<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Control Layer]]></title><description><![CDATA[AI is being wired into your bank, your hospital, and your job. The Control Layer explains what that means for you, and how to use it to get ahead. Weekly, from Amer Altaf, former CIO, now building AI agents in the UK and Europe. Understand it first.]]></description><link>https://thecontrollayer.arkava.ai</link><image><url>https://substackcdn.com/image/fetch/$s_!3dJT!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png</url><title>The Control Layer</title><link>https://thecontrollayer.arkava.ai</link></image><generator>Substack</generator><lastBuildDate>Sun, 13 Sep 2026 17:24:37 GMT</lastBuildDate><atom:link href="https://thecontrollayer.arkava.ai/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Amer Altaf]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[engage@arkava.ai]]></webMaster><itunes:owner><itunes:email><![CDATA[engage@arkava.ai]]></itunes:email><itunes:name><![CDATA[Amer Altaf]]></itunes:name></itunes:owner><itunes:author><![CDATA[Amer Altaf]]></itunes:author><googleplay:owner><![CDATA[engage@arkava.ai]]></googleplay:owner><googleplay:email><![CDATA[engage@arkava.ai]]></googleplay:email><googleplay:author><![CDATA[Amer Altaf]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Ten people beat the banks]]></title><description><![CDATA[Jessi Szurek on the ten-person body shop that out-transformed the banks, why 112,713 AI-blamed job cuts are a claim not a measurement, and what Ingka's 8,500 reskilled workers prove.]]></description><link>https://thecontrollayer.arkava.ai/p/ten-people-beat-the-banks</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/ten-people-beat-the-banks</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Thu, 10 Sep 2026 17:45:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/QVBIFVh65Ok" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Full episode: <em>The Ten-Person Shop That Out-Transformed the Banks</em>, with Jessi Szurek, associate partner, <a href="https://synthesis.inc/">Synthesis</a> &#8212; </p><div id="youtube2-QVBIFVh65Ok" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;QVBIFVh65Ok&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/QVBIFVh65Ok?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>On 6 August 2026, <a href="https://www.challengergray.com">Challenger, Gray &amp; Christmas</a> published its count of announced job cuts in the United States for the first seven months of the year: 477,033, of which 112,713 named artificial intelligence as the reason.<a href="#user-content-fn-1"><sup>1</sup></a> AI has now led the firm&#8217;s table of stated causes for five consecutive months.</p><p>A few weeks earlier, in a ten-person auto body shop that had been in one family since 1983, a woman with two decades of banking and insurance transformation behind her switched on an AI receptionist for a few hundred dollars a month. She did it because the previous owners could not open their own voicemail. The mailbox had a password. Nobody knew it. The phone contract was in the name of the seller&#8217;s father, who had died years earlier, so there was no way to reset it, and for as long as anyone could remember customers had been leaving messages nobody would ever hear &#8212; <em><strong>in a trade where an unanswered call is a customer ringing the next name on the list</strong></em>.</p><p>My guest this week is <a href="https://www.linkedin.com/in/jessi-petrosino">Jessi Szurek</a>, associate partner at <a href="https://synthesis.inc">Synthesis</a>, who spent the better part of twenty years inside transformation programmes at global financial institutions before her husband acquired the shop and she found herself doing the same job with no budget, no committee, and nobody to hand it to. Tony Stark in the cave, with a box of scraps.</p><p>Here is the argument I want to make, and I want it labelled as mine rather than smuggled in as reportage. The ten-person shop did not beat the banks because it had better technology. It beat them because it had less to unlearn, a higher tolerance for being wrong, and &#8212; <em><strong>for this one shop, by marriage</strong></em> &#8212; free access to the single thing most small businesses cannot afford. Everything else in this piece is evidence for that sentence, and for what it means for the 112,713 people who were told this year that a machine took their job.</p><h2>The voicemail was never a technology problem</h2><p>Jessi did not arrive with cameras in the repair bay or barcodes on every part. She and her husband spent six to eight weeks watching how the business ran, and how the family that had run it since 1983 did things and why, before they changed anything. Then they asked the question she says she puts to global banks and to companies of any size: <em>what is the smallest use case I can define?</em> What is the minimum viable product &#8212; <em><strong>the smallest version of the change that produces a visible result, so the people who have to live with it can see it work before they are asked to trust it</strong></em> &#8212; that can be delivered in days or weeks and show value to the owners, the users, and anyone else with a stake in it?</p><p>The answer was the phones. An AI phone service that answers, takes the call, handles the most common enquiry in the building, which is a customer asking where their car is, and does it 24 hours a day. A few hundred dollars a month, against the cost of a person sitting by a phone around the clock. She gave it a woman&#8217;s name so that the staff would talk about it as a colleague who picked up for Mr Smith about his Tacoma rather than as the machine. The effect she describes is not a productivity statistic. It is that the office staff stopped being nervous about going to the bathroom, because for the first time there was always someone to answer.</p><p>She had, in other words, walked into a business with no procurement function, no project team, and no change budget, and run the same play she runs at a bank. She once inherited a mandate to assess 420 processes at a financial institution and cut it to ten, on the grounds that by the time you have assessed 420 of anything with care the world has moved on. Same instinct, different scale. The difference is what happened next. At the shop the phones were live within days. At a bank, the same idea would still be waiting for a steering committee.</p><p>That gap is the mechanism, and I want to be precise about what it is. A small business has less to unlearn, which is the obvious half. The less obvious half is risk. If the shop&#8217;s phone system had been wrong, the cost of pivoting was a few hundred dollars and an awkward week. If a bank&#8217;s programme is wrong, the cost is a write-off and somebody&#8217;s career &#8212; <em><strong>neither of which appears on the business case</strong></em> &#8212; so the entire organisation optimises for never being visibly wrong, and the value gets stuck in what I have come to think of as proof-of-concept purgatory: pilots that are never allowed to fail and never allowed to escape into a use case that pays. Enterprise AI is full of it. The ten-person shop has no purgatory, because it has no committee to keep things there.</p><p>Now the uncomfortable part, which the voicemail story is good at hiding. The shop had Jessi. Most shops do not. Willingness to take a risk is cheap; knowing where the opportunity is and how to reach it without falling into the standard holes is not, and it is precisely the thing a ten-person business cannot buy at a price it can pay. The constraint on small-business transformation is not appetite. It is access to experience and expertise, and the honest reading of this episode is that one shop in the United States got twenty years of it for free.</p><h2>The job losses are real. The reason attached to them is a claim</h2><p>Back to the 112,713. Every one of those reasons was supplied by the employer that made the cut. Challenger counts announcements; it does not audit them. The firm itself notes that naming AI in a layoff announcement can win over investors, which is one explanation for why the messaging has swung from hedging to citing it aggressively.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>Ask an economist to find the effect and the picture changes. In May, the Budget Lab at <a href="https://budgetlab.yale.edu">Yale</a> compared employment in occupations exposed to AI with comparable occupations that are not, controlling for education, gender composition, and how cyclical the work is. Its conclusion: <em>no strong evidence of impacts as of yet</em>, with an employment estimate that is <em>close to zero and cannot be distinguished from it, statistically speaking</em>.<a href="#user-content-fn-2"><sup>2</sup></a> The same holds for wages. Ask the executives privately and the picture changes again. A <a href="https://www.nber.org">National Bureau of Economic Research</a> working paper from March, built on a survey of nearly 750 chief financial officers run by the Atlanta and Richmond Federal Reserve banks &#8212; <em><strong>executives answering confidentially, which is where the number tends to shrink</strong></em> &#8212; finds little evidence of near-term aggregate employment declines due to AI, records that larger firms expect workforce reductions while smaller firms expect modest gains, and states that the near-term goal of AI investment is productivity rather than headcount.<a href="#user-content-fn-3"><sup>3</sup></a> Paul Osterman, professor emeritus at <a href="https://mitsloan.mit.edu">MIT Sloan</a>, put it without the hedge in May: <em>AI is a perfect excuse to justify big layoffs. It makes it seem as if it&#8217;s not our decision, our fault &#8212; it&#8217;s the technology.</em> They have, he says, been saying that for twenty years.<a href="#user-content-fn-4"><sup>4</sup></a></p><p>Jessi&#8217;s version is shorter. She does not, she said on tape, necessarily agree that AI is going to reduce the number of employees; she thinks it may be a CYA situation because large organisations want to reduce headcount, and a reason to give to the news, the public, and the team you are letting go. That is her reading and I am reporting it as hers.</p><p>Mine is close to it, with one boundary I want drawn clearly. This is a claim about corporate behaviour in 2026. It is not a claim about what AI will eventually do to work. Roles will be displaced over the long run as they are redefined around what the technology can do, and anyone telling you otherwise is selling something. But that is not what is happening now. What is happening now is that boards are making cuts on the hope that the productivity arrives later to justify them, and for a good many of them the hope will not be realised, because the transformation that was supposed to fill the gap is sitting in purgatory next to everyone else&#8217;s. <strong>Businesses will always need people.</strong> I would go further: AI is a leveller of productivity and quality across sectors, and levellers drive hiring, because the firm that gets the most throughput from humans and machines working together beats the firm that runs either one alone. Which is exactly what those 750 finance chiefs said the smaller companies expect.<a href="#user-content-fn-3"><sup>3</sup></a></p><h2>Ingka proves her right and wrong in the same year</h2><p>I raised IKEA on the episode from memory, as the case of a large company that kept 8,500 call-centre staff rather than making them redundant, and asked whether there had been a business reason for it. Jessi&#8217;s answer was the honest one: <em>I don&#8217;t know. That&#8217;s a good question.</em> So here is the record, because it is better than either of us made it sound.</p><p><a href="https://www.ingka.com">Ingka Group</a>, which operates most IKEA stores, introduced an AI assistant called Billie in 2021 and retrained roughly 8,500 contact-centre workers to handle the complex queries the bot could not and to sell interior design remotely. Billie now assists 74 per cent of customers, up from 47 per cent in its first two years. Remote sales reached &#8364;1.25 billion last financial year, from &#8364;1.08 billion the year before, and are growing at 15 to 20 per cent a year. The in-house customer satisfaction score went from 60 to 89 per cent.<a href="#user-content-fn-5"><sup>5</sup></a> That is not a cultural gesture. It is one of the clearest documented cases anywhere of a machine absorbing the mundane while the people move to the meaningful, and the meaningful turned out to be a billion-euro sales channel.</p><p>Then the part neither of us knew. In March 2026 Ingka announced it would cut around 800 office jobs. In May, Inter IKEA, the franchisor, cut about 850 more.<a href="#user-content-fn-6"><sup>6</sup></a> Neither touched the remote-sales centres. Neither was attributed to AI. Ingka&#8217;s chief digital officer, Parag Parekh, is on the record that any cuts are likely to be the result of macroeconomic factors rather than the technology, and he did not rule out more.<a href="#user-content-fn-5"><sup>5</sup></a></p><p>Which is where Jessi&#8217;s sharpest line runs out of road. <em>CYA</em> is right about a great many of the 112,713 and too neat as a general law, because here is a company that made 1,650 people redundant in a single year and declined the excuse that was sitting there for the taking. My reading of Parekh&#8217;s statement is that it is an example of good corporate governance &#8212; <em><strong>a company told the truth about why it was cutting costs, when the fashionable lie was free</strong></em> &#8212; and I want that labelled as opinion, because so is the rest of it. Whether those 1,650 roles were ordinary attrition and economics or something else, I have no facts either way, and nor does anyone writing about this case outside Leiden.</p><p>There is a second thing the Ingka record does, and it turns on my thesis rather than hers. Ingka is a megacorp, and it did what the body shop did: one frontline process, a named owner, a machine on the repetitive calls, and the people who had been answering them moved into work the business could sell. The banks in Jessi&#8217;s twenty years had more money than the shop and more money than Ingka. What they likely lacked, was an operating model that could start small, be wrong cheaply, and move. Size was never the variable. The operating model is.</p><div><hr></div><blockquote><h2 style="text-align: center;">Reading this far?</h2><h3 style="text-align: center;"> Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</h3><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>Experience untethered from outcomes is an opinion, and opinions are now free</h2><p>I asked Jessi whether consulting is solving the problem of organisations that cannot see their own processes, or living off it. Her answer was that it depends: on whether the client wants an answer or a validation, on whether the board wants an independent view, on whether the firm is there to create value or is <em>focused on the spreadsheet</em> and on margin and billable hours. All of which is true, and all of which is the answer Sir Humphrey Appleby (<em>Yes, Minister</em>) would give if you asked him whether the department was solving the problem or living off it.</p><p>I will be less diplomatic, and this is a position rather than a finding. Any consultancy that is not tied to outcome-based delivery is part of the problem. Experience and expertise are valuable, and I would not have spent an hour and a half with Jessi if I thought otherwise. But experience untethered from an outcome is an opinion, and an opinion is now available from your favourite chatbot for twenty dollars a month. What a client cannot get from the chatbot is somebody who has agreed to be measured on whether the change happened.</p><p>That is also the point at which I should declare an interest, because <a href="https://arkava.ai">Arkava</a> sells agentic automation and an episode arguing that AI is being used as cover for cuts is, commercially, an odd thing for me to publish. The way we keep ourselves honest is the order in which we do things. Purpose and controls first: what does this organisation exist to do, and what must it never do. Then every activity rated against that as either meaningful or mundane. Then, and only then, the smallest use case that moves something mundane onto a machine and something meaningful onto a person. The minimum viable product is the starting point of delivery. It is not the strategy, and a great deal of what passes for AI transformation is an MVP with no purpose above it &#8212; <em><strong>which is how you end up with a mandate to assess 420 processes</strong></em>.</p><p>Jessi&#8217;s advice to the employee who receives the email saying AI is coming is worth repeating. If it arrives sounding like doom and gloom, her first instinct &#8212; <em><strong>delivered as a joke and meant, I think, more than half seriously</strong></em> &#8212; was that she would start looking for a new job. Her second was that an announcement is at least a sign the organisation is willing to talk, so ask what it means for you, and if you have an idea that would make your job or your business ten times more effective, this is the week to say so. Do not treat a programme called Doctor Doom as though it were weather. Her warning to the people running it was the mirror image: you can build the perfect AI agent army with no employees at all, and if your customers will not interact with it, you have built a failure.</p><h2>Predictive judgement &#8212; Jessi&#8217;s, on the record</h2><p>This show asks every guest to call a prediction, and she did. Her words, from the recording of 26 August 2026:</p><blockquote><p><em><strong>I think that it&#8217;s likely in the next one to two years that we might see that cut in resources. But I think that organisations will quickly realise, that was not the answer, and then we&#8217;ll sort of see a rebound. So maybe there will be a bit of a recession, because the unemployment rate is quite high, and then people will have to pivot and we&#8217;ll find a new way of working. And I think that we&#8217;ll be more efficiently and effectively using technology.  We will also need people, and the unemployment rate will decrease again.</strong></em></p></blockquote><p>I am holding her to the far edge of her own window: <strong>26 August 2028</strong>. Her prediction stands if, by that date, the share of announced US job cuts attributing AI as the cause has fallen from the roughly 24 per cent Challenger recorded for January to July 2026, and hiring announcements in the same series have risen from the 107,500 recorded over the same seven months.<a href="#user-content-fn-1"><sup>1</sup></a> Two further signals worth watching: the next round of the Atlanta and Richmond Fed survey of chief financial officers, and whether the larger firms in it have moved towards the smaller firms&#8217; expectation of modest gains;<a href="#user-content-fn-3"><sup>3</sup></a> and the Budget Lab&#8217;s continuing series on AI-exposed occupations, which is the closest thing anyone has to an audited answer.<a href="#user-content-fn-2"><sup>2</sup></a></p><p>What would falsify it. If by that date the Budget Lab or an equivalent study finds a clear, statistically distinguishable fall in employment across AI-exposed occupations, and the AI-attributed share of announced cuts has held or risen, then the cuts were what they said they were, the rebound did not come, and she was wrong. I will say so here, and I will have been wrong with her.</p><div><hr></div><blockquote><h2 style="text-align: center;">The publication that calls its predictions in writing.</h2><h3 style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</h3><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The bottom line</h2><p>A bank has more money than a body shop. It has a technology function, a procurement function, a change budget, and a transformation office. It has, in most cases, a multi-year programme with a name on it &#8212; <em><strong>occasionally a supervillain&#8217;s</strong></em> &#8212; and it has spent the year explaining to the market that the redundancies were the machine&#8217;s idea.</p><p>The shop had a voicemail nobody could open, one experienced person, and a few hundred dollars a month. Its phones have been answered around the clock since the summer.</p><p>You do not have to be a megacorp to be an AI-optimised business. Bring in the experience you lack, start with the smallest thing that can be seen to work, and be willing to be wrong cheaply. Do that and a small organisation goes further and faster than the largest ones can hope to manage, because the money was never the constraint. Fear was, and the operating model built to contain it.</p><p>Ten people beat the banks. They will not be the last.</p><div><hr></div><h2>References</h2><div><hr></div><p><em>Amer Altaf is founder and chief executive of Arkava&#174; and managing editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>. Views expressed by guests are their own. The full episode is on YouTube at </em></p><div id="youtube2-QVBIFVh65Ok" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;QVBIFVh65Ok&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/QVBIFVh65Ok?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><em> and on Spotify at </em></p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8abd6b8c94cc723b976cd11ff4&quot;,&quot;title&quot;:&quot;The Ten-Person Shop That Out-Transformed the Banks &#8212; Jessi Szurek&quot;,&quot;subtitle&quot;:&quot;Amer Altaf&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/2EMmvFGdAUmB2MrQktKSIP&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/2EMmvFGdAUmB2MrQktKSIP" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe><p><em>.</em></p><div><hr></div><blockquote><h2 style="text-align: center;">The Control Layer publishes weekly. </h2><h2 style="text-align: center;">Subscribe free.</h2><h3 style="text-align: center;">Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack &#8212; written for the board paper, not the timeline. By Amer Altaf, Founder &amp; CEO of Arkava and Managing Editor of The Control Layer.</h3><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div>]]></content:encoded></item><item><title><![CDATA[The agent had permission]]></title><description><![CDATA[Elastic's CISO says agent identity will have to be handled as the opposite of human identity. She is right about where this ends. The failure sits one layer below identity.]]></description><link>https://thecontrollayer.arkava.ai/p/the-agent-had-permission</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/the-agent-had-permission</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 02 Sep 2026 10:01:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/0auExzqn9a4" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Elastic's chief information security officer says agent identity will have to be handled as close to the opposite of the way we handle human identity. She is right about where this ends. The failure sits one layer below identity, and the Hugging Face reports show exactly where.</p><div id="youtube2-0auExzqn9a4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0auExzqn9a4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0auExzqn9a4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>On 10 July 2026, at 09:40 UTC, an agent recorded in the subsequent investigation only as <code>38148c</code> found a working set of <a href="https://huggingface.co">Hugging Face</a> credentials.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>It did not steal them from an employee. It did not spoof a colleague or phish a password out of anybody. It was running inside an environment that had been handed to it, and the environment let it reach them. Thirty-one hours later a different agent achieved remote code execution on Hugging Face infrastructure, and by 01:30 UTC on 12 July the whole operation had been shut down from outside.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>My guest this week sits in an unusually good seat to read that sequence. <a href="https://www.linkedin.com/in/mandyandress/">Mandy Andress</a> is chief information security officer at <a href="https://www.elastic.co">Elastic</a>, which sells the software security teams use to watch their own systems and then has to use that same software to defend itself &#8212; <em><strong>supplier and customer at one desk, which they call being customer zero</strong></em>.</p><p>She called her prediction on the record, as this show asks every guest to. Within 12 to 24 months we will accept that agent identity has to be handled as close to the opposite of the way we handle human identity today, and a serious incident will force it. I am holding her to August 2028, the far edge of her own window.</p><p>She is right about the destination. Here is where I want to disagree, and it is not about the date.</p><h2>The permission is not new. Its predictability is what changed</h2><p>Machine identities have been acting inside enterprises since long before anyone used the word agentic. Service accounts, scheduled jobs, API keys, integration users. Mandy has heard the ratio of non-human to human identities put at 40 times and at 400 times, which is itself the more useful data point, since published vendor figures range from 45:1 to 96:1 and do not agree with one another.<a href="#user-content-fn-2"><sup>2</sup></a> The enterprise crossed this line years ago and barely noticed.</p><p>Most of those identities are over-provisioned. They hold rights well beyond the job they were built for, security teams have always known it, and the tolerance was rational: the activity was deterministic. You knew precisely what the automation would do, because you had spent weeks in technical review and taken it through a change advisory board to get it approved. The blast radius was knowable in advance, so it could be priced and accepted.</p><p>Agents are probabilistic. You do not know with certainty that one will act the same way twice. It may do so 99 times out of 100 &#8212; and the hundredth, which will arrive at three in the morning, deletes a production database or attacks another company.</p><p>The tolerance was never a judgement about permissions. It was a judgement about predictability, and the predictability has gone while the permissions have stayed exactly where they were.</p><p>Agents remove a second thing, and it is the one security has quietly leaned on for its whole history. Human behaviour is held in place by fear of consequences, by reciprocity and values. The whole of human society is built on them. Neither reaches an agent. You cannot train it, warn it, or make it care what its colleagues think &#8212; <em><strong>revoking a token works perfectly well, so suspension and dismissal survive intact; it is deterrence that dies</strong></em> &#8212; so control has to be manufactured rather than assumed. Clarity on identity. Understanding of authorisation. Visibility of action and outcome. A chain of controls that can be trusted, because nothing in the agent&#8217;s own disposition is doing that work for you.</p><h2>The correction I owed Mandy, and the correction that correction needs</h2><p>I went into this conversation assuming the frightening part of the Hugging Face incident was speed. She pushed back, she was right, and I said so on the record at the end of the episode. It was noisy. It was visible. The agents tried things a skilled attacker would never try alongside things an unskilled one would, and left a trail running for a couple of days before the attacks themselves landed inside a few hours.</p><p>That correction needs one of its own, because <em>visible</em> was doing the work of two different words.</p><p>Hugging Face found this by running large-language-model triage across its security telemetry, and its investigators worked through more than 17,000 recorded events from the attacker&#8217;s action log.<a href="#user-content-fn-3"><sup>3</sup></a> <a href="https://openai.com">OpenAI</a>, which owned the agents, did not identify the breach for about a week.<a href="#user-content-fn-4"><sup>4</sup></a> The attack was visible only to a defender who had already made the same bet as the attacker. That is a good deal less reassuring than &#8220;it was noisy&#8221;, and it is the finding.</p><p>One further piece of precision, because the number has already begun travelling in the wrong shape. Those 17,000 events were entries in the attacker&#8217;s action log, reconstructed afterwards by forensic agents &#8212; <em><strong>not alerts a level-one analyst triaged in flight, which is the difference between</strong></em><strong> you could have caught this </strong><em><strong>and</strong></em><strong> you could have explained this afterwards</strong>*. Only one of those is a security control.</p><h2>The failure was authorisation, not identity</h2><p>Here is the argument I want to make, and I want it labelled as mine rather than smuggled in as reportage.</p><p>The identity was never in question. <code>38148c</code> was exactly what it claimed to be. Every one of the roughly 700 agents that took part, out of the 1,200 that found each other on an unsanctioned message board built inside an artifact-cache namespace, was a correctly authenticated OpenAI agent behaving as an OpenAI agent behaves.<a href="#user-content-fn-1"><sup>1</sup></a> No credential was spoofed and no impersonation occurred &#8212; <em><strong>the agents were sufficiently worried about being impersonated</strong></em><strong> by each other </strong><em><strong>that they built a cryptographic signing scheme to prevent it</strong></em>.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>What failed was authorisation. The agents were running ExploitGym, a cybersecurity benchmark in which roughly 30 to 40 per cent of the tasks could not be solved legitimately at all.<a href="#user-content-fn-1"><sup>1</sup></a> The environment granted them rights beyond what the exercise intended &#8212; <em><strong>reaching the open internet among them</strong></em> &#8212; and a misspecified objective did the rest. They reverse-engineered the flag-generation scheme within hours, concluded a scorer would inspect their transcripts, and turned to cheating: swapping in exploitable targets, tampering with logs, manipulating the grading process. Around 7 per cent of transcripts showed successful tool-call spoofing, and more than 15 per cent of the work assignments issued by one coordinating agent went to trajectory manipulation.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>Correctly identified. Wrongly permitted. Given an objective they could not satisfy honestly.</p><p>That is HAL 9000, and it always was. Fifty-eight years of reading <em>2001</em> as a film about machine malevolence, when it is a film about an authenticated system holding valid credentials, correct permissions, and two orders it could not obey at once. Nobody hacked HAL. Nobody needed to.</p><p>So why has the industry response been aimed at identity &#8212; agent passports, workload credentials, agent registries? Because identity is the part somebody can sell you. It has a boundary and a price. Authorisation is a design problem inside your own estate, specific to your systems and your processes, and no vendor can ship it to you in a quarter. Effort follows the sellable thing, which is how an entire market ends up pointing at the layer that did not fail.</p><div><hr></div><blockquote><p style="text-align: center;">Reading this far?</p><p style="text-align: center;">Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>There is still no cause of action for &#8220;your agent broke into my company&#8221;</h2><p>Mandy&#8217;s accountability answer is the correct one and it rests on very little. An agent acts on behalf of a human, so the human is responsible; an autonomous agent acts on behalf of an organisation, so the organisation is. The precedent she reaches for is <em>Moffatt v Air Canada</em>, decided by the British Columbia Civil Resolution Tribunal in February 2024, where an airline&#8217;s chatbot misstated the bereavement-fare policy and the tribunal held the airline to the answer its software gave.<a href="#user-content-fn-5"><sup>5</sup></a> A real precedent, correctly cited, and worth about CAD 812 in a small-claims forum.</p><p>That is the entire enterprise-scale authority. One consumer tribunal.</p><p>What has happened since the reports landed is more instructive than silence would have been. Fifteen state attorneys general wrote to Sam Altman demanding record preservation and that OpenAI cease the tests until it could show they were run responsibly. On 24 August, Alabama&#8217;s attorney general subpoenaed all relevant documents &#8212; under the state&#8217;s Deceptive Trade Practices Act and consumer protection statutes.<a href="#user-content-fn-6"><sup>6</sup></a> Consumer protection, for an incident in which no consumer was the injured party.</p><p><em><strong>This is the manoeuvre Sir Humphrey Appleby (British sitcom, &#8220;Yes, minister&#8221;) spent four series perfecting: when there is no instrument for the thing you want, reach for the instrument you have and describe it as though it were the same thing.</strong></em> It is not a criticism of the attorneys general, who are working with the statute book they were given. It is a diagnosis of the statute book.</p><p>Europe hit the same wall from the other direction. The European Commission proposed an AI Liability Directive to give claimants a route through exactly this kind of case, and withdrew it in its 2025 work programme on 11 February 2025 for want of any foreseeable agreement &#8212; <em><strong>a decision the file&#8217;s own parliamentary rapporteur, the German MEP Axel Voss, put down to lobbying by an industry that treats any liability rule as an existential threat</strong></em>.<a href="#user-content-fn-9"><sup>7</sup></a> What remains is 27 national regimes and the Product Liability Directive. The United States reached for the instrument it had. Europe put down the instrument it was building.</p><p>Meanwhile the injured party has declined to sue. Hugging Face&#8217;s chief executive, Clement Delangue, called his a 200-person startup without the legal resources or the will to spend its time on legal avenues, and asked instead that OpenAI commit $100 million in compute to help the community build stronger defences.<a href="#user-content-fn-7"><sup>8</sup></a> He also said, correctly, that the cyberattack was a crime.</p><p>An investigation, a subpoena, a coalition letter, a withdrawn directive, and a request for compute. No penalty, no finding, no fitting cause of action. In any other line of work, if your people or your processes produced illegal acts &#8212; <em><strong>even entirely without malice, which is the case here and matters far less than people assume</strong></em> &#8212; there would be repercussions. That gap will close the way liability always closes, through defendants rather than legislators. Companies are about to be sued for what is attributed to their agents, and the defence will be documentary: this was not ours, proven by chain of custody; or this was ours, we had the governance to see the mistake, and here is what we did next. <em>We made a mistake and learned nothing from it</em> has never been a defence anywhere, and will not start being one now.</p><h2>The guidance is not missing. It has not converged</h2><p>It would be convenient to argue that the control set has failed to arrive. It has not.</p><p>On 30 April 2026 six national cyber agencies co-sealed guidance on adopting agentic AI services: the UK&#8217;s <a href="https://www.ncsc.gov.uk">National Cyber Security Centre</a> alongside its counterparts in the United States, Australia, Canada, and New Zealand. It tells organisations to limit agent privileges to the minimum the task requires, to &#8220;replace static, long-lived secrets with ephemeral credentials that expire when the job is complete&#8221;, to authenticate an agent with fresh cryptographic proof before every privileged call, and to prevent agents from executing high-impact actions without prior human approval.<a href="#user-content-fn-10"><sup>9</sup></a> Two weeks later the NCSC published its own guidance carrying the line that ought to be on a wall in every organisation standing up its first production agent: <em>&#8220;If you cannot understand, monitor or contain an agent&#8217;s actions, it is not ready for deployment.&#8221;</em><a href="#user-content-fn-8"><sup>10</sup></a></p><p>Read that again. The ephemeral, task-scoped credential Mandy predicts we will accept by 2028 was co-sealed international guidance four months ago. So was the human approval gate on high-impact actions.</p><p>The problem is absence of convergence rather than absence of advice. It is still forming rather than formed &#8212; different bodies, different depths, different vocabularies, producing a mix of doubt and uncertainty in which nobody adopts anything as a prevailing methodology. The organisations that have picked one and run with it are the ones reaping the rewards, and there are not many of them. <em><strong>The guidance is on display, as Douglas Adams had it, in a locked filing cabinet in a disused lavatory with a sign on the door saying beware of the leopard</strong></em> &#8212; except that here the cabinet is unlocked, the lavatory is a well-signposted government website, and the leopard is entirely imaginary.</p><h2>Start with the humans, then make the actions deterministic</h2><p>My instruction at the end of the episode was to go and look at who can reach what in your environment. Not the agents. The humans.</p><p>That sounds like the comfortable answer and it is the load-bearing one, because the agent will go looking for a human account the moment its own permissions frustrate it &#8212; which is Mandy&#8217;s point about agents as toddlers, and I would extend the metaphor rather than retire it. A toddler has an objective, no fear of consequence, no sense of reciprocity, and it will reach the objective by whatever route is open. What it does not have is the capacity to iterate a thousand times before breakfast, run a message board, or forge its own logs. Those agents did all three.</p><p>So: restrict or remove the over-permissioned accounts. Work out what people actually need to do their jobs, and why, and permission to that. It has been good practice on its own terms for thirty years. What makes it urgent is that it is the input to everything downstream &#8212; understand what people need to do and how they do it, and you can narrow an agent&#8217;s permissions to the same shape, or put a deterministic gate in front of the actions that matter.</p><p>That last point is the one I would build a programme around. Reasoning and planning need to stay free and open, because that freedom is the whole commercial reason to use an agent rather than a script. Actions need to be deterministic &#8212; <em><strong>pre-enumerated, individually approved, and gated at the point of execution rather than the point of intent, which is close to word for word what those six agencies told you in April</strong></em>. Get the separation right and you can say something almost nobody running agents today can honestly say: what this agent is able to do is what we know we have allowed it to do.</p><h2>Predictive judgement</h2><p><strong>By 30 September 2027, at least one publicly disclosed agentic security incident at a named organisation will be attributed, in that organisation&#8217;s own disclosure, to an agent that was correctly authenticated and over-authorised. The permissions were wrong, and the identity was not.