Verification
A rule is only as good as the reading behind it. Every rule carries a record of what was read, at one of three strengths, and this page reproduces all of them from the rules themselves rather than from a summary that could drift.
How strength is graded #
| Level | Means | May be relied on | Rules |
|---|---|---|---|
| official text | Read against the text as published in the Official Journal, or the consolidated version on EUR-Lex | Yes, subject to your own judgement | 19 |
| official guidance | Confirmed against a European Commission page or official guidance, not against the text itself | As a strong starting point | 6 |
| corroborated | Confirmed across independent professional sources; the wording has not been read | As a starting point only | 53 |
| unchecked | Encoded from working knowledge | No. The build reports these, and none currently exist. | 0 |
A pack's strength is computed from its weakest rule rather than declared, because an average would hide exactly the rule a reader needs to know about.
Artificial Intelligence Act #
Regulation (EU) 2024/1689 · 21 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Social scoring leading to detrimental treatment | Article 5(1)(c) | 2025-02-02 | official text | OJ text, recital 31 (social scoring leading to detrimental or disproportionate treatment) (2026-08-06) |
| Predicting offending from profiling or traits alone | Article 5(1)(d) | 2025-02-02 | official text | OJ text, recital 42 (prediction based solely on profiling or personality traits) (2026-08-06) |
| Untargeted scraping of facial images | Article 5(1)(e) | 2025-02-02 | official text | OJ text, recital 43 (untargeted scraping of facial images from the internet or CCTV) (2026-08-06) |
| Emotion inference in the workplace or education | Article 5(1)(f) | 2025-02-02 | official text | OJ text, recital 44 (emotion inference in the workplace and education, excluding medical and safety uses) (2026-08-06) |
| Biometric categorisation inferring sensitive attributes | Article 5(1)(g) | 2025-02-02 | official text | OJ text, recital 30, and recital 40 which cites Article 5(1) first subparagraph point (g) (2026-08-06) |
| Real-time remote biometric identification in public spaces for law enforcement | Article 5(1)(h) | 2025-02-02 | official text | OJ text, recitals 32 to 38, and recital 40 which cites Article 5(1) first subparagraph point (h) (2026-08-06) |
| Subliminal or manipulative techniques distorting behaviour | Article 5(1)(a) | 2025-02-02 | official text | OJ text, recital 29 (subliminal and manipulative techniques materially distorting behaviour) (2026-08-06) |
| Exploiting vulnerabilities of age, disability or circumstance | Article 5(1)(b) | 2025-02-02 | official text | OJ text, recital 29 (exploitation of vulnerabilities of age, disability or social or economic situation) (2026-08-06) |
| Generating non-consensual intimate imagery of identifiable people | Article 5, as amended | 2026-12-02 | corroborated | Regulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read (2026-08-06) |
| Generating child sexual abuse material, or lacking safeguards against it | Article 5, as amended | 2026-12-02 | corroborated | Regulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read (2026-08-06) |
| High-risk: falls within an Annex III area | Article 6(2) and Annex III | 2027-12-02 | official text | OJ text, recitals 54 to 62 (the eight Annex III areas); the deferred date is from Regulation (EU) 2026/1744 (2026-08-06) |
| Annex III area, with the Article 6(3) derogation claimed | Article 6(3) | 2027-12-02 | official text | OJ text, recital 53 (all four Article 6(3) conditions, the documentation duty and EU database registration) (2026-08-06) |
| The derogation is unavailable because the system profiles people | Article 6(3), final subparagraph | 2027-12-02 | official text | OJ text, recital 53 (profiling within the meaning of Article 4(4) GDPR removes the derogation) (2026-08-06) |
| High-risk as a regulated product or its safety component | Article 6(1) and Annex I | 2028-08-02 | official text | OJ text, recitals 50 and 51 (products under Union harmonisation legislation with third-party assessment) (2026-08-06) |
| Tell people they are interacting with an AI system | Article 50(1) | 2026-08-02 | corroborated | Article 50 transparency obligations confirmed as applying from 2 August 2026 across the Commission's reporting and several law firms; the wording of Article 50(1) is not yet read (2026-08-06) |
| Mark synthetic content in a machine-readable way | Article 50(2) | 2026-08-02 | corroborated | Deferral to 2026-12-02 for systems already on the market, confirmed across the same sources (2026-08-06) |
| Inform people exposed to emotion recognition or biometric categorisation | Article 50(3) | 2026-08-02 | corroborated | Article 50(3) as reported consistently; wording not yet read (2026-08-06) |
