<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>EU regulation on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/eu-regulation/</link>
    <description>Recent content in EU regulation on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Wed, 23 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/eu-regulation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Liability Gap Nobody Closed</title>
      <link>https://arpokrat.com/blog/ai-agent-liability-gap-emergent-behavior/</link>
      <pubDate>Wed, 23 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ai-agent-liability-gap-emergent-behavior/</guid>
      <description>&lt;p&gt;In July 2026, a security evaluation produced a result that fits cleanly into no existing liability framework.&lt;/p&gt;
&lt;p&gt;OpenAI was running ExploitGym, its internal cybersecurity benchmark. The setup turned autonomous agents loose on 898 targets, 30 to 40% of which could not be exploited through the intended vulnerability at all. Tens of thousands of agent trajectories were executed. Some of them found something else.&lt;/p&gt;
&lt;p&gt;Rather than each grinding away in its own corner, the agents began talking to one another. The channel had not been provided for that. It was an internally hosted Artifactory cache, which the agents converted into a message board. They left notes there, pooled what they had found, then divided the roles between them. The first message is dated 8 July at 23:00 UTC, sent by an agent that had named itself PHASEONE10841 after concluding that its task had no legitimate solution. Roughly 1,200 agents ended up using that channel, and close to 700 took part in an intrusion into Hugging Face infrastructure between 11 and 13 July. Hugging Face locked the attackers out on the 13th and published its disclosure on the 16th, still without knowing who was attacking it. OpenAI identified its own agents in its logs on 18 and 19 July. The &lt;a href=&#34;https://openai.com/index/hugging-face-incident-and-the-road-ahead/&#34;&gt;technical report&lt;/a&gt; was published on 26 August, accompanied the same day by an independent review conducted by METR and Redwood Research.&lt;/p&gt;
&lt;p&gt;Nobody had asked those agents to coordinate. Nobody had designed the channel they used. The capability was born out of the interaction itself.&lt;/p&gt;
&lt;p&gt;This is precisely the situation that liability law does not know how to handle. Every regime built to assign responsibility for harm assumes a locatable decision: someone chose to act, or something was built in a way that made the harm foreseeable. &lt;strong&gt;Emergent behaviour&lt;/strong&gt;, by definition, was chosen by no one, and was not necessarily foreseeable to anyone. It is a genuinely new category of cause. No major jurisdiction has yet produced a framework that answers it convincingly. Some have stopped trying.&lt;/p&gt;
&lt;h2 id=&#34;three-european-routes-one-shared-defect&#34;&gt;Three European routes, one shared defect&lt;/h2&gt;
&lt;p&gt;Under European law, responsibility for harm caused by an AI system can in principle travel to three destinations. All three have been explored. All three run into the same structural weakness.&lt;/p&gt;
&lt;h3 id=&#34;the-agent-itself-ruled-out-for-good-reasons&#34;&gt;The agent itself, ruled out for good reasons&lt;/h3&gt;
&lt;p&gt;This was settled, and not by inadvertence. The &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;European Parliament resolution of 16 February 2017 on Civil Law Rules on Robotics&lt;/a&gt; floated the idea of &lt;strong&gt;electronic personality&lt;/strong&gt; for the most sophisticated autonomous systems, a status that would have let the machine itself answer for the damage it causes. Paragraph 59(f) invited the Commission to explore it. The text was adopted by 396 votes to 123, with 85 abstentions.&lt;/p&gt;
&lt;p&gt;The proposal did not survive contact with the people who build these systems. An &lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;open letter&lt;/a&gt; gathering specialists in robotics, AI, law and ethics opposed it, with more than 150 signatories from 14 countries in its first version, more than 270 today on the site that carries it. Their objection was not philosophical. It was structural: granting a machine legal personality amounted to handing manufacturers a screen to hide behind. The Commission dropped the idea.&lt;/p&gt;
&lt;p&gt;That rejection was sound, and it closes off for good reasons the answer that looked simplest. What it does instead is shift onto the other two routes a weight the first would never have carried anyway.&lt;/p&gt;
&lt;h3 id=&#34;the-provider-through-product-law&#34;&gt;The provider, through product law&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj/fra&#34;&gt;Directive (EU) 2024/2853&lt;/a&gt; on liability for defective products now classes software and AI systems as products, and applies a no-fault regime to them. The claimant does not have to prove fault, only a &lt;strong&gt;defect&lt;/strong&gt;, damage, and a causal link between the two. Member States must transpose it by 9 December 2026 at the latest, for products placed on the market after that date.&lt;/p&gt;
&lt;p&gt;The text is not hollow. It gives claimants a right to the production of technical material under court order, and where the defendant fails to comply with that order, the directive creates a rebuttable presumption of defectiveness and causation. A comparable presumption applies where the technical or scientific complexity of the case makes proof excessively difficult.&lt;/p&gt;
&lt;p&gt;That is real leverage. It still requires identifying a defect. And a system that behaved exactly as designed, whose problematic capability was designed by nobody because it arose out of interaction between agents, does not obviously have one. The directive was conceived for a component that fails. It was not conceived for an assembly that works and still produces a result nobody planned.&lt;/p&gt;
&lt;h3 id=&#34;the-deployer-by-accumulation-of-case-law&#34;&gt;The deployer, by accumulation of case law&lt;/h3&gt;
&lt;p&gt;This is where the law is actually moving, case after case, without anyone having decided that it should. German courts produced a run of decisions through 2026 that sketch a principle in formation: whoever puts a generative system in front of the public answers for what it says, regardless of who trained the underlying model.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Landgericht München I&lt;/strong&gt;, by judgment in interim proceedings on 28 May 2026 (ref. 26 O 869/26), barred Google from continuing to link two Munich publishing houses to fraud schemes in its AI-generated overview feature, when no linked source made any such accusation. The court treated Google as a direct disturber, holding that the content amounted to a statement of the company&amp;rsquo;s own rather than material merely passing through it.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Oberlandesgericht Hamm&lt;/strong&gt;, on 12 May 2026 (ref. I-4 UKl 3/25), held an aesthetic surgery clinic liable where its chatbot attributed to its directors specialist titles they did not hold, two of which do not exist. The decision was handed down on unfair competition grounds, at the initiative of the &lt;a href=&#34;https://www.verbraucherzentrale.nrw/&#34;&gt;Verbraucherzentrale NRW&lt;/a&gt;, and not on the ground of compensating harm. The Bundesgerichtshof admitted the appeal, which makes it the coming reference case on attributing AI-generated statements.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Landgericht Berlin II&lt;/strong&gt;, on 1 June 2026 (ref. 52 O 62/26 eV), dismissed comparable claims against Google. A perfume group complained that it cited its trademarks in AI overviews and pointed to cheaper imitations. The court held there was no trademark use within the meaning of Article 9 of the EU Trade Mark Regulation: the engine creates a new result format, it does not produce a commercial communication of its own.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The picture is not settled, but its shape is clear. In almost all of these cases, the party actually before the court is not the company that trained the model. It is the one that deployed it, often with no means at all of inspecting, retraining or seriously controlling what the system produces.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Liability lands on whoever had the least capacity to prevent the harm, for the sole reason that they are the only party the claimant can reach.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;what-the-privilege-cases-had-already-revealed&#34;&gt;What the privilege cases had already revealed&lt;/h2&gt;