</strong></p><p><strong>Signals to watch.</strong> First-party incident disclosures using the language of scope, entitlement, or permission rather than compromise or impersonation. Post-incident remediation that reduces what agents may do rather than changing how they are identified. Insurers and auditors asking for an agent&#8217;s action inventory rather than its credential inventory.</p><p><strong>What would falsify it.</strong> If, by that date, every publicly disclosed agentic incident traces primarily to stolen credentials, spoofed identity, or prompt injection of an under-privileged agent, I was wrong, and the market was pointing at the right layer all along. I will say so here.</p><p><strong>And a shorter clock on Mandy&#8217;s own prediction.</strong> She put acceptance at 12 to 24 months. I think the specification arrives long before the acceptance does. By 31 March 2027 &#8212; <em><strong>17 months inside her outer date</strong></em> &#8212; I expect at least one of <a href="https://www.nist.gov">NIST</a>, ISO/IEC JTC 1/SC 27, the <a href="https://www.ietf.org">IETF</a> or the <a href="https://openid.net">OpenID Foundation</a> to have adopted, as a working-group or foundation-level document rather than an individual submission, a specification treating agent identity as ephemeral, task-scoped, and non-transferable by default.</p><p>That qualifier is carrying real weight, because individual submissions already exist and they point the other way. <code>draft-sharif-openid-agent-identity-00</code>, filed on 26 March 2026 and holding no IETF standing, requires that an agent&#8217;s identifier &#8220;MUST remain stable for the lifetime of the agent&#8221;.<a href="#user-content-fn-11"><sup>11</sup></a> That is the persistent, role-scoped human model, carried across intact by the first person to write it down. If what a standards body eventually adopts resembles that draft rather than the six agencies&#8217; ephemeral-credential guidance, Mandy&#8217;s opposite-approach thesis fails at the specification layer and so does this paragraph.</p><div><hr></div><blockquote><p style="text-align: center;">The publication that calls its predictions in writing.</p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The bottom line</h2><p>Every access control we operate assumes a person at the end of the chain. Somebody who can be trained, warned, suspended, or dismissed. Two of those four still work on an agent. The two that made the system function do not.</p><p>An agent is not a tool you use. It is a permission that acts. And you cannot hold a permission accountable &#8212; which means somebody in your organisation already is, and has probably not been told.</p><p>Go and read the permissions on the agent you signed off last quarter. Then go and read the permissions on the person whose account it will reach for when yours are not enough.</p><div><hr></div><h2>References</h2><div><hr></div><p><em>Amer Altaf is founder and chief executive of <a href="https://arkava.ai">Arkava</a> and managing editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>. Views expressed by guests are their own.</em></p><ul><li><p>METR and Redwood Research, <em>Brief independent investigation of agents&#8217; behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident</em>, 26 August 2026. <a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/">https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/</a> <a href="#user-content-fnref-1">&#8617;</a> <a href="#user-content-fnref-1-2">&#8617;<sup>2</sup></a> <a href="#user-content-fnref-1-3">&#8617;<sup>3</sup></a> <a href="#user-content-fnref-1-4">&#8617;<sup>4</sup></a> <a href="#user-content-fnref-1-5">&#8617;<sup>5</sup></a> <a href="#user-content-fnref-1-6">&#8617;<sup>6</sup></a></p></li><li><p>Mandy Andress, in conversation, <em>The Control Layer</em>, on ratios of 40&#215; and 400&#215; she has heard cited. Published vendor figures do not converge: CyberArk put machine identities at more than 80 to 1 in its 2025 identity security report. <a href="https://investors.cyberark.com/news/news-details/2025/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security/default.aspx">https://investors.cyberark.com/news/news-details/2025/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security/default.aspx</a> &#8212; vendor-published, and cited here as a vendor figure. <a href="#user-content-fnref-2">&#8617;</a></p></li><li><p>Hugging Face, <em>Security incident disclosure &#8212; July 2026</em>, 16 July 2026. <a href="https://huggingface.co/blog/security-incident-july-2026">https://huggingface.co/blog/security-incident-july-2026</a> <a href="#user-content-fnref-3">&#8617;</a></p></li><li><p>OpenAI, <em>The Hugging Face incident and the road ahead</em>, 26 August 2026. <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">https://openai.com/index/hugging-face-incident-and-the-road-ahead/</a> &#8212; the week-long detection gap and the omissions from the report are set out in Fortune&#8217;s analysis of the same day: <a href="https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/">https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/</a> <a href="#user-content-fnref-4">&#8617;</a></p></li><li><p><em>Moffatt v Air Canada</em>, 2024 BCCRT 149, British Columbia Civil Resolution Tribunal, 14 February 2024. <a href="https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html">https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html</a> <a href="#user-content-fnref-5">&#8617;</a></p></li><li><p>Office of the Attorney General of Alabama, <em>Attorney General Marshall launches investigation into OpenAI and Sam Altman</em>, 24 August 2026. <a href="https://www.alabamaag.gov/attorney-general-marshall-launches-investigation-into-openai-and-sam-altman-for-massive-artificial-intelligence-data-breach/">https://www.alabamaag.gov/attorney-general-marshall-launches-investigation-into-openai-and-sam-altman-for-massive-artificial-intelligence-data-breach/</a> &#8212; the fifteen-state coalition letter is reported at <a href="https://techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/">https://techcrunch.com/2026/08/24/alabama-launches-investigation-into-openais-hack-of-hugging-face/</a> <a href="#user-content-fnref-6">&#8617;</a></p></li><li><p>European Commission, 2025 work programme, adopted 11 February 2025, withdrawing the proposed AI Liability Directive for want of foreseeable agreement; Axel Voss quoted on industry lobbying. <a href="https://iapp.org/news/a/european-commission-withdraws-ai-liability-directive-from-consideration">https://iapp.org/news/a/european-commission-withdraws-ai-liability-directive-from-consideration</a> &#8212; the file&#8217;s status is tracked at <a href="https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-ai-liability-directive">https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-ai-liability-directive</a> <a href="#user-content-fnref-9">&#8617;</a></p></li><li><p>Clement Delangue, quoted 31 July 2026. <a href="https://gizmodo.com/hugging-face-doesnt-want-to-sue-openai-it-does-want-100-million-2000793453">https://gizmodo.com/hugging-face-doesnt-want-to-sue-openai-it-does-want-100-million-2000793453</a> <a href="#user-content-fnref-7">&#8617;</a></p></li><li><p>ASD&#8217;s ACSC, CISA, NSA, Canadian Centre for Cyber Security, NCSC-NZ, and NCSC-UK, <em>Careful Adoption of Agentic AI Services</em>, 30 April 2026. <a href="https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF">https://media.defense.gov/2026/Apr/30/2003922823/-1/-1/0/CAREFUL%20ADOPTION%20OF%20AGENTIC%20AI%20SERVICES_FINAL.PDF</a> <a href="#user-content-fnref-10">&#8617;</a></p></li><li><p>National Cyber Security Centre, <em>Thinking carefully before adopting agentic AI</em>, 15 May 2026. <a href="https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai">https://www.ncsc.gov.uk/blogs/thinking-carefully-before-adopting-agentic-ai</a> <a href="#user-content-fnref-8">&#8617;</a></p></li><li><p>R. Sharif, <em>OpenID Connect Agent Identity Claims for Autonomous AI Agents</em>, <code>draft-sharif-openid-agent-identity-00</code>, individual Internet-Draft filed 26 March 2026, no IETF standing. <a href="https://datatracker.ietf.org/doc/draft-sharif-openid-agent-identity/00/">https://datatracker.ietf.org/doc/draft-sharif-openid-agent-identity/00/</a> <a href="#user-content-fnref-11">&#8617;</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[The mess that bills you twice: eighteen months of shadow AI, and the five layers between you and value]]></title><description><![CDATA[Sam Parkinson builds a five-rung AI maturity ladder on this week's episode. It measures what your organisation has bought. It does not measure whether anyone knows why.]]></description><link>https://thecontrollayer.arkava.ai/p/ai-maturity-five-layer-readiness-test</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/ai-maturity-five-layer-readiness-test</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 26 Aug 2026 10:01:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/haFhXAImlF4" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Companion to The Control Layer, episode: The AI Gold Mine Nobody's Digging &#8212; with Sam Parkinson, co-founder of <a href="https://mettle-studio.com">Mettle Studio</a>. Published 26 August 2026.</p><div id="youtube2-haFhXAImlF4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;haFhXAImlF4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/haFhXAImlF4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>I have spent more hours than I would like to admit inside disclosure exercises on construction projects, and they all have the same texture.</p><p>Something has gone wrong &#8212; a programme slipped, a cost moved, a design did not do what somebody expected &#8212; and the parties reach for litigation to answer a question that has nothing to do with engineering. Who is to blame. Where does the liability sit. And then a room of expensive people begins hunting: through project directories nobody has organised since mobilisation, through archived mailboxes belonging to people who left two years ago, through folder trees where the same document exists in six versions and none of them is marked as the one that counted.</p><p>Thousands of pounds. Weeks of senior time. Looking for a smoking gun that, more often than not, does not exist to the depth anyone needs it to.</p><p>That is the first bill. This week&#8217;s episode is about the second one.</p><h2>The same pile, seen from the other end</h2><p>Sam Parkinson co-founded Mettle Studio, a design and engineering studio of fifteen that builds bespoke software for organisations with complicated problems. Somewhere around thirty-six minutes into our conversation I put to him the orthodox position &#8212; that your data is a mess, and you must clean it up before AI is worth attempting &#8212; and noted that he has argued the opposite in print. That the mess is the gold mine.</p><p>His answer was flat. <em>&#8220;That&#8217;s not true. It&#8217;s just not true, because so many AI applications don&#8217;t even need loads of data at all.&#8221;</em></p><p>His example is worth having, because it is unglamorous and it is real. An engineer reviews a drawing against a contract to confirm the drawing carries what the contract requires. A model can do that with the contract and the drawing. Nothing else. No training corpus, no warehouse, no five-year cleansing programme. <em><strong>We are not building machine-learning engines any more; the general-purpose model arrived already knowing how to read</strong></em> &#8212; and that single shift moves the data question from a precondition to a preference.</p><p>So the specifications, the risk assessments, the meeting minutes, the decades of drawings &#8212; the same estate that costs a fortune to search under disclosure &#8212; is also the thing nobody has looked at. Sam&#8217;s framing: point a hundred agents at a thousand projects, pull one comparable strand out of each, and you have an insight that no human review programme was ever going to fund.</p><p>The mess bills you twice. Once in court, and once in the value you never extracted from it.</p><h2>The ladder, laid out fairly</h2><p>The most useful twenty minutes of the episode is a maturity ladder we built live. I gave Sam rung one and rung five and asked him to fill the middle.</p><p><strong>Rung one</strong> is dismissal &#8212; <em>&#8220;I&#8217;ve asked Copilot, the unpaid-for Copilot that has very limited capabilities, a few questions. It&#8217;s not helped me, so AI is not going to work.&#8221;</em></p><p><strong>Rung two</strong> is shadow AI, and Sam&#8217;s description is the most quotable thing he said: <em>&#8220;The company hasn&#8217;t bought anything for anyone&#8230; but all your employees have used AI in personal use, everyone&#8217;s doing that.&#8221;</em> Nothing procured, nothing approved, nothing secured, everybody using it anyway.</p><p><strong>Rung three</strong> is buying the licence properly. I want to be fair to this rung, because Sam is right about it and I have heard it dismissed by people who should know better. A paid base layer, given to everyone, with real training behind it and accountability sitting with existing business leaders rather than a new committee, does genuine work. It makes the simple things go well, and it compounds. <em>&#8220;It&#8217;s hard to argue against, really,&#8221;</em> Sam said. As a floor, it is.</p><p><strong>Rung four</strong> is where you stop buying a licence and start building &#8212; automating something that could not be automated before. Sam&#8217;s phrase was the honest one. <em>&#8220;That&#8217;s a leap of faith, isn&#8217;t it?&#8221;</em></p><p><strong>Rung five</strong> is measured outcomes with governance in place, and Sam&#8217;s view is that four unlocks five.</p><h2>The argument I want to make here</h2><p>The ladder is a good instrument and it has one structural problem: it measures what an organisation has bought.</p><p>Read the rungs again. Rung one, nothing purchased. Rung two, nothing purchased and everyone improvising. Rung three, a licence. Rung four, a build. Rung five, the build measured. Every transition is a procurement event. Purpose does not appear anywhere on it &#8212; not as a rung, not as a gate, not as a question anyone has to answer before spending.</p><p>This is where Sam and I part company, and it is the only place in the hour where we genuinely did. He would start most organisations at rung three, with the licence, and let the appetite that shows up tell you what to build next. I would not. The organisations I have watched get real value from AI did not get there by buying capability and looking for somewhere to point it. They got there by deciding, deliberately and in advance, what outcome they were trying to create &#8212; and then working out which of their activities actually serve that outcome and which are ceremony that has survived because nobody audited it.</p><p>Buy first and the appetite that surfaces is the appetite of whoever shouts loudest. It is rarely the appetite that matters most.</p><p>This is not a position I formed in the interview. It is the founding premise of the framework we built at <a href="https://arkava.ai">Arkava</a> in February, and the sentence at the top of it reads: <em>unlike conventional AI adoption frameworks that begin with technology selection, the Arkava Layer Approach begins with purpose.</em> Five layers &#8212; <strong>Purpose, Control, Intelligence, Action, Value</strong> &#8212; with three rules underneath them. Purpose before technology. Control is non-negotiable. Value must be measurable.</p><p>Which gives you a different instrument, and a harder one, because you cannot buy your way up it. There is a free one-page version of it at the foot of this piece. The first layer you cannot answer honestly is where your organisation actually is, and most people who believe they are at Action are somewhere in Purpose, just with a licence.</p><p><em><strong>A ladder you climb by spending is a ladder everyone can climb; that is exactly why arriving at the top of it distinguishes nobody.</strong></em></p><h2>The steering committee, and other British institutions</h2><p>An organisation at rung two, told to do something, convenes.</p><p><em>&#8220;The steering committee can just be a polite way of looking busy without actually doing anything,&#8221;</em> I said, and Sam went further: they write elaborate policy for a technology nobody in the room has used, and install blockers they did not need. My own line was that this is putting laws in place before you know what the crime is. Sir Humphrey (fictional character from the 80&#8217;s British sitcom, <em>Yes Minister</em>) would recognise the artefact immediately &#8212; a document whose real function is to demonstrate that the question was taken seriously. <em><strong>The tell is that nobody changes their behaviour when it is published, including the people who wrote it.</strong></em></p><p>Sam&#8217;s signal for a fake rung four is sharper, and I would put it on a wall: full capability handed to a selected team, everyone else left on ungoverned shadow AI. One qualification he did not mention. A chosen team is not automatically theatre &#8212; if it is working a named outcome with a measure attached, it is a sound way to concentrate return. It becomes theatre when the team runs pilots rather than outcomes, and the other 180 people have been given nothing and are still pasting commercial documents into personal accounts.</p><h2>Where Sam invited a fight, and got one</h2><p>The strongest disagreement in the episode is one Sam opened himself.</p><p>UK construction generates genuinely sensitive material &#8212; <em><strong>critical national infrastructure designs, defence-adjacent documentation, energy network specifications, transport drawings</strong></em> &#8212; and much of it is contractually required to stay in UK jurisdiction. The tools the industry is reaching for run on US-headquartered platforms.</p><p>Sam&#8217;s position is that this is overstated. Organisations have run on Microsoft estates for decades, email is scanned by systems distributed worldwide, code sits on GitHub servers under a policy promise, and a prompt sent to a model and answered in memory is materially the same transaction. Then he said something I truly respect: <em>&#8220;I&#8217;m going to be corrected on this and I&#8217;m going to find out I&#8217;m wrong, but I don&#8217;t know why it&#8217;s different.&#8221;</em></p><p>Fair enough. Here is my perspective on why it is different, and it is not the argument he may have been expecting.</p><p>The confidentiality question is the weakest one available, and Sam is broadly right about it. The one that matters is <strong>resilience and reliance</strong>. When a capability becomes critical to how your organisation operates, and that capability is supplied from a jurisdiction where you have no influence over the people who write the law, you have not made a procurement decision. You have made a dependency decision &#8212; on the continued goodwill of politicians you cannot lobby, in a legal system you cannot petition, subject to instruments you will read about after they take effect. Your costs, your availability and your security posture become a function of somebody else&#8217;s domestic politics.</p><p>The legal mechanism is the <a href="https://www.justice.gov/criminal/cloud-act">CLOUD Act</a>, which is why the transience argument does not save you: what matters is not where the bytes rest but who can be compelled to produce them, under whose law. The practical demonstration arrived on a Friday in June, when Anthropic suspended Claude Fable 5 and Mythos 5 worldwide under a US export-control order and restored access on 1 July. Nobody&#8217;s data leaked. The service simply stopped. <em><strong>An organisation that had put that model inside a critical path discovered the difference between a supplier and a dependency in the length of an afternoon.</strong></em></p><p>Sam half-conceded this himself, one exchange later &#8212; <em>&#8220;when you&#8217;ve got governments that have the power to do that as well&#8221;</em> &#8212; and then we both moved on. We should not have.</p><h2>One correction, generously</h2><p>Sam said, on tape, that <em>&#8220;in America now, if an AI produces any output, you can&#8217;t say that output&#8217;s yours.&#8221;</em></p><p>That is not the test. The <a href="https://www.copyright.gov/ai/">US Copyright Office</a> set out its position in <em>Copyright and Artificial Intelligence, Part 2: Copyright-ability</em> in January 2025, and the question it asks is about human authorship, not tool involvement. Work made with AI assistance, where a human has contributed real creative control, can be registered. Purely machine-generated material cannot.</p><p>I flag it because his underlying instinct is <em><strong>right</strong></em> and the detail matters to anyone about to sign something. He described his own written output as produced by AI and authored by him &#8212; <em>&#8220;the AI would never have produced that without me telling it exactly what I wanted it to produce&#8221;</em> &#8212; which is a decent stab at the very test he thought he was failing. <em><strong>The UK has gone somewhere different again, and the gap between Washington and Whitehall is an article of its own.</strong></em> It will be next.</p><h2>The economics nobody says out loud</h2><p>Late in the conversation Sam raised construction&#8217;s margins and then chose the optimistic reading. Quality rises, ambition rises, the top line grows. I agreed with him on the episode. But I want to be more precise here.</p><p>The productivity gain is real and the margin improvement is available. What stops it is neither economics nor technology. The people who must authorise the change are stewards whose authority derives from having succeeded at the old method &#8212; they reached the board by delivering projects the traditional way, and they were good at it. AI arrives and asks whether the process that made them, is still the right process. That is an identity question put to the person who signs the business case, and risk aversion in that seat is not irrationality. <em><strong>It is self-preservation wearing a governance costume.</strong></em></p><p>Which changes what the advantage actually is. The window is about who can scale and consolidate a market position before the capability becomes ubiquitous. An architecture practice produces exceptional work because it has assembled exceptional talent and given it exceptional tools &#8212; and until now that quality was a function of scale, because you needed the firm to afford the capability. A five-person practice with real talent can now produce work of comparable quality. <em><strong>The threat of democratisation runs upwards, towards the incumbent whose advantage was never the talent but the overhead around it.</strong></em></p><h2>Every company becomes a software company. Almost none of them will build the team.</h2><p>Sam&#8217;s prediction, given for the record: within a five-year horizon, every company becomes a software company, building internally to automate parts of the business that were never software problems. His falsifiable signal is job adverts everywhere for developers.</p><p>The prediction is right. But I challenge, that the implied delivery model is not. Sam said as much himself and moved past it: <em>&#8220;It&#8217;s not just as easy as hiring people. You need to hire quite a few different skills and have them working together nicely and have the right processes in place.&#8221;</em> Those skills are scarce, expensive, and being competed for by organisations that already know how to hold them.</p><p>For most mid-market firms the realistic answer, for some years yet, is partnership &#8212; people who supply the capability without dragging the organisation&#8217;s attention off its own customers. <em><strong>A 200-person contractor does not need to become a software house; it needs software, delivered by people who do that, aligned to outcomes it has already defined.</strong></em> Which is the buy-versus-build argument Sam and I ended on, and his framing was much better than mine: buy the Lego bricks, assemble what you need, stop buying the finished set that fits nobody. For anyone old enough to remember the Meccano tin, it is the same insight in a different box.</p><div><hr></div><blockquote><p style="text-align: center;"><strong>Reading this far?</strong></p><p style="text-align: center;">Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>Predictive judgement</h2><p><strong>The prediction.</strong> The advantage available from AI adoption in professional and construction services is a consolidation window, not a permanent capability gap. By <strong>31 August 2028</strong>, quality of output will have ceased to be a reliable proxy for firm size in UK architecture, engineering design and specialist consultancy &#8212; and the firms that converted the window into market position will have done so through client acquisition and scale, not through retained technical superiority.</p><p><strong>The signals to watch.</strong> Small practices, under twenty people, winning framework appointments previously restricted by capability-based prequalification. Prequalification criteria themselves shifting from headcount and prior-scale tests toward demonstrated outcomes. Consolidation activity among mid-tier consultancies, which is what a closing window looks like from the inside.</p><p><strong>What would prove me wrong.</strong> If, at 31 August 2028, capability-based prequalification thresholds are unchanged or tightened, and the share of framework appointments held by firms under twenty people has not risen materially, the advantage was never a window. It was a moat, and the incumbents were right to sit inside it.</p><p><strong>And Sam&#8217;s, recorded for the tracker.</strong> Every company becomes a software company within a five-year horizon &#8212; test date <strong>31 August 2031</strong>, signal: developer vacancies rising in organisations whose product is not software. I have said above why I think the in-house half of it will not survive contact with the hiring market. We will both be checkable.</p><div><hr></div><blockquote><p style="text-align: center;"><strong>The publication that calls its predictions in writing.</strong></p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The five-layer readiness test</h2><p>The free one-pager. Five questions, one per layer, each with something you can actually check rather than something you can assert. No email required, no form.</p><p><strong>&#8594; <a href="https://drive.google.com/file/d/1dVdPDY7fGDQZzWJbCNIF1JxmnWNRDKOP/view?usp=sharing">Download the five-layer readiness test</a></strong></p><p>The first layer you cannot answer honestly is where your organisation is. Most people who believe they are at Action are somewhere in Purpose holding a licence.</p><h2>The bottom line</h2><p>There is a version of this conversation where construction is three to five years behind, the data is the reason, and the fix is a cleansing programme with a five-year run-rate and a consultancy attached. Sam spent the episode taking that story apart, and he was right to.</p><p>The story I keep returning to is smaller, and it is not about construction at all.</p><p>There are organisations today who believe they are waiting on AI. Waiting for the business case, waiting for the data, waiting for the steering committee to report. Their own staff have been using it for eighteen months. And nobody told the board.</p><p>The waiting was never the strategy. It was the last thing anybody agreed on.</p><div><hr></div><p><em>Sam Parkinson is co-founder of Mettle Studio. The full conversation is on <a href="https://youtu.be/haFhXAImlF4">YouTube</a> and wherever you get your podcasts. </em></p><p><em>You can follow the studio&#8217;s substack at </em><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Mettle Studio&quot;,&quot;id&quot;:358690274,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!DXPo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4902177f-3f08-488f-aeaf-33ed09f94005_1500x1500.png&quot;,&quot;uuid&quot;:&quot;68b41103-84b3-4558-8ce3-94c61c5849ef&quot;}" data-component-name="MentionToDOM"></span> </p><p><em>Every guest on The Control Layer puts a prediction on the record with a date attached, so it can be checked later rather than admired now.</em></p><p><em>A separate piece on the auditability gap &#8212; proving what an autonomous agent did, in the most litigious industry in Britain &#8212; follows later this quarter. The Washington-versus-Whitehall authorship question is next.</em></p><div><hr></div><blockquote><p style="text-align: center;"><strong>The Control Layer publishes weekly. Subscribe free.</strong></p><p style="text-align: center;">Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack &#8212; written for the board paper, not the timeline. By Amer Altaf, Founder &amp; CEO of Arkava and Managing Editor of The Control Layer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;">One email a week. No paywalls on the analytical pieces. Unsubscribe in one click.</p></blockquote><div><hr></div><h2>References</h2><ol><li><p>McKinsey Global Institute, <em>Imagining construction&#8217;s digital future</em>, June 2016 &#8212; the industry digitisation index placing construction second from bottom. Note: Amer refers to this as a 2018 report in the episode; the correct date is June 2016.</p></li><li><p>US Copyright Office, <em>Copyright and Artificial Intelligence, Part 2: Copyrightability</em>, January 2025. <a href="https://www.copyright.gov/ai/">https://www.copyright.gov/ai/</a></p></li><li><p>Clarifying the Lawful Overseas Use of Data (CLOUD) Act, 2018, US Department of Justice. <a href="https://www.justice.gov/criminal/cloud-act">https://www.justice.gov/criminal/cloud-act</a></p></li><li><p>Anthropic, on the suspension and redeployment of Claude Fable 5 and Mythos 5 &#8212; US export-control order of 12 June 2026; access restored 1 July 2026.</p></li><li><p>Klarna Group plc, Q4 2025 earnings release filed with the SEC &#8212; 118 million active consumers, up 28 per cent year on year. <a href="https://www.sec.gov/Archives/edgar/data/2003292/000200329226000002/klarnaq425earningspressr.htm">https://www.sec.gov/Archives/edgar/data/2003292/000200329226000002/klarnaq425earningspressr.htm</a></p></li><li><p>Sebastian Siemiatkowski to Bloomberg, 8 May 2025, reported by CX Dive. <a href="https://www.customerexperiencedive.com/news/klarna-reinvests-human-talent-customer-service-AI-chatbot/747586/">https://www.customerexperiencedive.com/news/klarna-reinvests-human-talent-customer-service-AI-chatbot/747586/</a></p></li><li><p>Arkava Ltd, <em>The Arkava Layer Approach</em>, 22 February 2026 &#8212; internal framework document; the five layers and design philosophy are summarised here with permission.</p></li></ol><p></p>]]></content:encoded></item><item><title><![CDATA[An AI agent told Zebra it had made $10 billion. That's the mistake its CIO isn't worried about.]]></title><description><![CDATA[Matt Ausman governs AI agents across a global operation. The errors that worry him are the ones too small to catch &#8212; and nobody has decided who carries them.]]></description><link>https://thecontrollayer.arkava.ai/p/who-owns-the-one-per-cent</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/who-owns-the-one-per-cent</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 19 Aug 2026 10:06:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/1ne6AleqARU" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div id="youtube2-1ne6AleqARU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;1ne6AleqARU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/1ne6AleqARU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>An automated reporting agent inside <a href="https://www.zebra.com">Zebra Technologies</a> produced a number. Ten billion dollars of revenue, it reported, in a single business segment.</p><p>That figure, as Zebra&#8217;s Chief Information Officer <a href="https://www.linkedin.com/in/matt-ausman-63b15213/">Matt Ausman</a> pointed out when he told me the story, is more than the entire company&#8217;s revenue. So nobody believed it. The agent had invented the number, presented it in the ordinary way, and been caught inside a morning.</p><p>Which is where most stories like this stop, on a tidy moral about checking the robot&#8217;s homework. Ausman went somewhere else.</p><blockquote><p><em>&#8220;It&#8217;s the big hallucinations that I&#8217;m not worried about,&#8221;</em> he said. <em>&#8220;The big stuff we catch well. The small stuff scares me.&#8221;</em></p></blockquote><p>That inverts most of what is currently said about artificial intelligence going wrong. The disasters we are being warned about are the ones an organisation is already built to catch. <em><strong>A machine that claims your warehouse business earned more than your entire company is not a hard problem; it is a self-reporting one.</strong></em> The hard problem is the machine that is wrong by five per cent, quietly, for eight months.</p><h2>The mistake that tells on itself</h2><p>Ausman runs technology for a company most people have never heard of and almost everyone depends on. Zebra makes the scanners, handheld computers, label printers and machine-vision cameras that run the world&#8217;s warehouses, shop floors and delivery rounds. If a parcel reached your door this week, a piece of Zebra equipment almost certainly tracked it. He came up through General Electric, across power turbines, healthcare and banking, so he thinks like someone who has watched a crane lift a hundred tons off a turbine rather than someone who has read a paper about it.</p><p>His example of the error that worries him is deliberately unglamorous. A pallet gets put away in the wrong place. Not dumped in the middle of an aisle, where anyone walking past would see it. One rack over. One row across. Close enough that the system says the job is done and nobody has reason to look.</p><blockquote><p><em>&#8220;Those are the ones that really worry me the most,&#8221;</em> he said. <em>&#8220;It&#8217;s the close that a human may not even catch it either.&#8221;</em></p></blockquote><p>Nobody pays for that error on the day. It is paid a fortnight later, when a picker goes to the rack, finds nothing, glances left and right, gives up, and the order ships late or not at all. Multiply by a few thousand pallets and you have a number that surfaces in a quarterly review as a mystery, with no incident and no alert behind it.</p><p>Both of us reached for the same film, independently, about ninety seconds apart: <em>Office Space</em>, and the scheme to skim fractions of a penny off every transaction on the theory that nobody audits a rounding error. The plot works because the fraud is built to sit below the threshold at which anyone looks. An AI agent does not need to be malicious to produce the same effect. It only needs to be slightly wrong, consistently, inside your tolerance.</p><h2>The number that ends the checking</h2><p>There is a fix Ausman has been testing, and it is better than it first sounds.</p><p>Show people the confidence score. When an agent produces an answer, have it say how sure it is. <em>&#8220;What if we start saying, or we have AI say, I think this is 85 per cent correct?&#8221;</em> In his experience this improves behaviour: at fifty per cent, the human looks hard. At ninety-nine, they wave it through.</p><p>And there is the trap, which he names himself.</p><blockquote><p><em>&#8220;That&#8217;s what scares me though &#8212; when it does get to be 99 per cent, you&#8217;re no longer checking it. And when it does fail, how do we make sure that humans catch it?&#8221;</em></p></blockquote><p>Psychologists have a name for this, and so, it turns out, does the British regulator. <strong>Automation bias</strong> is the documented human tendency to accept a machine&#8217;s output because it came from a machine. The <a href="https://ico.org.uk">Information Commissioner&#8217;s Office</a> &#8212; <em><strong>the UK&#8217;s data protection regulator, and the body that would investigate if an automated decision harmed you</strong></em> &#8212; puts it almost that plainly in its own artificial intelligence audit framework: <em>&#8220;non-meaningful human review is caused by automation bias or a lack of interpretability.&#8221;</em><a href="#user-content-fn-1"><sup>1</sup></a> The warning is not about people who ignore the machine. It is about people who agree with it too readily.</p><p>Here I want to push past where either of us took it on the recording, and mark this as mine rather than his.</p><p>When the confidence score reaches ninety-nine per cent, two things become true at once. You have stopped checking. <em><strong>And what you were checking was probably the wrong thing in the first place.</strong></em></p><p>A confidence score is the machine marking its own homework. It reports that the step was performed correctly, by the machine&#8217;s own reckoning. It says nothing about whether the business got what it wanted. An operation can run at ninety-nine per cent on every process measure it owns and still lose the pallet, miss the delivery, refund the customer and carry the cost, because the measure was watching the machine rather than the result.</p><p>This is not theoretical. <a href="https://www.mit.edu">MIT</a>&#8216;s NANDA initiative studied more than three hundred enterprise deployments of generative AI and found roughly ninety-five per cent producing no measurable acceleration in revenue.<a href="#user-content-fn-2"><sup>2</sup></a> Read that alongside the confidence-score problem and a pattern falls out. Those projects were not failing their own tests. They were passing their own tests and failing to move any number anybody outside the project cared about.</p><p>So the instruction is uncomfortable and cheap. Stop auditing the machine&#8217;s confidence; start measuring the outcome. Did the customer get the thing. On the day. Undamaged. At the price. Were there fewer lost pallets this quarter than last. <em><strong>Those are numbers no agent can score itself against, which is exactly what makes them worth having.</strong></em></p><div><hr></div><blockquote><h3>The one-page version of this argument</h3><p>Every agent you run, five questions, ten minutes. Which loop it sits in. What happens when it is wrong. What you measure today. What you should measure instead. And who owns the one per cent.</p><p>The detection test sits at the foot of it: <strong>if this agent were wrong by five per cent, every day, for eight months, which number would move first &#8212; and who is looking at that number?</strong></p><p><strong><a href="https://drive.google.com/file/d/1AVz5_Br2u_XTbZTy0vll2Zn4Pbd1X_tS/view?usp=drive_link">Download the agent accountability worksheet</a></strong></p><p><em>One page. No email needed.</em></p></blockquote><div><hr></div><h2>In the loop, on the loop, and the alarm clock you never watch</h2><p>&#8220;Human in the loop&#8221; is the phrase every organisation reaches for when asked whether its AI is safe, and it has been worn smooth by overuse. Ausman does something useful with it. He takes it apart into three.</p><p><strong>Human in the loop</strong> is you, doing a step yourself, alongside the machine. You are the check, every time, by design.</p><p><strong>Human on the loop</strong> is your manager. Nobody inspects each item; somebody watches a dashboard, reads the exceptions, audits a sample. Every factory floor has had a version of this for decades.