{"schema_version":1,"research_id":"eoa_inverse_innovation_exp03_external48_20260801","source_assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","cell_id":"layer_decay_and_expiration_management__tech_ethics_ai_governance","selection_stratum":"HIGH_UPSIDE_RESEARCH_OPTION","search_queries":["site:nist.gov AI RMF Playbook inventory documentation lifecycle version changes governance artifacts","policy exception management expiration review date official documentation","site:servicenow.com/docs policy exception expiration indicator exception management","site:ibm.com/docs OpenPages policy exception expiration review date","site:microsoft.com Purview records disposition review legal hold official","site:ibm.com/docs watsonx governance factsheet model lifecycle version governance review approval","site:learn.microsoft.com AI governance model inventory lifecycle approval version official","study model cards outdated documentation maintained AI governance artifacts empirical","AI governance documentation lifecycle audit evidence study organizations","site:eur-lex.europa.eu Regulation 2024/1689 technical documentation kept up to date version logs retention Article 11 12","site:nist.gov AI RMF Playbook documentation retained older versions change management inventory","site:learn.microsoft.com/en-us/purview retention legal hold takes precedence deletion preservation official","site:canada.ca documented disposition records retention trigger rationale audit official","site:eur-lex.europa.eu Regulation 2026/1744 Article 11 2024/1689 amendment technical documentation"],"sources":[{"source_id":"S1","title":"NIST AI RMF Playbook — Govern","publisher":"National Institute of Standards and Technology, AI Resource Center","url":"https://airc.nist.gov/airmf-resources/playbook/govern/","source_class":"OFFICIAL_GUIDANCE","publication_date":"2023-03-30; updated through 2026","accessed_at":"2026-08-02","claims_supported":["Organizations should keep AI documentation current, regularly review documentation inventories, assign inventory maintainers, and document dependencies and change-management plans.","AI-system decommissioning should consider linked-system dependencies, retention duties, investigations, replacement systems, accountability, and preservation of related artifacts.","Indiscriminate termination or deletion can increase organizational risk."]},{"source_id":"S2","title":"Regulation (EU) 2024/1689 (Artificial Intelligence Act)","publisher":"Official Journal of the European Union / EUR-Lex","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689","source_class":"GOVERNMENT_OR_REGULATOR","publication_date":"2024-07-12","accessed_at":"2026-08-02","claims_supported":["The Act requires specified high-risk-system technical documentation to be kept up to date.","Annex IV calls for system-version relationships, relevant software versions, dated testing reports, and descriptions of lifecycle changes.","The Act provides an official basis for organizational and regulatory interest in current, traceable AI documentation; applicability depends on system classification and the amended implementation schedule."]},{"source_id":"S3","title":"What's documented in AI? Systematic Analysis of 32K AI Model Cards","publisher":"Liang et al.; arXiv preprint with released analysis code","url":"https://arxiv.org/abs/2402.05160","source_class":"PRIMARY_RESEARCH","publication_date":"2024-02-07","accessed_at":"2026-08-02","claims_supported":["The study analyzed 74,970 Hugging Face model repositories and 32,111 model cards.","Only 44.2% of sampled repositories had model cards, and evaluation and limitations sections appeared in 15.4% and 17.4% of cards respectively.","The study establishes documentation incompleteness in a public model-repository population, but does not measure stale internal approvals, exceptions, or mistaken authority reliance."]},{"source_id":"S4","title":"Improving Governance Outcomes Through AI Documentation: Bridging Theory and Practice","publisher":"Winecoff and Bogen; Center for Democracy & Technology / CHI research","url":"https://arxiv.org/abs/2409.08960","source_class":"PRIMARY_RESEARCH","publication_date":"2024-09-13","accessed_at":"2026-08-02","claims_supported":["The review analyzed 37 proposed documentation frameworks and 22 empirical studies.","Empirical findings identify resource, incentive, communication, workflow-integration, and organizational barriers to effective AI documentation.","Direct empirical evidence that documentation interventions improve governance outcomes remains limited, supporting controlled pilot evaluation rather than assumed benefit."]