Verification
A rule is only as good as the reading behind it. Every rule carries a record of what was read, at one of three strengths, and this page reproduces all of them from the rules themselves rather than from a summary that could drift.
How strength is graded #
| Level | Means | May be relied on | Rules |
|---|---|---|---|
| official text | Read against the text as published in the Official Journal, or the consolidated version on EUR-Lex | Yes, subject to your own judgement | 45 |
| official guidance | Confirmed against a European Commission page or official guidance, not against the text itself | As a strong starting point | 8 |
| corroborated | Confirmed across independent professional sources; the wording has not been read | As a starting point only | 56 |
| unchecked | Encoded from working knowledge | No. The build reports these, and none currently exist. | 0 |
A pack's strength is computed from its weakest rule rather than declared, because an average would hide exactly the rule a reader needs to know about.
Artificial Intelligence Act #
Regulation (EU) 2024/1689 · 21 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Social scoring leading to detrimental treatment | Article 5(1)(c) | 2025-02-02 | official text | OJ text, recital 31 (social scoring leading to detrimental or disproportionate treatment) (2026-08-06) |
| Predicting offending from profiling or traits alone | Article 5(1)(d) | 2025-02-02 | official text | OJ text, recital 42 (prediction based solely on profiling or personality traits) (2026-08-06) |
| Untargeted scraping of facial images | Article 5(1)(e) | 2025-02-02 | official text | OJ text, recital 43 (untargeted scraping of facial images from the internet or CCTV) (2026-08-06) |
| Emotion inference in the workplace or education | Article 5(1)(f) | 2025-02-02 | official text | OJ text, recital 44 (emotion inference in the workplace and education, excluding medical and safety uses) (2026-08-06) |
| Biometric categorisation inferring sensitive attributes | Article 5(1)(g) | 2025-02-02 | official text | OJ text, recital 30, and recital 40 which cites Article 5(1) first subparagraph point (g) (2026-08-06) |
| Real-time remote biometric identification in public spaces for law enforcement | Article 5(1)(h) | 2025-02-02 | official text | OJ text, recitals 32 to 38, and recital 40 which cites Article 5(1) first subparagraph point (h) (2026-08-06) |
| Subliminal or manipulative techniques distorting behaviour | Article 5(1)(a) | 2025-02-02 | official text | OJ text, recital 29 (subliminal and manipulative techniques materially distorting behaviour) (2026-08-06) |
| Exploiting vulnerabilities of age, disability or circumstance | Article 5(1)(b) | 2025-02-02 | official text | OJ text, recital 29 (exploitation of vulnerabilities of age, disability or social or economic situation) (2026-08-06) |
| Generating non-consensual intimate imagery of identifiable people | Article 5, as amended | 2026-12-02 | corroborated | Regulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read (2026-08-06) |
| Generating child sexual abuse material, or lacking safeguards against it | Article 5, as amended | 2026-12-02 | corroborated | Regulation (EU) 2026/1744 as reported by multiple firms; awaiting an EUR-Lex read (2026-08-06) |
| High-risk: falls within an Annex III area | Article 6(2) and Annex III | 2027-12-02 | official text | OJ text, recitals 54 to 62 (the eight Annex III areas); the deferred date is from Regulation (EU) 2026/1744 (2026-08-06) |
| Annex III area, with the Article 6(3) derogation claimed | Article 6(3) | 2027-12-02 | official text | OJ text, recital 53 (all four Article 6(3) conditions, the documentation duty and EU database registration) (2026-08-06) |
| The derogation is unavailable because the system profiles people | Article 6(3), final subparagraph | 2027-12-02 | official text | OJ text, recital 53 (profiling within the meaning of Article 4(4) GDPR removes the derogation) (2026-08-06) |
| High-risk as a regulated product or its safety component | Article 6(1) and Annex I | 2028-08-02 | official text | OJ text, recitals 50 and 51 (products under Union harmonisation legislation with third-party assessment) (2026-08-06) |
| Tell people they are interacting with an AI system | Article 50(1) | 2026-08-02 | corroborated | Article 50 transparency obligations confirmed as applying from 2 August 2026 across the Commission's reporting and several law firms; the wording of Article 50(1) is not yet read (2026-08-06) |
| Mark synthetic content in a machine-readable way | Article 50(2) | 2026-08-02 | corroborated | Deferral to 2026-12-02 for systems already on the market, confirmed across the same sources (2026-08-06) |
| Inform people exposed to emotion recognition or biometric categorisation | Article 50(3) | 2026-08-02 | corroborated | Article 50(3) as reported consistently; wording not yet read (2026-08-06) |
| Disclose deep fakes and AI-generated text on matters of public interest | Article 50(4) | 2026-08-02 | corroborated | Article 50(4) as reported consistently; wording not yet read (2026-08-06) |
| General-purpose model documentation, downstream information, copyright policy and training-content summary | Article 53 | 2025-08-02 | corroborated | Chapter V obligations applying from 2 August 2025, reported consistently; Article 53 wording not yet read (2026-08-06) |
| Systemic-risk evaluation, adversarial testing, incident reporting and cybersecurity | Articles 51 and 55 | 2025-08-02 | corroborated | Articles 51 and 55 with the 10^25 floating point operation presumption, reported consistently; wording not yet read (2026-08-06) |
| AI literacy: ensure staff dealing with the system are sufficiently competent | Article 4 | 2025-02-02 | official text | OJ text, recital 20 (AI literacy for providers, deployers and affected persons) (2026-08-06) |
Cyber Resilience Act #
Regulation (EU) 2024/2847 · 10 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Report actively exploited vulnerabilities and severe incidents to ENISA and the CSIRT | Article 14 | 2026-09-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act (2026-08-06) |
| Essential cybersecurity requirements in design, development and production | Article 13 and Annex I | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Vulnerability handling, including a coordinated disclosure policy and security updates | Annex I Part II | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Software bill of materials covering top-level dependencies | Annex I Part II(1) | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Conformity assessment, EU declaration of conformity and CE marking | Articles 32, 28 and 30 | 2027-12-11 | official guidance | https://digital-strategy.ec.europa.eu/en/policies/cra-summary (2026-08-06) |
| Define and publish the support period, at least five years unless the expected use is shorter | Article 13(8) | 2027-12-11 | corroborated | Commission summary describes the support period; the five year default and the Article 13(8) reference are not yet confirmed against the text (2026-08-06) |
| Verify the manufacturer's conformity assessment and marking before placing on the market | Article 19 | 2027-12-11 | corroborated | Commission summary describes importer duties; the Article 19 number is not yet confirmed against the text (2026-08-06) |
| Act with due care in relation to the requirements when making a product available | Article 20 | 2027-12-11 | corroborated | Commission summary describes distributor duties; the Article 20 number is not yet confirmed against the text (2026-08-06) |
| Software supplied outside a commercial activity is outside this Regulation entirely | Article 2 | 2027-12-11 | corroborated | Corrected after external review on 2026-08-09; free and open-source software supplied outside a commercial activity is outside the scope entirely; a steward operating within a commercial context carries lighter duties than a manufacturer (2026-08-09) |
| Draw up technical documentation showing how the product meets the essential requirements | Article 13 and Annex VII | 2027-12-11 | corroborated | Corrected after external review on 2026-08-09; technical documentation demonstrating conformity with the essential requirements must be drawn up before placing the product on the market (2026-08-09) |
General Data Protection Regulation #
Regulation (EU) 2016/679 · 14 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Identify and record a lawful basis for each purpose | Article 6 | 2018-05-25 | corroborated | Article index reproductions of Regulation (EU) 2016/679 (gdpr-info.eu and others), consistent on Article 6 (2026-08-06) |
| Establish an Article 9 condition before processing special categories | Article 9 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 9 for special categories (2026-08-06) |
| Inform people at collection, in clear and accessible terms | Articles 13 and 14 | 2018-05-25 | corroborated | Article index reproductions, consistent on Articles 13 and 14 (2026-08-06) |
| Maintain a record of processing activities | Article 30 | 2018-05-25 | corroborated | Corrected after external review on 2026-08-09; Article 30(5) exempts organisations under 250 people only where processing is occasional, poses no risk, and involves no special categories or criminal data. Payroll and HR are not occasional, so the exemption rarely applies (2026-08-09) |
| Carry out a data protection impact assessment before starting | Article 35 | 2018-05-25 | official text | EUR-Lex text: Article 36(1) refers to 'a data protection impact assessment under Article 35', confirming both the duty and its numbering (2026-08-06) |
| Automated decisions with legal or similarly significant effects need a basis, safeguards and human intervention | Article 22 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 22 for automated individual decision-making (2026-08-06) |
| A written processing agreement with every processor | Articles 28(3) and 28(4) | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 28 for processor contracts (2026-08-06) |
