HomeSearch

Lenses
Business lenslens
Certifying body lenslens
End user / data subject lenslens
Front-line staff lenslens
Government lenslens
Human rights / privacy advocate lenslens
Policymaker (Government lens)lens
Regulator / enforcer (Government lens)lens
Africa
Egyptplanned
Ghanaplanned
Kenyaplanned
Moroccoplanned
Nigeriaplanned
Rwandaplanned
South Africaplanned
Asia-Pacific
Australiaplanned
Chinadrafting
Hong Kongplanned
Indiaplanned
Indonesiaplanned
Japanplanned
Malaysiaplanned
New Zealandplanned
Philippinesplanned
Singaporeplanned
South Koreaplanned
Thailandplanned
Vietnamplanned
Europe
European Uniondrafting
Switzerlandplanned
Türkiyeplanned
United Kingdomplanned
Latin America
Argentinaplanned
Brazilplanned
Chileplanned
Colombiaplanned
Peruplanned
Uruguayplanned
Middle East
Bahrainplanned
Israelplanned
Qatarplanned
Saudi Arabiaplanned
United Arab Emiratesplanned
North America
Canadaplanned
Mexicoplanned
United States (federal)drafting
United States
Californiadrafting
Coloradoplanned
Connecticutplanned
Delawareplanned
Floridaplanned
Indianaplanned
Iowaplanned
Kentuckyplanned
Marylandplanned
Minnesotaplanned
Montanaplanned
Nebraskaplanned
New Hampshireplanned
New Jerseyplanned
Ohioplanned
Oregonplanned
Rhode Islandplanned
Tennesseeplanned
Texasplanned
Utahplanned
Virginiaplanned
Menu

Human rights / privacy advocate

Who does this regime fail, and can that be shown.

Handbook §66 · 15 sections

Drafting material: not yet published or verified for publication. States what the sources say; not legal advice.

66.1 /

What this handbook is

The advocate lens, assembled. It is the longest lens in every block and the toolkits are scattered across eleven volumes.

Who it is for. Somebody arguing that the law falls short of the right it claims to protect, and deciding where to spend limited effort.

What it adds to the fifteen blocks it draws on. Three things. The toolkits collected and ranked, at sections 66.8 to 66.11. An alliance nobody has named, at section 66.12. And section 66.14, where the advocate should concede, which is here because a case that overstates is easier to dismiss than one that does not.

The voice, and it differs from section 65 deliberately. Section 65 addresses a person about what to do. This section addresses an argument.

Vol. 43 · §66.1 · Currency 2026-09-03 · drafting

66.2 /

The position, stated without softening

Section 45.12 and section 53.20 give it: no system examined in this document has both a gate that operates and a remedy that reaches the person.

The Union has a gate and almost no remedy. Section 40.40: the affected person holds an untested explanation right, some interface disclosures, and a complaint route into a product safety process with no individual remedy — and section 41.7 records that the actual remedy runs through product liability rather than through the AI Act. Section 27.5 records that the gate itself did not operate.

The United States has a strong remedy and no gate, and section 43.19 records that the remedy is switched off by a term of service.

China has a functioning gate directed at a different object. Section 44.15: its primary function is control of information reaching the public, and section 44.13 records that the individual protections are real and unverifiable.

And most jurisdictions have neither. Section 52.11: a net importer with a deployment-facing statute and no operational regulator has the right instrument and no means of using it.

What follows for an advocate. The gap is not a drafting failure in one place. It recurs across every system examined, which means arguments framed as “this jurisdiction got it wrong” are weaker than arguments framed as “this is what every version of this design produces.”

Vol. 43 · §66.2 · Currency 2026-09-03 · drafting

66.3 /

Where the individual is visible

Section 61.3 gives the frame and it is the most useful strategic observation available.

Two points, and only two. When data is collected, per section 30.28 — the individual is present, addressed, and something is asked of them. When they exercise a right, per section 35.1.

