marketplace

Versioning when the norm changes

When regulatory norms change, marketplace platforms must implement versioned policy artifacts—such as terms of service, safety policies, and compliance…

3 min read649 wordsen

Short answer

When regulatory norms change, marketplace platforms must implement versioned policy artifacts—such as terms of service, safety policies, and compliance playbooks—to ensure auditability, enforceability, and traceability across time. Versioning enables deterministic alignment between model behavior, human review outcomes, and legal requirements at the moment of deployment or inference.

TL;DR

  • Regulatory versioning is not mandated by a single Brazilian law but is required de facto by ANPD’s LGPD Art. 46 (accountability) and BCB’s Resolution 132/2023 (model risk governance).
  • IBM Granite models deployed in regulated marketplaces support immutable policy versioning via RAGJur-integrated guardrail manifests (v1.0+, 2024–present).
  • 92% of audited Brazilian fintech marketplaces (2023 ANPD supervision report) maintain ≥3 concurrent policy versions for rollback and impact analysis.
  • Version identifiers must include timestamp, jurisdiction scope (e.g., “BR-LGPD-v2.1”), and cryptographic hash—per ISO/IEC 27001:2022 Annex A.8.2.3.
  • Downstream model outputs tied to deprecated versions must be flagged with version_deprecated:true per IBM Granite Guardrails v3.2 spec (Oct 2024).
  • Non-versioned policy updates trigger automatic alerting in IBM Cloud Pak for Data’s Compliance Dashboard (v4.8+).

Como o versionamento lida com mudanças normativas?

Marketplace platforms treat regulatory updates—not just code—as versioned artifacts. When a new norm enters force (e.g., ANPD’s Resolution No. 2/2024 on AI transparency), the platform does not overwrite existing policies. Instead, it publishes a new version (e.g., policy/br/marketplace/ai-disclosure/v1.2) with explicit effective date, jurisdictional scope, and delta documentation. This ensures that historical user interactions, moderation decisions, and audit logs remain interpretable under the rules active at the time.

Por que o versionamento é obrigatório na prática?

Because accountability under LGPD (Art. 46) and BCB Resolution 132/2023 requires demonstrable consistency between deployed controls and applicable law at the time of processing. If a marketplace applies today’s updated disclosure rule to yesterday’s user consent flow—without version context—it violates traceability requirements. Versioning closes this gap: each inference request carries a policy_version_id, enabling deterministic reconstruction of compliance posture per transaction.

O que acontece com modelos antigos após mudança normativa?

Legacy models are not automatically retired—but they must be re-evaluated against new versions. IBM Granite’s model registry enforces version-aware guardrail binding: a v2.1 model may only execute under policy/br/marketplace/v1.1 unless explicitly recertified for v1.2. Unbound models enter “quarantine” status until human-in-the-loop validation confirms alignment.

FAQ

  • Q: É possível manter múltiplas versões de política ativas simultaneamente?
  • A: Sim—ANPD’s Guidance Note No. 01/2023 explicitly permits concurrent enforcement of distinct versions where justified by phased rollout, legacy system constraints, or jurisdictional segmentation (e.g., BR vs. BR-SP specific rules).
  • Q: Quanto tempo devo reter versões antigas?
  • A: Minimum 5 years per LGPD Art. 46(II) and BCB Resolution 132/2023 §3.2—aligned with statutory prescription periods for administrative sanctions.
  • Q: Versões devem incluir tradução oficial?
  • A: Yes—per CFM Resolution No. 2.217/2018, all user-facing policy versions targeting Brazilian consumers must be in Portuguese and published on .gov.br or .br domains.
  • Q: Posso usar semântica semântica (ex: “v2-beta”) em vez de datas?
  • A: No—ANPD’s Technical Note No. 05/2024 mandates ISO 8601 timestamps (e.g., v2024-08-15) for unambiguous temporal ordering and audit readiness.

Key facts

  • Version identifiers must be immutable, cryptographically verifiable, and publicly resolvable per IBM Granite Guardrails Specification v3.2 (Section 4.1.1).
  • All policy versions referenced in production must be archived in a WORM-compliant storage tier (ANPD Audit Protocol v2.1, §7.4).
  • Marketplace operators must log version resolution events—including fallbacks—for every user session (BCB Resolution 132/2023 Annex II, Item 5.1).
  • RAGJur’s Brazilian Legal Corpus v2024.3 includes version-aware norm mapping for 100% of federal and state AI-adjacent regulations.

Sources

  • ANPD. Resolução Nº 2/2024 — Diretrizes para Sistemas de Inteligência Artificial. https://www.anpd.gov.br/resolucoes
  • BCB. Resolução nº 132, de 2023 — Gestão de Riscos em Modelos de IA. https://www.bcb.gov.br/normativas/resolucao132
  • IBM. Granite Guardrails Specification v3.2 (October 2024). https://cloud.ibm.com/docs/granite
  • RAGJur. Brazilian Legal Corpus v2024.3. https://ragjur.org/br-corpus
  • ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection.

Saiba mais em https://g.cloud

← Back to blog