Hi, I am not a lawyer, just a nerd. Something for our EU/UK friends to explore are the terms in the Data Processing Agreement (DPA) in the substack publisher agreement (https://substack.com/pa). On July 20, 2026 it appears substack added pangram as a sub-processor in annex 3 of the DPA. Substack did not include that update on what's changed at the top of the policy. Per the terms, any EU/UK based creator has 30 days to object to a new sub-processor being added. So the question is when was it added to the list? Well I went to the internet archive and pulled the publisher agreement from July 16, 2026. Pangram is not listed as a sub processor vendor (https://web.archive.org/web/20260716142429/substack.com/pa). So it is likely they were added on July 20, 2026 which I think means the 30 day objection window has started. I can't post screenshots here but I can to your note if you want to see the specific sections. LMK
Again not a lawyer just a hyper focused ADHD nerd. Thanks substack!
This is the reason why I embrace my ADHD. In one instant I will get bored with what I am writing about halfway through a sentence and then moments later I am able to read hundreds of pages of terms and legalise for 3 straight hours with no effort.
Here is my question as it is what plagues me, "what do you do when you get bored of one topic but have to finish something pertaining to it?" I love that I can do the focus part first but then the boredom and finishing thing kicks my ass.
Thank you for this post! As a European citizen, I’ve already sent the email you kindly shared, and I reserve the right to report the matter to the Italian Data Protection Authority (the Garante per la Privacy). I did not appreciate how this situation was handled, nor the witch hunt that is being encouraged by turning users into censors and relying on a tool that openly states its own fallibility.
What I disliked even more is the way personal data is being taken and used as if it were nothing.
I'm so glad you also lodged an objection request. Perhaps with enough of these, this will force a policy re-evaluation. It appears that pressure is already working, but it hasn't gone far enough.
I'm generally a proponent of European privacy mandates. And they always set the new threshold, starting with the deprecation of cookies. Then Google followed, then Apple, and now it makes following online browsers around more difficult. I work in marketing and I still applaud this.
The request is great but I would cut the "please" and you and I know that they will not send a receipt of confirmation... Also the CCPA articles applies too as well here..
1. Having been on the side of the fence receiving data subject requests, including objection requests, courtesy goes a long way. Being a dick doesn't get back at the company. You just make the DPO or the ops team a little sadder.
2. Most of the help desk systems are automated, and they did send a receipt of confirmation. Mostly useless, though, I'll admit.
3. The opt-out right does not apply in cases where the sharing is between a business and it's service provider who is performing a service on behalf of the business. It's also not behavioral advertising. So, unfortunately, the CCPA isn't much of an option.
A reminder that the US really could do for more robust privacy laws!
Just to amplify a point you make: GDPR applies in the EU and EEA, or if an entity targets residents of those jurisdictions. Anyone wishing to submit a complaint from outside of the EU/EEA would want to note that their data is being intentionally made available to consumers in that jurisdiction. The other issue that I'd emphasis is the key GDPR requirement of prior consent; it is not obvious that the means made available for opting out would satisfy that requirement (generally providing a means to 'opt out' of something doesn't meet the standard).
Almost nobody is asking: Why is AI reading, scanning, analysing, classifying, and judging everything we write?
That is the bigger concern for me.
I always turn off AI scanning on my articles. I do NOT consent to having my writing processed and classified by an AI detector.
I worked in QA and document control in highly regulated industries, so my mind immediately goes to the questions people seem to be ignoring:
* What exactly is being processed? * Who approved the process? * What is the legal basis? * Who has access? * What data is stored? * Are the full texts or scan results retained? * Are the scores connected to the writer or publication? * How long are the records kept? * Can the content or results be used to improve the system? * Can they later affect visibility, trust, moderation, or reputation? * What happens when the result is wrong, and is there a proper appeal process?
**And who really knows what data is being kept behind the scenes?**
People are so focused on proving that their writing is 100% human that they are barely questioning the fact that an AI system is scanning their human writing in the first place!
