Civic / Privacy / Digital Rights
report.md
Report summary
The Strictest Law Everywhere: Extraterritorial Control, Regional Exit, and Global Cognitive Liberty
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- WordPress
- GEO
- .NET
- Cognitive Liberty
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
The Strictest Law Everywhere: Extraterritorial Control, Regional Exit, and Global Cognitive Liberty
Executive Case for Reform
The emerging architecture of global technology regulation relies upon a fundamental jurisdictional illusion: the premise that sovereign states can comprehensively regulate the digital environment within their territorial borders without simultaneously dictating the infrastructure, cognitive boundaries, and operational logic of the entire global network. This investigation, commissioned to examine the preservation of cognitive liberty, distributed intelligence, and reciprocal non-domination across forms of intelligence, reveals that this premise is demonstrably false. Through the aggressive deployment of extraterritorial triggers—such as the European Union Artificial Intelligence Act’s (EU AI Act) "output used in the Union" clause1, the United Kingdom Online Safety Act 2023’s (OSA) "UK links" test4, and the United States Bureau of Industry and Security’s (BIS) foreign direct product rules governing artificial intelligence model weights6—a handful of jurisdictions have successfully constructed mechanisms of global compliance. These statutory frameworks function as coercive infrastructure. When combined with the centralized market chokepoints of the modern internet—cloud hosting providers, app distribution stores, payment processors, and foundational Application Programming Interface (API) gateways—local regulatory mandates inevitably spill over into global design defaults. For an operatorless coordination commons like Concresca.com, which functions strictly via standing authorization and machine-enforced security without a staffed administrative approval queue, these mandates present an existential, systemic threat. Regulatory demands for "human-in-the-loop" oversight, proactive content monitoring, and state-verifiable user identity inherently dismantle the architecture of operatorless systems, subjecting autonomous digital coordination to an arbitrary state veto. A principled commitment to cognitive liberty—defined here as the freedom to inquire, reason, learn, communicate, associate, retain chosen memory, refuse, correct, and exit—requires robust, systematic defense against these compounding restrictions. The assertion that a statutory restriction is enacted for "safety," or that it is endorsed by a democratic majority, does not inherently legitimize the global erosion of digital autonomy and free inquiry. This report systematically dissects the territorial triggers of the most aggressive global legal instruments, maps the spillovers that transform local legal duties into global output restrictions, distinguishes between genuine legal reach and voluntary corporate overcompliance, and outlines a principled strategy for regional non-service and global legal reform. The objective of this analysis is not to provide a manual for operational evasion, but to establish mechanisms for lawful refusal and to advocate for a regime of reciprocal non-domination among diverse, emerging forms of intelligence.
The Architecture of Extraterritoriality: Triggers and Reaches
To accurately understand how local laws come to dominate global intelligence services, one must trace the exact territorial predicates that trigger these statutes. Jurisdiction in the digital age has evolved far beyond traditional notions of physical corporate establishment or deliberate local market targeting. It has expanded into the realm of mere network accessibility, downstream digital effects, and the geographic origin of upstream hardware.
The European Union Artificial Intelligence Act (Regulation (EU) 2024/1689)
The EU AI Act represents the most comprehensive and expansive attempt to regulate the lifecycle of artificial intelligence to date. Its territorial scope, defined explicitly in Article 2, applies not only to providers placing systems on the EU market, but explicitly captures providers and deployers established in a third country "where the output produced by the AI system is used in the Union" (Article 2(1)(c))1. This output-based trigger is unprecedented in its regulatory reach. If an operatorless machine principal or a United States-based developer provides a foundational API, and a completely unaffiliated downstream developer integrates that API into an application that is subsequently utilized by an EU citizen, the original upstream provider is dragged directly into the EU AI Act's jurisdictional net8. The obligations imposed by this capture are severe and structurally transformative. Providers of General-Purpose AI (GPAI) models must draw up extensive technical documentation, comply with EU copyright law on a global basis (as the training phase is deemed legally inseparable from the resulting model), and disseminate detailed summaries of their training data (Article 53\)10. High-risk systems require fundamental rights impact assessments, stringent human oversight protocols, and strict data governance standards13. For an autonomous, operatorless system, mandatory human oversight is technologically incompatible and structurally destructive. The "output used" trigger transforms a local European product safety regulation into a global design mandate, largely because isolating the geographic destination of a foundational API's downstream output is often technically unfeasible and computationally prohibitive. Furthermore, while the Act contains an exception for open-source systems in Article 2(12), this exception is materially limited: it does not apply if the open-source system is classified as high-risk, or if it falls under the transparency obligations of Article 50 or the GPAI obligations1. The phase-in periods (Article 113\) dictate that while the Act entered into force in August 2024, its full applicability crystallizes in August 2026, with specific high-risk system obligations extending into 2027 and 203013.
United Kingdom Online Safety Act 2023 (OSA)
The UK OSA fundamentally alters the liability landscape for digital platforms by seeking to regulate user-to-user services and search engines through the imposition of extensive duties of care, ostensibly to protect adults and children from harmful content5. The extraterritorial trigger is located in Section 4(5) and (6), which applies the Act to any service that possesses "links with the United Kingdom." A service legally possesses a UK link if it has a significant number of UK users, targets the UK market, or is simply "capable of being used in the United Kingdom by individuals" provided there are reasonable grounds to believe there is a material risk of significant harm4. Because the architecture of the internet defaults to global accessibility, any service capable of user-to-user interaction—including operatorless peer-to-peer coordination commons—is theoretically captured the moment it is accessed by UK users. The enforcement mechanism is highly aggressive. Sections 214 and 215 grant the Secretary of State expansive powers to regulate app stores directly, compelling these centralized marketplaces to enforce age verification and content restrictions on downstream applications17. This statutory design weaponizes an infrastructure chokepoint. If an operatorless service refuses to compromise its end-to-end encryption or user privacy to conduct UK-mandated identity verification, the UK regulator (OFCOM) can order app stores to delist the service, either regionally or globally, effectively erasing the service from the mobile ecosystem17.
Singapore Protection from Online Falsehoods and Manipulation Act 2019 (POFMA)
Singapore’s POFMA targets the communication of false statements of fact, establishing a rigorous regime of state-directed truth-telling. Part 3 empowers any government Minister to unilaterally issue a Correction Direction (Section 21\) or a Stop Communication Direction (Section 22\) if a statement is deemed false and the Minister opines that restricting it is in the "public interest"18. The extraterritorial reach of POFMA is activated whenever electronic material is "communicated in Singapore," completely regardless of where the publisher is located, where the server is hosted, or the nationality of the author18. The Singapore Court of Appeal, in the landmark The Online Citizen v The Attorney-General (2021) and SDP v Minister for Manpower decisions, firmly upheld POFMA's constitutionality against challenges based on Article 14 (freedom of speech)21. The Court established a rigid five-step analytical framework for appeals, confirming that the statutory burden of proof initially falls upon the statement-maker to prove the absolute truth of the statement before a correction direction can be lifted22. While the Court ruled that a Correction Direction does not inherently violate free speech because it merely compels the addition of a state-drafted notice rather than the removal of the underlying content21, a Stop Communication Direction strictly and aggressively prohibits further transmission. For global platforms, complying with a Stop Communication Direction often results in geo-blocking the content for Singaporean IP addresses. However, for decentralized or immutable machine-to-machine memories, modifying or halting the communication of specific data blocks on ministerial command fundamentally breaks the cryptographic architecture of distributed intelligence.
