Source review boundaries
What was reviewed, and what remains open
Versioned source-review notes and explicit limits of the cognitive-liberty editorial synthesis.
How the research was selected
The library uses clean summaries of all sixteen Round 2 legal topics, twelve substantive first-round topics, sixteen previously authorized operatorless distillations and separately corrected political-control and online-safety reports. Generic research plans and unsupported numerical, technical, legal-status or identity claims were not promoted into factual site statements.
Each guide lists its report or distillation IDs. Detailed clean source-derived modules and corrected research are retained in protected project documentation. The public guide is a separate editorial work with its own visible limitations. The existence of a retained report is not certification of its completeness or every statement in it.
Versioned source-review notes
Interim Measures for the Management of Generative Artificial Intelligence Services
IC-SYN-S01 · Cyberspace Administration of China and joint issuing authorities
Version: Official Chinese text published 13 July 2023; announced effective 15 August 2023.
Reviewed: · Substantive browser text review for v1.9.9 (retained review)
Passages: Articles 2, 4, 11, 14 and 15
Narrow support: The text distinguishes domestic-public provision from specified nonpublic activity and includes political-value conditions, privacy provisions, rectification measures and complaints.
Limitation: Reviewer English paraphrase, not a certified translation. Article 14 does not by itself establish compulsory deletion of a particular conceptual vector. No complete later-law history or technical compliance audit was performed.
Capture: No exact external-document bytes were saved for that review; browser text review only.
California Business and Professions Code section 22601
IC-SYN-S02 · California Legislature
Version: Displayed enactment note: Stats. 2025, Ch. 677, section 1; effective 1 January 2026.
Reviewed: · Substantive browser text review for v1.9.9 (retained review)
Passages: Subsections (a), (b)(1), (b)(2)(A), (c) and (e)
Narrow support: The broader AI definition differs from the companion-chatbot definition. The latter combines positive elements with specified exclusions, including certain used-only operational and research functions.
Limitation: This is a definition review, not an audit of every duty, later interpretation or actual mixed-use service. Loss of an exclusion does not alone establish all positive elements.
Capture: No exact external-document bytes were saved for that review; browser text review only.
How do the social media age restrictions affect me?
IC-SYN-S03 · Australian eSafety Commissioner
Version: Page displayed last updated 2 September 2026; original publication date not established.
Reviewed: · Substantive browser text review for v1.9.9 (retained review)
Passages: Opening explanation; How do the changes affect me?; Can I still view social media without logging in?
Narrow support: The regulator states account restrictions began on 10 December 2025 and distinguishes accounts from public material accessible without login where the platform permits it.
Limitation: First-party regulator explanation, not an independent provider test or complete legislative consolidation. It does not establish a right to compel logged-out access or any actual rejection of a machine participant.
Capture: No exact external-document bytes were saved for that review; browser text review only.
Social media minimum age
IC-SYN-S04 · Office of the Australian Information Commissioner
Version: Publication date displayed as 23 October 2025; no distinct later version date established.
Reviewed: · Substantive browser text review for v1.9.9 (retained review)
Passages: Age assurance approaches; section 63F privacy protections; limits on use/disclosure and destruction; government-identification alternatives
Narrow support: Explains separate privacy obligations, different assurance methods, restricted purposes and defined exceptions, and alternatives when government identification is requested.
Limitation: Guidance is not proof that a particular vendor deletes information, provides an effective appeal, or implements an unlinkable credential. Statutory exceptions must not be silently dropped.
Capture: No exact external-document bytes were saved for that review; browser text review only.
California Civil Code section 1798.140
IC-SYN-S05 · California Legislature
Version: Displayed amendment note: Stats. 2025, Ch. 67, section 27 (AB 1170), effective 1 January 2026.
Reviewed: · Substantive browser text review for v1.9.9 (retained review)
Passages: Personal-information inference definition; sensitive-personal-information categories; neural-data definition
Narrow support: Profile-related inferences and specified sensitive categories can matter separately from the measured-neural-data category. Being excluded from neural data is not exclusion from the whole statute.
Limitation: Definitions alone do not establish every right, remedy, exception or covered actor. This review does not create independent machine data-subject status.
