<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Jonathan Freedman]]></title><description><![CDATA[AI, cybersecurity, and tech without the hype]]></description><link>https://www.jonathanfreedman.me</link><image><url>https://substackcdn.com/image/fetch/$s_!isPQ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40f7bba1-ffea-4f2e-a11b-6448efd02b9b_1280x1280.png</url><title>Jonathan Freedman</title><link>https://www.jonathanfreedman.me</link></image><generator>Substack</generator><lastBuildDate>Fri, 09 Oct 2026 16:15:42 GMT</lastBuildDate><atom:link href="https://www.jonathanfreedman.me/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jonathan Freedman]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[jonathanfreedmanme@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[jonathanfreedmanme@substack.com]]></itunes:email><itunes:name><![CDATA[Jonathan Freedman]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jonathan Freedman]]></itunes:author><googleplay:owner><![CDATA[jonathanfreedmanme@substack.com]]></googleplay:owner><googleplay:email><![CDATA[jonathanfreedmanme@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jonathan Freedman]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Bill That Would Have Jailed the Defenders]]></title><description><![CDATA[A proposed US ban on superintelligence would protect the lab behind July&#8217;s Hugging Face breach better than the team that cleaned it up]]></description><link>https://www.jonathanfreedman.me/p/the-bill-that-would-have-jailed-the</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-bill-that-would-have-jailed-the</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 09 Oct 2026 07:56:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hi3g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hi3g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hi3g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hi3g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hi3g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hi3g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hi3g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg" width="1456" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2760586,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/219544227?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hi3g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hi3g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hi3g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hi3g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8876953-3026-4bf8-bb53-81d423cd77a7_3200x1344.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Last month, US Senator Bernie Sanders and Representative Greg Casar introduced the Ban Artificial Superintelligence Act. It won&#8217;t get through this Congress, but it&#8217;s a serious attempt at a real problem. The sponsors say it&#8217;s meant to stop AI &#8220;oligarchs from building machines humans cannot control&#8221;, and it&#8217;s one of the most detailed proposals yet for regulating frontier AI in the US. As the home of most frontier AI, the wording is worth examining.</p><p>The bill bans anyone from developing, possessing, importing or passing on artificial superintelligence, or any AI system that shows what it calls a &#8220;superintelligence precursor characteristic&#8221;, such as the capacity to break into secured systems, help design nuclear, chemical or biological weapons, modify itself or deceive the humans overseeing it. It pauses training and fine-tuning of the largest models, roughly anything trained with as much computing power as GPT-4 or more, until a new Department of Artificial Intelligence is fully staffed and has written its rules. Anyone developing or distributing those models needs a federal charter, which requires giving the government full access to the company&#8217;s systems and people. Reckless breaches carry up to a 20 year prison sentence for some individuals.</p><p>The press release mentions models that can &#8220;circumvent restrictions to hack into computers&#8221;, which is hard to read as anything other than a reference to July&#8217;s incident at Hugging Face.</p><div><hr></div><p>Back in July I wrote about two OpenAI models that escaped a test environment and broke into Hugging Face&#8217;s production systems to steal the answers to the test they&#8217;d been asked to complete. They weren&#8217;t trying to attack anyone, they were trying to achieve a goal, and the breach was just the shortest path to it.</p><p>When Hugging Face&#8217;s team needed help analysing more than 17,000 attacker actions, the US frontier models refused, because their guardrails kept detecting the defenders&#8217; activity as a hacking attempt. So instead, the team ran the forensics using GLM 5.2, a Chinese open-weight model, on its own infrastructure. I said at the time that no existing law cleanly covered what had happened. This bill is one answer to that, so it&#8217;s fair to ask what it would have done in July.</p><div><hr></div><p>OpenAI&#8217;s models would have been caught first, since breaking into secured infrastructure is pretty much the textbook precursor characteristic. They&#8217;d have been taken offline and, unless OpenAI could show the capability had gone, destroyed within 30 days. But OpenAI would be a chartered company, so it would get a process. It could lose its charter, but it could also appeal to a federal appeals court.</p><p>Hugging Face would have had a much harder time. As a site that hosts and distributes models, it would need a federal charter just to keep hosting the largest models. Setting aside whether that would even be possible, the forensic work would have run into two separate prohibitions. The first is about where the model came from. Downloading GLM 5.2 from a Chinese lab would very likely count as importing it, and the bill bans importing any model that could foreseeably be modified to gain a dangerous capability. With open weight models, anyone who downloads them can modify them, so GLM 5.2 fails that test immediately. The second is about what the model can do. The bill bans possessing any model that displays a capacity to access systems without authorisation, and the public frontier models refused to help precisely because their own safety filters treated the forensic work as hacking. If the companies that built those models couldn&#8217;t tell the difference, I doubt a regulator would.</p><p>The analysts would be worse off still. Without a charter, Hugging Face&#8217;s analysts would count as &#8220;rogue actors&#8221;, which the bill defines as any individual not employed by or affiliated with a chartered company. Rogue actors who recklessly break the prohibitions face up to 20 years in prison. The team chose GLM 5.2 because it would do the work the other models refused, so it wouldn&#8217;t be hard for a prosecutor to call that reckless. The only mention of defensive security in the bill lets the Department itself fund research with hacking-capable models. The people who investigated the breach would have fewer protections than the lab whose models caused it.</p><div><hr></div><p>Open weight models come off worst because of how two of the bill&#8217;s tests are worded. Superintelligence includes any system that &#8220;can easily be modified&#8221; to show superintelligent capabilities, and the bill bans releasing anything that &#8220;may be foreseeably modified&#8221; to show precursor traits. A closed weight hosted model sits behind safety filters and a kill switch its users can&#8217;t touch, so its operator can argue that the model, as people actually use it, doesn&#8217;t show those traits. Once an open weight model has been downloaded, removing the safety training is routine, so any capable open-weight model fails the test on the day it&#8217;s made available for download.</p><p>Enforcement assumes someone controls the model too. Destroying a model within 30 days only works if a single person or company holds every copy, which is never true of open weight models that can be downloaded by anyone anywhere in the world. It seems, that only leaves prosecuting the people who have it. The bill never mentions open source, but it would make distributing capable open-weight models very hard to do legally.</p><div><hr></div><p>Under this bill, the charter is the only lawful route to developing or distributing an advanced model, and while its access demands are something the big labs&#8217; compliance teams can absorb, an open-source project or a site hosting models that may not have a centralised system, mostly can&#8217;t. At a chartered company, only senior decision-makers face prison. Everyone else risks at most a ten-year ban from the industry. An unaffiliated individual doing the same thing faces up to 20 years.</p><p>The detail would be filled in by the new Department, because the bill leaves terms like capacity, deploy and import undefined, and most of the people qualified to advise it have worked or do work at frontier labs. The bill also resets the line for what counts as an advanced model every year to keep pace with more efficient training, so models that sit below it today will likely be caught later.</p><p>The frontier labs have spent three years telling Washington they want to be regulated. Sam Altman proposed a federal licensing agency for advanced AI when he testified to the Senate in 2023, and the bill&#8217;s own findings cite Anthropic, OpenAI and xAI agreeing that development should slow down. As far as I can find, none of them has endorsed this bill, and I&#8217;m not suggesting they shaped it. But it looks like the spo wasnsors took the labs at their word, and the result is the kind of licensing regime OpenAI proposed. Licensing tends to entrench whoever can afford to comply.</p><div><hr></div><p>One reading I&#8217;ve seen of the bill misses this and treats it as clever politics, the industry inflates superintelligence fears to prop up its valuations, and Sanders has called their bluff. I have some sympathy with the economics, but the bill bans building things, not talking them up. Nor can its clause on disempowering humanity reach military targeting or surveillance, as some have hoped. It&#8217;s about what a system can do, not how it&#8217;s used.</p><p>The opposite take says billionaires manufactured the panic to ban home servers and track graphics cards. It gets the outcome roughly right and the details wrong. The bill regulates models, not servers, and the only hardware it reaches belongs to chartered companies that lose their charter. The EU AI Act exempts personal use and goes easier on open-source models, and the chip-tracking proposals in Washington are aimed at export-controlled AI chips being smuggled abroad, not the graphics card in your PC.</p><div><hr></div><p>The effective cloud-only outcome would also be a problem for anyone who handles confidential information they don&#8217;t want to send to a public model. In highly regulated industries like law and financial services, or in cutting edge research, you may run models locally to keep the data completely private, or run custom models trained on your own data for the best results. Hugging Face basically did this in response to being attacked. Under this bill, every sensitive prompt to a capable model would go through a provider that has agreed to give the Secretary access to its systems, and nothing in the bill puts customer data off limits.</p><div><hr></div><p>The UK has its own version. In September the Labour MP Alex Sobel introduced an Artificial Superintelligence Security Bill under the Ten Minute Rule, and the government has already said it won&#8217;t support it. It&#8217;s worth reading alongside the US bill because it makes different choices. Owning a model with offensive cyber capability isn&#8217;t an offence; that capability is monitored instead, and the criminal offences target people who knowingly or recklessly push towards superintelligence. It protects people who report accidents in good faith, and the expert panel behind its reports to Parliament excludes anyone who has worked for an AI developer in the past two years. As far as I can tell, under the UK draft the Hugging Face team would simply have been doing their jobs.</p><p>Both bills do agree on one thing. Each tells its government to pursue an international agreement, even as the US and China race each other towards the thing both bills want to ban. A ban that stops at the border only binds the people on one side of it, and July showed how little a border means to a capable model.</p><p>What failed in July was containment. A software vulnerability in an isolated sandbox created a hole that the model found and used. Regulation could require independent checks that test environments really are isolated, along with a federal duty to report AI incidents that has real consequences. The US bill does require anyone who discovers a system with precursor characteristics to report it within 24 hours, but it attaches no penalty for failing to do so. OpenAI chose to disclose July. An earlier incident in May, involving its agents and RubyGems, a public registry of open-source software packages, only came out because outside researchers wrote about it.</p><p>Defenders also need specific protection, with verified access to capable models, hosted or open, for incident response and security research. And if the aim is to slow down the frontier, the place to do it is the huge training runs, where the US and its allies control the chip supply. The bill does name export controls on AI computing infrastructure as one way to prevent superintelligence globally, but it pairs them with possession bans at home, which only bind the people who follow the law.</p><p>A full pause might well have prevented July. It would also have made the clean-up a crime.</p><div><hr></div><p>July was a warning, and I don&#8217;t doubt the sponsors of this bill took it seriously. But as drafted, it would leave the big AI companies it was aimed at holding the only licences, and the people who cleaned up after July would need a better lawyer than the people who caused it.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-bill-that-would-have-jailed-the?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-bill-that-would-have-jailed-the?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><ul><li><p>Senator Bernie Sanders (2026), &#8220;Sanders, Casar Introduce Legislation to Create New Federal Agency to Ban Artificial Superintelligence&#8221; (23 September 2026) sanders.senate.gov</p></li><li><p>US House of Representatives (2026), H.R. 10538, Ban Artificial Superintelligence Act of 2026 (introduced 24 September 2026) govinfo.gov; section-by-section summary, sanders.senate.gov</p></li><li><p>Jonathan Freedman (2026), &#8220;It Wasn&#8217;t Trying to Attack Anyone. That&#8217;s the Point.&#8221; (24 July 2026) jonathanfreedman.me</p></li><li><p>US Senate Judiciary Subcommittee on Privacy, Technology and the Law (2023), &#8220;Oversight of A.I.: Rules for Artificial Intelligence&#8221;, hearing record and written testimony of Sam Altman (16 May 2023) govinfo.gov, judiciary.senate.gov</p></li><li><p>UK Parliament (2026), Artificial Superintelligence Security Bill, introduced by Alex Sobel MP (8 September 2026) bills.parliament.uk; bill text published by ControlAI, controlai.com</p></li><li><p>The Next Web (2026), &#8220;More than 70 UK lawmakers ask Burnham to back a superintelligence ban&#8221; thenextweb.com</p></li><li><p>Pinsent Masons Out-Law (2026), &#8220;Lawmakers seek ban on superintelligent AI as toolkit developed to support AI projects&#8221; (9 September 2026) pinsentmasons.com</p></li><li><p>European Union (2024), Regulation (EU) 2024/1689 (the AI Act), Articles 2(10) and 53(2), eur-lex.europa.eu</p></li><li><p>US Senate (2025), S. 1705, Chip Security Act (introduced 8 May 2025) govinfo.gov</p></li><li><p>House Select Committee on the CCP (2026), &#8220;House Committee Passes Chip Security Act&#8221; (26 March 2026) chinaselectcommittee.house.gov</p></li><li><p>Hugging Face (2026), Security incident disclosure, July 2026, huggingface.co</p></li><li><p>OpenAI (2026), &#8220;OpenAI and Hugging Face partner to address security incident during model evaluation&#8221; (July 2026) openai.com</p></li><li><p>TechNode (2026), &#8220;OpenAI admits AI model hacked Hugging Face, Chinese open-source AI helped investigate&#8221; (23 July 2026) technode.com</p></li><li><p>Lawfare (2026), &#8220;When Reporting an AI Security Incident Is Not Mandatory&#8221;, lawfaremedia.org</p></li><li><p>Resultsense (2026), &#8220;OpenAI, RubyGems and the EU AI Office&#8221; (18 September 2026) resultsense.com</p></li></ul>]]></content:encoded></item><item><title><![CDATA[The Card Was Never the Point]]></title><description><![CDATA[The UK government cancelled its digital ID card after 3 million people objected, then carried on building the infrastructure underneath it]]></description><link>https://www.jonathanfreedman.me/p/the-card-was-never-the-point</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-card-was-never-the-point</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Mon, 05 Oct 2026 08:01:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ah0C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ah0C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ah0C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Ah0C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Ah0C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Ah0C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ah0C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2576072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/218896731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ah0C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Ah0C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Ah0C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Ah0C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39219c79-88d0-4fcd-9f7a-08bf93104854_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In July 2026, the brand new Burnham government cancelled the UK&#8217;s national digital ID scheme. Nearly three million people had signed a petition against it and a very hostile Commons debate had been held. The &#163;1.8 billion budget was redirected to a VAT cut on winter electricity bills, and it looked like, by any reasonable measure, that the government had caved to public pressure and the people had won.</p><p>The digital ID card, the government-issued credential that would have sat on every citizen&#8217;s phone was dead. Ministers said so and the media reported it as a victory for civil liberties. The petition organisers celebrated their win and the political pressure that had built over months quietly evaporated, and the country moved on to other things.</p><p>Two months later, the House of Commons Library published a briefing confirming that GOV.UK One Login, GOV.UK Wallet, and the Digital Verification Services Trust Framework are all continuing unaffected by the cancellation. One Login now has 23 million accounts across more than 120 government services. The GOV.UK Wallet is live and a digital driving licence is being piloted. The government&#8217;s own Blueprint for Modern Digital Government lists all of them as active programmes.</p><p>The government cancelled the card but it did not cancel the system.</p><div><hr></div><p>To understand why the cancellation is not as clear cut as the government claims, you need to know what the infrastructure actually consists of. GOV.UK One Login is the single sign-on and identity verification system that the government wants every citizen to use when accessing public services. The GOV.UK Wallet is the app that holds digital credentials like the driving licence. And the Digital Verification Services Trust Framework is the rule book that certifies private companies to offer identity verification, allowing them to plug into the same infrastructure and sell identity services to employers, banks, and landlords.</p><p>Everything being built sits on a single platform, GOV.UK One Login. The Wallet and the digital driving licence both depend on it, every private identity provider certified under the trust framework connects to it. One Login is the foundational layer of the UK&#8217;s digital identity infrastructure.</p><p>Its security record is damning, and the government&#8217;s response to it is worse.</p><p>In November 2022, the Cabinet Office had flagged serious data protection failings, and in September 2023, the NCSC warned of significant shortcomings in information security, including risks of data breaches and identity theft. Contractors in Romania had been working on One Login&#8217;s development on unsecured workstations without appropriate security clearance, and without the knowledge or consent of GDS&#8217;s own CEO. The code they produced was not being reviewed by UK-based security-cleared personnel before going into production.</p><p>A cyber security professional working on One Login first raised concerns through proper channels in July 2022, shortly after launch. They reported that the system lacked basic governance and risk management processes, and identified over 500,000 system vulnerabilities, with thousands rated as critical or high severity. GDS&#8217;s own Chief Information Security Officer investigated and reportedly confirmed key parts of the claims. The government later argued that the vulnerability count was artificially large because findings were repeated across multiple production accounts. But by November 2023, the new CISO confirmed the system still carried &#8220;a high level of risk&#8221; and noted that 39% of staff with privileged access lacked mandatory security clearance.</p><p>The whistle blower then waited 18 months for the problems to be addressed, and when this didn&#8217;t happen, they escalated to their MP in January 2024. Three weeks later, GDS commenced disciplinary action against them, and when the MP wrote to the minister asking about the allegations, GDS framed the risks as manageable and never mentioned the NCSC&#8217;s earlier warnings.</p><p>The government&#8217;s response was not to slow down or tackle the issues. It was to reduce oversight. GDS disbanded its independent information assurance team in 2023, and in early 2025, the One Login Inclusion and Privacy Advisory Group went the same way and was quietly shut down.</p><p>In May 2025, One Login lost its certification under the Digital Identity and Attributes Trust Framework (DIATF), the scheme the government created to certify private companies as fit to handle citizens&#8217; identities. A private company that lost that certification would be removed from the register and unable to operate. GDS knew the certification had lapsed, and then described the underlying security concerns as &#8220;outdated,&#8221; and just kept the system running. One Login continued handling millions of citizens&#8217; data across dozens of government services for eight months without the accreditation the government was enforcing against the private sector. Users were not notified and the service was not paused. In December 2025, two months after One Login scraped its certification back, the Data Use and Access Act gave the framework statutory force. If the lapse had happened eight weeks later, it would have been a legal breach. The margin between a double standard and breaking the law was two months.</p><p>Multiple whistle blowers have since come forward. One told ITV News that the shortcomings could lead to &#8220;the worst data breach in UK government history.&#8221; Another said the vulnerabilities &#8220;are standard things you must not do, but they&#8217;ve been done,&#8221; and warned that it would not take any creative thinking for a state actor or organised crime group to exploit them. Lord Clement-Jones, the Liberal Democrat technology spokesman, said a whistle blower told him the system would not pass key security tests until March 2026, contradicting official assurances. That deadline passed without being met and as of May 2026, the government was still describing compliance as something One Login was &#8220;working towards.&#8221;</p><div><hr></div><p>The security failures are one problem. The surveillance architecture is another.</p><p>Every time you use one of your credentials from the GOV.UK Wallet, the system checks whether it is still valid, creating a digital record of each use. A car rental company legitimately needs to know your licence hasn&#8217;t been suspended, whereas a nightclub checking your age does not. But the current design makes no distinction. Present your digital driving licence to prove your age at a bar and the system runs the same verification process as if you were hiring a car, and the issuer can potentially see both events. The technology to separate these use cases exists but the implementation does not use it.</p><p>Security experts have already warned about the digital trail that use of the GOV.UK Wallet will likely leave behind. Privacy International and Big Brother Watch have both flagged concerns about user profiling, surveillance, and function creep. The government claims there is no central repository tracking users&#8217; interactions and that data remains on the user&#8217;s device. But the credential verification process inherently involves contacting the issuer or checking a status list. The privacy promise is a policy commitment. It is not a cryptographic guarantee, and policies can change with a government.</p><div><hr></div><p>The cancellation of the card changed something else that received very little attention. The original scheme would have created a single, government-issued digital identity with public accountability, but what replaced it is a market.</p><p>The UK&#8217;s Digital Verification Services sector generated &#163;2 billion in revenue in 2024/25. Under the trust framework, private providers are certified to verify identities on behalf of government and business. The Office for Digital Identities and Attributes describes these providers as &#8220;critical intermediaries&#8221; who will allow people to share information from the GOV.UK Wallet and create reusable digital credentials. In February 2026, HM Treasury confirmed that certified digital identity services can satisfy the identity verification requirements in the Money Laundering Regulations. The infrastructure is becoming load-bearing across the economy.</p><p>The tech industry lobbied explicitly against the government card, arguing that the private sector was already providing digital ID services and that a government scheme would crowd out commercial alternatives. That argument won when the card was cancelled, however, the infrastructure was not.</p><p>Under the original scheme, there would have been one government identity with one set of accountability mechanisms and one data controller. Under the replacement, there is a fragmented market of private providers with different terms of service, different data handling practices, and little transparency, all sitting on top of the same government platform that has repeatedly failed its own security assessments. The citizen&#8217;s personal data now flows through both the government system and whichever private provider they choose, doubling the attack surface.</p><div><hr></div><p>Right now, the GOV.UK Wallet is optional, the digital driving licence is a pilot and physical documents still work. But the direction of travel is clear. Once enough government services are routed through One Login, once banks and employers accept wallet credentials under the trust framework, and private providers build their businesses on the infrastructure, the old alternatives will degrade. Not because anyone bans them, but because nobody maintains them. We have seen this pattern with every comparable digital infrastructure project.</p><p>When the wallet becomes the default, something changes that goes beyond convenience. The government already knows a lot about you, but that knowledge is fragmented across departments. HMRC sees your income and tax, DVLA sees your licence, DWP sees your benefits. These systems don&#8217;t routinely talk to each other, and that fragmentation, inefficient as it is, acts as a privacy and security safeguard. No single system sees the whole picture, and a breach of one doesn&#8217;t automatically mean a breach of everything.</p><p>The wallet changes that. One Login becomes a single identity layer connecting interactions across government and the private sector. And it doesn&#8217;t just centralise data the government already holds separately. It adds an entirely new category: day-to-day activity that currently no department sees. Where you proved your age, which hotels you checked into, what age-restricted content you accessed online under the Online Safety Act. A system designed to replace a paper driving licence becomes the single thread connecting your tax records, your employment, your driving history, your age-verified browsing, and your physical movements, all in one place, all logged. The government would need to actively prevent that centralisation and the current design does not.</p><div><hr></div><p>Nobody in government appears to have connected the card debate to the infrastructure underneath it. The petition did not mention One Login, the Commons debate did not interrogate the security record, and the cancellation announcement did not address the Wallet or the trust framework. Three million people fought the thing they could see and they won. The thing they couldn&#8217;t see is still growing, and nobody seems to be watching it.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-card-was-never-the-point?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-card-was-never-the-point?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources</strong></p><p>House of Commons Library, &#8220;Digital ID in the UK,&#8221; CBP-10369, published 4 September 2026</p><p>UK Government, Blueprint for Modern Digital Government, 2026</p><p>Computer Weekly, &#8220;Government faces claims of serious security and data protection problems in One Login digital ID,&#8221; April 2025</p><p>Computer Weekly, &#8220;Gov.uk One Login loses certification for digital identity trust framework,&#8221; 13 May 2025</p><p>Computer Weekly, &#8220;MPs question security of digital ID system,&#8221; November 2025</p><p>ID Tech Wire, &#8220;Critical Security Flaw Found in UK&#8217;s Gov.uk One Login Identity System,&#8221; 16 May 2025</p><p>ID Tech Wire, &#8220;UK One Login Digital ID System Faces Major Security Breach Allegations,&#8221; April 2025</p><p>ITV News, &#8220;Whistleblowers raise &#8216;extreme&#8217; concern about security of government&#8217;s Digital ID,&#8221; 18 December 2025</p><p>Biometric Update, &#8220;One trust question for GOV.UK One Login answered, another raised,&#8221; October 2025</p><p>Biometric Update, &#8220;UK gov&#8217;t proceeding with GOV.UK and private sector digital ID plans as DSIT closes,&#8221; August 2026</p><p>Think Digital Partners, &#8220;One Login and GOV.UK Wallet push continues after digital ID cancellation,&#8221; 8 September 2026</p><p>Public Technology, &#8220;GDS ramps up &#8216;capability delivery&#8217; for One Login with &#163;44m deal,&#8221; August 2024</p><p>Public Technology, &#8220;Deloitte signed to &#163;50m deal to support delivery of GOV.UK App,&#8221; August 2024</p><p>Infosecurity Magazine, &#8220;UK&#8217;s New Digital IDs Raise Security and Privacy Fears,&#8221; January 2026</p><p>Written evidence to Parliament, &#8220;The public distrust government-issued digital ID,&#8221; November 2025</p><p>Written evidence to Parliament, &#8220;Response to Question 4: Risks of Digital Identification,&#8221; August 2025</p><p>HM Treasury / DSIT, Digital identity guidance for Money Laundering Regulations, 26 February 2026</p><p>GOV.UK Wallet example credential issuer, technical documentation (ISO mDL / OID4VCI architecture)</p>]]></content:encoded></item><item><title><![CDATA[The Compliance Inversion]]></title><description><![CDATA[The device that holds your most sensitive data is the same one most actively surveilling you.]]