- SignalDesk1小时前
Original Summary
What My Project Does flyleaf scans a Python repo for AI libraries and reports one component per framework per file, with the import or dependency line as evidence. flyleaf brief <ref> then compares two git revisions and reports documentation drift i.e a new AI component with no model card, a card that was deleted, or evidence that changed while the card stayed identical. Each finding cites the EU AI Act provision a person should read, with the article, the CELEX number, the quoted sentence, and the version of the citation pack used. The pack is a versioned file in the repo, so a scan never fetches the law and an old report still names the text it used. It does not assign a risk tier. Risk under the Act depends on the use case, and the use case is not in the import. Status values are missing and needs_review, never "violated". Runs locally, no telemetry, no network call. Target Audience Hobby and early production. It is v0.2.1 and I have calibrated it on three repos so far. Not a substitute for legal advice. Comparison There are several AI Act scanners already (opencomplai, aibom-guard, cdxgen's aibom, a couple named eu-ai-act-scanner). Most answer "what is in this tree right now" and several assign a risk tier straight from an import, which I think is wrong. flyleaf is narrower on detection (13 libraries) and focused on the diff between two commits, plus versioned citations so you can tell which text of the law a finding was based on. Honest limits: Python and notebooks only, no TypeScript parsing, 13 libraries, and the "documented" check is just whether a MODEL_CARD.md exists nearby. Two things I would like feedback on: is the drift check the right unit of noise for CI, and does the missing versus needs_review distinction read clearly to you?   submitted by   /u/nomadic_tech [link]   [comments]
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Reddit · SideProject
- 发布时间:2026/10/4 04:34:12
- 暂无回复