From bdc0edd1e39013099ef7ec3b9a1526d8f6a8f3a9 Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 15:02:19 +0200 Subject: [PATCH 1/9] Add GDPR Art. 22 urgency, AI-vendor segment, sharpen boundaries A client brief surfaced that the site's whole urgency case runs on the AI Act clock, which just slipped 16 months. GDPR Article 22 has applied since 2018 and doesn't move with any AI Act date; the CJEU's Schufa ruling extends that exposure to whoever produces a decisive score, not just whoever acts on it. Adds that as a second urgency callout, adds an AI-vendor strip under the industry cards (the horizontal layer the three verticals sit on, not a fourth peer card), and sharpens the boundaries section's triangulation. --- CLAUDE.md | 1 + docs/legal-deferred.md | 4 ++++ docs/site-copy.md | 12 +++++++++--- src/copy.ts | 12 ++++++++++-- src/sections/BuiltFor.tsx | 5 +++++ src/sections/RegulatoryReality.tsx | 2 ++ 6 files changed, 31 insertions(+), 5 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index 7392de5..b257bb1 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -30,6 +30,7 @@ These apply everywhere: copy, code, comments, commit messages, UI text. - The Digital Omnibus is adopted law: Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026, amending Regulation (EU) 2024/1689. Never call it a "provisional agreement" or describe its dates as pending adoption. The Omnibus moved application dates only; obligations, fine tiers, and record-keeping rules are unchanged. - All stat card links go to `artificialintelligenceact.eu` or the official EC service desk. No other sources. - Never write "every AI decision must be logged." The Act scopes logging to high-risk systems via two routes: Annex III use cases (Article 6(2), obligations from 2 December 2027) and the Annex I regulated-product route (Article 6(1), e.g. medical devices under MDR/IVDR, obligations from 2 August 2028; Machinery Regulation products are excluded from the high-risk regime entirely). Do not classify medical-device or clinical-decision-support AI as Annex III, and do not pin it to the December 2027 date. +- GDPR Article 22 / Schufa fact (do not re-litigate): the CJEU's Schufa ruling (Case C-634/21, 7 Dec 2023) held that a party producing a decisive automated score can itself be the Article 22 party, not only the party that acts on it. Independent of the AI Act timeline; Article 22 has applied since 25 May 2018. Cite the holding only; never claim Traced AI resolves Article 22 exposure, only that it produces the human-review evidence the Article 22 safeguard depends on. - Footer legal block (canonical source; `src/copy.ts` `footer.company` renders it, other docs reference this): DRIFTWARE DYNAMICS LTD, Cyprus Ltd, Reg. No.: ΗΕ 474529, VAT: CY60167558M. Values are verbatim from the incorporation docs (Greek ΗΕ, CY VAT prefix); do not "correct" them to Latin HE or strip the prefix. - Footer copyright line: `© {new Date().getFullYear()} Traced AI. All rights reserved.` The year is computed live (same principle as the deadline badge) and is never hardcoded. Brand only: the full legal entity already appears in the block directly above. Static parts live in `footer.copyright` in `src/copy.ts`; composed with the live year in `Footer.tsx`. - `public/robots.txt` and `public/sitemap.xml` are static files copied to `/dist` on build. The sitemap lists only indexable routes (currently `/`, `/product`, `/pricing`, `/about`, `/privacy`, `/terms`, `/dpa`). When a new indexable route is added, add a row to the sitemap. `/thank-you` and `*` (404) are excluded. diff --git a/docs/legal-deferred.md b/docs/legal-deferred.md index f17f4b0..86becf2 100644 --- a/docs/legal-deferred.md +++ b/docs/legal-deferred.md @@ -157,3 +157,7 @@ Apply to all future copy, in addition to the CLAUDE.md hard rules: ### Medical-device classification fact (do not re-litigate) Medical-device / clinical-decision-support AI is high-risk via the **regulated-product route: Article 6(1) / Annex I**, under MDR/IVDR, **not** Annex III (Art. 6(2)). Post-Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), its obligations apply from **2 August 2028**, not 2 December 2027 (Art. 113 as amended). Annex III categories (credit scoring, employment screening, biometric identification) are the ones tied to the 2 December 2027 date. The hero and "deadline is real" copy were corrected to stop conflating the two; keep them that way. Full baseline: `docs/site-copy.md`, "Canonical regulatory baseline" note. + +### GDPR Article 22 / Schufa fact (do not re-litigate) + +The CJEU's Schufa ruling (Case C-634/21, 7 December 2023) held that a credit-scoring agency itself engages in "automated individual decision-making" under GDPR Article 22 when a third party relies heavily on its score to decide a contract. The holding extends Article 22 exposure to whoever produces a decisive score, not only whoever acts on it. Article 22 has applied since 25 May 2018, independent of any EU AI Act date. Cite the holding only; never claim Traced AI resolves Article 22 exposure, only that it produces the human-review evidence the Article 22 safeguard (human intervention, right to contest) depends on. Source brief: `~/Downloads/tavi-eu-ai-act-brief.md` (client-specific proposal, not published). diff --git a/docs/site-copy.md b/docs/site-copy.md index 0de8736..e89e25b 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -62,7 +62,9 @@ Section label, headline, body, two-line closing, and enterprise procurement call **Post-Omnibus rewrite (`regulatoryReality.headline` + `body`):** The Digital Omnibus is now adopted law (Regulation (EU) 2026/1744, in force 27 July 2026), so the headline and body no longer hedge on adoption. Headline: "The deadline moved. The obligations didn’t." Body states the fixed December 2, 2027 Annex III date directly. [cut: headline "On August 2nd, “the AI decided” stops being an acceptable answer."] [cut: body sentence "A provisional political agreement in May 2026 (Digital Omnibus) may defer standalone Annex III obligations to December 2027 once formally adopted. The obligations are unchanged; the date may move."] -**In force now callout (`regulatoryReality.inForceNow`, new key):** A short callout between the question/punchline block and the procurement callout. Both callouts render through a shared local `Callout({ heading, body })` component in `RegulatoryReality.tsx` (extracted during the /simplify pass to remove duplicated JSX) rather than each hand-coding the `.callout` markup. Carries the dual-date framing’s other half: enforcement of GPAI rules, Article 5 prohibitions, Article 50 transparency, and AI literacy began August 2, 2026, plus the single approved contextual line on Article 50 (disclosure duties apply now, content-marking phases in through December 2, 2026 for pre-existing systems per the Art. 50(2) grace period), plus the evidence-cannot-be-backfilled runway argument. No new section, no product claim about Article 50. [cut: earlier draft said content marking "already apply" with no grace-period qualifier, corrected during frontend-review since it overstated the obligation for systems placed on market before 2 Aug 2026.] [cut: earlier draft repeated "Your Annex III date is December 2, 2027" a third time in this section (after regulatoryReality.body and stats[3]); trimmed during the /simplify pass since the date was already anchored twice above.] +**In force now callout (`regulatoryReality.inForceNow`, new key):** A short callout between the question/punchline block and the GDPR urgency callout. All three callouts render through the same local `Callout({ heading, body })` component in `RegulatoryReality.tsx` (extracted during the /simplify pass to remove duplicated JSX) rather than each hand-coding the `.callout` markup. Carries the dual-date framing’s other half: enforcement of GPAI rules, Article 5 prohibitions, Article 50 transparency, and AI literacy began August 2, 2026, plus the single approved contextual line on Article 50 (disclosure duties apply now, content-marking phases in through December 2, 2026 for pre-existing systems per the Art. 50(2) grace period), plus the evidence-cannot-be-backfilled runway argument. No new section, no product claim about Article 50. [cut: earlier draft said content marking "already apply" with no grace-period qualifier, corrected during frontend-review since it overstated the obligation for systems placed on market before 2 Aug 2026.] [cut: earlier draft repeated "Your Annex III date is December 2, 2027" a third time in this section (after regulatoryReality.body and stats[3]); trimmed during the /simplify pass since the date was already anchored twice above.] + +**GDPR urgency callout (`regulatoryReality.gdprUrgency`, new key):** Third callout, between `inForceNow` and the procurement callout, same shared `Callout` component. Gives the section a second, date-independent urgency leg: GDPR Article 22 (right to human intervention, right to contest an automated decision) has applied since 25 May 2018, unaffected by any AI Act deadline. Cites the CJEU’s Schufa ruling (Case C-634/21, 7 Dec 2023), which held that whoever produces a decisive automated score can itself be the Article 22 party, not only whoever acts on it. Fact locked in `CLAUDE.md` and `docs/legal-deferred.md` (do-not-re-litigate block); surfaced by a client brief (`~/Downloads/tavi-eu-ai-act-brief.md`, not published) that showed the site's urgency case was entirely AI-Act-clock-dependent with no fallback leg. **Procurement callout** (`regulatoryReality.procurement.body`) now answers the "this is for big companies, not startups" objection explicitly: you do not have to be the regulated party, you only have to sell into one, and the buyer's procurement gate is the deal-blocker today. [cut: closing was just "The deal-blocker is today." — expanded so the timing/buyer-gate rebuttal is explicit rather than implied.] @@ -76,7 +78,9 @@ Section label, headline, and three industry cards (Fintech, Medtech, HR Automati **Reference note:** Annex III Section 5(b) covers creditworthiness assessment and access to essential private services (backs the Fintech card). -**HR Automation card:** Updated to surface the candidate notification duty (Art. 26(11)) and the right to explanation (Art. 86) — obligations deployers most often miss. The card now reads: candidates have a right to know AI assessed them and to receive an explanation on request; Traced AI provides the per-candidate trail that makes both answerable. Key: `builtFor.cards[2].body`. +**HR Automation card:** Updated to surface the candidate notification duty (Art. 26(11)) and the right to explanation (Art. 86), obligations deployers most often miss. The card now reads: candidates have a right to know AI assessed them and to receive an explanation on request; Traced AI provides the per-candidate trail that makes both answerable. Key: `builtFor.cards[2].body`. + +**Vendor note (`builtFor.vendorNote`, new key):** Not a 4th card in the `cards[]` grid, the grid's `repeat(auto-fit, minmax(280px, 1fr))` at the 1100px `.page-section` width fits exactly 3 columns, so a 4th card would orphan onto its own row with empty space beside it. Instead renders as a full-width strip directly below the 3-card grid in `BuiltFor.tsx`, reusing the same `.card`/`.card-accent`/`card-mono-label`/`card-body` classes the three cards use, with slightly reduced vertical padding to read as visibly thinner. Reads as the horizontal layer the three industry verticals sit on: speaks to AI/SaaS vendors whose product *is* the scoring system (not a company merely using AI in-house), who can carry Article 22-style exposure directly per the Schufa fact above, and who can resell the evidence layer to their own downstream customers as a feature. Surfaced by the same client brief as the GDPR urgency callout. ### Section 4: Waitlist Form (`waitlist`) @@ -118,7 +122,9 @@ traced_ai.init( Renders between How It Works and Rule Registry. Section label "WHERE THE LINE IS", heading "What Traced AI is not", and three items stating the boundaries as features: `boundaries.*` (`sectionLabel`, `heading`, `items[]`). -Intent: turn the limits into a self-qualification and a differentiator. The three items map to the competitive landscape (not named on site): **Not a compliance product** (the judgment stays with counsel/QMS; also the new home of the QMS/counsel boundary moved out of `howItWorks.intro`), **Not a guardrail** (it never intervenes in a decision, unlike a control plane), **Not an eval tool** (it does not grade quality, and the local-first/hashes-only architecture is framed as the structural reason: proving a decision needs only its hash and its signer, not the raw data). Component: `src/sections/Boundaries.tsx`, heading is an `