Everywhere else they are absent. Storage, security, transfer, vendors, destruction, certification, conformity assessment, standards.

Why this matters for where to spend effort. The two visible points are where individual action produces results and where evidence can be generated. Sections 66.8 to 66.10 are built on them.

And it explains a pattern across the whole document. Section 39.12: enforcement selects for what can be seen from outside. The stages where the individual is absent are the same stages regulators do not reach, which is not a coincidence — both are consequences of the same invisibility.

Vol. 43 · §66.3 · Currency 2026-09-03 · drafting

66.4 /

What cannot be found out

Section 61.25 collects it for an individual. For an advocate the question is different: which of these are permanent and which are policy choices.

Permanent, because they follow from what the thing is. Whether destruction happened. Section 36.16: the outcome is an absence, and absence cannot be demonstrated. Nobody can make this observable — not the individual, not the regulator, not an auditor.

Policy choices, and therefore campaignable. What the impact assessment said. Section 38.16 records that it is a document that exists and could be shown, and that the reason it is not shown is a policy choice rather than a structural impossibility. Whether a system was classified correctly, per section 40.40 — the determination is documented and internal. Which specific organisations received the data, per section 19.29 — responses name categories because that is what the obligation is read to require.

The distinction is the most useful thing in this section. Section 63.14 records it from the regulator’s side: a policymaker can make a document visible, and nobody can make an absence observable. Effort spent on the second category produces change; effort spent on the first produces frustration.

Vol. 43 · §66.4 · Currency 2026-09-03 · drafting

66.5 /

Rights that exist and are unusable

Section 61.26 lists them for an individual. For an advocate, each is a campaign target and they differ in tractability.

The automated decision right. Section 35.20 and section 40.21: defeated by a nominal reviewer, in every regime that has one. Section 5.9 records it as the widest gap between right and reality in the European framework. Tractable in principle and very hard to draft — section 63.21 records that requiring effectiveness rather than existence is the difficulty.

Portability. Section 35.19: narrow scope, no format standards, nowhere to send the file. Section 35.19 records two jurisdictions concluding that the right alone does not work and building transmission infrastructure instead, which is the answer and is expensive.

Beneficiary status under certification. Sections 20.17 and 26.15: named as a beneficiary, no role, no rights, no standing. Section 26.15 records the sharpest form — data may leave the Union on a certificate the individual cannot see, from a body they cannot challenge, under criteria they cannot petition on.

And the cybersecurity instruments. Section 5.12A, quoted as a finding rather than an omission: no rights under any of the three, and it is not a drafting oversight.

Vol. 43 · §66.5 · Currency 2026-09-03 · drafting

66.6 /

The mechanism that produces most of it

Section 53.21 records it and it is the argument this handbook should lead with, because it explains several separate complaints at once.

Where a statute states an outcome and a standard states what satisfies it, the standard is the operative rule. Section 27.7 records that Union outcome obligations were to be given content by harmonised standards; section 44.11 records Chinese national standards doing the same work; section 53.15 records the five routes by which a standard acquires force and that only one involves a legislature.

Section 53.21’s characterisation. Delegated legislation without the delegation being visible. Drafted in a private body, by committee, without public consultation, without legislative scrutiny, and without any of the procedural protections attaching to lawmaking.

Why this is a better frame than complaining about any single rule. It explains the impact assessment gap, the certification exclusion, the conformity self-assessment and the standards vacuum as one problem — and section 26.15’s finding applies to all of them: public control of criteria is necessary and not sufficient; a public stake in the outcome is what matters.

Vol. 43 · §66.6 · Currency 2026-09-03 · drafting

66.7 /

Who is at the table

Section 53.16 answers it and the answer is structural rather than a matter of effort.

Formally open. Participation is through national standards bodies, which are open to members, with liaison organisations able to take part.

Actually. National delegations are substantially staffed and funded by industry, because standards bodies are membership organisations whose subscribers are the companies the standards govern.