| Disclose deep fakes and AI-generated text on matters of public interest | Article 50(4) | 2026-08-02 | corroborated | Article 50(4) as reported consistently; wording not yet read (2026-08-06) |
| General-purpose model documentation, downstream information, copyright policy and training-content summary | Article 53 | 2025-08-02 | corroborated | Chapter V obligations applying from 2 August 2025, reported consistently; Article 53 wording not yet read (2026-08-06) |
| Systemic-risk evaluation, adversarial testing, incident reporting and cybersecurity | Articles 51 and 55 | 2025-08-02 | corroborated | Articles 51 and 55 with the 10^25 floating point operation presumption, reported consistently; wording not yet read (2026-08-06) |
| AI literacy: ensure staff dealing with the system are sufficiently competent | Article 4 | 2025-02-02 | official text | OJ text, recital 20 (AI literacy for providers, deployers and affected persons) (2026-08-06) |
Cyber Resilience Act #
Regulation (EU) 2024/2847 · 9 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Report actively exploited vulnerabilities and severe incidents to ENISA and the CSIRT | Article 14 | 2026-09-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act (2026-08-06) |
| Essential cybersecurity requirements in design, development and production | Article 13 and Annex I | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Vulnerability handling, including a coordinated disclosure policy and security updates | Annex I Part II | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Software bill of materials covering top-level dependencies | Annex I Part II(1) | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Conformity assessment, EU declaration of conformity and CE marking | Articles 32, 28 and 30 | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Define and publish the support period, at least five years unless the expected use is shorter | Article 13(8) | 2027-12-11 | corroborated | Commission summary describes the support period; the five year default and the Article 13(8) reference are not yet confirmed against the text (2026-08-06) |
| Verify the manufacturer's conformity assessment and marking before placing on the market | Article 19 | 2027-12-11 | corroborated | Commission summary describes importer duties; the Article 19 number is not yet confirmed against the text (2026-08-06) |
| Act with due care in relation to the requirements when making a product available | Article 20 | 2027-12-11 | corroborated | Commission summary describes distributor duties; the Article 20 number is not yet confirmed against the text (2026-08-06) |
| Open-source software outside a commercial activity is treated differently | Article 2 and Recitals | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
General Data Protection Regulation #
Regulation (EU) 2016/679 · 11 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Identify and record a lawful basis for each purpose | Article 6 | 2018-05-25 | corroborated | Article index reproductions of Regulation (EU) 2016/679 (gdpr-info.eu and others), consistent on Article 6 (2026-08-06) |
| Establish an Article 9 condition before processing special categories | Article 9 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 9 for special categories (2026-08-06) |
| Inform people at collection, in clear and accessible terms | Articles 13 and 14 | 2018-05-25 | corroborated | Article index reproductions, consistent on Articles 13 and 14 (2026-08-06) |
| Maintain a record of processing activities | Article 30 | 2018-05-25 | official text | EUR-Lex text: Article 30 named as the record of processing activities; the Article 30(5) exemption for organisations under 250 people is conditional as encoded (2026-08-06) |
| Carry out a data protection impact assessment before starting | Article 35 | 2018-05-25 | official text | EUR-Lex text: Article 36(1) refers to 'a data protection impact assessment under Article 35', confirming both the duty and its numbering (2026-08-06) |
| Automated decisions with legal or similarly significant effects need a basis, safeguards and human intervention | Article 22 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 22 for automated individual decision-making (2026-08-06) |
| A written processing agreement with every processor | Article 28 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 28 for processor contracts (2026-08-06) |
| Security appropriate to the risk, and the ability to demonstrate it | Article 32 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 32 for security of processing (2026-08-06) |
| Notify a personal data breach to the authority within 72 hours where it is likely to result in risk | Articles 33 and 34 | 2018-05-25 | official text | EUR-Lex text of Regulation (EU) 2016/679: Article 33(1) read verbatim, including the 72 hour limit and the risk qualifier (2026-08-06) |
| A transfer mechanism, and a transfer impact assessment where required | Chapter V | 2018-05-25 | corroborated | Article index reproductions, consistent on Chapter V, Articles 44 to 50 (2026-08-06) |
