AI Policy Wiki
Dashboard

Gap Scan — 2026-07-28

Daily gap hunt — what the wiki is missing and how each gap was triaged.

Scanned

Recent window: 1 dev-log file in the last 48h (2026-07-27-2205-ai-developments.md, 13 sources, 10 enriched); the 07-27 08:20 file and the 07-27 backfill report were already processed. Rotation slice: 12 — sources/ I–P (126 pages).

Wiki-wide broken-link scan run across all 1,199 content pages. Scanner note: the top of the broken-link ranking is dominated by escaped-pipe artifacts (companies/anthropic\, models/gpt-55\, and 14 others) produced by [[target\|Alias]] inside markdown tables. These are not gaps. This is the same bin/lint-scan.py target-capture bug the 07-26 run diagnosed and the 07-27 run confirmed; it is still unapplied and still lint's lane. Two further false positives were filtered: the literal [[sources/...]] and [[wikilinks]] placeholders in documentation prose.

Gaps actioned (5 of 23 found)

New pages created (live)

  • Foundation Models (score ~6) — gap type 8, and a defect the ordinary broken-link scan cannot see. No page links [[concepts/foundation-models]], so in-degree reads as zero — but Frontier Models was self-linking twice to stand in for it: once inline ([[concepts/frontier-models|foundation models]] in its own lead sentence, a link that resolves to the page it sits on) and once as a typed relationship (related: [[concepts/frontier-models]] — frontier models are the leading-edge subset of foundation models, a page declaring itself a subset of itself). Both were plainly written intending a foundation-models target. Alias resolution confirmed no existing page covers the term: concepts/frontier-models, concepts/general-purpose-ai, concepts/dual-use-frontier-ai, concepts/open-weight-frontier-models and concepts/jagged-frontier all address adjacent but distinct subjects, and general-purpose-ai is explicitly the EU regulatory term, not the technical one. Flagged as a below-threshold candidate on 07-24, 07-25, 07-26 and 07-27, each time as "the strongest of these."

Built from the primary source on two canonical hosts — the arXiv abstract page for 2108.07258 and the CRFM report PDF on crfm.stanford.edu — with the coinage rationale ("to underscore their critically central yet incomplete character"), the emergence-and-homogenization pairing quoted verbatim, the inherited-defect argument, the "high-leverage single point of failure" characterisation, and the Steinhardt commentary as attributed contemporaneous dispute. The substantive content beyond the origin section is a four-way disambiguation table setting the CRFM technical definition against the EU AI Act Art. 3(63) GPAI-model definition, EO 14110's dual-use foundation model definition and the Anderljung frontier-model framing, with the containment relationships stated and the regulatory definitions taken from the wiki's own EU AI Act (Regulation 2024/1689) and Executive Order 14110 — Safe, Secure, and Trustworthy AI source pages rather than re-derived. medium, sources 4.

Pages expanded (live)

  • Managing Advanced Cyber Risks in Frontier AI Frameworks (score ~7) — the slice's largest reliance/depth mismatch and the one sitting on the week's live thread. In-degree 25 against 416 words summarizing a 9,953-word raw source — a 24:1 ratio, the worst in the slice — with sources_count absent and last_updated 2026-06-06. Deepened to roughly 2,900 words directly from Raw Sources/Managing Advanced Cyber Risks in Frontier AI Frameworks.md, the primary text, not the web.

Added: the dual-use framing the report opens with; the full seven-component threat-modeling section (kill chains via Cyber Kill Chain, MITRE ATT&CK and STRIDE; assumption articulation; threat-scenario identification anchored on NotPetya and the Morris Worm; bottleneck projection; risk-factor mapping via OWASP Top 10 and Mandiant M-Trends; explicit threat-model-to-evaluation mapping; continuous updating); the stated tradeoff for each of the four threshold types, restructured as a table, plus the report's proposed mixed approach of compute-as-scope-signal followed by reference-model benchmarking; the full Table 1 of published cyber thresholds for all six member firms — Amazon, Anthropic, Google, Meta, Microsoft and OpenAI — which the page previously did not carry at all despite its own Relationships section referencing "the comparison table"; the five points of divergence the report identifies, including the undefined meaning of "significant" uplift, the near-total absence of APT-actor treatment in frameworks, the cumulative-versus-single-actor uplift question, and the absent consensus on what constitutes a security "best practice"; per-method limitations for all five evaluation methods (elicitation non-standardization, the instructed-objective divergence from real threat-actor conditions, training-data contamination, benchmark saturation, and the absence of defenders in cyber-range environments); the nine-benchmark table with citing firms; the six evaluation domains; the five bottleneck assessments and the cumulative-evidence rule; the complete three-level safeguard taxonomy and all five safeguard categories with their recorded limitations; the three mitigation-assessment approaches and the argument that mitigation assessments outlive capability benchmarks because safeguards do not saturate; and the three continuing-work areas including the explicit statement that acceptable risk–benefit tradeoffs are not for developers to determine alone.

