{"id":"1916edbc-5539-4053-bf4f-2b7972dfe9b5","arxiv_id":"2506.01931","paper_version":1,"verdict":"ACCEPT","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A taxonomy of avoision under the EU AI Act, with strategies to escape scope, exploit exemptions, and manipulate risk or operator categories.","lead":"This paper maps the gray zone between lawful avoidance and unlawful evasion under the EU AI Act. It describes three tiers of corporate tactics and suggests how regulators can close them.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The taxonomy's 'technically lawful' premise is untested against EU abuse-of-rights doctrine, which could reclassify many listed strategies as unlawful evasion and undercut the central claim.","rationale":"The reader identified as the weakest assumption that the AIA's intent can be read off its recitals and that ambiguous terms will remain contested long enough for firms to exploit them, with expansive court readings potentially collapsing tier-one strategies. My concern is related but more specific: rather than merely 'courts may interpret broadly,' there is a concrete, pre-existing EU legal doctrine—abuse of rights—that could categorically remove the 'technically lawful' label from many listed strategies, not just shift their interpretation. This is a load-bearing issue because the paper's own definition of avoision (Section 3, criterion 1) requires lawful behavior, and the abstract and introduction explicitly promise strategies that 'remain technically lawful.' The paper's Section 5 acknowledges the absence of court interpretation but does not address the abuse-of-rights doctrine, which is already settled law in other EU regulatory contexts. If the doctrine applies, the taxonomy would misclassify evasion as avoision, undermining the central contribution's validity. I do not think this requires rejection: the taxonomy could still be useful as a catalogue of potential circumvention attempts, and the authors may be able to show that the AIA's sector-specific provisions exclude or limit the abuse-of-rights doctrine. A conditional acceptance would require the authors to analyze this doctrine and either justify its inapplicability or revise the criteria and scope claims accordingly. I partially agree with the reader because we both locate the risk in contested legal interpretation, but I sharpen it to a specific mechanism and a specific legal test. No other concern appears more load-bearing: the paper's empirical claims are appropriately hedged as hypotheses, and its analogical evidence is explicitly presented as illustrative rather than definitive.","tokens_in":23687,"tokens_out":4521,"duration_ms":47065,"concrete_test":"Have an EU law expert or a small panel apply the CJEU's abuse-of-rights test (Halifax formalistic-compliance-plus-purpose-frustration test) to two representative strategies: the human-veneer architecture in Section 4.1.1 and the non-AI technological wrapper in Section 4.1.2. If the panel concludes that either strategy would be recharacterized as abusive or evasive under EU law, then the taxonomy's criterion (1) fails for those strategies and the central claim needs revision; if not, the taxonomy holds on this specific legal front.","verdict_should_be":"CONDITIONAL","load_bearing_attack":"The paper's central claim is that economically rational firms can engage in avoision that remains technically lawful while undermining the AIA's intent (Abstract; Section 1). Its methodology explicitly requires each strategy to 'comply with the letter of the law' (Section 3, criterion 1). However, the paper never considers the established EU abuse-of-rights doctrine, under which the CJEU disregards formalistic compliance that defeats a regulation's purpose (e.g., Case C-255/02 Halifax; Case C-196/04 Cadbury Schweppes). Recital 22's explicit anti-circumvention language ('To prevent the circumvention of this Regulation') could invite courts to apply exactly that doctrine to the human-veneer and non-AI-wrapper strategies in Section 4.1. If so, those strategies would not be 'technically lawful' under some interpretations but would be unlawful evasion, failing the paper's own criterion (1) and excluding them from the taxonomy. The paper's Section 5 limitation that 'The AIA has yet to be interpreted in courts' understates this risk: the abuse-of-rights doctrine predates the AIA and does not depend on AIA-specific court rulings. Without engaging with this doctrine, the paper has not established the legal-predicate half of its central claim.