{"schemaVersion":"1.0","generatedAt":"2026-08-21","purpose":"AI-RE review package: authentic sources, Y.3172 traceability, AI Readiness self-assessment, and policy gaps","knowledgeBase":[{"id":"y3172","title":"Architectural framework for machine learning in future networks including IMT-2020","publisher":"ITU-T Study Group 13","edition":"Recommendation ITU-T Y.3172 (06/2019)","url":"https://www.itu.int/rec/T-REC-Y.3172-201906-I/en","about":"Defines the ML pipeline through named nodes: SRC, C, PP, M, P, D and SINK. It also defines the layer that manages them. Clause 8.1 contains the pipeline definition.","usedFor":"The platform's architecture is described in these seven nodes, and each node names the component implementing it and the policy governing it. This is the primary conformance reference.","appliedIn":["src/lib/standards.ts","src/components/PipelineDiagram.tsx"]},{"id":"ai-ready-2","title":"AI Ready: Analysis Towards a Standardized Readiness Framework, Report 2.0","publisher":"ITU","edition":"January 2026 · ISBN 978-92-61-41911-0","url":"https://aiforgood.itu.int/event/ai-readiness-hackathon-kingdom-of-saudi-arabia/","about":"Defines 13 dimensions of AI readiness and a three-part framework for identifying gaps.","usedFor":"Fursah assesses its work against all 13 dimensions. It also uses the report's framework to organise policy gaps. Dimension 9 identifies skills gap analysis as a desired output, which is a central function of Fursah.","appliedIn":["src/lib/standards.ts"]},{"id":"y3181","title":"Architectural framework for machine learning sandbox in future networks including IMT-2020","publisher":"ITU-T Study Group 13","edition":"Recommendation ITU-T Y.3181 (2022)","url":"https://www.itu.int/rec/T-REC-Y.3181/en","about":"Specifies a sandbox in which an ML model or policy is evaluated before it is allowed to affect a live system.","usedFor":"The governance scenario simulator: a proposed control is stated, checked against the safeguards, and requires a recorded human decision before activation.","appliedIn":["src/actions/governance.ts","src/app/admin/governance/page.tsx"]},{"id":"y3176","title":"Machine learning marketplace integration in future networks including IMT-2020","publisher":"ITU-T Study Group 13","edition":"Recommendation ITU-T Y.3176 (2020)","url":"https://www.itu.int/rec/T-REC-Y.3176/en","about":"Covers orchestration, versioning and lifecycle management of ML models across a pipeline.","usedFor":"Every scoring surface stamps its model version onto the audit trail, so a past result can be traced to the ruleset that produced it and that ruleset can be rolled back.","appliedIn":["src/lib/intelligence/readiness.ts","src/app/admin/monitoring/page.tsx"]},{"id":"pdpl","title":"Personal Data Protection Law","publisher":"Kingdom of Saudi Arabia","edition":"Royal Decree M/19 of 1443H, as amended by M/148, with Implementing Regulations","url":"https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf","about":"The national law for lawful processing, data minimisation, individual rights, and transfers outside the Kingdom.","usedFor":"The privacy policy follows this law clause by clause. Fursah does not collect protected characteristics. Consent is specific to each purpose and can be withdrawn. The platform also supports four data-rights requests.","appliedIn":["src/lib/policies.ts","src/app/student/data-rights/page.tsx","docs/DPIA.md"],"language":"Arabic and English"},{"id":"sdaia-ethics","title":"AI Ethics Principles","publisher":"SDAIA, Saudi Data and Artificial Intelligence Authority","edition":"Version 1.0","url":"https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf","about":"Seven principles for AI in the Kingdom, including fairness, transparency and explainability, accountability, and human oversight.","usedFor":"Every score can be reconstructed from published weights. A named reviewer can also override any automated result. These controls support explainability and human oversight.","appliedIn":["src/lib/ai.ts","src/lib/policies.ts"],"language":"Arabic and English"},{"id":"ndmo","title":"National Data Management and Personal Data Protection Standards","publisher":"NDMO, National Data Management Office at SDAIA","edition":"Current issue","url":"https://sdaia.gov.sa/ndmo/Files/PoliciesEn.pdf","about":"Data classification, quality, retention and governance controls for data held in the Kingdom.","usedFor":"Classification of evidence documents as