Kleros at a Crossroads: Governance, Execution and Accountability

Kleros at a Crossroads: Governance, Execution and Accountability

Intention of the discourses;

This post aims to give a general overview of the decisions and its impact(s) in one overview. The over arching intention of this post is for the betterment for both the Kleros Protocol as well as protective of the Kleros Cooperative as the primary custodians of the arbitration protocol.

Court development chronology (aka “Court V2”)

The following chronology provides an overview of the development of Kleros’ most important project: court V2. These developments has been communicated in the past as a means to increase the number of PNK tokenholders and hold for longer. The project was first teased in 2019, with a promised delivery in 2022 and hasn’t had any deliverable yet in 2026, misleading tokenholders’ expectations and putting into question the allocation of the cooperative’s funds and it’s senior direction.

February 2022. In Kleros Project Update – February 2022, Kleros co-founder Federico Ast wrote:

“In November 2021, we released the specs and officially launched the development of Kleros 2.0. The new release, which is expected for Q3 2022…”

[1]

May 2023. In the following project update, Federico Ast reported:

“The functionalities for Kleros 2.0 have been implemented at 90% on the smart contract level.”

And regarding the frontend:

“the essential arbitration functionalities have been implemented at 75%.”

The same update notes that the roadmap had evolved since the previous release plan. [2]

January 2024. In Court V2 Integration Sneak Peek, Guangmian Kung and Damjan Malbašić opened with:

“As the launch of Kleros V2 is finally just around the corner…”

At the end of the same article, V2 is described as being:

“currently in the testing phase”

on Arbitrum Sepolia. [3]

November 2024. Jean P announced Kleros 2.0 Beta on Arbitrum One as:

“the first beta deployment of Kleros 2.0 on Arbitrum One”

The purpose of the deployment was to:

“test core features in a controlled live environment”

The article separately places “Modular Architecture” and “Cross-Chain Capabilities” under Future Developments. [4]

September 2025 update — published 22 October 2025. In her monthly development report, Parul Yadav reproduced a September 2 statement from the official Kleros account:

“We’re gearing up for audits as the next chapter unfolds.”

The same development update describes Court V2 as something that:

“approaches full production deployment.”

The report also states that the V2 contracts had entered internal review. [5]

October 2025 update — published 7 November 2025. In the Looking Ahead section, Parul Yadav listed among the upcoming tasks:

“Finalize Court V2 contract audits with external security firms”

and:

“Prepare mainnet deployment roadmap”

At this point, external audit completion and the mainnet deployment roadmap were still future work. [6]

March 2026 update — published 15 April 2026. Following the Certora review and subsequent fixes, Parul Yadav wrote:

“Court V2 contracts are now ready for internal review, with a deadline set for April 19th.”

The report also states that meta-audit fixes resulting from the Certora review were still being merged during March. [7]

April 2026 update — published 15 May 2026. In the following month’s report, Parul Yadav wrote:

“Court V2 contracts: internal review completed, with findings now in triage.”

The Court V2 section further records that attempts to exploit issues identified during that review were still being investigated. [8]

May 2026 update — published 12 June 2026. Parul Yadav reported:

“Contract simplification work then began across the dispute kits”

with the next planned changes including:

“governance removal, sortition tree simplification, and a reworked reward staking mechanism”

The same update describes the eventual production migration as moving Beta data to:

“new stable contracts.” [9]

Telegram discussion — May 19, 2026

Kleros CTO Clément Lesaege said:

“I am now spending more time in improving V2 contracts (not just finding vulns).”
“normally I just come in the end to do the security procedure”

Green questioned why major V2 refactoring was only happening after years of development and after the Certora audit.

Clément responded:

“V2 was assigned a lead. I never led V2.”
“the bigger code modification is to fix a vuln which couldn’t be fixed without significant modifications.”

Shortly afterwards, Jay Buidl, the V2 lead, stated:

“I led V2. We found that the V2 contracts had never been looked at by our internal authority on smart contract security until 2 hours after the Certora audit was published on Feb 17th.”
“That is 4 months after the start of the formal audit and 6 months after the code freeze and start of internal reviews.”