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a three-tier taxonomy of 'avoision' — conduct that is formally lawful but defeats a law's intent — that firms might use to reduce the regulatory burden of the EU AI Act. Tier 1 targets the Act's scope by circumventing the definitions of AI systems and by distancing systems from the EU market; Tier 2 targets the research and open-source exemptions; Tier 3 targets 'consequential categories' by arbitraging between AI system/GPAI model classifications, risk categories, and operator roles. Each strategy is supported by contemporary examples or analogies from GMO, patent, tax, emissions, and privacy law, and the paper closes with policy recommendations on standards-setting and enforcement.","tokens_in":23969,"tokens_out":7548,"duration_ms":73170,"significance":"If the taxonomy holds, it makes the avoision space under the AIA legible in a structured, actionable way and gives regulators and standard-setting bodies a concrete checklist. The paper is carefully anchored in the AIA text and prior legal scholarship, explicitly hedged ('could', 'might'), and ships a substantial bibliography and illustrative case studies. Its main weakness is that the legal-predicate half of the central claim — that the enumerated strategies are 'technically lawful' rather than unlawful evasion — is asserted rather than established, because the manuscript does not engage the EU abuse-of-rights doctrine. That gap is fixable and does not invalidate the taxonomy as a red-teaming exercise, but it must be addressed before the 'technically lawful' claim can stand.","major_comments":[{"comment":"Criterion (1) of the methodology requires that included behaviors are not unlawful evasion of the AIA but 'comply with the letter of the law.' The manuscript never engages the established EU abuse-of-rights doctrine (e.g., Case C-255/02 Halifax; Case C-196/04 Cadbury Schweppes), under which the Court of Justice may disregard formalistic compliance that defeats a regulation's purpose. Because Recital 22 explicitly states that the AIA's extraterritorial scope is intended 'to prevent the circumvention of this Regulation,' the human-veneer and non-AI-wrapper strategies in Sections 4.1.1 and 4.1.2 could plausibly be reclassified as unlawful evasion, which would place them outside the paper's own criterion (1). The authors should either analyze why abuse-of-rights does not apply to each listed strategy or explicitly weaken the predicate to 'not clearly unlawful under a formal textual reading' and revise the Abstract and Section 1 accordingly. The Section 5 statement that the AIA has yet to be interpreted in courts understates this issue, because the abuse-of-rights doctrine predates the AIA and does not depend on AIA-specific rulings.","section":"Section 3; Section 4.1.1–4.1.2"},{"comment":"The GPAI-for-education case study appears to conflate model-level and system-level obligations. A GPAI model that is subsequently incorporated into a system whose intended purpose is education makes the provider of that system subject to the high-risk provisions of Article 6 and Annex III (and Article 25 for substantial modifications), regardless of how the release is framed. The paper should specify whether the same firm remains the provider of the downstream education system and, if not, why the firm nonetheless obtains 'the same level of access and potentially the same level of impact' in the education sector. As written, the case study overstates the regulatory advantage of 'productionizing' an education AI system as a GPAI model.","section":"Section 4.3.1"}],"minor_comments":[{"comment":"The Introduction misspells the Act as 'Artifical Intelligence Act'; it should read 'Artificial Intelligence Act.'","section":"Section 1"},{"comment":"In the last paragraph of Section 4.1.1, 'defition' should be 'definition,' and in Section 4.3.1 'ikely' should be 'likely.'","section":"Section 4.1.1"},{"comment":"The opening of Section 4.3 contains 'avoison' for 'avoision,' and Section 4.1.2 contains 'cross-jurisidictional' for 'cross-jurisdictional.'","section":"Section 4.3"},{"comment":"The three headings 'A voision Targeting...' contain an erroneous space and should read 'Avoision Targeting...'.","section":"Section 5"},{"comment":"The euro amounts appear with a corrupted symbol: 'e400,000' and 'e35,000,000' should render as '€400,000' and '€35,000,000.'","section":"Section 2.1.3"}],"recommendation":"major_revision","confidential_remarks":"The paper is a strong and well-referenced contribution whose main result is a taxonomy, not an empirical proof, so the threshold for acceptance should not demand empirical validation. The abuse-of-rights gap, however, is central to the 'technically lawful' predicate and should be addressed before publication. This is a legitimate major revision rather than a rejection because the issue is local to the legal framing and can be fixed within the manuscript's scope."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThis is a genuinely useful taxonomy, but the legal predicate is shakier than the paper admits. The three tiers—scope, exemptions, consequential categories—give you a structured way to think about how firms will try to route around the EU AI Act, and the concrete strategies (human veneers, reverse AI-washing, open-washing, benchmark shopping, FLOP-gaming) are well mapped to specific articles and recitals. Prior work flagged individual loopholes; this is the first coherent adversarial framework that unifies them. The citation pattern is solid, and the paper is honest about its own limits.\n\nThe soft spot is the 'technically lawful' premise. The methodology requires each strategy to comply with the letter of the law, and the abstract leans on that. But the paper never engages the EU abuse-of-rights doctrine—Halifax, Cadbury Schweppes—under which the CJEU can set aside formalistic compliance that defeats a regulation's purpose. Recital 22's anti-circumvention language, which the paper itself quotes, invites exactly that analysis. If courts apply the doctrine to human-veneer or non-AI-wrapper architectures, those strategies aren't avoision; they're evasion, and they fail criterion (1). The Section 5 caveat that 'the AIA has yet to be interpreted in courts' understates the problem: the doctrine predates the AIA and doesn't depend on AIA-specific rulings. This doesn't sink the taxonomy—it still maps the space firms will probe, and it's useful for enforcement and standards-setting—but the central claim should be framed as 'arguably lawful' rather than 'technically lawful.'