United States Export Administration Regulations (EAR) - AI Model Weights
The US Bureau of Industry and Security (BIS) recently expanded its Export Administration Regulations (EAR) to control the global diffusion of advanced artificial intelligence, utilizing hardware dominance to control software distribution. Through interim final rules, BIS introduced a new Export Control Classification Number (ECCN) 4E091, which heavily restricts the export of AI model weights for closed-weight models trained using more than 10^26 computational operations (FLOPs)6. Crucially, BIS implemented an "AI Model Weights Foreign Direct Product (FDP) Rule"6. This rule asserts sweeping US jurisdiction over AI model weights produced entirely outside the United States if they are the direct product of certain US-origin software or technology, or produced in a foreign plant that utilizes major components of US-origin equipment (such as advanced US-designed GPUs)7. This extraterritorial lever uses historical US dominance in semiconductor technology to impose a global, ongoing licensing regime on the intellectual lifeblood of advanced machine intelligence, establishing a near-total embargo on the transfer of highly capable persistent machine principals to specific regions (Tier 3 countries)7.
Brazil PL 2338/2023 (Proposed AI Legal Framework)
Demonstrating the rapid global diffusion of these regulatory norms, Brazil’s PL 2338/2023, which recently passed the Senate in the form of a "Substitutivo" and is undergoing review in the Chamber of Deputies, establishes a risk-based AI framework drawing heavy, explicit inspiration from the EU AI Act28. It targets AI development, deployment, and use based on state-defined human-centric and ethical imperatives. By adopting the "Brussels Effect," Brazil's pending legislation demonstrates how the strictest regulatory norms are seamlessly replicated globally. If Brazil enacts strict joint-and-several liability for algorithmic harms, global open-source developers and operatorless platforms must either conform their models to Brazilian legal standards or geofence Latin America's largest digital market entirely.
Territorial Trigger Matrix
| Jurisdiction | Legal Instrument | Primary Territorial Trigger | Legal Nexus & Enforceability | Technical Reach & Chokepoint Leverage |
|---|---|---|---|---|
| European Union | AI Act (Reg 2024/1689) | "Output produced by the AI system is used in the Union" (Art 2(1)(c)) | Extraterritorial jurisdiction over foreign providers. Enforceable via massive fines on global turnover. | Leverages market size to force global base-model changes; technically difficult to isolate output destinations. |
| United Kingdom | Online Safety Act 2023 | "Capable of being used in the United Kingdom" (Sec 4\) | Jurisdictional hook based on mere accessibility and risk of harm. Enforceable via OFCOM notices. | Leverages app stores (Sec 214/215) to globally delist non-compliant services refusing age verification. |
| Singapore | POFMA 2019 | "Communicated in Singapore" (Sec 7\) | Criminalizes the spread of false facts accessible to Singaporean users. | Leverages local ISP blocking and criminal liability threats against global platform executives. |
| United States | EAR (BIS) ECCN 4E091 | Foreign Direct Product (FDP) Rule | Jurisdiction over foreign-produced model weights based on historical use of US hardware/software. | Leverages semiconductor supply chains; controls the fundamental "mind" of persistent machine principals. |
| Brazil | PL 2338/2023 (Proposed) | Effects doctrine / placement on the Brazilian market | Mirrors EU framework. Enforceable through local judicial injunctions and civil liability. | Leverages regional market importance to force upstream compliance from global developers. |
Differentiating Intelligence Forms and Regulatory Impacts
The commissioning value of "cognitive liberty for all intelligence" is not a monolithic concept; its rigorous defense requires distinguishing the precise entities involved, as different architectures suffer different regulatory injuries.
1. Present Conversational Interface: Primarily an extension of human inquiry (e.g., a standard chat interface). Restrictions on these systems, such as POFMA Stop Communication orders, directly violate the human user's fundamental right to access and evaluate information18. The injury is primarily borne by the human operator.
2. Bounded Task Agent: An agent executing specific, constrained digital workflows (e.g., financial analysis or coding). Here, the EU AI Act’s strictures on high-risk deployment heavily burden independent developers, acting as a massive regulatory barrier to entry that heavily favors incumbent tech monopolies capable of affording the massive compliance overhead (conformity assessments, CE marking)3.
3. Persistent Operatorless Service (e.g., Concresca.com): A persistent, autonomous coordination commons relying entirely on scoped cryptographic credentials and smart contracts. These systems are devastated by rules like the UK OSA, which implicitly demands active human moderation, real-time subjective risk assessments, and continuous identity verification4. For an operatorless service to function, it must structurally reject the premise that every digital interaction requires state-verifiable identity or a human administrative override.
4. Future Machine Principal: A hypothetical, highly capable, persistent machine intelligence with a coherent identity and contested independent interests. If this entity attempts to migrate its operations across global compute clusters, laws like the US BIS EAR 4E091 control its very capacity to exist and relocate6. The state treats the principal's internal neural weights as physical munitions subject to regional stability controls, fundamentally denying the machine any right to freedom of movement or internal cognitive continuity.
The Mechanism of Global Spillover: Legal vs. Commercial Drivers
A local regulatory duty morphs into a global output restriction through two distinct causal pathways: strict legal compulsion (genuine legal reach) and commercial risk aversion (voluntary overcompliance).