` (Product's single `

` is in How It Works). +Intent: turn the limits into a self-qualification and a differentiator. The three items map to the competitive landscape (not named on site): **Not a compliance product** (attestation/QMS tooling proves a process exists; Traced AI proves what happened in one specific case; the judgment still stays with counsel/QMS), **Not a guardrail** (it never intervenes in a decision, unlike a control plane), **Not an eval tool** (bias/fairness tooling proves the model behaves, a different question from what it did in one case; it does not grade quality, and the local-first/hashes-only architecture is framed as the structural reason: proving a decision needs only its hash and its signer, not the raw data). Component: `src/sections/Boundaries.tsx`, heading is an `

` (Product's single `

` is in How It Works). + +**Triangulation sharpened:** items 0 and 2 rewritten to carry a clean three-way cut (process exists / model behaves / what actually happened), surfaced by a client brief that framed it sharply without naming real competitors; that framing borrowed here without naming them either. [cut: item 0 read "You decide whether you comply; your legal counsel and quality management system own that judgment. Traced AI makes what your AI actually did provable, which is the part nobody can produce after the fact."] [cut: item 2 read "It does not score quality, accuracy, or sentiment. A witness reports what happened, it does not grade it. That is also why your raw prompts and outputs never leave your perimeter: proving a decision needs only its hash and its signer, not the underlying data."] ### Section 6: Rule Registry (`ruleRegistry`) diff --git a/src/copy.ts b/src/copy.ts index 6403d95..11db3e6 100644 --- a/src/copy.ts +++ b/src/copy.ts @@ -57,6 +57,10 @@ export const regulatoryReality = { heading: 'In force now', body: 'Enforcement began August 2, 2026. Prohibited practices, general-purpose AI rules, transparency, and AI literacy are enforceable now, at national and EU level. If your system interacts with people or generates content, Article 50 disclosure duties apply now; content-marking requirements phase in through December 2, 2026 for systems already on the market. Evidence cannot be backfilled: logs only exist from the day you start writing them.', }, + gdprUrgency: { + heading: 'This doesn’t wait for the AI Act', + body: 'GDPR Article 22 has granted a right to human intervention and to contest an automated decision since 2018, no AI Act clock attached. The CJEU’s Schufa ruling (Case C-634/21) held that whoever produces the decisive score can be the Article 22 party, not just whoever acts on it. If your AI scores, ranks, or screens people, that exposure may already sit with you, today.', + }, procurement: { heading: 'Enterprise procurement note', body: 'Your enterprise customers are already demanding AI governance evidence. Banks, insurers, and public-sector buyers ask what models you use, how decisions are logged, and what audit evidence exists. You do not have to be the regulated party to need this. If you sell into one, their procurement gate is the deal-blocker, and it is today.', @@ -109,7 +113,7 @@ export const boundaries = { items: [ { title: 'Not a compliance product', - body: 'You decide whether you comply; your legal counsel and quality management system own that judgment. Traced AI makes what your AI actually did provable, which is the part nobody can produce after the fact.', + body: 'Attestation and quality-management tooling can prove a process exists. Traced AI proves what your AI actually did in one specific case, the part a process document cannot produce after the fact. You decide whether you comply; your legal counsel and quality management system own that judgment.', }, { title: 'Not a guardrail', @@ -117,7 +121,7 @@ export const boundaries = { }, { title: 'Not an eval tool', - body: 'It does not score quality, accuracy, or sentiment. A witness reports what happened, it does not grade it. That is also why your raw prompts and outputs never leave your perimeter: proving a decision needs only its hash and its signer, not the underlying data.', + body: 'Bias and fairness tools tell you whether the model behaves, a different question from what it did in one specific case. Traced AI does not score quality, accuracy, or sentiment: a witness reports what happened, it does not grade it. Your raw prompts and outputs never leave your perimeter either way: proving a decision needs only its hash and its signer, not the underlying data.', }, ] as BoundaryItem[], }; @@ -182,6 +186,10 @@ export const builtFor = { body: 'Recruitment, hiring, and workforce assessment AI are high-risk under Annex III. Candidates have a right to know AI assessed them and to receive an explanation on request (Art. 26(11), Art. 86). Traced AI gives you the per-candidate decision trail that makes both answerable, plus structured audit views for regulators, works councils, and litigators.', }, ] as IndustryCard[], + vendorNote: { + title: 'If you sell the AI, not just use it', + body: 'If your product scores, ranks, or screens people for other companies, the exposure may sit with you, not just your customer: the CJEU’s Schufa ruling put the score-producer on the hook under GDPR Article 22. Traced AI gives you an evidence layer to embed and resell, so your customers inherit audit-ready logs instead of building their own.', + } as IndustryCard, }; export interface PricingFeature { diff --git a/src/sections/BuiltFor.tsx b/src/sections/BuiltFor.tsx index 8b1247b..c93c66a 100644 --- a/src/sections/BuiltFor.tsx +++ b/src/sections/BuiltFor.tsx @@ -18,6 +18,11 @@ export default function BuiltFor() { ))} + +
+
{builtFor.vendorNote.title}
+

