Operating Standard
We mark what we know,
and what we only heard.
An institution that certifies other people's evidence has to be legible about its own. Every claim we publish carries a classification, a source, and a confidence. When we get something wrong, the correction is published as prominently as the error was.
The four marks
These appear on intelligence briefings, assessments and reports. They are not decoration and they are not graded on effort: each one has a test, and a claim that fails the test gets the lower mark.
Verified
Checked against a primary source, and the source is cited so you can check it yourself.
Test: could a reader reach the same conclusion from the document we linked, without trusting us?
Reported
Stated by a credible outlet or party, not independently confirmed by us.
Test: do we know who said it, and have we said so plainly rather than absorbing it into our own voice?
Interpretation
Our reading of what the evidence means. The facts underneath are marked separately.
Test: is the underlying evidence separable from our conclusion, so a reader can accept one and reject the other?
Hypothesis
A forward-looking claim we cannot yet evidence. Held to a lower standard and labelled as such.
Test: have we said what would prove it wrong?
The direction of the marks matters. Overstating what is settled is the expensive error, because it is the one a knowledgeable reader catches first and it discredits every accurate claim beside it. Where a mark is genuinely ambiguous, we take the lower one.
The correction policy
Any standard nobody has ever been held to is decoration. Ours is this: when we publish something wrong, we correct it in place, we say what was wrong and why we got it wrong, and we do not quietly promote a claim from one classification to another without recording the source that justified the move.
Here is that policy applied to ourselves.
Correction · issued 19 August 2026
We told readers that two obligations were in force when they were not.
On 18 August this site published a live instrument stating that the EU AI Act's Annex III high-risk obligations applied from 2 August 2026, and our risk scorer gave paying users that same date. Both were wrong.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the deadline it moved. It deferred the Annex III high-risk obligations to 2 December 2027 and the Annex I product obligations to 2 August 2028. It deliberately left Article 50 transparency exactly where it was.
- What we got wrong
- We overstated what binds today, which is the worst direction to be wrong in for an institution selling the interpretation of deadlines.
- Why
- We read the founding regulation and not the instrument amending it. Being right about four dates does not survive being wrong about the fifth.
- How it was found
- While researching an unrelated outreach list. It was not caught by our own review, which is the part worth admitting.
- Corrected
- Within the hour, in the instrument itself and in the scorer, with the amending regulation now cited on every affected entry. Two obligations we had been missing entirely were added at the same time, including the transitional date under Article 50(2), which is currently the nearest binding deadline in the Act. [Corrected 21 August 2026: this entry originally read “2 February 2027”. The correct date is 2 December 2026 — the Omnibus grants four months, not six. See the fourth correction below.]
- What changed so it cannot recur
- No page on this site states a date. Dates live in one table that computes tense at the moment of reading, and that table now carries a written instruction to check amendments and not only founding texts.
Correction · issued 20 August 2026
We stated a California obligation without the threshold that decides who it binds.
Our instrument carried the California AI Transparency Act, SB 942 as amended by AB 853, with its operative date of 2 August 2026 and this summary: “Covered providers must offer free AI-detection tooling and embed latent disclosure in generated content.” The date is correct. The sentence is not, because it never says what the word covered is doing.
The Act reaches generative systems with over one million monthly users. Below that line it imposes nothing. As written, our row read as though it bound every generative system operating in California — which would include most of the organisations we write to, and does not.
- What we got wrong
- We overstated reach rather than timing. It is the same error as overstating a date and it is caught just as quickly, by exactly the reader we most want to persuade.
- Why
- The threshold was already stated correctly in this site's structured data, so the fact was never unknown to us. It was dropped when the obligation was compressed into a single line, and nothing in our review compares a summary against the fuller statement elsewhere on the same site.
- How it was found
- While verifying the operative date, which had been carried without a confirming source since the instrument was built. The date survived the check. The sentence around it did not.
- Corrected
- The row now names the threshold. We also added the second wave of AB 853, 1 January 2027, for generative hosting platforms and large online platforms, which we had been missing entirely.
- What changed so it cannot recur
- Applicability is now treated as part of an obligation rather than as detail beneath it. A row that states what an obligation requires without stating who it reaches is incomplete, and the instrument carries that instruction in writing next to the entry that failed it.
Correction · issued 21 August 2026
We called a voluntary framework a mandate, and gave it a date it never had.
Our AI context file, our identity graph and our compliance timeline all carried Executive Order 14409 as a “30-day cybersecurity testing mandate for frontier models” and a “federal agency compliance requirement,” active from 24 July 2026. Our identity file listed the order among the standards this institution assesses against.
The order was signed 2 June 2026 and published in the Federal Register on 5 June. Its frontier-model framework is voluntary: a developer may offer a covered model to federal agencies for up to thirty days of pre-release evaluation. Section 3(c) says in terms that nothing in it authorises “a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.” The binding thirty-day clocks are in Section 2 and they run against federal agencies hardening their own systems — not against anyone building a model.
- What we got wrong
- Three things in one entry. We converted a voluntary programme into a mandate, we attached the thirty-day agency deadlines from Section 2 to the developer framework in Section 3, and we published a date that corresponds to nothing in the order’s history. This is the third time we have overstated what binds, and the first time we did it about an instrument that binds nobody in our audience at all.
- Why
- The entry was never checked against the order. It was written from secondary coverage, carried forward across three files, and then read back to us by our own structured data as though that were confirmation. Our two previous corrections were both caught by going to primary law; this row had never been there.
- How it was found
- While auditing every regulatory claim on this site before publishing the corpus in machine-readable form. It was not caught by our own review either, which now makes two of three.
- Corrected
- The claim is corrected in llms.txt, in our identity graph, and on the compliance timeline, each now linking the Federal Register text so a reader can check the wording of Section 3(c) without trusting us. The order has been removed from the list of standards we assess against, because it is not one. FedRAMP and FISMA were removed from that same list in the same pass: both are United States federal programmes, we hold no authorisation under either, and listing them implied a status we do not have.
- What changed so it cannot recur
- Obligations now live in one generated corpus with a link to primary law on every entry, and the build refuses to publish an entry that has no source or that claims an amendment it does not link. The deeper rule is the one this error broke: an instrument that binds nobody does not go in the table at all. EO 14409 is now described where readers ask about it and is deliberately absent from the corpus, because a short table that is right beats a long one that is mostly right.
Correction · issued 21 August 2026
We gave the nearest deadline in the Act, and gave it four months too late.
Two days ago we corrected our Annex III date and added, in the same edit, the Article 50(2) transitional date for generative systems already on the market. We called it the nearest binding deadline in the entire Act, which it is. We put it at 2 February 2027, which it is not.
The Digital Omnibus grants a transitional period of four months, not six. Recital 38 of Regulation (EU) 2026/1744: “it is appropriate to introduce a transitional period of four months for providers who have already placed their systems on the market before the 2 August 2026.” Four months from 2 August is 2 December 2026.
Every organisation reading that row was told it had until February. It has until December.
- What we got wrong
- We understated what binds, and this is the first time. The three corrections before this one all overstated — we called things binding that were not, or reached further than they do, and the cost of that error is embarrassment. This one has the opposite shape and a worse cost: a reader who acted on our date would have planned for February, and missed a real deadline in December by two months. We have written repeatedly that overstating is the expensive direction. It is the expensive direction for us. Understating is the expensive direction for the people who pay us, and that is worse.
- Why
- There are two real dates a few weeks apart and we took the wrong one. The Code of Practice sets 2 February 2027 for watermark-detection interoperability — a different instrument, a different obligation, and voluntary. It is adjacent enough in the source material to be picked up by someone reading quickly, and that is what happened. We also never derived the date from the four-month period; we carried it as a date, and a date carried is a date nobody can check.
- How it was found
- While researching which organisations this deadline actually reaches, in order to write to them. The row had survived the review two days earlier that produced the Annex III correction, because that review checked the amendment and not the arithmetic. Three of our four corrections have now been caught by something other than our own review.
- Corrected
- The date is 2 December 2026 in the instrument, in the published corpus, in the free assessment on our homepage and in the citation the MCP server hands to AI systems. The entry now cites the four-month period and the recital that grants it, rather than a date, so the next reader can do the arithmetic themselves. The earlier correction has been annotated in place rather than quietly edited.
- What changed so it cannot recur
- Where an instrument states a period, the entry now records the period and the provision granting it, not just the resulting date — a date with no derivation behind it cannot be checked by anyone, including us. The homepage assessment no longer contains any date at all: all three it used to carry are now read from the instrument, which is the rule that existed before this error and which this line was breaking at the moment it was wrong.
Correction · issued 24 August 2026
We read the Omnibus as the act that defers things, and missed a prohibition inside it.
Regulation (EU) 2026/1744 is described on this site, accurately, as the instrument that deferred the Annex III high-risk regime to December 2027 and the Annex I products to August 2028. That is what it is known for here, and it is how we filed it. The same regulation also inserts two new prohibited practices into Article 5 of the AI Act — Article 1(7) adds Article 5(1)(ba) and (bb) and paragraphs 1a and 1b — and Article 1(40)(a) gives them their own application date of 2 December 2026, apart from the rest of Chapters I and II.
They prohibit placing on the market, putting into service or using an AI system that generates or manipulates intimate imagery of an identifiable person without that person's explicit consent, or child sexual abuse material. A general-purpose image or video generator is within reach of the provision where such output is a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks adequate safeguards. It sits in the highest penalty tier the Act has — Article 99(3), up to €35,000,000 or 7% of worldwide turnover — and it was not in our corpus at all.
In the same pass we found that the Article 50(2) transitional entry — the subject of the correction directly above — cited recital 38. Recitals explain a regulation; they do not bind under it. The operative provision is Article 111(4) of Regulation (EU) 2024/1689, inserted by Article 1, point (39)(b) of the Omnibus, and it says the same thing with legal force.
- What we got wrong
- Two things, one of them new in kind. The missing prohibition is an omission rather than a wrong date: every entry we published was correct, and the table was still not a true picture of what the Act does to a generative system three months from now. The recital citation is a defect in the evidence itself — we told readers to check us against the source and pointed them at a source that cannot carry the claim.
- Why
- An amending act gives and takes in the same breath, and we only went looking for what it took. Once the Omnibus was labelled “the deferral regulation” every subsequent read of it was a search for postponements. The recital citation has a plainer cause: we went looking for the four-month period, found it stated in the recital, and stopped there instead of reading on to the article that enacts it.
- How it was found
- By re-reading both regulations end to end against the corpus, rather than checking the corpus against what we remembered of them. Prompted by a plan to publish a demonstration comparing our answers to a model's, which is only worth publishing if our own answers survive the same scrutiny we would be inviting.
- Corrected
- The prohibition is in the corpus as
eu-prohibitions-synthetic, with its inserting provision, its own date and its penalty tier; the February 2025 prohibitions entry now records that it is no longer the whole of Chapters I and II. The applicability model asks one further question — whether a system produces images, audio or video rather than only text — and flags the prohibition where it can reach, while stating in terms that this is not a finding of unlawfulness: the safeguards limb of paragraph 1a is the whole question and seven inputs cannot answer it. The Article 50(2) entry now cites Article 111(4). All of it is signed and independently verifiable.
- What changed so it cannot recur
- The rule that produced this was “check for amendments, not just the founding text.” It was followed and it was not sufficient, because it says nothing about what an amendment might add. It now reads: an amending act is read in full, for what it inserts as well as for what it postpones, and the entry records the inserting provision rather than the summary of the act. The applicability model's inputs are also now read from the published model by the MCP server instead of being listed a second time in its code — a rule referring to an input that server had never heard of used to evaluate false, which reads exactly like “does not apply.”
We publish these because the alternative is worse. A compliance authority that has never issued a correction is either very lucky or not looking, and a prospect who finds an uncorrected error learns more about us than any accurate page would have taught them.
What this means if you buy from us
Every assessment we deliver carries these marks on each finding. Where an obligation binds you, we cite the article. Where we are reading a situation rather than reporting one, we say so, and you are free to disagree with the reading while keeping the facts.
And where nothing binds you, we say that too. The thirty second check on our homepage has seven possible outcomes and two of them tell the reader that Article 50 does not reach them. A qualifier that only ever escalates is a sales funnel, not an assessment.
Sources for the corrections above
See the standard in use
The briefing on what changed on 27 July carries these marks on every claim, with the source attached to each one.
Read the briefing