Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cybersecurity Directive That Reached Ten Times More Entities

The headline change in Europe's network security directive is scope. Directive (EU) 2022/2555 reaches an estimated hundred and sixty thousand entities across eighteen sectors, roughly ten times what its predecessor covered. ‍ The more consequential change is who decides. Under the previous regime a member state identified operators of essential services individually, through an assessment of criticality and dependency.

AI Review of Privileged Material and the Waiver Question

Sending privileged material through an external AI service is a disclosure to a third party, and voluntary disclosure to a third party waives privilege. The reasoning is straightforward and a federal court has now applied it. ‍ A second federal court reached the opposite conclusion on the same question within days, on a distinction the first did not draw. The position is genuinely unsettled, and the parts that are settled point at configuration choices rather than at a prohibition. ‍

The AI Act Duty That Applies Regardless of Risk Tier

Almost every obligation in the AI Act is keyed to a risk classification. Work out which tier a system falls into and the duties follow. ‍ Article 4 is not. It applies to providers and deployers of any AI system whatever it does, its subject is people rather than systems, and national authorities began supervising and enforcing it from 2 August 2026 while the high-risk regime moved to December 2027. It is the live one, and it sits outside the structure most governance programs are built on. ‍

Cyber Loss When the Company Is Someone Else's Fourth Party

Third-party risk content is written from the customer's side. Assess your provider, tier your vendors, understand your concentration. ‍ A technology provider is on the other end of every one of those assessments, and its own incident propagates outward through contract rather than inward through remediation. The instinct is that the contracts therefore determine the loss. They determine the smaller half of it. ‍

Cyber Loss When the Product Is a Clinical Trial

A cyber loss model for a research organization counts subject records and applies a per-record cost. Personal health information, a notification exercise, a regulatory penalty. ‍ The mechanism that matters in a trial is integrity rather than confidentiality, and it produces a loss that occurs even where nothing was altered. What gets destroyed is the ability to demonstrate that nothing was. ‍

AI Governance When the Data Subject Is a Minor

The assumption about AI systems affecting children is that the consent structure carries the difficulty. The subject cannot consent, so a parent consents instead, and the governance problem is collecting and tracking that permission. ‍ The assumption is backwards. Consent is usually the wrong lawful basis for these deployments, so the parental consent machinery is not required at all. What differs is something else entirely. ‍

Measuring AI Agent Coverage Against the Gateway Log

A tool gateway reads every call that crosses it and enforces policy on each one. It is blind to whatever never traverses it, which is established and not the interesting part. ‍ The useful number is what fraction of an agent's total action surface the gateway covers. Blindness of unknown size and blindness of known size are different problems, and only the second lets you state what a gateway-based claim is worth. ‍

Fine-Tuning Is Not What Reclassifies an AI Deployer

The concern about fine-tuning is that it quietly converts a deployer into a provider, pulling in conformity assessment, technical documentation and a quality management system nobody budgeted for. ‍ The concern is misdirected. Fine-tuning is among the least likely routes to reclassification, and the route almost nobody worries about requires no training compute at all. ‍

AI Governance for Public Bodies, and Who Shares the Obligation

A public body running a high-risk AI system owes a fundamental rights impact assessment under Article 27 before first use, with the results notified to a market surveillance authority. The obligation is real and it is not yet in force. ‍ Regulation (EU) 2026/1744, in force since July 2026, deferred the section of the Act containing Article 27 to December 2027 for standalone high-risk systems and August 2028 for those embedded in regulated products.