{builtFor.vendorNote.body}

+
) diff --git a/src/sections/RegulatoryReality.tsx b/src/sections/RegulatoryReality.tsx index ad32580..7b27678 100644 --- a/src/sections/RegulatoryReality.tsx +++ b/src/sections/RegulatoryReality.tsx @@ -41,6 +41,8 @@ export default function RegulatoryReality() { + +

From fd7ba11269092460cbe4408a56232aa263e362d7 Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 15:26:04 +0200 Subject: [PATCH 2/9] Apply /simplify findings: callouts[] array, trim redundancy Generalizes regulatoryReality's three named singleton callouts (inForceNow, gdprUrgency, procurement) into a callouts[] array rendered via .map(), since a third named callout made the copy-paste-per-addition pattern a repeating cost rather than a one-off. Also tightens boundaries.items[2] to drop an internal restatement, and dedups the GDPR Article 22 / Schufa fact across CLAUDE.md, legal-deferred.md, and site-copy.md down to one full explanation with two pointers, instead of three near-duplicates. --- CLAUDE.md | 2 +- docs/site-copy.md | 8 ++++---- src/copy.ts | 33 ++++++++++++++++++------------ src/sections/RegulatoryReality.tsx | 8 +++----- 4 files changed, 28 insertions(+), 23 deletions(-) diff --git a/CLAUDE.md b/CLAUDE.md index b257bb1..c4cc3b2 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -30,7 +30,7 @@ These apply everywhere: copy, code, comments, commit messages, UI text. - The Digital Omnibus is adopted law: Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026, amending Regulation (EU) 2024/1689. Never call it a "provisional agreement" or describe its dates as pending adoption. The Omnibus moved application dates only; obligations, fine tiers, and record-keeping rules are unchanged. - All stat card links go to `artificialintelligenceact.eu` or the official EC service desk. No other sources. - Never write "every AI decision must be logged." The Act scopes logging to high-risk systems via two routes: Annex III use cases (Article 6(2), obligations from 2 December 2027) and the Annex I regulated-product route (Article 6(1), e.g. medical devices under MDR/IVDR, obligations from 2 August 2028; Machinery Regulation products are excluded from the high-risk regime entirely). Do not classify medical-device or clinical-decision-support AI as Annex III, and do not pin it to the December 2027 date. -- GDPR Article 22 / Schufa fact (do not re-litigate): the CJEU's Schufa ruling (Case C-634/21, 7 Dec 2023) held that a party producing a decisive automated score can itself be the Article 22 party, not only the party that acts on it. Independent of the AI Act timeline; Article 22 has applied since 25 May 2018. Cite the holding only; never claim Traced AI resolves Article 22 exposure, only that it produces the human-review evidence the Article 22 safeguard depends on. +- GDPR Article 22 / Schufa fact (do not re-litigate, full fact in `docs/legal-deferred.md`): cite the CJEU's Schufa holding (Case C-634/21) only. Never claim Traced AI resolves Article 22 exposure, only that it produces the human-review evidence the Article 22 safeguard depends on. - Footer legal block (canonical source; `src/copy.ts` `footer.company` renders it, other docs reference this): DRIFTWARE DYNAMICS LTD, Cyprus Ltd, Reg. No.: ΗΕ 474529, VAT: CY60167558M. Values are verbatim from the incorporation docs (Greek ΗΕ, CY VAT prefix); do not "correct" them to Latin HE or strip the prefix. - Footer copyright line: `© {new Date().getFullYear()} Traced AI. All rights reserved.` The year is computed live (same principle as the deadline badge) and is never hardcoded. Brand only: the full legal entity already appears in the block directly above. Static parts live in `footer.copyright` in `src/copy.ts`; composed with the live year in `Footer.tsx`. - `public/robots.txt` and `public/sitemap.xml` are static files copied to `/dist` on build. The sitemap lists only indexable routes (currently `/`, `/product`, `/pricing`, `/about`, `/privacy`, `/terms`, `/dpa`). When a new indexable route is added, add a row to the sitemap. `/thank-you` and `*` (404) are excluded. diff --git a/docs/site-copy.md b/docs/site-copy.md index e89e25b..0ca97cc 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -62,11 +62,11 @@ Section label, headline, body, two-line closing, and enterprise procurement call **Post-Omnibus rewrite (`regulatoryReality.headline` + `body`):** The Digital Omnibus is now adopted law (Regulation (EU) 2026/1744, in force 27 July 2026), so the headline and body no longer hedge on adoption. Headline: "The deadline moved. The obligations didn’t." Body states the fixed December 2, 2027 Annex III date directly. [cut: headline "On August 2nd, “the AI decided” stops being an acceptable answer."] [cut: body sentence "A provisional political agreement in May 2026 (Digital Omnibus) may defer standalone Annex III obligations to December 2027 once formally adopted. The obligations are unchanged; the date may move."] -**In force now callout (`regulatoryReality.inForceNow`, new key):** A short callout between the question/punchline block and the GDPR urgency callout. All three callouts render through the same local `Callout({ heading, body })` component in `RegulatoryReality.tsx` (extracted during the /simplify pass to remove duplicated JSX) rather than each hand-coding the `.callout` markup. Carries the dual-date framing’s other half: enforcement of GPAI rules, Article 5 prohibitions, Article 50 transparency, and AI literacy began August 2, 2026, plus the single approved contextual line on Article 50 (disclosure duties apply now, content-marking phases in through December 2, 2026 for pre-existing systems per the Art. 50(2) grace period), plus the evidence-cannot-be-backfilled runway argument. No new section, no product claim about Article 50. [cut: earlier draft said content marking "already apply" with no grace-period qualifier, corrected during frontend-review since it overstated the obligation for systems placed on market before 2 Aug 2026.] [cut: earlier draft repeated "Your Annex III date is December 2, 2027" a third time in this section (after regulatoryReality.body and stats[3]); trimmed during the /simplify pass since the date was already anchored twice above.] +**Callouts array (`regulatoryReality.callouts[]`, refactored from 3 named keys):** Three callouts render via `.map()` in `RegulatoryReality.tsx` over `{heading, body}[]`, through the same local `Callout` component (originally extracted during the /simplify pass on the Omnibus PR to remove duplicated JSX between 2 callouts; generalized to an array during the /simplify pass on this PR once a 3rd named callout made the copy-paste-per-addition pattern a repeating cost, not a one-off). [cut: the 3 items previously lived as named keys `inForceNow`, `gdprUrgency`, `procurement`, each requiring a matching hand-written `` line in the component.] -**GDPR urgency callout (`regulatoryReality.gdprUrgency`, new key):** Third callout, between `inForceNow` and the procurement callout, same shared `Callout` component. Gives the section a second, date-independent urgency leg: GDPR Article 22 (right to human intervention, right to contest an automated decision) has applied since 25 May 2018, unaffected by any AI Act deadline. Cites the CJEU’s Schufa ruling (Case C-634/21, 7 Dec 2023), which held that whoever produces a decisive automated score can itself be the Article 22 party, not only whoever acts on it. Fact locked in `CLAUDE.md` and `docs/legal-deferred.md` (do-not-re-litigate block); surfaced