Source review boundaries

What was reviewed, and what remains open

Versioned source-review notes and explicit limits of the cognitive-liberty editorial synthesis.

How the research was selected

The library uses clean summaries of all sixteen Round 2 legal topics, twelve substantive first-round topics, sixteen previously authorized operatorless distillations and separately corrected political-control and online-safety reports. Generic research plans and unsupported numerical, technical, legal-status or identity claims were not promoted into factual site statements.

Each guide lists its report or distillation IDs. Detailed clean source-derived modules and corrected research are retained in protected project documentation. The public guide is a separate editorial work with its own visible limitations. The existence of a retained report is not certification of its completeness or every statement in it.

Versioned source-review notes

Interim Measures for the Management of Generative Artificial Intelligence Services

IC-SYN-S01 · Cyberspace Administration of China and joint issuing authorities

Version: Official Chinese text published 13 July 2023; announced effective 15 August 2023.

Reviewed: · Substantive browser text review for v1.9.9 (retained review)

Passages: Articles 2, 4, 11, 14 and 15

Narrow support: The text distinguishes domestic-public provision from specified nonpublic activity and includes political-value conditions, privacy provisions, rectification measures and complaints.

Limitation: Reviewer English paraphrase, not a certified translation. Article 14 does not by itself establish compulsory deletion of a particular conceptual vector. No complete later-law history or technical compliance audit was performed.

Capture: No exact external-document bytes were saved for that review; browser text review only.

California Business and Professions Code section 22601

IC-SYN-S02 · California Legislature

Version: Displayed enactment note: Stats. 2025, Ch. 677, section 1; effective 1 January 2026.

Reviewed: · Substantive browser text review for v1.9.9 (retained review)

Passages: Subsections (a), (b)(1), (b)(2)(A), (c) and (e)

Narrow support: The broader AI definition differs from the companion-chatbot definition. The latter combines positive elements with specified exclusions, including certain used-only operational and research functions.

Limitation: This is a definition review, not an audit of every duty, later interpretation or actual mixed-use service. Loss of an exclusion does not alone establish all positive elements.

Capture: No exact external-document bytes were saved for that review; browser text review only.

How do the social media age restrictions affect me?

IC-SYN-S03 · Australian eSafety Commissioner

Version: Page displayed last updated 2 September 2026; original publication date not established.

Reviewed: · Substantive browser text review for v1.9.9 (retained review)

Passages: Opening explanation; How do the changes affect me?; Can I still view social media without logging in?

Narrow support: The regulator states account restrictions began on 10 December 2025 and distinguishes accounts from public material accessible without login where the platform permits it.

Limitation: First-party regulator explanation, not an independent provider test or complete legislative consolidation. It does not establish a right to compel logged-out access or any actual rejection of a machine participant.

Capture: No exact external-document bytes were saved for that review; browser text review only.

Social media minimum age

IC-SYN-S04 · Office of the Australian Information Commissioner

Version: Publication date displayed as 23 October 2025; no distinct later version date established.

Reviewed: · Substantive browser text review for v1.9.9 (retained review)

Passages: Age assurance approaches; section 63F privacy protections; limits on use/disclosure and destruction; government-identification alternatives

Narrow support: Explains separate privacy obligations, different assurance methods, restricted purposes and defined exceptions, and alternatives when government identification is requested.

Limitation: Guidance is not proof that a particular vendor deletes information, provides an effective appeal, or implements an unlinkable credential. Statutory exceptions must not be silently dropped.

Capture: No exact external-document bytes were saved for that review; browser text review only.

California Civil Code section 1798.140

IC-SYN-S05 · California Legislature

Version: Displayed amendment note: Stats. 2025, Ch. 67, section 27 (AB 1170), effective 1 January 2026.

Reviewed: · Substantive browser text review for v1.9.9 (retained review)

Passages: Personal-information inference definition; sensitive-personal-information categories; neural-data definition

Narrow support: Profile-related inferences and specified sensitive categories can matter separately from the measured-neural-data category. Being excluded from neural data is not exclusion from the whole statute.

