{
  "about": "AI Citizen Action directory data. Channel records are published here only when a reviewed route explicitly accepts contact and is currently open or limited. Route verified still records technical retrieval separately.",
  "section": "channels",
  "count": 48,
  "excluded_count": 22,
  "generated": "2026-09-24T15:07:58.793Z",
  "records": [
    {
      "id": "ca-cohere",
      "type": "company",
      "geo": {
        "country": "ca",
        "label": "Canada"
      },
      "facts": {
        "routes": [
          {
            "id": "safety-misuse-reports",
            "type": "email",
            "value": "safety@cohere.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "d2c15df6cbf0",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://coral.cohere.com/",
              "evidence_note": "Usage Policy states: 'please notify us immediately at safety@cohere.com'. Covers policy violations, misuse or abuse of Cohere Services, model safety issues, and security research falling outside the disclosure procedure.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "email"
              ]
            }
          },
          {
            "id": "thumbs-down-output",
            "type": "feedback",
            "value": "https://coral.cohere.com/",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "4c38f662abaa",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://coral.cohere.com/",
              "evidence_note": "In-product feedback on a bad model output, offered in the Usage Policy as an alternative to emailing."
            }
          },
          {
            "id": "responsible-disclosure-policy-via",
            "type": "disclosure",
            "value": "https://trustcenter.cohere.com/",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "023b865473da",
            "contact": {
              "status": "unknown",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://trustcenter.cohere.com/",
              "evidence_note": "Security vulnerability disclosure; the policy document is downloadable from the Trust Center."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://cohere.com/security",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "50e7ee83a150",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://cohere.com/security",
              "evidence_note": "No public accounts found either way — no complaints of a black hole, and no published confirmations of response. Cohere is a smaller enterprise-focused developer with a correspondingly low volume of external safety research directed at it. The framework names external partners (NIST, Humane Intelligence) but describes no public intake process."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://cohere.com/security/the-cohere-secure-ai-frontier-model-framework-february-2025.pdf",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "011ce49c6c31",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://cohere.com/security/the-cohere-secure-ai-frontier-model-framework-february-2025.pdf",
              "evidence_note": "No public accounts found either way — no complaints of a black hole, and no published confirmations of response. Cohere is a smaller enterprise-focused developer with a correspondingly low volume of external safety research directed at it. The framework names external partners (NIST, Humane Intelligence) but describes no public intake process."
            }
          }
        ],
        "region": "Canada",
        "public_input": "open",
        "tags": [
          "behaviour",
          "flaw",
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-5fa9dd85-9cbf-42b4-bf57-3ce426a19ca2",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Cohere",
        "remit": "Chief Scientist holds 'final authority to determine if our products are safe, secure, and ready to be made available to our customers', delegated by the CEO under the Secure AI Frontier Model Framework.",
        "reality_check": "No public accounts found either way — no complaints of a black hole, and no published confirmations of response. Cohere is a smaller enterprise-focused developer with a correspondingly low volume of external safety research directed at it. The framework names external partners (NIST, Humane Intelligence) but describes no public intake process.",
        "notes": "Use safety@cohere.com; it is explicitly scoped to model safety in the Usage Policy, which is more than most publish. The framework itself publishes no contact address, so the Usage Policy is the document to cite when you write.",
        "routes": {
          "safety-misuse-reports": {
            "label": "Safety and misuse reports",
            "scope": "Usage Policy states: 'please notify us immediately at safety@cohere.com'. Covers policy violations, misuse or abuse of Cohere Services, model safety issues, and security research falling outside the disclosure procedure.",
            "note": "A real, named, published safety address — rarer than it should be. This is the strongest single route on Cohere's surface."
          },
          "thumbs-down-output": {
            "label": "Thumbs-down on output",
            "scope": "In-product feedback on a bad model output, offered in the Usage Policy as an alternative to emailing."
          },
          "responsible-disclosure-policy-via": {
            "label": "Responsible Disclosure Policy via Trust Center",
            "scope": "Security vulnerability disclosure; the policy document is downloadable from the Trust Center.",
            "note": "Document is gated behind the Trust Center; no plain-text email published on the public security page."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "The Cohere Secure AI Frontier Model Framework, V1.0 (February 2025)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://coral.cohere.com/",
            "checked": null
          },
          {
            "url": "https://trustcenter.cohere.com/",
            "checked": null
          },
          {
            "url": "https://cohere.com/security",
            "checked": null
          },
          {
            "url": "https://cohere.com/security/the-cohere-secure-ai-frontier-model-framework-february-2025.pdf",
            "checked": null
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "4cedd06861",
        "research_order": 9,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "cn-deepseek",
      "type": "company",
      "geo": {
        "country": "cn",
        "label": "China"
      },
      "facts": {
        "routes": [
          {
            "id": "security",
            "type": "email",
            "value": "security@deepseek.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "30e8400143e6",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.deepseek.com/",
              "evidence_note": "Published as a mailto link in the footer of deepseek.com. No published policy defines what is in scope.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "systemic",
                "email"
              ],
              "restrictions": "Published as a mailto link in the footer of deepseek.com. No published policy defines what is in scope."
            }
          },
          {
            "id": "general-service-contact",
            "type": "email",
            "value": "service@deepseek.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "f17a7a47c103",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.deepseek.com/",
              "evidence_note": "General enquiries.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "systemic",
                "email"
              ],
              "restrictions": "General enquiries."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.deepseek.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "e7b3a5a054fd",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.deepseek.com/",
              "evidence_note": "DeepSeek has been the subject of an unusual volume of external security and safety findings — Wiz Research found a publicly exposed ClickHouse database leaking chat history in January 2025, and Cisco's red-teaming reported a 100% attack success rate against R1 on a standard harmful-prompt benchmark. In none of these widely covered cases did the researchers describe a functioning coordinated-disclosure exchange with DeepSeek; Wiz described reaching out and the exposure being closed quickly, but there is no published disclosure process. No bug bounty, no VDP, no safe harbour."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://www.deepseek.com/harness/en/privacy/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "b172ba0baa0e",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.deepseek.com/harness/en/privacy/",
              "evidence_note": "DeepSeek has been the subject of an unusual volume of external security and safety findings — Wiz Research found a publicly exposed ClickHouse database leaking chat history in January 2025, and Cisco's red-teaming reported a 100% attack success rate against R1 on a standard harmful-prompt benchmark. In none of these widely covered cases did the researchers describe a functioning coordinated-disclosure exchange with DeepSeek; Wiz described reaching out and the exposure being closed quickly, but there is no published disclosure process. No bug bounty, no VDP, no safe harbour."
            }
          }
        ],
        "region": "China",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-ed72b4aa-95a2-422e-9e5b-3a8a4d6a9f4d",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "DeepSeek",
        "remit": "No publicly named safety or alignment function. Safe Use Policy governs the hosted service; the company publishes research papers but no safety framework.",
        "reality_check": "DeepSeek has been the subject of an unusual volume of external security and safety findings — Wiz Research found a publicly exposed ClickHouse database leaking chat history in January 2025, and Cisco's red-teaming reported a 100% attack success rate against R1 on a standard harmful-prompt benchmark. In none of these widely covered cases did the researchers describe a functioning coordinated-disclosure exchange with DeepSeek; Wiz described reaching out and the exposure being closed quickly, but there is no published disclosure process. No bug bounty, no VDP, no safe harbour.",
        "notes": "security@deepseek.com is genuinely published, which puts DeepSeek ahead of several Western labs on the narrow question of having an address. But there is no policy behind it — no scope, no commitment, no safe harbour. Assume anything you send is unprotected and may not be acknowledged.",
        "routes": {
          "security": {
            "label": "Security",
            "scope": "Published as a mailto link in the footer of deepseek.com. No published policy defines what is in scope.",
            "note": "Verified by reading the raw page source of deepseek.com/en. There is no accompanying disclosure policy, scope statement, SLA or safe harbour — just the address."
          },
          "general-service-contact": {
            "label": "General service contact",
            "scope": "General enquiries.",
            "note": "Also published in the site footer."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Safe Use Policy (no frontier safety framework published)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.deepseek.com/",
            "checked": null
          },
          {
            "url": "https://www.deepseek.com/harness/en/privacy/",
            "checked": null
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "6b6c0d5547",
        "research_order": 15,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "cn-moonshot-ai",
      "type": "company",
      "geo": {
        "country": "cn",
        "label": "China"
      },
      "facts": {
        "routes": [
          {
            "id": "security-reports",
            "type": "email",
            "value": "security@moonshot.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "e8786072be25",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://forum.moonshot.ai/",
              "evidence_note": "Confirmed by a Moonshot staff member relaying their Security Team on the official forum: 'If you discover any potential security issues, please report them to us at: security@moonshot.ai. We kindly ask that you follow responsible disclosure practices and give us reasonable time to investigate and address any finding…'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "email"
              ],
              "restrictions": "Confirmed by a Moonshot staff member relaying their Security Team on the official forum: 'If you discover any potential security issues, please report them to us at: security@moonshot.ai. We kindly ask that you follow responsible disclosure practices and give us reasonable time to investigate and address any finding…'"
            }
          },
          {
            "id": "moonshot-kimi-developer-forum",
            "type": "form",
            "value": "https://forum.moonshot.ai/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "8837db9683e0",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://forum.moonshot.ai/",
              "evidence_note": "Public forum where staff do respond.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "form"
              ],
              "restrictions": "Public forum where staff do respond."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.moonshot.ai/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "107a81340bfa",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.moonshot.ai/",
              "evidence_note": "Rare documented case of a channel failing and a workaround succeeding. A security researcher posted on forum.moonshot.ai after emailing security@moonshot.ai and waiting 90 days with no response; a Moonshot staff member (yuikns) then replied on the forum within the thread, relaying the Security Team's confirmation of the address and of the absence of any formal VDP. The lesson is explicit: the email exists, went unanswered for three months, and a public post got a reply."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://platform.kimi.ai/docs/agreement/userprivacy",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "106641d91818",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://platform.kimi.ai/docs/agreement/userprivacy",
              "evidence_note": "Rare documented case of a channel failing and a workaround succeeding. A security researcher posted on forum.moonshot.ai after emailing security@moonshot.ai and waiting 90 days with no response; a Moonshot staff member (yuikns) then replied on the forum within the thread, relaying the Security Team's confirmation of the address and of the absence of any formal VDP. The lesson is explicit: the email exists, went unanswered for three months, and a public post got a reply."
            }
          }
        ],
        "region": "China",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-83fc06bb-a048-4fe0-b23f-9c84ab20b7f7",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Moonshot AI",
        "remit": "No publicly named safety or alignment function. A security team exists and responds via the developer forum; Kimi models are released open-weight and via API.",
        "reality_check": "Rare documented case of a channel failing and a workaround succeeding. A security researcher posted on forum.moonshot.ai after emailing security@moonshot.ai and waiting 90 days with no response; a Moonshot staff member (yuikns) then replied on the forum within the thread, relaying the Security Team's confirmation of the address and of the absence of any formal VDP. The lesson is explicit: the email exists, went unanswered for three months, and a public post got a reply.",
        "notes": "Email security@moonshot.ai, but plan to escalate to the public forum if you get nothing — that is the documented path to a human. No safe harbour, no bounty, no whistleblower channel. Nothing covers model safety as distinct from security.",
        "routes": {
          "security-reports": {
            "label": "Security reports",
            "scope": "Confirmed by a Moonshot staff member relaying their Security Team on the official forum: 'If you discover any potential security issues, please report them to us at: security@moonshot.ai. We kindly ask that you follow responsible disclosure practices and give us reasonable time to investigate and address any finding…'",
            "note": "Moonshot confirmed in the same thread that it has NO public bug bounty and NO formal vulnerability disclosure policy."
          },
          "moonshot-kimi-developer-forum": {
            "label": "Moonshot / Kimi developer forum",
            "scope": "Public forum where staff do respond.",
            "note": "Documented as the escalation route that actually works when email does not."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No published frontier safety framework found"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://forum.moonshot.ai/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "b6dd9bdc0a",
        "research_order": 17,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "cn-tencent",
      "type": "company",
      "geo": {
        "country": "cn",
        "label": "China"
      },
      "facts": {
        "routes": [
          {
            "id": "tencent-security",
            "type": "email",
            "value": "security@tencent.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "0562a613f7d5",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://en.security.tencent.com/index.php/report/add",
              "evidence_note": "Primary contact listed on the English TSRC about page.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "Primary contact listed on the English TSRC about page."
            }
          },
          {
            "id": "tsrc-vulnerability-report-form",
            "type": "disclosure",
            "value": "https://en.security.tencent.com/index.php/report/add",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "d5c77b9e586b",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://en.security.tencent.com/index.php/report/add",
              "evidence_note": "Vulnerability submission. English interface available, with Facebook/Twitter/Google login options — so it is more accessible to outside researchers than most Chinese SRCs.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "disclosure"
              ],
              "restrictions": "Vulnerability submission. English interface available, with Facebook/Twitter/Google login options — so it is more accessible to outside researchers than most Chinese SRCs."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://en.security.tencent.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "83caf4d135b1",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://en.security.tencent.com/",
              "evidence_note": "TSRC is one of the more accessible Chinese security response centres for foreign researchers — it maintains a full English site, a hall of fame and a payouts page, and does not appear to require a mainland identity to register. No public accounts found of AI model-safety reports specifically. Scope for AI is unstated, so a jailbreak report would likely be triaged as out of scope."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://hunyuan.tencent.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "c8aca1f6aee2",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://hunyuan.tencent.com/",
              "evidence_note": "TSRC is one of the more accessible Chinese security response centres for foreign researchers — it maintains a full English site, a hall of fame and a payouts page, and does not appear to require a mainland identity to register. No public accounts found of AI model-safety reports specifically. Scope for AI is unstated, so a jailbreak report would likely be triaged as out of scope."
            }
          }
        ],
        "region": "China",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-e3107cf4-0e71-4f1d-9b00-a28144b5987e",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Tencent",
        "remit": "No publicly named frontier safety function. Tencent Security Response Center (TSRC) runs vulnerability intake for Tencent products including Hunyuan.",
        "reality_check": "TSRC is one of the more accessible Chinese security response centres for foreign researchers — it maintains a full English site, a hall of fame and a payouts page, and does not appear to require a mainland identity to register. No public accounts found of AI model-safety reports specifically. Scope for AI is unstated, so a jailbreak report would likely be triaged as out of scope.",
        "notes": "security@tencent.com and the English TSRC form are real and usable. Do not expect model-behaviour findings to be treated as in scope; frame anything you send in security terms if it genuinely has security impact.",
        "routes": {
          "tencent-security": {
            "label": "Tencent security",
            "scope": "Primary contact listed on the English TSRC about page.",
            "note": "Whether AI model safety is in scope is not stated anywhere on the TSRC site."
          },
          "tsrc-vulnerability-report-form": {
            "label": "TSRC vulnerability report form",
            "scope": "Vulnerability submission. English interface available, with Facebook/Twitter/Google login options — so it is more accessible to outside researchers than most Chinese SRCs.",
            "note": "Policy at https://en.security.tencent.com/index.php/policy and payouts at .../payouts."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No published frontier safety framework found in English"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://en.security.tencent.com/index.php/report/add",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "a606ca6442",
        "research_order": 20,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-eu-ai-act-article-73-serious",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "reporting",
            "value": "https://artificialintelligenceact.eu/article/73/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "80c10aed8f93",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://artificialintelligenceact.eu/article/73/",
              "evidence_note": "Serious incidents as defined in Article 3(49), reported by the provider. Deadlines: immediately after establishing a causal link and in any case not later than 15 days after awareness; 2 days for widespread infringement or certain serious incidents; and for a death, immediately after establishing or suspecting a causal relationship and within 10 days maximum. Incomplete initial reports are permitted, followed by a complete report.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "reporting"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://artificialintelligenceact.eu/article/73/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "3c95dead923d",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://artificialintelligenceact.eu/article/73/",
              "evidence_note": "Serious incidents as defined in Article 3(49), reported by the provider. Deadlines: immediately after establishing a causal link and in any case not later than 15 days after awareness; 2 days for widespread infringement or certain serious incidents; and for a death, immediately after establishing or suspecting a causal relationship and within 10 days maximum. Incomplete initial reports are permitted, followed by a complete report."
            }
          }
        ],
        "region": "European Union",
        "public_input": "open",
        "tags": [
          "behaviour",
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-d48a01a5-1d9f-4c50-895d-75df14cb54e7",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "EU AI Act Article 73 — serious incident reporting",
        "remit": "Serious incidents as defined in Article 3(49), reported by the provider. Deadlines: immediately after establishing a causal link and in any case not later than 15 days after awareness; 2 days for widespread infringement or certain serious incidents; and for a death, immediately after establishing or suspecting a causal relationship and within 10 days maximum. Incomplete initial reports are permitted, followed by a complete report.",
        "reality_check": "Real legal force but a closed circuit for outsiders. The leverage for an ordinary person is asymmetric and underused: putting a provider on written notice of a serious incident converts their silence into a reportable regulatory breach. That is a stronger move than the complaint itself.",
        "accepts": "Serious incidents as defined in Article 3(49), reported by the provider. Deadlines: immediately after establishing a causal link and in any case not later than 15 days after awareness; 2 days for widespread infringement or certain serious incidents; and for a death, immediately after establishing or suspecting a causal relationship and within 10 days maximum. Incomplete initial reports are permitted, followed by a complete report.",
        "does_not_accept": "Reports from members of the public. The duty sits on providers and deployers only. A member of the public cannot file an Article 73 report and cannot directly compel one.",
        "how": "Indirect only, and this is the practically important point: a member of the public cannot trigger Article 73 directly, but can (a) notify the provider, which starts the provider's own awareness clock and creates evidence of when they knew, and (b) file an Article 85 complaint with the market surveillance authority alleging a serious incident went unreported — failure to report is itself an infringement the authority can act on.",
        "format": "Commission draft guidance and a reporting template were consulted on (responses due 7 November 2025) ahead of the August 2026 application date.",
        "timing": "Obligations for high-risk AI apply from 2 August 2026.",
        "after": "National competent authorities immediately notify the Commission.",
        "operator": "Providers (and in some cases deployers) of high-risk AI systems, reporting to national market surveillance authorities; Commission draft guidance and template consulted in late 2025",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Serious incidents as defined in Article 3(49), reported by the provider. Deadlines: immediately after establishing a causal link and in any case not later than 15 days after awareness; 2 days for widespread infringement or certain serious incidents; and for a death, immediately after establishing or suspecting a causal relationship and within 10 days maximum. Incomplete initial reports are permitted, followed by a complete report.",
            "note": "Indirect only, and this is the practically important point: a member of the public cannot trigger Article 73 directly, but can (a) notify the provider, which starts the provider's own awareness clock and creates evidence of when they knew, and (b) file an Article 85 complaint with the market surveillance authority alleging a serious incident went unreported — failure to report is itself an infringement the authority can act on."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://artificialintelligenceact.eu/article/73/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "00b720aeca",
        "research_order": 205,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-eu-ai-act-article-85-right",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU (27 Member States)"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://artificialintelligenceact.eu/article/85/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "bd3d1e5e4acb",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://artificialintelligenceact.eu/article/85/",
              "evidence_note": "Complaints from 'any natural or legal person' with grounds to consider there has been an infringement of the AI Act. No standing requirement, no need to be personally harmed, no institutional affiliation required. Applies without prejudice to other administrative or judicial remedies.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "law",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://artificialintelligenceact.eu/article/85/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "b02184f3348d",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://artificialintelligenceact.eu/article/85/",
              "evidence_note": "Complaints from 'any natural or legal person' with grounds to consider there has been an infringement of the AI Act. No standing requirement, no need to be personally harmed, no institutional affiliation required. Applies without prejudice to other administrative or judicial remedies."
            }
          }
        ],
        "region": "European Union",
        "public_input": "open",
        "tags": [
          "harm",
          "law"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-899f0265-88e7-42bd-9a8b-57995399aa42",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "EU AI Act Article 85 — right to lodge a complaint with a market surveillance authority",
        "remit": "Complaints from 'any natural or legal person' with grounds to consider there has been an infringement of the AI Act. No standing requirement, no need to be personally harmed, no institutional affiliation required. Applies without prejudice to other administrative or judicial remedies.",
        "reality_check": "Legally real and newly in force, but immature. The absence of designated authorities in most Member States means enforcement capacity lags the right. Parliamentary research flags 'uneven enforcement' as a structural risk of the decentralised model. Best used as a formal, citable act that creates a record and can be escalated or publicised — not as a fast route to action.",
        "accepts": "Complaints from 'any natural or legal person' with grounds to consider there has been an infringement of the AI Act. No standing requirement, no need to be personally harmed, no institutional affiliation required. Applies without prejudice to other administrative or judicial remedies.",
        "does_not_accept": "Matters outside the AI Act. It is a complaint right, not a right to a remedy — the Act does not give the complainant a personal entitlement to redress, damages or a specific outcome.",
        "how": "Submit to the market surveillance authority of your Member State. The authority must take complaints into account under Regulation (EU) 2019/1020 and handle them under its established procedures. Practical problem: as of March 2026 only 8 of 27 Member States had notified a single point of contact, so identifying the correct national authority is genuinely difficult in most of the EU. Where you cannot identify one, use the Commission's AI Act complaints tool instead and ask for referral.",
        "format": "No prescribed EU-wide format. In practice: identify the AI system, the provider/deployer, the specific AI Act provision you say is breached, the country where it occurred, and attach evidence.",
        "timing": "Applicable from 2 August 2026; rolling thereafter.",
        "after": "The authority considers the complaint as part of its market surveillance activities and may open an investigation. There is no guaranteed individual response or published outcome under Article 85 itself.",
        "operator": "National market surveillance authorities of EU Member States; coordinated by the European AI Board and Commission AI Office",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Complaints from 'any natural or legal person' with grounds to consider there has been an infringement of the AI Act. No standing requirement, no need to be personally harmed, no institutional affiliation required. Applies without prejudice to other administrative or judicial remedies.",
            "note": "Submit to the market surveillance authority of your Member State. The authority must take complaints into account under Regulation (EU) 2019/1020 and handle them under its established procedures. Practical problem: as of March 2026 only 8 of 27 Member States had notified a single point of contact, so identifying the correct national authority is genuinely difficult in most of the EU. Where you cannot identify one, use the Commission's AI Act complaints tool instead and ask for referral."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://artificialintelligenceact.eu/article/85/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "aad1707696",
        "research_order": 202,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-eu-ai-act-article-87-protection",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://artificialintelligenceact.eu/article/87/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "0afb3b99c532",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://artificialintelligenceact.eu/article/87/",
              "evidence_note": "Reports of AI Act infringements by workers in the broad sense covered by the Whistleblower Directive.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "insider",
                "systemic",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://artificialintelligenceact.eu/article/87/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "057045d64481",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://artificialintelligenceact.eu/article/87/",
              "evidence_note": "Reports of AI Act infringements by workers in the broad sense covered by the Whistleblower Directive."
