Public AIBOM, ahead of EU AI Act enforcement.
AI Bill of Materials per module, model cards per surface, EU AI Act risk-tier classification, red-team summaries, C2PA content provenance. Most platform vendors will get to this in 2026 because they have to. FlyttGo is here in 2025 because procurement asks.
- AI surfaces · live8
- High-risk · EU AI Act3
- Surfaces with HITL5
- Unacceptable-risk surfaces0
Four anchors for AI transparency.
- AG.PR.01
AIBOM · AI Bill of Materials
Per-module declaration of every model in production: weights origin, training data class, retraining cadence, drift telemetry. Refreshed in the changelog every release.
- AG.PR.02
Model cards on every surface
Each model surface ships a model card declaring intended use, out-of-scope use, performance bounds, fairness evaluation, demographic and geographic coverage, known failure modes.
- AG.PR.03
EU AI Act risk-tier classification
Pre-emptive classification of every AI surface against the EU AI Act risk taxonomy (minimal / limited / high / unacceptable). Public registry, refreshed when a surface changes risk-tier.
- AG.PR.04
Red-team summary archive
Annual external red-team exercises against every high-risk surface (Identra liveness, Payvera fraud, Civitas triage). Executive summaries published; technical reports available under MNDA.
Eight surfaces. Every model accounted for.
| Code | Module | Surface · model · weights | Risk-tier | HITL |
|---|---|---|---|---|
| AG.S.01 | Transify | Provider routing optimiser Routes orders across providers optimising cost × time × coverage under regulatory constraints (cabotage, hazmat). model: Custom multi-objective optimiser + tabular regressionweights: In-house · weekly retrained | Limited | No |
| AG.S.02 | Workverge | Shift dispatch optimiser Suggests shift coverage and dispatch order under labour-law constraints. Operator approves the slate. model: Constraint solver + heuristic warm-startweights: In-house · daily retrained | Limited | Yes |
| AG.S.03 | Civitas | Application triage classifier Triages incoming citizen applications into the responsible agency. Civil servant validates before action. model: Fine-tuned multilingual transformerweights: In-house · monthly retrained | High | Yes |
| AG.S.04 | Identra | Liveness + spoofing detection Liveness detection during identity verification. Adversarial-tested against PA-DSS 4 attack vectors. model: Vision transformer · liveness ensembleweights: Hybrid · vendor-licensed core | High | Yes |
| AG.S.05 | Payvera | Anomaly + fraud scoring Real-time anomaly scoring on payment intents. Falls back to rule engine if model uncertainty exceeds threshold. model: Gradient-boosted ensemble + behavioural sequence modelweights: In-house · streaming-updated | High | Yes |
| AG.S.06 | EduPro | Cohort analytics aggregator Privacy-preserving cohort analytics — no per-student inferences ever leave the boundary. model: Differential-privacy-aggregated tabular modelweights: In-house · DP-SGD trained | Limited | No |
| AG.S.07 | AskFlyttGo | Procurement assistant (planned) Drafts CAIQ responses, RFP responses, custom proposals. Every artefact carries a signed provenance manifest. model: Anthropic Claude · Sonnet tier · grounded retrievalweights: Vendor · context-only | Limited | Yes |
| AG.S.08 | FlyttGo Marketplace | Pricing intelligence Per-region reference pricing surfaced to buyers; anomaly flags on under/over-priced supply for the operator. model: Per-corridor reference price + anomaly detectionweights: In-house · daily refreshed | Limited | No |
Risk-tier follows the EU AI Act taxonomy. Surfaces categorised ‘high’ carry mandatory HITL, full model card, fairness evaluation and quarterly drift report.
Six quarters tracked publicly, ahead of enforcement.
- AG.RM.Q3.25Q3 2025
Initial AIBOM published
First public AIBOM listing every AI surface across the platform. Voluntary; not yet a regulatory requirement.
- AG.RM.Q4.25Q4 2025
Model cards for high-risk surfaces
Identra liveness, Payvera fraud and Civitas triage shipped first model cards.
- AG.RM.Q1.26Q1 2026
Risk-tier classifications complete
Every AI surface tagged against the EU AI Act risk taxonomy. Registry refreshed monthly.
- AG.RM.Q2.26Q2 2026
External red-team baseline
First external red-team exercise across all high-risk surfaces. Executive summary published.
- AG.RM.Q3.26Q3 2026
EU AI Act enforcement begins
High-risk obligations enforceable from August 2026. FlyttGo positions ahead of the line, not at it.
- AG.RM.Q4.26Q4 2026
C2PA content provenance · GA
Every AI-generated artefact (proposals, summaries, CAIQ responses) signed with a C2PA provenance manifest.
AI transparency is one layer of the trust framework.
The AIBOM doesn't stand alone — it sits inside the broader trust posture and the agent surface. The four pathways below take a programme from this manifest into a signed engagement.
- AI.00
AI agent surface
How LLM agents discover and drive FlyttGo safely. The procurement assistant lives here.
AI.00 · MCP · scopes · HITL - TC.00
Trust artefacts
SOC 2, ISO 27001, DPA, subprocessors. Full red-team reports under MNDA.
TC.00 · 8 artefacts - SB.00
SBOM registry
Software Bill of Materials per release — the engineering supply-chain side of the manifest.
SB.00 · CycloneDX 1.6 - CB.00
Open AI scoping
Routed under CT.01 platform architecture session — AI-led security review track.
CT.01 · CB.00