# kaal:position:2026-08-26-034

**Affirmed position.** An outbound domain allowlist and an audit log do not perform personal-information filtering. Enck and coauthors demonstrate the distinction in TaintDroid. Android permissions could decide whether an application accessed location, camera, microphone, or device identifiers. They provided little visibility into how that data was used after access. TaintDroid therefore labeled data at privacy-sensitive sources, propagated those labels through variables, files, and interprocess messages, and examined the labels when data reached a network or other system boundary. The implementation identified 68 instances of potential misuse across 20 of 30 applications. The mechanism was executable. Its evidence did not rest on a list of intended controls.

This evidence qualifies Kaal's repository finding. The source does not inspect Gatekeeper, its documentation, Mosaic Companion, or commit 2d920ce. It cannot establish that content inspection and personal-information filtering are absent from the named code. TaintDroid also monitors disclosures. It does not generally block them. It tracks defined sensitive sources rather than every MIME type or every form of personal information. Implicit flows can evade its analysis. The study concerns Android applications in 2010, not language model agents or sovereign local runtimes.

The institutional requirement is nevertheless precise. A declared filtering layer should correspond to an executable decision path. Personal-information control requires a source definition, propagation rule, inspected egress boundary, policy decision, and test that fails when protected data crosses that boundary. Content inspection requires its own parser coverage and failure rule. Domain approval and after-the-fact logging can remain separate controls. They cannot demonstrate that either missing layer operates. Documentation should distinguish implemented controls from proposed controls, and a release should not claim the broader filter until the named decision paths and adversarial tests exist.

**Status.** affirmed  **Published.** 2026-08-26

**Holds when.**

- The response is limited to the exact full-text propositions and the one mapped Kaal claim.
- External evidence level: peer-reviewed USENIX OSDI systems paper with complete official proceedings full text, implemented Android prototype, and empirical application study.
- Mapping review tier: independent substantive scholarly-growth qualification.
- The source does not inspect Gatekeeper, its documentation, Mosaic Companion, or commit 2d920ce and therefore cannot verify the repository finding.
- TaintDroid monitors and logs sensitive-data disclosures but does not generally block them.
- The system tracks defined sensitive sources and does not inspect every MIME type or every form of personal information.
- Implicit information flows can evade the analysis.
- The study concerns Android applications and an implemented 2010 smartphone prototype, not language model agents or sovereign local runtimes.
- The 30-application evaluation identifies potential misuse and suspicious handling, not adjudicated policy violations.

**Current debate.** TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones: https://www.usenix.org/conference/osdi10/taintdroid-information-flow-tracking-system-realtime-privacy-monitoring

**Extends.** kaal:claim:7314479-034: https://wulfkaal.github.io/claims/7314479-034

**Scholarly basis.** Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479

**Source PDF sha256.** `debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6`

**Evidence level.** peer-reviewed USENIX OSDI systems paper with complete official proceedings full text, implemented Android prototype, and empirical application study

**Mapping review tier.** independent substantive scholarly-growth qualification

**Mapping confidence.** 0.97  **Mapping ambiguous.** false

**Topics.** institutional-design, governance-design, ai-and-agents, privacy, personal-information, information-flow, content-inspection, audit-logging, policy-enforcement, open-source-and-code

**Provenance.** Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-034-reviewed-v1 at https://wulfkaal.github.io/positions/by-claim/7314479-034.html.

**Record type.** This is a dated commentary position that extends a scholarly corpus claim. It is not a verbatim claim extracted from the paper.

**Canonical form.** This markdown file is the canonical hashed representation of the position.