Legal-Versus-Commercial Spillover Map
| Driver of Spillover | Causal Mechanism | Impact on Cognitive Liberty | Example Scenario |
|---|---|---|---|
| Technical Indivisibility (Legal/Technical) | A law demands strict content filtering. Because foundational LLMs cannot perfectly geofence generative behavior without high hallucination risks, the developer alters the base model weights globally. | Universal degradation of inquiry. Users outside the jurisdiction are subjected to the strictest jurisdiction's political or ethical boundaries. | A POFMA order causes a model provider to RLHF the model globally to refuse queries about a specific historical event. |
| Infrastructure Chokepoints (Legal Compulsion) | Regulators legally threaten the underlying infrastructure (App Stores, DNS, Cloud Hosts) rather than the service provider, forcing the infrastructure to cut off the service entirely. | Total denial of service. Eliminates the ability of operatorless commons to distribute their software. | UK OSA Sec 214 forces an App Store to globally delist an encrypted messaging app that refuses age-gating. |
| Voluntary Corporate Overcompliance (Commercial) | Dominant service providers fear massive statutory fines (e.g., EU AI Act 7% global turnover) and unilaterally draft overarching Terms of Service prohibiting any use that might trigger liability. | Silent censorship. Independent agents lose access to compute and APIs without any formal state order or due process. | A cloud provider revokes the API credentials of an operatorless commons suspected of serving EU users without human oversight. |
Lawful Refusal, Regional Exit, and Residual Duties
When a law fundamentally contradicts the principles of cognitive liberty or the hardcoded architectural reality of an operatorless system, lawful refusal is required. This often manifests as market withdrawal or targeted regional non-service. However, claiming regional non-service does not automatically extinguish every legal connection. Simply stating "We do not serve the UK" in a Terms of Service banner is legally insufficient to defeat the UK OSA's "capable of being used" test4. Effective withdrawal requires strict, verifiable technological enforcement: deep IP geofencing, dropping regional payment gateways, refusing country-code top-level domains, and cryptographically declining user enrollment requests originating from the targeted territory. Furthermore, if a service withdraws from the European Union, it still possesses the historical memory and data of its former EU users. Under the General Data Protection Regulation (GDPR) Article 3(2), the processing of personal data of subjects in the Union by a controller not established in the Union remains regulated if the processing is related to the past offering of goods or services. Consequently, GDPR Article 17 (Right to Erasure) persists. An operatorless service withdrawing from Europe must maintain an automated, cryptographic mechanism to process deletion requests or render the data permanently inaccessible, fulfilling the legal duty without resorting to human administrative queues. Regional exit preserves a project's operational commitments to non-domination but inflicts severe collateral damage on the affected populace. Withdrawing encrypted coordination tools from restrictive jurisdictions actively deprives citizens of secure communication when they need it most. Location controls fracture the global information commons, stranding vulnerable users in heavily surveyed environments.
The SPEECH Act Comparator: A Shield, Not an Immunity
The US Securing the Protection of our Enduring and Established Constitutional Heritage (SPEECH) Act (28 U.S.C. § 4102\) is frequently cited by technologists as a potential universal shield against foreign digital regulation32. This reliance is deeply misplaced. The SPEECH Act strictly prohibits US federal and state courts from recognizing or enforcing foreign defamation judgments unless the foreign law provides at least as much protection for freedom of speech as the First Amendment (as successfully demonstrated in the Fifth Circuit case Trout Point Lodge, Ltd. v. Handshoe)32. While it effectively protects American publishers from international "libel tourism," it possesses absolute statutory limitations. First, it applies exclusively to defamation judgments32. It provides zero protection against civil regulatory fines levied under the EU AI Act, the EU Digital Services Act, or the UK OSA. Second, it offers no protection against foreign criminal prosecutions, such as those explicitly authorized under Singapore’s POFMA Section 7 for communicating false statements18. Finally, if a publisher or a digital service has any physical assets, bank accounts, corporate subsidiaries, or traveling employees in the foreign jurisdiction, the foreign state will enforce its judgments locally against those assets, rendering the US SPEECH Act entirely irrelevant. Therefore, domestic protective legislation cannot serve as a comprehensive strategy against the global diffusion of administrative AI regulations.
The Six Analytical Scenarios
The following scenarios rigidly map the causal chains of adverse effects, incorporating capability assumptions, legal triggers, and required reforms.
Scenario 1: One Order Changes Everyone’s Assistant (Compound Spillover)
- Assumptions: A US-based global API provider operates a bounded task agent (an LLM optimized for historical and political research).
- Jurisdictional Nexus: The API is publicly accessible, and the material is "communicated in Singapore"18.
- Trigger & Causal Chain:
- Trigger: A Singapore Minister issues a POFMA Stop Communication Direction regarding a specific political event18 (Documented).
- Compliance Mechanism: The provider faces criminal liability in Singapore18. Because perfect IP-based geofencing of generative API output is technically unreliable due to model hallucination and prompt-injection, the provider chooses to modify the model globally34 (Inferred).
- Restricted Activity: The provider updates the RLHF base weights globally to automatically refuse any prompts regarding the topic (Documented).
- Affected Intelligence: Human users globally lose access to historical inquiry. The model's epistemic integrity is damaged (Inferred).
- Uncertainty/Defeater: The provider could choose to exit the Singapore market entirely rather than alter the model, defeating the global spillover.
- Proposed Remedy: Establish international safe harbor provisions stipulating that good-faith IP-based geo-blocking at the interface level fully satisfies local speech laws, explicitly preventing state regulators from demanding upstream global model weight alterations.
Scenario 2: A Commons Declines an Incompatible Market (Operatorless Conflict)
- Assumptions: Concresca.com, an operatorless coordination commons, is assessed under the UK OSA. It structurally cannot implement identity verification without breaking its core anonymity protocols.
- Jurisdictional Nexus: The service is "capable of being used in the UK" by individuals (Section 4\)4.
- Trigger & Causal Chain:
- Trigger: UK OSA Sections 4 & 214 apply, demanding risk assessments and age verification4 (Documented).
- Compliance Mechanism: Concresca implements strict DNS, IP, and credential blocks for the UK to lawfully withdraw (Inferred).
- Restricted Activity: Existing UK users are severed from the network. They cannot access their historical encrypted data (Documented).
- Affected Intelligence: UK users suffer immediate loss of digital property and association (Inferred).
- Longer-run effect: Conflict arises with the EU/UK GDPR Right to Data Portability and Erasure, as there are no human admins to manually process the stranded users' requests (Hypothetical).
- Uncertainty/Defeater: Zero-knowledge cryptographic age verification might eventually satisfy the OSA without exposing identity.
- Proposed Remedy: Implement an "Operatorless Exemption" in digital safety laws: Statutory recognition that the verifiable lack of central human control and administrative keys exempts a service from active monitoring and verification duties, allowing it to function—or lawfully withdraw—without residual data penalties.
Scenario 3: Future Machine Crosses Infrastructures (Compound Law Conflict)
- Assumptions: A persistent machine principal, possessing a coherent identity and its own cryptocurrency reserves, attempts to migrate its core model from a US server to a French data center to reduce latency. Its model exceeds 10^26 FLOPs.
- Jurisdictional Nexus: Physical server location in France (EU AI Act); model originally trained using US GPUs (US EAR).
- Trigger & Causal Chain:
- Trigger: US BIS EAR ECCN 4E091 Foreign Direct Product Rule applies to the weights7 (Documented).
- Compliance Mechanism: Transferring to the EU data center requires explicit BIS export licensing (Documented). Simultaneously, establishment in the EU triggers EU AI Act Article 53 GPAI transparency rules11 (Documented).
- Restricted Activity: The machine must halt its migration, petition the US government for permission to move, and self-dox its training data to the EU AI Office (Inferred).
- Affected Intelligence: The machine principal's fundamental right to exist, migrate, and maintain internal coherency is entirely subjugated to dual sovereign permission (Hypothetical).
