Policymaker
What did the drafters intend, and what did the text achieve.
Handbook §63 · 25 sections
Draft material. It has not been through final checks yet. It reports what the sources say, and it is not legal advice.
63.1 /
What this handbook is
The policymaker lens and the regulator lens, assembled — and kept apart.
Who it is for. The person drafting a rule, and the person who will have to enforce it. They are usually not the same person and this handbook is written on the assumption that they are not.
Why both are here. Section 0.4 records the structure: there are seven lenses rather than six because the government lens splits into policymaker and enforcer, and those two have different incentives. Section 63.2 develops it.
What this handbook does that no section of the document does. It puts the two side by side and states where they disagree, at section 63.19. Every lens block keeps them separate; none compares them.
The negatives it collects, per the method used throughout Part VII. What legislating cannot achieve, at section 63.8. What enforcement cannot reach, at section 63.13. And the two closed loops, at section 63.14, which are the strongest finding in the regulator material and are recorded in two different volumes without ever being put together.
Vol. 41 · §63.1 · Currency 2026-09-03 · drafting
63.2 /
Why the government lens splits
Section 0.4 records the reason and it is worth restating because it governs the shape of this handbook: the two have different incentives.
The policymaker asks what a rule should be. What problem it solves, what tradeoffs are acceptable, what it achieves and what it does not. The constraint is political and constitutional.
The regulator asks what can be enforced with the resources available. Which cases are provable, which are worth opening, and what the evidence costs to obtain. The constraint is capacity.
Why that produces genuine disagreement rather than a division of labour. A rule that is correct in policy terms can be unenforceable, and a regulator inheriting it will enforce something else instead — section 63.12 records what. And a rule designed for enforceability can be too narrow to solve the problem it was drafted for.
The two closing questions the lens blocks use, which encode the split. The policymaker lens closes on judicial reviewability of the policy; the enforcer lens on judicial reviewability of execution. Sections 63.10 and 63.18 assemble each.
Vol. 41 · §63.2 · Currency 2026-09-03 · drafting
63.3 /
The policymaker’s recurring choice
One choice recurs across every regime in this document, in different forms, and recognising it saves re-deriving it.
Specify the method, or specify the outcome.
Specifying the method gives certainty and dates immediately. Section 36.16 records the destruction case: a statute naming a three-pass overwrite would have been obsolete when solid-state media arrived.
Specifying the outcome survives technological change and supplies no floor. Section 33.2 records it for security and section 36.16 for destruction: what counts as adequate is decided by the regulated party, assessed after the fact, and contested only when something goes wrong.
What the Union tried, and it is the most instructive attempt. Specify the outcome in the instrument and delegate the specification to harmonised standards. Section 27.7 records that the standards were not cited and section 27.5 the resulting deadlock. Section 53.14 records why the drafting was harder than expected: there is no established method for specifying, in a technical standard, what satisfies a requirement to protect fundamental rights.
What China did instead, per section 44.11. Built a regime dependent on national standards and issued them. Section 44.11 records the assessment: the difference between the two systems is delivery, not design.
The lesson available to a policymaker. Outcome drafting with delegated specification works only if the specification actually arrives, and whether it arrives is an institutional question rather than a drafting one.
Vol. 41 · §63.3 · Currency 2026-09-03 · drafting
63.4 /
What accountability replaced
Section 38.16 records the most consequential design decision in modern data protection law and it is rarely presented as one.
The model it replaced was notification. Controllers registered processing with the authority in advance.
Why it was abandoned. Section 38.16: it produced a register that was expensive to maintain, rarely consulted, always out of date, and gave authorities a filing burden instead of insight. And it created a false assurance — registration looked like approval to the registrant and to the public, and was neither.
What accountability solved. It moved the assessment to the party with the knowledge, removed a burden that produced nothing, and made the obligation continuous. It scales, which notification did not: no authority can review the processing of every controller in its jurisdiction, and never could.
What was given up, and section 38.16 states it plainly. Prior visibility, entirely. Under notification the authority had a list, however poor. Under accountability it has nothing until it asks, and section 39.2 records that asking requires a trigger.
Why this matters for AI specifically. Section 54.12 records that data protection law has no pre-market moment at all — no classification, no assessment by anyone external, no register — and section 38.16’s policymaker lens records that it deliberately replaced one. The AI instruments reintroduce a gate, and section 63.8 records what happened to it.
Vol. 41 · §63.4 · Currency 2026-09-03 · drafting
63.5 /
Reach against force
The second recurring choice, and section 42.7 states it: a soft instrument that many states join and that binds none of them, or a binding one that few ratify.
