Our Latest Articles
-
The AI Act Now Recognises Agents. Its Security Rules Still Miss Them.
The Commission's AI Act Service Desk says agents are covered by the existing definitions and calls its own considerations preliminary.…
Read More » -
One AI Incident, Four Reporting Regimes, and the Carve-Outs That Decide Which Apply
Cyber Resilience Act reporting starts 11 September 2026, joining three other European regimes. The AI Act already limits its own…
Read More » -
The AI Act’s Transparency Code Relies on Watermarks That Break
Article 50 requires marking that is effective and robust as far as technically feasible, and prescribes no technique. The Code…
Read More » -
The AI Act’s GPAI Security Chapter Is a Weight Security Mandate
Article 55(1)(d) requires an adequate level of cybersecurity for a frontier model and its physical infrastructure, and the Commission-endorsed Code…
Read More » -
Article 15 Requires Robustness Nobody Can Measure
Article 15(5) runs to three sentences and most summaries quote only the first. The other two set a proportionality standard…
Read More » -
The EU AI Act for Security Teams
The first enforcement step under the EU AI Act was a demand for security evidence. What the Digital Omnibus deferred…
Read More » -
You Can Bomb the Data Centre. You Cannot Uncopy the Model.
Striking AI infrastructure can stop a training run, destroy accelerators and deny a rival its models for months. What force…
Read More » -
Your Multi-Region Architecture Assumes the Weather
Cloud resilience architecture is built against hazards: storms, fibre cuts, bad deploys. On 1 March 2026 one AWS region absorbed…
Read More » -
What Still Keeps Frontier Training Concentrated
Every argument about attacking AI compute assumes frontier training stays physically concentrated. That is an engineering trade-off rather than a…
Read More »