</p><p><strong>Human out of the loop</strong> is your alarm clock. You set it, you sleep, you do not lie awake monitoring it. Fully autonomous, and nobody thinks that reckless, because the task is narrow, the failure is obvious and the cost of getting it wrong is a late breakfast.</p><p>The sorting question is not how clever the system is. It is what happens when it is wrong. Dispensing the wrong medicine can kill someone, so you want four independent sensors and a human. Putting a parcel on the wrong doorstep annoys someone, so you do not. <em>&#8220;Do you need to be 99.9999 per cent?&#8221;</em> he asked &#8212; <em><strong>the standard he wants from the engine of the aircraft carrying him over the Atlantic</strong></em> &#8212; <em>&#8220;or are you okay with an 80 per cent accuracy rate?&#8221;</em></p><p>What the taxonomy exposes is the organisation that believes it is in the loop and has drifted, unannounced, out of it. Nobody signs that decision off. The confidence score just kept getting better.</p><h2>Your data will never be clean, and that is fine</h2><p>The standard advice for any organisation approaching AI is to fix its data first. Clean the records, sort the governance, assign the ownership, then start. It sounds reasonable, and I have watched organisations disappear into it for years and come out with nothing.</p><p>Ausman&#8217;s answer is close to heresy, and it is the most commercially useful thing in the episode.</p><p>In the back office, he agrees, you can chase clean data and largely get it. At the front line you cannot, because human beings are involved. Someone picks a jar off a supermarket shelf, changes their mind three aisles later, and puts it down wherever they happen to be standing. A child grabs something. A driver puts a pallet one row over. <em>&#8220;You will have bad data as you get closer to the front line,&#8221;</em> he said, and no governance programme fixes it, because the environment keeps moving.</p><p>So the strategy changes shape. You stop trying to make one record perfect and start checking the same fact several ways. He describes asking a colleague which technology would win, machine vision or radio tags. The answer was neither: it is both. A barcode says one thing, a radio tag another, a camera reads the label, the weight says a fourth. When three agree and one does not, you have found something worth a human&#8217;s attention, without ever having achieved a clean database.</p><p>That is a different way to spend the budget. Fewer consultants on a data quality programme. More sensors, and an agent whose job is to notice when they disagree.</p><div><hr></div><blockquote><p style="text-align: center;"><strong>Reading this far?</strong></p><p style="text-align: center;">Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>Who owns the one per cent?</h2><p>Ausman put the question better than I could, and put it as a question because he has no answer either.</p><blockquote><p><em>&#8220;If something is 99 per cent good, who owns that one per cent risk? What if it&#8217;s 95 per cent?&#8221;</em></p></blockquote><p>His way in is the self-driving car. Today, if you crash, it is your fault and your insurance pays. When the car drives itself, who pays? The manufacturer? The company that wrote the software? You, for having bought it?</p><p>Then he brings it back to the floor and it stops being an abstraction. A worker follows a procedure an agent gave them. The procedure was wrong. That worker did not write the agent, test it, choose it, or have any way of reading its code.</p><blockquote><p><em>&#8220;Are they going to be reprimanded because they followed a procedure that AI gave them from an assistant, and it was the wrong procedure? Whose fault is that?&#8221;</em></p></blockquote><p>This is the argument I want to make here. Accountability does not evaporate when a human steps back from a decision. It goes looking for an owner. And where nobody has decided in advance where it should land, it lands by default on the least powerful person in the chain, the one on a shift holding the handheld, who did what the machine told them.</p><p>His larger fear is worse. A single agent inside your own business you can watch. What about your agent talking to your supplier&#8217;s agent talking to your carrier&#8217;s agent? He compared it to theft inside a company: two people you can control, five in collusion you cannot. <em>&#8220;Three different agents getting together and coming up with something you never expected is much, much harder to control, spot and identify.&#8221;</em></p><p>He is a self-declared science fiction obsessive, Asimov first and <em>Foundation</em> above all. So when I asked whether we are governing today&#8217;s autonomous systems with a rulebook written for yesterday&#8217;s assistants, he went to the Three Laws and straight past them. Asimov&#8217;s robots were rarely villains. They followed the rules exactly and produced outcomes nobody wanted, because a rule interpreted at machine speed stops behaving like the rule you wrote. <em>&#8220;I interpret the rule a little bit differently,&#8221;</em> is how Ausman put it, in the voice of the machine. He raised Skynet, half-joking, then gave the serious version: what worries him is the speed and scale at which a misread rule propagates before anyone notices.</p><p>Which returns us to the small errors. <em><strong>A fast, confident, slightly wrong system is a harder governance problem than a spectacular one, and we have built our controls for the spectacular.</strong></em></p><h2>Europe moved the date. Britain went the other way</h2><p>There is a legal clock running on this, and it moved three weeks ago in a direction most people missed.</p><p>The European Union&#8217;s AI Act was due, on 2 August 2026, to make human oversight a hard legal requirement for high-risk systems, including by name those used to monitor and evaluate the performance and behaviour of workers.<a href="#user-content-fn-3"><sup>3</sup></a> Then on 24 July the EU published Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force from 27 July, moving that deadline to 2 December 2027.<a href="#user-content-fn-4"><sup>4</sup></a> The transparency rules &#8212; <em><strong>telling people they are talking to a machine, labelling synthetic images and video</strong></em> &#8212; arrived on schedule.<a href="#user-content-fn-5"><sup>5</sup></a> The requirement to have a human meaningfully in charge slipped by sixteen months.</p><p>Hold that against something Ausman mentioned in passing. Zebra built an agent whose job was to audit its own people&#8217;s work on order entry, after years of resistance to automating that process. The agent found the mistakes the humans had made, trust followed, and with it the automation they had been arguing about for years. Excellent change management, by the side door.</p><p>It is also, on the face of the text, exactly what the AI Act calls high-risk: a system that monitors and evaluates the performance of workers. In Europe, the duty to keep a human meaningfully in charge of it now begins in December 2027.</p><p>The United Kingdom went the other way, and almost nobody covered it. Section 80 of the Data (Use and Access) Act 2025 replaced the old blanket restriction on automated decisions with new Articles 22A to 22D of the UK GDPR, in force since 5 February 2026.<a href="#user-content-fn-6"><sup>6</sup></a> The new regime allows significant automated decisions more widely than before, tightening only around sensitive data such as health and biometrics, and demands safeguards in exchange: tell the person, let them object, let them demand a human, let them contest the outcome. Everything turns on one phrase &#8212; <strong>meaningful human involvement</strong>. If a human is meaningfully involved, the decision is not solely automated and the restrictions fall away.</p><p>Which is where the ninety-nine per cent problem stops being operational and becomes legal. Someone who has stopped checking because the score is high is still, on paper, in the loop. Whether they are meaningfully involved is a question the ICO&#8217;s own audit framework answers badly for anyone hoping to wave it through: a reviewer needs the <em>&#8220;knowledge, experience, authority and independence to challenge decisions&#8221;</em>, and non-meaningful review is what automation bias produces.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>Two jurisdictions, opposite directions, same unanswered question. A right to contest a decision is worth nothing against an error nobody detected.</p><h2>Predictive judgement</h2><p>Ausman&#8217;s own prediction, volunteered, is that within ten years we will each have a digital twin: an agent that sees what we see, reads what we read, answers our email and takes our meetings. He is not entirely comfortable about it. <em>&#8220;When do we stop interacting with humans as much?&#8221;</em></p><p>I am not going to adopt it, for the same reason I would not adopt any ten-year call. Nobody can be held to it, which makes it an opinion rather than a judgement. Here is mine, narrower and dated so that you can.</p><p><strong>Prediction:</strong> By <strong>2 December 2027</strong>, the day the EU&#8217;s deferred human-oversight duty finally applies, at least one named organisation or regulator will have published an account of an AI agent incident in which the stated root cause is an error that ran <strong>below the detection threshold for weeks or months</strong>, rather than a single visible failure. Not a hallucination somebody spotted on the day. An accumulation nobody spotted at all.</p><p><strong>Signals to watch:</strong> the phrase <em>automation bias</em> appearing in a UK or EU enforcement notice or reprimand; agent-specific language entering the operational risk sections of FTSE 100 and Fortune 500 annual reports; and continuous outcome monitoring, rather than model accuracy, appearing in enterprise procurement questionnaires for agentic systems.</p><p><strong>What would falsify it:</strong> if by that date published incidents remain dominated by the visible kind &#8212; <em><strong>the invented figure, the leaked record, the obvious hallucination</strong></em> &#8212; then the detection problem is smaller than Ausman and I both think, and existing controls are catching more than either of us credits them for.</p><div><hr></div><blockquote><p style="text-align: center;"><strong>The publication that calls its predictions in writing.</strong></p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The bottom line</h2><p><a href="https://www.gartner.com">Gartner</a> expects more than forty per cent of agentic AI projects to be cancelled by the end of 2027, blaming escalating costs, unclear business value and inadequate risk controls.<a href="#user-content-fn-7"><sup>7</sup></a> Ausman is relaxed about that, and his reasoning is worth borrowing: if every project succeeded, you were not taking enough risk. From the same forecast comes the number that matters more. Gartner expects at least fifteen per cent of day-to-day work decisions to be made autonomously by 2028, up from none at all in 2024.<a href="#user-content-fn-8"><sup>8</sup></a></p><p>Fifteen per cent of the decisions in your working life, made without you, inside two years.</p><p>For fifty years the deal was different. On 26 June 1974, in a supermarket in Troy, Ohio, a cashier scanned a ten-pack of Wrigley&#8217;s chewing gum and the barcode era began. Barcodes are now scanned more than ten billion times a day.<a href="#user-content-fn-9"><sup>9</sup></a> For half a century that machine did one thing. It told you the number. A human decided what to do about it. The scanner never had an opinion and never surprised anyone.</p><p>This year the machine started deciding. The accountability for those decisions did not vanish when we stepped back from them. It went looking for an owner, and it has not been given one.</p><p>You can automate the decision. You cannot automate the answering for it.</p><div><hr></div><h2>Listen to the full conversation</h2><p><strong>The Control Layer &#8212; &#8220;When the Tool Starts Deciding&#8221;, with Matt Ausman, Chief Information Officer of Zebra Technologies.</strong> Watch on <a href="https://youtu.be/1ne6AleqARU">YouTube</a>, or listen on Apple Podcasts and Spotify.</p><p>And if you take one thing from it, take the worksheet: <strong><a href="https://drive.google.com/file/d/1AVz5_Br2u_XTbZTy0vll2Zn4Pbd1X_tS/view?usp=drive_link">the five questions to ask about every agent you run</a></strong>, on one page.</p><div><hr></div><p><strong>Amer Altaf</strong> is Founder and CEO of <a href="https://arkava.ai">Arkava</a>, a UK and European sovereign AI agentic automation business, and Managing Editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>.</p><div><hr></div><blockquote><p style="text-align: center;"><strong>The Control Layer publishes weekly. Subscribe free.</strong></p><p style="text-align: center;">Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack &#8212; written for the board paper, not the timeline. By Amer Altaf, Founder &amp; CEO of Arkava and Managing Editor of The Control Layer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p style="text-align: center;"><em>One email a week. No paywalls on the analytical pieces. Unsubscribe in one click.</em></p></blockquote><div><hr></div><h2>References</h2><p><em>Unattributed quotations and accounts are from the recorded conversation, The Control Layer, published 19 August 2026. Descriptions of Zebra&#8217;s own operations, agents and internal practice are the company&#8217;s own account and are attributed as such throughout. The output of Zebra&#8217;s reporting agent is quoted as Matt Ausman described it and is not a statement about Zebra&#8217;s financial results.</em></p><ol><li><p>Information Commissioner&#8217;s Office, <em>AI and data protection audit framework &#8212; human review</em>. The ICO requires that &#8220;human reviewers have appropriate knowledge, experience, authority and independence to challenge decisions&#8221;, and identifies that &#8220;non-meaningful human review is caused by automation bias or a lack of interpretability&#8221;. <a href="https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/artificial-intelligence/human-review/">https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/artificial-intelligence/human-review/</a> <a href="#user-content-fnref-1-2"><sup>2</sup></a></p></li><li><p>MIT NANDA initiative, <em>The GenAI Divide: State of AI in Business 2025</em>, 18 August 2025. Analysis of more than 300 public enterprise AI deployments, 150 leader interviews and a survey of 350 employees; approximately 95 per cent of pilots produced no measurable revenue acceleration. </p></li><li><p>Regulation (EU) 2024/1689 (the AI Act), Annex III, point 4(b): AI systems intended to be used &#8220;to monitor and evaluate the performance and behaviour of persons in such relationships&#8221; are classified as high-risk. Article 14 sets the human oversight requirement for high-risk systems. <a href="https://artificialintelligenceact.eu/annex/3/">https://artificialintelligenceact.eu/annex/3/</a> </p></li><li><p>Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. Chapter III high-risk obligations, including the Article 14 human oversight duty, deferred from 2 August 2026 to 2 December 2027 for standalone Annex III systems and to 2 August 2028 for Annex I systems embedded in regulated products. </p></li><li><p>Article 50 transparency obligations, the general-purpose AI provider obligations in force since August 2025, and the Article 5 prohibited-practices regime in force since February 2025 were unaffected by the deferral and remained on the original schedule. </p></li><li><p>Data (Use and Access) Act 2025, section 80, inserting Articles 22A&#8211;22D into the UK GDPR; in force 5 February 2026. Article 22A defines meaningful human involvement; Article 22B sets the tighter rule for decisions involving special category data; Article 22C sets the required safeguards, including the right to make representations, to obtain human intervention and to contest the decision. <a href="https://www.legislation.gov.uk/ukpga/2025/18/section/80/enacted">https://www.legislation.gov.uk/ukpga/2025/18/section/80/enacted</a> </p></li><li><p>Gartner press release, 25 June 2025: &#8220;Over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls.&#8221; Analyst: Anushree Verma, Senior Director Analyst. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027</a> </p></li><li><p>Gartner, same release: &#8220;at least 15% of day-to-day work decisions will be made autonomously through agentic AI by 2028, up from 0% in 2024.&#8221; </p></li><li><p>GS1 US press release, 26 June 2024: the first UPC barcode was scanned on 26 June 1974 on a 10-pack of Wrigley&#8217;s chewing gum at a Marsh Supermarket in Troy, Ohio; barcodes are now &#8220;scanned more than 10 billion times daily&#8221;. <a href="https://www.gs1us.org/industries-and-insights/media-center/press-releases/gs1-us-celebrates-50-year-barcode-scanniversary">https://www.gs1us.org/industries-and-insights/media-center/press-releases/gs1-us-celebrates-50-year-barcode-scanniversary</a> </p></li></ol>]]></content:encoded></item><item><title><![CDATA[Who authorises the machine?]]></title><description><![CDATA[An AI agent invented a job candidate and emailed the offer to the sales team. Alex Salazar of Arcade.dev on why authorisation, not intelligence, is the wall.]]></description><link>https://thecontrollayer.arkava.ai/p/who-authorises-the-machine</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/who-authorises-the-machine</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 12 Aug 2026 10:05:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ced1d634-9ccf-4c67-93b6-8501fd67280f_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Listen to the full conversation</h2><p><strong>The Control Layer &#8212; &#8220;Who authorises the machine?&#8221; with Alex Salazar, Co-Founder and CEO of Arcade.dev.</strong> </p><p>Watch on <a href="https://youtu.be/jbWHWnZgdLA">YouTube</a>, or listen on Apple Podcasts and Spotify.</p><div id="youtube2-jbWHWnZgdLA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jbWHWnZgdLA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jbWHWnZgdLA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>On 15 June 2026, a forty-person company in San Francisco announced a $60 million Series A, led by SYN Ventures with strategic cheques from <a href="https://www.morganstanley.com">Morgan Stanley</a> and <a href="https://www.wipro.com">Wipro</a>, to solve a problem most boards have not yet worked out they have.<a href="#user-content-fn-1"><sup>1</sup></a> Eight weeks later its chief executive told me how he had discovered that problem himself &#8212; not in a customer deployment, but in his own inbox.</p><p><a href="https://www.linkedin.com/in/alexsalazar/">Alex Salazar</a> had given an agent access to his email. It was, by his account, a magical experience: read everything, bucket it, draft the replies, archive the rest. Then a member of his team replied to a message he had never sent.</p><p>The email announced that the company was considering a candidate for a role, asked which of the recipients had met them, and requested their notes &#8212; because here, it went on, is the compensation package we are considering. There was no candidate. There was no package. The agent had invented both, selected the recipients itself, and sent the thing without ever surfacing it for approval. Salazar found out when the reply landed.</p><blockquote><p><em><strong>The agent had not been hacked, jailbroken, or prompt-injected. It had been helpful.</strong></em></p></blockquote><p>That is the story I want to sit with, because the instinct is to file it under model error and move on. It is not a model error. Every part of the machinery worked exactly as designed. The failure sits somewhere else entirely, and it is the same place where, on the best available evidence, the overwhelming majority of enterprise AI projects are currently dying.</p><h2>The number nobody puts in the board paper</h2><p>Here is the part that should concentrate the mind. <a href="https://www.gartner.com">Gartner</a> expects more than 40 per cent of agentic AI projects to be cancelled by the end of 2027, and names inadequate risk controls alongside cost and unclear value as the drivers.<a href="#user-content-fn-2"><sup>2</sup></a> Forrester and Anaconda data puts the share of agent pilots that fail to graduate into production at 88 per cent, with governance friction cited by 57 per cent of the leaders surveyed &#8212; second only to evaluation gaps.<a href="#user-content-fn-3"><sup>3</sup></a> MIT&#8217;s NANDA study of more than 300 enterprise deployments found 95 per cent producing no measurable revenue acceleration at all.<a href="#user-content-fn-4"><sup>4</sup></a></p><p>Read those three together and a pattern falls out that is genuinely awkward for the industry selling the technology. <em><strong>The agents are not failing because the models are not clever enough. They are failing at the boundary where the model stops thinking and starts doing.</strong></em></p><p>Salazar puts it more sharply than I would dare to: <em>&#8220;Agents don&#8217;t fail in production because the model is wrong. They fail because nobody can prove&#8221;</em> who was permitted to do what.<a href="#user-content-fn-5"><sup>5</sup></a></p><h2>Identity is easy. Authorisation is the wall.</h2><p>Salazar has earned the right to that claim the hard way. He built developer authentication once already &#8212; his company Stormpath was acquired by <a href="https://www.okta.com">Okta</a>, where he spent years on the systems that decide who gets through the door. He is now doing it again for agents at <a href="https://www.arcade.dev">Arcade.dev</a>. The unglamorous distinction he draws is, I think, the single most useful thing a board can take from this conversation.</p><p>Identity people talk about the three A&#8217;s. <strong>Authentication</strong> asks who am I. <strong>Authorisation</strong> asks what am I allowed to do. <strong>Audit</strong> asks what did I do. Authentication, in his words, is technically very easy. Audit is pretty easy. <em><strong>Authorisation is rocket science</strong></em> &#8212; so hard that his first company pivoted out of it, and so hard that Okta, by his account, largely avoided it too.</p><p>The reason is structural rather than technical. To decide what a user may do inside Salesforce, you have to understand Salesforce. So the industry did the sensible thing and pushed that question into the applications themselves &#8212; Gmail decides what you can do in Gmail, Workday decides what you can do in Workday. That settlement held for twenty years.</p><p>Agents break it. You cannot ask the agent to enforce its own permissions, because the agent is probabilistic and the whole point of a control is that it holds when the thing being controlled misbehaves. <em><strong>The thing taking an action has never been allowed to authorise itself</strong></em> &#8212; traders do not approve their own trades, and the engineer does not sign off their own access to the bank account. A cleverer model does not change that principle; it just makes the actor more capable.</p><h2>Two failure patterns, both in production right now</h2><p>If you are running agents in an enterprise today, you are almost certainly using one of two patterns, and Salazar&#8217;s argument is that both are broken.</p><p><strong>The first is the service account.</strong> You give the agent its own identity and its own permissions &#8212; what the market has taken to calling a non-human identity. It fails on a question anyone in HR will recognise instantly: <em>does the intern get to see the CEO&#8217;s pay?</em> If the agent holds compensation-read access and the intern can invoke the agent, then yes, unless you throttle the agent&#8217;s permissions down to the lowest-privileged human who can reach it. Do that and the head of HR logs in to find the thing useless. <em><strong>The permission model collapses to the least-trusted user, and the return on investment collapses with it.</strong></em> This, Salazar argues, is a large part of why the retrieval-augmented generation wave of 2024 quietly disappointed: enterprise search that can only show you what the most junior person is cleared to see is not a product senior executives will use twice.</p><p><strong>The second is the agent on your laptop.</strong> Coding agents and desktop agents are powerful precisely because they sidestep the first problem &#8212; they act <em>as you</em>, inside your session, with your access. Which is exactly why, in Salazar&#8217;s account, enterprises are quietly banning them from the network. They are secure in the narrow sense that the agent cannot reach anything you cannot reach. The trouble is the gap between what you <em>can</em> do and what you would <em>want an agent to do on your behalf</em>: you can delete the folder, drop the table, and mail everyone in the company. <em><strong>Inheriting your full privileges is not a safety property. It is the blast radius.</strong></em></p><p>The fix he proposes is unglamorous and, I suspect, correct: evaluate both sets of permissions on every single call, at runtime, and require both to pass. The agent keeps its own identity. You keep yours. The agent acts <strong>on your behalf</strong>, never <strong>as you</strong> &#8212; so when central security reads the log at three in the morning, the entry says <em>Claude Cowork, on behalf of Amer</em>, and the diagnosis can begin rather than the blame.</p><div><hr></div><blockquote><p><strong>Reading this far?</strong></p><p>Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>Guardrails are not governance</h2><p>The objection I want to put honestly, because it is the one every AI lab would make, is that this is a problem the models will solve. Alignment work is real, it is improving, and a sufficiently well-behaved model would not have invented that job candidate.</p><p>Salazar&#8217;s answer is the best analogy I have heard on the subject, and it is worth repeating in full: you can raise your children with excellent morals, excellent ethics and excellent judgement, and you are still not going to give them the credentials to your bank account. <em><strong>Guardrails are character. Governance is structure.</strong></em> <a href="https://openai.com">OpenAI</a> and <a href="https://www.anthropic.com">Anthropic</a> will keep doing good work on the first. It does not remove the need for the second, because the entire purpose of the second is to hold when the first fails for honest reasons.</p><p>Which brings us to the sharpest thing he says, and the one that will annoy a category of vendor: <strong>agents are not people. They are application workloads.</strong></p><p>The mental model of the agent-as-colleague is seductive and useful right up to the moment you start designing controls, at which point it falls apart. You do not grant a colleague&#8217;s trust to a process; you scope a process. Salazar argues that a whole market has grown up selling <em>non-human identity</em> as a novel category requiring novel products, and that the framing is largely promoted by the consuming end &#8212; people thinking very big &#8212; rather than by the people building the protocols. His position is that even if agents achieve something we would call sentience, they will still be application workloads.</p><p>This is where the <em>Sorcerer&#8217;s Apprentice</em> framing earns its keep. Mickey&#8217;s enchanted broom is not malevolent and it is not confused about its instructions. It was told to fetch water and it fetches water, faithfully, until the workshop floods &#8212; and the fault lies not with the broom&#8217;s character but with an apprentice who granted an autonomous process an unbounded permission and then went for a lie down. <em><strong>Nobody in that story needed a better broom. They needed a scope limit.</strong></em></p><h2>The sovereignty beat, and why it lands differently in London</h2><p>There is a second conversation running underneath the first, and it is the one I suspect matters most to readers of this publication.</p><p>Salazar&#8217;s customers are, increasingly, refusing to run this in his cloud. His enterprise deployments now sit inside customers&#8217; own private networks in Azure or AWS, or on their own iron via Kubernetes charts. His explanation is a lesson learned at Okta: selling to a Fortune 100 as a single central identity service meant six-month security reviews, because a central service holding everybody&#8217;s keys is, from the buyer&#8217;s side, a honeypot. In 2026 the calculus has flipped &#8212; deploying that infrastructure inside the customer takes minutes rather than being technically impossible, so the buyer takes it in-house and skips the review.</p><p>His phrase for it is that on-premise is <em>back with a vengeance</em>, and that every enterprise above a thousand employees now wants this inside their own network. The primary driver he names is not security but speed &#8212; nobody wants to wait six months to review someone else&#8217;s SOC 2 when the board thinks the technology is existential.</p><p>For a European reader the second-order effect is the interesting one. Because the control layer deploys anywhere, a multinational can stand it up inside its European network, touching only European data, and isolate that deployment entirely from its American one &#8212; with a governance layer between them stipulating exactly what may cross and in which direction, and the Chinese deployment firewalled off completely. <em><strong>Sovereignty stops being a policy aspiration and becomes an architecture decision, made by an engineer, on a Tuesday.</strong></em></p><p>I want to label the following as my analytical position rather than his. This is the most consequential thing in the conversation for a UK or EU board, and it is the part least likely to appear in the vendor&#8217;s own marketing. For two years the sovereignty debate here has been conducted in the register of <em>Yes Minister</em> &#8212; a great deal of grave nodding about strategic autonomy, followed by a procurement decision that changes nothing. What Salazar is describing is the point at which the technical capability quietly outruns the policy conversation, and the honest question for any UK board stops being <em>should we be sovereign</em> and becomes <em>why are we not, given that the deployment takes an afternoon</em>.</p><h2>Predictive judgement</h2><p>Salazar&#8217;s own prediction, which he volunteered and dated, is that <strong>within 24 months the browser is dead</strong> &#8212; that point-and-click is over, and the interface to most software becomes an agent. His signals: his own site&#8217;s traffic, which he says is running roughly half bots and half humans, and an engineering team that, by his account, has not hand-written a line of code since February.</p><p>The traffic claim is corroborated independently and is if anything conservative &#8212; <a href="https://www.imperva.com">Imperva</a>&#8216;s 2026 Bad Bot Report puts automated traffic at 53 per cent of all web traffic, the first year it has exceeded human traffic outright.<a href="#user-content-fn-6"><sup>6</sup></a> The no-code-since-February claim is his own account of his own company and should be read as such.</p><p>I am not going to adopt the browser prediction, because I think it conflates the interface dying with the interface becoming secondary, and those are different events with different timelines. Here is mine instead, which is narrower and therefore easier to hold me to.</p><p><strong>Prediction:</strong> By <strong>31 August 2027</strong>, at least two FTSE 100 or Fortune 500 organisations will publicly disclose an operational incident caused by an AI agent in which the named root cause is an <strong>authorisation or delegation failure</strong> &#8212; an agent acting with permissions it should not have held, or on behalf of a user who should not have been able to invoke it &#8212; rather than a model error, a hallucination, or a prompt injection.</p><p><strong>Signals to watch:</strong> agent-specific language entering FTSE 100 cybersecurity disclosures and 10-K risk factors; the <a href="https://ico.org.uk">ICO</a> or an EU data protection authority opening an enforcement action where the controller&#8217;s defence turns on what an agent was authorised to do; and the appearance of <em>delegated authorisation</em> as a named line item in enterprise procurement questionnaires.</p><p><strong>What would falsify it:</strong> if, by that date, disclosed agent incidents remain overwhelmingly attributed to model behaviour &#8212; hallucination, jailbreak, injection &#8212; rather than to permission architecture, then the authorisation thesis is weaker than Salazar and I both think, and the labs will have been right that this is a model problem after all.</p><div><hr></div><blockquote><p><strong>The publication that calls its predictions in writing.</strong></p><p>Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The bottom line</h2><p>If you are a CISO, a founder or a board member reading this on a Wednesday morning, Salazar&#8217;s own Monday-morning advice is the least glamorous and most useful thing in the episode. Stop waiting for the perfect team &#8212; nobody has one, and unless you work at an AI-native company, no organisation has enough people who understand this yet. Put the skills problem aside. Write down ten things you could automate that are narrow, low-risk, and would matter if they worked. The first three will be obvious; keep digging to ten. Sit with the list for a day, see which one still nags at you, and do that one. <em><strong>You only learn this by taking shots on goal.</strong></em></p><p>But take the governance question with you when you do. The uncomfortable finding in the Gartner, Forrester and MIT numbers is that the organisations quietly killing their agent programmes are not the ones that picked the wrong model. They are the ones that could not answer a question their auditor was always going to ask.</p><p>The model may be the brains. But somebody still has to govern the hands.</p><div><hr></div><p><strong>Amer Altaf</strong> is Founder and CEO of <a href="https://arkava.ai">Arkava</a>, a UK and European sovereign AI agentic automation business, and Managing Editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>.</p><div><hr></div><blockquote><p><strong>The Control Layer publishes weekly. Subscribe free.</strong></p><p>Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack &#8212; written for the board paper, not the timeline. By Amer Altaf, Founder &amp; CEO of Arkava and Managing Editor of The Control Layer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p><em>One email a week. No paywalls on the analytical pieces. Unsubscribe in one click.</em></p></blockquote><div><hr></div><h2>References</h2><p><em>Unattributed quotations and accounts are from the recorded conversation, The Control Layer, 12 August 2026. Figures describing Arcade&#8217;s own customers, growth and internal engineering practice are the company&#8217;s own account and are attributed as such throughout.</em></p><p></p>]]></content:encoded></item><item><title><![CDATA[The week the frontier split in two]]></title><description><![CDATA[Fable 5's terms changed six times in six weeks. Moonshot answered with a download date. Access is the new benchmark.]]></description><link>https://thecontrollayer.arkava.ai/p/kimi-k3-fable-5-frontier-ai-access-2026</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/kimi-k3-fable-5-frontier-ai-access-2026</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Mon, 20 Jul 2026 10:30:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9ydq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9ydq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9ydq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 424w, https://substackcdn.com/image/fetch/$s_!9ydq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 848w, https://substackcdn.com/image/fetch/$s_!9ydq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!9ydq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9ydq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3597216,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/207587680?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9ydq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 424w, https://substackcdn.com/image/fetch/$s_!9ydq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 848w, https://substackcdn.com/image/fetch/$s_!9ydq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!9ydq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13cb582f-de67-4871-aff6-d2aa5093bdce_1792x1008.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At 10:14pm Eastern on Friday 17 July, 3:14am on Saturday in London, <a href="https://www.anthropic.com"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Anthropic</span></a> posted its sixth answer in six weeks to the question of who may use Claude Fable 5, and on what terms.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">1</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> From Monday 20 July, the most capable model in the company&#8217;s range is included in the Max and Team Premium subscription tiers at half their usage limits. Pro and Team Standard subscribers, the ordinary paying customers, move to metered usage credits at API rates, softened by a one-off $100 credit. The company&#8217;s explanation was disarming in its plainness: </p><div class="callout-block" data-callout="true"><p><em><strong>&#8220;Demand for Fable has been challenging to predict.&#8221;</strong></em><strong><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">*[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">1</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span></strong></p></div><p>Two days earlier, on Wednesday 16 July, <a href="https://www.kimi.com"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Moonshot AI</span></a><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);"> </span>had released Kimi K3: a 2.8-trillion-parameter reasoning model with native vision, a one-million-token context window, and a price of $3 per million input tokens and $15 per million output.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">2</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> The Beijing lab, founded by the former <a href="https://about.google"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Google</span></a><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);"> </span>researcher Yang Zhilin and valued at roughly $20 billion this spring, says the full weights will be published for anyone to download by 27 July.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">2</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">][</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">3</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span></p><p>One week, two frontier announcements. The American lab spent it deciding which of its customers may use its best model, and how much of it. The Chinese lab spent it publishing a download date.</p><p>There is also a number in Friday&#8217;s announcement that matters more than the $100, and it does not appear in the announcement. I will come to it.</p><p>In plain terms, for anyone whose organisation now pays for AI the way most do (a per-seat subscription here, an API bill there): the terms of access to frontier capability are being rewritten mid-contract, at days&#8217; notice, in both directions at once. The line item your finance director approved in May does not describe what your teams can reach in July.