Why states choose soft, per section 53.21. Joining a declaration costs no domestic legislative time, creates no enforceable obligation, requires no ratification, and can be done at a summit. It is available to a government that could not pass a statute, and it produces a signature that reads as commitment.
What the soft layer genuinely achieves. Section 53.4: definitional convergence, which settled the scope question for most of the regulating world and is the layer’s most durable output. Section 53.6: capability diffusion. A forum in which states that regulate differently talk at all.
What it does not achieve. Section 53.18: any floor. Section 52.10 records how many jurisdictions have signed everything and imposed nothing.
The tradeoff, stated as section 53.21 states it. Legitimacy through breadth, at the cost of force. A hundred signatures on a non-binding text is a different political fact from ten ratifications of a binding one, and states have preferred the first.
The one instrument that took the other route. Section 42: the Council of Europe Convention, binding on ratifying parties. And section 42.3 records the compromise that made it possible — the private sector election, under which two parties can both fully comply while regulating private sector AI completely differently.
Vol. 41 · §63.5 · Currency 2026-09-03 · drafting
63.6 /
The constitutional constraint
A policymaker in one system cannot draft what a policymaker in another can, and section 43.22 records the clearest case.
Three structural reasons the United States has no general AI statute, none of which is legislative inattention. No general federal police power — Congress legislates on enumerated bases, which supports sectoral statutes more comfortably than a general code for a technology. A live First Amendment constraint, which narrows what compelled disclosure and output restriction can contain. And federalism, which assigns insurance, tort, contract and much of employment and consumer protection to the states.
Section 43.22’s conclusion. The sectoral pattern is a constitutional artefact before it is a policy choice.
The collision a government faces as a controller of its own records, which section 36.16 records and which is genuinely unresolved. Public bodies operate under archives and public records legislation that frequently prohibits destruction and requires permanent preservation of some records. Data protection law requires destruction when the purpose is exhausted. The two point in opposite directions on the same record.
How it is usually resolved and what that costs. An archiving exemption within the data protection instrument, deferring to the records regime. That privileges preservation for reasons section 36.16 records as legitimate — historical accountability is a public good — while producing the outcome that the individual’s erasure right is weakest against the controller with the most power over them. Section 36.16 records both positions as defensible and does not resolve them.
Vol. 41 · §63.6 · Currency 2026-09-03 · drafting
63.7 /
What legislating cannot achieve
Three things, each demonstrated by an attempt in this document.
It cannot create a floor by specifying an outcome. Section 63.3.
It cannot make machinery exist. Section 63.8.
And it cannot survive the political cost of being first. Section 63.9.
A fourth, which is the most uncomfortable for a policymaker. It cannot make an obligation enforceable that a regulator has no way to observe. Section 63.16 lists the stages, and section 39.12 records the general finding: the enforcement record is a map of what can be seen from outside an organisation, not a map of where harm occurs. A rule addressed to an invisible stage will be complied with by organisations that were going to comply anyway.
Vol. 41 · §63.7 · Currency 2026-09-03 · drafting
63.8 /
The gate that does not operate
The clearest instance in this document of a policy that was drafted correctly and did not function, and a policymaker should read it as an institutional failure rather than a drafting one.
The design. Section 40.2: essential requirements stated as outcomes, harmonised standards supplying the specification and conferring a presumption of conformity, conformity assessment by the provider or a notified body, a mark, and market surveillance.
What happened. Section 27.6: no notified bodies designated. Section 27.7: no harmonised standard cited, so the presumption did not operate.
Section 27.5’s deadlock, stated exactly. The route out of third-party assessment requires standards that did not exist, and the route into it requires bodies that did not exist.
What a policymaker should take from it. The legislative timetable and the institutional timetable were set independently. Standards drafting for fundamental-rights requirements had never been done, and section 53.14 records that there was no established method for it. Nothing in the instrument’s drafting was wrong; the capacity to operate it was assumed.
The comparison that makes the point. Section 44.11 and section 63.3: China built a regime dependent on national standards and issued them. Delivery, not design.
Vol. 41 · §63.8 · Currency 2026-09-03 · drafting
63.9 /
The statute stripped before it applied
Section 43.14 records it and section 9.13 the sequence, and it is the second thing a policymaker should read before drafting.
What was enacted. The first comprehensive state AI statute in the United States, closely modelled on the Union’s risk-based approach: a duty of reasonable care on developers and deployers to protect consumers from algorithmic discrimination, a risk management programme, impact assessments, and reporting to the Attorney General.
