Nobody Ever Disclosed the Associate
Substack scans for AI now. The law asks a different question.
An associate spends two weeks on an article. Research, structure, argument, several drafts. A partner reads it, changes a heading, and the firm publishes it under his name.
This is not a scandal. It is how law firms, the Big Four, consultancies, politics and most of business have worked for as long as any of us have been in it. The named author supplied the judgment about whether the thing was right, and the accountability for it being wrong. The associate supplied the keystrokes.
And in ordinary commercial publishing, nobody has ever demanded a disclosure. No client alert has carried a line reading “100% written by our paralegal.” Formal rules do exist at the edges, where the stakes are personal: several US bars require a lawyer to disclose ghostwriting for a self-represented litigant, and academic authorship standards require contributors to be named. But for the alerts, the briefings and the thought leadership that make up most professional writing, nobody asked, because nobody thought the keystrokes were what they were buying.
Then the assistant stopped being a person, and suddenly the keystrokes are the only thing anyone wants to measure.
Two instruments now claim to deliver transparency about written work. One is law and has applied since August 2. The other is a button on this platform, live since July 21. They point at the same anxiety, they measure completely different objects, and if you write a newsletter it is worth knowing which one should actually matter you.
The Law: In the Version That Concerns Writers
I went through Article 50 in full last week, including what human review, editorial control and editorial responsibility mean in the European Commission’s reading. The provision that concerns anyone publishing text is the second subparagraph of Article 50(4). The first subparagraph is about deepfakes. The second one is about you.
Start with whether it reaches you at all, because a lot of people reading this are not in Europe. The AI Act binds deployers established or located in the Union, and deployers in third countries where the output of the system is used in the Union. A newsletter written in Ohio with subscribers in Dublin is not obviously outside that. Whether “output used in the Union” condition is met by EU readers opening an email is untested, and we don’t know yet how this will play out.
Then four questions, in the order the provision actually asks them.
The first one I skipped last week.
Article 50(4) applies to deployers of an AI system that generates or manipulates text. If nothing generated or manipulated your text, nothing that follows applies. So where does editing assistance stop and generation start? The AIAct does not say so.
Article 50(2), which governs marking by providers rather than disclosure by deployers, carves out systems performing an assistive function for standard editing, or not substantially altering the input data or its meaning. That carve-out sits textually in 50(2) and does not appear in 50(4). So the argument that polishing is not generating is available, and it is not airtight.
Second, are you a deployer? You are, if you use an AI system under your own authority in a professional capacity. The Commission draws the line at economic activity: a natural person who gains economic benefit on a regular basis, or is otherwise engaged in business, trade, occupational or freelance activity, is a deployer. Purely personal, non-professional use sits outside the EU AI Act entirely.
A newsletter for six friends is out. Paid subscriptions put you in. So does a free newsletter that feeds a consulting practice, or that you treat as professional work. That somebody else pays your salary is irrelevant to your own publication, which is your own professional activity. Inside your day job the analysis differs, because employees acting under a company’s instructions are not separate deployers.
Third, is it a matter of public interest? The European Commission’s list is illustrative rather than closed, and it runs through politics and democratic processes, public administration and services, the administration of justice and law enforcement, fundamental rights, public security, public health, the environment, consumer safety, and economic, financial, scientific and cultural developments relevant to public debate. Write about any of those seriously and you are inside it. There is no case law. There is guidance, which sets out a three-part test of published, informative to the public, and on a matter of public interest, and which does not tell you where the boundary runs.
Fourth, did a person examine the substance, and is a person answerable for it. That is the exemption, and it needs both parts at the same time.
However, the Commission’s guidelines are interpretive and not binding. Market surveillance authorities can be expected to follow them. The Court of Justice is the only body that decides what the AI Act means, and it has not been asked yet.
If you get this wrong the ceiling is €15 million or 3% of worldwide turnover, enforced by national market surveillance authorities. For a solo newsletter the realistic exposure is somewhere near nothing. The line still matters, because it is the only defensible thing you can say.
And the fourth question is the same question the partner was answering.
It has never required a disclosure.
The Platform: Live Since July 21
On July 21 Substack switched on AI detection built with Pangram. Any reader can open a post, tap three dots, choose Scan for AI text, and get an estimate of how much of it was human-written and how much was AI-assisted.
It works only on posts and Notes published on or after July 21. It runs in the Substack Reader on web and in the iOS app, with Android still to come, and it covers Notes in the feed plus individual comments and replies. Reported minimum lengths differ between outlets, and neither Substack’s help page nor the announcement gives a firm number, so treat any figure you have seen as unconfirmed.
Writers get two controls. A statement under Settings called “How I make this,” which surfaces to anyone who scans your work. And the option to disable detection on a given post, after which readers see “AI detection unavailable,” which is its own kind of answer.
The European Commission wrote a rule about editorial responsibility. Substack shipped a classifier that reads sentence patterns.
Both were called transparency.
What Happened When I Scanned My Own Work
My article on MS Copilot Agent, published on July 22, came back as fully AI-assisted text. The reading was 100%. That piece was researched by me, argued by me, experienced by me in my day job, checked line by line against the Commission’s guidelines, and rewritten repeatedly (one part of it I rewrote eight time) because the ambiguity at its centre would not land clearly enough.