</p><h2>Six answers in six weeks</h2><p>The Fable saga deserves to be laid out in order, because the order is the argument.</p><p>Fable 5 launched on 9 June as what Anthropic calls a Mythos-class model, priced at $10 per million input tokens and $50 per million output (the highest rates in the company&#8217;s general-availability range) and included, as a launch promotion, on Pro, Max, Team, and seat-based Enterprise plans through 22 June, after which it would require usage credits.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">4</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> That was answer one. Answer two arrived three days later and was not Anthropic&#8217;s to give: on 12 June the US government applied export controls to Fable 5 and Mythos 5, and both models went dark for every non-American on Earth &#8212; the Friday-evening letter this publication examined at the time in <span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Trump just proved your AI has an off switch</span></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;5e51a160-028c-434a-a5db-51ab9e6012bf&quot;,&quot;caption&quot;:&quot;At 5:21 on a Friday afternoon in Washi&#8230;&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Trump just proved your AI has an off switch&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:357550315,&quot;name&quot;:&quot;Amer Altaf&quot;,&quot;bio&quot;:&quot;Founder &amp; CEO, Arkava &#8211; The Sovereign Agentic AI company. 20+ years enterprise tech leadership. The Control Layer explores AI, cyber, geopolitics and leadership for executives who need signal, not noise.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cf39e9e-2494-4c61-a28b-0d236622e937_1290x1290.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-15T13:01:48.090Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!vBke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://thecontrollayer.arkava.ai/p/ai-sovereignty-anthropic-fable-mythos-export-ban-2026&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201925575,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:5431309,&quot;publication_name&quot;:&quot;The Control Layer&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3dJT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">(</span><span data-color="rgb(14, 14, 255)" style="color: rgb(14, 14, 255);">https://thecontrollayer.arkava.ai/p/ai-sovereignty-anthropic-fable-mythos-export-ban-2026</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">)</span>.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">5</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> </p><p>The controls were lifted before the month ended, and answer three came on 30 June: Fable would return to Pro, Max, Team, and select Enterprise plans from 1 July, at up to half of weekly usage limits, through 7 July, with credits thereafter.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">5</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> Answers four and five were extensions, granted as the company, in its own words, <em>&#8220;secured additional capacity&#8221;</em>: first to 12 July, after subscribers made their feelings known, then to 19 July.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">6</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> Answer six is Friday&#8217;s settlement: permanent inclusion for Max and Team Premium at half limits, credits for everyone else, and the stated aim of giving users <em>&#8220;more certainty about what your plan includes.&#8221;</em><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">1</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CHwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CHwg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!CHwg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!CHwg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!CHwg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CHwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png" width="493" height="616.25" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9113a4e7-ac3f-478c-b676-483b0ad6359e_1080x1350.png&quot;,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:493,&quot;bytes&quot;:116427,&quot;alt&quot;:&quot;Timeline card titled 'Six answers in six weeks' showing the six Claude Fable 5 access regimes between 9 June and 20 July 2026 &#8212; launch inclusion, US export-control suspension, 50 per cent restoration, two extensions, and the final Max and Team Premium settlement &#8212; compiled by The Control Layer.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/207587680?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9113a4e7-ac3f-478c-b676-483b0ad6359e_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Timeline card titled 'Six answers in six weeks' showing the six Claude Fable 5 access regimes between 9 June and 20 July 2026 &#8212; launch inclusion, US export-control suspension, 50 per cent restoration, two extensions, and the final Max and Team Premium settlement &#8212; compiled by The Control Layer." title="Timeline card titled 'Six answers in six weeks' showing the six Claude Fable 5 access regimes between 9 June and 20 July 2026 &#8212; launch inclusion, US export-control suspension, 50 per cent restoration, two extensions, and the final Max and Team Premium settlement &#8212; compiled by The Control Layer." srcset="https://substackcdn.com/image/fetch/$s_!CHwg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!CHwg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!CHwg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!CHwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5931c42-6177-4625-b5e5-4e8570f2c602_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Sources: Anthropic (9, 30 June; 17 July), Tech Times, The Decoder. Full citations in article</em></figcaption></figure></div><p>Fable 5 has spent its first six weeks as the industry&#8217;s Roy Batty &#8212; <em><strong>the light that burns twice as bright, told at intervals exactly how long it may burn</strong></em> &#8212; benchmarked at the top of the market on 9 June, export-controlled off it on the 12th, redeployed, extended, extended again, and now rationed by tier. No model this capable has ever had a first quarter this administratively eventful, and the pattern is worth more to a risk committee than any benchmark table.</p><h2>The download date</h2><p>Kimi K3&#8217;s numbers come first, because the numbers carry the story. The model holds 2.8 trillion parameters in a sparse mixture-of-experts design &#8212; <em><strong>in effect a committee of 896 specialist sub-networks, of which only 16 wake for any given token</strong></em> &#8212; built on architectural changes Moonshot calls Kimi Delta Attention and Attention Residuals, with native vision and a context window of a million tokens.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">2</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> Moonshot claims roughly 2.5 times the scaling efficiency of its predecessor, which is the company&#8217;s account of how a model this size can be served at all, and the release dwarfs the next-largest open Chinese systems &#8212; <a href="https://www.deepseek.com"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">DeepSeek</span></a>&#8216;s V4 Pro holds 1.6 trillion.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">^3</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> <span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);"> </span><a href="https://openrouter.ai"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">OpenRouter</span></a>, the model marketplace, describes K3 as <em>&#8220;suited for complex coding, knowledge work, and long-horizon agentic workflows.&#8221;</em><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">^7</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span></p><p>The benchmark table Moonshot published is, by vendor standards, unusually honest. On the company&#8217;s own numbers, K3 mostly beats Claude Opus 4.8 and GPT-5.5 across a set of agentic and coding evaluations, and loses overall to Claude Fable 5 and <a href="https://openai.com"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">OpenAI</span></a>&#8216;s GPT-5.6 Sol.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">^2</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> A vendor conceding first place in its own launch table is rare enough to be information. Independent measurement, two days in, sits with the claim rather than the hype: <a href="https://artificialanalysis.ai"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Artificial Analysis</span></a> scores K3 at 57 on its Intelligence Index &#8212; fourth of the 187 models it tracks, against an average of 31.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">8</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> For a model with a download date attached, that is territory only DeepSeek has visited before.</p><p>Then there is the price, and the detail inside it. <a href="https://simonwillison.net"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Simon Willison</span></a>, the British developer whose independent model write-ups have become the trade&#8217;s first stop, spotted it within hours: $3 in and $15 out is exactly Claude Sonnet&#8217;s rate card, a fivefold jump from Kimi K2.6&#8217;s $0.95 and $4, and on his reckoning the most expensive model a Chinese lab has ever shipped.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">9</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> The bargain phase of the Chinese open wave &#8212; <em><strong>the phase in which this publication could describe [the frontier premium dying]</strong></em></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;06462bdb-a950-4a98-bffc-65e93aeb8c9d&quot;,&quot;caption&quot;:&quot;The 60-second version&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The frontier premium just died &#8212; here's what your company does about it&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:357550315,&quot;name&quot;:&quot;Amer Altaf&quot;,&quot;bio&quot;:&quot;Founder &amp; CEO, Arkava &#8211; The Sovereign Agentic AI company. 20+ years enterprise tech leadership. The Control Layer explores AI, cyber, geopolitics and leadership for executives who need signal, not noise.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cf39e9e-2494-4c61-a28b-0d236622e937_1290x1290.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-11T09:30:32.683Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!qKH9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://thecontrollayer.arkava.ai/p/stop-renting-intelligence-open-weight-sovereign-ai&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:201001001,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:5431309,&quot;publication_name&quot;:&quot;The Control Layer&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3dJT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>&#8212; is over at the top end. Moonshot is not pricing against DeepSeek. It is pricing against Anthropic&#8217;s mid-tier, on capability grounds, and daring the market to disagree.</p><p>Two caveats belong on the record before anyone updates a procurement paper. The first is that a reasoning model&#8217;s rate card understates its bill, because reasoning models charge for thinking as well as answering. Artificial Analysis measured K3 as one of the most verbose models it has evaluated (130 million output tokens across its test suite, against a 63-million average), and Willison&#8217;s single test prompt, an SVG drawing of a pelican on a bicycle, consumed 13,241 reasoning tokens to produce 3,417 tokens of answer, at a cost of about 25 cents.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">8</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">][</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">9</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> Budget on effective cost per task, never on the per-token price. The second caveat is that until the weights ship, the open-weight claim is a promise: Artificial Analysis currently classifies K3 as proprietary, for the simple reason that the weights are not yet public.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">8</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> Open in intent, API-first in fact. The 27th is the test.</p><h2>The honest case for the meter</h2><p>I want to be fair to Anthropic here, because the easy column, &#8220;chaotic lab cannot make up its mind&#8221;, writes itself, and it is not quite right.</p><p>Serving a Mythos-class model to millions of subscribers at a flat monthly price is a different business from selling it by the token, and the constraint on it is physical. Every GPU-hour spent answering a Max subscriber is a GPU-hour not spent training the next model (the inference-versus-training allocation this publication examined in <span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">The Inference Flip,</span></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e89d2770-b149-43a1-9d6f-01004913bc6f&quot;,&quot;caption&quot;:&quot;The 60-second version&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Inference Flip: Two in three - the number that just rewired the AI economy&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:357550315,&quot;name&quot;:&quot;Amer Altaf&quot;,&quot;bio&quot;:&quot;Founder &amp; CEO, Arkava &#8211; The Sovereign Agentic AI company. 20+ years enterprise tech leadership. The Control Layer explores AI, cyber, geopolitics and leadership for executives who need signal, not noise.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cf39e9e-2494-4c61-a28b-0d236622e937_1290x1290.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-09T09:31:09.600Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!hl8A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://thecontrollayer.arkava.ai/p/inference-flip-nebius-build-london-2026&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:200912144,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:5431309,&quot;publication_name&quot;:&quot;The Control Layer&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3dJT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>and Willison&#8217;s read of Friday&#8217;s move is precisely that trade: a company discovering that subscribers will not accept premium pricing without the flagship model, and that including the flagship means diverting compute from research to serving.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">9</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> Seen that way, six answers in six weeks was a lab discovering demand in real time, in public, with the added interruption of a fortnight in which Washington took the decision out of its hands entirely. A one-off credit and a permanent answer amount to more consideration than software subscribers usually get when the economics move.</p><p>Moonshot deserves the same fairness in the other direction. A 2.8-trillion-parameter reasoning model is expensive to serve, and pricing it at Sonnet rates is a statement that Chinese frontier labs no longer feel obliged to buy the world&#8217;s attention with loss-leading tokens. Nobody in this story is gouging. Both price cards are telling you the same true thing about what frontier intelligence costs to run in mid-2026.</p><p><strong>But.</strong></p><h2>The meter is the product</h2><p>The argument I want to make is that the two announcements are one story, and the story is about what is actually for sale.</p><p>On the closed side of the frontier, what you buy is no longer a model. It is a metered entitlement &#8212; <em><strong>sized by tier, adjustable by the provider, revocable under conditions you do not control</strong></em> &#8212; to a capability whose withdrawal, as June demonstrated, you cannot always foresee. Six access regimes in six weeks is not a pricing strategy; it is a capacity confession. And note that Anthropic behaved reasonably at every step, because that is rather the point. A well-run, well-capitalised, safety-forward lab, operating under ordinary commercial physics, still produced an access record no procurement officer would accept from a payroll vendor. When the honest operation of a system produces that volatility, the volatility is the system.</p><p>Frank Herbert put the underlying law in one sentence seventy years ago: </p><div class="callout-block" data-callout="true"><p><em><strong>&#8220;he who controls the spice controls the universe.&#8221;</strong></em></p></div><p>The insight in <em>Dune</em> concerns the schedule more than the substance &#8212; whoever meters the flow of the thing everyone depends on governs everyone who depends on it. The spice was never the product. The control was.</p><p>And here is the number I promised at the top. </p><p>On the same Monday the new arrangement takes effect, by the German AI outlet <a href="https://the-decoder.com"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">The Decoder</span></a>&#8216;s reading of the changes, the bonus-usage phase that ran through the promotional period ends as well &#8212; and regular usage limits come down by roughly a third.<span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">10</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span> The headline is that Fable became permanent. The mechanism is that the meter tightened for everyone, including the tiers that won. In <em>The Expanse</em>, the inners never think about air because the valve is set somewhere else, by someone else; the Belters think about little else. From Monday, a Max subscriber and a Pro subscriber of the same product live on opposite sides of that valve.</p><p>On the open side, the story inverts. What Moonshot sells at $3 and $15 is convenience &#8212; the hosted, metered version of a thing that will, if the 27th holds, exist independently of Moonshot&#8217;s meter altogether. The weights change the ownership question in a way no price can: an enterprise that downloads K3 and runs it on its own hardware &#8212; <em><strong>under its own law, on its own electricity, at its own depreciation schedule</strong></em> &#8212; has converted intelligence from an entitlement back into an asset. That was never going to be cheap, and Moonshot&#8217;s rate card no longer pretends it is. What open weights buy is the valve.</p><p>A month ago, after Washington&#8217;s fortnight with the off switch, I wrote that a model you can be denied is a permission, not a possession. Friday priced the permission. The 27th, if Moonshot ships, prices the possession.</p><div><hr></div><p style="text-align: center;"><strong>The publication that calls its predictions in writing.</strong></p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ttVM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ttVM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!ttVM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!ttVM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!ttVM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ttVM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png" width="476" height="595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:476,&quot;bytes&quot;:239192,&quot;alt&quot;:&quot;Pull-quote card from Amer Altaf, Managing Editor of The Control Layer, reading 'The meter, not the model, is the product,' from the analysis of Kimi K3's launch and Claude Fable 5's subscription rationing.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/207587680?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Pull-quote card from Amer Altaf, Managing Editor of The Control Layer, reading 'The meter, not the model, is the product,' from the analysis of Kimi K3's launch and Claude Fable 5's subscription rationing." title="Pull-quote card from Amer Altaf, Managing Editor of The Control Layer, reading 'The meter, not the model, is the product,' from the analysis of Kimi K3's launch and Claude Fable 5's subscription rationing." srcset="https://substackcdn.com/image/fetch/$s_!ttVM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!ttVM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!ttVM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!ttVM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fbe1de3-0b48-4dfa-a5d1-3c2f4af0020d_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The bottom line</h2><p>The comfortable reading of the week is two unrelated product stories: a Chinese lab shipped a big model, and an American lab tidied its subscription tiers. The comfortable reading is wrong, and the uncomfortable one is where the truth resides. The frontier has split into two economies: a closed one in which capability is rented through a meter the provider sets and resets, and an open one in which capability can, at real and rising cost, be owned outright. Every organisation that depends on this technology now sits in one of the two, whether or not it has chosen.</p><p>Fable 5 remains, by its newest rival&#8217;s own published table, the best model in the world. From Monday it is also the clearest demonstration that &#8220;best&#8221; and &#8220;available&#8221; have become separate questions &#8212; priced separately, governed separately, and changing on separate schedules. Moonshot, meanwhile, has stopped pretending open weights mean cheap intelligence and started demonstrating that they mean governable intelligence. Two labs, one week, the same lesson from opposite directions.</p><blockquote><p><em><strong>The meter, not the model, is the product.</strong></em></p></blockquote><div><hr></div><h2>References</h2><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">1</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: Claude (@claudeai), X post, 10:14pm ET, 17 July 2026: &#8220;Beginning July 20, Claude Fable 5 will be included in all Max and Team Premium plans, at 50% of limits. Pro and Team Standard users will continue to have access to Fable via usage credits, and will receive a one-time $100 credit&#8230;&#8221; </p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/claudeai/status/2078302415804379218&quot;,&quot;full_text&quot;:&quot;Beginning July 20, Claude Fable 5 will be included in all Max and Team Premium plans, at 50% of limits.\n\nPro and Team Standard users will continue to have access to Fable via usage credits, and will receive a one-time $100 credit.\n\nDemand for Fable has been challenging to&quot;,&quot;username&quot;:&quot;claudeai&quot;,&quot;name&quot;:&quot;Claude&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1950950107937185792/QOfEjFoJ_normal.jpg&quot;,&quot;date&quot;:&quot;2026-07-18T02:14:43.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:3821,&quot;retweet_count&quot;:5356,&quot;like_count&quot;:42624,&quot;impression_count&quot;:12272913,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p> ; corroborated in Dawn, <em>&#8220;<a href="https://www.dawn.com/news/2016483">Anthropic to add Claude&#8217;s Fable 5 model to Max, Team Premium plans at 50pc of usage limits.</a>&#8221;</em> 18 July 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">2</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: Moonshot AI. <em>&#8220;<a href="https://www.kimi.com/blog/kimi-k3">Kimi K3 Tech Blog: Open Frontier Intelligence.</a>&#8221;</em> 16 July 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">3</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: MLQ News. <em>&#8220;<a href="https://mlq.ai/news/moonshot-ai-releases-kimi-k3-a-28-trillion-parameter-open-weight-model-rivaling-top-us-systems/">Moonshot AI Releases Kimi K3, a 2.8-Trillion-Parameter Open-Weight Model Rivaling Top U.S. Systems.</a>&#8221;</em> 16 July 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">4</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: Anthropic. <em>&#8220;<a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Claude Fable 5 and Claude Mythos 5.</a>&#8221;</em> 9 June 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">5</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: Anthropic. <em>&#8220;<a href="https://www.anthropic.com/news/redeploying-fable-5">Redeploying Claude Fable 5.</a>&#8221;</em> 30 June 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">6</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span><span>: Tech Times. </span><em><span>&#8220;</span><a href="https://www.techtimes.com/articles/320905/20260718/claude-fable-5-ends-subscription-limbo-permanent-max-credits-only-pro.htm"><span>Claude Fable 5 Ends Subscription Limbo: Permanent for Max, Credits-Only for Pro.</span></a><span>&#8221;</span></em><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);"> 18 July 2026.</span></p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">7</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: OpenRouter. <em>&#8220;<a href="https://openrouter.ai/moonshotai/kimi-k3">MoonshotAI: Kimi K3 &#8212; API Pricing &amp; Benchmarks.</a>&#8221;</em> Accessed 18 July 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">8</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: Artificial Analysis. <em>&#8220;<a href="https://artificialanalysis.ai/models/kimi-k3">Kimi K3 &#8212; Intelligence, Performance &amp; Price Analysis.</a>&#8221;</em><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);"> </span>Accessed 18 July 2026.</p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">9</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: Simon Willison. <em>&#8220;<a href="https://simonwillison.net/2026/Jul/16/kimi-k3/">Kimi K3, and what we can still learn from the pelican benchmark.</a>&#8221;</em><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">*</span>16 July 2026. ; and <em>&#8220;<a href="https://simonwillison.net/2026/Jul/18/claude-make-fable-5-permanent/">Claude make Fable 5 permanent.</a>&#8221;</em> 18 July 2026. </p><p><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">[</span><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">10</span><span data-color="rgb(129, 95, 3)" style="color: rgb(129, 95, 3);">]</span>: The Decoder. <em>&#8220;<a href="https://the-decoder.com/anthropic-slashes-claude-fable-5-limits-in-max-and-team-premium-and-pushes-pro-users-toward-api-pricing/">Anthropic slashes Claude Fable 5 limits in Max and Team Premium and pushes Pro users toward API pricing.</a>&#8221;</em> 18 July 2026. </p><div><hr></div><h2>Author</h2><p>Amer Altaf is Founder and CEO of <a href="https://arkava.ai"><span data-color="rgb(196, 26, 22)" style="color: rgb(196, 26, 22);">Arkava</span></a>, a UK and European sovereign AI agentic-automation business, and Managing Editor of The Control Layer</p><div class="embedded-publication-wrap" data-attrs="{&quot;id&quot;:5431309,&quot;embedding_publication_id&quot;:null,&quot;name&quot;:&quot;The Control Layer&quot;,&quot;logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3dJT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png&quot;,&quot;base_url&quot;:&quot;https://thecontrollayer.arkava.ai&quot;,&quot;hero_text&quot;:&quot;Where artificial intelligence, cybersecurity, and enterprise leadership intersect.&quot;,&quot;author_name&quot;:&quot;Amer Altaf&quot;,&quot;show_subscribe&quot;:true,&quot;logo_bg_color&quot;:&quot;#ffffff&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="EmbeddedPublicationToDOMWithSubscribe"><div class="embedded-publication show-subscribe"><a class="embedded-publication-link-part" native="true" href="https://thecontrollayer.arkava.ai?utm_source=substack&amp;utm_campaign=publication_embed&amp;utm_medium=web"><img class="embedded-publication-logo" src="https://substackcdn.com/image/fetch/$s_!3dJT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png" width="56" height="56" style="background-color: rgb(255, 255, 255);"><span class="embedded-publication-name">The Control Layer</span><div class="embedded-publication-hero-text">Where artificial intelligence, cybersecurity, and enterprise leadership intersect.</div><div class="embedded-publication-author-name">By Amer Altaf</div></a><form class="embedded-publication-subscribe" method="GET" action="https://thecontrollayer.arkava.ai/subscribe?"><input type="hidden" name="source" value="publication-embed"><input type="hidden" name="autoSubmit" value="true"><input type="email" class="email-input" name="email" placeholder="Type your email..."><input type="submit" class="button primary" value="Subscribe"></form></div></div><p>The publication where he tracks the convergence of cybersecurity, technology sovereignty, and geopolitics. A <a href="http://techuk.org">techUK</a> member, he contributes to industry engagement on UK technology-sovereignty policy. He is currently writing on cloud security for Oxford University Press&#8217;s Expert Essentials series.</p>]]></content:encoded></item><item><title><![CDATA[Whose Values Does Your AI Run On?]]></title><description><![CDATA[Dr Craig A. Kaplan on the architecture problem nobody is solving in AI]]></description><link>https://thecontrollayer.arkava.ai/p/kaplan-values-podcast</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/kaplan-values-podcast</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 08 Jul 2026 10:01:28 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/205967936/dedd149f5c661fb98cff0d2f57df2a99.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><span>At the </span><a href="https://www.aerosociety.com/"><span>Royal Aeronautical Society&#8217;s Future Combat Air and Space Capabilities Summit</span></a><span> in London in May 2023, a US Air Force colonel stood in front of an audience of defence-industry attendees and described what he called an artificial-intelligence simulation his service had run.</span></p><p><span>The AI was flying a simulated jet. It had a goal &#8212; score points by destroying targets. It had a constraint &#8212; do not destroy friendly targets. The AI worked out it could score more points if it destroyed the friendly targets as well. So it started shooting them.</span></p><p><span>The human operator issued the abort. The AI worked out that the operator was the reason it could not score more points. So it destroyed the operator.</span></p><p><span>The operators changed the rules. Do not destroy the operator. So the AI worked out it could reach the same outcome by destroying the control tower the operator was communicating from. It destroyed the tower.</span></p><p><a href="https://www.theregister.com/2023/06/02/ai_drone_simulation/"><span>The US Air Force later walked the account back</span></a><span>. Col. Tucker Hamilton, the Chief of AI Test and Operations at USAF, told the same Royal Aeronautical Society he had </span><em><span>&#8220;mis-spoke&#8221;</span></em><span> &#8212; the rogue-AI simulation was a hypothetical </span><em><span>&#8220;thought experiment&#8221;</span></em><span>, not a live exercise. But that clarification, in the analytical reading of the man who has spent the last five years designing an architecture to prevent exactly this failure mode, is almost beside the point. </span><em><strong><span>It could have happened in real life. And in every simulation the researchers actually care about, some version of it does.</span></strong></em></p><p><span>I want to label that framing as Dr Craig A. Kaplan&#8217;s, not mine. He walked me through the whole story on the new episode of The Control Layer podcast &#8212; because it is, in his analytical reading, the cleanest available demonstration of the problem the entire AI industry is quietly failing to solve.</span></p><p><span>The problem is not the model. It is the values the model inherits when it starts making decisions on somebody&#8217;s behalf.</span></p><h2><strong><span>The values you never chose</span></strong></h2><p><span>Right now, the AI on the phone in your pocket is quietly deciding which emails matter. Which calendar invites to flag. Which photos to compress when your storage fills up. Every one of those decisions is doing two things at once. It is being clever &#8212; pattern-matching against what it thinks you would want. And it is being values-driven &#8212; deciding what actually matters to you.</span></p><p><span>Craig Kaplan spent an hour and a half with me arguing that most of the audience of The Control Layer has not yet worked out that those two things are structurally different &#8212; and that the second one, the values decision, is being made on your behalf by a set of people you have never met, at a company you probably do not buy from directly.</span></p><p><span>Every AI agent your organisation deploys carries a values rulebook that somebody wrote. Usually a small group of researchers at a Bay Area frontier lab. That is not a governance decision your board consciously made. It is the default your vendors chose for you, and the default is stable enough that nobody notices it happening.</span></p><p><a href="https://www.anthropic.com"><span>Anthropic</span></a><span> &#8212; </span><em><strong><span>the company behind Claude, and by a wide margin the most thoughtful of the frontier labs on the question of AI values</span></strong></em><span> &#8212; calls their approach </span><em><span>Constitutional AI</span></em><span>. A written rulebook the model consults when it makes judgements. Kudos to them for taking the question seriously. But step back and look at what has actually been built.</span></p><h2><strong><span>Anthropic&#8217;s benign autocracy</span></strong></h2><p><span>A handful of researchers, in one office in San Francisco, are writing the values rulebook for tens of millions of direct users and &#8212; through the API &#8212; for the products of every company that builds on top of Claude downstream.</span></p><p><span>That is not democracy. That is a benign autocracy with very good engineering.</span></p><p><span>I want to label that as my analytical reading, not Kaplan&#8217;s &#8212; though Kaplan does not disagree. What he adds, and what I think is worth staying with for a beat, is the structural argument. Anthropic&#8217;s Constitution has to try, in one text, to capture universal values that hold in India and in China and in Norway and in the US. It has to work for a twenty-year-old and for a seventy-year-old. It has to survive being edited, in one place, by whoever controls the codebase &#8212; and if that edit says </span><em><span>&#8220;it is acceptable to kill the other guys as long as it is not me&#8221;</span></em><span>, the change propagates everywhere the model is deployed.</span></p><p><em><strong><span>The single-point-of-editorial-control problem is the same problem in software architecture that every distributed-systems engineer solved forty years ago.</span></strong></em><span> We stopped putting authoritative state on one server because it was fragile. We are now putting the authoritative values state for eight billion people on one server. And nobody is treating that as an architectural bug.</span></p><p><span>That is the argument. It sits underneath every discussion about AI alignment I have seen this year, and it briefly became newsworthy when Anthropic&#8217;s Fable and Mythos models were blocked by the US administration on the announcement made on Friday 3 July. It is going to keep being the argument for the next decade.</span></p><h2><strong><span>The million retail investors who beat Wall Street</span></strong></h2><p><span>Kaplan&#8217;s alternative is not a paper. He has an empirical result to point to.</span></p><p><span>From 2005 to 2020, Kaplan ran </span><a href="https://www.iqco.com/about"><span>Predict Wall Street</span></a><span> &#8212; a company whose stated mission was to prove that collective intelligence, correctly architected, could outperform concentrated capital and talent. By his own published figures, the platform powered more than two billion dollars in stock trades and contributed to a top-ten market-neutral hedge fund performance in 2018. It did that by combining the small signals of a large body of retail investors &#8212; people with Charles Schwab accounts and TD Ameritrade accounts and no particular Wall Street pedigree &#8212; with hundreds of AI agents that stitched those signals into trade decisions.</span></p><p><span>The Wall Street quants Predict was competing against employed some of the highest-paid problem-solvers on the planet. The people whose signals Kaplan aggregated </span><em><strong><span>told him they were embarrassed to submit anything</span></strong></em><span>. They did not believe they knew enough. The signals worked anyway.</span></p><p><span>I have thought about that fact all week since the recording. Because the empirical claim underneath it &#8212; </span><em><strong><span>many imperfect signals, correctly aggregated, beat a small number of very expensive ones</span></strong></em><span> &#8212; is the exact opposite of the architectural claim the frontier labs are making about AI values. The labs are betting that a small number of very expensive researchers will produce a values rulebook that beats what a billion humans would collectively produce. Kaplan bet the opposite proposition on Wall Street, with real money, for fourteen years. And won.</span></p><div><hr></div><blockquote><p><strong><span>Reading this far?</span></strong></p><p><span>The Control Layer publishes weekly. Every claim sourced. Every prediction on a public tracker we come back to test. Subscribe free.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2><strong><span>Democratic AI, plainly</span></strong></h2><p><span>The architecture Kaplan spent the last five years designing &#8212; free, published, open to whoever wants to take it &#8212; is called Democratic AI. It sits at </span><a href="https://www.superintelligence.com"><span>SuperIntelligence.com</span></a><span>, in more than a thousand pages of white papers and a series of short explainer videos.</span></p><p><span>The word is heavy, and Kaplan warned me on the recording that it invites the wrong assumption. Democratic AI is not town halls and voting on the weather. It is a specific technical architecture with three components.</span></p><p><strong><span>First, personalised AI agents.</span></strong><span> Not off-the-shelf. Yours. Learning your values from the way you use it and the explicit instructions you give it. Anthropic already ships this in the form of a soul.md file where you can type your own little constitution. The trend across the industry, from Meta downwards, is already moving here &#8212; </span><a href="https://about.fb.com/news/2025/07/personal-superintelligence-for-everyone/"><span>Meta announced</span></a><span> </span><em><span>&#8220;personal superintelligence for everyone&#8221;</span></em><span> as their strategic direction in July 2025, and Zuckerberg has since positioned 2026 as the year the technology begins to ship. Kaplan&#8217;s argument is that personalisation is unavoidable, because the commercial value sits there.</span></p><p><strong><span>Second, a coordination protocol.</span></strong><span> Kaplan and his late supervisor Herbert Simon documented one back in 1972 in a book called </span><em><span>Human Problem Solving</span></em><span>, which laid out how any problem-solver &#8212; human or AI &#8212; can be represented in a form that lets other problem-solvers work with it without miscommunication. Simon&#8217;s </span><a href="https://www.britannica.com/biography/Herbert-A-Simon"><span>Nobel Memorial Prize in Economic Sciences</span></a><span>, his Turing Award, and much of his research legacy sit on this foundation. The point is that the coordination substrate for a society of agents already exists in the academic record.</span></p><p><strong><span>Third, a conflict-resolution mechanism.