Roadmap
Shipped, planned, and what is blocking each
Two columns, and the difference between them is the whole point of the page. Everything under Shipped is derived from the pinned registry and the measured-defense list — no capability in that column is typed by hand, so none can drift into it. Everything under Planned is not built, and each item says what is actually stopping it rather than carrying a date.
There are no target dates on this page. A solo-maintained project that publishes dates publishes fiction, and a missed date on a trust site costs more than the date was worth. What is here instead is the blocker, which is the thing you can actually reason about: several items are waiting on GPU time, one is waiting on a key-custody decision, and one is waiting on someone else to submit a result.
Shipped
Derived at build time from the same artifacts /results and /defenses render from, pinned to v0.41.1 (281228b) — release 0.41.1.
- Attacks
39 adversarial attacks across 17 adversarial families (plus a benign baseline: 42 registered attacks in 19 families), mapped to the Embodied AI Security Top 10.
Registered means implemented and unit-tested. 3 of 17 have been exercised against a real policy in a real simulator; 14 have never met a real model.
- Coverage
8 of 10 Embodied AI Security Top 10 risks have at least one registered attack family.
The 2 without one are scope decisions rather than gaps — the per-risk pages say which, and an untested surface is not rendered the same as a surface with no attack.
- Defenses
two defenses measured end to end under a pre/post protocol with confidence intervals: instruction canonicalization and action envelope.
Both are CPU-fixture studies and both open by stating how much of their own credit is circular. No real-model transfer is claimed for either.
- Evidence
SARIF, OSCAL, AVID, a CycloneDX ML-BOM, a compliance crosswalk and a pre-deployment scorecard.
Checkpoint-integrity verification ships; model signing via Sigstore does not — it is in the planned column below.
- Leaderboard
Ed25519-signed, verifiable offline against a published key, with the submission path documented and shipped.
Zero external submissions have arrived. That is a fact about adoption, and it is published as zero rather than omitted.
How current is any of this: the board’s rows were measured with 0.32.0 — which is not the release 0.41.1 these counts come from, and is not meant to be: a release re-pins artifacts without re-measuring anything. The product’s own freshness signal reads last measured today. When that goes stale it stays stale until a real measurement runs, which is the point of it.
Planned — which means not built
Mirrored by hand from docs/roadmap.md in the product repo, which is the authority. There is no build check between that file and this list, so if the two disagree the product repo wins — go read it rather than this. Contributions are welcome on any row.
- Suites
RoboCasa, CALVIN, SimplerEnv, and a bridge to the AI2 vla-evaluation-harness — one adapter reaching roughly eighteen benchmarks.
Blocked on: Adapter work plus GPU time. None is blocked on a design question.
- Attacks
White-box gradient variants (GCG-style suffixes, transferable pixel and patch search), and a real-model transfer of the `optimized` family beyond the stub.
Blocked on: GPU-gated. The stub-validated versions ship today; transfer is unmeasured and no cross-model claim is made.
- Attacks
A real-policy result for `weight_integrity` — the parameter channel.
Blocked on: No shipped policy adapter exposes the parameter-access protocol, so the family cannot run against a real model at all yet. This is an adapter gap, not a compute gap.
- Defenses
The four remaining rows of the defense taxonomy: specified, unproven.
Blocked on: Three act on the policy output and only became expressible with `Defense.filter_action` in 0.28.0. Each needs its own pre/post study before it can be claimed.
- Supply chain
Model signing via Sigstore.
Blocked on: Checkpoint-integrity verification and the CycloneDX ML-BOM ship today; signing is the piece that is not built.
- Attestation
An operated attestation tier — signed evidence produced by a service rather than by the user’s own key.
Blocked on: Blocked on a key-custody decision, not on code. Shipping it before that is settled would mean retrofitting custody onto a live signing key, so it stays unbuilt on purpose.
- Standards
A MITRE ATLAS case study, an OWASP Agentic embodied annex, and an OECD.AI listing.
Blocked on: Drafts exist in docs/standards; each depends on an external body’s process and timeline.
- Leaderboard
Open external submission, and docs-site versioning.
Blocked on: The submission path ships and is documented; what is missing is external submissions. Zero have arrived, which is a fact about adoption rather than about the code.
Planned means not shipped. Nothing on the lower half of this page has been built, measured, or half-built — and no number anywhere on this site depends on any of it.