CSOAI   Home · Journal · Certification · Fabric
The 52-Article Charter · 32–36 of 52 · full text

Article 32–36: Complete

Published from the canonical CSOAI Partnership Charter (effective 15 January 2026). Full text below.

Version: 1.0 Effective Date: January 15, 2026, 09:00 GMT


ARTICLE 32: SUPPLY CHAIN TRANSPARENCY

32.1 VENDOR DUE DILIGENCE

32.1.1 Security Assessment

All Third-Party Vendors Must Undergo:

32.1.2 Privacy Compliance Verification

32.1.3 Labor Practices Review

32.1.4 Environmental Impact Assessment

32.1.5 Financial Stability Check

32.2 CONFLICT MINERALS

32.2.1 Hardware Supply Chain

Requirements:

32.2.2 Due Diligence

32.3 LABOR STANDARDS

32.3.1 Manufacturing and Operations

All Supply Chain Partners Must:

32.3.2 Data Annotation Workers

Specific Protections:

32.4 SUPPLY CHAIN MAPPING

32.4.1 Full Traceability

Requirements:

32.4.2 Risk Assessment

Regular Assessment:

32.4.3 Disclosure

32.5 PROCUREMENT ETHICS

32.5.1 Anti-Corruption

32.5.2 Diversity in Suppliers


ARTICLE 33: INSURANCE & LIABILITY

33.1 REQUIRED INSURANCE COVERAGE

33.1.1 Liability Insurance Minimums

| Risk Tier | General Liability | Cyber Insurance | E&O Insurance | Product Liability |
|-----------|------------------|-----------------|---------------|-------------------|
| Low | £1M | £500K | £500K | £1M |
| Medium | £10M | £5M | £2M | £5M |
| High | £50M | £25M | £10M | £25M |
| Critical | £500M | £100M | £50M | £100M |

33.1.2 Coverage Types

General Liability:

Cyber Liability:

Errors & Omissions (E&O):

Product Liability:

33.2 CSOAI INSURANCE POOL

33.2.1 Shared Risk Pool

Structure:

33.2.2 Contribution Formula

``` Annual Contribution = Base Rate × Risk Tier Factor × Claims History Factor × Revenue Factor

Where:

```

33.3 LIABILITY FRAMEWORK

33.3.1 Product Liability Model

Who's Liable for AI Harms?

Primary Liability:

Strict Liability:

Negligence:

33.3.2 Shared Liability

When Multiple Parties Involved:

33.3.3 CSOAI Role

33.4 CLAIMS PROCESS

33.4.1 When AI Causes Harm

33.4.2 CSOAI Assistance

33.5 INSURANCE INNOVATION

33.5.1 Parametric Insurance

Automatic Payouts on Triggers:

33.5.2 AI-Specific Coverage

Emerging Products:

ARTICLE 34: INTELLECTUAL PROPERTY

34.1 AI-GENERATED CONTENT OWNERSHIP

34.1.1 Current Legal Landscape

US:

EU/UK:

CSOAI Position:

34.1.2 Disclosure Requirements

AI-Generated Content Must Be Labeled:

34.2 MODEL WEIGHTS AS IP

34.2.1 Protection Strategies

Trade Secret:

Copyright:

Patent:

34.2.2 CSOAI Guidance

34.3 TRAINING DATA ATTRIBUTION

34.3.1 Respect Creators

Principles:

34.3.2 Data Licensing

34.4 PATENT COMMONS

34.4.1 Defensive Patent Pool

CSOAI AI Safety Patent Pool:

34.4.2 Participation

34.5 OPEN SOURCE AI

34.5.1 CSOAI Position

Support Open Source With Safety Guardrails:

34.5.2 Dual Licensing

Commercial + Open Source:

ARTICLE 35: EMERGENCY RESPONSE PROTOCOLS

35.1 INCIDENT CLASSIFICATION

35.1.1 Severity Levels

Level 1 (Minor):