private by default, the retention posture, and the aggregate-only treatment of institutional reporting.","appliedIn":["src/lib/documents.ts","src/lib/cohort.ts"],"language":"Arabic and English"},{"id":"nca-ecc","title":"Essential Cybersecurity Controls (ECC) and Cloud Cybersecurity Controls (CCC)","publisher":"NCA, National Cybersecurity Authority","edition":"ECC-1:2018 · CCC-1:2020","url":"https://nca.gov.sa/en/regulatory-documents/controls-list/","about":"Baseline cybersecurity controls for national organisations and for workloads hosted in cloud environments.","usedFor":"Private object storage with no public bucket access, server-held credentials that never reach the browser, and the hosting-region gap recorded openly in the DPIA rather than left implicit.","appliedIn":["src/lib/r2.ts","src/lib/assistant/llm.ts","docs/DPIA.md"],"language":"Arabic and English"},{"id":"dga-accessibility","title":"Digital Accessibility Standards and Guidelines","publisher":"DGA, Digital Government Authority","edition":"Current issue","url":"https://dga.gov.sa/en/policies-and-regulations","about":"Accessibility and interoperability requirements for digital services, referencing WCAG 2.1 Level AA.","usedFor":"The accessibility statement's conformance target, the Arabic runtime layer across every portal, and the keyboard and contrast requirements applied to the interface.","appliedIn":["src/lib/i18n/translate.ts","src/components/AccessibleViewControls.tsx"],"language":"Arabic and English"},{"id":"vision2030","title":"Saudi Vision 2030 and the Human Capability Development Program","publisher":"Kingdom of Saudi Arabia","edition":"Programme documents and published KPIs","url":"https://www.vision2030.gov.sa/","about":"National strategy, including the commitment to align education with labour-market needs and the published unemployment and participation targets.","usedFor":"The stated alignment on the National Impact page, quoted against specific programme commitments rather than the strategy in general.","appliedIn":["src/lib/nationalImpact.ts"],"language":"Arabic and English"},{"id":"gastat","title":"Labour Force Survey","publisher":"GASTAT, General Authority for Statistics","edition":"Q3 2024 and Q2 2025 releases","url":"https://www.stats.gov.sa/en/w/news/6","about":"The official quarterly labour statistics: unemployment, participation, and employment-to-population ratios.","usedFor":"The labour indicators on the National Impact page, and the evidence for the argument that the Kingdom's constraint is matching quality rather than aggregate participation.","appliedIn":["src/lib/nationalImpact.ts"],"language":"Arabic and English"},{"id":"cua","title":"Graduate statistics","publisher":"Council of Universities Affairs","edition":"2023","url":"https://www.cua.gov.sa/","about":"Annual graduate totals by degree level across the Kingdom's universities.","usedFor":"The 2023 graduate figure and its degree-level breakdown on the National Impact page.","appliedIn":["src/lib/nationalImpact.ts"],"language":"Arabic"},{"id":"unesco-gem","title":"Global Education Monitoring Report: Saudi Arabia country case study","publisher":"UNESCO","edition":"2026 edition","url":"https://www.unesco.org/gem-report/en/2026-gem-report-country-case-studies/saudi-arabia","about":"Tertiary enrolment growth and the shift in the distribution of graduates by field of study.","usedFor":"The field-mix argument: that graduate output grew while concentrating in some fields, which is the distributional problem Fursah addresses.","appliedIn":["src/lib/nationalImpact.ts"]},{"id":"iso42001","title":"ISO/IEC 42001:2023: Artificial intelligence management system","publisher":"ISO/IEC","edition":"2023","url":"https://www.iso.org/standard/81230.html","about":"Management-system requirements for organisations developing or using AI, including risk and impact assessment.","usedFor":"The structure of the governance surfaces: recorded decisions, model versioning, monitoring with a paused state, and a documented impact assessment.","appliedIn":["docs/DPIA.md","src/app/admin/monitoring/page.tsx"]},{"id":"iso23894","title":"ISO/IEC 23894:2023: Guidance on risk management for AI","publisher":"ISO/IEC","edition":"2023","url":"https://www.iso.org/standard/77304.html","about":"Guidance on identifying, analysing and treating risks specific to AI systems.","usedFor":"The risk register in the DPIA, including the treatment decision recorded against each