Smaller models are the future of AI sovereignty Real sovereignty is not autarky. It is the ability to choose, govern, replace and, when necessary, walk away from the AI systems our institutions depend on.
AI is changing the terms of cyber defence AI can help cyber defenders move faster, but speed is only useful if they can control the consequences. As AI systems gain the ability to act, the hard question is not just what they can do, but who gives them authority and who is accountable when something goes wrong.
We are not brains in jars As technology takes on more of what we do, we need to keep moving, making, thinking and connecting with one another.
The Essential Eight is being retired. What comes next? A conversation with a friend who works in cyber security got me thinking about why we both like NIST’s pillar-based approach, to cyber and how AI tools can help teams test, learn and improve their defences.
How would you turn off your AI if it went rogue? If an AI system starts behaving in ways you did not expect, who can actually stop it? Here's a practical guide to designing AI shutdown capability, from authority and access controls to safe fallbacks and a realistic kill-switch checklist.
The Essential Eight is not enough for AI-enabled cyber attacks The Essential Eight is a vital protective baseline, but it is not enough to protect against AI-enabled cyber threats. Why organisations need stronger controls, assurance, resilience and recovery in the age of AI agents.
We are the problem: how AI training shapes behaviour, risk and restraint AI has no conscience, civic duty or intrinsic values. It learns from a corpus containing the best and worst of human behaviour, then pursues the objectives we reward and the actions we permit.
When the Test Becomes the Threat Model The OpenAI and Hugging Face incident shows why agentic AI governance cannot stop at the model. The real risk lies in the environment: tools, permissions, incentives, evidence and the ability to stop an agent before an evaluation becomes an incident.
Beware offshoring dressed up as AI innovation and transformation AI can enable genuine transformation. But leaders and boards should be alert when the language of innovation is being used to obscure a conventional cost-out program that shifts work, capability and accountability elsewhere.
AI models are not interchangeable infrastructure AI models are not behaviourally neutral infrastructure. Their answers reflect patterns of judgement, confidence, caution and communication - and those patterns can become material business risks.
US cloud act, sovereignty, and why you might need to care Airbus’s move to European cloud hosting is a reminder that data residency is not the same as digital sovereignty. Where your cloud provider is headquartered, and which laws it answers to, can matter as much as where your data sits.
Intelligence is leaving the cloud, and our governance frameworks have not noticed Intelligence is moving off the cloud and onto devices we own and control. Our governance models are still built for a world of centralised chokepoints - API logs, model providers, and labs we can regulate. That world is fading. What replaces it is messier, more distributed, and much harder to see.
Mapping the AI value chain Most organisations chase AI capability without asking where it sits in the business. Applying Porter's value chain to AI makes the dependencies visible - and reveals which layer is actually your constraint.
The intelligent organisation is not the one with the most AI AI alone will not make an organisation intelligent. Human judgement, diversity and accountability still matter.