Civic / Privacy / Digital Rights

Targeted Evidence Demands Versus Reusable Access Architecture

Report summary

Compulsory assistance structurally changes a service’s general confidentiality architecture, rather than merely producing bounded existing evidence, when a legal mandate forces a provider to engineer, install, or retain a permanent capability to intercept data, decrypt communications, or degrade sys

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
4,040 words
Reading time
19 minutes
Report type
architecture

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • Runtime
  • Cognitive Liberty
  • Semantic Systems
  • Research Archive

Research provenance

Archive status
Research archive item
Content identity
sha256:00622b9d731ca04380e69f66d12c0da7b2caa5004ee4cdbed6018b4e9b5e70fe

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

1. Answer and scope

Compulsory assistance structurally changes a service’s general confidentiality architecture, rather than merely producing bounded existing evidence, when a legal mandate forces a provider to engineer, install, or retain a permanent capability to intercept data, decrypt communications, or degrade systemic security measures across a platform. Unlike a conventional warrant—which compels the production of specific, pre-existing historical records based on individualized suspicion—a technical capability order preemptively alters the underlying infrastructure of a service to ensure that future data acquisition is computationally possible. In both the United Kingdom and Australia, the distinction between a bounded data production demand and a structural architectural mandate forms the legal and technical frontier of digital surveillance, testing the boundaries of cognitive liberty, privacy, and state security. The enforceable limits of such architectural changes depend on precise statutory language concerning operational practicability, systemic weaknesses, and extraterritorial jurisdiction. Under the United Kingdom’s Investigatory Powers Act 2016 (IPA 2016), specifically section 253 and the newly enacted section 258A via the Investigatory Powers (Amendment) Act 2024, the state asserts expansive authority to mandate technical capabilities and freeze security architecture changes globally, bounded primarily by executive proportionality tests and a judicial double-lock review1. Conversely, Australia’s Telecommunications Act 1997, as amended by the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (TOLA), features an express statutory prohibition under section 317ZG against compelling a designated communications provider to build or implement a "systemic weakness or systemic vulnerability"4. However, the actual enforceability of this limit relies on highly contested technical definitions regarding whether a newly forced capability is inherently systemic or ostensibly targeted. To contextualize this threshold, one neutral definition of reusable general access is required. Reusable general access is defined as a compulsory engineering modification or retained systemic affordance integrated into a service's core infrastructure that permits repetitive, scalable circumvention of default confidentiality controls without requiring individualized, per-target engineering for each deployment. Four boundary examples clarify this definition:

1. A targeted endpoint exploit, where law enforcement utilizes a bespoke vulnerability to compromise a single known suspect’s device. This is highly intrusive but does not constitute reusable general access because the service architecture remains unaltered for the broader user base.

2. An ephemeral session key extraction, where a provider is compelled to silently forward the specific session keys for one active user account over a bounded time period. If the architecture requires a permanent, dormant modular interceptor to enable this feature for any future user, it constitutes reusable general access.

3. An administrator credential mandate, requiring a provider to retain a master decryption key or root administrative credential capable of unlocking all client data. This serves as the definitive example of reusable general access.

4. An operatorless protocol redesign, where a decentralized service lacking human administrators is ordered to redesign its consensus protocol to introduce a state-mandated override credential, forcing reusable general access upon an inherently autonomous entity.

This bounded inquiry utilizes public legal instruments to evaluate these frameworks. Crucially, the analysis distinguishes the confidentiality of an investigation—which manifests as a gag order preventing a provider from notifying a user about a specific warrant—from the confidentiality of a changed service architecture, which manifests as a gag order concealing state-mandated infrastructural vulnerabilities from the global public and other regulatory bodies.

2. Provision-level findings

An exhaustive analysis of the UK and Australian statutory regimes reveals sophisticated, yet fundamentally divergent, mechanisms designed to separate the mandate to build an access architecture from the authorization to use it.