risk.","appliedIn":["docs/DPIA.md"]},{"id":"dpia","title":"Data Protection Impact Assessment","publisher":"Fursah AI, Trust and Safety","edition":"Version 1.1 · 21 August 2026 · prototype assessment","url":"https://github.com/Shoug-Alomran/AI-Powered-Workforce-Readiness-Ecosystem/blob/main/docs/DPIA.md","about":"Assessment of the processing this platform performs: evidence uploads and R2 storage, Workers AI inference, the role-scoped assistant, deterministic scoring and matching, university aggregation and cohort suppression, human verification, and appeals and data rights. Opens with a one-page summary and carries an eight-risk register with residual ratings.","usedFor":"The controls it records are the ones implemented in this repository, and the two verification scripts assert them against live data. Cross-border inference is recorded as blocking for production rather than resolved.","appliedIn":["src/lib/cohort.ts","scripts/verify-privacy.ts","scripts/verify-evidence.ts"]},{"id":"sdgs","title":"Sustainable Development Goals: targets 4.4, 5.5, 8.5, 8.6 and 10.3","publisher":"United Nations","edition":"2030 Agenda","url":"https://sdgs.un.org/goals","about":"The official target wording against which contribution can be assessed by published indicator.","usedFor":"The SDG alignment on the National Impact page, cited to the numbered target rather than the goal alone.","appliedIn":["src/lib/nationalImpact.ts"]}],"y3172Pipeline":[{"id":"SRC","label":"Source","standardFunction":"Supplies the data used as input to the ML pipeline.","fursah":"Evidence documents, employer role requirements, university offerings","implementation":["prisma/schema.prisma","src/lib/documents.ts","src/actions/employer.ts"],"governs":"PDPL · NDMO data classification","tone":"data"},{"id":"C","label":"Collector","standardFunction":"Collects data from one or more source nodes.","fursah":"Role-scoped ingestion through APIs, identity federation and institutional integration","implementation":["src/app/api/","src/lib/session.ts","src/lib/r2.ts"],"governs":"NCA ECC & CCC · DGA interoperability","tone":"data"},{"id":"PP","label":"Preprocessor","standardFunction":"Cleans, aggregates and otherwise prepares collected data before it reaches the model.","fursah":"Extraction, normalisation to the skill taxonomy, consent enforcement","implementation":["src/lib/evidence-ai.ts","src/lib/careerTracks.ts","src/actions/documents.ts"],"governs":"PDPL data minimisation · DPIA","tone":"data"},{"id":"M","label":"Model","standardFunction":"Hosts the machine learning models that produce the pipeline's output.","fursah":"Deterministic scoring engine + grounded language model","implementation":["src/lib/intelligence/readiness.ts","src/lib/ai.ts","src/lib/assistant/llm.ts"],"governs":"SDAIA AI Ethics · ISO/IEC 42001 & 23894","tone":"model"},{"id":"P","label":"Policy","standardFunction":"Carries the policies that constrain how the pipeline may operate.","fursah":"Consent rules, review thresholds, suppression floor, and the human override that binds M","implementation":["src/actions/governance.ts","src/lib/cohort.ts","src/lib/policies.ts"],"governs":"SDAIA human oversight · PDPL rights","tone":"human"},{"id":"D","label":"Distributor","standardFunction":"Distributes the model's output results to their destinations.","fursah":"Releases each result only to the role authorised to receive it; aggregates suppressed below 5 students","implementation":["src/lib/intelligence/ecosystem.ts","src/lib/cohort.ts","src/lib/assistant/context.ts"],"governs":"National Data Governance · cloud hosting rules","tone":"data"},{"id":"SINK","label":"Sink","standardFunction":"Receives the distributed output and acts on it.","fursah":"Student, employer, university and policy interfaces","implementation":["src/app/student/","src/app/employer/","src/app/university/","src/app/workforce-intelligence/"],"governs":"DGA accessibility (WCAG 2.1 AA) · Arabic-first","tone":"data"}],"aiReadinessDimensions":[{"number":1,"title":"Data/model Marketplace","measures":"Creation of an environment where data, expert knowledge and models are exchanged and turned into business value.","coverage":"partial","fursah":"The skill taxonomy is a shared reference that employers, universities and students all write against, which is the precondition for exchange. No marketplace or monetisation layer exists in the prototype.","evidence":"src/lib/careerTracks.ts"},{"number":2,"title":"Generated Content Marketplace","measures":"Ease of creating new datasets, models and services by plugging existing materials together.","coverage":"out-of-scope","fursah":"Fursah generates no tradeable content. The language model reads documents and explains results; it produces no dataset or model asset intended for reuse or exchange."