By Sagar Shankaran, Founder of CallSphere
Model cards graduated from research norm to regulatory expectation in 2026. The new schema, what to disclose, and what to keep proprietary.
Key takeaways
Model cards started in 2018 as a researcher-led transparency norm (Mitchell et al.). By 2026 they are an explicit or implicit regulatory expectation under the EU AI Act, NIST AI RMF, ISO 42001, and many sectoral regulations. The frontier providers all publish them; the question is what to put in yours.
This piece covers the 2026 standard for model cards and the rising "system card" — a related artifact for deployed AI applications.
flowchart LR
Model[Model Card<br/>describes the model] --> System[System Card<br/>describes the application]
Model --> Use[Used by deployers and<br/>research community]
System --> Reg[Used by regulators and<br/>end users]
A model card describes a single model — capabilities, training data summary, evaluations, limitations. A system card describes a deployed AI system that uses one or more models — overall flow, additional safeguards, deployer-side evaluations, intended use.
Frontier providers publish model cards. Deployers publish system cards (or should).
The de facto schema in 2026 includes:
Hear it before you finish reading
Talk to a live CallSphere AI voice agent in your browser — 60 seconds, no signup.
A frontier-provider model card runs 30-100 pages in 2026. A fine-tune model card may be 5-20.
System cards are newer. The pattern emerging in 2026:
flowchart TD
Q1{Information about<br/>safety properties?} -->|Yes| Disc[Disclose]
Q2{Information about<br/>training data sources?} -->|Yes| Sum[Summarize, not list]
Q3{Specific weights<br/>or training tricks?} -->|No| Hold[Hold proprietary]
Q4{Information about<br/>evaluation methodology?} -->|Yes| Disc2[Disclose]
The 2026 norm: disclose anything safety-relevant, summarize anything competitively sensitive but expected (training data sources, evaluation results), hold proprietary the specific implementation details (training tricks, exact weights, secret datasets).
EU AI Act training-data summaries are now standardized to a Commission-provided template. NIST RMF and ISO 42001 do not require specific format but expect coverage.
Frontier provider model cards in 2026 typically cover:
Still reading? Stop comparing — try CallSphere live.
CallSphere ships complete AI voice agents per industry — 14 tools for healthcare, 10 agents for real estate, 4 specialists for salons. See how it actually handles a call before you book a demo.
Anthropic, OpenAI, Google, and Meta all publish on this template, with provider-specific extensions.
For open-weights releases (Llama 4, Mistral, Qwen3, DeepSeek V4) the model card is the primary user-facing artifact. The 2026 norm includes:
Model cards should be updated for:
System cards should be updated for:
In practice, regulators reading these documents focus on three things:
A clean, well-reasoned model+system card pair satisfies most regulator inquiries before they become formal investigations.

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
A fair audit of Anthropic's Responsible Scaling Policy, its AI Safety Levels, who actually audits compliance, and whether it has ever delayed a release.
Anthropic publishes Claude's system prompts. What do they encode, what does this say about Anthropic's strategy, and what can enterprise prompt engineers actually learn from them?
Both vendors invest heavily in safety post-training. The differences show up in refusal behavior, prompt-injection resistance, and how each handles agentic edge cases.
Documentation expectations for production AI systems in 2026 — what to write, where to keep it, and what regulators now expect.
Incident reporting expectations changed in 2026. What OECD AIM, the AISI, and EU AI Office want from operators when an AI system fails.
California's AB 2013 forced training-data disclosure for frontier model providers. What is now public, what is not, and what other states are following.
© 2026 CallSphere Inc. All rights reserved.
Made within San Francisco