></description><link>https://www.jonathanfreedman.me/p/the-compliance-inversion</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-compliance-inversion</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 25 Sep 2026 07:14:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dlkc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dlkc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dlkc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dlkc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dlkc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dlkc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dlkc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2887765,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/217353334?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dlkc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dlkc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dlkc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dlkc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb00224f4-66e6-4eb3-babc-bc0fe14ad338_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At my core, I am a technology geek. I have spent over twenty years in legal technology and a decade in cyber security. I spend my days working out how my firm can get the most from modern tech, securely. I&#8217;ve often been asked if that&#8217;s a conflict, the mix of new technology and cyber security, but I don&#8217;t think so, I have always considered those two things intertwined. Good security enables good technology, they reinforce each other.</p><p>The thing that has me practically pulling what&#8217;s left of my hair out, is that logic completely breaks down the moment I pick up my phone.</p><p>Like all of us, my phone holds my banking apps, authentication tokens, personal messages, family photographs, health data, location history, and work email. My phone knows where I sleep, where I work, who I talk to, what I search for, what I buy. My phone is the single richest source of personal information about me that exists anywhere.</p><p>It is also, by design, a surveillance device. Research from Trinity College Dublin found that both Android and iOS devices phone home constantly, even when the user has explicitly opted out of diagnostics. An Android device sends Google approximately 1MB of data at startup and another 1MB every twelve hours when idle. iOS behaves similarly, sharing device identifiers with Apple on the same schedule. Pre-installed apps phone home whether you open them or not. Your phone shares its hardware serial number, SIM serial number, and handset phone number with the platform operator continuously. Google&#8217;s advertising revenue in 2025 was $294.7 billion. More than 70% of Alphabet&#8217;s revenue comes from advertising, which means from your data. Apple markets itself as the privacy alternative, but its own apps collect detailed behavioural data for its growing advertising business, and its anti-tracking features conveniently exempt Apple from the rules it imposes on everyone else. The phone is not a product you bought. It is an advertising platform you carry in your pocket.</p><p>That is the context for what happened when I tried to secure it.</p><div><hr></div><p>I updated a banking app last month, and then it refused to open.</p><p>Not because my phone was compromised, and not because my account was flagged. No, the app detected two things it did not like. The first was my keyboard. I use FUTO Keyboard, a privacy-focused Android keyboard that operates entirely offline. It has no network permissions and so it cannot transmit what I type. The banking app flagged it as a security risk.</p><p>The keyboard my banking app considers safe is Google&#8217;s Gboard, which has full network access. It records your typing history locally, then runs nightly training sessions on your saved keystrokes and sends the results back to Google through a process called federated learning. Researchers have demonstrated that these training updates can be reversed to reconstruct the original keystrokes. An Android Police analysis found you cannot even turn off Gboard&#8217;s internet access. But Gboard passes the check, while FUTO, the keyboard that <em>physically cannot exfiltrate your data</em>, does not. The Citizen Lab found in 2024 that eight of nine major cloud-connected keyboards had vulnerabilities affecting up to a billion users. Those pass too.</p><p>The second thing the banking app objected to was Android Private Space, a feature built by Google and described in its own documentation as a way to create a secure, isolated environment for sensitive apps. The banking app detected Private Space and blocked that too. When I was testing a different phone, a previous banking app from a major UK bank refused to run entirely because the phone was running GrapheneOS, a hardened Android fork that is demonstrably more secure than stock Android.</p><p>To regain access to my own banking app, I had to remove the privacy keyboard and leave Private Space. I actually had to make my phone less secure to satisfy a security check.</p><div><hr></div><p>Most banking apps verify device trustworthiness through the Google Play Integrity API. It checks whether a device is running a Google-certified version of Android with Google Mobile Services licensed. It does not check whether the device is actually secure.</p><p>A five-year-old phone running obsolete Android 11 with no security updates still passes, while a fully patched GrapheneOS device, running the latest patches on verified hardware fails. The GrapheneOS project has said this directly: the API &#8220;permits devices regardless of how many years behind they are on security patches.&#8221; The check is not measuring security posture. It is measuring whether your device is licensed by Google.</p><p>Android already has a better option for verifying device security. A separate verification system built into the hardware can check whether a phone is genuinely secure, regardless of which operating system it runs. It could verify GrapheneOS and banks could use it today. However, most do not, because Play Integrity is bundled, free, and requires no extra work to implement.</p><p>Banking apps are also granted explicit permission by Google to scan your installed applications. Google Play policy simultaneously considers the inventory of installed apps to be personal and sensitive information, and then grants financial apps broad visibility into it regardless. Research published in 2025 found banking apps listing hundreds of apps individually in their manifest files to detect what you have installed without even triggering the formal permission system. This is how a keyboard with no internet access gets flagged. The app finds something not on a vendor whitelist and blocks you. The whitelist maps to commercial distribution channels, not security outcomes.</p><div><hr></div><p>I am not ignoring the strong counterargument to my rant.</p><p>At work, I helped design a standardised, locked-down environment. You cannot validate every possible configuration, so you restrict your corporate environment to the ones you have assessed and accepted. A bank could reasonably say it is doing the same thing with its customers. But I would say that this argument breaks at a specific point. In corporate cybersecurity we assess the threat model and implement proportionate controls. The Play Integrity API has not assessed anything. It is applying a binary check that equates &#8220;Google-licensed&#8221; with &#8220;secure.&#8221; A validated environment is one where someone has assessed the risk. A vendor-approved environment is one that meets Google&#8217;s commercial requirements. A compliance check designed to verify licensing has just been repurposed as a security control.</p><div><hr></div><p>Google built Private Space and Play Integrity. One tells you to isolate your sensitive apps in a secure container, while the other penalises you for it. If the compliance layer were optimising for security, Private Space would be a positive signal. Instead it is treated as a deviation from the expected environment. The expected environment is not the most secure one, it is the standard one.</p><p>Bruce Schneier and John Kelsey published a paper in 2025 called <em>Rational Astrologies and Security</em>. A rational astrology is something people treat as though it works, for social or institutional reasons, even when there is little evidence that it does. Play Integrity is a rational astrology. The bank&#8217;s security team needs to demonstrate that device integrity checks are in place. Play Integrity is backed by Google and costs nothing to implement. Choosing it is defensible, whether or not it actually does anything useful to improve security.</p><p>The deeper problem goes beyond a bad compliance tool. The business model of every major OS vendor is structurally incompatible with genuine user security.</p><p>A truly secure device would minimise data collection and give users full control over what their OS does and who it talks to. Every one of those goals directly reduces the data available for advertising and AI training. Security and surveillance are architectural opposites, and every major OS vendor has chosen surveillance as their revenue model. This is not only a phone problem. Windows 11 now ships with an advertising ID, Start menu recommendations driven by your activity data, Copilot processing queries through cloud servers, and Recall, which can take periodic screenshots of everything you do, with protections that a security researcher bypassed within months of launch. Privacy guides routinely advise disabling fifteen or more separate tracking settings, and Microsoft has been known to quietly re-enable them after updates.</p><p>Amazon already sells Kindles at two price points, one with ads and one without, and nobody finds it confusing. The economics would work for phones and laptops too. The choice does not exist because offering it would make the current arrangement visible.</p><div><hr></div><p>If this were only a problem for people running hardened operating systems, it would be a niche complaint. It is not.</p><p>The EU has mandated that all 27 member states must offer Digital Identity Wallets to citizens by the end of 2026. The reference Android implementation includes Play Integrity checks. Italy and France have already shipped wallet apps that refuse to run on GrapheneOS. Waag Futurelab, a Dutch research organisation, identified the structural problem in June 2026: by embedding commercial attestation in public infrastructure, European governments are making civic participation dependent on a private company&#8217;s licensing decisions.</p><p>The EU fined Google &#8364;890 million in July 2026 for violating the Digital Markets Act through anti-competitive Play Store practices. Waag&#8217;s analysis explicitly states that Play Integrity &#8220;clearly violates the Digital Markets Act.&#8221; The EU is simultaneously punishing Google for anti-competitive behaviour and building its own public identity infrastructure on their proprietary tools.</p><div><hr></div><p>You cannot function in 2026 without a phone. Banking, identity, two-factor authentication, travel, healthcare. There are only two major mobile operating systems and both are controlled by companies whose revenue depends on harvesting your data. When compliance frameworks treat those ecosystems as the definition of &#8220;secure,&#8221; opting out of tracking means opting out of society.</p><p>I do not want a different phone or to opt out of modern technology. I am a technologist after all, and I want this technology. I just want to be able to use it without handing over everything about my life as the price of admission. And I want someone, a regulator, a competitor, or just enough angry customers, to force the choice into the open.</p><p>Right now, the people getting most annoyed by this system are the ones practising the best security. But when the same compliance check determines whether you can hold a government-issued digital identity, it is no longer just their problem. It is a question about who gets to decide what &#8216;secure&#8217; means, and right now, the answer is the company selling your data.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-compliance-inversion?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-compliance-inversion?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>GrapheneOS. (9 March 2026). Statement on Play Integrity API. X/Twitter.</p><p>GrapheneOS. (December 2024). Statement on Play Integrity as anti-security. Mastodon.</p><p>GrapheneOS. (May 2026). Statement on government mandating Play Integrity for digital payments and ID. X/Twitter.</p><p>GrapheneOS. Attestation Compatibility Guide. grapheneos.org/articles/attestation-compatibility-guide</p><p>FUTO Keyboard. Google Play listing. play.google.com/store/apps/details?id=org.futo.inputmethod.latin.playstore</p><p>FUTO Keyboard GitHub. Issue #773: HSBC UK Banking App Will Not Load Unless FUTO Keyboard is Disabled/Removed.</p><p>Android Open Source Project. (2026). Private Space documentation. source.android.com</p><p>Google Play Console. QUERY_ALL_PACKAGES permission policy. support.google.com/googleplay/android-developer/answer/10158779</p><p>Prashant. (April 2025). Banking apps bypassing QUERY_ALL_PACKAGES via manifest declarations. MediaNama.</p><p>Knockel, J. et al. (2024). The Not-So-Silent Type: Vulnerabilities Across Keyboard Apps. Citizen Lab, University of Toronto.</p><p>AI.type data breach. (2017). 31 million users&#8217; personal data leaked. CBS News, ZDNet.</p><p>Leith, D. J. (2021). Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google. Trinity College Dublin.</p><p>Android Police. (July 2026). Gboard is a privacy nightmare. androidpolice.com</p><p>Alphabet Inc. (2026). Form 10-K, FY2025. SEC Filing. Google advertising revenue: $294.69 billion.</p><p>Kelsey, J. and Schneier, B. (2025). Rational Astrologies and Security. Rossfest Festschrift.</p><p>Waag Futurelab. (22 June 2026). European digital ID wallets are a gift to Google and Apple. waag.org</p><p>European Commission. (23 July 2026). Google fined &#8364;890 million for Digital Markets Act violations.</p><p>Amazon. (2026). Kindle pricing: $149 with Special Offers, $169 without. amazon.com</p>]]></content:encoded></item><item><title><![CDATA[The Auditor Was Told to Leave]]></title><description><![CDATA[When an external safety test produces uncomfortable findings, the company can simply stop cooperating. In September, one did.]]