Before a nation deploys a new weapon, Article 36 of Additional Protocol I to the Geneva Conventions requires it to determine whether that weapon would be lawful under international law. Should AI face its own Article 36 moment? It is a simple but powerful principle, before delegating the ability to cause significant harm, independent scrutiny […]
July 20, 2026
Following an article on Cyber Insurance in the Financial Times today ‘Growing threats prompt rethink over cyber insurance’ I felt a moment of déjà vu, as I reflected on a piece I wrote just over 10 years ago to the day Cyber Insurance – Let the dance begin. In which I predicted the disruption to […]
July 18, 2026
A rather novel line in a recent policy review leapt out at me. It mandated that users of corporate mobile devices DID NOT customise their voicemail welcome message but leave the default carrier welcome. Why? The creative nature of threat actors are harvesting these custom voice clips to use in AI deepfake autodial human engineering […]
July 12, 2026
Further to my earlier piece, The Adaptation Gap, several readers argued that leaders have always had to navigate technological change and questioned whether AI is truly different. My view is that AI is truly different. For decades, executive leadership was rewarded for consistency. Stable assumptions, proven operating models and incremental change produced predictable outcomes. Experience […]
July 12, 2026
Truth be told despite the view that History has a habit of repeating itself, it does not. However this does not preclude us from drawing lessons from it. In the 18th and 19th centuries, landowners enclosed common land, transforming shared resources into private estates. Wealth accumulated to those who controlled the land. Everyone else paid […]
July 11, 2026
For most of modern history, organisations have operated in a world of largely linear change. Technology evolved in relatively predictable increments, threats emerged at a pace that allowed analysis and response, and strategic planning assumed that tomorrow would resemble today, only slightly different. Artificial intelligence is disrupting that assumption. The significance of AI is not […]
July 9, 2026
The recent reports surrounding an alleged compromise of Accenture are noteworthy not because a major consultancy may have suffered a cyber incident but because of the nature of the assets reportedly involved; source code, encryption keys, SSH/RSA keys, cloud access tokens and configuration data. If verified, this moves the discussion well beyond traditional notions of […]
July 8, 2026
Yet again the news is awash with AI, Cyber Risk and Financial Stability FUD (fear, uncertainty doubt) but to cut through the verbiage, the attack path really has not changed. Whilst it is fair to say regulators are right to be worried about AI enabled cyber risk in financial services, the concern needs to be […]
July 7, 2026
Like a magician performing a sleight of hand, the cybersecurity industry may be becoming fixated on the hand it can see while missing what is happening elsewhere on the stage. I call it the Great AI Source Code Vulnerability Distraction. Today, that visible hand is source code vulnerability discovery. Frontier AI models are astonishingly effective […]
July 5, 2026
A follow on thought stimulated by my missive of yesterday on America’s AI Doctrine has me considering the connection and implications on digital sovereignty. For organisations concerned with digital sovereignty, I feel the most challenging growing question is no longer simply one of residency, control or jurisdiction. It is who conditions the intelligence that thinks, […]
July 4, 2026
Following recent announcements from the US government, the US approach to AI is beginning to resemble a constitutional magic trick. Domestically, Washington wants to sweep away onerous state level safeguards in the name of innovation and competative advantage. The message to Silicon Valley is reassuringly simple; build, scale, dominate and try not to let individual […]
June 28, 2026
Recent news reports Anthropic alleges that operators linked to Alibaba used nearly 25,000 accounts and 28.8 million interactions with Claude to accelerate competing models towards ‘Mythos-class’ capabilities. The allegation remains contested and has not been independently proven but it illustrates both the appeal and the limitations of large scale model distillation. (Reuters) Large scale illicit […]
June 26, 2026
Historically organisations had years to adapt governance and risk management to technological change, AI is compressing those cycles into months. For me the blind spot for C-Levels I speak to is understanding the most important impact of AI, is not intelligence, it is speed. The challenge for leadership teams is that governance, procurement, compliance and […]
June 21, 2026
Further to extensive and growing debate on the digital sovereignty theme, I get the sense the powers that be are finally beginning to define technology sovereignty in terms that match the reality of the AI age. For several years, European technology sovereignty was often discussed as an aspiration Europe should control its data, reduce reliance […]
June 20, 2026
Are you getting tired of the language used to describe artificial intelligence (AI) that is subliminally softening the reality of what these systems are actually doing? I certainly am … We are told that models are not perfect, as though they are accurate mirrors of reality with a few defects. In truth, an AI model […]
July 22, 2026
0