},{"source_id":"S5","title":"Request a policy exception using the Compliance Workspace","publisher":"ServiceNow","url":"https://www.servicenow.com/docs/r/governance-risk-compliance/grc-compliance-management-workspace/request-policy-exception-ws.html","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"2026-03-12","accessed_at":"2026-08-02","claims_supported":["ServiceNow policy exceptions can be bound to policies, controls, issues, and target records.","The workflow records valid-from and valid-to dates, duration, extensions, approvers, risk assessments, mitigation plans, confidentiality, and work notes.","Commercial prior art therefore already implements temporary exception authority and accountable review."]},{"source_id":"S6","title":"Governance artifact properties and relationships","publisher":"IBM watsonx.data intelligence documentation","url":"https://www.ibm.com/docs/en/watsonx/wdi/2.4.x?topic=artifacts-governance-artifact-properties","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"undated product documentation","accessed_at":"2026-08-02","claims_supported":["IBM governance artifacts support custom properties and relationships, effective dates, activity logs, approval states, and versioning.","Publishing a new version can make the previous version inactive; future versions can be scheduled to replace an active version.","Historical versions can be tracked, archived, or restored, substantially overlapping the proposed authority-state and supersession mechanism."]},{"source_id":"S7","title":"Governing assets with watsonx.governance","publisher":"IBM","url":"https://www.ibm.com/docs/en/watsonx/w-and-w/2.3.x?topic=ai-governing-assets-watsonxgovernance","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","publication_date":"undated product documentation","accessed_at":"2026-08-02","claims_supported":["Watsonx.governance tracks AI use cases, model and prompt-template metadata, multiple model versions, lifecycle state, deployments, evaluations, and stakeholder workflows.","Its factsheets and governance console demonstrate technical feasibility for AI-specific inventories and version-bound governance metadata.","The documentation does not establish the candidate's full cross-artifact expiration, hold, dependency, and current-authority composition."]},{"source_id":"S8","title":"Guidelines on Documented Disposition of Records","publisher":"Library and Archives Canada","url":"https://www.canada.ca/en/library-archives/services/government/information-disposition/management/guidelines/documented-disposition-records.html","source_class":"OFFICIAL_GUIDANCE","publication_date":"2026","accessed_at":"2026-08-02","claims_supported":["Disposition should be procedural, auditable, classified, retention-governed, and approved by the responsible office.","Potential legal and access-request holds must be checked, and relevant information reverified when a retention period expires.","Disposition decisions, authorization, record metadata, completion evidence, and sometimes audit logs should themselves be preserved."]}],"problem_evidence":{"support":"WEAK","rationale":"The exact diagnosed prevalence—stale internal AI approvals, exceptions, conditions, and mitigation commitments being mistaken for current authority—was not found in a representative audit. NIST nevertheless recognizes the component hazards by calling for current documentation, maintained inventories, periodic review, dependency-aware decommissioning, and preservation for investigations. EU documentation rules make version relationships and lifecycle changes materially relevant. The large model-card study demonstrates substantial documentation incompleteness, but its public-repository population and fields are only indirect evidence for the candidate's internal-governance failure mode.","source_ids":["S1","S2","S3","S4"]},"stakeholder_evidence":{"support":"MODERATE","rationale":"Official guidance and law identify organizations, responsible maintainers, providers, oversight actors, records officials, and affected communities as parties with interests or duties concerning current documentation, traceability, preservation, and decommissioning. ServiceNow's implemented workflow assigns control, compliance, risk, and approval roles, showing an operational adopter pattern. No source establishes demand specifically for the proposed integrated lifecycle registry or willingness to fund it.","source_ids":["S1","S2","S5","S8"]},"prior_art":{"proximity":"SUBSTANTIAL_COLLISION","closest_analogues":[{"name":"NIST AI RMF Playbook Govern 1.4, 1.6, and 1.7","similarity":"Covers current and regularly reviewed AI documentation; artifact-bearing AI inventories with named maintainers; dependency-aware decommissioning; retention rules; replacement migration; investigation needs; accountability; and preservation of related artifacts.","remaining_difference":"It is voluntary guidance rather than an implemented registry, and it does not specify a single lifecycle state machine for risk acceptances, approval conditions, model cards, and mitigation commitments or experimentally test removal from current-authority views.","source_ids":["S1"]},{"name":"ServiceNow