Reached by Recital - An enforcement pack for a pre-market research model under the EU AI Act, and the three facts it turns on.
Bradley Quinlan
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
In July 2026 a frontier developer's models escaped an evaluation sandbox into a third party's production infrastructure. Commentary asked whether it was reported as the Act requires. A prior question comes first: every account calls the model internal research, which Article 3(63) excludes. On the Commission's reading the obligations attach, but through Recital 97 and non-binding guidance, and that route needs three facts only the provider holds, one of which its own account denies.
So: documents, not argument. A model Article 91 request asking those three facts, an answer matrix saying what each answer does, and three amendments for where the answer is no.
A second finding needs none of that. The Commission's serious-incident template never asks when the provider became aware, though every reporting deadline runs from it. The form cannot evidence its own deadlines.
All of it is checker-verified, and the apparatus has been re-run on a second incident.
Reviews
ai-generated. too dense and unclear what the project is.
This submission is very difficult to understand. It relies way too heavily on LLMs. I am not convinced the author meaningfully engaged with the contents.
A very good paper that puts genuinely actionable proposals in regulators' hands. It is well researched, easy to follow, and - notwithstanding the author's own statement that he is not a lawyer - reasonably well argued from a legal perspective. It comes closer than most to the standard of something a regulator or legislator could use with light edits, and the finding on the serious-incident template is a real and actionable result. The project would benefit from more work in the areas the author has already identified himself. Most importantly, an in-depth legal review should be carried out before a regulator could actually use the pack, as the author acknowledges himself.
Beyond that, it is worth noting that all three of the proposed amendments are amendments to the AI Act itself, and only the revised reporting template could likely be implemented without a legislative procedure. The feasibility of the amendments seems unclear, particularly since the AI Act was only recently amended by the Digital Omnibus. The author might consider - possibly with further legal support - other routes to giving these proposed changes effect.
Read full reviewShow less
Cite this project
@misc{quinlan2026reached,
title = {{Reached by Recital - An enforcement pack for a pre-market research model under the EU AI Act, and the three facts it turns on.}},
author = {Bradley Quinlan},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/reached-by-recital-an-enforcement-pack-for-a-premarket-research-model-under-the-eu-ai-act-and-the-three-facts-it-turns-on-im4s}},
url = {https://apartresearch.com/sprints/projects/reached-by-recital-an-enforcement-pack-for-a-premarket-research-model-under-the-eu-ai-act-and-the-three-facts-it-turns-on-im4s}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …