{"id":"6939f332-26cd-4bb8-bbc0-63872d3906a3","arxiv_id":"2508.07356","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":5.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"Web 3.0's system and application level interoperability is only partially covered by the EU Data Act's data-centric interoperability rules.","lead":"This paper compares how Web 3.0 technologies achieve interoperability with how the EU Data Act regulates it, finding that the law focuses on data while the technology also covers systems and applications. It recommends the Data Act broaden its scope and use softer standard-setting tools.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The central mismatch claim depends on the premise that the DA regulates only data interoperability, but the quoted Art. 2(40) definition includes systems and applications; the paper never shows that binding provisions stop at the data layer.","rationale":"The reader's weakest assumption is exactly the load-bearing premise: the paper asserts, without a detailed article-by-article demonstration, that the DA's operational provisions cover only data interoperability. My reading of the paper confirms this is the hinge for the central mismatch claim. The definition quoted in Section I explicitly includes systems and applications, and the paper's own citations to smart contracts and switching provisions suggest that binding provisions do touch the application/service layer. The paper's normative recommendations—broadening the DA and adding soft-law standardisation—could survive a weaker version of the claim, but the claim as stated needs recalibration. Since the reader already issued CONDITIONAL on essentially this ground, no verdict change is needed; the same corrective work (reconcile with the final Data Act text) is required.","tokens_in":8978,"tokens_out":4396,"duration_ms":47237,"concrete_test":"Perform a systematic legal audit of the final Regulation (EU) 2023/2854. For each clause of Chapter VIII (interoperability), Article 30 (smart contracts), and the switching-related provisions (Articles 23-26 and Chapter VI), code the compliance object and addressee: (a) data only, (b) systems/applications/components, (c) both. Separate binding main-text provisions from recitals. Specifically, check whether Article 33's essential requirements reference open specifications, APIs, or common data spaces in a way that obligates system-level interfaces, and whether Article 30's smart-contract requirements apply to decentralised applications. If any binding provision imposes a requirement on a system, application, smart contract, or API, the paper's 'data-only' premise fails. An independent legal reader should be able to reproduce the table from the regulation text alone.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's main finding—that the Data Act 'focuses solely on data' and fails to cover Web3.0's system/application interoperability—rests on an interpretive premise that is both unproven and in tension with the DA's own text. Article 2(40) of the DA (quoted in Section I) defines interoperability as the ability of data spaces, networks, systems, connected products, applications, data processing services, or components to exchange and use data. That is a definition about interoperating systems and applications, not a definition limited to data as the sole object. The paper never resolves this tension; it asserts that 'since DA directly addresses only data interoperability' (Section I) and later claims that 'regulations concerning system and application interoperability are broad and primarily found in the recitals' (Section IV.A). The latter is an empirical legal claim requiring an article-by-article analysis, and the paper does not provide one. Moreover, the paper itself cites binding provisions that target services and software: Article 30 on essential requirements for smart contracts, Chapter VI on switching data processing services, and the general interoperability chapter. Absent a demonstration that these provisions do not impose system- or application-level requirements, the central mismatch is overstated. This is not a disagreement with the normative recommendation—the DA could still be criticised for shallow or under-enforced system interoperability—but the factual premise underpinning the critique needs correction.