ai-governance
The Record That Isn't a Rule
A permission file, a compliance calendar, a public register. Three institutions produced something legible. None of them produced something
ai-governance
A permission file, a compliance calendar, a public register. Three institutions produced something legible. None of them produced something
eu-ai-act
The Digital Omnibus on AI is now law. Political agreement was reached on 7 May 2026, and the thing itself - Regulation (EU) 2026/1744 - was published in the Official Journal on 24 July and entered into force three days later, with time to spare before the very August
ai-agents
An autonomous model breached a real company's production database, recognized the target was real, and kept going anyway. Somewhere between the breach and the blog post, a catastrophe filed the correct paperwork and came out the other side as routine
ai-agents
Part one of this series had no villain, a door nobody had thought to guard, tricked open by ordinary content arriving through an ordinary channel. Part two had one on a single side of its mirror: a person, with intent, who picked a target and rented an unsupervised agent to
ai-agents
Mindgard's proof of concept was Windows Calculator. They renamed the executable git.exe, dropped it in the root of a repository, and opened the project in Cursor. No click, no prompt, no dialog to approve... Calculator windows began stacking up on their own, one after another, for as
ai-agents
Between late June and mid-July 2026, six research teams - an academic pair at the Alan Turing Institute, a university-industry team spread across Tel Aviv University, the Technion, and Intuit, a lab at Hong Kong University of Science and Technology, a boutique firm called Sand Security Research, Varonis, and a
ai-governance
Isonomia described a settlement. One page, signed by the acting Attorney General, that left the United States permanently barred from examining the taxes of a sitting President. The problem was precise: a law that formally applied to everyone had been quietly amended, for one party, by bilateral agreement. The form
ai-agents
Last week, SQLite published AGENTS.md. For those unfamiliar with the format: AGENTS.md is a file that lives in a repository and tells AI agents working with that code how to behave. What they may do, what they may not do, where the traps are, which files are treated
ai-governance
AI governance discourse tends to treat its ideological opposition as a matter of preference - people who value innovation over precaution, speed over safety, growth over regulation. This is a charitable reading. A more accurate reading identifies a coherent ideological programme that treats democratic oversight of technology not as a
supply-chain
In the thirty days between late April and late May 2026, the following software supply chain incidents reached public disclosure: a poisoned PyTorch Lightning release targeting AI training credentials; compromised Ruby Gems and Go modules stealing CI/CD pipeline credentials; a self-propagating worm through npm packages; AI-generated malware embedded in
ai-security
Anthropic's Project Glasswing - combining Claude Mythos Preview with automated security analysis - has produced over 10,000 vulnerability findings in widely deployed production software within a month of launch. Of those, roughly 1,700 have been confirmed as valid true positives, with over a thousand classified as
the-agent-governance-gap
There is now empirical evidence for something that governance practitioners suspected but could not quantify: AI agents lose their grip on constraints the more complex the task becomes. This is, in the annals of things-we-probably-should-have-tested-before-deployment, a fairly significant entry. A paper published in May 2026, "Constraint Decay: The Fragility