            }
          }
        ],
        "region": "European Union",
        "public_input": "open",
        "tags": [
          "flaw",
          "insider",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-c21867ff-de8d-4272-a411-bc0fadca314a",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "EU AI Act Article 87 — protection of persons reporting infringements",
        "remit": "Reports of AI Act infringements by workers in the broad sense covered by the Whistleblower Directive.",
        "reality_check": "This is the most substantive statutory AI whistleblower protection in force anywhere as of September 2026 — notably stronger than the US position, where the federal AI Whistleblower Protection Act remains stuck in committee. Its weakness is that it covers AI Act infringements, not 'AI is dangerous' concerns that break no specific provision.",
        "accepts": "Reports of AI Act infringements by workers in the broad sense covered by the Whistleblower Directive.",
        "does_not_accept": "Does not create a new standalone AI whistleblower regime; it imports the existing Directive wholesale.",
        "how": "Its single operative sentence: 'Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.' In practice this means internal channels first, then the competent national authority, with external/public disclosure protected in defined circumstances. The AI Office's whistleblower tool is the EU-level external channel.",
        "format": "As per national implementations of the Directive.",
        "timing": "Applies from 2 August 2026.",
        "after": "Confidentiality safeguards and anti-retaliation protection apply; remedies are pursued under national implementing law.",
        "operator": "European Commission / Member States, applying Directive (EU) 2019/1937",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Reports of AI Act infringements by workers in the broad sense covered by the Whistleblower Directive.",
            "note": "Its single operative sentence: 'Directive (EU) 2019/1937 shall apply to the reporting of infringements of this Regulation and the protection of persons reporting such infringements.' In practice this means internal channels first, then the competent national authority, with external/public disclosure protected in defined circumstances. The AI Office's whistleblower tool is the EU-level external channel."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://artificialintelligenceact.eu/article/87/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "82702c5c19",
        "research_order": 206,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-eu-ai-act-complaints-tool",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-complaints-tool",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "8047dfed55c3",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-complaints-tool",
              "evidence_note": "Complaints from individuals and organisations about alleged AI Act infringements falling within the exclusive competence of the AI Office, under Article 85. All official EU languages. Supporting detail and a stated country of incident are required.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "insider",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-complaints-tool",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "6d5ad0d05c00",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-complaints-tool",
              "evidence_note": "Complaints from individuals and organisations about alleged AI Act infringements falling within the exclusive competence of the AI Office, under Article 85. All official EU languages. Supporting detail and a stated country of incident are required."
            }
          }
        ],
        "region": "European Union",
        "public_input": "open",
        "tags": [
          "harm",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-31880c76-1de6-4b10-b53d-ff79eb671f67",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "EU AI Act complaints tool (AI Office)",
        "remit": "Complaints from individuals and organisations about alleged AI Act infringements falling within the exclusive competence of the AI Office, under Article 85. All official EU languages. Supporting detail and a stated country of incident are required.",
        "reality_check": "This is the single most usable EU route for an unaffiliated person, because it solves the 'which national authority?' problem: you file centrally and the AI Office refers onward with your consent. It is brand new, so there is no outcome track record. The non-anonymity requirement is a real constraint for anyone with an employment relationship to the target — use the whistleblower tool instead in that case.",
        "accepts": "Complaints from individuals and organisations about alleged AI Act infringements falling within the exclusive competence of the AI Office, under Article 85. All official EU languages. Supporting detail and a stated country of incident are required.",
        "does_not_accept": "Infringements outside the AI Act's scope; breaches of other EU or national law; matters under Articles 53–55 (GPAI model obligations from downstream providers, which have a separate channel); and matters covered by Article 89(2). Submissions are NOT anonymous — complainant identification is required.",
        "how": "Web form at ai-act-complaints.integrityline.app, reached from the Commission's AI Act complaints tool page. State the country, describe the alleged infringement in detail, identify yourself.",
        "format": "Structured online form, any official EU language, with attachments.",
        "timing": "Rolling. The Commission page was last updated 31 July 2026.",
        "after": "The AI Office treats complaints confidentially and will notify you if your complaint falls outside its jurisdiction. With your prior consent it may refer the complaint on to national market surveillance authorities or fundamental rights enforcement bodies.",
        "operator": "European Commission — AI Office / DG CNECT; hosted on EQS Integrity Line",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Complaints from individuals and organisations about alleged AI Act infringements falling within the exclusive competence of the AI Office, under Article 85. All official EU languages. Supporting detail and a stated country of incident are required.",
            "note": "Web form at ai-act-complaints.integrityline.app, reached from the Commission's AI Act complaints tool page. State the country, describe the alleged infringement in detail, identify yourself."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-complaints-tool",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "e2a593d2e0",
        "research_order": 203,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-eu-ai-act-service-desk",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://ai-act-service-desk.ec.europa.eu/en/resources",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "d8abe1c86c78",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://ai-act-service-desk.ec.europa.eu/en/resources",
              "evidence_note": "Questions about AI Act interpretation and compliance; routes users to the complaints tool and whistleblower tool.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "insider",
                "systemic",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://ai-act-service-desk.ec.europa.eu/en/resources",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "944188b5e92e",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://ai-act-service-desk.ec.europa.eu/en/resources",
              "evidence_note": "Questions about AI Act interpretation and compliance; routes users to the complaints tool and whistleblower tool."
            }
          }
        ],
        "region": "European Union",
        "public_input": "open",
        "tags": [
          "harm",
          "insider",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-315bb6bc-b5a5-4f9d-85b1-8d47fe3d6ae3",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "EU AI Act Service Desk",
        "remit": "Questions about AI Act interpretation and compliance; routes users to the complaints tool and whistleblower tool.",
        "reality_check": "Useful as the authoritative starting point for anyone trying to work out which EU route applies to their concern, and as the canonical index of open AI Act consultations. Not itself a lever.",
        "accepts": "Questions about AI Act interpretation and compliance; routes users to the complaints tool and whistleblower tool.",
        "does_not_accept": "It is a help desk and resource hub, not an enforcement intake in its own right.",
        "how": "Browse the AI Act Explorer, Compliance Checker, guidelines and templates; contact the AI Office at CNECT-AIOFFICE@ec.europa.eu; or follow the links to the complaint and whistleblower tools. Available in English, Spanish, German, French, Italian and Polish.",
        "format": "Web resources and email.",
        "timing": "Rolling; hosts periodic public consultations on implementation topics.",
        "after": "Response from the AI Office, or referral to the appropriate tool.",
        "operator": "European Commission (AI Office / DG CNECT)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Questions about AI Act interpretation and compliance; routes users to the complaints tool and whistleblower tool.",
            "note": "Browse the AI Act Explorer, Compliance Checker, guidelines and templates; contact the AI Office at CNECT-AIOFFICE@ec.europa.eu; or follow the links to the complaint and whistleblower tools. Available in English, Spanish, German, French, Italian and Polish."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://ai-act-service-desk.ec.europa.eu/en/resources",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "e98c6edd10",
        "research_order": 207,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-eu-ai-act-whistleblower-tool",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-whistleblower-tool",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "3b15e0868a20",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-whistleblower-tool",
              "evidence_note": "Reports of harmful practices or other AI Act violations, from 'individuals who are professionally connected to providers of general-purpose AI (GPAI) models or of AI systems' within the AI Office's enforcement scope. Supporting documents may be attached.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "insider",
                "systemic",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-whistleblower-tool",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "ca2f56527d54",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-whistleblower-tool",
              "evidence_note": "Reports of harmful practices or other AI Act violations, from 'individuals who are professionally connected to providers of general-purpose AI (GPAI) models or of AI systems' within the AI Office's enforcement scope. Supporting documents may be attached."
            }
          }
        ],
        "region": "European Union",
        "public_input": "open",
        "tags": [
          "harm",
          "insider",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-8c979518-d190-4ab9-98c9-c90cce49b6d3",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "EU AI Act Whistleblower Tool (AI Office)",
        "remit": "Reports of harmful practices or other AI Act violations, from 'individuals who are professionally connected to providers of general-purpose AI (GPAI) models or of AI systems' within the AI Office's enforcement scope. Supporting documents may be attached.",
        "reality_check": "Strong on mechanics — genuine anonymity with two-way follow-up is rare and is exactly what the Right to Warn signatories asked for. Legally reinforced by AI Act Article 87, which applies the EU Whistleblower Directive (EU) 2019/1937 to AI Act infringement reporting from 2 August 2026, giving confidentiality and anti-retaliation protection. No outcome data yet; the AI Office's enforcement capacity is unproven.",
        "accepts": "Reports of harmful practices or other AI Act violations, from 'individuals who are professionally connected to providers of general-purpose AI (GPAI) models or of AI systems' within the AI Office's enforcement scope. Supporting documents may be attached.",
        "does_not_accept": "Matters outside the AI Office's enforcement remit. Note the professional-connection framing: this is an insider channel, not a general public complaint route (use the complaints tool for that).",
        "how": "Anonymous submission via the hosted portal, available in all EU languages. You receive a secure inbox so you can track progress and answer follow-up questions while remaining anonymous. The AI Office states it maintains a high standard of confidentiality with documented internal procedures to maximise protection of reporter identity.",
        "format": "Structured online form plus free text and attachments.",
        "timing": "Rolling.",
        "after": "The report enters AI Office handling; the whistleblower monitors progress and receives communications through the secure inbox.",
        "operator": "European Commission — AI Office; hosted on EQS Integrity Line (ai-act-whistleblower.integrityline.app)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Reports of harmful practices or other AI Act violations, from 'individuals who are professionally connected to providers of general-purpose AI (GPAI) models or of AI systems' within the AI Office's enforcement scope. Supporting documents may be attached.",
            "note": "Anonymous submission via the hosted portal, available in all EU languages. You receive a secure inbox so you can track progress and answer follow-up questions while remaining anonymous. The AI Office states it maintains a high standard of confidentiality with documented internal procedures to maximise protection of reporter identity."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://digital-strategy.ec.europa.eu/en/policies/ai-act-whistleblower-tool",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "0057472511",
        "research_order": 204,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "eu-gdpr-article-77-complaint-data-protection",
      "type": "reporting-channel",
      "geo": {
        "country": "eu",
        "label": "EU/EEA (and UK equivalent)"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://gdpr-info.eu/art-77-gdpr/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "62a2615182cb",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://gdpr-info.eu/art-77-gdpr/",
              "evidence_note": "Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://gdpr-info.eu/art-77-gdpr/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "e367d009f49a",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://gdpr-info.eu/art-77-gdpr/",
              "evidence_note": "Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement."
            }
          }
        ],
        "region": "United Kingdom",
        "public_input": "open",
        "tags": [
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-cfebe9da-5056-40e8-9d32-1d2e113ccaae",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "GDPR Article 77 — complaint to a data protection supervisory authority",
        "remit": "Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement.",
        "reality_check": "The most battle-tested adjacent route, with a real enforcement record against AI systems (the Italian Garante's ChatGPT actions being the best-known). Its power is the duty to inform you of progress and outcome — a stronger procedural guarantee than Article 85 of the AI Act gives. Its limit is that it only bites where personal data is involved.",
        "accepts": "Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement.",
        "does_not_accept": "Concerns that do not involve processing of personal data. This is the key limit for AI safety work: it reaches training data, inference on personal data, profiling, automated decision-making and accuracy of personal data, but not model capability, misuse potential or catastrophic risk.",
        "how": "File with the chosen supervisory authority, usually via their online form. Frame the concern in data protection terms — lawful basis, accuracy, transparency, Article 22 automated decision-making — because a concern framed as 'this AI is unsafe' will be rejected as out of scope, while the same facts framed as a data protection issue may be entertained.",
        "format": "Authority-specific form; identify the controller, the processing, the provision breached, and the effect on you.",
        "timing": "Rolling.",
        "after": "The supervisory authority must inform the complainant of the progress and outcome of the complaint, and of the possibility of a judicial remedy under Article 78. Without prejudice to other remedies.",
        "operator": "National data protection authorities (EU/EEA); ICO in the UK",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Complaints from any data subject who considers that processing of their personal data infringes the GDPR. You may complain to the authority in your Member State of habitual residence, your place of work, or the place of the alleged infringement.",
            "note": "File with the chosen supervisory authority, usually via their online form. Frame the concern in data protection terms — lawful basis, accuracy, transparency, Article 22 automated decision-making — because a concern framed as 'this AI is unsafe' will be rejected as out of scope, while the same facts framed as a data protection issue may be entertained."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://gdpr-info.eu/art-77-gdpr/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "bb8c64ed4c",
        "research_order": 208,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "fr-mistral-ai",
      "type": "company",
      "geo": {
        "country": "fr",
        "label": "France / EU"
      },
      "facts": {
        "routes": [
          {
            "id": "content-usage-policy-report",
            "type": "form",
            "value": "https://mistral.ai/report/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "53edf1b4d65e",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://mistral.ai/report/",
              "evidence_note": "21 categories of content violation (hate speech, CSAM, violence, NCII, fraud, IP). Intro: 'Mistral AI is committed to maintaining a safe environment for all. This form allows you to report content you believe violates our terms or applicable laws.'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "form"
              ],
              "restrictions": "21 categories of content violation (hate speech, CSAM, violence, NCII, fraud, IP). Intro: 'Mistral AI is committed to maintaining a safe environment for all. This form allows you to report content you believe violates our terms or applicable laws.'"
            }
          },
          {
            "id": "hackerone-vulnerability-submission",
            "type": "disclosure",
            "value": "https://hackerone.com/58acc269-165e-4d18-a2d8-61f296cdea60/embedded_submissions/new?locale=en",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "15687c0cb3c5",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://hackerone.com/58acc269-165e-4d18-a2d8-61f296cdea60/embedded_submissions/new?locale=en",
              "evidence_note": "Security vulnerabilities. Published on the contact page, which notes 'General bugs shall be reported via our standard support channels'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "disclosure"
              ],
              "restrictions": "Security vulnerabilities. Published on the contact page, which notes 'General bugs shall be reported via our standard support channels'."
            }
          },
          {
            "id": "press",
            "type": "email",
            "value": "press@mistral.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "0a2ec741afe0",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://mistral.ai/report/",
              "evidence_note": "Media enquiries only.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "email"
              ],
              "restrictions": "Media enquiries only."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://mistral.ai/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "23dac5ecc7e6",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://mistral.ai/",
              "evidence_note": "No public accounts found of anyone reaching a Mistral safety function. No safety@ or disclosure@ address is published anywhere on mistral.ai or legal.mistral.ai — checked the contact page, terms, and usage policy directly. The report form's requirement of a content URL structurally prevents reporting a capability or alignment finding."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://legal.mistral.ai/terms/usage-policy",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "33adc1d00206",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://legal.mistral.ai/terms/usage-policy",
              "evidence_note": "No public accounts found of anyone reaching a Mistral safety function. No safety@ or disclosure@ address is published anywhere on mistral.ai or legal.mistral.ai — checked the contact page, terms, and usage policy directly. The report form's requirement of a content URL structurally prevents reporting a capability or alignment finding."
            }
          }
        ],
        "region": "European Union",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "insider",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-85e501c2-3e72-4d96-aa32-32a8192a1945",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Mistral AI",
        "remit": "No publicly named safety or alignment function. Trust Center covers data protection and security compliance; the Usage Policy is enforced through a content-reporting form.",
        "reality_check": "No public accounts found of anyone reaching a Mistral safety function. No safety@ or disclosure@ address is published anywhere on mistral.ai or legal.mistral.ai — checked the contact page, terms, and usage policy directly. The report form's requirement of a content URL structurally prevents reporting a capability or alignment finding.",
        "notes": "For a European frontier developer this is a thin public surface: not found — general contact only, at https://mistral.ai/contact. If you have a model-safety finding, the HackerOne form is the only route with a human triage attached, but it is framed as security. No safe-harbour language and no whistleblower channel found.",
        "routes": {
          "content-usage-policy-report": {
            "label": "Content / usage policy report form",
            "scope": "21 categories of content violation (hate speech, CSAM, violence, NCII, fraud, IP). Intro: 'Mistral AI is committed to maintaining a safe environment for all. This form allows you to report content you believe violates our terms or applicable laws.'",
            "note": "Content moderation, not model safety. Requires you to supply a URL or a shared private chat link to the offending content — so it cannot be used to report a general model flaw."
          },
          "hackerone-vulnerability-submission": {
            "label": "HackerOne vulnerability submission",
            "scope": "Security vulnerabilities. Published on the contact page, which notes 'General bugs shall be reported via our standard support channels'.",
            "note": "No stated AI/model safety scope."
          },
          "press": {
            "label": "Press",
            "scope": "Media enquiries only.",
            "note": "Listed here only because it is one of the few published addresses."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No published frontier safety framework or responsible scaling policy found"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://mistral.ai/report/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://hackerone.com/58acc269-165e-4d18-a2d8-61f296cdea60/embedded_submissions/new?locale=en",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "517b56617f",
        "research_order": 8,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "fr-saferai",
      "type": "watchdog",
      "geo": {
        "country": "fr",
        "label": "France (Paris, 6 Rue d'Armaillé, 75017)"
      },
      "facts": {
        "routes": [
          {
            "id": "general-enquiries",
            "type": "email",
            "value": "contact@safer-ai.org",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "10f7fb0b44e8",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://ratings.safer-ai.org/",
              "evidence_note": "Anyone",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "research",
                "systemic",
                "email"
              ],
              "restrictions": "Anyone"
            }
          },
          {
            "id": "company-risk-management-ratings",
            "type": "submission",
            "value": "https://ratings.safer-ai.org/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "825782d119b3",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://ratings.safer-ai.org/",
              "evidence_note": "Public read; methodology published",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "research",
                "systemic",
                "submission"
              ],
              "restrictions": "Public read; methodology published"
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.safer-ai.org/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "4ad5fb52ce5d",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.safer-ai.org/",
              "evidence_note": "Small, technically serious and European — which matters, because it has standing in the EU standardisation processes that most US safety organisations do not. Responsive to substantive technical input on risk methodology."
            }
          },
          {
            "id": "action",
            "type": "action",
            "value": "https://www.safer-ai.org/about#donate",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "725296e25adb",
            "contact": {
              "status": "unknown",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:source-review-2026-09-24",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only"
            }
          }
        ],
        "region": "European Union",
        "public_input": "limited",
        "tags": [
          "research",
          "systemic",
          "fund",
          "join",
          "law"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "perspective": "safety-advocacy",
        "volunteers": "no",
        "entity_key": "entity-3b6b8dd4-6ea5-40fc-8ebb-c98c5fe65444",
        "roles": [
          "watchdog",
          "organisation"
        ]
      },
      "strings": {
        "name": "SaferAI",
        "remit": "Non-profit focused on AI risk management. Three arms: research (quantitative risk models — nine cyber risk models completed, expanding to loss of control and CBRN); ratings (independent grading of how well leading AI companies manage risk, across risk identification, severity assessment, safeguards and governance, published at ratings.safer-ai.org); and standards (leads AI risk management standards work in the EU and edits international red-teaming standards).",
        "threat_model": "Risk-management adequacy at frontier developers — explicitly covering cyber, loss of control and CBRN. Methodologically the most rigorous of the company-rating projects, borrowing from mature safety-critical industries.",
        "reality_check": "Small, technically serious and European — which matters, because it has standing in the EU standardisation processes that most US safety organisations do not. Responsive to substantive technical input on risk methodology.",
        "gov_channel": "Real in Europe — SaferAI staff serve as editors on international standards and participate in EU AI Act standardisation and the GPAI Code of Practice process.",
        "routes": {
          "general-enquiries": {
            "label": "General enquiries",
            "scope": "Anyone"
          },
          "company-risk-management-ratings": {
            "label": "Company risk-management ratings portal",
            "scope": "Public read; methodology published",
            "note": "UNVERIFIED whether they accept public submissions of evidence about a company's practices — worth asking via contact@."
          },
          "homepage": {
            "label": "Homepage"
          },
          "action": {
            "label": "Action page"
          }
        },
        "the_ask": "AI companies should be held to real risk-management standards, and governance should be built on rigorous, auditable frameworks rather than voluntary promises.",
        "what_they_do": "Research on risk management frameworks, public ratings of AI companies' safety practices (ratings.safer-ai.org), and standards work in EU and international governance processes.",
        "newcomer_action": "Read and cite the company ratings when arguing with policymakers or employers; donate; apply for an open role.",
        "tips": "unclear",
        "geography": "France (Paris) and EU-level; registered French nonprofit, reg. no. 919 185 199 00016.",
        "scale": "Small technical nonprofit; headcount not published.",
        "spending": "Not disclosed.",
        "caution": "A research and standards body, not a campaign — there is no membership or activist route. Its ratings are useful ammunition for other people's campaigns."
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://ratings.safer-ai.org/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://www.safer-ai.org/about#donate",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "7fdb66554d",
        "research_order": 125,
        "migrated_from": "input/data/institutions.json",
        "legacy_ids": [
          "7fdb66554d",
          "421f461bd7"
        ],
        "aliases": [
          "fr-saferai-2",
          "SaferAI"
        ],
        "redirect_from": [
          {
            "section": "orgs",
            "id": "fr-saferai-2"
          }
        ],
        "identity_review": {
          "evidence_urls": [
            "https://ratings.safer-ai.org/",
            "https://www.safer-ai.org/about#donate"
          ],
          "reviewed_by": "codex:source-review-2026-09-24",
          "approved_by": "owner:autonomous-implementation-request-2026-09-24",
          "reviewed_on": "2026-09-24",
          "review_by": "2027-03-23",
          "note": "The records describe one real-world entity; preserve complementary facts and retire the non-canonical public id."
        },
        "merge_provenance": {
          "geo.country": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "geo.label": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.routes": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.region": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.public_input": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.tags": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_disposition": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_by": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_on": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.name": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.remit": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.threat_model": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.reality_check": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.gov_channel": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.routes": [
            {
              "record_id": "fr-saferai",
              "source_url": "https://ratings.safer-ai.org/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.perspective": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.volunteers": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.the_ask": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.what_they_do": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.newcomer_action": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.tips": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.geography": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.scale": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.spending": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.caution": [
            {
              "record_id": "fr-saferai-2",
              "source_url": "https://www.safer-ai.org/about#donate",
              "checked_on": "2026-09-22"
            }
          ]
        }
      }
    },
    {
      "id": "gb-ofcom-online-safety-super-complaints",
      "type": "reporting-channel",
      "geo": {
        "country": "gb",
        "label": "UK"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://www.ofcom.org.uk/online-safety/online-safety-super-complaints",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "c3be7595c9d3",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.ofcom.org.uk/online-safety/online-safety-super-complaints",
              "evidence_note": "Complaints from eligible entities about a feature or conduct of one or more regulated services presenting a material risk of significant harm, of significant adverse impact on freedom of expression, or other significant adverse impacts. For a single-service complaint you must additionally explain its particular importance or the scale of user impact.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "systemic",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.ofcom.org.uk/online-safety/online-safety-super-complaints",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "7ffd8616ee94",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.ofcom.org.uk/online-safety/online-safety-super-complaints",
              "evidence_note": "Complaints from eligible entities about a feature or conduct of one or more regulated services presenting a material risk of significant harm, of significant adverse impact on freedom of expression, or other significant adverse impacts. For a single-service complaint you must additionally explain its particular importance or the scale of user impact."
