At the end of August we published a post arguing that September was not going to be a quieter month. The reasoning was simple. August had a dated deadline attached to it, which made it feel like an event. September had no single headline moment, which makes a month feel optional. Obligations do not work that way. The ones already in force keep running, and the work they create does not pause because the calendar looks empty.
September is now over. This is the honest version of what changed, including on our own platform, and what is still sitting open.
What actually moved in the rules
Three things are worth carrying into October, and none of them are new obligations. They are clarifications of obligations that already existed.
A rights reservation has to be readable by a machine. A German court took the view that an opt-out written only in prose, in terms of service, does not do the job that the law expects of it. If the reservation is meant to stop text and data mining, it has to be expressed in a form a crawler can act on. That is a practical instruction, not a philosophical one, and it lands on whoever publishes the work rather than on whoever trains the model.
The opt-out is the rightsholder's job to express, and the provider's job to respect. These are two separate duties and they do not cancel each other out. A publisher who never expresses a reservation has not created an obligation for anyone else to honour. A provider who ignores an expressed reservation cannot point at the publisher.
Content credentials are still not evidence. More companies adopted provenance metadata over the summer, which is a genuinely good direction. It is still metadata attached to a file. It travels with the file, it can be stripped from the file, and it does not by itself tie the work to a person or fix the moment the work existed. Adoption is not the same as proof.
You can read our fuller treatment of the transparency duties on the EU AI Act page.
What changed on this platform
September was also the month the register side of this platform stopped being a plan and became something you can use. Four things went live together, and they are easier to understand as one flow than as four features.
Identity. A registration can now be tied to a person whose passport has been checked, rather than to whoever happens to hold the login. This is the piece everything else leans on. A timestamp can prove a file existed at a moment. It has never been able to say who made it.
Escrow storage in Switzerland. You can move your storage to Swiss escrow, and the files you already have move with you. After that, every folder you seal goes there on its own. The difference from a cloud drive is not the location, it is the release condition: a cloud folder opens for whoever has the password, and an escrow deposit is handed back to a person whose identity was verified. Two things are worth knowing before you switch, because they are not obvious. The move takes your existing files with it, and it does not reverse.
An ISCC on declared files. A hash proves a file is byte for byte the file you sealed. It says nothing once that file is resized, re-saved or re-encoded, because at that point it is a different file. An ISCC is a code for the work rather than the container, so a copy can still be recognised as your work later. It is an international standard, ISO 24138, and it is written into your proof certificate. Some formats cannot be fingerprinted, and those files are still sealed and timestamped, they simply carry no code.
Content labels. Every file you seal now carries one label saying what part AI played in making it. There are six to choose from. Four describe the work and two describe the person behind it. The choice is fixed once you seal the folder, which is the point: a label nobody can quietly change afterwards is worth more than one that can.
We wrote about the register opening here.
What is still open
Two things are genuinely unfinished, and it is more useful to say so than to imply the month closed cleanly.
Digital identity wallets. The European Commission's own position is that Member States are to make a wallet available to citizens by the end of 2026. That is a quarter away, and for most organisations the relevant question is not the deadline itself but whether anything in their signing or onboarding flow assumes a wallet that does not exist yet.
The transparency duties keep applying. The marking and disclosure obligations under the AI Act's transparency article are already in force. They did not begin in September and they do not end in December. What changes over the next quarter is how much tolerance there is for having done nothing about them.
The check worth doing before October
In August we suggested a five minute check rather than a project. The same advice holds, with one addition.
Take one piece of work your organisation produced this month. Ask three questions about it. Can you show when it existed, in a form that does not depend on your own file server. Can you show who made it, in a form that does not depend on someone still having a login. Can you say what part a machine played in it, in a form you would be comfortable defending.
If the answer to any of those is no, that is the October task. It is smaller than it sounds, and it is considerably smaller now than it will be after somebody asks you the question in a dispute.
The deadline that matters is still the ongoing one
The argument we made in August has not changed. A dated deadline creates a burst of activity and then a gap. The obligations that actually generate work are the continuous ones, and they are indifferent to which month it is. September proved that by being a month with no single headline date and a considerable amount of change in it.
October will look the same. Treat it accordingly.






