Onyx Digital Intelligence.

X's Reply-spam it's limited, you deserve to know why.

"Open Source" Transparency: A Regulatory Analysis (#OnyxAudit)

Prepared 14 August 2026. Evidentiary tiers: Tier A = verified against a primary source (regulation text, official regulator document, court/company statement, or the source code itself); Tier B = single credible secondary source or reasoned inference, labelled as such; Tier C = speculation, marked. UK English throughout.

TL;DR

Key Findings

  1. DSA transparency obligations are real and specific, but scoped. Article 27 requires only the "main parameters" and "most significant" criteria of recommender systems, not every parameter or the full algorithm. Article 17 unambiguously treats visibility reduction, demotion and "shadow banning" as restrictions that require a statement of reasons. Article 15(1)(e) requires a "qualitative description" plus accuracy and error-rate indicators for automated moderation, not source code.

  2. The central legal question resolves against X's framing but not cleanly. The gameability exclusion is neither expressly permitted nor expressly prohibited for moderation transparency. It is "unaddressed" because the DSA never requires the withheld detail in the first place. The one textual circumvention/security carve-out (Article 40(5)(b)) sits in the researcher-data-access regime.

  3. The Commission has already fined X and is still investigating recommender systems. On 5 December 2025 the Commission imposed its first-ever DSA non-compliance fine of €120 million (Articles 25, 39, 40(12)). A separate December 2023 proceeding remains open and was extended on 26 January 2026 to examine recommender-system risk management. Digital Policy Alert eucrim

  4. No prior coverage of the reply-spam specifics was located. Reporting on the 2023, January/May 2026, and 13 August 2026 releases is extensive but generic. The grox reply-spam pipeline details appear in no located reporting.

  5. Terminology traces to documented X concepts. Grey badge = government/multilateral accounts; high_page_rank_v2 plausibly descends from 2023's Tweepcred (inference); Strato is X internal infrastructure; "visibility filtering"/"VF" is documented from 2018 and the 2022 Twitter Files.

  6. South African users have no DSA equivalent. POPIA section 71 covers automated decisions with legal/material effect only; there is no Article 27 or Article 40 analogue. Jurisdiction, not user choice, determines the remedy.

Details

Question 1: EU DSA obligations for VLOPs

X (Twitter International Unlimited Company) has been a designated VLOP since April 2023. Goodwin The canonical regulation text is Regulation (EU) 2022/2065, at https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng.

(a) Article 27 recommender transparency (Tier A). Article 27(1) requires providers to set out "in plain and intelligible language, the main parameters used in their recommender systems, as well as any options for the recipients of the service to modify or influence those main parameters." Socialmediatransparency Article 27(2): the main parameters "shall include, at least: (a) the criteria which are most significant in determining the information suggested to the recipient of the service; (b) the reasons for the relative importance of those parameters." Digital Services Act Socialmediatransparency Recital 70 clarifies these "should include at least the most important criteria in determining the information suggested to the recipient of the service and the reasons for their respective importance." Freshfields' analysis notes Article 27 "does not require platforms to provide information on each and every parameter used or provide information on how individual parameters are weighted." The scope is deliberately high-level. URL: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_27.html.

(b) Article 17 statements of reasons (Tier A). Article 17(1) requires "a clear and specific statement of reasons" for "any restrictions of the visibility of specific items of information ... including removal of content, disabling access to content, or demoting content." Recital 55 is explicit: "Restriction of visibility may consist in demotion in ranking or in recommender systems, as well as in limiting accessibility by one or more recipients of the service or blocking the user from an online community without the user being aware ('shadow banning')." So visibility reduction and demotion plainly count as restrictions requiring a statement of reasons. Article 17(3)© requires "where applicable, information on the use made of automated means in taking the decision, including information on whether the decision was taken in respect of content detected or identified using automated means." Crucially this is an existence disclosure (that automated means were used), not a requirement to disclose how the classifier works. The only carve-out is "deceptive high-volume commercial content" (Article 17(1); Recital 55). URL: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_17.html.

© Article 24(5) and the Transparency Database (Tier A). Article 24(5) requires platforms to submit their statements of reasons to the Commission's DSA Transparency Database "without undue delay," in a standard, machine-readable format (Recital 66). Since visibility reduction and demotion are Article 17 restrictions, reduced-visibility decisions in principle must be submitted. Database and FAQ: https://transparency.dsa.ec.europa.eu and https://digital-strategy.ec.europa.eu/en/faqs/dsa-transparency-database-questions-and-answers.