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper offers an interdisciplinary comparison between the technical interoperability of Web 3.0 and the legal interoperability framework of the EU Data Act (DA). It argues that Web 3.0 interoperability spans data, systems, and applications, while the DA focuses solely on data interoperability, creating a mismatch that risks ecosystem fragmentation. The paper recommends broadening the DA's concept of interoperability to include system and application layers and introducing soft-law mechanisms such as negative lists for standardized protocols. The analysis is qualitative, drawing on selected DA provisions and illustrative Web 3.0 examples, and concludes with policy-oriented recommendations.","tokens_in":9216,"tokens_out":3984,"duration_ms":42062,"significance":"If the central mismatch claim were well supported, this would be a timely and useful contribution to an active policy discussion on interoperability in the EU digital single market and the Web 3.0 ecosystem. The paper correctly identifies that technical interoperability standards (e.g., cross-chain protocols, ERC standards) and legal interoperability obligations may not be aligned, and it proposes concrete, if preliminary, legal design suggestions. The paper does not provide machine-checked proofs or quantitative analysis, but its contribution lies in framing the interdisciplinary question and offering comparative observations. The main significance is contingent on substantiating the claim that the DA's binding provisions are limited to data-level interoperability, which currently rests on an unsupported interpretive premise.","major_comments":[{"comment":"The paper quotes the DA's definition of interoperability as 'the ability of two or more data spaces or communication networks, systems, connected products, applications, data processing services or components to exchange and use data' and then asserts that 'since DA directly addresses only data interoperability.' These two statements are in direct tension. The quoted definition explicitly includes systems and applications as subjects of the exchange/use capability. The paper never reconciles this tension or demonstrates through an article-by-article analysis of the final Data Act text that the binding obligations stop at the data layer. This is the load-bearing premise for the paper's central mismatch argument and must be fixed.","section":"Section I (quoted Art. 2(40) definition)"},{"comment":"The paper claims that 'the regulations concerning system and application interoperability are broad and primarily found in the recitals, lacking the legal enforceability and practical applicability needed for effective interoperability.' This is contradicted by the paper's own survey in the same section: it cites Chapter VI on data processing services, Articles 23–26 on switching, Article 28–29 on interoperability requirements, and Article 30 on smart contracts. These are binding main-text provisions, not recitals. The paper needs to explain why these provisions do not constitute system/application interoperability obligations. Without that demonstration, the central mismatch is overstated. The recital claim is a factual legal assertion requiring specific evidence.","section":"Section IV.A"},{"comment":"The examples used to illustrate conflicts between Web 3.0 interoperability and legal requirements are not about interoperability as defined by the DA. The DEX/KYC example concerns financial regulation and anti-money laundering, not data interoperability. The DeFi/social-media example is about privacy protection, not about system/application interoperability. These examples may support a broader claim about technology complying with sectoral law, but they do not support the section's title: 'Aspects of Web 3.0 Technical Interoperability That May Conflict with Legal Requirements.' The paper should either find examples where the technical interoperability mechanism itself (e.g., cross-chain bridges or DApp integration) collides with DA provisions, or retitle the section to reflect the actual scope.","section":"Section III.B"},{"comment":"The recommendation to introduce a 'negative list' for standardized protocols is asserted rather than argued. The paper repeats the same paragraph nearly verbatim (the duplicated text about negative lists appears twice in this section), which suggests drafting oversight. More importantly, the proposal relies on citation [14], a self-citation by one of the authors, without explaining how such a negative list would interact with the DA's existing standardization mechanisms, such as Article 29 (essential requirements) and Article 33 (essential requirements for data interoperability). To be persuasive, this recommendation should be tied to the DA's enforcement structure and discuss how a negative list would be monitored and updated.","section":"Section VI.B"}],"minor_comments":[{"comment":"Capitalization is inconsistent: 'Firstly, Web 3.0’s concept...' and 'Secondly' appear capitalized mid-sentence. Also, the abstract uses 'Web3.0' without a space in some places, while the main text uses 'Web 3.0'.","section":"Abstract"},{"comment":"The paragraph beginning 'Secondly, the DA addresses the establishment of standardised protocols only within the recitals...' is a near-duplicate of the preceding paragraph about negative lists. One of them should be removed.","section":"Section VI.B"},{"comment":"The statement that 'GDPR ... implicitly supports data sharing and flow' is an overgeneralization. GDPR's data portability right is narrower