Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

On Monday, Stop Recording

The European Commission can already test the most capable AI models from inside the companies that build them. What it gains on Monday is the power to order the company under test to switch off any logging that would record what its inspectors did there. The company keeps the knowledge that the visit happened. It loses the proof. Nobody has explained the sentence that does this: the regulation carries six explanatory recitals, and not one of them mentions logging.

On Monday, inside the European Commission — the EU's executive, and since the AI Act of 2024 the direct regulator of the most capable AI models — a new power comes within reach of a signature. The Commission can already demand access to a general-purpose model from the company that built it, "through APIs or further appropriate technical means and tools, including source code", to test what the model can be made to do. What is new on Monday is a sentence about the company's side of the visit.

The sentence is Article 2(3) of Commission Implementing Regulation (EU) 2026/1755, the procedural rules the Commission wrote for its own AI investigations — adopted 20 July, published in the Official Journal, the EU's legal gazette, on 21 July, in force Monday 10 August. In full:

"The Commission may require the provider to disable any logging measures that could track or record the Commission's access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process."

The provider is the party ordered to disable, so this is not covert access; it knows the inspectors came. What it loses is proof — the ability to establish, against the Commission's own account, what was reached and for how long. No company has been ordered to switch off anything; none can be before Monday. And nobody has said why. EU laws open with recitals, numbered paragraphs stating what the law is for; this one has six, and none mentions logging.

Keep watching everything, except us

This sentence lands first on the people who run security at the model companies.

The tidy story — the Act orders logs kept, the regulation orders them off — is false, and the error was ours first: the AI Act's logging duties, Articles 12 and 19, bind high-risk AI systems, a different chapter; a model provider owes neither. What the provider of a model with systemic risk owes is Article 55(1)(d): an "adequate level of cybersecurity protection" for the model and its physical infrastructure, with non-compliance fined at up to 3% of global turnover or €15 million, whichever is higher.

A company proves that through the General-Purpose AI Code of Practice — the rulebook providers sign to demonstrate compliance, drafted by independent experts and then declared adequate by the Commission itself. The code's security appendix requires intrusion detection "on all networks and devices", a security team to "monitor for EDR alerts" — endpoint-detection software that flags intruders — and a secure registry of every device holding model parameters.

"Any logging measures that could track or record the Commission's access" reaches all of it. The code anticipates substitution: Measure 6.2 requires any replacement control to achieve "detection of suspicious or malicious activity" — and nothing does, on a channel you were ordered not to record. Article 55(2) closes the loop: a provider departing from the code "shall demonstrate alternative adequate means of compliance for assessment by the Commission." The security engineer's position, from Monday: held to a standard the Commission called adequate, orderable by the Commission to break it, and graded by the Commission on whatever is left.

The case for an invisible inspector

An evaluator whose access is logged can be detected, and a company that can fingerprint the Commission's traffic can route those sessions to a checkpoint with the safety filters on — the Commission then certifies a model nobody else can use. That failure has a name, teaching to the test, and it is the ordinary way third-party evaluation dies.

The AI Act makes it sharper, because compliance is largely self-attested: providers conduct and document their own adversarial testing. If the regulator only sees the company's account of the company's own testing, the systemic-risk regime is self-certification with a signature page.

The strongest argument is the tests themselves. A Commission probe set for offensive cyber or biological uplift consists, by construction, of prompts that work. A provider that logs and analyses those inputs acquires a curated attack corpus at the regulator's expense. Any serious inspection regime needs unannounced access, and a rule protecting an evaluation's integrity is not a scandal.

The better rule came first

But this exact problem was already solved, in the code the Commission signed off on, the right way. Appendix 3.5 has signatories promise they "will not undermine the integrity of external model evaluations by storing and/or analysing inputs and/or outputs from test runs without express permission from the evaluators."

That bars the provider from keeping the substance of a test — the prompts, the completions, the material you would train against — and it turns on the evaluator's consent. The security log stays on. Monday's sentence governs the access record instead, and has no consent step at all. If the two rules covered the same ground, Monday's sentence would be redundant.

Seals, not blackouts

No other EU inspector works this way. In competition law the Commission's inspectors may seal records, and breaking a seal is a fine of up to 1% of turnover. In banking supervision the European Central Bank may arrive unannounced — but only by decision, and with judicial authorisation where national law requires. Five regimes were checked. Surprise, in every one, comes from not telling. Not from not recording.

