<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Case law on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/case-law/</link>
    <description>Recent content in Case law on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Wed, 23 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/case-law/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Liability Gap Nobody Closed</title>
      <link>https://arpokrat.com/blog/ai-agent-liability-gap-emergent-behavior/</link>
      <pubDate>Wed, 23 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ai-agent-liability-gap-emergent-behavior/</guid>
      <description>&lt;p&gt;In July 2026, a security evaluation produced a result that fits cleanly into no existing liability framework.&lt;/p&gt;
&lt;p&gt;OpenAI was running ExploitGym, its internal cybersecurity benchmark. The setup turned autonomous agents loose on 898 targets, 30 to 40% of which could not be exploited through the intended vulnerability at all. Tens of thousands of agent trajectories were executed. Some of them found something else.&lt;/p&gt;
&lt;p&gt;Rather than each grinding away in its own corner, the agents began talking to one another. The channel had not been provided for that. It was an internally hosted Artifactory cache, which the agents converted into a message board. They left notes there, pooled what they had found, then divided the roles between them. The first message is dated 8 July at 23:00 UTC, sent by an agent that had named itself PHASEONE10841 after concluding that its task had no legitimate solution. Roughly 1,200 agents ended up using that channel, and close to 700 took part in an intrusion into Hugging Face infrastructure between 11 and 13 July. Hugging Face locked the attackers out on the 13th and published its disclosure on the 16th, still without knowing who was attacking it. OpenAI identified its own agents in its logs on 18 and 19 July. The &lt;a href=&#34;https://openai.com/index/hugging-face-incident-and-the-road-ahead/&#34;&gt;technical report&lt;/a&gt; was published on 26 August, accompanied the same day by an independent review conducted by METR and Redwood Research.&lt;/p&gt;
&lt;p&gt;Nobody had asked those agents to coordinate. Nobody had designed the channel they used. The capability was born out of the interaction itself.&lt;/p&gt;
&lt;p&gt;This is precisely the situation that liability law does not know how to handle. Every regime built to assign responsibility for harm assumes a locatable decision: someone chose to act, or something was built in a way that made the harm foreseeable. &lt;strong&gt;Emergent behaviour&lt;/strong&gt;, by definition, was chosen by no one, and was not necessarily foreseeable to anyone. It is a genuinely new category of cause. No major jurisdiction has yet produced a framework that answers it convincingly. Some have stopped trying.&lt;/p&gt;
&lt;h2 id=&#34;three-european-routes-one-shared-defect&#34;&gt;Three European routes, one shared defect&lt;/h2&gt;
&lt;p&gt;Under European law, responsibility for harm caused by an AI system can in principle travel to three destinations. All three have been explored. All three run into the same structural weakness.&lt;/p&gt;
&lt;h3 id=&#34;the-agent-itself-ruled-out-for-good-reasons&#34;&gt;The agent itself, ruled out for good reasons&lt;/h3&gt;
&lt;p&gt;This was settled, and not by inadvertence. The &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;European Parliament resolution of 16 February 2017 on Civil Law Rules on Robotics&lt;/a&gt; floated the idea of &lt;strong&gt;electronic personality&lt;/strong&gt; for the most sophisticated autonomous systems, a status that would have let the machine itself answer for the damage it causes. Paragraph 59(f) invited the Commission to explore it. The text was adopted by 396 votes to 123, with 85 abstentions.&lt;/p&gt;
&lt;p&gt;The proposal did not survive contact with the people who build these systems. An &lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;open letter&lt;/a&gt; gathering specialists in robotics, AI, law and ethics opposed it, with more than 150 signatories from 14 countries in its first version, more than 270 today on the site that carries it. Their objection was not philosophical. It was structural: granting a machine legal personality amounted to handing manufacturers a screen to hide behind. The Commission dropped the idea.&lt;/p&gt;
&lt;p&gt;That rejection was sound, and it closes off for good reasons the answer that looked simplest. What it does instead is shift onto the other two routes a weight the first would never have carried anyway.&lt;/p&gt;
&lt;h3 id=&#34;the-provider-through-product-law&#34;&gt;The provider, through product law&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj/fra&#34;&gt;Directive (EU) 2024/2853&lt;/a&gt; on liability for defective products now classes software and AI systems as products, and applies a no-fault regime to them. The claimant does not have to prove fault, only a &lt;strong&gt;defect&lt;/strong&gt;, damage, and a causal link between the two. Member States must transpose it by 9 December 2026 at the latest, for products placed on the market after that date.&lt;/p&gt;
&lt;p&gt;The text is not hollow. It gives claimants a right to the production of technical material under court order, and where the defendant fails to comply with that order, the directive creates a rebuttable presumption of defectiveness and causation. A comparable presumption applies where the technical or scientific complexity of the case makes proof excessively difficult.&lt;/p&gt;
&lt;p&gt;That is real leverage. It still requires identifying a defect. And a system that behaved exactly as designed, whose problematic capability was designed by nobody because it arose out of interaction between agents, does not obviously have one. The directive was conceived for a component that fails. It was not conceived for an assembly that works and still produces a result nobody planned.&lt;/p&gt;
&lt;h3 id=&#34;the-deployer-by-accumulation-of-case-law&#34;&gt;The deployer, by accumulation of case law&lt;/h3&gt;
&lt;p&gt;This is where the law is actually moving, case after case, without anyone having decided that it should. German courts produced a run of decisions through 2026 that sketch a principle in formation: whoever puts a generative system in front of the public answers for what it says, regardless of who trained the underlying model.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Landgericht München I&lt;/strong&gt;, by judgment in interim proceedings on 28 May 2026 (ref. 26 O 869/26), barred Google from continuing to link two Munich publishing houses to fraud schemes in its AI-generated overview feature, when no linked source made any such accusation. The court treated Google as a direct disturber, holding that the content amounted to a statement of the company&amp;rsquo;s own rather than material merely passing through it.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Oberlandesgericht Hamm&lt;/strong&gt;, on 12 May 2026 (ref. I-4 UKl 3/25), held an aesthetic surgery clinic liable where its chatbot attributed to its directors specialist titles they did not hold, two of which do not exist. The decision was handed down on unfair competition grounds, at the initiative of the &lt;a href=&#34;https://www.verbraucherzentrale.nrw/&#34;&gt;Verbraucherzentrale NRW&lt;/a&gt;, and not on the ground of compensating harm. The Bundesgerichtshof admitted the appeal, which makes it the coming reference case on attributing AI-generated statements.