Frontmatter repaired (sources_count 1, source_url added, national-security tag). Typed relationships extended to Autonomous cyber-agents, OpenAI Preparedness Framework V.2 and Anthropic's Responsible Scaling Policy (Version 3.1) — the last two being the sources of thresholds the report reproduces, a connection the page did not previously make. Confidence stays medium: the primary text is now fully read, but it remains a single source and the threshold table is explicitly stated as accurate only as of January 2026, which is outside the 3-month fast-decay window for capability claims. Every prior fact, citation and relationship preserved; original backed up in _meta/_revision-backups/2026-07-28/.

  • OpenAI — Industrial Policy for the Intelligence Age (score ~5) — 391 words against a 5,457-word raw source at in-degree 15, stale since 06-06, sources_count absent. The prior page carried the four pillars and nothing of the twenty proposals that constitute the document. Deepened to roughly 2,400 words from the raw file.

Added: the definition of superintelligence the document uses and its stated epistemic posture ("intentionally early and exploratory," US-first but ultimately global); the five named risks; the Progressive Era / New Deal analogy and the explicit limiting principle that markets are presumptively adequate and industrial policy applies only where market forces are insufficient; the public-private sequencing intended to "stave off regulatory capture"; the two near-term positions — that AI data centers "should pay their own way on energy so that households aren't subsidizing them," and that regulation should protect children and mitigate national security risks without entrenching incumbents; the document's acknowledgment that gains may "concentrate within a small number of firms like OpenAI"; all eleven open-economy proposals (worker perspectives, AI-first entrepreneurs, Right to AI, tax-base modernization including taxes on automated labor, the Public Wealth Fund, grid expansion with its narrow federal transmission authority, efficiency dividends including the 32-hour-week pilots, adaptive safety nets with automatic metric-triggered activation, portable benefits, care-economy pathways, and distributed AI-enabled laboratories); all nine resilient-society proposals (safety systems and competitive safety markets, the AI trust stack, auditing regimes via CAISI, model-containment playbooks, mission-aligned corporate governance including auditing for "hidden loyalties," guardrails for government use including FOIA modernization and the federal-records status of agentic action logs, public-input mechanisms, incident and near-miss reporting, and the global network of AI Institutes with its antitrust safe-harbor ask); and the three follow-through commitments including the $100,000 grant and $1M API-credit pilot.

A short provenance paragraph was added recording that this is a company position document and that three of its proposals — audits confined to "a small number of companies and the most advanced models," internationally-adopted standards framed as fragmentation reduction, and the treatment of state regulation as settled upstream landscape — bear on questions where OpenAI is an interested party. Frontmatter repaired (sources_count 1, source_url, energy tag); typed ## Relationships added. Confidence stays medium. Original backed up.

  • [[concepts/frontier-models|foundation models]][[concepts/foundation-models|foundation models]] on Frontier Models (1 instance, inline lead).
  • related: [[concepts/frontier-models]]related: [[concepts/foundation-models]] on Frontier Models (1 instance, self-referential typed relationship removed).