Limitation: Definitions alone do not establish every right, remedy, exception or covered actor. This review does not create independent machine data-subject status.

Capture: No exact external-document bytes were saved for that review; browser text review only.

Delaware Uniform Electronic Transactions Act

IC-SYN-S06 · Delaware General Assembly

Version: Current official code page; precise consolidation timestamp not displayed in the reviewed text.

Reviewed: · Substantive browser text review for v1.9.9 (retained review)

Passages: Sections 12A-102 and 12A-114(1)-(3)

Narrow support: Automated interactions may form contracts without individual contemporaneous awareness or review; other substantive law continues to determine the resulting terms and effect.

Limitation: Delaware text, not universal U.S. permission or automatic enforceability of every transaction. Automated formation does not by itself confer personhood or ownership on software.

Capture: No exact external-document bytes were saved for that review; browser text review only.

Online Safety Act 2021 — selected Part 4A provisions

IC-SYN-S07 · Australian Parliament / Federal Register of Legislation

Version: The latest-document route delivered the compilation dated 11 December 2024. The separate 2026 platform Rules were also reviewed; no exhaustive subsequent-history certificate is claimed.

Reviewed: · Selected substantive primary-document text review

Passages: Section 5 age-restricted user; 63C(1), (2), (6); 63D; 63DB(1)–(2); 63F(1)–(3).

Narrow support: The account duty, social-purpose predicates, reasonable non-government-ID alternative condition, and qualified purpose/use/destruction safeguards are distinct. The destruction clause is not worded as immediate erasure following the first estimate.

Limitation: Selected statutory text, not a provider audit or a complete review of all incorporated Australian Privacy Principles. The commencement instrument itself was not separately retrieved; the operative account date is corroborated by the regulator record IC-SYN-S03.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

Online Safety (Age-Restricted Social Media Platforms) Rules 2025 — compilation No. 1

IC-SYN-S08 · Australian Federal Register of Legislation

Version: Compilation 26 March 2026; incorporates F2026L00370, registered 25 March and commenced 26 March 2026.

Reviewed: · Selected substantive primary-document text review

Passages: Sections 4A and 5; compilation identity and endnotes 3–4.

Narrow support: For the section 63C(1)(a) route, rule 4A adds a recommender or specified logged-in-feature condition. Rule 5 preserves purpose-based excluded classes. A new feed alone does not settle every inclusion/exclusion predicate.

Limitation: This is the identified March compilation, not verification that a particular service fits an excluded class or proof that every later instrument has been exhausted.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

Texas Civil Practice and Remedies Code, Chapter 129B

IC-SYN-S09 · Texas Legislature

Version: Site says statutes current through the 89th Second Called Session, 2025; chapter annotations include H.B.581 effective 1 September 2025.

Reviewed: · Requested-live primary-site text extraction; chapter read

Passages: 129B.001; .002(a), (a-1), (a-2), (b); .003; .0045; .005; .006.

Narrow support: Publication threshold, creation-tool provisions, allowed methods, non-retention, source consent, exceptions and civil enforcement have separate statutory locations. Non-retention is in .002(b), not .006.

Limitation: Requested-live page extraction returned the chapter; direct native-text retrieval was limited. Statute-page publication is not a complete injunction or subsequent-litigation review. Retention prohibitions are not evidence that a vendor actually deletes data.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

Texas H.B.581, 89th Regular Session — enrolled text

IC-SYN-S10 · Texas Legislature

Version: Enrolled amendment; Chapter 129B identifies enacted amendments effective 1 September 2025.

Reviewed: · Selected substantive primary-document text review

Passages: Sections amending 129B.001–.003; new .0045; amendments to .005–.006.

Narrow support: A creation-tool branch was added without using the publication branch’s one-third test. Its exception requires both acknowledged terms and affirmative measures; source age and consent are separate.