Level 2 (Moderate):

Level 3 (Major):

Level 4 (Critical):

Level 5 (Catastrophic):

35.2 EMERGENCY OPERATIONS CENTER (EOC)

35.2.1 Staffing

For Critical Tier Systems:

For High Tier:

35.2.2 Capabilities

35.3 ESCALATION PROCEDURES

35.3.1 Clear Chain of Command

| Timeline | Action | Responsible |
|----------|--------|-------------|
| 0-5 min | Incident detected | Monitoring system/reporter |
| 5-15 min | On-call engineer notified | Automated |
| 15-30 min | Incident commander assigned | On-call engineer |
| 30-60 min | Executive notified (Level 2+) | Incident commander |
| 1 hour | CSOAI notified (Level 2+) | Incident commander |
| 2 hours | Human Council (Level 3+) | CSOAI |
| 24 hours | Public disclosure (Level 3+) | Communications team |

35.3.2 Decision Authority

35.4 CRISIS COMMUNICATION

35.4.1 Pre-Prepared Templates

Templates Ready For:

35.4.2 Communication Principles

35.5 POST-INCIDENT REVIEW

35.5.1 Mandatory After Every Incident

Timeline: Within 2 weeks of resolution

Process:

35.5.2 CSOAI Incident Database


ARTICLE 36: BUSINESS CONTINUITY & DISASTER RECOVERY

36.1 BUSINESS IMPACT ANALYSIS

36.1.1 Critical Functions Identified

Priority 1 (Mission Critical):

Priority 2 (Essential):

Priority 3 (Important):

36.1.2 Maximum Tolerable Downtime (MTD)

| Priority | MTD |
|----------|-----|
| Critical tier AI | 1 hour |
| High tier AI | 4 hours |
| Medium tier AI | 24 hours |
| Low tier AI | 1 week |
| Byzantine Council | 15 minutes |

36.2 BACKUP STRATEGIES

36.2.1 3-2-1 Rule

36.2.2 Backup Frequency

| System Type | Backup Frequency | Retention |
|-------------|------------------|-----------|
| Critical data | Real-time replication | 7 years |
| High priority | Hourly | 3 years |
| Medium priority | Daily | 1 year |
| Low priority | Weekly | 6 months |

36.2.3 Testing

36.3 REDUNDANCY REQUIREMENTS

36.3.1 No Single Point of Failure

For Critical Systems:

36.3.2 Infrastructure Redundancy

36.4 DISASTER SCENARIOS

36.4.1 Scenarios Prepared For

Natural Disasters:

Cyber Attacks:

Infrastructure Failures:

Pandemics:

Key Personnel Loss:

36.5 RECOVERY PROCEDURES

36.5.1 Documented Runbooks

For Each Critical System:

36.5.2 Recovery Time Objective (RTO)

| System | RTO |
|--------|-----|
| Byzantine Council | 15 minutes |
| Critical AI services | 1 hour |
| High priority services | 4 hours |
| Medium priority | 24 hours |

36.5.3 Recovery Point Objective (RPO)

| System | RPO (max data loss) |
|--------|-----|
| Byzantine Council logs | 0 (no loss) |
| Critical AI services | 15 minutes |
| High priority | 1 hour |
| Medium priority | 24 hours |

END OF PHASE 4: OPERATIONAL REQUIREMENTS (Articles 29-36)

Phase 4 Complete!

Progress: 36 of 52 Articles (69%)

Next: Phase 5 - Economic & Social (Articles 37-44) Then: Phase 6 - Long-Term Governance (Articles 45-52)

From charter to certificate. This article is part of the standard behind Watchdog Certification — independent assessment, Ed25519-signed, publicly verifiable. The crosswalks to the EU AI Act, ISO/IEC 42001 and 18 more frameworks are in the Crosswalk Library; the runtime tools are in the fabric.

The 52-Article Charter is published in full in the Journal. Bespoke briefings: hello@meok.ai.