| Designate a data protection officer | Article 37 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 37 for designation of the data protection officer (2026-08-06) |
NIS2 Directive #
Directive (EU) 2022/2555 · 5 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Your obligations are those of the transposing national law, not the directive itself | Article 41 | 2024-10-18 | corroborated | Transposition deadline of 17 October 2024 corroborated widely; as of mid-2026 transposition remains uneven and the Commission has referred several Member States to the Court of Justice, which is exactly why this pack refuses to assert a national obligation (2026-08-06) |
| Register with the competent national authority | Article 3(4) | 2024-10-18 | corroborated | Article 3(4) requires Member States to establish lists of essential and important entities with information submitted by them; note that Article 27 imposes a separate registry duty on certain digital entity types, which this pack does not yet distinguish (2026-08-06) |
| Risk management measures: policies, incident handling, continuity, supply chain, cryptography and access control | Article 21 | 2024-10-18 | corroborated | Multiple independent analyses of Directive (EU) 2022/2555, consistent on Article 21 for risk management measures (2026-08-06) |
| Early warning within 24 hours, notification within 72 hours, final report within one month | Article 23 | 2024-10-18 | corroborated | Multiple independent analyses, consistent on Article 23 and the 24 hour, 72 hour and one month structure (2026-08-06) |
| Management bodies approve the measures and can be held personally liable | Article 20 | 2024-10-18 | corroborated | Multiple independent analyses, consistent on Article 20 for management approval, oversight, training and personal liability (2026-08-06) |
Data Act #
Regulation (EU) 2023/2854 · 8 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Design connected products so that the data they generate is accessible to the user by default | Article 3 | 2026-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: connected products placed on the market after 12 September 2026 must be designed so that data is accessible by default (2026-08-09) |
| Make product and related service data available to the user, and to a third party at the user's request | Articles 4 and 5 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read (2026-08-09) |
| Remove switching charges: reduced until 12 January 2027, prohibited from that date | Article 29 | 2025-09-12 | official text | EUR-Lex text read on 2026-08-09: Article 29 read verbatim. From 12 January 2027 no switching charges; reduced charges permitted from 11 January 2024 until then, capped at costs directly incurred (2026-08-09) |
| Contractual terms enabling a customer to switch provider, run several in parallel, or move on premises | Chapter VI, Articles 23 to 31 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Chapter VI, Articles 23 to 31, requires contractual terms enabling switching to another provider or to on-premises infrastructure (2026-08-09) |
| Functional equivalence for infrastructure services, and open interfaces for other data processing services | Chapter VIII | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: functional equivalence for infrastructure services, open interfaces for others (2026-08-09) |
| Publish the jurisdiction your infrastructure sits under, and the safeguards against unlawful international governmental access | Article 32 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: publish the jurisdiction of the ICT infrastructure and the measures against unlawful governmental access to non-personal data (2026-08-09) |
| Unilaterally imposed unfair data terms do not bind the other party, and this reaches older contracts from 12 September 2027 | Article 13 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: unfairly imposed data-sharing terms are not binding; extends to pre-existing contracts from 12 September 2027 (2026-08-09) |
| Where the data is personal, the GDPR continues to apply alongside this Regulation | Article 1(5) | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: the Data Act covers personal and non-personal data and does not displace the GDPR (2026-08-09) |
Digital Services Act #
Regulation (EU) 2022/2065 · 12 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Terms and conditions in plain language, machine readable, with changes notified | Article 14 | 2024-02-17 | official text | EUR-Lex text read on 2026-08-09: Article 14 read. Terms in clear, plain, intelligible, user-friendly and unambiguous language, publicly available and machine readable, with significant changes notified; where a service is directed at or predominantly used by minors, the conditions must be explained so minors can understand (2026-08-09) |
