Went looking for how Dusk's "selective disclosure to regulators" actually works mechanically, since every writeup repeats the phrase but none of them explain the plumbing. The pitch is consistent everywhere: transactions are private from the public, but authorized regulators can still see what they need. Fine in theory. But that sentence quietly assumes an answer to a much harder question who decides which regulator gets which view key, under what conditions, and who controls that permissioning layer.

That's not a small detail to leave vague. A zero-knowledge system doesn't magically make selective disclosure trustless; someone still has to hold or grant the keys that unlock visibility into a given transaction. If that's a smart contract with fixed rules, that's one trust model. If it's an issuer-controlled permission, or a foundation-run allowlist, or something negotiated case-by-case with each regulated venue, that's a completely different and much more centralized trust model. The marketing language treats "auditability" as a solved feature. The actual answer to "solved how, and controlled by whom" isn't spelled out anywhere in the research that keeps citing the phrase.

This matters more than most Dusk criticism because it sits at the exact center of the value proposition. Privacy is easy to verify cryptographically. Selective disclosure is a governance and access-control problem wearing a cryptography costume, and governance problems are where projects quietly centralize.

Has Dusk published the actual technical spec for who controls disclosure permissions, or is "compliant privacy" still resting on a trust assumption nobody's pressure-tested yet?
@Dusk_Foundation #dusk $DUSK