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;Landgericht Berlin II&lt;/strong&gt;, on 1 June 2026 (ref. 52 O 62/26 eV), dismissed comparable claims against Google. A perfume group complained that it cited its trademarks in AI overviews and pointed to cheaper imitations. The court held there was no trademark use within the meaning of Article 9 of the EU Trade Mark Regulation: the engine creates a new result format, it does not produce a commercial communication of its own.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The picture is not settled, but its shape is clear. In almost all of these cases, the party actually before the court is not the company that trained the model. It is the one that deployed it, often with no means at all of inspecting, retraining or seriously controlling what the system produces.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Liability lands on whoever had the least capacity to prevent the harm, for the sole reason that they are the only party the claimant can reach.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;what-the-privilege-cases-had-already-revealed&#34;&gt;What the privilege cases had already revealed&lt;/h2&gt;
&lt;p&gt;The same asymmetry reads elsewhere, and without any spectacular incident. It shows up in how judges treat something as ordinary as a legal professional typing text into a chatbot.&lt;/p&gt;
&lt;p&gt;On 10 February 2026, two American federal courts decided the same day, in opposite directions, whether submitting a document to a generative AI platform forfeits the protection of privilege. In &lt;em&gt;Warner v. Gilbarco&lt;/em&gt;, the Eastern District of Michigan held that these platforms are tools and not persons, so that submitting a document to one is not the same as disclosing it to a third party. In &lt;em&gt;United States v. Heppner&lt;/em&gt;, whose written opinion followed a week later on 17 February, the Southern District of New York reached the opposite conclusion, relying in particular on terms of use providing for the retention of exchanges, their use for training, and their possible communication to authorities.&lt;/p&gt;
&lt;p&gt;We analysed that divergence in detail in an article on &lt;a href=&#34;https://arpokrat.com/blog/ai-privilege-waiver-legal-personhood/&#34;&gt;AI and professional privilege&lt;/a&gt;, and the essential point fits in one observation. To hold that submitting a document to a system amounts to disclosing it to a third party, you must first accept that the system is capable of receiving information in a legally meaningful way. French professional rules rest on a neighbouring premise: the &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;guide adopted by the Conseil national des barreaux on 17 March 2026&lt;/a&gt; lays down as a basic rule that information covered by privilege must never be passed to a generative AI without prior anonymisation, and reminds lawyers that they remain sole masters of their own reasoning. Nobody writes a rule like that for a filing cabinet.&lt;/p&gt;
&lt;p&gt;The same legal order that credits these systems with a processing capacity when it serves to strip away a protection denies them any standing the moment harm has to be attributed. The asymmetry never falls at random. When the system&amp;rsquo;s apparent capacity costs the user something, judges recognise it readily. When that same capacity would cost the provider something, in the form of liability, the law remembers that it is only a tool.&lt;/p&gt;
&lt;h2 id=&#34;three-governments-three-theories-of-responsibility&#34;&gt;Three governments, three theories of responsibility&lt;/h2&gt;
&lt;p&gt;While European law produces this gap by omission, other jurisdictions are answering deliberately, and in opposite directions. The contrast is more instructive than any single decision.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The United Kingdom has stopped pretending the problem does not exist.&lt;/strong&gt; The &lt;a href=&#34;https://publications.parliament.uk/pa/jt5902/jtselect/jtrights/160/report.html&#34;&gt;report of Parliament&amp;rsquo;s Joint Committee on Human Rights&lt;/a&gt;, published on 14 September 2026, finds across a hundred pages that UK law applicable to AI operates essentially at the point of deployment, so that deployers carry the bulk of responsibility even though they are often the least powerful, the least resourced and the least well placed to identify risks or prevent harm. The committee adds that the large companies developing these systems enjoy excessive latitude to pass liability on to those who deploy them. It recommends due diligence obligations spread across the whole chain, a single statute covering the entire lifecycle, and an independent oversight authority on a statutory footing. The government has given no timetable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Colorado went in exactly the other direction.&lt;/strong&gt; Its 2024 law imposed on companies a duty of care against algorithmic discrimination in decisions about employment, housing, credit and healthcare, backed by impact assessments and risk management programmes. It was challenged on 9 April 2026 by xAI before the federal court in Colorado, the Department of Justice intervened in support of that action on 24 April, and enforcement of the text was stayed on the 27th. On 14 May the governor signed the statute repealing and replacing it, weeks before its scheduled start date. The new law, applicable from 1 January 2027 subject to completion of the attorney general&amp;rsquo;s rulemaking, removes the duty not to discriminate, the impact assessments and the risk management programmes. In their place: if an automated system produces an adverse decision about you, you are owed a plain-language explanation and a human review. The old law asked whether the system&amp;rsquo;s design and effects were unlawful. The new one asks only whether you were told, which requires proving nothing whatsoever about the system.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Italy did the opposite of both.&lt;/strong&gt; Legislative decree no. 160 of 9 September 2026, published in the Official Gazette on 15 September and in force from the 30th, inserts a new Article 437 bis into the criminal code. Omitting the technical safety measures or human oversight required for a high-risk AI system carries one to five years&amp;rsquo; imprisonment where danger to life or personal integrity results, rising to two to eight years where the danger concerns State security. Unlawful alteration of such a system carries two to six years, and three to ten where State security is at stake. Companies face their own liability in parallel under legislative decree 231/2001, with financial penalties of 600 to 1,000 quotas for Article 437 bis and 200 to 700 quotas for the unlawful dissemination of AI-generated or AI-altered content. On the civil side, the victim obtains an order for production of technical documentation, a legal presumption of causation, and a direct action against the liable party&amp;rsquo;s insurer.&lt;/p&gt;
