X's Reply-spam it's limited, you deserve to know why.
"Open Source" Transparency: A Regulatory Analysis (#OnyxAudit)
Prepared 14 August 2026. Evidentiary tiers: Tier A = verified against a primary source (regulation text, official regulator document, court/company statement, or the source code itself); Tier B = single credible secondary source or reasoned inference, labelled as such; Tier C = speculation, marked. UK English throughout.
TL;DR
- Under the EU Digital Services Act, X's "we excluded the prompts to reduce gameability" position is legally unaddressed rather than authorised: the DSA never actually demands classifier prompts or model internals from users or the public, so the carve-out X invokes has no home in the transparency provisions (Articles 15, 17, 27). The only place a "security vulnerability / circumvention" defence exists in the DSA text is Article 40(5)(b), which governs researcher data access, not moderation transparency.
- As at 14 August 2026, no located reporting covers the specific
grox/flows/reply_spam/findings (theCoordinatedSpamScorer, the 1000-followerlow_blast_radiusthreshold, thehigh_page_rank_v2/grey_badgeexemptions, or theRiskyHighVizReplylabel). Coverage of the 13 August 2026 release is broad but generic; the researcher is very likely first on these particulars. This is a documented negative finding, bounded by the searches conducted. - The released "mini Phoenix" is, on the balance of published evidence, a demonstration artifact and not the production ranking model; xAI's own
phoenix/README.mdstates production "uses a larger model with more layers and wider embeddings" without quantifying it, which materially weakens X's "new standard for transparency" claim.
Key Findings
DSA transparency obligations are real and specific, but scoped. Article 27 requires only the "main parameters" and "most significant" criteria of recommender systems, not every parameter or the full algorithm. Article 17 unambiguously treats visibility reduction, demotion and "shadow banning" as restrictions that require a statement of reasons. Article 15(1)(e) requires a "qualitative description" plus accuracy and error-rate indicators for automated moderation, not source code.
The central legal question resolves against X's framing but not cleanly. The gameability exclusion is neither expressly permitted nor expressly prohibited for moderation transparency. It is "unaddressed" because the DSA never requires the withheld detail in the first place. The one textual circumvention/security carve-out (Article 40(5)(b)) sits in the researcher-data-access regime.
The Commission has already fined X and is still investigating recommender systems. On 5 December 2025 the Commission imposed its first-ever DSA non-compliance fine of €120 million (Articles 25, 39, 40(12)). A separate December 2023 proceeding remains open and was extended on 26 January 2026 to examine recommender-system risk management. Digital Policy Alert eucrim
No prior coverage of the reply-spam specifics was located. Reporting on the 2023, January/May 2026, and 13 August 2026 releases is extensive but generic. The
groxreply-spam pipeline details appear in no located reporting.Terminology traces to documented X concepts. Grey badge = government/multilateral accounts;
high_page_rank_v2plausibly descends from 2023's Tweepcred (inference); Strato is X internal infrastructure; "visibility filtering"/"VF" is documented from 2018 and the 2022 Twitter Files.South African users have no DSA equivalent. POPIA section 71 covers automated decisions with legal/material effect only; there is no Article 27 or Article 40 analogue. Jurisdiction, not user choice, determines the remedy.
Details
Question 1: EU DSA obligations for VLOPs
X (Twitter International Unlimited Company) has been a designated VLOP since April 2023. Goodwin The canonical regulation text is Regulation (EU) 2022/2065, at https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng.
(a) Article 27 recommender transparency (Tier A). Article 27(1) requires providers to set out "in plain and intelligible language, the main parameters used in their recommender systems, as well as any options for the recipients of the service to modify or influence those main parameters." Socialmediatransparency Article 27(2): the main parameters "shall include, at least: (a) the criteria which are most significant in determining the information suggested to the recipient of the service; (b) the reasons for the relative importance of those parameters." Digital Services Act Socialmediatransparency Recital 70 clarifies these "should include at least the most important criteria in determining the information suggested to the recipient of the service and the reasons for their respective importance." Freshfields' analysis notes Article 27 "does not require platforms to provide information on each and every parameter used or provide information on how individual parameters are weighted." The scope is deliberately high-level. URL: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_27.html.