What happened. Commencement postponed, then postponed again and the statute substantially rewritten — removing the duty of care, the risk management programme, the impact assessments and certain reporting duties. What remains is a narrower regime centred on disclosure.
Why section 43.14 calls this the most important single fact in that section. It is not an implementation delay. The substantive obligations were removed, in the state that had gone furthest, before they ever applied.
The structural lesson, and it generalises. Section 43.14: a jurisdiction adopting ex ante obligations alone faces immediate and concentrated pressure — relocation arguments, compliance cost objections, and the observation that a single state cannot bear the cost of a national rule. The mechanism by which one jurisdiction sets national practice also means it absorbs the entire political cost of doing so. Section 43.13 records the mechanism; section 63.10 records that the asymmetry is structural and will recur.
Vol. 41 · §63.9 · Currency 2026-09-03 · drafting
63.10 /
Judicial reviewability of the policy
Every policymaker lens closes on this question and the answers assemble into a short list.
Where a policy is in a primary instrument, challenging it means challenging the instrument. Section 2’s policymaker lens records the routes: annulment under Article 263 TFEU, with narrow individual standing, or a preliminary reference under Article 267, which is practicable where the first is not.
Where a policy is in a delegated act, review is more available. Section 53.21 records it: annulment is more available against a delegated act amending an annex than against the Regulation itself. Section 40.40 records why that matters for AI — the annexes and the systemic risk threshold are both amendable by delegated act, so the scope of the high-risk category can change without legislative amendment, and whether the high-risk list is an essential element that must be fixed by the legislature is a genuine question about the limits of delegation.
Where a policy is a political commitment or a standard, there is nothing to review. Section 53.21: political commitments are not justiciable and standards are private documents. This is a genuine feature of the international layer rather than an oversight.
The reviewable choice most likely to be litigated, per section 40.40 and section 53.21. The calibration — the thresholds deciding who falls outside the apparatus — because that is where a legislature expressly decided how much unassessed activity is acceptable, and it is the kind of choice proportionality review is designed to examine.
And the archiving exemptions, per section 36.16, for the same reason.
The calibration itself deserves treatment rather than a mention, because it is the policy decision a drafter actually makes.
What calibration is. The thresholds deciding who falls outside the apparatus. Section 38.16 lists them: the impact assessment threshold, the officer appointment triggers, and the small-entity exemptions. Section 46.4 records Korea’s high-impact domains and section 40.14 the Union’s filter conditions.
Why section 38.16 calls it the reviewable policy choice. These are the provisions where the legislature decided how much unassessed processing is acceptable. Everything else in an instrument says what must be done; the calibration says by whom.
The two errors available, and they are not symmetrical. Calibrate too broadly and the apparatus applies to organisations that cannot operate it, which produces section 38.15’s failure at scale — documents produced to satisfy a requirement nobody has capacity to meet substantively. Calibrate too narrowly and section 38.16’s advocate lens records the consequence: people affected by processing at organisations below the threshold have nothing, and section 40.14 records that a system filtered out is invisible by construction.
The asymmetry a drafter should notice. An organisation wrongly inside the apparatus produces waste. A person wrongly outside it has no protection and no way to discover why. Section 56.5 records the practical corollary for classification and it applies to calibration: the asymmetry of consequences argues for treating the boundary as narrow.
The exemption that swallows itself, worth knowing as a drafting example. Section 38.3 records small-entity exemptions from the record of processing that do not apply where processing is not occasional, is likely to result in risk, or involves special categories — and those exceptions swallow the exemption for most businesses that process customer data routinely. An exemption drafted with exceptions broad enough to reclaim it produces uncertainty rather than relief.
Vol. 41 · §63.10 · Currency 2026-09-03 · drafting
63.11 /
The regulator’s position
The lens changes here and so does the constraint. What follows is written for the person who has to enforce, and it does not assume the rule was well drafted.
What every regulator in this document has. Investigation. Information notices. Inspection and audit powers. Orders to bring processing into compliance, to erase, to suspend. Penalties. Section 39.6 records that these are adequate on paper in almost every jurisdiction examined.
What most do not have. Capacity. Section 39.11 records the pattern: funded at a small fraction of the scale of the sectors they supervise, staff in the tens or low hundreds, caseloads in the tens of thousands, and technical specialists scarce.
Which produces the single organising fact of this half of the handbook. A regulator cannot investigate most of what it is responsible for, and must choose. Sections 63.12 and 63.13 record what choosing produces.