I then scanned the AI Act Tracker. Same desk, same process, different week. 11% AI. 89% human.
The tempting conclusion is that the detector is broken.
I do not think that, and I would rather not build an argument on a claim that is convenient. Pangram publishes a false positive rate on the order of one in ten thousand. More usefully, an independent evaluation by Jabarian and Imas, written up by Chicago Booth Review, tested it against three competitors and found it the only detector holding what they call policy-grade accuracy across models, though performance degrades on very short passages.
So I guess it was doing its job both times, and between those two pieces the amount of AI assistance in the prose genuinely differed. Note the words the tool actually uses. It reports AI-assisted rather than machine-written, and it calls the figure an estimate rather than a verdict. Both of those are more careful than a round 100% makes them sound.
In my opinion that is the actual problem.
Both pieces went through the same editorial process. Both were verified against primary sources by a lawyer. Both carry my name, my judgment, and my liability if they are wrong. Under Article 50(4) they are indistinguishable, and I believe that both sit inside the exemption.
One scored 11%. The other scored 100%.
The number moved. My accountability did not.
The detector is not malfunctioning. It is answering a question the law does not ask. Article 50(4) wants to know whether a person examined the substance and whether a person is answerable for it. A classifier cannot see either, because neither is in the text.
What is in the text is rhythm, cadence and word choice.
Polish.
The least substantive layer of any piece of writing. Not the argument, not the structure, not whether the article number is right or the deadline is real.
Which is why the verdict and the obligation come apart in both directions. You can be compliant and flagged. You can also be non-compliant and clean, because a writer who pastes raw output, runs it through a rewording tool and publishes without reading it properly may well scan as human.
That writer is the one Article 50(4) was written for.
The Hole In the Tool
Substack’s own documentation says the scan is unavailable for video or audio posts, for posts viewed on standalone Substack sites including custom domains, and for emails.
Three exclusions, and the last two are the ones that reach you. This newsletter lives at ailawdecoded.com. Most of you are reading this in your inbox, because that is what a newsletter is.
In both of those places the label does not exist. No scan on the website, no scan in the email. The verdict is visible only to a reader who opens the piece inside the Substack Reader or the iOS app.
A transparency tool that cannot reach the publisher’s own website, and cannot reach the email that delivers the writing to the people who subscribed to it, has a fairly substantial gap where its transparency should be.
There is a third instrument, for completeness. The Commission’s Code of Practice on Transparency of AI-generated Content, finalized in June, covers the labelling duties in Article 50(4) and gives signatories an approved route to demonstrating compliance. It is built for platforms and generative AI companies rather than individual writers, and signing it is not a realistic move for a person with a newsletter. Worth knowing it exists before somebody tells you that you should have signed it.
So, the law measures editorial responsibility and cannot see how the text was made.
The detector measures how the text was made and cannot see who is responsible for it. And it only looks in one of the three places people read.
What Editorial Control Looks Like From the Inside
The practical question for a writer is not whether you use AI. It is whether you could describe your process to a reader, or a regulator, and have it clear the exemption.
Mine, in the detail the standard actually asks for:
Topics come from practice. From the work itself, and from questions readers leave in the comments. Nothing gets written because it would be easy to generate.
Every piece starts from a brief I write: the article numbers in play, the argument, the opening, the point the piece has to drive at. Then research, and verification of every claim against the regulation, the official guidance, and other lawyers’ readings of it. Where something cannot be confirmed, the draft says so, and that sentence survives into publication.
Then editing, which takes most of the time. Like I mentioned, a piece can go through eight rewrites. Not for typos. For the angle, for which points survived, for the closing. Seven versions may not be clear enough about an ambiguity that matters, so they don’t get to be published.
That is human review of the substance. Somebody with relevant knowledge decided what was true, what was arguable, and what was not going out, and my name is on the result, which means I hold the legal responsibility for every claim in it.
A classifier cannot see any of that. It sees the eighth version’s sentences and reports on their texture.
If you publish, there are three things worth doing:
Work out whether you are a deployer. That mostly means asking whether the newsletter is professional activity or a hobby, and answering honestly.
Decide whether your process would survive the description above. “AI drafts it, I skim it, it ships” does not, and that is the case the label exists for.
Write the process down. Substack now gives you somewhere to put it, under Settings, called “How I make this.” It is the voluntary version of a disclosure the law may or may not require of you.
Detection is on for this piece. Turning off the scanner on an article about AI disclosure would be indefensible, so whatever it returns is what it returns.
The associate was never the disclosure. The partner’s name was the disclosure, because the name carried the judgment and the liability. That has not changed. Only the assistant has.
I won’t apologize for using AI for my prose. You shouldn’t either.





What stands out to me is that the scanner does more than classify text. It teaches readers what to treat as evidence of authorship.
Once a percentage is attached to the prose, sentence texture becomes visible while judgment, verification, and responsibility remain hidden. Readers are encouraged to ask who produced the words rather than who decided what was true and accepted responsibility for publishing it.
A tool built for transparency may quietly be redefining authorship around production rather than accountability.