than interoperability; the paper should phrase this more carefully to avoid conflating data portability with data sharing.","section":"Section II.A"},{"comment":"The article numbering in the paper appears to be based on an earlier version of the Data Act; the final adopted Regulation (EU) 2023/2854 may have different article numbers. The authors should verify and cite the final text throughout, especially when discussing Articles 23-30.","section":"References"},{"comment":"The claimed advantages of system-level interoperability are normative and not grounded in the technical literature cited in the paper. Consider adding concrete technical references or toning down the language to avoid unsupported advocacy.","section":"Section VI.A"}],"recommendation":"major_revision","confidential_remarks":"The paper has a promising and timely topic, but the central claim is currently under-supported. The major issue is the unresolved contradiction between the DA's statutory definition (which includes systems/applications) and the paper's assertion that the DA 'focuses solely on data.' The authors need to provide a detailed article-by-article analysis of the final Data Act text to show which binding provisions do or do not impose system/application interoperability obligations. Without that, the paper reads as a position statement rather than a rigorous legal-technical analysis. I would also flag the self-citation [14] used to support the negative-list recommendation; it is not improper, but the recommendation should be argued from the DA's own provisions and independent sources. The paper is suitable for a workshop or policy forum after these revisions, but major strengthening of the legal argument is required before it can be accepted."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Short version: this is a plausible policy analysis with a genuinely under-explored comparison—Web 3.0 technical interoperability versus the EU Data Act's legal interoperability. The technical side is described accurately enough, and the observation that a lot of the Data Act's interoperability substance sits in recitals rather than binding articles is worth making. But the central claim, that the Data Act 'focuses solely on data,' is asserted rather than demonstrated. The paper quotes Article 2(40), which explicitly defines interoperability as covering systems, applications, connected products, and data spaces, and then just moves on. Later it softens to say system/application interoperability provisions are 'broad and primarily found in the recitals.' Those are two different claims. The second is more defensible but requires an article-by-article analysis of the binding text—Chapter VI on switching data processing services, Article 30 on smart contracts, and the interoperability chapter. The paper cites these but never grapples with why they don't count as system- or application-level requirements. The stress-test note is right: without that analysis, the mismatch is overstated.\n\nWhat the paper does well: the framing is new in the cited literature, and the normative suggestions—broadening the concept of interoperability to cover systems and applications, using soft law and negative lists—are sensible and grounded in comparisons with the AI Act and DSA. The technical examples (Polkadot, Cosmos, ERC standards) are standard but correct.\n\nSoft spots, in proportion: (1) the interpretive premise is the load-bearing issue; (2) the DEX/KYC example is about financial regulation, not the Data Act, so it doesn't actually illustrate a conflict with the DA; (3) there's a duplicated paragraph in Section VI.B that looks like an editing slip; (4) citation [13] analyzes the proposed Data Act, not the final Regulation (EU) 2023/2854, and the paper should engage with the final text. None of these are fatal to the research question, but they prevent the central argument from holding in its current form.\n\nWho this is for: legal scholars and policy people working on data law and Web3. I would not cite it as authority for a 'data-only' reading of the Data Act until that reading is actually defended.\n\nRecommendation: send it to peer review with a clear expectation of major revision. There is a real question here, and the paper has the right instinct. It just hasn't earned its conclusion yet.","headline":"Plausible but under-demonstrated: the paper's core claim that the Data Act covers only data interoperability is asserted, not shown, despite the Act's own broader definition.","tokens_in":9722,"tokens_out":2806,"would_cite":false,"duration_ms":29832,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"EU Data Act's interoperability stops at data while Web 3.0 spans systems and applications, the paper argues, and this gap could fragment the digital ecosystem.","keywords":["interoperability","Web 3.0","EU Data Act","legal compliance","blockchain","decentralized applications","standardised protocols","regulation"],"falsifier":"A