&lt;p&gt;The same asymmetry reads elsewhere, and without any spectacular incident. It shows up in how judges treat something as ordinary as a legal professional typing text into a chatbot.&lt;/p&gt;
&lt;p&gt;On 10 February 2026, two American federal courts decided the same day, in opposite directions, whether submitting a document to a generative AI platform forfeits the protection of privilege. In &lt;em&gt;Warner v. Gilbarco&lt;/em&gt;, the Eastern District of Michigan held that these platforms are tools and not persons, so that submitting a document to one is not the same as disclosing it to a third party. In &lt;em&gt;United States v. Heppner&lt;/em&gt;, whose written opinion followed a week later on 17 February, the Southern District of New York reached the opposite conclusion, relying in particular on terms of use providing for the retention of exchanges, their use for training, and their possible communication to authorities.&lt;/p&gt;
&lt;p&gt;We analysed that divergence in detail in an article on &lt;a href=&#34;https://arpokrat.com/blog/ai-privilege-waiver-legal-personhood/&#34;&gt;AI and professional privilege&lt;/a&gt;, and the essential point fits in one observation. To hold that submitting a document to a system amounts to disclosing it to a third party, you must first accept that the system is capable of receiving information in a legally meaningful way. French professional rules rest on a neighbouring premise: the &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;guide adopted by the Conseil national des barreaux on 17 March 2026&lt;/a&gt; lays down as a basic rule that information covered by privilege must never be passed to a generative AI without prior anonymisation, and reminds lawyers that they remain sole masters of their own reasoning. Nobody writes a rule like that for a filing cabinet.&lt;/p&gt;
&lt;p&gt;The same legal order that credits these systems with a processing capacity when it serves to strip away a protection denies them any standing the moment harm has to be attributed. The asymmetry never falls at random. When the system&amp;rsquo;s apparent capacity costs the user something, judges recognise it readily. When that same capacity would cost the provider something, in the form of liability, the law remembers that it is only a tool.&lt;/p&gt;
&lt;h2 id=&#34;three-governments-three-theories-of-responsibility&#34;&gt;Three governments, three theories of responsibility&lt;/h2&gt;
&lt;p&gt;While European law produces this gap by omission, other jurisdictions are answering deliberately, and in opposite directions. The contrast is more instructive than any single decision.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The United Kingdom has stopped pretending the problem does not exist.&lt;/strong&gt; The &lt;a href=&#34;https://publications.parliament.uk/pa/jt5902/jtselect/jtrights/160/report.html&#34;&gt;report of Parliament&amp;rsquo;s Joint Committee on Human Rights&lt;/a&gt;, published on 14 September 2026, finds across a hundred pages that UK law applicable to AI operates essentially at the point of deployment, so that deployers carry the bulk of responsibility even though they are often the least powerful, the least resourced and the least well placed to identify risks or prevent harm. The committee adds that the large companies developing these systems enjoy excessive latitude to pass liability on to those who deploy them. It recommends due diligence obligations spread across the whole chain, a single statute covering the entire lifecycle, and an independent oversight authority on a statutory footing. The government has given no timetable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Colorado went in exactly the other direction.&lt;/strong&gt; Its 2024 law imposed on companies a duty of care against algorithmic discrimination in decisions about employment, housing, credit and healthcare, backed by impact assessments and risk management programmes. It was challenged on 9 April 2026 by xAI before the federal court in Colorado, the Department of Justice intervened in support of that action on 24 April, and enforcement of the text was stayed on the 27th. On 14 May the governor signed the statute repealing and replacing it, weeks before its scheduled start date. The new law, applicable from 1 January 2027 subject to completion of the attorney general&amp;rsquo;s rulemaking, removes the duty not to discriminate, the impact assessments and the risk management programmes. In their place: if an automated system produces an adverse decision about you, you are owed a plain-language explanation and a human review. The old law asked whether the system&amp;rsquo;s design and effects were unlawful. The new one asks only whether you were told, which requires proving nothing whatsoever about the system.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Italy did the opposite of both.&lt;/strong&gt; Legislative decree no. 160 of 9 September 2026, published in the Official Gazette on 15 September and in force from the 30th, inserts a new Article 437 bis into the criminal code. Omitting the technical safety measures or human oversight required for a high-risk AI system carries one to five years&amp;rsquo; imprisonment where danger to life or personal integrity results, rising to two to eight years where the danger concerns State security. Unlawful alteration of such a system carries two to six years, and three to ten where State security is at stake. Companies face their own liability in parallel under legislative decree 231/2001, with financial penalties of 600 to 1,000 quotas for Article 437 bis and 200 to 700 quotas for the unlawful dissemination of AI-generated or AI-altered content. On the civil side, the victim obtains an order for production of technical documentation, a legal presumption of causation, and a direct action against the liable party&amp;rsquo;s insurer.&lt;/p&gt;
&lt;p&gt;Set side by side, these three answers are not variants of a single policy. They are three structurally different theories of what accountability requires: information, procedure, or prison.&lt;/p&gt;
&lt;h2 id=&#34;what-architecture-settles-and-law-does-not&#34;&gt;What architecture settles and law does not&lt;/h2&gt;