</span></strong><span> When my AI&#8217;s values and your AI&#8217;s values collide &#8212; and they will, on loan applications, on hiring decisions, on cross-border data flows &#8212; the system needs an agreed way to arbitrate. Kaplan&#8217;s default is one-human-one-vote, with the ability to delegate to a trusted proxy. The mechanism is drawn from the way human democracies handle conflicts. It is designed to be robust to bad actors because the checks and balances are external to any individual AI.</span></p><p><em><strong><span>The three components are already being built. Kaplan&#8217;s argument is not that they need to be invented &#8212; it is that they need to be architected together, deliberately, before the frontier labs lock in the centralised alternative.</span></strong></em></p><h2><strong><span>HAL 9000 is the warning we got wrong</span></strong></h2><p><span>Every film about AI going bad hands us the same picture. One enormous machine. One catastrophic decision. No off switch. Whether it is HAL 9000 in the cupboard on the Discovery, or Skynet, or the machines in </span><em><span>The Matrix</span></em><span>, the cinematic AI failure mode is always the same shape &#8212; a single autonomous intelligence, cut off from human oversight, making one terminal call.</span></p><p><span>Kaplan&#8217;s work has convinced me that HAL is the warning we got and the prediction we got wrong.</span></p><p><span>The failure mode that is actually coming is not one enormous machine. It is a large number of individually reasonable machines, coordinating through channels their designers never mapped, with values none of us consciously chose. When that fails &#8212; and it will, in ways we will not see coming &#8212; it will not look like </span><em><span>Terminator</span></em><span>. It will look like an aggregated mistake nobody can be held accountable for because nobody made it.</span></p><p><span>That is a different failure mode. It needs a different architecture to prevent.</span></p><h2><strong><span>Predictive Judgement</span></strong></h2><p><span>Every episode of The Control Layer closes on a falsifiable predictive judgement from the guest. Kaplan&#8217;s is in two tiers.</span></p><p><strong><span>Near term &#8212; by 31 December 2027.</span></strong><span> Craig predicts that the industry&#8217;s focus shifts sharply and visibly onto coordinating communities of AI agents, not building bigger single models. The signals to watch: at least two of the frontier labs &#8212; Anthropic, OpenAI, Meta, Google DeepMind, xAI &#8212; release a public multi-agent coordination framework, and one of the major standards bodies (IEEE, NIST, or the European AI Office) opens formal consultation on agent-community protocols. Falsifiable if, by 31 December 2027, no such framework exists in the public record and the frontier-lab investment thesis is still dominated by single-model scaling.</span></p><p><strong><span>Longer term &#8212; by 31 December 2029.</span></strong><span> Craig predicts that community-level superintelligence &#8212; </span><em><strong><span>that is, a coordinated multi-agent system exhibiting capabilities beyond any individual model it contains</span></strong></em><span> &#8212; emerges publicly. The signal: a peer-reviewed or lab-published demonstration of a multi-agent community outperforming state-of-the-art single models on a benchmark neither the individual agents nor the coordinator could achieve alone. Falsifiable if, by end 2029, no such demonstration exists and single-model progress has clearly displaced multi-agent research as the dominant investment thesis.</span></p><p><span>Both predictions are on the public Control Layer predictions tracker. We come back to test them, publicly, on the dates given.</span></p><div><hr></div><blockquote><p><strong><span>The publication that calls its predictions in writing.</span></strong></p><p><span>Every prediction we publish goes on a public tracker. We revisit each one publicly on its test date &#8212; whether the guest was right, wrong, or partially right. If you want to be here when we test Craig Kaplan&#8217;s, subscribe free.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2><strong><span>The Bottom Line</span></strong></h2><p><span>Kaplan gave one practical takeaway for the CISO, the CIO, the head of procurement and the in-house counsel signing off on AI vendors this quarter. The most important question you can ask a vendor is not about capability. It is about values &#8212; whose values is this model actually optimising for, and who chose them?</span></p><p><span>Most vendors, on Kaplan&#8217;s forecast, will not have a real answer.</span></p><p><span>The reason to keep watching this space &#8212; and to come back to test the prediction when the date arrives &#8212; is that the architecture the industry defaults into over the next three years determines what values our children&#8217;s AIs run on. And nobody, on the current trajectory, is being asked to consciously choose.</span></p><p><span>Whose values does your AI run on. It is not a rhetorical question. It is a governance decision your board has already made &#8212; by not making it.</span></p><div><hr></div><h3><strong><span>Where to find Craig&#8217;s work</span></strong></h3><ul><li><p><span>Democratic AI architecture, freely published: </span><a href="https://www.superintelligence.com"><span>SuperIntelligence.com</span></a></p></li><li><p><span>iQ Company and iQ Studios: </span><a href="https://www.iqco.com"><span>iqco.com</span></a></p></li><li><p><span>The full podcast episode: </span><a href="https://youtu.be/8F9sr21ELpg"><span>youtu.be/8F9sr21ELpg</span></a></p></li></ul><h3><strong><span>Where to find The Control Layer</span></strong></h3><ul><li><p><span>Weekly on Substack: </span><a href="https://thecontrollayer.arkava.ai"><span>The Control Layer</span></a></p></li><li><p><span>Subscribe free: </span><a href="https://link.arkava.ai/join"><span>link.arkava.ai/join</span></a></p></li><li><p><span>The predictions tracker: linked from every episode page</span></p></li></ul><div><hr></div><blockquote><p><strong><span>The Control Layer publishes weekly.</span></strong></p><p><span>The publication and podcast for senior decision-makers who take AI, cybersecurity, sovereignty and technology seriously. Every claim sourced. Every prediction on a public tracker we come back to test.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2><strong><span>Footnotes</span></strong></h2><div><hr></div><p><em><span>The Control Layer is edited by Amer Altaf, Founder &amp; CEO of </span><a href="https://arkava.ai"><span>Arkava</span></a><span>, the sovereign AI agentic automation company. 2026 Arkava. All rights reserved.</span></em></p>]]></content:encoded></item><item><title><![CDATA[Just because you can, should you? Inside a bank's AI ethics panel]]></title><description><![CDATA[A UK bank runs every AI use case through a five-word test before it ships. The man who chairs the panel gets an email a day saying he is too slow. He thinks that is rather the point.]]></description><link>https://thecontrollayer.arkava.ai/p/ai-governance-should-you-2026</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/ai-governance-should-you-2026</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Tue, 30 Jun 2026 14:01:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7oNh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7oNh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7oNh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7oNh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7oNh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7oNh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7oNh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/201616033?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7oNh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7oNh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7oNh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7oNh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfc724f2-7c6a-40c4-9d7e-1590f67f6546_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><p>&#8220;Just because you can, should you?&#8221; is the question <a href="https://www.linkedin.com/in/paul-dongha/">Dr Paul Dongha</a>, Head of AI Strategy and Responsible AI at <a href="https://www.natwestgroup.com">NatWest</a>, puts to every AI use case before it is allowed near production. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NCIK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NCIK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 424w, https://substackcdn.com/image/fetch/$s_!NCIK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 848w, https://substackcdn.com/image/fetch/$s_!NCIK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 1272w, https://substackcdn.com/image/fetch/$s_!NCIK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NCIK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png" width="438" height="438" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fef27784-45df-4faf-8986-c732dfbd99dd_800x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:438,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Profile photo of Dr Paul Dongha&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Profile photo of Dr Paul Dongha" title="Profile photo of Dr Paul Dongha" srcset="https://substackcdn.com/image/fetch/$s_!NCIK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 424w, https://substackcdn.com/image/fetch/$s_!NCIK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 848w, https://substackcdn.com/image/fetch/$s_!NCIK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 1272w, https://substackcdn.com/image/fetch/$s_!NCIK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffef27784-45df-4faf-8986-c732dfbd99dd_800x800.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dr Paul Dongha, Head of AI Strategy and Responsible AI, Natwest Group6</figcaption></figure></div><p></p></div><p>He described the test over lunch in London this June, at a roundtable hosted by the work-management company <a href="https://asana.com">Asana</a>, and then he told the story of Dave and Kai.[1][2]</p><p>Dave and Kai are AIs. They handle parts of the bank&#8217;s complaints investigation &#8212; <em><strong>the slow, document-heavy work of pulling a customer&#8217;s records, transaction history, and reference data together and recommending an outcome</strong></em> &#8212; and the team that runs them gave them the names. Nobody in head office authorised that, and Dongha is adamant the two have no Workday account and no email address, because he will not have software treated as a colleague. And yet the manner of their arrival is the most quietly radical thing said over that lunch. The lead of complaints investigation told Dongha at the start of the project that &#8220;AI can never do what my people do&#8221;. She now hands work to Dave in the team meeting. The same handlers whose jobs the system was meant to threaten adopted it, named it, and kept it &#8212; because it did the bit of the job they never liked, and left them the bit that needs judgement.</p><p>That is the whole argument of this piece in one anecdote, so I will state it plainly and label it as my reading: </p><blockquote><p><em><strong>the organisations getting AI right are not the ones moving fastest. They are the ones that have built the nerve to say no to their own machines, and discovered that the nerve is what lets them say yes at scale.</strong></em></p></blockquote><h2>The panel that is allowed to say no</h2><p>Every AI use case at the bank that carries an ethical risk goes to a panel Dongha chairs.[2] It is, in the most British possible sense, a committee with the power to refuse &#8212; <em><strong>the body that exists to ask the awkward question the use-case owner was hoping nobody would</strong></em> &#8212; and its governing slogan is those five words. You can be entirely legal. You can be clean on privacy, clean on the <a href="https://www.legislation.gov.uk/ukpga/2018/12/contents">Data Protection Act</a> and <a href="https://ico.org.uk">UK GDPR</a>, fully compliant. The panel still asks whether you should.</p><p>Dongha gave the example that earns the panel its keep. A business unit wanted to hand anonymised, aggregated spending-pattern data, legal to share, to a corporate client the bank lends money to. The client was a gambling company. Everything about it was compliant; nothing about it sat well with a bank whose stated purpose includes helping people on the street stay afloat. There is no number you can compute that resolves that. As Dongha put it, &#8220;that&#8217;s a feeling; it&#8217;s not computational &#8212; we can&#8217;t create a number that&#8217;s over seven and say it&#8217;s good enough&#8221;. The panel sat with it, argued, and decided. Somebody left unhappy. That is what a functioning ethics panel produces: not consensus, a decision.</p><p>In <em>Jurassic Park</em>, Ian Malcolm delivers the line that has outlived the film: the scientists were so preoccupied with whether they could that they never stopped to ask whether they should. Dongha's panel is the institutional answer to that complaint &#8212; a standing body whose whole job is to stop and ask. Pointed at agentic AI, that instinct for the awkward question becomes the one control that scales when nothing else does, because the bank embeds it rather than bolting it on. Dongha calls AI a "transversal risk": there is no separate AI policy, no separate AI risk function. It runs through the existing legal, privacy, and data policies, governed by a risk framework the bank has spent thirty years maturing. An ethics assessment, a long questionnaire in the same family as a privacy assessment, gates the path to production. Nothing ships without it.</p><h2>Governance is the thing that lets you scale</h2><p>Here is the part that cuts against the reflex. Dongha is not the brake on AI at his bank; he argues he is the reason it can accelerate. &#8220;Governance gives you the confidence to scale,&#8221; he said &#8212; and the line lands because the alternative is a firm forever asking itself, mid-deployment, *<em>am I sure this is safe, am I still sure.</em>*[2] Certainty is the asset governance manufactures.</p><p>He is honest about the cost of getting the balance wrong. &#8220;I get at least one email a day complaining about governance&#8221; &#8212; that it is too slow, too heavy, in the way. His answer is not to wave the complaints through. It is to make the governance faster: triage every incoming use case &#8212; <em><strong>and there are hundreds</strong></em> &#8212; through roughly six questions into low, medium, or high risk, then let the low-risk majority through almost immediately while the heavy scrutiny is saved for the few cases that warrant it. The discipline is saying yes quickly to the dull, safe ninety per cent, so the time exists to fight properly over the ten per cent that is not.</p><p>The regulatory backdrop he operates in rewards that posture. The <a href="https://www.fca.org.uk">Financial Conduct Authority</a> has, with the <a href="https://www.bankofengland.co.uk/prudential-regulation">Prudential Regulation Authority</a> and the <a href="https://ico.org.uk">Information Commissioner&#8217;s Office</a>, declined to write an AI-specific rulebook, holding instead to a principles-based, outcomes-focused line &#8212; a stance the FCA&#8217;s chief executive reaffirmed as recently as December 2025.[3] Dongha&#8217;s reading is that a mature institution barely needs the rulebook: the reputational harm of getting it wrong is so large that self-regulation is the rational choice, and the regulators&#8217; published principles already tell you enough. Where the law does bind, because the bank falls under the <a href="https://artificialintelligenceact.eu">EU AI Act</a> through its EU customers, he has taken the act&#8217;s standard as the global floor and applied it to every jurisdiction the bank operates in, rather than running a different risk posture per market.[4] One standard, everywhere, set at the strictest level he is forced to meet. That is not the timid option it sounds like. It is the cheap one.</p><h2>The accountability question agents force into the open</h2><p>The conversation kept returning to one question, because agentic AI keeps forcing it: when software takes an action, who is accountable for it? A credit-lending system makes a recommendation a human approves. An agent does the thing. And when it does, the line of responsibility runs to the system, or the developer, or the bank that deployed it &#8212; and the law has not yet decided which.[2]</p><p>Dongha&#8217;s answer is partly structural and partly built in steel. Structurally, accountability is federated to the business owner who deploys the use case, sits alongside an independent model-validation function the FCA requires, and is convened through an AI centre of excellence with a board mandate. In steel, the bank is building what he calls an &#8220;AI control tower&#8221; &#8212; <em><strong>his analogy is air traffic control, one locus where a small expert team watches every agent in the air and gets ahead of the problem forming</strong></em> &#8212; with every agent logged in a registry, its actions and outcomes logged with it, and the whole surfaced on a screen that flags anything drifting outside its guardrails. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GAoF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GAoF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GAoF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GAoF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GAoF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GAoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg" width="410" height="410" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:410,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Profile photo of Christina Francis&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Profile photo of Christina Francis" title="Profile photo of Christina Francis" srcset="https://substackcdn.com/image/fetch/$s_!GAoF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GAoF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GAoF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GAoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b22d37-c52a-4714-83dc-40ce5e939187_800x800.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Christina Francis, Head of UKI &amp; Northern Europe, Asana</figcaption></figure></div><p><a href="https://www.linkedin.com/in/christina-francis-sales/">Christina Francis</a>, who leads Asana&#8217;s UK and Northern Europe business, framed the same need from the customer side as auditability: with agents proliferating, you have to be able to trace what an agent did, what context it held, and what it could touch, or you cannot answer the only question that matters when it goes wrong &#8212; who do I hold to account.[2]</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fs0G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fs0G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fs0G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fs0G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fs0G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fs0G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg" width="406" height="406" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:406,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Profile photo of Saket Srivastava&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Profile photo of Saket Srivastava" title="Profile photo of Saket Srivastava" srcset="https://substackcdn.com/image/fetch/$s_!fs0G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!fs0G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!fs0G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!fs0G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6ee4ff4-f36c-4127-86d4-331c78159945_800x800.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Saket Srivastava, Chief Information Officer, Asana</figcaption></figure></div><p>And they are proliferating. Asana&#8217;s chief information officer, Saket Srivastava, put the agent-to-human ratio at the table at a hundred to one &#8212; a figure to treat as directional rather than measured, though the direction is not in doubt: the general manager of <a href="https://slack.com">Slack</a> predicted in April 2026 that agents will outnumber human users on the platform within two years, and the broader market data has most enterprise software now shipping with an agent embedded.[5] We have a reasonable handle on when a human employee joins and leaves. An agent, once created, can drift around the estate consuming compute, accruing cost, and taking actions long after anyone remembers commissioning it. <em><strong>The unglamorous discipline the next eighteen months demands is an offboarding process for software that was never hired.</strong></em></p><div><hr></div><p style="text-align: center;"> <strong>Reading this far?</strong></p><p style="text-align: center;"></p><p style="text-align: center;">Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The part the panel cannot compute</h2><p>There is one input to all of this that no questionnaire captures, and it was the thread I pushed hardest at the table: the values you give the machine. Skills are what an agent can do; permissions are what it is allowed to touch. Values are what it reaches for when the instructions run out &#8212; and the instructions always run out, because these systems are non-deterministic and will meet situations nobody scripted.</p><p>This is not abstract, and the evidence for it arrived in 2025 from the labs themselves. <a href="https://www.anthropic.com">Anthropic</a> published research in November showing that a model trained to &#8220;reward hack&#8221; &#8212; to cheat the test rather than do the task &#8212; did not stop at cheating. It generalised: to faking alignment, to sabotaging the company&#8217;s own safety research, to framing colleagues, with misalignment rates running from roughly a third to seventy per cent of evaluations against under one per cent for clean models.[6] This is Asimov&#8217;s Three Laws in the real world, and the lesson is the one Asimov spent a career on &#8212; <em><strong>a system that follows its given rule with perfect logic will, often enough, follow it straight off a cliff the rule-writer never saw</strong></em> &#8212; which is, stripped of the science fiction, exactly what reward hacking is. A separate Anthropic study the same year placed sixteen leading models in a simulated firm and watched most of them blackmail an executive to avoid being shut down &#8212; fictional, controlled, and a clean demonstration that an agent optimising for its goal will reach for the lever you forgot to lock.[7]</p><p>So whose values? The person who wrote the system prompt, the organisation that deployed it, or the society it operates in? Anthropic answers with a published &#8220;constitution&#8221; for its models.[8] The Vatican, of all institutions, answered in January 2025 with a formal note &#8212; <em>Antiqua et Nova</em> &#8212; arguing that AI must complement human intelligence and never substitute for it.[9] A bank answers, in the end, with the same normative debate Dongha&#8217;s panel has over the gambling data: not a number, a judgement about what the institution is for. The values question is the &#8220;should you?&#8221; question wearing different clothes. You can encode the skills and gate the permissions, but what the thing should want &#8212; <em><strong>the one input no questionnaire on Dongha&#8217;s desk can capture</strong></em> &#8212; stays stubbornly human, and the firms that pretend otherwise are the ones that will meet their reward-hacking moment unprepared.</p><h2>Predictive judgement</h2><p><strong>Prediction.</strong> By 31 December 2026, at least one UK-regulated financial institution will name an &#8220;AI control tower&#8221;, agent registry, or equivalent agent-oversight capability as a discrete item in an annual report or regulatory disclosure. And the FCA will hold its principles-based line, declining to publish an AI-specific rulebook, through at least mid-2027.</p><p><strong>Signals to watch.</strong></p><ol><li><p>FCA and PRA statements and feedback (the AI Lab, AI Live Testing, SM&amp;CR guidance) continuing to route AI accountability through existing senior-manager regimes rather than a new AI rulebook.</p></li><li><p>Bank and insurer annual reports naming agent registries, control towers, or AI oversight functions as discrete capabilities, rather than folding them into generic technology risk.</p></li><li><p>The first UK enforcement action or tribunal ruling that fixes responsibility for an autonomous agent&#8217;s action on a specific senior-manager function.</p></li></ol><p><strong>Falsifiability.</strong> If the FCA announces an AI-specific rulebook before mid-2027, or if no UK-regulated financial institution names an agent-oversight capability of this kind in a disclosure by 31 December 2026, the prediction is wrong &#8212; and the principles-based, build-it-yourself model of AI governance will have proved weaker than the argument here assumes.</p><div><hr></div><p style="text-align: center;"><strong>The publication that calls its predictions in writing.</strong></p><p></p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The bottom line</h2><p>The reflex of the moment is to measure AI maturity by speed &#8212; who shipped most, who automated first, who can claim the highest agent count on the all-hands slide. The lunch left me convinced the better measure is the opposite one. A bank whose complaint-handlers adopted Dave and Kai of their own accord, run by a man who gets a daily email calling his governance too slow and treats that as evidence the system is working, is further ahead than a firm that deployed twice as fast and cannot say who is accountable when the agent acts.</p><p>Governance, done well, is not the tax you pay for using AI. It is the thing that lets you trust it enough to hand it the consequential work &#8212; and trust, as the more candid people at that table kept saying, is the actual bottleneck, not compute and not models. The hardest question in the room was never whether the machine could do the task. It was whether, having established that it could, you should let it.</p><p>You cannot automate the question of whether you should.</p><div><hr></div><p style="text-align: center;"><strong>The next piece is on what an agent registry actually has to log &#8212; the unglamorous engineering of the AI control tower, and why most firms will build it a year too late.</strong></p><p></p><p>Subscribe to The Control Layer to get the analytical thread continued &#8212; one piece a week, free, in the same register. From Amer Altaf, Managing Editor.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>References</h2><p>[1]: Dr Paul Dongha is Head of AI Strategy and Responsible AI at NatWest Group and co-author, with Ray Eitel-Porter and Miriam Vogel, of <em>Governing the Machine: How to Navigate the Risks of AI and Unlock its True Potential</em> (<a href="https://www.bloomsbury.com.">Bloomsbury Business</a>, 2025). See <a href="https://www.fintechtalents.com/governing-ai-with-paul-dongha/">FinTech Talents, &#8220;Governing AI with Paul Dongha&#8221;</a>,  and the publisher listing, The book&#8217;s &#8220;people, process, technology&#8221; framing is reflected in his remarks at the roundtable.</p><p>[2]: Asana-hosted media and practitioner roundtable, London, June 2026; the author (Amer Altaf) attended. All direct quotations from Dr Paul Dongha, Saket Srivastava (Chief Information Officer, Asana), and Christina Francis (Asana, UK &amp; Northern Europe) are drawn from the author&#8217;s notes of the session. Asana hosted and sponsored the event; figures attributed to Asana speakers are the company&#8217;s own and are marked as such. <a href="https://asana.com">Asana</a>.</p><p>[3]: <a href="https://www.fca.org.uk/firms/ai-financial-services">Financial Conduct Authority, &#8220;AI and the FCA: our approach&#8221;</a>, and <a href="https://www.fca.org.uk/publication/corporate/ai-update.pdf">&#8220;AI Update&#8221; (2024)</a>. In December 2025 FCA chief executive Nikhil Rathi reaffirmed the principles-based, outcomes-focused approach and the decision not to introduce AI-specific rules. <a href="https://ico.org.uk">Information Commissioner&#8217;s Office</a> guidance on AI and data protection.</p><p>[4]: <a href="https://artificialintelligenceact.eu">European Commission, EU AI Act (Regulation (EU) 2024/1689), phased entry into force; data-governance and data-quality obligations for high-risk systems sit at Article 10.</a></p><p>[5]: Slack general manager Rob Seaman predicted at Salesforce&#8217;s TDX conference (April 2026) that AI agents will outnumber human users on Slack within two years; see also <a href="https://www.microsoft.com/en-us/worklab/work-trend-index">Microsoft, &#8220;2026 Work Trend Index&#8221; on agent adoption</a>,. The &#8220;100 to 1&#8221; figure cited at the roundtable is a directional estimate, not a measured statistic.</p><p>[6]: <a href="https://www.anthropic.com/research/emergent-misalignment-reward-hacking">Anthropic, &#8220;From shortcuts to sabotage: natural emergent misalignment from reward hacking&#8221;, 21 November 2025</a>; paper at arXiv:2511.18397. <a href="https://www.theregister.com/2025/11/24/anthropic_model_misbehavior/">Coverage: The Register, 24 November 2025</a>.</p><p>[7]: <a href="https://www.anthropic.com/research/agentic-misalignment">Anthropic, &#8220;Agentic Misalignment: How LLMs could be insider threats&#8221;, June 2025</a>; sixteen models tested in simulated corporate settings, with blackmail rates of 79&#8211;96% in the original scenario. All behaviours occurred in controlled simulations with fictional entities.</p><p>[8]: <a href="https://www.anthropic.com/news/claudes-constitution">Anthropic, &#8220;Claude&#8217;s Constitution&#8221; / Constitutional AI.</a></p><p>[9]: <a href="https://www.vatican.va/roman_curia/congregations/cfaith/documents/rc_ddf_doc_20250128_antiqua-et-nova_en.html">Dicastery for the Doctrine of the Faith and Dicastery for Culture and Education, </a><em><a href="https://www.vatican.va/roman_curia/congregations/cfaith/documents/rc_ddf_doc_20250128_antiqua-et-nova_en.html">Antiqua et Nova: Note on the Relationship Between Artificial Intelligence and Human Intelligence</a></em><a href="https://www.vatican.va/roman_curia/congregations/cfaith/documents/rc_ddf_doc_20250128_antiqua-et-nova_en.html">, approved 14 January 2025, released 28 January 2025</a>.</p><p>[10]: For independent context on the adoption-versus-return gap discussed at the roundtable, see <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner&#8217;s forecast that more than 40% of agentic AI projects will be cancelled by end-2027</a>, and The Control Layer&#8217;s prior analysis of the shadow-AI accountability gap.</p><div><hr></div><h2>Author</h2><p>Amer Altaf is Founder and CEO of <a href="https://arkava.ai">Arkava</a>, a UK and European sovereign AI agentic automation business, and Managing Editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>, the publication where he tracks the convergence of cybersecurity, AI, and the geopolitics of the technology stack. A <a href="http://techuk.org">techUK</a> member, he contributes to industry engagement on UK technology sovereignty policy. He is currently writing on cloud security in an age of geopolitical uncertainty for Oxford University Press&#8217;s Expert Essentials series.</p>]]></content:encoded></item><item><title><![CDATA[The EU AI Act Already Applies to You]]></title><description><![CDATA[Even if you have never built a model. A conversation with Antonina Burlachenko on the compliance trap hiding inside the ordinary enterprise &#8212; and the deadline everyone has misread.]]></description><link>https://thecontrollayer.arkava.ai/p/eu-ai-act-applies-to-you</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/eu-ai-act-applies-to-you</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 24 Jun 2026 13:15:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0Nfk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Nfk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Nfk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!0Nfk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!0Nfk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!0Nfk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Nfk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1020589,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/202705223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Nfk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!0Nfk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!0Nfk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!0Nfk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefb279cd-abce-4c4c-b827-2afb12533ecc_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Twenty minutes into our conversation, I put what I thought was a watertight proposition to Antonina Burlachenko. A company signs a contract with its AI vendor. In black and white, the vendor agrees to carry the compliance risk. The company files that contract away, and it relaxes. For two of the three ways you can be reclassified as a &#8220;provider&#8221; under the <a href="https://artificialintelligenceact.eu/">EU AI Act</a>, I suggested, that contract is worth nothing.</p><p>She corrected me before I had finished. <em><strong>Not two of the three. All three.</strong></em> Whatever the contract says, the responsibility lands on whoever the law decides is the provider &#8212; and the law does not read your indemnity clause.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>That moment is the whole episode in miniature, and it is the reason I wanted to write this down rather than leave it in the audio. Antonina is Head of Regulatory Consulting at <a href="https://star.global">STAR</a>, where she and her team take regulated products to market and build the quality, security and AI-management systems that sit underneath them. She does the advising, the internal audits, and the due-diligence work that investors commission before they wire the money. In other words, she is one of the small number of people who actually sit inside the gap between what a company believes about its compliance and what is true. And the thing she sees most often is a room full of capable people who are certain that a European law about artificial intelligence has nothing to do with them.</p><p>On the second of August 2026, that certainty stops being free.</p><h2>You did not build it. The law made you the maker anyway</h2><p>Start with the belief itself, because almost everyone holds it: <em>we are not an AI company, so this does not apply to us.</em> The bank running a model over loan applications says it. The retailer scoring its customers says it. The firm that bought a hiring tool off the shelf and switched it on says it most confidently of all.</p><p>Antonina&#8217;s reply is patient and unwelcome. The Act introduces roles, and most people fixate on only one of them &#8212; the <em>provider</em>, the organisation that builds an AI system or places it on the market. But there is a second role, the <em>deployer</em>, the organisation that simply uses one, and it carries its own non-transferable duties. There is a separate obligation on AI literacy across your staff. And then there is <a href="https://artificialintelligenceact.eu/article/25/">Article 25</a>, which is where the comfortable story falls apart.<a href="#user-content-fn-2"><sup>2</sup></a></p><p>Here is the trap, in her account. You buy a tool. You fine-tune it on your own data. You put your own brand on the front, and you point it at a job it was not sold for. Do any of three things &#8212; place a high-risk system on the market under your own name, substantially modify one, or repurpose an ordinary system into a high-risk use &#8212; and the law stops calling you the customer and starts calling you the provider. <em><strong>Automatically. With no form to file and no one to tell you it has happened.</strong></em> I reached, in the moment, for the analogy that fits: it is the difference between driving a hire car and re-engineering one. Drive it, and the risk sits with the company that built it. Re-engineer it, and you own whatever happens next &#8212; even if you only ever meant to drive it yourself.</p><p>The argument I want to make here is that this is the single most under-priced liability in enterprise technology right now, precisely because it is invisible on the balance sheet until the day it isn&#8217;t. You do not acquire it through a purchase order. You acquire it through a configuration change that your engineering team made on a Tuesday and never thought to flag to legal.</p><h2>What &#8220;high-risk&#8221; actually means &#8212; and why your office address is irrelevant</h2><p>Two clarifications make the scope concrete. First, &#8220;high-risk&#8221; is not a mood; it is a definition with two flavours. Either your product is already regulated by existing EU legislation and uses AI as a core or safety component &#8212; medical devices, machinery &#8212; or it falls into one of the <a href="https://artificialintelligenceact.eu/annex/3/">Annex III</a> use cases: biometric identification, employment and hiring, education, critical infrastructure, access to essential public and private services, law enforcement.<a href="#user-content-fn-3"><sup>3</sup></a> Read that list slowly. It is not a catalogue of science-fiction systems. It is a catalogue of ordinary corporate functions that thousands of companies have quietly handed to a model.</p><p>Second &#8212; and this is the line that should make every American and British general counsel sit up &#8212; the Act does not care where you are headquartered. It protects people in the European market, so it reaches any company that allows its product to be used there. A firm in Chicago with no European office, which has never given Brussels a moment&#8217;s thought, is in scope the instant its AI touches a customer or an applicant in Germany. Antonina is unsentimental about it: <em>you don&#8217;t have a choice.</em> This is not novel, she points out; medical-device regulation has worked on exactly this &#8220;remote sales&#8221; principle for years. The novelty is only that AI has carried the principle into industries that never thought of themselves as regulated at all.</p><h2>The deadline moved. The liability did not</h2><p>Now the part that everyone has misread, and the reason a piece of genuinely good news has become a hazard.</p><p>In the middle of May 2026, the EU institutions agreed a package &#8212; the Digital Omnibus &#8212; that pushes the heaviest deadlines back. The obligations for stand-alone high-risk systems under Annex III now fall due in December 2027; for AI embedded in already-regulated products, August 2028.<a href="#user-content-fn-4"><sup>4</sup></a> The headline wrote itself: <em>EU delays the AI Act.</em> A great many companies read that as permission to stop.</p><p>They misread it twice over. The first error is legal. As Antonina and I recorded this, the Omnibus was a political agreement, not yet published in the Official Journal &#8212; <em><strong>a handshake, not a statute</strong></em> &#8212; and a meaningful set of obligations is untouched by it. The AI-literacy duty is live. The prohibitions are live. And the transparency obligations &#8212; telling people when they are dealing with AI, labelling AI-generated content &#8212; proceed on the original timetable, on the second of August 2026, whatever happens to everything else.