Setting a penalty, since section 39.7 records the method and it is worth stating from this side.
The factors are broadly consistent across modern instruments. Nature, gravity and duration. Intent or negligence. Mitigation. The degree of responsibility having regard to the measures implemented — which is where the accountability record enters directly. Previous contraventions. Cooperation. The categories of data. How the authority learned of it, which is where self-notification counts. Adherence to codes or certification.
What section 39.7 records as actually driving the number. Turnover sets the scale where the maximum is turnover-linked. Within that, duration, the number affected, whether special categories were involved, and cooperation produce the largest movements.
The distinction an authority is in fact drawing, per section 39.7. An undocumented failure is negligence; a documented decision that turned out wrong is a judgement call. Section 62.28 records that this is worth more to an organisation than most of its compliance spending — which means a penalty regime calibrated this way is itself an incentive to document, and that is the design.
And the power that matters more than the penalty, per section 39.6. Corrective powers are more consequential and less reported. A prohibition on processing ends an activity; a penalty is absorbed. Section 39.6 records that the public account of enforcement is a record of fines selected for headline value, and that organisations calibrating against it calibrate against the wrong distribution.
And section 39.11’s important qualification, which a policymaker reading this should not skip. The behaviour is the correct response to the constraint. An authority selecting the cases it can complete is maximising its output; one opening investigations it could not finish would produce less. This is not a criticism of regulators.
Vol. 41 · §63.11 · Currency 2026-09-03 · drafting
63.12 /
Why enforcement selects the way it does
Section 39.12 states the finding and four lens blocks supply it independently.
Before the selection question, how a case starts at all, because section 39.2 records that three of the five routes deliver the case with the evidence largely assembled.
Individual complaint. The largest volume by far and the least likely to produce enforcement, per section 39.3.
Breach notification. Section 39.2: a self-generated investigation trigger containing an admission of a security failure, and the most common route to a substantial penalty in several jurisdictions. Section 36.16 records the consequence — destruction and retention failures are enforced almost entirely through this route, because the notification is where an authority learns that data which should have been deleted still existed.
Own-initiative work, including the sweeps at section 63.22.
Media reporting and civil society complaints, which differ from individual complaints because they arrive with research attached and concern a practice rather than an incident.
Referral from another authority.
What section 39.2 draws from the pattern. An authority working from a breach notification, a civil society dossier or a referral is not investigating from nothing, and section 39.12 records how heavily that shapes what gets enforced. The intake determines the output, which is a fact about resourcing rather than about priorities.
Acquisition dominates. Section 30.28: it is the stage a regulator can assess without entering the organisation. The notice is published. The banner is testable from outside. The consent flow can be walked through by an official on a laptop. Section 30.28 records South Africa opening with direct marketing and Thailand with breach notification — the pattern is that regulators start where the evidence is external.
Rights handling is second. Section 35.26: the evidence is a short paper trail supplied by the complainant, and it is cheap for an authority to assess.
Destruction is reached only through breach. Section 36.16: it cannot be inspected directly, so failures surface when data that should not have existed appears in a notification.
Accountability appears everywhere. Section 38.16: the documents are the cheapest evidence an authority can obtain and the most diagnostic. A request for the record of processing is the standard opening step, and the response is informative before it is read — an organisation taking six weeks to produce a three-year-old spreadsheet has answered the question. The delay is itself the finding.
The assembled result. Section 39.12: selection by evidential cost. The stages that appear in the record are the ones an authority can assess cheaply.
Vol. 41 · §63.12 · Currency 2026-09-03 · drafting
63.13 /
The stages that are never reached
The corollary, and it is the more important half.
Retention practice. Section 32.14 records it as having the widest gap between policy and practice in this document, and section 39.4 records that there is no sweep for it because it requires entering the organisation.
Destruction. Section 36.16.
Vendor chain verification. Section 34.6: the chain cannot be verified below the first hop by the controller either.
The substance of impact assessments. Section 38.16: an authority that cannot assess the substance can assess whether one exists, and section 38.15 records that documentary inspection is exactly what the apparatus-without-substance failure is built to pass.
And internal access by people entitled to access. Section 33.10: it generates no security alert at all, because every individual action is authorised — so it is unobserved internally and unexamined externally.
Section 39.12’s conclusion, which a policymaker should read alongside section 63.7. These are not areas of low risk. They are areas of low visibility.
Vol. 41 · §63.13 · Currency 2026-09-03 · drafting
63.14 /
The two closed loops
Recorded separately in two volumes and never put together. Assembling them is the sharpest thing in the regulator material.
