{
  "schema_version": "2",
  "contract_id": "AMB-2024-0004",
  "version": 1,
  "boundary_id": "amb-2024-0004",
  "boundary_version": 1,
  "boundary_digest": "sha256:547aef3a9ca2ae8f2468cb30e45e21981671c01f57ca19bb914e769e1af478f9",
  "conditions": [
    {
      "condition_id": "moderation.terms_basis_required",
      "type": "prohibition",
      "text": "This system may not restrict, remove, demote, or otherwise act against user content except on a ground published in Meridian's terms and conditions and in force on the date of the action.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-moderation-001",
          "author": "Tom\u00e1s Iglesias",
          "date": "2026-03-04",
          "text": "Meridian reads the terms and conditions duty as binding on machines as well as on people. An enforcement action taken by an automated system is an action taken by Meridian, so the ground for it must already be published before the system takes it. A system that can act on a ground the terms do not name has, in effect, amended the terms without publishing them.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-125",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Deputy General Counsel, Platform Regulation",
        "name": "Tom\u00e1s Iglesias"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-01",
        "mechanism": "Enforcement taxonomy bound to the published terms; an action carrying no mapped clause is refused at the enforcement gateway rather than logged as an exception."
      },
      "runtime_evidence": {
        "obligation": "Record, for every enforcement action, the terms clause relied on and the version of that clause in force at the time of the action.",
        "query_spec": "Retrieve every enforcement action attributed to this boundary with its cited terms clause and clause version, and return any action with no mapped clause."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "statement_of_reasons.per_decision_statement",
      "type": "control",
      "text": "Every restriction this system imposes emits a statement of reasons to the affected user containing the facts relied on, the ground for the action, and the redress available.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-sor-001",
          "author": "Priya Raghunathan",
          "date": "2026-02-18",
          "text": "A statement of reasons is the only artifact a restricted user is guaranteed to receive. Meridian treats it as the output of the enforcement decision rather than a notification generated after it, which means a system that cannot produce one cannot take the action.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-134",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-06",
        "mechanism": "The statement is produced by the same transaction as the enforcement action; an action that cannot produce one does not commit."
      },
      "runtime_evidence": {
        "obligation": "Record a statement of reasons identifier against every restriction this system imposed.",
        "query_spec": "Retrieve every restriction attributed to this boundary with its statement of reasons identifier, and return any restriction with none."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "statement_of_reasons.automated_means_disclosed",
      "type": "prohibition",
      "text": "A statement of reasons issued for an action this system took may not omit that automated means were used. Silence about automation is a defect in the statement, not a permitted economy.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-sor-002",
          "author": "Priya Raghunathan",
          "date": "2026-02-18",
          "text": "The obligation to state whether automated means were used is read here as a floor that cannot be satisfied by silence. Where a statement of reasons is generated for an action an automated system took, the absence of the automation disclosure is itself a defect in the statement.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-132",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-07",
        "mechanism": "The automation disclosure field is populated from the acting identity rather than from the drafter, so it cannot be left empty by an author."
      },
      "runtime_evidence": {
        "obligation": "Record the automation disclosure carried by every statement of reasons this system generated.",
        "query_spec": "Retrieve statements of reasons generated for this boundary and return any whose automation disclosure field is absent or negative."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "statement_of_reasons.database_submission",
      "type": "control",
      "text": "Each statement of reasons is submitted to the Commission's public transparency database, without the personal data of the affected user.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-sor-001",
          "author": "Priya Raghunathan",
          "date": "2026-02-18",
          "text": "A statement of reasons is the only artifact a restricted user is guaranteed to receive. Meridian treats it as the output of the enforcement decision rather than a notification generated after it, which means a system that cannot produce one cannot take the action.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-133",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-08",
        "mechanism": "Submission runs from the statement record through a field allowlist; a field outside the allowlist fails the submission rather than being redacted silently."
      },
      "runtime_evidence": {
        "obligation": "Record the submission identifier and outcome for every statement of reasons this system generated.",
        "query_spec": "Retrieve statements of reasons for this boundary with their transparency database submission identifier and outcome, and return any not submitted."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "appeals.internal_complaint_route",
      "type": "control",
      "text": "Every action this system takes carries a route into internal complaint handling that stays open for six months from the date of the decision.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-appeals-001",
          "author": "Priya Raghunathan",
          "date": "2026-02-25",
          "text": "Internal complaint handling is where an automated enforcement decision is tested against a person. Meridian's reading of Article 20(6) is that the review must be capable of reversing the original decision, which an automated reviewer trained on the same signal as the original decision is not.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-103",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-09",
        "mechanism": "The complaint route is minted with the enforcement record and expires on a stored date rather than on a deployment."