What participation requires. Sustained funding of a specialist who can draft technical text, across a cycle measured in years, plus travel and membership. Section 53.16 records that almost no civil society organisation is funded in a way that permits it and that industry participants treat the same cost as ordinary overhead.

And the access barrier that is rarely named as one. Section 53.16: standards that function as law are copyrighted documents sold to readers. A rule with legal force that costs money to read is a barrier to exactly the participants least able to pay.

Vol. 43 · §66.7 · Currency 2026-09-03 · drafting

66.8 /

The toolkit: generating evidence

First of four, and the ranking is by what produces material nobody else has.

Access requests, used systematically. Section 38.16 records this as the only mechanism available to civil society for generating evidence, and that it works at scale when coordinated. Section 36.16 adds the specific use: requests made repeatedly against organisations that confirmed erasure, which is the only available test of whether deletion happened.

Freedom of information for public sector impact assessments. Section 38.16: it works, produces the most usable evidence available, and should be run systematically rather than case by case. Section 38.16 also records the asymmetry it reveals — public sector assessments are obtainable and private sector ones essentially never are.

Breach disclosures as a research corpus. Section 36.16: notification records and published enforcement decisions contain the retention facts. Systematic analysis of how much notified breach data should already have been destroyed is the most persuasive available evidence and can be assembled from public sources.

And litigation discovery, per section 66.10.

Vol. 43 · §66.8 · Currency 2026-09-03 · drafting

66.9 /

The toolkit: the public registers

Second, and section 40.40 records the first of these as the single most valuable resource in the whole AI governance framework for civil society.

The high-risk systems database. Section 27.9 and section 40.40: a public list of high-risk deployments assembled by the deployers themselves, including public authority deployments. It should be monitored systematically and analysed as a corpus. Section 40.40 records why it matters disproportionately: it is the one place where the self-assessment architecture generates external evidence.

And it contains something easy to miss. Section 40.14 records that a provider using the Article 6(3) filter must register the system notwithstanding that it concluded the system is not high risk. That is a filtered-out population, counted, in a public register — and section 63.21 records that nobody is reading it.

Training content summaries. Section 40.33: the only provision anywhere in this document requiring public disclosure of what a model was trained on.

Government algorithm registers. Section 48.3 records Canada publishing algorithmic impact assessments and section 45.8 the United Kingdom’s transparency records. Section 48.3 records that Canada’s predates every comparable mechanism and publishes more.

Published bias audit summaries, per section 43.22 — with section 9.14’s caution that the mandate behind them was found to be ineffectively enforced.

Vol. 43 · §66.9 · Currency 2026-09-03 · drafting

66.10 /

The toolkit: litigation

Third, and its value differs by jurisdiction more than any other item.

Where it is strongest. Section 43.19 and section 43.22: discovery. An American claimant can compel production of training data documentation, validation studies, vendor communications and internal assessments — the equivalents of the three things section 40.40 records a European individual cannot obtain. Section 43.17 records statutory damages making claims viable that would otherwise never be brought.

What neutralises it, and section 43.22 records it as the central issue. Arbitration clauses with class action waivers. Section 66.13 records the campaign that follows.

The framing that works best for AI. Section 40.40: strategic litigation on misclassification, framed as a challenge to the Article 6(3) determination rather than to the system, because the classification is the gate everything else passes through.

The route most likely to produce a remedy. Section 41.7: product liability, which reaches software, eases the burden of proof, and does not require establishing any breach of the AI Act — defectiveness is the test.

And where statutes are absent. Section 50.8 records habeas data across Latin America as fast, constitutionally grounded and available against private entities, with the limit that it reaches held data and not inference. Section 49.9 records Indian public interest litigation as reaching diffuse harm without requiring an affected claimant.

And the collective actors, because section 39.10 records that the economics of individual claims rarely work and section 3.4 that the availability of a collective mechanism determines whether private enforcement exists at all.

Consumer bodies, which several regimes empower to bring representative actions, and section 3.4 records the comparative position.