Frontmatter repaired (live)

  • sources_count added to the 10 slice-12 sources/ pages that lacked it: intro-ai-safety-ethics (1), least-understood-driver-of-ai-progress (1), machines-of-loving-grace (1), metr-long-tasks (4), new-york-raise-act (7), oecd-ai-risks-benefits (1), on-the-biology-of-a-llm (1), open-problems-emergent-misalignment (1), premature-antitrust-standards-algorithmic-pricing (1), project-glasswing (3). Counts derived as one (the anchoring raw source) plus the number of distinct inline (Source: URL) citations. The remaining two of the twelve — managing-cyber-risks-frontier-ai and openai-industrial-policy — were repaired as part of their expansions above. last_updated deliberately not bumped on the ten: no substantive content changed. Slice 12 now has zero pages missing sources_count and zero missing source_type.

Queued — foundational sources

  • Caleb Biddulph, "Untrusted advice for AI control: Short, strong advice significantly uplifts weak LLMs" (guest post, Redwood Research blog, 2026-07-27) (score ~8: live thread +3, dangling foundational +3, wiki core area +2) — gap type 1. The third post in Redwood's July 2026 AI-control sequence, and the only one advancing an original empirical claim rather than reading an incident; the first two were queued by the 07-26 scan. The protocol is named on AI Control with a supporting cite only. Verified: blog.redwoodresearch.org (the organization's own domain and the same host as the two queued posts); og:url matches the request URL; og:title matches; HTTP 200; article:modified_time 2026-07-28T00:05:06.979Z UTC, consistent with 07-27 US publication; corroborated by the Redwood blog index and an independent podcast-feed listing carrying the same title; substance matches the dev-log's characterisation of a trusted executor acting under constrained advice from an untrusted advisor. Verified: yes.

Full text not saved to Raw Sources/. Two retrieval attempts (markdown, then structured-JSON extraction) returned a page whose full markdown exceeds the reader's single-response limit; a partial capture would have produced a raw file that looks complete and is not — precisely the failure the v4.7 no-enrichment rule exists to prevent. Per the gap-identifier protocol for artifacts best fetched fresh at ingest time, the queued task carries the verified canonical URL and the ingesting run should fetch the full post. Queued: INGEST-redwood-biddulph-untrusted-advice-2026-07-28.md. Verification trail: queue/gap-scan/proposed-sources/redwood-biddulph-untrusted-advice-2026.md.

Source-fidelity finding recorded in both files. The 07-27 22:05 dev-log attributes the post to "Redwood Research published…" with no author. It is a guest post by Caleb Biddulph. This is the actors left anonymous failure class from .claude/skills/source-fidelity/SKILL.md. The same dev-log entry also marks the item "scraped — read in part only," so the digest paragraph is not a sufficient basis for a sources/ page.

Authenticity-verification failures

None. One source was pulled and it verified.

Deferred backlog (over the daily cap — re-surfaces next run)

