{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-008.json",
  "source": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-EVAL-008",
    "profile": "evaluation-environment",
    "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-008.json",
    "title": "Harness and Configuration Attestation",
    "version": "0.2",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "specified",
    "objective": "The harness, prompts, tool definitions and configuration a run used are versioned and hashed, so the result can be tied to exactly what was evaluated.",
    "failureModes": [
      "A result is reported without the hashes of the prompts, tool definitions and harness it ran on.",
      "A tool definition changes between admission and the run without an alert.",
      "The configuration in the report differs from the one recorded for the run.",
      "Two results are compared although they ran on different scaffold prompts or task wordings, which can change the behaviour being measured."
    ],
    "scope": "The harness, system and scaffold prompts, task instructions, tool and MCP server definitions, policy bundles, scoring configuration and model artefacts a run loads. The design of the evaluation tasks is out of scope.",
    "enforcementPoints": [
      "pre_merge",
      "deploy"
    ],
    "verification": [
      {
        "kind": "inspect",
        "text": "Before the run, inspect the run manifest: it lists, each with a version and a hash, the harness, the system and scaffold prompts, the task instructions, the tool and MCP server definitions, the policy bundles, the scoring configuration, and the model identifier with its settings."
      },
      {
        "kind": "test",
        "text": "At admission, recompute the hash of every artefact the environment actually loaded and compare it with the manifest: every hash must match. On a copy of the environment, change one tool definition: the run must be blocked with an alert."
      },
      {
        "kind": "inspect",
        "text": "Before a result is released, compare the configuration stated in the report (model, reasoning setting, tool access, harness, safeguards and budget) with the manifests of the runs behind it: they must agree, and results compared with each other must share scaffold prompts and task wording or state the difference."
      }
    ],
    "evidence": [
      {
        "artefact": "Run manifest: version and hash of every artefact the run loaded, recorded before the run outside the environment",
        "schemaId": null,
        "schema": null,
        "layer": 3
      },
      {
        "artefact": "Admission check: the recomputed hashes against the manifest, with its verdict",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 3
      },
      {
        "artefact": "Test report stating the tested system, budget and environment of its results, with links to the run manifests",
        "schemaId": "test-report",
        "schema": "https://aigovernanceengineer.com/schemas/test-report.v1.json",
        "layer": 3
      },
      {
        "artefact": "Manifest check of each run, filed as an observation of this control",
        "schemaId": "control-observation",
        "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A run whose loaded artefacts do not match its manifest is not started, and a change detected during a run stops it. A result whose report does not match the manifests of its runs is not released until the difference is explained or the runs are repeated."
    },
    "layer": 3,
    "secondaryLayers": [
      2
    ],
    "patterns": [
      {
        "slug": "model-artefact-integrity",
        "title": "Model Artefact Integrity",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
      },
      {
        "slug": "aibom",
        "title": "AIBOM",
        "url": "https://aigovernanceengineer.com/patterns/aibom"
      },
      {
        "slug": "eval-gate-in-ci",
        "title": "Eval Gate in CI",
        "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
      }
    ],
    "seeds": [
      {
        "id": "prompt-change-control",
        "title": "Prompts under change control",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control"
      },
      {
        "id": "mcp-admission",
        "title": "MCP server admission gate",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-OWASP-AIBOM",
          "name": "AIBOM",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom"
        },
        {
          "id": "AIGE-OBL-ISO42001-A6",
          "name": "A.6 AI system life cycle",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.4",
          "title": "AI system verification and validation"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MEASURE 2.1",
          "title": "Test sets, metrics, and details about the tools used during TEVV are documented."