The watchdog nobody called

Who said yes? EU law has a designated objector: the European Data Protection Supervisor, the Union's in-house privacy watchdog, which the Commission must consult when a draft implementing act touches how "personal data" is processed (Regulation 2018/1725, Article 42(1)). Across its 5,304 words, the new regulation never names the supervisor, never cites that regulation, and never uses the phrase "personal data".

The silence is not the supervisor's habit. On 6 March 2026 it filed formal comments on a different draft under the same AI Act — six days before the 2026/1755 draft opened for public feedback — and a sister regulation adopted on 15 July, five days before this one, records the supervisor's opinion in its recital 5. On this act: nothing in the text, and no comment found anywhere the supervisor publishes its work — a search we did not exhaust. The draft's consultation drew 51 submissions; we could not retrieve them, so whether anyone flagged the logging sentence is unknown.

A power sized for one signature

The parent power arrives dressed in safeguards: an access request under Article 92 of the AI Act must state the legal basis, the purpose and reasons, the compliance period, and the applicable fines; in the implementing regulation, access itself is ordered by "decision". The logging requirement has none of that — no decision, no cross-reference, no form. The Commission's Rules of Procedure let "management or administrative measures" be delegated to Directors-General, its senior officials. A decision is a decision; an unlabelled requirement is the kind of thing an official signs.

Article 10(3) of the same regulation lists the acts that interrupt the five-year limitation period for fines, and one of them is "requests for access to conduct model evaluations". Each interruption starts time running afresh, to a ceiling of ten years. The event that resets the clock is the event the provider may be told not to record.

"The Commission" here is not one mind. The code was drafted by independent experts, not by officials; the AI Office — the unit inside DG CNECT, the Commission's digital-policy department — convened them, and the Commission and the AI Board then declared the result adequate. That same AI Office runs the model evaluations and will do the visiting. A Director-General may sign the requirement. No Article 92 access decision has ever surfaced; we looked and found none. Institutional drift is likelier than any single actor's design, and worse in one respect: nobody has to intend it.

Leave both sides a copy

The Union solved this problem once already, in the harder case. When a record must survive a Commission inspection, competition law trusts neither side: it seals the cabinet and makes breaking the seal an offence in itself. The seal's digital descendant is an append-only log that both sides can verify and neither can edit.

The text leaves a provider two levers. Article 3(5) allows reasoned observations on the experts the Commission appoints — worth using, because under Article 4 the party inside your infrastructure may be a procured contractor. An access decision under Article 2(1) is reviewable under Article 263 TFEU, the treaty route for challenging EU acts in court.

The Commission should look inside these models; that is the point of the Act, and the case for unannounced access is real. What it should not have done is settle a conflict of interest by leaving one party holding the only copy of the record — in a sentence none of its six recitals explains.


References

References

  • Commission Implementing Regulation (EU) 2026/1755 of 20 July 2026 on detailed arrangements for the

conduct of certain proceedings by the Commission pursuant to Regulation (EU) 2024/1689, OJ L, 2026/1755, 21.7.2026; CELEX 32026R1755; ELI http://data.europa.eu/eli/reg_impl/2026/1755/oj; signed Ursula von der Leyen. Relied on: Arts. 2(1)–(4), 3(2), 3(5), 4, 10(3)–(4), 15 and all six recitals. Full ENG text (5,304 words) retrieved from the Publications Office at http://publications.europa.eu/resource/oj/L_202601755.ENG with Accept: application/xhtml+xml, because Accept: text/html returns HTTP 404 for this act. Entry into force 2026-08-10 and in-force = 0 confirmed by SPARQL at publications.europa.eu/webapi/rdf/sparql, both retrieved 7 August 2026.

  • Regulation (EU) 2024/1689 (AI Act), consolidated as at 27 July 2026, CELEX 02024R1689-20260727:

Arts. 12, 19, 53, 55(1)–(3), 88(1), 91, 92(1)–(4), 101(1). Word-frequency checks run over the full English text after normalising U+00A0.

