Automated content moderation is now permanent infrastructure — and the EU AI Act's transparency rules are the accountability lever nobody is using yet.
elcome to issue eleven. This week the story that kept demanding our attention is not a fine or a deadline, but a structural admission: automated moderation is no longer a temporary crisis fix, it is permanent infrastructure, and accountability has not kept pace. We also have the European Commission quietly choosing Big Tech lock-in over interoperability, which tells you something about where enforcement energy is going. Strap in, there is a lot to chew through.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We updated the Flux compliance scan checklist to flag automated content moderation tools as a category requiring explicit transparency and appeals-path documentation under the AI Act.
- Updated The Flux vendor tracker now includes a note on Google's reCAPTCHA Mobile Verification scheme and its potential implications for operators running AI tools on Android-based edge devices.
- ICYMI Last week's issue on the US Supreme Court's location-data ruling is still worth a read if you have any AI logistics or movement-tracking tools in your stack — the compliance questions it raises have not gone away.
Automated content moderation is permanent infrastructure now, and the EU AI Act's transparency rules are the only accountability tool on the table

Six years ago platforms promised automated moderation would be temporary. According to EFF's two-part series published this week, those crisis-era protocols never left. Meta's own leaked documents showed its terrorist-content detection algorithms incorrectly removed nonviolent Arabic-language content 77 percent of the time, while simultaneously failing to catch actual hate speech. The systems stayed. The accountability did not.
For EU operators, this is not an abstract concern. Any business deploying AI to moderate content, flag users, or make automated decisions affecting people's access to services sits squarely in the EU AI Act's high-risk and transparency categories. The Act requires these systems to be logged, explained, and contestable. Right now most of them are none of those things, and that gap is where enforcement will eventually land.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓European Commission declined to mandate full interoperability between social platforms, drawing criticism from digital rights groups who say it entrenches Big Tech gatekeeping.
- ✓No new AI Act implementing measures published this week, but the automated moderation accountability gap highlighted by EFF maps directly onto existing Act obligations that are already in force.
- ✓EU users remain subject to platform moderation systems that are opaque by design, with no new Commission guidance on how the Act's transparency rules apply to third-party moderation tools.
- ~The US House passed the KIDS Act, bundling age-gating and content moderation mandates into one package; EFF is urging the Senate to reject it, arguing it harms privacy more than it protects children.


- 1EFF's Automated Moderation SeriesAccountability
A two-part deep dive into how automated moderation became permanent infrastructure and what accountability should look like.
Why we like it. Gives you the factual grounding to push back on vendors who claim their moderation AI is exempt from transparency requirements.
- 2EU AI Act Article 13 Plain TextRegulation
The transparency obligations that apply to high-risk AI systems, including logging, human oversight, and explainability requirements.
Why we like it. If you are deploying any automated decision tool, this is the article your lawyers and engineers need to read together, not separately.
- 3AlgorithmWatch EU AI Act TrackerMonitoring

Permanent infrastructure deserves permanent accountability, and that starts with you
By John Ferguson
The EFF series this week crystallised something I have been circling for months. We talk about AI systems as if they are experiments, pilots, or temporary fixes. We use language like 'we are testing this' and 'we will review it quarterly.' But the evidence suggests that once an automated system is in production, it tends to stay there, long after the original justification expires.
Meta's 77 percent error rate on Arabic content is not a historical curiosity. It is a live case study in what happens when accountability does not keep pace with deployment. Those systems are still running in some form. The EU AI Act exists precisely to prevent that pattern from becoming the default.
Here is the practical implication for anyone reading this: if you are deploying an automated decision tool today, assume it will still be running in five years. Design the logging, the appeals path, and the human oversight mechanism as if they are permanent, because they probably are.
The 503 days until the high-risk AI deadline feels like a long runway. It is not. If your vendor cannot tell you today how their moderation or decision system logs its outputs and handles contestation, that is a conversation to have before the deadline, not after.
John Ferguson · Founder, Agentic Fluxus

Short answer.Both of you carry obligations, but yours are different. The vendor must meet transparency and documentation standards for the model itself. You, as the deployer, must ensure users can contest automated decisions, that there is meaningful human oversight, and that you can produce logs if a regulator asks. Signing a contract with a vendor does not transfer your compliance responsibility away.
Does your organisation have a documented appeals or review process for automated decisions made by AI tools?

Meta's own internal documents showed its AI removed nonviolent Arabic-language content at a 77 percent error rate while missing actual hate speech. The system stayed in production for years after the leak.
A Texas sheriff's office queried the feeds of more than 83,000 automated licence plate readers to locate a woman suspected of self-managing an abortion. The cameras were marketed as tools for finding stolen vehicles.