| A point of contact for authorities and for users, and a legal representative if you are not established in the Union | Articles 11 to 13 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: single points of contact for authorities and for recipients, and a legal representative where not established in the Union (2026-08-09) |
| Notice and action mechanism for illegal content, easy to access and electronic | Article 16 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Article 16 requires easy-to-access, user-friendly electronic notice mechanisms for illegal content (2026-08-09) |
| A statement of reasons for every restriction, published to the Commission's database by online platforms | Articles 17 and 24(5) | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: a statement of reasons for each restriction, submitted to the Commission database for online platforms (2026-08-09) |
| Internal complaint handling, free and electronic, open for at least six months | Article 20 | 2024-02-17 | official text | EUR-Lex text read on 2026-08-09: Article 20(1) read. Online platforms must give access to an effective internal complaint-handling system, electronically and free of charge, for at least six months after the decision (2026-08-09) |
| Out-of-court dispute settlement available to users, and cooperation with trusted flaggers | Articles 21 and 22 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read (2026-08-09) |
| Interfaces that deceive or manipulate a user's ability to decide freely are prohibited | Article 25 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Article 25 prohibits interface design that deceives, manipulates or distorts users' ability to make free decisions (2026-08-09) |
| Advertising identifiable in real time, with the payer and the main targeting parameters shown, and no targeting on special categories | Article 26 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: advertising must be identifiable, with the payer and the main targeting parameters disclosed; profiling on special categories is prohibited (2026-08-09) |
| No advertising based on profiling where you know the recipient is a minor | Article 28(2) | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: no advertising based on profiling where the platform is aware the recipient is a minor (2026-08-09) |
| Know your business customer: obtain and verify trader details before allowing them to sell | Articles 30 to 32 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: marketplaces must obtain and check trader identification before allowing use of the service (2026-08-09) |
| Micro and small enterprises are excluded from the platform-specific obligations | Article 19 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Article 19 excludes micro and small enterprises from the platform-specific obligations in Section 3 (2026-08-09) |
| Systemic risk assessment and mitigation, independent audit, ad repository and researcher access | Articles 34 to 40 | 2023-08-25 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: systemic risk assessment and mitigation, independent audit, advertisement repository and researcher data access for designated very large platforms (2026-08-09) |
Digital Operational Resilience Act #
Regulation (EU) 2022/2554 · 6 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| The management body carries final responsibility for ICT risk, and must be able to show it | Article 5 | 2025-01-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: the management body bears final responsibility for ICT risk management (2026-08-09) |
| An ICT risk management framework: identify, protect, detect, respond, recover and learn | Articles 6 to 16 | 2025-01-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: an ICT risk management framework covering protection, detection, response, recovery and learning (2026-08-09) |
| Classify ICT incidents and report major ones to your competent authority | Articles 17 to 23 | 2025-01-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: classification of ICT-related incidents and reporting of major incidents to the competent authority (2026-08-09) |
| A resilience testing programme, with threat-led penetration testing where you are significant | Articles 24 to 27 | 2025-01-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: a digital operational resilience testing programme, with threat-led penetration testing for significant entities (2026-08-09) |
| A register of ICT third-party arrangements, mandatory contract terms, and a documented exit strategy for each | Articles 28 to 30 | 2025-01-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: a register of information on contractual arrangements with ICT third-party providers, and mandatory contractual terms including exit strategies (2026-08-09) |
