Open SMB Disclosure Compliance Methodology (OSDCM) v1.0

Version: 1.0.0 Author of record: Brett Halverson Stewardship: Halverson Co. License: CC BY 4.0 (this document); Apache 2.0 (accompanying schemas) Repository: github.com/bch1212/sbcis (OSDCM ships alongside SBCIS; same trust spine, sibling methodology) Canonical web rendering: compliancebeacon.app/methodology Effective date: 2026-05-13 (planned v1.0 publication) Prior versions: none


Cite this version

Halverson, B. (2026). Open SMB Disclosure Compliance Methodology (OSDCM) v1.0. Halverson Co. Available at https://compliancebeacon.app/methodology.

BibTeX:

@techreport{halverson2026osdcm,
  author = {Halverson, Brett},
  title = {Open SMB Disclosure Compliance Methodology (OSDCM) v1.0},
  institution = {Halverson Co.},
  year = {2026},
  url = {https://compliancebeacon.app/methodology}
}

Preface (non-normative)

OSDCM scores how exposed a small or medium-sized business (SMB) is to state and federal AI-disclosure laws based on the actual content and structure of its public-facing website. The framework is intended for SMB owners, compliance counsel, marketing agencies, and the journalists and regulators tracking how the new disclosure regime is being implemented in practice.

OSDCM is the sibling methodology to SBCIS (Small Business Compliance Impact Scoring). SBCIS scores a rule once and produces a per-SMB cost estimate; OSDCM scores a specific site against the active rule corpus and produces a per-site exposure estimate. The two methodologies share a license, a stewardship model, an open-review process, and a vendor-disclosure rule.

This methodology builds on three established conventions (cited inline where applied):

  1. The Federal Trade Commission’s Section 5 unfairness-and-deception authority and the FTC’s published guidance on AI-related claims (FTC, 2023; 2024).
  2. State-AG disclosure regimes, principally Colorado SB 24-205 (effective 2026-06-30), California’s CPPA ADMT rulemaking, and Illinois HB 3773. Each state’s enforcement language and definitions are cited per-axis in Section H.
  3. Existing website-audit conventions for accessibility (WCAG 2.2), security (OWASP), and consumer protection. OSDCM extends these into the AI-disclosure dimension.

OSDCM does not give legal advice. It gives a defensible, reproducible exposure estimate against named, citable state and federal authorities, and a per-axis list of what to fix.


Section A: Scope

A.1 What’s in scope

OSDCM v1.0 scores:

  1. Public-facing US-accessible websites (including e-commerce, SaaS marketing pages, professional-services sites, and any URL a consumer reaches without authentication).
  2. Pages that interact with consumers via any of: AI chatbot, AI-generated recommendation engine, automated decision-making with consequential effect, generative content disclosed or undisclosed as AI-generated, or biometric/inference-based personalization.
  3. Site behaviors triggered by US state residence (geofencing, consent banners, jurisdictional notices).

For each in-scope site, OSDCM produces a single Exposure Score (0 to 25) and per-axis findings, plus a per-state risk indicator for the four highest-risk states (CO, CA, IL, NY) and an aggregate federal-FTC risk indicator.

A.2 What’s out of scope (v1.0)

  1. Internal employee-facing systems (CCPA employee-data carveouts and Illinois HB 3773 employer rules are partial exceptions and are scored only when the public site exposes them).
  2. Mobile apps. v1.x will extend; v1.0 is web-only.
  3. EU AI Act and GDPR (different regime; tracked in a separate methodology by ComplianceBeacon’s roadmap).
  4. Section 230-protected user-generated content unless the operator endorses or modifies it.
  5. Health-specific HIPAA disclosure rules (separate domain).

A.3 Geographic scope

OSDCM v1.0 covers United States state and federal AI-disclosure law. State enforcement is jurisdictionally bounded by the user’s residence at the time of interaction, so sites with US visitors are in scope.

A.4 SMB scope

“SMB” follows the SBA size standards (13 CFR Part 121) as in SBCIS. OSDCM v1.0 is calibrated for SMBs of 1 to 500 employees; larger enterprises are technically scorable but the cost figures lose accuracy because enterprise legal infrastructure dominates.


Section B: Exposure dimensions

OSDCM recognizes three exposure dimensions:

B.1 Active risk (rules currently in force)

State or federal AI-disclosure rules that are in active enforcement at the time the score is produced. As of 2026-05-13, the active set includes the FTC Section 5 enforcement actions on undisclosed AI claims, and Colorado SB 24-205 (effective 2026-06-30).

B.2 Imminent risk (rules with a near-term effective date)

Rules already enacted with an effective date within 6 months of scoring. This dimension is what differentiates ComplianceBeacon from existing site-auditing tools: it scores you against rules that will be enforced soon, not just what’s already in force.

B.3 Speculative risk (rules in active rulemaking)

Rules under formal notice-and-comment that have not yet been adopted. Scored at lower weight (Section C.5) and clearly labeled as speculative.