We are teaching language models to write more like humans while using another AI system to judge whether human writing sounds too much like AI.
I find it far more concerning to hand over my writing patterns and personal voice for AI systems to scan than to use AI consciously as a tool to help me express my own ideas.
I wrote my own before reading , but this template is pretty similar and approved by my friend working as a lawyer at the AEPD ( spanish data protection service : the ones we have to report those behaviors, there's one for every UE country )
One observation that concerns me: after I inserted photographs into my article, Pangram's score dropped from 95% human to 77% human. The article itself did not change. I wrote every word myself, and the photographs were my own original images taken with my personal Iphone camera. They were not AI-generated, edited, or enhanced in any way.
If adding my own unedited photographs can lower the reported "human" score, it raises questions about what Pangram is actually evaluating and how reliable these percentages are as an indicator of human authorship.
By checking my old published posts I can confirm that THEY HAVE AUTOMATICALLY ADDED THE AI INTEGRATION TO ALL OLD POSTS. Have to go into each one to manually disable. 😡
So what does that mean, did they say they weren't going to? I don't see how this is legal. They've applied it automatically, and also not notified users of this change. Why not from posts going forward from when it was added (not saying it should be there but damn, some on here have hundreds of posts, to then have to go and manually disable on every single one 😭)
Dear Carey, This is a masterclass in interrogating a 'feature' that is being mis-sold as 'trust' and showing us it's a liability multiplier. I'll definitely follow your updates keenly, and I hope this forces Substack to confront the asymmetry you've highlighted. You’ve effectively shown us how to demand the 'compelling legitimate grounds' they likely don’t have.
By invoking the GDPR articles, you’ve exposed exactly what I argued in my recent essay, ‘The Detector and the Discreditor’ (https://technologyforhumans.substack.com/p/the-detector-and-the-discreditor) that Pangram isn’t just a brittle tool; it’s an epistemic weapon deployed without consent. The founders of these tools have zero skin in the game. When Pangram's algorithm falsely flags a writer as an AI fraud, it is the writer who bears the full weight of reputational damage and the chilling effect of self-censorship.
If Pangram’s 'transparency' relies on processing personal data without a robust legal basis, then the tool isn’t protecting truth - it’s manufacturing it through a closed loop of statistical bias. Your objection doesn’t just opt you out; it threatens to dismantle the entire infrastructure of this 'quiet war' on creative and critical writing.
Worth noting how little of this the EU AI Act touches. A detection system on a publishing platform isn't in Annex III, and the Article 50 transparency duties run at whoever generates synthetic content, not at whoever claims to spot it. So the tool marketed as an authenticity safeguard sits almost entirely outside the AI-specific regime, and the only real leverage is the one you've used here. That pattern is going to keep repeating.
I'm not really surprised. I mean, until the Omnibus, NCII and CSEM were not listed as prohibited uses. They really ignored the worst use-cases.
I am wondering though, if there's an (admittedly weak) argument for including this particular use of Pangram as prohibited social scoring. And there's also potentially the DSA's content moderation rules, but again, a stretch. Others have flagged Brasil's ADM provisions, which I completely overlooked.
Hi, I am not a lawyer, just a nerd. Something for our EU/UK friends to explore are the terms in the Data Processing Agreement (DPA) in the substack publisher agreement (https://substack.com/pa). On July 20, 2026 it appears substack added pangram as a sub-processor in annex 3 of the DPA. Substack did not include that update on what's changed at the top of the policy. Per the terms, any EU/UK based creator has 30 days to object to a new sub-processor being added. So the question is when was it added to the list? Well I went to the internet archive and pulled the publisher agreement from July 16, 2026. Pangram is not listed as a sub processor vendor (https://web.archive.org/web/20260716142429/substack.com/pa). So it is likely they were added on July 20, 2026 which I think means the 30 day objection window has started. I can't post screenshots here but I can to your note if you want to see the specific sections. LMK
Again not a lawyer just a hyper focused ADHD nerd. Thanks substack!
Thank you for doing all this work, Steve.