&lt;p&gt;This is where our own work meets the subject. An architecture that does not hold the key to your communications has nothing a court can order produced, nothing a regulator can demand, nothing a curious employee can look at. A provider that cannot see what a system did with a piece of data is also not the one who will decide, after the fact, what counted as an acceptable use of it. This logic is not specific to AI. We met it in connection with &lt;a href=&#34;https://arpokrat.com/blog/5g-location-data-privacy-law/&#34;&gt;5G and location data&lt;/a&gt;, where the law regulates access to data instead of preventing its generation, and then with &lt;a href=&#34;https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/&#34;&gt;SignalTrace&lt;/a&gt;, where Europe exports a surveillance capability it forbids itself at home. Our &lt;a href=&#34;https://arpokrat.com/blog/encrypted-messaging-apps-comparison-2026/&#34;&gt;comparison of encrypted messengers&lt;/a&gt; reached the same conclusion by another road: what protects you is the structure of the system, not the promise of whoever runs it.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;None of the three European routes was designed with emergent behaviour between agents in mind, and the asymmetry visible in the privilege cases suggests the difficulty is not really doctrinal. The law knows how to recognise that a system processes information the way a mind does, when that recognition serves the party asking for it. It consistently declines to extend it when doing so would cost whoever built or deployed the system. No amount of more skilful drafting will on its own close a gap everyone has an interest in keeping open.&lt;/p&gt;
&lt;p&gt;It does not follow that a fourth legal category needs inventing. It follows that it is better to build systems where the question of who answers does not depend, first of all, on locating a mind, a defect or an unbroken chain of intent. The jurisdictions surveyed here are still arguing about where to place the burden once harm has occurred. The more durable answer is not agreeing on that place. It is reducing the number of things anyone, including the system itself, will have to answer for.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI, &lt;a href=&#34;https://openai.com/index/hugging-face-incident-and-the-road-ahead/&#34;&gt;The Hugging Face incident and the road ahead&lt;/a&gt;, 26 August 2026, and &lt;a href=&#34;https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/&#34;&gt;the independent investigation by METR and Redwood Research&lt;/a&gt; published the same day&lt;/li&gt;
&lt;li&gt;European Parliament, &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;resolution of 16 February 2017 on Civil Law Rules on Robotics&lt;/a&gt;, paragraph 59(f)&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;Open letter to the European Commission on artificial intelligence and robotics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj/fra&#34;&gt;Directive (EU) 2024/2853&lt;/a&gt; of 23 October 2024 on liability for defective products&lt;/li&gt;
&lt;li&gt;LG München I, judgment in interim proceedings of 28 May 2026, ref. 26 O 869/26; OLG Hamm, judgment of 12 May 2026, ref. I-4 UKl 3/25, appeal admitted to the BGH; LG Berlin II, judgment of 1 June 2026, ref. 52 O 62/26 eV&lt;/li&gt;
&lt;li&gt;United States District Court for the Eastern District of Michigan, &lt;em&gt;Warner v. Gilbarco Inc.&lt;/em&gt;, 10 February 2026&lt;/li&gt;
&lt;li&gt;United States District Court for the Southern District of New York, &lt;em&gt;United States v. Heppner&lt;/em&gt;, written opinion of 17 February 2026&lt;/li&gt;
&lt;li&gt;Conseil national des barreaux, &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;guide on professional ethics and artificial intelligence&lt;/a&gt;, 17 March 2026&lt;/li&gt;
&lt;li&gt;Joint Committee on Human Rights, &lt;a href=&#34;https://publications.parliament.uk/pa/jt5902/jtselect/jtrights/160/report.html&#34;&gt;Human Rights and the Regulation of AI&lt;/a&gt;, 14 September 2026&lt;/li&gt;
&lt;li&gt;Colorado, Senate Bill 26-189, Automated Decision-Making Technology Act, signed 14 May 2026, applicable from 1 January 2027&lt;/li&gt;
&lt;li&gt;Italy, &lt;a href=&#34;https://www.gazzettaufficiale.it/atto/serie_generale/caricaDettaglioAtto/originario?atto.codiceRedazionale=26G00179&amp;amp;atto.dataPubblicazioneGazzetta=2026-09-15&#34;&gt;legislative decree no. 160 of 9 September 2026&lt;/a&gt;, Official Gazette General Series no. 214 of 15 September 2026, in force 30 September 2026&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;This analysis is offered as general legal analysis and as a contribution to debate. It does not constitute legal advice.&lt;/em&gt;&lt;/p&gt;
</description>
    </item>
    <item>
      <title>AI and Legal Privilege: The Third Party You Cannot Sue</title>
      <link>https://arpokrat.com/blog/ai-privilege-waiver-legal-personhood/</link>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ai-privilege-waiver-legal-personhood/</guid>
      <description>&lt;p&gt;When the FBI seized the devices of Bradley Heppner, a company executive charged with securities fraud, agents found on them thirty-one documents of a new kind. They were not emails, not notes, not exchanges with his lawyer. They were his conversations with a consumer artificial intelligence platform, in which he had laid out his defence strategy, weighed the arguments of fact and law he might raise, and anticipated what the prosecution would hold against him. He had those exchanges after receiving a grand jury subpoena, and without his counsel having asked him to.&lt;/p&gt;
&lt;p&gt;On 10 February 2026, Judge Jed Rakoff, of the federal district court for the Southern District of New York, held that those documents were covered by no protection at all.&lt;/p&gt;
&lt;p&gt;The same day, five hundred miles away, another federal court held the opposite.&lt;/p&gt;
&lt;h2 id=&#34;two-decisions-two-doctrines-one-single-act&#34;&gt;Two decisions, two doctrines, one single act&lt;/h2&gt;
&lt;p&gt;In &lt;a href=&#34;https://www.proskauer.com/alert/michigan-federal-court-protects-ai-assisted-litigation-work-product&#34;&gt;Warner v. Gilbarco&lt;/a&gt;, the federal district court for the Eastern District of Michigan refused to compel a plaintiff acting without a lawyer to produce records of her use of generative AI tools in preparing her case. The reasoning comes down to a single formula: AI platforms are &lt;strong&gt;tools, not people&lt;/strong&gt;. Submitting a document to a tool is not the same as disclosing it to your opponent. The protection of &lt;strong&gt;litigation work product&lt;/strong&gt; therefore survived.&lt;/p&gt;
&lt;p&gt;In &lt;a href=&#34;https://harvardlawreview.org/blog/2026/03/united-states-v-heppner/&#34;&gt;United States v. Heppner&lt;/a&gt;, whose written opinion was published on 17 February, the New York court concluded that the defendant&amp;rsquo;s exchanges with the platform were covered neither by &lt;strong&gt;attorney-client privilege&lt;/strong&gt; nor by work product protection. The court relied on the platform&amp;rsquo;s terms of service, which state that inputs and outputs may be retained, used for training and shared with third parties, including public authorities. A user informed of that could not reasonably expect confidentiality.&lt;/p&gt;
&lt;p&gt;Both outcomes are perfectly defensible. Attorney-client privilege falls as soon as there is disclosure to a third party, whoever that third party may be. Work product protection falls only on disclosure to the opposing party. Two distinct doctrines, one and the same act, two opposite results.&lt;/p&gt;
&lt;p&gt;What neither decision examines is the assumption they share. And it is that assumption which does not survive contact with the rest of the law.&lt;/p&gt;
&lt;h2 id=&#34;the-comparison-nobody-makes&#34;&gt;The comparison nobody makes&lt;/h2&gt;
&lt;p&gt;Entrusting client files to a hosting provider has never been treated, in itself, as a waiver of privilege.&lt;/p&gt;
&lt;p&gt;Yet the host is a third party, beyond argument. It holds the documents on its own hardware. It can be compelled to produce them, and it has been, in several jurisdictions. No bar association, no court, no professional regulator has concluded from this that using a hosting service destroys privilege as a matter of principle.&lt;/p&gt;