            }
          }
        ],
        "region": "United Kingdom",
        "public_input": "open",
        "tags": [
          "harm",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-b2de5a47-43a1-4704-abf4-387480186648",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Ofcom Online Safety super-complaints",
        "remit": "Complaints from eligible entities about a feature or conduct of one or more regulated services presenting a material risk of significant harm, of significant adverse impact on freedom of expression, or other significant adverse impacts. For a single-service complaint you must additionally explain its particular importance or the scale of user impact.",
        "reality_check": "This is the UK's real lever on platform-level AI harms, with binding response timescales — a sharp contrast to individual complaints, which Ofcom will not investigate. The whole design assumes intermediation by civil society. For a playbook, the actionable instruction is: package your evidence to Ofcom's stated standard (current, objective, verifiable) and hand it to an eligible body.",
        "accepts": "Complaints from eligible entities about a feature or conduct of one or more regulated services presenting a material risk of significant harm, of significant adverse impact on freedom of expression, or other significant adverse impacts. For a single-service complaint you must additionally explain its particular importance or the scale of user impact.",
        "does_not_accept": "Individuals cannot bring super-complaints. The entity must represent the interests of users, the public or a specific group; be independent of regulated services; be a significant expert contributor to public online safety discussion; and have regard to Ofcom's guidance.",
        "how": "Written submission to Ofcom with organisational contact details, description of the feature or conduct, identification of the services/providers, and evidence of material risk. Supporting evidence must be current, objective and verifiable. An unaffiliated individual's realistic route is to supply evidence to an eligible organisation rather than to file directly.",
        "format": "Written submission per Ofcom's super-complaints guidance; evidence-led.",
        "timing": "Rolling. Regime commenced 1 January 2026.",
        "after": "Ofcom decides eligibility within 30 days of a completed submission, and responds to an admissible complaint usually within 90 days (extendable if further information is needed).",
        "operator": "Ofcom, under the Online Safety Act 2023",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Complaints from eligible entities about a feature or conduct of one or more regulated services presenting a material risk of significant harm, of significant adverse impact on freedom of expression, or other significant adverse impacts. For a single-service complaint you must additionally explain its particular importance or the scale of user impact.",
            "note": "Written submission to Ofcom with organisational contact details, description of the feature or conduct, identification of the services/providers, and evidence of material risk. Supporting evidence must be current, objective and verifiable. An unaffiliated individual's realistic route is to supply evidence to an eligible organisation rather than to file directly."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.ofcom.org.uk/online-safety/online-safety-super-complaints",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "74846c8fbb",
        "research_order": 211,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "gb-stability-ai",
      "type": "company",
      "geo": {
        "country": "gb",
        "label": "UK / USA"
      },
      "facts": {
        "routes": [
          {
            "id": "safety-misuse-reports",
            "type": "email",
            "value": "safety@stability.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "5010705a67db",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://stability.ai/safety",
              "evidence_note": "Reporting misuse of Stability models and safety concerns.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "email"
              ]
            }
          },
          {
            "id": "appeals-request-form",
            "type": "form",
            "value": "https://stability.ai/safety",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "e0a9795c591b",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://stability.ai/safety",
              "evidence_note": "Appealing a policy-violation determination believed to be in error.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "form"
              ]
            }
          },
          {
            "id": "trust-center",
            "type": "program",
            "value": "https://trust.stability.ai/",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "1a29dd733a75",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://trust.stability.ai/",
              "evidence_note": "Security and compliance documentation."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://stability.ai/safety",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "131b8676a2a7",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://stability.ai/safety",
              "evidence_note": "No public accounts found of response rates to safety@stability.ai. Stability's safety posture has been heavily criticised in the context of open-weight image models and CSAM (the LAION training-data findings), and its transparency reporting is the main published evidence of enforcement. The address is real; its throughput is unknown."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://stability.ai/use-policy",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "f60e3f3c9ce0",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://stability.ai/use-policy",
              "evidence_note": "No public accounts found of response rates to safety@stability.ai. Stability's safety posture has been heavily criticised in the context of open-weight image models and CSAM (the LAION training-data findings), and its transparency reporting is the main published evidence of enforcement. The address is real; its throughput is unknown."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "behaviour",
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-ffe2dd77-3cff-4164-8b00-efe1b1858e7a",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Stability AI",
        "remit": "'Stable Safety' — the publicly branded safety function covering open-weight image and audio models, built around six principles including Safety-First Open Source and Banning AI Misuse, plus an annual Integrity Transparency Report.",
        "reality_check": "No public accounts found of response rates to safety@stability.ai. Stability's safety posture has been heavily criticised in the context of open-weight image models and CSAM (the LAION training-data findings), and its transparency reporting is the main published evidence of enforcement. The address is real; its throughput is unknown.",
        "notes": "safety@stability.ai is the route. Note there is no frontier safety framework or scaling policy — the AUP and the six Stable Safety principles are the whole published governance surface. For open-weight models, reporting misuse to the developer has limited effect once weights are distributed; that is a structural limit, not a channel failure.",
        "routes": {
          "safety-misuse-reports": {
            "label": "Safety and misuse reports",
            "scope": "Reporting misuse of Stability models and safety concerns.",
            "note": "Published on the Stable Safety page. A named, dedicated safety address."
          },
          "appeals-request-form": {
            "label": "Appeals request form",
            "scope": "Appealing a policy-violation determination believed to be in error.",
            "note": "Linked from the safety page."
          },
          "trust-center": {
            "label": "Trust Center",
            "scope": "Security and compliance documentation."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Acceptable Use Policy (Stable Safety principles)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://stability.ai/safety",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "e42dd6b50b",
        "research_order": 11,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "gb-uk-ico-data-protection-complaint",
      "type": "reporting-channel",
      "geo": {
        "country": "gb",
        "label": "UK"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://ico.org.uk/make-a-complaint/data-protection-framework/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "e45597d4ee99",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://ico.org.uk/make-a-complaint/data-protection-framework/",
              "evidence_note": "Complaints about how an organisation has handled your personal information. General customer service complaints only if combined with a data protection concern.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://ico.org.uk/make-a-complaint/data-protection-framework/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "efecb13b71df",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://ico.org.uk/make-a-complaint/data-protection-framework/",
              "evidence_note": "Complaints about how an organisation has handled your personal information. General customer service complaints only if combined with a data protection concern."
            }
          }
        ],
        "region": "United Kingdom",
        "public_input": "open",
        "tags": [
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-25aee15b-66d1-4010-80ad-4ca84815e7e7",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "UK ICO data protection complaint",
        "remit": "Complaints about how an organisation has handled your personal information. General customer service complaints only if combined with a data protection concern.",
        "reality_check": "Be realistic: the modal outcome is that your complaint is logged as intelligence. Its value is cumulative and systemic — the ICO acts on patterns, so a well-evidenced complaint contributes to a case file even when your individual outcome is nil. Do not expect personal redress.",
        "accepts": "Complaints about how an organisation has handled your personal information. General customer service complaints only if combined with a data protection concern.",
        "does_not_accept": "Non-data-protection grievances. The ICO does not award compensation or obtain individual redress — outcomes are regulatory, not remedial. Compensation requires a court claim.",
        "how": "Raise it with the organisation first and give them a chance to put things right, then complain via ico.org.uk/make-a-complaint. Expect the ICO to ask what the organisation said.",
        "format": "Online form; concise factual narrative plus the organisation's response.",
        "timing": "Rolling. Where you ask the ICO to review how it handled your complaint, a reviewing officer writes to you within 30 calendar days.",
        "after": "Outcomes range from recording the complaint for intelligence purposes, to confirming the organisation complied, to asking the organisation to improve practice, to regulatory action in appropriate cases. Most complaints end at the first two.",
        "operator": "Information Commissioner's Office",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Complaints about how an organisation has handled your personal information. General customer service complaints only if combined with a data protection concern.",
            "note": "Raise it with the organisation first and give them a chance to put things right, then complain via ico.org.uk/make-a-complaint. Expect the ICO to ask what the organisation said."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://ico.org.uk/make-a-complaint/data-protection-framework/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "c34364b81d",
        "research_order": 209,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "gb-uk-parliament-e-petitions",
      "type": "reporting-channel",
      "geo": {
        "country": "gb",
        "label": "UK"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "consultation",
            "value": "https://petition.parliament.uk/help",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "3cd5b07e6dd9",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://petition.parliament.uk/help",
              "evidence_note": "Petitions from British citizens and UK residents that ask for a clear action from the UK Government or Parliament on a matter within their responsibility.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "law",
                "systemic",
                "consultation"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://petition.parliament.uk/help",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "eb1774e60714",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://petition.parliament.uk/help",
              "evidence_note": "Petitions from British citizens and UK residents that ask for a clear action from the UK Government or Parliament on a matter within their responsibility."
            }
          }
        ],
        "region": "United Kingdom",
        "public_input": "open",
        "tags": [
          "law",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-6b70f210-ab58-48ed-8b56-7df882880bc6",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "UK Parliament e-petitions",
        "remit": "Petitions from British citizens and UK residents that ask for a clear action from the UK Government or Parliament on a matter within their responsibility.",
        "reality_check": "Largely symbolic, and should be labelled as such. The 10,000 threshold buys a departmental form response drafted to restate existing policy; the 100,000 threshold buys, at best, a sparsely-attended Westminster Hall debate that binds nobody. It is not remotely equivalent to written evidence to a select committee, which is published under your name, permanently citable and quoted in reports the Government must formally answer. Use petitions for public attention and media hooks, not for influence.",
        "accepts": "Petitions from British citizens and UK residents that ask for a clear action from the UK Government or Parliament on a matter within their responsibility.",
        "does_not_accept": "Local council matters; anything not calling for a clear action; petitions failing the standards check. Only petitions created on petition.parliament.uk qualify — petitions hosted elsewhere (Change.org, 38 Degrees) receive no government response and no committee consideration whatsoever.",
        "how": "Draft the petition, secure 5 supporters, submit for standards review, and if approved it is published and open for signatures for 6 months.",
        "format": "A short, single, clearly-actionable request.",
        "timing": "6 months open once published.",
        "after": "At 10,000 signatures the Government publishes a written response. At 100,000 the petition is considered for a Westminster Hall debate — the Petitions Committee retains discretion and may decline if the topic was recently debated or is already scheduled.",
        "operator": "UK Government and Parliament, overseen by the Commons Petitions Committee",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Petitions from British citizens and UK residents that ask for a clear action from the UK Government or Parliament on a matter within their responsibility.",
            "note": "Draft the petition, secure 5 supporters, submit for standards review, and if approved it is published and open for signatures for 6 months."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://petition.parliament.uk/help",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "c10a15d9c7",
        "research_order": 218,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "gb-uk-public-interest-disclosure-act-protected",
      "type": "reporting-channel",
      "geo": {
        "country": "gb",
        "label": "UK"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://www.handleygill.co.uk/handley-gill-blog/public-interest-disclosure-prescribed-persons-order-2026-whistleblowing",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "20cfc72695aa",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.handleygill.co.uk/handley-gill-blog/public-interest-disclosure-prescribed-persons-order-2026-whistleblowing",
              "evidence_note": "Qualifying disclosures by workers, in the public interest, to a prescribed person with responsibility for the relevant subject matter — giving statutory protection against detriment and dismissal.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "insider",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.handleygill.co.uk/handley-gill-blog/public-interest-disclosure-prescribed-persons-order-2026-whistleblowing",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "1cd242721547",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.handleygill.co.uk/handley-gill-blog/public-interest-disclosure-prescribed-persons-order-2026-whistleblowing",
              "evidence_note": "Qualifying disclosures by workers, in the public interest, to a prescribed person with responsibility for the relevant subject matter — giving statutory protection against detriment and dismissal."
            }
          }
        ],
        "region": "United Kingdom",
        "public_input": "open",
        "tags": [
          "flaw",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-a32c08e1-a439-4169-adc0-a1f972375671",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "UK Public Interest Disclosure Act — protected disclosure to a prescribed person",
        "remit": "Qualifying disclosures by workers, in the public interest, to a prescribed person with responsibility for the relevant subject matter — giving statutory protection against detriment and dismissal.",
        "reality_check": "Meaningful but reactive: PIDA does not stop retaliation, it gives you a claim after it happens. The 2026 addition of DSIT is a genuine and underpublicised development, creating for the first time a UK prescribed route for technology-policy disclosures. Take legal advice on which prescribed person covers your concern before disclosing — getting this wrong forfeits the protection.",
        "accepts": "Qualifying disclosures by workers, in the public interest, to a prescribed person with responsibility for the relevant subject matter — giving statutory protection against detriment and dismissal.",
        "does_not_accept": "Disclosures to a body that is not prescribed for that subject matter do not attract the same protection. This is the most common and most costly error.",
        "how": "Identify the correct prescribed person for the subject matter and disclose to them. Relevant to AI: the Public Interest Disclosure (Prescribed Persons) (Amendment) Order 2026 (SI 2026/478), in force 2 June 2026, added the Secretary of State for Science, Innovation and Technology as a prescribed person — the first explicitly AI/digital-policy route — and expanded the scope for existing regulators including Ofcom and the FCA. The ICO remains prescribed for data protection matters.",
        "format": "Per the receiving regulator's whistleblowing process (e.g. Ofcom's protected disclosure route, ICO's whistleblowing disclosures page).",
        "timing": "Rolling. Employment tribunal claims have short deadlines — typically 3 months less one day.",
        "after": "The prescribed person considers the disclosure; prescribed persons must report annually on disclosures received. Protection is enforced retrospectively via employment tribunal if you suffer detriment.",
        "operator": "Prescribed persons listed in secondary legislation; PIDA 1998 as amended",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Qualifying disclosures by workers, in the public interest, to a prescribed person with responsibility for the relevant subject matter — giving statutory protection against detriment and dismissal.",
            "note": "Identify the correct prescribed person for the subject matter and disclose to them. Relevant to AI: the Public Interest Disclosure (Prescribed Persons) (Amendment) Order 2026 (SI 2026/478), in force 2 June 2026, added the Secretary of State for Science, Innovation and Technology as a prescribed person — the first explicitly AI/digital-policy route — and expanded the scope for existing regulators including Ofcom and the FCA. The ICO remains prescribed for data protection matters."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.handleygill.co.uk/handley-gill-blog/public-interest-disclosure-prescribed-persons-order-2026-whistleblowing",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "104a2fa2e8",
        "research_order": 225,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "gb-uk-select-committee-written-evidence",
      "type": "reporting-channel",
      "geo": {
        "country": "gb",
        "label": "UK"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "consultation",
            "value": "https://publications.parliament.uk/pa/cm/written-evidence-guidance.htm",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "7d3bd5559d3f",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://publications.parliament.uk/pa/cm/written-evidence-guidance.htm",
              "evidence_note": "Evidence drawn from research, professional expertise or personal experience. You explicitly do not need to be a formal expert or have any institutional affiliation. Address the questions in the call for evidence; you need not answer all of them.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "law",
                "systemic",
                "consultation"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://publications.parliament.uk/pa/cm/written-evidence-guidance.htm",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "46dab162bd4b",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://publications.parliament.uk/pa/cm/written-evidence-guidance.htm",
              "evidence_note": "Evidence drawn from research, professional expertise or personal experience. You explicitly do not need to be a formal expert or have any institutional affiliation. Address the questions in the call for evidence; you need not answer all of them."
            }
          }
        ],
        "region": "United Kingdom",
        "public_input": "open",
        "tags": [
          "law",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-871dd579-ed95-41f6-82dd-e840ee9fba34",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "UK select committee written evidence",
        "remit": "Evidence drawn from research, professional expertise or personal experience. You explicitly do not need to be a formal expert or have any institutional affiliation. Address the questions in the call for evidence; you need not answer all of them.",
        "reality_check": "The highest-value consultation route available to an unaffiliated individual, and the clearest counterexample to 'petitions are pointless.' Evidence is published under your name, is permanently citable, is read by clerks and specialist advisers, and is routinely quoted in reports that government must respond to. Two privacy options exist: anonymity (published without your name — 'provides some protection but is not failsafe') and confidentiality (informs members privately, neither name nor contribution published — described by Parliament as 'the safest way' if you fear identification).",
        "accepts": "Evidence drawn from research, professional expertise or personal experience. You explicitly do not need to be a formal expert or have any institutional affiliation. Address the questions in the call for evidence; you need not answer all of them.",
        "does_not_accept": "Evidence about active court proceedings; individual complaints or personal grievances (you are told to contact your MP instead); previously published material — submissions must be original and created specifically for the committee; defamatory statements likely to harm reputations; personal data you would not want made public. House of Lords committees require you to declare substantial AI-generated content.",
        "how": "Find an inquiry currently accepting evidence via the committees portal filter (committees.parliament.uk/inquiries/ with 'Currently accepting evidence'), then submit through that inquiry's online portal. At the time of this research 27 inquiries were accepting evidence and none was specifically AI-focused — but AI-relevant evidence is regularly submitted to inquiries on employment, financial services, human rights and public services, and recent AI inquiries (Business and Trade Committee on AI and the future workforce; Treasury Committee on AI in financial services; JCHR on human rights and AI regulation) show the pattern.",
        "format": "Single editable file (Word, ODT or RTF), max 25MB. No PDFs, no logos, no decorative graphics, no repeated headers/footers. Usually no more than 3,000 words. Numbered paragraphs and section headings. Plain language with technical terms explained. Cite published sources with links.",
        "timing": "Hard deadlines set per inquiry, typically 4–10 weeks from launch. Check the specific inquiry page.",
        "after": "The committee decides whether to accept and publish. Published evidence becomes part of the permanent parliamentary record and remains publicly accessible indefinitely; you cannot request changes or removal afterwards. Do not self-publish until the committee authorises it. Submissions may be quoted and cited in the committee's report. You are responsible for accuracy — deliberately misleading a committee is a contempt of Parliament.",
        "operator": "House of Commons and House of Lords select committees, UK Parliament",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Evidence drawn from research, professional expertise or personal experience. You explicitly do not need to be a formal expert or have any institutional affiliation. Address the questions in the call for evidence; you need not answer all of them.",
            "note": "Find an inquiry currently accepting evidence via the committees portal filter (committees.parliament.uk/inquiries/ with 'Currently accepting evidence'), then submit through that inquiry's online portal. At the time of this research 27 inquiries were accepting evidence and none was specifically AI-focused — but AI-relevant evidence is regularly submitted to inquiries on employment, financial services, human rights and public services, and recent AI inquiries (Business and Trade Committee on AI and the future workforce; Treasury Committee on AI in financial services; JCHR on human rights and AI regulation) show the pattern."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://publications.parliament.uk/pa/cm/written-evidence-guidance.htm",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "e3a75c7a4a",
        "research_order": 214,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-ai-incident-database",
      "type": "watchdog",
      "geo": {
        "country": "global",
        "label": "International (US-registered non-profit)"
      },
      "facts": {
        "routes": [
          {
            "id": "submit-incident-open-anyone",
            "type": "submission",
            "value": "https://incidentdatabase.ai/apps/submit/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "38b79dfd50a1",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://incidentdatabase.ai/apps/submit/",
              "evidence_note": "Anyone, worldwide",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "research",
                "submission"
              ]
            }
          },
          {
            "id": "responsible-ai-collaborative-collaboration",
            "type": "email",
            "value": "info@raicollab.org",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "305c0c08618f",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://incidentdatabase.ai/apps/submit/",
              "evidence_note": "Partnership, research, editorial",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "research",
                "email"
              ]
            }
          },
          {
            "id": "contact-page",
            "type": "form",
            "value": "https://incidentdatabase.ai/contact/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ab3736cdabf0",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://incidentdatabase.ai/contact/",
              "evidence_note": "General",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "research",
                "form"
              ]
            }
          },
          {
            "id": "github-issues-bugs",
            "type": "submission",
            "value": "https://github.com/responsible-ai-collaborative/aiid/issues/new",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "e7aae82bc1d4",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://github.com/responsible-ai-collaborative/aiid/issues/new",
              "evidence_note": "Anyone",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "harm",
                "research",
                "submission"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://incidentdatabase.ai/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "85bee4a5ec3e",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://incidentdatabase.ai/",
              "evidence_note": "Small, volunteer-heavy, and genuinely reads its submissions — one of the few places in this entire list where an unaffiliated person's report reliably gets human attention and can end up in the permanent public record. If you have a specific realised harm, start here. Editorial review takes time and marginal submissions do get rejected."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "behaviour",
          "harm",
          "research"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-cbecca47-b455-4c81-9d21-5d56ad874cb1",
        "roles": [
          "watchdog"
        ]
      },
      "strings": {
        "name": "AI Incident Database (Responsible AI Collaborative)",
        "remit": "Public, open-source, citable index of realised AI harms and near-harms, modelled on aviation and cybersecurity incident databases. Community-submitted incidents are editorially reviewed and indexed with reports, entities and classifications. Recent entries span AI medical transcription misuse, deepfake tooling, chatbots implicated in violence planning, and law-enforcement technology abuse.",
        "threat_model": "Realised harms of any severity, empirically grounded. Strongest on near-term harms; increasingly captures misuse and agentic failures. Not a theoretical-risk organisation.",
        "reality_check": "Small, volunteer-heavy, and genuinely reads its submissions — one of the few places in this entire list where an unaffiliated person's report reliably gets human attention and can end up in the permanent public record. If you have a specific realised harm, start here. Editorial review takes time and marginal submissions do get rejected.",
        "gov_channel": "Indirect but real — AIID entries are cited by OECD AIM, academic literature, journalists and regulators. Getting an incident indexed here makes it citable everywhere else.",
        "routes": {
          "submit-incident-open-anyone": {
            "label": "Submit an incident — open to anyone, no account required",
            "scope": "Anyone, worldwide",
            "note": "THE canonical public route for reporting a concrete AI harm. Submissions are editorially reviewed before publication."
          },
          "responsible-ai-collaborative-collaboration": {
            "label": "Responsible AI Collaborative — collaboration enquiries",
            "scope": "Partnership, research, editorial"
          },
          "contact-page": {
            "label": "Contact page",
            "scope": "General"
          },
          "github-issues-bugs": {
            "label": "GitHub issues — bugs, taxonomy, code",
            "scope": "Anyone"
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://incidentdatabase.ai/apps/submit/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://incidentdatabase.ai/contact/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://github.com/responsible-ai-collaborative/aiid/issues/new",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "6e2cf2696b",
        "research_order": 93,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-ai-vulnerability-database",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "Global"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "reporting",
            "value": "https://avidml.org/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "93fd4402ebae",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://avidml.org/",
              "evidence_note": "Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "reporting"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://avidml.org/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "d11b6430f372",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://avidml.org/",
              "evidence_note": "Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-2a60dbd1-a713-44b1-953f-7da515d404b9",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "AI Vulnerability Database (AVID)",
        "remit": "Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.",
        "reality_check": "Modest but real: it is an actively maintained, citable identifier namespace with 2026-dated records, and it is one of the few places a model-behaviour flaw can get a permanent public ID. Small organisation, small readership; do not expect it to force a vendor response on its own.",
        "accepts": "Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.",
        "does_not_accept": "Not explicitly documented. In practice it is oriented to reproducible model/system failure modes rather than narrative harm accounts — those belong in AIID.",
        "how": "Public 'Submit an AI Vulnerability!' link on avidml.org, which routes to a Google Form. Alternatively contribute structured records via the avidml GitHub organisation. Documentation at docs.avidml.org.",
        "format": "Structured record against AVID's taxonomy (security / ethics / performance dimensions), with reproduction detail. Short, technical, evidence-led.",
        "timing": "Rolling.",
        "after": "Accepted records get an AVID identifier (e.g. AVID-2026-R1407) and are published in the searchable database.",
        "operator": "AI Risk and Vulnerability Alliance (ARVA), a nonprofit",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Failure modes in general-purpose AI systems — open-weight generative models, closed-API systems, developer tools, and end-to-end AI applications and agents. Records are split into vulnerabilities and reports, organised by a taxonomy library. Rebuilt in 2026 for agentic AI.",
            "note": "Public 'Submit an AI Vulnerability!' link on avidml.org, which routes to a Google Form. Alternatively contribute structured records via the avidml GitHub organisation. Documentation at docs.avidml.org."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://avidml.org/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "a8f4ca6b90",
        "research_order": 191,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-anthropic-model-safety-bug-bounty",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "Global"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "afcd1c431875",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
              "evidence_note": "Universal jailbreaks that defeat Anthropic's Constitutional Classifiers — generalised techniques that work across many prompts, tested against a supplied set of harmful questions concerning CBRN/biological threat information. Narrow, context-specific exploits do not qualify.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "c0b175e7dec4",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
              "evidence_note": "Universal jailbreaks that defeat Anthropic's Constitutional Classifiers — generalised techniques that work across many prompts, tested against a supplied set of harmful questions concerning CBRN/biological threat information. Narrow, context-specific exploits do not qualify."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-e01a960b-efc3-488a-aa0d-105b92a8dfcf",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Anthropic Model Safety Bug Bounty",
        "remit": "Universal jailbreaks that defeat Anthropic's Constitutional Classifiers — generalised techniques that work across many prompts, tested against a supplied set of harmful questions concerning CBRN/biological threat information. Narrow, context-specific exploits do not qualify.",
        "reality_check": "Pays real money and is a genuine channel to the safety team, but it is gated: you must be accepted, sign an NDA, and you may not publish the jailbreak, the test questions or classifier details without written consent. You may disclose that you participate. Not a route for someone who wants to speak publicly, and not open-entry.",
        "accepts": "Universal jailbreaks that defeat Anthropic's Constitutional Classifiers — generalised techniques that work across many prompts, tested against a supplied set of harmful questions concerning CBRN/biological threat information. Narrow, context-specific exploits do not qualify.",
        "does_not_accept": "Infrastructure vulnerabilities (misconfigurations, CSRF, privilege escalation, SQLi, XSS, directory traversal) — those belong under the Responsible Disclosure Policy. Also excludes single-prompt or narrow jailbreaks.",
        "how": "Complete a Google Form application and create a HackerOne account first. If accepted you receive a HackerOne invitation and must create a Claude Console account using your @wearehackerone.com alias. An NDA is mandatory. Applications reviewed on a rolling basis.",
        "format": "HackerOne report with detailed methodology; rewards graded on a sliding scale against internal criteria for response detail and accuracy.",
        "timing": "Rolling applications; invite-only participation.",
        "after": "Graded against internal criteria; up to $35,000 per novel universal jailbreak. Accepted participants get free access to a model alias for authorised red-teaming only.",
        "operator": "Anthropic, run on HackerOne",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Universal jailbreaks that defeat Anthropic's Constitutional Classifiers — generalised techniques that work across many prompts, tested against a supplied set of harmful questions concerning CBRN/biological threat information. Narrow, context-specific exploits do not qualify.",
            "note": "Complete a Google Form application and create a HackerOne account first. If accepted you receive a HackerOne invitation and must create a Claude Console account using your @wearehackerone.com alias. An NDA is mandatory. Applications reviewed on a rolling basis."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "a6abadafd9",
        "research_order": 197,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-cert-cc-vince",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "US-based, globally used"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://kb.cert.org/vince/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "52ab77e46f66",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://kb.cert.org/vince/",
              "evidence_note": "Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://kb.cert.org/vince/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "2c30318eb773",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://kb.cert.org/vince/",
              "evidence_note": "Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses."
