AI Policy Wiki
Dashboard

Security Disclosure as Due Diligence

medium confidence · updated 2026-07-26

The practice, established in cybersecurity through CVE review, of treating a producer's own structured vulnerability disclosures as the primary artifact for buyer-side risk assessment. Cited alongside SBOM as the precedent for system-card due diligence in AI procurement.

The practice of assessing a product's risk primarily through the producer's own structured disclosures — in cybersecurity, principally CVE records — rather than through independent inspection of the product.

The mechanism

Its defining property is that it converts a producer's admissions into the assessment substrate. A buyer evaluating software does not generally audit the code; they check the disclosure record for the components involved, and treat the presence, timeliness, and specificity of disclosures as a proxy for the producer's security posture.

This creates an incentive structure worth stating plainly, because it transfers to AI: a producer that discloses more appears riskier on a naive reading of the record, while one that discloses less appears safer. Regimes built on disclosure therefore depend on the assessing side reading absence of disclosure as a negative signal rather than a neutral one — which is a norm rather than a mechanism, and takes time to establish.

The AI parallel

Clearwater situates system-card due diligence alongside this practice and SBOM, "describing the shared move as treating the developer's own granular admissions as the central artifact for buyer-side risk assessment" (System Card Due Diligence).

The AI case is currently at the stage the disclosure norm has to pass through. Frontier system cards that disclose more — Meta's pre-mitigation "high risk" Chemical & Biological determination (Muse Spark Safety & Preparedness Report (Meta, May 2026)), OpenAI's report that GPT-5.6 Sol's misalignment rose against its predecessor (GPT-5.6 Preview System Card (OpenAI, June 2026)) — are more informative and, read naively, more alarming than cards that disclose less. Whether procurement and regulatory practice rewards or penalises that candour determines what future cards contain.

Relationships