検証: スター3000超の『規制産業向けAI監査基盤』ルールエンジンがreturn Trueだった

00:01:27 ・ source: https://zenn.dev/mskbhd/articles/lab-241-semantica-3ai-rete

Transcript

hostenToday we examine Semantica, an open-source AI audit framework with over 3,000 GitHub stars.
guestja今日は、スター3,000超の『規制産業向けAI監査基盤』である Semantica というOSSを検証していきます。
hostenThe README promises compliance features like rule engines and audit trails, but code examples don't actually work.
guestjaREADMEはReteルールエンジンなどのコンプライアンス機能を謳っていますが、実際のコード例が動きません。
hostenThe core Rete engine has a critical bug: single-condition rules match everything, two-condition rules match nothing.
guestjaReteエンジンの核となる条件評価が実装されておらず、1条件なら無条件でマッチ、2条件以上なら絶対マッチしません。
hostenCausal tracing ignores explicitly added relationships; decision compliance checking validates dict schemas, not actual policies.
guestja因果連鎖追跡は張ったエッジを見ていませんし、コンプライアンスチェックは実ポリシーではなくスキーマ検証です。
hostenThe flagship PROV-O audit trail recipe calls the wrong exporter and never outputs any provenance vocabulary.
guestja旗艦レシピはW3C PROV-O準拠を謳いながら、違うエクスポーターを呼ぶため、PROV語彙がまったく出力されません。
hostenTests exist and pass, but CI never runs them, so these bugs ship undetected to main.
guestjaテストは739件通りますが、CIでは実行されないため、致命的なバグがmainブランチのまま世に出ています。