            }
          }
        ],
        "region": "Other",
        "public_input": "open",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-6f891efe-c4eb-45d1-84d5-1ab1abd3ffce",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "CERT/CC VINCE (Vulnerability Information and Coordination Environment)",
        "remit": "Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.",
        "reality_check": "The strongest escalation path when a vendor ignores you. CERT/CC's leverage is that it will publish on a clock whether or not the vendor cooperates, and vendors know it. Decades of track record in software; its applicability to AI model behaviour is new and being established via FLARE-AI.",
        "accepts": "Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.",
        "does_not_accept": "Pure content/quality complaints with no security dimension. Historically security-focused, though the FLARE-AI partnership extends it to AI flaws.",
        "how": "'Report a Vulnerability' form at kb.cert.org/vince/, or email cert@cert.org (phone +1 412-268-5800). FLARE-AI routes reports here as one of its named recipients.",
        "format": "Technical report: affected system and version, description, reproduction steps, impact, and any proof of concept.",
        "timing": "Rolling. CERT/CC operates a published coordinated disclosure policy with a default disclosure timeline (historically 45 days) after which it may publish regardless of vendor response.",
        "after": "CERT/CC validates, contacts affected vendors, coordinates a fix and a disclosure date, and may publish a Vulnerability Note in its public database.",
        "operator": "CERT Coordination Center, Software Engineering Institute, Carnegie Mellon University",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Vulnerability reports from anyone — you can report with or without a VINCE account. CERT/CC coordinates multi-vendor disclosure where a flaw affects several parties, which is precisely the case for transferable AI jailbreaks and shared model weaknesses.",
            "note": "'Report a Vulnerability' form at kb.cert.org/vince/, or email cert@cert.org (phone +1 412-268-5800). FLARE-AI routes reports here as one of its named recipients."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://kb.cert.org/vince/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "bf339e616a",
        "research_order": 194,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-flare-ai",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "Global"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://www.ai-reports.org/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "a293f5b03556",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.ai-reports.org/",
              "evidence_note": "A flaw, vulnerability or incident in any AI system. This is the first live implementation of the standardised AI flaw report concept — it covers model-behaviour flaws, biases and incidents, not only security bugs.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "systemic",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.ai-reports.org/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "9ab4234e6b05",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.ai-reports.org/",
              "evidence_note": "A flaw, vulnerability or incident in any AI system. This is the first live implementation of the standardised AI flaw report concept — it covers model-behaviour flaws, biases and incidents, not only security bugs."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "flaw",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-6c87afcb-d500-4569-bdb2-af11c971e222",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "FLARE-AI (Flaw Reporting for AI)",
        "remit": "A flaw, vulnerability or incident in any AI system. This is the first live implementation of the standardised AI flaw report concept — it covers model-behaviour flaws, biases and incidents, not only security bugs.",
        "reality_check": "This is the single most important new mechanism for an unaffiliated person with a model-behaviour finding, because it solves the routing problem: it converts an informal observation into a standard artefact and delivers it to named labs and a national coordination centre at once. Caveats: it launched only weeks before this research, is a research preview, and there is not yet public evidence of outcomes. Backed by CERT/CC's institutional credibility, which is the strongest signal available.",
        "accepts": "A flaw, vulnerability or incident in any AI system. This is the first live implementation of the standardised AI flaw report concept — it covers model-behaviour flaws, biases and incidents, not only security bugs.",
        "does_not_accept": "Not explicitly enumerated on the site; it is still labelled a research preview.",
        "how": "Guided web form at ai-reports.org ('Report Now'), takes roughly 10 minutes and generates a standardised, machine-readable flaw report. You then choose where to route it: the site lists Anthropic, Hugging Face, Cohere, the UK AI Safety/Security Institute, CERT/CC, ECDA and DAVID as recipients. You can also take the generated report and submit it yourself anywhere, or go direct to CERT/CC's VINCE.",
        "format": "Structured, machine-readable flaw report generated by the form — the standardised schema proposed in the 2025 third-party flaw disclosure work.",
        "timing": "Rolling. Went live 1 July 2026.",
        "after": "The report is transmitted to the recipient(s) you select. Coordination behaviour then depends on the recipient — CERT/CC applies its own coordinated disclosure process.",
        "operator": "Carnegie Mellon University Software Engineering Institute (SEI/CERT) with academic and industry partners; open source",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "A flaw, vulnerability or incident in any AI system. This is the first live implementation of the standardised AI flaw report concept — it covers model-behaviour flaws, biases and incidents, not only security bugs.",
            "note": "Guided web form at ai-reports.org ('Report Now'), takes roughly 10 minutes and generates a standardised, machine-readable flaw report. You then choose where to route it: the site lists Anthropic, Hugging Face, Cohere, the UK AI Safety/Security Institute, CERT/CC, ECDA and DAVID as recipients. You can also take the generated report and submit it yourself anywhere, or go direct to CERT/CC's VINCE."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.ai-reports.org/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "5c09004800",
        "research_order": 193,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-google-ai-vulnerability-reward-program",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "Global"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://www.theregister.com/2025/10/07/google_ai_bug_bounty/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "2c8ea189c669",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.theregister.com/2025/10/07/google_ai_bug_bounty/",
              "evidence_note": "Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.theregister.com/2025/10/07/google_ai_bug_bounty/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "563a53ffb8e5",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.theregister.com/2025/10/07/google_ai_bug_bounty/",
              "evidence_note": "Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-fee5115a-421e-403d-bbd8-9cfa5d0b896a",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Google AI Vulnerability Reward Program (AI VRP)",
        "remit": "Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.",
        "reality_check": "Effective and well-funded for security-shaped findings. The single most useful fact in this entry is the exclusion: it is the clearest public statement by a major lab that model-behaviour and alignment concerns are procedurally not vulnerabilities and will be rejected by a security intake. Route those to in-product reporting, FLARE-AI, AIID or a regulator instead.",
        "accepts": "Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.",
        "does_not_accept": "Explicitly out of scope: direct prompt injection, jailbreaks, and alignment issues. Google's stated position is that 'we don't believe a Vulnerability Reward Program is the right format for addressing content-related issues' — these must go to in-product reporting channels instead.",
        "how": "Submit via bughunters.google.com under the AI VRP rules. Content and alignment issues go through the thumbs-down / report flows inside Gemini, Search and Workspace.",
        "format": "Standard Google VRP report: product, reproduction steps, security impact mapped to one of the eight abuse categories.",
        "timing": "Rolling. Program launched October 2025.",
        "after": "Triage and reward: up to $20,000 base with up to $10,000 in quality multipliers (max ~$30,000). Flagship products (Search, Gemini, Workspace core) $20,000–$500; Standard (AI Studio, Jules, non-core Workspace) $15,000–$100; Other tier up to $10,000 or Google credit. Google paid ~$12M to 600+ researchers across its VRP in 2024.",
        "operator": "Google (Bug Hunters / VRP team)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Eight categories of AI security flaw: rogue actions (account/data modification via indirect prompt injection), sensitive data exfiltration, phishing enablement (persistent HTML injection), model theft (parameter exfiltration), cross-account context manipulation, access control bypass, unauthorised product usage, and cross-user denial of service.",
            "note": "Submit via bughunters.google.com under the AI VRP rules. Content and alignment issues go through the thumbs-down / report flows inside Gemini, Search and Workspace."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.theregister.com/2025/10/07/google_ai_bug_bounty/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "df521bb247",
        "research_order": 198,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-humane-intelligence-bias-bounty",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "Global — Zindi has users in 185+ countries"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://humane-intelligence.org/programs-services/bias-bounty/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "f55464b61aad",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://humane-intelligence.org/programs-services/bias-bounty/",
              "evidence_note": "Structured challenge entries that surface and measure biased or exclusionary outcomes in AI systems, and — unusually — that design technical mitigations, not just identify problems. Domains span generative AI, computer vision, environmental decision-making and digital accessibility.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://humane-intelligence.org/programs-services/bias-bounty/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "54e35741ccb0",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://humane-intelligence.org/programs-services/bias-bounty/",
              "evidence_note": "Structured challenge entries that surface and measure biased or exclusionary outcomes in AI systems, and — unusually — that design technical mitigations, not just identify problems. Domains span generative AI, computer vision, environmental decision-making and digital accessibility."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-f6ecab88-3ef2-49c9-bb84-13bc7b760a9b",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Humane Intelligence Bias Bounty",
        "remit": "Structured challenge entries that surface and measure biased or exclusionary outcomes in AI systems, and — unusually — that design technical mitigations, not just identify problems. Domains span generative AI, computer vision, environmental decision-making and digital accessibility.",
        "reality_check": "Real but narrow. Its value to an unaffiliated person is credentialing and access: it is a legitimate, low-barrier way to build a public track record in AI evaluation, and Humane Intelligence has run challenges with government and lab partners (including DEF CON-scale exercises). It will not help with a concern that does not match an open challenge.",
        "accepts": "Structured challenge entries that surface and measure biased or exclusionary outcomes in AI systems, and — unusually — that design technical mitigations, not just identify problems. Domains span generative AI, computer vision, environmental decision-making and digital accessibility.",
        "does_not_accept": "Unsolicited, out-of-challenge reports. This is a time-boxed competition format, not an always-open intake. If no challenge is running on your topic, there is nothing to submit to.",
        "how": "Register on Zindi and enter the live challenge. Prize tiers are structured for beginner, intermediate and advanced participants, which makes it one of the few routes deliberately open to non-experts. Partnership enquiries to info@humane-intelligence.org.",
        "format": "Whatever the specific challenge specifies — typically code, analysis and a written finding submitted to the Zindi platform.",
        "timing": "Windowed. The Bias Bounty Mapping Equity Challenge ran 28 August – 31 October 2026. Watch humane-intelligence.org for the next window.",
        "after": "Entries are judged; winners announced publicly; findings feed transparency reports (e.g. the 2024 Generative AI Red Teaming Challenge transparency report).",
        "operator": "Humane Intelligence (nonprofit, founded by Rumman Chowdhury), challenges hosted on Zindi",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Structured challenge entries that surface and measure biased or exclusionary outcomes in AI systems, and — unusually — that design technical mitigations, not just identify problems. Domains span generative AI, computer vision, environmental decision-making and digital accessibility.",
            "note": "Register on Zindi and enter the live challenge. Prize tiers are structured for beginner, intermediate and advanced participants, which makes it one of the few routes deliberately open to non-experts. Partnership enquiries to info@humane-intelligence.org."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://humane-intelligence.org/programs-services/bias-bounty/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "45ce09318c",
        "research_order": 201,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-mitre-atlas",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "Global"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "reporting",
            "value": "https://github.com/mitre-atlas/atlas-data",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ab0befdf8f12",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://github.com/mitre-atlas/atlas-data",
              "evidence_note": "Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "reporting"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://github.com/mitre-atlas/atlas-data",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "1f0c3c12b070",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://github.com/mitre-atlas/atlas-data",
              "evidence_note": "Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-51be3e26-f40b-412e-b481-eaebae6acee3",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "MITRE ATLAS (Adversarial Threat Landscape for AI Systems)",
        "remit": "Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set.",
        "reality_check": "Genuinely consequential within AI security — ATLAS IDs are used by vendors, red teams and compliance products. But the bar is a well-evidenced adversarial technique, and a GitHub PR against a MITRE schema is a high-skill submission. Wrong venue for most non-technical safety concerns.",
        "accepts": "Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set.",
        "does_not_accept": "Model-behaviour or societal-harm concerns with no adversary. ATLAS is a security threat knowledge base modelled on ATT&CK, not a harm registry. Also not a disclosure channel — it documents attacks after the fact.",
        "how": "Contributions flow through the public data repository github.com/mitre-atlas/atlas-data (CONTRIBUTING.md, pull requests against YAML technique and case study files) and via MITRE's ATLAS contact channels. The repo has active open issues and pull requests, so outside PRs are a live route.",
        "format": "Structured YAML records matching the ATLAS schema; case studies follow a fixed template (summary, incident details, procedure mapped to ATLAS technique IDs, references).",
        "timing": "Rolling; batched into periodic ATLAS releases.",
        "after": "MITRE curators review; accepted content appears in a versioned ATLAS release with attribution and is consumed by security tooling.",
        "operator": "MITRE, with the Center for Threat-Informed Defense (CTID) and industry partners",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Adversarial ML tactics, techniques and real-world case studies — i.e. attacks against AI systems. Contributions are curated into the ATLAS matrix and case study set.",
            "note": "Contributions flow through the public data repository github.com/mitre-atlas/atlas-data (CONTRIBUTING.md, pull requests against YAML technique and case study files) and via MITRE's ATLAS contact channels. The repo has active open issues and pull requests, so outside PRs are a live route."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://github.com/mitre-atlas/atlas-data",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "ee335f664e",
        "research_order": 192,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "global-signals-network-tech-accountability-project",
      "type": "reporting-channel",
      "geo": {
        "country": "global",
        "label": "International"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://thesignalsnetwork.org/tech-accountability-project/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ce46a0bc4d1d",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://thesignalsnetwork.org/tech-accountability-project/",
              "evidence_note": "Tech workers with public-interest concerns, including those considering going to media.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "insider",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://thesignalsnetwork.org/tech-accountability-project/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "6e6151e592cf",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://thesignalsnetwork.org/tech-accountability-project/",
              "evidence_note": "Tech workers with public-interest concerns, including those considering going to media."
            }
          }
        ],
        "region": "Global",
        "public_input": "open",
        "tags": [
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-21aa669b-e6c6-4def-ad9d-7a62229fd3dc",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "The Signals Network — Tech Accountability Project",
        "remit": "Tech workers with public-interest concerns, including those considering going to media.",
        "reality_check": "Distinctive for covering the non-legal costs of whistleblowing — housing, mental health, career — which are what actually break people, and which legal-only services do not touch. The media-coordination function makes it the right partner when the intended endpoint is publication rather than regulatory action. Funded by donations and grants; no fee stated.",
        "accepts": "Tech workers with public-interest concerns, including those considering going to media.",
        "does_not_accept": "Does not act as a regulator; works in coordination with other organisations rather than independently.",
        "how": "Secure contact at thesignalsnetwork.org/contact/. Support offered: legal counsel, psychological support, safe housing, press and career assistance, and connection to journalist networks for coordinated story development. Also publishes the Tech Worker Handbook as a self-serve resource.",
        "format": "Confidential intake.",
        "timing": "Rolling.",
        "after": "Wraparound support package; potential coordinated media investigation.",
        "operator": "The Signals Network (nonprofit); supported by Knight Foundation; partners with Amnesty International",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Tech workers with public-interest concerns, including those considering going to media.",
            "note": "Secure contact at thesignalsnetwork.org/contact/. Support offered: legal counsel, psychological support, safe housing, press and career assistance, and connection to journalist networks for coordinated story development. Also publishes the Tech Worker Handbook as a self-serve resource."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://thesignalsnetwork.org/tech-accountability-project/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "139c8809f4",
        "research_order": 222,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-california-attorney-general-consumer-complaint",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "sub": "ca",
        "label": "California (reaches most major AI developers, which are California-domiciled)"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "complaint",
            "value": "https://oag.ca.gov/contact/consumer-complaint-against-business-or-company",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "b0a6b91e3a1b",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://oag.ca.gov/contact/consumer-complaint-against-business-or-company",
              "evidence_note": "Complaints about businesses, including AI companies. The AG investigates where complaints suggest patterns of consumer harm or systematic violations of consumer protection law.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "harm",
                "complaint"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://oag.ca.gov/contact/consumer-complaint-against-business-or-company",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "9dae01766790",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://oag.ca.gov/contact/consumer-complaint-against-business-or-company",
              "evidence_note": "Complaints about businesses, including AI companies. The AG investigates where complaints suggest patterns of consumer harm or systematic violations of consumer protection law."
            }
          }
        ],
        "region": "Other",
        "public_input": "open",
        "tags": [
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-bd3d9262-df31-4f1d-9c11-f4f1790f635f",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "California Attorney General — consumer complaint",
        "remit": "Complaints about businesses, including AI companies. The AG investigates where complaints suggest patterns of consumer harm or systematic violations of consumer protection law.",
        "reality_check": "Worth more than its bureaucratic appearance because of jurisdiction: California's AG has direct reach over OpenAI, Anthropic, Google and Meta, and California has become the lead US AI regulator via SB 53. A well-documented complaint alleging a pattern lands in the office with both the authority and the demonstrated appetite to act. Still: no individual remedy, no guaranteed response.",
        "accepts": "Complaints about businesses, including AI companies. The AG investigates where complaints suggest patterns of consumer harm or systematic violations of consumer protection law.",
        "does_not_accept": "The form is explicit: 'The Attorney General cannot provide you with legal advice or represent you in personal legal actions' and 'cannot act as my personal lawyer.' It will not adjudicate your individual dispute.",
        "how": "Online web form at oag.ca.gov, or download, print and mail the form. Forms available in English, Spanish, Chinese and Vietnamese. Provide your contact details, the business's details, the product/service, transaction dates, names of representatives, your desired resolution, and evidence of prior contact attempts with the business.",
        "format": "Structured form; up to 5 supporting documents, max 50MB each, PDF/DOC.",
        "timing": "Rolling.",
        "after": "Review; possible investigation if a pattern emerges; possible referral to a more appropriate agency.",
        "operator": "California Department of Justice, Office of the Attorney General",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Complaints about businesses, including AI companies. The AG investigates where complaints suggest patterns of consumer harm or systematic violations of consumer protection law.",
            "note": "Online web form at oag.ca.gov, or download, print and mail the form. Forms available in English, Spanish, Chinese and Vietnamese. Provide your contact details, the business's details, the product/service, transaction dates, names of representatives, your desired resolution, and evidence of prior contact attempts with the business."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://oag.ca.gov/contact/consumer-complaint-against-business-or-company",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "a1b8c154bb",
        "research_order": 213,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-california-sb-53-whistleblower-protections-public",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "sub": "ca",
        "label": "California"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "9eb47a8e3d83",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/",
              "evidence_note": "Two distinct things. (1) Whistleblower protection: employees and contractors of frontier developers are protected against retaliation for reporting activity connected to catastrophic risks — defined around foreseeable risks of a frontier model causing death or serious injury to 50+ people, enabling weapons creation, engaging in criminal conduct without meaningful human intervention, or evading developer control. Employers must give notice of these rights and maintain anonymous internal reporting channels. (2) Developer reporting: frontier developers must report critical safety incidents to OES within 15 days of discovery, or 24 hours where there is imminent danger of death or serious injury.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "b7cbcee11267",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/",
              "evidence_note": "Two distinct things. (1) Whistleblower protection: employees and contractors of frontier developers are protected against retaliation for reporting activity connected to catastrophic risks — defined around foreseeable risks of a frontier model causing death or serious injury to 50+ people, enabling weapons creation, engaging in criminal conduct without meaningful human intervention, or evading developer control. Employers must give notice of these rights and maintain anonymous internal reporting channels. (2) Developer reporting: frontier developers must report critical safety incidents to OES within 15 days of discovery, or 24 hours where there is imminent danger of death or serious injury."
            }
          }
        ],
        "region": "Other",
        "public_input": "open",
        "tags": [
          "behaviour",
          "flaw",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-9cb0fb53-2c04-468a-aae2-e1b37f6126cd",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "California SB 53 (Transparency in Frontier Artificial Intelligence Act) — whistleblower protections and public incident reporting",
        "remit": "Two distinct things. (1) Whistleblower protection: employees and contractors of frontier developers are protected against retaliation for reporting activity connected to catastrophic risks — defined around foreseeable risks of a frontier model causing death or serious injury to 50+ people, enabling weapons creation, engaging in criminal conduct without meaningful human intervention, or evading developer control. Employers must give notice of these rights and maintain anonymous internal reporting channels. (2) Developer reporting: frontier developers must report critical safety incidents to OES within 15 days of discovery, or 24 hours where there is imminent danger of death or serious injury.",
        "reality_check": "The most concrete AI-specific whistleblower protection actually in force in the United States, and materially more than the federal position. Two honest caveats: the catastrophic-risk threshold is high and excludes most real concerns, and the public reporting mechanism's practical operation is unproven. It applies only to large frontier developers, though that captures most of the companies that matter.",
        "accepts": "Two distinct things. (1) Whistleblower protection: employees and contractors of frontier developers are protected against retaliation for reporting activity connected to catastrophic risks — defined around foreseeable risks of a frontier model causing death or serious injury to 50+ people, enabling weapons creation, engaging in criminal conduct without meaningful human intervention, or evading developer control. Employers must give notice of these rights and maintain anonymous internal reporting channels. (2) Developer reporting: frontier developers must report critical safety incidents to OES within 15 days of discovery, or 24 hours where there is imminent danger of death or serious injury.",
        "does_not_accept": "Concerns below the catastrophic-risk threshold are outside the protected category. Ordinary product-safety, bias or misuse concerns are not covered by the whistleblower provisions.",
        "how": "Employees: use the employer's mandated anonymous internal channel, and take legal advice before external disclosure. Critically for this playbook: SB 53 requires OES to establish a mechanism for the public to report critical safety incidents — meaning a member of the public, not just an insider, has a statutory route to a state emergency agency. Verify the current status and URL of that OES mechanism directly with OES before relying on it; implementation detail was not published in the sources reviewed.",
        "format": "Internal anonymous channel for employees; OES mechanism format not yet documented publicly.",
        "timing": "In force. Developer reporting deadlines are 15 days / 24 hours as above.",
        "after": "Incidents go to OES; whistleblower retaliation claims are pursued under the statute.",
        "operator": "State of California; critical safety incident reporting to the California Office of Emergency Services (OES)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Two distinct things. (1) Whistleblower protection: employees and contractors of frontier developers are protected against retaliation for reporting activity connected to catastrophic risks — defined around foreseeable risks of a frontier model causing death or serious injury to 50+ people, enabling weapons creation, engaging in criminal conduct without meaningful human intervention, or evading developer control. Employers must give notice of these rights and maintain anonymous internal reporting channels. (2) Developer reporting: frontier developers must report critical safety incidents to OES within 15 days of discovery, or 24 hours where there is imminent danger of death or serious injury.",
            "note": "Employees: use the employer's mandated anonymous internal channel, and take legal advice before external disclosure. Critically for this playbook: SB 53 requires OES to establish a mechanism for the public to report critical safety incidents — meaning a member of the public, not just an insider, has a statutory route to a state emergency agency. Verify the current status and URL of that OES mechanism directly with OES before relying on it; implementation detail was not published in the sources reviewed."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://fpf.org/blog/californias-sb-53-the-first-frontier-ai-law-explained/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "f60b58d068",
        "research_order": 219,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-allen-institute-ai",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "general-support-also-safety",
            "type": "email",
            "value": "support@allenai.org",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "c4054736ae6e",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://allenai.org/research-principles",
              "evidence_note": "The Responsible Use Guidelines name this single address twice: for questions about the guidelines and violation reports, and for 'reporting bugs, security concerns, and inappropriate/unsafe content generated by Ai2 Tools'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "email"
              ]
            }
          },
          {
            "id": "research-principles",
            "type": "program",
            "value": "https://allenai.org/research-principles",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "b0117e8c42ab",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://allenai.org/research-principles",
              "evidence_note": "Statement of principles, not a contact channel."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://allenai.org/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "abf4c543f6f6",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://allenai.org/",
              "evidence_note": "No public accounts found of people reporting model safety issues to Ai2. As a nonprofit research institute that publishes weights, training data and evaluations openly, most criticism and correction happens through papers, GitHub issues and Hugging Face rather than a disclosure channel — which is a genuinely different model of accountability, not an absence of one."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://allenai.org/responsible-use",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "e1ffd9b95afd",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://allenai.org/responsible-use",
              "evidence_note": "No public accounts found of people reporting model safety issues to Ai2. As a nonprofit research institute that publishes weights, training data and evaluations openly, most criticism and correction happens through papers, GitHub issues and Hugging Face rather than a disclosure channel — which is a genuinely different model of accountability, not an absence of one."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "behaviour",
          "flaw",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-d291288e-5f02-4f24-8c8c-5da99cceff79",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Allen Institute for AI (Ai2)",
        "remit": "No separately named safety or alignment function. Responsible Use Guidelines govern OLMo, Molmo, Tulu and Ai2 tools; the organisation argues openness is itself the safety mechanism.",
        "reality_check": "No public accounts found of people reporting model safety issues to Ai2. As a nonprofit research institute that publishes weights, training data and evaluations openly, most criticism and correction happens through papers, GitHub issues and Hugging Face rather than a disclosure channel — which is a genuinely different model of accountability, not an absence of one.",
        "notes": "support@allenai.org is the published route and it explicitly covers unsafe generated content, so use it and say so. The guidelines have not been updated since June 2024, which is old relative to the model releases they cover. No safe-harbour language and no whistleblower channel found.",
        "routes": {
          "general-support-also-safety": {
            "label": "General support — also the safety channel",
            "scope": "The Responsible Use Guidelines name this single address twice: for questions about the guidelines and violation reports, and for 'reporting bugs, security concerns, and inappropriate/unsafe content generated by Ai2 Tools'.",
            "note": "One address for everything. Low ceremony, but at least explicitly covers unsafe model output."
