Legal / regulation challenge — 18 September 2026
Role. Adversarial legal/regulation challenger. This file is not legal advice. It flags landmines for a US-only SaaS pivot. Counsel must review before any public claim, ToS, or geo-policy ships.
Scope. /root/cryptobook-next/ideas/ was empty after polling (~3+ minutes). Verdicts therefore attack BRIEF candidate directions A–E. If later idea files appear, re-run this pass against their actual claims — marketing copy is what regulators read.
Kill list (instant KILL if the product as described does it). High-risk EU AI Act Annex III use; money transmission / holding customer funds / prepaid LLM wallets; CFAA / unauthorized third-party access; unauthorized practice of law; medical, credit, or HR decisioning; crypto tokens / securities; export-controlled quantum hardware or QPU-control software; “we make you compliant / certified”; storing or processing children’s data; US state privacy / ADMT landmines this VPS team cannot operationalize.
Sources actually fetched (18 Sep 2026)
EU AI Act — Annex III and transparency
- Official Annex III text (Regulation (EU) 2024/1689), reproduced at Praxikon / Annex III (“text reproduced verbatim” from EUR-Lex). Eight areas: (1) biometrics, (2) critical infrastructure, (3) education and vocational training, (4) employment / workers’ management, (5) essential private/public services (credit, insurance, benefits, emergency dispatch), (6) law enforcement, (7) migration/asylum/borders, (8) administration of justice and democratic processes.
- Commission draft guidelines on high-risk classification, 19 May 2026: digital-strategy.ec.europa.eu. High-risk if (i) Annex I product/safety-component + third-party CA, or (ii) an Annex III use case. Classification turns on intended purpose, not the underlying model.
- Timeline: Annex III standalone duties deferred to 2 December 2027 by the 2026 Digital Omnibus (Regulation (EU) 2026/1744; Commission AI Act page, updated Sep 2026: digital-strategy.ec.europa.eu/policies/regulatory-framework-ai). That is not a free pass to build high-risk systems now.
- Article 50 transparency already applies from 2 August 2026. Text: artificialintelligenceact.eu/article/50. Art. 50(1): providers of systems intended to interact directly with natural persons must inform them they are interacting with AI unless obvious. Art. 50(2): machine-readable marking of synthetic audio/image/video/text. Commission FAQ, 18 Sep 2026: digital-strategy.ec.europa.eu/faqs/transparency-obligations-under-article-50-ai-act. Chatbots, agents, playgrounds are in 50(1) even if not high-risk.
- Territorial trap: US-only intent does not automatically kill EU exposure if the product is placed on the EU market or its output is used in the Union. Geo-block + ToS + no EU marketing is the operational patch, not a legal opinion.
Ninth Circuit CFAA — agents act for users (Aug/Sep 2026)
- Opinion: Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026) (Smith, J.), official PDF: cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf.
- Holding (access, not authorization): “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” “It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.” Perplexity’s servers did not directly communicate with Amazon’s servers; the user’s browser did. Panel vacated the CFAA/CDAFA preliminary injunction.
- Explicit limits (opinion at 17): “We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability… Our holding here is limited to ‘access’ as contemplated by the CFAA… on the record before us.” Different facts — vendor servers talking directly to third-party APIs, more vendor control, stored credentials used from the vendor’s network — are left open. Distinguished from Facebook v. Power Ventures, 844 F.3d 1058 (9th Cir. 2016), where the defendant’s own systems caused messages on Facebook.
- Coverage actually read: PYMNTS, 14 Sep 2026; Cooley alert, 6 Aug 2026; Jones Day / Mondaq, 16 Sep 2026.
- Product implication: do not build a hosted agent that logs into third-party sites, scrapes password-protected pages, or calls third-party APIs from our IP using stored user secrets. Terms-of-service, copyright, DMCA, and tort claims survived the ruling. BRIEF constraint (“Do not build a product that logs into third-party sites for users”) is still the right kill line.
Money transmission basics
- Federal definition, 31 C.F.R. § 1010.100(ff)(5): a money transmitter is a person that provides “money transmission services” — “the acceptance of currency, funds, or other value that substitutes for currency from one person and the transmission of … value that substitutes for currency to another location or person by any means” — or any other person engaged in the transfer of funds. Facts-and-circumstances; no dollar threshold for money transmitters. Source: eCFR / 2011 MSB Rule; FinCEN FIN-2013-G001.