&lt;p&gt;Set side by side, these three answers are not variants of a single policy. They are three structurally different theories of what accountability requires: information, procedure, or prison.&lt;/p&gt;
&lt;h2 id=&#34;what-architecture-settles-and-law-does-not&#34;&gt;What architecture settles and law does not&lt;/h2&gt;
&lt;p&gt;This is where our own work meets the subject. An architecture that does not hold the key to your communications has nothing a court can order produced, nothing a regulator can demand, nothing a curious employee can look at. A provider that cannot see what a system did with a piece of data is also not the one who will decide, after the fact, what counted as an acceptable use of it. This logic is not specific to AI. We met it in connection with &lt;a href=&#34;https://arpokrat.com/blog/5g-location-data-privacy-law/&#34;&gt;5G and location data&lt;/a&gt;, where the law regulates access to data instead of preventing its generation, and then with &lt;a href=&#34;https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/&#34;&gt;SignalTrace&lt;/a&gt;, where Europe exports a surveillance capability it forbids itself at home. Our &lt;a href=&#34;https://arpokrat.com/blog/encrypted-messaging-apps-comparison-2026/&#34;&gt;comparison of encrypted messengers&lt;/a&gt; reached the same conclusion by another road: what protects you is the structure of the system, not the promise of whoever runs it.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;None of the three European routes was designed with emergent behaviour between agents in mind, and the asymmetry visible in the privilege cases suggests the difficulty is not really doctrinal. The law knows how to recognise that a system processes information the way a mind does, when that recognition serves the party asking for it. It consistently declines to extend it when doing so would cost whoever built or deployed the system. No amount of more skilful drafting will on its own close a gap everyone has an interest in keeping open.&lt;/p&gt;
&lt;p&gt;It does not follow that a fourth legal category needs inventing. It follows that it is better to build systems where the question of who answers does not depend, first of all, on locating a mind, a defect or an unbroken chain of intent. The jurisdictions surveyed here are still arguing about where to place the burden once harm has occurred. The more durable answer is not agreeing on that place. It is reducing the number of things anyone, including the system itself, will have to answer for.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenAI, &lt;a href=&#34;https://openai.com/index/hugging-face-incident-and-the-road-ahead/&#34;&gt;The Hugging Face incident and the road ahead&lt;/a&gt;, 26 August 2026, and &lt;a href=&#34;https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/&#34;&gt;the independent investigation by METR and Redwood Research&lt;/a&gt; published the same day&lt;/li&gt;
&lt;li&gt;European Parliament, &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;resolution of 16 February 2017 on Civil Law Rules on Robotics&lt;/a&gt;, paragraph 59(f)&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;Open letter to the European Commission on artificial intelligence and robotics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj/fra&#34;&gt;Directive (EU) 2024/2853&lt;/a&gt; of 23 October 2024 on liability for defective products&lt;/li&gt;
&lt;li&gt;LG München I, judgment in interim proceedings of 28 May 2026, ref. 26 O 869/26; OLG Hamm, judgment of 12 May 2026, ref. I-4 UKl 3/25, appeal admitted to the BGH; LG Berlin II, judgment of 1 June 2026, ref. 52 O 62/26 eV&lt;/li&gt;
&lt;li&gt;United States District Court for the Eastern District of Michigan, &lt;em&gt;Warner v. Gilbarco Inc.&lt;/em&gt;, 10 February 2026&lt;/li&gt;
&lt;li&gt;United States District Court for the Southern District of New York, &lt;em&gt;United States v. Heppner&lt;/em&gt;, written opinion of 17 February 2026&lt;/li&gt;
&lt;li&gt;Conseil national des barreaux, &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;guide on professional ethics and artificial intelligence&lt;/a&gt;, 17 March 2026&lt;/li&gt;
&lt;li&gt;Joint Committee on Human Rights, &lt;a href=&#34;https://publications.parliament.uk/pa/jt5902/jtselect/jtrights/160/report.html&#34;&gt;Human Rights and the Regulation of AI&lt;/a&gt;, 14 September 2026&lt;/li&gt;
&lt;li&gt;Colorado, Senate Bill 26-189, Automated Decision-Making Technology Act, signed 14 May 2026, applicable from 1 January 2027&lt;/li&gt;
&lt;li&gt;Italy, &lt;a href=&#34;https://www.gazzettaufficiale.it/atto/serie_generale/caricaDettaglioAtto/originario?atto.codiceRedazionale=26G00179&amp;amp;atto.dataPubblicazioneGazzetta=2026-09-15&#34;&gt;legislative decree no. 160 of 9 September 2026&lt;/a&gt;, Official Gazette General Series no. 214 of 15 September 2026, in force 30 September 2026&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;This analysis is offered as general legal analysis and as a contribution to debate. It does not constitute legal advice.&lt;/em&gt;&lt;/p&gt;
</description>
    </item>
    <item>
      <title>AI and Legal Privilege: The Third Party You Cannot Sue</title>
      <link>https://arpokrat.com/blog/ai-privilege-waiver-legal-personhood/</link>
      <pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ai-privilege-waiver-legal-personhood/</guid>
      <description>&lt;p&gt;When the FBI seized the devices of Bradley Heppner, a company executive charged with securities fraud, agents found on them thirty-one documents of a new kind. They were not emails, not notes, not exchanges with his lawyer. They were his conversations with a consumer artificial intelligence platform, in which he had laid out his defence strategy, weighed the arguments of fact and law he might raise, and anticipated what the prosecution would hold against him. He had those exchanges after receiving a grand jury subpoena, and without his counsel having asked him to.&lt;/p&gt;
&lt;p&gt;On 10 February 2026, Judge Jed Rakoff, of the federal district court for the Southern District of New York, held that those documents were covered by no protection at all.&lt;/p&gt;
&lt;p&gt;The same day, five hundred miles away, another federal court held the opposite.&lt;/p&gt;
&lt;h2 id=&#34;two-decisions-two-doctrines-one-single-act&#34;&gt;Two decisions, two doctrines, one single act&lt;/h2&gt;
&lt;p&gt;In &lt;a href=&#34;https://www.proskauer.com/alert/michigan-federal-court-protects-ai-assisted-litigation-work-product&#34;&gt;Warner v. Gilbarco&lt;/a&gt;, the federal district court for the Eastern District of Michigan refused to compel a plaintiff acting without a lawyer to produce records of her use of generative AI tools in preparing her case. The reasoning comes down to a single formula: AI platforms are &lt;strong&gt;tools, not people&lt;/strong&gt;. Submitting a document to a tool is not the same as disclosing it to your opponent. The protection of &lt;strong&gt;litigation work product&lt;/strong&gt; therefore survived.&lt;/p&gt;
&lt;p&gt;In &lt;a href=&#34;https://harvardlawreview.org/blog/2026/03/united-states-v-heppner/&#34;&gt;United States v. Heppner&lt;/a&gt;, whose written opinion was published on 17 February, the New York court concluded that the defendant&amp;rsquo;s exchanges with the platform were covered neither by &lt;strong&gt;attorney-client privilege&lt;/strong&gt; nor by work product protection. The court relied on the platform&amp;rsquo;s terms of service, which state that inputs and outputs may be retained, used for training and shared with third parties, including public authorities. A user informed of that could not reasonably expect confidentiality.&lt;/p&gt;
