecycle_status: operative
last_verified: 2026-07-24
search_terms:
- admt
- adverse decision
- explanation
- 30 days
- colorado
- sb26-189
---
## Summary
Within 30 days of an adverse consequential decision made using covered automated decision-making technology, the deployer must give the consumer a plain-language explanation covering the AI's role in the decision, its degree of contribution, the types of data processed, and the sources of that data.
## What Counts
- Explanation delivered inside the 30-day window running from the adverse decision
- Plain-language account of what the ADMT contributed and how much it drove the outcome
- Identification of the categories of personal data processed
- Identification of where that data came from
## What Does Not Count
- Explanation supplied only on the consumer's second or escalated request
- A conclusory statement that the decision "was based on your profile"
- Technical model documentation offered in place of a plain-language explanation
- Omitting degree of contribution while describing only the data used
## Statute Anchors
- C.R.S. §6-1-1705 — Consumer rights; 30-day post-adverse explanation (as enacted by Colorado SB 26-189)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: high-risk-ai-consumer-notice-correction-and-appeal
name: High-Risk AI Consumer Notice, Correction, And Appeal
group: requirement
status: draft
lifecycle_status: never-operative
last_verified: 2026-07-25
search_terms:
- high-risk artificial intelligence
- consumer notice
- adverse consequential decision
- data correction
- appeal
- human review
- colorado
- sb24-205
---
## Summary
Deployers would have been required to notify consumers before using a high-risk artificial intelligence system in a consequential decision and, after an adverse decision, provide the principal reasons, an opportunity to correct incorrect personal data, and an appeal with human review where technically feasible. The obligation was enacted in Colorado SB 24-205 but never became operative because the statute was superseded before its delayed effective date.
## What Counts
- Pre-decision notice identifying the high-risk system's role and the nature of the consequential decision
- Plain-language explanation of the principal reasons for an adverse decision
- Disclosure of the data types and sources used in the adverse decision
- A working process to correct incorrect personal data
- An appeal process with human review where technically feasible
## What Does Not Count
- Treating the enacted consumer-rights bundle as currently operative after SB 24-205 was superseded
- Notice delivered only after the consequential decision
- A correction channel that does not feed into reconsideration
- An automated rerun presented as human review
- An explanation that omits the system's contribution to the adverse decision
## Statute Anchors
- C.R.S. §6-1-1703(4)(a) — Pre-decision consumer notice (as enacted by Colorado SB 24-205)
- C.R.S. §6-1-1703(4)(b) — Adverse-decision explanation, correction, and appeal rights (as enacted by Colorado SB 24-205)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: high-risk-ai-impact-assessment
name: High-Risk AI Impact Assessment
group: requirement
status: draft
lifecycle_status: never-operative
last_verified: 2026-07-25
search_terms:
- high-risk artificial intelligence
- impact assessment
- annual assessment
- algorithmic discrimination
- deployer
- colorado
- sb24-205
---
## Summary
Deployers would have been required to complete an impact assessment for each covered high-risk artificial intelligence system, repeat it at least annually and after intentional and substantial modifications, and retain the assessment records. The obligation was enacted in Colorado SB 24-205 but never became operative because the statute was superseded before its delayed effective date.
## What Counts
- Initial assessment of purpose, use context, benefits, inputs, outputs, performance, limitations, and discrimination risks
- Annual reassessment while the high-risk system remains deployed
- Reassessment within ninety days after an intentional and substantial modification
- Documentation of transparency measures, safeguards, monitoring, and risk mitigation
- Retention of current and prior assessments for the statutory period
## What Does Not Count
- Treating the enacted assessment mandate as currently operative after SB 24-205 was superseded
- A one-time assessment with no annual or modification-triggered review
- An assessment that omits reasonably foreseeable algorithmic-discrimination risks
- Generic system documentation that does not evaluate the deployer's actual deployment context
## Statute Anchors
- C.R.S. §6-1-1703(3) — Deployer impact assessments and record retention (as enacted by Colorado SB 24-205)
---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Requirement"
id: high-risk-ai-reasonable-care-against-algorithmic-discrimination
name: High-Risk AI Reasonable Care Against Algorithmic Discrimination
group: requirement
status: draft
lifecycle_status: never-operative
last_verified: 2026-07-25
search_terms:
- high-risk artificial intelligence
- reasonable care
- algorithmic discrimination
- developer
- deployer
- colorado
- sb24-205
---
## Summary
Developers and deployers of high-risk artificial intelligence systems would have been required to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination. The obligation was enacted in Colorado SB 24-205 but never became operative because the statute was superseded before its delayed effective date.
## What Counts
- Developer controls addressing discrimination risks arising from intended and contracted uses
- Deployer controls addressing discrimination risks arising from deployment
- Risk management measures proportionate to known and reasonably foreseeable risks
- Compliance evidence sufficient to support the statute's rebuttable presumption of reasonable care
## What Does Not Count
- Treating the enacted duty as currently operative after SB 24-205 was superseded
- Limiting review to intentional discrimination while ignoring foreseeable disparate impacts
- Relying on developer documentation without deployer-specific risk controls
- Generic responsible-AI principles without controls tied to the covered high-risk system
## Statute Anchors
- C.R.S. §6-1-1702(1) — Developer duty of reasonable care (as enacted by Colorado SB 24-205)
- C.R.S. §6-1-1703(1) — Deployer duty of reasonable care (as enacted by Colorado SB 24-205)
+5
-5

@@ -28,5 +28,5 @@ ---

url: "https://leg.colorado.gov/sites/default/files/2024a_205_signed.pdf"
- cite: "C.R.S. §6-1-1703 (deployer duty of reasonable care; impact assessments; consumer notice)"
- cite: "C.R.S. §6-1-1703 (deployer duty of reasonable care; impact assessments; consumer notice, correction, and appeal)"
url: "https://leg.colorado.gov/sites/default/files/2024a_205_signed.pdf"
- cite: "C.R.S. §6-1-1704 (consumer rights to explanation, correction, human review)"
- cite: "C.R.S. §6-1-1704 (disclosure when consumers interact with an AI system)"
url: "https://leg.colorado.gov/sites/default/files/2024a_205_signed.pdf"

@@ -50,6 +50,6 @@ - cite: "C.R.S. §6-1-1706 (Attorney General enforcement; rulemaking authority)"

disclaimer: ""
last_verified: 2026-05-21
last_verified: 2026-07-25
schema: https://publedge.org/schema/instrument.schema.json
created: 2026-05-21
modified: 2026-05-21
modified: 2026-07-25
---

@@ -83,3 +83,3 @@

- Imposed parallel duties on deployers, including impact assessments, consumer notice at or before use of high-risk AI, and risk management programs (§6-1-1703).
- Granted consumers rights to plain-language explanation of adverse consequential decisions, opportunity to correct incorrect personal data, and human review where technically feasible (§6-1-1704).
- Granted consumers rights to plain-language explanation of adverse consequential decisions, opportunity to correct incorrect personal data, and human review where technically feasible (§6-1-1703(4)).
- Reserved enforcement to the Colorado Attorney General; no private right of action (§6-1-1706).

@@ -86,0 +86,0 @@

@@ -155,1 +155,26 @@ # NOTE: build.js hardcodes the mapping field name as `regulation`.

- sec-reg-d-506c-verification-safe-harbor
# --- Colorado statutes ---
- id: sb24-205-never-operative-obligations
regulation: us-co-legislature-statute-2024-sb24-205
authority: colorado-legislature
source_file: data/examples/instruments/us-co-legislature-statute-2024-sb24-205.md
source_heading: Summary
obligations:
- high-risk-ai-reasonable-care-against-algorithmic-discrimination
- high-risk-ai-impact-assessment
- high-risk-ai-consumer-notice-correction-and-appeal
- id: sb26-189-admt-act-obligations
regulation: us-co-legislature-statute-2026-sb26-189
authority: colorado-legislature
source_file: data/examples/instruments/us-co-legislature-statute-2026-sb26-189.md
source_heading: Summary
obligations:
- admt-developer-documentation-to-deployer
- admt-deployer-pre-decision-notice
- admt-post-adverse-explanation-30-days
- admt-correction-and-human-review
- admt-deployer-3-year-record-retention
- admt-60-day-cure-period

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-18

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: expired
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: expired
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: expired
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

@@ -7,2 +7,3 @@ ---

status: draft
lifecycle_status: operative
last_verified: 2026-04-21

@@ -9,0 +10,0 @@ search_terms:

{
"name": "publedge",
"version": "0.1.2",
"version": "0.1.3",
"mcpName": "io.github.snapsynapse/publedge",

@@ -63,5 +63,7 @@ "description": "MCP server and recordkeeping protocol for fact-specific written interpretations between two parties: JIAs, RMAs, no-action letters, advisory opinions, private letter rulings. Plain markdown, manifest-checked, gist-bound. The verifiable-records layer of the PAICE legal graph.",

"validate:of": "node scripts/validate-obligation-first.js",
"check:of": "node scripts/check-of-version.js",
"verify": "node scripts/verify.js",
"evals": "node scripts/evals.js",
"eval:instrument-schema": "node scripts/eval-instrument-schema.js",
"eval:obligation-schema": "node scripts/eval-obligation-schema.js",
"eval:record-schema": "node scripts/eval-record-schema.js",