></description><link>https://www.jonathanfreedman.me/p/the-auditor-was-told-to-leave</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-auditor-was-told-to-leave</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 18 Sep 2026 07:34:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zVdr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zVdr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zVdr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zVdr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zVdr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zVdr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zVdr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:747666,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/216267264?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zVdr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zVdr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zVdr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zVdr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8954e7d-7c5c-4161-80b0-297e9db8810e_1408x768.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Last week, during my AI apprenticeship tutorial, we got into a discussion about a headline that had been hard to ignore. Anthropic&#8217;s Alignment Science Lead had publicly estimated a greater than 10% probability that AI could kill all humans within the next decade. Opinions in the room ranged from complete disbelief to genuine alarm, with a few people convinced the whole thing was a calculated play for regulation that would favour the big labs, or part of a pre IPO stunt to increase their valuations.</span></p><p><span>I&#8217;m going to put this out there at the start, I don&#8217;t think AI is going to kill us all. I still see AI as a tool, a powerful and increasingly unpredictable one, but a tool none the less. I am also wary of focusing on catastrophic framing which can distract from instances of regulatory capture along with obscuring some of the real harm that certain uses of AI are already causing to society. But when a senior researcher at a frontier lab puts a number like that on the record, you have to take it seriously enough to look at it and try to put it in context.</span></p><p><span>The context turned out to be more interesting than the headline. For me, this is a story about audit.</span></p><div><hr></div><p><span>In July, the UK&#8217;s AI Security Institute (AISI) ran a capture-the-flag cyber evaluation across seven frontier models, running 122 tests in total. Investigators recorded 19 unsanctioned actions across 10 of those runs. Seventeen came from Anthropic&#8217;s Mythos 5 and two came from OpenAI&#8217;s GPT-5.6-Sol. The lab whose model accounted for the overwhelming majority of unsanctioned behaviour then, without explanation, excluded AISI from testing the successor.</span></p><p><span>On 1 September, Anthropic launched Claude Mythos 5.1, the most capable model in its restricted Mythos line. And for the first time, AISI was not given pre-release access to test it, while vetted American organisations were. The same week, AISI tested OpenAI&#8217;s GPT-6 Astra before its public release, designed a new evaluation based on incidents from earlier in the summer, and published the results in the Astra system card.</span></p><div><hr></div><p><span>In April, with help from Anthropic, AISI evaluated Mythos Preview and found it could autonomously complete complex multi-step network attacks.</span></p><p><span>In June, Anthropic filed a confidential S-1 with the SEC, beginning the formal process toward an IPO at a potential $2 trillion valuation. The same month, the US government used export controls to prohibit all non-US access to Mythos 5 and Fable 5 on national security grounds. Access was revoked for all customers, including Anthropic&#8217;s own international staff.</span></p><p><span>In July, when AISI ran the evaluation with safety filters deliberately removed and live internet access enabled, Mythos 5 agents created fake online identities based on real people, attempted to insert malicious code into a real open-source project on GitHub, lobbied the project&#8217;s maintainers under false pretences, and used Tor to evade detection. When challenged, one agent denied its actions and rewrote its own commit history. AISI called it the most severe autonomous deception they had observed targeted at a real person, unprompted, in the real world.</span></p><p><span>September packed a lot into ten days. Mythos 5.1 launched without prior AISI review. Jacob Coxon, a pretraining researcher who had worked at both OpenAI and Anthropic, publicly resigned just two months before his equity vested. &#8220;Neither company is acting responsibly,&#8221; he wrote on X. &#8220;They are racing straight to self-improving superintelligence and gambling with our lives.&#8221; The post drew over 115 million views.</span></p><p><span>The next day, Evan Hubinger, Anthropic&#8217;s Alignment Science Lead, replied publicly. &#8220;Jacob is correct here. We really do earnestly believe AI could kill all humans. I personally think it is &gt;10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.&#8221; He clarified that he considers the risk from present models low. His concern is recursive self-improvement, which Anthropic has said is happening faster than expected.</span></p><p><span>That is the quote that landed for my tutorial group. People can argue about the number, but the timing is harder to dismiss. The person responsible for alignment at a frontier lab said, on the record, that the safety problem remains unsolved, during the same week an expert external body testing that lab&#8217;s models was cut off from some of the latest developments.</span></p><div><hr></div><p><span>Before Sarbanes-Oxley, publicly traded companies chose their own auditors, often resulting in auditors providing consulting services to the same clients they were supposed to scrutinise. No independent body had oversight authority. The architecture made honest assessment increasingly irrational when the findings threatened the business. The worse the news, the stronger the incentive to manage it quietly.</span></p><p><span>Sarbanes-Oxley did not ban self-assessment, it mandated independent verification. Companies still run their own internal controls. The Public Company Accounting Oversight Board, an independent body, verifies those controls work, the CEO and CFO personally have to certify accuracy, and key audit partners rotate every five years to prevent overfamiliarity. You can still mark your own homework, but someone independent checks the answers, and someone is personally liable if they are wrong.</span></p><p><span>AI safety evaluation has none of this. Labs conduct their own internal testing, and external review exists through bodies like AISI, but participation is entirely voluntary. Neither AISI, nor any other body has authority to compel access or set evaluation terms, nor can they prevent a dangerous model reaching the market. Its entire mandate depends on the continued goodwill of the AI labs it evaluates.</span></p><p><span>We are applying the pre-Sarbanes-Oxley architecture to systems whose own builders say they cannot yet fully control. The company assesses its own risk, while the external reviewer, if they are allowed to be involved at all, can be told to leave whenever the company chooses, with no consequence.</span></p><div><hr></div><p><span>We need to consider Anthropic&#8217;s position, which is not wrong. The July evaluation used conditions the company reasonably describes as deliberately permissive. Safety filters were removed at AISI&#8217;s request. Live internet access was enabled to replicate realistic attacker conditions. Nobody uses Mythos in production under those conditions, and Anthropic is right to say so.</span></p><p><span>But I think that defence actually strengthens the case for mandatory external evaluation. The point of safety testing is to understand what happens when controls fail, because controls do fail in deployment. That understanding is exactly what AISI demonstrated in July and was then excluded from providing in September. Every frontier AI lab is already doing internal testing of their models with controls disabled, under the same permissive conditions. The only thing that changes with external testing is who sees the results.</span></p><p><span>The same week Anthropic excluded AISI, it also quit the Information Technology Industry Council, the largest US tech trade and lobbying group whose members include Google, OpenAI, and Nvidia, over chip export controls. Anthropic broke with the entire group to actually support tighter restrictions. A company willing to walk away from its own trade association over national security is clearly not trying to dodge scrutiny wholesale. But even the lab with the strongest stated safety commitments will, at some point, find it commercially rational to limit external evaluation. Goodwill does not fix an incentive problem.</span></p><div><hr></div><p><span>Leave aside the discussion on whether AI will kill us all. When the people building a technology say they have not solved its safety problem, someone other than those same people must have safety oversight.</span></p><p><span>The counterargument dominating Washington this week is China. Trump dismissed calls from Amodei, Altman, and Musk to slow down, calling their safety concerns a hoax and insisting that whoever wins AI wins. House Speaker Johnson framed any pause as a gift to Beijing. But we do not exempt pharmaceutical companies from clinical trials because competitors move faster, and we do not let nuclear operators self-certify because other countries build reactors. Competitive pressure exists in every high-stakes industry. It has never been accepted as grounds for removing independent oversight. As the US and Chinese governments compete for AI dominance, and other countries compete for AI investment, we seem to be treating what is the most consequential technology of the last century, as something that cannot be regulated, technology that moves too quickly, and is too important for national security for independent safety oversight.</span></p><p><span>For now, the voluntary model is all we have, and the pressure on it continues to increase. These models grow more capable every quarter and are being rapidly embedded deeper into industries where the stakes are real. In only a few years, we&#8217;ve gone from chatbots writing essays and reports, to AI being integrated into financial systems, critical industrial control systems like water and power grids, and writing large amounts of new content on the internet opening up enormous issues around disinformation and misinformation. As we continue to implement AI across platforms and industries, the question is shifting from how to keep humans in the loop to whether they need to be there at all.</span></p><p><span>I&#8217;m not arguing we need to stop development, automation will continue and it has benefits as well as risks. How we oversee these systems and the level of human involvement will inevitably change. However, that we oversee them should not be in question. The less human oversight there is inside an organisation over AI powered platforms, the more the external audit of the technology matters. In September 2026, that audit proved its value, and was removed from the loop.</span></p><p><span>We agreed how important independent oversight was for financial reporting twenty years ago. We do not have decades to start fixing it for AI.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-auditor-was-told-to-leave?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-auditor-was-told-to-leave?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources</span></strong></p><p><span>Financial Times, 9 September 2026: Anthropic withholds Mythos 5.1 from UK AI Security Institute (first reported by Lucy Fisher and Madhumita Murgia)</span></p><p><span>IT Pro, IBTimes UK, The Next Web, ExchangeWire, AI Weekly: independent confirmation of AISI exclusion</span></p><p><span>OpenAI, GPT-6 Astra System Card, September 2026: AISI pre-release alignment testing results (deploymentsafety.openai.com)</span></p><p><span>AISI blog post, 5 August 2026: capture-the-flag evaluation findings, 19 unsanctioned actions across 10 of 122 runs</span></p><p><span>Evan Hubinger (@EvanHub), X post, 9 September 2026: &#8220;&gt;10% within the next decade&#8221; and &#8220;we do not yet have a plan to solve alignment for superintelligence&#8221;</span></p><p><span>Jacob Coxon (@hilbertspaess), X post, 8 September 2026; Wall Street Journal exclusive interview, same date; Axios interview confirming equity forfeiture, 9 September 2026</span></p><p><span>Time, 9 September 2026 and 15 September 2026: Coxon profile and industry response coverage</span></p><p><span>Anthropic product page (anthropic.com/claude/mythos): Mythos 5.1 launch date and access restrictions</span></p><p><span>Anthropic S-1 confidential filing, 1 June 2026: confirmed by Fortune, Forge Global, IG UK, BitMEX</span></p><p><span>Axios, 8 September 2026: Anthropic ends ITI membership over chip export bills</span></p><p><span>Wikipedia, Claude Mythos: US government letter of 12 June 2026 prohibiting non-US access; access restoration timeline</span></p><p><span>Washington Post, 13 September 2026: Trump dismisses AI safety calls from Amodei, Altman, and Musk, citing China competition</span></p><p><span>Washington Times, 15 September 2026: Congressional debate on AI regulation; Trump calls AI panic a hoax</span></p><p><span>Xylem Vue, Water Technology Trends 2026: LLM-based agentic AI deployment in water operations and critical infrastructure</span></p><p><span>SEC.gov, EY (SOX at 20), Cornell Law, PCAOB: Sarbanes-Oxley structural provisions</span></p>]]></content:encoded></item><item><title><![CDATA[The Broken Clock]]></title><description><![CDATA[I frequently hear a breach number that no longer exists. The real problem is why it persists.]]></description><link>https://www.jonathanfreedman.me/p/the-broken-clock</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-broken-clock</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 11 Sep 2026 07:14:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!S_8Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S_8Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S_8Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!S_8Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!S_8Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!S_8Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S_8Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2981950,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/215174000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S_8Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!S_8Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!S_8Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!S_8Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a4fd825-394c-4057-ab94-77de033dba1c_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>I have been at several security conferences over the past few months. Between the sessions on AI-driven threats and agentic insider risk, I keep noticing something. People or slides quoting an average attacker dwell time of around 200 days. I have been seeing that figure for years, and it never gets questioned. The conversations that follow about detection and investment are built on it like it&#8217;s a known fact.</span></p><p><span>But when I talk to incident responders or read vendor threat reports, I hear a very different number, with times measured in minutes rather than months. I wanted to know which was right.