Onyx Digital Intelligence.

The law never asked

#DSA #POPIA #transparency #regulation #OnyxAudit

A companion piece

I wrote earlier this week about what is in X's newly released visibility code, and about the sentence in its own source saying the classifier prompts were excluded to reduce gameability. This is the other half: whether that exclusion is permitted, by whom, and what any of it means for someone reading X in Pinetown rather than in Paris.

I expected the answer to be straightforward. It is not, and the way it fails to be straightforward is the finding.


What the regulation actually demands

X is a designated Very Large Online Platform under the European Union's Digital Services Act, and has been since April 2023. Three provisions matter here.

Article 17 requires a clear and specific statement of reasons for any restriction on the visibility of information. Recital 55 removes all doubt about scope: restriction of visibility "may consist in demotion in ranking or in recommender systems, as well as in limiting accessibility by one or more recipients of the service or blocking the user from an online community without the user being aware ('shadow banning')."

So a reply scored to zero and labelled is squarely a restriction. Article 17(3)© then requires information on the use made of automated means. Read it carefully: it requires disclosure that automated means were used, not disclosure of how they work.

Article 27 requires the main parameters of a recommender system in plain and intelligible language, specifically the criteria which are most significant and the reasons for their relative importance. Freshfields' reading of it is that the article "does not require platforms to provide information on each and every parameter used or provide information on how individual parameters are weighted." Deliberately high level.

Article 15(1)(e) requires transparency reporting on automated moderation: a qualitative description, the precise purposes, and indicators of accuracy and error rate. Not source code. Not prompts.


Where the defence lives, and where it does not

Here is the thing I did not expect.

There is no gameability exemption anywhere in the DSA's transparency provisions. No article, no recital, no Commission guidance I could find, permits a platform to withhold moderation detail from users or the public on the ground that disclosure would help people evade the system.

The only place in the regulation where a circumvention or security argument has a home is Article 40(5)(b), which lets a platform ask for a researcher's data request to be amended where access would create significant vulnerabilities in the security of the service or expose trade secrets. That sits in the researcher and regulator access channel. It does not travel to Article 17 or Article 27, and Recital 97 constrains even there, stating that commercial interests "should not lead to a refusal to provide access to data necessary for the specific research objective."

So the correct finding is narrow and it needs stating precisely, because the obvious version of it is wrong.

Withholding the prompts does not breach the DSA. It cannot, because the DSA never asked for prompts, weights or source code. The obligations were drafted at a level of abstraction that fine-grained classifier internals never reach.

But there is also no gameability exemption to rely on. X is not exercising a right the regulation granted. It is declining to volunteer something nobody demanded, and describing that decision in language borrowed from a security exception that lives somewhere else entirely.

Those two things sound similar and are not. The first is compliance. The second is framing.

The gap, therefore, is not between X and the law. It is between X and its own sentence about setting a new standard for transparency.


The regulator is already on the pitch

This does not happen in a vacuum.

On 5 December 2025 the European Commission fined X 120 million euros, the first non-compliance decision issued under the DSA. The findings concerned the deceptive design of the blue checkmark under Article 25, the advertising repository under Article 39, and researcher data access under Article 40(12). Henna Virkkunen, the Commission Executive Vice-President responsible, said that deceiving users with blue checkmarks, obscuring information on advertisements and shutting out researchers "have no place online in the EU."

Separately, the formal proceeding opened in December 2023 remains live, and on 26 January 2026 it was extended to examine X's compliance with recommender system risk management obligations under Articles 34 and 35.

None of the concluded findings touch automated moderation transparency. The recommender strand is unresolved. So a European regulator is currently examining the machinery that produces exactly the labels I was reading in the code, and has already demonstrated it will fine.


Everybody does this, which is rather the point

Before this reads as a prosecution, the comparison matters.

No major platform publishes the prompts or model weights behind its production moderation classifiers. Meta open-sourced Llama Guard as a developer safety tool, but that is not what moderates Facebook. Google, YouTube and TikTok publish transparency reports and research access, not classifier internals.

The one genuine counter-example is Bluesky, which open-sourced Ozone, the actual labelling service its own moderators use, and permits third-party labellers to publish competing moderation that users can stack. That is a smaller platform with a rules-and-reports model rather than a large opaque classifier, so it is not a like-for-like comparison. It is still the only case of a platform releasing the tool it actually runs.

