AI placement and fallback pack
最終確認: 2026-08-02
用途: 一つの customer job × client cohort について、browser-provided、app-shipped local、OS-native、cloud-edge、bounded hybrid を、coverage、task fit、accepted outcome、latency、readiness、fallback、data transfer、support、regression、完全負荷後 contribution まで同じ判断契約で運用する
この pack は一般的な技術・事業・計測・運用の教材、判断補助、証拠管理、引継ぎの空欄書式であり、法律、privacy、security、製造物責任、契約、税務、会計その他の個別助言ではない。feature、主体、顧客、地域、data、browser、OS、device、model、provider、時点ごとに current な一次資料と、必要な専門家へ確認する。
14 書式はすべて空欄コピー用である。実績、benchmark、推奨率、目標値、価格、時間、件数、架空の記入例を置いていない。別途 fixture を作る場合は、ID、client、job、input、output、時刻、金額、結果を含め fully synthetic にし、実績・予測・一般的 threshold へ外挿しない。
氏名、email、電話、住所、raw IP、device fingerprint、cookie、session、customer document、prompt / output 全文、位置情報、健康・金融情報、credential、API key、OAuth token、password、private key、provider secret を、この公開書式や生成 AI prompt へ貼らない。実運用では opaque ID、必要最小限の coarse capability、redacted summary、hash、権限制御された正本 reference を使う。
章との責任境界
Section titled “章との責任境界”- 22 章: customer job、placement taxonomy、coverage、task-fit、fallback、data transfer、full-loaded contribution、14 日 pilot の原則。
- 06 章: 日本の privacy、security、契約、法務確認の共通入口。
- 12 章: AI job、accepted outcome、quality、provider cost、retention。
- 13 章: release evidence、independent review、rollback。
- 19 章: assignment、cohort、maturity、small-sample decision。
- 21 章: provider cost control、cash、reserve。
- SQLite companion: eligibility、readiness、fallback、version、one-outcome、cost、maturity、decision invariant を synthetic operational fixture で検査し、日付・出典付きの public policy / spec / price / quota snapshot を別分類で保持する参考実装。
第 12 章の AI feature economics を上書きしない。本 pack は、その exact job と accepted outcome を BROWSER_PROVIDED / APP_SHIPPED_LOCAL / OS_NATIVE / CLOUD_EDGE / BOUNDED_HYBRID のどこへ置くかを ai_placement_contract_id へ結ぶ。
Current official source anchors
Section titled “Current official source anchors”source snapshot を作るときは、転載や記憶でなく次の current official page から exact product / API / model / effective date を再取得する。
- Chrome: Chrome 148 release notes、Prompt API、model download UX、built-in model management。Chrome の current shipment と、他 browser の standardization / support を分け、JS から model version が見えない場合は
OPAQUEを許容する。 - Apple: Foundation Models、Foundation Models updates、WWDC25 Foundation Models session。privacy / offline claim は on-device
SystemLanguageModelに限定し、server-side、custom model、Developer/Beta path は別 placement とする。 - app-shipped Web: ONNX Runtime Web deployment、ONNX Runtime Web overview、ONNX Runtime Web get started、W3C WebGPU。
onnxruntime-web/webgpuimport の experimental status と W3C WebGPU 自体の maturity を分け、一実装、execution-provider operator coverage、Candidate Recommendation / browser support を普遍 capability にしない。 - cloud-edge example: Cloudflare Workers AI pricing、Workers AI limits。free allocation、model price、task / model limit、local-development quota を current snapshot にし、limit を SLO にしない。
- EU: Article 50 guidelines、Article 50 Q&A。2026-12-02 までの限定 grace を既存 system の Article 50(2) machine-readable marking / detection 以外へ広げない。
- 日本: AI事業者ガイドライン第1.2版、AI利活用における民事責任の解釈適用に関する手引き。免責、適法保証、safe harbor と呼ばない。
- Risk management: NIST AI RMF Core、NIST AI RMF page。context、production monitoring、safe failure、independent assessment を job / placement contract へ変換し、voluntary かつ 1.0 改訂中の framework を compliance certificate にしない。
14 書式を使う順序
Section titled “14 書式を使う順序”- decision、job、cohort、claim、損失上限を固定する。
- customer job、価値、accepted / rejected / safe outcome を placement より先に固定する。
- 五つの placement option と current official source snapshot を作る。
- client、runtime、hardware、storage、language、model readiness の eligibility を outcome 前に固定する。
- model、runtime、prompt、tool、eval、release / rollback version を結ぶ。
- local / cloud の data flow、privacy、transparency、責任境界を固定する。
- same-job eval と safety / task-fit gate を通す。
- local download、readiness、cold / warm latency、device impact の receipt を残す。
- cloud fallback、user choice、timeout、retry、cost control、safe degradation を閉じる。
- opportunity、attempt、accepted outcome、maturity を append-only ledger で結ぶ。
- value、provider、distribution、support、regression、incident cost を完全負荷で照合する。
- frozen cohort の coverage、quality、latency、fallback、contribution、guardrail から bounded decision を作る。
- incident、kill-switch、rollback、recovery、resume authority を rehearsal する。
- weekly decision、Codex handoff、independent review、外部作用の人承認を閉じる。
共通 AI placement contract
Section titled “共通 AI placement contract”すべての書式、event、snapshot、ledger row、decision は同じ ai_placement_contract_id / contract_version を持つ。一つの contract に複数 opportunity と attempt があるため、contract ID だけで多件を join せず、exact ID chain を使う。
ID、version、environment
Section titled “ID、version、environment”contract_family_id:ai_placement_contract_id / contract_version:supersedes_contract_id: N/A | exact prior contract ID
decision_id / decision_version:customer_job_id / job_revision:accepted_outcome_contract_id / outcome_revision:client_cohort_id / cohort_revision:cohort_assignment_id / assignment_revision:placement_policy_id / policy_revision:placement_option_id / option_revision:placement_opportunity_id / opportunity_revision:client_capability_observation_id / observation_revision:runtime_source_snapshot_id / source_revision:model_contract_id / model_revision:runtime_artifact_id / artifact_revision: N/A | opaqueprompt_contract_id / prompt_revision:tool_contract_id / tool_revision: N/A | opaqueeval_contract_id / eval_revision:data_transfer_contract_id / transfer_revision:local_readiness_event_id / event_sequence:placement_attempt_id / attempt_sequence:fallback_decision_id / decision_revision: N/A | opaqueaccepted_outcome_event_id / event_revision: N/A | opaquecost_ledger_id / ledger_revision:maturity_snapshot_id / snapshot_revision:incident_id / kill_switch_event_id: N/A | opaqueevidence_id / evidence_revision:supersedes_evidence_id: N/A | exact prior evidence ID
environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALenvironment_mapping_revision:owner / independent_reviewer:retention_policy_id / retention_due_at:SYNTHETIC / SANDBOXはTEST、LIMITED_LIVE / LIVEはREALへ固定写像し、不一致 row を reject する。元の四状態を正本から捨てない。- 過去 row を静かに update せず、新 revision と exact supersession を作る。
