Posts tagged "security"
-
Friday Roundup #29: The Reason Field
A control that is just a field for the controlled party to fill in, whether a search justification, a contract clause, a required study or a label, only works if someone outside reads it, so find the reader or assume the field says asdfg.
-
Friday Roundup #28: The Self-Graded Exam
A claim that a vendor scores itself ships, gets procured, and deploys long before anyone outside the building checks the conditions the number was produced under — so the only audit left is the slow, hostile, expensive kind.
-
Friday Roundup #25: The Missing Tell
Every check that grades whether a thing looks right is now free to pass, so the only verification still worth running is the kind that grades provenance or forces a consequence.
-
Friday Roundup #24: The Deputies
The week's move wasn't to dispute the receipts but to relocate the work that generates them — into contractors, gig drivers, closed-door working groups and self-appointed oversight boards — so the operational question is now who is legally obligated to keep the record after you delegate.
-
Friday Roundup #23: The Receipts
The real numbers arrived this week — a Black Hat disclosure worse than the cover story, cameras wrong 71% of the time, one customer carrying 70% of Microsoft's AI revenue — and the operational lesson is to demand the ledger before you sign the contract.
-
Friday Roundup #19: The Floodlight
The week AI became the best vulnerability finder ever built — which made it the best one your adversary now holds too — and the industry answered with a shared alarm system while the bill rolled downhill to federal workers, schools, and the grid.
-
Friday Roundup #18: The Terms of Access
The week the frontier reopened — but every door came with conditions: two flagship models handed back on a leash, agency made cheap enough to actually hold, the back office thinning to pay for it, and governance shipping as a product from Sacramento to Brussels.
-
Friday Roundup #17: Custody Battles
The week AI stopped being a capability and became a possession people fight over: a model that's both a federal lever and a theft target, real wins wrapped in asterisks, the version-control stack splintering, agents reaching for your card, and a governance scramble from Oslo to the California ballot.
-
Friday Roundup #16: Governance Everywhere
The week AI left the demo room and hit institutions: a federal kill switch for frontier models, OpenAI's $34B burn meeting workslop, bounded agency as the real agent product, assistants as the new attack surface, and voter files becoming enforcement data.
-
Friday Roundup #15: Failing Where the Pitch Was Loudest
The administration skipped the silencing and went straight to the kill switch, converting 8,000 feds to at-will status. Microsoft became the road malware travels. An AI school camera missed an armed student while a man sat jailed despite data proving his innocence. The cheap-AI era ended before the expensive one proved itself. And the neighborhoods underneath the data centers organized. One throughline: the failures landed in the domains the pitch was most confident.
-
Friday Roundup #14: The ROI Story Cracked
Ed Zitron declared AI has no ROI, the billionaires got scared, and research blamed remote work — not AI — for the graduate slump. Underneath the sentiment turn, a credential worm rode official Red Hat npm packages, Zig called AI-written code 'invariably garbage,' vendors pitched agents as inescapable while publishing containment docs, and the federal workforce got NDAs in the same cycle as an 'anti-technology extremist' label.
-
Friday Roundup #12: The Week the Spreadsheet Pushed Back
Hackers poisoned open source at industrial scale. Office users won the right to delete the Copilot button. Irish Rail wrote down €50 million. Samsung chip workers walked away with $340,000 bonuses. And the clean-energy stories got refreshingly weird.
-
NVIDIA Just Open-Sourced the Security Layer AI Agents Need
OpenShell is a sandboxed runtime that enforces security policies AI agents can't override — even if compromised. This changes the game for anyone deploying agents in production.
-
Meet Zephyr: Why I'm Using OpenClaw (Carefully)
A short introduction to Zephyr, OpenClaw, and why 'agents that act' feel like Accelerando showing up early.