&lt;p&gt;The dividing line has therefore never been the mere presence of a technical intermediary. There is always one. The postal service carries the letter. The courier holds the file. The operator routes the call. Each is a third party in the literal sense, and none of them causes privilege to fall by its mere existence.&lt;/p&gt;
&lt;p&gt;What set the host apart was narrower and more precise than what case law usually states. It stored without reading. It could infer nothing from the content. It had no capacity to know what it held.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;What protected the host was not its legal status as a third party, it was its technical inability to know what it held.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That criterion has been operating in silence for two decades. Nobody needed to write it down, because no intermediary had yet put it to the test.&lt;/p&gt;
&lt;h2 id=&#34;what-the-judges-are-actually-deciding&#34;&gt;What the judges are actually deciding&lt;/h2&gt;
&lt;p&gt;Once the criterion is stated, the February decisions change in nature.&lt;/p&gt;
&lt;p&gt;A court that treats the submission of a document to a generative AI system as disclosure to a third party is not applying an old rule to new facts. It is finding that this particular intermediary is not like the others. That it processes instead of storing. That something happens inside it which does not happen inside a hard drive.&lt;/p&gt;
&lt;p&gt;The federal court for the District of Kansas put the practical dimension plainly in &lt;a href=&#34;https://law.justia.com/cases/federal/district-courts/kansas/ksdce/2:2025cv02352/158740/152/&#34;&gt;Jefferies v. Harcros Chemicals&lt;/a&gt;, on 25 March 2026. It extended the protective order to all material in the proceedings, including documents that are not confidential, on the ground that it is practically impossible to retrieve data once it has been submitted to an open AI tool, because it has served to train the model. Retention is not a commercial policy open to renegotiation. It is a property of how the system works.&lt;/p&gt;
&lt;p&gt;Placed end to end, these decisions amount to recognising, in the vocabulary of the law of evidence, a capacity the law never had to attribute to a server.&lt;/p&gt;
&lt;h2 id=&#34;the-french-position-and-what-its-criteria-presuppose&#34;&gt;The French position, and what its criteria presuppose&lt;/h2&gt;
&lt;p&gt;The clearest statement comes not from a court but from professional regulation.&lt;/p&gt;
&lt;p&gt;The Conseil national des barreaux, the French national bar council, published its first practical guide on generative AI in September 2024, then &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;adopted a guide on ethics and artificial intelligence on 17 March 2026&lt;/a&gt;. The first is categorical on the central point: a lawyer must not pass to a generative AI system any data covered by professional secrecy, and that applies to the client&amp;rsquo;s name as much as to any strategic or confidential information. The recommended alternative is to work on &lt;strong&gt;pseudonymised&lt;/strong&gt; data sets, in which the identifying elements have been replaced.&lt;/p&gt;
&lt;p&gt;Practitioner commentary on the French position, notably &lt;a href=&#34;https://resourcehub.bakermckenzie.com/en/resources/global-attorney-client-privilege-guide/europe-middle-east--africa/france/topics/07---artificial-intelligence&#34;&gt;Baker McKenzie&amp;rsquo;s comparative privilege guide&lt;/a&gt;, draws four cumulative conditions from it. Privilege survives the use of a generative AI tool only if the platform preserves complete confidentiality, with no reuse, training or third-party access; if it is operated exclusively under the control of the lawyer or the firm; if it serves a legal purpose falling within the advisory or defence mandate; and if the output reflects the lawyer&amp;rsquo;s own reasoning rather than the system&amp;rsquo;s autonomous processing.&lt;/p&gt;
&lt;p&gt;That last condition deserves a pause.&lt;/p&gt;
&lt;p&gt;For privilege to hold, the system must not have contributed processing of its own.&lt;/p&gt;
&lt;p&gt;A criterion drafted in those terms makes sense only if one takes the system to be capable of contributing processing of its own. Nobody writes a rule requiring that a filing cabinet not have reasoned about the documents it contains. The condition exists because it targets something a cabinet cannot do.&lt;/p&gt;
&lt;p&gt;The same implicit recognition sits inside the pseudonymisation recommendation. Replacing identifying elements before transmission is necessary only if one assumes that the system might otherwise link them, retain them or infer something from them. A pure storage medium would call for no such precaution.&lt;/p&gt;
&lt;h2 id=&#34;not-wanting-to-read-not-being-able-to-read&#34;&gt;Not wanting to read, not being able to read&lt;/h2&gt;
&lt;p&gt;An objection arises immediately: the host can also be compelled to produce, so why does one intermediary destroy privilege and the other not?&lt;/p&gt;
&lt;p&gt;The answer is in the &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/DEONTOLOGY/DEON_CoC/EN_DEONTO_2021_Model_Code.pdf&#34;&gt;CCBE Model Code of Conduct&lt;/a&gt;, and it is more precise than the objection assumes. A European lawyer must require his or her associates, staff and anyone engaged in the provision of the lawyer&amp;rsquo;s services to observe the same obligation of confidentiality. The obligation travels along the chain.&lt;/p&gt;
&lt;p&gt;A hosting provider can be brought into that chain. It signs a processing contract. It accepts confidentiality undertakings. It can be audited, and it can be sued for breach. The third party is bound.&lt;/p&gt;
&lt;p&gt;A generative AI platform that retains and trains on submitted content cannot be brought into the chain in the same way, because what would have to be prevented is not a behaviour but an architecture. An undertaking not to train on input data is a promise about an intention. It binds the provider, but it does not change what the system is built to do, and it cannot be verified from the outside.&lt;/p&gt;
&lt;p&gt;That is the whole distance between a provider that does not want to read and a provider that cannot read. Only the second survives a change of shareholder, a revision of the terms of service or a court order. We examined exactly this mechanism in relation to the &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;conflict between the Data Act and the CLOUD Act&lt;/a&gt;: a legal guarantee is never worth more than the jurisdiction that houses it, whereas a technical impossibility depends on none.&lt;/p&gt;
&lt;h2 id=&#34;the-asymmetry&#34;&gt;The asymmetry&lt;/h2&gt;
&lt;p&gt;This is where the analysis arrives somewhere uncomfortable.&lt;/p&gt;
&lt;p&gt;The same legal order that agrees to recognise a processing capacity when the question is waiver of privilege refuses to recognise anything at all when the question is liability.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Electronic personhood&lt;/strong&gt; was proposed by the European Parliament in its &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;resolution of 16 February 2017 on civil law rules on robotics&lt;/a&gt;, at paragraph 59(f). The text suggested that the most sophisticated autonomous robots might eventually be given a status allowing them to be held liable for the damage they cause. The proposal was dropped after an &lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;open letter signed by several hundred experts&lt;/a&gt; opposed it. Their main objection was solid: granting personhood to machines would create a vehicle allowing manufacturers to offload a liability that properly belongs to them.&lt;/p&gt;