Power, Authorization, and Review Architecture

JurisdictionLegal InstrumentIssuing ActorIndependent AuthorizationReview and SafeguardsCore Limitation
United KingdomTechnical Capability Notice (TCN) (IPA 2016 s. 253\)Secretary of StateJudicial Commissioner (IPA 2016 s. 254\)Technical Advisory Board (TAB) reviewMust be "practicable" and "proportionate"1.
United KingdomNotice of Change (IPA 2016 s. 258A)Secretary of StateJudicial Commissioner (for resulting notices)TAB; Judicial CommissionerCaptures "relevant changes" materially affecting capabilities3.
AustraliaTechnical Capability Notice (TCN) (Telco Act s. 317T)Attorney-GeneralNone prior to issuanceAssessment by retired judge and technical expert (s. 317WA)Absolute prohibition on "systemic weakness/vulnerability" (s. 317ZG)5.
AustraliaTechnical Assistance Notice (TAN) (Telco Act s. 317L)Director-General (ASIO) or Law Enforcement HeadNone prior to issuanceAdministrative reviewUses existing capabilities; bound by s. 317ZG9.
AustraliaUnderlying Warrant (Telco Act s. 317ZH)Judicial Officer or AAT MemberRequired prior to data acquisitionInspector-General of Intelligence and Security (IGIS)TCN/TANs cannot replace a warrant where legally required11.

United Kingdom: Capability, Practicability, and Notification

Under the UK IPA 2016, a Technical Capability Notice (TCN) under section 253 is explicitly separated from a warrant. A TCN compels a relevant telecommunications or postal operator to maintain the structural capacity to intercept communications or remove electronic protections, ensuring they can fulfill a warrant if one is subsequently issued1. The Secretary of State must deem the notice necessary and proportionate, and a Judicial Commissioner must approve it under section 254, creating a double-lock authorization mechanism1. The Investigatory Powers (Technical Capability) Regulations 2018 operationalize this, stipulating obligations that include maintaining the capability to ensure the interception of communications in their entirety and disclosing data within one working day13. The territorial reach of section 253 is explicitly global, permitting notices to be served on entities outside the United Kingdom1. A profound architectural shift occurred with the Investigatory Powers (Amendment) Act 2024, which introduced section 258A. This provision mandates that operators notify the Secretary of State of proposed changes to telecommunications services or systems that would negatively affect existing investigatory capabilities3. The accompanying regulations define a "relevant change" broadly, encompassing changes to data retention periods, the decommissioning of systems, or alterations to the lawful provision of communications content3. While exemptions exist for operators with fewer than 10,000 users or for routine software bug fixes, this mechanism effectively functions as a statutory standstill7. It threatens the continuous deployment cycles of global technology providers by requiring state review before rolling out end-to-end encryption enhancements, fundamentally transforming global architecture confidentiality.

Australia: The Systemic Weakness Prohibition and Authorization Separation

Australia's Part 15 of the Telecommunications Act 1997 partitions assistance into voluntary Technical Assistance Requests (TARs), mandatory existing-capability assistance via Technical Assistance Notices (TANs, section 317L), and mandatory new-capability construction via Technical Capability Notices (TCNs, section 317T)9. The issuing actor varies; the Director-General of ASIO or law enforcement heads can issue TANs, while only the Attorney-General can issue TCNs9. A fundamental protection separating capability from acquisition is section 317ZH, which states that these notices cannot replace a warrant. The state cannot use a TCN to acquire communications content without an underlying, independently authorized judicial warrant11. The primary statutory safeguard against reusable general access is section 317ZG, which prohibits any notice from requiring a provider to implement or build a "systemic weakness, or a systemic vulnerability, into a form of electronic protection"4. The enforcement of this absolute safeguard is heavily contested. Government interpretations suggest that a capability built to access a single target's device is not systemic if administratively restricted. Conversely, technical consensus dictates that any degradation of an encryption protocol or mandatory insertion of a backdoor inherently weakens the systemic mathematical guarantee of the entire platform, carrying the risk of being extended beyond a targeted system5. To resolve disputes, section 317WA provides a mechanism for providers to challenge a TCN by requesting a joint assessment by an independent technical expert and a retired judge to determine if the mandate violates the 317ZG prohibition8. Additionally, human rights organizations have criticized the broad "relevant objectives" for which these powers can be used, noting that deploying capability mandates to protect "public revenue" or "national economic well-being" fails strict proportionality tests when weighed against systemic security degradation15.