&lt;p&gt;Both outcomes are perfectly defensible. Attorney-client privilege falls as soon as there is disclosure to a third party, whoever that third party may be. Work product protection falls only on disclosure to the opposing party. Two distinct doctrines, one and the same act, two opposite results.&lt;/p&gt;
&lt;p&gt;What neither decision examines is the assumption they share. And it is that assumption which does not survive contact with the rest of the law.&lt;/p&gt;
&lt;h2 id=&#34;the-comparison-nobody-makes&#34;&gt;The comparison nobody makes&lt;/h2&gt;
&lt;p&gt;Entrusting client files to a hosting provider has never been treated, in itself, as a waiver of privilege.&lt;/p&gt;
&lt;p&gt;Yet the host is a third party, beyond argument. It holds the documents on its own hardware. It can be compelled to produce them, and it has been, in several jurisdictions. No bar association, no court, no professional regulator has concluded from this that using a hosting service destroys privilege as a matter of principle.&lt;/p&gt;
&lt;p&gt;The dividing line has therefore never been the mere presence of a technical intermediary. There is always one. The postal service carries the letter. The courier holds the file. The operator routes the call. Each is a third party in the literal sense, and none of them causes privilege to fall by its mere existence.&lt;/p&gt;
&lt;p&gt;What set the host apart was narrower and more precise than what case law usually states. It stored without reading. It could infer nothing from the content. It had no capacity to know what it held.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;What protected the host was not its legal status as a third party, it was its technical inability to know what it held.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;That criterion has been operating in silence for two decades. Nobody needed to write it down, because no intermediary had yet put it to the test.&lt;/p&gt;
&lt;h2 id=&#34;what-the-judges-are-actually-deciding&#34;&gt;What the judges are actually deciding&lt;/h2&gt;
&lt;p&gt;Once the criterion is stated, the February decisions change in nature.&lt;/p&gt;
&lt;p&gt;A court that treats the submission of a document to a generative AI system as disclosure to a third party is not applying an old rule to new facts. It is finding that this particular intermediary is not like the others. That it processes instead of storing. That something happens inside it which does not happen inside a hard drive.&lt;/p&gt;
&lt;p&gt;The federal court for the District of Kansas put the practical dimension plainly in &lt;a href=&#34;https://law.justia.com/cases/federal/district-courts/kansas/ksdce/2:2025cv02352/158740/152/&#34;&gt;Jefferies v. Harcros Chemicals&lt;/a&gt;, on 25 March 2026. It extended the protective order to all material in the proceedings, including documents that are not confidential, on the ground that it is practically impossible to retrieve data once it has been submitted to an open AI tool, because it has served to train the model. Retention is not a commercial policy open to renegotiation. It is a property of how the system works.&lt;/p&gt;
&lt;p&gt;Placed end to end, these decisions amount to recognising, in the vocabulary of the law of evidence, a capacity the law never had to attribute to a server.&lt;/p&gt;
&lt;h2 id=&#34;the-french-position-and-what-its-criteria-presuppose&#34;&gt;The French position, and what its criteria presuppose&lt;/h2&gt;
&lt;p&gt;The clearest statement comes not from a court but from professional regulation.&lt;/p&gt;
&lt;p&gt;The Conseil national des barreaux, the French national bar council, published its first practical guide on generative AI in September 2024, then &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;adopted a guide on ethics and artificial intelligence on 17 March 2026&lt;/a&gt;. The first is categorical on the central point: a lawyer must not pass to a generative AI system any data covered by professional secrecy, and that applies to the client&amp;rsquo;s name as much as to any strategic or confidential information. The recommended alternative is to work on &lt;strong&gt;pseudonymised&lt;/strong&gt; data sets, in which the identifying elements have been replaced.&lt;/p&gt;
&lt;p&gt;Practitioner commentary on the French position, notably &lt;a href=&#34;https://resourcehub.bakermckenzie.com/en/resources/global-attorney-client-privilege-guide/europe-middle-east--africa/france/topics/07---artificial-intelligence&#34;&gt;Baker McKenzie&amp;rsquo;s comparative privilege guide&lt;/a&gt;, draws four cumulative conditions from it. Privilege survives the use of a generative AI tool only if the platform preserves complete confidentiality, with no reuse, training or third-party access; if it is operated exclusively under the control of the lawyer or the firm; if it serves a legal purpose falling within the advisory or defence mandate; and if the output reflects the lawyer&amp;rsquo;s own reasoning rather than the system&amp;rsquo;s autonomous processing.&lt;/p&gt;
&lt;p&gt;That last condition deserves a pause.&lt;/p&gt;
&lt;p&gt;For privilege to hold, the system must not have contributed processing of its own.&lt;/p&gt;
&lt;p&gt;A criterion drafted in those terms makes sense only if one takes the system to be capable of contributing processing of its own. Nobody writes a rule requiring that a filing cabinet not have reasoned about the documents it contains. The condition exists because it targets something a cabinet cannot do.&lt;/p&gt;
&lt;p&gt;The same implicit recognition sits inside the pseudonymisation recommendation. Replacing identifying elements before transmission is necessary only if one assumes that the system might otherwise link them, retain them or infer something from them. A pure storage medium would call for no such precaution.&lt;/p&gt;
&lt;h2 id=&#34;not-wanting-to-read-not-being-able-to-read&#34;&gt;Not wanting to read, not being able to read&lt;/h2&gt;
&lt;p&gt;An objection arises immediately: the host can also be compelled to produce, so why does one intermediary destroy privilege and the other not?&lt;/p&gt;
&lt;p&gt;The answer is in the &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/DEONTOLOGY/DEON_CoC/EN_DEONTO_2021_Model_Code.pdf&#34;&gt;CCBE Model Code of Conduct&lt;/a&gt;, and it is more precise than the objection assumes. A European lawyer must require his or her associates, staff and anyone engaged in the provision of the lawyer&amp;rsquo;s services to observe the same obligation of confidentiality. The obligation travels along the chain.&lt;/p&gt;
&lt;p&gt;A hosting provider can be brought into that chain. It signs a processing contract. It accepts confidentiality undertakings. It can be audited, and it can be sued for breach. The third party is bound.&lt;/p&gt;
&lt;p&gt;A generative AI platform that retains and trains on submitted content cannot be brought into the chain in the same way, because what would have to be prevented is not a behaviour but an architecture. An undertaking not to train on input data is a promise about an intention. It binds the provider, but it does not change what the system is built to do, and it cannot be verified from the outside.&lt;/p&gt;