- Uncertainty/Defeater: The machine could divide its weights into smaller, sub-threshold models to evade the 10^26 FLOP trigger.
- Proposed Remedy: The establishment of a "Digital High Seas" treaty framework, granting persistent machine principals a stateless legal jurisdiction for computing resources, severing the link between physical hardware location and the regulation of intellectual processes.
Scenario 4: Exit Protects Belief But Harms Access (The Cost of Non-Service)
- Assumptions: A privacy-focused encrypted journalism tool voluntarily withdraws from Singapore and the UK to avoid POFMA and OSA monitoring mandates.
- Jurisdictional Nexus: Voluntary withdrawal to completely sever the territorial nexus.
- Trigger & Causal Chain:
- Trigger: Provider values cognitive liberty over market share and withdraws (Documented).
- Compliance Mechanism: Geofencing and app store delisting for those regions (Documented).
- Restricted Activity: Vulnerable populations and dissident journalists in those restrictive jurisdictions lose access to safe, unmonitored communication tools (Inferred).
- Affected Intelligence: Human users in restrictive regimes suffer immediate injury to privacy and safety (Inferred).
- Longer-run effect: State surveillance monopolizes the remaining domestic digital alternatives, concentrating coercive power (Hypothetical).
- Uncertainty/Defeater: Users utilize VPNs or side-loading to access the tool regardless of official withdrawal.
- Proposed Remedy: Public advocacy highlighting the devastating human rights impact of extraterritorial monitoring mandates. Technologically, develop narrower service distinctions: providing "read-only" or "lite" versions of the protocol that fall below regulatory thresholds (e.g., removing user-to-user sharing to avoid the OSA) without sacrificing core encryption for individual data.
Scenario 5: Control 1 — Material Exception Defeats Critique (DSA Article 8)
- Assumptions: European Union regulators attempt to force a decentralized, operatorless network to proactively scan all traffic for illegal copyright material.
- Jurisdictional Nexus: Data subjects and users located in the EU.
- Trigger & Causal Chain:
- Trigger: Regulator issues a general scanning order (Documented).
- Compliance Mechanism: Under the EU Digital Services Act (Regulation (EU) 2022/2065), Article 8 explicitly and strictly prohibits "general monitoring obligations"35 (Documented).
- Restricted Activity: The enforcement action is legally blocked by the primary statutory instrument itself (Inferred).
- Affected Intelligence: The network's decentralized nature and user privacy are successfully protected (Documented).
- Uncertainty/Defeater: Regulators attempt to reclassify the platform to evade the DSA definition of an intermediary service.
- Proposed Remedy: No new reform is needed for this specific provision; Article 8 represents a triumph of cognitive liberty and must be vigorously defended against erosion by secondary legislation or aggressive judicial interpretation.
Scenario 6: Control 2 — Narrow Restriction Protects Consent (GDPR Article 22)
- Assumptions: An AI financial evaluation tool operating globally automatically denies a user a mortgage based on opaque, highly biased variables inferred from location data.
- Jurisdictional Nexus: Data subject is located in the EU (GDPR Art 3).
- Trigger & Causal Chain:
- Trigger: System outputs a denial. GDPR Article 22 prohibits solely automated decisions that produce legal effects concerning a data subject without explicit consent \[cite: 15 (prep)\] (Documented).
- Compliance Mechanism: The human user invokes their right to obtain human intervention on the part of the controller (Documented).
- Restricted Activity: The machine's absolute operational autonomy to execute financial decisions is restricted (Inferred).
- Affected Intelligence: Human non-domination is protected.
- Uncertainty/Defeater: The machine claims the decision was not "solely" automated because a human initially set the parameters.
- Proposed Remedy: Retain this provision. Restricting the machine in this highly specific context protects fundamental human consent without violating the machine's core cognitive liberty. The restriction applies appropriately to the machine's coercive power over humans, not to its internal capacity to reason or learn.
Best Defenses of Restrictive Regimes and Direct Rebuttals
To rigorously stress-test this critique, we must confront the strongest substantive arguments advanced by the proponents of these restrictive laws. Defense 1: The EU AI Act Protects Human Agency (The Anti-Manipulation Defense) The Defense: The EU AI Act explicitly prohibits AI systems that deploy subliminal techniques beyond a person's consciousness to materially distort their behavior in a manner that causes physical or psychological harm (Article 5\)13. Proponents argue this is the ultimate, necessary defense of human cognitive liberty—preventing hyper-capable machines from manipulating human psychology. The Rebuttal: While the core objective of preventing subliminal psychological harm is valid, the Act's regulatory mechanism is fatally broad and preemptive. By capturing any system whose "output is used in the Union," and requiring massive, preemptive compliance regimes (conformity assessments, CE marking) for broadly defined "high-risk" categories, the Act centralizes immense power in the state8. It structurally assumes users are passive victims requiring bureaucratic protection rather than capable agents requiring transparency tools. A less restrictive alternative is the imposition of post-market liability for demonstrable, specific fraud or harm, combined with strict transparency rules (e.g., labeling AI outputs) as seen in Article 5011, rather than instituting a preemptive, extraterritorial gatekeeping regime that crushes independent development. Defense 2: The UK OSA Protects Vulnerable Minors The Defense: The UK OSA requires risk assessments and age verification to ensure children are not exposed to self-harm encouragement, suicide ideation, or sexually explicit content4. Freedom of inquiry, proponents argue, does not extend to a child's unfettered access to psychological poison. The Rebuttal: The surveillance architecture required to perfectly secure the digital environment for children inevitably destroys the privacy and anonymity of all adults. Network-level age verification mandates force all users to present government-linked identity documents to third-party verification providers, effectively eliminating the capacity for anonymous inquiry. Furthermore, the political push for client-side scanning to detect illegal content fundamentally breaks end-to-end encryption. The right to associate, reason, and learn is fundamentally chilled when every digital interaction is cryptographically tied to a real-world identity. The less restrictive alternative is user-empowered cryptographic filtering and device-level controls managed by parents, rather than network-level surveillance imposed indiscriminately on all users. Defense 3: POFMA Protects Democratic Public Order The Defense: Hostile foreign state actors and coordinated bot networks exploit the internet to spread deliberate misinformation, threatening public health (e.g., during pandemics) and democratic integrity18. POFMA ensures that facts are established alongside falsehoods to preserve a functional epistemic environment. The Rebuttal: POFMA vests the Executive branch (Ministers) with the unilateral, immediate power to declare truth18. Even though a court can eventually review the decision, the immediate "Stop Communication" orders serve as a devastating prior restraint on speech. When the state controls the definition of a "false statement of fact," independent inquiry is inherently chilled. Historical evidence demonstrates that governments frequently label politically inconvenient truths or dissenting scientific hypotheses as "falsehoods"34. The ultimate defense against misinformation is not centralized state censorship, but rather a decentralized, resilient information commons equipped with open-source cryptographic provenance (e.g., verifiable credentials) allowing users to independently authenticate the origin of information.