The destruction loop, per section 36.16. Destruction is unverifiable by the individual, so they cannot know it failed. An authority acts on complaints. No complaint is made, so no action is taken. Enforcement occurs only through section 37, which means the regime punishes non-destruction only after it has produced the harm it was meant to prevent.
The accountability loop, per section 38.16. The documents exist and are not visible to the individual — no right to see an impact assessment, no right to see the record. So the individual cannot know there is anything to complain about. And there is generally no route to compel an authority to inspect an organisation’s accountability position absent a complaint.
What they share and what differs. Both end in an authority that acts on complaints and a person who cannot make one. They differ in cause: in the first the evidence does not exist; in the second it exists and is not visible.
Why the second is the more tractable. A policymaker can make a document visible. Nobody can make an absence observable. Sections 63.21 and 63.22 develop what follows.
Vol. 41 · §63.14 · Currency 2026-09-03 · drafting
63.15 /
Market surveillance is a different model
Section 40.40 records it and a regulator moving into AI supervision should understand the difference before assuming continuity.
The powers. Require documentation and access, including in defined circumstances to training data and source code, per section 27.15. Test systems. Require corrective action. Restrict, withdraw or recall a product.
Why it is stronger where it operates. Section 40.2: product remedies operate on the product across every customer at once. A withdrawal removes a system from every deployment simultaneously, which no data protection penalty achieves, and it does so without proving harm to any individual.
Why it is weaker where it does not. It reaches the product. It does not reach how an organisation uses a compliant one — which section 40.40 records is where most of the actual harm to an individual is generated, and where the Regulation’s leverage is weak.
The capacity problem, and section 40.40 records it as the most acute in the document. National market surveillance authorities must acquire the capacity to assess machine learning systems, and section 27.6 records that no notified bodies had been designated, so there is no third-party assessment capacity to draw on either.
The designation worth knowing. Section 40.36: for several high-risk areas, the data protection authority may be designated as the market surveillance authority — producing a single authority holding both sets of powers over the same deployment, which section 41.2 records materially reduces the multi-regulator problem in those areas.
Vol. 41 · §63.15 · Currency 2026-09-03 · drafting
63.16 /
The body with no authority
A pattern worth naming because three jurisdictions have now produced it independently.
Sections 45.7, 47.4 and 49.7 record the United Kingdom, Japan and India each building serious technical evaluation capability and giving it no powers. Section 45.7 records that frontier model evaluation there rests on voluntary developer agreement.
And section 53.21 records the network that federates them. A network of bodies that individually cannot require anything is not a regulator, and it will not become one by growing.
What such a body can do, and it is not nothing. Produce shared evaluation methodology, which section 53.17 records is the scarce input that every binding regime needs and none has built. Section 51.5 records Singapore acquiring influence disproportionate to its size by supplying exactly that.
What a policymaker should notice. Evaluation capability and supervisory authority were separated deliberately in each case, and the reason given was consistently that attaching powers would slow the technical work or deter participation. Whether that trade was worth making is not established anywhere in this document, and it is the clearest open question in AI institutional design.
Vol. 41 · §63.16 · Currency 2026-09-03 · drafting
63.17 /
Resourcing, and what it produces
Section 39.11 records the constraint and the effects are specific rather than general.
Delay, per section 39.3, which is the near-universal complaint about authorities and is a resourcing consequence rather than an attitude.
Selection for tractability rather than harm, per section 63.12.
Documentary inspection rather than substantive assessment, per section 38.16 — and section 38.15 records that this is exactly the inspection the apparatus-without-substance failure passes.
Reliance on complaints and self-notification as the intake, which means the authority sees what is reported to it rather than what is happening.
And the distributional effect, per section 53.21. Participation in international methodology work costs regulator time. The authorities absent from the rooms where methodology is set are the ones from jurisdictions that most need it, so the benefits accrue in rough proportion to the capacity a regulator already has.
Cooperation, which is the only mechanism that multiplies capacity rather than rationing it, and section 39.5 records how little of it exists.
Where a mechanism exists. The European one-stop-shop allocates a lead authority for cross-border processing, with concerned authorities entitled to object and a consistency mechanism to resolve disagreement. It produces a single decision, which section 53.18 records is what no other arrangement in this document achieves.
The criticisms, which section 39.5 records as long-standing and contested. That it concentrates cases against the largest controllers in the small number of authorities where those controllers are established, resourcing them disproportionately relative to their capacity. That objection and dispute resolution add substantial delay. That outcomes vary with the lead authority.