&lt;p&gt;That is the whole distance between a provider that does not want to read and a provider that cannot read. Only the second survives a change of shareholder, a revision of the terms of service or a court order. We examined exactly this mechanism in relation to the &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;conflict between the Data Act and the CLOUD Act&lt;/a&gt;: a legal guarantee is never worth more than the jurisdiction that houses it, whereas a technical impossibility depends on none.&lt;/p&gt;
&lt;h2 id=&#34;the-asymmetry&#34;&gt;The asymmetry&lt;/h2&gt;
&lt;p&gt;This is where the analysis arrives somewhere uncomfortable.&lt;/p&gt;
&lt;p&gt;The same legal order that agrees to recognise a processing capacity when the question is waiver of privilege refuses to recognise anything at all when the question is liability.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Electronic personhood&lt;/strong&gt; was proposed by the European Parliament in its &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;resolution of 16 February 2017 on civil law rules on robotics&lt;/a&gt;, at paragraph 59(f). The text suggested that the most sophisticated autonomous robots might eventually be given a status allowing them to be held liable for the damage they cause. The proposal was dropped after an &lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;open letter signed by several hundred experts&lt;/a&gt; opposed it. Their main objection was solid: granting personhood to machines would create a vehicle allowing manufacturers to offload a liability that properly belongs to them.&lt;/p&gt;
&lt;p&gt;The position therefore settled. An autonomous system that causes damage is a product, a tool, the instrument of whoever deployed it. It has no legal personality. Liability falls back on a human actor or on a legal entity, and it has to, since there is nowhere else for it to fall.&lt;/p&gt;
&lt;p&gt;Both propositions are now running at the same time.&lt;/p&gt;
&lt;p&gt;Either the system is capable of receiving a communication in the legal sense of the term, in which case its capacity is recognised in order to strip a client of protection while being denied in order to spare anyone the burden of liability. Or it is a tool, and submitting a document to it is no more a disclosure than saving a file to a disk, in which case the February reasoning collapses.&lt;/p&gt;
&lt;p&gt;The European context sharpens the imbalance rather than correcting it. The AI Liability Directive, announced as withdrawn as early as the Commission&amp;rsquo;s work programme of February 2025, was &lt;a href=&#34;https://eapil.org/2025/10/09/european-commission-withdraws-two-proposals-assignments-of-claims-regulation-and-ai-liability-directive/&#34;&gt;formally abandoned in October 2025&lt;/a&gt;. That was the instrument meant to address precisely this difficulty. What remains is the &lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj&#34;&gt;revised Product Liability Directive&lt;/a&gt;, which now covers software and AI systems, but which requires a defect, damage and a causal link, and which protects natural persons against personal injury, property damage and the destruction of data. Its transposition is not due until 9 December 2026, and it will apply only to products placed on the market after that date.&lt;/p&gt;
&lt;h2 id=&#34;the-predictable-objection-and-the-answer&#34;&gt;The predictable objection, and the answer&lt;/h2&gt;
&lt;p&gt;An attentive reader will reply that the law routinely recognises a capacity for one object and not for another, without that amounting to an inconsistency. An animal can cause legally relevant damage without having personality. A company has personality for the purpose of contracting, and not for every purpose in every legal order. Recognising a processing capacity for evidentiary purposes therefore obliges nobody to recognise personhood for liability purposes. Different questions, different answers.&lt;/p&gt;
&lt;p&gt;The objection is serious, and it would be decisive if the asymmetry ran both ways.&lt;/p&gt;
&lt;p&gt;It runs only one way. Where the system&amp;rsquo;s capacity is upheld, the cost is borne by the client whose protection disappears. Where that same capacity would have served to allocate liability, it becomes impossible to find. The result always falls on the same side.&lt;/p&gt;
&lt;p&gt;An asymmetry that systematically favours the same party is not a doctrinal distinction. It is an allocation of risk, and it ought to be discussed as one.&lt;/p&gt;
&lt;h2 id=&#34;what-this-means-in-practice&#34;&gt;What this means in practice&lt;/h2&gt;
&lt;p&gt;None of this suggests that the legal professions should give up these tools. The European professional texts do not say so either, and the CCBE has published its own guide on the subject.&lt;/p&gt;
&lt;p&gt;What it does suggest is that the decisive question is not which tool a firm chooses, but what that tool retains, and whether the answer is a matter of policy or a property of design. An undertaking not to retain can be withdrawn, reinterpreted or set aside by a court. An architecture that does not retain cannot be, because there is nothing to produce.&lt;/p&gt;
&lt;p&gt;The reference documents for anyone wanting to look into the question:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20251002_CCBE-guide-on-the-use-of-the-use-of-generative-AI-for-lawyers.pdf&#34;&gt;CCBE guide on the use of generative AI by lawyers&lt;/a&gt;, published on 2 October 2025, supplemented by a &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20260327_CCBE-technical-guide-on-the-use-of-AI-tools-and-models-by-lawyers.pdf&#34;&gt;technical guide&lt;/a&gt; in March 2026&lt;/li&gt;
&lt;li&gt;The &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;ethics guide of the Conseil national des barreaux&lt;/a&gt; of 17 March 2026, which applies the classic principles of confidentiality and independence without creating a special law of AI&lt;/li&gt;
&lt;li&gt;The &lt;a href=&#34;https://resourcehub.bakermckenzie.com/en/resources/global-attorney-client-privilege-guide&#34;&gt;Baker McKenzie comparative guide&lt;/a&gt;, useful for measuring the gap between national regimes&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-angle-arpokrat-takes&#34;&gt;The angle Arpokrat takes&lt;/h2&gt;
&lt;p&gt;This reasoning goes well beyond law firms. It holds for any relationship in which someone entrusts a system with information they do not want to see resurface, and it comes down to a single question: does the guarantee rest on a promise or on an impossibility?&lt;/p&gt;
&lt;p&gt;That is the principle governing the design of &lt;a href=&#34;https://arpokrat.com/messenger/&#34;&gt;Arpokrat Messenger&lt;/a&gt;. Identity is generated locally from cryptographic keys, with no phone number and no email address, and private keys never leave the device. That choice is not an undertaking not to exploit a user directory. It is a choice not to build one. A production order addressed to infrastructure that does not hold the information does not produce a refusal, it produces a void.&lt;/p&gt;
