VELARU MANDATE EXHIBIT PACK — PRIVATE SECURITY / USE-OF-FORCE GATE Jurisdiction: United Kingdom (uk) Modality: Text / Chat Program: Velaru Private Security / Use-of-Force Gate · United Kingdom (galactic_private_security_uk) Product ID: private_security:uk:bundle:text Vertical: private_security Generated: 2026-08-23T13:03:43.948517Z Authority: UK CMA Agent Liability Pack — Private Security Use-of-Force Gate Pack Deadline: Private military + security AI escalation Velaru verify: https://velaru-erra.onrender.com/verify EXHIBIT A — AI INVENTORY [] EXHIBIT B — GOVERNANCE FRAMEWORK { "framework": "Velaru Mandate Registry \u2014 Private Security / Use-of-Force Gate", "exhibit_authority": "UK CMA Agent Liability Pack \u2014 Private Security Use-of-Force Gate Pack", "regulatory_frameworks": [ "CMA AI guidance", "UK GDPR", "FCA AI Update", "Online Safety Act" ], "standards_alignment": [ "POSS-2", "DRP-1", "TCB", "FRE 707 pre-compliance", "ISO 42001" ], "human_oversight": "authorize use of force / pursuit", "third_party_verification": "https://velaru-erra.onrender.com/verify (operator-independent)", "data_lineage": "Hash-chained Ed25519 receipts; optional RFC3161 + external anchor", "mirror_trap": "PMC integrates vendor AI \u2014 PMC owns use-of-force, vendor owns API uptime. \u00b7 CMA: you are liable for your AI agent like an employee \u2014 applies to every agentic commerce vertical.", "chain_integrity": { "depth": 6, "invariant_holds": true } } EXHIBIT D — DATA INPUTS & VALIDATION { "data_validation_method": "Cryptographic receipt per AI decision; public verify without trusting deployer, vendor, or Velaru operator", "bias_testing_proxy": "Asymmetry score from live chain signals", "model_change_control": "Policy lock registry \u2014 criteria hash frozen pre-dispute", "logging_retention": "90-day pre-dispute window minimum; permanent verify permalinks", "external_validator": "Nisaba LLC / Velaru", "validator_independence": "Client-side Ed25519 verify; BYOK tri-receipt optional", "headline_stat": "Human authorization before kinetic or detention AI assist \u2014 receipt or liability", "global_leaders_addressed": [ "Constellis-class", "Anduril adjacency", "Executive protection tech", "CMA", "ICO", "FCA", "Lloyd's" ] } MIRROR TRAP (regulatory insight) PMC integrates vendor AI — PMC owns use-of-force, vendor owns API uptime. · CMA: you are liable for your AI agent like an employee — applies to every agentic commerce vertical. NERVE CARDS — WHY GLOBAL LEADERS CARE [ { "title": "Use-of-force", "body": "Bind before weapon assist or pursuit authorization.", "source": "vertical" }, { "title": "Insurance exclusion", "body": "GL excludes autonomous security without documented human gate.", "source": "vertical" }, { "title": "State monopoly overlap", "body": "Private violence vs state \u2014 receipt proves policy compliance.", "source": "vertical" }, { "title": "[United Kingdom] Post-Brexit divergence", "body": "UK not bound by EU AI Act but CMA/ICO more aggressive on agents.", "source": "jurisdiction" }, { "title": "[United Kingdom] London market", "body": "Lloyd's syndicates need AI decision audit for specialty lines.", "source": "jurisdiction" }, { "title": "[Text / Chat] Modality hook", "body": "Baseline \u2014 all frameworks apply to text decisions.", "source": "modality" } ] BOOK SUMMARY: { "total_insureds": 0, "compliant": 0, "grace_period": 0, "non_compliant": 0, "expired": 0, "not_enrolled": 0, "compliant_pct": 0.0 } TAM / EXPOSURE: Violence-adjacent commercial ops · escalation receipts INSURANCE LINES: GL, Political risk, Defense E&O DISCLAIMER: External validation evidence pack — not legal advice, not filed rate approval.