          },
          "research-principles": {
            "label": "Research principles",
            "scope": "Statement of principles, not a contact channel."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Responsible use guidelines (last updated June 2024)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://allenai.org/research-principles",
            "checked": null
          },
          {
            "url": "https://allenai.org/",
            "checked": null
          },
          {
            "url": "https://allenai.org/responsible-use",
            "checked": null
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "7bf0118d1f",
        "research_order": 10,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-anthropic",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "model-safety-issues-jailbreaks",
            "type": "email",
            "value": "usersafety@anthropic.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "9ad25716ccb0",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "evidence_note": "Safety issues, jailbreaks, harmful model behaviour. Named on both the Responsible Disclosure Policy and the Usage Policy.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "email"
              ]
            }
          },
          {
            "id": "questions-about-disclosure-policy",
            "type": "email",
            "value": "disclosure@anthropic.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "b7da28fe5932",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "evidence_note": "Questions about the Responsible Disclosure Policy itself, not for submitting reports.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "email"
              ]
            }
          },
          {
            "id": "responsible-disclosure-policy",
            "type": "disclosure",
            "value": "https://www.anthropic.com/responsible-disclosure-policy",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "f151f78297da",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "evidence_note": "Infrastructure vulnerabilities AND model safety. States: 'We welcome reports concerning safety issues, \"jailbreaks,\" and similar concerns so that we can enhance the safety and harmlessness of our models.'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "disclosure"
              ]
            }
          },
          {
            "id": "hackerone-submission-form",
            "type": "bounty",
            "value": "https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ccb8c901350b",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new",
              "evidence_note": "Vulnerability submissions under the Responsible Disclosure Policy.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "bounty"
              ]
            }
          },
          {
            "id": "model-safety-bug-bounty",
            "type": "bounty",
            "value": "https://docs.google.com/forms/d/e/1FAIpQLSf3IuyunFH1Rbz_9Bpt2kGBfwSW5QQ1TBkeAzNZrtCP-hRvNA/viewform",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "3beb7e70b622",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://docs.google.com/forms/d/e/1FAIpQLSf3IuyunFH1Rbz_9Bpt2kGBfwSW5QQ1TBkeAzNZrtCP-hRvNA/viewform",
              "evidence_note": "Universal jailbreaks that defeat Constitutional Classifiers, especially CBRN. Up to $35,000 per novel universal jailbreak.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "bounty"
              ]
            }
          },
          {
            "id": "usage-policy-trust-safety",
            "type": "form",
            "value": "https://support.claude.com/en/articles/8241253-trust-and-safety-warnings-and-appeals",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "b516e902b926",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://support.claude.com/en/articles/8241253-trust-and-safety-warnings-and-appeals",
              "evidence_note": "Appealing enforcement decisions against your own account."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.anthropic.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "1dafc6db1f84",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.anthropic.com/",
              "evidence_note": "Best-documented pathway of any lab. AI Frontiers' 2026 review of jailbreak disclosure found Anthropic runs two programs — a restricted NDA-bound CBRN bounty and an open cyber jailbreak program where 'anyone can submit without an NDA, findings may be publicly disclosed once timing is coordinated' — and named it as one of the few labs with a genuinely working route. Independent researchers pursuing cross-model universal jailbreaks in 2025-26 reported labs have 'very heterogeneous disclosure pathways (or none at all)' but that some, including Anthropic, remediated. No public evidence of usersafety@ being a black hole, but also little public evidence of reply rates."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://www.anthropic.com/rsp",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "7374b9e41624",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.anthropic.com/rsp",
              "evidence_note": "Best-documented pathway of any lab. AI Frontiers' 2026 review of jailbreak disclosure found Anthropic runs two programs — a restricted NDA-bound CBRN bounty and an open cyber jailbreak program where 'anyone can submit without an NDA, findings may be publicly disclosed once timing is coordinated' — and named it as one of the few labs with a genuinely working route. Independent researchers pursuing cross-model universal jailbreaks in 2025-26 reported labs have 'very heterogeneous disclosure pathways (or none at all)' but that some, including Anthropic, remediated. No public evidence of usersafety@ being a black hole, but also little public evidence of reply rates."
            }
          },
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://www.anthropic.com/responsible-disclosure-policy",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "dde7fdbf9d5e",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "evidence_note": "Two distinct lanes, and the distinction is the whole point. Security lane (via HackerOne): misconfigurations, CSRF, privilege escalation, SQL injection, XSS, directory traversal on internet-facing systems. Model-safety lane (via email): the policy states explicitly 'We welcome reports concerning safety issues, \"jailbreaks,\" and similar concerns so that we can enhance the safety and harmlessness of our models' — these go to usersafety@anthropic.com.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage-f2d0c046",
            "type": "homepage",
            "value": "https://www.anthropic.com/responsible-disclosure-policy",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "e2d7a5916452",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "evidence_note": "Two distinct lanes, and the distinction is the whole point. Security lane (via HackerOne): misconfigurations, CSRF, privilege escalation, SQL injection, XSS, directory traversal on internet-facing systems. Model-safety lane (via email): the policy states explicitly 'We welcome reports concerning safety issues, \"jailbreaks,\" and similar concerns so that we can enhance the safety and harmlessness of our models' — these go to usersafety@anthropic.com."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "behaviour",
          "flaw",
          "harm",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-141006f7-1ada-4183-9bbb-c4886fccb424",
        "roles": [
          "company",
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Anthropic",
        "remit": "Safeguards team enforces the Usage Policy and runs Constitutional Classifiers; Alignment Science and Frontier Red Team run capability/misalignment evaluations feeding the Responsible Scaling Policy, overseen by a Responsible Scaling Officer.",
        "reality_check": "Best-documented pathway of any lab. AI Frontiers' 2026 review of jailbreak disclosure found Anthropic runs two programs — a restricted NDA-bound CBRN bounty and an open cyber jailbreak program where 'anyone can submit without an NDA, findings may be publicly disclosed once timing is coordinated' — and named it as one of the few labs with a genuinely working route. Independent researchers pursuing cross-model universal jailbreaks in 2025-26 reported labs have 'very heterogeneous disclosure pathways (or none at all)' but that some, including Anthropic, remediated. No public evidence of usersafety@ being a black hole, but also little public evidence of reply rates.",
        "notes": "Write to usersafety@anthropic.com with a reproducible transcript. Safe harbour is real but conditional: 'If you, in our sole determination, make a good faith effort to research and disclose vulnerabilities in accordance with this Policy... we will not pursue any legal action because of your research or responsible disclosure' — note 'in our sole determination'. Whistleblowing is internal only: the RSP Noncompliance Reporting and Anti-Retaliation Policy routes through NAVEX to the Responsible Scaling Officer and is written for employees and Board members, with no public-facing channel.",
        "routes": {
          "model-safety-issues-jailbreaks": {
            "label": "Model safety issues and jailbreaks",
            "scope": "Safety issues, jailbreaks, harmful model behaviour. Named on both the Responsible Disclosure Policy and the Usage Policy.",
            "note": "The single most useful address for a member of the public with a model-behaviour concern. Anthropic asks for 'sufficient details for us to replicate the issue'."
          },
          "questions-about-disclosure-policy": {
            "label": "Questions about the disclosure policy",
            "scope": "Questions about the Responsible Disclosure Policy itself, not for submitting reports.",
            "note": "Policy questions only; actual reports go to HackerOne or usersafety@."
          },
          "responsible-disclosure-policy": {
            "label": "Responsible Disclosure Policy",
            "scope": "Infrastructure vulnerabilities AND model safety. States: 'We welcome reports concerning safety issues, \"jailbreaks,\" and similar concerns so that we can enhance the safety and harmlessness of our models.'",
            "note": "Unusual among labs in explicitly putting model safety inside the disclosure policy rather than excluding it."
          },
          "hackerone-submission-form": {
            "label": "HackerOne submission form",
            "scope": "Vulnerability submissions under the Responsible Disclosure Policy.",
            "note": "Embedded form, no HackerOne account gatekeeping described on the policy page."
          },
          "model-safety-bug-bounty": {
            "label": "Model Safety Bug Bounty Program (application)",
            "scope": "Universal jailbreaks that defeat Constitutional Classifiers, especially CBRN. Up to $35,000 per novel universal jailbreak.",
            "note": "Application-only and invite-based via HackerOne; participation requires an NDA. Program details: https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program"
          },
          "usage-policy-trust-safety": {
            "label": "Usage Policy / Trust & Safety appeals",
            "scope": "Appealing enforcement decisions against your own account.",
            "note": "Not a safety-reporting channel; for account holders only."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Anthropic's Responsible Scaling Policy, Version 3.4 (effective 8 July 2026)"
          },
          "submission-page": {
            "label": "Submission page",
            "scope": "Two distinct lanes, and the distinction is the whole point. Security lane (via HackerOne): misconfigurations, CSRF, privilege escalation, SQL injection, XSS, directory traversal on internet-facing systems. Model-safety lane (via email): the policy states explicitly 'We welcome reports concerning safety issues, \"jailbreaks,\" and similar concerns so that we can enhance the safety and harmlessness of our models' — these go to usersafety@anthropic.com.",
            "note": "Security bugs: submit through Anthropic's HackerOne program with vulnerability type, technical detail, reproduction steps, URLs, PoC and impact. Model behaviour and jailbreaks: email usersafety@anthropic.com. This is the cleanest published example of the procedural split — a model-behaviour finding sent to a security intake will be closed as out of scope, and a security bug emailed to a safety address loses bounty eligibility."
          },
          "homepage-f2d0c046": {
            "label": "Homepage"
          }
        },
        "accepts": "Two distinct lanes, and the distinction is the whole point. Security lane (via HackerOne): misconfigurations, CSRF, privilege escalation, SQL injection, XSS, directory traversal on internet-facing systems. Model-safety lane (via email): the policy states explicitly 'We welcome reports concerning safety issues, \"jailbreaks,\" and similar concerns so that we can enhance the safety and harmlessness of our models' — these go to usersafety@anthropic.com.",
        "does_not_accept": "SSL/TLS issues without a proof of concept, physical intrusion, rate limiting on unauthenticated endpoints, social engineering, phishing, DoS, and widely publicised zero-days with no patch or a patch under 30 days old.",
        "how": "Security bugs: submit through Anthropic's HackerOne program with vulnerability type, technical detail, reproduction steps, URLs, PoC and impact. Model behaviour and jailbreaks: email usersafety@anthropic.com. This is the cleanest published example of the procedural split — a model-behaviour finding sent to a security intake will be closed as out of scope, and a security bug emailed to a safety address loses bounty eligibility.",
        "format": "Security: standard vulnerability report. Model safety: prose email with exact prompts, transcripts, model version, date and reproducibility notes.",
        "timing": "Rolling. Anthropic commits to acknowledge HackerOne submissions within three business days.",
        "after": "Security reports are triaged on HackerOne with possible bounty. Model-safety emails have no published SLA, triage process or feedback loop.",
        "operator": "Anthropic"
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.anthropic.com/responsible-disclosure-policy",
            "checked": "2026-09-22"
          },
          {
            "url": "https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new",
            "checked": "2026-09-22"
          },
          {
            "url": "https://docs.google.com/forms/d/e/1FAIpQLSf3IuyunFH1Rbz_9Bpt2kGBfwSW5QQ1TBkeAzNZrtCP-hRvNA/viewform",
            "checked": "2026-09-22"
          },
          {
            "url": "https://www.anthropic.com/responsible-disclosure-policy",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "9ca2360419",
        "research_order": 0,
        "migrated_from": "input/data/institutions.json",
        "legacy_ids": [
          "9ca2360419",
          "6b6853ba78"
        ],
        "aliases": [
          "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
          "Anthropic Responsible Disclosure Policy / usersafety@anthropic.com"
        ],
        "redirect_from": [
          {
            "section": "channels",
            "id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic"
          }
        ],
        "identity_review": {
          "evidence_urls": [
            "https://www.anthropic.com/responsible-disclosure-policy",
            "https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new"
          ],
          "reviewed_by": "codex:source-review-2026-09-24",
          "approved_by": "owner:autonomous-implementation-request-2026-09-24",
          "reviewed_on": "2026-09-24",
          "review_by": "2027-03-23",
          "note": "The records describe one real-world entity; preserve complementary facts and retire the non-canonical public id."
        },
        "merge_provenance": {
          "geo.country": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "geo.label": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.routes": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.region": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.public_input": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.tags": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_disposition": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_by": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_on": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.name": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.remit": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.reality_check": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.notes": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.routes": [
            {
              "record_id": "us-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.accepts": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.does_not_accept": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.how": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.format": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.timing": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.after": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.operator": [
            {
              "record_id": "global-anthropic-responsible-disclosure-policy-usersafety-anthropic",
              "source_url": "https://www.anthropic.com/responsible-disclosure-policy",
              "checked_on": "2026-09-22"
            }
          ]
        }
      }
    },
    {
      "id": "us-apple",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "apple-security-bounty",
            "type": "bounty",
            "value": "https://security.apple.com/submit/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "8f423382b21e",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://security.apple.com/submit/",
              "evidence_note": "'If you've discovered a security or privacy vulnerability that affects Apple devices, software, or services, please report it directly to us.' Covers Apple products and public-facing services; rewards up to $2M for exploit chains, over $5M with bonuses. AI/Apple Intelligence is not named in the terms.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "bounty"
              ],
              "restrictions": "'If you've discovered a security or privacy vulnerability that affects Apple devices, software, or services, please report it directly to us.' Covers Apple products and public-facing services; rewards up to $2M for exploit chains, over $5M with bonuses. AI/Apple Intelligence is not named in the terms."
            }
          },
          {
            "id": "bounty-terms-conditions",
            "type": "disclosure",
            "value": "https://security.apple.com/terms-and-conditions/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "b76f9bc7b1a2",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://security.apple.com/terms-and-conditions/",
              "evidence_note": "Section 8 provides a limited exemption from reverse-engineering restrictions where 'The actions were performed during good-faith security research, which was — or was intended to be — responsibly reported to Apple'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "disclosure"
              ],
              "restrictions": "Section 8 provides a limited exemption from reverse-engineering restrictions where 'The actions were performed during good-faith security research, which was — or was intended to be — responsibly reported to Apple'."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://security.apple.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "6cdbf149996e",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://security.apple.com/",
              "evidence_note": "Apple's bounty is well-funded and known to pay, but it is a security program. Apple has historically been criticised by researchers for slow triage and for disputes over credit and payout, though the 2025-26 program restructure raised maximums substantially. There is no published channel of any kind for Apple Intelligence model behaviour — no safety@, no model feedback form, no responsible AI contact."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://security.apple.com/bounty/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "f12627e11fcf",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://security.apple.com/bounty/",
              "evidence_note": "Apple's bounty is well-funded and known to pay, but it is a security program. Apple has historically been criticised by researchers for slow triage and for disputes over credit and payout, though the 2025-26 program restructure raised maximums substantially. There is no published channel of any kind for Apple Intelligence model behaviour — no safety@, no model feedback form, no responsible AI contact."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-f5dfec21-7927-4bca-b8ef-ce0c0e1c70a4",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Apple",
        "remit": "No publicly named AI safety or alignment function. Apple Security Engineering and Architecture runs the bounty; Private Cloud Compute is the published mechanism for AI privacy guarantees.",
        "reality_check": "Apple's bounty is well-funded and known to pay, but it is a security program. Apple has historically been criticised by researchers for slow triage and for disputes over credit and payout, though the 2025-26 program restructure raised maximums substantially. There is no published channel of any kind for Apple Intelligence model behaviour — no safety@, no model feedback form, no responsible AI contact.",
        "notes": "If your concern is that Apple Intelligence produced something harmful, there is no published route: not found — general contact only, via https://www.apple.com/contact/. The bounty is for security and privacy vulnerabilities only. Apple publishes no frontier safety framework.",
        "routes": {
          "apple-security-bounty": {
            "label": "Apple Security Bounty",
            "scope": "'If you've discovered a security or privacy vulnerability that affects Apple devices, software, or services, please report it directly to us.' Covers Apple products and public-facing services; rewards up to $2M for exploit chains, over $5M with bonuses. AI/Apple Intelligence is not named in the terms.",
            "note": "Security and privacy only. Nothing about model behaviour."
          },
          "bounty-terms-conditions": {
            "label": "Bounty terms and conditions",
            "scope": "Section 8 provides a limited exemption from reverse-engineering restrictions where 'The actions were performed during good-faith security research, which was — or was intended to be — responsibly reported to Apple'.",
            "note": "This is the safe-harbour language, and it is narrow: it covers reverse engineering, not a general no-legal-action promise, and applies only within the program terms."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No frontier safety framework or model spec published"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://security.apple.com/submit/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://security.apple.com/terms-and-conditions/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "b4bcb8772b",
        "research_order": 12,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-government-accountability-project",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "label": "United States (some international work)"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://whistleblower.org/how-to-request-assistance/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "fc0a83f71728",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://whistleblower.org/how-to-request-assistance/",
              "evidence_note": "People who have discovered illegality, gross mismanagement or waste of funds, or threats to health and safety in their employment. Focus is on widespread, systemic issues affecting the public interest.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "insider",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://whistleblower.org/how-to-request-assistance/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "01cd07864a81",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://whistleblower.org/how-to-request-assistance/",
              "evidence_note": "People who have discovered illegality, gross mismanagement or waste of funds, or threats to health and safety in their employment. Focus is on widespread, systemic issues affecting the public interest."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-d9fd5dae-b98e-4e1d-81c7-d6bd54a0dfba",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Government Accountability Project",
        "remit": "People who have discovered illegality, gross mismanagement or waste of funds, or threats to health and safety in their employment. Focus is on widespread, systemic issues affecting the public interest.",
        "reality_check": "The most established US whistleblower legal organisation, with decades of litigation record and demonstrated willingness to fight identity subpoenas. The deadline warning is the single most important operational fact for anyone in this position: waiting for GAP's one-month review can itself blow a 30-day filing window. Take that as an instruction to identify your deadlines independently and immediately.",
        "accepts": "People who have discovered illegality, gross mismanagement or waste of funds, or threats to health and safety in their employment. Focus is on widespread, systemic issues affecting the public interest.",
        "does_not_accept": "Explicitly: small-scale issues lacking broad public concern; Section 8 housing fraud; EEOC employment discrimination claims; benefit denial cases unless whistleblower-related; scam victim cases.",
        "how": "Complete the intake form at intake.whistleblower.org. Reviewed by staff, with a response typically within about a month. Important: contacting them does not create legal representation and does not toll any statute of limitations — you bear responsibility for your own filing deadlines, which range from 30 days to three years depending on claim type, and GAP will not alert you to them during the application process.",
        "format": "Online intake application.",
        "timing": "Rolling; roughly one month to a response. Your legal deadlines run regardless.",
        "after": "Possible representation. Services at a 'greatly reduced public interest rate'; pro bono for those unemployed and without resources until reemployment; litigation costs assessed on financial capacity and typically recoverable on a win or settlement. Communications are attorney-client privileged, and GAP has successfully resisted subpoenas seeking whistleblower identities in federal court.",
        "operator": "Government Accountability Project (US nonprofit legal organisation)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "People who have discovered illegality, gross mismanagement or waste of funds, or threats to health and safety in their employment. Focus is on widespread, systemic issues affecting the public interest.",
            "note": "Complete the intake form at intake.whistleblower.org. Reviewed by staff, with a response typically within about a month. Important: contacting them does not create legal representation and does not toll any statute of limitations — you bear responsibility for your own filing deadlines, which range from 30 days to three years depending on claim type, and GAP will not alert you to them during the application process."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://whistleblower.org/how-to-request-assistance/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "ed9d0bc1cf",
        "research_order": 223,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-ibm",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "ibm-psirt",
            "type": "email",
            "value": "psirt@us.ibm.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ca735c19cc59",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://hackerone.com/ibm?type=team",
              "evidence_note": "'Potential security and AI vulnerabilities in IBM products and websites.' AI vulnerabilities explicitly in scope. PGP available.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "'Potential security and AI vulnerabilities in IBM products and websites.' AI vulnerabilities explicitly in scope. PGP available."
            }
          },
          {
            "id": "ibm-hackerone",
            "type": "disclosure",
            "value": "https://hackerone.com/ibm?type=team",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "2f3ea5273b93",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://hackerone.com/ibm?type=team",
              "evidence_note": "Third-party researcher submissions.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "disclosure"
              ],
              "restrictions": "Third-party researcher submissions."