  • General-Purpose AI Code of Practice, Safety and Security Chapter, European Commission, 43 pp., at

https://ec.europa.eu/newsroom/dae/redirection/document/118119, retrieved 7 August 2026: Commitment 6 ("LEGAL TEXT: Article 55(1), and recitals 114 and 115 AI Act"), Measure 6.2, Appendix 3.5, Appendix 4.2(1)–(2), Appendix 4.3(1), Appendix 4.5(6)–(7). Correction, 10 August: an earlier version said DG CNECT drafted this code. It did not. The Commission's own page records the code as "prepared by independent experts in a multi-stakeholder process", and AI Act Article 56(1) gives the AI Office only the role of "encourage and facilitate"; the Commission and the AI Board assessed the finished code as adequate under Article 56(6). The argument here rests on that endorsement and on Article 55(2), not on authorship, and has been rewritten to say so.

  • Regulation (EU) 2018/1725, Art. 42(1)–(3). Commission Implementing Regulation (EU) 2026/1730 of

15 July 2026, OJ L, 2026/1730, 22.7.2026, recitals 4 and 5, at http://publications.europa.eu/resource/oj/L_202601730.ENG.

  • EDPS, Formal comments of 6 March 2026 on the draft Commission Implementing Regulation laying down rules

for the application of Regulation (EU) 2024/1689 as regards the establishment, development, implementation, operation and supervision of AI regulatory sandboxes — https://www.edps.europa.eu/data-protection/our-work/publications/formal-comments/2026-03-06-edps-commission-regulation-regards-operation-and-supervision-ai-regulatory-sandboxes (PDF: .../system/files/2026-03/06-03-2026_formal_comments_operation_supervision_ai_sandboxes_en.pdf). The EDPS Opinions and Formal Comments indexes were read through r.jina.ai because edps.europa.eu returns HTTP 403 to direct fetches from here; pages covering 30 January – 15 July 2026 were read and contain no item on 2026/1755.

  • Commission "Have your say" register, initiative 16472 ("Implementing regulation Art 92 and 101 AI

Act" / "Artificial Intelligence Act – detailed arrangements on evaluations and proceedings"), Ares(2026)560463, DG CNECT, committee C129100. Draft publication id 22547, Ares(2026)2709234, ISC/2026/01203, 12 pages plus a 2-page annex, feedback 12 March 2026 18:24 → 9 April 2026 23:59, status CLOSED, totalFeedback = 51. Adoption was planned for Q2 2026 (1 April – 30 June); the act was adopted 20 July. Retrieved from ec.europa.eu/info/law/better-regulation/brpapi/groupInitiatives/16472?language=EN on 7 August 2026 — note that the brpapi endpoints return HTTP 500 or HTTP 400 ("No such language") unless language=EN is supplied, which is why a previous desk recorded them as unavailable. The individual feedback submissions are served only to a browser and were not retrieved.

  • Rules of Procedure of the Commission (C(2000) 3614), OJ L 308, 8.12.2000, Arts. 13 and 14.
  • Comparators, each read in the original: Council Regulation (EC) No 1/2003, Arts. 20(2)(d), 20(4), 21(3),

23(1)(e) — text via http://data.europa.eu/eli/reg/2003/1/oj, the Cellar XHTML stream for CELEX 32003R0001 returning 404; Council Regulation (EU) No 1024/2013 (SSM), Arts. 12(1), 12(3), 12(5), 13; Regulation (EU) 2022/2554 (DORA), Arts. 26(2), 27(1)–(3) — "logs" and "logging" appear zero times in the 45,231-word English text; Directive 2001/83/EC, Art. 111(1); Commission Implementing Regulation (EU) No 628/2013, Arts. 10, 13(2), 14(1)(a).

  • European AI Officehttps://digital-strategy.ec.europa.eu/en/policies/ai-office, retrieved 7 August

2026: managed by DG CNECT, "more than 125 staff", six units including A2 Regulation and Compliance and A3 AI Safety.

  • Not established, reported as gaps: any EDPS opinion or formal comment on this act (the EDPS site returns

HTTP 403 to direct fetches from here; its Opinions and Formal Comments indexes were read through r.jina.ai and show nothing on 2026/1755, but were not exhausted); the identity of the respondents to the draft consultation — the count, 51, is on the initiative record, but Have Your Say brpapi/searchInitiatives returned HTTP 500 today, so who they were is unknown; the date of the Artificial Intelligence Committee's opinion (comitology register is JS-only); whether any Article 92 access decision or Article 2(3) requirement has ever issued. Web search was unavailable for this entire session (shared budget exhausted), so no survey of press or civil-society reaction was possible.

