Mission
The Ethos AI Registry exists to make consequential AI systems legible to the public. We publish a searchable record of deployed AI systems, their intended purpose, their operators, and the harms they have been reported to cause — evaluated against an open, NIST-aligned rubric.
Our mission is civic, not commercial. We do not sell scores, accept payment for placement, or offer paid removal of adverse records. The registry is operated by the Algorithmic Accountability Project, an initiative of the TechGeekette Foundation, a US 501(c)(3) public charity.
Governance model
Editorial authority for the registry rests with the Registry Steward, appointed by the TechGeekette Foundation board. The Steward is advised by a rotating Methodology Committee composed of independent researchers, civil-society representatives, and practitioners with deployment experience.
- Registry Steward — final decision on publication, corrections, and appeals; publishes an annual transparency report.
- Methodology Committee — reviews scoring rubric changes; each version is published for public comment before adoption.
- Community Reviewers — vetted volunteers who triage incoming reports; no reviewer may evaluate a system they are employed by or hold a financial interest in.
Conflicts of interest are disclosed publicly on reviewer profiles. Funding sources for the operating nonprofit are published in the annual Form 990 and the transparency report.
Scoring methodology
Every registered system receives a composite Transparency Score from 0 to 100, calculated from a 10-question instrument covering two functions of the NIST AI Risk Management Framework: Govern and Map.
| Response | Points | Interpretation |
|---|---|---|
| Yes | 10 | Control is fully implemented and documented. |
| Partial | 5 | Control is in progress or partially documented. |
| No | 0 | Control is absent or undocumented. |
The Governance subsection contributes 40 points (4 questions) and the Map subsection contributes 60 points (6 questions). The Community Signal — incident reports, verified harms, and framework flags — is displayed alongside but does not modify the composite score. This preserves the integrity of the operator-attested rubric while giving reviewers full context.
Framework mapping
Each rubric question is mapped to at least one external framework so that operators can reuse existing compliance artifacts. Current mappings:
- NIST AI RMF 1.0 — primary rubric spine (Govern, Map).
- ISO/IEC 42001:2023 — governance and lifecycle controls.
- EU AI Act — risk-tier disclosures for high-risk systems.
- OECD AI Principles — transparency and accountability.
The full crosswalk is maintained in the public methodology repository and updated with each framework revision.
Data sources
The registry aggregates and publishes signals from:
- Operator submissions — self-attested system profiles and rubric responses.
- AI Incident Database (AIID) — public, curated harm reports.
- NIST publications — framework updates and technical guidance.
- Community reports — signed submissions from researchers, journalists, and affected communities.
- Regulatory filings — public enforcement actions and disclosures.
Every published record links to its underlying source. Records without a verifiable source are not published.
Submission standards
To be accepted, a submission must include:
- Identifiable operator and system name.
- A description of intended use and deployment context.
- At least one verifiable public reference (URL, filing, or attested document).
- Contact information for correction and appeal.
Community-reported incidents additionally require a first-hand account, a documentary artifact, or a corroborating public source. Anonymous reports are accepted but held to a higher corroboration bar before publication.
Review process
- Intake — automated validation for completeness and duplicates.
- Triage — a Community Reviewer confirms sources and flags conflicts of interest.
- Editorial review — a second reviewer independently confirms the record.
- Operator notice — the named operator is notified with a 10-business-day response window before publication of any adverse record.
- Publication — the record is published with sources, review timestamps, and reviewer identifiers.
Appeals process
Any operator or affected party may file an appeal within 30 days of publication. Appeals are handled by a reviewer not involved in the original decision and resolved within 15 business days.
Outcomes are one of:
- Uphold — record stands; rationale is appended.
- Correct — record is amended; original text and correction are shown together.
- Retract — record is removed with a public notice of retraction.
Records are never silently deleted. The full appeal history is part of the public record.
Update cadence
- Incident feeds — refreshed continuously from AIID and community sources.
- System profiles — re-reviewed at least annually or on material change.
- Scoring rubric — versioned; revisions issued no more than twice per year.
- Methodology document — this page — republished with a dated changelog on each revision.
Transparency principles
- Show the source. Every claim links to a verifiable record.
- Show the reviewer. Every decision has a named, accountable human.
- Show the change. Every correction preserves the original text.
- Show the funding. Operating funds are disclosed annually.
- Show the code. Scoring logic and data schema are open source.
Limitations
Readers should evaluate the registry with these limitations in mind:
- The rubric is operator-attested. It measures disclosed governance, not runtime behavior.
- Absence of an incident record is not evidence of absence — only that no verified report has been received.
- Scores are not certifications and are not a substitute for independent audit, regulatory approval, or procurement due diligence.
- Coverage is broadest for English-language, publicly deployed systems; systems operating in closed environments are systematically underrepresented.
Ethics statement
We treat the people affected by AI systems as our primary constituency. We prioritize verifiable evidence over narrative, name individuals only when they hold institutional accountability, and refuse to publish identifying details of harmed individuals without their consent.
We do not accept advertising, sponsored placement, or undisclosed funding from operators of registered systems. We will publicly retract and correct our own errors on the same terms we hold others to.