&lt;p&gt;The distinction deserves to be stated honestly, because it decides everything. A privacy policy, however sincere and however well drafted, is a declaration of intent backed by a company, by its shareholders of the moment and by the jurisdiction in which it is established. Those three things change. An architecture that does not collect does not change because a board changes. It is the same shift we described in relation to &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;collecting today for decryption later&lt;/a&gt;: the risk does not sit at the moment the promise is made, it sits at the moment somebody else decides.&lt;/p&gt;
&lt;p&gt;The law takes time to absorb that distinction, and the debate on legal privilege gives a good measure of it. The same goes for the &lt;a href=&#34;https://arpokrat.com/blog/5g-location-data-privacy-law/&#34;&gt;protection of location data&lt;/a&gt;, where most of the legal construction bears on access to data whose existence is never questioned.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Case law will eventually settle. Appellate courts will resolve the split, regulators will publish criteria, firms will adjust their engagement letters and their clauses. None of that is in doubt.&lt;/p&gt;
&lt;p&gt;But the underlying question will not be settled that way, because it is not really about legal privilege. It is about whether a legal order can recognise that a thing knows, without ever having to say who answers for what it does with that knowledge.&lt;/p&gt;
&lt;p&gt;As long as that question stays open, the only variable a user genuinely controls is not the quality of the undertakings given to them. It is the amount of information they let exist.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This article offers a general legal analysis intended for discussion. It does not constitute legal advice or a legal opinion.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;United States District Court for the Eastern District of Michigan, Warner v. Gilbarco Inc., 10 February 2026, &lt;a href=&#34;https://www.proskauer.com/alert/michigan-federal-court-protects-ai-assisted-litigation-work-product&#34;&gt;Proskauer analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;United States District Court for the Southern District of New York, &lt;a href=&#34;https://harvardlawreview.org/blog/2026/03/united-states-v-heppner/&#34;&gt;United States v. Heppner&lt;/a&gt;, 10 February 2026, written opinion of 17 February 2026&lt;/li&gt;
&lt;li&gt;United States District Court for the District of Kansas, &lt;a href=&#34;https://law.justia.com/cases/federal/district-courts/kansas/ksdce/2:2025cv02352/158740/152/&#34;&gt;Jefferies et al. v. Harcros Chemicals Inc. et al.&lt;/a&gt;, no. 2:25-cv-02352, 25 March 2026&lt;/li&gt;
&lt;li&gt;Conseil national des barreaux, &lt;a href=&#34;https://cnb.avocat.fr/actualite/le-cnb-adopte-un-guide-sur-la-deontologie-et-l-intelligence-artificielle&#34;&gt;The CNB adopts a guide on ethics and artificial intelligence&lt;/a&gt;, 17 March 2026&lt;/li&gt;
&lt;li&gt;Baker McKenzie, &lt;a href=&#34;https://resourcehub.bakermckenzie.com/en/resources/global-attorney-client-privilege-guide/europe-middle-east--africa/france/topics/07---artificial-intelligence&#34;&gt;Global Privilege and Professional Secrecy Guide, France, Artificial Intelligence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CCBE, &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/DEONTOLOGY/DEON_CoC/EN_DEONTO_2021_Model_Code.pdf&#34;&gt;Model Code of Conduct for European Lawyers&lt;/a&gt;, 8 October 2021&lt;/li&gt;
&lt;li&gt;CCBE, &lt;a href=&#34;https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20251002_CCBE-guide-on-the-use-of-the-use-of-generative-AI-for-lawyers.pdf&#34;&gt;Guide on the use of generative AI by lawyers&lt;/a&gt;, 2 October 2025&lt;/li&gt;
&lt;li&gt;European Parliament, &lt;a href=&#34;https://www.europarl.europa.eu/doceo/document/TA-8-2017-0051_FR.html&#34;&gt;Resolution of 16 February 2017 with recommendations to the Commission on Civil Law Rules on Robotics&lt;/a&gt;, 2015/2103(INL)&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://robotics-openletter.eu/&#34;&gt;Open Letter to the European Commission on Artificial Intelligence and Robotics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;EAPIL, &lt;a href=&#34;https://eapil.org/2025/10/09/european-commission-withdraws-two-proposals-assignments-of-claims-regulation-and-ai-liability-directive/&#34;&gt;European Commission Withdraws Two Proposals: Assignments of Claims Regulation and AI Liability Directive&lt;/a&gt;, 9 October 2025&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://eur-lex.europa.eu/eli/dir/2024/2853/oj&#34;&gt;Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>5G, Location Data and the Law&#39;s Targeting Error</title>
      <link>https://arpokrat.com/blog/5g-location-data-privacy-law/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/5g-location-data-privacy-law/</guid>
      <description>&lt;p&gt;In 2011, Detroit police asked a mobile operator for the cell site records of Timothy Carpenter&amp;rsquo;s phone. They obtained 12,898 location points spread over 127 days, around a hundred a day. Seven years later, the Supreme Court of the United States held that the request amounted to a search and required a warrant.&lt;/p&gt;
&lt;p&gt;Those 12,898 points came from fourth-generation towers, each covering a radius of several kilometres. The same request, addressed today to an urban 5G network, would not return a hundred points a day accurate to a few kilometres. It would return a far larger volume, accurate to a few dozen metres.&lt;/p&gt;
&lt;p&gt;The technology has changed scale. The legal reasoning has stayed at the same point in the chain.&lt;/p&gt;
&lt;h2 id=&#34;a-legal-interest-that-judges-recognise-on-both-sides-of-the-atlantic&#34;&gt;A legal interest that judges recognise on both sides of the Atlantic&lt;/h2&gt;
&lt;p&gt;There is an interest almost everyone accepts and almost no legal text protects effectively: the right to be somewhere without that fact being recorded.&lt;/p&gt;
&lt;p&gt;European case law established it unambiguously. In &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt; (joined cases C-293/12 and C-594/12, 8 April 2014), and then in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt; (joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016), the Court of Justice of the European Union held that such data, taken as a whole, allow very precise conclusions to be drawn concerning people&amp;rsquo;s private lives: daily habits, places of residence, movements, activities carried out and social relationships.&lt;/p&gt;
&lt;p&gt;The Supreme Court of the United States reached a comparable conclusion in &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296 (2018). It stressed a point American scholarship has commented on at length: the &lt;strong&gt;inescapable and automatic&lt;/strong&gt; nature of that collection. Nobody consents to being attached to a cell tower; you are attached because you own a phone that is switched on.&lt;/p&gt;
&lt;p&gt;The legal interest therefore exists, and it is recognised by the two courts that matter in this field. The problem lies elsewhere.&lt;/p&gt;
&lt;h2 id=&#34;what-5g-actually-changed&#34;&gt;What 5G actually changed&lt;/h2&gt;