This is the reason why I embrace my ADHD. In one instant I will get bored with what I am writing about halfway through a sentence and then moments later I am able to read hundreds of pages of terms and legalise for 3 straight hours with no effort.
Here is my question as it is what plagues me, "what do you do when you get bored of one topic but have to finish something pertaining to it?" I love that I can do the focus part first but then the boredom and finishing thing kicks my ass.
Another breach... Why am I not surprised.
Thank you for this post! As a European citizen, I’ve already sent the email you kindly shared, and I reserve the right to report the matter to the Italian Data Protection Authority (the Garante per la Privacy). I did not appreciate how this situation was handled, nor the witch hunt that is being encouraged by turning users into censors and relying on a tool that openly states its own fallibility.
What I disliked even more is the way personal data is being taken and used as if it were nothing.
I'm so glad you also lodged an objection request. Perhaps with enough of these, this will force a policy re-evaluation. It appears that pressure is already working, but it hasn't gone far enough.
https://substack.com/profile/331506166-signornumerotto/note/c-300810624
Wanting to give this situation more visibility, I wrote a note as a European citizen, tagging Substack’s CEO, Chris Best.
I'm generally a proponent of European privacy mandates. And they always set the new threshold, starting with the deprecation of cookies. Then Google followed, then Apple, and now it makes following online browsers around more difficult. I work in marketing and I still applaud this.
Google kinda started to do the right thing, then they backed out. Privacy sandbox is dead, though shifting from MAID to GBRAID was a useful change.
The request is great but I would cut the "please" and you and I know that they will not send a receipt of confirmation... Also the CCPA articles applies too as well here..
1. Having been on the side of the fence receiving data subject requests, including objection requests, courtesy goes a long way. Being a dick doesn't get back at the company. You just make the DPO or the ops team a little sadder.
2. Most of the help desk systems are automated, and they did send a receipt of confirmation. Mostly useless, though, I'll admit.
3. The opt-out right does not apply in cases where the sharing is between a business and it's service provider who is performing a service on behalf of the business. It's also not behavioral advertising. So, unfortunately, the CCPA isn't much of an option.
A reminder that the US really could do for more robust privacy laws!
Just to amplify a point you make: GDPR applies in the EU and EEA, or if an entity targets residents of those jurisdictions. Anyone wishing to submit a complaint from outside of the EU/EEA would want to note that their data is being intentionally made available to consumers in that jurisdiction. The other issue that I'd emphasis is the key GDPR requirement of prior consent; it is not obvious that the means made available for opting out would satisfy that requirement (generally providing a means to 'opt out' of something doesn't meet the standard).
Everyone is asking: Did AI write this?
Almost nobody is asking: Why is AI reading, scanning, analysing, classifying, and judging everything we write?
That is the bigger concern for me.
I always turn off AI scanning on my articles. I do NOT consent to having my writing processed and classified by an AI detector.
I worked in QA and document control in highly regulated industries, so my mind immediately goes to the questions people seem to be ignoring:
* What exactly is being processed? * Who approved the process? * What is the legal basis? * Who has access? * What data is stored? * Are the full texts or scan results retained? * Are the scores connected to the writer or publication? * How long are the records kept? * Can the content or results be used to improve the system? * Can they later affect visibility, trust, moderation, or reputation? * What happens when the result is wrong, and is there a proper appeal process?
**And who really knows what data is being kept behind the scenes?**
People are so focused on proving that their writing is 100% human that they are barely questioning the fact that an AI system is scanning their human writing in the first place!
We are teaching language models to write more like humans while using another AI system to judge whether human writing sounds too much like AI.
I find it far more concerning to hand over my writing patterns and personal voice for AI systems to scan than to use AI consciously as a tool to help me express my own ideas.
That is the real contradiction.
So true! I love this thought process. And yet it's actually scary what's happening real time 😭
It really is...