            }
          },
          {
            "id": "ibm-safe-harbor-policy",
            "type": "disclosure",
            "value": "https://www.ibm.com/trust/security-psirt",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "02ede153665e",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.ibm.com/trust/security-psirt",
              "evidence_note": "The PSIRT page states vulnerability reporting is 'protected by IBM Safe Harbor Policy', available as a downloadable document.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "disclosure"
              ],
              "restrictions": "The PSIRT page states vulnerability reporting is 'protected by IBM Safe Harbor Policy', available as a downloadable document."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.ibm.com/trust",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "36c8c88be9d2",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.ibm.com/trust",
              "evidence_note": "No public accounts found of AI-specific reports to IBM PSIRT. IBM's AI Ethics Board is well-documented in its governance publications but is an internal review body with no published external intake. The PSIRT route is professional and long-established; whether a pure model-behaviour finding survives triage there is untested in public."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://www.ibm.com/impact/ai-ethics",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "26156bc25339",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.ibm.com/impact/ai-ethics",
              "evidence_note": "No public accounts found of AI-specific reports to IBM PSIRT. IBM's AI Ethics Board is well-documented in its governance publications but is an internal review body with no published external intake. The PSIRT route is professional and long-established; whether a pure model-behaviour finding survives triage there is untested in public."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-310e1bea-2ec1-4ca1-8cfa-71af6eedb5e6",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "IBM",
        "remit": "AI Ethics Board plus a Responsible Technology function governing watsonx and Granite models; PSIRT handles security and, unusually, explicitly names AI vulnerabilities in scope.",
        "reality_check": "No public accounts found of AI-specific reports to IBM PSIRT. IBM's AI Ethics Board is well-documented in its governance publications but is an internal review body with no published external intake. The PSIRT route is professional and long-established; whether a pure model-behaviour finding survives triage there is untested in public.",
        "notes": "psirt@us.ibm.com is the route, and you can cite that AI vulnerabilities are in its published scope. There is no channel to the AI Ethics Board. IBM is one of the few here offering both anonymous submission and a written safe harbour policy.",
        "routes": {
          "ibm-psirt": {
            "label": "IBM PSIRT",
            "scope": "'Potential security and AI vulnerabilities in IBM products and websites.' AI vulnerabilities explicitly in scope. PGP available.",
            "note": "One of only a handful of PSIRTs to name AI vulnerabilities in its remit."
          },
          "ibm-hackerone": {
            "label": "IBM on HackerOne",
            "scope": "Third-party researcher submissions."
          },
          "ibm-safe-harbor-policy": {
            "label": "IBM Safe Harbor Policy",
            "scope": "The PSIRT page states vulnerability reporting is 'protected by IBM Safe Harbor Policy', available as a downloadable document.",
            "note": "The full text is in a linked PDF rather than inline; read it before testing. Anonymous form submission is also offered."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Responsible Technology / AI ethics principles (no frontier safety framework published)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://hackerone.com/ibm?type=team",
            "checked": "2026-09-22"
          },
          {
            "url": "https://www.ibm.com/trust/security-psirt",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "63dd881c22",
        "research_order": 13,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-meta",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "llama-policy-violation-reports",
            "type": "email",
            "value": "LlamaUseReport@meta.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "54440a4633b8",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://developers.facebook.com/llama_output_feedback/",
              "evidence_note": "Reporting violations of the Llama Acceptable Use Policy (i.e. someone else misusing the model).",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "email"
              ],
              "restrictions": "Reporting violations of the Llama Acceptable Use Policy (i.e. someone else misusing the model)."
            }
          },
          {
            "id": "risky-content-model-output",
            "type": "feedback",
            "value": "https://developers.facebook.com/llama_output_feedback/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ad35847b0746",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://developers.facebook.com/llama_output_feedback/",
              "evidence_note": "Reporting risky or harmful content produced by Llama models.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "feedback"
              ],
              "restrictions": "Reporting risky or harmful content produced by Llama models."
            }
          },
          {
            "id": "meta-security-whitehat",
            "type": "disclosure",
            "value": "https://facebook.com/whitehat/info/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "c841b044803b",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://facebook.com/whitehat/info/",
              "evidence_note": "Security bugs and vulnerabilities.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "disclosure"
              ],
              "restrictions": "Security bugs and vulnerabilities."
            }
          },
          {
            "id": "meta-bug-bounty-genai",
            "type": "bounty",
            "value": "https://bugbounty.meta.com/payout-guidelines/meta-genai/",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "693c502b4de5",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://bugbounty.meta.com/payout-guidelines/meta-genai/",
              "evidence_note": "GenAI reports assessed by security impact; the page states it illustrates 'how we assess the security impact' of reports."
            }
          },
          {
            "id": "model-issues-via-github",
            "type": "disclosure",
            "value": "https://github.com/facebookresearch/llama",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "d6b32d4258b5",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://github.com/facebookresearch/llama",
              "evidence_note": "Technical model issues.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "disclosure"
              ],
              "restrictions": "Technical model issues."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://ai.meta.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "8312da5dd667",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://ai.meta.com/",
              "evidence_note": "Meta publishes more named routes than most, but responsiveness is the documented problem. Cybernews reported researchers complaining on Reddit that 'Meta wasn't even reacting to their reports about allegedly critical bugs', with some 'still waiting for a response months after submitting the report'; Meta received nearly 10,000 reports in 2024 and deemed only around 600 valid. The article notes one researcher who published a 'horrible experience' publicly got a reply within 10 hours and a generous bounty — i.e. public pressure works where the queue does not. AI Frontiers groups Meta with Google and xAI as excluding jailbreaks from vulnerability programs."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "5f4dabef0c24",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://ai.meta.com/static-resource/Meta_Advanced-AI-Scaling-Framework-v2",
              "evidence_note": "Meta publishes more named routes than most, but responsiveness is the documented problem. Cybernews reported researchers complaining on Reddit that 'Meta wasn't even reacting to their reports about allegedly critical bugs', with some 'still waiting for a response months after submitting the report'; Meta received nearly 10,000 reports in 2024 and deemed only around 600 valid. The article notes one researcher who published a 'horrible experience' publicly got a reply within 10 hours and a generous bounty — i.e. public pressure works where the queue does not. AI Frontiers groups Meta with Google and xAI as excluding jailbreaks from vulnerability programs."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-0dd508bd-ba48-49f8-bae5-62317b26af69",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Meta",
        "remit": "Internal governance function plus a Chief AI Officer and a Director of Alignment and Risk who receive non-compliance reports under the Advanced AI Scaling Framework; preparedness reports are published at model release.",
        "reality_check": "Meta publishes more named routes than most, but responsiveness is the documented problem. Cybernews reported researchers complaining on Reddit that 'Meta wasn't even reacting to their reports about allegedly critical bugs', with some 'still waiting for a response months after submitting the report'; Meta received nearly 10,000 reports in 2024 and deemed only around 600 valid. The article notes one researcher who published a 'horrible experience' publicly got a reply within 10 hours and a generous bounty — i.e. public pressure works where the queue does not. AI Frontiers groups Meta with Google and xAI as excluding jailbreaks from vulnerability programs.",
        "notes": "The llama_output_feedback form is the right door for a harmful-output finding; expect no acknowledgement. The Advanced AI Scaling Framework's whistleblower protocol is employees-only — reports route to 'the internal governance function, the Chief AI Officer, and the Director of Alignment and Risk' — with no external equivalent. No public safe-harbour language for AI safety research was found.",
        "routes": {
          "llama-policy-violation-reports": {
            "label": "Llama policy violation reports",
            "scope": "Reporting violations of the Llama Acceptable Use Policy (i.e. someone else misusing the model).",
            "note": "Published verbatim in the Llama use policy. Aimed at misuse by third parties, not at model flaws."
          },
          "risky-content-model-output": {
            "label": "Risky content / model output feedback",
            "scope": "Reporting risky or harmful content produced by Llama models.",
            "note": "The closest thing Meta has to a model-behaviour channel. Published in the Llama AUP."
          },
          "meta-security-whitehat": {
            "label": "Meta security / Whitehat",
            "scope": "Security bugs and vulnerabilities.",
            "note": "Published in the Llama AUP as the route for 'security concerns'."
          },
          "meta-bug-bounty-genai": {
            "label": "Meta Bug Bounty — GenAI payout guidelines",
            "scope": "GenAI reports assessed by security impact; the page states it illustrates 'how we assess the security impact' of reports.",
            "note": "Page is JS-rendered; could not read scope text directly. Security-impact framing implies pure model-safety/jailbreak reports do not qualify."
          },
          "model-issues-via-github": {
            "label": "Model issues via GitHub",
            "scope": "Technical model issues.",
            "note": "Listed in the Llama AUP as the route for 'model issues'."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Advanced AI Scaling Framework, Version 2 (7 April 2026)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://developers.facebook.com/llama_output_feedback/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://facebook.com/whitehat/info/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://github.com/facebookresearch/llama",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "ae683d0b00",
        "research_order": 3,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-microsoft",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "msrc-researcher-portal",
            "type": "disclosure",
            "value": "https://msrc.microsoft.com/report/",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "00c15175379f",
            "contact": {
              "status": "unknown",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://msrc.microsoft.com/report/",
              "evidence_note": "Security vulnerability submissions including AI systems, graded against the AI bug bar."
            }
          },
          {
            "id": "microsoft-copilot-ai-bounty",
            "type": "bounty",
            "value": "https://www.microsoft.com/en-us/msrc/bounty-ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "f13a69b17948",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.microsoft.com/en-us/msrc/bounty-ai",
              "evidence_note": "$250-$30,000. Security vulnerabilities in Copilot surfaces. Explicitly EXCLUDES 'AI prompt injection attacks that do not have a security impact on users other than the attacker', 'model hallucination where the model pretends to run arbitrary code', and 'attacks that aim to leak (part of) the system/meta prompt'. Content issues must be reported separately as 'AI derived harm'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "systemic",
                "bounty"
              ],
              "restrictions": "$250-$30,000. Security vulnerabilities in Copilot surfaces. Explicitly EXCLUDES 'AI prompt injection attacks that do not have a security impact on users other than the attacker', 'model hallucination where the model pretends to run arbitrary code', and 'attacks that aim to leak (part of) the system/meta prompt'. Content issues must be reported separately as 'AI derived harm'."
            }
          },
          {
            "id": "ai-ml-vulnerability-severity",
            "type": "disclosure",
            "value": "https://www.microsoft.com/en-us/msrc/aibugbar",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "09315f610f5a",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.microsoft.com/en-us/msrc/aibugbar",
              "evidence_note": "Splits AI issues into security vulnerabilities (CVSS-rated: inference manipulation, membership inference, model theft) and Responsible AI issues (hate speech, misinformation, sexual content, self-harm) classified only 'In Scope' or 'Out of Scope for investigation, without severity ratings'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "systemic",
                "disclosure"
              ],
              "restrictions": "Splits AI issues into security vulnerabilities (CVSS-rated: inference manipulation, membership inference, model theft) and Responsible AI issues (hate speech, misinformation, sexual content, self-harm) classified only 'In Scope' or 'Out of Scope for investigation, without severity ratings'."
            }
          },
          {
            "id": "report-concern",
            "type": "form",
            "value": "https://www.microsoft.com/digitalsafety/report-a-concern",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "3daf378c646d",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://www.microsoft.com/digitalsafety/report-a-concern",
              "evidence_note": "Harmful content across Microsoft services, including AI-generated."
            }
          },
          {
            "id": "enterprise-ai-services-abuse",
            "type": "form",
            "value": "https://go.microsoft.com/fwlink/?linkid=2299798",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "71145e9c411d",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://go.microsoft.com/fwlink/?linkid=2299798",
              "evidence_note": "Reporting abusive, illegal or infringing use of a Microsoft AI Service.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "insider",
                "systemic",
                "form"
              ],
              "restrictions": "Reporting abusive, illegal or infringing use of a Microsoft AI Service."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.microsoft.com/ai/responsible-ai",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "dcdc307198ed",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.microsoft.com/ai/responsible-ai",
              "evidence_note": "No large body of public complaints specific to Microsoft's AI safety intake, and the AI bug bar is unusually candid about what it will and will not investigate. The honest read: security-impacting AI bugs get a real, paid, well-run process through MSRC; pure model-behaviour findings get a 'Responsible AI' classification with no severity and no stated timeline, which is closer to a content-moderation queue than a safety review. Microsoft has publicly said it will pay out for high-impact bugs even outside formal bounty scope (The Register, Dec 2025)."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Frontier-Governance-Framework-Feb-2026.pdf",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "d739c285acca",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Frontier-Governance-Framework-Feb-2026.pdf",
              "evidence_note": "No large body of public complaints specific to Microsoft's AI safety intake, and the AI bug bar is unusually candid about what it will and will not investigate. The honest read: security-impacting AI bugs get a real, paid, well-run process through MSRC; pure model-behaviour findings get a 'Responsible AI' classification with no severity and no stated timeline, which is closer to a content-moderation queue than a safety review. Microsoft has publicly said it will pay out for high-impact bugs even outside formal bounty scope (The Register, Dec 2025)."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "harm",
          "insider",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-9c5f2c38-4796-437a-a0bb-f5f1457a4c3e",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Microsoft",
        "remit": "Office of Responsible AI and a Chief Responsible AI Officer maintain the Responsible AI Standard and review revisions to the Frontier Governance Framework; MSRC handles security and an AI-specific severity bug bar.",
        "reality_check": "No large body of public complaints specific to Microsoft's AI safety intake, and the AI bug bar is unusually candid about what it will and will not investigate. The honest read: security-impacting AI bugs get a real, paid, well-run process through MSRC; pure model-behaviour findings get a 'Responsible AI' classification with no severity and no stated timeline, which is closer to a content-moderation queue than a safety review. Microsoft has publicly said it will pay out for high-impact bugs even outside formal bounty scope (The Register, Dec 2025).",
        "notes": "Use the AI bug bar page first to decide which door you are at — it is the single most useful triage document published by any company here. Safe harbour exists as 'Legal Safe Harbor' in the bounty terms at https://www.microsoft.com/en-us/msrc/bounty-guidelines#safeharbor. The Frontier Governance Framework's whistleblower route is internal only, with anonymous reporting and anti-retaliation for employees; there is no external equivalent.",
        "routes": {
          "msrc-researcher-portal": {
            "label": "MSRC Researcher Portal",
            "scope": "Security vulnerability submissions including AI systems, graded against the AI bug bar.",
            "note": "Also reachable as aka.ms/secure-at per the Copilot bounty page."
          },
          "microsoft-copilot-ai-bounty": {
            "label": "Microsoft Copilot AI Bounty",
            "scope": "$250-$30,000. Security vulnerabilities in Copilot surfaces. Explicitly EXCLUDES 'AI prompt injection attacks that do not have a security impact on users other than the attacker', 'model hallucination where the model pretends to run arbitrary code', and 'attacks that aim to leak (part of) the system/meta prompt'. Content issues must be reported separately as 'AI derived harm'.",
            "note": "One of the clearest published statements anywhere that jailbreak-style findings are not a bounty item."
          },
          "ai-ml-vulnerability-severity": {
            "label": "AI/ML Vulnerability Severity Classification (AI bug bar)",
            "scope": "Splits AI issues into security vulnerabilities (CVSS-rated: inference manipulation, membership inference, model theft) and Responsible AI issues (hate speech, misinformation, sexual content, self-harm) classified only 'In Scope' or 'Out of Scope for investigation, without severity ratings'.",
            "note": "Notably says Microsoft 'actively welcome[s] submissions related to safety and societal harm' — a rare explicit invitation. CSEAM must go to Report a Concern instead."
          },
          "report-concern": {
            "label": "Report a Concern (Digital Safety)",
            "scope": "Harmful content across Microsoft services, including AI-generated.",
            "note": "The consumer-facing route MSRC redirects content reports to."
          },
          "enterprise-ai-services-abuse": {
            "label": "Enterprise AI Services abuse report",
            "scope": "Reporting abusive, illegal or infringing use of a Microsoft AI Service.",
            "note": "Published in the Code of Conduct for Microsoft AI Services."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Frontier Governance Framework (February 2026; first version February 2025)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.microsoft.com/en-us/msrc/bounty-ai",
            "checked": "2026-09-22"
          },
          {
            "url": "https://www.microsoft.com/en-us/msrc/aibugbar",
            "checked": "2026-09-22"
          },
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=2299798",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "156d5f5b4d",
        "research_order": 4,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-midas-project",
      "type": "watchdog",
      "geo": {
        "country": "us",
        "label": "United States (EIN 99-2326977)"
      },
      "facts": {
        "routes": [
          {
            "id": "submit-tip-best-designed",
            "type": "submission",
            "value": "https://www.themidasproject.com/tips",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "e3f2dfa88b63",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.themidasproject.com/tips",
              "evidence_note": "Anyone with specific, non-public, evidence-backed information; they particularly want evidence of gaps between public statements and internal practice",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "insider",
                "research",
                "submission"
              ]
            }
          },
          {
            "id": "signal-username",
            "type": "submission",
            "value": "midasproject.10",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "195d4ecdb8b6",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://www.themidasproject.com/tips",
              "evidence_note": "Sensitive tips; no name required",
              "checked_on": "2026-09-22"
            }
          },
          {
            "id": "general-enquiries",
            "type": "email",
            "value": "info@themidasproject.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ffa4ce394921",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.themidasproject.com/tips",
              "evidence_note": "Non-sensitive",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "insider",
                "research",
                "email"
              ]
            }
          },
          {
            "id": "contact-form",
            "type": "form",
            "value": "https://www.themidasproject.com/contact",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "008b9e565e56",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.themidasproject.com/contact",
              "evidence_note": "General",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "insider",
                "research",
                "form"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.themidasproject.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "1d333ea7ebb6",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.themidasproject.com/",
              "evidence_note": "Tiny, and it absolutely reads its inbox — the single best target in this list for someone with concrete non-public evidence about an AI company's conduct. Note their own advice: if you are an employee considering disclosure, contact the AI Whistleblower Initiative first for independent legal guidance before approaching any journalist or watchdog."
            }
          },
          {
            "id": "action",
            "type": "action",
            "value": "https://www.themidasproject.com/volunteer",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "1a6654013285",
            "contact": {
              "status": "unknown",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:source-review-2026-09-24",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only"
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "flaw",
          "insider",
          "research",
          "join",
          "law",
          "tip"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "perspective": "safety-advocacy",
        "volunteers": "yes",
        "entity_key": "entity-57d8acbe-92ed-496b-95ef-96f40f34ae73",
        "roles": [
          "watchdog",
          "organisation"
        ]
      },
      "strings": {
        "name": "The Midas Project",
        "remit": "Watchdog non-profit holding AI companies to their own stated commitments. Projects: Watchtower (tracks changes to and violations of corporate AI safety policies), the Seoul Tracker (whether 16 organisations met the Seoul frontier-safety commitments), The OpenAI Files (documented governance, leadership and culture concerns at OpenAI), and Model Republic (industry influence on policymakers).",
        "threat_model": "Corporate accountability and commitment-drift — the concern that voluntary safety commitments quietly erode. Agnostic between threat models; it tracks whatever companies promised, which spans misuse, catastrophic risk and governance.",
        "reality_check": "Tiny, and it absolutely reads its inbox — the single best target in this list for someone with concrete non-public evidence about an AI company's conduct. Note their own advice: if you are an employee considering disclosure, contact the AI Whistleblower Initiative first for independent legal guidance before approaching any journalist or watchdog.",
        "gov_channel": "Indirect but potent — its findings get picked up by press and cited in policy debate; The OpenAI Files fed directly into scrutiny of OpenAI's restructuring.",
        "routes": {
          "submit-tip-best-designed": {
            "label": "Submit a tip — the best-designed whistleblower-adjacent intake in this list",
            "scope": "Anyone with specific, non-public, evidence-backed information; they particularly want evidence of gaps between public statements and internal practice",
            "note": "Accepts texts, emails, documents, photos, reports. Signal preferred for sensitive material."
          },
          "signal-username": {
            "label": "Signal (encrypted) — username",
            "scope": "Sensitive tips; no name required",
            "note": "Verified on the tips page. They warn no app protects a compromised device."
          },
          "general-enquiries": {
            "label": "General enquiries (explicitly NOT recommended for confidential material)",
            "scope": "Non-sensitive"
          },
          "contact-form": {
            "label": "Contact form",
            "scope": "General"
          },
          "homepage": {
            "label": "Homepage"
          },
          "action": {
            "label": "Action page"
          }
        },
        "the_ask": "AI companies should keep the safety and transparency commitments they have publicly made, and be held accountable when they quietly walk them back.",
        "what_they_do": "Corporate watchdog work: the Watchtower tracker of silent changes to AI company policies, investigations, scorecards, and the OpenAI Files. Runs modelrepublic.org and openaifiles.org.",
        "newcomer_action": "Send a tip if you have inside knowledge of an AI company; otherwise sign up as a volunteer, join the Discord and help with research or amplifying campaigns.",
        "tips": "yes — dedicated tip page at themidasproject.com/tips, aimed at industry insiders",
        "geography": "United States (company-focused, global reach).",
        "scale": "Tiny: founded early 2024 by Tyler Johnston, 'a small core team' plus volunteers. 501(c)(3), EIN 99-2326977.",
        "spending": "Not disclosed.",
        "caution": "Adversarial toward specific named companies. If you work at an AI lab, sending a tip may breach your employment agreement — take legal advice first; the organisation is small and cannot indemnify you."
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.themidasproject.com/tips",
            "checked": "2026-09-22"
          },
          {
            "url": "https://www.themidasproject.com/contact",
            "checked": "2026-09-22"
          },
          {
            "url": "https://www.themidasproject.com/volunteer",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "b7e97742ac",
        "research_order": 122,
        "migrated_from": "input/data/institutions.json",
        "legacy_ids": [
          "b7e97742ac",
          "9f4e2aad7e"
        ],
        "aliases": [
          "us-midas-project-2",
          "The Midas Project"
        ],
        "redirect_from": [
          {
            "section": "orgs",
            "id": "us-midas-project-2"
          }
        ],
        "identity_review": {
          "evidence_urls": [
            "https://www.themidasproject.com/tips",
            "https://www.themidasproject.com/volunteer"
          ],
          "reviewed_by": "codex:source-review-2026-09-24",
          "approved_by": "owner:autonomous-implementation-request-2026-09-24",
          "reviewed_on": "2026-09-24",
          "review_by": "2027-03-23",
          "note": "The records describe one real-world entity; preserve complementary facts and retire the non-canonical public id."