- FinCEN virtual-currency guidance, FIN-2013-G001 (18 Mar 2013), still the baseline: fincen.gov FIN-2013-G001. User of virtual currency ≠ MSB. Administrator or exchanger that accepts and transmits convertible virtual currency is a money transmitter unless an exemption applies. “Accepting and transmitting anything of value that substitutes for currency makes a person a money transmitter.”
- Software/network exemption: § 1010.100(ff)(5)(ii)(A) — not a money transmitter if the person only “provides the delivery, communication, or network access services used by a money transmitter to support money transmission services.” Payment-processor exemption (ii)(B) is narrow (goods/services through a BSA-only clearing system, by agreement with the seller).
- State MTLs sit on top. ~49 states license money transmitters; FinCEN MSB registration is separate and not a substitute (Cornerstone Licensing, reviewed May 2026; CSBS/NMLS model). Holding customer funds, issuing stored value, P2P wallets, or “prepaid LLM credits” we sell and then spend against OpenAI/Anthropic on the user’s behalf is the classic trigger.
- SaaS subscription billed on a card, where we never accept funds for onward transmission, is the safe pattern. Users keep their own LLM API keys; we must not resell model access as a prepaid wallet (BRIEF hard constraint 3).
Other landmines we actually checked
- UPL. Every US state. Line is legal information vs applying law to a person’s facts and recommending action. DoNotPay FTC “robot lawyer” (Operation AI Comply); Nippon Life v. OpenAI, N.D. Ill. Mar 2026 (UPL theory against a chatbot, untested). NY S.7263 would bar chatbots from UPL-equivalent answers. Disclaimers help; they do not immunize a product that tells a user “you are compliant” or “this receipt is legally sufficient.”
- FTC § 5 / fake compliance. FTC continues to police false statements about capabilities and certifications even as 2026 enforcement of “AI washing” of model quality has narrowed (Skadden Feb 2026; Workado accuracy order 2025; Operation AI Comply). “HIPAA compliant” is not a government certification (Fisher Phillips, Jun 2026). Delve (Mar 2026) is the cautionary tale for fabricated SOC 2 / ISO packs. BRIEF: no “we are SOC2 auditors,” no fake compliance certificates, no “AI Act compliant.”
- Children / COPPA. FTC COPPA Rule amendments: compliance deadline 22 April 2026. Separate parental consent for third-party disclosure; AI training on kids’ data is not “integral” (FTC; Davis Polk Apr 2026). California 2026: AB 2246 (AADC replacement, signed 10 Sep 2026), SB 1119 (Adam’s Law chatbot audits), SB 867 (chatbot toys), AB 1709 (addictive features under 16) — Kelley Drye, 14 Sep 2026. A public playground with no age gate is a COPPA/state-kids trap. Do not store or process children’s data. 18+.
- US state privacy / ADMT. CCPA ADMT rules: pre-use notice, opt-out, and logic access for “significant decisions” (employment, lending, housing, education, healthcare) — consumer opt-out 1 Jan 2027 (Brownstein; PrivacyLawMap). Colorado ADMT rewrite (SB 26-189, May 2026). Connecticut automated employment-decision rules from 1 Oct 2026. FCRA theories against AI hiring scores: Kistler v. Eightfold AI, N.D. Cal. 2026. We cannot staff a 20-state ADMT/FCRA program on this VPS. Do not decision people.
- Crypto / securities. SEC/CFTC joint interpretation 17 Mar 2026: Howey still governs investment contracts; most native tokens are not themselves securities, but tokenized securities remain securities, and a non-security token sold with managerial-profit promises is still an investment contract (Paul Weiss; SEC Peirce statement 17 Sep 2026). No tokens, no “receipt coins,” no points that look like stored value.
- Quantum export. BIS Sep 2024 IFR: ECCN 4A906 (quantum computers above qubit/error thresholds, starting ~34 fully-controlled connected working physical qubits), 4D906 / 4E906 software and technology specially designed for development/production of those items; plus cryo-CMOS / control electronics in the 3A901 series. Educational/open published circuit toolkits on classical hardware are not automatically 4A906. Claiming we run a QPU, shipping pulse-control stacks, or “deemed exporting” controlled tech to foreign nationals is the kill. Cornell eCFR 15 C.F.R. Supp. 1 to Part 774, ECCN 4A906.