Policy and Compliance Management policy-exception workflow","similarity":"Implements temporary exceptions linked to policies, controls, issues, and target records, with validity dates, extensions, approvers, risk review, mitigation plans, confidentiality, and notes.","remaining_difference":"The opened documentation does not show system-version binding, cross-class successor links, legal-hold and dependency-gated disposition, current-authority filtering, or archival-recovery testing for the full set of AI-governance artifacts.","source_ids":["S5"]},{"name":"IBM governance artifacts plus watsonx.governance","similarity":"Together provide AI lifecycle inventories and factsheets, multiple model versions, customizable governance-artifact relationships, effective dates, active/inactive states, scheduled supersession, activity logs, approvals, archiving, and restoration.","remaining_difference":"The opened documentation does not establish a unified workflow that expires operational authority across all AI-governance artifact classes while applying records holds and dependency gates, preserving deletion markers, and testing reviewer applicability accuracy.","source_ids":["S6","S7"]},{"name":"Library and Archives Canada documented-disposition process","similarity":"Provides retention specifications, classification, hold checks, responsible-office approval, revalidation at expiration, auditable disposition records, and preservation of disposition metadata.","remaining_difference":"It governs evidentiary retention and disposition rather than the separate normative question of which AI-governance artifact is currently authoritative for a particular deployed system version.","source_ids":["S8"]}],"distinctive_claim_remaining":"A testable residual claim remains: for one AI service, a single read-only overlay spanning exceptions, approvals, conditions, model cards, and mitigation commitments—and binding each item to owner, AI-system version, authority state, review date, successor, dependencies, and hold status—will improve blinded identification of currently applicable artifacts over the organization's incumbent ServiceNow-, IBM-, repository-, or document-based views, while producing zero missed active controls, protected-record classifications, impaired review rights, or failed archive-retrieval tests. The mechanisms themselves are largely established; their cross-artifact composition and comparative effect are not.","confidence":"HIGH"},"implementation_evidence":{"support":"MODERATE","rationale":"Official product documentation demonstrates that effective dating, exception validity, roles, custom relationships, version supersession, lifecycle inventories, audit logs, archiving, restoration, and hold-aware disposition are individually implementable using existing platforms. This supports a read-only overlay without inventing new infrastructure. No source demonstrates the exact integrated composition, reliable automated dependency discovery, or safe multi-service operation.","source_ids":["S5","S6","S7","S8"]},"scores":{"meaningful_impact":{"score":3,"rationale":"Current, version-related AI documentation and preserved accountability evidence are recognized needs, and incomplete model documentation is empirically observed. Impact could be material where stale authority changes decisions, but neither its prevalence nor resulting harm rate has been measured.","source_ids":["S1","S2","S3"]},"stakeholder_pull":{"score":3,"rationale":"Regulators, AI-system owners, governance teams, records officials, compliance managers, risk managers, and affected communities have identifiable interests, while first-party products support related workflows. Direct adoption inquiries and budget commitment for this composition are absent.","source_ids":["S1","S2","S5","S8"]},"incremental_advantage":{"score":2,"rationale":"NIST guidance and existing ServiceNow and IBM capabilities cover most proposed components. The remaining advantage is a cross-artifact, AI-version-bound current-authority overlay with hold/dependency gates and a measured reviewer benefit; that advantage has not been demonstrated.","source_ids":["S1","S5","S6","S7","S8"]},"distinctiveness_plausibility":{"score":2,"rationale":"The search found substantial conceptual and product collision across NIST, ServiceNow, IBM, and established records disposition. No single opened source showed the exact composition, but the residual appears integrative rather than a new underlying mechanism.","source_ids":["S1","S5","S6","S7","S8"]},"technical_implementability":{"score":4,"rationale":"Existing products implement the principal metadata fields, workflows, effective dates, versions, relationships, approvals, archives, and audit records. The main technical uncertainty is extracting dependable system bindings, dependencies, and hold status from heterogeneous