},{"number":3,"title":"Cross-domain correlation analysis","measures":"Similarities and patterns across domain workflows, and opportunities to integrate AI across them.","coverage":"partial","fursah":"The platform compares higher education with labour demand. It publishes the coverage gap between them as one figure.","evidence":"src/lib/intelligence/ecosystem.ts"},{"number":4,"title":"Contextualization and Regional Impact","measures":"Adaptation of solutions to regional context: locally collected data, regional guidelines, indigenous solutions.","coverage":"addressed","fursah":"Built for the Saudi context rather than localised into it: the taxonomy, the evidence types, the Arabic interface layer, and the governance mapping to PDPL, SDAIA, NDMO and NCA instruments are all regional inputs, not translations of a foreign design.","evidence":"src/lib/i18n/, src/lib/policies.ts"},{"number":5,"title":"Level of Integration of AI in Workflows","measures":"How well AI is integrated into a domain workflow and what benefit it delivers; interoperability of the interfaces involved.","coverage":"addressed","fursah":"AI supports four defined points in the education-to-employment workflow: evidence extraction, readiness scoring, role matching, and curriculum alignment. Each point has a named input, a named output, and a later human decision.","evidence":"src/lib/intelligence/"},{"number":6,"title":"Human Interface","measures":"Accessibility of interfaces, multi-modal content, local language availability, ease of interaction for people with special needs.","coverage":"addressed","fursah":"Arabic runs as a full runtime layer across every portal rather than a separate site, targets WCAG 2.1 AA, and the role-scoped assistant provides a conversational route to the same figures the dashboards show. The accessibility conformance claim is internal review, not an independent audit.","evidence":"src/lib/i18n/translate.ts, src/components/FursahAssistant.tsx"},{"number":7,"title":"Strategy Alignment","measures":"Coordination of AI integration across industry, academia, and government.","coverage":"addressed","fursah":"The three stakeholder groups the report names are the platform's three portals, and the intelligence layer is the coordination mechanism between them. Alignment to the Human Capability Development Program is stated against specific commitments.","evidence":"src/lib/nationalImpact.ts"},{"number":8,"title":"Collaboration with AI","measures":"The degree to which humans dynamically interact with and shape AI output, rather than only consuming it.","coverage":"addressed","fursah":"Every extraction is a proposal a human accepts or rejects, and the rejection is retained. Students may dismiss a suggested career direction, and appeals against any automated result route to a named reviewer whose decision supersedes the model.","evidence":"src/actions/documents.ts, src/actions/governance.ts"},{"number":9,"title":"Impacts of Humans in AI Integration","measures":"Skill levels, talent development capacity, and analysis of the skills that are currently lacking.","coverage":"addressed","fursah":"This is the platform's primary output. Fursah computes the skills gap at three resolutions: per student against a target role, per institution against employer demand, and per ecosystem as the set of requested skills no university offering covers.","evidence":"src/lib/intelligence/readiness.ts, src/app/workforce-intelligence/page.tsx"},{"number":10,"title":"AI & Policies","measures":"The ability of decision makers to experiment with and review policy impact using AI, and the readiness of policy to enable AI integration.","coverage":"addressed","fursah":"The governance sandbox lets an operator state a proposed control, see which safeguards it breaches, and record the human decision. The workforce-intelligence surface is the evidence base a policymaker would review between statistical releases.","evidence":"src/app/admin/governance/page.tsx"},{"number":11,"title":"AI for Inclusion","measures":"Use of AI techniques to bridge access gaps for underserved groups.","coverage":"addressed","fursah":"Fursah