(d) Article 40 researcher data access (Tier A). Article 40(4) grants vetted researchers access to data to study systemic risks; Article 40(12) covers public data access. Policy Review On 2 July 2025 the Commission adopted the delegated act laying down procedures and technical conditions European Commission and is launching the DSA Data Access Portal (https://digital-strategy.ec.europa.eu/en/news/commission-adopts-delegated-act-data-access-under-digital-services-act). Article 40(5)(b) lets a platform request amendment of a request where access "will lead to significant vulnerabilities in the security of their service or the protection of confidential information, in particular trade secrets," Policy Review but Recital 97 limits this: commercial interests "should not lead to a refusal to provide access to data necessary for the specific research objective." Article 40(3) requires platforms to explain "the design, the logic, the functioning and the testing of their algorithmic systems, including their recommender systems" to regulators. URL: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_40.html.

(e) Articles 34-35 systemic risk (Tier A/B). Articles 34 and 35 require VLOPs to assess and mitigate systemic risks stemming from the design and operation of their services, expressly including recommender systems and content-moderation systems. This is the hook under which the Commission's recommender-system investigation of X proceeds.

(f) Articles 15 and 42 transparency reporting (Tier A). Article 15(1)(e) requires reporting of "any use made of automated means for the purpose of content moderation, including a qualitative description, a specification of the precise purposes, indicators of the accuracy and the possible rate of error of the automated means used ... and any safeguards applied." Digital Services Act Article 42 tightens this to six-monthly for VLOPs and adds human-resources and linguistic-expertise reporting; Lexology Article 42(2)© requires accuracy indicators "broken down by each official language." The DSA Observatory noted (8 January 2026) that Article 15(1)(e) "indicators of accuracy" disclosures so far are "essentially meaningless." URLs: https://www.eu-digital-services-act.com/Digital_Services_Act_Article_15.html and .../Digital_Services_Act_Article_42.html.

Conclusion: unaddressed, and therefore not a recognised lawful defence for user-facing or public transparency (Tier A analysis). There is no provision in the DSA (Articles 15, 17, 24, 27), no recital, and no located Commission guidance or decision, that expressly permits withholding automated-moderation detail from users or the public on the ground that disclosure would enable gaming or circumvention. The obligations are scoped so that fine-grained classifier internals are never demanded in the first place: Article 17(3)© requires existence-only disclosure; Article 27(2) requires only "main"/"most significant" parameters; Socialmediatransparency Article 15(1)(e) requires only a "qualitative description." Consequently, X's stated rationale for excluding the prompt templates is best characterised as unaddressed under the transparency regime rather than sanctioned by it.

The one textual anchor for a circumvention/security-vulnerability defence is Article 40(5)(b), read with Recital 97, and it lives only in the researcher/regulator data-access channel. It cannot be assumed to transfer to Article 17 or Article 27 duties. A widely-cited secondary summary (dsa-library.com) asserts that "technical details protecting security can be withheld" under Article 15, but this cannot be traced to operative DSA text and should be treated as commentary (Tier C), not authority.

The practical upshot: excluding the prompts does not by itself breach the DSA, because the DSA never required the prompts. But X cannot rely on a DSA "gameability" exemption to justify the exclusion, because none exists for transparency duties. X's own framing ("we are committed to setting a new standard for transparency") is a voluntary standard, and the gap between the voluntary claim and the exclusion is an editorial and accountability point, not a statutory breach. This is the sharpest, most defensible line for the piece.

Question 3: Commission proceedings against X

None of the concluded findings concern the gameability of automated moderation. The recommender-system strand is live and unresolved as at August 2026. The full non-compliance decision document was not located publicly; findings rest on the Commission press release and reputable summaries (Goodwin, IAPP, eucrim, TechPolicy.Press).

Question 4: Prior reporting and prior releases

2023 release (twitter/the-algorithm), 31 March 2023 (Tier A/B). Twitter open-sourced much of the For You ranking code Gupta Deepak but excluded training data, model weights, and trust-and-safety code, explicitly to reduce gaming by bad actors. Researchers found the Tweepcred PageRank reputation score (0-100), Steventey which reduces rank for accounts with many followings but few followers; a documented Twitter Blue boost (per the 2023 README as documented by Steve Tey and the Knight First Amendment Institute, Blue subscribers receive "a 4x boost in the algorithm if you're in the same network as the author of the tweet, and a 2x boost if you're not" - the Knight Institute cautions this is a score multiplier, not a literal reach multiplier); and code flags identifying whether a tweet author was Elon Musk or whether an account was Democrat/Republican (widely reported as for testing/monitoring). arxiv A December 2025 arXiv study ("Rabble-Rousers in the New King's Court") confirms "the algorithm's code contained identifying flags for whether a user was a Democrat or Republican, or even for whether a tweet was authored by Elon Musk." The repository went largely dormant afterwards. Musk's stated "acid test" (31 March 2023): "independent third parties should be able to determine, with reasonable accuracy, what will probably be shown to users."