by a client brief (`~/Downloads/tavi-eu-ai-act-brief.md`, not published) that showed the site's urgency case was entirely AI-Act-clock-dependent with no fallback leg. - -**Procurement callout** (`regulatoryReality.procurement.body`) now answers the "this is for big companies, not startups" objection explicitly: you do not have to be the regulated party, you only have to sell into one, and the buyer's procurement gate is the deal-blocker today. [cut: closing was just "The deal-blocker is today." — expanded so the timing/buyer-gate rebuttal is explicit rather than implied.] +- **[0] In force now:** carries the dual-date framing’s other half: enforcement of GPAI rules, Article 5 prohibitions, Article 50 transparency, and AI literacy began August 2, 2026, plus the single approved contextual line on Article 50 (disclosure duties apply now, content-marking phases in through December 2, 2026 for pre-existing systems per the Art. 50(2) grace period), plus the evidence-cannot-be-backfilled runway argument. No new section, no product claim about Article 50. [cut: earlier draft said content marking "already apply" with no grace-period qualifier, corrected during frontend-review since it overstated the obligation for systems placed on market before 2 Aug 2026.] [cut: earlier draft repeated "Your Annex III date is December 2, 2027" a third time in this section (after regulatoryReality.body and stats[3]); trimmed during the /simplify pass since the date was already anchored twice above.] +- **[1] This doesn't wait for the AI Act (GDPR urgency, new):** gives the section a second, date-independent urgency leg: GDPR Article 22 is unaffected by any AI Act deadline. Full fact and citation in `docs/legal-deferred.md`'s "GDPR Article 22 / Schufa fact" do-not-re-litigate block; surfaced by a client brief (`~/Downloads/tavi-eu-ai-act-brief.md`, not published) that showed the site's urgency case was entirely AI-Act-clock-dependent with no fallback leg. +- **[2] Enterprise procurement note:** answers the "this is for big companies, not startups" objection explicitly: you do not have to be the regulated party, you only have to sell into one, and the buyer's procurement gate is the deal-blocker today. [cut: closing was just "The deal-blocker is today." — expanded so the timing/buyer-gate rebuttal is explicit rather than implied.] Four stat cards: `stats[]` (each has `value`, `label`, `url`). Sources are on the `CLAUDE.md` allowlist. [cut: stats[3] read value "Aug 2, 2026", label "Full application of high-risk system requirements per Article 113": replaced with the fixed December 2, 2027 date now that the Omnibus is adopted.] diff --git a/src/copy.ts b/src/copy.ts index 11db3e6..39c31c5 100644 --- a/src/copy.ts +++ b/src/copy.ts @@ -47,24 +47,31 @@ export const stats: Stat[] = [ }, ]; +export interface RegulatoryCallout { + heading: string; + body: string; +} + export const regulatoryReality = { sectionLabel: 'THE DEADLINE IS REAL', headline: 'The deadline moved. The obligations didn’t.', body: 'If your system handles credit decisions, employment screening, or biometric identification, Annex III classifies it as high-risk. Decisions made by that system must be logged, explainable, and defensible. The Digital Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) moved the standalone Annex III date to December 2, 2027: a fixed date, no conditions attached.', question: 'When enforcement comes, good intentions don\'t appear in audit logs.', questionPunchline: 'Documented evidence does.', - inForceNow: { - heading: 'In force now', - body: 'Enforcement began August 2, 2026. Prohibited practices, general-purpose AI rules, transparency, and AI literacy are enforceable now, at national and EU level. If your system interacts with people or generates content, Article 50 disclosure duties apply now; content-marking requirements phase in through December 2, 2026 for systems already on the market. Evidence cannot be backfilled: logs only exist from the day you start writing them.', - }, - gdprUrgency: { - heading: 'This doesn’t wait for the AI Act', - body: 'GDPR Article 22 has granted a right to human intervention and to contest an automated decision since 2018, no AI Act clock attached. The CJEU’s Schufa ruling (Case C-634/21) held that whoever produces the decisive score can be the Article 22 party, not just whoever acts on it. If your AI scores, ranks, or screens people, that exposure may already sit with you, today.', - }, - procurement: { - heading: 'Enterprise procurement note', - body: 'Your enterprise customers are already demanding AI governance evidence. Banks, insurers, and public-sector buyers ask what models you use, how decisions are logged, and what audit evidence exists. You do not have to be the regulated party to need this. If you sell into one, their procurement gate is the deal-blocker, and it is today.', - }, + callouts: [ + { + heading: 'In force now', + body: 'Enforcement began August 2, 2026. Prohibited practices, general-purpose AI rules, transparency, and AI literacy are enforceable now, at national and EU level. If your system interacts with people or generates content, Article 50 disclosure duties apply now; content-marking requirements phase in through December 2, 2026 for systems already on the market. Evidence cannot be backfilled: logs only exist from the day you start writing them.', + }, + { + heading: 'This doesn’t wait for the AI Act', + body: 'GDPR Article 22 has granted a right to human intervention and to contest an automated decision since 2018, no AI Act clock attached. The CJEU’s Schufa ruling (Case C-634/21) held that whoever produces the decisive score can be the Article 22 party, not just whoever acts on it. If your AI scores, ranks, or screens people, that exposure may already sit with you, today.', + }, + { + heading: 'Enterprise procurement note', + body: 'Your enterprise customers are already demanding AI governance evidence. Banks, insurers, and public-sector buyers ask what models you use, how decisions are logged, and what audit evidence exists. You do not have to be the regulated party to need this. If you sell into one, their procurement gate is the deal-blocker, and it is today.', + }, + ] as RegulatoryCallout[], sourceAttr: 'EU AI Act, Regulation EU 2024/1689, as amended by Regulation EU 2026/1744, Articles 9, 11, 12, 13, 14, 19, 26(6), Annex III, Annex IV. Official text:', sourceUrl: @@ -121,7 +128,7 @@ export const boundaries = { }, { title: 'Not an eval tool', - body: 'Bias and fairness tools tell you whether the model behaves, a different question from what it did in one specific case. Traced AI does not score quality, accuracy, or sentiment: a witness reports what happened, it does not grade it. Your raw prompts and outputs never leave your perimeter either way: proving a decision needs only its hash and its signer, not the underlying data.', + body: 'Bias and fairness tools tell you whether the model behaves. Traced AI does not score quality, accuracy, or sentiment, it reports what happened in one specific case. Your raw prompts and outputs never leave your perimeter either way: proving a decision needs only its hash and its signer, not the underlying data.', }, ] as BoundaryItem[], }; diff --git a/src/sections/RegulatoryReality.tsx b/src/sections/RegulatoryReality.tsx index 7b27678..7529ff7 100644 --- a/src/sections/RegulatoryReality.tsx +++ b/src/sections/RegulatoryReality.tsx @@ -39,11 +39,9 @@ export default function RegulatoryReality() {