| Security appropriate to the risk, and the ability to demonstrate it | Article 32 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 32 for security of processing (2026-08-06) |
| Notify a personal data breach to the authority within 72 hours where it is likely to result in risk, and tell affected people where the risk is high | Articles 33(1) and 34 | 2018-05-25 | corroborated | Third external review, 2026-08-09; Articles 33(1) and 34 place the notification duties on the controller; Article 33(2) requires a processor to notify the controller instead (2026-08-09) |
| As a processor, notify the controller without undue delay after becoming aware of a breach | Article 33(2) | 2018-05-25 | corroborated | Third external review, 2026-08-09; Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a breach (2026-08-09) |
| A transfer mechanism, and a transfer impact assessment where required | Chapter V | 2018-05-25 | corroborated | Article index reproductions, consistent on Chapter V, Articles 44 to 50 (2026-08-06) |
| Designate a data protection officer | Article 37 | 2018-05-25 | corroborated | Article index reproductions, consistent on Article 37 for designation of the data protection officer (2026-08-06) |
| Facilitate and answer data subject requests: access, rectification, erasure, restriction, portability and objection | Chapter III, Articles 12 to 22 | 2018-05-25 | corroborated | Corrected after external review on 2026-08-09; Chapter III, Articles 12 to 22, requires controllers to facilitate the exercise of data subject rights and to respond within one month (2026-08-09) |
| Data protection by design and by default, from the moment the means of processing are chosen | Article 25 | 2018-05-25 | corroborated | Corrected after external review on 2026-08-09; Article 25 requires data protection by design and by default, at the time the means of processing are determined and during processing (2026-08-09) |
NIS2 Directive #
Directive (EU) 2022/2555 · 5 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Your obligations are those of the transposing national law, not the directive itself | Article 41 | 2024-10-18 | corroborated | Transposition deadline of 17 October 2024 corroborated widely; as of mid-2026 transposition remains uneven and the Commission has referred several Member States to the Court of Justice, which is exactly why this pack refuses to assert a national obligation (2026-08-06) |
| Submit your registration details to the competent authority, as an essential or an important entity | Articles 3(4) and 27 | 2024-10-18 | corroborated | Article 3(4) requires Member States to establish lists of essential and important entities with information submitted by them; note that Article 27 imposes a separate registry duty on certain digital entity types, which this pack does not yet distinguish (2026-08-06) |
| Risk management measures, owed by essential and important entities alike: policies, incident handling, continuity, supply chain, cryptography and access control | Article 21 | 2024-10-18 | corroborated | Multiple independent analyses of Directive (EU) 2022/2555, consistent on Article 21 for risk management measures (2026-08-06) |
| Early warning within 24 hours, notification within 72 hours, final report within one month | Article 23 | 2024-10-18 | corroborated | Multiple independent analyses, consistent on Article 23 and the 24 hour, 72 hour and one month structure (2026-08-06) |
| Management bodies approve the measures and can be held personally liable | Article 20 | 2024-10-18 | corroborated | Multiple independent analyses, consistent on Article 20 for management approval, oversight, training and personal liability (2026-08-06) |
Data Act #
Regulation (EU) 2023/2854 · 9 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Design connected products, and provide related services, so that the data generated is accessible to the user by default | Article 3 | 2026-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: connected products placed on the market after 12 September 2026 must be designed so that data is accessible by default (2026-08-09) |
| Make product and related service data available to the user, and to a third party at the user's request | Articles 4 and 5 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read (2026-08-09) |
| Remove switching charges: reduced until 12 January 2027, prohibited from that date | Article 29 | 2025-09-12 | official text | EUR-Lex text read on 2026-08-09: Article 29 read verbatim. From 12 January 2027 no switching charges; reduced charges permitted from 11 January 2024 until then, capped at costs directly incurred (2026-08-09) |
| Contractual terms enabling a customer to switch provider, run several in parallel, or move on premises | Chapter VI, Articles 23 to 31 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Chapter VI, Articles 23 to 31, requires contractual terms enabling switching to another provider or to on-premises infrastructure (2026-08-09) |
| Functional equivalence for infrastructure services, and open interfaces for other data processing services | Chapter VIII | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: functional equivalence for infrastructure services, open interfaces for others (2026-08-09) |
| Publish the jurisdiction your infrastructure sits under, and take measures against unlawful international governmental access | Articles 30 and 32 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: publish the jurisdiction of the ICT infrastructure and the measures against unlawful governmental access to non-personal data (2026-08-09) |
| Unilaterally imposed unfair data terms do not bind the other party, and this reaches older contracts from 12 September 2027 | Article 13 | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: unfairly imposed data-sharing terms are not binding; extends to pre-existing contracts from 12 September 2027 (2026-08-09) |
| Where the data is personal, the GDPR continues to apply alongside this Regulation | Article 1(5) | 2025-09-12 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: the Data Act covers personal and non-personal data and does not displace the GDPR (2026-08-09) |
| Make data available to a public body that demonstrates an exceptional need, such as a public emergency | Chapter V, Articles 14 to 22 | 2025-09-12 | corroborated | Corrected after external review on 2026-08-09; Chapter V, Articles 14 to 22, requires a data holder to make data available to a public sector body demonstrating an exceptional need, such as a public emergency (2026-08-09) |
Digital Services Act #
Regulation (EU) 2022/2065 · 15 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Terms and conditions in plain language, machine readable, with changes notified | Article 14 | 2024-02-17 | official text | EUR-Lex text read on 2026-08-09: Article 14 read. Terms in clear, plain, intelligible, user-friendly and unambiguous language, publicly available and machine readable, with significant changes notified; where a service is directed at or predominantly used by minors, the conditions must be explained so minors can understand (2026-08-09) |
| A point of contact for authorities and for users, and a legal representative if you are not established in the Union | Articles 11 to 13 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: single points of contact for authorities and for recipients, and a legal representative where not established in the Union (2026-08-09) |
| Notice and action mechanism for illegal content, easy to access and electronic | Article 16 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Article 16 requires easy-to-access, user-friendly electronic notice mechanisms for illegal content (2026-08-09) |
| Give a statement of reasons to the user for every restriction | Article 17 | 2024-02-17 | corroborated | Corrected after external review on 2026-08-09; Article 17 binds hosting services; the duty to publish to the Commission database is Article 24(5) and binds online platforms only (2026-08-09) |
| Submit those statements of reasons to the Commission's public database | Article 24(5) | 2024-02-17 | corroborated | Corrected after external review on 2026-08-09; Article 24(5) requires online platforms to submit statements of reasons to the Commission's public database (2026-08-09) |
| Internal complaint handling, free and electronic, open for at least six months | Article 20 | 2024-02-17 | official text | EUR-Lex text read on 2026-08-09: Article 20(1) read. Online platforms must give access to an effective internal complaint-handling system, electronically and free of charge, for at least six months after the decision (2026-08-09) |
| Out-of-court dispute settlement available to users, and cooperation with trusted flaggers | Articles 21 and 22 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read (2026-08-09) |
| Interfaces that deceive or manipulate a user's ability to decide freely are prohibited | Article 25 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Article 25 prohibits interface design that deceives, manipulates or distorts users' ability to make free decisions (2026-08-09) |
| Advertising identifiable in real time, with the payer and the main targeting parameters shown, and no targeting on special categories | Article 26 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: advertising must be identifiable, with the payer and the main targeting parameters disclosed; profiling on special categories is prohibited (2026-08-09) |
| No advertising based on profiling where you are aware with reasonable certainty that a recipient is a minor | Article 28(2) | 2024-02-17 | corroborated | Second external review, 2026-08-09; Article 28(2) applies wherever the platform is aware with reasonable certainty that a recipient is a minor, not only where the service is directed at minors (2026-08-09) |
| Know your business customer: obtain and verify trader details before allowing them to sell | Articles 30 to 32 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: marketplaces must obtain and check trader identification before allowing use of the service (2026-08-09) |