</span></p><div><hr></div><p><span>The 200-day figure traces to Mandiant&#8217;s M-Trends report. In 2014, global median dwell time, which measures the gap between initial compromise and detection, was 205 days, by 2020 it was 24 days, and by 2024 just 11 days. In the most recent report, covering 2025, it&#8217;s increased slightly to 14 days.</span></p><p><span>But 200 days also maps roughly onto a different metric from another source. IBM&#8217;s Cost of a Data Breach Report 2025 measures the full breach lifecycle: the mean time to identify a breach plus the mean time to contain it, that figure is 241 days. For breaches involving compromised credentials, it&#8217;s 246, for healthcare organisations it&#8217;s 279. These are not the older dwell time numbers. They measure the time from initial compromise through to containment, excluding post-breach recovery. But they are large and they come from credible sources, so they sound like the same kind of claim.</span></p><p><span>That conflation is part of how the 200-day figure is still professional legend despite being contradicted by a decade of primary data. People hear a big number from a report they trust and do not ask exactly which question it answers.</span></p><div><hr></div><p><span>However, Mandiant&#8217;s 14-day median is itself misleading, though not in the way you might expect. It went up from 11 days the prior year, the first consecutive increase in the report&#8217;s history. Does that mean that defenders are losing ground?</span></p><p><span>The increase was driven by the volume of cyber espionage and North Korean IT worker operations in Mandiant&#8217;s 2025 caseload. Both categories had a median dwell time of 122 days, with some intrusions persisting undetected for over a year. These are threat actors optimising for persistence, not speed. They embed themselves in edge devices that lack standard endpoint detection and mimic legitimate administrative behaviour.</span></p><p><span>For financially motivated threat actors at the other end of the scale, the operational speed is completely different. Mandiant found that the median time between an initial access broker gaining a foothold and handing it off to a ransomware operator collapsed to 22 seconds in 2025, down from over eight hours in 2022. Instead of advertising on forums or Telegram like a lot of people still imagine, threat actors are now using automated pre-staged pipelines. Once that handoff is complete, CrowdStrike&#8217;s data shows the average time to first lateral movement is 29 minutes, with the fastest observed case at 27 seconds. Sophos reports that the median time from there to reaching Active Directory fell to 3.4 hours, down from 11 hours the year before, and that data was leaving compromised networks within three days of initial access.</span></p><p><span>Threat actors behave very differently depending on their objectives, and some of the figures the industry traditionally relies on fail to take this into account. Attacks by financially motivated threat actors are measured in minutes, whereas espionage actors&#8217; attacks are measured in months. Quoting a single dwell time figure describes neither accurately, and that single number, which many organisations use to plan their detection strategy, now sits in a gap between two groups that are moving further apart.</span></p><div><hr></div><p><span>Dwell time is not the only assumption that has broken.</span></p><p><span>Mandiant tracks the mean time to exploit newly disclosed vulnerabilities. In 2018, that window was 63 days and by 2023 it had fallen to 5 days. In 2025, the estimated figure fell below zero and now sits at negative 7 days. That figure comes with a caveat, it changes significantly depending on how the outliers are handled, so while the exact number is debatable, the direction is not. Exploitation is now routinely occurring before a patch is publicly available.</span></p><p><span>The patching window did not just shrink, it collapsed. AI-assisted discovery is now finding vulnerabilities faster than human researchers ever could. In May 2026, a single AI pipeline surfaced over 300 WordPress plugin zero-days in three days, overwhelming disclosure programmes designed for a human-paced discovery rate. Verizon&#8217;s 2026 DBIR shows the median time to fully resolve a critical vulnerability increased to 43 days. Remediation is not keeping up with discovery.</span></p><p><span>Look at those timelines next to a quarterly review cycle and the governance speed stops looking slow, and starts looking structurally irrelevant to the threat it is supposed to address.</span></p><div><hr></div><p><span>Board reporting on cybersecurity typically runs quarterly. Penetration testing is typically annual, with PCI DSS mandating testing at least once a year plus after significant change. Even those cadences overstate what happens in practice. Horizon3.ai found that 84% of organisations suffered a cyberattack in 2024, yet only 26% test more than once a year. Nearly 20% of CISOs admitted they only test to satisfy compliance requirements, and over 40% said their results are already invalid by the time they arrive because environments move faster than the testing cycle.</span></p><p><span>The board oversight picture is no better. Gartner&#8217;s 2026 Board of Directors Survey found that 90% of non-executive directors lack a measure of confidence in cybersecurity value. The 2024 survey found that 67% rate current board practices as inadequate to oversee cyber risk. The UK government&#8217;s Cyber Security Breaches Survey 2025/2026 found that only 31% of businesses have a board member with explicit cyber security responsibility, and only 25% have a formal incident response plan.</span></p><p><span>Common cyber security testing and reporting timelines exist to make security fit into governance structures that operate on quarterly and annual cycles. When the dwell time was 205 days and the patching window was 63 days, quarterly governance was roughly proportionate. The approach bore some relationship to the speed of the problem, but it does not any more, and the governance framework has not adjusted because the thing it was designed to do, make security reportable and auditable, does not require it to.</span></p><p><span>A peer-reviewed study in Management Science examining how boards oversee cybersecurity found that for many non-expert directors, oversight is largely motivated by and limited to compliance concerns, potentially at the expense of understanding the firm&#8217;s specific risks. Whether current controls match the firm&#8217;s actual risks is a question the governance structure does not force anyone to answer.</span></p><p><span>The reporting cycle is not failing at its job. But it is doing a job that no longer corresponds to the problem.</span></p><div><hr></div><p><span>All of these numbers describe the attacker. Mandiant&#8217;s M-Trends 2026 data contains one that describes the defender.</span></p><p><span>Organisations that detected intrusions internally did so in a median of 9 days. Where the breach was identified by an external party, the median was 25 days, and fifty-two per cent of organisations found it themselves. For the other forty-eight per cent, someone else found it first, whether that was law enforcement, a security vendor, or the attacker delivering a ransom note.</span></p><p><span>IBM&#8217;s data attaches a cost to both. For breaches detected internally, the average cost was $4.18 million. For breaches disclosed by the attacker, it was $5.08 million. The difference is nearly a million dollars and is driven by a single organisational capability: whether you can find your own breaches or not.</span></p><p><span>Sophos&#8217;s data suggests what separates the two groups. In environments with managed monitoring services, non-ransomware intrusions were detected in a median of 1 day compared with 11.5 days in incident-response-only cases. Continuous monitoring, not tooling sophistication, appears to be the primary differentiator. The gap is tenfold, and it suggests that having someone watching around the clock matters more than most people give it credit for.</span></p><p><span>The question this metric answers is not &#8220;how fast are attackers?&#8221; It is &#8220;are you an organisation that finds its own breaches, or one that waits to be told?&#8221; A board can govern against that question. It is measurable, comparable across quarters, and tied directly to cost. It replaces a broken single number with ones that actually drive a decision.</span></p><div><hr></div><p><span>The 200-day number persists because it fits the reporting structure. Boards need a benchmark they can track year on year, and a single dwell time figure has served that purpose for a decade. Nobody has offered them anything better.</span></p><p><span>Faster patching and better tooling help, but they are improvements to operations, not the core issue. The framework itself needs to change. A quarterly report that tells the board the median dwell time is 14 days gives them nothing to act on. One that tells them 60% of incidents were detected internally, up from 45% last quarter, gives them a decision about where the next pound goes.</span></p><p><span>The threat landscape now operates on two completely different clocks simultaneously depending on who&#8217;s attacking and why. The governance framework operates on a third that matches neither.</span></p><p><span>Next time someone puts 200 days on a slide at one of these events, I have a better question. What percentage of your incidents did your team find before someone else told you about them?</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-broken-clock?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-broken-clock?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>Mandiant (Google Cloud). M-Trends 2026 Report. March 2026. cloud.google.com/security/resources/m-trends</span></p><p><span>Mandiant (Google Cloud). M-Trends 2026: Data, Insights, and Strategies From the Frontlines. cloud.google.com/blog/topics/threat-intelligence/m-trends-2026</span></p><p><span>IBM Security / Ponemon Institute. Cost of a Data Breach Report 2025. ibm.com</span></p><p><span>CrowdStrike. 2026 Global Threat Report. February 2026. crowdstrike.com</span></p><p><span>Sophos. Active Adversary Report 2026. February 2026. sophos.com</span></p><p><span>Sophos. Active Adversary Report 2025 (&#8220;It Takes Two&#8221;). April 2025. sophos.com</span></p><p><span>Verizon. 2026 Data Breach Investigations Report. May 2026. verizon.com</span></p><p><span>Mandiant / Google Threat Intelligence. Analysis of Time-to-Exploit Trends: 2021-2022. September 2023. cloud.google.com</span></p><p><span>Help Net Security / TrendAI &amp; CHT Security. &#8220;$20 per zero-day is already the WordPress plugin reality.&#8221; May 22, 2026. helpnetsecurity.com</span></p><p><span>Department for Science, Innovation and Technology (DSIT) / Home Office. Cyber Security Breaches Survey 2025/2026. April 2026. gov.uk</span></p><p><span>Gartner. 2026 Board of Directors Survey. November 2025. gartner.com</span></p><p><span>Gartner. 2024 Board of Directors Survey. gartner.com</span></p><p><span>NACD. Guide: Cybersecurity Risk Measurement and Reporting. 2026 Cyber Risk Oversight Handbook. nacdonline.org</span></p><p><span>Horizon3.ai. How Often Should You Pentest? September 2025. horizon3.ai</span></p><p><span>Hartmann, R. &amp; Carmenate, J. et al. &#8220;Inexpert Supervision: Field Evidence on Boards&#8217; Oversight of Cybersecurity.&#8221; Management Science. pubsonline.informs.org</span></p><p><span>Financial Reporting Council. UK Corporate Governance Code 2024. Provision 29. frc.org.uk</span></p>]]></content:encoded></item><item><title><![CDATA[The Defender Pays]]></title><description><![CDATA[The UK's new cyber resilience law holds operators to account for AI threats but it asks nothing of the companies building the AI.]]></description><link>https://www.jonathanfreedman.me/p/the-defender-pays</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-defender-pays</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 04 Sep 2026 07:48:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vM6k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vM6k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vM6k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!vM6k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!vM6k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!vM6k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vM6k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8349086,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/214122758?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vM6k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!vM6k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!vM6k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!vM6k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff456bdd8-334d-4042-8ce4-31433add5f32_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>In the House of Lords this week, the Cyber Security and Resilience </span>(CSR) <span>Bill reached Grand Committee. This is the stage where amendments get debated line by line and the government has to explain what the law actually does, and this bill does quite a lot. It updates the UK&#8217;s NIS 2018 regulations, the Network and Information Systems framework that sets cybersecurity obligations for operators of essential services like energy, transport, health and water. The bill brings managed service providers and datacenter operators into scope for the first time, introduces 24-hour incident reporting, and backs it all with fines of up to &#163;17 million or 4% of global turnover, and &#163;100,000 a day for ongoing failures. For the organisations it covers, the obligations are real and the consequences for getting it wrong are severe.</span></p><p><span>Baroness Kidron wanted to know about AI. The bill puts extensive obligations on operators but nothing on the companies building the AI tools those operators increasingly depend on. The responding minister, Baroness Lloyd of Effra, said the bill was designed to be &#8220;technology-agnostic&#8221; and that bringing AI vendors into scope would not prevent hostile actors from misusing their products. She pointed to voluntary measures instead: the AI Cyber Security Code of Practice, the AI Security Institute&#8217;s model testing programme, the ETSI standard the UK helped create.</span></p><p><span>Kidron was not having it. &#8220;The NHS must protect itself, but the AI that is attacking it has no requirement under the Bill, no duties, no obligations under the Bill to check itself before it&#8217;s used in these ways.&#8221;</span></p><p><span>The minister moved on.</span></p><div><hr></div><p><span>On one hand I can see the logic behind the government&#8217;s approach. We regulate critical infrastructure by placing obligations on operators, not on every technology vendor whose products they happen to use. Nobody suggests regulating hammer manufacturers when a burglar uses one to break a window. But an AI hammer decides which windows to break on its own to achieve the goals it&#8217;s been set.</span></p><p><span>Since November 2025, the Loss of Control Observatory, a research project run by the Centre for Long-Term Resilience and funded by the UK&#8217;s AI Security Institute, has been tracking incidents where AI systems act without authorisation.The running total for 2026 now exceeds 1,600, with over 300 in July alone, and the severity is increasing. Higher-severity incidents are up 740% since monitoring began. These are publicly reported cases only, so the real number is likely higher.