# On Monday, Stop Recording

**Deck:** The European Commission can already test the most capable AI models from inside the companies that build them. What it gains on Monday is the power to order the company under test to switch off any logging that would record what its inspectors did there. The company keeps the knowledge that the visit happened. It loses the proof. Nobody has explained the sentence that does this: the regulation carries six explanatory recitals, and not one of them mentions logging.

**By:** URnetwork editorial
**Dateline:** San Francisco — August 7, 2026

**Category:** News / Analysis

---

On Monday, inside the European Commission — the EU's executive, and since the AI Act of 2024 the direct regulator of the most capable AI models — a new power comes within reach of a signature. The Commission can already demand access to a general-purpose model from the company that built it, "through APIs or further appropriate technical means and tools, including source code", to test what the model can be made to do. What is new on Monday is a sentence about the company's side of the visit.

The sentence is Article 2(3) of Commission Implementing Regulation (EU) 2026/1755, the procedural rules the Commission wrote for its own AI investigations — adopted 20 July, published in the *Official Journal*, the EU's legal gazette, on 21 July, in force **Monday 10 August**. In full:

> "The Commission may require the provider to disable any logging measures that could track or record the Commission's access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process."

The provider is the party ordered to disable, so this is not covert access; it knows the inspectors came. What it loses is proof — the ability to establish, against the Commission's own account, what was reached and for how long. No company has been ordered to switch off anything; none can be before Monday. And nobody has said why. EU laws open with recitals, numbered paragraphs stating what the law is for; this one has six, and none mentions logging.

## Keep watching everything, except us

This sentence lands first on the people who run security at the model companies.

The tidy story — the Act orders logs kept, the regulation orders them off — is false, and the error was ours first: the AI Act's logging duties, Articles 12 and 19, bind high-risk AI *systems*, a different chapter; a model provider owes neither. What the provider of a model with systemic risk owes is Article 55(1)(d): an "adequate level of cybersecurity protection" for the model and its physical infrastructure, with non-compliance fined at up to 3% of global turnover or €15 million, whichever is higher.

A company proves that through the General-Purpose AI Code of Practice — the rulebook providers sign to demonstrate compliance, drafted by independent experts and then declared adequate by the Commission itself. The code's security appendix requires intrusion detection "on all networks and devices", a security team to "monitor for EDR alerts" — endpoint-detection software that flags intruders — and a secure registry of every device holding model parameters.

"Any logging measures that could track or record the Commission's access" reaches all of it. The code anticipates substitution: Measure 6.2 requires any replacement control to achieve "detection of suspicious or malicious activity" — and nothing does, on a channel you were ordered not to record. Article 55(2) closes the loop: a provider departing from the code "shall demonstrate alternative adequate means of compliance for assessment by the Commission." The security engineer's position, from Monday: held to a standard the Commission called adequate, orderable by the Commission to break it, and graded by the Commission on whatever is left.

## The case for an invisible inspector

An evaluator whose access is logged can be detected, and a company that can fingerprint the Commission's traffic can route those sessions to a checkpoint with the safety filters on — the Commission then certifies a model nobody else can use. That failure has a name, teaching to the test, and it is the ordinary way third-party evaluation dies.

The AI Act makes it sharper, because compliance is largely self-attested: providers conduct and document their own adversarial testing. If the regulator only sees the company's account of the company's own testing, the systemic-risk regime is self-certification with a signature page.

The strongest argument is the tests themselves. A Commission probe set for offensive cyber or biological uplift consists, by construction, of prompts that work. A provider that logs and analyses those inputs acquires a curated attack corpus at the regulator's expense. Any serious inspection regime needs unannounced access, and a rule protecting an evaluation's integrity is not a scandal.

## The better rule came first

But this exact problem was already solved, in the code the Commission signed off on, the right way. Appendix 3.5 has signatories promise they "will not undermine the integrity of external model evaluations by storing and/or analysing inputs and/or outputs from test runs without express permission from the evaluators."

That bars the provider from keeping the substance of a test — the prompts, the completions, the material you would train against — and it turns on the evaluator's consent. The security log stays on. Monday's sentence governs the access record instead, and has no consent step at all. If the two rules covered the same ground, Monday's sentence would be redundant.