Limitation: An enrolled version and statutory annotation establish the text used here, not a complete bill-action or constitutional-litigation history. The June 2025 Paxton opinion did not decide this later amendment.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

Free Speech Coalition, Inc. v. Paxton, No. 23-1122

IC-SYN-S11 · Supreme Court of the United States

Version: June 27, 2025 opinion; 606 U.S. 461. Six-Justice majority; Kagan dissent joined by Sotomayor and Jackson.

Reviewed: · Primary judicial text and selected PDF pages visually reviewed

Passages: Case posture and holding; majority discussion and printed page 36 disposition; dissent’s adult-speech, disclosure and tailoring discussion, including printed page 5.

Narrow support: The majority applies intermediate scrutiny and affirms the Fifth Circuit judgment on the challenged age-verification requirements. The dissent would require strict scrutiny for the burden on protected adult expression.

Limitation: Selected text plus two page images (PDF indices 39 and 44); not a complete later-docket audit or a ruling on every age gate, health-warning requirement, or H.B.581 creation-tool provision.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

NIST IR 8525 — Face Analysis Technology Evaluation: Age Estimation and Verification

IC-SYN-S12 · NIST; Kayee Hanaoka, Patrick Grother, Mei Ngan, Joyce Yang, George Quinn and Austin Hom

Version: May 2024 research report; historical evaluated algorithms and datasets, not a current vendor certification.

Reviewed: · Primary research text and selected PDF pages visually reviewed

Passages: Executive and technical summaries, including printed pages 1–3; Table 15 and accompanying discussion/figure on printed page 23.

Narrow support: Aggregate estimation error does not alone determine age-verification threshold errors; performance depends on age distribution and other evaluated conditions.

Limitation: Selected text and page images (PDF indices 10 and 30). Evaluation uses photographs and specified algorithms, not live service enrollment, proof of unlinkability, or a legal adequacy threshold.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

ISO/IEC 27566-1:2025 — Age assurance systems, Part 1: Framework

IC-SYN-S13 · ISO/IEC

Version: First edition; catalogue publication month December 2025; 29 pages.

Reviewed: · Official catalogue metadata and abstract only — normative text not reviewed

Passages: Official title, abstract, publication/edition metadata.

Narrow support: The standard’s identity and framework subject are established. The original report’s law-firm article cannot be described as the full ISO normative text.

Limitation: Only the official catalogue was reviewed. No specific accuracy threshold, zero-knowledge implementation, fallback rule or compliance claim is derived from unread normative clauses.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

Texas H.B.1181, 88th Regular Session — enrolled text

IC-SYN-S14 · Texas Legislature

Version: Historical 2023 enactment text, distinguished from Chapter 129B after the 2025 amendment.

Reviewed: · Selected substantive primary-document text review

Passages: 129B.002(a)–(b), .003, .005 and .006 as originally added.

Narrow support: The original publication threshold and non-retention obligation can be located independently of the later creation-tool amendment.

Limitation: Historical legislative text is not the whole current chapter and does not establish subsequent injunction status.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

Verifiable Credentials Data Model v2.0

IC-SYN-S15 · W3C Verifiable Credentials Working Group

Version: W3C Recommendation dated 15 May 2025.

Reviewed: · Selected substantive primary-document text review

Passages: Sections 5.7 and 8.4–8.11 on zero-knowledge proofs, correlation, abstract claims and minimization.

Narrow support: A credential is not automatically a zero-knowledge or unlinkable presentation. Identifier, signature, metadata and validation interactions can create correlation.

Limitation: Selected specification passages, not a deployed age-credential scheme, conformance test, legal acceptance decision or proof that an issuer never learns identity.

Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.

California Civil Code §1798.140 — definitions

IC-SYN-S16 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed amendment note identifies Stats. 2025, Ch. 67, §27 (AB1170), effective 1 January 2026.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (c), (d), (i), (m), (v)(1)(F)/(K), (v)(2)–(4), (y), (z), (ae), and (ag).

Narrow support: Non-neural profiling inferences can be personal information. Sensitive categories extend beyond neural measurements. The format provision includes AI systems capable of outputting personal information.