January/May 2026 release (xai-org/x-algorithm) (Tier B). A Rust/Python rewrite (roughly 63% Rust). The 15 May 2026 update shipped a runnable end-to-end pipeline (phoenix/run_pipeline.py) and the "mini Phoenix" checkpoint. It was received as a genuine step beyond 2023 but still criticised because production weights remain proprietary; xAI redacted numerical engagement weights in January 2026 citing security. Tech Times One Yahoo/Tech report noted the repo sat at a single commit four months after the open-source promise, before the May update.

13 August 2026 release (Tier A/B). Per the @XOpenSource announcement (https://x.com/XOpenSource/status/2087951962004230428): "We're open-sourcing the code that affects a post's visibility in the For You timeline, and releasing a new tool that shows people labels applied to their account or posts that might limit visibility." The "Under the Hood" tool lets accounts that posted 10+ times in the prior month download a JSON of labels applied, initially to a randomised test group of accounts at least one year old. Reporting is broad: TechCrunch (13 August), TechBriefly, Dataconomy, BigGo, WERSM and others. Coverage is generic. BigGo noted: "Some systems remain closed, including those using Grok for rule-violation prediction, to prevent gaming." X VP of Product Keith Coleman told TechCrunch: "You'll get the core ranking code that pulls posts and ranks them for any given user and assembles the feed."

Documented negative finding (Tier A as to absence). In the sources located, no reporting covers the grox/flows/reply_spam/ pipeline specifics: the CoordinatedSpamScorer, the TaskCoordinatedSpamFilter, FOLLOWER_COUNT_THRESHOLD_FOR_SPAM_DETECTION = 1000 / low_blast_radius, the one_level_deep gate, the high_page_rank_or_grey_badge exemption, or SafetyLabelType.RiskyHighVizReply. General-audience "how to grow on X" posts (OpenTweet, Postory, note.com/jmworks) discuss a Grox spam classifier "for people with few followers" in passing, but none surface the follower threshold, the PageRank/grey-badge exemption, the two-levels-deep gate, or the specific safety label. The researcher is very likely first on these particulars. Frame this as "no prior coverage located as of 14 August 2026," not as proof of universal absence.

Question 5: Terminology

Question 6: Freedom of reach and prior statements

Question 7: Comparative practice

Assessment: Excluding the prompts of a production moderation classifier is normal industry practice; no major platform publishes the prompts or weights of its production moderation classifiers. What is unusual is X's simultaneous claim to be "setting a new standard for transparency" while doing what everyone else does. The gap is rhetorical, not exceptional in substance. Bluesky's Ozone is the strongest counter-example of a platform actually releasing production moderation tooling.

Question 8: The "mini model" question

Assessment: the mini Phoenix is a demonstration artifact, not the production model (Tier A/B). A model of the released size (~3GB, on the order of a few transformer layers and a few attention heads) is orders of magnitude smaller than any plausible production ranker serving a feed that, per X's own framing, processes 100M+ posts per day OpenTweet and narrows ~500M daily posts to ~1,500 candidates per user in under 1.5 seconds. OpenTweet xAI's own phoenix/README.md states the checkpoint is "a mini version of the Phoenix model... trained on the same real-time engagement data as the production system. Production uses a larger model with more layers and wider embeddings." Independent write-ups concur: TechTimes (18 May 2026) called the checkpoint "a compressed but architecturally faithful representation of the production ranking system," and Aihola noted bluntly "The production model is bigger. xAI doesn't say how much bigger."

Source conflict flagged (Tier B): the researcher's reading records the artifact as 256-dim, 4 attention heads, 2 transformer layers; the enricher surfaced a README quotation citing "128-dim, 4-layer." These may reflect different releases or a transcription difference. Verify the exact figures against the pinned commit before publishing.

Implication: releasing runnable code plus a toy checkpoint, but not the production weights, means independent parties cannot reproduce production ranking or verify that the public code matches production behaviour. That is meaningful architectural transparency but not meaningful outcome transparency. In fairness to X, releasing full production weights would be unprecedented and raises legitimate security, gaming and cost issues; no major platform has done it. The honest reading in both directions: real progress on inspectability, but the "new standard for transparency" claim overstates what a toy checkpoint delivers, and it directly undercuts Musk's own 2023 "acid test" that third parties should be able to determine "with reasonable accuracy, what will probably be shown to users."