Section C: Scoring axes

OSDCM scores each site on five axes. Each axis is a float between 0.0 and 5.0. The aggregate Exposure Score is the sum (0.0 to 25.0).

C.1 AI-feature disclosure presence

Score whether the site discloses AI-driven features that interact with consumers:

Axis value What the site has
0 Disclosed all AI features clearly at point-of-use
1 Disclosed AI features in privacy policy only
2 Partially disclosed (some features acknowledged, others not)
3 AI features present but undisclosed
4 AI features present, undisclosed, and decision-consequential (eligibility, pricing, hiring)
5 Multiple high-consequence AI features undisclosed; pattern suggests intentional non-disclosure

C.2 Right-to-decline / human-review presence

Score whether the site provides a mechanism to decline automated decision-making or request human review where required (Colorado SB 24-205 § 6, similar provisions in CA ADMT):

Axis value What the site has
0 Clear mechanism present and discoverable in 1 click
1 Mechanism present, requires 2-3 clicks
2 Mentioned in privacy policy only, no UI affordance
3 No mechanism, but site uses no consequential automated decisions
4 Consequential automated decisions present, no decline mechanism
5 Consequential automated decisions present, no decline mechanism, and dark-pattern friction against the request

C.3 Generative-content labeling

Score whether AI-generated content (text, images, video) is labeled where required:

Axis value What the site has
0 All AI-generated content clearly labeled
1 Labeled in most contexts; one or two gaps
2 Labeled in some contexts, not in marketing copy
3 Substantial unlabeled AI content (likely violates FTC guidance for some claims)
4 Substantial unlabeled AI content including testimonials, reviews, or endorsements
5 Material misrepresentation: AI content presented as human in ways likely to deceive

C.4 Biometric / inference-based personalization disclosure

Score whether the site discloses use of biometric data, location inferences, or behavioral profiling at the level state law requires (Illinois BIPA, Texas CUBI, CCPA inferences):

Axis value What the site has
0 No biometric or inference use, or fully disclosed and consented
1 Limited use, partial disclosure
2 Use without explicit opt-in where opt-in is required
3 Use without disclosure but no biometric data is captured
4 Biometric data captured without compliant Illinois BIPA notice (statutory damages risk)
5 Biometric data captured + shared with third parties without compliant notice

C.5 Jurisdictional readiness for imminent rules

Score how well the site is positioned for the next 6 months of effective dates. This axis is weighted at 0.7x in the aggregate (because it’s forward-looking and speculative), implemented by capping its contribution at 3.5 of the nominal 5.0:

Axis value What the site has
0 Already compliant with the next 6 months of effective rules
1 Minor work needed; on schedule
2 Material work needed; on schedule
3 Material work needed; no plan visible
4 Substantial gaps relative to Colorado SB 24-205, CA ADMT, or IL HB 3773
5 Substantial gaps + the site appears to be marketing into the affected states

C.6 Exposure Score buckets

Exposure Score Bucket Action
0 to 8.99 low Annual re-scan; monitor for new rules
9 to 14.99 mid Address gaps within 90 days; subscribe to dispatches
15 to 19.99 high Address gaps within 30 days; counsel review recommended
20 to 25 critical Immediate counsel review; statutory damages risk imminent

Section D: Cost calculation

OSDCM converts an Exposure Score into a per-violation-event monetary risk by mapping each axis to the named statutory penalty for the relevant rule. For a representative 25-employee SMB with US-wide marketing:

state_max_per_violation = max across CO (≈$20,000), IL BIPA ($1,000 to $5,000 per negligent violation), CA (CCPA $2,500/$7,500), federal FTC (case-specific up to civil-penalty cap)

annual_risk_low  = exposure_score * 0.5 * mean_per_violation
annual_risk_high = exposure_score * 2.0 * max_per_violation_p25

The “p25” notation reflects that the high-risk estimate is calibrated to a 25th-percentile enforcement scenario (a small number of violations cited, not the worst-case multi-violation class action). This is conservative on purpose: OSDCM scores are meant to motivate remediation, not panic.

Per-violation maxes are versioned in examples/penalty-table.json and updated whenever statutes are amended.


Section E: Site-context weighting

OSDCM v1.0 applies site-context weighting based on:

E.1 Sector

Higher-risk sectors get a 1.2x multiplier on axes C.1 and C.2: healthcare-adjacent, financial-services, hiring-tech, education-tech. The justification is that these sectors have additional sector-specific automated-decision rules (FCRA, ADA, FERPA, HIPAA) layered atop the state disclosure regime.

E.2 Audience size

Sites with under 1,000 monthly visitors (a proxy for “true SMB”) get a 0.9x multiplier on all axes. Enforcement priorities historically target larger audience sizes first, even when statutory authority is identical.

E.3 State-marketing detection

If the site has Colorado-specific content (shipping language, sales-tax disclosure, geographic targeting tags), C.5 is uncapped and weighted at 1.0x instead of 0.7x.