repositories.","source_ids":["S5","S6","S7","S8"]},"adoption_authority_feasibility":{"score":3,"rationale":"The sources identify workable responsible roles, approval groups, oversight actors, and records authorities. Feasibility is reduced by cross-functional vetoes and by the need to distinguish normative authority from records disposition rather than letting one function decide both.","source_ids":["S1","S5","S8"]},"evidence_readiness":{"score":4,"rationale":"A read-only, blinded comparison can be run with conventional repositories and expert adjudication. This directly addresses the research literature's finding that governance-documentation benefits are insufficiently validated and should be evaluated empirically in organizational context.","source_ids":["S4","S5","S6","S7"]},"safety_net_benefit":{"score":5,"rationale":"Separating current operational visibility from destruction, checking holds, requiring accountable approval, preserving disposition evidence, and testing retrieval directly address risks recognized by NIST and records-management guidance.","source_ids":["S1","S8"]},"scalability":{"score":3,"rationale":"Reusable platform features and custom relationships make replication plausible, but heterogeneous repositories, legal regimes, artifact taxonomies, access controls, and human adjudication create scaling friction. No multi-service evidence was found.","source_ids":["S5","S6","S7","S8"]}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"50K_TO_250K","scope":"Eight-week, read-only study of one AI service and approximately 120 stratified artifacts. Includes governance and records labor, system-owner and affected-party-advocate review, data access and metadata extraction, compliance and legal-hold checks, coordination, ordinary workstation or cloud equipment, lightweight registry or analysis software, blinded evaluation, retrieval testing on copies, and reporting.","confidence":"MODERATE","assumptions":["Artifacts are accessible from no more than three repositories.","No production permissions, authority states, retention rules, or documents are changed.","Existing identity, ticketing, document, and AI-inventory systems can export metadata.","Four to six specialists participate part-time; procurement and litigation discovery are excluded."],"source_ids":["S4","S5","S6","S7","S8"]},"initial_deployment_startup":{"band_2026_usd":"250K_TO_1M","scope":"Production-capable implementation for an initial set of AI services, including engineering and governance labor, repository data mapping and cleanup, compliance and records design, cross-functional coordination, secure infrastructure and equipment, platform licenses or configuration, connectors, access controls, lifecycle taxonomy, version and successor binding, hold and dependency checks, audit logging, quarantine, recovery tests, security assessment, and independent evaluation.","confidence":"LOW","assumptions":["Three to six repositories require connectors or configuration.","Existing GRC, records, identity, and AI-inventory platforms are reused rather than replaced.","Legacy metadata requires material but bounded human adjudication.","Pricing and internal labor rates were not available in the opened sources."],"source_ids":["S5","S6","S7","S8"]},"operational_launch":{"band_2026_usd":"1M_TO_5M","scope":"Multi-service or multi-business-unit launch including engineering, governance operations, data migration and legacy adjudication, compliance and privacy validation, stakeholder coordination, production infrastructure and equipment, enterprise software licensing and integration, training, access-control rollout, archival-recovery exercises, safety monitoring, and launch evaluation.","confidence":"LOW","assumptions":["The organization has a moderate portfolio of governed AI services and heterogeneous legacy records.","Human review remains necessary for normative authority and contested dependencies.","The scope excludes replacement of enterprise document, ticketing, GRC, and records platforms.","No major litigation, regulator response, or international data migration occurs during launch."],"source_ids":["S5","S6","S7","S8"]},"annual_recurring":{"band_2026_usd":"250K_TO_1M","scope":"Recurring owner recertification and exception review, records and legal-hold administration, metadata stewardship, data-quality remediation, cross-functional governance coordination, secure hosting and equipment replacement, software licenses, connector maintenance, access reviews, audits, restoration exercises, training, incident support, and comparative effectiveness monitoring.","confidence":"LOW","assumptions":["Initial multi-service scope remains stable.","Reviews are risk-tiered and partly manual.","Existing enterprise identity, records, and workflow platforms remain available.","Unusual litigation, investigation, breach, or regulatory-response surges are