Ship's log
Corpus changelog.
Every dated revision to Landfall's obligation corpus — what changed, how many records it touched, and why.
Revision cadence
Corpus revisions land on the first working day of each quarter unless a regulation changes sooner — a new instrument, an amendment, or a correction we find ourselves. Out-of-cycle revisions are published here on the day they ship, with the same detail as a scheduled one.
ECA Digital AI, age-assurance and parental safeguards receive distinct scope and privacy-conscious assessment evidence.
Scoped natural-language AI interface safeguards1 records
A separate DRAFT record maps Decreto 12.880/2026 Article 11 to fresh child-access and natural-language content-generation/interaction facts. Source, tasks and evidence retain transparency about automated interaction, prevention of behavioral manipulation, algorithmic safety/health risk assessment and developmental safeguards. Evidence uses synthetic or sanitized cases and excludes real children's conversations and intimate disclosures from ordinary task attachments, exports and logs. The record preserves the decree's 18 March 2026 commencement; current ANPD implementing criteria, historical outcomes, other provider duties and qualified Portuguese review remain open.
Age-assurance roles, signals and privacy safeguards3 records
Three separate DRAFT records cover age-appropriate service experiences and age signals, app-store/operating-system responsibilities, and privacy and challenge safeguards when age assurance is performed. Fresh provider-role/activity facts replace feature or audience shortcuts. Tasks and evidence preserve guardian authorization without presumed silence, minimum age-signal data, more-protective handling of conflicting signals, immediate document deletion, purpose limits and dispute paths. Ordinary evidence excludes real child identities, raw credentials, documents and dispute material. Statutory and decree commencement dates remain distinct; current criteria, historical outcomes, broader ECA coverage and qualified Portuguese review remain open.
Parental information, impact reports, supervision and monitoring5 records
Five separate DRAFT records distinguish independent access to child-safety/privacy information, controller risk and impact/monitoring/evaluation reports, parental-supervision tools, and child-monitoring protections, plus the decree's child-safety impact assessment and accessible public summary. The public summary remains separate from raw reports and personal data; the decree/statute cross-reference discrepancy stays explicit for review. Fresh controller/monitoring-role facts and complete Article 39 conditions preserve the different scopes; information/report duties cannot be suppressed by that limited dispensation. Source, tasks and evidence retain accessible Portuguese controls, protective defaults, age-appropriate monitoring notice and privacy constraints. Ordinary evidence excludes children's conversations, recordings, precise locations and raw personal-data reports. Current implementing criteria, historical outcomes, broader ECA coverage and qualified Portuguese review remain open.
Seed imports remain DRAFT, UK AADC standards 11 and 12 follow the ICO's numbering, and review packets distinguish labelled paraphrases from unverified source wording.
ECA Digital sources, reporting procedures and conditional dispensation corrected7 records
Five existing ECA records plus distinct serious-violation reporting and Article 39 safeguard records cite Lei 15.211/2025 and its amended 17 March 2026 commencement. Source, saved scope facts, tasks and evidence preserve age/ad protections, privacy and excessive-use safeguards, identified notices and appeals, confidential reporting custody and receipt-based deletion. Article 39 relief requires its eligible service class and all four safeguards together; replacement safeguards and non-listed duties remain. Unsupported fixed deadlines and blanket feature proxies are removed. Article 9 tasks now retain the Decree's sector safeguards and conditional alternatives for social services, commerce, editorial content and loot boxes, with document deletion and separate 17/18 March commencement dates. No service label grants an automatic exemption. All remain DRAFT; current implementing criteria/protocols, remaining role-specific duties, historical assessment and qualified Portuguese-language review remain outstanding.
Seed imports cannot establish review
Obligation seed imports remain DRAFT. Static validators reject REVIEWED or VERIFIED records even when scalar reviewer names and dates are supplied; the database gate rejects legacy VERIFIED assertions. A preserved review of the exact current source content is required through the review workflow. Regenerated worksheets remain pending review and do not establish counsel certification.
UK AADC standards 11 and 12 renumbered3 records
The profiling obligation and its harm-assessment record cite Standard 12; the parental-controls obligation cites Standard 11. Obligation ids remain unchanged to preserve existing references. Article references, citations, trigger references, harmonization rationales, ambiguity prompts and contract templates carry the corrected numbering.
Licensed-source wording status made explicit28 records
The 28 IEEE and ISO interpretation records still need comparison with the licensed standards for source accuracy, scope, completeness and distribution rights. A framework name does not establish that stored wording is a paraphrase. Review packets use per-record paraphrase labels only where explicitly authored; other wording retains an unverified quotation status. The source wording itself is unchanged.
Evidence cadence and category extended from the EU AI Act and GDPR to every framework in the corpus.
Evidence cadence across all frameworks221 records
Every evidence requirement in the corpus now states how often its evidence must be re-assessed and which kind of evidence it wants (legal, technical, process or adversarial test). Cadences derive from the requirement's evidence type and verification method, or from a plainly stated audit-frequency note; the one-off EU database registrations under Art. 49 keep no cadence. Evidence freshness in the readiness chain, the audit report and the CI gate therefore applies to the children's-safety, privacy and standards frameworks as well.
EU AI Act corpus correction pass, plus a GDPR slice and three precedence fixes found while checking it.
EU AI Act corrected corpus40 records
A full re-read of the seeded AI Act obligations against Regulation (EU) 2024/1689 as published. Article references, severities, trigger conditions and evidence requirements were corrected where they diverged from the text; every record now cites the article it is drawn from.
GDPR slice
The GDPR obligations that an AI deployment actually reaches — Art. 22 automated decisions, Art. 35 DPIA, Art. 36 prior consultation, Art. 25 data protection by design — were separated from the general-purpose privacy set so an AI Act project no longer inherits the whole regulation.
GPAI keying
General-purpose AI model duties (Arts. 51-55) are now keyed to the GPAI provider role rather than to the high-risk classification. A deployer of a GPAI model no longer picks up the model provider's Art. 53 documentation duties, and a GPAI provider no longer loses them by answering 'not high-risk'.
Art. 55 precedence
Where a model is classified as GPAI with systemic risk, the Art. 55 duties (adversarial testing, incident reporting, cybersecurity) now take precedence over the general Art. 53 transparency set rather than sitting alongside it, so the stricter obligation is the one that surfaces.
Art. 36 review cap
GDPR Art. 36 prior consultation is capped at REQUIRES_REVIEW rather than being asserted as APPLICABLE. Whether a DPIA leaves high residual risk is a judgement a supervisory authority makes on the facts; the corpus now says the question is open instead of answering it.
Want to know when the corpus moves?
Revisions land on the first working day of each quarter, and out of cycle when a regulation does. Tell us which frameworks you care about.