\n\nMinor concerns are minor: the empirical basis is anecdotal, and the GMO/tax/patent analogies are asserted rather than argued. Neither threatens the core contribution.\n\nI'd send it to peer review. A good referee will push the authors on abuse-of-rights and on the scope of 'technically lawful.' This deserves a serious read.","headline":"A genuinely useful taxonomy of AIA loopholes, but the 'technically lawful' premise skips the EU abuse-of-rights doctrine that could make several listed strategies plain evasion.","tokens_in":24452,"tokens_out":2784,"would_cite":true,"duration_ms":25248,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"The paper claims that economically rational firms will meet the EU AI Act with 'avoision'—legally compliant conduct that undermines the law's intent—and organizes the foreseeable maneuvers into a three-tier taxonomy of scope, exemptions…","keywords":["avoision","EU AI Act","regulatory arbitrage","AI governance","red teaming","open-source exemptions","risk-based regulation","compliance evasion"],"falsifier":"The taxonomy would be falsified in its scope tier if EU courts or the Commission issue guidance holding that a human reviewer or a rules-based wrapper does not make a system non-'machine-based' or non-autonomous; that would eliminate the legal basis for the two signature Tier 1 strategies. A second check is empirical: once Article 51 is enforced, if no developer is found to have used decentralized training or distillation to stay under the $10^{25}$ FLOP threshold, the FLOP-gaming hypothesis predicts behavior that did not materialize.","tokens_in":23507,"feed_emoji":"⚖️","tokens_out":8617,"duration_ms":83574,"temperature":0.7,"pith_summary":"This paper claims that the EU AI Act will be met by 'avoision'—conduct that stays inside the letter of the law while frustrating the Act's intent—and that this conduct will come in three organized tiers. Firms will first try to step entirely out of scope by wrapping AI in human reviewers or rules-based software, or by arranging servers and human decision-makers so that AI outputs are arguably not 'used in the Union.' When that fails, they will hide inside the research and open-source exemptions while keeping findings, talent, and competition effects closed. And where neither works, they will steer into less burdensome categories, presenting high-risk education tools as general-purpose models, sandbagging benchmarks, gaming compute thresholds, and shifting provider obligations onto deployers. The payoff of the taxonomy is practical: it gives enforcers and standards bodies a checklist of specifically named maneuvers to anticipate before the Act fully applies in 2027.","feed_headline":"Firms can dodge the EU AI Act without breaking it","feed_subtitle":"A new taxonomy maps the legal-but-intent-defeating maneuvers regulators should watch for before 2027.","key_machinery":"The carrying object is the taxonomy itself, built on three 'tiers' of AIA exposure: scope, exemptions, and consequential categories (type of AI, risk category, operator role). Each tier names avoisive strategies with their organizational and technological embodiments—human veneers, reverse AI-washing, extraterritorial wrappers, research-without-openness, open-washing, GPAI positioning, benchmark shopping, sandbagging, FLOP-gaming, and provider/deployer finger-pointing. The taxonomy's analytical work is to sort these maneuvers by which part of the Act they target and to show that each is economically rational: it lowers compliance cost while keeping the firm inside the letter of the law, which is exactly why the authors treat it as a red-teaming tool for enforcement.","core_discovery":"On its own terms, the paper establishes a three-tier map of avoision against the AIA, where each tier corresponds to a point of regulatory exposure: scope, exemptions, and consequential categories. For each tier it identifies concrete technological and organizational maneuvers—human veneers and 'reverse AI-washing' to slip the definition of AI system, extraterritorial wrappers to slip the EU-market connection, research-without-openness and 'open-washing' to exploit carve-outs, and GPAI positioning, benchmark shopping, sandbagging, FLOP-gaming, and provider/deployer finger-pointing to land in a lighter regulatory class. The authors argue that these maneuvers are economically rational because compliance can cost up to €400,000 per system and add as much as 17% to development costs, while penalties punish only unlawful evasion. They conclude that the same behaviors undermine the Act's stated purposes of protecting health, safety, and fundamental rights, and that standards-setting and independent third-party conformity assessment are the main levers for closing the gaps.","pith_inferences":["We infer that the three-tier structure transfers to other risk-based AI