| Micro and small enterprises are excluded from the platform and marketplace obligations | Articles 19 and 29 | 2024-02-17 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: Article 19 excludes micro and small enterprises from the platform-specific obligations in Section 3 (2026-08-09) |
| Publish an annual transparency report on your content moderation | Article 15 | 2024-02-17 | corroborated | Corrected after external review on 2026-08-09; Article 15 requires annual transparency reports on content moderation from all intermediary services, with additional detail for platforms (2026-08-09) |
| Suspend, after a warning, users who frequently post manifestly illegal content | Article 23 | 2024-02-17 | corroborated | Corrected after external review on 2026-08-09; Article 23 requires platforms to suspend, after warning, recipients who frequently provide manifestly illegal content, and to suspend the processing of abusive notices (2026-08-09) |
| Systemic risk assessment and mitigation, independent audit, ad repository and researcher access | Articles 34 to 40 | 2023-08-25 | corroborated | Corroborated across independent professional sources on 2026-08-09; wording not read: systemic risk assessment and mitigation, independent audit, advertisement repository and researcher data access for designated very large platforms (2026-08-09) |
Digital Operational Resilience Act #
Regulation (EU) 2022/2554 · 21 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| The obligations apply from 17 January 2025 | Article 64 | 2025-01-17 | official text | EUR-Lex ELI metadata for CELEX 32022R2554 read on 2026-08-12: date_document 2022-12-14, date_publication 2022-12-27, first_date_entry_in_force 2025-01-17 (2026-08-12) |
| The management body carries final responsibility for ICT risk, and must be able to show it | Article 5 | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 5(2) reads that the management body shall define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework referred to in Article 6(1) (2026-08-12) |
| A sound, comprehensive and well-documented ICT risk management framework, forming part of the overall risk management system | Articles 6 to 15, with the technical standards in Delegated Regulation (EU) 2024/1774 | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 6(1) reads that financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system (2026-08-12) |
| An incident is major where it affected critical services and either the data-loss threshold or two of the other thresholds are met | Article 18, with Delegated Regulation (EU) 2024/1772 Articles 6, 8 and 9 | 2025-01-17 | official text | Official Journal text of Commission Delegated Regulation (EU) 2024/1772, OJ L 2024/1772 of 25.6.2024, Article 8 read 2026-08-12: an incident is major where it has affected critical services as referred to in Article 6 and where either the materiality threshold in Article 9(5) point (b) is met, or two or more of the other materiality thresholds in Articles 9(1) to (6) are met (2026-08-12) |
| Report a major incident in three stages: initial within four hours of classifying it, intermediate within 72 hours, final within one month | Articles 19 and 20, with Delegated Regulation (EU) 2025/301 Article 5 | 2025-01-17 | official text | Official Journal text of Commission Delegated Regulation (EU) 2025/301, OJ L 2025/301 of 20.2.2025, read 2026-08-12: Article 5 sets the initial notification within four hours from classification of the incident as major, and Article 5(1)(b) reads that the intermediate report is due at the latest within 72 hours from the submission of the initial notification, even where the status or the handling of the incident have not changed, with an updated intermediate report without undue delay and in any case when regular activities have been recovered. The empowerment is DORA Article 20, third subparagraph, not Article 19 (2026-08-12) |
| A deadline falling on a weekend or bank holiday may be met later, unless you are one of the excluded categories | Delegated Regulation (EU) 2025/301, Article 5 | 2025-01-17 | official text | Official Journal text of Delegated Regulation (EU) 2025/301, Article 5(4) read 2026-08-12: where the time limit for an initial notification, intermediate report or final report falls on a weekend day or a bank holiday in the Member State of the reporting financial entity, the entity may submit it later. The list of entities excluded from that extension, and the reported deadline of noon on the next working day, were not in the text returned and remain corroborated (2026-08-12) |
| Notifying a significant cyber threat is voluntary, not required | Article 19(2) | 2025-01-17 | corroborated | Article 19(2) of Regulation (EU) 2022/2554 as reported consistently: notification of significant cyber threats is voluntary (2026-08-12) |
| A digital operational resilience testing programme, with the systems supporting critical functions tested at least yearly | Articles 24 and 25 | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 24 establishes the testing programme; Article 24(6) reads that financial entities other than microenterprises shall ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions (2026-08-12) |
| As a microenterprise, still test: risk-based, with strategic planning rather than a full programme | Article 25(3) | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 25(3) reads that microenterprises shall perform the tests referred to in paragraph 1 by combining a risk-based approach with strategic planning of ICT testing (2026-08-12) |
| Threat-led penetration testing at least every three years, where the authorities identify you for it | Article 26 | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 26(1) reads that financial entities other than entities referred to in Article 16(1) first subparagraph, and other than microenterprises, which are identified in accordance with paragraph 8 third subparagraph, shall carry out at least every three years advanced testing by means of threat-led penetration testing (2026-08-12) |
| A register of ICT third-party arrangements, mandatory contract terms, and a documented exit strategy for each | Articles 28 to 30 | 2025-01-17 | corroborated | Structure corroborated on 2026-08-12 across a primary-source guide citing article ranges, the EUR-Lex record and three independent analyses: Chapter II Section 2 is Articles 6 to 15, Article 16(1) is the simplified regime, Articles 17 to 23 incidents, 24 to 27 testing, 28 to 30 third-party principles, 31 to 44 oversight, 64 application. The article text itself has still not been read. (2026-08-12) |
| If designated critical, an ICT provider to the financial sector comes under direct EU oversight | Articles 31 to 44 | 2025-01-17 | corroborated | Structure corroborated on 2026-08-12 across a primary-source guide citing article ranges, the EUR-Lex record and three independent analyses: Chapter II Section 2 is Articles 6 to 15, Article 16(1) is the simplified regime, Articles 17 to 23 incidents, 24 to 27 testing, 28 to 30 third-party principles, 31 to 44 oversight, 64 application. The article text itself has still not been read. (2026-08-12) |
| Adopt and regularly review a strategy on ICT third-party risk, including any multi-vendor strategy | Article 28(2), with Article 6(9) | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554, L 333 of 27.12.2022, read 2026-08-12: Article 28(2) reads that financial entities, other than microenterprises, shall adopt and regularly review a strategy on ICT third-party risk, taking into account the multi-vendor strategy referred to in Article 6(9) where applicable (2026-08-12) |
| The management body must keep its own ICT knowledge current, with regular training | Article 5(4) | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 5(4) reads that members of the management body shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including by following specific training on a regular basis, commensurate to the ICT risk being managed (2026-08-12) |
| Name someone: a role monitoring ICT third-party arrangements, or a senior manager accountable for them | Article 5(3) | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 5(3) reads that financial entities other than microenterprises shall establish a role to monitor the arrangements concluded with ICT third-party service providers, or shall designate a member of senior management as responsible for overseeing the related risk exposure and documentation (2026-08-12) |
| An independent control function for ICT risk, with the three lines of defence kept separate | Article 6(4) | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 6(4) reads that entities other than microenterprises shall assign responsibility for managing and overseeing ICT risk to a control function with an appropriate level of independence, and shall ensure segregation of risk management, control and internal audit functions according to the three lines of defence model (2026-08-12) |
| Review the framework yearly, after every major incident, and include a digital operational resilience strategy | Articles 6(5), 6(6) and 6(8) | 2025-01-17 | official text | Official Journal text of Regulation (EU) 2022/2554 read 2026-08-12: Article 6(5) reads that the framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents and following supervisory instructions or conclusions from testing or audit; Article 6(6) requires internal audit of the framework for entities other than microenterprises; Article 6(8) requires the framework to include a digital operational resilience strategy (2026-08-12) |
