Executive Summary
If you have ever filed a comment on a proposed rule, you probably wondered what happened next. Which provision did it actually reach? A study posted to arXiv on August 11, 2026 took 70,075 public comments filed on 36 rulemakings at the US Environmental Protection Agency and matched them not to the rules as wholes but to the individual duties written inside those rules. Jianing Fan and Yue Yao wrote it, and the paper has been accepted as a full paper at ACM EAAMO this year in Munich.
The paper starts from the gap between a right and a capacity: anyone may file a comment, but not everyone can move the text. Comments filed mostly by organizations landed on outcomes that tidied wording rather than outcomes that changed what a duty requires. The authors place that asymmetry upstream of the moment an agency writes its response, in the differing ability to locate a specific legal obligation, read it, and argue with it.
Korea ran its own version of this procedure twice for the enforcement decree of the AI Framework Act, which took effect on July 21, 2026. No public record has been found that lets anyone follow those comments down to the provisions they changed. The EPA figures do not transfer to Korea. What transfers is the question that produced them.
Key Figures
The first two numbers give the size of the audit. The last two are what did not come out as expected, even at that size.
Source: arXiv:2608.10329
70,075
Comments matched duty by duty
The anchor sample drawn from 36 EPA rulemakings
786,197
Comments in the corpus behind it
Across 6,145 dockets, from 2010 through 2022
Support or oppose
The signal that split nothing
Neither direction clearly tracked where the final text landed
Editorial refinement
Where organizational comments clustered
Their share of substantive changes to duties ran lower
Receipt Is Recorded, Influence Is Not
Federal regulation in the United States runs through a procedure called notice-and-comment. An agency publishes a proposed rule, anyone affected may file a comment, and the agency has to consider those comments before it issues the final rule. The design is egalitarian, and that is where the paper begins. The formal right of access is identical for everyone; the substantive capacity to move rule text is not.
Measuring that difference has been the hard part. Existing approaches work on a rule as a single object, or on the comment corpus in aggregate. The paper argues that this unit is too coarse, because what commenters try to change is never the rule as a whole but a discrete obligation buried inside it. A request to stretch a reporting cycle from 90 days to 180, to lift a category of emission source out of scope, to loosen a measurement tolerance, all of them aim at one sentence somewhere in the text. Count at the level of the rule and whether that request was granted disappears into the average.
What the authors propose is obligation-level responsiveness auditing. It runs in four steps. First, extract the individual obligations from the proposed rule and from the final rule. Second, attach each incoming comment to the obligation it addresses. Third, classify what happened to that obligation on the way from proposal to final text. Fourth, check the results against blind human judgment at every component that carries weight. AI does the classification, and people, working blind, recount it to see whether the classification holds.
The material is 786,197 comments filed across 6,145 EPA dockets between 2010 and 2022. Within that, 36 anchor rulemakings and 70,075 comments went through the detailed matching. Read as a receipt log, those 786,197 filings are evidence of participation. Only after the recount at obligation level does it become visible which of them moved any text.
Neither Volume nor Direction Separated the Outcomes
The paper reports three findings. All three cut against the intuitive expectation.
None of the three is causal. What the paper measured is the degree to which public-comment engagement co-occurs with changes to specific regulatory duties. It does not say that a given comment produced a given revision; it says the two showed up together. In the table below, the first row was measured inside a single docket and the third compares across dockets, so the three findings do not share one yardstick.
| Expectation | Observed | Caveat |
|---|---|---|
| Duties drawing more comments get revised more | An association holds, but the magnitude is small | Measured within a single docket |
| Support keeps the text, opposition changes it | Direction does not differentiate outcomes | A result at odds with a simple preference-tally model |
| Organizations move the substance of a duty | They cluster in outcomes that refine wording | A cross-docket comparison resting on a permissive reconstruction of commenter type |
Compiled by Pebblous. The three descriptive findings stated in the abstract of arXiv:2608.10329, rearranged as expectation, observation, and caveat.
Start with the first. Within the same docket, obligations that drew more comments were indeed more likely to be revised than obligations that drew fewer. The size of that difference was modest. Participation is not futile, but the count of comments is too thin to serve as a proxy for whether anything was heeded. This is where the habit of reporting intake volume as an outcome starts to wobble.
The second finding is stranger. Whether an obligation drew mostly supportive comments or mostly opposed ones did not clearly decide its fate. The paper treats this not as a failure to find something but as an informative null, because a procedure that tallied positions and shifted the text toward the majority could not produce this value. What regulators count is something other than raised hands.
The third finding is the one the title turns on. Participation dominated by organizations concentrated in outcomes that tidied the language rather than outcomes that changed what a duty requires. This comes with a condition attached. The source records do not cleanly say whether a filer is an individual or an organization, so the authors reconstructed the type permissively and then compared at the cross-docket level. The paper states plainly that the finding leans on that labeling.
They then handed the doubt to people. Blind human auditors relabeled the portions that carry the outcome contrast, and the third finding survived on the corrected labels. The same check produced one more methodological result. Text similarity between proposed and final language, on its own, cannot separate an editorial fix from a substantive regulatory change. How much a sentence moved says nothing about what moved.
Put the three side by side and the equity problem relocates. It is no longer only a question of which comments an agency answers and which it passes over. It becomes a question of who can find the obligation at stake in the first place, read it, and argue with it, and who cannot. The paper's closing line places that divide upstream of the agency's response.
An Audit Holds Only One Duty at a Time
Obligation level sits a notch below what we normally call a provision, because a single provision routinely carries several duties. When a duty to report, a duty to retain records, and a duty to notify are bundled into one section, knowing that the section was amended tells you nothing about which of the three moved. The unit at which an audit becomes possible is not the document and not the section. It is the single duty.
