⭐ Star on GitHub

Append-only. Newest entries at the bottom.


2026-07-28 — Initial ingest

Sources ingested: raw/AI-regulations/ — 2 files, ~107,700 words.

  • Regulation - EU - 2024_1689.md — full official text of the EU AI Act (CELEX:32024R1689), ~105,700 words
  • Small Businesses' Guide to the AI Act...md — ~1,900 words

Reading coverage: The Regulation is too large to read in full. Read in full: Chapter II (Art 5), Arts 6–7, Art 8, Art 15, Art 50, Arts 51–56, Art 73, Art 99, Arts 112–113, Annex III opening sections. Read at heading/opening-paragraph level: Arts 9–14, remaining chapters. Recitals not read.

Anything on these pages sourced from an unread portion would be a defect — all quotations here come from the passages actually read.

Also drawn on (primary home is laws-wiki, cited here where they interpret specific articles): the EU AI Act explainer set in raw/Laws/ — Enforcement of Chapter V, Modifying AI, Art 50 transparency guide, GPAI guidelines, GPAI providers, staffing businesses.

Pages created (13):

  • index.md, log.md
  • eu-ai-act.md — structure and architecture
  • prohibited-ai-practices.md — Art 5
  • high-risk-ai-systems.md — Arts 6–7, Annex III
  • high-risk-requirements.md — Arts 8–15
  • article-15-cybersecurity.md — Art 15
  • article-50-transparency.md — Art 50
  • gpai-and-systemic-risk.md — Arts 51–56
  • serious-incident-reporting.md — Art 73 + Code of Practice C9
  • enforcement-and-penalties.md — Art 99, Ch V enforcement
  • ai-act-timeline.md — Arts 112–113
  • provider-vs-deployer.md — roles and modification
  • ai-act-and-smes.md

Findings recorded:

  • Art 15(5) names five attack classes but not prompt injection or indirect/tool injection — the list predates the agentic threat model and derives from the adversarial-ML canon (same three classes NIST names).
  • Two incident-reporting regimes with different clocks; the Code of Practice’s 5-day cybersecurity-breach tier has no Art 73 equivalent.
  • GPAI obligations bound from 2 Aug 2025 but Commission enforcement powers only from 2 Aug 2026.
  • Profiling defeats the Art 6(3) derogation unconditionally.

Root index updated: yes.

Open items:

  • Annexes I, II, IV, XI, XII, XIII not read in detail. Annex XIII (systemic-risk designation criteria) and Annex IV (technical documentation contents) are the two most worth a follow-up pass.
  • Recitals unread; they carry interpretive weight for Art 5 and Art 6(3).

2026-07-28 — Cross-linking new collections

article-15-cybersecurity.md updated in two places:

  • The Art 15(5) mapping table now points at the new Data Poisoning and Model Theft collections rather than only at PITAX clusters.
  • Added a caution on the “detect” limb: if poisoning success depends on absolute sample count rather than proportion, proportional anomaly detection cannot satisfy it at any dataset scale. Sources disagree; linked to data-poisoning-wiki/poisoning-thresholds.md.
  • ATLAS noted as ingested, with its 114 Agentic AI technique tags flagged against Art 15(5)‘s silence on the agentic surface.