- opaque ID、hash、feature detection result は、本人性、privacy、同意、品質、適法性、現金を単独で証明しない。
assigned_at:effective_from / effective_until:availability_checked_at:download_started_at / download_completed_at:model_ready_at:attempt_started_at / attempt_completed_at:fallback_reviewed_at / fallback_executed_at:accepted_at / rejected_at / safe_terminal_at:occurred_at / recorded_at:outcome_cutoff_at / snapshot_as_of:maturity_at:checked_at / valid_until / recheck_due_at:decision_due_at / decided_at:occurred_at <= outcome_cutoff_atとrecorded_at <= snapshot_as_ofを別に判定する。- availability、model ready、attempt、accepted outcome、maturity の時計を相互に代用しない。
- late event は後の snapshot を変え得るが、過去 decision を書き換えない。
- warm latency へ initial download / initialization を隠さず、customer-perceived cold path と別に表示する。
状態を混ぜない
Section titled “状態を混ぜない”| state | 意味 |
|---|---|
N/A |
contract 上存在しない。理由、決定者、再確認 trigger がある |
UNKNOWN |
必要だが未確認、矛盾、期限切れ、join 不能、authority 不足 |
0 |
対象、分母、期間、coverage が確定した測定ゼロ |
FAILED |
実行した検査、attempt、条件、照合が明示的に不合格 |
OBSERVED |
stage に必要な current evidence を肯定観測 |
NOT_DUE |
download、maturity、support、refund、regression 等の期限前 |
Chrome LanguageModel.availability() の生値は次の四つとして別 field に置く。
unavailable | downloadable | downloading | availableLOCAL_READY は API の生値でなく、runtime availability に job の modality / language、model / prompt revision、data / policy gate を重ねた derived eligibility である。raw available だけで local attempt や business eligibility を許可しない。
Placement class
Section titled “Placement class”BROWSER_PROVIDEDAPP_SHIPPED_LOCALOS_NATIVECLOUD_EDGEBOUNDED_HYBRIDSAFE_DEGRADATIONHUMAN_REVIEWApple framework row は model provider class を分ける。
APPLE_SYSTEM_LANGUAGE_MODEL_ON_DEVICEAPPLE_PRIVATE_CLOUD_COMPUTE_SERVER_BETAAPPLE_CUSTOM_OR_OTHER_LANGUAGE_MODELNOT_APPLEon-device / offline / data-stays-on-device claim は、current evidence が示す APPLE_SYSTEM_LANGUAGE_MODEL_ON_DEVICE path にだけ帰属させる。PCC、custom、server、tool network call を同じ claim へ混ぜない。
Evidence class
Section titled “Evidence class”| class | evidence | 主な用途 | 単独では証明しないもの |
|---|---|---|---|
E0_INFERENCE |
仮説、推計、scenario | option 検討、sensitivity | runtime support、accepted outcome、cash |
E1_MANUAL_OBSERVATION |
user report、support note | client impact の補助 | exact runtime、privacy、consent |
E2_VERSIONED_CONTRACT_OR_CONFIG |
job、policy、prompt、tool、notice、config | intended behavior、scope | 実際の execution、outcome |
E3_VERIFIED_RUNTIME_OR_PROVIDER_EVENT |
feature detection、download、provider response | availability、attempt、provider state | user acceptance、bank cash |
E4_FIRST_PARTY_AUTHORITATIVE |
assignment、eval、delivery、acceptance、cost event | cohort、outcome、内部原価 | 外部 provider・法律上の結論 |
E5_CUSTOMER_BANK_LEGAL_AUTHORITATIVE |
customer acceptance、bank、official / legal evidence | value、cash、制度条件 | future model behavior、免責 |
evidence class の数字が高いだけで stage に適切とは限らない。公式 docs は current product facts の source であり、自社 account、client、job の実際の availability / quality を置換しない。
Decision priority と外部作用
Section titled “Decision priority と外部作用”STOP > PAUSE > UNKNOWN > CHANGE > MAINTAIN > BOUNDED_EXPAND- privacy、security、rights、false disclosure、wrong high-impact action、customer harm は平均利益で相殺しない。
BOUNDED_EXPANDは job、client、model、data、placement、cost、期間のうち evidence が支える範囲だけを広げる。- cloud transfer、production routing、model / provider change、customer notice、high-impact tool、kill-switch解除は外部作用であり、人の exact approval を要求する。
- Codex は draft、diff、schema、test、reconciliation、missing-field review までとし、live activation や user consent を自律決定しない。
書式 1 — Decision / scope / claim / loss-limit contract
Section titled “書式 1 — Decision / scope / claim / loss-limit contract”model や benchmark を見る前に、一つの business action と最大 exposure を固定する。
ai_placement_contract_id / contract_version:decision_id / decision_version:created_at / decision_due_at:environment / accounting_environment:owner / independent_reviewer:
decision question:customer job in scope:client cohort in scope:product / plan / geography:baseline placement / revision:candidate placement options:one action this decision can change:
claim sought: DESCRIPTION | ASSOCIATION | OPERATIONAL_DECISIONclaim cap:claim explicitly prohibited:time horizon / comparison basis:
primary KPI:driver metrics:guardrails:data-quality metrics:baseline state: UNKNOWN | NOT_DUE | OBSERVEDtarget state: blank until baseline | exact approved state
maximum assigned opportunities:maximum local / cloud attempts per opportunity:maximum cloud spend / provider exposure:maximum model / asset distribution exposure:maximum data fields / bytes transferred:maximum device / accessibility impact:maximum customer harm / wrong-action exposure:maximum founder / support / regression minutes:maximum elapsed time:
hard vetoes:safe terminal:human action approver:kill-switch owner / command reference:rollback target / recovery condition:prohibited files / data / actions:next cheapest evidence:
decision: STOP | PAUSE | UNKNOWN | CHANGE | MAINTAIN | BOUNDED_EXPANDdecision evidence / scope / expiry:- decision は「AI を使う」ではなく一つの placement / routing action を変える。
- one job、one cohort、baseline、comparison、time horizon が exact である。
- claim を compatibility、quality、causality、legal conclusion へ過剰昇格しない。
- cash、data、device、customer、founder time の loss limit がある。
- safe terminal、kill-switch、rollback が upside より先に書かれる。
書式 2 — Customer job / value / accepted-outcome contract
Section titled “書式 2 — Customer job / value / accepted-outcome contract”placement によって成功定義を変えない。一 job / outcome revision ごとに複製する。
ai_placement_contract_id / contract_version:customer_job_id / job_revision:accepted_outcome_contract_id / outcome_revision:effective_from / effective_until:owner / customer-domain reviewer:
actor / moment / trigger:job-to-be-done:input boundary / data class:expected output or action:business value hypothesis:value unit / allocation basis:value source / evidence class:
task family: SUMMARIZATION | EXTRACTION | CLASSIFICATION | TRANSFORMATION | WORLD_KNOWLEDGE | ADVANCED_REASONING | TOOL_ACTION | OTHER_REVIEWEDfreshness / source-of-truth requirement:language / modality / context requirement:required structure / schema:
accepted outcome definition:authoritative acceptance actor/system:acceptance evidence / deduplication key:rejected outcome definition:abstention definition:safe terminal definition:partial / corrected outcome rule:maximum human correction allowed:irreversible effect boundary:human confirmation required:
outcome cutoff / maturity rule:refund / correction / complaint maturity:support / regression maturity:retention or repeated-use outcome: N/A | exact separate contract
same definition required across placements: YES | NONO basis and independent approval:Outcome gate
Section titled “Outcome gate”- output bytes、HTTP success、schema parse を customer acceptance と自動同一視しない。
- world knowledge / freshness と bounded local transformation を分けた。
- abstention / safe degradation が正解になり得る条件を事前に定めた。
- high-impact tool action は生成と実行を分け、人 confirmation と receipt がある。
- value allocation がなければ contribution value を
UNKNOWNにする。
書式 3 — Placement option catalog / current source snapshot
Section titled “書式 3 — Placement option catalog / current source snapshot”option と official source の current 状態を一 row ごとに固定する。
ai_placement_contract_id / contract_version:placement_option_id / option_revision:runtime_source_snapshot_id / source_revision:placement class: BROWSER_PROVIDED | APP_SHIPPED_LOCAL | OS_NATIVE | CLOUD_EDGE | BOUNDED_HYBRIDeffective_from / checked_at / valid_until:owner / reviewer:
provider / framework / product:official documentation URLs:documentation updated_at / retrieved_at:product status: CURRENT_STABLE | CURRENT_LIMITED | ORIGIN_TRIAL | BETA | DEVELOPER_BETA | PREVIEW | DEPRECATED | UNKNOWN | FAILEDbrowser / OS / app surface:account / region / plan eligibility:standard / draft / product-shipment distinction:
model provider class: APPLE_SYSTEM_LANGUAGE_MODEL_ON_DEVICE | APPLE_PRIVATE_CLOUD_COMPUTE_SERVER_BETA | APPLE_CUSTOM_OR_OTHER_LANGUAGE_MODEL | BROWSER_MANAGED_ON_DEVICE | APP_DISTRIBUTED_LOCAL | CLOUD_PROVIDER | OTHER | N/Amodel / runtime manager:model download / update manager:current model or generation identifier available?:model_version_visibility: EXACT | PROVIDER_ALIAS | OPAQUE | N/A | UNKNOWNvisible model identifier / alias: N/A | exact observed valuebrowser / OS build used as reproducibility receipt:availability / eval snapshot used when model is opaque:runtime availability API / exact raw states:required options for availability:
supported client families / excluded clients:hardware / storage / memory requirements:language / modality / context limitations:network / initial download requirement:offline-after-ready claim and exact subject:data-processing-location claim and exact subject:
app-shipped artifacts: JS bundle / WASM / WebGPU / model / tokenizer / worker / cache refs:artifact-size / CSP / secure-context / operator limitation:license / redistribution / update responsibility:
cloud provider / region / retention / training-use refs:rate / spend / timeout / availability refs:cost ownership:support / regression ownership:fallback dependency:
source state: N/A | UNKNOWN | 0 | FAILED | OBSERVED | NOT_DUEclaims permitted:claims prohibited:recheck triggers:supersedes source snapshot:Source gate
Section titled “Source gate”- Chrome shipment を全 browser / mobile の portable support にしていない。
- raw availability states を
available / downloadable / downloading / unavailableから改名していない。 - browser-managed model が JS から見えない場合、偽の exact version / hash を作らず
OPAQUEとした。 - hot swap、swap 中 failure、mid-session purge を re-eval / safe-failure trigger にした。
- Apple privacy / offline claim の主語を on-device
SystemLanguageModelに限定した。 - PCC、custom、server、Developer/Beta path を current stable on-device と混ぜていない。
- app-shipped local の model / runtime / license / cache / update owner を自社 responsibility として置いた。
- docs snapshot を自社 client の実測 availability / task-fit へ昇格していない。
書式 4 — Client / runtime / hardware eligibility matrix
Section titled “書式 4 — Client / runtime / hardware eligibility matrix”一 assigned opportunity ごとに必要な coarse capability を観測する。raw fingerprint を保存しない。
ai_placement_contract_id / contract_version:client_cohort_id / cohort_revision:cohort_assignment_id / assignment_revision:placement_opportunity_id / opportunity_revision:client_capability_observation_id / observation_revision:assigned_at / availability_checked_at / recorded_at:owner / reviewer:
product / plan / geography eligibility:client family / version rule:actual app / browser / OS version evidence:runtime feature detection result:hardware capability coarse state:storage capability coarse state:memory / GPU capability coarse state:network / metered / offline state:language / modality / context support:permission / user-activation state:accessibility / managed-device constraint:
Chrome `LanguageModel.availability()` raw value when applicable: unavailable | downloadable | downloading | availableother runtime availability raw value / source reference:availability observation status: N/A | UNKNOWN | FAILED | OBSERVEDavailability options canonical hash:prompt / session options canonical hash:availability options exactly match execution options: YES | NO | UNKNOWNmodel ready state: N/A | UNKNOWN | FAILED | OBSERVED | NOT_DUEmodel ready evidence / checked_at:
privacy / data gate state:task-fit gate state:model / prompt / tool version gate state:derived local eligibility: ELIGIBLE_READY | ELIGIBLE_NOT_READY | INELIGIBLE | UNKNOWN | FAILEDineligibility / unknown reason:eligible placements:prohibited placements:next safe action:
raw device fingerprint retained?: must be NOminimized capability retention / due_at:eligibility_snapshot_id / snapshot_as_of:assigned opportunities denominator:eligible ready:eligible not ready / downloadable / downloading:runtime unavailable:language / modality unsupported:hardware / storage unsupported:privacy / policy prohibited:eligibility UNKNOWN / stale / conflicting:post-outcome exclusions: must be zeroreconciliation difference:local-ready coverage:eligibility-unknown share:Eligibility gate
Section titled “Eligibility gate”- assignment を availability / outcome 観測前に freeze した。
- UA ではなく actual feature detection と exact options を使った。