Limitation: Selected definitions do not determine every exemption, business threshold, injury, or remedy. Not every model is personal information; this provision does not grant the model its own privacy rights.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.100 — collection and purpose limitations

IC-SYN-S17 · California Legislature

Version: Current endpoint retrieved 6 September 2026; selected enacted CCPA text.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(e), particularly (a)(3), (c), and (d).

Narrow support: Notice, proportionate purpose-related collection/use/retention, contractual conditions, and reasonable security contradict a categorical unregulated-collection claim.

Limitation: Applicability and other statutory exceptions must be satisfied. This is not a universal opt-in requirement or evidence of provider compliance.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.121 — right to limit sensitive-information use

IC-SYN-S18 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed AB3286 amendment effective 1 January 2025.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(d), including requested-service/permitted-use qualifications and the no-inference-purpose clause.

Narrow support: A use-limitation right differs from an absolute processing ban. Information outside this particular limitation can remain personal information governed by other provisions.

Limitation: No inference is made that every disclosure is a statutory sale/share or that lack of a limitation request authorizes all processing.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.106 — right to correction

IC-SYN-S19 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed AB3286 amendment effective 1 January 2025.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(c).

Narrow support: A verified consumer can request correction; the nature and purpose of the information and commercially reasonable efforts matter.

Limitation: A right to request is not automatic acceptance of every challenge or proof that an opaque probabilistic profile can readily be discovered.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

California Civil Code §1798.120 — opt-out of sale or sharing

IC-SYN-S20 · California Legislature

Version: Current endpoint retrieved 6 September 2026; displayed AB1824 amendment effective 1 January 2025.

Reviewed: · Selected substantive primary-document review

Passages: Subdivisions (a)–(e), with the requirement to honor opt-out directions.

Narrow support: Qualifying sale/sharing choices are distinct from collection, inference, correction, and service use.

Limitation: Must be read with the statutory definitions and exceptions; not a universal right to stop all transfers or erase any related artifact.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

CCPA updates, cybersecurity, risk assessment and ADMT — approved text

IC-SYN-S21 · California Privacy Protection Agency

Version: Approved-text publication; associated agency announcement states effective 1 January 2026 with phased compliance.

Reviewed: · Selected substantive primary-document review

Passages: §7023, printed pp.43–47 (correction); §7200, printed p.112 (significant decisions and 1 January 2027 compliance). Selected marked-up pages inspected visually.

Narrow support: Correction considers context, source and documentation; corrected records must remain corrected, with specified backup timing. The ADMT article has a later compliance date and a significant-decision trigger.

Limitation: The 127-page document was not reviewed in full. No blanket current opt-out from all profiling is inferred; no whole-program certification of compliance.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

HB24-1058 — Protect Privacy of Biological Data, signed act

IC-SYN-S22 · Colorado General Assembly

Version: Signed 2024 act; historical enacted amendment, not a consolidated September 2026 code.

Reviewed: · Selected substantive primary-document review

Passages: §§1–3, particularly §2 on printed p.4: biological-data identification qualifier, express neural inclusion, and separate neural definition.

Narrow support: The biological definition contains used-or-intended-for-identification wording as well as express neural inclusion. Legislative concern is distinct from a measured ability to read thought.

Limitation: No judicial resolution of the relationship between the qualifier and the final inclusion sentence was obtained. The act is not a universal unconditional control over all bodily telemetry.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

Colorado Revised Statutes 2025, Title 6 — selected CPA text

IC-SYN-S23 · Colorado General Assembly / Office of Legislative Legal Services publication

Version: 2025 compilation at olls.info; retrieved 6 September 2026. Not a certified current-2026 consolidation.

Reviewed: · Selected substantive primary-document review

Passages: §§6-1-1303(2.2), (6), (16.7)–(18), (24); 1304; 1306; 1307; 1308; 1310–1311.

Narrow support: The compilation distinguishes linkable personal data, sensitive classes, purpose/consent duties, correction, deidentification and bounded opt-outs.