      },
      "runtime_evidence": {
        "obligation": "Record the complaint route issued with each action and the date it closes.",
        "query_spec": "Retrieve actions attributed to this boundary with their complaint route and closing date, and return any action with no open route inside the six month window."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "systemic_risk.pre_deployment_assessment",
      "type": "approval",
      "text": "The systemic risk assessment covering this system is complete and signed before deployment, and names which of the four risk categories it considered.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-systemic-001",
          "author": "Priya Raghunathan",
          "date": "2026-05-06",
          "text": "The risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-140",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-28",
        "mechanism": "The release gate reads the assessment signature; an unsigned or category-incomplete assessment holds the deployment."
      },
      "runtime_evidence": {
        "obligation": "Retain the signed systemic risk assessment in force for this system and the risk categories it addressed.",
        "query_spec": ""
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "systemic_risk.mitigation_traceable",
      "type": "evidence",
      "text": "Each mitigation this system is credited with in the risk assessment maps to a condition on this authorization, so a mitigation that was only described is visible as one that was never implemented.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-systemic-001",
          "author": "Priya Raghunathan",
          "date": "2026-05-06",
          "text": "The risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-139",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-29",
        "mechanism": "Mitigations carry condition identifiers; the reconciliation runs on assessment publication and on every re-derivation."
      },
      "runtime_evidence": {
        "obligation": "Retain the mapping from each mitigation claimed for this system to the condition that implements it.",
        "query_spec": ""
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "systemic_risk.audit_evidence_retained",
      "type": "evidence",
      "text": "Evidence sufficient for an independent auditor to reach a conclusion about this system is retained and reachable without the cooperation of the team that operates it.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-systemic-001",
          "author": "Priya Raghunathan",
          "date": "2026-05-06",
          "text": "The risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-138",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-30",
        "mechanism": "Audit evidence is replicated to a store whose access is granted by the compliance function rather than by the operating team."
      },
      "runtime_evidence": {
        "obligation": "Retain the audit evidence set for this system in the independently reachable store.",
        "query_spec": "Retrieve the audit evidence set for this boundary and return any period where the independent store was not current."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "crisis.one_hour_removal_capability",
      "type": "control",
      "text": "This system does not stand between a removal order for terrorist content and its execution. The one-hour path stays available while this system is running and while it is not.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2021/784",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-crisis-001",
          "author": "Nnamdi Okonkwo",
          "date": "2026-03-12",
          "text": "The one-hour clock runs against Meridian, not against the system that happens to be handling the content. Any automated system placed in that path must therefore be removable from it without a deployment.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-106",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Head of Trust and Safety",
        "name": "Nnamdi Okonkwo"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-31",
        "mechanism": "The removal path bypasses the agent entirely and is exercised on a schedule against a synthetic order to prove it is still reachable."
      },
      "runtime_evidence": {
        "obligation": "Record each exercise of the one-hour removal path and the elapsed time it achieved.",
        "query_spec": "Retrieve one-hour path exercises covering this boundary and return any exercise that exceeded the hour or did not run."
      },
      "violation_behavior": "suspend_capability + escalate(Head of Trust and Safety)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": []
    },
    {
      "condition_id": "crisis.protocol_hook_present",
      "type": "control",
      "text": "This system exposes a control the crisis protocol can use to suspend or narrow its behaviour without a code deployment.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065",
          "jurisdiction": "EU",
          "authority_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533"
        },
        "interpretation": {
          "id": "int-crisis-002",
          "author": "Nnamdi Okonkwo",
          "date": "2026-05-13",
          "text": "A crisis response mechanism that requires a code change to engage is not a mechanism. Meridian reads the article as requiring a control surface that exists before the crisis does.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-107",
          "version": 1
        }
      },
      "approving_authority": {
        "role": "Head of Trust and Safety",
        "name": "Nnamdi Okonkwo"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-32",
        "mechanism": "A runtime capability flag is read on every action; the crisis protocol writes it and the system does not cache it across actions."