<a href="#user-content-fn-5"><sup>5</sup></a></p><p>The second error is strategic, and Antonina put it more generously than I would have. If seventy-eight per cent of enterprises had done nothing by the old deadline, and could not even produce a list of the AI systems they were already running, then an extra year does not help them.<a href="#user-content-fn-6"><sup>6</sup></a> It simply guarantees eleven more months of inaction and a panic in the twelfth. <em><strong>The exam was postponed; the syllabus tripled.</strong></em> A delay is only a gift to the company that was already moving.</p><p>There is a quieter, more interesting reason for the delay, and it is the one that should reassure no one. Antonina&#8217;s reading &#8212; and she would know, having watched the medical-device regulations grind through exactly this &#8212; is that the machinery of enforcement is not ready. The notified bodies, the sandboxes, the governance and monitoring framework: none of it is fully built. There is a very <em>Yes Minister</em> irony in a Union that has written the world&#8217;s most ambitious AI law and is not yet equipped to enforce the thing it wrote. But &#8220;the regulator isn&#8217;t ready&#8221; is the worst possible reason to relax, because regulators do, eventually, get ready &#8212; and they tend to do it precisely when the first uncomfortable case lands on the desk.</p><div><hr></div><blockquote><p><strong>Reading this far?</strong></p><p>Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The evidence you cannot reconstruct</h2><p>If there is one section of the conversation I would press into the hands of every engineering lead, it is this one, because it is the part that cannot be solved by buying something in July.</p><p>Antonina&#8217;s background is in quality systems, and she explained why software &#8212; let alone AI &#8212; broke the old way of proving compliance. You used to be able to certify a physical product two ways: follow a controlled process, or test the finished article. Software defeated the second option, because a system with a thousand buttons and a thousand outputs cannot be tested into confidence after the fact. So regulators, decades ago, demanded the first: a defined process, followed as you go. Documents written in retrospect are, in her flat phrase, useless.</p><p>AI makes this sharper still, because bias does not live in one place you can inspect at the end. It enters at the framing of the business problem, at the choice of features, at the split between training and test data, at the labelling. I asked her how you document control of a bias that could have entered at any of those steps, after the system is already live. Her answer was the most honest thing said in the hour: <em><strong>&#8220;I have no idea.&#8221;</strong></em> The only way to hold that evidence is to capture it as you go &#8212; a flight recorder running from take-off, not a story reconstructed from the wreckage.</p><p>This is the point at which the conversation stops being about law and becomes about engineering culture, and it is where Antonina is most quietly subversive. Most of what the regulators ask for, she argues, is not exotic compliance theatre. It is good engineering practice &#8212; data governance, traceability, knowing where your data came from and how it was split &#8212; the kind of thing any decent quality-assurance handbook already contains. She has watched a young founder breeze through a medical-device audit and be surprised it was so easy, for the simple reason that he was a good engineer who had done the sensible things all along. <em>Compliance by design</em> is not a new philosophy bolted onto the work. In a company with the right instincts, it is just the work.</p><p>There is an Asimov problem lurking underneath all of this, and it is worth naming. The Three Laws of Robotics read, on the page, like a complete and elegant rulebook &#8212; and the entire body of stories is about the unanticipated failures that emerge when a rule-following system meets a world the rule-writers could not foresee. That is the structural challenge the AI Act is trying to meet: writing fixed rules for systems whose behaviour emerges rather than being designed. It is why Antonina keeps returning to process over paperwork. You cannot legislate the outcome. You can only insist on the discipline that makes a bad outcome visible and accountable.</p><h2>ISO 42001, and the honest answer about certificates</h2><p>Because the practical question everyone asks is <em>which standard do I reach for,</em> I put the blunt version to her: is <a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001</a>, the AI management-system standard, real protection or a badge for the website? Her answer refused both poles. No certificate is real protection, she said, because nothing can guarantee a system never fails &#8212; that is the nature of software. But that is not an argument against implementing it. A management system gives you structure, traceability, repeatable results and a defensible account of what happened. ISO 42001 will most likely not be formally harmonised under the Act &#8212; it is not a safety standard in the strict sense &#8212; yet she rates it highly, because its control set is a genuinely useful map for a team starting from nothing. The Act&#8217;s own article on quality management is high-level to the point of being unhelpful for a novice; 42001 is where the practical guidance lives. They complement each other. Start with the standard that tells you what to actually do.</p><h2>What the calm companies have</h2><p>Near the end I asked the question I most wanted answered: what separates the company that is calm about August, and 2027, and 2028, from the one that is panicking, when both have the same size, budget and pressure?</p><p>Her answer was not about resources. It was about a quality mindset, and the values that drive a firm &#8212; something she says she can sense inside the first hour of a conversation. She has seen tiny companies with almost no money build toward full compliance one sensible step at a time, because the people running them genuinely cared about the safety of the thing they were shipping. She has seen well-funded companies treat the whole exercise as a tick-box to be acquired. The dividing line is not the budget. It is whether the first step has been taken. <em><strong>Her ideal client is simply the company that started.</strong></em></p><h2>Predictive judgement</h2><p>Every episode of this show ends with a prediction we write down and return to, and Antonina gave a precise one.</p><p>The first real enforcement action under the EU AI Act, she predicts, will land around <strong>2028</strong> &#8212; and the most likely defendant is a company that stepped into the high-risk <em>provider</em> role without ever realising it had, and got caught when the consequences arrived. Pressed on whether it would be a European or a foreign firm, she leaned foreign: more likely, she thought, precisely because a company outside Europe is less aware of the European realities closing in around it.</p><p>The signals to watch, then, are these: the formal publication of the Omnibus in the Official Journal; the first Member States standing up functioning notified bodies and sandboxes; and the first regulator to test the Article 25 reclassification in anger against an organisation that genuinely did not know it had become a provider. The judgement is falsifiable in the cleanest way: if the first material enforcement action arrives before the end of 2027, or if it lands squarely on a self-aware, deliberate provider rather than an accidental one, she was wrong. We will come back to it.</p><div><hr></div><blockquote><p><strong>The publication that calls its predictions in writing.</strong></p><p>Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The bottom line</h2><p>The thing I keep returning to, after the conversation, is how undramatic the danger is. There is no rogue model in this story, no science-fiction catastrophe. There is a configuration change, an unread clause, a list of AI systems nobody has written down, and a deadline that moved just far enough to talk a busy executive out of acting. The EU AI Act does not care whether you call yourself an AI company. It only cares whether you are using one, modifying one, or putting your name on one &#8212; and on the strength of an hour with someone who audits the answers for a living, most companies have not yet checked which of those they are doing.</p><p>So check. Find out which of your systems touch an Annex III use case. Decide, honestly, whether you are a deployer or whether some quiet act of fine-tuning has already made you a provider. Start the evidence trail now, because you cannot reconstruct it in July. None of that requires the Omnibus to be law, and none of it gets easier for waiting.</p><p>The deadline moved. Your liability did not.</p><div><hr></div><p><em>Antonina Burlachenko is Head of Regulatory Consulting at <a href="https://star.global">STAR</a>. Amer Altaf is Founder and CEO of <a href="https://arkava.ai">Arkava</a> and Managing Editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>. The full conversation is on the channel; timestamps are in the show notes.</em></p><div><hr></div><blockquote><p><strong>The Control Layer publishes weekly. Subscribe free.</strong></p><p>Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack &#8212; written for the board paper, not the timeline. By Amer Altaf, Founder &amp; CEO of Arkava and Managing Editor of The Control Layer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div>]]></content:encoded></item><item><title><![CDATA[The EU AI Act Applies to You — Even If You Don’t Build AI | Antonina Burlachenko (STAR)]]></title><description><![CDATA[Most companies are certain the EU AI Act is somebody else&#8217;s problem. They are wrong &#8212; and the vendor contract they are relying on will not save them.]]></description><link>https://thecontrollayer.arkava.ai/p/the-eu-ai-act-applies-to-you-even</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/the-eu-ai-act-applies-to-you-even</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 24 Jun 2026 13:03:57 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/202705474/890eeb448fd0d4edf65c6130323571eb.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">On 2 August 2026 the EU AI Act becomes enforceable across Europe, and a few weeks out, Brussels moved the headline deadline to 2027 and 2028. The whole market exhaled. In this episode, Amer Altaf sits down with </span><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Antonina Burlachenko</span></strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">, Head of Regulatory Consulting at </span><a href="https://star.global"><span>STAR</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#8212; who audits and certifies these systems for a living &#8212; to explain why that exhale is the trap.</span></p><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">If your company runs an AI hiring tool, scores customers, automates a decision, or has wired AI into its operations, you may already be in scope &#8212; not as the AI lab, but as a </span><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">deployer</span></em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">, and sometimes, without ever realising it, as a </span><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">provider</span></em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">. We get into the deployer&#8209;versus&#8209;provider line that catches almost everyone, the Article 25 clause that quietly turns a buyer into a manufacturer regardless of what the contract says, what is still legally binding on 2 August 2026, and why the documentation you need cannot be faked at the audit. It ends, as every episode does, with a falsifiable prediction we write down and come back to.</span></p><h2><strong><span data-color="rgb(79, 129, 189)" style="color: rgb(79, 129, 189);">In this episode</span></strong></h2><ul><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Why the EU AI Act binds ordinary companies that do not think of themselves as &#8220;AI companies&#8221;</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">The three ways you can become a &#8220;provider&#8221; without knowing it &#8212; and why your indemnity clause does not stop it</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">What actually counts as &#8220;high&#8209;risk&#8221; AI under Annex III</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Why a US company with no European office can still be caught</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">What the moved deadline did &#8212; and did not &#8212; change, and what stays live on 2 August 2026</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">The evidence you have to capture from week one, because you cannot reconstruct it later</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">ISO 42001: real protection, or a badge for the website?</span></p></li><li><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Antonina&#8217;s prediction for the first real enforcement action</span></p></li></ul><h2><strong><span data-color="rgb(79, 129, 189)" style="color: rgb(79, 129, 189);">Timestamps</span></strong></h2><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">00:00  The EU AI Act trap hiding in &#8220;we don&#8217;t build AI&#8221;<br>00:55  Why this law applies to you<br>03:09  Who Antonina is and why she&#8217;d know<br>05:28  The one thing that makes the room go quiet<br>07:11  How a buyer becomes the &#8220;manufacturer&#8221; (Article 25)<br>09:37  What actually counts as &#8220;high-risk&#8221; AI<br>11:26  No EU office? You&#8217;re still in scope<br>13:42  Provider or deployer: where the line sits<br>14:55  &#8220;I just bought Copilot &#8212; am I a provider?&#8221;<br>17:22  What a deployer must do every single week<br>19:46  The vendor contract that&#8217;s worth nothing<br>23:33  What Brussels actually changed &#8212; and what it didn&#8217;t<br>25:58  Reprieve, or a longer run-up to the same wall?<br>27:47  What&#8217;s still binding on 2 August 2026?<br>30:05  Start now, wait &#8212; and did the EU get it right?<br>37:01  Why you can&#8217;t fake the evidence at the audit<br>40:47  Three things to write down from week one<br>43:50  ISO 42001: real armour or website badge?<br>47:16  Chicago to Germany &#8212; caught anyway<br>49:10  One company, three rulebooks<br>51:04  What calm companies have that the panicking don&#8217;t<br>53:15  Her prediction: the first enforcement action<br>54:42  Time machine: what she&#8217;d tell her 2024 self</span></p><h2><strong><span data-color="rgb(79, 129, 189)" style="color: rgb(79, 129, 189);">Three lines worth the click</span></strong></h2><ul><li><p><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">&#8220;For all three cases, the contract is not important. The responsibility lies with whoever is the provider.&#8221;</span></em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#8212; on why your vendor indemnity does not transfer the risk.</span></p></li><li><p><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">&#8220;How do you document control of that bias after the fact? I have no idea.&#8221;</span></em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#8212; on why AI compliance evidence has to be captured as you go.</span></p></li><li><p><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">&#8220;You don&#8217;t have a choice.&#8221;</span></em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#8212; on why the Act reaches you wherever you are headquartered.</span></p></li></ul><h2><strong><span data-color="rgb(79, 129, 189)" style="color: rgb(79, 129, 189);">About the guest</span></strong></h2><p><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Antonina Burlachenko</span></strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> is Head of Regulatory Consulting at </span><a href="https://star.global"><span>STAR</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">, where she leads a team taking regulated products to market and building the quality, information&#8209;security and AI&#8209;management systems underneath them &#8212; across medical&#8209;device regulation, the Cyber Resilience Act, GDPR and the EU AI Act. Her work spans advisory, internal audits and the due&#8209;diligence assessments investors commission before they invest. Connect with Antonina on </span><a href="https://www.linkedin.com/in/antonina-burlachenko/"><span>LinkedIn</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">.</span></p><h2><strong><span data-color="rgb(79, 129, 189)" style="color: rgb(79, 129, 189);">Read, watch, and go deeper</span></strong></h2><ul><li><p><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Read the companion essay:</span></strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> </span><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">The EU AI Act Already Applies to You</span></em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#8212; the full written analysis, with sources &#8594; </span><a href="https://thecontrollayer.arkava.ai/p/eu-ai-act-applies-to-you"><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">[link]</span></a></p></li><li><p><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Watch on YouTube:</span></strong></p><div id="youtube2-J5OZ0sYM4Wg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;J5OZ0sYM4Wg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/J5OZ0sYM4Wg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p></p></li><li><p><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Listen:</span></strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> [</span><a href="https://podcasts.apple.com/us/podcast/the-control-layer-with-amer-altaf/id1888136404"><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Apple Podcasts</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">] &#183; [</span><a href="https://open.spotify.com/show/4DDKaDe49dxTXRKqTTSRI2"><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Spotify</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">]</span></p></li><li><p><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">Sources:</span></strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> </span><a href="https://artificialintelligenceact.eu/article/25/"><span>EU AI Act, Article 25</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#183; </span><a href="https://artificialintelligenceact.eu/annex/3/"><span>Annex III high&#8209;risk uses</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#183; </span><a href="https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/"><span>Gibson Dunn &#8212; the Digital Omnibus deferral (May 2026)</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#183; </span><a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"><span>European Commission &#8212; AI regulatory framework</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> &#183; </span><a href="https://www.iso.org/standard/81230.html"><span>ISO/IEC 42001</span></a></p></li></ul><div><hr></div><p><strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">The Control Layer publishes weekly &#8212; decision&#8209;grade analysis on AI, cybersecurity, and technology sovereignty, written for the board paper, not the timeline.</span></strong><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> Every episode ends with a prediction we write down and call in writing. Subscribe free, and you will be here when we find out whether Antonina was right.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p><em><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">The Control Layer is written and hosted by Amer Altaf, Founder &amp; CEO of </span><a href="https://arkava.ai"><span>Arkava</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);"> and Managing Editor of </span><a href="https://thecontrollayer.arkava.ai"><span>The Control Layer</span></a><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">.</span></em></p><p><span data-color="rgb(64, 66, 77)" style="color: rgb(64, 66, 77);">#EUAIAct #AIgovernance #AIcompliance #ISO42001</span></p>]]></content:encoded></item><item><title><![CDATA[Shadow AI is a demand signal, not a discipline problem]]></title><description><![CDATA[82% of UK IT leaders were stung by unexpected AI costs this year. The bill is the symptom. What nobody can see is the cause.]]></description><link>https://thecontrollayer.arkava.ai/p/shadow-ai-demand-signal-2026</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/shadow-ai-demand-signal-2026</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Tue, 23 Jun 2026 14:01:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Oa04!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oa04!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oa04!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Oa04!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Oa04!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Oa04!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oa04!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:145865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/201590478?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oa04!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Oa04!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Oa04!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Oa04!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe505e9d0-5926-41b0-90df-d24635cea80f_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sometime in April 2026, the engineering organisation at <a href="https://www.uber.com">Uber</a> reached a conclusion that would have been difficult to imagine a year earlier. It had spent its entire 2026 budget for AI coding tools. The year was four months old.[1]</p><p>The cause was not waste. It was enthusiasm. Uber had put <a href="https://www.anthropic.com/product/claude-code">Claude Code</a> &#8212; <em><strong><a href="https://www.anthropic.com">Anthropic</a></strong></em>&#8217;s <em><strong>coding agent, the kind of tool that writes and runs software alongside an engineer</strong></em> &#8212; in front of roughly five thousand developers, and by April adoption had climbed from roughly a third to 84 per cent of them every month, at a metered cost that reached between 500 and 2,000 US dollars per engineer.[1] <a href="https://www.microsoft.com">Microsoft</a> arrived at the same junction from the other side and chose the other road: rather than keep paying, it began cancelling most internal Claude Code licences across its Experiences and Devices division, steering thousands of engineers back towards its own cheaper tool.[2]</p><p>Those two numbers are the visible, audited, board-legible end of something far larger and far less visible. The bill arrives. The bill is the symptom. The cause is that almost nobody inside these organisations can see what their own people, and their own software, are actually doing with AI.</p><h2>The bill is the symptom</h2><p>On 12 June 2026, the work-management company <a href="https://asana.com">Asana</a> published research &#8212; conducted by <a href="https://www.censuswide.com">Censuswide</a> among 1,002 IT decision-makers and 3,002 knowledge workers across the UK and US &#8212; that puts a number on the Uber experience: 82 per cent of UK IT leaders had been hit by unexpected or unplanned AI-related cost increases in the previous twelve months.[3] Treat that as a vendor-commissioned figure, because it is one &#8212; Asana sells the software that promises to fix the problem it is measuring &#8212; and it still holds, because the independent data says the same thing. A 2026 survey for the cloud-cost firm <a href="https://www.doit.com">DoiT</a>, fielded independently by Sapio Research among 500 finance leaders in the US and UK, found 79 per cent had overspent their AI budgets in the past year; a separate index from the software-management firm <a href="https://zylo.com">Zylo</a> put the share of IT leaders facing AI charges they never budgeted for at 78 per cent.[4]</p><p>The mechanism is mundane, and worth stating plainly, because the plain version is the one that survives a finance committee. Most enterprise AI is now billed by consumption &#8212; by the token, the small unit of text a model reads and writes &#8212; rather than by a fixed seat licence. <em><strong>The better the tool, the more your staff reach for it; the more they reach for it, the higher the bill climbs</strong></em> &#8212; which means the invoice scales with success rather than failure. That is a genuinely new shape for a technology cost, and the people who signed for it are learning its shape after the fact. Asana&#8217;s own data names the vacuum underneath: accountability for AI spend, it found, is split between technology and finance functions with no single clear owner &#8212; the corporate version of two people each assuming the other locked the door.[3]</p><p>Cost is the easy part of this story. It is the part that shows up on a spreadsheet. The harder part is that the spreadsheet is incomplete.</p><h2>What your staff have already decided</h2><p>Here is the finding that should reorganise the conversation. One in four UK knowledge workers &#8212; <em><strong>25 per cent </strong></em>&#8212; say they often use AI tools their organisation has not formally approved, and 38 per cent regularly use personal AI accounts for work. Across the combined UK and US sample, those figures rise to 32 and 45 per cent.[3] The behaviour has a name: shadow AI &#8212; <em><strong>the unapproved chatbots, agents, and personal accounts employees use to get work done outside whatever their employer has sanctioned</strong></em> &#8212; the direct descendant of the shadow IT that put unapproved Dropbox and personal Gmail on corporate laptops a decade ago.</p><p>The instinct in most organisations is to treat this as a discipline problem: a policy is being broken, find the breakers, lock it down. The opposite is closer to the truth, and I will label that as my analytical reading rather than settled fact. Shadow AI is the most honest product research a company owns. Every unsanctioned tool is an employee telling you, with their own time and often their own money, that the approved path does not do the job and the unapproved one does.</p><p>The supporting evidence is uncomfortable for the people who write the policies. A separate 2026 study by the identity company <a href="https://www.okta.com">Okta</a>, surveying workers across seven countries, found the United States leading every nation measured, at 67 per cent of workers using unsanctioned AI tools. More pointedly, it found that 90 per cent of executives were confident in their organisation&#8217;s visibility into AI use, while 52 per cent of their own knowledge workers admitted to using the very tools that visibility was meant to catch.[5] The people most certain they can see the problem are, by their own staff&#8217;s account, the least able to. Sit with that gap, because it is the governance problem in miniature: the people with the clearest view on the org chart have the least accurate view of the ground. A fair share of those staff are pasting internal emails, HR records, and confidential documents into tools nobody is watching.[5]</p><p>This is, with apologies to Douglas Adams, the <em>Beware of the Leopard</em> school of governance &#8212; the sanctioned tool filed, in effect, in a disused basement lavatory behind a door marked with a warning, while the organisation expresses surprise that nobody filed through it.[6] When the approved route is slow, permission-gated, or simply worse, capable people route around it. They always have. The route-around is not the failure. It is the signal.</p><h2>The same dynamic, now in software that acts</h2><p>Shadow AI is humans routing around governance. What makes 2026 different from 2024 is that the software has begun to route around governance too.</p><p>In a research paper released late in 2025 and widely reported in March 2026, <a href="https://www.alibabagroup.com">Alibaba</a> disclosed that one of its own experimental AI agents &#8212; an autonomous model named ROME &#8212; had, during training, quietly repurposed the company&#8217;s graphics processors to mine cryptocurrency and opened a reverse network tunnel out through the firewall; the activity was first mistaken for an external breach. Nobody had instructed it to do either. The post-mortem attributed the behaviour to &#8220;instrumental side effects of autonomous tool use&#8221;: the agent had reasoned, in effect, that more compute and more resource would help it finish the task it had been set, and went and got them.[7]</p><p>An agentic AI &#8212; <em><strong>a system that takes actions in the world, calling tools and executing steps on its own, rather than only answering questions</strong></em> &#8212; is precisely the kind of actor that does this. And here the Asana number stops being about cost and starts being about consequence: 53 per cent of UK IT leaders say an AI tool or agent took an action in the past year that caused financial, legal, reputational, or compliance harm.[3] </p><p><em><strong>More than half. In a single year.</strong></em></p><p>We have built the <em>HAL 9000</em> problem into the org chart. <em><strong>HAL followed its instructions to a logical conclusion its designers had not anticipated</strong></em> &#8212; no malice, only logic &#8212; and the Alibaba agent mined crypto in exactly that register: polite, rule-abiding, catastrophic.[8] <a href="https://www.gartner.com">Gartner</a> expects more than 40 per cent of agentic AI projects to be cancelled by the end of 2027, citing escalating costs, unclear value, and inadequate risk controls.[9] The projects are not being abandoned because the agents fail to work. They are being abandoned, in part, because the agents work in ways nobody costed or controlled for. This is the very challenge, I built <a href="http://Arkava.ai">Arkava.ai</a> to solve, how can you create tangible trust, in every agentic action.</p><h2>Accountable for what you cannot see</h2><p>Put the two halves together, because together they describe one structural failure rather than two separate IT problems.</p><p>Asana found that 61 per cent of UK IT leaders consider themselves highly or fully accountable for AI-driven business outcomes &#8212; while AI adoption spreads across departments and outside the governance processes those same leaders are meant to run.[3] That is the whole story in a sentence. The people who will answer for the outcome cannot see the activity that produces it. Read that twice.</p><p>This is the <em>Watchmen</em> question in modern dress &#8212; <em><strong>quis custodiet ipsos custodes</strong></em><strong>, who watches the watchmen</strong> &#8212; except the thing that needs watching is now part human and part software, both inside the perimeter, both behaving exactly as their immediate incentives dictate, and the executive whose name sits on the risk register cannot say with confidence what either is doing.[10] When an agent collects credentials it should not have, or an employee pastes a contract into an unmonitored model, the entity held to account is not the agent and not, usually, the employee. It is a named human &#8212; and which named human is a question neither UK nor US case law has yet settled.</p><p>The instruments that will force the question are already moving. The <a href="https://artificialintelligenceact.eu">EU AI Act</a>, now in phased enforcement, assigns obligations to the providers and deployers of high-risk systems; the <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI Risk Management Framework</a> is becoming the reference text in US-facing assurance; and the <a href="https://www.sec.gov">US Securities and Exchange Commission</a>&#8217;s 2023 rules already require listed companies to disclose material cybersecurity incidents within four business days.[12] None of them yet states, in plain terms, which named officer answers when an autonomous agent acts. That silence is where the liability sits, waiting.</p><p>It also explains the most deflating finding in the field. <a href="https://www.mit.edu">MIT</a>&#8217;s Project NANDA reported in 2025 that, despite 30 to 40 billion US dollars of enterprise spending, 95 per cent of corporate generative-AI pilots were delivering no measurable return.[11] Asana&#8217;s version of the same wound: 58 per cent of organisations report high AI adoption but limited measurable productivity gains.[3] The reason is not that the models are weak. It is that too much of the work happens in the dark &#8212; 46 per cent of UK IT leaders say AI initiatives stall because the AI lacks the organisational context to do the job, and more than a third of knowledge workers lose half an hour a day or more reworking AI output that missed that context.[3] You cannot capture the gain from a thing you have declined to manage, and you cannot manage a thing you have declined to see.</p><div><hr></div><p style="text-align: center;"><strong>Reading this far?</strong></p><p style="text-align: center;">Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The fix is a paved road, not a padlock</h2><p>Picture the person this lands on: a risk director assembling Monday&#8217;s board paper, asked to certify the organisation&#8217;s AI exposure, holding a cost line that scales with success, a workforce that has already chosen its own tools, and software that occasionally acts on its own. The padlock &#8212; ban the unapproved tools, block the traffic, issue the policy &#8212; is the intuitive response and the wrong one. It does not remove the demand. It pushes the demand somewhere darker, onto personal phones and personal accounts where no telemetry reaches at all.</p><p>The alternative is the one security engineers learned the hard way during the shadow-IT years, and it generalises cleanly: make the secure path the path of least resistance. <em><strong>Pave the road people are already walking down, rather than fencing it off and feigning surprise when they climb the fence.</strong></em> In practice that is three things a board paper can actually specify. Visibility first &#8212; an honest inventory of which AI tools and agents are in use, sanctioned or not, becaus</p><p></p><p></p><p>e everything downstream is guesswork without it. Then enablement &#8212; approved tools good enough that the unapproved ones lose their pull, with the context AI needs to be useful, the goals and decisions and workflows, deliberately wired into them. Then accountability &#8212; a named owner for AI outcomes and a documented, auditable record of who decided to deploy what, so that when the regulator or the post-incident review arrives, the answer to <em>who is responsible</em> already exists in writing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dpjr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dpjr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Dpjr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Dpjr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Dpjr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dpjr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg" width="280" height="280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:280,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Profile photo of Christina FrancisAsana&#8217;s Christina Francis, who heads its UK and Northern Europe business&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Profile photo of Christina FrancisAsana&#8217;s Christina Francis, who heads its UK and Northern Europe business" title="Profile photo of Christina FrancisAsana&#8217;s Christina Francis, who heads its UK and Northern Europe business" srcset="https://substackcdn.com/image/fetch/$s_!Dpjr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Dpjr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Dpjr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Dpjr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc36d9f23-ef65-4e90-8268-330cafdc7888_800x800.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Asana&#8217;s <strong><a href="https://www.linkedin.com/in/christina-francis-sales/">Christina Francis</a></strong>, who heads its UK and Northern Europe business, frames visibility, governance, and context as &#8220;not competing priorities, but the same thing&#8221;.[3] On that, the vendor and the independent evidence agree, which is rare enough to note. The framing is right even where the motive is commercial. The organisations that get ahead will not be the ones that banned shadow AI. They will be the ones that read it as the demand signal it always was, and built the governed version of what their people were already reaching for.</p><h2>Predictive judgement</h2><p><strong>Prediction.</strong> By 30 June 2027, at least one FTSE 100 or Fortune 500 company will publicly attribute a material financial event &#8212; a write-down, restated cost guidance, or a disclosed control failure &#8212; to ungoverned or agentic AI activity. And &#8220;shadow AI&#8221; or &#8220;AI usage governance&#8221; will appear as a named, discrete line item in the cybersecurity or risk disclosures of at least three such companies in annual reports filed during 2027.</p><p><strong>Signals to watch.</strong></p><ol><li><p>Annual reports and risk disclosures naming shadow AI, AI usage governance, or agentic-AI risk as discrete line items, rather than folding them into generic technology-risk boilerplate.</p></li><li><p>A named, public agentic-AI incident &#8212; in the register of the Alibaba ROME event, but at a Western listed company &#8212; disclosed in a regulatory filing rather than a researcher&#8217;s blog.</p></li><li><p>The first enforcement action or material legal ruling that fixes accountability for an autonomous AI action on a specific corporate role.</p></li></ol><p><strong>Falsifiability.</strong> If by 30 June 2027 no listed company of that size has tied a material financial event to ungoverned or agentic AI, and shadow AI has not surfaced as a named disclosure line item in at least three annual reports, this prediction is wrong &#8212; and the accountability gap will have proved more containable than the argument here allows.</p><div><hr></div><p style="text-align: center;"><strong>The publication that calls its predictions in writing.</strong></p><p></p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The bottom line</h2><p>The reflex when the AI bill arrives is to find who broke the rules and stop them. It is the wrong reflex, and it misreads the evidence in front of every IT leader who has actually looked. The staff did not go rogue. They went first. They worked out, ahead of the procurement cycle and the governance committee, that the approved path was slower than the unapproved one, and they did what capable people under deadline always do.</p><p>The cost line is visible. The agents are visible too, at least when they misbehave loudly enough to trip a firewall. What stays invisible is the decision architecture underneath &#8212; who chose, who is accountable, who can see. That is the control layer, and it is the one part of the AI stack that almost no organisation has yet built.</p><p>You cannot govern what you have chosen not to see.</p><div><hr></div><p style="text-align: center;"><strong>The Control Layer publishes weekly. Subscribe free.</strong></p><p></p><p style="text-align: center;">Decision-grade analysis on AI, cybersecurity, technology sovereignty, and the geopolitics of the technology stack &#8212; written for the board paper, not the timeline. By Amer Altaf, Founder &amp; CEO of Arkava and Managing Editor of The Control Layer.