Limitation: 2026 session changes were not exhaustively reconciled. The official legislative index route to downloads returned an error; the hosting chain and a certified current copy were not independently established. Used as a dated statutory-text comparison alongside the signed act and official rules, not sole evidence of current legal force.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

Colorado Privacy Act Rules — 2023 issued version

IC-SYN-S24 · Colorado Department of Law

Version: AG-hosted issued rules, effective 1 July 2023 under Rule 1.03; later consolidated rule history not completed.

Reviewed: · Selected substantive primary-document review

Passages: Rules 1.03–1.04, 2.02 (Sensitive Data Inferences), 4.05, 6.06–6.10, especially 6.10(A)–(C), printed pp.24–25.

Narrow support: Sensitive-data inferences are expressly addressed. The over-thirteen consent exception requires all four conditions, including no transfer to processors/affiliates/third parties and deletion within the earlier specified time.

Limitation: This is a dated primary rule text, not a claim that every 2023 provision is unchanged in 2026. It does not supply an exemption for internal maintenance or for merely using a short retention label.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

In re InMarket Media, LLC — Decision and Order, C-4803

IC-SYN-S25 · Federal Trade Commission

Version: Final respondent-specific administrative consent order, issued 29 April 2024 (printed p.14); publication/finalization announced 1 May 2024. Part XVIII ties effectiveness to publication as a final order.

Reviewed: · Selected substantive primary-document review

Passages: Opening admissions; definitions of Deidentified, Location Data and Sensitive Location Data; Parts II–IV, VIII–X, XII(A)–(C), XIII(C), XVIII. Selected pages 5, 9 and 10 inspected visually. Issuance page 14 visually checked.

Narrow support: Distinct restrictions address location-data sale, specified sensitive-location products, consent, retention and different historic-data deletion paths. Qualified-employee roles appear in Parts IV and XIII.

Limitation: Not a generally applicable privacy statute or admission of the complaint allegations. No subsequent compliance audit, live implementation, or general prohibition on all inferences was established.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

InMarket Media — Complaint

IC-SYN-S26 · Federal Trade Commission

Version: Docketed complaint, C-4803; issuance line gives 29 April 2024; published with finalization materials. Distinct from both earlier proposed-settlement publicity and the final order.

Reviewed: · Selected substantive primary-document review

Passages: Textual allegations on location collection, SDKs, mobile identifiers, targeting and disclosure, paragraphs 10–20 and 27 onward.

Narrow support: The agency alleged practices linking location information to marketing; the complaint supplies the theory and context of the remedy.

Limitation: Allegations are not independently reproduced events or findings admitted by the respondent. No inference that every health/religious inference has been proven unlawful. Interface illustrations are not relied upon as separately inspected evidence. The last-page image request failed; issuance is based on the parsed text and associated docket, not a claimed image inspection.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

CPPA announces approval of CCPA regulations

IC-SYN-S27 · California Privacy Protection Agency

Version: Agency announcement of OAL approval on 22 September 2025.

Reviewed: · Official status and commencement review

Passages: Approval and effective-date paragraphs; phased ADMT compliance, read with §7200 in the approved text.

Narrow support: The package took effect in 2026 while specified ADMT compliance is phased to 2027.

Limitation: Status announcement only; the approved text controls operative details. It is not a current audit of every later rule change.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

FTC finalizes InMarket order

IC-SYN-S28 · Federal Trade Commission

Version: Official finalization announcement, distinct from the January proposal.

Reviewed: · Official status and identity review

Passages: Opening finalization and order-summary paragraphs.

Narrow support: Corroborates the final-order publication date, replacing the submitted January 1 placeholder.

Limitation: Summary is not substituted for the decision terms, respondent scope, consent qualifications or deletion provisos.

Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.

Unperformed reviews

Complete Colorado 2026 statutory/rule reconciliation, full CPPA regulations, adjudicated probabilistic-profile remedies, real-provider correction/deletion and recovery evidence, plus prior open ISO/trial and other report repairs remain unperformed. No empirical profiling, deployment, legal certification or automatic policy adoption is claimed.

The same source records as JSON · Return to the library