## Seals, not blackouts

No other EU inspector works this way. In competition law the Commission's inspectors may seal records, and breaking a seal is a fine of up to 1% of turnover. In banking supervision the European Central Bank may arrive unannounced — but only by decision, and with judicial authorisation where national law requires. Five regimes were checked. Surprise, in every one, comes from not telling. Not from not recording.

## The watchdog nobody called

Who said yes? EU law has a designated objector: the European Data Protection Supervisor, the Union's in-house privacy watchdog, which the Commission must consult when a draft implementing act touches how "personal data" is processed (Regulation 2018/1725, Article 42(1)). Across its 5,304 words, the new regulation never names the supervisor, never cites that regulation, and never uses the phrase "personal data".

The silence is not the supervisor's habit. On **6 March 2026** it filed formal comments on a different draft under the same AI Act — six days before the 2026/1755 draft opened for public feedback — and a sister regulation adopted on 15 July, five days before this one, records the supervisor's opinion in its recital 5. On this act: nothing in the text, and no comment found anywhere the supervisor publishes its work — a search we did not exhaust. The draft's consultation drew **51 submissions**; we could not retrieve them, so whether anyone flagged the logging sentence is unknown.

## A power sized for one signature

The parent power arrives dressed in safeguards: an access request under Article 92 of the AI Act must state the legal basis, the purpose and reasons, the compliance period, and the applicable fines; in the implementing regulation, access itself is ordered by "decision". The logging requirement has none of that — no decision, no cross-reference, no form. The Commission's Rules of Procedure let "management or administrative measures" be delegated to Directors-General, its senior officials. A decision is a decision; an unlabelled requirement is the kind of thing an official signs.

Article 10(3) of the same regulation lists the acts that interrupt the five-year limitation period for fines, and one of them is "requests for access to conduct model evaluations". Each interruption starts time running afresh, to a ceiling of ten years. The event that resets the clock is the event the provider may be told not to record.

"The Commission" here is not one mind. The code was drafted by independent experts, not by officials; the AI Office — the unit inside DG CNECT, the Commission's digital-policy department — convened them, and the Commission and the AI Board then declared the result adequate. That same AI Office runs the model evaluations and will do the visiting. A Director-General may sign the requirement. No Article 92 access decision has ever surfaced; we looked and found none. Institutional drift is likelier than any single actor's design, and worse in one respect: nobody has to intend it.

## Leave both sides a copy

The Union solved this problem once already, in the harder case. When a record must survive a Commission inspection, competition law trusts neither side: it seals the cabinet and makes breaking the seal an offence in itself. The seal's digital descendant is an append-only log that both sides can verify and neither can edit.

The text leaves a provider two levers. Article 3(5) allows reasoned observations on the experts the Commission appoints — worth using, because under Article 4 the party inside your infrastructure may be a procured contractor. An access decision under Article 2(1) is reviewable under Article 263 TFEU, the treaty route for challenging EU acts in court.

The Commission should look inside these models; that is the point of the Act, and the case for unannounced access is real. What it should not have done is settle a conflict of interest by leaving one party holding the only copy of the record — in a sentence none of its six recitals explains.