Anyone working on data lineage will recognize the shape. Declaring the provenance of a training dataset as one object is a different act from stating which column came from where and which value was rewritten under which rule. The first is an inventory; only the second is an audit. The same distinction transfers to regulatory text without modification.
What happens when the resolution is set too low is exactly what the byproduct above shows. Measuring similarity between the proposed and final text as whole documents produces clean numbers and automates easily. That number cannot tell a fixed comma apart from a category lifted out of scope. A metric that spread because it was convenient was failing to measure the thing it was meant to measure, and nobody could see that until people recounted it by hand.
This is also why the authors attached blind human judgment to each component. Whether automated classification can be trusted is not a question automated classification can answer. Defer human verification to the end of an audit design, as a luxury, and what you keep is statistics built on wrong labels, looking perfectly presentable.
The same arXiv category that carries this paper also carries one reconciling ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act into a single governance taxonomy, and another working out how to qualify and quantify the risk the EU AI Act refers to. Deciding how to comply with regulation is a crowded field. Deciding what unit to record the making of regulatory text in is still a mostly empty one.
Korea's AI Framework Act Decree Faces the Same Question
Korea has just run the same kind of procedure twice, for the enforcement decree of the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation of Trust. On September 8, 2025 the Ministry of Science and ICT released a draft decree together with two notices and five guidelines and opened it for comment. On November 12 it gave public notice of the proposed decree and took comments until January 21, 2026. The act was then amended and its effective date pushed back, so a revised decree went out for public notice again on May 21, 2026, with comments accepted until June 19. The act took effect on July 21, 2026.
The original target had been January 22, 2026, which puts the schedule roughly half a year late, and the revision noticed in May widened the definition of vulnerable groups, among other changes. Running the procedure twice opened the comment window twice. The diagram below places those two windows in sequence, from the day the draft appeared to the day the act came into force.
Everything to this point is on the public notices. Carry the EPA paper's question across, though, and there is nothing to answer it with. How many comments arrived across the two windows, which provisions of the decree those comments aimed at, and how those provisions came out in the final text: no public record has been found that connects them provision by provision. Korean public-notice practice does include summarizing submitted comments and their disposition, but for this decree no case has turned up where that table was published in a form tied to individual provisions.
So this article has no basis for saying that organizational comments in Korea clustered in wording fixes, or that comment volume had nothing to do with revision. The EPA numbers belong to the EPA. The question that produced them does travel. Who aimed at which duty, what did they ask for, and what became of it in the final text. That the currently published record cannot answer this is itself a finding.
This is a law that asks high-impact AI operators to account for data sources and training process at the level of individual provisions. If the making of its own enforcement decree leaves behind no record that can be retraced at that same level, then two different resolutions are in force, one for the side doing the asking and one for the side being asked.
What an Auditable Comment Process Leaves Behind
The procedure the paper demonstrates converts directly into a list of requirements. Extract the obligations from the proposed text, attach incoming comments to those obligations, classify what happened to each one in the final text, and have people verify that classification blind. Three of those four can be done after the fact if the documents exist. The second, the link between a comment and a duty, is hard to reconstruct later if it was not created at intake.
A single field on the submission form asking for the provision number changes a great deal of this. The intake register becomes the matching data, and publishing dispositions grouped by provision turns into a clerical task rather than a research project. Without that field, someone later has to re-link comments to text with natural language processing, and the reliability of that result is unknown until people recount it by hand, exactly as this paper found.
The same finding lands on the people filing comments. The third result is not a story about organizations being powerful. It is a story about organizations, too, scoring their wins on wording rather than substance. A comment meant to change regulatory text has to name the duty in a given section and the wording it should become, and it has to remain in a state where its disposition in the final text can be checked. How many filings you sent is a secondary matter.
Three things can be checked today by anyone running or joining a comment process. They are the four steps above turned into a checklist, so they apply to a procedure already under way.
- Does the intake register have a column linking a comment to a provision? Without it, the procedure proves nothing beyond how many filings arrived.
- Are dispositions recorded separately for editorial fixes and substantive changes? Collapse the two into one field and a percentage of comments accepted stops meaning anything.
- If classification is automated, has anyone recounted the output blind? Text similarity could not tell the two kinds of change apart.
Editor's Note: Pebblous has been repeating one line about data lineage for a while. A provenance document written at dataset level is not audit material; only at the level of columns and values can it answer who changed what, and when. This recount of EPA rulemaking, duty by duty, confirms the same structure on the side of regulatory text. The unit you choose to preserve decides what you will be able to ask later.
References
Academic Papers
- 1.Fan, J., & Yao, Y. (2026). "Who Gets Heeded? An Obligation-Level Audit of Responsiveness in EPA Rulemaking." arXiv:2608.10329. Accepted at ACM EAAMO '26.
- 2.Dhiman, V. (2026). "Bridging AI Risk Frameworks: Reconciling ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act into a Unified Governance Taxonomy." arXiv:2608.07515.
- 3.Gasiola, G. G., Cen, S. H., & Zufall, F. (2026). "Qualifying and Quantifying Risk under the EU AI Act." arXiv:2608.08564.
Official Documents
- 4.Korea Law Information Center. (2025). "Public Notice of the Proposed Enforcement Decree of the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation of Trust." Ministry of Government Legislation.
Industry and Press
- 5.Lawtimes. (2025). "Public Notice of the AI Framework Act Enforcement Decree."
- 6.Lawtimes. (2026). "Ministry of Science and ICT Gives Notice of the Amended AI Framework Act Enforcement Decree."
- 7.Lexology. (2025). "Draft Notices and Guidelines Released Following the AI Framework Act Enforcement Decree."
- 8.CODIT Insights. (2026). "Analyzing the Administrative Regulation Structure of the Draft AI Framework Act Decree."