(b) Article 17 statements of reasons (Tier A). Article 17(1) requires "a clear and specific statement of reasons" for "any restrictions of the visibility of specific items of information ... including removal of content, disabling access to content, or demoting content." Recital 55 is explicit: "Restriction of visibility may consist in demotion in ranking or in recommender systems, as well as in limiting accessibility by one or more recipients of the service or blocking the user from an online community without the user being aware ('shadow banning')." So visibility reduction and demotion plainly count as restrictions requiring a statement of reasons. Article 17(3)© requires "where applicable, information on the use made of automated means in taking the decision, including information on whether the decision was taken in respect of content detected or identified using automated means." Crucially this is an existence disclosure (that automated means were used), not a requirement to disclose how the classifier works. The only carve-out is "deceptive high-volume commercial content" (Article 17(1); Recital 55). URL: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_17.html.
© Article 24(5) and the Transparency Database (Tier A). Article 24(5) requires platforms to submit their statements of reasons to the Commission's DSA Transparency Database "without undue delay," in a standard, machine-readable format (Recital 66). Since visibility reduction and demotion are Article 17 restrictions, reduced-visibility decisions in principle must be submitted. Database and FAQ: https://transparency.dsa.ec.europa.eu and https://digital-strategy.ec.europa.eu/en/faqs/dsa-transparency-database-questions-and-answers.
(d) Article 40 researcher data access (Tier A). Article 40(4) grants vetted researchers access to data to study systemic risks; Article 40(12) covers public data access. Policy Review On 2 July 2025 the Commission adopted the delegated act laying down procedures and technical conditions European Commission and is launching the DSA Data Access Portal (https://digital-strategy.ec.europa.eu/en/news/commission-adopts-delegated-act-data-access-under-digital-services-act). Article 40(5)(b) lets a platform request amendment of a request where access "will lead to significant vulnerabilities in the security of their service or the protection of confidential information, in particular trade secrets," Policy Review but Recital 97 limits this: commercial interests "should not lead to a refusal to provide access to data necessary for the specific research objective." Article 40(3) requires platforms to explain "the design, the logic, the functioning and the testing of their algorithmic systems, including their recommender systems" to regulators. URL: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_40.html.
(e) Articles 34-35 systemic risk (Tier A/B). Articles 34 and 35 require VLOPs to assess and mitigate systemic risks stemming from the design and operation of their services, expressly including recommender systems and content-moderation systems. This is the hook under which the Commission's recommender-system investigation of X proceeds.
(f) Articles 15 and 42 transparency reporting (Tier A). Article 15(1)(e) requires reporting of "any use made of automated means for the purpose of content moderation, including a qualitative description, a specification of the precise purposes, indicators of the accuracy and the possible rate of error of the automated means used ... and any safeguards applied." Digital Services Act Article 42 tightens this to six-monthly for VLOPs and adds human-resources and linguistic-expertise reporting; Lexology Article 42(2)© requires accuracy indicators "broken down by each official language." The DSA Observatory noted (8 January 2026) that Article 15(1)(e) "indicators of accuracy" disclosures so far are "essentially meaningless." URLs: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_15.html and .../Digital_Services_Act_Article_42.html.
Question 2: The central legal question - is the gameability exclusion lawful?
Conclusion: unaddressed, and therefore not a recognised lawful defence for user-facing or public transparency (Tier A analysis). There is no provision in the DSA (Articles 15, 17, 24, 27), no recital, and no located Commission guidance or decision, that expressly permits withholding automated-moderation detail from users or the public on the ground that disclosure would enable gaming or circumvention. The obligations are scoped so that fine-grained classifier internals are never demanded in the first place: Article 17(3)© requires existence-only disclosure; Article 27(2) requires only "main"/"most significant" parameters; Socialmediatransparency Article 15(1)(e) requires only a "qualitative description." Consequently, X's stated rationale for excluding the prompt templates is best characterised as unaddressed under the transparency regime rather than sanctioned by it.
