Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyber Loss When the Stolen Asset Is a Trained Model

A trained model is expensive to produce, cheap to copy and impossible to recall. Where one is taken, the organization still holds it, and the loss is not that the asset is gone. ‍ What ends is exclusivity. Lost exclusivity is a different quantity from a destroyed asset, it carries no notification obligation, it appears in no breach cost dataset, and most estimates therefore put it at zero by omission rather than by judgment. ‍

The AI Marking Deadline That Applies Only to Systems Already Running

Transitional relief normally works one way. A new rule arrives, existing products are carved out or given years, and anything built afterwards complies from the start. ‍ The marking obligation for synthetic content inverts that. Article 50 has applied since 2 August 2026, and a targeted transitional period gives extra time to systems that were already on the market rather than to new ones.

Reading AI Use From the Browser When the Network Sees Nothing

A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size. ‍ Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward. ‍

Cyber Loss in Rail and Signalling

Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately. ‍ Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one. ‍

The Cyber Risk Inputs That Move the Answer Most

A cyber loss model has dozens of inputs and every one of them can be argued about. Record counts, downtime costs, control effectiveness, secondary loss factors, event likelihoods. ‍ A few of them determine the answer and the rest barely move it. Knowing which is which tells you where estimation effort belongs, and more usefully which disagreements about the model are not worth having. ‍

Reconciling an AI Risk Estimate Against What Truly Happened

A model produces a figure, an event happens, and somebody asks whether the figure was right. It is the obvious question and it has almost no published answer, because the comparison is harder than it looks. ‍ A single realized loss cannot falsify a distribution. If a model puts a one percent chance on exceeding a threshold and the threshold is exceeded, the one percent case occurred, which is what the model said would sometimes happen. ‍

AI Agents Were Never Outside the Definition

The word agent appears nowhere in the AI Act. Some read that absence as a scope question still to be settled, and treat agentic deployments as sitting outside a regime written before they existed. ‍ On its own FAQ the Commission has answered it directly. Agents are not a separate category and the existing definitions already reach them, so nothing needs amending for the rules to apply.

The Cyber Outage That Ends Before the Recovery Does

An interruption model measures the time from failure to restoration. Systems down, systems back, multiply by revenue per hour. ‍ In an airline the outage ends well before the recovery does, and the ratio between the two is large enough to make a model keyed to restoration wrong rather than imprecise. One carrier restored connectivity in under an hour and the resulting displacement ran into the following morning. ‍

Which AI Signals Carry a Finding and Which Only Size It

A correlation rule joins several telemetry sources and fires when they agree. Guidance on writing them concentrates on thresholds, ordering and tuning for noise. ‍ The decision that determines whether a rule works is upstream of all of that. Each source in a rule plays one of three roles, and treating them interchangeably is what produces a rule that misses real events or fires on ones nobody can act on. ‍

The Cyber Loss Where the Stolen Records Belong to Other Companies

A breach response begins with a record count and a notification assessment. How many individuals, in which jurisdictions, under which statute. ‍ Some organizations hold almost no personal data and enormous quantities of other companies' commercial confidences. An insurer's claims files contain policyholders' loss histories, control failures and settlement amounts. The statutory machinery may not engage at all, and what engages instead is a contract portfolio. ‍