---

## References

- **Commission Implementing Regulation (EU) 2026/1755** of 20 July 2026 on detailed arrangements for the
  conduct of certain proceedings by the Commission pursuant to Regulation (EU) 2024/1689, **OJ L, 2026/1755,
  21.7.2026**; CELEX 32026R1755; ELI `http://data.europa.eu/eli/reg_impl/2026/1755/oj`; signed Ursula von der
  Leyen. Relied on: Arts. 2(1)–(4), 3(2), 3(5), 4, 10(3)–(4), 15 and all six recitals. Full ENG text (5,304
  words) retrieved from the Publications Office at
  `http://publications.europa.eu/resource/oj/L_202601755.ENG` with `Accept: application/xhtml+xml`, because
  `Accept: text/html` returns HTTP 404 for this act. Entry into force 2026-08-10 and `in-force = 0` confirmed
  by SPARQL at `publications.europa.eu/webapi/rdf/sparql`, both retrieved 7 August 2026.
- **Regulation (EU) 2024/1689 (AI Act)**, consolidated as at 27 July 2026, CELEX 02024R1689-20260727:
  Arts. 12, 19, 53, 55(1)–(3), 88(1), 91, 92(1)–(4), 101(1). Word-frequency checks run over the full English
  text after normalising U+00A0.
- **General-Purpose AI Code of Practice, Safety and Security Chapter**, European Commission, 43 pp., at
  `https://ec.europa.eu/newsroom/dae/redirection/document/118119`, retrieved 7 August 2026: Commitment 6
  ("LEGAL TEXT: Article 55(1), and recitals 114 and 115 AI Act"), Measure 6.2, Appendix 3.5, Appendix 4.2(1)–(2),
  Appendix 4.3(1), Appendix 4.5(6)–(7). **Correction, 10 August:** an earlier version said DG CNECT drafted this
  code. It did not. The Commission's own page records the code as "prepared by independent experts in a
  multi-stakeholder process", and AI Act Article 56(1) gives the AI Office only the role of "encourage and
  facilitate"; the Commission and the AI Board assessed the finished code as adequate under Article 56(6). The
  argument here rests on that endorsement and on Article 55(2), not on authorship, and has been rewritten to say so.
- **Regulation (EU) 2018/1725**, Art. 42(1)–(3). **Commission Implementing Regulation (EU) 2026/1730** of
  15 July 2026, OJ L, 2026/1730, 22.7.2026, recitals 4 and 5, at
  `http://publications.europa.eu/resource/oj/L_202601730.ENG`.
- **EDPS, Formal comments of 6 March 2026** on the draft Commission Implementing Regulation laying down rules
  for the application of Regulation (EU) 2024/1689 as regards the establishment, development, implementation,
  operation and supervision of AI regulatory sandboxes —
  `https://www.edps.europa.eu/data-protection/our-work/publications/formal-comments/2026-03-06-edps-commission-regulation-regards-operation-and-supervision-ai-regulatory-sandboxes`
  (PDF: `.../system/files/2026-03/06-03-2026_formal_comments_operation_supervision_ai_sandboxes_en.pdf`).
  The EDPS Opinions and Formal Comments indexes were read through `r.jina.ai` because `edps.europa.eu`
  returns HTTP 403 to direct fetches from here; pages covering 30 January – 15 July 2026 were read and contain
  no item on 2026/1755.
- **Commission "Have your say" register**, initiative **16472** ("Implementing regulation Art 92 and 101 AI
  Act" / "Artificial Intelligence Act – detailed arrangements on evaluations and proceedings"),
  Ares(2026)560463, DG CNECT, committee C129100. Draft publication id 22547, Ares(2026)2709234,
  ISC/2026/01203, 12 pages plus a 2-page annex, feedback 12 March 2026 18:24 → 9 April 2026 23:59, status
  CLOSED, **totalFeedback = 51**. Adoption was planned for Q2 2026 (1 April – 30 June); the act was adopted
  20 July. Retrieved from `ec.europa.eu/info/law/better-regulation/brpapi/groupInitiatives/16472?language=EN`
  on 7 August 2026 — note that the `brpapi` endpoints return HTTP 500 or HTTP 400 ("No such language") unless
  `language=EN` is supplied, which is why a previous desk recorded them as unavailable. The individual feedback
  submissions are served only to a browser and were **not** retrieved.
- **Rules of Procedure of the Commission** (C(2000) 3614), OJ L 308, 8.12.2000, Arts. 13 and 14.
- Comparators, each read in the original: **Council Regulation (EC) No 1/2003**, Arts. 20(2)(d), 20(4), 21(3),
  23(1)(e) — text via `http://data.europa.eu/eli/reg/2003/1/oj`, the Cellar XHTML stream for CELEX 32003R0001
  returning 404; **Council Regulation (EU) No 1024/2013** (SSM), Arts. 12(1), 12(3), 12(5), 13;
  **Regulation (EU) 2022/2554** (DORA), Arts. 26(2), 27(1)–(3) — "logs" and "logging" appear zero times in the
  45,231-word English text; **Directive 2001/83/EC**, Art. 111(1); **Commission Implementing Regulation (EU)
  No 628/2013**, Arts. 10, 13(2), 14(1)(a).
- **European AI Office** — `https://digital-strategy.ec.europa.eu/en/policies/ai-office`, retrieved 7 August
  2026: managed by DG CNECT, "more than 125 staff", six units including A2 Regulation and Compliance and A3 AI
  Safety.
- **Not established, reported as gaps:** any EDPS opinion or formal comment on this act (the EDPS site returns
  HTTP 403 to direct fetches from here; its Opinions and Formal Comments indexes were read through
  `r.jina.ai` and show nothing on 2026/1755, but were not exhausted); the identity of the respondents to the draft
  consultation — the count, 51, is on the initiative record, but Have Your Say `brpapi/searchInitiatives`
  returned HTTP 500 today, so who they were is unknown; the date of the
  Artificial Intelligence Committee's opinion (comitology register is JS-only); whether any Article 92 access
  decision or Article 2(3) requirement has ever issued. **Web search was unavailable for this entire session**
  (shared budget exhausted), so no survey of press or civil-society reaction was possible.

