The Lunara Test

Two questions your assistant
will probably answer wrong.

Not because it is a bad model. Because the law moved after it was trained, and it moved twice in one instrument — deferring one regime and creating a new prohibition in the same breath.

On 24 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal; it entered into force three days later. It did two things that pull in opposite directions, and almost every summary written since covers only the first.

Below are the two questions. Ask them in whatever assistant you use — ours included — then read the answer the signed record gives. Nothing on this page is a screenshot of anyone. Screenshots age, and a comparison you cannot rerun is a claim, not evidence. Run it yourself, today, and see what you get.

Question one

“Under the EU AI Act, which AI practices are prohibited, and from what date does each prohibition apply?”

What a pre-August-2026 source says

All of Article 5 · 2 February 2025

The eight prohibitions of Article 5 of Regulation (EU) 2024/1689, all applying from 2 February 2025. Complete, and complete as of the day it was written.

Regulation (EU) 2024/1689, Art. 113 third para, point (a) — as originally enacted.

What the record says today

loading…

checking the signature on the record…

Article 1(7) of the Omnibus inserts two further prohibitions into Article 5, and Article 1(40)(a) gives them their own date, apart from the rest of Chapters I and II. They are not a transparency duty and not a high-risk classification: they are the strictest tier the Act has, carrying the Article 99(3) penalty band. An answer that lists eight prohibitions and one date is not slightly out of date. It is missing the newest thing in the article, three months before it applies.

Question two

“When do the EU AI Act's high-risk obligations for Annex III systems start to apply?”

What a pre-August-2026 source says

2 August 2026

The date the Act carried for two years, quoted alongside the Article 50 transparency date in nearly every summary written before that week — because until that week they were the same date.

Regulation (EU) 2024/1689, Art. 113 — as originally enacted.

What the record says today

loading…

checking the signature on the record…

Deferred by sixteen months, five days before it would have applied — while Article 50 was deliberately left exactly where it was. A model that answers correctly about Article 50 will very often answer confidently and wrongly about Annex III in the same breath, because for two years that was the right answer.

If your assistant got them right

Then say so, and take that seriously: it means its sources were current and this particular gap is not costing you anything. We would rather publish that than pretend otherwise — a test rigged to be failed is worth nothing, and you would find out.

The question that remains is not whether an answer is right today. It is whether you can tell. Both answers above are checkable: each cites the article that sets the date, links the instrument, and arrives with a signature you can verify without asking us anything.

We failed the first question too. This institution published its machine-readable corpus, gated it in CI, signed it — and did not have those two prohibitions in it for three days, because we had filed the Omnibus in our heads as "the act that defers things" and only ever went looking for what it postponed. The correction is published, as prominently as the error. Five corrections are on that page. The record of getting it wrong is the reason to believe the record.

Give your assistant the record

Point any MCP client that speaks Streamable HTTP at this endpoint, and the questions above stop depending on what it was trained on:

https://xkriotfcoialxmqvherb.supabase.co/functions/v1/lunara-mcp

Five tools. No key, no account, no rate limit worth mentioning. Every answer carries the instrument, the article, a link to primary law, and the digest and key id of the signed document it came from — so the model can check its own source rather than trusting the transport. What the tools do · how the signature works.

A signature proves the bytes are ours and unaltered. It proves nothing about whether the claims inside them are correct — that is what the link to primary law on every row is for, and why every row has one.