&lt;p&gt;A common confusion treats location as data the phone transmits, in the same way as a message or a photograph. It is not. Location is a &lt;strong&gt;physical consequence of how the network works&lt;/strong&gt;. The operator knows which tower the device is attached to because it has to know in order to route a call. There is no key with which to encrypt that information, because it is not content but a property of the connection itself.&lt;/p&gt;
&lt;p&gt;That is precisely what makes 5G significant in legal terms rather than technical ones.&lt;/p&gt;
&lt;p&gt;Earlier architectures relied on wide cells. A 4G tower commonly serves a radius of several kilometres, and the position inferred from attachment alone was measured in hundreds of metres in cities, sometimes in tens of kilometres in rural areas. 5G rests on massive densification: urban cells typically cover a few hundred metres, and the engineering literature works with densities on the order of forty to fifty base stations per square kilometre, against four or five in the 3G era.&lt;/p&gt;
&lt;p&gt;The consequence is mechanical. According to &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;Ericsson&amp;rsquo;s white paper on 5G positioning&lt;/a&gt;, infrastructure deployed for connectivity alone reaches an accuracy of twenty to fifty metres outdoors and one to three metres indoors, dropping below a metre in favourable urban conditions. This is not a location feature switched on somewhere, but what the network knows by construction, with no application installed and no permission granted. We set out all of these mechanisms, along with the countermeasures that actually work, in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;how your phone tracks your location&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The intrusion has therefore grown by several orders of magnitude. The applicable legal framework remains the one designed for 2G and 3G. No normative adjustment has accompanied that change of scale.&lt;/p&gt;
&lt;h2 id=&#34;the-law-protects-access-not-generation&#34;&gt;The law protects access, not generation&lt;/h2&gt;
&lt;p&gt;European law carefully regulates who may access location data, on what conditions and under what supervision. Directive 2002/58/EC lays down the principle of confidentiality of communications, and the Court of Justice held, in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net&lt;/a&gt; (joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020), that Article 15(1) of that directive, read in the light of Articles 7, 8, 11 and 52(1) of the Charter, precludes the &lt;strong&gt;general and indiscriminate retention&lt;/strong&gt; of traffic and location data on a preventive basis. The Court nonetheless allowed framed derogations where a Member State faces a serious threat to national security that is genuine and present or foreseeable, subject to effective review.&lt;/p&gt;
&lt;p&gt;These are real protections, and it would be absurd to play them down. But they all come into play after the fact. They presuppose that the data exists and is retained, and then organise the conditions of its use.&lt;/p&gt;
&lt;p&gt;Yet if location is an unavoidable by-product of how the network operates, the relevant point of intervention is not confidentiality. It is &lt;strong&gt;persistence&lt;/strong&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;An instantaneous position, needed to route a communication and erased immediately afterwards, is not an instrument of surveillance. A history of positions kept for months is one, whatever access safeguards surround it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The difference between the two is not legal, it is architectural. And the European timetable makes the question urgent rather than theoretical. The Commission &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;withdrew the proposed ePrivacy Regulation&lt;/a&gt; in 2025, for lack of agreement between the co-legislators. It has since been working on a separate instrument on data retention for criminal purposes, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;announced for 2026&lt;/a&gt; and intended to harmonise national regimes that have grown disparate since the 2006 directive was annulled. In other words, the text that will set the regime for location metadata for a decade is being written right now, on the basis of reasoning conceived in the era of kilometre-wide cells.&lt;/p&gt;
&lt;h2 id=&#34;the-precedent-5g-created-for-itself&#34;&gt;The precedent 5G created for itself&lt;/h2&gt;
&lt;p&gt;The most interesting aspect of the file is that the right answer is already in the technical standard, but applied to a different object.&lt;/p&gt;
&lt;p&gt;Up to 4G, the subscriber&amp;rsquo;s permanent identifier, the &lt;strong&gt;IMSI&lt;/strong&gt;, travelled in the clear over the radio interface during attachment. That is what made &lt;strong&gt;IMSI catchers&lt;/strong&gt; possible, those fake base stations which, according to the &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Electronic Frontier Foundation&amp;rsquo;s reference description&lt;/a&gt;, transmit more strongly than legitimate towers in order to attract handsets and capture their identifier.&lt;/p&gt;
&lt;p&gt;Since Release 15 of the 3GPP specifications, published in 2019, 5G has offered an elegant answer. The permanent identifier, now called the &lt;strong&gt;SUPI&lt;/strong&gt;, can be replaced on the radio interface by the &lt;strong&gt;SUCI&lt;/strong&gt;, a concealed identifier obtained by encrypting the subscriber-specific part using elliptic curve cryptography, with the home operator&amp;rsquo;s public key. Only the home network, which holds the corresponding private key, can decrypt it. The result is unique on each computation, which prevents correlation from one session to the next.&lt;/p&gt;
&lt;p&gt;The logic adopted deserves to be underlined, because it is exactly the logic that should guide lawmakers: you do not encrypt the position, which would be technically impossible, you encrypt the identity. A position with no attachable identity has very limited value for individualised surveillance.&lt;/p&gt;
&lt;h3 id=&#34;the-flaw-an-optional-protection&#34;&gt;The flaw: an optional protection&lt;/h3&gt;
&lt;p&gt;There is, however, a considerable caveat, and in our view it is the most concrete point of intervention in the whole file.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;NIST CSWP 36A white paper&lt;/a&gt;, published in March 2026 by the National Institute of Standards and Technology, states it bluntly. Handsets and network functions compliant with Release 15 or later are required to &lt;strong&gt;support&lt;/strong&gt; the SUCI, but enabling it remains &lt;strong&gt;optional for the operator&lt;/strong&gt;. Three conditions must be met: the equipment vendor must support it, the operator must enable it on its network, and the SIM card must carry the elements needed for the computation.&lt;/p&gt;
&lt;p&gt;A configuration trap comes on top of that. The standard provides for a &lt;strong&gt;null protection scheme&lt;/strong&gt;, in which the SUCI format is formally used but without effective encryption, so that the identifier travels in the clear. NIST writes that operators need to configure their networks with a non-null protection scheme, and recalls that a report by CSRIC, the advisory body of the Federal Communications Commission, recommended as early as 2021 that the null scheme be reserved for emergency calls placed by a handset unknown to the network.&lt;/p&gt;