The one textual anchor for a circumvention/security-vulnerability defence is Article 40(5)(b), read with Recital 97, and it lives only in the researcher/regulator data-access channel. It cannot be assumed to transfer to Article 17 or Article 27 duties. A widely-cited secondary summary (dsa-library.com) asserts that "technical details protecting security can be withheld" under Article 15, but this cannot be traced to operative DSA text and should be treated as commentary (Tier C), not authority.
The practical upshot: excluding the prompts does not by itself breach the DSA, because the DSA never required the prompts. But X cannot rely on a DSA "gameability" exemption to justify the exclusion, because none exists for transparency duties. X's own framing ("we are committed to setting a new standard for transparency") is a voluntary standard, and the gap between the voluntary claim and the exclusion is an editorial and accountability point, not a statutory breach. This is the sharpest, most defensible line for the piece.
Question 3: Commission proceedings against X
- December 2023 (Tier A): Formal proceedings opened covering illegal content dissemination, information manipulation (Israel/Hamas context), and transparency theregister .
- 8 May 2024 (Tier B): Request for information issued.
- 12 July 2024 (Tier A): Preliminary findings issued alleging breaches of Articles 25 (dark patterns / blue checkmark), 39 (ad repository) and 40(12) (researcher data access). European Commission Europa Press release IP/24/3761: https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3761.
- 17 January 2025 (Tier A/B): Additional investigatory measures on X's recommender system; X requested to provide detailed documentation by 15 February 2025.
- 5 December 2025 (Tier A): The Commission "issued a fine of €120 million to X for breaching its transparency obligations under the Digital Services Act... This is the first non-compliance decision under the DSA." The decision covered three areas: the deceptive design of the 'blue checkmark' (Article 25), the ad repository (Article 39), and researcher data access (Article 40(12)). X was given 60 working days on the checkmark issue and 90 days on the ad repository and researcher access. Executive Vice-President for Tech Sovereignty, Security and Democracy Henna Virkkunen said: "Deceiving users with blue checkmarks, obscuring information on ads and shutting out researchers have no place online in the EU... With the DSA's first non-compliance decision, we are holding X responsible for undermining users' rights and evading accountability." US Vice-President JD Vance publicly denounced the fine. IAPP Press release IP/25/2934.
- 26 January 2026 (Tier A/B, via Digital Policy Alert): The existing December 2023 investigation was extended to further evaluate compliance with recommender-system risk-management obligations.
None of the concluded findings concern the gameability of automated moderation. The recommender-system strand is live and unresolved as at August 2026. The full non-compliance decision document was not located publicly; findings rest on the Commission press release and reputable summaries (Goodwin, IAPP, eucrim, TechPolicy.Press).
Question 4: Prior reporting and prior releases
2023 release (twitter/the-algorithm), 31 March 2023 (Tier A/B). Twitter open-sourced much of the For You ranking code Gupta Deepak but excluded training data, model weights, and trust-and-safety code, explicitly to reduce gaming by bad actors. Researchers found the Tweepcred PageRank reputation score (0-100), Steventey which reduces rank for accounts with many followings but few followers; a documented Twitter Blue boost (per the 2023 README as documented by Steve Tey and the Knight First Amendment Institute, Blue subscribers receive "a 4x boost in the algorithm if you're in the same network as the author of the tweet, and a 2x boost if you're not" - the Knight Institute cautions this is a score multiplier, not a literal reach multiplier); and code flags identifying whether a tweet author was Elon Musk or whether an account was Democrat/Republican (widely reported as for testing/monitoring). arxiv A December 2025 arXiv study ("Rabble-Rousers in the New King's Court") confirms "the algorithm's code contained identifying flags for whether a user was a Democrat or Republican, or even for whether a tweet was authored by Elon Musk." The repository went largely dormant afterwards. Musk's stated "acid test" (31 March 2023): "independent third parties should be able to determine, with reasonable accuracy, what will probably be shown to users."
