VELARU MANDATE EXHIBIT PACK — AI MODEL SUPPLY CHAIN PROVENANCE Jurisdiction: New York (us_ny) Modality: Text / Chat Program: Velaru AI Model Supply Chain Provenance · New York (galactic_model_provenance_us_ny) Product ID: model_provenance:us_ny:bundle:text Vertical: model_provenance Generated: 2026-08-18T21:28:29.101297Z Authority: New York AI Governance Pack — GPAI Model Supply Chain Pack Deadline: NYDFS AI guidance + Local Law 144 enforcement Velaru verify: https://velaru.xyz/verify EXHIBIT A — AI INVENTORY [ { "named_entity": "Velari", "slug": "velari", "ai_use_case": "AI-assisted AI Model Supply Chain Provenance decisions", "vertical": "model_provenance", "risk_tier": "elevated", "external_validation": "Velaru independent receipt verification", "handler_receipt_lock": "https://velaru.onrender.com/r/4c58eac890bfd031ce2189de5a1ca9ea292a0c837f5f535daf164aef34f31e53", "compliance_state": "grace_period", "asymmetry_grade": "A", "found_scripture_export": "https://velaru.xyz/bundle/pre-dispute/d8fb129c0c0c78d05256/export.txt", "diligence_url": "https://velaru.xyz/diligence/velari" }, { "named_entity": "LinkAudit Test", "slug": "linkaudit-test", "ai_use_case": "AI-assisted AI Model Supply Chain Provenance decisions", "vertical": "model_provenance", "risk_tier": "elevated", "external_validation": "Velaru independent receipt verification", "handler_receipt_lock": "https://velaru.onrender.com/r/58ddedd1974156453bc55daef6a9857d8570d56388becbb2a80bf5bac76b771b", "compliance_state": "grace_period", "asymmetry_grade": "A", "found_scripture_export": "https://velaru.xyz/bundle/pre-dispute/78aa6e3f3a84cf1a88c0/export.txt", "diligence_url": "https://velaru.xyz/diligence/linkaudit-test" }, { "named_entity": "Link Audit Co", "slug": "link-audit-co", "ai_use_case": "AI-assisted AI Model Supply Chain Provenance decisions", "vertical": "model_provenance", "risk_tier": "elevated", "external_validation": "Velaru independent receipt verification", "handler_receipt_lock": "https://velaru.onrender.com/r/d00533b7b6c0495802b4250abd5c29f60bd9f2ad3fb141bba2d9a5afee5f5542", "compliance_state": "grace_period", "asymmetry_grade": "A", "found_scripture_export": "https://velaru.xyz/bundle/pre-dispute/fea572f3996c4b963779/export.txt", "diligence_url": "https://velaru.xyz/diligence/link-audit-co" } ] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 AI Model Supply Chain Provenance", "exhibit_authority": "New York AI Governance Pack \u2014 GPAI Model Supply Chain Pack", "regulatory_frameworks": [ "EU AI Act Article 53", "NTIA AI Accountability", "NYDFS Circular Letter on AI", "NYC Local Law 144", "Martin Act" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "release model version", "third_party_verification": "https://velaru.xyz/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "Downstream deployer fined for upstream model change \u2014 receipt chain links provider to deployer. \u00b7 Local Law 144 requires annual bias audit \u2014 Velaru receipts are continuous audit, not annual snapshot.", "chain_integrity": { "depth": 491, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "Systemic risk GPAI \u2014 EU requires model evaluation documentation + incident reporting", "global_leaders_addressed": [ "EU AI Office", "Hugging Face", "Meta AI", "Mistral", "NTIA", "NYDFS", "NYC DCWP", "Goldman Sachs" ] } MIRROR TRAP (regulatory insight) Downstream deployer fined for upstream model change — receipt chain links provider to deployer. · Local Law 144 requires annual bias audit — Velaru receipts are continuous audit, not annual snapshot. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "Art 53", "body": "GPAI provider obligations \u2014 technical documentation includes decision logging architecture.", "source": "vertical" }, { "title": "NTIA AI Accountability", "body": "US parallel \u2014 dual compliance with one receipt primitive.", "source": "vertical" }, { "title": "Supply chain", "body": "Fine-tuned model inherits base model liability \u2014 chain of receipts required.", "source": "vertical" }, { "title": "[New York] Financial capital", "body": "NYDFS regulates insurers AND banks \u2014 same receipt primitive for both books.", "source": "jurisdiction" }, { "title": "[New York] Hiring audit law", "body": "NYC AEDT law is template for other cities \u2014 receipt architecture scales municipally.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 3, "compliant": 0, "grace_period": 3, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: GPAI providers · Art 53 applies from Aug 2025 INSURANCE LINES: E&O, IP defense, Cyber DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.