| Assess recurring incidents monthly: several small ones sharing a root cause can together be one major incident | Delegated Regulation (EU) 2024/1772, Article 8(2) | 2025-01-17 | official text | Official Journal text of Delegated Regulation (EU) 2024/1772, Article 8(2) read 2026-08-12: recurring incidents that individually are not major shall be considered as one major incident where they meet all of the stated conditions; financial entities shall assess the existence of recurring incidents on a monthly basis; that paragraph does not apply to microenterprises or to entities listed in Article 16(1) of Regulation (EU) 2022/2554 (2026-08-12) |
| If you over-reported, say so: a reclassification from major to non-major must be notified on its own template | Implementing Regulation (EU) 2025/302 | 2025-01-17 | official text | Official Journal text of Commission Implementing Regulation (EU) 2025/302, OJ L 2025/302 of 20.2.2025, read 2026-08-12: where after further assessment the entity concludes that an incident previously reported as major at no time fulfilled the criteria and thresholds in Article 8 of Delegated Regulation (EU) 2024/1772, it shall notify the competent authority of the reclassification using the template in Annex II, describing why the incident does not fulfil and is not expected to fulfil the criteria (2026-08-12) |
| The six thresholds you will actually measure against, with the figures | Delegated Regulation (EU) 2024/1772, Article 9 | 2025-01-17 | official text | Official Journal text of Delegated Regulation (EU) 2024/1772, Article 9 read 2026-08-12: 9(1) clients, financial counterparts and transactions, met where affected clients exceed 10 per cent of all clients using the affected service, or exceed 100 000, or affected financial counterparts exceed 30 per cent, or affected transactions exceed 10 per cent of the daily average number or amount, or relevant clients or counterparts are affected, with estimation from comparable reference periods where actual figures cannot be determined; 9(2) reputational impact by reference to Article 2 points (a) to (d); 9(3) duration and service downtime, met where service downtime is longer than 2 hours for ICT services supporting critical or important functions; 9(4) geographical spread, met where the incident has an impact in two or more Member States; 9(5) data losses; 9(6) economic impact, met where costs and losses have exceeded or are likely to exceed 100 000 euro (2026-08-12) |
| If you will miss a deadline, tell the authority before it passes and say why | Delegated Regulation (EU) 2025/301, Article 5(3) | 2025-01-17 | official text | Official Journal text of Delegated Regulation (EU) 2025/301, Article 5(3) read 2026-08-12: financial entities unable to submit the initial notification, intermediate report or final report within the time limits shall inform the competent authority without undue delay and no later than the respective time limit, and shall explain the reasons for the delay (2026-08-12) |
European Accessibility Act #
Directive (EU) 2019/882 · 14 rules · official source
| Rule | Provision | From | Checked | What was read |
|---|---|---|---|---|
| Your obligations are those of the transposing national law, not the directive itself | Article 31, with penalties under Article 30 | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882, L 151, 7.6.2019: the article list reads Article 29 Enforcement, Article 30 Penalties, Article 31 Transposition, Article 32 Transitional measures (2026-08-12) |
| Meet the accessibility requirements: Annex I Section I for every product, Section II for products other than self-service terminals, Sections III and IV for services | Article 4(1) and (2), and Annex I | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 4(1) reads that Member States shall ensure, subject to Article 14, that economic operators only place on the market products and only provide services that comply with the accessibility requirements in Annex I; Article 4(2) divides those requirements between Section I for all products and Section II for products other than self-service terminals (2026-08-12) |
| Publish how the service meets the requirements, in written and oral form, accessibly, and keep it for as long as the service runs | Article 13 and Annex V | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 13(1) reads that service providers shall ensure they design and provide services in accordance with the accessibility requirements; Article 13(2) reads that they shall prepare the information in accordance with Annex V, explain how the services meet the requirements, make it available to the public in written and oral format including in a manner accessible to persons with disabilities, and keep it for as long as the service is in operation (2026-08-12) |
| Microenterprises providing services are exempt, but not microenterprises making or distributing covered products | Article 4(5) | 2025-06-28 | official text | Official Journal text, Article 2(2) read: without prejudice to Article 32, this Directive applies to the listed services provided to consumers after 28 June 2025 (2026-08-12) |
| The disproportionate burden defence must be assessed, documented and periodically reviewed, not merely asserted | Article 14 and Annex VI | 2025-06-28 | official guidance | EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: the requirements apply provided they do not alter the basic nature of the product or service or impose a disproportionate burden, assessed against the criteria in Annex VI; the assessment is documented, kept for five years, and for a service repeated whenever it is altered or at least every five years (2026-08-12) |
| Products already used to provide a service have until 28 June 2030, unless you replace them sooner | Article 32 and recital 101 | 2025-06-28 | official text | Official Journal text, recital 101 read: a transitional period of five years after the date of application, during which products used for the provision of a service and placed on the market before that date need not comply unless the provider replaces them (2026-08-12) |
| Self-service terminals already in use may continue until the end of their economic life | Article 32 and recital 101 | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 32(2) reads that Member States MAY provide that self-service terminals lawfully used by service providers before 28 June 2025 may continue to be used in the provision of similar services until the end of their economically useful life, but no longer than 20 years after their entry into use (2026-08-12) |
| Products already lawfully in use have until 28 June 2030, and a contract agreed before 28 June 2025 may run to its expiry within five years | Article 32 | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 32(1) reads that Member States shall provide for a transitional period ending on 28 June 2030 during which service providers may continue to provide services using products lawfully used by them to provide similar services before that date, and that service contracts agreed before 28 June 2025 may continue without alteration until they expire, but no longer than five years from that date (2026-08-12) |
| Archived web content not updated or edited after 28 June 2025 is outside the Directive | Article 2(4) | 2025-06-28 | official guidance | EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: the Directive does not apply to certain website and mobile application content, including archives whose content is not updated or edited after 28 June 2025 (2026-08-12) |
| For a covered product: technical documentation, conformity assessment, declaration of conformity and CE marking | Article 7 and Annex IV | 2025-06-28 | corroborated | Corrected after external review on 2026-08-09; as a New Legislative Framework directive, manufacturers of covered products owe technical documentation, a conformity assessment, an EU declaration of conformity and CE marking (2026-08-09) |
| As importer or distributor: verify the CE marking, the documentation and the manufacturer's conformity before making the product available | Articles 9, 10 and 11 | 2025-06-28 | official guidance | EUR-Lex legislative summary for CELEX 32019L0882 read 2026-08-12: Chapter III sets obligations for economic operators dealing with products: Article 7 manufacturers, Article 8 authorised representatives, Article 9 importers, Article 10 distributors, Article 11 cases in which manufacturers' obligations apply to importers and distributors (2026-08-12) |
| Keep procedures that hold the service in conformity as it changes, and as the standards change under it | Article 13(3) | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 13(3) reads that service providers shall ensure procedures are in place so that the provision of services remains in conformity, and that changes in the characteristics of the service, in the applicable requirements, and in the harmonised standards or technical specifications shall be adequately taken into account (2026-08-12) |
| On finding your service non-compliant, correct it and immediately tell the authority in every Member State where it is provided | Article 13(4) | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 13(4) reads that in the case of non-conformity service providers shall take the corrective measures necessary, and where the service is not compliant shall immediately inform the competent national authorities of the Member States in which the service is provided, giving details of the non-compliance and of any corrective measures taken (2026-08-12) |
| On a reasoned request, produce everything needed to demonstrate conformity and cooperate with the authority | Article 13(5) | 2025-06-28 | official text | Official Journal text of Directive (EU) 2019/882 read 2026-08-12: Article 13(5) reads that service providers shall, further to a reasoned request from a competent authority, provide all information necessary to demonstrate the conformity of the service with the applicable accessibility requirements, and shall cooperate with that authority at its request (2026-08-12) |
The reading log #
Every session, what was read, what it settled, and what it did not. Sorted newest first. A verification log that records only successes is a marketing page, so the last two columns carry as much weight as the first.