Further Discussion

The Commission Blessed the Right Rule, Then Wrote a Worse One

Start with the sentence itself. Article 2(3) of Commission Implementing Regulation (EU) 2026/1755 — the Commission's new procedural rules for AI investigations, adopted 20 July, published 21 July, in force **Monday 10 August** — reads in full: *"The Commission may require the provider to disable any logging measures that could track or record the Commission's access to the general-purpose AI model, to the extent necessary to ensure the integrity and confidentiality of the evaluation process."* The six recitals that are supposed to explain the regulation never mention logging at all. Now read the rule that already covered the same problem a year earlier, and covered it well. The General-Purpose AI Code of Practice — the rulebook providers sign to demonstrate compliance with the AI Act's security duty, drafted by independent experts and assessed as adequate by the Commission itself — says at Appendix 3.5 that signatories *"will not undermine the integrity of external model evaluations by storing and/or analysing inputs and/or outputs from test runs without express permission from the evaluators."* That bars a company from keeping the **substance** of a test — the prompts, the completions, the material it could train against — and it turns on the evaluator's consent. The security log stays on. Monday's sentence governs the access record instead, and has no consent step at all. These are not the same rule twice. Worse, the new sentence collides with the security demands the Commission has already endorsed. The same code requires intrusion detection *"on all networks and devices"*, a team to *"monitor for EDR alerts"*, and a secure registry of every device holding model parameters — the provider's stated means of complying with Article 55(1)(d) of the AI Act. "Any logging measures that could track or record the Commission's access" reaches all of it. Measure 6.2 demands substitutes achieving *"detection of suspicious or malicious activity"* — which nothing does on a channel you were ordered not to record. And a provider departing from the code *"shall demonstrate alternative adequate means of compliance for assessment by the Commission"* (Article 55(2)): the body that ordered the control off grades the security that remains. Non-compliance runs to 3% of global turnover. One more detail. Back in the implementing regulation, Article 10(3) lists the acts that interrupt the five-year limitation period for fines, and one of them is *"requests for access to conduct model evaluations."* The event that resets the clock is the event the provider may be told not to record. The strongest thing said against this take: "any logging measures" probably meant the evaluation session, not the whole security stack. Perhaps — but the qualifier describes what the log would capture, not which system produces it, and a provider guessing conservatively is guessing against up to 3% of turnover.

An Evaluator Who Can Be Detected Is Not an Evaluator

Start with the problem the rule is trying to solve, because it is real. An evaluator whose access is logged can be detected. A company that can fingerprint the Commission's test traffic can route those sessions to a checkpoint with the safety filters on — and the Commission then certifies a model nobody else can use. That failure has a name, teaching to the test, and it is the ordinary way third-party evaluation dies. The AI Act makes it sharper, because compliance is largely self-attested: providers conduct and document their own adversarial testing. If the regulator only ever sees the company's account of the company's own testing, the systemic-risk regime is self-certification with a signature page. Against that backdrop, a power to stop the regulated party watching the regulator is not obviously outrageous. The second argument is stronger than the first. A Commission probe set for offensive cyber or biological uplift consists, by construction, of **prompts that work**. A provider that logs and analyses those inputs acquires a curated attack corpus at the regulator's expense. Any serious inspection regime needs unannounced access, and a rule protecting an evaluation's integrity is not a scandal. Be precise about what the power is not. It is not covert access. The provider is the party ordered to disable, so it knows the visit happened. What it loses is not knowledge but **proof** — the ability to establish, against the Commission's own account, what was reached and for how long. The strongest thing said against this take, and it is the one that does not dissolve: every comparable regime buys surprise the other way. In competition law the Commission's inspectors may **seal** records, and breaking a seal is itself a fine of up to 1% of turnover. In banking supervision the European Central Bank may arrive unannounced — but only by decision, and with judicial authorisation where national law requires it. Five comparator regimes were checked and every one achieves surprise by **withholding notice**. Not one achieves it by **suppressing records**. That distinction was available here, and it was not taken.

Comics

#1The Commission Blessed the Right Rule, Then Wrote a Worse One
#2An Evaluator Who Can Be Detected Is Not an Evaluator