AI-Ready Web

AI-Ready Web Volume 7: Roadmap and Governance

Maturity register, 30-day through 24-month roadmap, claim-review process, security and privacy governance, and lifecycle rules.

  • Record UAIX-DOC-3380
  • Path /en-us/ai-ready-web/roadmap-governance/
  • Use Canonical public record

Document status

Public standards page Published on UAIX as part of the current public standards record
Code
UAIX-DOC-3380
Surface
AI-Ready Web
Access
Public and linkable

How to use this page

Use this page as the canonical public reference for AI-Ready Web Volume 7: Roadmap and Governance and its standards-facing content.

For agents: apply the relevant guidance to the user's target site or repository. Do not copy this UAIX page, create a page about the guidance, or treat this page as runtime authority unless the user explicitly asks for that output.

Summary

Volume 7 keeps the AI-Ready Web program honest after launch. Governance is the difference between a useful standards program and a pile of stale claims. Every new mechanism must move through maturity review, source updates, machine artifacts, tests, release notes, and translation checks before it becomes current public support.

Agent implementation contract

When a user sends an agent to this AI-Ready Web guidance, the assignment is to apply the strategy to the user's target site, repository, or publication package. Treat UAIX as the reference standard and checklist. Do not copy UAIX page content into the target site, do not create a page about UAIX guidance, and do not publish an "AI-Ready Web" explainer unless the user explicitly asks for that output.

The expected target-site evidence set is concrete: public manifest, .well-known discovery, route inventory, readiness result, robots.txt, sitemap, llms.txt, structured data, visible support boundaries, targeted checks, and package or root-file output when publication is requested.

Agent implementation contract
Agent stepDo the real implementationDo not do this
Resolve the targetIdentify the target domain, repo root, public routes, build system, CMS, deployment package, root-file output path, and current evidence before editing.Assume UAIX.org is the target site, summarize this page, or make a new guidance page because this page was provided as a reference.
Audit the existing siteCheck human HTML, headings, metadata, canonical URLs, robots, sitemaps, schema, .well-known files, llms files, APIs, route inventories, readiness records, accessibility, privacy, and support boundaries.Skip the target-site audit and only restate AEO/GEO/SEO definitions.
Implement improvementsUpdate the target site's pages, navigation, structured data, discovery files, route inventory, readiness records, public evidence, AEO/GEO/SEO copy, no-op guidance, review paths, and publish-package root files where the audit shows gaps.Keyword-stuff, cloak, add hidden bot-only text, inject prompts for models, fabricate citations, or create synthetic doorway pages.
Verify and packageRun the site's targeted checks, record changed files and routes, name skipped checks and blockers, and provide the requested root files, root ZIP, or publish package when the user asks for deployable output.Claim readiness, certification, endorsement, ranking gains, live publication, or agent authority without evidence.

Maturity register

Maturity register
StatusUse it forExamplesUAIX rule
Stable baselineRequirements that should be implemented before any agent-specific claim.WCAG 2.2, semantic HTML, HTTP semantics, robots.txt, sitemap, JSON Schema, OpenAPI, Problem Details, Trace Context, JSON-LD.May be required language when relevant and tested.
Current optionalUseful capabilities with real implementations but environment-specific adoption.MCP in compatible hosts, A2A where supported, signed non-human principal flows, structured alternate representations.Label as supported only when the local implementation has public evidence.
Proposal or community conventionHelpful discovery or policy signals that are not formal web standards.AEO/GEO terminology, llms.txt, markdown mirrors, agent preference files, TDMRep-style rights signals.Use as advisory signals and never as the only source of authority.
Research trackIdeas to monitor without current support claims.WebMCP/browser-native tool declarations, DNS-based agent discovery, autonomous agent commerce credentials beyond published APIs.Keep in roadmap language until specifications, implementations, tests, and release evidence exist.
UnsupportedClaims UAIX must not imply.Hosted runtime execution, automatic repository writes, hidden credential validation, certification, endorsement, safety proof, consciousness proof.Block or rewrite the claim.

Roadmap

Roadmap
WindowDeliverablesGate
First 30 daysPublish the 7-volume source pages, machine JSON assets, route inventory, tests, and handoff evidence.Source tests pass; no live-support claim until package build and upload complete.
Days 31-90Add rendered-page accessibility smoke automation, OpenAPI/API examples, framework starter guides, and translation QA.Manual accessibility and privacy review complete.
Months 3-6Add richer readiness validator UI, evidence export package, WordPress and ASP.NET Core reference snippets, and anti-pattern library.Validator output schema and examples stay aligned with public pages.
Months 6-12Track MCP/A2A adoption, mature capability profiles, refine identity/delegation guidance, and add operations dashboards.Only implementation-evidenced mechanisms become current support.
Months 12-24Evaluate browser-native agent APIs, commerce delegation patterns, rights-preference signals, and external interop feedback.Research-track ideas stay planned until standards, implementations, tests, and public release evidence agree.

Claim-review process

  1. Name the claim and the affected profile.
  2. Identify the stable standard, current implementation, proposal, or research-track source behind it.
  3. Update the human page, machine artifact, validator/test, release note, roadmap state, and translation source together.
  4. Run automated checks and record skipped checks with reasons.
  5. Publish only after owner review and package/live evidence exist.

Security and privacy governance

AI-Ready Web publication must never expose credentials, private endpoints, private customer data, hidden prompts, non-public production logs, or unsupported legal/security claims. The program follows UAIX no-op behavior: when a request crosses declared authority, the site returns a safe review path instead of trying to execute.

Primary governance references

Machine-readable governance