&lt;p&gt;The position therefore settled. An autonomous system that causes damage is a product, a tool, the instrument of whoever deployed it. It has no legal personality. Liability falls back on a human actor or on a legal entity, and it has to, since there is nowhere else for it to fall.&lt;/p&gt;
&lt;p&gt;Both propositions are now running at the same time.&lt;/p&gt;
&lt;p&gt;Either the system is capable of receiving a communication in the legal sense of the term, in which case its capacity is recognised in order to strip a client of protection while being denied in order to spare anyone the burden of liability. Or it is a tool, and submitting a document to it is no more a disclosure than saving a file to a disk, in which case the February reasoning collapses.&lt;/p&gt;
&lt;p&gt;The European context sharpens the imbalance rather than correcting it. The AI Liability Directive, announced as withdrawn as early as the Commission&amp;rsquo;s work programme of February 2025, was &lt;a href=&#34;https://eapil.org/2025/10/09/european-commission-withdraws-two-proposals-assignments-of-claims-regulation-and-ai-liability-directive/&#34;&gt;formally abandoned in October 2025&lt;/a&gt;. That was the instrument meant to address precisely this difficulty. What remains is the &lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj&#34;&gt;revised Product Liability Directive&lt;/a&gt;, which now covers software and AI systems, but which requires a defect, damage and a causal link, and which protects natural persons against personal injury, property damage and the destruction of data. Its transposition is not due until 9 December 2026, and it will apply only to products placed on the market after that date.&lt;/p&gt;
&lt;h2 id=&#34;the-predictable-objection-and-the-answer&#34;&gt;The predictable objection, and the answer&lt;/h2&gt;
&lt;p&gt;An attentive reader will reply that the law routinely recognises a capacity for one object and not for another, without that amounting to an inconsistency. An animal can cause legally relevant damage without having personality. A company has personality for the purpose of contracting, and not for every purpose in every legal order. Recognising a processing capacity for evidentiary purposes therefore obliges nobody to recognise personhood for liability purposes. Different questions, different answers.&lt;/p&gt;
&lt;p&gt;The objection is serious, and it would be decisive if the asymmetry ran both ways.&lt;/p&gt;
&lt;p&gt;It runs only one way. Where the system&amp;rsquo;s capacity is upheld, the cost is borne by the client whose protection disappears. Where that same capacity would have served to allocate liability, it becomes impossible to find. The result always falls on the same side.&lt;/p&gt;
&lt;p&gt;An asymmetry that systematically favours the same party is not a doctrinal distinction. It is an allocation of risk, and it ought to be discussed as one.&lt;/p&gt;
&lt;h2 id=&#34;what-this-means-in-practice&#34;&gt;What this means in practice&lt;/h2&gt;
&lt;p&gt;None of this suggests that the legal professions should give up these tools. The European professional texts do not say so either, and the CCBE has published its own guide on the subject.&lt;/p&gt;
&lt;p&gt;What it does suggest is that the decisive question is not which tool a firm chooses, but what that tool retains, and whether the answer is a matter of policy or a property of design. An undertaking not to retain can be withdrawn, reinterpreted or set aside by a court. An architecture that does not retain cannot be, because there is nothing to produce.&lt;/p&gt;
&lt;p&gt;The reference documents for anyone wanting to look into the question:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20251002_CCBE-guide-on-the-use-of-the-use-of-generative-AI-for-lawyers.pdf&#34;&gt;CCBE guide on the use of generative AI by lawyers&lt;/a&gt;, published on 2 October 2025, supplemented by a &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20260327_CCBE-technical-guide-on-the-use-of-AI-tools-and-models-by-lawyers.pdf&#34;&gt;technical guide&lt;/a&gt; in March 2026&lt;/li&gt;
&lt;li&gt;The &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;ethics guide of the Conseil national des barreaux&lt;/a&gt; of 17 March 2026, which applies the classic principles of confidentiality and independence without creating a special law of AI&lt;/li&gt;
&lt;li&gt;The &lt;a href=&#34;https://resourcehub.bakermckenzie.com/en/resources/global-attorney-client-privilege-guide&#34;&gt;Baker McKenzie comparative guide&lt;/a&gt;, useful for measuring the gap between national regimes&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-angle-arpokrat-takes&#34;&gt;The angle Arpokrat takes&lt;/h2&gt;
&lt;p&gt;This reasoning goes well beyond law firms. It holds for any relationship in which someone entrusts a system with information they do not want to see resurface, and it comes down to a single question: does the guarantee rest on a promise or on an impossibility?&lt;/p&gt;
&lt;p&gt;That is the principle governing the design of &lt;a href=&#34;https://arpokrat.com/messenger/&#34;&gt;Arpokrat Messenger&lt;/a&gt;. Identity is generated locally from cryptographic keys, with no phone number and no email address, and private keys never leave the device. That choice is not an undertaking not to exploit a user directory. It is a choice not to build one. A production order addressed to infrastructure that does not hold the information does not produce a refusal, it produces a void.&lt;/p&gt;
&lt;p&gt;The distinction deserves to be stated honestly, because it decides everything. A privacy policy, however sincere and however well drafted, is a declaration of intent backed by a company, by its shareholders of the moment and by the jurisdiction in which it is established. Those three things change. An architecture that does not collect does not change because a board changes. It is the same shift we described in relation to &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;collecting today for decryption later&lt;/a&gt;: the risk does not sit at the moment the promise is made, it sits at the moment somebody else decides.&lt;/p&gt;
&lt;p&gt;The law takes time to absorb that distinction, and the debate on legal privilege gives a good measure of it. The same goes for the &lt;a href=&#34;https://arpokrat.com/blog/5g-location-data-privacy-law/&#34;&gt;protection of location data&lt;/a&gt;, where most of the legal construction bears on access to data whose existence is never questioned.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Case law will eventually settle. Appellate courts will resolve the split, regulators will publish criteria, firms will adjust their engagement letters and their clauses. None of that is in doubt.&lt;/p&gt;
&lt;p&gt;But the underlying question will not be settled that way, because it is not really about legal privilege. It is about whether a legal order can recognise that a thing knows, without ever having to say who answers for what it does with that knowledge.&lt;/p&gt;
&lt;p&gt;As long as that question stays open, the only variable a user genuinely controls is not the quality of the undertakings given to them. It is the amount of information they let exist.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This article offers a general legal analysis intended for discussion. It does not constitute legal advice or a legal opinion.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;United States District Court for the Eastern District of Michigan, Warner v. Gilbarco Inc., 10 February 2026, &lt;a href=&#34;https://www.proskauer.com/alert/michigan-federal-court-protects-ai-assisted-litigation-work-product&#34;&gt;Proskauer analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;United States District Court for the Southern District of New York, &lt;a href=&#34;https://harvardlawreview.org/blog/2026/03/united-states-v-heppner/&#34;&gt;United States v. Heppner&lt;/a&gt;, 10 February 2026, written opinion of 17 February 2026&lt;/li&gt;
