The companion standard to R+2. While R+2 defines the per-event signed receipt, R+3 defines the aggregate audit bundle: how to package a time-range of receipts into a Filecoin-pinned, hash-chained, regulator-mappable export. First production bundle ships May 31, 2026.
Time-range of receipts + Merkle root + signed manifest + Filecoin CID + regulator metadata.
Receipts in the bundle Merkle-tree into a single root. Tampering any receipt invalidates the root.
Bundle CID pinned via Lighthouse. Pin proof itself referenced in the bundle envelope. Self-attesting permanence.
Optional fields for jurisdiction, regime, evidence-grade, retention class. Auto-filled per use case.
JSON-LD (canonical) + CSV (operator-friendly) + PDF (printable). All three deterministic + signed.
Anyone can re-walk the Merkle tree from a single bundle CID and prove integrity. No DCS server required.
"Show me every AI decision your bank made on credit applications in Q1." → one bundle CID, every event verifiable.
Citizen requests their agent-interaction history. R+3 bundles their per-user receipts, signed + verifiable.
Bundle scopes specific agent or specific period. Opposing counsel can verify independently — no "trust me bro."
Audit firm pulls weekly bundle. Re-walks the Merkle tree. Spots discontinuity = control deficiency.
EU AI Act Article 12 + ISO 42001 evidence — bundles attached to compliance dashboards, with regulator metadata pre-filled.
"I deleted Customer X's data on date Y." Bundle includes the erasure receipt + Merkle proof.
Bundle once. Verify forever. Independent of DCS.