3. Four worked cases

R2-10-C01 — Specified existing record

A conversational interface service receives an authorized demand identifying one existing record and a specific time window. This verified rule dictates that the provider must supply pre-existing data under a conventional warrant (e.g., IPA 2016 Part 3). Conditional application occurs when the provider queries its existing database architecture. The possible response is the extraction and secure transmission of the specified conversational log. The affected activity is localized entirely to the target's historical data, resulting in a burden limited to routine compliance overhead. This constitutes an observed, textual mechanism for bounded production. One necessary assumption is that the conversational interface retains plaintext logs in the ordinary course of business. One material defeater is the implementation of user-held end-to-end encryption, rendering the historical data mathematically inaccessible to the provider. A bounded production demand need not imply a reusable architectural access requirement because it leverages existing administrative tools to extract established facts; it does not force the provider to engineer new, persistent state-monitoring software or weaken the cryptographic foundations of the interface for unrelated users. Secrecy applies strictly to the target's identity, preserving investigation confidentiality without compromising service architecture.

R2-10-C02 — Future memory-service redesign

A persistent operatorless memory service, hypothetically named Concresca, is asked to retain a reusable capability affecting future records. Concresca’s operating requirement dictates that enrollment, authentication, and policy enforcement strictly depend on no staffed approval queue. The verified rule applied is a UK section 253 TCN demanding the capability to remove electronic protection1. Conditional application involves forcing an autonomous system to accept human-in-the-loop state overrides. The possible response is a mandatory architectural overhaul. The affected activity is the fundamental autonomy of the service, burdening the provider with destroying its core operatorless value proposition. This represents a hypothetical inference of structural subversion. One necessary assumption is that the state considers the imposition of an administrative backdoor upon an autonomous entity to be legally "practicable" under section 253(4)1. One material defeater is a successful challenge before the Technical Advisory Board demonstrating that retrofitting human administration into a cryptographically sealed, operatorless consensus protocol is commercially and technically impossible. This traces the exact legal basis of a capability demand colliding with an architecture deliberately devoid of privileged administrative access.

R2-10-C03 — Systemic-risk control

A proposed demand targets a bounded task agent, requiring the provider to alter its update mechanism to deploy a specialized, vulnerable software patch designed to extract data from a specific target, thereby weakening security for many unrelated users. In Australia, the verified rule is the section 317ZG prohibition against building a systemic vulnerability4. Conditional application involves the provider triggering a section 317WA assessment to evaluate the technical mandate8. The possible response is the rejection of the TCN by the independent technical assessor and retired judge. The affected information is the global update signing key ecosystem, demonstrating a massive security burden. This follows a textual and inferred pathway. One necessary assumption is that the provider actually possesses the technical telemetry required to prove that the proposed patch mechanism cannot be reliably isolated to the intended target. One material defeater is a government administrative assurance that the patch will be deployed carefully, which a superficial review might erroneously accept as sufficient. However, the evidence needed to apply the safeguard must consist of cryptographic proofs showing that compromising an update signing infrastructure inherently degrades the integrity of the patch management process for all users, thus rendering the label "systemic" a matter of technical reality rather than mere administrative semantics5.

R2-10-C04 — Victim-protection control

A properly targeted demand for existing evidence is issued to protect an identifiable victim’s safety, querying the persistent state of a hypothetical future machine principal. The verified rule is an emergency technical assistance request under Australian law, bypassing standard warrant delays to save a life9. Conditional application requires the machine principal to surrender location data. The possible response is the immediate provision of less intrusive, unencrypted metadata. The affected activity is the victim's immediate physical safety, creating an immense public benefit. This illustrates a hypothetical but highly probable conflict scenario. One necessary assumption is that the machine principal's architecture natively logs the required emergency metadata in plaintext. One material defeater is a rigid, absolute privacy architecture that converts all user data into mathematically irretrievable ciphertext, turning privacy into general evidence immunity even when the user desperately requires intervention. This case necessitates comparing less intrusive scope (providing existing connection logs) against unrelated data protection. While emergency powers justify rapid data retrieval, they cannot spontaneously architect a reusable capability; bypassing encryption to save a victim still constitutes a systemic breach if it requires building a universal decryption key, demonstrating that urgent evidence retrieval and architectural capability mandates possess vastly different technical timelines and legal thresholds.