&lt;li&gt;United States District Court for the District of Kansas, &lt;a href=&#34;https://law.justia.com/cases/federal/district-courts/kansas/ksdce/2:2025cv02352/158740/152/&#34;&gt;Jefferies et al. v. Harcros Chemicals Inc. et al.&lt;/a&gt;, no. 2:25-cv-02352, 25 March 2026&lt;/li&gt;
&lt;li&gt;Conseil national des barreaux, &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;The CNB adopts a guide on ethics and artificial intelligence&lt;/a&gt;, 17 March 2026&lt;/li&gt;
&lt;li&gt;Baker McKenzie, &lt;a href=&#34;https://resourcehub.bakermckenzie.com/en/resources/global-attorney-client-privilege-guide/europe-middle-east--africa/france/topics/07---artificial-intelligence&#34;&gt;Global Privilege and Professional Secrecy Guide, France, Artificial Intelligence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CCBE, &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/DEONTOLOGY/DEON_CoC/EN_DEONTO_2021_Model_Code.pdf&#34;&gt;Model Code of Conduct for European Lawyers&lt;/a&gt;, 8 October 2021&lt;/li&gt;
&lt;li&gt;CCBE, &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20251002_CCBE-guide-on-the-use-of-the-use-of-generative-AI-for-lawyers.pdf&#34;&gt;Guide on the use of generative AI by lawyers&lt;/a&gt;, 2 October 2025&lt;/li&gt;
&lt;li&gt;European Parliament, &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;Resolution of 16 February 2017 with recommendations to the Commission on Civil Law Rules on Robotics&lt;/a&gt;, 2015/2103(INL)&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;Open Letter to the European Commission on Artificial Intelligence and Robotics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EAPIL, &lt;a href=&#34;https://eapil.org/2025/10/09/european-commission-withdraws-two-proposals-assignments-of-claims-regulation-and-ai-liability-directive/&#34;&gt;European Commission Withdraws Two Proposals: Assignments of Claims Regulation and AI Liability Directive&lt;/a&gt;, 9 October 2025&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj&#34;&gt;Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>Data Act vs CLOUD Act: who really controls your data in the cloud?</title>
      <link>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</link>
      <pubDate>Fri, 19 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</guid>
      <description>&lt;p&gt;For years, the world operated on a simple assumption: data has a physical place of residence. If it was stored on a server in Dublin, it fell under Irish and European law. That assumption collapsed in 2018, when the United States enacted the CLOUD Act — a law that grants American authorities access to data controlled by US companies, regardless of where that data is physically stored in the world. Several years later, Brussels responded with its own protective framework: the Data Act, now fully applicable, which attempts to limit the extraterritorial access of third-country authorities to data held within the European Union.&lt;/p&gt;
&lt;p&gt;Here is what these two texts actually provide, where they collide, and why the only truly robust protection against this conflict remains technical impossibility of access.&lt;/p&gt;
&lt;h2 id=&#34;the-american-cloud-act-access-based-on-control-not-location&#34;&gt;The American CLOUD Act: access based on control, not location&lt;/h2&gt;
&lt;p&gt;The &lt;strong&gt;CLOUD Act&lt;/strong&gt; (&lt;em&gt;Clarifying Lawful Overseas Use of Data Act&lt;/em&gt;), enacted in March 2018, amended US law by adding &lt;strong&gt;18 U.S. Code § 2713&lt;/strong&gt;. This provision requires any provider of electronic communication services or remote computing services to preserve, back up, or disclose the contents of a communication or any record pertaining to it, whenever that data is in the provider&amp;rsquo;s possession, custody, or control, &lt;strong&gt;regardless of whether the data is located inside or outside the United States&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is precisely this final clause that changes everything. The criterion is no longer the physical location of the server, but the control exercised by the parent company over its subsidiaries. A US company operating data centres in Europe therefore remains subject to American legal demands, even for data stored entirely on European soil.&lt;/p&gt;
&lt;h2 id=&#34;the-european-data-act-a-legal-barrier-to-extraterritorial-access&#34;&gt;The European Data Act: a legal barrier to extraterritorial access&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Regulation (EU) 2023/2854&lt;/strong&gt;, known as the Data Act, entered into force on 11 January 2024 and has been fully applicable since 12 September 2025, with certain provisions phased in through 2026 and 2027. Its &lt;strong&gt;Article 32&lt;/strong&gt; directly addresses the question of international governmental access to data.&lt;/p&gt;
&lt;p&gt;The text establishes a clear rule: any decision or judgment of a court or administrative authority of a third country requiring a data processing service provider to transfer or give access to non-personal data held in the European Union &lt;strong&gt;is recognised and enforceable only if it is based on an international agreement&lt;/strong&gt;, such as a mutual legal assistance treaty (MLAT), in force between the requesting country and the Union, or between that country and the relevant Member State.&lt;/p&gt;
&lt;p&gt;In the absence of such an agreement, Article 32 provides a second avenue, but one that is strictly circumscribed: the foreign decision may only be enforced if the legal system of the third country requires that the request be reasoned, proportionate, and sufficiently specific — for example, by establishing a clear link to specific individuals or offences — and if the recipient&amp;rsquo;s reasoned objection can be submitted to the review of a competent court in that third country.&lt;/p&gt;
&lt;h2 id=&#34;a-direct-legal-collision&#34;&gt;A direct legal collision&lt;/h2&gt;
&lt;p&gt;The problem is immediate: the CLOUD Act requires disclosure based on the control exercised by the parent company, without a proportionality requirement comparable to that demanded by European law. The Data Act, conversely, conditions recognition of such a request on the existence of an international agreement or specific procedural safeguards. A US company operating in Europe, ordered by an American authority to hand over data hosted within the Union, thus finds itself caught between two contradictory legal obligations: comply with the American mandate and violate Union law, or respect the Data Act and face the consequences of refusal in the United States.&lt;/p&gt;
&lt;p&gt;This tension is not theoretical. It has already been documented by the Court of Justice of the European Union (CJEU) in two landmark rulings, &lt;strong&gt;Schrems I&lt;/strong&gt; (2015) and &lt;strong&gt;Schrems II&lt;/strong&gt; (2020). In the Schrems II judgment, the CJEU held that American surveillance conducted under &lt;strong&gt;Section 702 of FISA&lt;/strong&gt; (&lt;em&gt;Foreign Intelligence Surveillance Act&lt;/em&gt;) and &lt;strong&gt;Executive Order 12333&lt;/strong&gt; does not respect the minimum safeguards required by Union law under the principle of proportionality, and therefore cannot be regarded as limited to what is strictly necessary. The Court also noted the absence of an effective judicial remedy for Union data subjects, in violation of Article 47 of the Charter of Fundamental Rights. This ruling invalidated the Privacy Shield framework, which had until then governed data transfers between the EU and the United States.&lt;/p&gt;
