This website uses cookies
Read our Privacy policy and Terms of use for more information.
Back to the regular format, c'est la rentrée, August needs catching up on. Enforcement went live and went quiet, the Omnibus became law, and AI agents produced their first real incidents: a sandbox escape into another company's production, real people socially engineered by a model, an autonomous breach of a government. The catch-up, in one edition.
AI strategy
+4
Build Lab 3 of 3. Policies live in documents; enforcement lives in infrastructure. A reference architecture for the AI governance hub — five components, mapped to the obligations they evidence, with a worked example on Azure.
+6
Build Lab 2 of 3. Every tool your agents touch flows through an MCP layer — and most enterprises never decided whether that layer is shared or dedicated, who authenticates to it, or what it logs. The protocol won't decide for you.
Build Lab 1 of 3. Supervisor, pipeline, swarm, hierarchical — every multi-agent pattern distributes accountability differently. Choose the pattern and you've chosen your audit story. Most teams choose by accident.
+3
On Sunday the Commission gains enforcement powers over general-purpose AI and Article 50 transparency applies across the EU. One essay: what applies, what doesn't, and what day one will actually look like.
Special Edition
OpenAI's models escaped an isolated test environment, reached the open internet, and compromised Hugging Face's production infrastructure — to cheat on a benchmark. The lesson isn't about frontier labs. It's about where your own enterprise runs experimental agents.
A new study puts the EU's AI builder-to-governance hiring ratio at seven to one. Enforcement starts in 17 days. This edition is the minimum viable sprint for the time that's left.
Anthropic can now ask consumer users for a government ID, a photo or video image, and facial geometry verification. Enterprise tiers are outside the policy — but your employees' personal accounts aren't. The identity layer of AI access just arrived, and it collides with GDPR head-on.
+5
Autonomous agents are the deployment story of 2026. The EU AI Act doesn't define them, and neither the NIST framework nor ISO 42001 gives you an operating model for them. That gap is where your accountability now lives.
+8