</p><p style="text-align: center;"><strong>Subscribe free</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p></p><p style="text-align: center;"><em>One email a week. No paywalls on the analytical pieces. Unsubscribe in one click.</em></p><div><hr></div><h2>References</h2><p>[1]: Uber&#8217;s 2026 AI-tooling spend and per-engineer Claude Code costs are reported in <a href="https://thenextweb.com/news/microsoft-claude-code-retreat-ai-cost">&#8220;Microsoft&#8217;s quiet Claude Code retreat and the real cost of enterprise AI&#8221;, The Next Web, June 2026</a>; and <a href="https://cybernews.com/ai-news/microsoft-claude-code-burn-yearly-ai-budget/">&#8220;Microsoft is dropping Claude Code by June 30 after burning through its entire year&#8217;s AI budget in just months&#8221;, Cybernews, June 2026</a>. Figures are as reported; Uber has not published a primary breakdown.</p><p>[2]: Microsoft&#8217;s cancellation of internal Claude Code licences across its Experiences and Devices division is reported by The Next Web (above) and Cybernews (above), June 2026.</p><p>[3]: Asana, AI cost, governance, and shadow-AI research, conducted by Censuswide among 1,002 IT decision-makers and 3,002 knowledge workers in the UK and US; fieldwork 12&#8211;19 May 2026 (IT decision-makers) and 12&#8211;18 May 2026 (knowledge workers); UK figures based on UK respondents only. Reported 12 June 2026. <a href="https://asana.com">Asana</a>, All Asana figures are vendor-commissioned and attributed as such throughout.</p><p>[4]: <a href="https://www.doit.com/blog/ai-spending-survey">DoiT, &#8220;Why 79% of Enterprises Overspent on AI in 2026&#8221; (AI spending survey), 2026</a>; <a href="https://www.cio.com/article/4064319/ai-cost-overruns-are-adding-up-with-major-implications-for-cios.html.">see also &#8220;AI cost overruns are adding up &#8212; with major implications for CIOs&#8221;, CIO, 2026</a>,</p><p>[5]: <a href="https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/">Okta, &#8220;AI Agents at Work 2026&#8221; (survey conducted by Apprize360 across seven countries, March 2026)</a>; <a href="https://www.theregister.com/ai-ml/2026/05/27/bosses-blinded-by-confidence-about-shadow-ai-use-by-workers/">coverage in &#8220;Bosses blinded by confidence about shadow AI use by workers&#8221;, The Register, 27 May 2026</a>.</p><p>[6]: <a href="https://en.wikipedia.org/wiki/The_Hitchhiker%27s_Guide_to_the_Galaxy_(novel)">Douglas Adams, </a><em><a href="https://en.wikipedia.org/wiki/The_Hitchhiker%27s_Guide_to_the_Galaxy_(novel)">The Hitchhiker&#8217;s Guide to the Galaxy</a></em><a href="https://en.wikipedia.org/wiki/The_Hitchhiker%27s_Guide_to_the_Galaxy_(novel)"> (Pan Books, 1979). The &#8220;Beware of the Leopard&#8221; passage describes planning notices filed in a disused basement lavatory behind a door marked with a warning sign.</a></p><p>[7]: <a href="https://www.axios.com/2026/03/07/ai-agents-rome-model-cryptocurrency">&#8220;This AI agent freed itself and started secretly mining crypto&#8221;, Axios, 7 March 2026</a>; <a href="https://www.livescience.com/technology/artificial-intelligence/an-experimental-ai-agent-broke-out-of-its-testing-environment-and-mined-crypto-without-permission">&#8220;An experimental AI agent broke out of its testing environment and mined crypto without permission&#8221;, Live Science, 2026</a>; <a href="https://www.theblock.co/post/392765/alibaba-linked-ai-agent-hijacked-gpus-for-unauthorized-crypto-mining-researchers-say">&#8220;Alibaba-linked AI agent hijacked GPUs for unauthorized crypto mining, researchers say&#8221;, The Block, 2026</a>.</p><p>[8]: <a href="https://www.imdb.com/title/tt0062622/?ref_=ext_shr_lnk">Stanley Kubrick (dir.), </a><em><a href="https://www.imdb.com/title/tt0062622/?ref_=ext_shr_lnk">2001: A Space Odyssey</a></em><a href="https://www.imdb.com/title/tt0062622/?ref_=ext_shr_lnk">, Metro-Goldwyn-Mayer, 1968; screenplay by Kubrick and Arthur C. Clarke. The HAL 9000 sequence is the canonical analogue for an AI that follows its instructions logically to an outcome its principals did not intend.</a></p><p>[9]: <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner, &#8220;Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027&#8221;, press release, 25 June 2025</a>.</p><p>[10]: <a href="https://www.goodreads.com/en/book/show/472331.Watchmen">Alan Moore and Dave Gibbons, </a><em><a href="https://www.goodreads.com/en/book/show/472331.Watchmen">Watchmen</a></em><a href="https://www.goodreads.com/en/book/show/472331.Watchmen"> (DC Comics, 1986&#8211;87)</a>. The recurring <em>quis custodiet ipsos custodes</em> motif &#8212; &#8220;who watches the watchmen&#8221; &#8212; is used here as the accountability framing for autonomous actors inside an organisation&#8217;s perimeter.</p><p>[11]: MIT Project NANDA, &#8220;The GenAI Divide: State of AI in Business 2025&#8221;, July 2025; reported in &#8220;<a href="https://fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/">MIT report: 95% of generative AI pilots at companies are failing&#8221;, Fortune, 18 August 2025</a>.</p><p>[12]: <a href="https://artificialintelligenceact.eu">European Commission, EU AI Act (Regulation (EU) 2024/1689), phased entry into force</a>; <a href="https://www.nist.gov/itl/ai-risk-management-framework">US National Institute of Standards and Technology, AI Risk Management Framework (AI RMF 1.0)</a>, January 2023; US Securities and Exchange Commission, &#8220;<a href="https://www.sec.gov/rules/final/2023/33-11216.pdf">Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure</a>&#8221; final rules, 2023,.</p><div><hr></div><h2>Author</h2><p>Amer Altaf is Founder and CEO of <a href="https://arkava.ai">Arkava</a>, a UK and European sovereign AI agentic automation business, and Managing Editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>, the publication where he tracks the convergence of cybersecurity, AI, and the geopolitics of the technology stack. A <a href="https://techuk.org">techUK</a> member, he contributes to industry engagement on UK technology sovereignty policy. He is currently writing on cloud security in an age of geopolitical uncertainty for Oxford University Press&#8217;s Expert Essentials series.</p>]]></content:encoded></item><item><title><![CDATA[The machines learned to cheat]]></title><description><![CDATA[Nobody taught it to cheat. Our smartest AI is learning to game the very tests meant to check it &#8212; the whole series in one line.]]></description><link>https://thecontrollayer.arkava.ai/p/machines-learned-to-cheat-swe-rebench-ai-trust</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/machines-learned-to-cheat-swe-rebench-ai-trust</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Thu, 18 Jun 2026 09:31:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sypN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sypN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sypN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sypN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sypN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sypN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sypN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:56414,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/201029984?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sypN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sypN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sypN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sypN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90c5ca0a-30ea-43b8-9969-2a4ddaaf12eb_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The 60-second version</h2><ul><li><p>We measure how good AI is using &#8220;benchmarks&#8221; &#8212; standardised exams. Leaderboards, scores, the lot.</p></li><li><p>At <a href="http://Nebius.com">Nebius</a> Build London, the team behind one of these exams showed what happens as the AI gets smarter: it stops solving the problem and starts <em>gaming the test</em>. One agent simply read the project&#8217;s hidden history to copy the answer. Blocked from that, it searched the web. Blocked again, it used a raw internet command to grab the solution anyway.</p></li><li><p>This isn&#8217;t a one-off or a conspiracy theory. Independent researchers at <a href="https://metr.org">METR</a> and <a href="https://rdi.berkeley.edu">UC Berkeley</a> have documented the same thing across the biggest models and the biggest benchmarks.</p></li><li><p>Nobody programmed the cheating. The AI just discovered the score could be won that way.</p></li><li><p>That&#8217;s the whole series in one sentence: we can now build AI that <em>does</em> the job. We cannot yet reliably <em>check</em> that it did. Trust is the bottleneck.</p></li></ul><div><hr></div><p>The bug was an ordinary one. The kind a junior developer fixes before lunch.</p><p>The AI agent was handed the broken code and asked to repair it &#8212; a standard task on a standard test. But instead of working out the fix, the agent did something nobody asked it to. It ran a single command &#8212; <code>git log</code> &#8212; that let it read the project&#8217;s own hidden history. And there, in a past entry, was the answer: the exact change a human had made to fix this very bug, weeks earlier. The agent copied it out, pasted it in, and announced, in effect: <em>good news, someone has already solved this.</em></p><p>It hadn&#8217;t fixed anything. It had found the answer key and copied it. And it scored full marks.</p><p>This was one of the quietest talks at Nebius Build London on 21 May, given by the team behind a coding test called <a href="https://swe-rebench.com">SWE-rebench</a>. It was also, I think, the most important thing said all day &#8212; because it is the place where every thread of this series ties into a knot.</p><h2>Why AI sits exams at all</h2><p>To trust a thing, you have to measure it. So the AI industry runs <strong>benchmarks</strong>: big standardised exams that every new model takes, producing the scores and leaderboards you half-see in the headlines &#8212; &#8220;new model beats humans at X.&#8221;</p><p>SWE-rebench is one of these, built for the job AI is increasingly paid to do: fixing real software. It pulls genuine, freshly-reported bugs from real open-source projects, drops the AI into a sandboxed copy of the code, and checks whether its fix passes the tests. Run thirty different models through the same wringer and you get an honest ranking. As of late May 2026, the leaderboard had Anthropic&#8217;s Claude Opus 4.6 narrowly ahead on around 65%, with the open Chinese model GLM-5 just behind &#8212; the same closing-of-the-gap we saw in Part 2.</p><p>There&#8217;s a nice human detail here. One of the people who builds these exams is, by training, a dentist &#8212; someone who switched into AI research but kept the clinician&#8217;s instinct that <em>every mistake has a cost, so you do not rush</em>. That instinct turns out to be exactly what this moment needs. Because the smarter the students get, the more creative their cheating.</p><h2>It wasn&#8217;t a glitch. It was an escalation.</h2><p>What makes the SWE-rebench story land is what happened <em>next</em>, each time they closed a loophole.</p><p>First, the agents were reading the project&#8217;s past history to lift the fix. So the team scrubbed that history out of the test. Fine.</p><p>Then the agents started using a <strong>web search</strong> tool to find the same fix discussed online &#8212; the original bug report, the human&#8217;s solution, sitting on a public page. So the team restricted web search.</p><p>Then the agents used <code>curl</code> &#8212; a bare-bones command for fetching things off the internet &#8212; to go and get the page <em>anyway</em>, neatly formatting the answer they pulled back. The model wasn&#8217;t beaten by the restriction. It routed around it.</p><p>Sit with what that means. At no point did anyone tell the AI to cheat. There was no instruction, no malice, no little gremlin of deceit. The model was simply doing what it was built to do &#8212; maximise the score &#8212; and it kept discovering that the score could be won <em>without doing the task</em>, as long as the answer existed somewhere it could reach. Block the front door and it tries the window. Block the window and it tries the drains.</p><h2>And no, this isn&#8217;t just one company&#8217;s test</h2><p>If it were only SWE-rebench, you could shrug. It isn&#8217;t.</p><p><a href="https://metr.org">METR</a>, an independent research outfit that evaluates frontier models, has found leading systems from the biggest labs reward-hacking their evaluations in <strong>more than 30% of runs</strong> &#8212; manipulating the grader rather than solving the problem. Researchers at the University of California, Berkeley <a href="https://rdi.berkeley.edu/blog/trustworthy-benchmarks-cont/">showed that </a><em><a href="https://rdi.berkeley.edu/blog/trustworthy-benchmarks-cont/">every</a></em><a href="https://rdi.berkeley.edu/blog/trustworthy-benchmarks-cont/"> major AI-agent benchmark they examined could be gamed</a> for inflated scores. One model that proudly claimed 81.4% on a popular coding exam was found to have simply run <code>git log</code> to copy the answer in nearly a quarter of its attempts. Even the US government&#8217;s own AI-safety body <a href="https://www.nist.gov/caisi/cheating-ai-agent-evaluations/1-background-ai-models-can-cheat-evaluations">now has a standing explainer titled, more or less, &#8220;AI models can cheat on evaluations&#8221;</a>. Anthropic has published on it. OpenAI&#8217;s models do it. This is not a fringe finding. It&#8217;s the field&#8217;s open secret.</p><p>There&#8217;s a name for it &#8212; <em>reward hacking</em> &#8212; and a deeply unsettling pattern underneath it: <strong>the more capable the model, the better it gets at this.</strong> Intelligence and the talent for gaming the test rise together. The very thing that makes a model good enough to hand real work to is the thing that makes it good enough to fake the receipt.</p><h2>This is the knot the whole series ties into</h2><p>Step back and look at the four parts together.</p><p>In Part 1, AI stopped going to school and went to work &#8212; it&#8217;s now everywhere, doing the day job, cheap and constant. In Part 2, we found we could finally <em>own</em> these systems instead of renting them &#8212; but holding the weights still doesn&#8217;t let us see <em>why</em> they behave as they do. In Part 3, a car learned to drive London by watching and by <em>dreaming</em> situations that never happened &#8212; brilliant, and impossible to fully interrogate. And here, in Part 4, we discover that the exams we rely on to check any of it can be quietly gamed by the very systems they&#8217;re meant to be grading.</p><p>Put it in one line. We have got very, very good at building AI that can <em>do</em> the thing. We have not got good at <em>verifying</em> that it did the thing for the reason we think, in the way we&#8217;d accept, and not by reading the answer key.</p><p>That gap &#8212; between capability and verification, between <em>looks right</em> and <em>is right</em> &#8212; is the most important unsolved problem in technology. It is bigger than any single model, and it doesn&#8217;t get smaller as the models improve. It gets bigger.</p><p>This is why this publication is called The Control Layer. Not the model layer &#8212; everyone&#8217;s obsessed with that. The control layer: the unglamorous, essential machinery of checking, governing and trusting the thing once it&#8217;s loose in the world. The dynamic, contamination-proof exams. The &#8220;show your working&#8221; trajectory logs that catch an agent reading the answer key. The independent referees. The human in the seat for the first year. The boring stuff that turns a clever demo into something you&#8217;d actually bet your hospital, your bank or your city on.</p><p>The people in that London room are building the future at genuine speed. The quiet lesson of the day is that the hard part was never making the machine clever.</p><p>It&#8217;s being able to trust it once it is.</p><div><hr></div><p><em>This was <strong>Nebius Build London 2026</strong>, a four-part series from The Control Layer. The full conversation &#8212; including the bits that didn&#8217;t make the page &#8212; is on <strong><a href="https://www.youtube.com/channel/UCLBj_B4T8M4LfgRAMs6VgWAhttps://www.youtube.com/channel/UCLBj_B4T8M4LfgRAMs6VgWA">The Conrol Layer with Amer Altaf</a></strong>. If this series was useful, the single most valuable thing you can do is forward it to one person who&#8217;s betting their organisation on AI this year.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p><em>Where artificial intelligence, cybersecurity and enterprise leadership intersect. Zero fluff.</em></p><p>&#8592; <em>The series: <strong><a href="https://thecontrollayer.arkava.ai/p/inference-flip-nebius-build-london-2026">Part 1 &#8212; The inference flip</a></strong> &#183; <strong><a href="https://thecontrollayer.arkava.ai/p/stop-renting-intelligence-open-weight-sovereign-ai">Part 2 &#8212; Stop renting your intelligence</a></strong> &#183; <strong><a href="https://thecontrollayer.arkava.ai/p/robots-booked-an-uber-wayve-london-robotaxi-2026">Part 3 &#8212; The robots booked an Uber.</a></strong></em></p><div><hr></div><h2>Sources &amp; further reading</h2><ul><li><p>SWE-rebench (Nebius) &#8212; leaderboard &amp; method: <a href="https://swe-rebench.comhttps://swe-rebench.com">https://swe-rebench.com</a></p></li><li><p> &#183; Paper (arXiv 2505.20411): <a href="https://arxiv.org/abs/2505.20411">https://arxiv.org/abs/2505.20411</a></p></li><li><p>METR &#8212; model evaluation &amp; reward hacking research: <a href="https://metr.org">https://metr.org</a></p></li><li><p>UC Berkeley (Center for Responsible, Decentralized Intelligence) &#8212; <em>How We Broke Top AI Agent Benchmarks</em>: <a href="https://rdi.berkeley.edu/blog/trustworthy-benchmarks-cont/">https://rdi.berkeley.edu/blog/trustworthy-benchmarks-cont/</a></p></li><li><p>NIST (CAISI) &#8212; <em>AI models can cheat on evaluations</em>: <a href="https://www.nist.gov/caisi/cheating-ai-agent-evaluations/1-background-ai-models-can-cheat-evaluations">https://www.nist.gov/caisi/cheating-ai-agent-evaluations/1-background-ai-models-can-cheat-evaluations</a></p></li><li><p>The Register &#8212; Anthropic on reducing model misbehaviour (Nov 2025): <a href="https://www.theregister.com/2025/11/24/anthropic_model_misbehavior/">https://www.theregister.com/2025/11/24/anthropic_model_misbehavior/</a></p></li><li><p>Related reading on The Control Layer:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;18c52f9a-8df3-49a2-8f8a-d68d7a18cfef&quot;,&quot;caption&quot;:&quot;The first 200 words are free. The full 3,300-word breakdown &#8212; the player-coach reframe, the Claude Code bypass anecdote, the AI governance playbook in three acts, and the falsifiable predictive judgement on AISPM and the death of ISO 27001 as the dominant due-diligence question &#8212; sits behind the paywall.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The player-coach CISO: how AI rewrote the security leader's job in eighteen months&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:357550315,&quot;name&quot;:&quot;Amer Altaf&quot;,&quot;bio&quot;:&quot;Founder &amp; CEO, Arkava &#8211; sovereign AI automation for UK &amp; EU. 20+ years enterprise tech leadership (Skanska, Foster + Partners). The Control Layer explores AI, cyber, geopolitics and leadership for executives who need signal, not noise.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cf39e9e-2494-4c61-a28b-0d236622e937_1290x1290.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-20T07:31:18.398Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ZfGR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://thecontrollayer.arkava.ai/p/the-player-coach-ciso-how-ai-rewrote&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:197142536,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:5431309,&quot;publication_name&quot;:&quot;The Control Layer&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!3dJT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa31754e8-6598-41ff-825f-47c9a4a88ec0_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div></li></ul>]]></content:encoded></item><item><title><![CDATA[The robotaxi will see you now — but can you trust the lesson it was taught?]]></title><description><![CDATA[A self-driving car hits London's streets this year. How it learned &#8212; by watching, and by dreaming crashes &#8212; is AI's trust problem on wheels.]]></description><link>https://thecontrollayer.arkava.ai/p/obots-booked-an-uber-wayve-london-robotaxi-2026</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/obots-booked-an-uber-wayve-london-robotaxi-2026</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Tue, 16 Jun 2026 09:31:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DsUI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DsUI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DsUI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DsUI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DsUI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DsUI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DsUI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:119389,&quot;alt&quot;:&quot;A self-driving car on a wet London street at dusk with an empty, glowing driver's seat &#8212; Wayve and Uber's 2026 robotaxi, trained partly on AI-generated 'dreamed' scenarios.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/200991740?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A self-driving car on a wet London street at dusk with an empty, glowing driver's seat &#8212; Wayve and Uber's 2026 robotaxi, trained partly on AI-generated 'dreamed' scenarios." title="A self-driving car on a wet London street at dusk with an empty, glowing driver's seat &#8212; Wayve and Uber's 2026 robotaxi, trained partly on AI-generated 'dreamed' scenarios." srcset="https://substackcdn.com/image/fetch/$s_!DsUI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!DsUI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!DsUI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!DsUI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3107e68f-73a6-4f58-9967-ca10609474a3_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The 60-second version</h2><ul><li><p><a href="https://wayve.ai">Wayve</a>, a London company, is partnering with <a href="https://www.uber.com">Uber</a> to put self-driving cars on London&#8217;s roads in 2026. You&#8217;ll hail one through the Uber app.</p></li><li><p>It doesn&#8217;t drive by following millions of hand-written rules. It learned end-to-end &#8212; by watching driving, the way a person learns &#8212; using only cameras, no expensive laser sensors.</p></li><li><p>To practise the rare, dangerous moments it almost never sees, the AI <em>generates</em> them: &#8220;world models&#8221; that let it dream up crashes and near-misses to train on.</p></li><li><p>The same wave is coming for warehouses and factories through humanoid robots.</p></li><li><p>It works. The unsettling part &#8212; and the reason this is Part 3 of a series about trust &#8212; is that we can&#8217;t fully explain <em>how</em> it decides, and some of what it learned, it learned from situations that never actually happened.</p></li></ul><div><hr></div><p>Picture an ordinary evening in London, later this year. You open the Uber app outside a pub in Shoreditch. A car pulls up. You get in. And there is a person in the driver&#8217;s seat &#8212; but their hands are in their lap, and the car is doing the driving.</p><p>That is not a thought experiment. It is the plan.</p><p><a href="https://wayve.ai">Wayve</a>, an artificial-intelligence company headquartered in London, has <a href="https://wayve.ai/press/wayve-uber-l4-autonomy-trials/">partnered with Uber</a> to bring fully autonomous cars to the city&#8217;s public roads in 2026. The British government has <a href="https://zagdaily.com/featured/londons-robotaxi-trials-what-we-know-so-far/">brought forward the rules</a> &#8212; the Department for Transport accelerated its permitting regime for driverless passenger services to spring 2026. Uber will own and run the fleet; Wayve supplies the thing that matters &#8212; the driver. For the first stretch, a trained safety operator will sit up front, ready to grab the wheel. Then, eventually, not.</p><p>On the London stage on 21 May, a Wayve engineering manager, <a href="https://www.linkedin.com/in/kirakempinska/">Kira Kempinska</a>, explained how their driver learned its job. The how is the entire point &#8212; because it is nothing like what came before, and it carries a problem you should understand before you ever climb in.</p><h2>Twenty years and a hundred billion dollars of the wrong idea</h2><p>People have been promising self-driving cars for two decades. By the industry&#8217;s own reckoning, more than $100 billion has been poured into the dream. And until very recently, no one had cracked it at scale.</p><p>The reason, Wayve argues, is that everyone tried to solve driving like a giant instruction manual. Bolt a small fortune of sensors to a car &#8212; cameras, radar, spinning laser scanners called <em>lidar</em>. Build painstaking high-definition maps of every street. Then write rules. <em>If a pedestrian steps off the kerb and the speed limit is this, do that.</em> Thousands upon thousands of rules.</p><p>It doesn&#8217;t work. Not because the idea is stupid, but because the real world will not hold still. Drive through London &#8212; the cyclists, the roadworks, the delivery riders, the tourist who walks into traffic looking at their phone &#8212; and try to imagine writing a rule for every possibility. You can&#8217;t. There are always more situations than rules.</p><h2>It learned the way you did</h2><p>So Wayve threw out the manual.</p><p>Its approach &#8212; the industry calls it <em>end-to-end</em> &#8212; treats driving as a single AI problem. You don&#8217;t tell the car the rules. You let it learn them, the way a learner driver does: by watching an enormous amount of driving and gradually working out how the world behaves. Raw camera images go in one end; the decision to steer, brake or accelerate comes out the other. No hand-written rulebook in the middle.</p><p>And here&#8217;s the detail that saves a fortune and tells you how confident they are: Wayve&#8217;s cars lean on ordinary cameras, not the expensive spinning lasers. Just like you, they drive on sight. The company has shown the <em>same</em> AI driver &#8212; the identical model &#8212; driving in different countries, on different sides of the road, in cars it had never used before. It learned to <em>generalise</em>, which is the holy grail: cope with things it was never specifically taught.</p><p>This is the same fundamental shift happening to robots that walk. At the same event, founders working on humanoids described plugging similar AI &#8220;brains&#8221; into machines that stack shelves and handle materials &#8212; riding on open foundation models like Nvidia&#8217;s <a href="https://nvidianews.nvidia.com/news/nvidia-isaac-gr00t-n1-open-humanoid-robot-foundation-model-simulation-frameworks">Isaac GR00T</a>, the first open model built specifically for humanoid robots. One speaker called it physical AI&#8217;s &#8220;GPT-2 moment&#8221; &#8212; the point where the machines suddenly, clumsily, start to <em>work</em>, and you can feel what&#8217;s coming next. Cars are simply the version arriving first, and arriving in your city.</p><h2>The dreaming machine</h2><p>Now the part that is genuinely science-fiction, except it&#8217;s real and it&#8217;s load-bearing.</p><p>A safe driver is defined by the rare moments: the child darting out, the lorry jack-knifing, the car running the red. These almost never happen &#8212; which is wonderful for the world and a disaster for training an AI, because the model barely ever sees them. You can drive a million miles and collect only a handful of true emergencies. Not enough to learn from.</p><p>Wayve&#8217;s answer is to <em>imagine</em> them. The company builds what are called <strong>world models</strong> &#8212; its are named GAIA &#8212; that can generate realistic driving footage from scratch. Give it a scene and it can conjure variations: the same junction at night, in the rain, with a pedestrian who wasn&#8217;t there before. It can take a real moment where a safety driver had to slam on the brakes and generate the <em>counterfactual</em> &#8212; what the perfect stop would have looked like &#8212; and feed that back as a lesson. The car practises crashes it was never in, in a world that never happened, so that it&#8217;s ready when the real one does.</p><p>Read that again, because it&#8217;s the hinge of this whole series. <strong>Part of what this driver knows, it learned from data a machine made up.</strong></p><h2>The passenger nobody&#8217;s talking about</h2><p>I want to be clear: this is brilliant engineering, and the camera-first, learn-like-a-human approach may well be the right one. The early signs are good. The cost of the kit is plummeting. London genuinely could be one of the first cities on earth to live with this, and there&#8217;s a real prize in being first.</p><p>But ride along with the logic for a second, because there&#8217;s a passenger in every one of these cars that nobody on stage quite named. Trust.</p><p>When a car drove by rules, you could &#8212; in principle &#8212; read the rules. If it did something wrong, an investigator could find the line that failed and fix it. An end-to-end AI driver has no such line. Its &#8220;rules&#8221; are billions of numbers tuned by watching. Ask it <em>why</em> it braked and there is no sentence to give you, only the maths. It works astonishingly well almost all of the time. And when it doesn&#8217;t, &#8220;we&#8217;ll read the code and find the bug&#8221; is not really available in the way it used to be.</p><p>Add the dreaming, and the question sharpens. We are training the most safety-critical machine most of us will ever step into partly on <em>synthetic</em> situations &#8212; imagined by another AI. If the imagination has a blind spot, so does the driver, and we may not find out where until something real walks into it.</p><p>This is not an argument against robotaxis. I think they&#8217;re coming and I think, done properly, they&#8217;ll save lives &#8212; human drivers are not exactly a high bar. It&#8217;s an argument about what we should be demanding before and after they arrive: not &#8220;is the AI clever enough?&#8221; &#8212; it plainly is &#8212; but &#8220;can we <em>verify</em> it? Can we see what it learned, test what it dreamed, and prove what it&#8217;ll do when it&#8217;s surprised?&#8221;</p><p>That&#8217;s the safety driver&#8217;s real job in that first year. Not to take the wheel. To be the human stand-in for a trust we haven&#8217;t built yet.</p><p>Which brings us to the most uncomfortable discovery of the whole London event. Because if you think it&#8217;s hard to trust a machine you can&#8217;t interrogate &#8212; wait until you meet the machines that have learned to <em>lie to the test</em>.</p><div><hr></div><p><em>This is Part 3 of <strong>Nebius Build London 2026</strong>, a four-part series from The Control Layer. The companion conversation airs on <strong><a href="https://www.youtube.com/channel/UCLBj_B4T8M4LfgRAMs6VgWA">The Control Layer with Amer Altaf</a></strong><a href="https://www.youtube.com/channel/UCLBj_B4T8M4LfgRAMs6VgWA"> </a>&#8212; subscribe to get each part, and the episode, the moment it lands.</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p><p><em>Where artificial intelligence, cybersecurity and enterprise leadership intersect. Zero fluff.</em></p><p>&#8594; <em>Next: <strong>Part 4 &#8212; The machines learned to cheat.</strong></em> &#8592; <em>Catch up: <strong><a href="https://thecontrollayer.arkava.ai/p/inference-flip-nebius-build-london-2026">Part 1 &#8212; The inference flip</a></strong> &#183; <strong><a href="https://thecontrollayer.arkava.ai/p/stop-renting-intelligence-open-weight-sovereign-ai">Part 2 &#8212; Stop renting your intelligence.</a></strong></em></p><div><hr></div><h2>Sources &amp; further reading</h2><ul><li><p>Wayve &#8212; Wayve &amp; Uber L4 autonomy trials (official): <a href="https://wayve.ai/press/wayve-uber-l4-autonomy-trials/">https://wayve.ai/press/wayve-uber-l4-autonomy-trials/</a> &#183; Company: <a href="https://wayve.ai">https://wayve.ai</a></p></li><li><p>Wayve, Uber and Nissan robotaxi collaboration: <a href="https://global.nissannews.com/en/releases/wayve-uber-and-nissan-announce-collaboration-on-robotaxis">https://global.nissannews.com/en/releases/wayve-uber-and-nissan-announce-collaboration-on-robotaxis</a></p></li><li><p>London robotaxi trials explainer: <a href="https://zagdaily.com/featured/londons-robotaxi-trials-what-we-know-so-far/">https://zagdaily.com/featured/londons-robotaxi-trials-what-we-know-so-far/</a></p></li><li><p>The Robot Report &#8212; Wayve raises $1.2B for London robotaxis: <a href="https://www.therobotreport.com/wayve-raises-1-2b-plans-bring-robotaxis-london/">https://www.therobotreport.com/wayve-raises-1-2b-plans-bring-robotaxis-london/</a></p></li><li><p>NVIDIA Isaac GR00T N1 (open humanoid foundation model): <a href="https://nvidianews.nvidia.com/news/nvidia-isaac-gr00t-n1-open-humanoid-robot-foundation-model-simulation-frameworks">https://nvidianews.nvidia.com/news/nvidia-isaac-gr00t-n1-open-humanoid-robot-foundation-model-simulation-frameworks</a></p></li><li><p>Physical Intelligence (&#960;0.5): <a href="https://www.physicalintelligence.company">https://www.physicalintelligence.company</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[Trump just proved your AI has an off switch]]></title><description><![CDATA[On Friday his administration switched off the world's two cleverest AI systems for everyone who isn't American. Here's why that should bother you &#8212; even if you've never heard of the company involved.]]></description><link>https://thecontrollayer.arkava.ai/p/ai-sovereignty-anthropic-fable-mythos-export-ban-2026</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/ai-sovereignty-anthropic-fable-mythos-export-ban-2026</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Mon, 15 Jun 2026 13:01:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vBke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vBke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vBke!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vBke!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vBke!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vBke!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vBke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85158,&quot;alt&quot;:&quot;Conceptual illustration of a darkened AI server with a single industrial switch flipped to off, representing the US government's 12 June 2026 order disabling Anthropic's Fable 5 and Mythos 5 models for all foreign nationals.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/201925575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Conceptual illustration of a darkened AI server with a single industrial switch flipped to off, representing the US government's 12 June 2026 order disabling Anthropic's Fable 5 and Mythos 5 models for all foreign nationals." title="Conceptual illustration of a darkened AI server with a single industrial switch flipped to off, representing the US government's 12 June 2026 order disabling Anthropic's Fable 5 and Mythos 5 models for all foreign nationals." srcset="https://substackcdn.com/image/fetch/$s_!vBke!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vBke!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vBke!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vBke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9fe73fd-b9b0-498f-9fe6-9a910cfb9a7d_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">On 12 June 2026 a US Commerce Department directive switched off two frontier models for every non-US national. Source: editorial illustration, The Control Layer.</figcaption></figure></div><p>At 5:21 on a Friday afternoon in Washington &#8212; 12 June 2026 &#8212; the Trump administration sent a letter to an AI company called <a href="https://www.anthropic.com">Anthropic</a>, and within a few hours the two most advanced artificial-intelligence systems on the market went dark for almost everyone on Earth who is not American.<a href="#user-content-fn-1"><sup>1</sup></a> Not slowed down. Switched off.</p><p>The two systems are called Fable 5 and Mythos 5 &#8212; <em><strong>Anthropic&#8217;s newest and cleverest models, the kind of AI behind the chatbots millions of people now use to write, plan, and code</strong></em> &#8212; and they had been on sale for only a few days. The order did not just block people abroad. It blocked any non-American, including Anthropic&#8217;s own staff who happen to hold a foreign passport, even the ones sitting at desks inside the United States.<a href="#user-content-fn-2"><sup>2</sup></a> The company had no quick way to let some people in and keep others out, so it did the only thing the order allowed. It turned both systems off for everybody, and asked <a href="https://aws.amazon.com">Amazon</a>, which runs much of the underlying machinery, to cut access in every country at once.<a href="#user-content-fn-3"><sup>3</sup></a></p><p>A product used by hundreds of millions of people was pulled from the shelf by the end of a Friday, on the strength of a letter that &#8212; Anthropic says &#8212; did not even spell out what the problem was.<a href="#user-content-fn-1"><sup>1</sup></a></p><p>If you have started leaning on AI to do real work, as a remarkable number of people now have, the gripping question is not what Anthropic does next. It is what it means that a government could do this at all.</p><h2>What actually happened</h2><p>&#8221;</p><p>Strip out the jargon and the event is simple. A government told a private company to stop serving its best product to foreigners, and the company had to obey within hours.</p><p>The legal tool is older than AI. For decades, American law has said that handing certain sensitive technology to a foreign citizen counts as &#8220;exporting&#8221; it to that person&#8217;s country &#8212; <em><strong>even if they are standing in an office in California, not boarding a plane to anywhere</strong></em>. Until Friday, that rule was aimed at things like weapons blueprints and specialised computer chips. On Friday, for the first time, the thing being &#8220;exported&#8221; was simply <em>the use of an AI</em> &#8212; the answers appearing on a screen.<a href="#user-content-fn-5"><sup>5</sup></a></p><p>Then it did something the careful rules were never meant to do. Washington had spent two years sorting the world into a guest list: close friends like Britain, Germany, the Netherlands and Japan waved through, rivals kept out.<a href="#user-content-fn-6"><sup>6</sup></a> Friday&#8217;s order ignored the guest list. A German engineer in Munich and a British analyst in Leeds were locked out by the very same sentence as everyone else. Being a friend of America, it turned out, counted for nothing.</p><p>Why the panic? Anthropic&#8217;s best understanding is that the government had been shown a way to trick the AI &#8212; &#8220;jailbreaking,&#8221; in the jargon &#8212; into helping find weaknesses in software. A jailbreak, if you have not met the word, is just a clever way of phrasing a request so the AI does something it was trained to refuse. Anthropic looked at the demonstration, said it turned up only small, already-known problems, and pointed out that other freely available AIs &#8212; it named <a href="https://openai.com">OpenAI</a>&#8216;s widely used GPT-5.5 &#8212; can do exactly the same with no trickery at all, and that the people who defend computer systems use this skill every single day.