All documents · Legal

Legal / regulation challenge — 18 September 2026

Role. Adversarial legal/regulation challenger. This file is not legal advice. It flags landmines for a US-only SaaS pivot. Counsel must review before any public claim, ToS, or geo-policy ships.

Scope. /root/cryptobook-next/ideas/ was empty after polling (~3+ minutes). Verdicts therefore attack BRIEF candidate directions A–E. If later idea files appear, re-run this pass against their actual claims — marketing copy is what regulators read.

Kill list (instant KILL if the product as described does it). High-risk EU AI Act Annex III use; money transmission / holding customer funds / prepaid LLM wallets; CFAA / unauthorized third-party access; unauthorized practice of law; medical, credit, or HR decisioning; crypto tokens / securities; export-controlled quantum hardware or QPU-control software; “we make you compliant / certified”; storing or processing children’s data; US state privacy / ADMT landmines this VPS team cannot operationalize.


Sources actually fetched (18 Sep 2026)

EU AI Act — Annex III and transparency

Ninth Circuit CFAA — agents act for users (Aug/Sep 2026)

Money transmission basics

Other landmines we actually checked


Cross-cutting product rules (apply to every survivor)

These are not optional polish. They are the difference between FIX and KILL.

  1. US-only, 18+. Geo-restrict the EU/EEA/UK at the edge. Age gate. No child-directed design, no school accounts, no “classroom for kids.”
  2. Users bring their own LLM keys. We never take custody of fiat, crypto, or prepaid model credits to spend on a user’s behalf. Stripe (or similar) charges our SaaS fee only.
  3. Policy engine, not a browser agent. We answer allow / deny / ask. We do not log into Gmail, Amazon, GitHub (except OAuth the user grants to their repo for a yaml file), banks, or any third-party site. We do not scrape. If we must see a tool call, the user’s runtime sends us a description and we return a decision — our servers do not “enter” the third-party system (Perplexity architecture, not Power Ventures).
  4. No decisioning of natural persons for jobs, credit, insurance, housing, education access, benefits, healthcare, or emergency dispatch (Annex III pts 3–5; FCRA; CA/CO/CT ADMT).
  5. No legal, medical, or HR advice. UI copy: “Not legal advice. Not a compliance certification. Not an auditor.” English rules are the user’s policy, not our opinion of the law.
  6. No “AI Act / SOC 2 / HIPAA / ISO certified by us” claims. Disclose AI use in the playground (Art. 50(1) hygiene even for a US-only site). Do not CE-mark, do not sell “conformity packs.”
  7. No tokens. Receipts are JSON + signature, not an asset.
  8. Honest FTC posture. No fake social proof, no accuracy percentages we cannot substantiate, no “100% secure.”

Verdicts

A. Permit gateway for agent tools / MCP

Verdict: FIX (survives only if the patches below are in the product, not the slide)

English allow/deny/ask rules, spend cap on the user’s own keys, signed shareable receipts, one URL drop-in, explicitly not enterprise GRC.

Landmine Why it is not an automatic KILL How it still dies
Money transmission A cap on the user’s OpenAI/Anthropic key is a rate-limit, not acceptance-and-transmission of value. SaaS fee ≠ stored value. § 1010.100(ff)(5); FIN-2013-G001. We sell “$20 of GPT,” hold a balance, and spend it for them. That is a prepaid wallet / transmitter. Instant KILL.
CFAA A decision API the user’s agent calls is not “entering” a third-party computer. Perplexity, 26-1444, user-not-developer if we never talk to the third party. Hosted MCP that holds GitHub/Slack/Stripe tokens and calls those APIs from 173.249.19.205 is the Power Ventures fact pattern the Ninth Circuit left open. KILL that architecture.
Annex III Tool-permission policy is not biometrics, hiring, credit, education admissions, LE, or justice. Intended purpose test (Art. 6(2) + Commission May 2026 guidelines). Market it as “employment agent oversight” that scores workers, or as credit/spend underwriting of people. Then pt 4 or 5(b).
UPL / fake compliance Software that enforces the user’s English is a tool. Copy that says “AI Act compliant,” “SOC 2 ready,” “this receipt proves you met the law.” FTC § 5 + UPL.
Children / state privacy B2B, 18+, no sensitive-decision ADMT. API keys and policy text are customer data; CCPA only if we hit thresholds — operational, not a product kill. Public playground that logs chats from minors. COPPA (actual knowledge or child-directed).
Art. 50 Playground chatbot must disclose it is AI. Cheap. Pretend the bot is a human reviewer.

Required FIX (non-negotiable):

If those land, this is the least-dirty BRIEF candidate. It is still FIX, not a clean SURVIVE, because one bad proxy feature reopens CFAA and one “credits” SKU reopens FinCEN.


B. Repo agent-permit.yaml runtime (Dependabot-like)

Verdict: FIX (same family as A; slightly cleaner CFAA, slightly worse “compliance product” temptation)

Hosted enforcement of a yaml file in the user’s repo. Viral install. Not a GRC suite.

Survives if: we read a file the user granted via OAuth (authorized access to their repo), compile it to the same allow/deny engine as A, and never browse the rest of the internet as the user.

Kills if:

Required FIX: OAuth least-privilege (contents:read on one file), public-repo option with no private-data retention, no badge-as-certification, same US/18+/no-legal-advice chrome as A. Dependabot-like virality is a distribution trick, not a new legal class.

Treat A and B as one product with two install paths (URL gateway vs repo yaml). Do not ship two compliance stories.


C. Freelance / client agent receipts — “prove an agent did work”

Verdict: FIX, with a short leash. Default-narrow. One extra feature and it is KILL.

A signed log that an agent called tools X, Y, Z under policy P, at time T, on the freelancer’s own keys, can be ordinary software (like a build log). Courts take documents; selling a log is not UPL by itself.

KILL variants (do not ship):

  1. Escrow / “client pays when the receipt verifies.” We would accept funds from the client and transmit to the freelancer. That is money transmission under § 1010.100(ff)(5) from transaction one, plus ~49 state MTLs. No “we’re just a marketplace” story saves an unlicensed principal that holds the money. Payment-processor exemption needs a BSA clearing system and an agreement with the seller of goods/services — and even then, state law may still bite. Do not hold the fee.
  2. Quality / “hire-worthiness” score of the freelancer or the agent. Annex III pt 4(a)–(b) (recruitment, performance). FCRA consumer-report risk. CA ADMT “significant decision” (employment / independent contracting) from 1 Jan 2027. We cannot run that program.
  3. Warranty copy: “cryptographically proves the work was done / is court-admissible / satisfies the SOW.” That is a legal conclusion. FTC substantiation + UPL-adjacent. Receipts may be used as evidence; we must not opine they are sufficient.
  4. Tokenized receipts / points. Howey + stored-value. No.

Required FIX: receipt = signed JSON of policy inputs/outputs the user already owns. Client and freelancer settle off-platform. No ranking. Disclaimer on every share link. If the idea stays “too narrow” commercially, that is a market problem, not a reason to add escrow.


D. Quantum circuit classroom

Verdict: KILL

BRIEF already flags demand/monetization. Legal independently kills the classroom framing.