| Date | Instrument | What was read | Strength | Settled |
|---|---|---|---|---|
| 2026-08-12 | Directive (EU) 2019/882 eaa |
Official Journal text of Article 13 in all five paragraphs and Article 32 in both eur-lex.europa.eu, CELEX 32019L0882 |
official text | 6 |
| 2026-08-12 | Delegated Regulation (EU) 2025/301 and Regulation (EU) 2022/2554 dora |
Official Journal text of Article 5(2), 5(3) and 5(4) of the reporting standards eur-lex.europa.eu, OJ L 2025/301 |
official text | 5 |
| 2026-08-12 | Delegated Regulation (EU) 2024/1772 dora |
Official Journal text, Article 9 in its six paragraphs, and the article list of Chapter I eur-lex.europa.eu, OJ L 2024/1772 |
official text | 3 |
| 2026-08-12 | Delegated Regulation (EU) 2024/1772 and Implementing Regulation (EU) 2025/302 dora |
Official Journal text: Article 8 and 8(2) of the classification standards, and the reclassification provision of the implementing standards eur-lex.europa.eu, OJ L 2024/1772 and L 2025/302 |
official text | 3 |
| 2026-08-12 | Commission Delegated Regulation (EU) 2025/301 dora |
Official Journal text of the reporting technical standards, OJ L 2025/301 of 20 February 2025, Article 5, with Article 5(1)(b) quoted verbatim in an ESMA answer eur-lex.europa.eu, OJ L_202500301 |
official text | 4 |
| 2026-08-12 | Regulation (EU) 2022/2554 with Delegated Regulation (EU) 2025/301 dora |
Article 19 and a reproduction of Article 5 of the reporting technical standards, corroborated across six independent sources Corroboration and a reproduction of the RTS article; the delegated text itself not yet read |
corroborated | 6 |
| 2026-08-12 | Regulation (EU) 2022/2554 and Directive (EU) 2019/882 all |
Official Journal text for DORA Articles 5 and 6, and for Directive 2019/882 Article 4; the publisher's legislative summary for the Accessibility Act transitions and exclusions eur-lex.europa.eu, CELEX 32022R2554 and 32019L0882 |
official text | 6 |
| 2026-08-12 | Regulation (EU) 2022/2554 dora |
Official Journal text, L 333 of 27 December 2022: Articles 24(6), 25(1), 25(3), 26(1) and 28(2) eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554 |
official text | 4 |
| 2026-08-12 | Directive (EU) 2019/882 eaa |
Official Journal text, L 151 of 7 June 2019: Article 2(2), Article 4(2), recital 101 and the article list eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32019L0882 |
official text | 4 |
| 2026-08-12 | Regulation (EU) 2022/2554 dora |
EUR-Lex ELI metadata for CELEX 32022R2554, read directly from the publisher eur-lex.europa.eu/eli/reg/2022/2554/oj/eng |
official text | 2 |
| 2026-08-12 | Regulation (EU) 2022/2554 dora |
The EUR-Lex record and a primary-source guide citing article ranges, corroborated against three independent analyses eur-lex.europa.eu/eli/reg/2022/2554/oj/eng |
corroborated | 4 |
| 2026-08-09 | Third external review, all eight batches all |
A third review against ruleset v0.7.1, the first run against corrected rules audit/AUDIT-BRIEF.md, batched |
corroborated | 5 |
| 2026-08-09 | Second external review, all eight batches all |
A second independent model review, run against ruleset v0.6.0 before today's corrections were applied audit/AUDIT-BRIEF.md, batched |
corroborated | 7 |
| 2026-08-09 | External review, all eight batches all |
An independent model review, one instrument per batch, triaged against the provisions cited audit/AUDIT-BRIEF.md with per-instrument batches |
corroborated | 9 |
| 2026-08-09 | External review of the rule set gdpr |
An independent model review of the AI Act and GDPR packs, triaged against the official texts audit/AUDIT-BRIEF.md, batch review |
corroborated | 3 |
| 2026-08-09 | Regulation (EU) 2023/2854 data-act |
EUR-Lex text for Article 29, and Commission-adjacent professional analysis for the rest eur-lex.europa.eu/eli/reg/2023/2854/oj/eng |
official text | 3 |
| 2026-08-09 | Regulation (EU) 2022/2065 dsa |
EUR-Lex text for Articles 14 and 20, and professional sources for the tiered duties eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2065 |
official text | 4 |
| 2026-08-09 | Regulation (EU) 2022/2554 dora |
Professional sources and a published reproduction of Article 64 Corroboration only; the EUR-Lex text has not been read |
corroborated | 3 |
| 2026-08-09 | Directive (EU) 2019/882 eaa |
Professional sources across several jurisdictions Corroboration only; the directive text has not been read |
corroborated | 4 |
| 2026-08-06 | Regulation (EU) 2024/1689 ai-act |
Official Journal text, English, recitals 1 to 72 eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202401689 |
official text | 5 |
| 2026-08-06 | Regulation (EU) 2024/2847 cra |
European Commission pages for the Cyber Resilience Act, including the legislative summary digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act |
official guidance | 4 |
| 2026-08-06 | Regulation (EU) 2016/679 gdpr |
EUR-Lex text, Articles 30, 33 and 36 in the passages quoted eur-lex.europa.eu/eli/reg/2016/679/oj/eng |
official text | 3 |
| 2026-08-06 | Directive (EU) 2022/2555 nis2 |
Multiple independent professional analyses, consistent throughout Corroboration only; the directive text has not been read |
corroborated | 4 |
| 2026-08-06 | Regulation (EU) 2024/1689 and 2026/1744 ai-act |
Commission reporting and several independent law firms on the Digital Omnibus amendments Corroboration only |
corroborated | 5 |
Directive (EU) 2019/882 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| A doubt resolved against this instrument | Article 32(1) does contain the contract limb. Products lawfully used before the date may continue to 28 June 2030, and a contract agreed before 28 June 2025 may run without alteration until it expires and no longer than five years from that date. This pack had recorded scepticism about the contract transition because the recital described only products. The recital was incomplete, not the commentary |
| A worse error, and the kind this product exists to avoid | Article 32(2) says Member States MAY provide the twenty-year terminal transition. It is an option for each Member State, not a right an operator holds. The pack asserted it as though it applied everywhere, which for a directive is precisely the mistake it warns others about. The finding now says it depends on the transposing act |
| Article 13(2) | Read: the information follows Annex V, must explain how the service meets the requirements, must be public in written and oral form including accessibly, and must be kept for as long as the service is in operation |
| Article 13(3), which had no rule | Procedures must hold the service in conformity through three kinds of change: to the service, to the requirements, and to the harmonised standards it was declared against |
| Article 13(4), which had no rule | On non-conformity: corrective measures, and immediately inform the competent authority of every Member State where the service is provided, with details. A self-reporting duty owed to each of them rather than to one home authority |
| Article 13(5), which had no rule | On a reasoned request, produce all information necessary to demonstrate conformity and cooperate |
Also found
The reported outer date of 2045 for terminals follows from twenty years after 2025 and is arithmetic rather than text.
Not settled
For DORA: the exclusion list in 2025/301 Article 5(4), the 24-hour duration limb of 2024/1772 Article 9(3), and Article 16(1) from the Journal rather than a reproduction. National transposing acts remain out of scope by decision, which Article 32(2) has just made a more consequential decision than it looked.
Delegated Regulation (EU) 2025/301 and Regulation (EU) 2022/2554 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| A duty the pack did not have | Article 5(3) read: an entity unable to submit within the time limits shall inform the competent authority without undue delay and no later than the respective time limit, explaining the reasons. The notice is due while the clock is still running, and there is no provision for explaining a deadline once it has been missed |
| The weekend extension exists in the text | Article 5(4) read: where a time limit falls on a weekend day or a bank holiday in the Member State of the reporting entity, the entity may submit later. The exclusion list and the reported noon-next-working-day figure were not in what came back and stay corroborated, which the finding now says instead of asserting them |
| Late classification | Article 5(2) read: where an incident is classified as major after the first 24 hours, the four hours run from that later classification |
| Article 16(1) is a list, not a size test | Reported in full: small and non-interconnected investment firms, payment institutions exempted under Directive (EU) 2015/2366, institutions exempted under Directive 2013/36/EU where the Member State has not applied the Article 2(4) option, electronic money institutions exempted under Directive 2009/110/EC, and small institutions for occupational retirement provision. Being larger than a microenterprise does not put an entity outside it, and being small does not put it inside |
| A stale finding corrected | The classification finding still described the thresholds as corroboration after Article 9 had been read. A finding that contradicts its own pack's check record is worse than an unread one |
Also found
The Article 16(1) list comes from a reproduction rather than from the Official Journal, and is labelled as such in the finding.
Not settled
Accessibility Act Articles 13 and 32 in full wording. National transposing acts are out of scope by decision rather than by backlog, and the scope note says so.
Delegated Regulation (EU) 2024/1772 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| The figures | Read: clients above 10 per cent of those using the affected service or above 100 000; financial counterparts above 30 per cent; transactions above 10 per cent of the daily average number or value; service downtime longer than 2 hours for services supporting critical or important functions; impact in two or more Member States; costs and losses exceeding or likely to exceed 100 000 euro |
| The provision that makes four hours survivable | Article 9(1) requires estimation from comparable reference periods where actual numbers cannot be determined. Without it, an entity would be choosing between a late report and a wrong one |
| What is qualitative rather than numeric | Reputational impact and data losses are met by reference to Articles 2 and 5 rather than by a figure, which is worth saying because commentary presents all six as quantitative |
Also found
The 24-hour incident duration limb of Article 9(3) is reported consistently but was not in what came back, and the finding labels it as unread.
Not settled
The weekend and bank holiday paragraph of 2025/301 Article 5, DORA Article 16, and Accessibility Act Articles 13 and 32 in full. National transposing acts are a separate question, addressed in the scope note rather than the queue.
Delegated Regulation (EU) 2024/1772 and Implementing Regulation (EU) 2025/302 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| The shape was wrong, not just the citation | Article 8 read: an incident is major where it has affected critical services under Article 6 and where either the threshold in Article 9(5) point (b) is met, or two or more of the other thresholds in Articles 9(1) to (6) are met. Affecting critical services is a gate that must be satisfied first, not one of the criteria being counted. This instrument had said two of six criteria or one severe one, which counted the gate as a criterion |
| Recurring incidents | Article 8(2) read: incidents that are individually not major can together be one major incident, assessed monthly, and the paragraph does not apply to microenterprises or Article 16(1) entities. One of the few places where the simplified regime removes a duty rather than lightening it. There was no rule for this at all |
| The way back from over-reporting | Implementing Regulation (EU) 2025/302 read: an entity concluding that an incident reported as major never met the criteria must notify the reclassification on the Annex II template and say why. Reporting early against an uncertain classification is intended behaviour, and withdrawing quietly is not an option |
Also found
Individual threshold figures remain corroborated and are labelled as such in the finding: more than ten per cent of clients or more than a hundred thousand clients, more than thirty per cent of financial counterparts, costs and losses above a hundred thousand euro, and recurrence of at least twice in six months.