| If designated critical, an ICT provider to the financial sector comes under direct EU oversight | Articles 31 to 44 | 2025-01-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: critical ICT third-party providers are subject to an EU oversight framework (2026-08-09) |
European Accessibility Act #
Directive (EU) 2019/882 · 6 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Your obligations are those of the transposing national law, not the directive itself | Article 30 | 2025-06-28 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: a directive transposed by all Member States, with enforcement from 28 June 2025 and penalties set nationally (2026-08-09) |
| Meet the functional accessibility requirements; EN 301 549 gives a presumption of conformity | Annex I | 2025-06-28 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Annex I sets functional accessibility requirements; conformity with the harmonised standard EN 301 549 creates a presumption of conformity (2026-08-09) |
| Publish how the service meets the accessibility requirements, and keep it current | Article 13 and Annex V | 2025-06-28 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: service providers must publish information on how the service meets the accessibility requirements (2026-08-09) |
| Microenterprises providing services are exempt, but not microenterprises making or distributing covered products | Article 4(5) | 2025-06-28 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: microenterprises providing services are exempt; microenterprises manufacturing or distributing covered products are not (2026-08-09) |
| The disproportionate burden defence must be assessed, documented and periodically reviewed, not merely asserted | Article 14 | 2025-06-28 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: a disproportionate burden defence exists, and must be assessed, documented and re-assessed (2026-08-09) |
| Services provided under contracts concluded before 28 June 2025 have until 28 June 2030 | Article 32 | 2025-06-28 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: service contracts concluded before 28 June 2025 may continue until 28 June 2030 at the latest (2026-08-09) |
The reading log #
Every session, what was read, what it settled, and what it did not. Sorted newest first. A verification log that records only successes is a marketing page, so the last two columns carry as much weight as the first.
| Date | Instrument | What was read | Strength | Settled |
|---|---|---|---|---|
| 2026-08-09 | Regulation (EU) 2023/2854 data-act |
EUR-Lex text for Article 29, and Commission-adjacent professional analysis for the rest eur-lex.europa.eu/eli/reg/2023/2854/oj/eng |
official text | 3 |
| 2026-08-09 | Regulation (EU) 2022/2065 dsa |
EUR-Lex text for Articles 14 and 20, and professional sources for the tiered duties eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2065 |
official text | 4 |
| 2026-08-09 | Regulation (EU) 2022/2554 dora |
Professional sources and a published reproduction of Article 64 Corroboration only; the EUR-Lex text has not been read |
corroborated | 3 |
| 2026-08-09 | Directive (EU) 2019/882 eaa |
Professional sources across several jurisdictions Corroboration only; the directive text has not been read |
corroborated | 4 |
| 2026-08-06 | Regulation (EU) 2024/1689 ai-act |
Official Journal text, English, recitals 1 to 72 eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202401689 |
official text | 5 |
| 2026-08-06 | Regulation (EU) 2024/2847 cra |
European Commission pages for the Cyber Resilience Act, including the legislative summary digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act |
official guidance | 4 |
| 2026-08-06 | Regulation (EU) 2016/679 gdpr |
EUR-Lex text, Articles 30, 33 and 36 in the passages quoted eur-lex.europa.eu/eli/reg/2016/679/oj/eng |
official text | 3 |
| 2026-08-06 | Directive (EU) 2022/2555 nis2 |
Multiple independent professional analyses, consistent throughout Corroboration only; the directive text has not been read |
corroborated | 4 |
| 2026-08-06 | Regulation (EU) 2024/1689 and 2026/1744 ai-act |
Commission reporting and several independent law firms on the Digital Omnibus amendments Corroboration only |
corroborated | 5 |
Regulation (EU) 2023/2854 2026-08-09 · official text
| Settled | On what basis |
|---|---|
| Article 29, switching charges | Read verbatim: no switching charges from 12 January 2027, reduced charges permitted before that and capped at costs directly incurred |
| Application dates | In force 11 January 2024, applies 12 September 2025, access by design for products placed on the market from 12 September 2026 |
| Chapter VI and Chapter VIII | Switching and interoperability duties on providers of data processing services, corroborated consistently |
Also found
The unfair terms provisions reach contracts concluded before 12 September 2025 from 12 September 2027, which is the kind of retrospective date organisations miss.
Not settled
The wording of Articles 3, 4, 5, 13, 23 to 28, 30, 31 and 32. Only Article 29 was read.
