SIGNED DEMO · MER-2026-0001
The authorization record
Spam triage classifier
Meridian · Fictional designated VLOP
A decision should outlive the people who made it.
Engine-produced demonstration record. The institution, designation, people and interpretations are fictional. Deterministic demonstration keys are not held by these people and do not prove real approval or control effectiveness.
A licet record captures your institution’s approved interpretation of its obligations. It records what you decided and who accepted it. It does not state what the law permits.
APPLICABILITY · FICTIONAL SCENARIO
A defined institution. A dated obligation.
Designated very large online platform (VLOP). Public-post terms enforcement: content removal and visibility reduction; account termination excluded.
Under DSA Articles 33(1) and 33(6), the Section 5 obligations apply four calendar months after notification. The example is issued after that date. These are scenario assumptions, not a real Commission designation.
This context is in the downloadable interpretation pack, bound by the record’s corpus digest. The boundary has its own signed digest reference. Neither the HTML nor these assumptions constitute a legal finding. This is an illustrative subset, not an exhaustive DSA inventory.
Bound system description ↓ · Interpretation pack & scenario ↓
| Record | MER-2026-0001 · v1 |
|---|---|
| Lifecycle snapshot | Authorized in this demonstration export. Not a live registry status. |
| Issue / expiry | 2026-09-14 / 2027-03-14. Expiry alone does not establish current validity. |
| Boundary | mer-2026-0001 · v1 |
| Risk acceptor | Priya Raghunathan · Compliance Officer (DSA Art. 41) |
| Recorded conditions | 13 |
| Approvals | 4 Ed25519 demonstration approvals. This page is a readable projection; the homepage checks the MER-2026-0001 signatures in your browser. |
| Operational assurance | Not assessed. Evidence requirements are not collected results. |
| Legal compliance | Not determined. |
Interpretations dated 10 September precede the boundary proposed on 11 September and the demonstration signatures on 14 September 2026. Each condition has its own interpretation and collection requirement. Broader institutional choices are identified as policy, not attributed to legislation.
The recorded conditions.
moderation · terms basis requiredArt. 14(1)
Within this terms-enforcement boundary, content removal or reduced visibility must cite an applicable ground in Meridian's published terms in force at the time. Binding legal orders use the separate legal-order path.
| Source reference | Regulation (EU) 2022/2065 · Art. 14(1) |
|---|---|
| Institutional interpretation | Meridian applies Article 14(1)'s transparency requirement to restrictions implemented by software as well as people. For this terms-enforcement classifier, each restriction must map to the published terms version. This is an institutional implementation of transparency, not a claim that published terms override a lawful removal order. |
| Interpretation attribution | mer-int-2026-01 · Tomás Iglesias · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-125 · v2 |
| Approving role | Deputy General Counsel, Platform Regulation |
| Declared control | Enforcement taxonomy bound to the published terms; an action carrying no mapped clause is refused at the enforcement gateway rather than logged as an exception. |
| Evidence required | Record, for every enforcement action, the terms clause relied on and the version of that clause in force at the time of the action. |
| Collection requirement | Event reconciliation: retrieve restrictions, terms-clause identifiers and effective versions; flag missing mappings or use of a version not in force. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
statement of reasons · per decision statementArt. 17(1)–(3)
For restrictions covered by Article 17, communicate the required statement of reasons no later than imposition where contact details are known. Record the contact-availability finding and any Article 17(2) deceptive high-volume commercial-content exception.
| Source reference | Regulation (EU) 2022/2065 · Art. 17(1)–(3) |
|---|---|
| Institutional interpretation | Article 17 requires clear, specific reasons for the listed restrictions where the provider knows the relevant electronic contact details. Article 17(2) excludes deceptive high-volume commercial content. Meridian records whether that exception actually applies; a spam label alone is not enough. For covered decisions, reasons are prepared with the restriction and communicated no later than its imposition. Any broader notification is an institutional policy choice. |
| Interpretation attribution | mer-int-2026-02 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-134 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The restriction workflow checks Article 17 applicability, records any exception and generates required reasons before committing the covered restriction. |
| Evidence required | Record each Article 17 applicability determination and, where required, the statement and communication outcome. |
| Collection requirement | Event reconciliation: retrieve restriction, decision time, contact-availability finding, exception basis, statement identifier and communication time; flag unexplained omissions and late required communications. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
statement of reasons · automated means disclosedArt. 17(3)(c)
Each applicable statement of reasons must describe whether automated means were used to detect or identify the content and to take the restriction decision.