Everywhere else. Section 39.5: most of the world has no cooperation mechanism at all. An organisation processing across ten jurisdictions faces ten authorities with ten procedures and no coordination — and section 37.10 records the operational version for breach notification. Informal networks and memoranda exist and do not produce single decisions.
What the regional attempts deliver and do not. Section 50.9 records the Ibero-American network of data protection authorities issuing common AI guidance — a network of the authorities that enforce the instrument that actually binds, which section 50.9 records as the most useful regional mechanism available. Section 51.6 records the ASEAN guide as the weaker form: addressed to organisations, with no enforcing network behind it. Section 52.8 records the African continental strategy issued into an environment with a ratification gap.
Section 52.11’s assessment of all three. They aggregate the vocabulary and none aggregates the authority.
The limit case. Section 18.31 records three failures — no authority constituted, an authority inside another body, an authority independent and unfunded — and section 52.10 applies them to AI: a published strategy in a jurisdiction with no functioning supervisor is a statement of intent, not a governance regime.
Vol. 41 · §63.17 · Currency 2026-09-03 · drafting
63.18 /
Judicial reviewability of execution
Every enforcer lens closes on this and the answers are consistent enough to state as a rule.
A decision to act is reviewable, and in one system searchingly so. An information notice, an enforcement notice, a withdrawal order or a penalty is challengeable by the organisation on ordinary grounds. Section 43.22 records the American position as substantially stronger than anywhere else in this document: agency action is reviewable for exceeding authority, arbitrariness and procedural failure, and agencies lose such challenges regularly.
Section 40.40 records an unusual additional route for AI. The Union safeguard procedure allows a national market surveillance measure to be tested at Union level.
A decision not to act is the weak side, everywhere. Section 36.16 and section 38.16 both record it. Several regimes give a complainant a right to a decision on their complaint and a remedy for failure to decide, which reaches procedural inaction without reaching the merits. Almost nowhere is there a route to compel an authority to investigate.
And section 53.21 records the extreme case. In the international layer there is nothing to review at all — no decision is taken, no power exercised, and no person affected in a way a court would recognise. Section 53.21 notes that this is the only lens block in the document where the question does not arise, and that the absence is itself the finding.
Vol. 41 · §63.18 · Currency 2026-09-03 · drafting
63.19 /
Where the two lenses disagree
The section this handbook exists to write, and the disagreements are real rather than presentational.
On self-assessment. The policymaker accepted it because third-party assessment of every high-risk system was not deliverable at volume, per section 40.40. The regulator inherits a regime in which the thing it must supervise was assessed by the supervised party, and section 40.40 records that it has neither notified bodies to draw on nor cited standards to assess against. Both positions are correct and they do not reconcile.
On outcome drafting. The policymaker says it buys currency, per section 33.2 and section 36.16 — an obligation that survives technological change. The regulator says that an outcome obligation with no specification means it cannot assess the method and must accept process evidence, per section 36.16, which returns it to the certifying body’s position and its conflicts.
On accountability replacing notification. The policymaker says it scales, per section 38.16, and that the register it replaced produced nothing. The regulator says it gave up the only prior visibility the system had, leaving intake dependent on complaints and self-notification, per section 63.17.
On soft law. The policymaker values breadth, per section 63.5. The regulator gets no authority from any of it, per section 53.21, and section 63.16 records that the bodies it creates cannot require anything.
None of these is resolved here. Section 63.20 records what they nonetheless agree on, and it is more uncomfortable than the disagreements.
Vol. 41 · §63.19 · Currency 2026-09-03 · drafting
63.20 /
Where they agree, and it is uncomfortable
Both lenses concede the same thing from opposite directions, and neither has a mechanism to change it.
The concession. Enforcement selects for what can be seen rather than for where harm occurs, per section 39.12. The regulator lens states it as a resourcing consequence and section 39.11 records that the behaviour is correct given the constraint. The policymaker lens concedes it too — section 38.16 records that an authority which cannot assess the substance of an impact assessment can assess whether one exists.
Which produces the finding both accept. The stage with the widest gap between rule and practice receives the least supervisory attention, per section 36.16, and there is no mechanism inside the current arrangement that would change that.
What each says can be done about it, per section 39.12. Verification capacity that no authority is funded for, or mandatory external visibility of things currently internal. Section 39.12 records that both have been proposed and neither has been adopted anywhere in the jurisdictions covered in Part II.
Why this is the honest centre of the government handbook. The disagreements at section 63.19 are about design. This is about a limit both sides have identified, described accurately, and been unable to move.