Cross-cutting product rules (apply to every survivor)
These are not optional polish. They are the difference between FIX and KILL.
- US-only, 18+. Geo-restrict the EU/EEA/UK at the edge. Age gate. No child-directed design, no school accounts, no “classroom for kids.”
- Users bring their own LLM keys. We never take custody of fiat, crypto, or prepaid model credits to spend on a user’s behalf. Stripe (or similar) charges our SaaS fee only.
- Policy engine, not a browser agent. We answer allow / deny / ask. We do not log into Gmail, Amazon, GitHub (except OAuth the user grants to their repo for a yaml file), banks, or any third-party site. We do not scrape. If we must see a tool call, the user’s runtime sends us a description and we return a decision — our servers do not “enter” the third-party system (Perplexity architecture, not Power Ventures).
- No decisioning of natural persons for jobs, credit, insurance, housing, education access, benefits, healthcare, or emergency dispatch (Annex III pts 3–5; FCRA; CA/CO/CT ADMT).
- No legal, medical, or HR advice. UI copy: “Not legal advice. Not a compliance certification. Not an auditor.” English rules are the user’s policy, not our opinion of the law.
- No “AI Act / SOC 2 / HIPAA / ISO certified by us” claims. Disclose AI use in the playground (Art. 50(1) hygiene even for a US-only site). Do not CE-mark, do not sell “conformity packs.”
- No tokens. Receipts are JSON + signature, not an asset.
- Honest FTC posture. No fake social proof, no accuracy percentages we cannot substantiate, no “100% secure.”
Verdicts
A. Permit gateway for agent tools / MCP
Verdict: FIX (survives only if the patches below are in the product, not the slide)
English allow/deny/ask rules, spend cap on the user’s own keys, signed shareable receipts, one URL drop-in, explicitly not enterprise GRC.
| Landmine | Why it is not an automatic KILL | How it still dies |
|---|---|---|
| Money transmission | A cap on the user’s OpenAI/Anthropic key is a rate-limit, not acceptance-and-transmission of value. SaaS fee ≠ stored value. § 1010.100(ff)(5); FIN-2013-G001. | We sell “$20 of GPT,” hold a balance, and spend it for them. That is a prepaid wallet / transmitter. Instant KILL. |
| CFAA | A decision API the user’s agent calls is not “entering” a third-party computer. Perplexity, 26-1444, user-not-developer if we never talk to the third party. | Hosted MCP that holds GitHub/Slack/Stripe tokens and calls those APIs from 173.249.19.205 is the Power Ventures fact pattern the Ninth Circuit left open. KILL that architecture. |
| Annex III | Tool-permission policy is not biometrics, hiring, credit, education admissions, LE, or justice. Intended purpose test (Art. 6(2) + Commission May 2026 guidelines). | Market it as “employment agent oversight” that scores workers, or as credit/spend underwriting of people. Then pt 4 or 5(b). |
| UPL / fake compliance | Software that enforces the user’s English is a tool. | Copy that says “AI Act compliant,” “SOC 2 ready,” “this receipt proves you met the law.” FTC § 5 + UPL. |
| Children / state privacy | B2B, 18+, no sensitive-decision ADMT. API keys and policy text are customer data; CCPA only if we hit thresholds — operational, not a product kill. | Public playground that logs chats from minors. COPPA (actual knowledge or child-directed). |
| Art. 50 | Playground chatbot must disclose it is AI. Cheap. | Pretend the bot is a human reviewer. |
Required FIX (non-negotiable):
- Spend cap = local quota on customer-owned keys. Zero prepaid model inventory.
- Gateway returns
{allow, deny, ask}plus a signed receipt of what we were told. We do not execute the tool. - No stored third-party session cookies. GitHub/MCP credentials stay with the user runtime unless the user is only asking us to host a policy document.
- Receipts: “This is a log of a policy decision, not a legal or audit opinion.”
- Homepage: US-only, 18+, “Not legal advice. We do not certify compliance.”
- Do not name it “GRC,” “auditor,” “AI Act,” or “SOC.”
