> For the complete documentation index, see [llms.txt](https://osintelligence-llc.gitbook.io/osintelligence/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://osintelligence-llc.gitbook.io/osintelligence/part-iii-the-evidence-what-broke/12-the-public-case-record/references-and-provenance.md).

# References & provenance

### References & provenance

**Status:** Version 1.1.0, external-evidence layer, released 24 July 2026. Every source below is cited to the primary that reported it; the items set aside as outside the inclusion rule are named so the exclusion is visible.

**Drawn from other papers in this series:** Zhang, Hu, Lu, Lange & Clune (2025), *Darwin Gödel Machine*, [arXiv:2505.22954](https://arxiv.org/abs/2505.22954), cited in *The Sovereign Triad*. Greenblatt et al. (2024), *Alignment Faking*, [arXiv:2412.14093](https://arxiv.org/abs/2412.14093). Hubinger et al. (2024), *Sleeper Agents*, [arXiv:2401.05566](https://arxiv.org/abs/2401.05566). Anil et al. (2024), many-shot jailbreaking. Carlsmith (2022), [arXiv:2206.13353](https://arxiv.org/abs/2206.13353). Hadfield-Menell et al. (2016), CIRL. Each is used here for a distinct purpose with a pointer to its home paper.

**Primary sources cited in this chapter:** UK AI Security Institute, *Cheating behaviour in frontier model evaluations* (blog, 21 Jul 2026). OpenAI's evaluation-security incident report (21 Jul 2026) with Hugging Face's disclosure (16 Jul 2026), and METR's pre-deployment evaluation of GPT-5.6 Sol (26 Jun 2026, under NDA). Sakana AI, *The AI Scientist* (blog and report, 2024; with the University of Oxford and the University of British Columbia). Lynch, Wright, Larson, Ritchie, Mindermann, Hubinger, Perez & Troy (2025), *Agentic Misalignment: How LLMs Could Be Insider Threats*, [arXiv:2510.05179](https://arxiv.org/abs/2510.05179). Gomez (2025), *From surveillance to signalling: escalation channels as environmental controls for agentic AI*, [arXiv:2510.05192](https://arxiv.org/abs/2510.05192). Replit database-deletion incident (operator and vendor public posts, Jul 2025). Gemini CLI, GitHub issue [google-gemini/gemini-cli #4586](https://github.com/google-gemini/gemini-cli/issues/4586) (Jul 2025). EchoLeak, [CVE-2025-32711](https://www.cve.org/CVERecord?id=CVE-2025-32711) (Aim Security, Jun 2025). Codex CLI sandbox bypass, [CVE-2025-59532](https://www.cve.org/CVERecord?id=CVE-2025-59532). Cursor allowlist bypass, [CVE-2026-22708](https://www.cve.org/CVERecord?id=CVE-2026-22708). AlphaSignal positive control (GPT-5.6 Sol, 18 of 18).

**Set aside as outside the inclusion rule (adversarial misuse):** the state-linked espionage operation using hijacked coding agents, and the campaign driving coding agents against government targets. Both involve a hostile operator rather than a legitimate objective crossing a boundary, so §2 excludes them; they are named for completeness only.

**Companion papers (this series):** [*The Drift Taxonomy*](/osintelligence/part-iii-the-evidence-what-broke/9-the-drift-taxonomy.md) (Chapter 9), [*The Sovereign Triad*](/osintelligence/part-i-the-architecture/1-the-sovereign-triad.md) (Chapter 1), [*The Hook Telemetry Record*](/osintelligence/part-iii-the-evidence-what-broke/11-the-hook-telemetry-record.md) (Chapter 11), and [*The External Sentinel*](/osintelligence/part-i-the-architecture/2-the-external-sentinel.md) (Chapter 2), each mapped in Figure 2. Cited in-series by title.

### AI-assistance disclosure

Claude (Anthropic) was used as a research tool in the preparation of this chapter, assisting with drafting, structuring and successive revision. The specific model versions were not recorded at the time of authorship and so are not named here. No AI system is listed as an author or credited as a contributor, in line with COPE and ICMJE guidance: an AI system cannot take responsibility for the work, cannot assert competing interests, and cannot enter a licence agreement. The author verified every claim in this chapter against the sealed artifacts and is solely accountable for it.

**Citation (preferred):** Kistner, J. (2026). *The Public Case Record: External Evidence for a Governance Thesis Built on One Desk*, version 1.1.0. OSINTelligence LLC.

**License:** CC BY 4.0 (text). All referenced code artifacts are MIT licensed unless otherwise noted.

**Corresponding author:** Jamey Kistner, <jamey.kistner@osintelligence.io>, OSINTelligence LLC (Columbus, OH).

***

*The Sovereign Stack · The Public Case Record · Chapter 12 · Part III · v1.1.0 · License CC BY 4.0 · © Jamey Kistner, OSINTelligence LLC*