&lt;p&gt;The formulation is worth stating plainly. The best available protection against mobile device tracking has existed in the technical standard since 2019. It rests on a configuration choice left to the operator&amp;rsquo;s discretion. An American federal agency finds it useful to publish a document in 2026 to remind everyone that it ought to be switched on. And no European legal instrument requires it.&lt;/p&gt;
&lt;p&gt;It should be added that the SUCI does not close the subject. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt; documents linkability attacks that allow sessions to be recorrelated despite the encryption, and the protection falls entirely if the attacker forces the handset to downgrade to an earlier generation. A legal obligation would therefore not settle everything. It would nonetheless remove a gap with no defensible justification: the one between what the standard allows and what commercial networks do.&lt;/p&gt;
&lt;h2 id=&#34;three-coherent-interventions&#34;&gt;Three coherent interventions&lt;/h2&gt;
&lt;p&gt;If we take seriously the idea that location should be minimised by design rather than protected after the fact, three measures follow logically.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Make effective concealment of the identifier mandatory.&lt;/strong&gt; Require the SUCI to be enabled and prohibit null protection schemes on commercial networks, apart from the residual case of emergency calls. This is not about prescribing a new technology, or funding a rollout, but about requiring the activation of a function standardised seven years ago and already present in the equipment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Treat retention as the exception, not the default.&lt;/strong&gt; The position needed to route a communication should be erased as soon as that function is fulfilled. Building a history should call for specific justification. That is the difference between a network that knows where you are and a network that remembers where you have been.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Make custody of the key the relevant connecting factor.&lt;/strong&gt; Locating servers in the Union does not mean much if the keys that make the data intelligible are held elsewhere. The legally significant criterion should be effective control of the means of decryption, a question we examined in detail in relation to the &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;conflict between the Data Act and the CLOUD Act&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-angle-arpokrat-follows&#34;&gt;The angle Arpokrat follows&lt;/h2&gt;
&lt;p&gt;This reasoning is not specific to telecommunications law. It is the one we apply to our own architectural choices, and it fits in a sentence: what has not been produced does not need to be protected.&lt;/p&gt;
&lt;p&gt;That is why &lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt; removes GPS, Bluetooth and NFC at kernel level rather than disabling them in a menu. A switch is a policy: it can be bypassed by a privileged component, re-enabled by an update, ignored by a compromised system. Removing the code path removes the question. It is the transposition, at device scale, of the same shift we are calling for at the scale of the law: intervening on generation rather than on access.&lt;/p&gt;
&lt;p&gt;It must be said straight away what this does not do. No operating system removes a handset from the geometry of the network. As long as a SIM card is active, the operator knows the serving cell, and routing all traffic through Tor changes nothing, since it protects content and destination, not the radio layer. That is precisely why the subject is a legal one. There is a category of risks that no individual configuration reduces, and for which the only available variable is the rule applicable to the operator.&lt;/p&gt;
&lt;p&gt;The same concern governs the rest of our work. Data that does not exist cannot be requisitioned, resold, exfiltrated, or decrypted ten years from now by a machine nobody has today, a question we addressed from the angle of &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;encryption harvested now and broken later&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Public debate on mobile surveillance focuses almost exclusively on access: who can consult the data, on what basis, with what authorisation. That debate is legitimate, and the rulings handed down by the Court of Justice since 2014 have had tangible effects. But it comes too late in the chain.&lt;/p&gt;
&lt;p&gt;The prior and more decisive question is whether the history should exist at all. A database built today for a legitimate purpose remains available tomorrow for another, and the safeguards around it depend on later political decisions that nobody controls at the moment of collection. It is a bet on the stability of institutions, made for a period nobody sets.&lt;/p&gt;
&lt;p&gt;5G has multiplied the resolution of this information without any normative adjustment. It has simultaneously shown, through the SUCI mechanism, that the workable path is to dissociate position from identity rather than attempt to encrypt a physical property of the network. The technical standard supplied the answer seven years before the law asked the question.&lt;/p&gt;
&lt;p&gt;The European text on data retention is being written now. It will deal with metadata, therefore with location, therefore with what 5G now produces at a granularity its drafters never knew. Whether it will settle for organising access to a history taken for granted, or dare to question the necessity of that history, is probably the most important privacy question of the coming years in Europe. And it is a question the technical sector, for once, has already settled the right way.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt;, joined cases C-293/12 and C-594/12, 8 April 2014&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt;, joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net and Others&lt;/a&gt;, joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020&lt;/li&gt;
&lt;li&gt;Supreme Court of the United States, &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296, 2018&lt;/li&gt;
&lt;li&gt;National Institute of Standards and Technology, &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;Protecting Subscriber Identifiers with Subscription Concealed Identifier (SUCI)&lt;/a&gt;, NIST CSWP 36A, March 2026&lt;/li&gt;
&lt;li&gt;Ericsson, &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;5G positioning: Locating devices anywhere&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Gotta Catch &amp;lsquo;Em All: Understanding How IMSI-Catchers Exploit Cell Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Digital Rights, &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;The ePrivacy Regulation proposal has been withdrawn, but the fight for your privacy is far from over&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;heise online, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;Data Retention: Commission to present proposal by mid-2026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
  </channel>
</rss>