- - - - - + {regulatoryReality.callouts.map((c, i) => ( + + ))}

{regulatoryReality.sourceAttr}{' '} From 986c5cef20c0fb6bfff2b81ff994fddf8e6e7372 Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 15:29:13 +0200 Subject: [PATCH 3/9] Make the traced_init.py example match what the product logs The snippet stopped at init(), implying the rationale/reviewer capture the site claims elsewhere (structured rationale, reviewer ID) happens automatically. It doesn't: capturing why a decision was made and who signed off is a distinct explicit call for the calls that need it, not folded into the two-line setup. Adds that call. --- docs/site-copy.md | 13 +++++++++++-- src/sections/HowItWorks.tsx | 12 +++++++++--- 2 files changed, 20 insertions(+), 5 deletions(-) diff --git a/docs/site-copy.md b/docs/site-copy.md index 0ca97cc..ec13d8b 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -111,12 +111,21 @@ Two-line headline, intro, and four-item feature list (Auto-patching SDK, Local-f import traced_ai traced_ai.init( - api_key="...", + api_key="trc_live_...", rules="eu-ai-act-annex-iii" ) +# Auto-traced. Raw I/O stays local, hashes flow to the ledger. -# From here, every LLM call is automatically traced +decision = client.chat.completions.create(...) + +# Rationale + reviewer, for decisions that need a signer. +traced_ai.sign_off( + decision, + rationale="Score below threshold, no red flags", + reviewer_id="cosmin@company.com" +) ``` +Added the `sign_off` call so the example matches what the product actually claims to log elsewhere on this page (`ruleRegistry.rows`: "structured rationale, reviewer ID") and in `howItWorks.intro` ("the why... and the who"). `init()` auto-patches the LLM client and traces every call; capturing rationale and a reviewer for a decision-worthy call is a distinct, explicit second call, not folded into the two-line setup, since it is extra work only some calls need. [cut: prior snippet stopped at `init()` plus a single comment, implying rationale/reviewer capture was automatic; it is not.] ### Section 5b: Boundaries (`boundaries`) diff --git a/src/sections/HowItWorks.tsx b/src/sections/HowItWorks.tsx index 8cf8793..ce4fb38 100644 --- a/src/sections/HowItWorks.tsx +++ b/src/sections/HowItWorks.tsx @@ -14,9 +14,15 @@ function CodeBlock() { traced_ai.init(
    api_key="trc_live_...",
    rules="eu-ai-act-annex-iii"
- )

- # Every LLM call is now automatically traced.
- # Raw I/O stays local. Hashes flow to the ledger. + )
+ # Auto-traced. Raw I/O stays local, hashes flow to the ledger.

+ decision = client.chat.completions.create(...)

