Uber's €825M Fine Is a Product Spec, Not a Privacy Story
The mechanics the Dutch regulator just priced shipped as permissively licensed open source the same week, which turns descoping them from a tradeoff into a choice.
Three spec lines, now priced
A user opened the app and found the account gone. No human name on the decision, no reason code on the screen, nowhere to object. Read the Dutch finding as a checklist rather than a headline. Three things were absent: a human reviewer before the account went dark, a reason code surfaced to the person it happened to, and a route to appeal. Those are lines in a product spec, and exactly the lines cut when an enforcement epic loses a prioritization fight to feature velocity. The ceiling above this penalty is Meta's €1.2 billion Irish fine from 2023, so the ladder has room to climb.
The second component is inherited liability. TikTok and ByteDance's $400 million settlement with the U.S. Department of Justice explicitly covers infractions committed by Musical.ly, acquired in 2017. Nine-year-old product behavior, attached to the acquirer. When a company buys a consumer product with minors in the user base, age assurance and retention practice belong in diligence, not the post-close backlog.
The mechanics went open source the same week
CopilotKit shipped OpenBot under MIT, organized around one computer per bot: each agent gets its own browser, logins and files, a gateway that evaluates policy and writes an audit row before the browser moves, and mid-task human takeover. Alibaba open-sourced OpenSandbox under Apache 2.0 within the same seven days: cold starts under 800 milliseconds, hardened runtimes via gVisor, Kata Containers and Firecracker, per-sandbox egress control, and a credential vault that injects secrets without exposing them to the workload. Claude Code, Gemini CLI, Codex CLI, Qwen Code and Kimi CLI already run inside it.
Two teams with no shared incentive converged on the same requirement list, and it is the list the regulator just enforced: decide before you act, record what you did, let a human take the wheel. OpenBot is tagged v0.0.1 and labeled alpha, so the pattern is the deliverable, not the package. Separate what was released from what was demonstrated. The planning consequence is blunt. What looked like several sprints of undifferentiated runtime work is now a two-day evaluation, and the compliance artifact it emits is the part a buyer actually pays for.
The same artifacts have a second buyer
Enterprise procurement asks for this evidence anyway. In the detailed mapping of the $100K+ deal cycle, identity and access infrastructure (SSO, SCIM, RBAC, audit logs) is the one high-severity failure mode where flawless sales execution still loses the deal. Immutable action logs and machine-readable reason codes answer the regulator and the security questionnaire with a single build. That is how the work gets funded without a compliance budget.
One caution for anything shipping an assistant. Varonis's CoSnitch (CVE-2026-24301) was a one-click Copilot path to corporate data theft, and Copilot itself surfaced the flaw to researchers during ordinary use. Treat broad read scope as an exfiltration primitive until a review proves otherwise. The forcing function fits on one line: read scope broad or narrow, on one axis, and every read logged before it happens, on the other. The abuse path is one click for the user and one incident report for the team.
The regulator did not fine a leak. It fined a workflow: an algorithm acting alone, with nobody to appeal to.
What to do
Inventory every irreversible automated action in the product this week — suspend, ban, hold funds, demonetize, delist — and confirm each has a reason code, a human reviewer before it lands, and an appeal path a user can find.
Freeze any in-flight agent sandbox or isolated-runtime build and run a two-day spike this sprint comparing OpenSandbox against the in-house plan on cold start, egress control and secret injection.
Add a scope-and-exfiltration review to the launch gate for every assistant feature this sprint: what it can read, what it can be induced to send outward, and what a one-click abuse path looks like.