If those land, this is the least-dirty BRIEF candidate. It is still FIX, not a clean SURVIVE, because one bad proxy feature reopens CFAA and one “credits” SKU reopens FinCEN.
B. Repo agent-permit.yaml runtime (Dependabot-like)
Verdict: FIX (same family as A; slightly cleaner CFAA, slightly worse “compliance product” temptation)
Hosted enforcement of a yaml file in the user’s repo. Viral install. Not a GRC suite.
Survives if: we read a file the user granted via OAuth (authorized access to their repo), compile it to the same allow/deny engine as A, and never browse the rest of the internet as the user.
Kills if:
- We crawl other people’s private repos, GitHub Enterprise behind SSO we don’t own, or “fix” third-party apps. CFAA/ToS.
- CI “enforcement” starts blocking human employees based on behaviour scores → Annex III pt 4(b) (monitor/evaluate workers) + CA ADMT + possible FCRA CRA theory (Eightfold).
- We sell a badge: “this repo is AI-Act / SOC 2 agent-compliant.” Fake certification. KILL.
- Yaml authoring assistant that answers “does this satisfy the EU AI Act / NY DFS / NIST?” as applied to their facts. That is legal advice. UPL.
Required FIX: OAuth least-privilege (contents:read on one file), public-repo option with no private-data retention, no badge-as-certification, same US/18+/no-legal-advice chrome as A. Dependabot-like virality is a distribution trick, not a new legal class.
Treat A and B as one product with two install paths (URL gateway vs repo yaml). Do not ship two compliance stories.
C. Freelance / client agent receipts — “prove an agent did work”
Verdict: FIX, with a short leash. Default-narrow. One extra feature and it is KILL.
A signed log that an agent called tools X, Y, Z under policy P, at time T, on the freelancer’s own keys, can be ordinary software (like a build log). Courts take documents; selling a log is not UPL by itself.
KILL variants (do not ship):
- Escrow / “client pays when the receipt verifies.” We would accept funds from the client and transmit to the freelancer. That is money transmission under § 1010.100(ff)(5) from transaction one, plus ~49 state MTLs. No “we’re just a marketplace” story saves an unlicensed principal that holds the money. Payment-processor exemption needs a BSA clearing system and an agreement with the seller of goods/services — and even then, state law may still bite. Do not hold the fee.
- Quality / “hire-worthiness” score of the freelancer or the agent. Annex III pt 4(a)–(b) (recruitment, performance). FCRA consumer-report risk. CA ADMT “significant decision” (employment / independent contracting) from 1 Jan 2027. We cannot run that program.
- Warranty copy: “cryptographically proves the work was done / is court-admissible / satisfies the SOW.” That is a legal conclusion. FTC substantiation + UPL-adjacent. Receipts may be used as evidence; we must not opine they are sufficient.
- Tokenized receipts / points. Howey + stored-value. No.
Required FIX: receipt = signed JSON of policy inputs/outputs the user already owns. Client and freelancer settle off-platform. No ranking. Disclaimer on every share link. If the idea stays “too narrow” commercially, that is a market problem, not a reason to add escrow.
D. Quantum circuit classroom
Verdict: KILL
BRIEF already flags demand/monetization. Legal independently kills the classroom framing.
- Annex III pt 3 — education. High-risk if intended to (a) determine access/admission, (b) evaluate learning outcomes (including to steer the learning process), (c) assess the appropriate education level, or (d) monitor prohibited behaviour during tests. A “classroom” with quizzes, levels, or proctoring is (b)/(c)/(d) on its face. Commission guidelines: intended purpose, not the simulator backend. Art. 6(3) “narrow procedural task” is a documented exception, not a slogan.
- Children. “Classroom” invites K–12. COPPA (under 13, actual knowledge or child-directed) plus California AB 2246 / SB 1119 / SB 867 (2026). We will not implement verifiable parental consent, retention limits, or chatbot-audit duties for minors. Children’s data is an instant kill.
- Export / false hardware. A classical circuit visualizer with no QPU, no pulse-control, no “we have 34+ qubits,” and no 4D906-class control software can be EAR99/published. The moment copy says “quantum computer,” “run on real hardware,” or we wrap IBM/IonQ credentials and re-sell QPU time, we eat (i) BIS 4A906/4D906, (ii) cloud-vendor ToS, (iii) FTC capability claims. This VPS has no quantum hardware (BRIEF). Do not claim it.