Regulation (EU) 2022/2065 2026-08-09 · official text
| Settled | On what basis |
|---|---|
| Article 14, terms and conditions | Read: plain, intelligible, machine-readable terms, changes notified, and explained so minors can understand where a service is directed at them |
| Article 20, internal complaints | Read: free, electronic complaint handling open for at least six months after the decision |
| The tier structure | Intermediary, hosting, online platform, marketplace and very large platform duties, corroborated consistently |
| Article 19 | Micro and small enterprises are excluded from the platform-specific obligations |
Also found
Article 25 prohibits deceptive interface design, and Article 28(2) prohibits profiling-based advertising to known minors. Both are encoded as such.
Not settled
The wording of Articles 11 to 13, 16, 17, 21, 22, 25, 26, 28 and 30 to 40.
Regulation (EU) 2022/2554 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Application date | Applies from 17 January 2025, per Article 64 |
| The five pillars | Governance, ICT risk management, incident reporting, resilience testing and third-party risk, corroborated consistently |
| Oversight of critical providers | An EU oversight framework reaches ICT providers designated critical to the financial sector |
Also found
DORA operates as the more specific law where it covers the same ground as NIS2, which is now encoded as an overlap rather than left for the reader to discover.
Not settled
Every article number in this pack. None of the text has been read.
Directive (EU) 2019/882 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Application date | Obligations apply from 28 June 2025, after transposition due 28 June 2022 |
| Scope | Consumer e-commerce, banking, e-books, electronic communications, audiovisual media, transport ticketing, and certain terminals and consumer hardware |
| Microenterprise carve-out | Microenterprises providing services are exempt; those manufacturing or distributing covered products are not |
| Technical route | EN 301 549, which incorporates WCAG at level AA, gives a presumption of conformity with the functional requirements |
Also found
Services under contracts concluded before 28 June 2025 have until 28 June 2030, and enforcement has already begun in several Member States.
Not settled
All article numbers, the exact wording of Annex I, and the disproportionate burden test in Article 14. As a directive, the binding text is each national transposition rather than this one.
Regulation (EU) 2024/1689 2026-08-06 · official text
| Settled | On what basis |
|---|---|
| Eight prohibited practices | Recitals 29, 30, 31, 32 to 38, 42, 43 and 44, each matching the encoded rule |
| The Article 6(3) derogation | Recital 53 states all four conditions in the same terms, confirms that profiling removes it, and confirms the documentation and EU database duties |
| The eight Annex III areas | Recitals 54 to 62 |
| The Annex I route | Recitals 50 and 51 |
| AI literacy | Recital 20 |
Also found
Recital 40 cites Article 5(1) first subparagraph points (g) and (h), confirming this pack's lettering for biometric categorisation and real-time remote biometric identification.
Not settled
The enacting wording of Articles 5, 6, 9 to 15, 17, 26, 27, 43, 47 to 50, 53, 55, 72 and 73. Recitals state the substance; articles state the obligation. EUR-Lex records the consolidated version as 27 July 2026, which is the Omnibus amendment, and that consolidated text has not been read.
Regulation (EU) 2024/2847 2026-08-06 · official guidance
| Settled | On what basis |
|---|---|
| Entry into force | 10 December 2024 |
| Article 14 reporting | Applies from 11 September 2026, ahead of everything else |
| The remaining obligations | Apply from 11 December 2027 |
| Open-source stewards | Treated distinctly from manufacturers, the boundary turning on commercial activity |
Also found
Two facts found but not yet encoded: Chapter IV on notified bodies applies from 11 June 2026, and Article 69(3) extends the reporting duty to products already on the market.
Not settled
Article numbers for importer and distributor duties, and the five-year support period in Article 13(8), which the summary describes without numbering.
Regulation (EU) 2016/679 2026-08-06 · official text
| Settled | On what basis |
|---|---|
| Article 33(1) | Read verbatim: notification without undue delay and, where feasible, not later than 72 hours, unless the breach is unlikely to result in a risk |
| Article 35 | Confirmed through Article 36(1), which refers to a data protection impact assessment under Article 35 |
| Article 30 | Confirmed as the record of processing activities, with the exemption for organisations under 250 people being conditional rather than absolute, as this pack encodes it |
Also found
Articles 6, 9, 13, 14, 22, 28, 32, 37 and Chapter V corroborated across independent faithful reproductions of the article index. Numbering is consistent everywhere it appears.