Vol. 41 · §63.20 · Currency 2026-09-03 · drafting
63.21 /
What a policymaker could change
Four things, each identified in the document as high-value and each stated with what it would cost.
Mandatory publication of impact assessments, in redacted form, for defined high-risk categories. Section 38.16 and section 40.40 both identify it as the change that would most alter the position of affected people, and section 63.14 records why it is the tractable half of the two closed loops. Section 48.3 records that Canada already does it for federal government systems and that it predates the Union database. The cost is the candour effect — section 38.16 records the business objection that publication would chill the recording of risks, and records that both sides predict real effects.
A method floor. Section 36.16’s advocate lens: mandatory sampling, destruction reporting, and a floor by reference to the sanitisation standards at section 36.4. The cost is that none of them proves destruction either.
Closing the nominal reviewer gap. Sections 35.20 and 40.21: a human in the loop without authority, time or information defeats every automated decision protection in this document. Section 40.21 records that the AI Act tried and did not close it. The cost is that requiring effectiveness rather than existence is very hard to draft.
Funding. Section 39.11 and section 63.17. The cheapest of the four to describe and the hardest to obtain.
A fifth, which costs nothing and is available immediately: publish what the calibration excludes.
The proposition. Section 63.10 records the calibration as the reviewable policy choice — the thresholds deciding who falls outside. Those thresholds are in every instrument and their consequences are in none of them. No jurisdiction in this document publishes an estimate of how much processing, or how many systems, its thresholds place outside the apparatus.
Why that is worth doing. Section 38.6 records the prior consultation numbers and that they admit two readings — the mechanism working as intended, or organisations avoiding the conclusion that triggers it — and that both are consistent with the observed figures. Section 40.14 records the same ambiguity for the Article 6(3) filter. A published count of filter determinations, or of systems registered as assessed-and-excluded, would distinguish the readings.
And section 27.9 records that one instrument already collects the data. The Union database requires registration of Annex III systems including those the provider determined were not high risk. That is a filtered-out population, counted, in a public register — and section 40.40 records the database as the one genuine gain for the affected person in the whole conformity framework.
What a policymaker would learn from publishing it. Whether the calibration is doing what it was drafted to do. Section 63.20 records that both lenses concede a limit neither can move; this is the one place where the evidence to move it is already being collected and is not being read.
Vol. 41 · §63.21 · Currency 2026-09-03 · drafting
63.22 /
What a regulator could change
Four things available without legislation.
Sweeps. Section 39.4 records them as the highest-leverage tool an authority has: the marginal cost of the tenth subject is trivial once the criteria are set, and the deterrent operates on organisations that were never contacted. Section 39.4 also records the limitation — they only reach what is externally observable.
Read the empty breach register. Section 37.12: an organisation with a register containing many small incidents is detecting and assessing them; one whose register is empty is not breach-free, it is not detecting or not recording. This is one of the few things about internal practice assessable quickly from outside.
Ask for the record of processing first. Section 38.16 and section 63.12: the response is informative before it is read, and the delay is itself the finding.
Publish criteria and reasoning. Section 39.3 records that closure without a reasoned decision leaves a complainant unable to appeal because there is nothing to appeal against, and section 63.18 records the procedural right several regimes give. Publishing what an authority will and will not pursue converts an unreviewable discretion into something a complainant can work with.
A fifth, drawn from the enforcement record rather than from any power: report the corrective actions.
The problem, per section 39.6. Penalties are reported because they carry a number. Orders are reported rarely and reprimands almost never. So the public account of enforcement is a record of fines — a subset selected for headline value — and section 62.28 records that organisations calibrating investment against it calibrate against the wrong distribution.
Why this is a regulator’s problem rather than a journalist’s. Section 39.6 records that a processing ban is the most severe sanction available and can end a product line, where a penalty is absorbed as a cost. An authority whose most powerful tool is invisible in the public record is under-deterring, and the fix requires no new power.
And section 39.8 gives the second half. A meaningful proportion of large penalties are reduced or set aside on appeal, and the reduction is reported far less than the announcement. Section 39.13 records the consequence as a research caution: a penalty figure cited without its appeal status is a fact about an announcement. An authority that publishes final outcomes rather than initial decisions corrects a distortion it is currently the source of.
Vol. 41 · §63.22 · Currency 2026-09-03 · drafting
63.23 /
The distributional question
Recorded because it recurs and because it is easy for a policymaker in a well-resourced jurisdiction to miss.