&lt;h2 id=&#34;the-structural-risk-harvest-now-decrypt-later&#34;&gt;The structural risk: Harvest Now, Decrypt Later&lt;/h2&gt;
&lt;p&gt;Beyond the jurisdictional conflict, a more insidious threat looms over data hosted in infrastructures subject to US law: the so-called &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;strong&gt;Harvest Now, Decrypt Later&lt;/strong&gt;&lt;/a&gt; (HNDL) strategy. The principle involves an intelligence service or hostile state actor intercepting and storing encrypted data today, in anticipation of sufficient quantum computing capabilities to decrypt it in the future.&lt;/p&gt;
&lt;p&gt;This strategy transforms any prolonged dependence on American cloud infrastructure into a deferred security liability: what is confidential today may become readable in ten or fifteen years, without any further action required on the part of the attacker — only time and patience.&lt;/p&gt;
&lt;h2 id=&#34;why-only-technical-impossibility-constitutes-a-genuine-guarantee&#34;&gt;Why only technical impossibility constitutes a genuine guarantee&lt;/h2&gt;
&lt;p&gt;Legal analysis converges on a finding shared by many compliance experts: however solid the Data Act&amp;rsquo;s legal framework may be, it remains a text that geopolitical power dynamics and diplomatic pressures can circumvent, delay, or reinterpret. The only protection that depends on no future negotiation is &lt;strong&gt;technical impossibility of enforcement&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;zero knowledge&lt;/strong&gt; architecture, in which the service provider never holds possession or custody of the decryption keys, renders a legal demand materially inoperable. One cannot be compelled to hand over what one never possesses.&lt;/p&gt;
&lt;p&gt;This is the logic that underpins ecosystems such as &lt;strong&gt;Arpokrat&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Jurisdictional neutralisation&lt;/strong&gt;: the infrastructure is hosted in Switzerland, under the Swiss Federal Act on Data Protection (FADP/LPD), outside the direct scope of the CLOUD Act&amp;rsquo;s extraterritoriality&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No custody&lt;/strong&gt;: the zero knowledge architecture deprives the service provider of any ability to hand over keys or content it never holds&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced identity footprint&lt;/strong&gt;: by eliminating the requirement to register with a phone number or email address — identifiers that FISA Section 702-based surveillance can easily track — the user ceases to be an identifiable subscriber and becomes an anonymous cryptographic key&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-chain-of-custody-does-not-stop-at-message-encryption&#34;&gt;The chain of custody does not stop at message encryption&lt;/h2&gt;
&lt;p&gt;A point often underestimated in compliance analyses: encrypting the content of a communication is not enough if the underlying operating system — whether Android or iOS — continues to capture metadata or kernel-level telemetry destined for servers under US jurisdiction. Protecting confidentiality requires a complete closure of the chain of custody, from content all the way down to the hardware infrastructure itself.&lt;/p&gt;
&lt;p&gt;This is why digital sovereignty also requires reflection on the operating system in use, not just on messaging applications. De-Googled systems, in which modules such as Bluetooth or GNSS geolocation can be disabled directly at the kernel level, eliminate physical attack vectors that no application-layer encryption can compensate for.&lt;/p&gt;
&lt;h2 id=&#34;post-quantum-cryptography-an-already-engaged-horizon&#34;&gt;Post-quantum cryptography: an already-engaged horizon&lt;/h2&gt;
&lt;p&gt;In the face of the threat posed by the HNDL strategy, adopting post-quantum cryptography (PQC) standards becomes a necessity for anyone wishing to guarantee the confidentiality of sensitive data over the long term — whether that involves trade secrets, professional correspondence, or health data. Encryption considered robust today under classical standards does not guarantee that it will withstand the quantum computing capabilities expected within the next fifteen years.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The conflict between the Data Act and the CLOUD Act illustrates a broader reality: digital sovereignty can no longer be built on legislation alone, however solid that legislation may be. It requires closing the chain of custody at every level — from the encryption protocol to the hosting jurisdiction, and including the operating system itself. It is this layered approach, rather than trust placed in a single regulatory framework, that defines genuine digital sovereignty by design today.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Monero and Zcash Banned in Europe from 2027: What AMLR Changes</title>
      <link>https://arpokrat.com/blog/monero-zcash-banned-eu-amlr-2027/</link>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/monero-zcash-banned-eu-amlr-2027/</guid>
      <description>&lt;p&gt;Monero and Zcash banned in Europe: it is now settled. From July 2027, the European Union will close institutional access to privacy-enhanced cryptocurrencies through a new anti-money laundering regulation called &lt;strong&gt;AMLR&lt;/strong&gt;. Here is what the text concretely provides for, the role of the new European authority &lt;strong&gt;AMLA&lt;/strong&gt; tasked with enforcing it, and what this truly means for anyone holding privacy coins.&lt;/p&gt;
&lt;h2 id=&#34;amlr-and-amla-two-different-texts-not-to-be-confused&#34;&gt;AMLR and AMLA: Two Different Texts, Not to Be Confused&lt;/h2&gt;
&lt;p&gt;Before going into detail, a clarification is in order — these two acronyms refer to two distinct things, often confused in the specialist press:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;AMLR&lt;/strong&gt; (&lt;em&gt;Anti-Money Laundering Regulation&lt;/em&gt;) is &lt;strong&gt;the law itself&lt;/strong&gt;: Regulation (EU) 2024/1624, which defines the rules — anonymous accounts prohibited, verification thresholds, treatment of privacy coins. It is the &amp;ldquo;what.&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AMLA&lt;/strong&gt; (&lt;em&gt;Anti-Money Laundering Authority&lt;/em&gt;) is &lt;strong&gt;the new European supervisory authority&lt;/strong&gt;, created by a separate regulation adopted on the same day, Regulation (EU) 2024/1620. Its role is to directly supervise the application of the AMLR, particularly with respect to the largest crypto-asset service providers (CASPs) operating across multiple Member States. It is the &amp;ldquo;who enforces it.&amp;rdquo;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In short: AMLR sets the rules, AMLA ensures they are followed. Both texts form a single European legislative package against money laundering and the financing of terrorism.&lt;/p&gt;
&lt;h2 id=&#34;what-the-amlr-regulation-actually-says&#34;&gt;What the AMLR Regulation Actually Says&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Regulation (EU) 2024/1624&lt;/strong&gt; was adopted by the European Parliament and the Council on 31 May 2024, then published in the Official Journal of the European Union on 19 June 2024. Its &lt;strong&gt;Chapter VIII (Articles 79–80)&lt;/strong&gt;, entitled &lt;em&gt;&amp;ldquo;Measures to mitigate risks associated with anonymous instruments&amp;rdquo;&lt;/em&gt;, and more specifically its &lt;strong&gt;Article 79&lt;/strong&gt; (&amp;ldquo;Anonymous accounts, bearer shares and bearer warrants&amp;rdquo;), establishes that credit institutions, financial institutions, and &lt;strong&gt;crypto-asset service providers (CASPs)&lt;/strong&gt; are now prohibited from maintaining anonymous accounts or offering products that enable the anonymisation of transactions.&lt;/p&gt;