systematic article-by-article reading of the final Data Act text: if Articles 23-30 (especially the portability of applications and virtual machines under Article 26, and the smart-contract requirements of Article 30) already impose legally binding system- and application-level interoperability obligations, then the paper's central claim that the Data Act is data-only in its operational provisions would be falsified.","tokens_in":8823,"feed_emoji":"⚖️","tokens_out":2848,"duration_ms":29935,"temperature":0.7,"pith_summary":"This paper compares the technical interoperability built into Web 3.0 with the legal interoperability framework of the EU Data Act, asking whether the Data Act can support the kind of cross-platform integration Web 3.0 is designed to achieve. It argues that the Data Act operationally regulates only data-level interoperability, while Web 3.0 interoperability operates at data, system, and application layers. The mismatch means data can legally flow between platforms, but full system and application integration is neither recognized nor enabled by law, and in some cases legal compliance could actively limit it. The authors conclude that the Data Act should broaden its concept of interoperability to cover systems and applications, and should use soft-law mechanisms like negative lists to make standardised protocols legally actionable.","feed_headline":"Data Act and Web 3.0 mismatch on interoperability scope","feed_subtitle":"The law regulates data flow, but Web 3.0's system and application integration sits outside binding legal provisions, risking a fragmented ec","key_machinery":"The three-layer interoperability concept (data, system, application) is the analytic lens, mapped against the Data Act's provisions. The argument works by taking Web 3.0's technical stack—ERC token standards, cross-chain protocols, decentralised identity, DApps—and checking each layer against the Data Act's definitional articles, its chapter-wide interoperability provisions, and recitals 76-86. The mapping carries the conclusion that the Data Act recognises the data layer but neither regulates nor protects the system and application layers, which is the source of the mismatch.","core_discovery":"On its own terms, the paper establishes that the Data Act's binding provisions—Articles 2(40)-(41) on definitions, Chapter 8 on interoperability, Articles 28-30 on data processing services and smart contracts—are oriented toward data exchange and portability, whereas Web 3.0's technical interoperability spans data, systems, and applications through mechanisms such as ERC standards, cross-chain bridges (Polkadot, Cosmos), and decentralised identity. The paper classifies Web 3.0 interoperability into three categories relative to law: aspects already recognised (standardised protocols supporting data circulation, decentralised identity aligning with data-ownership goals), aspects that may confl","pith_inferences":["The same data-versus-systems comparison could be applied to sectoral Web 3.0 cases—finance, identity, supply chain—to test whether the mismatch is more severe in heavily regulated domains; the paper gestures at finance but does not carry this through.","A testable extension would code every article of the final Data Act for whether it imposes obligations on systems, applications, or only data; the paper asserts but does not perform such a systematic coding.","The paper implies, without stating, that Web 3.0's interoperability is itself layered—blockchain, protocol, and application—and that the Data Act's gap may be most acute at the application layer, which is the layer where DApps and cross-chain user interactions actually occur."],"forward_implications":["Cross-chain and DApp-integration projects face legal uncertainty under the Data Act, since none of its binding provisions address system or application-level interoperability.","The Data Act's stated goal of seamless data flow is only partially achievable: data travel is regulated, but the integrations that make data usable across platforms are not.","Broadening the Data Act to cover system and application interoperability would create new compliance questions, such as whether cross-chain bridges or DApp-to-DApp protocols become legally accountable for interoperability failures.","Using negative lists and soft-law standardisation could make protocol standards legally meaningful without freezing them into rigid technical mandates.","Aligning the Data Act's concept with Web 3.0's layered interoperability would also affect neighbouring legislation, since GDPR and the Interoperable Europe Act share the same data-centric emphasis."],"supporting_citations":[{"why":"Supplies the ISO/IEC/IEEE 24765 definition of interoperability as system-level information exchange, used to show technical interoperability exceeds data exchange.","marker":"[5]"},{"why":"Defines blockchain interoperability as collaborative operation across blockchains, grounding the system-level