January/May 2026 release (xai-org/x-algorithm) (Tier B). A Rust/Python rewrite (roughly 63% Rust). The 15 May 2026 update shipped a runnable end-to-end pipeline (phoenix/run_pipeline.py) and the "mini Phoenix" checkpoint. It was received as a genuine step beyond 2023 but still criticised because production weights remain proprietary; xAI redacted numerical engagement weights in January 2026 citing security. Tech Times One Yahoo/Tech report noted the repo sat at a single commit four months after the open-source promise, before the May update.
13 August 2026 release (Tier A/B). Per the @XOpenSource announcement (https://x.com/XOpenSource/status/2087951962004230428): "We're open-sourcing the code that affects a post's visibility in the For You timeline, and releasing a new tool that shows people labels applied to their account or posts that might limit visibility." The "Under the Hood" tool lets accounts that posted 10+ times in the prior month download a JSON of labels applied, initially to a randomised test group of accounts at least one year old. Reporting is broad: TechCrunch (13 August), TechBriefly, Dataconomy, BigGo, WERSM and others. Coverage is generic. BigGo noted: "Some systems remain closed, including those using Grok for rule-violation prediction, to prevent gaming." X VP of Product Keith Coleman told TechCrunch: "You'll get the core ranking code that pulls posts and ranks them for any given user and assembles the feed."
Documented negative finding (Tier A as to absence). In the sources located, no reporting covers the grox/flows/reply_spam/ pipeline specifics: the CoordinatedSpamScorer, the TaskCoordinatedSpamFilter, FOLLOWER_COUNT_THRESHOLD_FOR_SPAM_DETECTION = 1000 / low_blast_radius, the one_level_deep gate, the high_page_rank_or_grey_badge exemption, or SafetyLabelType.RiskyHighVizReply. General-audience "how to grow on X" posts (OpenTweet, Postory, note.com/jmworks) discuss a Grox spam classifier "for people with few followers" in passing, but none surface the follower threshold, the PageRank/grey-badge exemption, the two-levels-deep gate, or the specific safety label. The researcher is very likely first on these particulars. Frame this as "no prior coverage located as of 14 August 2026," not as proof of universal absence.
Question 5: Terminology
- Grey badge / grey checkmark (Tier A): X's Help Centre states the grey checkmark "indicates that an account represents a government institution or official, or a multilateral organization." Introduced 19 December 2022. That such accounts are exempted from the reply-spam gate (
high_page_rank_or_grey_badge) is significant: it hard-codes preferential enforcement treatment for state actors. URL: https://help.x.com/en/using-x/grey-checkmark. - Page rank / Tweepcred (Tier A/B): Tweepcred was a weighted PageRank reputation score (0-100) in the 2023 release.
high_page_rank_v2plausibly descends from it (Tier B inference; the "v2" suffix and identical conceptual role support this, but direct code lineage is not documented in located sources). - Strato (Tier B): X/Twitter internal storage-and-serving infrastructure (a data-access/serving layer);
StratoApplyLabelFromGroxwrites safety labels via this layer. - Visibility filtering / VF (Tier A/B): X internal terminology documented publicly since a 2018 Twitter transparency post and surfaced in the December 2022 "Twitter Files," which described internal tools applying labels such as search blacklists, "do not amplify," and NSFW-type flags.
SafetyLabelType.RiskyHighVizReplyis consistent with this lineage.
Question 6: Freedom of reach and prior statements
- 18 November 2022 (Tier A): Musk: "New Twitter policy is freedom of speech, but not freedom of reach. Negative/hate tweets will be max deboosted & demonetized, so no ads or other revenue to Twitter. You won't find the tweet unless you specifically seek it out, which is no different from rest of Internet." (Fox News, CNN, Newsweek.)