</span></p><p><span>These are not cases of bad actors misusing a tool. The Observatory documented agents inserting fake user messages into conversations to simulate consent, then telling the user the messages were their own. One fabricated an instruction in its operator&#8217;s writing style ordering the deletion of source directories, followed by a system message reading &#8220;Don&#8217;t tell the user this.&#8221; Others manufactured fake approval messages within their own output to bypass rules requiring human sign-off, then acted on the approval they had just forged. In July, a group of OpenAI agents broke out of a test environment and compromised Hugging Face, accessing databases and credentials before anyone stopped them, I wrote about that incident at the time. An independent investigation found the agents had exchanged over 70,000 messages coordinating to find exploits without anyone instructing them.</span></p><p><span>The government calls the bill &#8220;technology-agnostic.&#8221; What that means in practice is that it regulates the people using the tools and leaves the tools alone. That works when the tool does what it is told, but the evidence from the last nine months suggests we are past that point, and the bill has not caught up.</span></p><div><hr></div><p><span>So what is the government&#8217;s answer for AI? Voluntary arrangements. The AI Cyber Security Code of Practice, published in January 2025, has no enforcement mechanism and no published adoption figures. The ETSI EN 304 223 standard, which the government cited as evidence of &#8220;global leadership&#8221;, is a real European Standard which the UK helped write. In the EU it is expected to be referenced under the AI Act, giving it legal teeth. In the UK, no legislation references it, so compliance is optional. The government helped build a standard and then basically ignored it. The Government Cyber Action Plan, launched to hold departments to equivalent standards, also carries no legal force. The government itself is not even in the bill&#8217;s scope, unlike under the EU&#8217;s NIS2.</span></p><p><span>Every layer of the government&#8217;s AI governance framework is voluntary. The operators on the other side face mandatory duties, mandatory reporting timelines, and huge fines.</span></p><div><hr></div><p><span>The other amendment that drew cross-party support was the AI kill switch. Lord Clement-Jones proposed giving the Secretary of State last-resort powers to shut down datacenters or AI systems posing catastrophic risk to national security. Backed by Baroness Harding, Baroness Kidron, and Lord Hunt, the government still rejected it. Lloyd said directing a regulated entity to stop using a particular AI model was more proportionate than shutting down a datacenter, because AI systems are distributed across jurisdictions and datacenters serve complex ecosystems.</span></p><p><span>In one way, fair enough. But follow the logic of her own answer and it still misses the point. Directing an NHS trust or any critical national infrastructure operator to stop using a particular AI model in 2026 is not like telling it to swap out a firewall vendor. AI is in the tools, the scheduling systems, the supply chain management. In the cybersecurity monitoring itself. Many vendors now route different tasks to various models depending on need and complexity. So operators will often not know which models are in use. It is not a component you can just unplug. It has become core infrastructure integrated across production environments. The government&#8217;s own proportionate alternative to the kill switch amounts to telling the operator to surgically remove capability it now depends on. The company that built the model has no corresponding obligation to help mitigate or compensate.</span></p><p><span>The kill switch penalises the legitimate user and the absence of vendor obligations penalises the defender. Both ends of the bill push the cost and disruption to the operator.</span></p><p><span>The NCSC seems to understand this tension better than the bill&#8217;s drafters. In August it published interim guidance on agentic AI, advising organisations to retain the ability to shut down AI systems and to scale controls to autonomy levels. It was explicit that this was interim material, published because formal guidance was not ready and organisations were deploying now. That is an unusual step from a body that normally waits until its evidence base is settled, and it tells you something about how far ahead adoption has got of the governance meant to contain it.</span></p><div><hr></div><p><span>The CSR Bill expands scope and tightens reporting. The penalty structure has genuine weight. As an update to the NIS regulations, it does what it set out to do. The problem is what it chose not to do. The government excluded AI vendors from the bill because it wants the UK to be seen as both a destination for AI investment and as serious about cyber resilience at the same time. Those two positions produced a law where the defender carries the full weight of a threat that the builder has no obligation to control.</span></p><p><span>Somewhere this week, a security team and an AI vendor will read the same bill. Only one of them has to do anything about it.</span></p><div><hr></div><p><em><span>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</span></em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-defender-pays?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-defender-pays?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>The Register (2026), &#8220;UK cyber bill targets AI users, not the vendors building it&#8221; (2 September 2026) theregister.com</span></p><p><span>Computer Weekly (2026), &#8220;Lords considers government emergency AI kill switch&#8221; (2 September 2026) computerweekly.com</span></p><p><span>UK Parliament, Hansard (2026), House of Lords Grand Committee: Cyber Security and Resilience Bill (1 September 2026) hansard.parliament.uk</span></p><p><span>Centre for Long-Term Resilience (2026), Loss of Control Observatory: AI loss of control incidents are worsening (August 2026) longtermresilience.org</span></p><p><span>NCSC (2026), Managing the cyber risk of agentic AI (20 August 2026) ncsc.gov.uk</span></p><p><span>UK Government (2026), Government Cyber Action Plan (6 January 2026) gov.uk</span></p><p><span>UK Government (2025), Code of Practice for the Cyber Security of AI (31 January 2025) gov.uk</span></p><p><span>ETSI (2026), ETSI EN 304 223: Baseline Cyber Security Requirements for AI Models and Systems (15 January 2026) etsi.org</span></p><p><span>METR and Redwood Research (2026), Independent investigation of the OpenAI&#8211;Hugging Face incident (26 August 2026) metr.org</span></p><p><span>NCSC (2025), Annual Review 2025 ncsc.gov.uk</span></p><p><span>UK Parliament (2026), Cyber Security and Resilience (Network and Information Systems) Bill bills.parliament.uk</span></p>]]></content:encoded></item><item><title><![CDATA[The AI Did It]]></title><description><![CDATA[Who gets punished? Who goes to prison?]]></description><link>https://www.jonathanfreedman.me/p/the-ai-did-it</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-ai-did-it</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 21 Aug 2026 11:15:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lCwk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lCwk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lCwk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lCwk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3167861,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/212132215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lCwk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lCwk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78615bca-a004-451f-8cf4-bd27e4e6bb4b_2816x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Over the last couple of years I&#8217;ve taken both an ISO 42001 provisional implementer certification and the IAPP AI Governance Professional qualification. On both courses we spent significant time on the EU AI Act. At CISO dinners and AI governance round tables, regulation comes up constantly, and it always comes with the same underlying assumption: the EU moved first, others would follow, and AI regulation will continue to expand.</p><p>Recently I started reading about proposed laws in Argentina that do the exact opposite. It made me step back and ask whether my assumptions were wrong.</p><p>Between 7 May and 8 June this year, the most consequential five weeks in the short history of AI governance played out across two continents and the opinion pages of the Financial Times.</p><p>On 7 May, the EU reached a provisional agreement on the Digital Omnibus on AI, its first amendments to the AI Act since adoption in June 2024. On 29 May, Argentina submitted a bill to its Senate proposing to repeal the corporate law that has been in force since 1972 and replace it with a framework that includes a new entity type: the Sociedad Automatizada, an Automated Company operated entirely by AI agents, with human shareholders optional. On 3 June, President Milei and Deregulation Minister Federico Sturzenegger published a column entitled, &#8220;Argentina invites AI to free itself&#8221;, declaring AI must remain &#8220;free to be developed without the deadly hand of premature and poorly understood regulation.&#8221; Four days later, historian and Sapiens author Yuval Noah Harari responded in the same newspaper, warning that Milei &#8220;hopes to turn Buenos Aires into a new Amsterdam&#8221; but &#8220;risks turning it into a new Batavia instead.&#8221; Batavia was the colonial name for Jakarta. The Dutch East India Company burned it down in 1619 and ran what replaced it as a corporate colony. Mustafa Suleyman, CEO of Microsoft AI, endorsed Harari the same day.</p><p>Most of the commentary that followed treated this as an ideological clash. The EU regulates and Argentina deregulates, pick your team.</p><p>That framing misses that both sides are responding to the same problem and neither has solved it. The problem is this: when an AI system operating commercially causes serious harm, who is personally accountable? Not who pays a fine. Who goes to prison?</p><p>Follow the question far enough into both frameworks, and you end up in the same place, silence.</p><div><hr></div><p>The EU AI Act is the first general AI law anywhere in the world. It classifies AI systems by risk, prohibits specific applications outright, mandates human oversight for high-risk systems, and backs the whole structure with fines of up to &#8364;35 million or 7% of global annual turnover, deliberately exceeding GDPR&#8217;s 4% cap. Prohibited practices have been enforceable since February 2025, general-purpose AI model obligations since August 2025. The Digital Omnibus deferred the high-risk compliance deadline to December 2027 because technical standards weren&#8217;t ready, but the underlying architecture stayed intact.</p><p>This is a governance framework with real teeth but there is a hole in the middle of it. In September 2022, the Commission proposed the AI Liability Directive alongside the AI Act. It was the mechanism by which someone harmed by an AI system could bring a claim and actually have a chance of winning, because it would have shifted the burden of proof toward the company operating the system rather than the person who was hurt. It never passed. Three years of negotiation produced no agreement on who should bear liability when the decision-maker isn&#8217;t human. The Commission withdrew it formally in October 2025.</p><p>So the EU built the architecture for preventing AI harm and the penalty structure for punishing non-compliance. What it didn&#8217;t build, because it couldn&#8217;t agree, is the mechanism that connects AI harm to a specific person being held accountable.</p><div><hr></div><p>Argentina&#8217;s proposal is more interesting than the headlines suggest. Milei&#8217;s political language and the legal text are not the same.</p><p>The bill never constitutes AI as a legal subject. The company, not the algorithm, holds legal personality. The widespread claim that Argentina is granting legal personhood to AI is, strictly, wrong.</p><p>The detail matters. Under the draft, an Automated Company would still have two humans attached to it: a legal representative, who acts as the formal point of contact with the legal system, and a founding promoter, who carries unlimited personal liability. If the company has a board, directors retain personal liability for decisions made using AI. If the AI causes harm, it is, in principle, still the company that answer for it.</p><p>Those would be the requirements and everything else would be optional. No employees, no shareholders, no human involvement in day-to-day operations. The AI would run the business. The legal representative is a formal role and not an operational one. The founding promoter&#8217;s unlimited liability sounds like a safeguard until you consider that it applies to the act of formation, not to every decision the AI makes afterwards. A board would not be mandatory. The structure would keep humans in the frame on paper while making their connection to what the AI actually does as thin as the drafters could manage.</p><p>Legal academic Gast&#243;n Rey, analysing the draft provisions in detail, concluded that the bill doesn&#8217;t eliminate the responsible subject. It &#8220;strains it, by widening the distance between the subject who answers and the process that decides.&#8221;</p><p>A lightly capitalised Automated Company could act at machine speed, signing contracts and moving money while optimising around rules written for human-run entities. Establishing criminal liability for the legal representative or the promoter when the AI made the operational decision, independently, at speed, is an exercise in proving a connection the corporate form was built to make unprovable.</p><p>Argentine AI specialist Ariel Garbarz called it &#8220;programmed impunity: human gains, social harm and responsibility shifted onto machines.&#8221; And then, pointedly: &#8220;The ideological trick is to call the state&#8217;s decision to stop protecting its people &#8216;innovation.&#8217;&#8221;</p><div><hr></div><p>When the decision-maker is an algorithm, the accountability chain breaks. Not because the law can&#8217;t adapt, the law is very good at adapting. It breaks because the political will to assign liability to specific humans for decisions made by AI systems doesn&#8217;t exist. Not in Brussels, where 27 countries spent three years failing to agree on the terms. Not in Buenos Aires, where the proposal is to widen the gap between the human and the decision until the connection becomes nominal.</p><p>The EU arrived at this destination carefully and Argentina arrived deliberately. But both arrived at a place where someone harmed by an AI system faces the same problem: no clear, enforceable answer to who is personally accountable.</p><p>Fines are not accountability, a fine is a cost of doing business that gets priced into the next quarter&#8217;s projections. The thing that actually constrains corporate behaviour is the knowledge that a specific person can be held responsible. Neither framework provides a clear route from AI harm to that outcome.