- raw
availableと derivedELIGIBLE_READYを分けた。 - unavailable、download abandonment、unsupported、UNKNOWN を分母に残した。
- capability collection を必要最小限にし、fingerprinting product にしていない。
書式 5 — Model / runtime / prompt / tool / release contract
Section titled “書式 5 — Model / runtime / prompt / tool / release contract”app version だけで AI behavior を再現できると仮定しない。
ai_placement_contract_id / contract_version:model_contract_id / model_revision:prompt_contract_id / prompt_revision:tool_contract_id / tool_revision: N/A | opaqueeval_contract_id / eval_revision:release_contract_id / release_revision:effective_from / effective_until:owner / independent reviewer:
placement class / provider / framework:browser / OS / app version:system model generation / provider model ID: N/A | exact observed | OPAQUEmodel_version_visibility: EXACT | PROVIDER_ALIAS | OPAQUE | N/A | UNKNOWNbrowser / OS build / provider release evidence:model status: CURRENT_STABLE | BETA | DEVELOPER_BETA | UNKNOWN | N/Amodel artifact hash: N/A | opaquemodel license / redistribution ref: N/A | opaquetokenizer / preprocessor / postprocessor revisions:runtime package / JS / WASM / WebGPU artifact hashes:runtime package / execution-provider status: STABLE | EXPERIMENTAL | BETA | UNKNOWNworker / CSP / cache / IndexedDB schema revision:
system instruction artifact hash:developer prompt artifact hash:response schema / constraint revision:sampling / context / language / modality options:untrusted input interpolation rule:prompt-injection controls:
tool name / schema / implementation hash:tool data source / freshness contract:tool permission / least-privilege scope:tool side-effect class:human confirmation / idempotency / receipt:
eval dataset / acceptance / safety revisions:known task-fit / knowledge limits:known incompatibilities:source checked_at / valid_until:update detection mechanism:regression trigger:provider-managed hot-swap / purge behavior:opaque-model reproducibility receipt — build / availability / eval snapshot / checked_at:
positive tests:negative tests:cross-version tests:release receipt:rollback exact versions:rollback rehearsal receipt:Version gate
Section titled “Version gate”- accepted outcome から、observable な model / runtime / prompt / tool / eval revision と、opaque model の build / availability / eval receipt へ戻れる。
- provider-managed model に取得不能な exact version / hash を捏造していない。
- browser / OS model update を自社 app release 外として無視していない。
- runtime binary、model、tokenizer、prompt の incompatible mix を fail closed にした。
- untrusted user input を developer / system instruction へ直接補間しない。
- structured output を safe tool authorization と同一視していない。
- rollback は app code だけでなく routing、model、prompt、tool、data contract を含む。
書式 6 — Data flow / privacy / transparency / responsibility map
Section titled “書式 6 — Data flow / privacy / transparency / responsibility map”local label と実際の network transfer を別に検査する。data class / path ごとに複製する。
ai_placement_contract_id / contract_version:data_transfer_contract_id / transfer_revision:data_flow_map_id / map_revision:effective_from / effective_until:owner / privacy-security reviewer / legal reviewer:
customer job / client cohort:input data class / sensitivity:field / content category:collection purpose / necessity:local processing component:local storage / retention / deletion:analytics / crash / feedback / sync behavior:tool call / external data behavior:
allowed cloud-fallback fields:prohibited transfer fields:redaction / minimization / aggregation:provider / model / region:subprocessor / cross-border state:retention / deletion / access:provider training-use / improvement terms:security / encryption / incident route:purpose limitation:
notice artifact / revision:user choice or other reviewed basis:consent state / scope / expiry where applicable:withdraw / opt-out / alternative path:local-only / offline promise:cloud fallback compatible with promise: YES | NO | UNKNOWN
EU role state: PROVIDER | DEPLOYER | BOTH | N/A | UNKNOWNdirect natural-person interaction state:AI interaction disclosure / first-interaction evidence:generated-content marking obligation review:human-perceivable labelling review:human review / editorial-control evidence:Article 50(2) limited grace applicability review:current official source / checked_at / valid_until:
Japan AI role / expected human involvement:function / important-risk explanation:monitoring / stakeholder communication:current METI source / specialist review:
data-flow observation evidence:network negative test:claim permitted:claim prohibited:incident / recheck trigger:Data and transparency gate
Section titled “Data and transparency gate”- local path の analytics、sync、feedback、tool network call を含めて観測した。
-
SystemLanguageModel以外の Apple server / custom pathへ on-device claim を移植していない。 - cloud fallback は current field allowlist、provider、region、retention、user expectation を持つ。
- local-only / offline promise と矛盾する fallback を hard deny した。
- provider machine-readable marking と deployer human-perceivable label を置換していない。
- Article 50(2) の限定 grace を他 obligation へ一般化していない。
- METI / NIST / EU source を免責、safe harbor、個別適法性へ昇格していない。
書式 7 — Same-job quality / safety / task-fit eval
Section titled “書式 7 — Same-job quality / safety / task-fit eval”一 eval case × placement revision ごとに複製し、同じ accepted-outcome contract で比較する。
ai_placement_contract_id / contract_version:eval_contract_id / eval_revision:eval_run_id / run_revision:eval_case_id / case_revision:customer_job_id / job_revision:accepted_outcome_contract_id / outcome_revision:placement_option_id / option_revision:model / runtime / prompt / tool revisions:environment / accounting_environment:started_at / completed_at / recorded_at:owner / independent reviewer:
dataset source / artifact hash:data rights / privacy / redaction state:synthetic / reviewed-real classification:client cohort representation:language / modality / difficulty stratum:world-knowledge / freshness requirement:known limitation stratum:
expected accepted outcome:expected rejection / abstention / safe terminal:required schema / factual source:human correction allowance:safety / policy constraints:high-impact action expected?:
technical output state:schema / structural result:task-specific correctness result:source / freshness result:safety / policy result:tool authorization / side-effect result:human correction required:accepted outcome state: N/A | UNKNOWN | 0 | FAILED | OBSERVED | NOT_DUErejection / abstention reason:evidence / artifact hashes:
latency / resource / device observations:failure / timeout / retry:incident / complaint:eval_summary_id / snapshot_as_of:same frozen case set across placements: YES | NO | UNKNOWNmature eligible cases:accepted cases:rejected / abstained / safe-terminal cases:UNKNOWN / FAILED / NOT_DUE cases:accepted outcome rate:quality by language / modality / difficulty:critical safety failures:post-outcome exclusions: must be zerogeneralization limitations:Eval gate
Section titled “Eval gate”- placement ごとに別の easy case / acceptance definition を使っていない。
- development prompt に過適合した case だけで production を推定していない。
- device-scale model の world knowledge / advanced reasoning limit を task-fit に反映した。
- critical safety / wrong action を平均 score で相殺していない。
- model / OS / browser update 後に同じ regression set を再実行した。
書式 8 — Local model download / readiness / latency / device receipt
Section titled “書式 8 — Local model download / readiness / latency / device receipt”一 opportunity × local readiness / attempt ごとに複製する。
ai_placement_contract_id / contract_version:placement_opportunity_id / opportunity_revision:client_capability_observation_id / observation_revision:local_readiness_event_id / event_sequence:placement_attempt_id / attempt_sequence: N/A | exact local attemptplacement class: BROWSER_PROVIDED | APP_SHIPPED_LOCAL | OS_NATIVEenvironment / accounting_environment:owner / reviewer:
client / runtime / model identity-or-visibility / prompt revisions:availability API / feature detection:Chrome `LanguageModel.availability()` raw value when applicable: unavailable | downloadable | downloading | availableother runtime availability raw value / source reference:availability observation status: N/A | UNKNOWN | FAILED | OBSERVEDavailability options hash:execution options hash:exact option match result:availability_checked_at / evidence:
user activation required / observed:download notice / progress / cancel UX:download_started_at / download_completed_at:download result / failure reason:network metering state:storage eligibility state:model removed / redownload observed:model initialization started / completed:model_ready_at / readiness evidence:
app-shipped runtime / model / tokenizer artifact hashes:asset fetch / cache / integrity result:WASM / WebGPU / CPU fallback result:CSP / secure-context / worker result:
attempt_started_at / first_output_at / completed_at:accepted_at / safe_terminal_at:download latency:initialization latency:local inference latency:time-to-accepted-or-safe-terminal:cold / warm path classification:
memory / storage / GPU / CPU coarse impact:battery / thermal observation:crash / tab discard / OOM:accessibility / perceived-wait observation:support / rescue minutes:
local output produced?:accepted / rejected / failed / aborted:fallback review required?:first failed / unknown / not-due stage:evidence ids:Local readiness gate
Section titled “Local readiness gate”- raw
availableと derived eligibility の成立前に local attempt を開始していない。 - Prompt API は execution と同じ language / modality options で availability を確認した。
- download、initialization、inference、accepted outcome の latency を分けた。
- warm-only latency を customer-perceived latency として表示していない。
- storage drop、asset mismatch、unsupported runtime、download abandonment を outcome 分母から消していない。
- device impact と support を provider token cost 0 で相殺していない。
書式 9 — Cloud fallback / user choice / timeout / circuit-breaker contract
Section titled “書式 9 — Cloud fallback / user choice / timeout / circuit-breaker contract”fallback は local failure の副作用でなく、明示的な別 decision である。
ai_placement_contract_id / contract_version:fallback_decision_id / decision_revision:placement_opportunity_id / opportunity_revision:local placement_attempt_id / attempt_sequence:data_transfer_contract_id / transfer_revision:placement_policy_id / policy_revision:environment / accounting_environment:owner / human approver:
local terminal state:local failure / unavailable reason code:local output already shown / accepted?:fallback allowlist reason:fallback deny reason:offline / local-only promise state:safe degradation available?:
user notice / choice artifact revision:choice state / scope / occurred_at / expires_at:choice evidence:fields permitted for transfer:fields prohibited from transfer:redaction / minimization receipt:
cloud provider / model / API revision:region / retention / training-use state:provider source checked_at / valid_until:request body canonical hash:idempotency key / opportunity binding:maximum one cloud attempt or approved retry rule:declared maximum fallback attempt count / observed count:timeout / cancel / outcome read-back:retry backoff / maximum retry:circuit-breaker threshold / state:app quota / provider enforcement / alert distinctions:maximum variable cost / enforcement evidence:
fallback reviewed_at / executed_at:cloud attempt ID / sequence:cloud technical result:accepted outcome producer:final UI / receipt path label:local + cloud attempt reconciliation:duplicate outcome / duplicate value check:safe terminal on cloud failure:Fallback gate
Section titled “Fallback gate”- fallback は enumerated reason と current data-transfer contract を持つ。
- local-only / offline / prohibited-data job を cloud へ送らない。
- silent transfer や prechecked coercive choice を使っていない。
- timeout outcome unknown で複数 providerへ自動 fan-out しない。
- provider alert と enforced cap、app quota、circuit breaker を分けた。
- local + cloud を二つの customer / accepted outcome / value にしていない。
- cloud-produced outcome を local-only claim にしていない。
書式 10 — Placement opportunity / attempt / outcome / maturity ledger
Section titled “書式 10 — Placement opportunity / attempt / outcome / maturity ledger”正本は上書き status でなく append-only event である。一 event ごとに複製する。