  • models/mai-cyber-1-flash — declined on the quality gate, not on score. Microsoft launched MAI-Cyber-1-Flash on 07-27 alongside the Perception agentic security platform; at score ~5 it was inside the cap. Three things fail the gate: the two reports disagree on public-preview availability (August 3 per SiliconANGLE, November 3 per TechCrunch) and the dev-log recorded rather than resolved it; the only capability claim is Suleyman's Cyber Gym quote, with no model card, no published evaluation and no third-party assessment; and in-degree is zero. Creating it today would freeze an unresolved date into the graph. Note filed at queue/gap-scan/needs-review/2026-07-28-mai-cyber-1-flash-quality-gate.md with the three triggers that would make it buildable. Perception and MDASH are named nowhere in the wiki and should fold onto Microsoft rather than get pages.
  • On the Biology of a Large Language Model — routed to source-robustness-check, not expanded here. In-degree 22 at 553 words against a 189,467-word raw file. The ratio looks like the slice's worst mismatch but is misleading: the raw file is the full Transformer Circuits publication including embedded figure data, and the existing page already covers all nine case studies in proportionate summary. Deepening it properly means working through §§ 1–15 of the paper, which is a source-robustness-check job rather than a gap-scan side pass. Backed up alongside the two expanded pages; sources_count repaired.
  • Slice-12 residue, in reliance order. NIST AI Risk Management Framework (AI RMF 1.0) (in-deg 74, 706w, medium/3 — the slice's highest in-degree, but already deepened on 07-14 and the least stale page in the top ten, ~4); New York RAISE Act (S. 8828) (in-deg 73, 2,203w — proportionate, frontmatter only, now repaired); Paris AI Action Summit Declaration (2025) (in-deg 35, 598w, high/1, stale 06-06 — but the raw source is only 1,032 words, so the page is proportionate; the high-on-single-source rating is the real issue, ~3); Machines of Loving Grace (in-deg 28, ~4); Illinois SB 3444 — Artificial Intelligence Safety Act (in-deg 22, ~3); MIT NANDA — The GenAI Divide (State of AI in Business 2025) (in-deg 22, high/1, ~3); OpenAI Model Spec (in-deg 20, 576w, ~3); Lancet Endoscopist Deskilling Study (2025) (in-deg 18, ~3); ICRC Position on Autonomous Weapon Systems (source summary) and International AI Safety Report 2025 (in-deg 17 each — the latter proportionate at 582w against a 756w raw, ~3); Project Glasswing: Securing Critical Software for the AI Era (in-deg 17, 780w, ~3).
  • The high-on-sources_count: 1 question, now measured on a second slice. 82 of 126 slice-12 sources/ pages — 65% — carry confidence: high on sources_count: 1, against 57% measured on slice 11 on 07-27. Two consecutive slices at this rate confirm the 07-27 read: this is an inherited ingest convention, not a set of individual errors, and the fix is a policy decision the curator or lint should make once. Either the decay table's "3+ sources" bar means something different for a sources/ page faithfully summarizing one primary document — in which case CLAUDE.md should say so — or roughly 60% of every sources/ slice is overrated. Not actioned; a wrong call here propagates to 558 pages.
  • bin/lint-scan.py target-capture bug — third consecutive run flagging it. Diagnosed 07-26, confirmed 07-27, confirmed again today: 16 of the top 45 broken-link candidates are escaped-pipe artifacts. Proposed fix unchanged (\[\[([^\]|#]+?)(?:\\?\|[^\]]*)?\]\], or strip a trailing backslash from the captured target). Still unapplied; still lint's lane.
  • Recent-window items the nightly cycle already handled — no gap. entities/open-secure-ai-alliance, entities/leading-the-future and sources/amodei-position-open-weights-2026 all exist as of tonight's fold, and Raw Sources/Our position on open-weights models - Amodei.md is saved. The open-weights thread is currently the best-covered live thread in the wiki.
  • Recent-window items behind tonight's fold: the Consumer Federation of America / UCLA Information Policy Lab FTC complaint against Speechify (an entities/consumer-federation-of-america candidate and a litigation/-adjacent regulatory-complaint item, ~4 — the complaint itself is a foundational source-queue candidate); the Nvidia–SK Group collaboration above $500B stated value and the 07-27 4.99% Nvidia decline (Snapshot rows on Nvidia & TSMC — AI Compute Infrastructure and SK Hynix — HBM Leader); the Claude shared-conversation Google-indexing incident and its September 2025 antecedent (Anthropic and a privacy-concept fold); the Trump administration's near-final voluntary pre-release review framework, retrievable only as a paywalled abstract.