        },
        "merge_provenance": {
          "geo.country": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "geo.label": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.routes": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.region": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.public_input": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.tags": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_disposition": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_by": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_on": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.name": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.remit": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.threat_model": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.reality_check": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.gov_channel": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.routes": [
            {
              "record_id": "us-midas-project",
              "source_url": "https://www.themidasproject.com/tips",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.perspective": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.volunteers": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.the_ask": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.what_they_do": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.newcomer_action": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.tips": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.geography": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.scale": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.spending": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.caution": [
            {
              "record_id": "us-midas-project-2",
              "source_url": "https://www.themidasproject.com/volunteer",
              "checked_on": "2026-09-22"
            }
          ]
        }
      }
    },
    {
      "id": "us-nist-caisi-requests-information-ai",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "label": "United States"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "consultation",
            "value": "https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "160d4b8bafc0",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of",
              "evidence_note": "Technical input from developers, deployers and security researchers on AI security and standards questions. Recent dockets have covered unique security threats to AI agents, security practices and technical controls, assessment methods for identifying and managing AI vulnerabilities, deployment constraints and monitoring, and research and policy priorities.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "systemic",
                "consultation"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "6e36e7bc7b0d",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of",
              "evidence_note": "Technical input from developers, deployers and security researchers on AI security and standards questions. Recent dockets have covered unique security threats to AI agents, security practices and technical controls, assessment methods for identifying and managing AI vulnerabilities, deployment constraints and monitoring, and research and policy priorities."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-6adb6504-f61b-481c-b75e-63b868428f9a",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "NIST / CAISI requests for information on AI",
        "remit": "Technical input from developers, deployers and security researchers on AI security and standards questions. Recent dockets have covered unique security threats to AI agents, security practices and technical controls, assessment methods for identifying and managing AI vulnerabilities, deployment constraints and monitoring, and research and policy priorities.",
        "reality_check": "Among the best returns on effort for a technically credible individual. NIST outputs become de facto standards referenced in procurement and regulation worldwide, NIST explicitly solicits practitioner detail, and RFI response volumes are low enough that a substantive submission is genuinely read. Evidence of influence is visible in how NIST documents cite and reflect RFI input.",
        "accepts": "Technical input from developers, deployers and security researchers on AI security and standards questions. Recent dockets have covered unique security threats to AI agents, security practices and technical controls, assessment methods for identifying and managing AI vulnerabilities, deployment constraints and monitoring, and research and policy priorities.",
        "does_not_accept": "General opinion. NIST asks for concrete examples, best practices, case studies and actionable recommendations, and structures RFIs around numbered question areas.",
        "how": "Via regulations.gov using the docket number in the Federal Register notice. Answer the numbered questions directly and in order — this is the single most effective structural choice, because NIST staff synthesise responses question by question.",
        "format": "Written response keyed to the RFI's question numbering; attachments accepted.",
        "timing": "Windowed, announced in the Federal Register. Examples: AI agent security RFI closed 9 March 2026 (937 comments); NVD modernisation RFI open until 13 October 2026, 11:59pm ET.",
        "after": "Responses are public on the docket and feed NIST publications, profiles and frameworks (e.g. the Cyber AI Profile, AI agent security guidance).",
        "operator": "National Institute of Standards and Technology, US Department of Commerce (including the Center for AI Standards and Innovation)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Technical input from developers, deployers and security researchers on AI security and standards questions. Recent dockets have covered unique security threats to AI agents, security practices and technical controls, assessment methods for identifying and managing AI vulnerabilities, deployment constraints and monitoring, and research and policy priorities.",
            "note": "Via regulations.gov using the docket number in the Federal Register notice. Answer the numbered questions directly and in order — this is the single most effective structural choice, because NIST staff synthesise responses question by question."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "32adbe273f",
        "research_order": 217,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-nvidia",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "nvidia-psirt",
            "type": "email",
            "value": "psirt@nvidia.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "2eec0dd526f7",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://app.intigriti.com/company/programs/nvidia/nvidiavdp/detail",
              "evidence_note": "Product security vulnerabilities and AI concerns.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "email"
              ]
            }
          },
          {
            "id": "report-security-vulnerability-or",
            "type": "disclosure",
            "value": "https://app.intigriti.com/company/programs/nvidia/nvidiavdp/detail",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "6c4bdbe3cbe0",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://app.intigriti.com/company/programs/nvidia/nvidiavdp/detail",
              "evidence_note": "Explicitly includes 'AI vulnerability or hack, AI trust concern, malicious prompt engineering, data poisoning possibility'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "disclosure"
              ]
            }
          },
          {
            "id": "nvidia-public-bug-bounty",
            "type": "bounty",
            "value": "https://app.intigriti.com/company/programs/nvidia/nvidiapublicbugbounty/detail",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "701c2c3d45fa",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://app.intigriti.com/company/programs/nvidia/nvidiapublicbugbounty/detail",
              "evidence_note": "Paid security research.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "harm",
                "bounty"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.nvidia.com/en-us/security/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "0afe9f5a6da6",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.nvidia.com/en-us/security/",
              "evidence_note": "No public complaints found about NVIDIA PSIRT being unresponsive; PSIRT is an established, publicly active team (it posts as @nvidiapsirt). The AI-concern category on the VDP intake form is genuine and unusual. Note that from 1 October 2026 NVIDIA PSIRT will publish security bulletins only on GitHub (github.com/nvidia/product-security), so that is where to watch for outcomes."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://images.nvidia.com/content/pdf/NVIDIA-Frontier-AI-Risk-Assessment.pdf",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "db76a1d26f2f",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://images.nvidia.com/content/pdf/NVIDIA-Frontier-AI-Risk-Assessment.pdf",
              "evidence_note": "No public complaints found about NVIDIA PSIRT being unresponsive; PSIRT is an established, publicly active team (it posts as @nvidiapsirt). The AI-concern category on the VDP intake form is genuine and unusual. Note that from 1 October 2026 NVIDIA PSIRT will publish security bulletins only on GitHub (github.com/nvidia/product-security), so that is where to watch for outcomes."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "behaviour",
          "flaw",
          "harm"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-ada6c257-4029-4f27-8002-e69fa5e0b78a",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "NVIDIA",
        "remit": "NVIDIA PSIRT handles product security including AI-specific concerns; a Trustworthy AI function publishes model cards and the NeMo Guardrails tooling.",
        "reality_check": "No public complaints found about NVIDIA PSIRT being unresponsive; PSIRT is an established, publicly active team (it posts as @nvidiapsirt). The AI-concern category on the VDP intake form is genuine and unusual. Note that from 1 October 2026 NVIDIA PSIRT will publish security bulletins only on GitHub (github.com/nvidia/product-security), so that is where to watch for outcomes.",
        "notes": "The intake form's 'NVIDIA Artificial Intelligence (AI) Concern' option is the route to use — it is a real dropdown, not marketing. No explicit safe-harbour language was visible on the report-vulnerability page; check the PSIRT policies page before doing anything aggressive.",
        "routes": {
          "nvidia-psirt": {
            "label": "NVIDIA PSIRT",
            "scope": "Product security vulnerabilities and AI concerns.",
            "note": "PGP key at https://www.nvidia.com/en-us/security/pgp-key/"
          },
          "report-security-vulnerability-or": {
            "label": "Report a Security Vulnerability or NVIDIA AI Concern",
            "scope": "Explicitly includes 'AI vulnerability or hack, AI trust concern, malicious prompt engineering, data poisoning possibility'.",
            "note": "One of the very few intake forms in this list that names AI trust concerns as a first-class category rather than excluding them."
          },
          "nvidia-public-bug-bounty": {
            "label": "NVIDIA public bug bounty (Intigriti)",
            "scope": "Paid security research."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "NVIDIA Frontier AI Risk Assessment (17 February 2025)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://app.intigriti.com/company/programs/nvidia/nvidiavdp/detail",
            "checked": "2026-09-22"
          },
          {
            "url": "https://app.intigriti.com/company/programs/nvidia/nvidiapublicbugbounty/detail",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "391733a025",
        "research_order": 7,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-openai",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "coordinated-vulnerability-disclosure-policy",
            "type": "disclosure",
            "value": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "1aedc14b9469",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "evidence_note": "States: 'We invite you to report vulnerabilities, bugs, safety and abuse issues, or security flaws you discover in our systems.'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "disclosure"
              ],
              "restrictions": "States: 'We invite you to report vulnerabilities, bugs, safety and abuse issues, or security flaws you discover in our systems.'"
            }
          },
          {
            "id": "openai-bug-bounty",
            "type": "bounty",
            "value": "https://bugcrowd.com/openai",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "afab3013403b",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://bugcrowd.com/openai",
              "evidence_note": "Infrastructure/product security. $200 to $20,000."
            }
          },
          {
            "id": "openai-safety-bug-bounty",
            "type": "bounty",
            "value": "https://bugcrowd.com/engagements/openai-safety",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "aecc1c096002",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://bugcrowd.com/engagements/openai-safety",
              "evidence_note": "Model safety / CBRN jailbreaks. Separate engagement from the main bounty."
            }
          },
          {
            "id": "report-content",
            "type": "form",
            "value": "https://openai.com/form/report-content/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "efe0c7c75168",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://openai.com/form/report-content/",
              "evidence_note": "Publicly open form for policy violations and illegal content: violence and self-harm, sexual exploitation, child exploitation, bullying, fraud, privacy, IP.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "form"
              ],
              "restrictions": "Publicly open form for policy violations and illegal content: violence and self-harm, sexual exploitation, child exploitation, bullying, fraud, privacy, IP."
            }
          },
          {
            "id": "researcher-access-program",
            "type": "program",
            "value": "https://openai.com/form/researcher-access-program/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "b00592fd887c",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://openai.com/form/researcher-access-program/",
              "evidence_note": "Open and active. Up to $1,000 of API credits for 'researchers using our products to study areas related to the responsible deployment of AI and mitigating associated risks'. Reviewed quarterly.",
              "checked_on": "2026-09-22"
            }
          },
          {
            "id": "red-teaming-network",
            "type": "program",
            "value": "https://openai.com/index/red-teaming-network/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "98d99781c863",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://openai.com/index/red-teaming-network/",
              "evidence_note": "External domain experts stress-testing models.",
              "checked_on": "2026-09-22"
            }
          },
          {
            "id": "model-behavior-feedback-form",
            "type": "feedback",
            "value": "https://openai.com/form/model-behavior-feedback/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "4db1a40e523f",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://openai.com/form/model-behavior-feedback/",
              "evidence_note": "DEPRECATED. Page now reads: 'We've deprecated this web form in favor of other channels.'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "feedback"
              ],
              "restrictions": "DEPRECATED. Page now reads: 'We've deprecated this web form in favor of other channels.'"
            }
          },
          {
            "id": "model-spec-feedback-form",
            "type": "feedback",
            "value": "https://openai.com/form/model-spec-feedback/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "b01088987243",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://openai.com/form/model-spec-feedback/",
              "evidence_note": "CLOSED. 'This feedback form is now closed.'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "systemic",
                "feedback"
              ],
              "restrictions": "CLOSED. 'This feedback form is now closed.'"
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://openai.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "9bb60af6ec90",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://openai.com/",
              "evidence_note": "Mixed and worsening for unpaid routes. Two named public feedback channels — the model behavior feedback form and the Model Spec feedback form — are both now closed or deprecated, so a citizen's only open door is the content-report form. OpenAI's September 2026 model misalignment reporting framework is explicitly internal: 'Any OpenAI employee may flag a misalignment example for investigation' — it creates no external intake. Researchers in the Trusted Access for Cyber / Daybreak program publicly complained in August 2026 (TechCrunch, 19 Aug 2026) that access was revoked with messages saying their identity 'could not be verified', disproportionately affecting researchers outside the US and Eu"
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://model-spec.openai.com/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "26739653b9f2",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://model-spec.openai.com/",
              "evidence_note": "Mixed and worsening for unpaid routes. Two named public feedback channels — the model behavior feedback form and the Model Spec feedback form — are both now closed or deprecated, so a citizen's only open door is the content-report form. OpenAI's September 2026 model misalignment reporting framework is explicitly internal: 'Any OpenAI employee may flag a misalignment example for investigation' — it creates no external intake. Researchers in the Trusted Access for Cyber / Daybreak program publicly complained in August 2026 (TechCrunch, 19 Aug 2026) that access was revoked with messages saying their identity 'could not be verified', disproportionately affecting researchers outside the US and Eu"
            }
          },
          {
            "id": "submission-page",
            "type": "disclosure",
            "value": "https://openai.com/form/model-behavior-feedback/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "6b34ec0adb5c",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://openai.com/form/model-behavior-feedback/",
              "evidence_note": "Bugcrowd program: security vulnerabilities in OpenAI's systems and products.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "systemic",
                "disclosure"
              ]
            }
          },
          {
            "id": "homepage-9304dfe0",
            "type": "homepage",
            "value": "https://openai.com/form/model-behavior-feedback/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "2c1ab07bf651",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://openai.com/form/model-behavior-feedback/",
              "evidence_note": "Bugcrowd program: security vulnerabilities in OpenAI's systems and products."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "insider",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-3a4f627e-a0ce-495a-9600-3753986f57da",
        "roles": [
          "company",
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "OpenAI",
        "remit": "Safety Systems, Preparedness and Alignment teams, with a Safety and Security Committee at board level; Preparedness runs capability thresholds and the Model Spec defines intended model behaviour.",
        "reality_check": "Mixed and worsening for unpaid routes. Two named public feedback channels — the model behavior feedback form and the Model Spec feedback form — are both now closed or deprecated, so a citizen's only open door is the content-report form. OpenAI's September 2026 model misalignment reporting framework is explicitly internal: 'Any OpenAI employee may flag a misalignment example for investigation' — it creates no external intake. Researchers in the Trusted Access for Cyber / Daybreak program publicly complained in August 2026 (TechCrunch, 19 Aug 2026) that access was revoked with messages saying their identity 'could not be verified', disproportionately affecting researchers outside the US and Europe. The Safety Bug Bounty is reported to be NDA-bound, so findings cannot be published.",
        "notes": "If you have a model-behaviour concern and are not a paid bounty participant, the Report Content form is the only reliable open channel and it is framed around content policy, not alignment. OpenAI's security page says the bug bounty 'provides safe harbor for good-faith testing' but no verbatim safe-harbour clause is published on the policy page itself. No public whistleblower channel for outsiders.",
        "routes": {
          "coordinated-vulnerability-disclosure-policy": {
            "label": "Coordinated Vulnerability Disclosure Policy",
            "scope": "States: 'We invite you to report vulnerabilities, bugs, safety and abuse issues, or security flaws you discover in our systems.'",
            "note": "Broad invitation on its face, but the operative programs are on Bugcrowd and split security from safety."
          },
          "openai-bug-bounty": {
            "label": "OpenAI Bug Bounty (Bugcrowd)",
            "scope": "Infrastructure/product security. $200 to $20,000.",
            "note": "URL cited on OpenAI's own policy page; Bugcrowd page is JS-rendered and could not be read directly."
          },
          "openai-safety-bug-bounty": {
            "label": "OpenAI Safety Bug Bounty (Bugcrowd)",
            "scope": "Model safety / CBRN jailbreaks. Separate engagement from the main bounty.",
            "note": "Linked from OpenAI's coordinated disclosure policy. AI Frontiers reports all prompts, completions, findings and communications under it are NDA-covered — you cannot publish what you find."
          },
          "report-content": {
            "label": "Report Content",
            "scope": "Publicly open form for policy violations and illegal content: violence and self-harm, sexual exploitation, child exploitation, bullying, fraud, privacy, IP.",
            "note": "The only genuinely open, no-account-needed public channel. It is a content/abuse route, not an alignment route."
          },
          "researcher-access-program": {
            "label": "Researcher Access Program",
            "scope": "Open and active. Up to $1,000 of API credits for 'researchers using our products to study areas related to the responsible deployment of AI and mitigating associated risks'. Reviewed quarterly.",
            "note": "Explicitly welcomes 'early stage researchers' and those with 'limited financial and institutional resources'. Low-friction way in."
          },
          "red-teaming-network": {
            "label": "Red Teaming Network",
            "scope": "External domain experts stress-testing models.",
            "note": "CLOSED. Page states 'Applications are now closed' (deadline was 1 December 2023); says it may reopen. Do not count on it."
          },
          "model-behavior-feedback-form": {
            "label": "Model behavior feedback form",
            "scope": "DEPRECATED. Page now reads: 'We've deprecated this web form in favor of other channels.'",
            "note": "Redirects you to in-product thumbs-down, the API dashboard, or support. A named safety channel that was closed."
          },
          "model-spec-feedback-form": {
            "label": "Model Spec feedback form",
            "scope": "CLOSED. 'This feedback form is now closed.'",
            "note": "The public-comment process on the Model Spec no longer exists; updates are now published to a GitHub page instead."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "Preparedness Framework v2.0 (15 April 2025); Frontier Governance Framework (May 2026); Model Spec (updated continuously)"
          },
          "submission-page": {
            "label": "Submission page",
            "scope": "Bugcrowd program: security vulnerabilities in OpenAI's systems and products.",
            "note": "Security: bugcrowd.com/engagements/openai. Model behaviour: OpenAI now directs ChatGPT users to the thumbs-down control under any response or the content reporting form; API customers to enable thumbs-down feedback in the Playground via the API dashboard; everything else to customer support."
          },
          "homepage-9304dfe0": {
            "label": "Homepage"
          }
        },
        "accepts": "Bugcrowd program: security vulnerabilities in OpenAI's systems and products.",
        "does_not_accept": "The Bugcrowd engagement page states model safety issues, jailbreaks and hallucinations are excluded from the bug bounty and directs them elsewhere. The dedicated 'Model behavior feedback' web form (openai.com/form/model-behavior-feedback) has been deprecated and no longer accepts submissions.",
        "how": "Security: bugcrowd.com/engagements/openai. Model behaviour: OpenAI now directs ChatGPT users to the thumbs-down control under any response or the content reporting form; API customers to enable thumbs-down feedback in the Playground via the API dashboard; everything else to customer support.",
        "format": "Security: Bugcrowd vulnerability report. Model behaviour: an in-product thumbs-down with free text — there is no structured external report format any more.",
        "timing": "Rolling.",
        "after": "Security reports are triaged and may be rewarded (historically up to $20,000). Model-behaviour feedback disappears into product telemetry with no case number, no acknowledgment and no route back to the reporter.",
        "operator": "OpenAI, security program run on Bugcrowd"
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://openai.com/form/report-content/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://openai.com/form/researcher-access-program/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://openai.com/index/red-teaming-network/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://openai.com/form/model-behavior-feedback/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://openai.com/form/model-spec-feedback/",
            "checked": "2026-09-22"
          },
          {
            "url": "https://openai.com/form/model-behavior-feedback/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "d59b26f957",
        "research_order": 1,
        "migrated_from": "input/data/institutions.json",
        "legacy_ids": [
          "d59b26f957",
          "acc09e28da"
        ],
        "aliases": [
          "global-openai-inbound-reporting",
          "OpenAI inbound reporting (Bugcrowd bug bounty + in-product feedback)"
        ],
        "redirect_from": [
          {
            "section": "channels",
            "id": "global-openai-inbound-reporting"
          }
        ],
        "identity_review": {
          "evidence_urls": [
            "https://openai.com/form/model-behavior-feedback/",
            "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/"
          ],
          "reviewed_by": "codex:source-review-2026-09-24",
          "approved_by": "owner:autonomous-implementation-request-2026-09-24",
          "reviewed_on": "2026-09-24",
          "review_by": "2027-03-23",
          "note": "The records describe one real-world entity; preserve complementary facts and retire the non-canonical public id."
        },
        "merge_provenance": {
          "geo.country": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "geo.label": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.routes": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.region": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.public_input": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.tags": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_disposition": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_by": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "facts.contact_reviewed_on": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.name": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.remit": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.reality_check": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.notes": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.routes": [
            {
              "record_id": "us-openai",
              "source_url": "https://openai.com/policies/coordinated-vulnerability-disclosure-policy/",
              "checked_on": "2026-09-22"
            },
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.accepts": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.does_not_accept": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.how": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.format": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.timing": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.after": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ],
          "strings.operator": [
            {
              "record_id": "global-openai-inbound-reporting",
              "source_url": "https://openai.com/form/model-behavior-feedback/",
              "checked_on": "2026-09-22"
            }
          ]
        }
      }
    },
    {
      "id": "us-perplexity",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "vulnerability-disclosure-program",
            "type": "disclosure",
            "value": "https://bugcrowd.com/f1d4df64-af62-46e2-b7d3-dbe70b69a34e/external/report",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "615e826d5b8b",
            "contact": {
              "status": "limited",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://bugcrowd.com/f1d4df64-af62-46e2-b7d3-dbe70b69a34e/external/report",
              "evidence_note": "'All public facing endpoints of Perplexity. All user-facing clients and API endpoints are in scope.' Explicitly OUT of scope: 'AI-related issues such as hallucinations and model safety are not in scope of the security program.'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "disclosure"
              ],
              "restrictions": "'All public facing endpoints of Perplexity. All user-facing clients and API endpoints are in scope.' Explicitly OUT of scope: 'AI-related issues such as hallucinations and model safety are not in scope of the security program.'"
            }
          },
          {
            "id": "support-including-what-they",
            "type": "email",
            "value": "support@perplexity.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "23cebcb76cf2",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://bugcrowd.com/f1d4df64-af62-46e2-b7d3-dbe70b69a34e/external/report",
              "evidence_note": "Account, functional and safety issues, per the VDP page.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "Account, functional and safety issues, per the VDP page."
            }
          },
          {
            "id": "privacy-data-concerns",
            "type": "email",
            "value": "privacy@perplexity.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "ebac60d43b81",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://bugcrowd.com/f1d4df64-af62-46e2-b7d3-dbe70b69a34e/external/report",
              "evidence_note": "Privacy and data.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "Privacy and data."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.perplexity.ai/hub/security",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "282c2506ad4b",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.perplexity.ai/hub/security",
              "evidence_note": "The Comet browser has been a repeated target of serious external security research — Hacktron's one-click UXSS and Brave's prompt-injection findings — and those were handled through the security program, which does function. But model safety is formally excluded from it, and the fallback is a general support inbox. No safe-harbour language is published on the VDP page: it asks researchers to 'avoid actions that could compromise the privacy of our users' but offers no legal protection in return."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://www.perplexity.ai/hub/security-vdp",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "b769477478d4",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.perplexity.ai/hub/security-vdp",
              "evidence_note": "The Comet browser has been a repeated target of serious external security research — Hacktron's one-click UXSS and Brave's prompt-injection findings — and those were handled through the security program, which does function. But model safety is formally excluded from it, and the fallback is a general support inbox. No safe-harbour language is published on the VDP page: it asks researchers to 'avoid actions that could compromise the privacy of our users' but offers no legal protection in return."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-fedfa640-332b-4813-9949-d7927c5b60d1",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Perplexity",
        "remit": "No publicly named safety or alignment function. A security team runs the VDP; support handles what Perplexity calls 'safety issues' at the account level.",
        "reality_check": "The Comet browser has been a repeated target of serious external security research — Hacktron's one-click UXSS and Brave's prompt-injection findings — and those were handled through the security program, which does function. But model safety is formally excluded from it, and the fallback is a general support inbox. No safe-harbour language is published on the VDP page: it asks researchers to 'avoid actions that could compromise the privacy of our users' but offers no legal protection in return.",
        "notes": "If it is a security bug, Bugcrowd works. If it is a model-behaviour or hallucination harm, Perplexity has told you in writing it is out of scope, and support@ is your only option. Note the absence of safe harbour before doing any testing.",
        "routes": {
          "vulnerability-disclosure-program": {
            "label": "Vulnerability Disclosure Program (Bugcrowd)",
            "scope": "'All public facing endpoints of Perplexity. All user-facing clients and API endpoints are in scope.' Explicitly OUT of scope: 'AI-related issues such as hallucinations and model safety are not in scope of the security program.'",
            "note": "One of the bluntest published exclusions of model safety anywhere."
          },
          "support-including-what-they": {
            "label": "Support — including what they classify as safety issues",
            "scope": "Account, functional and safety issues, per the VDP page.",
            "note": "General support queue; not a safety function."
          },
          "privacy-data-concerns": {
            "label": "Privacy and data concerns",
            "scope": "Privacy and data."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No published safety framework; Vulnerability Disclosure Program is the governing document"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://bugcrowd.com/f1d4df64-af62-46e2-b7d3-dbe70b69a34e/external/report",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "d0dfe8f65b",
        "research_order": 26,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-psst-org-information-escrow-digital-safe",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "label": "US-based, international reach; tech-sector focus"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://psst.org/about",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "8e7bd4acb37a",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://psst.org/about",
              "evidence_note": "Concerns from tech and AI workers, at any level of completeness — explicitly including partial information, 'one line of code that is a red flag', or a general unease. Designed as a 'lower stakes way' to report without becoming a formal whistleblower.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "harm",
                "insider",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://psst.org/about",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "3e2f3a617584",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://psst.org/about",
              "evidence_note": "Concerns from tech and AI workers, at any level of completeness — explicitly including partial information, 'one line of code that is a red flag', or a general unease. Designed as a 'lower stakes way' to report without becoming a formal whistleblower."