Not settled
Article 9 itself, paragraph by paragraph, which is where those figures live. The weekend and bank holiday paragraph of 2025/301. DORA Article 16. Accessibility Act Articles 13 and 32 in full. And every national transposing act, which for a directive is what actually binds and which no amount of Union text will settle.
Commission Delegated Regulation (EU) 2025/301 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| A citation that was wrong | The deadlines are made under DORA Article 20, third subparagraph, which is the empowerment; Article 19 requires the reports. The rule cited Article 19 alone for a four-hour figure, which is the wrong provision even though the figure was right |
| The four hours | Read: the initial notification is due within four hours from the classification of the incident as major, including where the entity classifies it as major at a later stage |
| The 72 hours, and what commentary drops | Read: at the latest within 72 hours from the submission of the initial notification, even where the status or handling has not changed, and an updated intermediate report without undue delay and in any case when regular activities have been recovered. So the clock runs from the notification rather than from the incident, and an incident lasting more than 72 hours produces at least two intermediate reports |
| The classification instrument | The Official Journal reference for Delegated Regulation (EU) 2024/1772 confirms it specifies the classification criteria, the materiality thresholds and the details of reports. The rule now sits at official-summary, because the reference is read and the thresholds are not |
Also found
The two of six criteria figure remains corroboration rather than a reading, and the finding now says so in as many words.
Not settled
The weekend and bank holiday exclusion stays at corroborated: the surrounding article was read but that paragraph was not in what came back, and it is the kind of detail that decides whether somebody is on call at the weekend. Also unread: the materiality thresholds in 2024/1772, DORA Article 16, Accessibility Act Articles 13 and 32 in full, and every national transposing act.
Regulation (EU) 2022/2554 with Delegated Regulation (EU) 2025/301 2026-08-12 · corroborated
| Settled | On what basis |
|---|---|
| Where the deadlines actually live | Not in DORA. Article 19 requires the three reports; the time limits are in Article 5 of Commission Delegated Regulation (EU) 2025/301, and the forms in Implementing Regulation (EU) 2025/302. A rule citing only DORA for a four-hour deadline would be citing the wrong instrument |
| The three stages | Initial as early as possible, within four hours of classification as major and no later than 24 hours from becoming aware. Intermediate within 72 hours of the initial notification, even where nothing has changed. Final no later than one month after the latest intermediate report |
| The clock starts at classification | Not at detection. A slow classification does not buy time, it consumes it, and the finding now says so |
| Classification | Criteria and thresholds sit in Delegated Regulation (EU) 2024/1772, Articles 8 and 9, reported as two of six criteria exceeded or one where the impact is severe |
| A nuance worth encoding | The weekend and bank holiday extension is not available to credit institutions, central counterparties, operators of trading venues, or entities that are also essential or important under NIS2, and an authority may withdraw it from any entity it considers significant. Encoded as a caution, because a four-hour clock that does not pause at a weekend is an on-call rota rather than a policy |
| Voluntary notification | Article 19(2) makes notification of a significant cyber threat voluntary, which is worth stating so nobody treats it as a duty |
Also found
The overlap on one incident against three clocks now carries the three figures: four hours under DORA from classification, twenty-four under NIS2 from awareness, seventy-two under the GDPR from awareness.
Not settled
Deliberately left at corroborated rather than marked as read. These deadlines are the most consequential figures in the pack and they live in two delegated acts that have not been opened, so the level says corroborated and the citations name the instruments to open. A wrong deadline here would be worse than no rule.
Regulation (EU) 2022/2554 and Directive (EU) 2019/882 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| DORA Article 5 | Read: the management body defines, approves, oversees and is responsible for the framework under 5(2); entities other than microenterprises name a monitoring role or a senior manager for third-party arrangements under 5(3); and members must keep their own ICT knowledge current with regular training under 5(4), which has no size carve-out |
| DORA Article 6 | Read: 6(1) the framework itself, 6(4) an independent control function and three lines of defence for entities other than microenterprises, 6(5) yearly review or periodic for microenterprises and after every major incident, 6(6) internal audit, 6(8) a digital operational resilience strategy inside the framework. Four rules where the pack had one |
| Accessibility Act Article 4(1) | Read: economic operators may only place products on the market and provide services that comply with Annex I, subject to Article 14 |
| The disproportionate burden defence | The criteria are in Annex VI, the assessment must be documented and kept five years, repeated whenever a service is altered and at least every five years, and produced on request. The pack said it must be assessed and documented; it now says for how long and how often |
| Two transitions corrected | Self-service terminals may run to the end of their economic life but no longer than twenty years after entering service, a bound the pack lacked. And the third transition is described by the publisher as facilities already lawfully in use by 28 June 2025 rather than as contracts concluded before then, which is how it is usually reported |
| An exclusion the pack missed | Archived website and application content not updated or edited after 28 June 2025 is outside the Directive under Article 2(4), and editing it brings it back in |
Also found
The Accessibility Act's Chapter III structure confirmed from the article list: 7 manufacturers, 8 authorised representatives, 9 importers, 10 distributors, 11 when a manufacturer's duties fall on an importer or distributor.
Not settled
DORA Articles 16 and 17 to 23 on incident classification and reporting, where the deadlines are set partly by technical standards and a wrong figure would be worse than none. Accessibility Act Articles 13 and 32 in full wording, and any national transposing act.
Regulation (EU) 2022/2554 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| A rule that was wrong | The pack excluded microenterprises from resilience testing altogether. Article 25(3) requires them to test, combining a risk-based approach with strategic planning. That is a lighter duty, not an absent one, and telling a microenterprise it owed nothing was a wrong answer rather than an imprecise one |
| Article 24(6) | Read: entities other than microenterprises must ensure at least yearly that appropriate tests are conducted on all systems supporting critical or important functions. The programme rule now carries the yearly cadence |
| Article 26(1) | Read: threat-led penetration testing at least every three years, for entities that are neither Article 16(1) entities nor microenterprises and that are identified by the authority under paragraph 8. Three conditions, where the pack had said only that it applies where you are significant |
| Article 28(2) | Read: entities other than microenterprises shall adopt and regularly review a strategy on ICT third-party risk, taking the multi-vendor strategy in Article 6(9) into account. The pack had no rule for it |
Also found
Delegated Regulation (EU) 2024/1774 carries the technical standards for both the ordinary and the simplified frameworks, and is now named in the framework rule.
Not settled
Articles 5, 6 and 16 in full, and Articles 17 to 23 on incident reporting. The testing and third-party regimes are now read; governance, the framework itself and incident reporting are not.
Directive (EU) 2019/882 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| Article 2(2) | Read: without prejudice to Article 32, the Directive applies to the listed services provided to consumers after 28 June 2025. That settles both the date and the consumer qualifier this pack applies to services |
| Article 4(2) | Read: all products must meet Annex I Section I, and all products except self-service terminals must also meet Section II. The requirements rule now states that structure instead of pointing at Annex I as a whole |
| The article numbering | The Official Journal's own list: 29 Enforcement, 30 Penalties, 31 Transposition, 32 Transitional measures, 33 Report and review. This confirms the correction made earlier from a reviewer's finding |
| Recital 101, and a rule that was wrong | The five-year transition covers products used to provide a service and placed on the market before the date of application, and it ends early if the provider replaces the product. Self-service terminals have a separate and much longer transition, until the end of their economic life. The pack had one rule conflating these with a contract-based transition; it is now three, and the contract one is marked as reported rather than read |
Also found
The transition for service contracts concluded before 28 June 2025 running to 28 June 2030 is stated by several sources but is not what the recital describes, so it stands as corroborated and separate.
Not settled
Articles 9, 10, 13, 14, 15, 16 and 32 in full. The structure and the dates are now read; the wording of the operator duties is not.
Regulation (EU) 2022/2554 2026-08-12 · official text
| Settled | On what basis |
|---|---|
| Adoption and publication | Adopted 14 December 2022, published in the Official Journal on 27 December 2022, from the publisher's own date fields |
| Application | EUR-Lex records the first date of entry into force as 17 January 2025, which matches the application date this pack already carried |
Also found
A discrepancy worth recording rather than resolving: commentary widely gives 16 January 2023 as the date of entry into force, twenty days after publication, while the publisher's own metadata gives 17 January 2025. Nothing turns on it for a reader planning compliance, because the duties bind from January 2025 on either account, and the pack now states both rather than choosing one silently.
