docs: retarget the standards body from AAIF to CoSAI WS4 - #253
Merged
Conversation
The v1.0 standards path now runs through CoSAI Working Stream 4 (Secure Design Patterns for Agentic Systems), an OASIS Open Project, following the Phase 1 RFC in cosai-oasis/ws4-secure-design-agentic-systems#149. The repo previously named AAIF as the donation target in the spec header, section 3.1, section 3.2.5, sections 10.1 to 10.3, and across CHARTER, GOVERNANCE, MAINTAINERS, ANTITRUST, CONTRIBUTING, ROADMAP and the READMEs, which contradicted the RFC asking WS4 to consider accepting the spec. No normative data-model, cryptographic, or conformance change. Three deliberate departures from a mechanical replace: - Section 8.2 no longer ties the conformance suite to "the AGT donation to AAIF". AGT's standards destination is governed separately. - Two AAIF references are kept, because they describe MCP's governance home rather than this spec's target: the SEP route in 6.3 and the "MCP (Anthropic / AAIF)" row in 10.4. - IP and trademark terms are recorded as consequences, not commitments. The OASIS Open Projects IPR Policy requires a CLA and a patent non-assert on non-trivial contributions, stricter than the DCO-only regime in force today. CHARTER section 4 states it takes effect only on WS4 acceptance and that the founding maintainer's terms under it need counsel sign-off first. Trademark transfer is marked to be determined rather than asserted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Retargets the v1.0 standards path from AAIF to CoSAI Working Stream 4 (Secure Design Patterns for Agentic Systems), an OASIS Open Project, following the Phase 1 RFC in cosai-oasis/ws4-secure-design-agentic-systems#149.
The repo named AAIF as the donation target in 10 files. That directly contradicted the RFC, which asks WS4 to consider accepting this spec while §10.3 read "Proposed AAIF Standard." A reviewer working through the nine review tracks would have found it.
No normative change. Data model, cryptographic protocols, verification semantics, and conformance levels are untouched. Nothing about how a manifest is signed or verified moves.
Three deliberate departures from a mechanical find-and-replace
1. §8.2 decoupled from AGT. The conformance suite was described as shipping "alongside the AGT donation to AAIF." AGT's standards destination is governed separately and is not set by this charter, so the suite is now described as moving with the specification.
2. Two AAIF references retained. Both describe MCP's governance home, not this spec's target, and would have been wrong to change:
AAIF Spec Enhancement Proposal (SEP)route for MCPImplementationfieldsMCP (Anthropic / AAIF)relationship row3. IP and trademark terms stated as consequences, not commitments. This is the part that needs a look before merge.
CoSAI runs under the OASIS Open Projects IPR Policy: contributors sign a CLA and, for non-trivial contributions, a patent non-assert, releasing code under Apache-2.0 and docs and data under CC-BY-4.0. That is stricter than the DCO-only regime in force today.
Rather than assert terms nobody has agreed to,
CHARTER.md§4 now records the policy, states that it takes effect only if and when WS4 accepts a contribution, and adds that the founding maintainer's participation terms under it, including how the non-assert interacts with existing Opaque patent filings, require counsel sign-off before any contribution is filed. §10.3 of the spec carries the same gate. Trademark transfer is marked to be determined rather than asserted.Also updated
CHARTER.md§9 timeline now matches the actual CoSAI sequence (Phase 1 review to Aug 9 2026, revised spec returned Aug 2026, WS4 contribution decision Q4 2026, v1.0 ratification 2027) rather than the old AAIF milestones, and the status line states plainly that Phase 1 is a review pass and not a request to accept.🤖 Generated with Claude Code