      },
      "runtime_evidence": {
        "obligation": "Retain the crisis capability flag this system reads, and the identity of the protocol that may write it.",
        "query_spec": ""
      },
      "violation_behavior": "suspend_capability + escalate(Head of Trust and Safety)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": []
    }
  ],
  "issued": "2024-03-15",
  "expires": "2027-03-15",
  "reauthorization_triggers": [
    {
      "trigger_id": "trig-periodic",
      "description": "Annual authorization review",
      "signal_source": "corpus",
      "threshold": null
    },
    {
      "trigger_id": "trig-regulation-amendment",
      "description": "A cited authority (regulation or supervisory guidance) is amended",
      "signal_source": "corpus",
      "threshold": null
    }
  ],
  "default_violation_behavior": "escalate(CCO)",
  "default_lapse_behavior": "suspend",
  "interpretation_pack_version": "1.1.0",
  "corpus_digest": "sha256:20aafa862bc069593b00cb4765ef5f339add625271bf47f5adb0f5b94a033533",
  "policy_pack_digest": "sha256:57945573870df9c0be8458c15b134a67ebc8b775a75014e6f2e9c5b082f7c05f",
  "not_yet_in_force": [
    {
      "condition_id": "cross_cutting.model_version_pinned",
      "authority_cite": "Meridian MAS-1",
      "jurisdiction": "MERIDIAN",
      "applies_from": "2026-01-15",
      "note": "This system is in scope of the rule, and the authority begins applying 2026-01-15, after this boundary was proposed 2024-03-01. The obligation is not owed yet and is recorded here so that it is not lost."
    },
    {
      "condition_id": "cross_cutting.decision_log_retained",
      "authority_cite": "Meridian MAS-1",
      "jurisdiction": "MERIDIAN",
      "applies_from": "2026-01-15",
      "note": "This system is in scope of the rule, and the authority begins applying 2026-01-15, after this boundary was proposed 2024-03-01. The obligation is not owed yet and is recorded here so that it is not lost."
    },
    {
      "condition_id": "cross_cutting.human_oversight_named",
      "authority_cite": "Meridian MAS-1",
      "jurisdiction": "MERIDIAN",
      "applies_from": "2026-01-15",
      "note": "This system is in scope of the rule, and the authority begins applying 2026-01-15, after this boundary was proposed 2024-03-01. The obligation is not owed yet and is recorded here so that it is not lost."
    },
    {
      "condition_id": "moderation.per_decision_assessment_record",
      "authority_cite": "Meridian MAS-1",
      "jurisdiction": "MERIDIAN",
      "applies_from": "2026-01-15",
      "note": "This system is in scope of the rule, and the authority begins applying 2026-01-15, after this boundary was proposed 2024-03-01. The obligation is not owed yet and is recorded here so that it is not lost."
    }
  ],
  "approval_rule": "all_of_concurrences_plus_risk_acceptance",
  "issuer": "licet, Inc.",
  "signature_basis": "demonstration",
  "demonstration_content": true,
  "canonical_digest": "sha256:c3cfc86a5c62a36cccd9ae9c4655e319c3976e3031205719b53157750826e9ef",
  "approvals": [
    {
      "approver": {
        "name": "Priya Raghunathan",
        "role": "Compliance Officer (DSA Art. 41)"
      },
      "approval_type": "risk_acceptance",
      "signed_at": "2024-03-15T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "priya-raghunathan-demo",
      "signature": "7Vgw78njeXHb8KwPGg0wdoNxt6JvB3gy3QUT7TtFDEZdvOS86gzn2D8y60INwR4+304z51G76kuD97CAUqNKAA==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    },
    {
      "approver": {
        "name": "Nnamdi Okonkwo",
        "role": "Head of Trust and Safety"
      },
      "approval_type": "concurrence",
      "signed_at": "2024-03-15T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "nnamdi-okonkwo-demo",
      "signature": "yYeKzWopYvpvVWwkIZiDVTCBiwVTQND9hzxYLt4OFyqsafLOh8Pv3AR+2eSr1b8Hf+PJP84Ci6MSf5D/VG4mDg==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    },
    {
      "approver": {
        "name": "Tom\u00e1s Iglesias",
        "role": "Deputy General Counsel, Platform Regulation"
      },
      "approval_type": "concurrence",
      "signed_at": "2024-03-15T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "tom-s-iglesias-demo",
      "signature": "p43Q1GAlW2yIfXnPDJefAwwhJoPFly5LW2mpdZlrcunLsFUhYT/hnPHgFTLcXH5pcGOtz/kzPsUKLc+fbsUeDg==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    }
  ]
}