collects no gender, nationality, age or GPA field, so none can enter a ranking. Assessment is against published criteria identical for every institution, which is the mechanism by which a student from a less prestigious university is scored on evidence rather than on provenance.","evidence":"prisma/schema.prisma, docs/DPIA.md"},{"number":12,"title":"Granular Priorities","measures":"Availability of granular user priorities that map onto broader solutions, and customisation of the model to local context.","coverage":"partial","fursah":"Career tracks carry per-skill weights, and universities set their own offerings, so priorities are expressible at institution level. There is no mechanism yet for a region or sector to set its own weighting over the national taxonomy.","evidence":"src/lib/careerTracks.ts"},{"number":13,"title":"Digital Infrastructure","measures":"Availability of devices, computing capability, connectivity and energy, including the nodes identified in ITU-T Y.3172.","coverage":"partial","fursah":"The Y.3172 nodes are identified and mapped above. Infrastructure readiness is a national measure rather than an application measure. The prototype's hosting remains a declared implementation gap.","evidence":"src/lib/standards.ts"}],"policyRecommendations":[{"id":"fairness-without-attributes","category":"National policy","title":"Fairness cannot be measured without collecting what fairness law forbids collecting","observed":"Fursah deliberately collects no gender, nationality, age or GPA, so no protected characteristic can enter a score. The same decision makes disparate-impact testing impossible: there is no attribute to disaggregate outcomes by.","why":"Data minimisation and demonstrable non-discrimination pull in opposite directions, and no instrument we could find resolves which takes precedence for an employment-adjacent system. Proxies remain: institution, region and career interruption can each stand in for a protected class.","recommendation":"A lawful basis for holding protected attributes strictly for fairness auditing, held separately from the scoring path and accessible only to an auditor. Without it, every minimising system in this category is structurally unauditable.","owner":"SDAIA/NDMO with the Ministry of Human Resources and Social Development","trigger":"An employment-adjacent scoring system enters a controlled pilot or records 100 consequential recommendations.","metric":"Complete separation between audit attributes and scoring inputs, quarterly proxy review, and documented remediation for any material disparity.","reviewCadence":"Quarterly during pilots; annually after approval","blocking":false},{"id":"cross-border-inference","category":"National policy","title":"No in-Kingdom inference path for a prototype at this scale","observed":"Application hosting, object storage and model inference all currently run outside the Kingdom. The DPIA records this as risk R5 and marks it blocking for production.","why":"PDPL transfer conditions are clear about the obligation, but a small project has no accessible compliant inference option: the affordable model-serving platforms are all extraterritorial, and the in-Kingdom alternatives are procurement relationships rather than services one can sign up for.","recommendation":"A published tier of in-Kingdom inference reachable by research and prototype workloads, or a defined sandbox basis under which pre-production systems may use extraterritorial inference on non-production data with disclosure.","owner":"SDAIA, CST and approved in-Kingdom cloud providers","trigger":"Before production personal data or identifiable evidence is sent to a model endpoint.","metric":"All production inference and evidence storage completed in an approved region, with processor and transfer records retained.","reviewCadence":"Before launch and after every hosting or model-provider change","blocking":true},{"id":"skills-taxonomy-interoperability","category":"International standards","title":"No standard skill taxonomy for education-to-employment interoperability","observed":"Matching a course outcome to an employer requirement requires both to name the same skill. No national or international taxonomy is authoritative here, so Fursah carries its own seeded reference table.","why":"This is a data-harmonisation gap of the kind chapter 4 names directly. Every platform in this category invents its own taxonomy, which makes