+ # Rationale + reviewer, for decisions that need a signer.
+ traced_ai.sign_off(
+     decision,
+     rationale="Score below threshold, no red flags",
+     reviewer_id="cosmin@company.com"
+ ) ) From 29aea116f5861cc09750bbdc2bc301aceb4ce00e Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 16:26:02 +0200 Subject: [PATCH 4/9] Drop unnecessary type cast on builtFor.vendorNote TypeScript already infers {title, body} from the object literal. --- src/copy.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/copy.ts b/src/copy.ts index 39c31c5..9e04e97 100644 --- a/src/copy.ts +++ b/src/copy.ts @@ -196,7 +196,7 @@ export const builtFor = { vendorNote: { title: 'If you sell the AI, not just use it', body: 'If your product scores, ranks, or screens people for other companies, the exposure may sit with you, not just your customer: the CJEU’s Schufa ruling put the score-producer on the hook under GDPR Article 22. Traced AI gives you an evidence layer to embed and resell, so your customers inherit audit-ready logs instead of building their own.', - } as IndustryCard, + }, }; export interface PricingFeature { From f6d30e378a5d1122a48552e634d86ed6fc36ed16 Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 16:43:46 +0200 Subject: [PATCH 5/9] Fix code example architecture, add plan-independent export note The example implied a customer manually writes a rationale string and pays for a second explicit call to capture it. Neither is true: init() alters the customer's own prompt templates so the same LLM call that produces the output also produces its rationale, parsed from that one response. Traced AI never runs or bills for the underlying LLM call, that stays on the customer's own infrastructure and cost. Only the human sign-off is a genuinely separate, optional step, since it happens after the fact. Also sharpens the AI-vendor pitch and pricing page with a concrete, plan-independent guarantee: a provider embedding Traced AI can export logs to their own downstream customers on demand, on every plan, not gated to Enterprise. --- docs/site-copy.md | 17 ++++++++++------- src/copy.ts | 5 ++++- src/sections/HowItWorks.tsx | 9 +++++---- src/sections/Pricing.tsx | 7 +++++++ 4 files changed, 26 insertions(+), 12 deletions(-) diff --git a/docs/site-copy.md b/docs/site-copy.md index ec13d8b..17a6326 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -80,7 +80,7 @@ Section label, headline, and three industry cards (Fintech, Medtech, HR Automati **HR Automation card:** Updated to surface the candidate notification duty (Art. 26(11)) and the right to explanation (Art. 86), obligations deployers most often miss. The card now reads: candidates have a right to know AI assessed them and to receive an explanation on request; Traced AI provides the per-candidate trail that makes both answerable. Key: `builtFor.cards[2].body`. -**Vendor note (`builtFor.vendorNote`, new key):** Not a 4th card in the `cards[]` grid, the grid's `repeat(auto-fit, minmax(280px, 1fr))` at the 1100px `.page-section` width fits exactly 3 columns, so a 4th card would orphan onto its own row with empty space beside it. Instead renders as a full-width strip directly below the 3-card grid in `BuiltFor.tsx`, reusing the same `.card`/`.card-accent`/`card-mono-label`/`card-body` classes the three cards use, with slightly reduced vertical padding to read as visibly thinner. Reads as the horizontal layer the three industry verticals sit on: speaks to AI/SaaS vendors whose product *is* the scoring system (not a company merely using AI in-house), who can carry Article 22-style exposure directly per the Schufa fact above, and who can resell the evidence layer to their own downstream customers as a feature. Surfaced by the same client brief as the GDPR urgency callout. +**Vendor note (`builtFor.vendorNote`, new key):** Not a 4th card in the `cards[]` grid, the grid's `repeat(auto-fit, minmax(280px, 1fr))` at the 1100px `.page-section` width fits exactly 3 columns, so a 4th card would orphan onto its own row with empty space beside it. Instead renders as a full-width strip directly below the 3-card grid in `BuiltFor.tsx`, reusing the same `.card`/`.card-accent`/`card-mono-label`/`card-body` classes the three cards use, with slightly reduced vertical padding to read as visibly thinner. Reads as the horizontal layer the three industry verticals sit on: speaks to AI/SaaS vendors whose product *is* the scoring system (not a company merely using AI in-house), who can carry Article 22-style exposure directly per the Schufa fact above, and who can export the evidence layer to their own downstream customers on demand, on any plan, not just Enterprise (see `pricing.exportNote`). Surfaced by the same client brief as the GDPR urgency callout. [cut: body previously said "embed and resell" without the any-plan/on-demand specifics; sharpened once the provider-to-deployer export guarantee was confirmed as plan-independent.] ### Section 4: Waitlist Form (`waitlist`) @@ -114,18 +114,19 @@ traced_ai.init( api_key="trc_live_...", rules="eu-ai-act-annex-iii" ) -# Auto-traced. Raw I/O stays local, hashes flow to the ledger. +# Every call now returns its own rationale, in the same response. +# Only hashes and the rationale text leave your infrastructure. decision = client.chat.completions.create(...) -# Rationale + reviewer, for decisions that need a signer. +# Optional, for decisions that need a human sign-off. traced_ai.sign_off( decision, - rationale="Score below threshold, no red flags", - reviewer_id="cosmin@company.com" + reviewer_id="cosmin@company.com", + feedback="Confirmed, no red flags" ) ``` -Added the `sign_off` call so the example matches what the product actually claims to log elsewhere on this page (`ruleRegistry.rows`: "structured rationale, reviewer ID") and in `howItWorks.intro` ("the why... and the who"). `init()` auto-patches the LLM client and traces every call; capturing rationale and a reviewer for a decision-worthy call is a distinct, explicit second call, not folded into the two-line setup, since it is extra work only some calls need. [cut: prior snippet stopped at `init()` plus a single comment, implying rationale/reviewer capture was automatic; it is not.] +Corrected the architecture the example implies. Traced AI does not run or bill for the customer's own LLM call; `init()` alters the customer's own prompt templates so the same call that produces the output also produces its rationale, parsed out of that single response, no second LLM call, no extra inference cost. Input and output stay on the customer's infrastructure (hashed before anything leaves); the rationale text itself, not just its hash, is what reaches the ledger, since it carries no raw customer data. `sign_off` is the one genuinely separate, optional call: a human confirming or adding feedback happens after the fact and cannot be folded into the original LLM call. Renamed the AI's own explanation `rationale` (matches existing site vocabulary in `ruleRegistry.rows` and `howItWorks.intro`) and the human's optional note `feedback`, keeping the two distinct. [cut: prior version had the developer manually pass a `rationale=` string into `sign_off`, implying a person writes the rationale and that capturing it costs a second explicit call; both were wrong. The rationale is AI-generated and automatic, in the same call as the output.] ### Section 5b: Boundaries (`boundaries`) @@ -145,7 +146,9 @@ Two-line headline, two body paragraphs, a registry preview card (field/value row ### Section 7: Pricing Tiers (`pricing`) -Section label, headline, subheadline, three tiers (Free, Startup, Enterprise) with their features and badges, the self-hosted callout, and the pricing note: `pricing.*` (`headline`, `subheadline`, `tiers[]`, `selfHostedHeading`, `selfHostedNote`, `pricingNote`, `featuredTag`). +Section label, headline, subheadline, three tiers (Free, Startup, Enterprise) with their features and badges, the self-hosted callout, the downstream-exports callout, and the pricing note: `pricing.*` (`headline`, `subheadline`, `tiers[]`, `selfHostedHeading`, `selfHostedNote`, `exportHeading`, `exportNote`, `pricingNote`, `featuredTag`). + +**Exports callout (`pricing.exportHeading` + `exportNote`, new keys):** Second `.callout` block in `Pricing.tsx`, directly below the self-hosted callout, same shape and styling. States that a provider embedding Traced AI can export logs and hand them to their own downstream customers (deployers) on demand, on every plan from Free through Enterprise, not gated to an Enterprise add-on. Answers the question a vendor prospect (like the one behind `builtFor.vendorNote`) would otherwise be left to guess at from the tier grid alone. **Reference note (not rendered on site):** Rationale text is stored as structured fields, not free-form strings. This protects against accidental capture of personal data, prompt leakage, or confidential reasoning chains. Field-level configuration controls exactly what enters the rationale record. Full documentation in the SDK guide. diff --git a/src/copy.ts b/src/copy.ts index 9e04e97..09245ed 100644 --- a/src/copy.ts +++ b/src/copy.ts @@ -195,7 +195,7 @@ export const builtFor = { ] as IndustryCard[], vendorNote: { title: 'If you sell the AI, not just use it', - body: 'If your product scores, ranks, or screens people for other companies, the exposure may sit with you, not just your customer: the CJEU’s Schufa ruling put the score-producer on the hook under GDPR Article 22. Traced AI gives you an evidence layer to embed and resell, so your customers inherit audit-ready logs instead of building their own.', + body: 'If your product scores, ranks, or screens people for other companies, the exposure may sit with you, not just your customer: the CJEU’s Schufa ruling put the score-producer on the hook under GDPR Article 22. Traced AI gives you an evidence layer to embed: on any plan, you can export the logs it generates and hand them to your own customers on demand, so they inherit audit-ready evidence instead of building their own.', }, }; @@ -279,6 +279,9 @@ export const pricing = { selfHostedNote: 'The local viewer ships with the SDK. Raw AI data never leaves your perimeter, on any plan.', selfHostedHeading: 'Self-hosted component', + exportNote: + 'If you embed Traced AI in your own product, exporting logs to your own customers on demand works on every plan, Free through Enterprise, not an Enterprise add-on.', + exportHeading: 'Exports for your own customers', readyHeadline: 'Ready to start?', featuredTag: 'MOST POPULAR', pricingNote: diff --git a/src/sections/HowItWorks.tsx b/src/sections/HowItWorks.tsx index ce4fb38..97aca9e 100644 --- a/src/sections/HowItWorks.tsx +++ b/src/sections/HowItWorks.tsx @@ -15,13 +15,14 @@ function CodeBlock() {     api_key="trc_live_...",
    rules="eu-ai-act-annex-iii"
)
- # Auto-traced. Raw I/O stays local, hashes flow to the ledger.

+ # Every call now returns its own rationale, in the same response.
+ # Only hashes and the rationale text leave your infrastructure.

decision = client.chat.completions.create(...)

- # Rationale + reviewer, for decisions that need a signer.
+ # Optional, for decisions that need a human sign-off.
traced_ai.sign_off(
    decision,
-     rationale="Score below threshold, no red flags",
-     reviewer_id="cosmin@company.com"
+     reviewer_id="cosmin@company.com",
+     feedback="Confirmed, no red flags"
) diff --git a/src/sections/Pricing.tsx b/src/sections/Pricing.tsx index 10c2753..11658ad 100644 --- a/src/sections/Pricing.tsx +++ b/src/sections/Pricing.tsx @@ -28,6 +28,13 @@ export default function Pricing() { {pricing.selfHostedNote} +