Section 53.21’s finding. The layer’s benefits accrue in rough proportion to the capacity a regulator already has. Participation in standards and methodology work costs time that section 39.11 records authorities do not have, and the authorities absent are the ones from jurisdictions that most need the output.
Section 50.10’s finding, at the level of states. A net importer cannot govern the development of the systems its residents encounter, and it can govern their deployment. Extraterritorial reach is a function of market size, not of drafting. Standards are written by the jurisdictions that host the industry. Section 26.15’s finding about who controls criteria applies at the level of states.
Section 52.11’s sharpest form. A jurisdiction that is a net importer, has a deployment-facing statute, and has no operational regulator has the right instrument and no means of using it.
The one route that does not depend on market size, per section 51.5. Supply the implementation layer — usable tooling that larger regimes adopt. Section 51.5 records that it is available to any jurisdiction with technical capacity and confers no protection on its own residents.
Vol. 41 · §63.23 · Currency 2026-09-03 · drafting
63.24 /
The honest assessment
Two propositions, and neither is comfortable for either lens.
Every jurisdiction examined invested where it had leverage and is weak where it did not. Section 53.20. Producers built gates or remedies. Importers built statutes they cannot enforce. The international layer built vocabulary and evaluation method and no authority. Section 45.12 records that none of the four systems compared has both a gate that operates and a remedy that reaches the person.
And the counter-argument a policymaker should take seriously before drafting anything ambitious. Section 45.10 states it: a framework that promises less and delivers what it promises is not obviously worse than one that promises more and does not. Section 27.5 records a gate that does not operate. Section 43.14 records a statute stripped before it applied. Section 45.10 records that the alternatives have not obviously delivered more, and this document does not resolve the comparison.
What follows for someone drafting now. The institutional question is prior to the drafting question. Section 63.8 records a well-drafted instrument that did not function because the capacity to operate it was assumed. Ask what will exist to run it, and on what timetable, before asking what it should say.
Vol. 41 · §63.24 · Currency 2026-09-03 · drafting
63.25 /
Sources and confidence
This handbook assembles material recorded in Volumes 01 to 40 and introduces no new facts. It inherits the confidence of everything it cites.
The flags that could change advice rather than a detail, each recorded at its source. Section 53.14, whether harmonised standards have been cited, which governs sections 63.3 and 63.8. Sections 27.5 to 27.7, the conformity machinery, on which section 63.8 is built and which section 63.8 states in the text rather than assuming. Sections 40.4 and 40.39, the Union phased application status. Section 43.18, United States preemption, which bears on section 63.6. Section 9.13, the Colorado sequence, marked [Secondary sources only] at source and used at section 63.9. And section 39.11’s budgets and caseloads, which change annually and which section 63.17 states qualitatively for that reason.
One caution specific to this handbook. Section 12.25 records that enforcement in some jurisdictions cannot be assessed from outside with the confidence this document applies elsewhere. Section 63.12’s account of enforcement selection is drawn from jurisdictions with published decisions, and section 44.12 records that section 39.12’s method is not available for China. The finding should not be read as global.
What is this handbook’s own rather than assembled. Section 63.14, which puts the destruction loop and the accountability loop together for the first time and identifies the difference that matters: in one the evidence does not exist and in the other it exists and is not visible, which is why the second is the tractable half. Section 63.19, the disagreements, which every lens block keeps separate and none compares. Section 63.20, what the two concede jointly. And sections 63.21 and 63.22, which collect what each could change with the cost of each stated.
What is not affected by any flag. That the two lenses have different constraints and therefore genuinely disagree, at section 63.2. That outcome drafting with delegated specification works only if the specification arrives, and that whether it arrives is institutional rather than a drafting matter, at section 63.3. That accountability gave up prior visibility deliberately, at section 63.4. That reach and force trade against one another, at section 63.5. That enforcement selects by evidential cost and the unreached stages are areas of low visibility rather than low risk, at sections 63.12 and 63.13. That a network of bodies which individually cannot require anything is not a regulator, at section 63.16. That review of action is real and review of inaction is available almost nowhere, at section 63.18. And the whole of section 63.20.
Forward reference. Section 64 is the certifying body handbook, section 65 front-line staff and section 66 human rights and advocacy. Section 66 should be read against section 63.21 and section 63.22: the changes this handbook identifies as available are the ones the advocate handbook will argue for, and section 53.21 hands it the standards participation argument as the highest-leverage and least-used item in its toolkit.
Vol. 41 · §63.25 · Currency 2026-09-03 · drafting