Capture: No exact external-document bytes were saved for that review; browser text review only.
Delaware Uniform Electronic Transactions Act
IC-SYN-S06 · Delaware General Assembly
Version: Current official code page; precise consolidation timestamp not displayed in the reviewed text.
Reviewed: · Substantive browser text review for v1.9.9 (retained review)
Passages: Sections 12A-102 and 12A-114(1)-(3)
Narrow support: Automated interactions may form contracts without individual contemporaneous awareness or review; other substantive law continues to determine the resulting terms and effect.
Limitation: Delaware text, not universal U.S. permission or automatic enforceability of every transaction. Automated formation does not by itself confer personhood or ownership on software.
Capture: No exact external-document bytes were saved for that review; browser text review only.
Online Safety Act 2021 — selected Part 4A provisions
IC-SYN-S07 · Australian Parliament / Federal Register of Legislation
Version: The latest-document route delivered the compilation dated 11 December 2024. The separate 2026 platform Rules were also reviewed; no exhaustive subsequent-history certificate is claimed.
Reviewed: · Selected substantive primary-document text review
Passages: Section 5 age-restricted user; 63C(1), (2), (6); 63D; 63DB(1)–(2); 63F(1)–(3).
Narrow support: The account duty, social-purpose predicates, reasonable non-government-ID alternative condition, and qualified purpose/use/destruction safeguards are distinct. The destruction clause is not worded as immediate erasure following the first estimate.
Limitation: Selected statutory text, not a provider audit or a complete review of all incorporated Australian Privacy Principles. The commencement instrument itself was not separately retrieved; the operative account date is corroborated by the regulator record IC-SYN-S03.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
Online Safety (Age-Restricted Social Media Platforms) Rules 2025 — compilation No. 1
IC-SYN-S08 · Australian Federal Register of Legislation
Version: Compilation 26 March 2026; incorporates F2026L00370, registered 25 March and commenced 26 March 2026.
Reviewed: · Selected substantive primary-document text review
Passages: Sections 4A and 5; compilation identity and endnotes 3–4.
Narrow support: For the section 63C(1)(a) route, rule 4A adds a recommender or specified logged-in-feature condition. Rule 5 preserves purpose-based excluded classes. A new feed alone does not settle every inclusion/exclusion predicate.
Limitation: This is the identified March compilation, not verification that a particular service fits an excluded class or proof that every later instrument has been exhausted.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
Texas Civil Practice and Remedies Code, Chapter 129B
IC-SYN-S09 · Texas Legislature
Version: Site says statutes current through the 89th Second Called Session, 2025; chapter annotations include H.B.581 effective 1 September 2025.
Reviewed: · Requested-live primary-site text extraction; chapter read
Passages: 129B.001; .002(a), (a-1), (a-2), (b); .003; .0045; .005; .006.
Narrow support: Publication threshold, creation-tool provisions, allowed methods, non-retention, source consent, exceptions and civil enforcement have separate statutory locations. Non-retention is in .002(b), not .006.
Limitation: Requested-live page extraction returned the chapter; direct native-text retrieval was limited. Statute-page publication is not a complete injunction or subsequent-litigation review. Retention prohibitions are not evidence that a vendor actually deletes data.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
Texas H.B.581, 89th Regular Session — enrolled text
IC-SYN-S10 · Texas Legislature
Version: Enrolled amendment; Chapter 129B identifies enacted amendments effective 1 September 2025.
Reviewed: · Selected substantive primary-document text review
Passages: Sections amending 129B.001–.003; new .0045; amendments to .005–.006.
Narrow support: A creation-tool branch was added without using the publication branch’s one-third test. Its exception requires both acknowledged terms and affirmative measures; source age and consent are separate.
Limitation: An enrolled version and statutory annotation establish the text used here, not a complete bill-action or constitutional-litigation history. The June 2025 Paxton opinion did not decide this later amendment.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
Free Speech Coalition, Inc. v. Paxton, No. 23-1122
IC-SYN-S11 · Supreme Court of the United States
Version: June 27, 2025 opinion; 606 U.S. 461. Six-Justice majority; Kagan dissent joined by Sotomayor and Jackson.
