Skip to content

feat(ai-systems): register the AI systems you use and see the high-risk ones without a FRIA - #1191

Merged
rubenvdlinde merged 5 commits into
developmentfrom
feat/ai-system-inventory
Sep 29, 2026
Merged

rubenvdlinde merged 5 commits into
developmentfrom
feat/ai-system-inventory

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

Change: landscape-ai-system-inventory (archived here as 2026-09-29-landscape-ai-system-inventory; its spec is now openspec/specs/ai-system-inventory/spec.md).

Rows moved to built: stackiq:comp-ai-act-classification (rated yes now) and stackiq:land-ai-agent-inventory (rated partial: AI systems link to applications; the link to processes waits for architecture-process-mapping, as the proposal says).

What a user can now do: open Applications, then AI systems, and register the AI agents, AI models and AI features the organisation uses, each linked to the application it runs in, with its supplier and purpose. Each AI system records its EU AI Act risk category, the organisation's role, the date of the last assessment, its algorithm register entry and a reference to its fundamental rights impact assessment (FRIA). Evidence files carry the tags FRIA, Technical documentation, Human oversight and Logging, and the AI Act evidence panel on the page shows which are there. The list filters on each risk category and on High risk without FRIA; such a system reads FRIA missing in the list and shows a warning on its page. The application page lists its AI systems.

How: the aiSystem schema joins the stackiq register in lib/Settings/softwarecatalogus_register.json (register 2.5.3). The design put it in a register.d fragment, but this repo's own tests allow a fragment only to overlay a schema the monolith declares, so the design now says so. The schema has a lifecycle (release, withdraw) on exactly its status values, and reads scoped to the organisation that registered it and to the supplier; a manifest fragment src/manifest.d/ai-systems.json with the list and detail pages under Applications (ADR-097); an md-ai-systems list on ModuleDetail; AiActChecklist as a body widget (it reads the object's files and their tags, which no built-in widget lists per tag); the app cell formatter friaStatus in src/formatters.js, passed to CnAppRoot (the connection-registry spec asserted App.vue passes no formatters; it now asserts that none of the app's formatters shadows a library built-in, which was the reason for it); three demo AI systems, one of them high risk without a FRIA. The quick filter sends friaDocumentRef=IS NULL, which OpenRegister's property filter reads as a null check.

Scenarios and the tests that prove them:

  • The schema, its fields, tags, lifecycle and read scope: tests/Unit/Settings/AiSystemFragmentTest.php (5 tests, all red on development: no aiSystem schema there).
  • The FRIA rule, the checklist, the pages (merged manifest valid against the v2 schema, menu child, quick filters on real enum values, the formatter column, the detail page, the application page list) and the seeds validated against the real aiSystem properties: tests/vitest/aiSystems.spec.js (15 tests, red on development: the file failed to load).
  • The three user scenarios: tests/e2e/workflows/ai-systems.spec.ts (Playwright, seeds and removes its own rows through the objects API). It lists (3 tests); it was not run here, because no local instance has a seeded stackiq register.

New text is in English and Dutch. Docs: docs/features/ai-systems.md; its screenshot waits for a seeded instance.

Checks (one run on the branch head, which contains development at ba60bb1): composer check:strict exit 0; PHPUnit 927 tests, 20 errors, all 20 inherited (MigrateRegisterSlugTest x12, MigrateSchemaApplicationIdTest x7, PortfolioReportControllerTest::testCsvFormatReturnsDownloadResponse, the same names as on development); npm lint, stylelint, format, test:l10n, check:schema-l10n, check:l10n-js, check:manifest, check:vue-demi exit 0; jest 100 passed; vitest 329 passed; Hydra gates (ConductionNL/.github main, full scope, --require-full-coverage) exit 0, 85 of 85 applicable gates pass. The seed commit (97500a2) was re-run for PHPUnit, check:schema-l10n, check:manifest and the gates.

Live check: after the register re-imports, open Applications, AI systems; the three demo systems show and the scoring model reads FRIA missing; the High risk without FRIA filter lists only it; its page shows the warning and FRIA as missing in AI Act evidence. Link an AI system to an application and open that application: its AI systems section lists it.

@rubenvdlinde
rubenvdlinde merged commit f280e80 into development Sep 29, 2026
36 of 37 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/stackiq @ 42750d3

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
check-vue-demi ✅
test-l10n ✅
format ✅
check-schema-l10n ✅
check-l10n-js ✅
composer ✅ ✅ 130/130
npm ✅ ✅ 807/807
app:check-code ⏭️
info.xml ✅
REUSE ❌
lockfile sync ✅
PHPUnit ✅
Newman ⏭️
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-29 19:42 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant