Replying to @null and @SimonDeDeo, @matthewstoller, @joftius
For libs, the risk is almost null since they aren't controllers of the data, acting independently. I could imagine a complex & poorly documented system getting in the way of transparency obligations, but it's a stretch.