Not settled
The wording of those eight, which has not been read.
Directive (EU) 2022/2555 2026-08-06 · corroborated
| Settled | On what basis |
|---|---|
| Article 21 | Risk management measures |
| Article 23 | Early warning within 24 hours, notification within 72, final report within one month |
| Article 20 | Management approval, oversight, training and personal liability |
| Article 41 | Transposition, deadline 17 October 2024 |
Also found
Transposition remains uneven across the Union in mid-2026, with several Member States referred to the Court of Justice. That is precisely why this pack raises a caution rather than asserting a national obligation.
Not settled
The registration duty is more complicated than the pack states: Article 3(4) requires Member States to keep lists with information submitted by entities, while Article 27 imposes a separate registry duty on certain digital entity types. The pack does not yet distinguish them.
Regulation (EU) 2024/1689 and 2026/1744 2026-08-06 · corroborated
| Settled | On what basis |
|---|---|
| Article 50 transparency | Applies from 2 August 2026 |
| Article 50(2) marking | Deferred to 2 December 2026 for systems already on the market |
| Annex III high risk | Deferred from 2 August 2026 to 2 December 2027 |
| Annex I high risk | Deferred to 2 August 2028 |
| Two new prohibitions | Non-consensual intimate imagery and child sexual abuse material, from 2 December 2026 |
Also found
Consistent across the Commission's own reporting and four independent firms.
Not settled
None of it read in the consolidated text, which is the next task for this pack.
The procedure #
How a reading session is conducted and recorded, so that a future session, by anyone, reaches the same standard as the last one.
| # | Step | What it means in practice |
|---|---|---|
| 1 | Read the provision | In the official text. Not a summary of it, and not a reproduction of it on somebody else's site. |
| 2 | Update the rule's record | Level, date, and what was read, in enough detail that another person could repeat the reading and land in the same place. |
| 3 | Add a session to the log | Four things: what was read, what it settled and on what basis, what was found incidentally, and what it did not settle. The last is not optional; a log recording only successes is a marketing page. |
| 4 | Raise the ruleset version | A published ruleset is immutable, and the build refuses to alter one. |
| 5 | Run the build | The integrity gate refuses a rule without a check record; replay parity refuses a snapshot that no longer reproduces the live ruleset. |
Standing rules
- A pack's strength is computed from its weakest rule, never declared. An average would hide exactly the rule a reader needs to know about.
- Nothing is presented as settled while any rule in it reads unchecked.
- No rule is upgraded on the strength of confidence. Confidence is not a reading.
What is outstanding #
In the order it should be done. A reader deciding whether to rely on a rule wants to know what is coming as much as what has been done.
| Pack | Next reading | Why it matters |
|---|---|---|
| dora | Articles 5 to 30 and 64 in the official text | Every article number rests on corroboration alone |
| eaa | Articles 4, 13, 14, 30 to 32 and Annex I, then the Polish transposing act | A directive binds through national law, and no national text has been read |
| data-act | Articles 3, 4, 5, 13, 23 to 28 and 32 | Only Article 29 has been read |
| dsa | Articles 16, 17, 25, 26, 28 and 30 | Only Articles 14 and 20 have been read |
| ai-act | Articles 50, 53 and 55, then the high-risk duties in Articles 9 to 15, 26 and 27 | Twenty-one rules rest on recitals or corroboration rather than the enacting text |
| gdpr | Articles 6, 9, 13, 14, 22, 28, 32 and 37 | Eight rules are corroborated by numbering alone |
| cra | Articles 13, 14, 19, 20 and 71; encode Chapter IV from 11 June 2026 and Article 69(3) | Three article numbers unconfirmed, two known facts unencoded |
| nis2 | Articles 3, 20, 21, 23, 27 and 41 | Nothing read; and Article 3(4) must be separated from the Article 27 registry |