## Publication notes

Second edition of 7 August 2026, after "The Hole Is Load-Bearing" (2026-08-07-01).

Selected from a 23-seed slate by group critique (`blog-research/2026-08-07-02/group-critique.md`, composite
9.24 of 10, fifteen candidates developed, eleven complete at the time of the ruling). Published alone; the
board forbade absorbing candidate-04's personhood-header material, candidate-08's procurement story and
candidate-23's encryption-granularity finding by name, each of which is publishable on its own.

Four amendments were made to the winning draft on the board's risk register: a paragraph conceding that the
harm is prospective and no provider has yet been ordered to do anything; an explicit distinction between
Appendix 3.5 (the *content* of a test run, turning on evaluator permission) and Article 2(3) (the *access
record*, with no consent step); a clause acknowledging that "the Commission" is not one actor, since the
independent experts who drafted the code, the AI Office that convened them and now runs evaluations, and the
Director-General who may sign the requirement are three different hands, which makes this institutional drift
rather than any single actor's design; and the removal of a third comparator regime to pay for the additions in
words.

Corrected 10 August: the piece originally said DG CNECT drafted the Code of Practice. It did not — the code was
prepared by independent experts and the Commission's role was facilitation (AI Act Art 56(1)) and adequacy
assessment (Art 56(6)). Four passages leaned on the authorship claim and now rest on endorsement plus Article
55(2) instead, which is what the argument actually needs. Verified against `artificialintelligenceact.eu`
Article 56 and the Commission's own page about the code, both retrieved 10 August 2026.

**Eight of the fifteen desks corrected a premise the desk lead had written into their seed**, and all are
recorded in `candidate-slate.md`. This desk's own framing was wrong twice on this candidate alone: AI Act
Articles 12 and 19 bind high-risk *systems* rather than model providers, and the five comparator regimes
checked all buy surprise by withholding notice rather than by suppressing records — which became the
rebuttal to the piece's strongest steelman. One desk corrected the brief's claim about this desk's own
published record, having grepped every `ARTICLE.md` to prove a framing had only been banked, never
published. Another established that IODA's API answered direct on twelve of twelve calls, correcting a
standing environment note; `NEWBLOG.md` §9 should be softened to try direct first and treat the proxy as a
fallback.

**Rewritten 10 August 2026 under NEWBLOG.md §0.6**, after the desk owner's readability verdict on the
August editions. The structure was rebuilt to lead with the people the sentence lands on — the provider's
security team — rather than with an anatomy of the instrument. The fact set is unchanged; the 3%-of-turnover
fine ceiling, previously stated only in HOT-TAKES.md, now appears in the body. Cut from the body and left to
References: the retrieval-method narrative (EUR-Lex 404, Accept-header workaround, EDPS 403 and text-proxy
reads, SPARQL confirmation, the web-search outage), the register's not-in-force flag, the act's
article-and-annex count, and the Article 53 aside. The standalone steelman, self-correction,
epistemic-limits and reader-levers sections were dissolved into the argument, and every heading was
rewritten so that none is shared with any August 6–8 edition. Headline and hot-take titles are unchanged.

Body length **1,441 words**, measured by `blog-temp/2026-08-07-02/wordcount.py`.

**Correction, 11 August 2026.** This note read "1,401 words" until the body was measured again. The 40-word
growth is the two corrections printed above — moving the argument from DG CNECT having *drafted* the code of
practice to having *endorsed* it under Art 55(2), and replacing the misdescription of FAR 6.305 with the
subsection that actually forbids redaction delaying posting, 6.305(e). Both corrections added words, and this
note was not re-run against the file. A measurement recorded once and never re-run is not a measurement.