@@ -68,0 +70,0 @@ "eval:schema-parity": "node scripts/eval-schema-parity.js",

@@ -39,2 +39,13 @@ # PubLedge Project Configuration

color_light: "#1f7a43"
# Obligation legal lifecycle is separate from editorial status
# (draft/reviewed/published). This is a PubLedge-local vocabulary until
# Obligation First standardizes provision lifecycle.
lifecycle_statuses:
- prospective
- operative
- never-operative
- expired
- superseded
- withdrawn
- terminated
body_sections:

@@ -204,7 +215,9 @@ - Summary

# preserve amendment/supersession chains even when they do not introduce
# standalone PubLedge obligation mappings.
# standalone PubLedge obligation mappings. An instrument belongs here only
# when it imposed no operative duty: superseded before its effective date,
# amendment-only, or sunset-date-only. Operative statutes get mappings.
allowed_unmapped_instruments:
- us-co-legislature-statute-2024-sb24-205
# Amendment-only: moved SB 24-205's effective date, no substantive change.
- us-co-legislature-statute-2025-sb25b-004
- us-co-legislature-statute-2026-sb26-189
# Sunset-date-only: extended Utah Code Title 13 Chapter 72 repeal date.
- us-ut-legislature-statute-2025-sb332

@@ -211,0 +224,0 @@

---
"@type": "https://w3id.org/semanticarts/ns/ontology/gist/Specification"
title: "PubLedge Protocol"
version: "0.1.2-pre"
version: "0.1.3"
license: "CC-BY-4.0"
created: 2026-04-18
modified: 2026-04-18
modified: 2026-07-25
---

@@ -9,0 +9,0 @@

# PubLedge
[![CI](https://github.com/snapsynapse/publedge/actions/workflows/build.yml/badge.svg)](https://github.com/snapsynapse/publedge/actions/workflows/build.yml)
[![Spec](https://img.shields.io/badge/spec-v0.1.2--pre-blue)](PROTOCOL.md)
[![Registry](https://img.shields.io/badge/registry-18%20instruments%20%C2%B7%2026%20obligations%20%C2%B7%208%20authorities-informational)](data/examples/instruments/)
[![Spec](https://img.shields.io/badge/spec-v0.1.3-blue)](PROTOCOL.md)
[![Registry](https://img.shields.io/badge/registry-18%20instruments%20%C2%B7%2035%20obligations%20%C2%B7%208%20authorities-informational)](data/examples/instruments/)
[![Content license: CC BY 4.0](https://img.shields.io/badge/content-CC%20BY%204.0-lightgrey)](LICENSE-CC-BY-4.0)

@@ -14,3 +14,3 @@ [![Code license: Apache 2.0](https://img.shields.io/badge/code-Apache%202.0-lightgrey)](LICENSE-APACHE)

**Public and maintained. Protocol specification v0.1.2-pre; stable MCP server v0.1.2. Standalone product expansion is parked pending a concrete legal-graph or adopter demand signal.**
**Public and maintained. Protocol specification v0.1.3; stable MCP server v0.1.3. Standalone product expansion is parked pending a concrete legal-graph or adopter demand signal.**

@@ -38,3 +38,3 @@ ## Who this is for

1. **The protocol** — the [PROTOCOL.md](PROTOCOL.md) specification and the [PRIOR-ART.md](PRIOR-ART.md) survey that motivates it.
2. **Utah-shaped reference content** — 5 JIA/RMA templates anchored to Utah's AI Policy Act (Utah Code §13-72a) and GenAI safe-harbor (§13-75-104), plus 18 demonstration instruments under `data/examples/instruments/` spanning 8 authorities (Utah OAIP, Utah Legislature, Colorado Legislature, SEC, CFPB, IRS Chief Counsel, IRS TEGE, CFTC) and 7 instrument types (JIA, RMA, no-action letter, advisory opinion, private letter ruling, interpretive letter, statute). 26 first-class obligation records under `data/examples/obligations/` are mapped to the instruments via `data/examples/mapping/index.yml`.
2. **Utah-shaped reference content** — 5 JIA/RMA templates anchored to Utah's AI Policy Act (Utah Code §13-72a) and GenAI safe-harbor (§13-75-104), plus 18 demonstration instruments under `data/examples/instruments/` spanning 8 authorities (Utah OAIP, Utah Legislature, Colorado Legislature, SEC, CFPB, IRS Chief Counsel, IRS TEGE, CFTC) and 7 instrument types (JIA, RMA, no-action letter, advisory opinion, private letter ruling, interpretive letter, statute). 35 first-class obligation records under `data/examples/obligations/` are mapped to the instruments via `data/examples/mapping/index.yml`; legal lifecycle is tracked separately from editorial maturity.
3. **The published site** — rendered HTML under `docs/`, served by GitHub Pages from `main /docs`. Regenerate with `node scripts/build.js && node scripts/build-extras.js` before committing; CI fails if `docs/` drifts from sources.

@@ -41,0 +41,0 @@