Stay In The Know Brussels just moved the goalposts. On 27 July, the AI Omnibus entered into force. High-risk obligations under the AI Act shift from 2 August 2026 to 2 December 2027. Embedded high-risk systems get until August 2028. The Commission gave its reason plainly: harmonised standards and compliance tools were not ready. Read the delay correctly. The requirements survived intact. Data governance, logging, human oversight, security. You gained 16 months to build evidence, and your auditors gained 16 months to prepare sharper questions. The question that outlasts every deadline shift: where does your AI process sensitive data, and who can read it while the model runs? Confidential computing answers with hardware. Workloads stay encrypted during inference, and the CPU issues a cryptographic attestation that proves it. Teams that build this in now walk into December 2027 with evidence, while others start drafting policies. #AIAct #ConfidentialComputing #AICompliance
enclaive’s Post
More Relevant Posts
-
Public sector AI often fails to scale, not because models are weak, but because security and network architectures cannot support continuous, autonomous, cross-agency operation. This webinar explains why zero trust with continuous verification, inline inspection, and policy enforcement is the key enabler for mission-grade AI in sensitive government workflows, helping agencies expand automation without sacrificing compliance, auditability, or resilience. Check it out F5's on-demand webinar here: http://ms.spr.ly/6046v2cJQ
To view or add a comment, sign in
-
-
Public sector AI often fails to scale, not because models are weak, but because security and network architectures cannot support continuous, autonomous, cross-agency operation. This webinar explains why zero trust with continuous verification, inline inspection, and policy enforcement is the key enabler for mission-grade AI in sensitive government workflows, helping agencies expand automation without sacrificing compliance, auditability, or resilience. Check it out F5's on-demand webinar here: http://ms.spr.ly/6045v0iEt
To view or add a comment, sign in
-
-
Brittany Kaiser has seen what happens when data governance fails at scale. At the CCS 2026 keynote panel, the Cambridge Analytica whistleblower and Alpha Compute CEO described what she's seeing now: Nearly every organization is trying to integrate AI agents. The ones holding back aren't slow. They've done the math on data-breach exposure and can't get agents through compliance. Her conclusion: "Confidential computing is more and more not just a compliance issue. This is a national security issue. If we're attaching agents to all of our most sensitive data sets in both the public and private sector, we need to make sure we're running them on confidential computing." Agents amplify what you share. The substrate they run on decides what that costs you. #ConfidentialComputing #AIAgents #CCSummit2026
To view or add a comment, sign in
-
Every major infrastructure category was invisible until it wasn't. Nobody asked for TCP/IP. Nobody asked for SSL certificates. Nobody asked for GDPR compliance frameworks. Until the system broke without them. Right now, across AI, mobility, physical access, energy and financial services, systems are acting on behalf of people without verifying permission. AI agents are executing without verified authorisation. Fleet vehicles are charging without verified entitlement. Contractors are accessing sites without verified clearance. Micromobility vehicles are operating without verified governance. The cost so far: £110m in injury payouts from unverified vehicles. 78% of enterprises unprepared for AI Act enforcement. €35m maximum fine per breach from 2 August 2026. The pattern is always the same. The infrastructure gap is visible in hindsight. The category is built in foresight. Permission Infrastructure is being built now. By Tevver. Patent Pending GB2607457.5 | PCT/GB2026/051262 tevver.com
To view or add a comment, sign in
-
The EU just moved its biggest AI deadline. Most companies haven't noticed. High-risk AI system obligations were set to hit August 2026. That date is now gone. The EU's Digital Omnibus on AI, formally adopted June 2026, pushed things back: → Annex III systems (recruitment, credit scoring, law enforcement): August 2026 → December 2027 → Annex I embedded systems (medical devices, machinery): August 2027 → August 2028 One thing didn't move: Article 50 transparency and watermarking rules still apply from August 2026. Why the delay? The technical standards needed to actually comply weren't ready. Not because the risk went away. Here's the trap: treating extra runway as permission to wait. The requirements didn't shrink. Conformity assessments, Article 12 audit logging, human oversight, EU database registration — all still coming. Only the clock moved. And Article 12 logging is impossible without cryptographic agent identity. You can't build a trustworthy audit trail if you can't prove which agent did what. 16 months isn't a reason to relax. It's time to build this properly instead of scrambling in Q4 2027. #AIGovernance #EUAIACT #AIAgents #AgenticAI #Deadline #moved
To view or add a comment, sign in
-
-
📢 Have you submitted your feedback yet? The PCI DSS v4.0.1 RFC remains open, giving eligible PCI SSC stakeholders an opportunity to share real-world implementation insights and help inform the future evolution of the standard. Stakeholders are encouraged to provide feedback on strengths, opportunities, and emerging technology considerations, including AI innovation. Learn more: https://bit.ly/4dVR4GU