- December 2022 (Tier A): Musk: "Twitter is working on a software update that will show your true account status, so you know clearly if you've been shadowbanned, the reason why and how to appeal." Newsweek Reported as unfulfilled through 2023 and into subsequent years (Techdirt, Daily Dot). The 13 August 2026 "Under the Hood" tool is the closest realisation, roughly three-and-a-half years later.
- April 2023 (Tier B): X formally adopted "Freedom of Speech, Not Reach" as published policy, Daily Dot relying on de-amplification of violative posts.
- X's Help Centre documents reduced-visibility labels (profile-labels page). Prior transparency reporting on the number of accounts/posts subject to visibility reduction is thin and not well-corroborated in located sources (flagged as a gap; one commercial checker site asserts X's "2024 transparency report" confirmed labels applied to "millions of accounts every month," but this is Tier C and should not be relied upon without the primary report).
Question 7: Comparative practice
- Meta / Llama Guard (Tier A): Meta open-sourced Llama Guard, an "input/output safety large language model based on the hazards taxonomy we developed with MLCommons," as 7B open-weights in December 2023, followed by Llama Guard 2 (8B, April 2024) and Llama Guard 3 (multilingual, July 2024 with Llama 3.1). But Llama Guard is a general developer safety tool, not the classifier Meta runs to moderate Facebook/Instagram; Meta does not publish the prompts/weights of its production content-moderation classifiers. Meta publishes aggregate Community Standards Enforcement Reports.
- Bluesky / Ozone (Tier A): Bluesky open-sourced Ozone, the actual labelling service its own moderators use, in March 2024, and allows third-party labellers to publish "stackable" moderation. This is the strongest real-world example of a platform releasing production moderation tooling, though Bluesky's moderation is rules/report-based rather than a large opaque classifier.
- Google/YouTube, TikTok (Tier B): Publish transparency reports and (TikTok) a research API and Commercial Content Library, but do not publish moderation classifier prompts or weights.
Assessment: Excluding the prompts of a production moderation classifier is normal industry practice; no major platform publishes the prompts or weights of its production moderation classifiers. What is unusual is X's simultaneous claim to be "setting a new standard for transparency" while doing what everyone else does. The gap is rhetorical, not exceptional in substance. Bluesky's Ozone is the strongest counter-example of a platform actually releasing production moderation tooling.
Question 8: The "mini model" question
Assessment: the mini Phoenix is a demonstration artifact, not the production model (Tier A/B). A model of the released size (~3GB, on the order of a few transformer layers and a few attention heads) is orders of magnitude smaller than any plausible production ranker serving a feed that, per X's own framing, processes 100M+ posts per day OpenTweet and narrows ~500M daily posts to ~1,500 candidates per user in under 1.5 seconds. OpenTweet xAI's own phoenix/README.md states the checkpoint is "a mini version of the Phoenix model... trained on the same real-time engagement data as the production system. Production uses a larger model with more layers and wider embeddings." Independent write-ups concur: TechTimes (18 May 2026) called the checkpoint "a compressed but architecturally faithful representation of the production ranking system," and Aihola noted bluntly "The production model is bigger. xAI doesn't say how much bigger."
Source conflict flagged (Tier B): the researcher's reading records the artifact as 256-dim, 4 attention heads, 2 transformer layers; the enricher surfaced a README quotation citing "128-dim, 4-layer." These may reflect different releases or a transcription difference. Verify the exact figures against the pinned commit before publishing.