Question 9: South African and Global South angle

Editorial finding: jurisdiction determines outcome (Tier A analysis). An EU user affected by RiskyHighVizReply has, in principle, an Article 17 right to a statement of reasons, a possible Article 40 route for researchers, and a regulator actively investigating X's recommender system. A South African user has none of these. The same code, the same label, the same account: the remedy exists or does not exist purely as a function of where the user sits. This is the strongest expression of the recurring #OnyxAudit theme.

Recommendations

Stage 1 - before publishing (immediate).

  1. Archive primary sources now: the EUR-Lex OJ text (Articles 15, 17, 24, 27, 40; Recitals 55, 66, 70, 97) at https://eur-lex.europa.eu/eli/reg/2022/2065/oj/eng; Commission press releases IP/24/3761 (https://ec.europa.eu/commission/presscorner/detail/en/ip_24_3761) and IP/25/2934; the 2 July 2025 delegated-act page; the X Help Centre grey-checkmark and profile-labels pages; the @XOpenSource announcement; and the specific source files in grox/flows/reply_spam/ at a pinned commit hash (not the branch).
  2. Verify Recital 97's exact wording and the full Article 40(5)(b) text against EUR-Lex before quoting.
  3. Confirm the source-code claims against the live repository at a pinned commit, screenshot and hash the files, and resolve the 256-dim vs 128-dim mini-Phoenix discrepancy, since the repository is updated on a stated cadence and content may change.

Stage 2 - framing the piece. Lead with the strongest, most defensible angle (below), not with a DSA-breach claim you cannot sustain. Be explicit that excluding the prompts is lawful under the DSA because the DSA never required them, and that the real story is the gap between X's "new standard for transparency" rhetoric and (a) the prompt exclusion, (b) the toy checkpoint, and © the hard-coded exemptions for high-PageRank and government (grey-badge) accounts.

Stage 3 - put questions to the three institutions (below); publish their answers or documented non-answers.

Strongest publishable angle: Not "X breaks the DSA," which the evidence does not support, but: "X invokes 'gameability' to withhold the prompts of an automated spam classifier while proclaiming a 'new standard for transparency' - yet the DSA contains no such exemption for user or public transparency, and the same system hard-codes a follower-count floor and exempts government and high-reputation accounts, so ordinary low-follower users are policed by rules the platform will not show them, and non-EU users have no right even to be told." That thesis is both novel (no prior coverage located) and fully supported.

Benchmarks that would change the analysis:

Questions to put to each institution

To the European Commission (DG Connect):

  1. Does the Commission consider that a VLOP withholding the prompt templates and thresholds of an automated coordinated-spam classifier is compatible with Articles 15(1)(e), 17 and 27, and does the Commission recognise "gameability" as a legitimate ground to limit any transparency disclosure outside Article 40(5)(b)?
  2. Does the ongoing recommender-system strand of the December 2023 proceeding (extended 26 January 2026) examine reply-visibility labels such as those applied to "risky high-visibility replies"?
  3. When a reply is assigned a score of 0.0 and a visibility-limiting safety label, does the Commission consider that an Article 17 statement of reasons is owed to the affected user?

To X / xAI:

  1. Why were the coordinated-spam prompt templates excluded, and under what specific policy or legal basis, given X's stated commitment to "a new standard for transparency"?
  2. What is the size and architecture of the production Phoenix model, and does the published code path match production behaviour bit-for-bit?
  3. Why are accounts with high_page_rank_v2 or a grey badge (government/multilateral) exempted from coordinated-spam enforcement, and does X apply RiskyHighVizReply labels to EU users with an Article 17 statement of reasons?
  4. How many accounts/posts received visibility-limiting labels in the last reporting period, and will this figure appear in the next DSA transparency report?

To the South African Information Regulator:

  1. Does the Regulator consider algorithmic visibility reduction (shadowbanning) by a platform to fall within POPIA section 71, and if not, does any South African law give a user a right to know why their content was demoted?
  2. Does the draft National AI Policy contemplate any recommender-system transparency or researcher-data-access obligation analogous to DSA Articles 27 and 40?
  3. Has the Regulator engaged with the Competition Commission's Media and Digital Platforms Market Inquiry findings on algorithmic amplification?

Caveats