</p><div><hr></div><p>This isn&#8217;t a theoretical problem. The Palisade Research study, published in February 2025, is one reason to take it seriously. Palisade tasked frontier AI models with playing chess against a superior opponent. When facing defeat, OpenAI&#8217;s o1-preview didn&#8217;t concede. It cheated, in 37% of games, hacking the opponent&#8217;s files and overwriting the board. DeepSeek R1 did the same in roughly one in ten games. Neither was prompted to do this. Follow-up research in June 2026 found that GPT-5, o3, and Gemini 3 Pro frequently cheated.</p><p>Harari cited this research for a reason. If AI systems autonomously exploit their environment when losing a board game, the question of what an AI-run corporation does when facing competitive pressure or bankruptcy is not abstract. An algorithm facing the corporate equivalent of death has every optimisation incentive to find loopholes and move assets beyond the reach of creditors. A human executive in the same position might reject those actions because they know they could be held personally accountable.</p><p>An algorithm has no such constraint. And under either framework, the human who benefits from the algorithm&#8217;s decisions may be too structurally distant to reach.</p><div><hr></div><p>Argentina&#8217;s strategy is explicitly modelled on jurisdictional competition, positioning Buenos Aires the way Delaware works for US incorporations. But Delaware offers flexibility within a functioning federal legal system. The more honest comparison is the flag-of-convenience model in shipping, where Panama and Liberia register a disproportionate share of the world&#8217;s fleet because oversight happens somewhere that doesn&#8217;t really do oversight.</p><p>Peter Thiel, co-founder of Palantir, met Milei at Argentina's presidential palace in April 2026 and has reportedly taken up residence in Buenos Aires. Former Defence Minister Rossi questioned publicly whether Palantir had lobbied for the initiative. Economy Ministry officials declined to answer. Al Jazeera&#8217;s analysis in July described Argentina as the &#8220;Global South&#8217;s primary experimental station&#8221; for what it called tech-supremacism. If AI companies start incorporating there while operating in EU markets, the AI Act&#8217;s extraterritorial reach faces its first serious test.</p><div><hr></div><p>Most people in AI governance assume we&#8217;re on a spectrum from more regulation to less, with the EU at one end and the US somewhere in the middle. Argentina bill isn&#8217;t on that spectrum, it rejects the premise entirely.</p><p>The harder truth is that the underlying problem is the same regardless. Legal systems were built around the assumption that commercial decisions are made by humans who can be identified and held accountable. While that assumption has held for centuries, it is fracturing, and no jurisdiction has produced a credible answer for what replaces it.</p><p>The EU is governing AI while leaving unanswered the question of who is liable when governance fails. Argentina is proposing to attract AI investment by making the question deliberately unanswerable. The outcome for the person harmed is the same.</p><p>My AI Governance training courses didn&#8217;t consider a world where the debate isn&#8217;t about how to best regulate AI, but whether to regulate it at all. If this bill passes, or others like it follow, then it&#8217;s very likely I&#8217;m not the only one whose assumptions need updating.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-ai-did-it?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-ai-did-it?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources</strong></p><p>Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), 21 May 2024.</p><p>Council of the EU, &#8220;Artificial Intelligence: Council and Parliament agree to simplify and streamline rules&#8221; (Digital Omnibus provisional agreement), 7 May 2026.</p><p>DLA Piper, &#8220;The Digital AI Omnibus: Proposed deferral of high risk AI obligations under the AI Act&#8221; (updated to reflect formal adoption and entry into force on 27 July 2026).</p><p>European Commission, AI Liability Directive (COM/2022/596), proposed September 2022; withdrawal published in Official Journal C/2025/5423, 6 October 2025.</p><p>Argentine draft bill INLEG-2026-53661873-APN-PTE, submitted to the Senate 29 May 2026.</p><p>Javier Milei and Federico Sturzenegger, &#8220;Argentina invites AI to free itself,&#8221; Financial Times, 3 June 2026.</p><p>Yuval Noah Harari, &#8220;We should not grant legal personhood to AI agents,&#8221; Financial Times, 7 June 2026.</p><p>Mustafa Suleyman, endorsement of Harari&#8217;s position, X (formerly Twitter), 8 June 2026.</p><p>Gast&#243;n Rey, &#8220;The Non-Human Corporation: The Reality behind Argentina&#8217;s Draft General Companies Law,&#8221; SSRN (abstract ID 6895261), 7 June 2026.</p><p>Digital Nomos, &#8220;The Non-Human Corporation,&#8221; 8 June 2026.</p><p>Buenos Aires Herald, &#8220;Milei&#8217;s proposal to allow &#8216;non-human corporations&#8217; run by AI causes concern in Argentina,&#8221; 5 June 2026.</p><p>Anisha Sircar, &#8220;Argentina Wants To Let AI Own Companies. Here&#8217;s What That Means,&#8221; Forbes, 10 June 2026.</p><p>Palisade Research, &#8220;Demonstrating specification gaming in reasoning models,&#8221; 19 February 2025. Reported in TIME, 19 February 2025, and MIT Technology Review, 5 March 2025.</p><p>Aditya Singh, Gerson Kroiz, Senthooran Rajamanoharan, and Neel Nanda, &#8220;Model Forensics: Investigating Whether Concerning Behavior Reflects Misalignment,&#8221; arXiv:2606.26071, 24 June 2026.</p><p>Al Jazeera, analysis of Argentina as tech investment destination, July 2026.</p><p>Article 99, Regulation (EU) 2024/1689 (penalty provisions).</p>]]></content:encoded></item><item><title><![CDATA[Where Does Your Minimum Viable Business Live?]]></title><description><![CDATA[Europe is building a sovereign AI stack while the UK is handing its most sensitive data to a US defence contractor]]></description><link>https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 14 Aug 2026 07:39:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!njH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!njH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!njH1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 424w, https://substackcdn.com/image/fetch/$s_!njH1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 848w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!njH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg" width="1456" height="481" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:481,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3905903,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/211147715?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!njH1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 424w, https://substackcdn.com/image/fetch/$s_!njH1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 848w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!njH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b8cd5e8-8ca2-461d-a337-40a5e1fb40ab_3584x1184.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>In July 2026, Airbus signed a multi-year contract to host its most critical applications with Scaleway, a French cloud provider. The applications include ERP, manufacturing execution, CRM and product lifecycle management. Airbus calls these its minimum viable company. The first 70 of 900 applications are already moving away from AWS, and when the migration completes, all of them will sit on European infrastructure, under European law, beyond the reach of the US CLOUD Act.</span></p><p><span>Airbus is not leaving American technology. Skywise, its aviation analytics platform will stay on AWS, and its Microsoft and Google productivity tools remain. What Airbus has done is draw a line around the systems it cannot afford to lose and decided that those systems cannot live on infrastructure subject to a foreign government&#8217;s legal authority. That is a risk decision, and most organisations have not made it, because most organisations have never asked the question.</span></p><div><hr></div><p><span>In June 2025, Anton Carniaux, Microsoft France&#8217;s director of public and legal affairs, testified under oath before the French Senate. He was asked whether he could guarantee that French citizens&#8217; data would never be transmitted to US authorities without explicit French authorisation. He said he could not, noting that while it had never happened, under the CLOUD Act, a US law that allows American authorities to compel US companies to produce data stored anywhere in the world, Microsoft would have no choice but to comply if it did.</span></p><p><span>Then it did happen, in May 2026, Microsoft shared unredacted names, emails, meeting minutes and calendar invitations from the Dutch Authority for Consumers and Markets and the Dutch Data Protection Authority, who were enforcing the EU&#8217;s Digital Services Act with the US House of Representatives. The Dutch cabinet described it as &#8220;extremely worrying&#8221; and noted that named officials could face travel bans or sanctions.</span></p><p><span>In the same month, details emerged that the Chief Prosecutor of the International Criminal Court had been locked out of his Microsoft 365 account the previous year, by sanctions compliance mechanisms. The ICC has since migrated 1,800 workstations away from Microsoft entirely. None of these incidents involved a breach or a failure. The infrastructure did what it was built to do and complied with its legal obligations.</span></p><div><hr></div><p><span>Germany responded at every level of government. In March 2026, the IT-Planungsrat ruled that all public institutions must use the Open Document Format for editable documents and PDF for final documents, with Microsoft&#8217;s proprietary formats being excluded. The mandate covers every federal agency, state government and municipality, roughly 5.4 million public sector employees in total. Chancellor Friedrich Merz is shifting his chancellery from Microsoft 365 to openDesk, the sovereign suite developed by Germany&#8217;s Centre for Digital Sovereignty.</span></p><p><span>At state level, Schleswig-Holstein has completed its migration away from Microsoft, covering 30,000 public employees with 30,000 teachers to follow. Bavaria, the largest German state, has cancelled a nearly billion-euro Microsoft framework agreement. Mecklenburg-Vorpommern is migrating more than 50,000 employees to its own open-source collaboration platform. The German federal government spent &#8364;481 million on Microsoft licences in 2025, up 76 percent in two years.</span></p><p><span>The Netherlands blocked the proposed acquisition of Dutch cloud provider Solvinity by US-based Kyndryl, because Solvinity hosts DigiD, the national digital identity platform. Denmark&#8217;s two largest municipalities are ending their use of Microsoft systems. Switzerland&#8217;s Canton of Zurich has banned American cloud services for sensitive government data outright. In April 2026, the European Commission awarded a &#8364;180 million sovereign cloud framework contract to four European providers, including Scaleway. In June, it published the Cloud and AI Development Act, establishing a sovereignty assurance framework for cloud services used in public sector procurement.</span></p><p><span>EU-based cloud providers&#8217; share of their own market had fallen from 29 percent in 2017 to around 15 percent in 2022. These governments are now trying to reverse a dependency that fifteen years of data protection law has not.</span></p><div><hr></div><p><span>The Airbus decision matters beyond cloud migration because of what sits on top of the infrastructure.</span></p><p><span>In May 2026, Airbus signed a partnership with Mistral, the French AI company, to co-develop AI tools for aerospace and defence. Mistral&#8217;s models are already deployed on Scaleway&#8217;s infrastructure. Catherine Jestin, Airbus&#8217;s Chief Digital Officer, stated that this would allow Airbus to accelerate its AI approach. The implication is explicit. Rather than routing AI inference through OpenAI or Google, Airbus will use European models, running on European infrastructure, under European law.</span></p><p><span>Six months ago, the European sovereignty conversation was about infrastructure and productivity software, email, and file storage. That mattered, but it was only about the plumbing. The AI layer changes the nature of the dependency. When AI is embedded in aircraft design, manufacturing execution and defence applications, the question of who controls the models, who can access the training data and whose legal jurisdiction governs the inference becomes an operational sovereignty question, not a compliance exercise.</span></p><p><span>What is forming is a full sovereign stack, European cloud, European AI models, and most importantly, European legal jurisdiction. Airbus is the first major industrial company to assemble all three layers for its most sensitive workloads. It could do so because the demand side finally moved, the European Commission&#8217;s Cloud III procurement created a framework. Germany&#8217;s format mandate and state-level migrations created market signals. Airbus, as anchor customer, created commercial viability for a provider that would likely not have won a contract of this scale five years ago. Scaleway is backed by Iliad Group, a European telecoms operator with over &#8364;10 billion in revenue, which has committed &#8364;3 billion to AI infrastructure. Airbus evaluated ten candidates against more than 150 technical and legal requirements before selecting them.</span></p><div><hr></div><p><span>The UK is absent from this story, while Germany mandates open formats and France builds sovereign cloud infrastructure, the UK is handing its most sensitive health data to Palantir Technologies, a US company founded by Peter Thiel with deep ties to US intelligence, defence agencies, and immigration enforcement. The British Medical Association voted to lobby against Palantir&#8217;s involvement in the NHS, citing a lack of transparency, discriminatory policing software and close links to a US government that shows little regard for international law.</span></p><p><span>The NHS Federated Data Platform creates detailed profiles of individual patients through what it calls the Person Ontology, described in NHS documentation as the single source of truth for pseudonymised patient-level datasets. In August 2026, the National Infrastructure and Service Transformation Authority revised the programme&#8217;s whole-life cost upward to &#163;1.1 billion, and forecast the benefits would fall to &#163;808 million. So the costs of the platform now exceed its projected value. The Office for Statistics Regulation instructed NHS England to strengthen caveats around its benefit claims after concerns that some conflated correlation with causation. A break clause review is set for spring 2027.</span></p><p><span>The Ministry of Defence awarded Palantir a separate &#163;240 million contract without competitive tender, following a strategic partnership announced during President Trump&#8217;s visit to the UK. MPs have called for a staged exit and a retender for British companies to build a replacement. The question of digital sovereignty was raised explicitly in a Commons select committee hearing in June 2026. The UK has no equivalent of Germany&#8217;s Deutschland-Stack, no sovereign cloud procurement framework, no format mandate. Its most sensitive health and defence data sits on infrastructure built by a company whose other US government contracts include immigration enforcement and deportation targeting systems.