I believe the chronology, which comprises Cooperative’s own communication speaks for itself in it’s inability to communicate clearly to the DAO, and even, to themselves. It also reflects the lack of accountability of leadership and blame shifting when things don’t go as expected. Which is a sad thing to see from the protocol custodians.

Key questions that remain unanswered:

  1. Discrepancy of “we are launching in 2022” to still being empty handed in 2026, likely extending into 2027. What are the timelines now?
  2. Why did the “Internal contract authority” wait until after the public audits to review the contracts? Kleros has weekly calls, all code is also on GitHub and has been for literally years. Do the members of the Cooperative still think this is the right way of working?
  3. Seeing how technically Cooperative is a democratic organization, do all members of the team, actively employed or not stand behind the decisions and communication style of Cooperative?
  4. Has Cooperative made any internal changes to their internal / external communication?
  5. Who or what mechanism makes the final call on decisions?

Foresight

For those who don’t know what this new project, here’s a description stated from the project

“The first experiment: 16 movies, 1 judge (our CTO Clément), 5 evaluated. Predict how Clément will rate each film. Get it right, you profit. Get it wrong, you lose.”

Foresight also appears frequently in the development updates on the blog.

In May, Kleros described Futarchy/Foresight as having had a “heavy month on the master branch.” [15]

Let’s also read the statue from the ANJ (French Gambling authority).
Authority to which the Kleros Cooperative has to respond to, being constituted in France as an entity.
Article L320-1 — default rule: gambling is prohibited

FR « Les jeux d’argent et de hasard sont prohibés. »
EN “Gambling and games of chance are prohibited.”

Meanwhile the ANJ (French Gambling authority) is also actively enforcing this towards the bigger fish.

Plateformes de marchés de prédiction : des sites illégaux en France qui peuvent présenter des risques pour les utilisateurs | ANJ

This iniative has now entered “Season 3” of CTO watching and reviewing movies.

Questions:

  1. What legal analysis was performed before a French cooperative devoted development resources to launching and promoting a real-money prediction-market interface, only days after the French gambling regulator publicly stated that prediction-market platforms are unauthorised gambling services in France?
  2. Can Cooperative share how much money and/or hours have been spent on this project?
  3. What % of Cooperative members stand behind this project?

Seer

The Seer seems like an external project, yet in branding it looks exactly like a Kleros app.
Most marketing also has been done through Kleros, their telegram channels and their blogs.
This project shares the same CTO with Kleros.

Seer also triggers the ANJ concerns.

In a perfect world, Seer would have integrated with Kleros without much help from the Cooperative and its resources (that should remain neutral, and not cross into grey / black legal areas). However listing the points above this seems not the case.
Also publicly in the Gitcoin Goverannce proposal strong ties with Kleros are insiunated.

Questions:

  1. How much money has been spent from Cooperative on Seer?
  2. How many roles, from design, Seer recruiting, UX, contracts came from the Cooperative?
  3. What % of Cooperative members stand behind this engagement?
  4. What legal review has Cooperative done before engaging so directly with this iniative?

Proof of Humanity

Proof of Humanity already has had two project revisions.

V1 had a strong start, but the decentralized Governance aspect fell apart fast with drama, unfortunately seeping into public events.

Kleros itself acknowledged this in May 2023:

“The governance difficulties in the Proof of Humanity DAO have delayed the launch of Proof of Humanity 2.0.”

[2]

Despite this, the project was not spun off from Kleros.

In its 2024 project update, Kleros stated:

“Kleros has continued its development on Proof of Humanity 2.0”

and described work across the smart contracts, UI, subgraphs and cross-chain integrations. [22]

Formal PoH DAO governance today appears substantially less active than during its original period, while the development relationship with Kleros has continued.

Disclaimer: I have reached out to Cooperative to share these findings, however was not met with a reply.

For this post I’d like to focus mainly on the regulatory aspects, namely GDPR and rules surrounding identity systems.

Seeing that Cooperative is a French entity, we’ll focus on the EU/French rules it certainly needs to consider.

What data is being collected?