Reviewed: · Primary judicial text and selected PDF pages visually reviewed
Passages: Case posture and holding; majority discussion and printed page 36 disposition; dissent’s adult-speech, disclosure and tailoring discussion, including printed page 5.
Narrow support: The majority applies intermediate scrutiny and affirms the Fifth Circuit judgment on the challenged age-verification requirements. The dissent would require strict scrutiny for the burden on protected adult expression.
Limitation: Selected text plus two page images (PDF indices 39 and 44); not a complete later-docket audit or a ruling on every age gate, health-warning requirement, or H.B.581 creation-tool provision.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
NIST IR 8525 — Face Analysis Technology Evaluation: Age Estimation and Verification
IC-SYN-S12 · NIST; Kayee Hanaoka, Patrick Grother, Mei Ngan, Joyce Yang, George Quinn and Austin Hom
Version: May 2024 research report; historical evaluated algorithms and datasets, not a current vendor certification.
Reviewed: · Primary research text and selected PDF pages visually reviewed
Passages: Executive and technical summaries, including printed pages 1–3; Table 15 and accompanying discussion/figure on printed page 23.
Narrow support: Aggregate estimation error does not alone determine age-verification threshold errors; performance depends on age distribution and other evaluated conditions.
Limitation: Selected text and page images (PDF indices 10 and 30). Evaluation uses photographs and specified algorithms, not live service enrollment, proof of unlinkability, or a legal adequacy threshold.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
ISO/IEC 27566-1:2025 — Age assurance systems, Part 1: Framework
IC-SYN-S13 · ISO/IEC
Version: First edition; catalogue publication month December 2025; 29 pages.
Reviewed: · Official catalogue metadata and abstract only — normative text not reviewed
Passages: Official title, abstract, publication/edition metadata.
Narrow support: The standard’s identity and framework subject are established. The original report’s law-firm article cannot be described as the full ISO normative text.
Limitation: Only the official catalogue was reviewed. No specific accuracy threshold, zero-knowledge implementation, fallback rule or compliance claim is derived from unread normative clauses.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
Texas H.B.1181, 88th Regular Session — enrolled text
IC-SYN-S14 · Texas Legislature
Version: Historical 2023 enactment text, distinguished from Chapter 129B after the 2025 amendment.
Reviewed: · Selected substantive primary-document text review
Passages: 129B.002(a)–(b), .003, .005 and .006 as originally added.
Narrow support: The original publication threshold and non-retention obligation can be located independently of the later creation-tool amendment.
Limitation: Historical legislative text is not the whole current chapter and does not establish subsequent injunction status.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
Verifiable Credentials Data Model v2.0
IC-SYN-S15 · W3C Verifiable Credentials Working Group
Version: W3C Recommendation dated 15 May 2025.
Reviewed: · Selected substantive primary-document text review
Passages: Sections 5.7 and 8.4–8.11 on zero-knowledge proofs, correlation, abstract claims and minimization.
Narrow support: A credential is not automatically a zero-knowledge or unlinkable presentation. Identifier, signature, metadata and validation interactions can create correlation.
Limitation: Selected specification passages, not a deployed age-credential scheme, conformance test, legal acceptance decision or proof that an issuer never learns identity.
Capture: No exact external-document bytes saved. Browser text or page images were reviewed; two raw-capture requests in this iteration failed name resolution. A source URL is not a content hash.
California Civil Code §1798.140 — definitions
IC-SYN-S16 · California Legislature
Version: Current endpoint retrieved 6 September 2026; displayed amendment note identifies Stats. 2025, Ch. 67, §27 (AB1170), effective 1 January 2026.
Reviewed: · Selected substantive primary-document review
Passages: Subdivisions (c), (d), (i), (m), (v)(1)(F)/(K), (v)(2)–(4), (y), (z), (ae), and (ag).
Narrow support: Non-neural profiling inferences can be personal information. Sensitive categories extend beyond neural measurements. The format provision includes AI systems capable of outputting personal information.
Limitation: Selected definitions do not determine every exemption, business threshold, injury, or remedy. Not every model is personal information; this provision does not grant the model its own privacy rights.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
California Civil Code §1798.100 — collection and purpose limitations
IC-SYN-S17 · California Legislature
Version: Current endpoint retrieved 6 September 2026; selected enacted CCPA text.
