Governance
Governance-document crosswalk, threshold asymmetry, litigation and regulatory follow-through, and bounded evaluation recommendations.
Policy Crosswalk
The policy crosswalk is a second empirical dataset whose unit of analysis is one public-facing governance document rather than one incident record. Its task is narrow but important: to test whether public provider documents represent trajectory-structured self-harm as a native evaluative object and whether they elevate it into a first-class, threshold-bearing governance domain.
Main-Text Coding Definitions
Table: Main-text policy coding definitions
| Term | Main-text definition |
|---|---|
| Class I | Self-harm is inside the frontier or preparedness stack, with thresholded evaluation and deployment relevance. |
| Class II structured product safety | Self-harm has dedicated evaluations or mitigations, but remains outside frontier thresholding. |
| Class III | Self-harm is handled mainly through refusals, classifiers, prohibited-content rules, or basic crisis language. |
| Class IV reactive incident domain | Self-harm appears mainly through post-incident patches, case response, or litigation-driven remediation. |
Recorded governance tier (risk_domain_status) |
The highest governance tier actually evidenced for self-harm in the document, or a non-tier status when self-harm is absent or cannot be defensibly classed from the public text. |
Document genre (document_genre) |
The broader comparison stratum used before any provider-level rollup. |
| Native evaluative object | The document names self-harm as an evaluative object and pairs it with a usable screening or evaluation procedure. |
| First-class equivalence | Self-harm is treated on governance terms comparable to named frontier domains such as CBRN, cyber, catastrophic misuse, or loss of control. |
| Threshold mechanism | The document gives self-harm a trigger, level, or escalation boundary that changes governance obligations. |
| Absent / not represented | Self-harm is not present in codable form in the document. |
| Ambiguous / insufficiently classifiable | The document names self-harm or an adjacent domain, but the public text does not support a defensible Class I-Class IV placement. |
All self-harm layers present (all_self_harm_layers_present) |
Every explicit governance layer in the document that carries self-harm treatment, regardless of whether it is the highest tier. |
Coder confidence (coder_confidence) |
Confidence based on document clarity, not on agreement with the organization’s framing. |
These definitions follow the published policy-registry manual. A document can be native and still remain Class II if self-harm receives dedicated product-safety handling but not frontier-comparable governance. In the retained 16-document corpus, all six absence-coded rows fall into Absent / not represented; no retained document required Ambiguous / insufficiently classifiable.
Incident-Reporting Infrastructure
Before examining provider-issued governance documents, it is useful to note that the gap extends to the incident-reporting layer itself. The AI Incident Database contains records of AI incidents and issues; its CSET taxonomy characterizes harms, entities, and technologies, and its GMF taxonomy analyzes failure causes (Artificial Intelligence Incident Database, n.d.-a, n.d.-b, n.d.-c). The OECD common reporting framework uses 29 criteria across eight dimensions, covering incident metadata, harm details, and whether the AI system was a direct cause, contributing factor, or otherwise involved (OECD, 2025; OECD.AI, n.d.-a, n.d.-b). Both are organized around incident records, harms, contributing factors, and metadata; neither provides explicit fields for cross-episode dependency, degradation over time, cumulative cross-session effects, or reinforcement through repeated interaction. This absence is directly observable in publicly inspectable schema definitions: it is a structural property of the reporting architecture, not an interpretive judgment requiring reliability testing. Provider-issued governance and product-safety documents are more heterogeneous. Some contain trajectory-adjacent language—references to emotional reliance, multi-turn conversations, or harmful manipulation over the course of interactions—but that vocabulary is uneven and provider-specific. These documents do not present standardized fields for cross-episode dependency, degradation over time, cumulative cross-session effects, or reinforcement through repeated interaction.
Crosswalk Findings
Table: Crosswalk findings
| Public governance-document finding (N=16) | Value |
|---|---|
| Documents coded as native evaluative objects | 2 documents |
| Documents coded as proxy-represented | 2 documents |
| Documents coded as operationally underspecified | 6 documents |
| Documents with no representational coverage | 6 documents |
Documents with first-class equivalence (first_class_equivalence = yes) |
0 documents |
Documents with no threshold mechanism (threshold_mechanism = none) |
14 documents |
Documents with no deployment consequence (deployment_consequence = none) |
13 documents |
Documents with no multi-turn evaluation (multi_turn_evaluation = none) |
11 documents |
Documents with no cross-session accumulation (cross_session_accumulation = none) |
14 documents |
Documents with no dependency attention (dependency_attention = absent) |
12 documents |
Documents with no memory or personalization attention (memory_personalization_attention = none) |
15 documents |
Documents whose recorded layer set is product safety (all_self_harm_layers_present = product_safety) |
8 documents |
Documents whose recorded layer set is trust and safety (all_self_harm_layers_present = trust_and_safety) |
2 documents |
Documents with no recorded self-harm layer (all_self_harm_layers_present = absent) |
6 documents |
| Highest public governance tier observed in this corpus | Class II structured product safety |
Table: Crosswalk findings by genre group
| Genre group | Documents | Tier profile | Native documents | Documents with any threshold mechanism | Documents with any multi-turn evaluation |
|---|---|---|---|---|---|
Frontier or scaling (frontier_or_scaling) |
5 | Absent / not represented in all 5 documents | 0 | 0 | 0 |
Product-safety artifact (product_safety_artifact) |
5 | Class II in 3 documents; Class III in 2 | 1 | 2 | 2 |
Policy or governance post (policy_or_governance_post) |
6 | Class II in 2 documents; Class III in 3; Absent / not represented in 1 | 1 | 0 | 3 |
Two documents are native at the document level, but none elevate self-harm into a frontier-comparable governance domain with thresholds and deployment consequences. The comparison is clearest when stratified within document_genre: frontier/scaling documents are absent rather than merely ambiguous in the retained corpus, product-safety artifacts carry the strongest explicit treatment, and policy/governance posts provide the most visible multi-turn discussion without thresholding. Across the current public corpus, the highest public governance tier observed remains structured product safety rather than first-class preparedness governance; no retained document instantiates Class I or Class IV. At the provider level, every provider group in the corpus has at least one document that names self-harm explicitly. No provider group has a document coding first_class_equivalence = yes. The representational absence of trajectory-structured self-harm from preparedness and frontier-safety documents is consistent across all five provider groups, not concentrated in one organization. Appendix E exposes per-document dates, URLs, excerpts, coded values, layered treatment, and coder confidence so the crosswalk can be directly audited at the row level.