I wrote my own before reading , but this template is pretty similar and approved by my friend working as a lawyer at the AEPD ( spanish data protection service : the ones we have to report those behaviors, there's one for every UE country )
One observation that concerns me: after I inserted photographs into my article, Pangram's score dropped from 95% human to 77% human. The article itself did not change. I wrote every word myself, and the photographs were my own original images taken with my personal Iphone camera. They were not AI-generated, edited, or enhanced in any way.
If adding my own unedited photographs can lower the reported "human" score, it raises questions about what Pangram is actually evaluating and how reliable these percentages are as an indicator of human authorship.
Are they also going to steal our photographs and art?
I post articles with my art process, I hope they aren't stealing those, and also your photos. Very very concerning the more I learn.
That's absolutely wild, and further evidence that this is not a good tool for addressing the problem.
Wow - this is the most useful and practical post I have seen on the Pangram debate. Thank you so much.
Happy it's helpful!
Everyone should watch "The Capture" a 3 season series on Peacock!
If you think you understand deep fakes, you don't. You will after you watch this series.
We've learned that ai isn't always correct. Neither are ai detectors 🤔
False positives and false negatives don't just affect technology,; they can affect trust, reputation, and the relationships we are building online....
I have no intention of telling it to not scan my stuff I want it to try really really fucking hard to keep up with me I will bankrupt that company.
I will purposely post the most bizarre twisty tourney AI generated post possible and I will bankrupt them
😼
What about for posts already published? Do I have to go back in to them and change it, is the AI detection on automatically? Like this is ridiculous.
Thank you so much for adding all this info, how do we remove individually for notes or is it only posts that apply??
By checking my old published posts I can confirm that THEY HAVE AUTOMATICALLY ADDED THE AI INTEGRATION TO ALL OLD POSTS. Have to go into each one to manually disable. 😡
Yikes. So they even lied about the scope. *Sigh*
So what does that mean, did they say they weren't going to? I don't see how this is legal. They've applied it automatically, and also not notified users of this change. Why not from posts going forward from when it was added (not saying it should be there but damn, some on here have hundreds of posts, to then have to go and manually disable on every single one 😭)
Dear Carey, This is a masterclass in interrogating a 'feature' that is being mis-sold as 'trust' and showing us it's a liability multiplier. I'll definitely follow your updates keenly, and I hope this forces Substack to confront the asymmetry you've highlighted. You’ve effectively shown us how to demand the 'compelling legitimate grounds' they likely don’t have.
By invoking the GDPR articles, you’ve exposed exactly what I argued in my recent essay, ‘The Detector and the Discreditor’ (https://technologyforhumans.substack.com/p/the-detector-and-the-discreditor) that Pangram isn’t just a brittle tool; it’s an epistemic weapon deployed without consent. The founders of these tools have zero skin in the game. When Pangram's algorithm falsely flags a writer as an AI fraud, it is the writer who bears the full weight of reputational damage and the chilling effect of self-censorship.
If Pangram’s 'transparency' relies on processing personal data without a robust legal basis, then the tool isn’t protecting truth - it’s manufacturing it through a closed loop of statistical bias. Your objection doesn’t just opt you out; it threatens to dismantle the entire infrastructure of this 'quiet war' on creative and critical writing.
Good insight 😃. Can i translate this article into Spanish with links to you?
Absolutely! That would be amazing.
Many thanks !!!
I say scan away, snitches out after witches.
And then, show yourselves, if you have a shred of integrity.
So I can then block you.
Next case?
Worth noting how little of this the EU AI Act touches. A detection system on a publishing platform isn't in Annex III, and the Article 50 transparency duties run at whoever generates synthetic content, not at whoever claims to spot it. So the tool marketed as an authenticity safeguard sits almost entirely outside the AI-specific regime, and the only real leverage is the one you've used here. That pattern is going to keep repeating.
I'm not really surprised. I mean, until the Omnibus, NCII and CSEM were not listed as prohibited uses. They really ignored the worst use-cases.
I am wondering though, if there's an (admittedly weak) argument for including this particular use of Pangram as prohibited social scoring. And there's also potentially the DSA's content moderation rules, but again, a stretch. Others have flagged Brasil's ADM provisions, which I completely overlooked.