This compliance control mapping has been withdrawn

On 2026-08-23 Summit Cognitive published a correction to its public claims. The control mapping that stood at this URL is withdrawn in full as part of that correction.

The mapping presented Decision Receipt as a control that stopped non-conforming autonomous actions from proceeding, and attached that reading to named NIST SP 800-171 controls, NIST AI RMF functions and EU AI Act articles. Our own records show that the policy evaluator's verdicts have never controlled a merge in our pipeline. A verdict that no required check consumes does not implement an access control, and a mapping built on that reading should not be relied on by anyone assessing their own compliance posture.

What is still true

Decision Receipt produces signed, hash-chained receipt records: a timestamp, actor metadata, an evidence digest, the policy evaluation and the verdict. Those are real evidence artifacts, and a holder can check their signatures and hash chain against the signing key published at /v1/keys/server and the published specification. What they are not is proof that an action was prevented; that depends on whether the integrating system consumes the verdict as a control.

Where to look instead

The production ledger snapshot states what the ledger contains and the limits of what it supports. The policy reference states what each verdict means. The published specifications, together with the signing key published at /v1/keys/server, are what a receipt holder checks a receipt against.

Withdrawn 2026-08-25. No replacement control mapping is published at this time.