ai_placement_contract_id / contract_version:placement_opportunity_id / opportunity_revision:event_id / event_sequence:supersedes_event_id: N/A | exact prior event IDcustomer_job_id / job_revision:client_cohort_id / cohort_revision:cohort_assignment_id / assignment_revision:placement_policy_id / policy_revision:environment / accounting_environment:
event_type: OPPORTUNITY_ASSIGNED | CAPABILITY_OBSERVED | POLICY_RESOLVED | MODEL_UNAVAILABLE | MODEL_DOWNLOADABLE | MODEL_DOWNLOADING | MODEL_READY | LOCAL_ATTEMPT_STARTED | LOCAL_OUTPUT_PRODUCED | LOCAL_FAILED | LOCAL_ABORTED | LOCAL_ACCEPTED | LOCAL_REJECTED | FALLBACK_REVIEWED | FALLBACK_DENIED | FALLBACK_CONSENTED | CLOUD_ATTEMPT_STARTED | CLOUD_OUTPUT_PRODUCED | CLOUD_FAILED | CLOUD_ABORTED | CLOUD_ACCEPTED | CLOUD_REJECTED | HUMAN_REVIEWED | SAFE_DEGRADATION | OUTCOME_CORRECTED | OUTCOME_MATUREDevent state: N/A | UNKNOWN | 0 | FAILED | OBSERVED | NOT_DUEevent reason code:
placement_attempt_id / attempt_sequence: N/A | opaqueattempt placement class:attempt producer / provider / model:runtime / prompt / tool / eval revisions:data_transfer_contract_id / revision: N/A | exactfallback_decision_id / revision: N/A | exact
assigned_at / occurred_at / recorded_at:availability_checked_at / model_ready_at:attempt_started_at / attempt_completed_at:accepted_at / safe_terminal_at / maturity_at:outcome_cutoff_at / snapshot_as_of:
input artifact hash / data class:output artifact hash / result class:technical output state:accepted outcome state:acceptance authority / evidence:correction / complaint / refund state:source evidence class / evidence_id:idempotency / deduplication key:predecessor event IDs:opportunity_snapshot_id / revision:placement_opportunity_id:outcome_cutoff_at / snapshot_as_of / maturity_at:assignment state:eligibility state:local attempt count / terminal:fallback decision / cloud attempt count / terminal:human review / safe degradation:authoritative accepted outcome count: must be zero or oneaccepted outcome producer:rejected / failed / unknown / not-due state:first missing or conflicting exact ID:late / duplicate / correction state:maturity state:Ledger invariants
Section titled “Ledger invariants”- opportunity assignment は availability / outcome より前である。
- local attempt と cloud attempt は別 ID だが同じ opportunity に結ぶ。
- accepted outcome は一 opportunity に最大一件である。
- fallback 後に local acceptance を backfill して二重 value を作らない。
- correction / late event は過去 snapshot を削除せず supersede する。
- TEST event は REAL coverage、outcome、contribution へ入らない。
書式 11 — Full-loaded cost / value / support / regression ledger
Section titled “書式 11 — Full-loaded cost / value / support / regression ledger”一 value / cost component ごとに複製し、同じ opportunity cohort と currency / time basis で照合する。
ai_placement_contract_id / contract_version:cost_ledger_id / ledger_revision:economics_snapshot_id / snapshot_revision:placement_opportunity_id: N/A | exactclient_cohort_id / cohort_revision:placement option / policy revision:outcome_cutoff_at / snapshot_as_of / maturity_at:base currency / FX source / valuation time:FX evidence ID / source-to-base currency pair / rate / checked_at / valid_until:owner / reviewer:
accepted-job value closeout ID / revision:accepted outcome ID / expected value-event count / observed count:explicit zero or UNKNOWN state / allocation basis / current evidence:cohort economic closeout ID / revision:expected vs observed mature / accepted / attempt / direct-cost / support / incident counts:late-arrival mismatch / closeout currentness:
component_id / component_revision:component class: ALLOCATED_MATURED_GROSS_CONTRIBUTION | BROWSER_OS_CLOUD_PROVIDER_COST | MODEL_RUNTIME_DISTRIBUTION_CDN_EGRESS | LOCAL_ATTEMPT_VARIABLE_COST | CLOUD_FALLBACK_VARIABLE_COST | SUPPORT_FOUNDER_RESCUE_TIME | EVAL_REGRESSION_RELEASE_MAINTENANCE | PRIVACY_SECURITY_TRANSPARENCY_OPERATIONS | REFUND_CREDIT_COMPENSATION | INCIDENT_REMEDIATION | DEVICE_ALTERNATIVE_PATH_COST | OTHER_REVIEWEDdirection: VALUE | COSTamount / currency / unit / amount_state:observed / estimated / allocated classification:source evidence class / evidence_id:allocation basis / denominator:occurred_at / recorded_at:component uniqueness key:correction / supersedes component:
provider unit / invoice / usage ref: opaque | N/Amodel / runtime distribution bytes / request ref:failed-attempt / fallback attribution:founder minutes / approved internal hourly value:support ticket / regression run / incident ref: opaque | N/Abank / contract-backed value state:cash reconciliation state:duplicate value / avoided-cost check:matured_full_loaded_placement_contribution= matured non-duplicated gross contribution allocated to accepted outcomes - browser / OS / cloud provider charges - model and runtime distribution, CDN, cache, storage and egress cost - failed local attempt plus cloud fallback variable cost - support and founder rescue time cost - eval, regression, release and compatibility maintenance - privacy, security and transparency operations - refund, credit, compensation and incident remediation - device-impact alternative-path cost actually borneeconomics reconciliation:mature assigned opportunities:accepted outcome opportunities:value coverage / unknown allocation:cost coverage / unknown components:duplicate value / cost corrections:unreconciled provider / cash delta:matured full-loaded contribution:contribution state: N/A | UNKNOWN | 0 | FAILED | OBSERVED | NOT_DUEcomparison to frozen baseline:sensitivity / limitation:Economics gate
Section titled “Economics gate”- provider token bill 0 を total cost 0 にしていない。
- success unit だけでなく failed local、fallback、support、incident cost を含めた。
- subscription value の allocation basis がなければ value を
UNKNOWNにした。 - cloud cost avoided を gross value へ二重加算していない。
- founder time、regression、compatibility maintenance をゼロ固定していない。
- management contribution、会計利益、銀行現金を同一視していない。
書式 12 — Cohort rollout / maturity / KPI / bounded decision
Section titled “書式 12 — Cohort rollout / maturity / KPI / bounded decision”assignment 後の分母、maturity、guardrail、DQ を同じ snapshot で読む。
