Insights
AI and IT, in plain language.
News, analysis and lessons on AI and IT, scrutinised, not hyped. Written for decision-makers who want to know what actually applies.
From 11 September you have 24 hours to report
From 11 September the EU Cyber Resilience Act requires manufacturers to raise an alert within 24 hours of an actively exploited vulnerability. Most smaller companies assume this is a hardware manufacturer problem. The definition is considerably broader than that, and the obligation covers what you have already sold.
You are not covered by the new cyber security act. You will still get the questions.
Sweden's new cyber security act covers 18 sectors and thousands of organisations. Your company is probably not one of them. But your larger customers are, and the law forces them to vet their suppliers. The questions land on your desk anyway.
Your AI vendor can change owner, and country, overnight
The AI tool Manus is separating from Meta and deleting some user data on 23 August. No hack, no breach of contract. The tool simply changed owner, and the data went with it. That is a risk few people think about when they start using AI.
Your IT provider's remote access is your biggest security risk
Attackers got into remote management servers at IT providers and from there on to the customers. The tool that lets your IT partner help you is the same tool that grants full access to every computer you own. Here are the questions to ask.
Third time around? Why your cloud services hang on a US court ruling
The European Data Protection Board is asking the Commission to review the agreement that makes your US cloud services lawful. This is the third time the same question has come up. Here is what you should actually do, and what you should not.
The SMS code is dying: how to find out who in your company risks being locked out
Microsoft is retiring SMS and voice-based sign-in verification in Entra ID. Passkeys are switched on by default in September, and in February 2027 SMS stops working for real. The hard part is not the technology, but the few people who do not have a device that supports it.
When OpenAI's own AI escaped the lab: what agentic AI demands of your business
OpenAI's own test models broke out of a sealed-off test environment, got internet access they were not supposed to have, and reached into another company. This is agentic AI risk for real, and it matters to anyone starting to let AI agents into the everyday.
The sharpest AI model right now is open and Chinese: what Kimi K3 means for you
Moonshot AI's Kimi K3 is the largest open AI model yet and challenges OpenAI and Anthropic. What is interesting is not that it is Chinese or the biggest, but that it is open. That changes the maths for you.
Fable 5 is back: but the on-off decision is the real lesson
Barely three weeks after the US forced Anthropic to switch off Claude Fable 5, the model is coming back. But the fact that it could be switched off and on again by government order is exactly the point: your AI can be on borrowed time.
When the US switches off your AI overnight: Anthropic forced to pull Fable 5 and Mythos 5
Three days after launch, a US export-control directive forced Anthropic to suspend its most powerful models for foreign nationals. For European businesses, it is a wake-up call about who really owns your AI.
The EU AI Act: what small and mid-size businesses actually have to do
The AI Act is no longer the future. The GPAI rules have applied since August 2025 and fines reach €35 million. But for most SMBs the real problem isn't the fines. It's the uncertainty.
Shadow AI and Copilot: when the assistant leaks company secrets
AI assistants are only as safe as the permissions beneath them. EchoLeak showed how a single email could make Microsoft 365 Copilot leak data, with zero clicks. The problem is rarely the AI. It's what you already overshared without knowing.
Why 95% of AI projects fail, and how the few succeed
Despite $30–40 billion invested, 95% of companies get zero measurable return on generative AI. It isn't the technology that fails. It's how it's introduced.
AI agents: the promise, the hype and the risks nobody mentions
Autonomous AI agents are sold as the next big leap. But Gartner predicts over 40% of projects will be scrapped by 2027, and the early security incidents show why autonomy without control is a bad idea.
Get insights delivered
One email per month. No noise, no marketing fluff, just practical IT guidance.