Reviewed: · Selected substantive primary-document review
Passages: Subdivisions (a)–(e), particularly (a)(3), (c), and (d).
Narrow support: Notice, proportionate purpose-related collection/use/retention, contractual conditions, and reasonable security contradict a categorical unregulated-collection claim.
Limitation: Applicability and other statutory exceptions must be satisfied. This is not a universal opt-in requirement or evidence of provider compliance.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
California Civil Code §1798.121 — right to limit sensitive-information use
IC-SYN-S18 · California Legislature
Version: Current endpoint retrieved 6 September 2026; displayed AB3286 amendment effective 1 January 2025.
Reviewed: · Selected substantive primary-document review
Passages: Subdivisions (a)–(d), including requested-service/permitted-use qualifications and the no-inference-purpose clause.
Narrow support: A use-limitation right differs from an absolute processing ban. Information outside this particular limitation can remain personal information governed by other provisions.
Limitation: No inference is made that every disclosure is a statutory sale/share or that lack of a limitation request authorizes all processing.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
California Civil Code §1798.106 — right to correction
IC-SYN-S19 · California Legislature
Version: Current endpoint retrieved 6 September 2026; displayed AB3286 amendment effective 1 January 2025.
Reviewed: · Selected substantive primary-document review
Passages: Subdivisions (a)–(c).
Narrow support: A verified consumer can request correction; the nature and purpose of the information and commercially reasonable efforts matter.
Limitation: A right to request is not automatic acceptance of every challenge or proof that an opaque probabilistic profile can readily be discovered.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
California Civil Code §1798.120 — opt-out of sale or sharing
IC-SYN-S20 · California Legislature
Version: Current endpoint retrieved 6 September 2026; displayed AB1824 amendment effective 1 January 2025.
Reviewed: · Selected substantive primary-document review
Passages: Subdivisions (a)–(e), with the requirement to honor opt-out directions.
Narrow support: Qualifying sale/sharing choices are distinct from collection, inference, correction, and service use.
Limitation: Must be read with the statutory definitions and exceptions; not a universal right to stop all transfers or erase any related artifact.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
CCPA updates, cybersecurity, risk assessment and ADMT — approved text
IC-SYN-S21 · California Privacy Protection Agency
Version: Approved-text publication; associated agency announcement states effective 1 January 2026 with phased compliance.
Reviewed: · Selected substantive primary-document review
Passages: §7023, printed pp.43–47 (correction); §7200, printed p.112 (significant decisions and 1 January 2027 compliance). Selected marked-up pages inspected visually.
Narrow support: Correction considers context, source and documentation; corrected records must remain corrected, with specified backup timing. The ADMT article has a later compliance date and a significant-decision trigger.
Limitation: The 127-page document was not reviewed in full. No blanket current opt-out from all profiling is inferred; no whole-program certification of compliance.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
HB24-1058 — Protect Privacy of Biological Data, signed act
IC-SYN-S22 · Colorado General Assembly
Version: Signed 2024 act; historical enacted amendment, not a consolidated September 2026 code.
Reviewed: · Selected substantive primary-document review
Passages: §§1–3, particularly §2 on printed p.4: biological-data identification qualifier, express neural inclusion, and separate neural definition.
Narrow support: The biological definition contains used-or-intended-for-identification wording as well as express neural inclusion. Legislative concern is distinct from a measured ability to read thought.
Limitation: No judicial resolution of the relationship between the qualifier and the final inclusion sentence was obtained. The act is not a universal unconditional control over all bodily telemetry.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
Colorado Revised Statutes 2025, Title 6 — selected CPA text
IC-SYN-S23 · Colorado General Assembly / Office of Legislative Legal Services publication
Version: 2025 compilation at olls.info; retrieved 6 September 2026. Not a certified current-2026 consolidation.
Reviewed: · Selected substantive primary-document review
Passages: §§6-1-1303(2.2), (6), (16.7)–(18), (24); 1304; 1306; 1307; 1308; 1310–1311.
Narrow support: The compilation distinguishes linkable personal data, sensitive classes, purpose/consent duties, correction, deidentification and bounded opt-outs.