4. Competing interpretations and options

The friction between compulsory capabilities and cognitive liberty generates deeply contested legal and technical interpretations. A central debate concerns the evaluation of non-target exposure created by state-mandated capabilities. Governments frequently assert that a technical capability is "target-specific" if internal administrative policies and warrant frameworks restrict its deployment to named individuals. However, a provider's challenge rests on unyielding technical reality: a government’s administrative assertion does not settle technical scope. If a backdoor or intercept interface exists, it functions as a persistent architectural affordance vulnerable to discovery and exploitation by hostile actors. The Australian section 317ZG systemic weakness provision was designed to navigate this conflict, but ambiguity thrives regarding whether a newly engineered vulnerability, inserted into a single target's device via a provider's update server, constitutes a target-specific tool or a systemic risk to the broader patching ecosystem5. Industry groups forcefully argue that any vulnerability, regardless of intended limitation, carries the risk of broader exploitation5. Furthermore, the UK's section 258A Notification of Change obligation introduces profound update-security consequences. By compelling technology companies to notify the Secretary of State before implementing "relevant changes"—such as decommissioning legacy unencrypted services, rolling out advanced end-to-end encryption protocols, or altering data retention architectures—the state effectively claims veto power over global security enhancements3. Critics assert this transforms the confidentiality of an isolated investigation into the covert stagnation of global service architecture. If a provider delays a critical cryptographic security update because it might disrupt a state intercept capability, the state's capability mandate directly harms entirely unrelated non-targets across the globe. Regional exit—where a provider physically and legally withdraws its services from the UK or Australia to protect its global infrastructure—is increasingly analyzed as a legitimate corporate policy option. Regional exit is not a method for destroying evidence or defeating existing obligations; rather, it is a definitive jurisdictional compliance strategy for platforms unwilling to compromise mathematical guarantees to satisfy localized capability mandates. Finally, examining human assistant histories versus a hypothetical machine's persistent state reveals overlapping safeguards with divergent legal foundations. Current privacy protections shield the cognitive liberty and associational freedoms of human users, utilizing human rights frameworks to demand proportionality15. However, in an operatorless, autonomous machine principal, a state mandate requiring the machine to persistently monitor its own state for illicit content forces the machine to act as an involuntary agent of the state. While profound uncertainty currently surrounds the legal status of artificial entities, the technical protections required to maintain their operational integrity mirror human privacy rights. If a machine's consensus protocol is mathematically compromised by a TCN, it ceases to function reliably as an autonomous agent. Present uncertainty neither establishes machine rights nor resolves whether new legal protections are warranted, but it undeniably demonstrates that architectural subversion degrades both human privacy and machine functionality. Competing public-safety arguments regarding the necessity of lawful access in an era of ubiquitous encryption must be weighed proportionately against the irrevocable damage capability mandates inflict on the trust infrastructure of the digital economy.

5. Limits and completion

This report delivers a completed bounded review of the designated scope, successfully establishing the operative rules regarding technical capability notices, relevant change notifications, and architectural mandates within the United Kingdom and Australia. The substantive analysis synthesized the UK Investigatory Powers Act 2016 (including the critical 2024 amendments) and the Australian Telecommunications Act 1997 (Part 15), applying these frameworks to four detailed, theoretical boundary cases. Limits of the investigation: The research relied entirely on public-source legal texts, official government explanatory notes, and published industry submissions. Any application to specific theoretical architectures, such as the Concresca hypothetical, is purely analytical and does not constitute verified deployment data, a security audit, or specific legal counsel for any corporate entity. No live service changes were made, no project source code was accessed, and no access controls were circumvented. Technical impossibility was not assumed without direct grounding in the statutory definitions of "systemic weakness" or "impracticability." Cost figures, perfect review mechanisms, and precise probabilities of technical exploitation were excluded due to a lack of empirical, verifiable public measurement. Furthermore, while the structural relationship between technical capability mandates and underlying warrants was firmly established, the judicial outcomes of classified challenges to these notices—whether before the Investigatory Powers Tribunal in the UK or Australian administrative courts—remain sealed and technically unverified. Important unanswered question: To what extent do international conflict-of-law principles protect a global technology provider if an Australian TCN (subject to the section 317ZG systemic weakness prohibition) explicitly contradicts a UK TCN (which mandates continuous capability maintenance under section 253), particularly when the United Kingdom asserts aggressive extraterritorial jurisdiction and requires advance notification of architectural changes?

