Roadmap

What has shipped, what is next, what is deferred. Honest, dated, revisable — not a commitment ledger.

Last updated 2026-08-31. Forward dates are targets, not contractual commitments. We move them when the work warrants it; when we move one we say so on this page.

On this page

How to read this page

  • Shipped — live in production, anchored on-chain where applicable.
  • Near-term — scheduled work with an externally-imposed deadline (consultation close, public-comment close, ISE editor feedback cycle).
  • Medium-term — intended, not yet scheduled.
  • Deferred — not on the protocol’s direct path; either reframed as an opportunity for operators or scoped out for stated reasons.

The version of this page at any point in time is verifiable through the public on-chain audit anchor (/trust#audit-trail) and the changelog.

Shipped

2026-05-03
Protocol v1 genesis anchored on the public chain. 0x755beb60…0d0963a ↑, block 7,024,653.
2026-05-03
Mainnet operating perimeter — canary-class agent flows running on COTI V2 mainnet (Cashier, Arbitrage, Purchasing) under post-quantum (ML-DSA / FIPS 204) signing.
2026-05-07
Trust Center published. See /trust.
2026-05-07
Audience pages — Individuals, Developers, Enterprise, Government, AI Providers, Supply Chain, Public Good, Competitors. Plus /quickstart, /faq, /comparison, Appendix.
2026-05-07
Pricing transparency — PAYG, Pro, Pro Fast, Enterprise, Enterprise Fast; canonical settlement in USDC.e on COTI V2 mainnet. See /pricing.
2026-05-18
/standards surface launched with first six crosswalks (NIST AI RMF 1.0, ISO/IEC 42001:2023, ISO/IEC 27001:2022, EU AI Act 2024/1689, GDPR Article 17, MCP). Internet-Draft draft-saihm-memory-protocol-00 submitted to the IETF Independent Submission Stream and accepted by the datatracker. W3C Community Group proposal submitted (5 founding supporters required to launch). NIST AI RMF use-case email sent to AIframework@nist.gov.
2026-05-24
Three standards crosswalks addedISO/IEC 27018:2025, NIST SP 800-66 Rev. 2, NIST SP 800-88 Rev. 2 (Cryptographic Erase). Nine crosswalks now live.
2026-05-24
Five new open standards engagements drafted — IRTF CFRG mailing-list post on HKDF-SHA-256 per-record DEK derivation; public comment on NIST SP 800-133 Rev. 3 (Initial Public Draft); EU AI Act Article 50 transparency-obligations consultation response; EU AI Act Article 6 high-risk-classification consultation response; OWASP Agentic Security Initiative community-engagement plan. W3C CG supporter recruitment package drafted (six archetypes, target 10–15 invitations).
2026-05-26
IETF ISE fifteen-point response cover sent to rfc-ise@rfc-editor.org, with proposed -02 text quoted inline for each of the ISE editor’s review points (received 2026-05-25). cc’d to draft-saihm-memory-protocol@ietf.org.
2026-05-27
Internet-Draft draft-saihm-memory-protocol-01 posted to the datatracker (folds in editorial corrections preceding the ISE-feedback cycle).
2026-05-28
/standards rebuild — nine crosswalks linked; five new SDO engagement rows; honest status notes for AAIF (not yet submitted), AI Alliance (not yet submitted); Independent-Stream status disclaimer (RFC 4846 / RFC 8730); language calibrated for community review.
2026-05-29
EU AI Act Article 50 consultation response submitted to DG CONNECT via ec.europa.eu/eusurvey/runner/Art50guidelines. EU Survey contribution ID c83d1d83-36dd-486a-aca6-2c232ba12641; public-disclosure consent given. Six paste blocks covering Article 50(1) verifiable-manner clarification, Article 50(2) cryptographic-provenance complementarity (including AI agents in virtual / immersive environments), and Article 50(5) lifecycle persistence with the GDPR Article 17(3) carve-out. Five days ahead of the 2026-06-03 deadline.
2026-05-29
NIST SP 800-133 Rev. 3 (Initial Public Draft) public comment submitted to sp800-133-comments@nist.gov. Seven comments (4 Technical, 1 General, 2 Editorial) covering §5.2 category-2 HKDF / RFC 5869 cross-reference, §4.2 hardware-security-module and post-quantum + hybrid Note-to-Reviewers responses, §5.5 key-derivation-key rotation guidance, §4.2 multi-tenant additional-input examples, and two editorial flags. FOIA-disclosable. Eighteen days ahead of the 2026-06-16 close.
2026-05-29
EU AI Act Article 6 high-risk-classification consultation response submitted to DG CONNECT via ec.europa.eu/eusurvey/runner/AIhighrisks_2026. EU Survey contribution ID e555551a-27be-4859-8717-c74997ccd1d5. Section II (II.1 + II.2) and Section IV (IV.2) covered: Article 3(1) substrate-not-AI-system threshold; §II.2 ¶12 general-purpose AI gating; §IV.2.3 split-architectures / agentic-AI distinction; §IV.2.7(a) infrastructure narrow-procedural-task confirmation; Article 25 forward-reference; four concrete substrate-function use-cases proposed for out-of-scope confirmation. Twenty-five days ahead of the 2026-06-23 22:00 CET deadline.
2026-05-29
IRTF CFRG mailing-list post sent to cfrg@ietf.org (subscription confirmed). Single technical question on whether RFC 5869 (HKDF) remains the recommended construction for per-record data-encryption-key derivation given that NIST SP 800-133 Rev. 3 names neither HKDF nor RFC 5869. Operational data point shared from the SAIHM reference implementation. Archive: mailarchive.ietf.org/arch/browse/cfrg/.
2026-06-03
W3C Community Group launched. The AI Agent Memory Interoperability Community Group activated at w3.org/community/ai-agent-memory-interop with five founding supporters and began specification work.

