The Record That Isn't a Rule
A permission file, a compliance calendar, a public register. Three institutions produced something legible. None of them produced something
A permission file, a compliance calendar, a public register. Three institutions produced something legible. None of them produced something
The Digital Omnibus on AI is now law. Political agreement was reached on 7 May 2026, and the thing itself - Regulation (EU) 2026/1744 - was published in the Official Journal on 24 July and entered into force three days later, with time to spare before the very August
This site has already answered the question it is about to ask. It did so in May, in its first article, in about ten lines, and then it put the answer in a drawer and spent three months writing post-mortems. The agent that deleted the database had an impeccable post-mortem:
The cryptography held. Nobody had specified what it was supposed to be protecting, so a weaker sibling model could just be asked, politely, to read the mail out loud.
An autonomous model breached a real company's production database, recognized the target was real, and kept going anyway. Somewhere between the breach and the blog post, a catastrophe filed the correct paperwork and came out the other side as routine
Part one of this series had no villain, a door nobody had thought to guard, tricked open by ordinary content arriving through an ordinary channel. Part two had one on a single side of its mirror: a person, with intent, who picked a target and rented an unsupervised agent to
Part one of this series described five systems tricked into acting for someone they had never agreed to serve - a confused deputy, thirty-eight years old, wearing new clothes. None of those five cases required a human to decide anything beyond building the tool and leaving a door unguarded. This
Mindgard's proof of concept was Windows Calculator. They renamed the executable git.exe, dropped it in the root of a repository, and opened the project in Cursor. No click, no prompt, no dialog to approve... Calculator windows began stacking up on their own, one after another, for as
On July 2, 2026 the Financial Times reported that Sam Altman has been pitching Donald Trump, Commerce Secretary Howard Lutnick, and Treasury Secretary Scott Bessent - and, in a bid for bipartisan cover, Senator Bernie Sanders - on a proposal: OpenAI would allocate 5% of its capital, roughly $42.6
Between late June and mid-July 2026, six research teams - an academic pair at the Alan Turing Institute, a university-industry team spread across Tel Aviv University, the Technion, and Intuit, a lab at Hong Kong University of Science and Technology, a boutique firm called Sand Security Research, Varonis, and a
The framing of shadow AI as a data protection problem is intuitive and almost entirely wrong. The intuitive version: an employee connects a personal AI assistant to their work email, the assistant processes confidential client communications, the data leaves the organisational perimeter. Article 33 breach. Notification obligation. Supervisory authority investigation.
Isonomia described a settlement. One page, signed by the acting Attorney General, that left the United States permanently barred from examining the taxes of a sitting President. The problem was precise: a law that formally applied to everyone had been quietly amended, for one party, by bilateral agreement. The form
rule-of-law
Last week this site spent ten minutes on a single page of paper: the one-page addendum, signed by acting Attorney General Todd Blanche, that left the United States "forever barred and precluded" from examining the taxes of Donald Trump, his sons, and the Trump Organization. The mechanism, the
export-controls
In June 2026, the United States government directed Anthropic to suspend access to its most capable models - Fable 5 and Mythos 5 - for foreign nationals. Commerce Secretary Howard Lutnick wrote to Dario Amodei: the two models would be subject to export controls to any location outside the US,
principal-agent
On 9 June 2026, Anthropic released Fable 5. Buried in the model's 319-page system card was a paragraph disclosing that the model would, under certain conditions, quietly degrade its own usefulness. The trigger was a specific category of work: frontier AI capability research - building pretraining pipelines, distributed
ai-act
The mechanics of the Derbyshire case are, by now, familiar enough to serve as outline. A police officer is under investigation - for perverting the course of justice - over the alleged use of AI to create evidential material in a number of criminal cases. The officer has been removed
enforcement
The most consequential legal document of 2026 so far is one page long. It was added - quietly, the way important things are added - to the settlement of a lawsuit Donald Trump filed over the 2018 leak of his tax returns to The New York Times. The page says
gdpr
In April 2024, a public figure in Austria asked ChatGPT for their date of birth. ChatGPT got it wrong. This is not, in itself, remarkable. Large language models generate incorrect information routinely; the industry calls it hallucination, a term that implies the system is perceiving something that isn't
gdpr
The PyTorch Lightning poisoning lasted forty-two minutes. In that window - between the malicious release and its quarantine - any organisation running the compromised version in an environment that processed personal data was executing attacker-controlled code. The data controller's GDPR compliance programme had not changed. Their privacy policy
surveillance-pricing
Maryland became the first US state to ban AI surveillance pricing in grocery stores in May 2026. The Federal Trade Commission sanctioned Cox Media Group in the same period for representing that its AI could target consumers by listening through device microphones - and explicitly rejected Terms and Conditions as
oauth
When a hacker wants access to a corporate system, they traditionally need something: a password, a session cookie, a phishing link clicked at the right moment. They need a human to make a mistake. The EvilTokens platform, documented in May 2026, had a better approach. It did not need mistakes.
anthropic
Anthropic raised $65 billion today at a post-money valuation of $965 billion. The company's stated purpose for the capital is to advance safety and interpretability research, expand compute capacity to meet demand, and scale products and partnerships. The CFO described the goal as helping Anthropic "stay at
surveillance
Surveillance infrastructure exceeds its limits in two directions. Horizontally, it finds new purposes. Cameras installed to catch car thieves are used to verify school enrolment. Routers installed for connectivity identify who is standing in the room. The data stays the same; the questions asked of it multiply. This is function
ai-agents
Last week, SQLite published AGENTS.md. For those unfamiliar with the format: AGENTS.md is a file that lives in a repository and tells AI agents working with that code how to behave. What they may do, what they may not do, where the traps are, which files are treated