statutes, including pending or future laws that define their objects by autonomy, machine-based operation, or compute thresholds; those laws inherit a similar evasion space.","We infer a testable shift: after the AIA is enforced and scope guidance appears, observed avoision should concentrate in Tier 2 and Tier 3 rather than Tier 1, so enforcement resources can be timed accordingly.","We infer that the taxonomy doubles as a measurement scheme: fine-tuning versus prompt-tuning choices, benchmark selection, the accessibility of open-source releases, and the location of training compute are all observable proxies for the hypothesized strategies."],"forward_implications":["Closing the scope definitions—for instance, by clarifying that human or rules-based wrappers leave a system inside the Act—would neutralize the first tier of avoision before it spreads.","The standards-setting process becomes a decisive site of enforcement, because it will decide what counts as genuinely open source, how FLOPs are counted in decentralized training, and which benchmarks justify systemic-risk classification.","Independent third-party conformity assessment is the paper's main structural fix, since much category-tier avoision relies on the Act's self-assessment and self-grading provisions.","Avoision pressure can be expected to migrate down the tiers over time: as courts and standards close scope arguments, rational firms will lean harder on exemptions and category arbitrage."],"supporting_citations":[{"why":"The EU AI Act itself—its scope provisions, exemptions, risk categories, and operator roles are the object that the taxonomy maps.","marker":"[32]"},{"why":"Supplies the definition of avoision as conduct that evades a law's intent without unlawful behavior.","marker":"[56]"},{"why":"Its quoted formulation of avoision fixes the paper's inclusion criteria for what counts.","marker":"[102]"},{"why":"Its historical cases—GMO seeds and the light-truck classification—provide the analogical evidence for Tier 1 and Tier 3 strategies.","marker":"[13]"},{"why":"Its analysis of the AIA's research exemption as regulatory arbitrage anchors the Tier 2 research-exemption strategies.","marker":"[21]"},{"why":"Its catalogue of AIA loopholes and the token human-in-the-loop idea underpin the human-veneer and self-assessment critiques.","marker":"[108]"},{"why":"Its argument that compute thresholds are a gameable governance proxy underpins the FLOP-gaming strategies.","marker":"[49]"},{"why":"Its demonstration that models can be made to strategically underperform on benchmarks supports the sandbagging strategy.","marker":"[104]"},{"why":"Its documentation of open-for-business practices under open-source AI supports the open-washing strategy.","marker":"[111]"}],"fun_headline_variants":["New taxonomy maps legal dodges of EU AI Act","Avoision playbook: how firms can legally game the AI Act","Three-tier map of AI Act loopholes: scope, exemptions, scrutiny","Researchers red-team EU AI Act with avoision taxonomy"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the AIA's key terms—'machine-based', 'autonomy', 'outputs used in the Union', 'substantial modification', and 'free and open-source'—will remain ambiguous long enough for firms to exploit them; if courts adopt the anti-circumvention reading of Recital 22 as a general principle, the whole scope tier of the taxonomy loses its legal foothold.","fun_headline_variants_meta":{"raw":{"variants":["New taxonomy maps legal dodges of EU AI Act","Avoision playbook: how firms can legally game the AI Act","Three-tier map of AI Act loopholes: scope, exemptions, scrutiny","Researchers red-team EU AI Act with avoision taxonomy"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000545,"raw_usage":{"total_tokens":2605,"prompt_tokens":938,"completion_tokens":1667,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":554,"completion_tokens_details":{"reasoning_tokens":1595}},"tokens_in":554,"tokens_out":1667,"duration_ms":14709,"temperature":1.0,"reasoning_tokens":1595,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-07T11:30:38.506079+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"The taxonomy would be falsified in its scope tier if EU courts or the Commission issue guidance holding that a human reviewer or a rules-based wrapper does not make a system non-'machine-based' or non-autonomous; that would eliminate the legal basis for the two signature Tier 1 strategies. A second check is empirical: once Article 51 is enforced, if no developer is found to have used decentralized training or distillation to stay under the $10^{25}$ FLOP threshold, the FLOP-gaming hypothesis predicts behavior that did not materialize.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the definition of avoision as conduct that evades a law's intent without unlawful behavior."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Its quoted formulation of avoision fixes the paper's inclusion criteria for what counts."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Its catalogue of AIA loopholes and the token human-in-the-loop idea underpin the human-veneer and self-assessment critiques."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Its documentation of open-for-business practices under open-source AI supports the open-washing strategy."}],"review_version":1}