X's exclusion is therefore unremarkable as industry practice. What is remarkable is doing the ordinary thing while announcing an extraordinary one.


And then there is here

An X user in the European Union whose reply is scored to zero and labelled has, at least in principle, three things. A right under Article 17 to a statement of reasons. A regulator with an open investigation into the recommender system that produced it. And a researcher access regime, with the delegated act adopted on 2 July 2025 and a data access portal being built, through which someone with standing might study the pattern.

A South African user has none of them.

POPIA section 71 restricts decisions based solely on automated processing that have legal consequences for the data subject or substantially affect them. It mirrors Article 22 of the GDPR, it provides no explicit right to an explanation, and a suppressed reply almost certainly does not clear the threshold. There is no local Article 27, no statement of reasons, no researcher access regime.

The Competition Commission's Media and Digital Platforms Market Inquiry reported on 13 November 2025 after two years, and it did examine algorithmic distribution, finding that social media algorithms "foster the spread of misinformation and disinformation by promoting sensationalist material over credible sources." It secured a R688 million media support package from Google and YouTube. But it is a competition instrument built to address media sustainability. It creates no individual right to know why your post was buried, and its provisional proposal to require changes to Meta's news distribution was dropped from the final report.

The draft National AI Policy references section 71 and does not add recommender transparency duties.

Same code. Same label. Same account. Whether anyone owes you an explanation depends on which country you were in when you opened the app.

That is the sentence I keep arriving at from different directions, and I have stopped being surprised by it.


What I have asked

I am putting the following to the European Commission, to X, and to the Information Regulator, and will publish the answers or the documented absence of them.

To the Commission: whether it considers withholding classifier prompts and thresholds compatible with Articles 15, 17 and 27; whether it recognises gameability as a legitimate ground outside Article 40(5)(b); whether the extended recommender proceeding covers reply visibility labels; and whether a reply scored to zero and labelled attracts an Article 17 statement of reasons.

To X: the specific basis for excluding the prompt templates; the size and architecture of the production ranking model, and whether the published code path matches production; why accounts with high internal reputation scores or government badges are exempted from coordinated spam enforcement; and how many accounts received visibility limiting labels in the last reporting period.

To the Information Regulator: whether algorithmic visibility reduction falls within section 71; whether any South African law gives a user a right to know why content was demoted; and whether the draft AI Policy contemplates anything analogous to Articles 27 or 40.


Method and limitations

The legal analysis here is my own reading of Regulation (EU) 2022/2065 and the Commission's published material. It is not legal advice and I am not a lawyer.

The full text of the 5 December 2025 non-compliance decision was not locatable publicly. The findings above rest on the Commission's own press release and on reputable secondary summaries, and are labelled accordingly.

The conclusion that no gameability exemption exists is a negative finding based on reading the operative text and searching for Commission guidance. A secondary source asserts that technical details protecting security may be withheld under Article 15, but I could not trace that to any operative provision and have not relied on it. If a reader can point me to guidance I have missed, I will correct this.

I have not verified every recital quotation against the canonical EUR-Lex text at the time of writing, and anyone relying on the wording should do so.

The absence of prior reporting on the code specifics is bounded by the searches I ran. It means none was located, not that none exists.


Sources

Regulation (EU) 2022/2065, Articles 15, 17, 24, 27, 34, 35, 40; Recitals 55, 66, 70, 97: https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng

European Commission, preliminary findings against X, 12 July 2024, IP/24/3761: https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3761

European Commission, first DSA non-compliance decision and fine, 5 December 2025, IP/25/2934

European Commission, delegated act on researcher data access, 2 July 2025: https://digital-strategy.ec.europa.eu/en/news/commission-adopts-delegated-act-data-access-under-digital-services-act

DSA Transparency Database: https://transparency.dsa.ec.europa.eu

Protection of Personal Information Act 4 of 2013, section 71

Competition Commission, Media and Digital Platforms Market Inquiry final report, 13 November 2025: https://www.compcom.co.za/media-and-digital-platforms-market-inquiry/

xai-org/x-algorithm: https://github.com/xai-org/x-algorithm


Clayton Bax

Published under ONYX Digital Intelligence Following the #OnyxAudit methodology.

"Adjacent to true is not true."

Truth has no flag nor favour, only a standard. And it's heavy

#DSA #OnyxAudit #POPIA #regulation #transparency