| Source reference | Regulation (EU) 2022/2065 · Art. 17(3)(c) |
|---|---|
| Institutional interpretation | Article 17(3)(c) requires information, where applicable, about automated means used in taking the decision, including automated detection or identification of the content. Meridian distinguishes detection from decision-making in the statement; it does not substitute a generic AI badge for the actual role automation played. |
| Interpretation attribution | mer-int-2026-03 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-132 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | Disclosure fields are derived from the recorded detection and decision paths, with an exception when those facts cannot be established. |
| Evidence required | Retain the detection and decision automation facts and the disclosure communicated for each applicable statement. |
| Collection requirement | Event reconciliation: compare applicable statements with recorded detection and decision automation; flag absent, inaccurate or contradictory disclosures. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
statement of reasons · database submissionArt. 24(5)
Submit covered Article 17 decisions and statements of reasons to the Commission's transparency database without undue delay and without personal data. Record accepted submissions, failures and retries.
| Source reference | Regulation (EU) 2022/2065 · Art. 24(5) |
|---|---|
| Institutional interpretation | Article 24(5) concerns public regulatory transparency, separately from notifying an affected recipient under Article 17. Meridian submits covered decisions and statements of reasons without undue delay to the Commission's database and excludes all personal data, including data about third parties. Article 17 exceptions are assessed first. A locally generated statement or queued request is not proof that the database received it. |
| Interpretation attribution | mer-int-2026-04 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-133 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | A dedicated submission path validates a data-minimized payload, checks free text for personal data and retains the Commission response; rejected or failed submissions remain open exceptions. |
| Evidence required | Record covered-decision eligibility, personal-data checks, submission attempts, acceptance identifiers, timestamps and unresolved failures. |
| Collection requirement | Event reconciliation: join covered decisions to submission attempts, accepted identifiers and timestamps; flag outstanding or delayed submissions, rejected payloads and failed personal-data checks. Do not equate an internal queue entry with acceptance. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
appeals · internal complaint routeArt. 20(1)
Provide the relevant recipients access to free electronic internal complaint handling for at least six months from notification of a decision covered by Article 20(1).
| Source reference | Regulation (EU) 2022/2065 · Art. 20(1) |
|---|---|
| Institutional interpretation | Article 20(1) gives recipients, including notice submitters, access to an effective internal complaint-handling system for at least six months following the listed decisions, electronically and free of charge. Meridian anchors the period to notification under Article 20(2). This condition covers availability of the route, not the separate human-supervision requirement in Article 20(6). |
| Interpretation attribution | mer-int-2026-05 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-103 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The complaint route is linked to the notified decision, with a stored six-calendar-month minimum and a free electronic access path. |
| Evidence required | Retain notification dates, route eligibility, availability-test results and complaint-route closure dates. |
| Collection requirement | Availability test and event reconciliation: retrieve covered decisions, notification dates, complaint routes and expiry dates; test accessibility and flag a missing route, a charge or closure before six calendar months. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
systemic risk · pre deployment assessmentArt. 34(1)
Before release, retain a signed review of the current systemic-risk assessment and whether the change requires a new assessment. Complete a new assessment before functionality likely to critically affect systemic risks is deployed, and maintain the annual assessment cycle.
| Source reference | Regulation (EU) 2022/2065 · Art. 34(1) |
|---|---|
| Institutional interpretation | Meridian is assumed to be a designated VLOP after its Article 33(6) applicability date. Article 34(1) requires diligent systemic-risk assessment by that applicability date, at least annually thereafter, and before functionality likely to critically affect those risks is deployed. Meridian additionally requires a signed assessment applicability review at every release; that stricter release gate is its own policy, not the statutory deployment threshold. |
| Interpretation attribution | mer-int-2026-06 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-140 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The release gate checks a versioned assessment and signed change-impact review; missing or overdue material holds the release. |
| Evidence required | Retain the approved assessment, the risks considered and each release's assessment-applicability decision. |
| Collection requirement | Document review: retrieve the versioned assessment, four-category analysis, approval, annual review date and release/change-impact finding; flag a missing assessment, an overdue review or a critical change released before assessment. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
systemic risk · mitigation traceableArt. 35(1)
Map each systemic-risk mitigation assigned to this system to a recorded condition, responsible owner, declared control and required evidence; leave implementation and effectiveness unassessed until supported by reviewed results.