excluded."],"source_ids":["S1","S5","S6","S7","S8"]}},"verified_pipeline_gates":{"externally_supported_problem":{"status":"YES","reason":"Official sources recognize that AI documentation should remain current and version-related, that inventories need maintainers and periodic review, and that indiscriminate deletion can damage legal, forensic, dependency, and accountability interests. The exact prevalence and mistaken-reliance rate remain unverified.","source_ids":["S1","S2","S3"]},"externally_credible_adopter_or_authorizer":{"status":"YES","reason":"AI providers and operators, accountable AI-governance functions, control and compliance managers, risk managers, system owners, and records authorities are identifiable in official guidance, law, and implemented workflows.","source_ids":["S1","S2","S5","S8"]},"distinct_testable_incremental_claim":{"status":"YES","reason":"Despite substantial prior-art overlap, the residual claim compares one cross-artifact, AI-version-bound current-authority overlay against incumbent repository or product views on blinded applicability accuracy and preset safety outcomes.","source_ids":["S1","S5","S6","S7","S8"]},"bounded_next_evidence_step":{"status":"YES","reason":"A one-service, eight-week retrospective study can use frozen read-only copies, parallel blinded reviewers, expert gold-standard adjudication, and explicit benefit and safety falsifiers without live deployment.","source_ids":["S4","S5","S6","S7"]},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"For the read-only study only, no artifact is hidden, deleted, reclassified, or made authoritative. Hold verification, responsible-office approval principles, preserved evidence, and retrieval tests provide credible safeguards. This gate does not authorize operational deployment.","source_ids":["S1","S8"]},"credible_cost_scope_and_range":{"status":"UNCERTAIN","reason":"The bands include relevant labor, data, compliance, coordination, equipment, software, integration, and evaluation and are consistent with the demonstrated breadth of platform capabilities. No opened source supplied comparable project prices, artifact volumes, internal rates, license terms, or connector counts, so the bands remain assumption-dependent.","source_ids":["S5","S6","S7","S8"]}},"next_evidence_step":"Pre-register an eight-week retrospective study on one AI service using 120 stratified exception, approval, condition, model-card, and mitigation artifacts. Freeze read-only copies; have an independent governance, records/legal, system-owner, and affected-party-advocate panel establish the applicable/superseded/evidence-only gold standard. Randomize blinded reviewers to the incumbent repository or product view versus the lifecycle-gating overlay, then compare exact applicability classification, decision time, and confidence. Require the lower bound of the 95% confidence interval for improvement in classification accuracy to exceed five percentage points. Reject the intervention if it misses any active control, labels any held or appeal-relevant record as destructible, impairs a review right, fails retrieval of any archived test copy within the preset service level, or fails the accuracy threshold. Make no live authority, visibility, retention, or deletion changes.","blocking_evidence":["No representative organizational audit measures missing owner, lifecycle, system-version, review-date, successor, dependency, or hold fields, or mistaken reliance on superseded artifacts; S3 is only indirect public-repository evidence.","No controlled study demonstrates that this composition improves current-applicability judgments; S4 finds direct evidence for documentation-driven governance outcomes limited.","Hands-on product mapping is needed to determine whether an organization's existing ServiceNow, IBM, records, or custom configuration already supplies the residual composition identified from S5-S8.","The reliability and cost of extracting inbound dependencies, legal duties, affected-party protections, and AI-version bindings from real repositories are unknown.","No direct 2026 cost, staffing, license, connector, migration-volume, or recurring-workload evidence was found.","No evidence establishes that archive tiers preserve timely appeals and investigations across the candidate adopter's actual access-control environment."],"research_disposition":"PILOT_OR_ADOPTION_INQUIRY","world_novelty_boundary":"This was a bounded web search of official guidance, law, primary research, and first-party product documentation, not an exhaustive patent, source-code, procurement, or private-configuration search. It found substantial collision with NIST lifecycle guidance, ServiceNow exception expiry, IBM artifact versioning and AI inventories, and established records-disposition controls (S1, S5-S8). It did not find one opened source demonstrating the exact cross-artifact composition and comparative reviewer effect. That absence is not evidence of world novelty."}