  • Genuine missing-page candidates confirmed by alias resolution but below the in-degree threshold (2 each), carried forward. concepts/foundation-models is now built and comes off this list. Remaining: concepts/economic-possibilities-for-artificial-intelligence, concepts/algorithmic-decisionmaking, concepts/ai-and-language-models, concepts/talent-flow-china-us, concepts/data-broker-regulation, concepts/a-vision-of-democratic-ai, concepts/safety-training-methodologies, concepts/ai-coarse-grainings, concepts/cross-national-ai-policy-tracking, concepts/ai-history, concepts/biometric-identification, concepts/inverse-cooking-problem and concepts/inverse-trust-problem (the last two curator-blocked as coined terms since 07-10); person pages entities/anil-seth, entities/orin-kerr, entities/eric-goldman, entities/kevin-klyman, entities/lee-anne-fennell, entities/michael-j-d-vermeer, entities/sacha-altay, entities/joseph-bernstein, entities/roge-karma, entities/alondra-nelson, entities/clayton-christensen, entities/adam-smith, entities/dina-powell-mccormick, entities/raja-krishnamoorthi, entities/samuel-weinbach, entities/ilhan-scheer, plus entities/david-luan, entities/girish-gupta, entities/alex-mallen and now entities/caleb-biddulph; institutions entities/federal-reserve, entities/ecb, entities/bank-of-england, entities/carnegie-mellon, entities/santa-fe-institute, entities/sais, entities/uw.
  • concepts/compute-thresholds — newly at in-degree 2 and confirmed missing (score ~4, next run's strongest concept candidate). Frontier Models has dangled this link since before today; Foundation Models now dangles it too, since the regulatory-definition table turns on it. Alias resolution: concepts/compute-governance is about export controls and the physical inputs to capability, not the 10²⁵ / 10²⁶ FLOP regulatory lines, and concepts/strategic-compute-reserve is unrelated. The two links were left in place rather than de-linked, so the demand signal is visible to the next scan. A page here would consolidate material currently split across EU AI Act (Regulation 2024/1689) (Art. 51's 10²⁵ FLOP rebuttable presumption), Executive Order 14110 — Safe, Secure, and Trustworthy AI (10²⁶ reporting), California SB 1047 — Safe and Secure Innovation for Frontier AI Models Act (enrolled + veto) (covered models) and General-Purpose AI (GPAI).
  • Two citation-format defects surfaced by the link scan (lint's lane, not gap-identifier's): [[raw sources/raine-vs-openai-et-al-complaint.md]] on Raine v. OpenAI, Inc. and Raine v. OpenAI — Wrongful Death Complaint (2025), and [[raw sources/garcia-v-character-technologies-inc complaint.md]] on Garcia v. Character Technologies — Wrongful Death Complaint (2024) and Garcia v. Character Technologies, Inc.. CLAUDE.md's citation format never wikilinks a raw file; these should be (Source: Raw Sources/…). Four instances across four pages. Also [[_meta/briefings/weekly-2026-w19]] from three pages, which points into _meta/ from mainspace.
  • Carried from prior runs: slice-11 residue (California SB 53 — Transparency in Frontier AI Act at in-deg 234, Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) 178, Executive Order 14365 — Ensuring a National Policy Framework for AI 144, Clawed 105, California SB 243 — Companion Chatbots 98 — the whole slice-11 list is the standing source-robustness-check queue and none of it moved today); the Anthropic's Responsible Scaling Policy (Version 3.1) status: superseded question left for the curator on 07-27; slice-10 analysis/ residue; slice-9 model/industry residue (DeepSeek-V3, DeepSeek-R1, Qwen3, Kimi K2, Gemma (Google open-weight models), Helix (Figure AI Vision-Language-Action model), LongCat-2.0 (Meituan), IsoDDE (Isomorphic Labs), Defense / Military — AI Deployment, Retail — AI Deployment, Energy and Electric Power Sector, Construction — AI Deployment); industries/manufacturing topical hole; slice-8 residue; H.R. 9619 primary text (congress.gov empty body ×4, not retried); METR "expenditure horizon"; Zitron "Subprime Data Center Crisis"; Pethokoukis transformative-AI essay; the OpenAI/Apollo "metagaming" post and the four arXiv papers surfaced by the 07-26 Redwood pulls; METR's May 19 2026 frontier risk report; the Zvi Mowshowitz 07-26 follow-up and the Tech Policy Press CFR/Stanford discussion; the college-admissions-essay homogenization study; Substack-redirect URL upgrades.
  • Standing carries (needs-review): claude-code / claude-cowork placement (curator-blocked, 07-09); inverse-cooking / inverse-trust coined terms (07-10); companies/fairly-trained misfile (07-16); entities/cdao / government/cdao duplicate (lint's lane); the 14 dated dashboard-rebuild-failed notes from June, which no run has revisited in six weeks — worth a curator decision on whether they are still live.

One-line summary

One new concept page built and two self-links behind it repaired, two sources/ pages deepened from primary text (the FMF cyber report by roughly 7×, including a six-firm threshold table the page never carried, and OpenAI's industrial-policy document from four pillars to all twenty proposals), slice-12 frontmatter brought to zero missing fields, and one verified Redwood Research post queued for ingest with a source-fidelity correction attached; the curator's two open decisions are the high-on-single-source convention, now measured at 57% and 65% on two consecutive slices, and whether the June dashboard-rebuild failures are still live.