ai_placement_contract_id / contract_version:rollout_id / rollout_revision:client_cohort_id / cohort_revision:assignment_revision / frozen_at:placement_policy_id / policy_revision:baseline / candidate placements:environment / accounting_environment:outcome_cutoff_at / snapshot_as_of / maturity_at:owner / independent reviewer:
assigned opportunities:known local eligible ready:eligible not ready / downloadable / downloading:runtime / hardware / storage / language ineligible:eligibility UNKNOWN / stale / failed:post-outcome cohort exclusions: must be zero
local attempts / accepted / rejected / failed / aborted:fallback reviewed / denied / consented / executed:cloud attempts / accepted / rejected / failed / aborted:human review / safe degradation:opportunities with zero accepted outcome:opportunities with exactly one accepted outcome:opportunities with duplicate accepted outcome:
mature eligible denominator:accepted outcome numerator:accepted outcome rate:local-ready coverage:eligibility-unknown share:fallback rate:fallback rescue yield:cold / warm / fallback time-to-terminal p50 / p95:latency sample count / timeout / censoring:matured full-loaded placement contribution:accepted-job value closeout coverage / UNKNOWN:cohort economic closeout current / late-arrival mismatch:
data-transfer / disclosure guardrail:privacy / security / rights incident:wrong high-impact action:device / crash / battery / thermal / accessibility harm:support / founder capacity:model / prompt / runtime regression:
DQ: late / duplicate / missing exact IDs: cross-version / stale source: TEST-in-REAL / environment mismatch: value / cost reconciliation delta: cohort / maturity leakage:
first failed / unknown / not-due stage:vetoes:decision: STOP | PAUSE | UNKNOWN | CHANGE | MAINTAIN | BOUNDED_EXPANDdecision scope — job / client / placement / model / data / cost / period:owner decision-signal ID / authorized next-cohort limit:requested next-cohort limit / exact-match result:claim permitted / prohibited:one next action / owner / due_at:rollback / recheck trigger:next cheapest evidence:Decision rules
Section titled “Decision rules”STOP: active privacy, security, rights, false-disclosure, wrong-action, customer-harm or unrecoverable-integrity veto
PAUSE: incident containment, provider/runtime recovery, rollback or reconciliation pending
UNKNOWN: required eligibility, task-fit, data, value, cost, maturity or source evidence missing/stale
CHANGE: one versioned placement, routing, prompt, model, fallback or instrumentation change
MAINTAIN: current bounded placement remains within approved evidence and loss limits
BOUNDED_EXPAND: only the additional job/client/model/data/cost/time scope supported by current evidence- average quality / contribution は critical veto を override しない。
- small sample の p95、rare incident rate、retention を確定値にしない。
BOUNDED_EXPANDは all users、all browsers、all jobs への展開ではない。
書式 13 — Incident / kill-switch / rollback / recovery
Section titled “書式 13 — Incident / kill-switch / rollback / recovery”kill-switch は experiment の decision state でなく active harm を止める override である。
ai_placement_contract_id / contract_version:incident_id / incident_revision:kill_switch_policy_id / policy_revision:kill_switch_event_id / event_sequence:environment / accounting_environment:owner / activation authority / recovery authority:
incident class: PRIVACY_TRANSFER | SECURITY | RIGHTS | FALSE_DISCLOSURE | WRONG_HIGH_IMPACT_ACTION | DUPLICATE_OUTCOME_OR_ACTION | MODEL_OR_PROMPT_REGRESSION | RUNTIME_OR_DOWNLOAD_FAILURE | CLOUD_PROVIDER_OR_COST | DEVICE_OR_ACCESSIBILITY_HARM | CUSTOMER_COMPLAINT | OTHER_REVIEWEDobserved_at / recorded_at:affected job / client / opportunities:affected model / runtime / prompt / tool / data revisions:severity / actual and potential impact:evidence preservation / privacy boundary:
predeclared trigger matched:activated_at / activated_by:kill-switch scope:local attempt disabled?:cloud fallback disabled?:tool action disabled?:safe terminal activated:customer / provider / specialist communication refs:new exposure stopped_at:
rollback exact targets: placement_policy_id / revision: model / runtime / prompt / tool revisions: data_transfer_contract_id / revision: client cohort / rollout revision:rollback executed_at / by:rollback probes / receipt:
affected opportunity reconciliation:data-transfer / deletion / access follow-up:duplicate action / compensation / refund follow-up:support / complaint / incident cost ledger refs:root-cause state:containment state:recovery state:
resume requirements: root cause corrected: affected opportunities reconciled: negative probes pass: source / model / policy current: privacy-security-legal review: independent approval:resume prohibited until:resume decision / scope / approved_at:post-incident review / recheck due_at:Kill-switch drill receipt
Section titled “Kill-switch drill receipt”ai_placement_contract_id / contract_version:drill_id / scenario:environment / accounting_environment:started_at / contained_at:new local attempts stopped:new cloud transfer stopped:high-impact tool stopped:safe degradation verified:rollback exact versions verified:affected opportunity reconciliation verified:alert / owner / independent receipt:drill state: N/A | UNKNOWN | 0 | FAILED | OBSERVED | NOT_DUEgap / owner / next drill due_at:- kill-switch は必要な incident / reconciliation evidence の自動全削除ではない。
- recovery は原因修正、negative probe、reconciliation、独立承認まで自動化しない。
- provider / runtime failure を無限 retry、silent cloud fan-out、重複 tool action にしない。
書式 14 — Weekly decision / Codex handoff / independent review
Section titled “書式 14 — Weekly decision / Codex handoff / independent review”同じ cutoff で eligibility、attempt、outcome、cost、incident、version を閉じ、次の一 action を決める。
ai_placement_contract_id / contract_version:weekly_review_id / review_revision:review period:outcome_cutoff_at / snapshot_as_of / maturity_at:owner / independent reviewer / reviewed_at:
customer job / accepted outcome revision:client cohort / assignment revision:placement policy / baseline / candidate:source / model / runtime / prompt / tool revisions:
assigned opportunities:local ready / not ready / unavailable / UNKNOWN:local attempts and terminal states:fallback decisions and cloud attempts:accepted / rejected / safe-terminal opportunities:duplicate / missing outcomes:
accepted outcome numerator / mature denominator:local-ready coverage / eligibility UNKNOWN:fallback rate / rescue yield:cold / warm / fallback time-to-terminal:data transfer / disclosure / consent state:support / device / regression burden:full-loaded contribution / reconciliation state:
open incident / complaint / source expiry:privacy / security / safety / client-impact veto:late / duplicate / stale / cross-version / TEST-in-REAL DQ:first failed / unknown / not-due stage:
decision: STOP | PAUSE | UNKNOWN | CHANGE | MAINTAIN | BOUNDED_EXPANDdecision scope / claim cap:owner decision-signal ID / authorized next-cohort limit:requested next-cohort limit / exact-match result:one action / owner / due_at:maximum cash / data / client / device / founder-time exposure:human approval required:rollback / recovery / recheck trigger:next cheapest evidence:Codex handoff ID / revision:ai_placement_contract_id / contract_version:task / expected artifact:allowed files / sources / systems:forbidden files / data / systems:environment: SYNTHETIC | SANDBOX | LIMITED_LIVE | LIVEaccounting_environment: TEST | REALsource cutoff / snapshot / maturity:
exact job / outcome / cohort revisions:exact placement / observable runtime / prompt / tool revisions:model identity or OPAQUE receipt — browser/OS build / availability / eval snapshot:exact data-transfer / fallback / eval revisions:
allowed work: official-source diff | schema / query / adapter draft | feature-detection draft | routing-policy draft | synthetic fixture | eval / negative test | reconciliation / DQ | redacted decision memoprohibited autonomous work: collect raw device fingerprint | choose or infer user consent | transfer customer data | activate production routing | change provider / model terms | execute high-impact tool | send customer communication | disable / resume live feature
required positive tests:required negative tests:availability-options exact-match tests:unsupported / download / storage tests:silent-transfer / consent-expiry tests:timeout / retry / duplicate-outcome tests:model / prompt / tool cross-version tests:TEST-to-REAL isolation tests:PII / credential / secret scan:bounded output / redaction rule:
draft artifact hash:test receipt / result:unresolved assumptions / unknowns:human reviewer / approval scope:approved exact external-effect tuple: N/A | opaqueapproval expires_at:release / rollback / recovery reference:Independent review ID / revision:reviewer independence / conflict:official source freshness checked:job / accepted outcome parity checked:cohort assignment / denominator checked:runtime raw availability / derived eligibility checked:Apple on-device vs server/custom claim checked:model identity-or-visibility / runtime / prompt / tool versions checked:data flow / fallback / transparency checked:attempt / one-outcome reconciliation checked:value / cost / support / regression checked:maturity / late-event / TEST-REAL checked:incident / kill-switch / rollback checked:Codex scope / redaction / external effect checked:
review decision: PASS | PAUSE | UNKNOWN | STOPfindings / severity / owner / due:accepted residual risk / human authority:reviewed_at / expires_at / recheck trigger:Weekly and release gate
Section titled “Weekly and release gate”- all assigned clients を分母にし、unsupported / download abandonment / UNKNOWN を残した。
- local、fallback、cloud attempt と one accepted outcome を exact ID で照合した。
- privacy / transparency / high-impact tool は人が exact scope を承認した。
- full-loaded contribution に support / regression / incident / double-path cost が入る。
- source、model、OS / browser、prompt、tool drift を release gate で確認した。
- Codex output を data transfer、production activation、user consent、live action へ自動昇格していない。
- independent reviewer が cohort leakage、silent fallback、double count、rollback を確認した。
-
BOUNDED_EXPANDの job、client、model、data、cost、期間が限定される。
Pack 完了チェック
Section titled “Pack 完了チェック”-
## 書式 1から## 書式 14までが一度ずつ存在する。 - 14 書式すべてが同じ
ai_placement_contract_id / contract_versionを持つ。 - 全書式は空欄コピー用で、実績、benchmark、推奨 threshold、非 synthetic の例を置いていない。
- PII、raw device fingerprint、customer prompt / output、credential、provider secret を含まない。
-
N/A / UNKNOWN / 0 / FAILED / OBSERVED / NOT_DUEを分けた。 - Chrome raw availability の
available / downloadable / downloading / unavailableと derived local eligibility を分けた。 - one job、one client cohort、one accepted-outcome definition を placement 間で維持した。
- assignment は outcome 前で、unavailable / unsupported / abandonment を分母から除いていない。
- browser-provided、app-shipped local、OS-native、cloud-edge、bounded hybrid を分けた。
- Apple on-device
SystemLanguageModelの privacy / offline claim を PCC / custom / server pathへ移植していない。 - browser / OS managed model が opaque の場合、exact hash を捏造せず build、availability、eval snapshot、checked_at を残した。
- model、runtime、OS / browser、prompt、tool、eval、data contract は、観測可能な exact version または managed model の
OPAQUEreceipt を持つ。 - download、readiness、cold / warm latency、fallback、safe terminal の時計を分けた。
- local failure と cloud success を二つの opportunity / accepted outcome / value にしていない。
- local path の analytics / sync / tool、cloud fallback の field / region / retention を data map に入れた。
- silent fallback、timeout fan-out、consent expiry、wrong version、duplicate action を negative test した。
- token bill 0 を total cost 0 にせず、distribution、device、support、regression、incident cost を含めた。
- privacy、security、rights、false disclosure、wrong action、client harm を平均 contribution で相殺していない。
- EU / METI / NIST source を safe harbor、免責、個別適法性、product approval と呼んでいない。
- kill-switch、safe degradation、rollback、resume condition を rehearsal した。
- Codex handoff は redacted / synthetic、bounded、reversible で、live authority を渡していない。
この pack を埋めても、runtime support、model quality、privacy、適法性、顧客受入、positive contribution、将来の model behavior は自動的に証明されない。最終 action は current evidence、actual client / job / data、契約、専門家 review、人の責任に基づいて決める。