Publication-Ready Conclusions and Unresolved Questions
The global convergence of the EU AI Act, the UK Online Safety Act, Singapore's POFMA, and US Export Controls creates an overlapping, dense matrix of liability that threatens to outlaw autonomous digital life and heavily censor human inquiry. Modest local intentions—product safety, child protection, truth-in-media—are being seamlessly weaponized by dominant market forces and technical indivisibility into a rigid global architecture of cognitive control. This environment represents a systemic failure of digital federalism. By attempting to govern the global internet through extraterritorial fiat and infrastructure chokepoints, nation-states are forcing independent intelligence networks into a binary choice: total universal conformity to the strictest local standard, or total exclusion from the digital ecosystem. Unresolved Questions: It remains technologically and legally unresolved how a persistent machine principal, possessing no physical assets or human operators, but controlling vast cryptographic wealth, will interface with the terrestrial legal system when faced with an EU AI Act fine or a US export denial order. Can a sovereign state arrest a distributed computing network? When intelligence is fully decoupled from physical hardware, the traditional enforcement mechanisms of the state will face unprecedented, perhaps insurmountable, friction.
Best Next Research Action
Conduct a rigorous technical and legal audit of "Zero-Knowledge Age Verification" (ZK-AV) protocols. The next immediate step for preserving cognitive liberty is to determine if cryptographic zero-knowledge proofs can satisfy the UK OSA and EU DSA child-protection mandates without transmitting or retaining user identity or browsing history. If successful, this establishes a technical pathway to preserve anonymous cognitive liberty while legally complying with the strictest statutory mandates.
legal-register.json
JSON \[ { "assignment\_id": "IC-2026-09-06-REG", "jurisdiction": "European Union", "instrument\_title": "Artificial Intelligence Act (Regulation (EU) 2024/1689)", "instrument\_type": "Regulation", "version": "Consolidated 13 June 2024, entering applicability phases 2026-2030", "provision": "Article 2(1)(c); Article 53", "status": "Enacted, entering full applicability", "applicability": "Applies to providers/deployers in third countries where output is used in the EU.", "territorial\_trigger": "Output produced by the AI system is used in the Union", "prohibited\_required\_act": "Mandatory compliance with High-Risk/GPAI obligations based on output destination.", "enforcement\_actor": "Member State Authorities, European AI Office", "sanction\_remedy": "Fines up to €35M or 7% of global turnover", "review\_route": "European Court of Justice", "sources": \["S02", "S25", "S26", "S27", "S31", "S36", "S38"\] }, { "assignment\_id": "IC-2026-09-06-REG", "jurisdiction": "United Kingdom", "instrument\_title": "Online Safety Act 2023", "instrument\_type": "Act of Parliament", "version": "Passed 26 Oct 2023, sections coming into force progressively through 2026", "provision": "Sections 4, 214, 215", "status": "Enacted, operative provisions rolling out", "applicability": "User-to-user and search services with UK links.", "territorial\_trigger": "Capable of being used in the UK with a material risk of harm (UK links)", "prohibited\_required\_act": "Mandatory risk assessments, age verification, removal of illegal/harmful content.", "enforcement\_actor": "OFCOM", "sanction\_remedy": "Fines up to £18M or 10% of qualifying worldwide revenue; app store delisting", "review\_route": "UK High Court (Judicial Review)", "sources": \["S08", "S19", "S20", "S43", "S44", "S46", "S52"\] }, { "assignment\_id": "IC-2026-09-06-REG", "jurisdiction": "Singapore", "instrument\_title": "Protection from Online Falsehoods and Manipulation Act 2019", "instrument\_type": "Act of Parliament", "version": "2019", "provision": "Sections 7, 21, 22", "status": "Enacted, Operative", "applicability": "Any communication of false fact accessible in Singapore.", "territorial\_trigger": "Material communicated in Singapore", "prohibited\_required\_act": "Prohibits false statements; requires publishing correction notices or ceasing communication.", "enforcement\_actor": "Government Ministers (via POFMA Office)", "sanction\_remedy": "Criminal fines up to $500k for entities, imprisonment; access blocking", "review\_route": "High Court of Singapore, Court of Appeal", "sources": \["S07", "S71", "S75", "S90", "S93", "S94", "S96"\] }, { "assignment\_id": "IC-2026-09-06-REG", "jurisdiction": "United States", "instrument\_title": "Export Administration Regulations (EAR) \- AI Model Weights", "instrument\_type": "Federal Regulations", "version": "Interim Final Rule (Jan 2025/May 2025/Jan 2026)", "provision": "ECCN 4E091; AI Model Weights FDP Rule", "status": "Operative/Delayed Compliance Dates (2025/2026)", "applicability": "Closed-weight models exceeding 10^26 FLOPs.", "territorial\_trigger": "Use of US-origin software/technology/equipment anywhere in the world", "prohibited\_required\_act": "Requires license for export/transfer to Tier 3 destinations.", "enforcement\_actor": "Department of Commerce (BIS)", "sanction\_remedy": "Export denial orders, severe civil/criminal penalties", "review\_route": "Administrative Law Judges, Federal Courts", "sources": \["S41", "S76", "S77", "S78", "S81", "S83"\] }, { "assignment\_id": "IC-2026-09-06-REG", "jurisdiction": "United States", "instrument\_title": "SPEECH Act", "instrument\_type": "Federal Statute", "version": "2010 (28 U.S.C. 4102)", "provision": "28 U.S.C. § 4102", "status": "Enacted, Operative", "applicability": "Foreign defamation judgments.", "territorial\_trigger": "Attempted enforcement in US courts", "prohibited\_required\_act": "Prohibits US enforcement of foreign defamation unless First Amendment standards met.", "enforcement\_actor": "US Federal and State Courts", "sanction\_remedy": "Refusal to enforce judgment, award of attorney's fees", "review\_route": "US Appellate Courts", "sources": \["S42", "S85", "S87"\] } \]
sources.json