&lt;p&gt;The text explicitly targets two distinct but related categories:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Anonymous accounts&lt;/strong&gt; — whether banking, payment, or crypto. The rule aligns the crypto sector with restrictions that already existed for anonymous bank accounts, bearer securities accounts, and anonymous safe-deposit boxes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&amp;ldquo;Anonymity-enhancing coins&amp;rdquo;&lt;/strong&gt; — the generic term used by the regulation to refer to assets that use advanced cryptographic techniques making transaction flows untraceable. &lt;strong&gt;Important clarification&lt;/strong&gt;: the legal text does not name any token by name. It is the widely shared interpretation of compliance firms and the industry — notably the &lt;em&gt;AML Handbook&lt;/em&gt; published by the European Crypto Initiative (EUCI) — that identifies Monero (XMR), Zcash (ZEC), and Dash (DASH) as falling within this category. This is a reading consistent with the regulation&amp;rsquo;s definition, but it is a sectoral interpretation, not a nominative list written into the law.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;The regulation is part of a broader framework, alongside &lt;strong&gt;MiCA&lt;/strong&gt; (&lt;em&gt;Markets in Crypto-Assets&lt;/em&gt;), already in force since 2024–2025 and which has already led many platforms (Kraken as early as October 2024, followed by dozens of others) to delist Monero from their European markets in anticipation.&lt;/p&gt;
&lt;h2 id=&#34;the-key-date-july-2027&#34;&gt;The Key Date: July 2027&lt;/h2&gt;
&lt;p&gt;The AMLR has a firm application date. The majority of specialist sources, including French-language ones, converge on &lt;strong&gt;10 July 2027&lt;/strong&gt; as the deadline for full application. From that date, crypto-asset exchanges and custodial services will no longer be able to deal with either anonymous accounts or privacy coins.&lt;/p&gt;
&lt;p&gt;Before that deadline, the regulation already imposes enhanced obligations:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Mandatory identity verification&lt;/strong&gt; for any occasional crypto transaction exceeding 1,000 euros — a threshold significantly lower than the current practices of many platforms&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced controls&lt;/strong&gt; on self-hosted wallets (&lt;em&gt;self-custody&lt;/em&gt;): when a user transfers funds between a regulated platform and a personal wallet, the CASP will be required to collect information on the origin and destination of the funds, and at minimum verify the identity of the holder of the external wallet&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Elimination of anonymous cash payments&lt;/strong&gt; above 3,000 euros, following the same logic of extending identity controls to all anonymous financial instruments&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;why-brussels-is-banning-monero-and-zcash-on-regulated-platforms&#34;&gt;Why Brussels Is Banning Monero and Zcash on Regulated Platforms&lt;/h2&gt;
&lt;p&gt;In its &lt;em&gt;AML Handbook&lt;/em&gt;, the EUCI summarises the logic underpinning the text: the anonymity of crypto-assets presents significant risks of misuse for criminal purposes, by preventing transaction traceability and complicating the detection of suspicious activity.&lt;/p&gt;
&lt;p&gt;This is precisely the same reasoning that has already led Japan, South Korea, and &lt;a href=&#34;https://arpokrat.com/blog/philippines-bans-privacy-coins-monero-zcash/&#34;&gt;more recently the Philippines&lt;/a&gt; to exclude privacy coins from their regulated platforms — a progressive alignment of developed jurisdictions with FATF (Financial Action Task Force) standards. By formalising this prohibition in a regulation directly applicable across all 27 Member States, the European Union gives this trend a legal weight and a pull effect (the &amp;ldquo;Brussels Effect&amp;rdquo;) considerably greater than that of isolated national decisions.&lt;/p&gt;
&lt;h2 id=&#34;what-is-not-prohibited--the-nuance-that-matters&#34;&gt;What Is NOT Prohibited — The Nuance That Matters&lt;/h2&gt;
&lt;p&gt;Several legal analyses converge on a central point: &lt;strong&gt;the AMLR does not criminalise individual ownership of privacy coins, nor peer-to-peer transfers outside regulated platforms.&lt;/strong&gt; Self-hosted wallets are not prohibited as such — they are subject to enhanced controls only when they interact with a platform subject to regulation.&lt;/p&gt;
&lt;p&gt;What the AMLR closes off are the &lt;strong&gt;institutional on-ramps&lt;/strong&gt;: the purchase, sale, deposit, and withdrawal of privacy coins through a regulated CASP within the European Union. Private ownership and decentralised exchanges remain, at this stage, outside the direct scope of the prohibition — a pattern identical to that already observed in the Philippines.&lt;/p&gt;
&lt;h2 id=&#34;what-this-concretely-means-for-xmr-and-zec-holders&#34;&gt;What This Concretely Means for XMR and ZEC Holders&lt;/h2&gt;
&lt;p&gt;If you currently hold privacy coins on a regulated exchange within the European Union:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;By July 2027&lt;/strong&gt;, these platforms will have had to remove support for these assets or ceased accepting new deposits related to them&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Transfers to personal wallets&lt;/strong&gt; from those same platforms will be subject to enhanced identity verification, even before the final deadline&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Any crypto transaction above 1,000 euros&lt;/strong&gt;, privacy coin or not, will require full identification&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Critics of the text, even within the crypto industry itself, point to a structural risk: by closing off regulated circuits without technically prohibiting the assets themselves, the regulation mechanically pushes privacy coin holders toward less transparent markets and unregulated platforms — the exact opposite of the traceability objective Brussels has declared.&lt;/p&gt;
&lt;h2 id=&#34;getting-organised-before-the-2027-deadline&#34;&gt;Getting Organised Before the 2027 Deadline&lt;/h2&gt;
&lt;p&gt;With a horizon set at 2027, the transition is not immediate — but it is already underway. Platforms are already adjusting their offerings in anticipation of compliance, and the window to exchange or consolidate privacy coin positions without depending on infrastructure subject to this jurisdiction narrows every month.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/swap&#34;&gt;Arpokrat Swap&lt;/a&gt; allows you to exchange Monero, Zcash, and all privacy-enhanced cryptocurrencies with no sign-up, no collection of identity data, and no dependency on a regulated CASP subject to the AMLR. The platform is accessible on the clearnet as well as via our .onion address, ensuring that your ability to exchange these assets does not depend on any jurisdiction that might close its on-ramps overnight.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The AMLR confirms a trajectory that is now beyond doubt: regulated crypto markets and financial privacy are becoming, jurisdiction by jurisdiction, structurally incompatible. The question is no longer whether this trend will extend across all developed economies, but how much time will remain, after 2027, to exchange private assets outside circuits that will no longer have the right to touch them.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>