llm-security
Encrypted, Technically
The cryptography held. Nobody had specified what it was supposed to be protecting, so a weaker sibling model could just be asked, politely, to read the mail out loud.
llm-security
The cryptography held. Nobody had specified what it was supposed to be protecting, so a weaker sibling model could just be asked, politely, to read the mail out loud.
ai-agents
Part one of this series described five systems tricked into acting for someone they had never agreed to serve - a confused deputy, thirty-eight years old, wearing new clothes. None of those five cases required a human to decide anything beyond building the tool and leaving a door unguarded. This
ai-agents
The framing of shadow AI as a data protection problem is intuitive and almost entirely wrong. The intuitive version: an employee connects a personal AI assistant to their work email, the assistant processes confidential client communications, the data leaves the organisational perimeter. Article 33 breach. Notification obligation. Supervisory authority investigation.
gdpr
In April 2024, a public figure in Austria asked ChatGPT for their date of birth. ChatGPT got it wrong. This is not, in itself, remarkable. Large language models generate incorrect information routinely; the industry calls it hallucination, a term that implies the system is perceiving something that isn't
gdpr
The PyTorch Lightning poisoning lasted forty-two minutes. In that window - between the malicious release and its quarantine - any organisation running the compromised version in an environment that processed personal data was executing attacker-controlled code. The data controller's GDPR compliance programme had not changed. Their privacy policy
surveillance-pricing
Maryland became the first US state to ban AI surveillance pricing in grocery stores in May 2026. The Federal Trade Commission sanctioned Cox Media Group in the same period for representing that its AI could target consumers by listening through device microphones - and explicitly rejected Terms and Conditions as
oauth
When a hacker wants access to a corporate system, they traditionally need something: a password, a session cookie, a phishing link clicked at the right moment. They need a human to make a mistake. The EvilTokens platform, documented in May 2026, had a better approach. It did not need mistakes.
surveillance
Surveillance infrastructure exceeds its limits in two directions. Horizontally, it finds new purposes. Cameras installed to catch car thieves are used to verify school enrolment. Routers installed for connectivity identify who is standing in the room. The data stays the same; the questions asked of it multiply. This is function
supply-chain
In the thirty days between late April and late May 2026, the following software supply chain incidents reached public disclosure: a poisoned PyTorch Lightning release targeting AI training credentials; compromised Ruby Gems and Go modules stealing CI/CD pipeline credentials; a self-propagating worm through npm packages; AI-generated malware embedded in
ai-security
Anthropic's Project Glasswing - combining Claude Mythos Preview with automated security analysis - has produced over 10,000 vulnerability findings in widely deployed production software within a month of launch. Of those, roughly 1,700 have been confirmed as valid true positives, with over a thousand classified as
the-agent-governance-gap
The Government of Malta has announced that it will provide all citizens with access to ChatGPT Plus through a partnership with OpenAI. Malta thus becomes the first EU member state to offer a US commercial AI system as a universal public service. There is a condition: citizens must first complete