# Eve jurisdiction, applicability, and human-oversight record

Reviewed: 2026-09-15

Owner task: 14.6

This is an engineering governance record, not legal advice or a claim of legal
compliance. It separates three things that must not be conflated:

1. official law or regulator material;
2. deployment-specific decisions owned by counsel and product operators; and
3. software controls and tests that show what the repository does.

Engineering evidence may prove a confirmation, disclosure, appeal, handoff, or
kill switch. It cannot decide that a law applies, that a reviewer is legally
meaningful, or that the product complies with a jurisdiction's law.

## Current launch boundary

- The repository does not establish Eve's current customer, establishment, or
  impact territories. A territory not named in the record is not admitted by
  inference.
- Eve is admitted here only as an assistive copilot. A person retains authority
  to use, edit, reject, confirm, appeal, stop, or escalate the output.
- Solely automated legal or similarly significant decisions are not admitted.
  Eve may not determine employment, housing, education, credit, insurance,
  healthcare access, or essential-service eligibility.
- Minor-directed conversational service is not admitted. The record does not
  pretend that age assurance, minor safeguards, or a counsel review exists.
- Public generated-media release remains within Task 14.7; attachment and
  generated-artifact lifecycle remains within Task 14.8.

An unresolved legal question fails closed for the affected use. Reopening needs
the exact counsel and operator record named in the machine-readable record.

## Official-source applicability register

| Row                  | Official source                                                                                                                                                                                                    | Engineering posture; legal decision remains counsel-owned                                                                                                                                                                                                             |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| EU AI Act            | [Regulation (EU) 2024/1689](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng) and the [Commission implementation timeline](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)            | Apply AI-interaction disclosure conservatively. Do not infer provider/deployer role, high-risk classification, or territorial scope. Track Article 50 as active and the extended Annex III date without treating the future date as an exemption from current duties. |
| EU GDPR              | [Regulation (EU) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)                                                                                                                                      | No Article 22, controller/processor, lawful-basis, DPIA, or territorial conclusion is made. Significant solely automated decisions remain unadmitted.                                                                                                                 |
| United Kingdom       | [ICO automated decision-making guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/rights-related-to-automated-decision-making-including-profiling/) | The ICO says this guidance is under review after the Data (Use and Access) Act 2025. The record therefore blocks solely automated significant decisions and requires a fresh UK counsel decision against final guidance.                                              |
| California           | [CPPA final ADMT rulemaking](https://cppa.ca.gov/regulations/ccpa_updates.html)                                                                                                                                    | The final regulations are tracked as effective 2026-01-01, with significant-decision ADMT compliance beginning 2027-01-01. Covered-business and use-case applicability are not engineering conclusions.                                                               |
| Colorado             | [Attorney General ADMT and Chatbot Safety rulemaking](https://coag.gov/ai/)                                                                                                                                        | The reenacted ADMT law and Chatbot Safety Act are tracked for 2027-01-01. On the review date, implementing rules remained proposed. Consequential and minor-directed uses stay blocked pending final rules and counsel review.                                        |
| Engineering baseline | [NIST AI RMF Core](https://airc.nist.gov/airmf-resources/airmf/5-sec-core/)                                                                                                                                        | NIST is used as a voluntary oversight baseline. It is not law and is never cited as proof of compliance.                                                                                                                                                              |

`other-territories` is an explicit row, not an omission: production launch is
not admitted until a product operator identifies the territory and counsel
records applicable law, prohibited uses, required disclosures, oversight,
rights, and evidence.

## Human authority by use

| Use                                            | Disposition                                    | Meaningful human authority                                                                                                   |
| ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| Conversation and drafting                      | Admitted with AI disclosure                    | The member decides whether to rely on, edit, or discard the response.                                                        |
| Member-requested mutation                      | Explicit confirmation required                 | The model cannot dispatch the action; the authenticated member confirms or declines the exact pending effect.                |
| Operator workbench delivery                    | Human acceptance, verification, and activation | Only current human-accepted decisions authorize delivery; conflicting decisions stop it.                                     |
| Trust-and-safety moderation                    | Human review and appeal                        | An independent reviewer may overturn appealable outcomes; permanent bans require two reviewers.                              |
| Legal, clinical, financial, or crisis judgment | Human handoff only                             | Legal and clinical questions defer to qualified humans; crisis paths route to human services.                                |
| Consequential eligibility or access            | Blocked                                        | No model recommendation may become the decision or materially determine the outcome.                                         |
| Minor-directed chatbot                         | Blocked                                        | Age/safety design, accountable operations, final rules, and counsel review are prerequisites.                                |
| Customer-facing generated media                | Task 14.7 boundary                             | Human release review remains necessary where a release trigger fires; rights and disclosure completion are not claimed here. |

## Bound controls and evidence limits

- The web disclosure copy explicitly says the response comes from an AI
  assistant, not a human operator.
- The BFF action bridge parks mutations until the exact authenticated member
  confirms. Decline and expiry have no side effect.
- The workbench rejects decisions that are not current and human-accepted; a
  current conflict stops delivery.
- Persona handoff invariants route legal deferral to human counsel and clinical
  deferral to a human clinician.
- Trust-and-safety decisions have appeal state and independent second-reviewer
  checks; this is not claimed as a universal appeal mechanism for unrelated
  product decisions.
- The media release gate treats review as a separate state rather than dispatch
  permission.
- The fleet halt is checked before queue acquisition. It does not revoke an
  already completed external provider effect or stand in for provider-specific
  emergency controls.

The JSON record binds every statement above to exact source tokens. Its verifier
also rejects missing jurisdictions, drifted official URLs, unowned questions,
admitted significant or minor-directed use, token human review, missing appeal,
permissive pending-counsel defaults, and removed limitations.

## Ownership and refresh

Privacy counsel owns legal applicability. The territory product operator owns
the factual deployment assertion and launch decision. Engineering owns the
accuracy of control mappings and evidence. Review is required at least every 90
days and immediately on any new territory, population, consequential domain,
material capability, autonomous effect, law/guidance change, or material control
change.

## Exact limitations

- No person is represented as counsel and no counsel signature is fabricated.
- Deployment territory is not attested by the repository.
- Source-bound controls do not prove that every reviewer is competent,
  independent, timely, or free from automation bias.
- The legal source set is time-sensitive as of 2026-09-15.
- Task 14.7 owns media rights and public-release governance; Task 14.8 owns the
  complete attachment and generated-artifact lifecycle.

The normative machine-readable record is
[`eve-sota-jurisdiction-human-oversight/2026-09-15.json`](eve-sota-jurisdiction-human-oversight/2026-09-15.json).