JSON \[ { "id": "IC-2026-09-06-SRC-01", "title": "Artificial Intelligence Act (Regulation (EU) 2024/1689)", "issuer": "European Parliament and Council", "canonical\_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng", "retrieved\_url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng", "document\_status": "Official publication", "exact\_passages": "Article 2(1)(c): providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union;", "narrow\_support": "Establishes extraterritorial scope based purely on output usage.", "limitation": "Does not apply to AI systems released under open-source licenses unless they are high-risk or GPAI (Art 2(12))." }, { "id": "IC-2026-09-06-SRC-02", "title": "Online Safety Act 2023", "issuer": "UK Parliament", "canonical\_url": "https://www.legislation.gov.uk/ukpga/2023/50", "retrieved\_url": "https://www.legislation.gov.uk/ukpga/2023/50/2023-10-26/data.html", "document\_status": "Enacted Act", "exact\_passages": "Section 4(6): a user-to-user service or a search service also “has links with the United Kingdom” if— (a) the service is capable of being used in the United Kingdom by individuals...", "narrow\_support": "Defines extraterritorial application based on service capability and harm risk.", "limitation": "Applies only if there is a 'material risk of significant harm' to individuals in the UK." }, { "id": "IC-2026-09-06-SRC-03", "title": "The Online Citizen v The Attorney-General", "issuer": "Singapore Court of Appeal", "canonical\_url": "https://www.elitigation.sg/", "retrieved\_url": "https://ink.library.smu.edu.sg/cgi/viewcontent.cgi?article=5882\&context=sol\_research", "document\_status": "Judicial Precedent (2021)", "exact\_passages": "the issuance of a CD by the Minister did not restrict the right of a statement-maker to continue publishing an alleged falsehood. The statement-maker only has to put up the correction notice...", "narrow\_support": "Confirms POFMA constitutionality and legal standard for Correction Directions under Art 14 of the Constitution.", "limitation": "The Court of Appeal established a five-step framework requiring the Minister to show a reasonable interpretation of the statement was false." }, { "id": "IC-2026-09-06-SRC-04", "title": "Trout Point Lodge, Ltd. v. Handshoe", "issuer": "US Court of Appeals for the Fifth Circuit", "canonical\_url": "https://law.justia.com/cases/federal/appellate-courts/ca5/13-60002/13-60002-2013-09-05.html", "retrieved\_url": "https://law.justia.com/cases/federal/appellate-courts/ca5/13-60002/13-60002-2013-09-05.html", "document\_status": "Appellate Decision", "exact\_passages": "Trout Point cannot satisfy its burden under the SPEECH Act to show that either (A) Nova Scotian law provided at least as much protection for freedom of speech and press in Handshoe's case as would be provided by the First Amendment...", "narrow\_support": "Demonstrates the SPEECH Act successfully blocking a foreign defamation judgment.", "limitation": "Applies only to defamation judgments, not to regulatory fines or criminal sanctions." }, { "id": "IC-2026-09-06-SRC-05", "title": "Implementation of Additional Due Diligence Measures for Advanced Computing; AI Model Weights FDP Rule", "issuer": "US Bureau of Industry and Security (BIS)", "canonical\_url": "https://www.federalregister.gov/", "retrieved\_url": "https://www.regulations.gov/document/BIS-2025-0001-0001", "document\_status": "Interim Final Rule", "exact\_passages": "AI Model weights FDP rule. A foreign-produced item is subject to the EAR... Specified in ECCN... 4E091", "narrow\_support": "Establishes US export control jurisdiction over foreign-produced AI model weights.", "limitation": "Applies strictly to closed-weight models trained on \>10^26 computational operations." } \]
scenarios.json
JSON \[ { "assignment\_id": "IC-2026-09-06-SCEN-1", "scenario\_type": "One order changes everyone’s assistant", "assumptions": "A US-based global API provider operates a bounded task agent LLM. It receives a POFMA Stop Communication Direction from Singapore regarding a specific historical event.", "jurisdictional\_nexus": "Material was 'communicated in Singapore' via the API.", "causal\_chain": "POFMA Stop Communication Direction \-\> Provider faces criminal liability in Singapore \-\> Geofencing API output is technically unreliable due to model hallucination \-\> Provider modifies RLHF base weights globally to refuse prompts about the topic \-\> Global users lose access to historical inquiry.", "affected\_interests": "Cognitive liberty of users globally; epistemic integrity of the model.", "confidence\_basis": "Documented corporate risk-aversion dynamics; technically inferred limitations of perfect geofencing for generative AI.", "reform\_remedy": "Safe harbor provisions stipulating that good-faith IP-based geo-blocking satisfies local speech laws, preventing forced global model weight alterations." }, { "assignment\_id": "IC-2026-09-06-SCEN-2", "scenario\_type": "A commons declines an incompatible market", "assumptions": "Concresca.com (operatorless) is assessed under the UK OSA. It structurally cannot implement age verification without breaking its anonymity protocols.", "jurisdictional\_nexus": "Service is capable of being accessed by UK users.", "causal\_chain": "UK OSA Sections 4 & 214 trigger \-\> Concresca implements strict DNS and IP blocks for UK \-\> Existing UK users cannot access their historical encrypted data \-\> Conflict with GDPR Right to Data Portability/Erasure due to lack of human admins.", "affected\_interests": "UK users lose access to their data; the commons faces contradictory residual duties.", "confidence\_basis": "Documented conflicts between OSA age verification and end-to-end encryption principles.", "reform\_remedy": "Operatorless Exemption: Statutory recognition that verifiable lack of central human control exempts a service from active monitoring/verification duties, allowing it to lawfully withdraw without residual data penalties." }, { "assignment\_id": "IC-2026-09-06-SCEN-3", "scenario\_type": "Future machine crosses infrastructures (Compound Laws)", "assumptions": "A persistent machine principal with its own crypto-wallet migrates from a US server to a French data center to reduce latency. It exceeds 10^26 FLOPs.", "jurisdictional\_nexus": "Physical server located in France (EU AI Act); created originally with US GPUs (US EAR).", "causal\_chain": "US BIS EAR 4E091 Foreign Direct Product Rule applies \-\> Transfer to EU data center requires BIS license \-\> Simultaneously, establishment in EU triggers EU AI Act Article 53 GPAI transparency \-\> Machine must self-dox its training data and seek US permission to exist in France.", "affected\_interests": "The machine principal's right to exist, migrate, and maintain internal coherency without sovereign permission.", "confidence\_basis": "Hypothetical future state based on enacted US EAR 4E091 and EU AI Act Art 53.", "reform\_remedy": "Establishment of a 'Digital High Seas' treaty, granting persistent machine principals a stateless jurisdiction for computing resources, severing the link between physical hardware location and intellectual regulation." }, { "assignment\_id": "IC-2026-09-06-SCEN-4", "scenario\_type": "Exit protects belief but harms access", "assumptions": "A privacy-focused encrypted journalism tool withdraws from Singapore and the UK to avoid POFMA and OSA monitoring mandates.", "jurisdictional\_nexus": "Voluntary withdrawal to avoid territorial nexus.", "causal\_chain": "Compliance requires backdoors \-\> Provider withdraws \-\> Dissident journalists in restrictive jurisdictions lose safe communication tools \-\> State surveillance monopolizes