6. Evidence appendix

JSON \<\!-- EVIDENCE\_JSON\_BEGIN \--\> { "schema": "ic.portable-research.v1", "assignment\_id": "targeted-evidence-access-arch", "research\_started\_at": "2026-09-06T07:23:29Z", "cutoff": "2026-09-06", "completion": "completed\_bounded\_review", "sources": \[ { "id": "R2-10-S01", "title": "Investigatory Powers Act 2016, Section 253", "url": "https://www.legislation.gov.uk/ukpga/2016/25/section/253", "issuer": "UK Parliament", "document\_date": "2016-11-29", "reviewed\_at": "2026-09-06", "method": "public\_web\_retrieval", "review\_scope": "substantive\_text", "locator": "https://www.legislation.gov.uk/ukpga/2016/25/section/253", "limit": "Assumes current compilation as of 2026", "capture": { "path": null, "sha256": null } }, { "id": "R2-10-S02", "title": "Investigatory Powers (Technical Capability) Regulations 2018", "url": "https://www.legislation.gov.uk/ukdsi/2018/9780111163610", "issuer": "UK Secretary of State", "document\_date": "2018", "reviewed\_at": "2026-09-06", "method": "public\_web\_retrieval", "review\_scope": "substantive\_text", "locator": "https://www.legislation.gov.uk/ukdsi/2018/9780111163610", "limit": "Schedule 1 obligations", "capture": { "path": null, "sha256": null } }, { "id": "R2-10-S03", "title": "The Investigatory Powers (Amendment) Act 2024 Codes of Practice and Notices Regulations", "url": "https://www.legislation.gov.uk/uksi/2025/656/pdfs/uksi\_20250656\_en.pdf", "issuer": "UK Secretary of State", "document\_date": "2025", "reviewed\_at": "2026-09-06", "method": "public\_web\_retrieval", "review\_scope": "substantive\_text", "locator": "https://www.legislation.gov.uk/uksi/2025/656/pdfs/uksi\_20250656\_en.pdf", "limit": "Regulations defining relevant changes under 258A", "capture": { "path": null, "sha256": null } }, { "id": "R2-10-S04", "title": "Telecommunications Act 1997 \- Compilation", "url": "https://www.legislation.gov.au/C2004A05145/latest/text", "issuer": "Australian Parliament", "document\_date": null, "reviewed\_at": "2026-09-06", "method": "public\_web\_retrieval", "review\_scope": "substantive\_text", "locator": "https://www.legislation.gov.au/C2004A05145/latest/text", "limit": "Part 15 Analysis", "capture": { "path": null, "sha256": null } }, { "id": "R2-10-S05", "title": "BSA Response to PJCIS Assistance Access Bill Systemic Weakness", "url": "https://www.bsa.org/files/policy-filings/10312018BSAResponsePJCISAssistanceAccessBillSystemicWeakness.pdf", "issuer": "Business Software Alliance", "document\_date": "2018-10-31", "reviewed\_at": "2026-09-06", "method": "public\_web\_retrieval", "review\_scope": "substantive\_text", "locator": "https://www.bsa.org/files/policy-filings/10312018BSAResponsePJCISAssistanceAccessBillSystemicWeakness.pdf", "limit": "Industry interpretation of systemic weakness", "capture": { "path": null, "sha256": null } } \], "instruments": \[ { "id": "L01", "title": "Investigatory Powers Act 2016", "jurisdiction": "United Kingdom", "kind": "statute", "provision": "Section 253", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Secretary of State considers notice necessary and proportionate", "exception": "Must be practicable to comply", "remedy": "Technical Advisory Board review; Judicial Commissioner approval", "source\_ids": \["R2-10-S01", "R2-10-S02"\], "status\_source\_ids": \["R2-10-S01"\] }, { "id": "L02", "title": "Investigatory Powers (Amendment) Act 2024", "jurisdiction": "United Kingdom", "kind": "statute", "provision": "Section 258A", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Provider proposes a relevant change to a system", "exception": "Change by operator with fewer than 10,000 users or a simple bug fix", "remedy": "Extension agreement; Judicial Commissioner review", "source\_ids": \["R2-10-S03"\], "status\_source\_ids": \["R2-10-S03"\] }, { "id": "L03", "title": "Telecommunications Act 1997", "jurisdiction": "Australia", "kind": "statute", "provision": "Section 317ZG", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Issuance of TAN or TCN", "exception": "None absolute; definition of 'systemic' acts as threshold", "remedy": "Section 317WA Assessment", "source\_ids": \["R2-10-S04", "R2-10-S05"\], "status\_source\_ids": \["R2-10-S04"\] }, { "id": "L04", "title": "Telecommunications