As of today, the Proof of Humanity website describes registration as:

“Provide your name, photo, and a short video to create your identity profile.”

[21]

The website also describes the system as providing verified human identities and links those identities to blockchain addresses/humanity IDs. [21]

Article 4(14) GDPR defines biometric data as personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics which allow or confirm unique identification.

Article 9 gives special protection to biometric data processed for the purpose of uniquely identifying a person. [23]

At minimum, this means that an identity system intentionally built to identify unique humans from identity/profile information, photographs and video deserves a serious GDPR analysis.

These concerns are not new

The first public concern I have found dates back to March 2021.

Community member Adam Burns asked in the Proof of Humanity Telegram:

“Does Kleros have a Data Protection Officer or Compliance Officer? This policy document does not align to the principles of the EU GDPR (data minimisation, etc)…”

Clément Lesaege responded:

“Kleros and Proof of Humanity are smart contracts. Not data processors.”

[28]

This position deserves revisiting.

CNIL’s (French Authority: Commission nationale de l’informatique et des libertés) own blockchain guidance says:

“When a blockchain contains personal data, the GDPR is applicable.”

CNIL further explains that in many cases a blockchain participant can qualify as a data controller where that participant determines the purposes and means of the processing. [24]

Whether Cooperative is controller, joint controller, processor, or has another legal role should therefore depend on the real operation of Proof of Humanity:

  • who designed the system;
  • who operates the frontend;
  • who determines what information is required;
  • who operates backend/subgraph infrastructure;
  • who develops the contracts;
  • who selects third-party processing services;
  • who promotes registrations;
  • and who determines how profile information is handled.

Simply describing the system as “smart contracts” does not by itself resolve those questions.

Also adding that at it’s own discretion, Cooperative, without informing the users, feeds uploaded videos from Proof of Humanity into an American deepfake AI tool. This to me only strengethens the fact that Cooperative is operating this and that “decentralisation” is far to be seen.

Permanence and the right to erasure

This is probably the biggest structural issue.

CNIL describes a defining property of blockchain as:

“irreversibility: once data is recorded, it cannot be altered or removed”

[24]

CNIL specifically identifies rectification and erasure as difficult areas when personal data is involved in a blockchain.

Proof of Humanity deliberately creates persistent links between humans, profiles and blockchain identifiers.

The concern is therefore not merely whether a profile can disappear from the current frontend.

The real question is what happens to:

  • historical evidence URIs;
  • IPFS CIDs;
  • cached copies;
  • third-party pins;
  • subgraph records;
  • blockchain references;
  • wallet-to-humanity relationships;
  • previously published photographs or videos.

The GDPR dossier I previously supplied (to Coop) goes into this issue in detail. [28]

If removing a profile from a frontend merely changes its current application status while the original personal-data trail remains retrievable, it is reasonable to ask how Article 16 rectification and Article 17 erasure are actually fulfilled.

PoH also does not ask from consent, it does not inform the user, it does not inform the user on deepfake processing, it does not explain IPFS and the nature that these profiles may be stored indefinitely by anyone. No privacy policy to be found on the app.

CNIL itself recommends questioning at the privacy-by-design stage whether blockchain is necessary at all for a processing operation involving personal data, and recommends avoiding storing personal data in cleartext on-chain. [24]

DPIA / Privacy by Design

Article 35 GDPR requires a Data Protection Impact Assessment (DPIA/AIPD) where processing is likely to result in a high risk to the rights and freedoms of individuals. [23]

CNIL describes the DPIA as the tool used to build and document GDPR-compliant high-risk processing. [25]

Proof of Humanity combines several features that make the question particularly relevant:

  • an identity system;
  • photos and video;
  • unique-human verification;
  • blockchain technology;
  • publicly accessible information;
  • persistent identifiers;
  • potentially large numbers of users;
  • and interaction with third-party infrastructure.

I therefore think it is reasonable to ask whether a DPIA was performed before the system went live and, if not, why not.

Questions

  1. Was a DPIA conducted before Proof of Humanity v2 went live?
  2. If so, can Cooperative publish it, or at least confirm its existence and conclusions?
  3. Who was identified as controller / joint controller / processor for each component?
  4. What retention model was approved?
  5. What deletion model was approved?
  6. Has CNIL ever been consulted regarding the architecture?

Data Protection Officer

Article 37 GDPR requires the appointment of a DPO in certain circumstances, including where core activities involve large-scale processing of special-category data. [23]

Special-category data in this case implies biometrics, live video and audio. Which PoH revolves around.

I do not want to assume the legal conclusion here without knowing Cooperative’s internal analysis.

So the questions are straightforward:

  1. Does Cooperative consider Proof of Humanity’s processing to fall within Article 37?
  2. If yes, who is its Data Protection Officer and where are their contact details published?
  3. If Cooperative considers Article 37 not applicable, on what analysis?

French criminal data-protection provisions

There are also French national provisions which make these questions more than theoretical.

Article 226-17 of the French Penal Code states:

« Le fait de procéder ou de faire procéder à un traitement de données à caractère personnel sans mettre en oeuvre les mesures prescrites aux articles 24, 25, 30 et 32 du règlement (UE) 2016/679 […] est puni de cinq ans d’emprisonnement et de 300 000 euros d’amende. »
EN: Processing or having processed personal data without implementing the measures prescribed in Articles 24, 25, 30 and 32 of Regulation (EU) 2016/679 […] is punishable by five years’ imprisonment and a fine of €300,000.”

[26]

This should not be read as an accusation that any individual at Kleros has committed this offence. That is for competent authorities and courts to determine.

It does however demonstrate why questions concerning:

  • accountability;
  • privacy by design;
  • records of processing;
  • and security of processing

cannot simply be dismissed as a philosophical disagreement over decentralisation.

Paying people in PNK to enter PoH

The current Proof of Humanity homepage advertises:

“Airdrop for early adopters: Register yourself as human, claim 1,200 $PNK and stake to double your allocation! First 10,000 humans only.”

[21]

This creates another data-protection question.
Consent needs to be genuinely freely given, and people need to be able to refuse or withdraw consent without pressure or detriment. [27]

Financial incentives or financial consequences can therefore become relevant when assessing whether consent is genuinely free.

Given that the registration process involves a person’s identity information, photograph and video, Cooperative should explain:

  • what legal basis it relies upon for processing this information;
  • whether Article 9 explicit consent is relied upon;
  • and, if so, how it concluded that directly attaching a financial reward to registration does not undermine the freely-given nature of that consent.

There is also the economic question of what the incentive has actually achieved for the Kleros ecosystem.

Questions

  1. What GDPR legal basis does Cooperative rely on for processing carried out through Proof of Humanity?
  2. Was a DPIA conducted, and when?
  3. Who has been identified as controller / joint controller / processor?
  4. How are Article 16 and Article 17 rectification and erasure requests fulfilled in practice?
  5. What happens to IPFS copies, CIDs and historical references when a user requests deletion?
  6. What third parties receive photos or video, and under what data-processing agreements and international-transfer mechanism?
  7. Of the PNK handed out, how much was immediately sold?
  8. Of the PNK handed out, how much was staked for longer than a month?
  9. What can Cooperative tell us about profile farming motivated primarily by the financial incentive?
  10. Does the wider Cooperative stand behind PoH?
  11. Has the legality of attaching PNK rewards to registration been reviewed by external privacy counsel?

Governance and accountability

The Court upgrade has seen Cooperative struggle to present a coherent plan, certain side projects of Cooperative not only risk dilution of attention to the Court, but also pushes the Cooperative into reguatlory conflict, which ultimately is not in the interest of the Court and the wider protocol.

From the Coperatives Statues (raison d’être):

FR « La Société a pour objet, en France et dans le monde, de créer, de développer et de promouvoir un protocole informatique et décentralisé de résolution des litiges. »
« KLEROS est un projet ouvert, dont le code source est distribué librement (open-source), gratuit et transparent. »
« L’activité de production de la Société a pour particularité de profiter à l’ensemble d’une communauté composée des utilisateurs – personnes arbitres ou justiciables, projets tiers recourant au service –, des fondateurs, des développeurs et des salariés. »

EN
The Company’s purpose, in France and worldwide, is to create, develop, and promote a decentralized, computerized protocol for dispute resolution.
KLEROS is an open-source project, with freely distributed (open-source), free of charge, and transparent.
The Company’s production activity is unique in that it benefits an entire community comprised of users—arbitrators or litigants, third-party projects using the service—founders, developers, and employees.

  1. What is the decision framework within Cooperative? Who ultimately decides what gets done?
  2. Given the scope of the raison d’être, are these side activities generally approved by all the members of the Cooperative, or these extra projects done at the sole discretion of the CEO and or CTO?

Closing thoughts

I’ve kept my personal opinions out of this post, and I encourgage for the continued discourse to only focus on the facts, avoiding gaslighting, personal political views and focus solely for the benefit of the cooperative and the broader Kleros arbitration protocol.

Appendices / evidence

Court V2

[1] Federico Ast, “Kleros Project Update - February 2022”, 25 February 2022

[2] Federico Ast, “Kleros Project Update - May 2023”, 3 May 2023

[3] Guangmian Kung & Damjan Malbašić, “Court V2 Integration Sneak Peek”, 29 January 2024

[4] Jean P, “Kleros 2.0 Beta is Here: Get Started”, 14 November 2024

[5] Parul Yadav, “Kleros Development Update: September 2025”, published 22 October 2025

[6] Parul Yadav, “Kleros Development Update: October 2025”, published 7 November 2025

[7] Parul Yadav, “Kleros Development Update March 2026”, published 15 April 2026

[8] Parul Yadav, “Kleros Development Update April 2026”, published 15 May 2026

[9] Parul Yadav, “Kleros Development Update May”, published 12 June 2026

[10] Kleros Telegram discussion — 19 May 2026
Archived Telegram export / screenshots retained by the author. Relevant discussion between Clément Lesaege, Jay Buidl, Green and other community members.

Foresight / Prediction Markets

[11] Parul Yadav, “16 Movies, 1 Judge, and a Prediction Market: Introducing the Kleros Foresight”, 4 March 2026

[12] Parul Yadav, “What the First Foresight Experiment Taught Us About Predicting Clément’s Movie Taste”, 3 June 2026

[13] Parul Yadav, “Kleros Development Update May”, 12 June 2026

[14] Kleros Foresight — public experiment index

[15] Code de la sécurité intérieure — Article L320-1, Légifrance
https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000039182525

[16] Code de la sécurité intérieure — Article L320-6, Légifrance
https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000039169738

[17] Autorité nationale des jeux, “Plateformes de marchés de prédiction : des sites illégaux en France qui peuvent présenter des risques pour les utilisateurs”, 24 February 2026

[18] Autorité nationale des jeux, “Promotion d’une offre de jeux d’argent illégale : blocage du site Polymarket”, July 2026

Seer

[19] Jean P, “Seer: Airdrop to Kleros Jurors and Proof of Humanity Users”, 2 November 2024

[20] Gitcoin Governance, “Metafunding: Fund PGF Mechanisms & Research”, 2025

Proof of Humanity / GDPR

[21] Proof of Humanity — official website

[22] Federico Ast, “Kleros Project Update 2024”, 15 August 2024

[23] Regulation (EU) 2016/679 — General Data Protection Regulation
Articles 4, 5, 7, 9, 12–17, 25, 30, 32, 35, 37 and 44–49
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679

[24] CNIL, “Blockchain and the GDPR: Solutions for a responsible use of the blockchain in the context of personal data”

[25] CNIL, “L’analyse d’impact relative à la protection des données (AIPD)”

[26] Code pénal — Article 226-17, Légifrance
https://www.legifrance.gouv.fr/codes/article_lc/LEGIARTI000037825504

[27] European Data Protection Board, “Guidelines 05/2020 on consent under Regulation 2016/679”

[28] POH_GDPR_VIOLATIONS — supporting dossier
Includes archived March 2021 Proof of Humanity Telegram discussion and analysis of GDPR Articles 3, 4/9, 5, 7, 12–13, 16–17, 25, 30, 32, 35, 37 and 44–49.