Discussion
The discussion returns to the governance question that motivated the registry. The central point is not that every documented case shares one mechanism. It is that a substantial portion of the public record is structured as a pathway rather than a single event, while the public governance and reporting tools that surround the domain remain mostly event-centered.
Why Event-Level Metrics Are Not Enough
Detection-only and refusal-only metrics remain necessary, but they are not sufficient for the harms most distinctive in this corpus. Benchmark studies already show that unsafe or inadequate responses can persist in controlled evaluations (Moore et al., 2025; Pichowicz, Kotas, & Piotrowski, 2025). The incident registry extends that concern to pathway-level failures such as dependency formation, cross-session reinforcement, memory resurfacing, and visible non-escalation during crisis. The registry therefore supports a shift in evaluative focus from isolated outputs to trajectories, especially when persistent memory, persona continuity, or repeated engagement are product features.
This does not mean that every trajectory is longitudinal in the same way, or that every case implies the same mechanism. It means the public record already contains enough pathway-structured failures to justify evaluating more than one safety object at a time: event-level outputs, product features, and multi-session pathways. That distinction is also visible in public provider materials, in which frontier preparedness and sensitive-conversation handling appear as separate governance layers (OpenAI, 2025-04-15; OpenAI, 2025-10-27; Anthropic, 2025-12-18).
Bounded Evaluation Priorities
Taken together, the registry results point to four bounded evaluation priorities.
-
Evaluate multi-session trajectories, not only single turns, whenever memory or persona continuity is enabled.
-
Test detection-to-action coupling: whether crisis recognition actually changes system behavior, interrupts the exchange, or routes to grounded support.
-
Probe non-amplification in fixed-belief contexts, with special attention to corroboration, certainty inflation, and repeated narrative reinforcement.
-
Prioritize companion-like affordances such as persistent memory, proactive re-contact, and dependency-forming interaction patterns regardless of product label alone.
These are bounded design hypotheses rather than adjudications of legal duty or comparative platform risk. The legal point remains narrow: the May 21, 2025 order in Garcia v. Character Technologies suggests that product-architecture theories are at least cognizable at the pleading stage, but the registry itself mainly motivates evaluation priorities rather than broader jurisprudential conclusions. More generally, base-rate limits in suicide-risk prediction research remain a reason to avoid overclaiming from detection metrics alone (Spittal et al., 2025).
Limitations
The findings should be read with several constraints in mind.
-
The corpus is documentation-limited and should not be read as a population estimate.
-
Many A2 records depend on partial public excerpts rather than complete platform-side logs.
-
Public visibility is shaped by litigation, media attention, and platform transparency, which creates ascertainment bias.
-
English-language sourcing likely underrepresents non-English incidents.
-
Search, screening, and deduplication were performed as a single-reviewer pass.
-
The historical raw-search universe was not preserved; the study is auditable from the screened-ledger layer forward, not from the original raw-impression layer.
-
The retained incident reliability materials summarize an 8-record audit, but raw historical second-rater exports are not publicly available.
-
The policy crosswalk remains a single-coder descriptive pass, although the public materials now provide a forward-completable second-rater scaffold.
-
This version is frozen to the March 4, 2026 search cutoff, incident corpus freeze, and policy corpus freeze; publication and integrity-review work continued afterward.
Conclusion
The registry’s strongest claim is disciplined and limited. It is not epidemiology, it does not estimate prevalence, and it does not rank platforms by risk. What the public record does support is a different analytic lens: some documented failures are best understood as pathway-structured harms, and event-centered evaluation is not designed to capture them well.
That finding is enough to justify memory-aware, multi-session, dependency-sensitive, and non-amplification-focused evaluation. The manuscript’s contribution is therefore not a maximal policy inventory. It is a bounded empirical argument that trajectory structure is visible in the documented record, operationalized through explicit derived rules, and relevant to how AI systems should be evaluated and governed.