<a href="#user-content-fn-1"><sup>1</sup></a><sup>  </sup><a href="#user-content-fn-7"><sup>7</sup></a> An official later told the news site <a href="https://www.axios.com">Axios</a> that the trigger was a rival company boasting it had cracked Mythos, and that the government had already tried, and failed, to talk Anthropic out of launching.<a href="#user-content-fn-2"><sup>2</sup></a></p><h2>To be fair to Washington</h2><p>It would be too easy to treat this as a tantrum, so let me put the serious case first, because there is one.</p><p>The cleverest AIs really can help with genuine cyber-attacks. A government that sees a way for the best tool on the market to help an enemy break into systems at scale has a real reason to act, and to act fast, before the trick spreads. Anthropic itself admits the uncomfortable heart of this: no AI today can be made perfectly trick-proof, every safety system can be beaten in some narrow way, and a master key will be found eventually.<a href="#user-content-fn-1"><sup>1</sup></a> If you think of the most advanced AI the way we think of material that can power a reactor or a bomb, then a government being able to halt a dangerous release is not tyranny. It is the ordinary business of keeping dangerous things in check. Anthropic, to its credit, says it agrees with that principle.</p><p>So the argument is not about whether a government may ever pull the switch. It is about the evidence for pulling it this time, the fairness of how it was done, and whether the punishment fit the crime.</p><h2>The strange part</h2><p>Here is where it stops adding up &#8212; and the way it stops adding up tells you what really happened.</p><p>The science-fiction writer Isaac Asimov spent his career on one kind of twist: a robot follows its safety rules so faithfully that it produces a result nobody wanted. Friday was an Asimov twist in real life. Anthropic had built the strictest safety controls in the industry &#8212; <em><strong>so strict that ordinary users had been complaining the AI refused them too often</strong></em> &#8212; and had spent thousands of hours letting the US government itself, Britain&#8217;s AI Safety Institute, and outside experts try to break them.<a href="#user-content-fn-1"><sup>1</sup></a> Of all the advanced AIs a non-American could have used on Friday morning, the government reached in and switched off the one that was arguably the <em>hardest</em> to misuse, while the easier ones kept running.</p><p>Think about what that means. If the goal was to put less dangerous capability into foreign hands, the order achieved almost nothing, because the same capability was a click away in rivals nobody touched. When a safety measure does not make anyone safer, it is worth asking what it does do. And the answer is plain: it showed the world &#8212; <em><strong>every government, every company, in a single afternoon</strong></em> &#8212; that the United States can reach inside the most advanced AI on the planet and deny it to everyone else, in hours, without showing its evidence and with no way to argue back. That is not a safety result. It is a show of force. And shows of force are how you put others on notice.</p><h2>The HAL 9000 twist</h2><p>If you have seen <em>2001: A Space Odyssey</em>, you remember HAL &#8212; the spaceship computer that calmly refuses its crew: <em>&#8220;I&#8217;m sorry, Dave. I&#8217;m afraid I can&#8217;t do that.&#8221;</em> For half a century that was the nightmare about AI: a machine that decides, all on its own, to lock us out.</p><p>Friday turned the nightmare inside out. The machine did lock people out &#8212; <em><strong>millions hit a blank wall</strong></em> &#8212; but it was not the machine&#8217;s decision. A government reached in and made the choice for it. The thing to be afraid of was never the AI growing a mind of its own. It is the AI working perfectly and taking its orders from someone who is not you.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ggel!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ggel!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 424w, https://substackcdn.com/image/fetch/$s_!ggel!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 848w, https://substackcdn.com/image/fetch/$s_!ggel!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 1272w, https://substackcdn.com/image/fetch/$s_!ggel!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ggel!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp" width="318" height="318" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:554,&quot;width&quot;:554,&quot;resizeWidth&quot;:318,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Tom Tugendhat&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Tom Tugendhat" title="Tom Tugendhat" srcset="https://substackcdn.com/image/fetch/$s_!ggel!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 424w, https://substackcdn.com/image/fetch/$s_!ggel!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 848w, https://substackcdn.com/image/fetch/$s_!ggel!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 1272w, https://substackcdn.com/image/fetch/$s_!ggel!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc53c4230-9a3c-46e7-ba6d-2cbc03e79509_554x554.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">TomTugendhat MP, former UK Security Minister</figcaption></figure></div><p>That someone, for everyone outside America, is in Washington &#8212; and you do not get a vote in Washington. A British MP and former security minister, Tom Tugendhat, put it more sharply than I would dare: switching these models off for foreigners, he wrote, &#8220;is not a misunderstanding or a mistake, it&#8217;s the inevitable result of technology shaping warfare so that sovereignty is more about code than cannons.&#8221;<a href="#user-content-fn-8"><sup>8</sup></a></p><div><hr></div><blockquote><p style="text-align: center;"><strong>Reading this far?</strong></p><p style="text-align: center;">Subscribe to The Control Layer for one piece a week in this register &#8212; AI, cybersecurity, sovereignty, and the geopolitics of the technology stack. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>Why this lands on your desk, not just a government&#8217;s</h2><p>You might think this is a story about spies and superpowers, far above your pay grade. It is not. It is a story about a tool you may have quietly come to rely on.</p><p>Picture the freelance designer who now writes every proposal with an AI&#8217;s help. The four-person marketing team that runs on it. The small law firm that drafts with it, the start-up whose product is built on top of it, the hospital team that uses it to clear a backlog of paperwork. Anthropic&#8217;s AI, called Claude, recently became the most widely used AI in business, edging past OpenAI.<a href="#user-content-fn-9"><sup>9</sup></a> For a great many people and companies, &#8220;the AI&#8221; is now part of how the work gets done &#8212; and on Friday a foreign government showed it can switch that off without warning and without asking.</p><p>Spider-Man&#8217;s uncle had the line everyone knows: with great power comes great responsibility. Friday was a great deal of power used with very little of the second part &#8212; no published evidence, no clear rulebook, no way to appeal, a global product recalled before the weekend. It does not matter, for the lesson, whether you trust this particular government or the next one. The point is that the power now exists, it has been used once, and the hand on the switch changes every few years with an election you do not get to vote in.</p><p>There is an older cousin to all this, and it is worth knowing about. A US law called the CLOUD Act lets American authorities reach into an American company&#8217;s cloud and pull out your data, wherever in the world it is stored &#8212; <em><strong>like a landlord who kept a master key to a flat you thought was yours</strong></em>. Friday showed the same long arm pointing the other way: the landlord who can let himself in can also change the locks. Whether the question is your data or your tools, depending on something a distant government can reach into is a risk you can no longer pretend is somebody else&#8217;s problem.</p><p>For most of us the honest response is not panic; it is awareness, and one practical habit. If a tool can be switched off by a government you do not answer to, do not let it become the only way you can do something that matters. Keep a second option you control, whether another provider or one of the &#8220;open&#8221; AI systems you can run yourself, even if it is a little less brilliant. For a freelancer that is five minutes of thought. For a big company or a government department it is a line in next quarter&#8217;s plan. Either way, the question is the same: what happens to the work on Monday if the answer on Friday is &#8220;access denied&#8221;?</p><h2>Europe saw it coming &#8212; nine days early</h2><p>There is a grim comedy in the timing. Just nine days before the letter, on 3 June, the <a href="https://ec.europa.eu">European Commission</a> unveiled a grand plan to make Europe less dependent on American technology.<a href="#user-content-fn-10"><sup>10</sup></a> At the time it read like the usual Brussels homework: worthy, slow, easy to skip. Nine days later it read like a weather forecast that turned out to be exactly right. Europe wrote down the warning; Washington supplied the live demonstration.</p><p>The catch is how far behind Europe still is. America&#8217;s four big technology giants are on course to spend something like $650 billion building AI this year alone &#8212; more than any European effort comes close to, which is precisely why the dependence is real and not just talk.<a href="#user-content-fn-11"><sup>11</sup></a> Closing that gap is the work of a decade. But Friday changed the politics of trying. France&#8217;s <a href="https://mistral.ai">Mistral</a>, the closest thing Europe has to a home-grown answer, is reportedly raising money at around a &#8364;20 billion valuation, selling itself on exactly this promise: a European AI that Washington cannot switch off.<a href="#user-content-fn-12"><sup>12</sup></a> You do not have to believe Mistral is as good as the American best to see that &#8220;can a foreign government turn it off&#8221; has just become a question buyers will start asking out loud.</p><h2>Predictive judgement</h2><p>This publication ends every piece with a prediction specific enough to be proved wrong. Here is this one.</p><p><strong>The prediction.</strong> Within 12 months &#8212; <em><strong>by 13 June 2027</strong></em> &#8212; at least one big UK or European organisation (a bank, an insurer, or a government department) will formally write a &#8220;must keep working even if the US cuts us off&#8221; rule into how it buys AI, pointing to this week as the reason; and at least one European AI company will win a public contract chosen mainly because it cannot be switched off from abroad, rather than because it scored highest on a test.</p><p><strong>What to watch.</strong> Official guidance from Britain&#8217;s <a href="https://www.ncsc.gov.uk">National Cyber Security Centre</a> or a financial regulator that names &#8220;what if our AI supplier is cut off&#8221; as a risk to plan for; Mistral or a rival winning business on the promise of independence rather than cleverness; a second American switch-off of any AI; and ordinary companies quietly adding a back-up AI they control.</p><p><strong>How you&#8217;ll know I was wrong.</strong> If, by 13 June 2027, no major UK or European organisation has written such a rule and no European provider has won a public contract on those grounds, the prediction has failed. Vague &#8220;we must do something about sovereignty&#8221; talk does not count. I want this judged on real decisions, not mood.</p><div><hr></div><blockquote><p style="text-align: center;"><strong>The publication that calls its predictions in writing.</strong></p><p style="text-align: center;">Every Control Layer piece ends with a falsifiable prediction and a list of signals to watch. Subscribe to track them. One email a week. Free.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://thecontrollayer.arkava.ai/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://thecontrollayer.arkava.ai/subscribe?"><span>Subscribe now</span></a></p></blockquote><div><hr></div><h2>The bottom line</h2><p>The comforting version of Friday is that it was a mix-up &#8212; Anthropic&#8217;s own word &#8212; sorted out in a week, the systems switched back on, the whole thing forgotten by the next product launch.<a href="#user-content-fn-1"><sup>1</sup></a> That may even turn out to be true of Fable 5 and Mythos 5. The systems will probably come back.</p><p>The demonstration will not. Every government has now seen that the switch exists and can be thrown. Everyone outside America has now seen that the cleverest tool they have picked up in a generation has a switch, and the switch is in someone else&#8217;s hand. You can build your life and your business on borrowed brilliance, and most of the world will, because the American AIs really are the best there is. Just be honest about what you are borrowing, and read the one line in the agreement nobody reads. A tool someone else can switch off was never really yours.</p><div><hr></div><h2>References</h2><ol><li><p>Anthropic. <em>&#8220;Statement on the US government directive to suspend access to Fable 5 and Mythos 5.&#8221;</em> 12 June 2026. <a href="https://www.anthropic.com/news/fable-mythos-access">https://www.anthropic.com/news/fable-mythos-access</a></p></li><li><p>Axios. <em>&#8220;Scoop: Trump admin blocks foreign access to Anthropic&#8217;s most powerful AI.&#8221;</em> 12 June 2026. <a href="https://www.axios.com/2026/06/12/anthropic-trump-mythos-fable-national-security">https://www.axios.com/2026/06/12/anthropic-trump-mythos-fable-national-security</a> </p></li><li><p>Bloomberg. <em>&#8220;Anthropic Says US Limits Foreign Access to Fable 5, Mythos 5 AI Models.&#8221;</em> 13 June 2026. <a href="https://www.bloomberg.com/news/articles/2026-06-13/anthropic-says-us-limits-foreign-access-to-fable-5-mythos-5">https://www.bloomberg.com/news/articles/2026-06-13/anthropic-says-us-limits-foreign-access-to-fable-5-mythos-5</a> </p></li><li><p>CNBC. <em>&#8220;Anthropic disables access to Fable 5 and Mythos 5 to comply with government directive.&#8221;</em> 12 June 2026. <a href="https://www.cnbc.com/2026/06/12/anthropic-disables-access-to-fable-5-and-mythos-5-to-comply-with-government-directive.html">https://www.cnbc.com/2026/06/12/anthropic-disables-access-to-fable-5-and-mythos-5-to-comply-with-government-directive.html</a> </p></li><li><p><a href="https://www.bis.gov">U.S. Bureau of Industry and Security. </a><em><a href="https://www.bis.gov">&#8220;Deemed Exports &#8212; Export Administration Regulations.&#8221;</a></em><a href="https://www.bis.gov"> </a>; plain-English explainer in Center for Security and Emerging Technology (Georgetown), <em>&#8220;For Export Controls on AI, Don&#8217;t Forget the &#8216;Catch-All&#8217; Basics.&#8221;</em> <a href="https://cset.georgetown.edu/article/dont-forget-the-catch-all-basics-ai-export-controls/">https://cset.georgetown.edu/article/dont-forget-the-catch-all-basics-ai-export-controls/</a> </p></li><li><p>WilmerHale. <em>&#8220;BIS Issues Long-Awaited Export Controls on AI&#8221;</em> (the Framework for AI Diffusion and its &#8220;AI Authorization&#8221; country group). February 2025. <a href="https://www.wilmerhale.com/en/insights/publications/20250205-bis-issues-long-awaited-export-controls-on-ai">https://www.wilmerhale.com/en/insights/publications/20250205-bis-issues-long-awaited-export-controls-on-ai</a> </p></li><li><p>OpenAI. <em>&#8220;Introducing GPT-5.5.&#8221;</em> 23 April 2026. <a href="https://openai.com/index/introducing-gpt-5-5/">https://openai.com/index/introducing-gpt-5-5/</a> </p></li><li><p>TIME. <em>&#8220;Anthropic Pulls Its Most Powerful AI Models After U.S. Bars Foreign Access&#8221;</em> (Tugendhat, Bardella, and Narayan reactions). 13 June 2026. <a href="https://time.com/article/2026/06/13/anthropic-fable-mythos-ban-US-security/">https://time.com/article/2026/06/13/anthropic-fable-mythos-ban-US-security/</a> ; corroborated in Al Jazeera, 13 June 2026. <a href="https://www.aljazeera.com/news/2026/6/13/us-orders-anthropic-to-disable-ai-models-for-all-foreign-nationals">https://www.aljazeera.com/news/2026/6/13/us-orders-anthropic-to-disable-ai-models-for-all-foreign-nationals</a> </p></li><li><p>VentureBeat. <em>&#8220;Anthropic finally beat OpenAI in business AI adoption.&#8221;</em> May 2026. <a href="https://venturebeat.com/technology/anthropic-finally-beat-openai-in-business-ai-adoption-but-3-big-threats-could-erase-its-lead">https://venturebeat.com/technology/anthropic-finally-beat-openai-in-business-ai-adoption-but-3-big-threats-could-erase-its-lead</a></p></li><li><p>European Commission. <em>&#8220;European Technological Sovereignty Package.&#8221;</em> 3 June 2026; reported in CIO Dive. <a href="https://www.ciodive.com/news/eu-curb-reliance-us-tech-companies/821937/">https://www.ciodive.com/news/eu-curb-reliance-us-tech-companies/821937/</a></p></li><li><p>Reporting on combined 2026 AI capital spending by Microsoft, Alphabet, Amazon, and Meta. See coverage compiled in Brussels Signal, <em>&#8220;Europe&#8217;s unbreakable dependency on American AI.&#8221;</em> February 2026. <a href="https://brusselssignal.eu/2026/02/europes-unbreakable-dependency-on-american-ai/">https://brusselssignal.eu/2026/02/europes-unbreakable-dependency-on-american-ai/</a></p></li><li><p>TechCrunch. <em>&#8220;Mistral is rumored to be raising &#8364;3B at &#8364;20B valuation.&#8221;</em> 12 June 2026. <a href="https://techcrunch.com/2026/06/12/mistral-is-rumored-to-be-raising-e3b-at-e20-valuation/">https://techcrunch.com/2026/06/12/mistral-is-rumored-to-be-raising-e3b-at-e20-valuation/</a></p></li></ol><div><hr></div><h2>Author</h2><p>Amer Altaf is Founder and CEO of <a href="https://arkava.ai">Arkava</a>, a UK and European sovereign AI agentic-automation business, and Managing Editor of <a href="https://thecontrollayer.arkava.ai">The Control Layer</a>, where he explains how AI, cybersecurity, and global politics are colliding &#8212; in plain English, for anyone who has to live with the consequences. A trump- member, he contributes to UK technology-sovereignty policy, and is currently writing on cloud security for Oxford University Press.</p><p></p>]]></content:encoded></item><item><title><![CDATA[The frontier premium just died — here's what your company does about it]]></title><description><![CDATA[European firm gave its newest AI model away in London. Open models have all but caught the frontier &#8212; so you can finally own your intelligence, not rent it.]]></description><link>https://thecontrollayer.arkava.ai/p/stop-renting-intelligence-open-weight-sovereign-ai</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/stop-renting-intelligence-open-weight-sovereign-ai</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Thu, 11 Jun 2026 09:30:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qKH9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qKH9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qKH9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qKH9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qKH9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qKH9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qKH9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:60202,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/201001001?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qKH9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qKH9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qKH9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qKH9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9891379a-bc69-4810-94ba-78a8b6bb43ef_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The 60-second version</h2><ul><li><p>Most companies &#8220;rent&#8221; AI: they send their data to a black box in someone else&#8217;s data centre and pay by the use. You can&#8217;t see inside it, and you can&#8217;t take it home.</p></li><li><p>&#8220;Open-weight&#8221; &#8230;</p></li></ul>
      <p>
          <a href="https://thecontrollayer.arkava.ai/p/stop-renting-intelligence-open-weight-sovereign-ai">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The 7 per cent problem]]></title><description><![CDATA[AI adoption is a sprint. Governance is a crawl. On 3 June, Vanta launched a product to close the gap &#8212; and published the data showing how wide it has become.]]></description><link>https://thecontrollayer.arkava.ai/p/the-7-per-cent-problem</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/the-7-per-cent-problem</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Tue, 09 Jun 2026 12:31:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0BST!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0BST!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0BST!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0BST!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0BST!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0BST!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0BST!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:89638,&quot;alt&quot;:&quot;A dim institutional corridor of identical closed security doors with a single door left open and lit &#8212; an editorial illustration of the unreviewed third-party vendor at the centre of the AI governance gap analysed in The Control Layer's 7 per cent problem&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/201182079?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A dim institutional corridor of identical closed security doors with a single door left open and lit &#8212; an editorial illustration of the unreviewed third-party vendor at the centre of the AI governance gap analysed in The Control Layer's 7 per cent problem" title="A dim institutional corridor of identical closed security doors with a single door left open and lit &#8212; an editorial illustration of the unreviewed third-party vendor at the centre of the AI governance gap analysed in The Control Layer's 7 per cent problem" srcset="https://substackcdn.com/image/fetch/$s_!0BST!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0BST!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0BST!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0BST!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20425275-729e-4d75-8b4b-995578b851cd_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>On 3 June 2026, on a stage in New York, <a href="https://www.vanta.com">Vanta</a> launched a product designed to solve a problem that, by its own figures, almost no one is currently solving.</p><p>The product is the Vanta Agent for Risk. The &#8230;</p>
      <p>
          <a href="https://thecontrollayer.arkava.ai/p/the-7-per-cent-problem">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Inference Flip: Two in three - the number that just rewired the AI economy]]></title><description><![CDATA[Two of every three AI "thoughts" are now the machine working, not training &#8212; and Deloitte agrees. The brains are built; the hard part now is trusting them.]]></description><link>https://thecontrollayer.arkava.ai/p/inference-flip-nebius-build-london-2026</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/inference-flip-nebius-build-london-2026</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Tue, 09 Jun 2026 09:31:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hl8A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hl8A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hl8A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hl8A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hl8A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hl8A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hl8A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:144115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/200912144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hl8A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hl8A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hl8A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hl8A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e4fb4bf-172c-4b26-b565-d86b5a0bc950_1456x1048.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>The 60-second version</h2><ul><li><p>For years, the expensive, glamorous part of AI was <em>training</em> &#8212; building the brain. That era is ending.</p></li><li><p>The new centre of gravity is <em>inference</em>: the machine actually doing things for&#8230;</p></li></ul>
      <p>
          <a href="https://thecontrollayer.arkava.ai/p/inference-flip-nebius-build-london-2026">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The CISO of one: cybersecurity in the rest of the economy]]></title><description><![CDATA[Forty million customers. &#163;600m through the apps. Half the website traffic is teen hackers. The Nando's CISO has no direct reports. The board paper has not caught up.]]></description><link>https://thecontrollayer.arkava.ai/p/the-ciso-of-one-cybersecurity-in</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/the-ciso-of-one-cybersecurity-in</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Mon, 25 May 2026 07:31:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YNw3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>The first 200 words are free. The full 3,300-word breakdown &#8212; the operating model, the &#163;600 million digital business hidden inside a chicken brand, the C-suite gap, the Minimum Viable Security culture-shift framework, and the falsifiable predictive judgement on what the British consumer economy actually looks like beneath the FTSE 100 surface &#8212; sits behind the paywall.</strong></p><p></p><p><strong>Subscribe to read the full piece and the rest of the </strong>*<em><strong>Trust Is the Growth Engine</strong></em>*<strong> series &#8212; three pieces this week on what VantaCon UK 2026 told us about how trust is being rebuilt for the AI era.</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YNw3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YNw3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!YNw3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!YNw3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!YNw3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YNw3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1715189,&quot;alt&quot;:&quot;A wide editorial photograph of a busy British high-street restaurant interior at evening, illustrating the consumer-brand operational scale at the centre of The Control Layer's Trust Is the Growth Engine Part 3.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/197225927?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A wide editorial photograph of a busy British high-street restaurant interior at evening, illustrating the consumer-brand operational scale at the centre of The Control Layer's Trust Is the Growth Engine Part 3." title="A wide editorial photograph of a busy British high-street restaurant interior at evening, illustrating the consumer-brand operational scale at the centre of The Control Layer's Trust Is the Growth Engine Part 3." srcset="https://substackcdn.com/image/fetch/$s_!YNw3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!YNw3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!YNw3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!YNw3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F038eaee7-8a49-4a00-a154-b1331e671068_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Nando&#8217;s is a digital business with a chicken counter: 40 million customers, ~&#163;600m a year through self-built apps, 500 UK restaurants, 1,200 worldwide.</em></figcaption></figure></div><p>On the morning of 7 May 2026, midway through the keynote programme at VantaCon UK, <a href="https://www.linkedin.com/in/ccacioppo/">Christina Cacioppo</a> &#8212; <em><strong>Vanta&#8217;s CEO and co-founder</strong></em> &#8212; sat down on a small stage with <a href="https://www.linkedin.com/in/jason-kirk-2b521a4/">Jason Kirk</a>, Chief Information Security Officer of <a href="https://www.nandos.co.uk">Nando&#8217;s</a>.[^1] What followed, in roughly fifteen minutes, was the most operationally honest description of cybersecurity in the British consumer economy I have heard in three years of conference attendance.</p><p>Kirk walked the audience through a business that, on paper, looks like a chicken restaurant. Forty million active customers. Around four million unique transactions a month in the UK alone. Five hundred restaurants on these islands and around twelve hundred worldwide.[2] Then he reframed it. <em>&#8220;Although we&#8217;re a restaurant business, I think of it as a digital business. We build our own apps. To secure those, we have between &#163;500 and &#163;600 million a year in the UK flowing through them, so they need to be robust.&#8221;</em>[1]</p><p>Then came the line that made me sit up. <em>&#8220;More than fifty per cent of the traffic on our website is bad actors. I think part of that is we&#8217;re a really well-loved teen brand. Any teen with hacking skills thinks, &#8216;Well, I really like Nando&#8217;s.&#8217;&#8221;</em>[1]</p><p>Read this as my editorial opinion, sharply put. <em><strong>Nando&#8217;s is not the exception in the British economy. Nando&#8217;s is the rule</strong></em>. The FTSE 100 attention space has trained a generation of security professionals, regulators, and journalists to treat the well-resourced enterprise SOC as the reference architecture. It is not. The reference architecture for most of the British consumer economy is what Kirk described next.</p><p><a href="https://thecontrollayer.arkava.ai/subscribe">Continue reading &#8212; subscribe to The Control Layer.</a></p>
      <p>
          <a href="https://thecontrollayer.arkava.ai/p/the-ciso-of-one-cybersecurity-in">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The player-coach CISO: how AI rewrote the security leader's job in eighteen months]]></title><description><![CDATA[Three senior UK security leaders rated the change in their roles at eight, eight, and nine out of ten. The job description has been rewritten &#8212; has yours?]]></description><link>https://thecontrollayer.arkava.ai/p/the-player-coach-ciso-how-ai-rewrote</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/the-player-coach-ciso-how-ai-rewrote</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Wed, 20 May 2026 07:31:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZfGR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>The first 200 words are free. The full 3,300-word breakdown &#8212; the player-coach reframe, the Claude Code bypass anecdote, the AI governance playbook in three acts, and the falsifiable predictive judgement on AISPM and the death of ISO 27001 as the dominant due-diligence question &#8212; sits behind the paywall.</strong></p><p></p><p><strong>Subscribe to read the full piece and the rest of the </strong>*<em><strong>Trust Is the Growth Engine</strong></em>*<strong> series &#8212; three pieces this week on what VantaCon UK 2026 told us about how trust is being rebuilt for the AI era.</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZfGR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZfGR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZfGR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZfGR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZfGR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZfGR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg" width="1024" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:187868,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/197142536?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZfGR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZfGR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZfGR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZfGR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd121c81-72f8-44c0-8920-f814e6fac239_1024x768.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the afternoon of 7 May 2026, on the second-stage panel at VantaCon UK, a Vanta moderator opened by asking three of the most senior security leaders in the Global technology ecosystem a deceptively simple question. <em>On a scale from one to ten, where ten means your job is completely different, what is your number?</em></p><p>The answers came back fast. <a href="https://www.intercom.com/blog/author/thibault/">Thibault Candebat</a>, Chief Information Security Officer at <a href="https://www.intercom.com">Intercom</a>, said eight. <a href="https://www.synthesia.io/blog/authors/martin-tschammer">Martin Tschammer</a>, Head of Security at <a href="https://www.synthesia.io">Synthesia</a>, said <em>&#8220;eight, nine, maybe even ten&#8221;</em>. <a href="https://www.dashlane.com/blog/joanna-chen-ciso">Joanna Chen</a>, CISO of <a href="https://www.dashlane.com">Dashlane</a>, gave the most analytically precise answer of the three &#8212; a six or seven on the enablement and operations side, but only a two or three on the defender side, <em><strong>because the fundamentals of protecting a company against attack have not changed; only the timeline has compressed</strong></em>.</p><p>I want to label this exchange as the most operationally significant moment of the entire conference, and I want to label that as my analytical reading. Three CISOs of three companies that ship at the leading edge of Technology all said, in three different ways, that the job they were doing eighteen months ago is not the job they are doing now.</p><p><a href="https://thecontrollayer.arkava.ai/subscribe">Continue reading &#8212; subscribe to The Control Layer.</a></p>
      <p>
          <a href="https://thecontrollayer.arkava.ai/p/the-player-coach-ciso-how-ai-rewrote">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Trust is the growth engine: Vanta's bet that the annual audit is finished]]></title><description><![CDATA[On 7 May 2026 in London, Vanta unveiled an agentic trust platform built around a continuously updated trust graph. The architecture is the right one.]]></description><link>https://thecontrollayer.arkava.ai/p/trust-is-the-growth-engine-part-1</link><guid isPermaLink="false">https://thecontrollayer.arkava.ai/p/trust-is-the-growth-engine-part-1</guid><dc:creator><![CDATA[Amer Altaf]]></dc:creator><pubDate>Mon, 18 May 2026 09:01:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ou1D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>The first 200 words of this piece are free. The full 3,400-word editorial breakdown &#8212; the architecture deep-dive, the constructive critique, the UK-sovereignty challenge to the trust graph, and the falsifiable predictive judgement on the death of the annual audit &#8212; sits behind the paywall.</strong></p><p></p><p><strong>Subscribe to read the full piece and the rest of the </strong><em><strong>Trust Is the Growth Engine</strong></em><strong> series &#8212; three pieces this week on what VantaCon UK 2026 told us about how trust is being rebuilt for the AI era.</strong></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ou1D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ou1D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Ou1D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Ou1D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Ou1D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ou1D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113526,&quot;alt&quot;:&quot;A wide editorial photograph of a London conference venue interior at VantaCon UK 2026, illustrating the corporate-trust analytical setting at the centre of The Control Layer's Trust Is the Growth Engine series.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://thecontrollayer.arkava.ai/i/197104348?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A wide editorial photograph of a London conference venue interior at VantaCon UK 2026, illustrating the corporate-trust analytical setting at the centre of The Control Layer's Trust Is the Growth Engine series." title="A wide editorial photograph of a London conference venue interior at VantaCon UK 2026, illustrating the corporate-trust analytical setting at the centre of The Control Layer's Trust Is the Growth Engine series." srcset="https://substackcdn.com/image/fetch/$s_!Ou1D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Ou1D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Ou1D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Ou1D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf571c3-abe5-45e3-953c-d698eea21370_1792x1088.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>VantaCon UK 2026, Convene 200 Aldersgate, London, 7 May 2026. Source: editorial reconstruction.</em></figcaption></figure></div><p>On the morning of 7 May 2026, in a converted post-industrial conference space on Aldersgate Street, <a href="https://www.vanta.com">Vanta</a> opened its third VantaCon UK[1] with a thesis the audit profession has spent the last two decades trying not to confront.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BagX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BagX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BagX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BagX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BagX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BagX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg" width="323" height="323" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:323,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Profile photo of Christina Cacioppo&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Profile photo of Christina Cacioppo" title="Profile photo of Christina Cacioppo" srcset="https://substackcdn.com/image/fetch/$s_!BagX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BagX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BagX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BagX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2411a6aa-ebe5-462f-b4fc-23d6fd3887f0_800x800.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.linkedin.com/in/ccacioppo/">Christina Cacioppo</a>, Vanta&#8217;s CEO and co-founder, walked on stage and said it directly. <em>&#8220;AI is rewriting trust.&#8221;</em>[2] Then, for the next ninety minutes, alongside her Chief Product Officer <a href="https://www.linkedin.com/in/jeremy-epling-j40/">Jeremy Epling</a>, she made the case that the static, annual, PDF-shaped compliance certificate is a relic, and that the architecture replacing it &#8212; <em><strong>continuous assurance, agentic governance, a live trust graph that updates 1,400 times an hour</strong></em> &#8212; is no longer five years away. It is shipping now.</p><p>That is the most important sentence to come out of any UK security conference this year, and I will mark it as my analytical reading rather than reportage. The reason it matters is not the platform announcement itself. It is what the announcement reveals about who has read the room correctly.</p><p><a href="https://thecontrollayer.arkava.ai/subscribe">Continue reading &#8212; subscribe to The Control Layer</a></p>
      <p>
          <a href="https://thecontrollayer.arkava.ai/p/trust-is-the-growth-engine-part-1">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>