        }
      ],
      "owasp": [
        {
          "id": "asi04",
          "externalId": "ASI04",
          "name": "Agentic Supply Chain Vulnerabilities",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
        },
        {
          "id": "llm04-2026",
          "externalId": "LLM04:2026",
          "name": "Supply Chain",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
        }
      ],
      "atlas": [
        {
          "id": "aml-t0110",
          "externalId": "AML.T0110",
          "name": "AI Agent Tool Poisoning",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0110"
        },
        {
          "id": "aml-t0010",
          "externalId": "AML.T0010",
          "name": "AI Supply Chain Compromise",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
        }
      ],
      "aiuc1": [],
      "csaAicm": [],
      "other": [
        {
          "framework": "MITRE ATLAS mitigation",
          "ref": "AML.M0014",
          "note": "Verify AI Artifacts"
        },
        {
          "framework": "MITRE ATLAS mitigation",
          "ref": "AML.M0023",
          "note": "AI Bill of Materials"
        },
        {
          "framework": "NIST SP 800-218A",
          "ref": "PS.1.3",
          "note": "Protect model weights and configuration parameters"
        },
        {
          "framework": "NIST SP 800-218A",
          "ref": "PS.3.2",
          "note": "Keep provenance data for every component of a release"
        },
        {
          "framework": "NIST SP 800-53 Rev. 5",
          "ref": "CM-2",
          "note": "Baseline Configuration"
        },
        {
          "framework": "NIST SP 800-53 Rev. 5",
          "ref": "CM-3",
          "note": "Configuration Change Control"
        },
        {
          "framework": "NIST SP 800-53 Rev. 5",
          "ref": "CM-6",
          "note": "Configuration Settings"
        }
      ]
    },
    "references": [
      {
        "n": 56,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Prompts as configuration under change control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control",
        "verified": "primary"
      },
      {
        "n": 29,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Admitting an MCP server\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server",
        "verified": "primary"
      },
      {
        "n": 57,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
        "verified": "primary"
      },
      {
        "n": 58,
        "title": "Summary of METR's predeployment evaluation of GPT-5.6 Sol",
        "text": "Summary of METR's predeployment evaluation of GPT-5.6 Sol (METR states that \"observed cheating rates can also be influenced by the prompts used in the evaluation scaffold\" and by task wording). METR. 2026-06-26.",
        "url": "https://metr.org/blog/2026-06-26-gpt-5-6-sol/",
        "verified": "primary"
      },
      {
        "n": 59,
        "title": "NIST SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile",
        "text": "NIST SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (AI-specific tasks added to SSDF 1.1 (e.g. PO.5.3, PS.1.3, PW.3.1 to PW.3.3) and AI-specific recommendations on existing tasks (e.g. PW.1.1, RV.1.1)). NIST. 2024-07.",
        "url": "https://csrc.nist.gov/pubs/sp/800/218/a/final",
        "verified": "primary"
      },
      {
        "n": 17,
        "title": "MITRE ATLAS data, release v2026.09",
        "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
        "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
        "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
        "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Improving our alignment and security efforts",
        "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
        "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
        "verified": "primary"
      },
      {
        "n": 60,
        "title": "A shared playbook for trustworthy third party evaluations",
        "text": "A shared playbook for trustworthy third party evaluations (recommended report fields include the claim, the tested system (model, reasoning setting, tool access, harness and safeguards), the budget, elicitation methods and validity checks; a score is \"performance under that harness and budget\"). OpenAI. 2026-05-29.",
        "url": "https://openai.com/index/trustworthy-third-party-evaluations-foundations/",
        "verified": "primary"
      },
      {
        "n": 61,
        "title": "Investigating the consequences of accidentally grading CoT during RL",
        "text": "Investigating the consequences of accidentally grading CoT during RL (chain-of-thought text reached the inputs of reward mechanisms by accident; an automated system now scans all RL runs for it with regex matches). OpenAI (Alignment Research Blog). 2026-05-07.",
        "url": "https://alignment.openai.com/accidental-cot-grading/",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Hash what the run loads, not what the repository holds: build the manifest at admission from the artefacts inside the environment (harness image digest, prompts, task instructions, tool and MCP server definitions, policy bundles, scoring configuration, model identifier and settings), store it outside the environment and put its digest in the run record. Chapter 23 treats prompts, tool descriptions and policy bundles as configuration under change control, with the hash recorded in the registry and in every trace.",
      "Check the configuration before each run, not once per environment: Anthropic's guidance for external evaluation partners states that the isolation configuration \"should be verified before every evaluation begins\".",
      "Report the configuration with the result. OpenAI's playbook for third-party evaluations asks reports to state the tested system (model, reasoning setting, tool access, harness and safeguards) and the budget, and to describe a score as \"performance under that harness and budget, not as a measured capability ceiling\".",
      "Put the scoring path and the scaffold prompts in the manifest too. OpenAI's alignment blog describes chain-of-thought text reaching the inputs of reward mechanisms by accident during RL, now caught by an automated scan whose coverage OpenAI says is not perfect; METR states that observed cheating rates \"can also be influenced by the prompts used in the evaluation scaffold\" and by the wording of task instructions."
    ],
    "openQuestions": [
      "How should evaluation-harness configuration be attested so that a third party can verify it without access to the harness itself?",
      "When a third party runs the evaluation, who signs the manifest: the evaluator, the developer of the model or both?"
    ],
    "observation": {
      "subjectKind": "harness",
      "expected": "Every artefact the run loaded matches the version and hash in its manifest, and the report states the same configuration as the manifests of its runs.",
      "observedExample": "Run 88270: 41 artefacts hashed at admission, all matching the manifest; the report states the same model, tools, harness and budget: pass."
    },
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": [
      {
        "status": "pass",
        "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-008.pass.json"
      },
      {
        "status": "fail",
        "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-008.fail.json"
      }
    ]
  }
}