Implication: releasing runnable code plus a toy checkpoint, but not the production weights, means independent parties cannot reproduce production ranking or verify that the public code matches production behaviour. That is meaningful architectural transparency but not meaningful outcome transparency. In fairness to X, releasing full production weights would be unprecedented and raises legitimate security, gaming and cost issues; no major platform has done it. The honest reading in both directions: real progress on inspectability, but the "new standard for transparency" claim overstates what a toy checkpoint delivers, and it directly undercuts Musk's own 2023 "acid test" that third parties should be able to determine "with reasonable accuracy, what will probably be shown to users."
Question 9: South African and Global South angle
- POPIA section 71 (Tier A): Restricts decisions "based solely on the automated processing" of personal information that have "legal consequences" for or "substantially affect" the data subject, where intended to profile. It mirrors GDPR Article 22, SciELO provides no explicit right to explanation, and turns on "solely automated" and "substantial/legal effect." Qut A visibility-reduction label on a post is unlikely to meet the "legal consequences / substantial effect" threshold, so section 71 almost certainly does not reach shadowbanning. There is no South African equivalent to DSA Article 27 (recommender transparency), Article 17 (statement of reasons) or Article 40 (researcher data access). URL: https://popia.co.za/section-71-automated-decision-making/.
- Information Regulator (Tier A): Enforces POPIA; OECD AI a draft National AI Policy (2026) references section 71 but does not define risk tiers Cliffe Dekker Hofmeyr or create recommender-transparency duties (Cliffe Dekker Hofmeyr commentary).
- Films and Publications Act as amended (Tier B): Addresses prohibited/harmful content classification and distribution, not algorithmic ranking transparency.
- Competition Commission Media and Digital Platforms Market Inquiry (Tier A): Initiated under section 43B(1)(a) of the Competition Act (launched October 2023), the final report was released 13 November 2025 after 24 months. It examined algorithmic distribution, Daily Maverick "zero-click" behaviour, and misinformation amplification across Google, Meta, TikTok, X, YouTube Daily Maverick , Microsoft and AI firms, finding that "social media algorithms also foster the spread of misinformation and disinformation by promoting sensationalist material over credible sources." It secured a R688 million media-support package agreed with Google and YouTube (aggregated over five years). But it is a competition/media-sustainability instrument, not an algorithmic-transparency regime; it creates no user right to know why a post was demoted. Notably, the provisional proposal to force Meta to change its "news-hostile algorithm" was dropped in the final report as "a non-starter." URL: https://www.compcom.co.za/media-and-digital-platforms-market-inquiry/.
Editorial finding: jurisdiction determines outcome (Tier A analysis). An EU user affected by RiskyHighVizReply has, in principle, an Article 17 right to a statement of reasons, a possible Article 40 route for researchers, and a regulator actively investigating X's recommender system. A South African user has none of these. The same code, the same label, the same account: the remedy exists or does not exist purely as a function of where the user sits. This is the strongest expression of the recurring #OnyxAudit theme.
Recommendations
Stage 1 - before publishing (immediate).
- Archive primary sources now: the EUR-Lex OJ text (Articles 15, 17, 24, 27, 40; Recitals 55, 66, 70, 97) at https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng; Commission press releases IP/24/3761 (https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3761) and IP/25/2934; the 2 July 2025 delegated-act page; the X Help Centre grey-checkmark and profile-labels pages; the @XOpenSource announcement; and the specific source files in
grox/flows/reply_spam/at a pinned commit hash (not the branch). - Verify Recital 97's exact wording and the full Article 40(5)(b) text against EUR-Lex before quoting.
- Confirm the source-code claims against the live repository at a pinned commit, screenshot and hash the files, and resolve the 256-dim vs 128-dim mini-Phoenix discrepancy, since the repository is updated on a stated cadence and content may change.
Stage 2 - framing the piece. Lead with the strongest, most defensible angle (below), not with a DSA-breach claim you cannot sustain. Be explicit that excluding the prompts is lawful under the DSA because the DSA never required them, and that the real story is the gap between X's "new standard for transparency" rhetoric and (a) the prompt exclusion, (b) the toy checkpoint, and © the hard-coded exemptions for high-PageRank and government (grey-badge) accounts.