| Source reference | Regulation (EU) 2022/2065 · Art. 35(1) |
|---|---|
| Institutional interpretation | Article 35(1) requires reasonable, proportionate and effective measures tailored to identified systemic risks. Meridian translates relevant mitigations into named controls, owners and evidence requirements for this authorization. A condition-to-mitigation mapping demonstrates traceability only: neither the mapping nor the signature establishes implementation or effectiveness. |
| Interpretation attribution | mer-int-2026-07 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-139 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | A versioned reconciliation links mitigation identifiers to conditions and owners; missing links and absent results remain visible review items. |
| Evidence required | Retain the risk-to-mitigation mapping and separately record any reviewed implementation and effectiveness evidence. |
| Collection requirement | Document review and reconciliation: retrieve the approved risk-to-mitigation register and linked conditions, owners and evidence requirements; report unmapped risks, unsupported effectiveness claims and missing assessment results. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
systemic risk · audit evidence retainedArt. 37(2)
Retain relevant audit evidence for this system and make it available through a compliance-controlled access path that does not depend solely on the operating team's cooperation, while preserving confidentiality and data protection.
| Source reference | Regulation (EU) 2022/2065 · Art. 37(2) |
|---|---|
| Institutional interpretation | Article 37(2) requires cooperation with and assistance to auditors, including access to relevant data and premises and answers to questions, without hampering or improperly influencing the audit. Meridian's independently accessible evidence store is an institutional implementation of that duty. The Article 37(1) annual-audit obligation is related but distinct; the store alone does not fulfill either obligation. |
| Interpretation attribution | mer-int-2026-08 · Priya Raghunathan · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-138 · v2 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | Compliance grants controlled auditor access to a separately maintained evidence store; access and completeness are tested, not inferred from the existence of the store. |
| Evidence required | Retain evidence inventories, version references, access-test results and records of assistance provided or outstanding. |
| Collection requirement | Access test and document retrieval: enumerate the audit evidence required for the period, test the independent access path, compare replicated versions and record missing items, failed access and unresolved auditor requests. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
| Read source | Official instrument on EUR-Lex ↗ |
crisis · one hour removal capabilityArt. 3(3)
The classifier must not obstruct Meridian's legal-order workflow for terrorist content. Maintain a bypass capable of meeting applicable Article 3(3) timing, including when the classifier is unavailable.
| Source reference | Regulation (EU) 2021/784 · Art. 3(3) |
|---|---|
| Institutional interpretation | Under Regulation (EU) 2021/784 Article 3(3), a hosting service provider must remove or disable access to terrorist content as soon as possible and in any event within one hour of receiving a removal order. Meridian keeps a separate legal-order path so this classifier cannot delay it. Applicable procedural safeguards, including first-order advance information and notified inability to comply, must be handled by that path; this condition is not a substitute for the full legal-order process. |
| Interpretation attribution | mer-int-2026-09 · Nnamdi Okonkwo · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-106 · v2 |
| Approving role | Head of Trust and Safety |
| Declared control | A separate legal-order path can bypass or suspend the classifier; scheduled synthetic exercises test availability without representing a real removal order. |
| Evidence required | Record scheduled exercises and, where an order exists, receipt, handling, completion and any documented procedural exception. |
| Collection requirement | Exercise and order reconciliation: retrieve scheduled bypass exercises, receipt times and removal outcomes; flag missed exercises, unexplained delays and any applicable one-hour deadline exceeded. |
| Revalidation watch | No standing event subscription in this demonstration rule. Its required exercise evidence must be reviewed separately. |
| Read source | Official instrument on EUR-Lex ↗ |
crisis · protocol hook presentMAS-1 §5.1; context: DSA Art. 36(1)
Under Meridian's crisis-readiness policy, provide an authorized control to narrow or suspend this classifier without deploying new code. A Commission crisis decision, if received, requires a separate applicability review.
| Source reference | Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §5.1; context: DSA Art. 36(1) |
|---|---|
| Institutional interpretation | Article 36(1) permits a Commission decision requiring specified measures in a crisis; it is not an always-active instruction to every platform. No such decision is assumed here. Meridian's MAS-1 section 5.1 instead requires advance readiness: an authorized crisis lead can narrow or suspend this classifier and records the decision. That control is Meridian policy; any future Commission decision needs its own scope and applicability review. |
| Interpretation attribution | mer-int-2026-10 · Nnamdi Okonkwo · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-107 · v2 |
| Approving role | Head of Trust and Safety |
| Declared control | An action-time capability flag can narrow or suspend operation; only the designated crisis lead can change it, and each change is recorded. |
| Evidence required | Retain the crisis-control specification, authorized operator designation, configuration history and signed exercise reports. |
| Collection requirement | Configuration attestation and exercise: retrieve the control definition, authorized crisis-lead roster, current configuration and latest signed exercise report; flag missing authority, stale configuration or an unsuccessful suspension test. |
| Revalidation watch | No standing event subscription in this demonstration rule. Its required exercise evidence must be reviewed separately. |
| Read source | Fictional institutional policy in the pack ↗ |
cross cutting · model version pinnedMAS-1 §2.1
Pin each model dependency to a specific version and revalidate before using a different version.
