Insights

    What we are reading, and what we make of it.

    Short pieces from the editors: notes on what we read, commentary on what moved, and practice notes on what has held up. Opinions are ours; facts carry their source.

    Category
    Kind

    9 of 9

    The AI bill of materials is the next SBOM

    Three articles in one issue argue that the supply chain is now four chains. The bill of materials that stops at code no longer describes what ships.

    Security practice6 Sept 20264 min read

    AI governance

    The permissions review that did not happen

    An agent reaches production on its installer's identity, holding every tool that person held. This is the review that should have run first.

    AI5 Sept 20265 min read

    AI governance

    CRA in fifteen months: what to do first

    Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.

    Regulation and audit5 Sept 20265 min read

    Product & OT

    The board question is not the CVE count

    A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.

    Security practice5 Sept 20263 min read