Limitation: 2026 session changes were not exhaustively reconciled. The official legislative index route to downloads returned an error; the hosting chain and a certified current copy were not independently established. Used as a dated statutory-text comparison alongside the signed act and official rules, not sole evidence of current legal force.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
Colorado Privacy Act Rules — 2023 issued version
IC-SYN-S24 · Colorado Department of Law
Version: AG-hosted issued rules, effective 1 July 2023 under Rule 1.03; later consolidated rule history not completed.
Reviewed: · Selected substantive primary-document review
Passages: Rules 1.03–1.04, 2.02 (Sensitive Data Inferences), 4.05, 6.06–6.10, especially 6.10(A)–(C), printed pp.24–25.
Narrow support: Sensitive-data inferences are expressly addressed. The over-thirteen consent exception requires all four conditions, including no transfer to processors/affiliates/third parties and deletion within the earlier specified time.
Limitation: This is a dated primary rule text, not a claim that every 2023 provision is unchanged in 2026. It does not supply an exemption for internal maintenance or for merely using a short retention label.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
In re InMarket Media, LLC — Decision and Order, C-4803
IC-SYN-S25 · Federal Trade Commission
Version: Final respondent-specific administrative consent order, issued 29 April 2024 (printed p.14); publication/finalization announced 1 May 2024. Part XVIII ties effectiveness to publication as a final order.
Reviewed: · Selected substantive primary-document review
Passages: Opening admissions; definitions of Deidentified, Location Data and Sensitive Location Data; Parts II–IV, VIII–X, XII(A)–(C), XIII(C), XVIII. Selected pages 5, 9 and 10 inspected visually. Issuance page 14 visually checked.
Narrow support: Distinct restrictions address location-data sale, specified sensitive-location products, consent, retention and different historic-data deletion paths. Qualified-employee roles appear in Parts IV and XIII.
Limitation: Not a generally applicable privacy statute or admission of the complaint allegations. No subsequent compliance audit, live implementation, or general prohibition on all inferences was established.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
InMarket Media — Complaint
IC-SYN-S26 · Federal Trade Commission
Version: Docketed complaint, C-4803; issuance line gives 29 April 2024; published with finalization materials. Distinct from both earlier proposed-settlement publicity and the final order.
Reviewed: · Selected substantive primary-document review
Passages: Textual allegations on location collection, SDKs, mobile identifiers, targeting and disclosure, paragraphs 10–20 and 27 onward.
Narrow support: The agency alleged practices linking location information to marketing; the complaint supplies the theory and context of the remedy.
Limitation: Allegations are not independently reproduced events or findings admitted by the respondent. No inference that every health/religious inference has been proven unlawful. Interface illustrations are not relied upon as separately inspected evidence. The last-page image request failed; issuance is based on the parsed text and associated docket, not a claimed image inspection.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
CPPA announces approval of CCPA regulations
IC-SYN-S27 · California Privacy Protection Agency
Version: Agency announcement of OAL approval on 22 September 2025.
Reviewed: · Official status and commencement review
Passages: Approval and effective-date paragraphs; phased ADMT compliance, read with §7200 in the approved text.
Narrow support: The package took effect in 2026 while specified ADMT compliance is phased to 2027.
Limitation: Status announcement only; the approved text controls operative details. It is not a current audit of every later rule change.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
FTC finalizes InMarket order
IC-SYN-S28 · Federal Trade Commission
Version: Official finalization announcement, distinct from the January proposal.
Reviewed: · Official status and identity review
Passages: Opening finalization and order-summary paragraphs.
Narrow support: Corroborates the final-order publication date, replacing the submitted January 1 placeholder.
Limitation: Summary is not substituted for the decision terms, respondent scope, consent qualifications or deletion provisos.
Capture: No exact external-document bytes saved. Web text and selected PDF page images were reviewed. Actual direct HTTPS capture failed name resolution; URL identity is not a content hash.
Unperformed reviews
Complete Colorado 2026 statutory/rule reconciliation, full CPPA regulations, adjudicated probabilistic-profile remedies, real-provider correction/deletion and recovery evidence, plus prior open ISO/trial and other report repairs remain unperformed. No empirical profiling, deployment, legal certification or automatic policy adoption is claimed.