results incomparable between platforms and prevents an institution from carrying its mapping to another system.","recommendation":"A standardised, versioned skill taxonomy with a defined extension mechanism, so that a curriculum mapping made once is portable and two platforms' readiness figures mean the same thing.","owner":"SDAIA, Ministry of Education, ETEC and sector skills councils","trigger":"Two institutions or platforms exchange course, credential or vacancy requirements.","metric":"At least 95% of exchanged skills resolve to a versioned national identifier; extensions carry an owner and review date.","reviewCadence":"Twice yearly, with emergency additions for regulated occupations","blocking":false},{"id":"verified-evidence-portability","category":"International standards","title":"Verified credentials are not portable between systems","observed":"A human reviewer approves an uploaded certificate and it becomes verified evidence inside Fursah. That verification cannot leave the platform: another system must re-verify from scratch.","why":"There is no standard representation for 'this evidence was checked by a named party under a stated procedure' that a receiving system can evaluate. Verification effort is therefore duplicated at every boundary, which is the cost that keeps credential checking manual.","recommendation":"A verifiable-credential profile for skills evidence that carries the verifying party, the procedure applied and its date, so a receiving system can decide whether to accept it rather than repeat it.","owner":"Ministry of Education, ETEC and participating credential issuers","trigger":"A verified skill or certificate is shared outside the system that reviewed it.","metric":"Every exported verification carries issuer, reviewer, method, date, status and revocation reference; receiving acceptance is auditable.","reviewCadence":"At issuance, revocation and annual trust-list review","blocking":false},{"id":"no-trend-baseline","category":"Implementation","title":"No public longitudinal series to validate workforce signals against","observed":"Fursah publishes no trend, growth or forecast figure anywhere, and the assistant is instructed to refuse trend questions, because the platform stores no historical series and none is available to check against.","why":"Graduate and labour figures are published annually or quarterly by separate authorities on separate schedules and cuts. There is no joined education-to-employment outcome series at the resolution a matching system would need to know whether its recommendations worked.","recommendation":"A published graduate-outcomes series linking field of study to employment outcome at a suppressed but usable granularity. Without it, no platform in this category can demonstrate effect rather than activity.","owner":"GASTAT, Ministry of Education and the Human Capability Development Program","trigger":"Annual graduate-outcomes publication and any platform effectiveness evaluation.","metric":"A documented, privacy-suppressed field-of-study-to-outcome series with stable definitions and at least three comparable periods.","reviewCadence":"Annual publication with quarterly quality review","blocking":false},{"id":"automated-decision-threshold","category":"Implementation","title":"No defined threshold for when employment decision support becomes an automated decision","observed":"Fursah ranks candidates and states the ranking is advisory. Nothing prevents an employer from screening by that ranking in practice, which would make it decisive without ever being labelled a decision.","why":"The distinction between decision support and automated decision-making is stated in principle but has no operational test. A platform can satisfy every disclosure requirement while its output is used exactly as an automated decision.","recommendation":"An operational test for effective automation, such as pass-through rate, override rate, or a required minimum review. The obligation should depend on how the output is used.","owner":"Ministry of Human Resources and Social Development with SDAIA","trigger":"A score, rank or recommendation is used to exclude, shortlist or materially prioritise a candidate.","metric":"Documented human review for every exclusion, monitored override and appeal rates, and suspension when review evidence is missing.","reviewCadence":"Monthly operational monitoring and quarterly governance review","blocking":false}]}