Not settled
The article text. Fetching the document returned the page furniture and the metadata rather than the provisions, so Articles 5, 6, 16, 24 and 28 are still corroborated rather than read. The next attempt needs a session with room to pull the full text in parts.
Regulation (EU) 2022/2554 2026-08-12 · corroborated
| Settled | On what basis |
|---|---|
| The article ranges | Articles 6 to 15 for the risk management framework, 16(1) for the simplified regime, 17 to 23 incidents, 24 to 27 testing, 28 to 30 third-party principles, 31 to 44 oversight of critical providers, 45 information sharing, 64 application |
| Two dates | In force 16 January 2023, applying from 17 January 2025 under Article 64 |
| A correction to the framework rule | It cited Articles 6 to 16, which folds the simplified regime into the standard one. Article 16 is the alternative, not part of the baseline |
| A correction to the simplified regime | The pack described Article 16(1) as a microenterprise carve-out. It is a list of entity types, of which microenterprises are one: small and non-interconnected investment firms and small institutions for occupational retirement provision are also on it. Being larger than a microenterprise does not put a reader outside the list, and the finding now says so |
Also found
Also noted for later encoding: the register of information sits in Article 28(9) rather than being a general Article 28 duty, Directive (EU) 2022/2556 is the amending directive accompanying DORA, and the first critical third-party providers were designated in November 2025.
Not settled
No article of DORA has been read against the official text. This pass corrected structure and wording from corroboration, which is worth doing and is not the same thing. Reading Articles 5, 6, 16, 24, 28 and 64 in the published text remains the next task for this pack.
Third external review, all eight batches 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Breach notification bound the wrong party | Articles 33(1) and 34 bind the controller; a processor notifies the controller under Article 33(2). The rule fired for everyone. Split into two |
| The NIS2 size floor was absolute | Article 2(2) reaches certain entities whatever their size, among them public administration, electronic communications providers and trust service providers. A micro public body was being excluded. Gate corrected |
| Access by design missed related services | Article 3(1) reaches connected products and related services alike; the condition read only the product |
| Two Accessibility duties were absent | Articles 9 and 10 impose verification duties on importers and distributors before a covered product is made available |
| A verbatim quote needed its application date | Article 29 is worded from 11 January 2024, but the Regulation applies from 12 September 2025 under Article 50, which is when the reduced-charge regime begins to bind. The quote stands; the finding now says both |
Also found
The Cyber Resilience Act and AI Act batches returned nothing at all. After three rounds that is the useful signal: the model has stopped finding defects, and what remains is reading official texts rather than asking a reviewer.
Not settled
Two disputes between reviews, both now recorded in the instrument rather than resolved by preference. Whether DORA displaces NIS2 wholly for a financial entity or duty by duty: the overlap states the mechanism and names the question. Whether the micro and small exclusion in the DSA reaches marketplace duties under Section 4: one review said it does, the next said it does not and cited a garbled provision, so the current encoding stands until Articles 19 and 29 are read. Two findings were rejected outright: one misread a condition that already contained the exemption it asked for, and one cited an article number that does not exist.
Second external review, all eight batches 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Article 28(2) was under-firing badly | The advertising prohibition fired only where a service was directed at minors. It reaches any platform aware with reasonable certainty that a recipient is a minor, which is every general-audience platform. Corrected |
| NIS2 had no size threshold | The directive generally reaches entities at or above medium size. A small energy company was being told it owed the full regime. Added to the gate |
| The registration duty cites two articles | Article 3(4) obliges Member States to keep lists; Article 27 carries the entity-facing registration duty. Both now cited |
| Two Data Act duties were welded together | Publishing the jurisdiction of the infrastructure and taking measures against unlawful governmental access are Articles 30 and 32 respectively |
| Accessibility transposition cited the penalties article | Article 31 is transposition; Article 30 is penalties. Corrected |
| A legacy rule borrowed the wrong date | The Accessibility transition runs from contracts concluded before 28 June 2025, but the rule was reading a question whose cut-off is 2 August 2026 and belongs to the AI Act. The rule no longer depends on it, and the question now names its own date |
| Three notes still read as advice | Wording in NIS2, DORA and the Accessibility pack told the reader what to check rather than what the provision says. Rewritten |
Also found
Most of this review independently reproduced corrections already made earlier the same day, because the batches predated them. Two reviewers reaching the same conclusions from the same text is worth more than either reaching it alone.
Not settled
The reviewer again reported the high-risk provider and deployer duties as missing, reading the rules array without the attached obligations. The export was changed for that reason after the first review, but these batches predated the change. It also asserted that any AI system is a product with digital elements and so within the CRA; that is too broad to encode without reading Article 3, and the question text now explains what counts instead.
External review, all eight batches 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Twenty-one conditions were wrong | Micro and small enterprise exemptions were missing throughout: DSA Articles 19 and 29, Data Act Article 7, DORA Articles 16 and 24. All added |
| Article 22 was over-firing | It fired on any profiling. It now requires decisions with legal or similarly significant effects, which is what the provision says, and a new question asks for that fact |
| Article 30(5) was under-firing | The record of processing exemption is narrow enough that routine payroll defeats it. The rule now fires for everyone, with the conditions stated |
| Two DSA duties were conflated | Article 17, a notice to the user by hosting services, and Article 24(5), publication to the Commission database by platforms. Split |
| The NIS2 gate missed sectors | Water, waste, manufacturing, postal and space are in Annexes I and II and were absent. Added |
| The NIS2 fact was misread | It was named for essential entities while asking about both. Renamed, because a reviewer reading the condition should not have to check the question text |
| Non-commercial open source was in scope | It is outside the CRA entirely rather than lightly regulated. The gate now excludes it, and the rule states the boundary |
| The Accessibility gate blocked product makers | A payment terminal sold business to business is still covered. The consumer test now applies to services rather than to products |
| Eight duties were missing | Data subject rights and data protection by design under the GDPR, transparency reports and repeat-offender suspension under the DSA, business-to-government sharing under the Data Act, technical documentation under the CRA, and product conformity and CE marking under the Accessibility Act |
Also found
Two findings were rejected: the reviewer read the export shape rather than the engine and reported the high-risk provider and deployer duties as missing, when they attach when the tier fires. The export now shows them, so the next reviewer is not misled the same way.
Not settled
One finding is unverified and recorded as such in the overlap itself: that the CRA provides for its requirements to be assessed within the AI Act conformity procedure for high-risk systems rather than separately. That mechanism must be read before the overlap asserts either position.
External review of the rule set 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Article 35(3) does not name a sector | The DPIA rule fired on profiling in the finance sector, which appears nowhere in the provision. Removed, and the three Article 35(3) cases are now stated in the finding itself |
| Article 37(1) turns on core activities | The DPO rule fired for any large organisation processing special categories. Incidental processing, such as employee health records, does not trigger it however large the organisation. Condition narrowed |
| Four passages read as advice | Wording in the overlap layer told the reader how to organise their work rather than what the law requires. Rewritten to state the requirement and stop |
Also found
The reviewer's three most confident findings asserted that Regulation (EU) 2026/1744 does not exist and that the AI Act still binds Annex III systems from 2 August 2026. Its knowledge predates the amendment. Those findings were discarded, and the audit tooling now detects that failure mode and states it as a fact about the reviewer rather than the rule.
Not settled
Six instruments were not reviewed at all: the reviewer covered two and stopped. The brief is now issued one instrument at a time, with the amendments in force stated in front of it.
Regulation (EU) 2023/2854 2026-08-09 · official text
| Settled | On what basis |
|---|---|
| Article 29, switching charges | Read verbatim: no switching charges from 12 January 2027, reduced charges permitted before that and capped at costs directly incurred |
| Application dates | In force 11 January 2024, applies 12 September 2025, access by design for products placed on the market from 12 September 2026 |
| Chapter VI and Chapter VIII | Switching and interoperability duties on providers of data processing services, corroborated consistently |
Also found
The unfair terms provisions reach contracts concluded before 12 September 2025 from 12 September 2027, which is the kind of retrospective date organisations miss.
Not settled
The wording of Articles 3, 4, 5, 13, 23 to 28, 30, 31 and 32. Only Article 29 was read.