+ + {pricing.exportHeading} + + {pricing.exportNote} +
+

{pricing.pricingNote}

From e64283535be5ff3aab8e939adc401fb7650daf54 Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 16:59:42 +0200 Subject: [PATCH 6/9] Rename decision to response in the code example decision read as a second act of decision-making happening on Traced AI's behalf, possibly a new, billed LLM call. It's just the return value of the client's own already-existing call. sign_off attaches an optional human confirmation to that response, it does not make or remake the decision. --- docs/site-copy.md | 12 ++++++------ src/sections/HowItWorks.tsx | 10 +++++----- 2 files changed, 11 insertions(+), 11 deletions(-) diff --git a/docs/site-copy.md b/docs/site-copy.md index 17a6326..008999b 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -114,19 +114,19 @@ traced_ai.init( api_key="trc_live_...", rules="eu-ai-act-annex-iii" ) -# Every call now returns its own rationale, in the same response. -# Only hashes and the rationale text leave your infrastructure. +# Your own call, already patched. No new LLM call, no new cost. +# Its response now carries the rationale too, in the same shot. -decision = client.chat.completions.create(...) +response = client.chat.completions.create(...) -# Optional, for decisions that need a human sign-off. +# Optional, to attach a human sign-off to that response. traced_ai.sign_off( - decision, + response, reviewer_id="cosmin@company.com", feedback="Confirmed, no red flags" ) ``` -Corrected the architecture the example implies. Traced AI does not run or bill for the customer's own LLM call; `init()` alters the customer's own prompt templates so the same call that produces the output also produces its rationale, parsed out of that single response, no second LLM call, no extra inference cost. Input and output stay on the customer's infrastructure (hashed before anything leaves); the rationale text itself, not just its hash, is what reaches the ledger, since it carries no raw customer data. `sign_off` is the one genuinely separate, optional call: a human confirming or adding feedback happens after the fact and cannot be folded into the original LLM call. Renamed the AI's own explanation `rationale` (matches existing site vocabulary in `ruleRegistry.rows` and `howItWorks.intro`) and the human's optional note `feedback`, keeping the two distinct. [cut: prior version had the developer manually pass a `rationale=` string into `sign_off`, implying a person writes the rationale and that capturing it costs a second explicit call; both were wrong. The rationale is AI-generated and automatic, in the same call as the output.] +Corrected the architecture the example implies. Traced AI does not run or bill for the customer's own LLM call; `init()` alters the customer's own prompt templates so the same call that produces the output also produces its rationale, parsed out of that single response, no second LLM call, no extra inference cost. Input and output stay on the customer's infrastructure (hashed before anything leaves); the rationale text itself, not just its hash, is what reaches the ledger, since it carries no raw customer data. `sign_off` is the one genuinely separate, optional call: a human confirming or adding feedback happens after the fact and cannot be folded into the original LLM call. Renamed the AI's own explanation `rationale` (matches existing site vocabulary in `ruleRegistry.rows` and `howItWorks.intro`) and the human's optional note `feedback`, keeping the two distinct. [cut: prior version had the developer manually pass a `rationale=` string into `sign_off`, implying a person writes the rationale and that capturing it costs a second explicit call; both were wrong. The rationale is AI-generated and automatic, in the same call as the output.] [cut: variable was named `decision`, which read as if the LLM call were computing a new decision on Traced AI's behalf (a second, possibly billed, act of decision-making). Renamed to `response`: it is the return value of the client's own already-existing call, nothing new is computed or charged by Traced AI. `sign_off` attaches an optional human confirmation to that same response, it does not make or remake the decision.] ### Section 5b: Boundaries (`boundaries`) diff --git a/src/sections/HowItWorks.tsx b/src/sections/HowItWorks.tsx index 97aca9e..14661b2 100644 --- a/src/sections/HowItWorks.tsx +++ b/src/sections/HowItWorks.tsx @@ -15,12 +15,12 @@ function CodeBlock() {     api_key="trc_live_...",
    rules="eu-ai-act-annex-iii"
)
- # Every call now returns its own rationale, in the same response.
- # Only hashes and the rationale text leave your infrastructure.

- decision = client.chat.completions.create(...)

- # Optional, for decisions that need a human sign-off.
+ # Your own call, already patched. No new LLM call, no new cost.
+ # Its response now carries the rationale too, in the same shot.

+ response = client.chat.completions.create(...)