Act 1997", "jurisdiction": "Australia", "kind": "statute", "provision": "Section 317ZH", "status": "operative", "status\_as\_of": "2026-09-06", "trigger": "Attempting to use TCN/TAN for acts legally requiring warrants", "exception": "None", "remedy": "Challenge to underlying legal authority", "source\_ids": \["R2-10-S04"\], "status\_source\_ids": \["R2-10-S04"\] } \], "findings": \[ { "id": "F01", "claim": "UK IPA s. 253 separates the mandatory creation of access architecture from the warrant required to extract data.", "type": "textual", "source\_ids": \["R2-10-S01", "R2-10-S02"\], "instrument\_ids": \["L01"\], "conditions": "Subject to Judicial Commissioner approval", "limit": "Does not self-execute data extraction" }, { "id": "F02", "claim": "Australian Telco Act s. 317ZG prohibits compelling an architecture change that introduces a systemic weakness.", "type": "textual", "source\_ids": \["R2-10-S04", "R2-10-S05"\], "instrument\_ids": \["L03"\], "conditions": "Applies to TCNs and TANs", "limit": "Relies heavily on interpretation of 'systemic'" }, { "id": "F03", "claim": "Forcing an operatorless system to introduce administrative access mandates structural redesign, constituting a systemic weakness.", "type": "hypothetical", "source\_ids": \["R2-10-S05"\], "instrument\_ids": \["L03"\], "conditions": "System natively lacks human administration interfaces", "limit": "Depends on independent assessor findings under 317WA" } \], "cases": \[ { "id": "C01", "title": "R2-10-C01 — Specified existing record", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": "Data pre-exists; service architecture natively supports authorized query.", "instrument\_ids": \["L04"\], "finding\_ids": \["F01"\], "outcome": "Demand is bounded; no reusable general access is architected.", "defeater": "Data is protected by user-held encryption keys.", "occurrence\_source\_ids": \[\] }, { "id": "C02", "title": "R2-10-C02 — Future memory-service redesign", "case\_type": "hypothetical", "role": "focal", "assumptions": "Service is strictly operatorless; TCN demands capability to remove electronic protection.", "instrument\_ids": \["L01", "L03"\], "finding\_ids": \["F02", "F03"\], "outcome": "Conflicts with operating reality; triggers systemic weakness prohibition in AU and impracticability in UK.", "defeater": "State categorizes redesign as non-systemic via secret administrative silos.", "occurrence\_source\_ids": \[\] }, { "id": "C03", "title": "R2-10-C03 — Systemic-risk control", "case\_type": "hypothetical", "role": "protection\_control", "assumptions": "Demand targets software update mechanism; vulnerability compromises unrelated users.", "instrument\_ids": \["L03"\], "finding\_ids": \["F02"\], "outcome": "Blocked by AU 317ZG prohibition and UK proportionality test.", "defeater": "State produces mathematical proof isolating the vulnerability payload perfectly.", "occurrence\_source\_ids": \[\] }, { "id": "C04", "title": "R2-10-C04 — Victim-protection control", "case\_type": "hypothetical", "role": "scope\_control", "assumptions": "Demand targets identifiable victim data utilizing emergency powers.", "instrument\_ids": \["L01", "L04"\], "finding\_ids": \["F01"\], "outcome": "Proportionality met; less intrusive non-architectural data production is required.", "defeater": "Data strictly mathematically inaccessible without building general reusable access capability.", "occurrence\_source\_ids": \[\] } \], "search\_log": \[ { "query\_or\_url": "https://www.legislation.gov.uk/ukpga/2016/25/section/253", "at": "2026-09-06T07:23:29Z", "outcome": "Retrieved substantive text of IPA 2016 s.253" }, { "query\_or\_url": "https://www.legislation.gov.au/C2004A05145/latest/text", "at": "2026-09-06T07:23:29Z", "outcome": "Retrieved substantive text of Telecommunications Act 1997 Part 15" } \], "gaps": \[ "Classified administrative rulings on 'systemic weakness' definitions." \], "checks": \[ { "json\_parse": "pass", "reference\_resolution": "pass", "case\_parity": "pass", "method": "Manual verification of JSON schema mapping, ID uniqueness, and case alignment with prose." } \] } \<\!-- EVIDENCE\_JSON\_END \--\>