To view or add a comment, sign in
-
-
THE NETWORK THAT OUTLIVED THE HAND The network stands behind the vanished handset. A mill body entered through water, fibre, and output. A cable body followed. A switching body formed beneath the public name. A phone body later received the face. The face became memory. The body remained in the signal. Burden passed through mills, rubber, cable, current, exchanges, and controlled distance. The hand received the object after the route had already been built. The old sound entered the public ear. The keypad entered the hand. The shell carried names, games, repairs, and pockets. It registered presence. The shell became mask. The switch worked below the mask. The first official call proved the route before the hand received the myth. The network survived without recognition. Volume became reassurance. Reassurance became delay. The shell kept selling while the higher layer moved away. Heat entered the shell. Hardware fault entered the record while software power moved elsewhere. A quarterly loss entered the books. The market moved below the device. The software layer became jurisdiction. Another system held the future terms. The partnership table received the platform burden. The operating system moved outside the house. Control moved elsewhere. The sale removed the public body from the legal body. Devices, teams, names, and memory changed custody. The shell that carried recognition left the chamber. The institution continued through networks, patents, standards, and trust. One archive left. Another entered. A larger laboratory entered the record. Transistor, information, operating-system, language, and neural records entered with it. The inherited ghost widened the burden without restoring the hand. The old phone returned by licence. Brand memory returned without full body. The new mark removed the old face. It asked the record to see beneath the handset. The cloud order entered the quarter. The AI file received capital from a stronger machine house. Intelligence entered through partnership. Dependence entered with it. Control reopened. The next body has routes, packets, standards, fibre, agents, and rules. It carries machines speaking to machines. The agent enters the network under policy. Action requires boundary. Automation requires explanation. The operator remains named in the control record. Intelligence without custody becomes another surrender. The old wound stays active. The company once held the object and lost the platform. The next layer asks for stricter custody. A network may carry intelligence and still lose the nervous system. The handset remains in public memory. The switch remains in the lower record. The standard remains in negotiation. The patent remains in custody. The laboratory remains as inherited witness. The hand remembers the object. The file governs the body beneath it. 𝘾𝙪𝙨𝙩𝙤𝙙𝙮 𝙧𝙚𝙢𝙖𝙞𝙣𝙨 𝙬𝙝𝙚𝙧𝙚 𝙩𝙝𝙚 𝙨𝙞𝙜𝙣𝙖𝙡 𝙞𝙨 𝙜𝙤𝙫𝙚𝙧𝙣𝙚𝙙 ◯│ . . #Nokia #Network #Memory #Custody
To view or add a comment, sign in
-
-
An attacker ran an AI agent unattended inside Thailand's Finance Ministry network. The operator deployed Hermes, an open-source AI assistant, on a rented server, disabled permission prompts, and let it run autonomously through the ministry's infrastructure. The agent performed kernel vuln scans, credential hunts, and crawled 13 years of staff personnel records on its own. The attacker left 470 MB of tooling exposed on an open directory, where researchers found everything. Blue teams need to start building detections for agentic attack patterns now: rapid sequential enumeration, automated LinPEAS runs, and bulk filesystem crawls from a single host are the new indicators of behavior to watch for. Has your SOC started tuning detections for AI-driven post-exploitation activity? #ThreatIntel #IncidentResponse #SOCAnalyst
To view or add a comment, sign in
-
An insightful article highlighting the rapid buildout of AI infrastructure and its potential impact on the Bulk Electric System. This situation raises questions about regulatory responses to address emerging risks. It will be interesting to see the developments from FERC in the near future. Their proactive stance, not waiting for NERC filings, suggests they recognize the urgency of the situation. Regulating defenses against rapidly evolving adversaries is challenging, especially as these adversaries leverage AI to develop anti-BES weapons. The combination of this swift AI infrastructure expansion and the evolving threat landscape presents risks that many may not fully grasp.
To view or add a comment, sign in
-
A secure model can still sit inside an insecure telecom decision loop. In an AI-enabled network, risk can enter through telemetry, data pipelines, model behavior, APIs, orchestration or the action taken after an inference. Focusing only on model accuracy leaves the surrounding system under-examined. The security question is not simply, “Can the model be attacked?” It is also: who can influence its inputs, what authority does its output receive, how is an action constrained, and what happens when the decision is wrong? AI security in telecom has to protect the complete path from evidence to action. That means provenance, authorization, policy boundaries, observability, and rollback must be designed together. P.S. Which part of the AI decision loop is most likely to be under-tested today? #AISecurity #TelecomSecurity #AIRedTeaming #SecurityArchitecture #CriticalInfrastructure
To view or add a comment, sign in
-
More from this author
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development