- Even the patched 18+ lab is a demand kill, which this legal pass does not need to relitigate. If someone later proposes a non-evaluative, 18+, classical, no-hardware-claim sandbox, re-score it as FIX. The BRIEF candidate as written is KILL.
E. “Anything more specific and more genius”
Verdict: no idea file existed. Placeholder = KILL until specified.
Any later E-idea is auto-KILL if it: scrapes/logs into third parties; holds funds or API-credit balances; issues tokens; decisions humans (hire/fire/credit/school/health); processes kids; claims certification; ships export-controlled quantum stacks; or practices law/medicine. Otherwise re-score.
Patched survivor (if PM needs one product that is not dead)
BRIEF: if everything is killed, invent a patch. A/B are FIX, not KILL. The legally cleanest merge:
PermitGate — MCP/tool policy runtime (US, 18+, BYOK)
What it is. A single HTTPS endpoint plus an optional agent-permit.yaml. The user’s local or self-hosted agent sends a tool-call descriptor. We return allow / deny / ask, enforce a numeric cap on the user’s own key, and emit a signed receipt the user can share. Homepage playground: paste a rule in English, fire a fake stripe.refunds.create, see allow/deny in <60 seconds. We never execute the tool.
Why the kill list does not fire (if we keep our hands clean):
| Kill item | Why this patch survives |
|---|---|
| Annex III high-risk | Intended purpose is authorization of software tools, not pts 1–8. No biometrics, hiring, credit, education access, LE, justice. Do not market into those. |
| Money transmission | No acceptance-and-transmission of value. BYOK. SaaS subscription only. § 1010.100(ff)(5); FIN-2013-G001 user vs exchanger. |
| CFAA | We do not access third-party computers. User’s runtime does. Amazon v. Perplexity, 26-1444 (user, not developer; tool not a person; no vendor-to-site TCP). |
| UPL | We enforce their English. We do not apply law to facts. Persistent “not legal advice / not a certification.” |
| Medical / credit / HR | Out of scope in ToS; refuse those templates in the playground. |
| Crypto securities | No token. Receipt is a signature over a log. |
| Quantum export | Out of product. |
| Compliance certification | Forbidden copy. FTC § 5. |
| Children’s data | 18+ age gate; not child-directed; no school SKU. COPPA actual-knowledge + CA 2026 kids/chatbot bills. |
| State ADMT | We do not make “significant decisions” about consumers. Policy decisions about tools. |
Residual risk (not KILL, must be owned):
- EU person uses the site anyway → Art. 50 disclosure still cheap; Annex III still avoided by purpose; geo-block is the belt.
- User uses our receipts as HR or credit evidence. ToS prohibition + no scores.
- User’s agent, after we say “allow,” commits CFAA. We are closer to Safari than to Comet-on-our-servers, but Cooley/Jones Day both warn: architecture and other theories (ToS, tort) remain. Keep vendor servers off the third-party path.
- CCPA if we grow into a “business.” Ordinary privacy policy, no sale of personal information, no kids’ data. Do not become a CRA.
This is still not a legal opinion that the product is “compliant.” It is a challenger’s statement that the shape does not trip the BRIEF instant-kill list.
Scoreboard
| ID | Idea | Verdict | One-line why |
|---|---|---|---|
| A | MCP/tool permit gateway | FIX | Legal if BYOK + decision-only + no cert claims; dies if it becomes a hosted agent or prepaid wallet |
| B | agent-permit.yaml runtime |
FIX | Same product as A, different install; no compliance badges |
| C | Freelance agent receipts | FIX | Logs only; escrow/scores/tokens = KILL |
| D | Quantum circuit classroom | KILL | Annex III education + children + hardware/export/false-claim stack |
| E | Unspecified | KILL until written | Empty ideas dir |
| Patch | PermitGate (A∩B, patched) | SURVIVE (conditional) | Only the merged, decision-only, US/18+/BYOK, no-certification form |
Do not ship D. Do not add payments to C. Do not let A/B grow a browser. PM should pick patched A/B (PermitGate) or kill the pivot.
Not legal advice. Sources are those fetched on 18 September 2026 as listed above.