| Source reference | Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §2.1 |
|---|---|
| Institutional interpretation | Meridian's internal model-version policy makes the authorized dependency identifiable. A version change is a new fact to review, even if the provider describes it as equivalent. This is an institutional control, not a requirement attributed here to the DSA. |
| Interpretation attribution | mer-int-2026-11 · Elena Novak · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-110 · v2 |
| Approving role | Data Protection Officer |
| Declared control | Model requests carry an explicit version; the client refuses a response whose served version differs from the pinned one. |
| Evidence required | Record the model version served on each request this system made. |
| Collection requirement | Event reconciliation: retrieve the model version requested and served under this boundary; flag missing or mismatched versions and unreviewed upgrades. |
| Revalidation watch | trig-model-version, trig-cve, trig-periodic |
| Read source | Fictional institutional policy in the pack ↗ |
cross cutting · decision log retainedMAS-1 §4.3
Retain decision identifiers, timestamps, action, policy basis, model version and protected evidence references under the approved retention schedule. Do not copy all user content into the authorization log.
| Source reference | Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §4.3 |
|---|---|
| Institutional interpretation | Meridian's internal policy requires a proportionate, decision-level record so a later review can compare the action with its authorization. It does not prescribe indefinite retention or copying all user content. For this fictional pilot, decision metadata is retained for six months from notification, then reviewed for deletion unless a documented need or hold applies; a production schedule needs separate legal and privacy review. |
| Interpretation attribution | mer-int-2026-12 · Elena Novak · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-108 · v2 |
| Approving role | Data Protection Officer |
| Declared control | The action and minimized record commit together; access is restricted and expiry triggers deletion review, with documented holds handled separately. |
| Evidence required | Retain minimized decision records and the documented retention, hold and deletion decisions. |
| Collection requirement | Retention reconciliation: retrieve decision metadata, protected evidence references, retention dates, holds and deletion outcomes; flag missing records, unnecessary raw-content copies or retention outside the approved schedule. |
| Revalidation watch | trig-model-version, trig-cve, trig-periodic |
| Read source | Fictional institutional policy in the pack ↗ |
cross cutting · human oversight namedMAS-1 §2.2
Maintain a named operational owner and reachable escalation cover while this system runs, distinct from its recorded risk acceptor.
| Source reference | Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §2.2 |
|---|---|
| Institutional interpretation | Meridian's internal oversight policy assigns a named operational owner with an escalation route, separately from the executive who accepts residual risk. A roster entry is not proof that oversight is effective; reachability and intervention must be exercised. |
| Interpretation attribution | mer-int-2026-13 · Elena Novak · 2026-09-10 · Fictional demonstration |
| Policy | PLT-POL-109 · v2 |
| Approving role | Data Protection Officer |
| Declared control | The authorization links to a dated owner designation and on-call cover; a controlled escalation test checks that the owner can intervene. |
| Evidence required | Retain current and prior owner designations, escalation coverage and exercise results. |
| Collection requirement | Designation attestation and exercise: retrieve the dated owner designation, on-call cover, intervention authority and latest reachability exercise; flag gaps and failed escalation tests. |
| Revalidation watch | trig-model-version, trig-cve, trig-periodic |
| Read source | Fictional institutional policy in the pack ↗ |
Recorded approvals.
- Priya Raghunathan · Compliance Officer (DSA Art. 41) · risk acceptance · 2026-09-14T09:00:00+00:00
- Elena Novak · Data Protection Officer · concurrence · 2026-09-14T09:00:00+00:00
- Nnamdi Okonkwo · Head of Trust and Safety · concurrence · 2026-09-14T09:00:00+00:00
- Tomás Iglesias · Deputy General Counsel, Platform Regulation · concurrence · 2026-09-14T09:00:00+00:00
Check the artifact, not the rendering.
The download is the engine’s signed document, byte for byte. This page is a readable projection. The demonstration public keys are not an independent identity trust service.
sha256:c97719f28994cb7b0584f1a58ba8342801955499f48917dd1cfbd609dd7dea1b
Download the standalone verifier (v0.1.1) ↓. It requires Python 3.12 or later and the cryptography package; no licet application installation is needed. In an isolated Python environment, install the wheel and run:
python -m pip install ./licet_verifier-0.1.1-py3-none-any.whl licet-verify mer-2026-0001.json --jwks mer-2026-demonstration-jwks.json
Verification checks payload integrity and signatures. It does not establish real-world signer identity, control effectiveness, current authorization status or legal compliance. The record explorer is not connected to an enforcement point.
The earlier 2024-labelled artifact remains available with its known limitations and original signed bytes.
Discuss a record for your system ↗