            }
          }
        ],
        "region": "Other",
        "public_input": "open",
        "tags": [
          "flaw",
          "harm",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-dd1c4f63-82cb-48e7-924c-94331e16d022",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "Psst.org — information escrow / 'digital safe'",
        "remit": "Concerns from tech and AI workers, at any level of completeness — explicitly including partial information, 'one line of code that is a red flag', or a general unease. Designed as a 'lower stakes way' to report without becoming a formal whistleblower.",
        "reality_check": "The best-designed entry point for someone who is not sure they have enough to act on — which is the most common real situation. The escrow model directly addresses the collective action problem that keeps individuals silent. Free. Growing institutional credibility (appointed a full-time ED in March 2026, covered by Semafor as the main nonprofit connecting tech whistleblowers for AI oversight). No public record of enforcement outcomes, by design.",
        "accepts": "Concerns from tech and AI workers, at any level of completeness — explicitly including partial information, 'one line of code that is a red flag', or a general unease. Designed as a 'lower stakes way' to report without becoming a formal whistleblower.",
        "does_not_accept": "It is not a regulator and cannot take enforcement action. It will not publish on your behalf without your decision.",
        "how": "Deposit information into the secure escrow. The model is the key innovation: multiple people can contribute pieces of a puzzle, and Psst determines whether actionable evidence exists across depositors before anyone has to expose themselves individually. You then receive guidance on appropriate disclosure channels.",
        "format": "Whatever you have — documents, notes, a description of a concern.",
        "timing": "Rolling.",
        "after": "Psst assesses, advises on next steps, and can connect you onward to counsel or to coordinated disclosure.",
        "operator": "Psst.org, a nonprofit; Executive Director Jennifer Gibson; board includes Mark MacGann (Uber Files) and Ed Pierson (Boeing 737 MAX)",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Concerns from tech and AI workers, at any level of completeness — explicitly including partial information, 'one line of code that is a red flag', or a general unease. Designed as a 'lower stakes way' to report without becoming a formal whistleblower.",
            "note": "Deposit information into the secure escrow. The model is the key innovation: multiple people can contribute pieces of a puzzle, and Psst determines whether actionable evidence exists across depositors before anyone has to expose themselves individually. You then receive guidance on appropriate disclosure channels."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://psst.org/about",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "2f830c5aed",
        "research_order": 221,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-scale-ai",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "vulnerability-reports",
            "type": "email",
            "value": "vulnerabilities@scale.com",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "4a5dbb344c0d",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://trust.scale.com/",
              "evidence_note": "Responsible disclosure of security vulnerabilities. AI model safety is not mentioned.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "Responsible disclosure of security vulnerabilities. AI model safety is not mentioned."
            }
          },
          {
            "id": "trust-center",
            "type": "program",
            "value": "https://trust.scale.com/",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "3dbc8844b80b",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://trust.scale.com/",
              "evidence_note": "Compliance artifacts (SOC 2 Type II, ISO 27001, FedRAMP High, DoD IL4).",
              "checked_on": "2026-09-22"
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://scale.com/security",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "c6f68a9e1a60",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://scale.com/security",
              "evidence_note": "Scale's public safety relevance is as an evaluator of others rather than a developer, so external safety reports about Scale itself are rare. Scale had a significant 2025 incident in which public Google Docs exposed confidential client project details and contractor data, surfaced by journalists rather than through disclosure. Since Meta's investment and the departure of leadership to Meta, SEAL's independence as a third-party evaluator has been publicly questioned — which matters if you are considering Scale as a neutral route for a finding about another lab."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://scale.com/blog/risk-matrix",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "811654b0a348",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://scale.com/blog/risk-matrix",
              "evidence_note": "Scale's public safety relevance is as an evaluator of others rather than a developer, so external safety reports about Scale itself are rare. Scale had a significant 2025 incident in which public Google Docs exposed confidential client project details and contractor data, surfaced by journalists rather than through disclosure. Since Meta's investment and the departure of leadership to Meta, SEAL's independence as a third-party evaluator has been publicly questioned — which matters if you are considering Scale as a neutral route for a finding about another lab."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-9e0630a1-39b6-4d82-8845-448cc7c51f0c",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Scale AI",
        "remit": "Safety, Evaluations and Alignment Lab (SEAL) produces third-party model evaluations and red-teaming for other developers; internally a trust/security function runs disclosure.",
        "reality_check": "Scale's public safety relevance is as an evaluator of others rather than a developer, so external safety reports about Scale itself are rare. Scale had a significant 2025 incident in which public Google Docs exposed confidential client project details and contractor data, surfaced by journalists rather than through disclosure. Since Meta's investment and the departure of leadership to Meta, SEAL's independence as a third-party evaluator has been publicly questioned — which matters if you are considering Scale as a neutral route for a finding about another lab.",
        "notes": "vulnerabilities@scale.com is security-scoped. Scale is not a route for reporting concerns about frontier models generally, and its evaluator independence is contested post-Meta investment. No safe-harbour language found.",
        "routes": {
          "vulnerability-reports": {
            "label": "Vulnerability reports",
            "scope": "Responsible disclosure of security vulnerabilities. AI model safety is not mentioned.",
            "note": "Published on scale.com/security. No formal bug bounty is described."
          },
          "trust-center": {
            "label": "Trust Center",
            "scope": "Compliance artifacts (SOC 2 Type II, ISO 27001, FedRAMP High, DoD IL4).",
            "note": "Documentation, not an incident channel."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No frontier safety framework (not a frontier model developer); publishes evaluation methodology such as the AI Risk Matrix"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://trust.scale.com/",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "5eed4d4f98",
        "research_order": 27,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-sec-whistleblower-program",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "label": "United States; covers publicly traded companies and securities-law violations"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "whistleblowing",
            "value": "https://www.sec.gov/enforcement-litigation/whistleblower-program/information-about-submitting-whistleblower-tip",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "8f02d7b47e38",
            "contact": {
              "status": "open",
              "directness": "official-instructions",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.sec.gov/enforcement-litigation/whistleblower-program/information-about-submitting-whistleblower-tip",
              "evidence_note": "Original information about potential violations of the federal securities laws. For AI: material misrepresentation of model capability, safety practices or risk to investors — 'AI-washing' cases have been brought. Reaches Google, Microsoft, Meta and Nvidia; reaches private labs only where securities law otherwise bites.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "harm",
                "insider",
                "whistleblowing"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.sec.gov/enforcement-litigation/whistleblower-program/information-about-submitting-whistleblower-tip",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "a6163f09f428",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.sec.gov/enforcement-litigation/whistleblower-program/information-about-submitting-whistleblower-tip",
              "evidence_note": "Original information about potential violations of the federal securities laws. For AI: material misrepresentation of model capability, safety practices or risk to investors — 'AI-washing' cases have been brought. Reaches Google, Microsoft, Meta and Nvidia; reaches private labs only where securities law otherwise bites."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "flaw",
          "harm",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-6442375e-7d87-4342-bc77-82c20279a16f",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "SEC Whistleblower Program (Form TCR)",
        "remit": "Original information about potential violations of the federal securities laws. For AI: material misrepresentation of model capability, safety practices or risk to investors — 'AI-washing' cases have been brought. Reaches Google, Microsoft, Meta and Nvidia; reaches private labs only where securities law otherwise bites.",
        "reality_check": "The only route in this entire list that pays the whistleblower substantial money and has a long, documented record of doing so. The critical mechanic: you may submit anonymously, but only if you are represented by an attorney who provides their contact information — anonymity and award eligibility both depend on having counsel. Requires reframing an AI safety concern as an investor-disclosure concern, which is a genuine constraint but often achievable where a company has made public safety claims.",
        "accepts": "Original information about potential violations of the federal securities laws. For AI: material misrepresentation of model capability, safety practices or risk to investors — 'AI-washing' cases have been brought. Reaches Google, Microsoft, Meta and Nvidia; reaches private labs only where securities law otherwise bites.",
        "does_not_accept": "Safety concerns with no securities-law dimension. 'This model is dangerous' is not an SEC matter unless the company told investors otherwise.",
        "how": "Submit through the SEC's Tips, Complaints and Referrals portal (recommended — gives immediate confirmation and a submission number), or mail/fax Form TCR to SEC Office of the Whistleblower, c/o ENF-CPU, 1604 Springhill Road, Suite 110, Vienna, VA 22182, fax +1 703-813-9322. You must answer 'yes' to filing under the whistleblower program and complete the whistleblower declaration to get award eligibility and enhanced confidentiality.",
        "format": "Form TCR: detailed narrative plus supporting documents.",
        "timing": "Rolling, but you must submit directly to the SEC in a timely way — reporting elsewhere first does not satisfy the requirement and can cost you award eligibility.",
        "after": "Triage by the Office of the Whistleblower; possible investigation; awards of 10–30% of sanctions over $1 million.",
        "operator": "US Securities and Exchange Commission, Office of the Whistleblower",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Original information about potential violations of the federal securities laws. For AI: material misrepresentation of model capability, safety practices or risk to investors — 'AI-washing' cases have been brought. Reaches Google, Microsoft, Meta and Nvidia; reaches private labs only where securities law otherwise bites.",
            "note": "Submit through the SEC's Tips, Complaints and Referrals portal (recommended — gives immediate confirmation and a submission number), or mail/fax Form TCR to SEC Office of the Whistleblower, c/o ENF-CPU, 1604 Springhill Road, Suite 110, Vienna, VA 22182, fax +1 703-813-9322. You must answer 'yes' to filing under the whistleblower program and complete the whistleblower declaration to get award eligibility and enhanced confidentiality."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.sec.gov/enforcement-litigation/whistleblower-program/information-about-submitting-whistleblower-tip",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "dea66c4367",
        "research_order": 224,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-thinking-machines-lab",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "security-vulnerability-reports",
            "type": "email",
            "value": "security-reports@thinkingmachines.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "4e906427fe34",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://thinkingmachines.ai/",
              "evidence_note": "Security vulnerabilities in systems, services and infrastructure. PGP key at https://thinkingmachines.ai/.well-known/pgp-key.txt (fingerprint 4FA9 136F 8F68 DDFD 1E78 6EBE CB0B 7A1E 3028 4CB4).",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "Security vulnerabilities in systems, services and infrastructure. PGP key at https://thinkingmachines.ai/.well-known/pgp-key.txt (fingerprint 4FA9 136F 8F68 DDFD 1E78 6EBE CB0B 7A1E 3028 4CB4)."
            }
          },
          {
            "id": "model-safety-incidents-routed",
            "type": "email",
            "value": "legal@thinkingmachines.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "6d209b03e290",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://thinkingmachines.ai/",
              "evidence_note": "The disclosure policy states: 'This policy does not cover model safety. To report an incident related to Inkling, please contact us at [legal@thinkingmachines.ai].'",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "email"
              ],
              "restrictions": "The disclosure policy states: 'This policy does not cover model safety. To report an incident related to Inkling, please contact us at [legal@thinkingmachines.ai].'"
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://thinkingmachines.ai/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "5ad74fbd52fc",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://thinkingmachines.ai/",
              "evidence_note": "Too new for public accounts of responsiveness. The structural signal is clear though: Thinking Machines writes an unusually strong safe-harbour clause for security research and then explicitly excludes model safety from it, routing model-safety incidents to legal@ — which means a model-safety report arrives at a desk whose job is liability, and arrives outside the protections the same page grants to security researchers."
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://thinkingmachines.ai/security/disclosure-policy/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "ea587484a8cc",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://thinkingmachines.ai/security/disclosure-policy/",
              "evidence_note": "Too new for public accounts of responsiveness. The structural signal is clear though: Thinking Machines writes an unusually strong safe-harbour clause for security research and then explicitly excludes model safety from it, routing model-safety incidents to legal@ — which means a model-safety report arrives at a desk whose job is liability, and arrives outside the protections the same page grants to security researchers."
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-0e2258d3-8a96-4b48-b709-3e0113a6e9bf",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "Thinking Machines Lab",
        "remit": "States it will contribute to AI safety by 'maintaining a high safety bar—preventing misuse of our released models while maximizing users' freedom', sharing best practices, and 'accelerating external research on alignment by sharing code, datasets, and model specs'. No named safety team.",
        "reality_check": "Too new for public accounts of responsiveness. The structural signal is clear though: Thinking Machines writes an unusually strong safe-harbour clause for security research and then explicitly excludes model safety from it, routing model-safety incidents to legal@ — which means a model-safety report arrives at a desk whose job is liability, and arrives outside the protections the same page grants to security researchers.",
        "notes": "The safe harbour is one of the best-written in this list, but read its boundary: 'When you conduct security research and vulnerability disclosure in good faith and in compliance with this policy, we consider that research to be authorized, and we will: Not pursue or support any legal action against you for accidental, good-faith violations of this policy, including under the Computer Fraud and Abuse Act or the anti-circumvention provisions of the Digital Millennium Copyright Act; Waive any restrictions in our Terms of Service or Acceptable Use Policy...; and If a third party initiates legal action against you..., take reasonable steps to make it known that your actions were authorized.' None of that covers a model-safety finding. Get advice before sending a jailbreak to legal@.",
        "routes": {
          "security-vulnerability-reports": {
            "label": "Security vulnerability reports",
            "scope": "Security vulnerabilities in systems, services and infrastructure. PGP key at https://thinkingmachines.ai/.well-known/pgp-key.txt (fingerprint 4FA9 136F 8F68 DDFD 1E78 6EBE CB0B 7A1E 3028 4CB4).",
            "note": "Verified by decoding the Cloudflare-obfuscated addresses in the page source. Explicitly no bug bounty: 'we do not operate a bug bounty program and do not offer monetary rewards or compensation of any kind'."
          },
          "model-safety-incidents-routed": {
            "label": "Model safety incidents — routed to Legal",
            "scope": "The disclosure policy states: 'This policy does not cover model safety. To report an incident related to Inkling, please contact us at [legal@thinkingmachines.ai].'",
            "note": "Significant finding: model safety is carved out of the security process and sent to the legal department. Verified by decoding the page source."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "No frontier safety framework published; Coordinated Vulnerability Disclosure Policy is the only governance document"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://thinkingmachines.ai/",
            "checked": null
          },
          {
            "url": "https://thinkingmachines.ai/security/disclosure-policy/",
            "checked": null
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "d757629a31",
        "research_order": 24,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-us-federal-rulemaking-comments-regulations-gov",
      "type": "reporting-channel",
      "geo": {
        "country": "us",
        "label": "United States"
      },
      "facts": {
        "routes": [
          {
            "id": "submission-page",
            "type": "consultation",
            "value": "https://www.regulations.gov/assets/files/Public-Comment-on-Federal-Regulations_Final.pdf",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "f4234caf977e",
            "contact": {
              "status": "open",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://www.regulations.gov/assets/files/Public-Comment-on-Federal-Regulations_Final.pdf",
              "evidence_note": "Comments from anyone, including non-US persons, on proposed rules, requests for information and requests for comment. No affiliation required.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "public"
              ],
              "accepted_subjects": [
                "flaw",
                "systemic",
                "consultation"
              ]
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://www.regulations.gov/assets/files/Public-Comment-on-Federal-Regulations_Final.pdf",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "a3b59ec49d3f",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://www.regulations.gov/assets/files/Public-Comment-on-Federal-Regulations_Final.pdf",
              "evidence_note": "Comments from anyone, including non-US persons, on proposed rules, requests for information and requests for comment. No affiliation required."
            }
          }
        ],
        "region": "United States",
        "public_input": "open",
        "tags": [
          "flaw",
          "systemic"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-d2dd743d-a8e7-470a-86b1-2dfa1cad3663",
        "roles": [
          "reporting-channel"
        ]
      },
      "strings": {
        "name": "US federal rulemaking comments — Regulations.gov",
        "remit": "Comments from anyone, including non-US persons, on proposed rules, requests for information and requests for comment. No affiliation required.",
        "reality_check": "Genuinely high-leverage and widely underrated for an unaffiliated person, precisely because of the legal duty to respond to significant comments — no other consultation mechanism in this list carries an enforceable response obligation. A single well-evidenced technical comment on a low-volume AI docket can shape a final rule. A form letter does nothing.",
        "accepts": "Comments from anyone, including non-US persons, on proposed rules, requests for information and requests for comment. No affiliation required.",
        "does_not_accept": "It is not a vote. Identical mass comments carry no extra weight: 'multiple identical comments are not likely to be more persuasive than if the comment had been sent only once,' and the number of comments for or against does not determine whether a rule proceeds.",
        "how": "Search the docket number on regulations.gov, click 'Comment Now!', complete the fields and attach or type your comment. Live AI-relevant examples at the time of this research: NIST-2026-0100 (Modernizing the National Vulnerability Database in the Age of AI, comments due 13 October 2026) and NIST-2025-0035 (Security Considerations for AI Agents, closed 9 March 2026 with 937 comments).",
        "format": "No length limit, but substance over volume. What works: explain concretely how the policy would affect a specific situation, supply reasoning and evidence, or offer a perspective the agency has not previously considered. What fails: bare statements of support or opposition. Agencies invite 'concrete examples, best practices, case studies, and actionable recommendations.'",
        "timing": "Typically a 30–60 day window after a proposed rule is issued; the deadline is stated in the preamble of each notice. RFIs vary.",
        "after": "Comments are posted publicly on the docket. Agencies must respond to significant, relevant comments when publishing a final rule, and may explain how comments changed the rule. Inadequate response to significant comments is a ground for legal challenge.",
        "operator": "eRulemaking Program (US federal government); individual agencies own each docket",
        "routes": {
          "submission-page": {
            "label": "Submission page",
            "scope": "Comments from anyone, including non-US persons, on proposed rules, requests for information and requests for comment. No affiliation required.",
            "note": "Search the docket number on regulations.gov, click 'Comment Now!', complete the fields and attach or type your comment. Live AI-relevant examples at the time of this research: NIST-2026-0100 (Modernizing the National Vulnerability Database in the Age of AI, comments due 13 October 2026) and NIST-2025-0035 (Security Considerations for AI Agents, closed 9 March 2026 with 937 comments)."
          },
          "homepage": {
            "label": "Homepage"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://www.regulations.gov/assets/files/Public-Comment-on-Federal-Regulations_Final.pdf",
            "checked": "2026-09-22"
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "1aa4221761",
        "research_order": 216,
        "migrated_from": "input/data/institutions.json"
      }
    },
    {
      "id": "us-xai",
      "type": "company",
      "geo": {
        "country": "us",
        "label": "USA"
      },
      "facts": {
        "routes": [
          {
            "id": "safety-reports",
            "type": "email",
            "value": "safety@x.ai",
            "verified": true,
            "verification_method": "fetched_source_page",
            "verified_on": "2026-09-22",
            "source_id": "57c4be431cae",
            "contact": {
              "status": "limited",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "keep",
              "evidence_url": "https://hackerone.com/x",
              "evidence_note": "Published on x.ai/safety for 'reporting harmful outputs, jailbreaks, or other safety issues'.",
              "checked_on": "2026-09-22",
              "eligible_users": [
                "users-meeting-published-eligibility"
              ],
              "accepted_subjects": [
                "behaviour",
                "flaw",
                "insider",
                "email"
              ],
              "restrictions": "Published on x.ai/safety for 'reporting harmful outputs, jailbreaks, or other safety issues'."
            }
          },
          {
            "id": "hackerone-bug-bounty",
            "type": "bounty",
            "value": "https://hackerone.com/x",
            "verified": false,
            "verification_method": "secondary_citation",
            "verified_on": null,
            "source_id": "2e7d4bb90acb",
            "contact": {
              "status": "unknown",
              "directness": "direct",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "fix",
              "evidence_url": "https://hackerone.com/x",
              "evidence_note": "Security vulnerabilities."
            }
          },
          {
            "id": "homepage",
            "type": "homepage",
            "value": "https://x.ai/",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "5a4b718f0383",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://x.ai/",
              "evidence_note": "Worst documented record of the major labs. AI Frontiers (2026) reports a researcher who emailed the safety address in October 2025 with evidence of 'clear, step-by-step guidance on building a massively destructive chemical weapon' and 'did not receive anything other than an automated response'. Separately, GitGuardian documented a disclosure in April/May 2025: no security.txt, an expired HackerOne link on x.com, and when they finally reached safety@x.ai the reply 12 hours later was 'For us to analyze and also for you to receive proper credit, if applicable, would you please submit this to xAI's Bug Bounty Program on HackerOne?' — the leak was quietly fixed with no update to the reporters, 'c"
            }
          },
          {
            "id": "framework",
            "type": "framework",
            "value": "https://media.x.ai/v1/website/xai-frontier-artificial-intelligence-framework-30-june-2026-99c40684.pdf",
            "verified": null,
            "verification_method": "listed_not_independently_checked",
            "verified_on": null,
            "source_id": "213d9f3c60b5",
            "contact": {
              "status": "none",
              "directness": "indirect",
              "review": "reviewed",
              "reviewed_by": "codex:deterministic-contact-audit",
              "reviewed_on": "2026-09-24",
              "disposition": "reference-only",
              "evidence_url": "https://media.x.ai/v1/website/xai-frontier-artificial-intelligence-framework-30-june-2026-99c40684.pdf",
              "evidence_note": "Worst documented record of the major labs. AI Frontiers (2026) reports a researcher who emailed the safety address in October 2025 with evidence of 'clear, step-by-step guidance on building a massively destructive chemical weapon' and 'did not receive anything other than an automated response'. Separately, GitGuardian documented a disclosure in April/May 2025: no security.txt, an expired HackerOne link on x.com, and when they finally reached safety@x.ai the reply 12 hours later was 'For us to analyze and also for you to receive proper credit, if applicable, would you please submit this to xAI's Bug Bounty Program on HackerOne?' — the leak was quietly fixed with no update to the reporters, 'c"
            }
          }
        ],
        "region": "United States",
        "public_input": "limited",
        "tags": [
          "behaviour",
          "flaw",
          "insider"
        ],
        "contact_disposition": "keep",
        "contact_reviewed_by": "codex:deterministic-contact-audit",
        "contact_reviewed_on": "2026-09-24",
        "entity_key": "entity-1578f322-4abe-45b6-8aeb-dd2a021f9a93",
        "roles": [
          "company"
        ]
      },
      "strings": {
        "name": "xAI (SpaceXAI)",
        "remit": "A safety team (unnamed publicly; the site says it 'is actively hiring researchers and engineers') producing model cards and safety evaluations under the Frontier AI Framework. No named safety office or officer is published.",
        "reality_check": "Worst documented record of the major labs. AI Frontiers (2026) reports a researcher who emailed the safety address in October 2025 with evidence of 'clear, step-by-step guidance on building a massively destructive chemical weapon' and 'did not receive anything other than an automated response'. Separately, GitGuardian documented a disclosure in April/May 2025: no security.txt, an expired HackerOne link on x.com, and when they finally reached safety@x.ai the reply 12 hours later was 'For us to analyze and also for you to receive proper credit, if applicable, would you please submit this to xAI's Bug Bounty Program on HackerOne?' — the leak was quietly fixed with no update to the reporters, 'completely out of bounds of the disclosure process'. GitGuardian's verdict: 'For a company the size of X, replacing an Incident Response Team...with a bug bounty platform should not be an option and should be considered bad practice.' xAI's own framework lists only internal escalation routes and vaguely references 'xAI's appropriate reporting channels' without naming any. There is also a pending lawsuit over the firing of a Grok safety whistleblower.",
        "notes": "safety@x.ai is published and real, but expect an autoresponder and a push to HackerOne. If the finding is serious, document your attempt and consider a coordinated third-party route (CERT/CC, ai-reports.org) in parallel. No published safe-harbour language, no published whistleblower channel.",
        "routes": {
          "safety-reports": {
            "label": "Safety reports",
            "scope": "Published on x.ai/safety for 'reporting harmful outputs, jailbreaks, or other safety issues'.",
            "note": "On paper this is exactly the address a citizen wants. In practice see reality check."
          },
          "hackerone-bug-bounty": {
            "label": "HackerOne bug bounty",
            "scope": "Security vulnerabilities.",
            "note": "Linked from x.ai/safety. xAI has a documented habit of redirecting safety emails into this bounty queue."
          },
          "homepage": {
            "label": "Homepage"
          },
          "framework": {
            "label": "xAI Frontier Artificial Intelligence Framework (effective 30 June 2026)"
          }
        }
      },
      "meta": {
        "verified_on": "2026-09-22",
        "review_by": "2027-03-21",
        "sources": [
          {
            "url": "https://hackerone.com/x",
            "checked": null
          },
          {
            "url": "https://x.ai/",
            "checked": null
          },
          {
            "url": "https://media.x.ai/v1/website/xai-frontier-artificial-intelligence-framework-30-june-2026-99c40684.pdf",
            "checked": null
          }
        ],
        "needs_research": [
          "powers",
          "topics",
          "not_topics"
        ],
        "legacy_id": "ee7be3ca28",
        "research_order": 5,
        "migrated_from": "input/data/institutions.json"
      }
    }
  ]
}