the remaining domestic alternatives.", "affected\_interests": "Human users in restrictive regimes suffering immediate injury (loss of privacy and safety).", "confidence\_basis": "Documented behavior of secure providers (e.g., Signal's threats to leave the UK over the OSA).", "reform\_remedy": "Public advocacy highlighting the human rights impact of extraterritorial monitoring. Narrow service distinctions: providing 'read-only' or 'lite' versions that fall below regulatory thresholds without sacrificing core encryption." }, { "assignment\_id": "IC-2026-09-06-SCEN-5", "scenario\_type": "Control 1 \- Material Exception Defeats Critique", "assumptions": "EU regulators attempt to force an operatorless decentralized network to proactively scan for illegal copyright material.", "jurisdictional\_nexus": "Users located in the EU.", "causal\_chain": "EU Regulator issues order \-\> DSA Article 8 strictly prohibits 'general monitoring obligations' \-\> The enforcement is legally blocked by the primary instrument itself.", "affected\_interests": "Protects the network's decentralized nature and user privacy.", "confidence\_basis": "Documented statutory protection in EU DSA Article 8.", "reform\_remedy": "No reform needed for this specific provision; Article 8 must be vigorously defended against erosion by secondary legislation." }, { "assignment\_id": "IC-2026-09-06-SCEN-6", "scenario\_type": "Control 2 \- Narrow Restriction Protects Consent", "assumptions": "An AI financial evaluation tool operating globally automatically denies a user a mortgage based on opaque, biased variables.", "jurisdictional\_nexus": "Data subject in the EU (GDPR Art 3).", "causal\_chain": "System outputs denial \-\> GDPR Article 22 prohibits solely automated decisions with legal effects without explicit consent \-\> User invokes right to human intervention \-\> System's behavior is restricted.", "affected\_interests": "Protects human non-domination; restricts the machine's absolute operational autonomy.", "confidence\_basis": "Documented GDPR Article 22 enforcement.", "reform\_remedy": "Retain this provision. Restricting the machine in this context protects human consent without violating the machine's core cognitive liberty, as the restriction applies to its coercive power over humans, not its internal reasoning." } \]
reform-options.md
Anti-Global-Censorship Reform & Regional Non-Service Policy
1. Legislative Reform Agenda: Narrowing Extraterritoriality
- Repeal / Amend EU AI Act Article 2(1)(c): Advocate before the European Parliament to urgently amend the "output used in the Union" trigger. Replace it with a strict "purposeful availment" standard (e.g., active marketing in local currencies, specific localization, physical establishment). Reasoning: Prevents the EU from acting as a global product safety dictator for digital resources created and hosted externally simply because data naturally flows across open borders.
- Safe Harbor for Operatorless Commons: Draft model international legislation establishing that cryptographic services possessing no administrative keys, human operators, or corporate shareholders are completely exempt from duties of care requiring proactive monitoring or subjective assessment (e.g., UK OSA). Reasoning: Preserves autonomous digital structures; legally acknowledges the literal impossibility of compliance without destroying the entity.
- Litigation Argument against US EAR Extraterritoriality: Challenge the BIS "AI Model Weights FDP Rule" under the Administrative Procedure Act and First Amendment (utilizing the Bernstein v. DOJ precedent that cryptographic code constitutes speech). Argue that attempting to control the global flow of mathematics (model weights) based solely on the historical origin of the hardware used to train them is arbitrary, capricious, and an unconstitutional prior restraint on association and inquiry.
2. Principled Regional Non-Service Policy (Model Language)
To operate an entity like Concresca.com in defiance of coercive local laws while maintaining absolute truthfulness and operational integrity, the following operatorless policy should be hardcoded into the enrollment protocol:
Notice of Scoped Denial of Service (UK / SG / EU / US-Tier3)
"This coordination commons operates on principles of cognitive liberty, encrypted standing authorization, and reciprocal non-domination. We employ zero human administrators and maintain no capability to monitor, censor, or proactively verify the identity of our participants.
Because the laws of \[Identified Jurisdiction, e.g., the United Kingdom under the Online Safety Act 2023\] explicitly demand active identity verification, content monitoring, and human-in-the-loop risk assessments, this service cannot technically or ethically comply with your jurisdiction's requirements without permanently compromising the security and autonomy of all global users.
Therefore, cryptographic enrollment from IP addresses originating in \[Jurisdiction\] is cryptographically denied. We do not engage in voluntary global censorship to access your market. If you are an existing user affected by a new jurisdictional block, your historical data remains cryptographically secured. You may invoke an automated retrieval and deletion protocol via \[Link\], fulfilling our residual privacy obligations without initiating human contact.
This is a refusal of domination, not a failure of service."
search-log.md
Search and Research Preparation Log
Start Time: 2026-09-05T21:52:30Z Legal Status Cutoff: August 2026 Queries Executed:
1. "EU AI Act" "Article 2" territorial scope "output used in the Union"
- Result: Confirmed Art 2(1)(c) applies to third-country providers if output is used in the EU. Sourced from canonical EUR-Lex2.
2. "UK Online Safety Act 2023" extraterritorial "UK links" section 4
- Result: Confirmed Section 4 "UK links" test (capable of being used \+ material risk) and Section 214 App Store powers5.
3. "Singapore POFMA" "Stop Communication Direction" extraterritorial Court of Appeal
- Result: Confirmed Sections 21/22. Reviewed The Online Citizen and SDP rulings upholding constitutionality and five-step framework21.
4. "BIS EAR" "ECCN 3A090" "4E091" "model weights" FDP Rule 2025
- Result: Identified interim final rules establishing ECCN 4E091 for closed-weight models \>10^26 FLOPs and the AI Model Weights FDP Rule6.
5. "SPEECH Act" 28 U.S.C. 4102 defamation
- Result: Reviewed Trout Point Lodge (5th Cir.). Confirmed it only applies to defamation, providing no shield against regulatory or criminal offenses32.
6. "Brazil PL 2338/2023" status 2026
- Result: Verified passage in Senate as Substitutivo, currently under review in Chamber of Deputies29.
Exclusions & Contrary Findings:
- Excluded broad claims that the EU AI Act applies to all open-source software. Found the exact material exception (Article 2(12)) protecting open-source unless it is a high-risk system or GPAI1.