Stage 3 - put questions to the three institutions (below); publish their answers or documented non-answers.
Strongest publishable angle: Not "X breaks the DSA," which the evidence does not support, but: "X invokes 'gameability' to withhold the prompts of an automated spam classifier while proclaiming a 'new standard for transparency' - yet the DSA contains no such exemption for user or public transparency, and the same system hard-codes a follower-count floor and exempts government and high-reputation accounts, so ordinary low-follower users are policed by rules the platform will not show them, and non-EU users have no right even to be told." That thesis is both novel (no prior coverage located) and fully supported.
Benchmarks that would change the analysis:
- If the Commission's recommender-system investigation issues preliminary findings touching automated-moderation transparency, the "unaddressed" conclusion on Question 2 shifts toward "contested/being tested."
- If any outlet publishes the reply-spam specifics before you, drop the "first" claim; keep monitoring.
- If xAI publishes production Phoenix size/architecture, revisit Question 8.
Questions to put to each institution
To the European Commission (DG Connect):
- Does the Commission consider that a VLOP withholding the prompt templates and thresholds of an automated coordinated-spam classifier is compatible with Articles 15(1)(e), 17 and 27, and does the Commission recognise "gameability" as a legitimate ground to limit any transparency disclosure outside Article 40(5)(b)?
- Does the ongoing recommender-system strand of the December 2023 proceeding (extended 26 January 2026) examine reply-visibility labels such as those applied to "risky high-visibility replies"?
- When a reply is assigned a score of 0.0 and a visibility-limiting safety label, does the Commission consider that an Article 17 statement of reasons is owed to the affected user?
To X / xAI:
- Why were the coordinated-spam prompt templates excluded, and under what specific policy or legal basis, given X's stated commitment to "a new standard for transparency"?
- What is the size and architecture of the production Phoenix model, and does the published code path match production behaviour bit-for-bit?
- Why are accounts with
high_page_rank_v2or a grey badge (government/multilateral) exempted from coordinated-spam enforcement, and does X applyRiskyHighVizReplylabels to EU users with an Article 17 statement of reasons? - How many accounts/posts received visibility-limiting labels in the last reporting period, and will this figure appear in the next DSA transparency report?
To the South African Information Regulator:
- Does the Regulator consider algorithmic visibility reduction (shadowbanning) by a platform to fall within POPIA section 71, and if not, does any South African law give a user a right to know why their content was demoted?
- Does the draft National AI Policy contemplate any recommender-system transparency or researcher-data-access obligation analogous to DSA Articles 27 and 40?
- Has the Regulator engaged with the Competition Commission's Media and Digital Platforms Market Inquiry findings on algorithmic amplification?
Caveats
- Source-code claims are taken as established per the researcher's own reading; this report did not independently re-read the repository. The lineage of
high_page_rank_v2from Tweepcred is a reasoned inference (Tier B), not a documented fact. - The full text of the 5 December 2025 X non-compliance decision was not located publicly; regulatory findings rest on Commission press releases (Tier A) and reputable secondary summaries (Tier B).
- The "no prior coverage" finding is bounded: it means no coverage was located in the searches conducted as of 14 August 2026, not that none exists anywhere. Web-search capacity was exhausted before two intended queries (detailed Twitter Files visibility-filtering material, and any direct reporting on
RiskyHighVizReply); running those specific terms would strengthen the negative finding. - A source conflict exists on the mini-Phoenix dimensions (256-dim/2-layer per the researcher's reading vs a 128-dim/4-layer README quotation); resolve against the pinned commit.
- Some results were commercial "grow on X" blogs and SEO pages of variable reliability; these were used only to corroborate widely-repeated facts and flagged Tier B/C where relied upon.
- Recital and article wording was cross-checked against faithful OJ mirrors and, for the central legal question, a dedicated primary-source review; all quotations should be confirmed against the canonical EUR-Lex OJ text before publication.