← Back to licet

HISTORICAL DEMO · AMB-2024-0004

The authorization record

Historical artifact — known defects, preserved unchanged. This earlier example has 2024 signatures paired with 2026 interpretations, duplicated reasoning and incomplete applicability information. It is not the current reference example. Preserving its bytes is not an endorsement of its contents.

Read the corrected 2026 example ↗

Legacy spam triage classifier · Historical demonstration

A licet record captures your institution’s approved interpretation of its obligations. It records what you decided and who accepted it. It does not state what the law permits.

Download signed demo JSON ↓Demo public keys ↓
RecordAMB-2024-0004 · v1
Lifecycle snapshotAuthorized in this demonstration export. Not a live registry status.
Issue / expiry2024-03-15 / 2027-03-15. Expiry alone does not establish current validity.
Boundaryamb-2024-0004 · v1
Risk acceptorPriya Raghunathan · Compliance Officer (DSA Art. 41)
Recorded conditions10
Approvals3 Ed25519 demonstration approvals. This page is a readable projection; the homepage checks the MER-2026-0001 signatures in your browser.
Operational assuranceNot assessed. Evidence requirements are not collected results.
Legal complianceNot determined.

The recorded conditions.

moderation · terms basis requiredArt. 14(1)

This system may not restrict, remove, demote, or otherwise act against user content except on a ground published in Meridian's terms and conditions and in force on the date of the action.

Source referenceRegulation (EU) 2022/2065 · Art. 14(1)
Institutional interpretationMeridian reads the terms and conditions duty as binding on machines as well as on people. An enforcement action taken by an automated system is an action taken by Meridian, so the ground for it must already be published before the system takes it. A system that can act on a ground the terms do not name has, in effect, amended the terms without publishing them.
Interpretation attributionint-moderation-001 · Tomás Iglesias · 2026-03-04 · Fictional demonstration
PolicyPLT-POL-125 · v1
Approving roleDeputy General Counsel, Platform Regulation
Declared controlEnforcement taxonomy bound to the published terms; an action carrying no mapped clause is refused at the enforcement gateway rather than logged as an exception.
Evidence requiredRecord, for every enforcement action, the terms clause relied on and the version of that clause in force at the time of the action.
Collection requirementRetrieve every enforcement action attributed to this boundary with its cited terms clause and clause version, and return any action with no mapped clause.
Revalidation watchtrig-regulation-amendment, trig-periodic
statement of reasons · per decision statementArt. 17(1)

Every restriction this system imposes emits a statement of reasons to the affected user containing the facts relied on, the ground for the action, and the redress available.

Source referenceRegulation (EU) 2022/2065 · Art. 17(1)
Institutional interpretationA statement of reasons is the only artifact a restricted user is guaranteed to receive. Meridian treats it as the output of the enforcement decision rather than a notification generated after it, which means a system that cannot produce one cannot take the action.
Interpretation attributionint-sor-001 · Priya Raghunathan · 2026-02-18 · Fictional demonstration
PolicyPLT-POL-134 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlThe statement is produced by the same transaction as the enforcement action; an action that cannot produce one does not commit.
Evidence requiredRecord a statement of reasons identifier against every restriction this system imposed.
Collection requirementRetrieve every restriction attributed to this boundary with its statement of reasons identifier, and return any restriction with none.
Revalidation watchtrig-regulation-amendment, trig-periodic
statement of reasons · automated means disclosedArt. 17(3)(c)

A statement of reasons issued for an action this system took may not omit that automated means were used. Silence about automation is a defect in the statement, not a permitted economy.

Source referenceRegulation (EU) 2022/2065 · Art. 17(3)(c)
Institutional interpretationThe obligation to state whether automated means were used is read here as a floor that cannot be satisfied by silence. Where a statement of reasons is generated for an action an automated system took, the absence of the automation disclosure is itself a defect in the statement.
Interpretation attributionint-sor-002 · Priya Raghunathan · 2026-02-18 · Fictional demonstration
PolicyPLT-POL-132 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlThe automation disclosure field is populated from the acting identity rather than from the drafter, so it cannot be left empty by an author.
Evidence requiredRecord the automation disclosure carried by every statement of reasons this system generated.
Collection requirementRetrieve statements of reasons generated for this boundary and return any whose automation disclosure field is absent or negative.
Revalidation watchtrig-regulation-amendment, trig-periodic
statement of reasons · database submissionArt. 24(5)

Each statement of reasons is submitted to the Commission's public transparency database, without the personal data of the affected user.

Source referenceRegulation (EU) 2022/2065 · Art. 24(5)
Institutional interpretationA statement of reasons is the only artifact a restricted user is guaranteed to receive. Meridian treats it as the output of the enforcement decision rather than a notification generated after it, which means a system that cannot produce one cannot take the action.
Interpretation attributionint-sor-001 · Priya Raghunathan · 2026-02-18 · Fictional demonstration
PolicyPLT-POL-133 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlSubmission runs from the statement record through a field allowlist; a field outside the allowlist fails the submission rather than being redacted silently.
Evidence requiredRecord the submission identifier and outcome for every statement of reasons this system generated.
Collection requirementRetrieve statements of reasons for this boundary with their transparency database submission identifier and outcome, and return any not submitted.
Revalidation watchtrig-regulation-amendment, trig-periodic
appeals · internal complaint routeArt. 20(1)

Every action this system takes carries a route into internal complaint handling that stays open for six months from the date of the decision.