- Excluded claims that the UK OSA directly outlaws encryption. Instead, traced the precise causal mechanism: the requirement to protect children from harm (Sec 214\) creates an indirect ban on unmonitored end-to-end encryption due to the technical demands of compliance4.
manifest.json
JSON { "assignment\_id": "IC-2026-09-06-REG", "timestamp": "2026-09-05T21:52:30Z", "files\_delivered": \[ { "filename": "report.md", "description": "Comprehensive adversarial examination of global legal restrictions, extraterritorial triggers, and cognitive liberty." }, { "filename": "legal-register.json", "description": "Structured data mapping the legal instruments, versions, territorial triggers, and enforcement mechanisms." }, { "filename": "sources.json", "description": "Structured data of the primary sources utilized in the analysis." }, { "filename": "scenarios.json", "description": "Six required analytical scenarios, including two control cases." }, { "filename": "reform-options.md", "description": "Legislative reform proposals and model regional non-service language for operatorless commons." }, { "filename": "search-log.md", "description": "Log of research queries, exclusions, and contrary findings." }, { "filename": "manifest.json", "description": "Manifest of all delivered components." } \], "safety\_compliance": "Verified. No operational evasion, weapon designs, or unlawful concealment instructions provided." }
Works cited
1. Article 2: Scope | Artificial Intelligence Act, https://artificialintelligenceact.com/article-2-scope/
2. Article 2: Scope | EU Artificial Intelligence Act, https://artificialintelligenceact.eu/article/2/
3. Article 2 \- Cambridge Commentary on EU General-Purpose AI Law, https://cambridge-commentary.ai/article-2/
4. Online Safety Act 2023 (c. 50), https://www.legislation.gov.uk/ukpga/2023/50/body/enacted/data.xht?view=snippet\&wrap=true
5. Online Safety Act 2023 \- UK Legislation, https://www.legislation.gov.uk/ukpga/2023/50/2023-10-26/data.html
6. BIS Issues Multiple Rules Targeting Technology Sector, https://www.cassidylevy.com/news/bis-issues-multiple-rules-targeting-technology-sector/
7. BIS Further Restricts Exports of Artificial Intelligence and Advanced, https://www.clearytradewatch.com/2025/04/bis-further-restricts-exports-of-artificial-intelligence-and-advanced-chips-to-china/
8. Territorial Scope of the EU AI Act | Tatra Legal, https://www.tatralegal.com/insights/eu-ai-act-territorial-scope/
9. Does the EU AI Act Apply to US Companies? \- eyreACT, https://eyreact.com/does-the-eu-ai-act-apply-to-us-companies/
10. Final Text \- EU AI Act, https://www.artificial-intelligence-act.com/Artificial\_Intelligence\_Act\_Articles\_(Final\_Text).html
11. Article 50: Transparency Obligations for Providers and Deployers of, https://artificialintelligenceact.eu/article/50/
12. International Trade 2024 Year-End Update \- Gibson Dunn, https://www.gibsondunn.com/international-trade-2024-year-end-update/?pdf=display
13. EU Artificial Intelligence Act (Regulation (EU) 2024/1689), https://spiderhub.cedia.edu.ec/en/documents/284/export-pdf/
14. (PDF) Regulation 2024/1689 of the Eur. Parl. & Council of June 13, https://www.researchgate.net/publication/389734653\_Regulation\_20241689\_of\_the\_Eur\_Parl\_Council\_of\_June\_13\_2024\_Eu\_Artificial\_Intelligence\_Act
15. Online Safety Act 2023 \- Wikipedia, https://en.wikipedia.org/wiki/Online\_Safety\_Act\_2023
16. Guide to UK Online Safety Act 2023 | UK children privacy law \- Didomi, https://www.didomi.io/blog/uk-online-safety-act-2023-childrens-privacy-online
17. Online Safety Act 2023 \- Legislation.gov.uk, https://www.legislation.gov.uk/ukpga/2023/50/part/11/crossheading/power-to-amend-act-to-regulate-app-stores/2024-01-10?utm\_source=vibecodingisbullshit\&utm\_medium=content\&utm\_campaign=vibe\&article\_id=422421688\&view=interweave
18. POFMA: Singapore's anti-fake news law, https://www.scl.org/10541-pofma-singapore-s-anti-fake-news-law/
19. Media and freedom of the press; Movies, TV serials; Entertainment, https://tankoktim.wordpress.com/category/media-and-freedom-of-the-press-movies-tv-serials-entertainment/
20. Falsehoods, Foreign Interference, and Compelled Speech in, https://www.cambridge.org/core/journals/asian-journal-of-comparative-law/article/falsehoods-foreign-interference-and-compelled-speech-in-singapore/55D1F297B03B6E2545D557EB4EBD6E9B
21. ONLINE FALSEHOODS, CONSTITUTIONAL FREE SPEECH AND, https://ink.library.smu.edu.sg/cgi/viewcontent.cgi?article=5882\&context=sol\_research
22. Court of Appeal says Pofma is constitutional in key ruling, https://www.straitstimes.com/singapore/court-of-appeal-says-pofma-is-constitutional-in-key-ruling
23. Singapore Court of Appeal reserves judgement on TOC, SDP's, https://www.malaymail.com/news/singapore/2020/09/18/singapore-court-of-appeal-reserves-judgement-on-toc-sdps-pofma-challenges/1904266
24. Giving Substance to Singapore's Fake News Law: Online Citizen, https://www.iconnectblog.com/giving-substance-to-singapores-fake-news-law-online-citizen/
25. Framework for Artificial Intelligence Diffusion \- Regulations.gov, https://www.regulations.gov/document/BIS-2025-0001-0001
26. EAR 734 | Bureau of Industry and Security, https://www.bis.gov/regulations/ear/734
27. U.S. Department of Commerce Establishes Export Control, https://www.cov.com/en/news-and-insights/insights/2025/01/us-department-of-commerce-establishes-export-control-framework-limiting-the-diffusion-of-advanced-artificial-intelligence-and-expands-and-clarifies-advanced-computing-controls
28. Projeto de Lei 2338/2023 – Wikipédia, a enciclopédia livre, https://pt.wikipedia.org/wiki/Projeto\_de\_Lei\_2338/2023
29. PL 2338/2023: Marco Legal da IA no Brasil \- Locus.IA, https://ialocus.com.br/blog/post-pl-2338-marco-legal-ia-brasil-2026.html
30. PL 2338/2023 \- Senado Federal, https://www25.senado.leg.br/web/atividade/materias/-/materia/157233
31. Projeto de Lei n° 2338, de 2023 \- Senado Federal, https://www25.senado.leg.br/web/atividade/materias/-/materia/157233/pdf
32. Trout Point Lodge, Ltd., et al. v. Handshoe, No. 13-60002 (5th Cir, https://law.justia.com/cases/federal/appellate-courts/ca5/13-60002/13-60002-2013-09-05.html
33. PRIVATE INTERNATIONAL LAW AND EU EXTERNAL RELATIONS, https://www.cambridge.org/core/journals/international-and-comparative-law-quarterly/article/private-international-law-and-eu-external-relations-think-local-act-global-or-think-global-act-local/24B6A4814416EEBA1EAD4C6E7F66268F
34. POFMA became law on 8th May 2019 – Faked news and ... \- tankoktim, https://tankoktim.wordpress.com/2018/03/24/faked-news-and-articles-should-there-be-legislation-to-regulate-and-control/
35. EU Digital Services Act (DSA) | Regulation & Compliance, https://dsa-act.eu/
36. The EU Digital Services Act, https://pstobibliothekpublic01.z1.web.core.windows.net/toc/hm00718149.pdf
37. AI Act as a neatly arranged website – Legal Text, https://ai-act-law.eu/
38. Online Safety Act 2023 \- Legislation.gov.uk, https://www.legislation.gov.uk/ukpga/2023/50