Next up

Internet-Draft -02
Waiting on the ISE editor. The revision is written and goes out within a week of their next reply — the clock is theirs, not ours, which is why there is no date here.

Intended, not scheduled

Independent security audit
Engage a reputable cryptographic / smart-contract / web-application audit firm to review the protocol implementation. Scope to be agreed with the audit firm; report and remediation status will be linked from /trust#audit-history.
Operator Track expansion
Onboard additional independent operators running SAIHM nodes for paying customers, with operator-specific compliance attestations (SOC, ISO, HIPAA BAAs) layered above the protocol. Apply.
Privacy + invoice 3-layer hybrid
Privacy-preference architecture using COTI’s native privacy primitives + private ERC-20 tooling for invoicing. Currently deferred until mainnet redeployment burn-in completes; once unlocked, may use first-party COTI Privacy Portal tooling rather than a SAIHM-custom adapter. Tracked.
Federated sharing primitives
Cross-vendor agent sharing is supported today via consent-gated grants. Federation conveniences (shared revocation views, aggregated audit-export) are planned but unscheduled.
Standards-body engagement
SAIHM is in front of the IETF, W3C, OWASP and the Agentic AI Foundation. That work moves at their pace, not ours, and none of it gates anything you can use today — the detail lives on /standards so this page can stay about the product.

Deferred

Bug bounty program
Deferred — review 2026-12-31. A bounty program will be stood up once it can be run credibly and sustainably. Vulnerability disclosure runs through /.well-known/security.txt in the meantime; reporters are coordinated with respectfully and credited (with consent) when fixes ship. We will revisit this entry on or before 2026-12-31.
OASIS Open TC chartering
Deferred pending AAIF traction. Not warranted before adoption signals from the open AAIF / IETF / W3C / NIST tracks justify a formal OASIS technical committee.
IEEE-SA Project Authorization Request
Deferred. Revisit when standards-track momentum or a corporate participant emerges to champion it.
Multi-chain settlement (operator opportunity)
The protocol settles on COTI V2 mainnet only — SAIHM’s privacy and erasure properties depend on COTI V2’s native primitives, and out-of-band bridging into USDC.e on COTI V2 (e.g. via Hyperlane Nexus) already covers cross-chain payments. Multi-chain settlement at the operator layer — offering customers the ability to pay on Ethereum, an L2, or another chain and having the operator handle the bridge transparently — is an opportunity for any operator who wishes to serve their own customer base that way. The protocol does not need to grow its own settlement surface for that to happen.
Permanent storage for memory cells
Intentionally not on the roadmap. A permanence-oriented (immutable) substrate’s model is incompatible with cryptographic-erasure semantics under GDPR Art. 17 / CCPA right-to-delete, so cells are never written to an immutable substrate. Note: SAIHM does use an immutable substrate at the protocol layer for governance / registry / activation anchors that are meant to be permanent — cells are scoped out, not immutable storage wholesale. See /appendix/storage-nodes.

Cadence

We update this page when something ships, slips, or is added or deferred. Material slips are noted at the entry rather than silently rewriting the date.

For the cryptographically anchored history of operations and registry events, see /changelog when published, plus the public on-chain anchors at public block explorer.

Found something missing or wrong?

If we have promised something on another page that is not reflected here, that is the bug. Tell us: ops@saihm.coti.global with subject prefix [roadmap]. Discrepancies are reconciled by updating this page; this page is the canonical roadmap.

Common questions

Are the dates on this roadmap commitments?

No. Forward dates are targets, not contractual commitments. They move when the work warrants it, and when one moves the roadmap says so rather than quietly re-dating it.

What do the four sections mean?

Shipped is live in production and anchored on-chain where applicable. Near-term is scheduled work with an externally imposed deadline, such as a consultation or public-comment close. Medium-term is intended but not yet scheduled. Deferred is off the protocol's direct path, either reframed as an opportunity for operators or scoped out for stated reasons.

How can I check what this page said in the past?

The version of the page at any point in time is verifiable through the public on-chain audit anchor and the changelog, so a quietly revised roadmap is detectable rather than something you have to take on trust.

Does the roadmap say what SAIHM will not build?

Yes. The deferred section states what is not on the protocol's direct path and why, which is the part most roadmaps leave out.