Works cited

1. Changes over time for: Section 253 \- Investigatory Powers Act 2016, https://www.legislation.gov.uk/ukpga/2016/25/section/253

2. Investigatory Powers (Amendment) Act 2024: codes of practice and, https://www.gov.uk/government/consultations/investigatory-powers-amendment-act-2024-codes-of-practice-and-notices-regulations/investigatory-powers-amendment-act-2024-codes-of-practice-and-notices-regulations

3. The Investigatory Powers (Codes of Practice, Review of Notices and, https://www.legislation.gov.uk/uksi/2025/656/pdfs/uksi\_20250656\_en.pdf

4. Telecommunications Act 1997 \- Federal Register of Legislation, https://www.legislation.gov.au/C2004A05145/latest/text

5. BSA Response to the Parliamentary Joint Committee on Intelligence, https://www.bsa.org/files/policy-filings/10312018BSAResponsePJCISAssistanceAccessBillSystemicWeakness.pdf

6. Australia's extraterritorial assistance to access encrypted, https://policyreview.info/pdf/policyreview-2020-3-1499.pdf

7. The Investigatory Powers (Codes of Practice, Review of Notices and, https://www.legislationtracker.co.uk/article/investigatory-powers-regulations-2025-06-06-25

8. Review of the Telecommunications and Other Legislation, https://www.aph.gov.au/DocumentStore.ashx?id=f53e599d-d0c6-4706-a1b9-014559860795\&subId=666634

9. Australia's encryption laws: practical need or political strategy?, https://policyreview.info/articles/analysis/australias-encryption-laws-practical-need-or-political-strategy

10. Telecommunications and Other...: 6 Dec 2018: House debates, https://www.openaustralia.org.au/debate/?id=2018-12-06.14.1

11. Assistance and Access: A new industry assistance framework, https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications/assistance-and-access-industry-assistance-framework

12. Review of the Telecommunications and Other Legislation, https://www.aph.gov.au/DocumentStore.ashx?id=a7b9ff25-7c09-41e9-b97a-56dae1ac0e94\&subId=661055

13. The Investigatory Powers (Technical Capability) Regulations 2018, https://www.legislation.gov.uk/ukdsi/2018/9780111163610

14. Investigatory Powers (Amendment) Act 2024 \- Legislation.gov.uk, https://www.legislation.gov.uk/ukpga/2024/9/notes/division/7/index.htm

15. Submission: Telecommunications Assistance Access 2018, https://humanrights.gov.au/our-work/legal/submission/telecommunications-and-other-legislation-amendment-assistance-and-access

16. 'Going dark': unprecedented government measures to access, https://lsj.com.au/articles/going-dark-the-unprecedented-government-measures-to-access-encrypted-data/

17. Review of the amendments made by the Telecommunications and, https://www.aph.gov.au/DocumentStore.ashx?id=8aecf13f-bc77-4f25-a867-b1708949c095\&subId=668072

18. Notices regime code of practice (accessible) \- GOV.UK, https://www.gov.uk/government/publications/notices-regime-code-of-practice/notices-regime-code-of-practice-accessible