scope of Web 3.0 interoperability.","marker":"[7]"},{"why":"Provides Polkadot as a concrete cross-chain bridge example of system-level integration in Web 3.0.","marker":"[8]"},{"why":"Provides Cosmos as a second cross-chain interoperability mechanism used to contrast with data-only legal interoperability.","marker":"[9]"},{"why":"Shows how ERC standards standardise smart contracts, supporting the claim that Web 3.0 interoperability rests on detailed technical standards.","marker":"[10]"},{"why":"SoK on decentralised exchanges that documents how DEXs omit traditional intermediaries, grounding the conflict with financial compliance.","marker":"[11]"},{"why":"Discusses regulation of Web 3.0, used to support the claim that decentralised systems challenge KYC and identity-based regulatory requirements.","marker":"[12]"},{"why":"Analyses switching and interoperability between data processing services in the proposed Data Act, underpinning the reading of the Act's interoperability provisions.","marker":"[13]"},{"why":"Proposes standardisation with prohibitive/negative-list elements from a data-protection perspective, the basis for the paper's negative-list recommendation.","marker":"[14]"}],"fun_headline_variants":["Web 3.0's broad interoperability clashes with Data Act's data-only scope","Data Act ignores system integration, hindering Web 3.0's full vision","EU Data Act narrow focus threatens Web 3.0 ecosystem integration","To fix interoperability, Data Act must cover systems and apps","Web 3.0's system-level interoperability outpaces EU law's data-only reach"],"cache_read_input_tokens":2816,"weakest_assumption_plain":"The entire mismatch argument rests on the interpretive premise that the Data Act's binding provisions cover only data-level interoperability, notwithstanding the Act's own statutory definition that explicitly includes systems, applications, and components; the paper asserts this premise without a detailed article-by-article demonstration.","fun_headline_variants_meta":{"raw":{"variants":["Web 3.0's broad interoperability clashes with Data Act's data-only scope","Data Act ignores system integration, hindering Web 3.0's full vision","EU Data Act narrow focus threatens Web 3.0 ecosystem integration","To fix interoperability, Data Act must cover systems and apps","Web 3.0's system-level interoperability outpaces EU law's data-only reach"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000362,"raw_usage":{"total_tokens":1824,"prompt_tokens":810,"completion_tokens":1014,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":554,"completion_tokens_details":{"reasoning_tokens":915}},"tokens_in":554,"tokens_out":1014,"duration_ms":8089,"temperature":1.0,"reasoning_tokens":915,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T22:09:27.168095+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A systematic article-by-article reading of the final Data Act text: if Articles 23-30 (especially the portability of applications and virtual machines under Article 26, and the smart-contract requirements of Article 30) already impose legally binding system- and application-level interoperability obligations, then the paper's central claim that the Data Act is data-only in its operational provisions would be falsified.","supporting_citations":[{"cited_title":"da Silva Serapião Leal, W","cited_arxiv_id":null,"evidence_quote":"Supplies the ISO/IEC/IEEE 24765 definition of interoperability as system-level information exchange, used to show technical interoperability exceeds data exchange."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Defines blockchain interoperability as collaborative operation across blockchains, grounding the system-level scope of Web 3.0 interoperability."},{"cited_title":"Kwon and E","cited_arxiv_id":null,"evidence_quote":"Provides Cosmos as a second cross-chain interoperability mechanism used to contrast with data-only legal interoperability."},{"cited_title":"Norvill, B","cited_arxiv_id":null,"evidence_quote":"Shows how ERC standards standardise smart contracts, supporting the claim that Web 3.0 interoperability rests on detailed technical standards."},{"cited_title":"Zuo, ‘Development, Application, And Regulation of Web3","cited_arxiv_id":null,"evidence_quote":"Discusses regulation of Web 3.0, used to support the claim that decentralised systems challenge KYC and identity-based regulatory requirements."},{"cited_title":"Schnurr, ‘Switching and Interoperability Between Data Processing Services in the Proposed Data Act’, Switch","cited_arxiv_id":null,"evidence_quote":"Analyses switching and interoperability between data processing services in the proposed Data Act, underpinning the reading of the Act's interoperability provisions."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Proposes standardisation with prohibitive/negative-list elements from a data-protection perspective, the basis for the paper's negative-list recommendation."}],"review_version":1}