The practice of assessing a product's risk primarily through the producer's own structured disclosures — in cybersecurity, principally CVE records — rather than through independent inspection of the product.
The mechanism
Its defining property is that it converts a producer's admissions into the assessment substrate. A buyer evaluating software does not generally audit the code; they check the disclosure record for the components involved, and treat the presence, timeliness, and specificity of disclosures as a proxy for the producer's security posture.
This creates an incentive structure worth stating plainly, because it transfers to AI: a producer that discloses more appears riskier on a naive reading of the record, while one that discloses less appears safer. Regimes built on disclosure therefore depend on the assessing side reading absence of disclosure as a negative signal rather than a neutral one — which is a norm rather than a mechanism, and takes time to establish.
The AI parallel
Clearwater situates system-card due diligence alongside this practice and SBOM, "describing the shared move as treating the developer's own granular admissions as the central artifact for buyer-side risk assessment" (System Card Due Diligence).
The AI case is currently at the stage the disclosure norm has to pass through. Frontier system cards that disclose more — Meta's pre-mitigation "high risk" Chemical & Biological determination (Muse Spark Safety & Preparedness Report (Meta, May 2026)), OpenAI's report that GPT-5.6 Sol's misalignment rose against its predecessor (GPT-5.6 Preview System Card (OpenAI, June 2026)) — are more informative and, read naively, more alarming than cards that disclose less. Whether procurement and regulatory practice rewards or penalises that candour determines what future cards contain.
Relationships
- related: System Card Due Diligence — the AI practice for which this is the cited precedent
- related: Software Bill of Materials (SBOM), AI Transparency, AI and Cybersecurity