  1. Annex III pt 3 — education. High-risk if intended to (a) determine access/admission, (b) evaluate learning outcomes (including to steer the learning process), (c) assess the appropriate education level, or (d) monitor prohibited behaviour during tests. A “classroom” with quizzes, levels, or proctoring is (b)/(c)/(d) on its face. Commission guidelines: intended purpose, not the simulator backend. Art. 6(3) “narrow procedural task” is a documented exception, not a slogan.
  2. Children. “Classroom” invites K–12. COPPA (under 13, actual knowledge or child-directed) plus California AB 2246 / SB 1119 / SB 867 (2026). We will not implement verifiable parental consent, retention limits, or chatbot-audit duties for minors. Children’s data is an instant kill.
  3. Export / false hardware. A classical circuit visualizer with no QPU, no pulse-control, no “we have 34+ qubits,” and no 4D906-class control software can be EAR99/published. The moment copy says “quantum computer,” “run on real hardware,” or we wrap IBM/IonQ credentials and re-sell QPU time, we eat (i) BIS 4A906/4D906, (ii) cloud-vendor ToS, (iii) FTC capability claims. This VPS has no quantum hardware (BRIEF). Do not claim it.
  4. Even the patched 18+ lab is a demand kill, which this legal pass does not need to relitigate. If someone later proposes a non-evaluative, 18+, classical, no-hardware-claim sandbox, re-score it as FIX. The BRIEF candidate as written is KILL.

E. “Anything more specific and more genius”

Verdict: no idea file existed. Placeholder = KILL until specified.

Any later E-idea is auto-KILL if it: scrapes/logs into third parties; holds funds or API-credit balances; issues tokens; decisions humans (hire/fire/credit/school/health); processes kids; claims certification; ships export-controlled quantum stacks; or practices law/medicine. Otherwise re-score.


Patched survivor (if PM needs one product that is not dead)

BRIEF: if everything is killed, invent a patch. A/B are FIX, not KILL. The legally cleanest merge:

PermitGate — MCP/tool policy runtime (US, 18+, BYOK)

What it is. A single HTTPS endpoint plus an optional agent-permit.yaml. The user’s local or self-hosted agent sends a tool-call descriptor. We return allow / deny / ask, enforce a numeric cap on the user’s own key, and emit a signed receipt the user can share. Homepage playground: paste a rule in English, fire a fake stripe.refunds.create, see allow/deny in <60 seconds. We never execute the tool.

Why the kill list does not fire (if we keep our hands clean):

Kill item Why this patch survives
Annex III high-risk Intended purpose is authorization of software tools, not pts 1–8. No biometrics, hiring, credit, education access, LE, justice. Do not market into those.
Money transmission No acceptance-and-transmission of value. BYOK. SaaS subscription only. § 1010.100(ff)(5); FIN-2013-G001 user vs exchanger.
CFAA We do not access third-party computers. User’s runtime does. Amazon v. Perplexity, 26-1444 (user, not developer; tool not a person; no vendor-to-site TCP).
UPL We enforce their English. We do not apply law to facts. Persistent “not legal advice / not a certification.”
Medical / credit / HR Out of scope in ToS; refuse those templates in the playground.
Crypto securities No token. Receipt is a signature over a log.
Quantum export Out of product.
Compliance certification Forbidden copy. FTC § 5.
Children’s data 18+ age gate; not child-directed; no school SKU. COPPA actual-knowledge + CA 2026 kids/chatbot bills.
State ADMT We do not make “significant decisions” about consumers. Policy decisions about tools.

Residual risk (not KILL, must be owned):

This is still not a legal opinion that the product is “compliant.” It is a challenger’s statement that the shape does not trip the BRIEF instant-kill list.


Scoreboard

ID Idea Verdict One-line why
A MCP/tool permit gateway FIX Legal if BYOK + decision-only + no cert claims; dies if it becomes a hosted agent or prepaid wallet
B agent-permit.yaml runtime FIX Same product as A, different install; no compliance badges
C Freelance agent receipts FIX Logs only; escrow/scores/tokens = KILL
D Quantum circuit classroom KILL Annex III education + children + hardware/export/false-claim stack
E Unspecified KILL until written Empty ideas dir
Patch PermitGate (A∩B, patched) SURVIVE (conditional) Only the merged, decision-only, US/18+/BYOK, no-certification form

Do not ship D. Do not add payments to C. Do not let A/B grow a browser. PM should pick patched A/B (PermitGate) or kill the pivot.

Not legal advice. Sources are those fetched on 18 September 2026 as listed above.