Trade unions and works councils, which this document has not previously identified as an advocacy route and which have a statutory lever nobody has named. Section 40.24 requires an employer deploying a high-risk system in the workplace to inform workers’ representatives and affected workers before putting it into use.

Why that is more useful than it looks. Section 40.13 places employment squarely in the high-risk category and section 43.9 records that employment screening is where AI reaches the most people. The information duty is owed to a collective body that already exists, is already funded, already has standing with the employer, and is not subject to the arbitration problem at section 66.10. It is triggered before deployment rather than after harm.

Its limits. It is an information right rather than a veto. It applies where the instrument applies, which section 40.4 flags. And section 43.22 records that in the United States employment data is exempt from most state comprehensive laws, so the equivalent leverage there runs through discrimination law rather than through notification.

Vol. 43 · §66.10 · Currency 2026-09-03 · drafting

66.11 /

The toolkit: standards and criteria

Fourth in order and first in leverage, and section 53.21 records it as the single highest-leverage and least-used item available.

Why it is highest leverage. Section 66.6: the standard is the operative rule. Participation reaches the content of obligations rather than their enforcement.

Why it is least used. Section 66.7.

What exists and is under-used. Section 53.21: some national bodies and some international committees provide funded or fee-waived routes for consumer and civil society representation. Section 53.21 records that these should be the first ask of any funder supporting AI accountability work.

The adjacent route with lower barriers. Section 26.15 and section 19.29 record that participation in certification criteria development is open, low-cost, and is where the standard is actually set — and that published criteria are public and are not being read. Comparative scrutiny of published criteria costs nothing.

And codes of conduct. Section 28.5 records that codes produced more than certification because a sponsoring body had an interest in adoption, and section 53.21 records that civil society participation in code drafting is achievable in a way that participation in individual assessments is not.

Vol. 43 · §66.11 · Currency 2026-09-03 · drafting

66.12 /

The alliance nobody has named

This handbook’s own contribution, and it follows from putting two lens blocks together.

Section 53.21 records that civil society is largely absent from criteria and standards drafting, structurally and for funding reasons.

Section 64.24 records that a certification body is already in the room, already funded to be there, and has a commercial interest that diverges from its clients’. The reasoning is section 64.8’s: vague criteria make an assessment unfalsifiable and therefore commercially weightless. A body that wants its certificate to mean something wants criteria specific enough to fail against.

Which produces an alignment that is not obvious and is real. An advocate arguing for demanding criteria and a certification body arguing for demanding criteria want the same text, for different reasons.

Where the alignment stops, and it should be stated so the alliance is not overestimated. On scope, because section 64.5 records that the client negotiates it and a body has no interest in a broader one. On liability, per section 64.17. And on enforcement, where a body’s interest is in a market that keeps buying certificates.

What to do with it. In criteria consultations, look for the assessor position rather than only the industry position, and treat it as a potential ally on specificity. Section 64.24 records the list a body would argue for — outcomes with stated levels, sampling requirements, scope statement content, and published methodology — and every item on it is also an advocate’s item.

Vol. 43 · §66.12 · Currency 2026-09-03 · drafting

66.13 /

What to campaign for

Six, ranked by the document’s own assessment of what would change most.

Mandatory publication of impact assessments, in redacted form, for defined high-risk categories. Sections 38.16 and 40.40 both identify it as the change that would most alter the position of affected people, and section 63.14 records why it is tractable: the document exists and is not visible. Section 48.3 records that Canada already does it for federal government systems.

Funded civil society participation in standards and criteria. Sections 66.11 and 53.21.

Closing the nominal reviewer gap. Sections 35.20 and 40.21. Section 63.21 records the difficulty honestly — requiring effectiveness rather than existence is hard to draft.

Ending arbitration clauses with class waivers, per section 66.10, which is upstream of every litigation item.

Defending disparate impact doctrine, per section 43.22: it is the legal theory most outcome-based claims depend on, and if it narrows the litigation route narrows with it without any AI-specific law changing.