Section F: Provenance rules

Every published OSDCM score must include at least three citation classes:

  1. The site URL scored and the timestamp of the scan.
  2. At least one named statute or rule cited per axis where that axis scored above 1.0. Citation must include section/subsection level.
  3. A jurisdictional-applicability source for each named statute. This is typically the state AG enforcement guidance page or the FTC press release that establishes the enforcement posture.

Scores published without all three citation classes are draft-quality and marked accordingly.


Section G: Anti-gaming rules

OSDCM explicitly forbids:

G.1 No “good-faith” exclusions

A score cannot drop because the operator claims they did not know about the rule. Strict-liability disclosure regimes do not depend on intent. Score the site as it is, not as the operator says it is.

G.2 No netting future remediation against present exposure

If the operator promises to fix the gap in 30 days, OSDCM still scores the current state. Remediation timeline goes in the rationale, not in the score.

G.3 No discounting for state non-residents in the audience mix

A site visible to Colorado residents is exposed to Colorado law, even if Colorado residents are a small fraction of the audience. Audience-size weighting in E.2 is about enforcement priority, not statutory applicability.

G.4 Vendor-tilted scoring

The author of a published OSDCM score must disclose any financial interest in the scored site, in tools that would close the gaps, or in regulatory outcomes. OSDCM v1.0 author Brett Halverson discloses: operates ComplianceBeacon, which sells AI-disclosure compliance scanning services to SMBs. This disclosure is mandatory for every score.


Section H: Worked example (calibration set)

This worked example is the v1.0 calibration anchor. Any conforming OSDCM implementation must reproduce this scoring given the same inputs.

H.1 Example: a hypothetical 25-employee Colorado e-commerce retailer

Site profile: sells consumer goods, accepts orders from Colorado residents, uses an AI-driven product-recommendation engine, AI-generated marketing copy on category pages, AI chat widget on product pages, no privacy-policy mention of AI features other than a generic “we use cookies and analytics” paragraph.

Scoring: - C.1 (AI-feature disclosure): 4.0. Three AI features (recommendation engine, generative marketing copy, chat widget) are present and undisclosed. The recommendation engine drives consequential purchase decisions; the marketing copy may include implicit endorsement claims. - C.2 (Right-to-decline): 4.0. Consequential automated decisions (personalized pricing, recommendation ranking) are present and no decline mechanism is offered. Privacy policy mentions “automated processing” once but provides no opt-out UI. - C.3 (Generative-content labeling): 3.0. Marketing copy on category pages is AI-generated and unlabeled. No testimonial fabrication observed (would be 4 or 5). - C.4 (Biometric / inference): 1.0. Recommendation engine uses behavioral inferences; this is disclosed in a cookie banner but not at the per-feature level. No biometric capture. - C.5 (Jurisdictional readiness, 0.7x weighted): 4.0 nominal → capped contribution 2.8. Colorado SB 24-205 enforcement begins 2026-06-30 and the site has substantial gaps.

Exposure Score: 4.0 + 4.0 + 3.0 + 1.0 + 2.8 = 14.8 (mid bucket; address within 90 days).

Annual risk band: under conservative estimate, $5,000 to $40,000 across Colorado-specific exposure plus possible FTC inquiry exposure if testimonial-shaped AI claims surface.

What this site should do, in order: 1. Add per-feature AI disclosure within 30 days (closes C.1 from 4 to 1). 2. Add a human-review request mechanism within 30 days (closes C.2 from 4 to 1). 3. Label AI-generated marketing copy within 60 days (closes C.3 from 3 to 1). 4. Document the recommendation engine’s data sources for inclusion in the privacy policy refresh (closes C.4 from 1 to 0).

After remediation: projected Exposure Score under 5.0 (low bucket).


Section I: Versioning

OSDCM uses Semantic Versioning 2.0.0, identical to SBCIS.

When OSDCM publishes a new minor or major version, prior scores remain stamped at their original version and remain interpretable.


Section J: Limitations and dispute resolution

J.1 What OSDCM does not do

J.2 Open review and dispute resolution

OSDCM is open for public review. The methodology, scoring code, and worked examples live alongside SBCIS at github.com/bch1212/sbcis. Anyone may file a GitHub issue or pull request. The steward (Halverson Co.) responds within 14 days.

This is the publish-then-iterate model (OWASP, CVSS, Carbon Disclosure Project), the same one SBCIS uses. There is no pre-publication private review gate.


Appendix A: Glossary

Appendix B: Contributor credits

OSDCM is open for public review (Section J.2). This appendix lists contributors who have filed substantive GitHub issues or pull requests that have been merged. As of v1.0 publication, this list is empty; it will be populated as contributions arrive.

To contribute, file an issue or pull request at github.com/bch1212/sbcis with the osdcm label.

Appendix C: Bibliography

Appendix D: Schema

A score conforming to OSDCM v1.0 validates against schema/osdcm-score.schema.json in the SBCIS repository, sibling to schema/sbcis-score.schema.json. Apache 2.0 licensed.


Changelog