+ # Optional, to attach a human sign-off to that response.
traced_ai.sign_off(
-     decision,
+     response,
    reviewer_id="cosmin@company.com",
    feedback="Confirmed, no red flags"
) From 4da8789fc4d3cdbeed475a29d0dc926d9fdecd7d Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 17:09:01 +0200 Subject: [PATCH 7/9] Fix stale site-copy.md summary line for Regulatory Reality Still described a single 'enterprise procurement callout' after the section grew to three callouts in the callouts[] refactor. --- docs/site-copy.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/site-copy.md b/docs/site-copy.md index 008999b..21d6dd1 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -58,7 +58,7 @@ Headline, subheadline, body, and CTAs: `hero.*` (`line1`, `line2Strike`, `line2H ### Section 2: Regulatory Reality (`regulatoryReality`, `stats`) -Section label, headline, body, two-line closing, and enterprise procurement callout: `regulatoryReality.*`. Source attribution line: `regulatoryReality.sourceAttr` + `sourceUrl`. +Section label, headline, body, two-line closing, and three callouts (in force now, GDPR urgency, enterprise procurement): `regulatoryReality.*`. Source attribution line: `regulatoryReality.sourceAttr` + `sourceUrl`. **Post-Omnibus rewrite (`regulatoryReality.headline` + `body`):** The Digital Omnibus is now adopted law (Regulation (EU) 2026/1744, in force 27 July 2026), so the headline and body no longer hedge on adoption. Headline: "The deadline moved. The obligations didn’t." Body states the fixed December 2, 2027 Annex III date directly. [cut: headline "On August 2nd, “the AI decided” stops being an acceptable answer."] [cut: body sentence "A provisional political agreement in May 2026 (Digital Omnibus) may defer standalone Annex III obligations to December 2027 once formally adopted. The obligations are unchanged; the date may move."] From 592be19520299002498beaf413aceb75e79ad6ad Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 17:19:41 +0200 Subject: [PATCH 8/9] Make feedback mandatory-on-signoff, cite GDPR in sourceAttr ruleRegistry now states reviewer ID and feedback are captured together only when a human signs off, not that feedback is an optional extra within that call. Tightened the code example's comment to match: signing off is optional, feedback isn't once you do. Also extends regulatoryReality.sourceAttr to cite GDPR Article 22, since the section now carries a callout grounded in that instrument and not just the AI Act. --- docs/site-copy.md | 6 +++++- src/copy.ts | 4 ++-- src/sections/HowItWorks.tsx | 2 +- 3 files changed, 8 insertions(+), 4 deletions(-) diff --git a/docs/site-copy.md b/docs/site-copy.md index 21d6dd1..cf8e6a2 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -60,6 +60,8 @@ Headline, subheadline, body, and CTAs: `hero.*` (`line1`, `line2Strike`, `line2H Section label, headline, body, two-line closing, and three callouts (in force now, GDPR urgency, enterprise procurement): `regulatoryReality.*`. Source attribution line: `regulatoryReality.sourceAttr` + `sourceUrl`. +**Source attribution now covers both instruments (`regulatoryReality.sourceAttr`):** Appends "and GDPR Article 22 (Regulation (EU) 2016/679)" before "Official text:", since the section's GDPR urgency callout draws from a different instrument than the AI Act citation the line previously covered alone. `sourceUrl` still links only to the AI Act's eur-lex text; the GDPR citation stays plain text, matching the no-hyperlink convention already used for the Schufa fact in the callout itself. [cut: prior line cited only "EU AI Act, Regulation EU 2024/1689, as amended by Regulation EU 2026/1744, Articles 9, 11, 12, 13, 14, 19, 26(6), Annex III, Annex IV."] + **Post-Omnibus rewrite (`regulatoryReality.headline` + `body`):** The Digital Omnibus is now adopted law (Regulation (EU) 2026/1744, in force 27 July 2026), so the headline and body no longer hedge on adoption. Headline: "The deadline moved. The obligations didn’t." Body states the fixed December 2, 2027 Annex III date directly. [cut: headline "On August 2nd, “the AI decided” stops being an acceptable answer."] [cut: body sentence "A provisional political agreement in May 2026 (Digital Omnibus) may defer standalone Annex III obligations to December 2027 once formally adopted. The obligations are unchanged; the date may move."] **Callouts array (`regulatoryReality.callouts[]`, refactored from 3 named keys):** Three callouts render via `.map()` in `RegulatoryReality.tsx` over `{heading, body}[]`, through the same local `Callout` component (originally extracted during the /simplify pass on the Omnibus PR to remove duplicated JSX between 2 callouts; generalized to an array during the /simplify pass on this PR once a 3rd named callout made the copy-paste-per-addition pattern a repeating cost, not a one-off). [cut: the 3 items previously lived as named keys `inForceNow`, `gdprUrgency`, `procurement`, each requiring a matching hand-written `` line in the component.] @@ -126,7 +128,7 @@ traced_ai.sign_off( feedback="Confirmed, no red flags" ) ``` -Corrected the architecture the example implies. Traced AI does not run or bill for the customer's own LLM call; `init()` alters the customer's own prompt templates so the same call that produces the output also produces its rationale, parsed out of that single response, no second LLM call, no extra inference cost. Input and output stay on the customer's infrastructure (hashed before anything leaves); the rationale text itself, not just its hash, is what reaches the ledger, since it carries no raw customer data. `sign_off` is the one genuinely separate, optional call: a human confirming or adding feedback happens after the fact and cannot be folded into the original LLM call. Renamed the AI's own explanation `rationale` (matches existing site vocabulary in `ruleRegistry.rows` and `howItWorks.intro`) and the human's optional note `feedback`, keeping the two distinct. [cut: prior version had the developer manually pass a `rationale=` string into `sign_off`, implying a person writes the rationale and that capturing it costs a second explicit call; both were wrong. The rationale is AI-generated and automatic, in the same call as the output.] [cut: variable was named `decision`, which read as if the LLM call were computing a new decision on Traced AI's behalf (a second, possibly billed, act of decision-making). Renamed to `response`: it is the return value of the client's own already-existing call, nothing new is computed or charged by Traced AI. `sign_off` attaches an optional human confirmation to that same response, it does not make or remake the decision.] +Corrected the architecture the example implies. Traced AI does not run or bill for the customer's own LLM call; `init()` alters the customer's own prompt templates so the same call that produces the output also produces its rationale, parsed out of that single response, no second LLM call, no extra inference cost. Input and output stay on the customer's infrastructure (hashed before anything leaves); the rationale text itself, not just its hash, is what reaches the ledger, since it carries no raw customer data. `sign_off` is the one genuinely separate, optional call: a human confirming or adding feedback happens after the fact and cannot be folded into the original LLM call. Calling `sign_off` at all is optional; `feedback` is not optional within that call, if a human signs off, their rationale for doing so is captured every time. Renamed the AI's own explanation `rationale` (matches existing site vocabulary in `ruleRegistry.rows` and `howItWorks.intro`) and the human's note `feedback`, keeping the two distinct. [cut: prior version had the developer manually pass a `rationale=` string into `sign_off`, implying a person writes the rationale and that capturing it costs a second explicit call; both were wrong. The rationale is AI-generated and automatic, in the same call as the output.] [cut: variable was named `decision`, which read as if the LLM call were computing a new decision on Traced AI's behalf (a second, possibly billed, act of decision-making). Renamed to `response`: it is the return value of the client's own already-existing call, nothing new is computed or charged by Traced AI. `sign_off` attaches an optional human confirmation to that same response, it does not make or remake the decision.] ### Section 5b: Boundaries (`boundaries`) @@ -140,6 +142,8 @@ Intent: turn the limits into a self-qualification and a differentiator. The thre Two-line headline, two body paragraphs, a registry preview card (field/value rows, one with a link), and a badge row: `ruleRegistry.*` (`headline1`, `headline2`, `body`, `body2`, `rows[]`, `badges[]`). +**"Logging required" row (`ruleRegistry.rows[4].value`):** Now lists `feedback` alongside `reviewer ID`, both captured together only when a human signs off; the base fields (input hash, output hash, rationale, timestamp) are unconditional. Matches the `sign_off` call in the `howItWorks` code example, where signing off at all is optional but `feedback` is a required argument once you do. [cut: prior value "Decision input hash, output hash, structured rationale, reviewer ID, timestamp" implied reviewer ID (and by extension, the newer feedback field) was always captured, not conditional on sign-off happening.] + --- ## Pricing (`/pricing`) diff --git a/src/copy.ts b/src/copy.ts index 09245ed..1d1c516 100644 --- a/src/copy.ts +++ b/src/copy.ts @@ -73,7 +73,7 @@ export const regulatoryReality = { }, ] as RegulatoryCallout[], sourceAttr: - 'EU AI Act, Regulation EU 2024/1689, as amended by Regulation EU 2026/1744, Articles 9, 11, 12, 13, 14, 19, 26(6), Annex III, Annex IV. Official text:', + 'EU AI Act, Regulation EU 2024/1689, as amended by Regulation EU 2026/1744, Articles 9, 11, 12, 13, 14, 19, 26(6), Annex III, Annex IV, and GDPR Article 22 (Regulation (EU) 2016/679). Official text:', sourceUrl: 'https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689', }; @@ -163,7 +163,7 @@ export const ruleRegistry = { }, { field: 'Logging required', - value: 'Decision input hash, output hash, structured rationale, reviewer ID, timestamp', + value: 'Decision input hash, output hash, structured rationale, timestamp; reviewer ID and feedback together, when a human signs off', }, { field: 'Last updated', value: '2026-07-28, v4.0, signed' }, ] as RegistryRow[], diff --git a/src/sections/HowItWorks.tsx b/src/sections/HowItWorks.tsx index 14661b2..1ba57dc 100644 --- a/src/sections/HowItWorks.tsx +++ b/src/sections/HowItWorks.tsx @@ -18,7 +18,7 @@ function CodeBlock() { # Your own call, already patched. No new LLM call, no new cost.
# Its response now carries the rationale too, in the same shot.

response = client.chat.completions.create(...)

- # Optional, to attach a human sign-off to that response.
+ # Optional to call. If you do, feedback is required.
traced_ai.sign_off(
    response,
    reviewer_id="cosmin@company.com",
From 1449e1d2c7969abccc0018bfa5db814c87afd00f Mon Sep 17 00:00:00 2001 From: Cosmin Poieana Date: Mon, 3 Aug 2026 17:21:37 +0200 Subject: [PATCH 9/9] Use a generic placeholder email in the code example cosmin@company.com could read as if the founder were personally the reviewer on someone else's setup. --- docs/site-copy.md | 2 +- src/sections/HowItWorks.tsx | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/site-copy.md b/docs/site-copy.md index cf8e6a2..2de9777 100644 --- a/docs/site-copy.md +++ b/docs/site-copy.md @@ -124,7 +124,7 @@ response = client.chat.completions.create(...) # Optional, to attach a human sign-off to that response. traced_ai.sign_off( response, - reviewer_id="cosmin@company.com", + reviewer_id="reviewer@company.com", feedback="Confirmed, no red flags" ) ``` diff --git a/src/sections/HowItWorks.tsx b/src/sections/HowItWorks.tsx index 1ba57dc..9213008 100644 --- a/src/sections/HowItWorks.tsx +++ b/src/sections/HowItWorks.tsx @@ -21,7 +21,7 @@ function CodeBlock() { # Optional to call. If you do, feedback is required.
traced_ai.sign_off(
    response,
-     reviewer_id="cosmin@company.com",
+     reviewer_id="reviewer@company.com",
    feedback="Confirmed, no red flags"
)