And publishing what the calibration excludes, per section 63.21 — the data is already collected in the section 27.9 database and nobody is reading it.

Vol. 43 · §66.13 · Currency 2026-09-03 · drafting

66.14 /

Where the advocate should concede

Five concessions, made because a case that overstates is easier to dismiss than one that does not, and each is recorded in the document as a genuine position.

Regulators are not failing through unwillingness. Section 39.11: the behaviour is the correct response to the constraint. An authority selecting cases it can complete is maximising its output.

The certification conflict is structural, not misconduct. Section 64.4: no individual assessor need do anything improper for the effect to operate.

The candour dilemma is real. Section 38.16 records the business position — a frank assessment is discoverable by a regulator and a claimant — and records that both sides predict real effects. An advocate arguing for publication should concede the chilling risk rather than deny it.

Technical standards need technical participants. Section 53.21 records the business answer to the participation argument, and it is not frivolous: opening the process to non-experts would degrade the output. The advocate’s answer is about funding expertise, not about admitting non-experts.

And a framework that promises less may deliver more. Section 45.10: a framework that promises less and delivers what it promises is not obviously worse than one that promises more and does not. Section 27.5 records a gate that did not operate and section 43.14 a statute stripped before it applied. An advocate arguing for ambitious legislation should have an answer to both.

Vol. 43 · §66.14 · Currency 2026-09-03 · drafting

66.15 /

Sources and confidence

Both sections assemble material recorded in Volumes 01 to 42 and introduce no new facts. They inherit the confidence of everything they cite. Part VII is complete with this volume, and section 45 remains the currency sweep.

What bears on section 65. The jurisdiction-specific items are few, because the front-line lens is largely about conduct rather than about rules. The exceptions are section 9.9’s biometric consent requirement, which section 65.7 records as the highest-liability act in that lens and which applies only in some states; section 8.5’s adverse action notice, likewise; and section 40.20’s instructions for use, which depend on section 40.4’s application status.

What bears on section 66. Section 53.14, whether harmonised standards have been cited, which governs section 66.6’s mechanism. Sections 27.5 to 27.7 and 27.9, on which sections 66.9 and 66.13 depend — if the database is not operating, the toolkit’s most valuable item is not available. Section 43.18, United States preemption, and section 43.22’s flag on disparate impact doctrine, which section 66.13 ranks as a campaign priority precisely because it is under challenge. And section 42.5, the Convention’s ratification and declaration position.

What is this volume’s own rather than assembled. Section 65.14, what to do having already done it, which no lens block treats and which is the situation a reader is most often in. Section 65.15, what an organisation owes its front-line staff, assembled from obligations recorded as duties on the organisation and never stated as entitlements of the person. Section 66.4’s distinction between what cannot be found out permanently and what cannot be found out by policy choice, which section 63.14 records from the regulator’s side and which reframes it as a targeting rule for an advocate. And section 66.12, the alliance between an advocate and a certification body on criteria specificity, which follows from putting section 53.21 and section 64.24 together and is stated nowhere else.

What is not affected by any flag. That you are the evidence, at section 65.2, and the rule that follows from it. That the conflicts at section 65.13 are the ones that actually occur and that escalating in writing is the answer to each. That no system examined has both a gate that operates and a remedy that reaches the person, at section 66.2. That the individual is visible at two points and absent everywhere else, at section 66.3. That a policymaker can make a document visible and nobody can make an absence observable, at section 66.4. That the standard is the operative rule and only one of the five routes to that involves a legislature, at section 66.6. And the five concessions at section 66.14.

Forward reference. Part VII is complete and section 66 is the last substantive section of the document. Volume 44 carries Appendices A to J, the glossary and the master chronology. Volume 45 is the currency sweep and the single-document assembly, and it is where the research debt recorded throughout is discharged — 140 flagged items across 32 volumes at the point this volume was written, with the register enumerated by section and volume rather than reproduced anywhere in the text.

Vol. 43 · §66.15 · Currency 2026-09-03 · drafting