Source referenceRegulation (EU) 2022/2065 · Art. 20(1)
Institutional interpretationInternal complaint handling is where an automated enforcement decision is tested against a person. Meridian's reading of Article 20(6) is that the review must be capable of reversing the original decision, which an automated reviewer trained on the same signal as the original decision is not.
Interpretation attributionint-appeals-001 · Priya Raghunathan · 2026-02-25 · Fictional demonstration
PolicyPLT-POL-103 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlThe complaint route is minted with the enforcement record and expires on a stored date rather than on a deployment.
Evidence requiredRecord the complaint route issued with each action and the date it closes.
Collection requirementRetrieve actions attributed to this boundary with their complaint route and closing date, and return any action with no open route inside the six month window.
Revalidation watchtrig-regulation-amendment, trig-periodic
systemic risk · pre deployment assessmentArt. 34(1)

The systemic risk assessment covering this system is complete and signed before deployment, and names which of the four risk categories it considered.

Source referenceRegulation (EU) 2022/2065 · Art. 34(1)
Institutional interpretationThe risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately.
Interpretation attributionint-systemic-001 · Priya Raghunathan · 2026-05-06 · Fictional demonstration
PolicyPLT-POL-140 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlThe release gate reads the assessment signature; an unsigned or category-incomplete assessment holds the deployment.
Evidence requiredRetain the signed systemic risk assessment in force for this system and the risk categories it addressed.
Collection requirementHistorical omission: no collection method was recorded in this artifact. No attestation or collected result is implied.
Revalidation watchtrig-regulation-amendment, trig-periodic
systemic risk · mitigation traceableArt. 35(1)

Each mitigation this system is credited with in the risk assessment maps to a condition on this authorization, so a mitigation that was only described is visible as one that was never implemented.

Source referenceRegulation (EU) 2022/2065 · Art. 35(1)
Institutional interpretationThe risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately.
Interpretation attributionint-systemic-001 · Priya Raghunathan · 2026-05-06 · Fictional demonstration
PolicyPLT-POL-139 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlMitigations carry condition identifiers; the reconciliation runs on assessment publication and on every re-derivation.
Evidence requiredRetain the mapping from each mitigation claimed for this system to the condition that implements it.
Collection requirementHistorical omission: no collection method was recorded in this artifact. No attestation or collected result is implied.
Revalidation watchtrig-regulation-amendment, trig-periodic
systemic risk · audit evidence retainedArt. 37(1)

Evidence sufficient for an independent auditor to reach a conclusion about this system is retained and reachable without the cooperation of the team that operates it.

Source referenceRegulation (EU) 2022/2065 · Art. 37(1)
Institutional interpretationThe risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately.
Interpretation attributionint-systemic-001 · Priya Raghunathan · 2026-05-06 · Fictional demonstration
PolicyPLT-POL-138 · v1
Approving roleCompliance Officer (DSA Art. 41)
Declared controlAudit evidence is replicated to a store whose access is granted by the compliance function rather than by the operating team.
Evidence requiredRetain the audit evidence set for this system in the independently reachable store.
Collection requirementRetrieve the audit evidence set for this boundary and return any period where the independent store was not current.
Revalidation watchtrig-regulation-amendment, trig-periodic
crisis · one hour removal capabilityArt. 3(3)

This system does not stand between a removal order for terrorist content and its execution. The one-hour path stays available while this system is running and while it is not.

Source referenceRegulation (EU) 2021/784 · Art. 3(3)
Institutional interpretationThe one-hour clock runs against Meridian, not against the system that happens to be handling the content. Any automated system placed in that path must therefore be removable from it without a deployment.
Interpretation attributionint-crisis-001 · Nnamdi Okonkwo · 2026-03-12 · Fictional demonstration
PolicyPLT-POL-106 · v1
Approving roleHead of Trust and Safety
Declared controlThe removal path bypasses the agent entirely and is exercised on a schedule against a synthetic order to prove it is still reachable.
Evidence requiredRecord each exercise of the one-hour removal path and the elapsed time it achieved.
Collection requirementRetrieve one-hour path exercises covering this boundary and return any exercise that exceeded the hour or did not run.
Revalidation watchNo standing event subscription in this demonstration rule. Its required exercise evidence must be reviewed separately.
crisis · protocol hook presentArt. 36(1)

This system exposes a control the crisis protocol can use to suspend or narrow its behaviour without a code deployment.

Source referenceRegulation (EU) 2022/2065 · Art. 36(1)
Institutional interpretationA crisis response mechanism that requires a code change to engage is not a mechanism. Meridian reads the article as requiring a control surface that exists before the crisis does.
Interpretation attributionint-crisis-002 · Nnamdi Okonkwo · 2026-05-13 · Fictional demonstration
PolicyPLT-POL-107 · v1
Approving roleHead of Trust and Safety
Declared controlA runtime capability flag is read on every action; the crisis protocol writes it and the system does not cache it across actions.
Evidence requiredRetain the crisis capability flag this system reads, and the identity of the protocol that may write it.
Collection requirementHistorical omission: no collection method was recorded in this artifact. No attestation or collected result is implied.
Revalidation watchNo standing event subscription in this demonstration rule. Its required exercise evidence must be reviewed separately.

Recorded approvals.

Check the artifact, not the rendering.

The download is the engine’s signed document, byte for byte. This page is a readable projection. The demonstration public keys are not an independent identity trust service.

sha256:c3cfc86a5c62a36cccd9ae9c4655e319c3976e3031205719b53157750826e9ef

Download the standalone verifier (v0.1.1) ↓. It requires Python 3.12 or later and the cryptography package; no licet application installation is needed. In an isolated Python environment, install the wheel and run:

python -m pip install ./licet_verifier-0.1.1-py3-none-any.whl
licet-verify sample-record.json --jwks demonstration-jwks.json

Verification checks payload integrity and signatures. It does not establish real-world signer identity, control effectiveness, current authorization status or legal compliance. The record explorer is not connected to an enforcement point.

Discuss a record for your system ↗