Regulation (EU) 2022/2065 2026-08-09 · official text
| Settled | On what basis |
|---|---|
| Article 14, terms and conditions | Read: plain, intelligible, machine-readable terms, changes notified, and explained so minors can understand where a service is directed at them |
| Article 20, internal complaints | Read: free, electronic complaint handling open for at least six months after the decision |
| The tier structure | Intermediary, hosting, online platform, marketplace and very large platform duties, corroborated consistently |
| Article 19 | Micro and small enterprises are excluded from the platform-specific obligations |
Also found
Article 25 prohibits deceptive interface design, and Article 28(2) prohibits profiling-based advertising to known minors. Both are encoded as such.
Not settled
The wording of Articles 11 to 13, 16, 17, 21, 22, 25, 26, 28 and 30 to 40.
Regulation (EU) 2022/2554 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Application date | Applies from 17 January 2025, per Article 64 |
| The five pillars | Governance, ICT risk management, incident reporting, resilience testing and third-party risk, corroborated consistently |
| Oversight of critical providers | An EU oversight framework reaches ICT providers designated critical to the financial sector |
Also found
DORA operates as the more specific law where it covers the same ground as NIS2, which is now encoded as an overlap rather than left for the reader to discover.
Not settled
Every article number in this pack. None of the text has been read.
Directive (EU) 2019/882 2026-08-09 · corroborated
| Settled | On what basis |
|---|---|
| Application date | Obligations apply from 28 June 2025, after transposition due 28 June 2022 |
| Scope | Consumer e-commerce, banking, e-books, electronic communications, audiovisual media, transport ticketing, and certain terminals and consumer hardware |
| Microenterprise carve-out | Microenterprises providing services are exempt; those manufacturing or distributing covered products are not |
| Technical route | EN 301 549, which incorporates WCAG at level AA, gives a presumption of conformity with the functional requirements |
Also found
Services under contracts concluded before 28 June 2025 have until 28 June 2030, and enforcement has already begun in several Member States.
Not settled
All article numbers, the exact wording of Annex I, and the disproportionate burden test in Article 14. As a directive, the binding text is each national transposition rather than this one.
Regulation (EU) 2024/1689 2026-08-06 · official text
| Settled | On what basis |
|---|---|
| Eight prohibited practices | Recitals 29, 30, 31, 32 to 38, 42, 43 and 44, each matching the encoded rule |
| The Article 6(3) derogation | Recital 53 states all four conditions in the same terms, confirms that profiling removes it, and confirms the documentation and EU database duties |
| The eight Annex III areas | Recitals 54 to 62 |
| The Annex I route | Recitals 50 and 51 |
| AI literacy | Recital 20 |
Also found
Recital 40 cites Article 5(1) first subparagraph points (g) and (h), confirming this pack's lettering for biometric categorisation and real-time remote biometric identification.
Not settled
The enacting wording of Articles 5, 6, 9 to 15, 17, 26, 27, 43, 47 to 50, 53, 55, 72 and 73. Recitals state the substance; articles state the obligation. EUR-Lex records the consolidated version as 27 July 2026, which is the Omnibus amendment, and that consolidated text has not been read.
Regulation (EU) 2024/2847 2026-08-06 · official guidance
| Settled | On what basis |
|---|---|
| Entry into force | 10 December 2024 |
| Article 14 reporting | Applies from 11 September 2026, ahead of everything else |
| The remaining obligations | Apply from 11 December 2027 |
| Open-source stewards | Treated distinctly from manufacturers, the boundary turning on commercial activity |
Also found
Two facts found but not yet encoded: Chapter IV on notified bodies applies from 11 June 2026, and Article 69(3) extends the reporting duty to products already on the market.
Not settled
Article numbers for importer and distributor duties, and the five-year support period in Article 13(8), which the summary describes without numbering.
Regulation (EU) 2016/679 2026-08-06 · official text
| Settled | On what basis |
|---|---|
| Article 33(1) | Read verbatim: notification without undue delay and, where feasible, not later than 72 hours, unless the breach is unlikely to result in a risk |
| Article 35 | Confirmed through Article 36(1), which refers to a data protection impact assessment under Article 35 |
| Article 30 | Confirmed as the record of processing activities, with the exemption for organisations under 250 people being conditional rather than absolute, as this pack encodes it |
Also found
Articles 6, 9, 13, 14, 22, 28, 32, 37 and Chapter V corroborated across independent faithful reproductions of the article index. Numbering is consistent everywhere it appears.
Not settled
The wording of those eight, which has not been read.
Directive (EU) 2022/2555 2026-08-06 · corroborated
| Settled | On what basis |
|---|---|
| Article 21 | Risk management measures |
| Article 23 | Early warning within 24 hours, notification within 72, final report within one month |
| Article 20 | Management approval, oversight, training and personal liability |
| Article 41 | Transposition, deadline 17 October 2024 |
Also found
Transposition remains uneven across the Union in mid-2026, with several Member States referred to the Court of Justice. That is precisely why this pack raises a caution rather than asserting a national obligation.
Not settled
The registration duty is more complicated than the pack states: Article 3(4) requires Member States to keep lists with information submitted by entities, while Article 27 imposes a separate registry duty on certain digital entity types. The pack does not yet distinguish them.
Regulation (EU) 2024/1689 and 2026/1744 2026-08-06 · corroborated
| Settled | On what basis |
|---|---|
| Article 50 transparency | Applies from 2 August 2026 |
| Article 50(2) marking | Deferred to 2 December 2026 for systems already on the market |
| Annex III high risk | Deferred from 2 August 2026 to 2 December 2027 |
| Annex I high risk | Deferred to 2 August 2028 |
| Two new prohibitions | Non-consensual intimate imagery and child sexual abuse material, from 2 December 2026 |
Also found
Consistent across the Commission's own reporting and four independent firms.
Not settled
None of it read in the consolidated text, which is the next task for this pack.
The procedure #
How a reading session is conducted and recorded, so that a future session, by anyone, reaches the same standard as the last one.
| # | Step | What it means in practice |
|---|---|---|
| 1 | Read the provision | In the official text. Not a summary of it, and not a reproduction of it on somebody else's site. |
| 2 | Update the rule's record | Level, date, and what was read, in enough detail that another person could repeat the reading and land in the same place. |
| 3 | Add a session to the log | Four things: what was read, what it settled and on what basis, what was found incidentally, and what it did not settle. The last is not optional; a log recording only successes is a marketing page. |
| 4 | Raise the ruleset version | A published ruleset is immutable, and the build refuses to alter one. |
| 5 | Run the build | The integrity gate refuses a rule without a check record; replay parity refuses a snapshot that no longer reproduces the live ruleset. |
Standing rules
- A pack's strength is computed from its weakest rule, never declared. An average would hide exactly the rule a reader needs to know about.
- Nothing is presented as settled while any rule in it reads unchecked.
- No rule is upgraded on the strength of confidence. Confidence is not a reading.
What is outstanding #
In the order it should be done. A reader deciding whether to rely on a rule wants to know what is coming as much as what has been done.
| Pack | Next reading | Why it matters |
|---|---|---|
| dora | DORA Article 1(2) and NIS2 Article 4, on whether the carve-out is total or duty by duty | Two reviews disagree and a financial entity would act on the answer |
| dsa | Articles 19 and 29, on whether the micro and small exclusion reaches Section 4 marketplace duties | Two reviews disagree; the current encoding exempts them |
| cra | Article 8 and Article 12, on how CRA conformity interacts with the AI Act procedure | An external review asserts the routes combine; the overlap currently records the question rather than an answer |
| dora | The exclusion list in 2025/301 Article 5(4), the 24-hour duration limb of 2024/1772 Article 9(3), and Article 16(1) in the Official Journal rather than in reproduction | Three specific figures and one list remain corroborated; everything around them is read |
| eaa | Whether Poland exercised the Article 32(2) option for self-service terminals | The twenty-year terminal transition is a Member State option, so its existence is a national question rather than a Union one |
| data-act | Articles 3, 4, 5, 13, 23 to 28 and 32 | Only Article 29 has been read |
| dsa | Articles 16, 17, 25, 26, 28 and 30 | Only Articles 14 and 20 have been read |
| ai-act | Articles 50, 53 and 55, then the high-risk duties in Articles 9 to 15, 26 and 27 | Twenty-one rules rest on recitals or corroboration rather than the enacting text |
| gdpr | Articles 6, 9, 13, 14, 22, 28, 32 and 37 | Eight rules are corroborated by numbering alone |
| cra | Articles 13, 14, 19, 20 and 71; encode Chapter IV from 11 June 2026 and Article 69(3) | Three article numbers unconfirmed, two known facts unencoded |
| nis2 | Articles 3, 20, 21, 23, 27 and 41 | Nothing read; and Article 3(4) must be separated from the Article 27 registry |