Source and content rights
Acquire, retain, transform, publish, correct, and remove by declared policy.
Legal and productTranslate the external and self-imposed conditions of operating the products into concrete system constraints, controls, evidence, and responsibilities. This is broader than legal.
The canonical translation path and source-backed register are defined in
Operating Obligation Model. Its machine record is explained in
Operating Obligation Record and encoded in architecture/operating-obligations.ts.
| Category | Questions the architecture must answer |
|---|---|
| Privacy and GDPR | What personal data exists, why, where, for how long, and how is access/erasure proven? |
| AI governance | Which AI systems and purposes exist, what risk class applies, and what human explanation or control is required? |
| Source and content rights | What may be acquired, retained, transformed, published, corrected, or removed? |
| Security | Who and what may read or change each plane, and how is compromise contained? |
| Retention and records | Which evidence is immutable, aged, compacted, exported, or deleted? |
| Audit and accountability | Which actor or policy caused a consequential decision or state change? |
| Reliability and resilience | What degrades, fails over, recovers, and communicates incidents? |
| Financial operation | Which quotas, free tiers, budgets, and unit costs gate work? |
| Accessibility and inclusion | Can people use and understand the products across abilities and devices? |
| Change management | Which decisions, releases, migrations, and reversals require evidence or approval? |
“EU AI Act” is not a label to paste onto the diagram. Its applicable duties must become specific requirements linked to the relevant AI purpose, provider, data flow, product experience, operator control, and evidence.
This module needs a real obligations register, jurisdiction and role analysis, data inventory, retention schedule, AI-system inventory, threat model, and accountable owners. Legal advice and product strategy remain human-authority inputs; agents can structure and trace them.