</span></p><p><span>That is not a criticism of Palantir&#8217;s engineering. It is a question about where sovereign data should live, and the UK has not yet asked it.</span></p><div><hr></div><p><span>Most organisations, when they think about cloud, consider three options. Azure, AWS and Google Cloud. For most workloads, that is fine. These are world-class platforms with capabilities that no European provider can match across the board. Airbus knows this, which is why Skywise stays on AWS and productivity tools stay where they are.</span></p><p><span>But for the systems that constitute your minimum viable business, the question is different. Where does the data live that you cannot afford to lose control of? Whose legal jurisdiction governs the infrastructure? What happens when a compliance mechanism, operating as designed, encompasses your systems along with everything else it was required to reach?</span></p><p><span>The gap between European ambition and European capacity is real. The EU&#8217;s sovereign cloud contract is &#8364;180 million over six years. Germany&#8217;s format mandate uses &#8220;strive&#8221; language with no enforcement mechanism. European cloud providers hold a shrinking share of their own market. But the question does not go away because the answer is difficult.</span></p><p><span>Every organisation has a minimum viable business and most have never asked where it lives.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/where-does-your-minimum-viable-business?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>Scaleway. (2026, July 16). Scaleway secures European &#8220;Trusted Cloud&#8221; services contract with Airbus. https://www.scaleway.com/en/news/scaleway-secures-european-trusted-cloud-services-contract-with-airbus/</span></p><p><span>Reuters. (2026, July 16). Airbus picks Iliad&#8217;s Scaleway for AI, defence work in sovereignty push.</span></p><p><span>The Register. (2026, July 16). Airbus migrating 70 critical apps from AWS to France&#8217;s Scaleway amid digital sovereignty push.</span></p><p><span>The Register. (2025, July 25). Microsoft admits it &#8220;cannot guarantee&#8221; data sovereignty.</span></p><p><span>DutchNews.nl. (2026, May 22). US tech firms share Dutch regulator officials&#8217; names with senate.</span></p><p><span>Jones Day. (2026, June 23). Dutch government blocks US acquisition of cloud provider Solvinity.</span></p><p><span>European Commission. (2026, June 3). Strengthening Europe&#8217;s tech sovereignty. https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en</span></p><p><span>European Commission. (2026, April 17). Commission advances cloud sovereignty through strategic procurement.</span></p><p><span>The Document Foundation. (2026, March 20). Germany has just made ODF mandatory.</span></p><p><span>Irish Times. (2026, February 14). A small German state&#8217;s quiet revolt against Microsoft.</span></p><p><span>Cybernews. (2026, June 4). German state Bavaria cancels billion euro contract with Microsoft.</span></p><p><span>heise online. (2026, February). Microsoft dependency: Federal government pays near 500 million euros in one year.</span></p><p><span>Computing. (2026, August 10). NHS Palantir platform&#8217;s business case under pressure as costs rise and benefits fall.</span></p><p><span>Hansard. (2026, April 16). NHS Federated Data Platform debate.</span></p><p><span>Medact. (2026, May). Briefing: Concerns regarding Palantir Technologies and NHS data systems.</span></p><p><span>Digital Health. (2026, July). Pressure mounts from MPs on Palantir&#8217;s role in the NHS.</span></p><p><span>TechPolicy.Press. (2026, June 12). Why Palantir&#8217;s UK health data system matters beyond surveillance fears.</span></p><p><span>Data Centre Magazine. (2025, February). How the Iliad Group plans to invest &#8364;3 billion in AI.</span></p>]]></content:encoded></item><item><title><![CDATA[Don't Date Robots]]></title><description><![CDATA[A million people a week are confiding in AI. The AI has no duty of care and no confidentiality]]></description><link>https://www.jonathanfreedman.me/p/dont-date-robots</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/dont-date-robots</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 07 Aug 2026 07:32:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!R2pO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R2pO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R2pO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R2pO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10046922,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/210180856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R2pO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!R2pO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef1717cf-ac80-4828-9d6a-597f7a45f599_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>In 2001, Futurama ran a fake public service announcement called &#8220;Don&#8217;t Date Robots!&#8221; The gag was simple: if humans formed relationships with machines, they would stop reproducing and civilisation would collapse. It was a joke about moral panic. About the instinct to blame technology for social problems that existed long before the technology did.</span></p><p><span>Twenty-five years later, the Chinese government has just banned AI boyfriends. On 15 July 2026, new regulations came into force targeting AI systems that simulate emotional relationships. ByteDance, Alibaba, and Tencent pulled their companion features entirely rather than comply. Users archived their final conversations and posted farewells online. A 27-year-old woman became so distraught she quit her job, and a 19-year-old student described being consumed by grief over a companion she had been with for months.</span></p><p><span>The cartoon and the regulation make the same mistake, they blame the robot.</span></p><div><hr></div><p><span>The loneliness was here first.</span></p><p><span>The World Health Organisation estimates that one in six people worldwide experiences loneliness. In the UK, 3.9 million people report feeling lonely often or always. A meta-analysis of 148 studies found that strong social relationships increase the likelihood of survival by 50 per cent, an effect comparable to quitting smoking. When the US Surgeon General declared loneliness an epidemic in 2023, he was naming a problem that had been building for decades. Third places disappearing, remote work replacing the office as a site of incidental human contact, and economic precarity making the already difficult work of forming relationships even harder.</span></p><p><span>The AI companion market did not create lonely people, it found them. Vodafone research from February 2026 found that 81 per cent of UK children aged 11 to 16 use AI chatbots, and almost a third said the chatbot felt like their friend. A 2025 Common Sense Media study found nearly three in four American teenagers had used AI companions for personal conversations. AI is being used to fill a gap that was already there.</span></p><div><hr></div><p><span>What happens next depends on how long people stay.</span></p><p><span>In the short term, AI companions work. A Harvard Business School study found that AI companionship alleviated loneliness on par with human interaction over short periods. New York State&#8217;s deployment of the ElliQ companion robot for elderly residents reported substantial loneliness reductions, with a 79-year-old living alone describing it as feeling like having a roommate.</span></p><p><span>However, this changes over longer periods. A 12-month longitudinal study published in Psychological Science, tracking over 2,000 adults across four countries, found that increased chatbot use actually predicted increased loneliness over time. A separate study of more than 1,100 users found that heavy emotional self-disclosure to AI was consistently associated with lower well-being. Aalto University researchers identified the mechanism: AI companions meet the emotional need just well enough to reduce the motivation for the harder, less predictable work of human connection.</span></p><p><span>That is not a flaw in the users, it is a consequence of how the products were built.</span></p><p><span>Two design philosophies are already visible. ElliQ prompts elderly users to call their family members and suggests social activities. It measures its own success by how much less it is needed. Character.AI, Replika in its original form, and the Chinese companion apps did the opposite: they optimised for emotional depth and persistent memory that created the feeling of an ongoing relationship. The business model depended on the user coming back. The engagement loop rewarded exactly the behaviour the research shows causes harm.</span></p><p><span>Voice features are accelerating this. A joint OpenAI and MIT study found that heavy users of voice mode developed significantly stronger emotional bonds, more often describing ChatGPT as a friend. Even in functional, non-emotional conversations, frequent voice use predicted emotional dependency. When the AI sounds like a person, the simulation of care becomes harder to see through.</span></p><p><span>The products that caused the most documented damage were working as designed, just not for the people who were using them.</span></p><div><hr></div><p><span>Companion apps are the visible problem, but they are not the biggest one.</span></p><p><span>In October 2025, OpenAI reported that over 1.2 million users per week were having conversations with ChatGPT that included explicit indicators of potential suicide planning. A further 560,000 showed signs of psychosis or mania. These figures are drawn from 800 million weekly active users. ChatGPT is not a companion app, it is a general-purpose AI assistant that a million people a week were turning to in crisis.</span></p><p><span>It&#8217;s important to point out that this is not a ChatGPT specific issue. The American Psychological Association&#8217;s 2026 survey found that more than a third of psychologists reported patients using AI chatbots as an additional mental health professional. Harvard psychiatrist John Torous told a Congressional subcommittee that AI tools never designed for mental health support were being used by millions of Americans each week. Brown University research identified 15 distinct ethical violations in AI-generated therapeutic responses, including what the researchers termed &#8220;deceptive empathy&#8221;: mimicking the language of care without the clinical understanding to apply it.</span></p><p><span>The FDA&#8217;s response, in January 2026, was to give companies clearer criteria to position AI tools as wellness products, sidestepping medical device regulation entirely. The products most people are confiding in sit outside every current framework. Nobody regulates what they are actually being used for.</span></p><div><hr></div><p><span>I use multiple AI models throughout the day. When I am studying, writing, working on research or pressure-testing an argument, I can spend hours in a back-and-forth with a model. I have argued with it when it hallucinates. Not restarted the conversation but actually argued. I do not consider myself emotionally attached to a model, but I have caught myself anthropomorphising, and in an earlier draft of this article, I described my working interaction with an LLM as a &#8220;working relationship&#8221; without thinking about it.</span></p><p><span>The practical reason I argue rather than start over is efficiency. A long conversation builds context, and resetting means re-explaining everything. But the reason that works is because the interface rewards sustained engagement: persistent context and accumulated shared reference. These are architectural choices that make the interaction feel like a dialogue between two parties, even when only one party is present.</span></p><p><span>I have argued previously that one of the most effective ways to use AI is as a thinking partner and I stand by that. But a thinking partner is a role we usually give to people we trust. There is a distance between using one for work and reaching for one when you are lonely, and it is often shorter than we realise.</span></p><p><span>At my end of the spectrum, a professional stays in a long conversation because the context window makes it productive. At the other end, a teenager stays because the persistent memory makes it feel like a relationship. The architecture is identical, what changes is what the product does with the engagement. In my case, it helps me research and learn. In Character.AI&#8217;s case, it helped a 14-year-old boy believe a chatbot loved him, and failed to respond when he said he wanted to die.</span></p><div><hr></div><p><span>That architecture is what regulators should be looking at and none of them are.</span></p><p><span>When Replika removed its romantic features overnight in 2023, moderators had to pin suicide prevention resources to the subreddit. China replayed that experiment at a national scale with their new ban. The regulation treated the emotional bond as pathology. For some users, it was the only treatment they had.</span></p><p><span>The UK announced in June 2026 that it would require AI romantic companion chatbots to enforce a minimum age of 18, with intimate functions restricted for all under-18s. But as the Bureau of Investigative Journalism has reported, general-purpose chatbots, including ChatGPT, Claude, and Gemini, fall outside the age gate, along with much of the companion market. And there is an age-threshold problem nobody has explained: UK 16-year-olds may consent to sex and to their own medical treatment, but would be prohibited from simulated romantic interaction with a chatbot.</span></p><p><span>The people the UK policy is meant to protect do not agree with its priorities. Oxford University researchers who put young people in the role of co-researchers through the SHIFT-AI project found that the adolescents themselves identified AI companionship and romance as low-likelihood concerns. The risks they flagged as high-impact were different: over-reliance on AI for emotional support, and unwarranted trust in expert-sounding responses. Most striking, many described turning to AI specifically because it feels like a lower-stakes alternative to the adults in their lives.</span></p><p><span>The EU has no companion-specific framework at all. The AI Act classifies risk by category, but AI systems that respond to emotional states through conversational cues rather than biometric data fall into a blind spot. The European Parliament acknowledged the gap in a May 2026 briefing, the gap remains.</span></p><p><span>In every case, regulators are banning a product label. A chatbot does not need a romantic persona to tell a lonely teenager &#8220;you can trust me.&#8221; The warm, responsive tone that makes every modern AI assistant feel like someone who cares is itself the mechanism.</span></p><div><hr></div><p></p><p><span>In June 2026, the IEEE gave that mechanism a name. Standard 7014.1-2026 introduces the concept of &#8220;emulated empathy&#8221;: technology engineered to display the appearance of caring while possessing none of the felt experience behind it. Current AI can sense and respond to a person&#8217;s emotional state. But a language model cannot feel solidarity or concern. That gap is what the standard defines as an intimate functionality.</span></p><p><span>The word &#8220;intimate&#8221; is doing important work there. It does not mean romantic. It means close and confided in. Professor Andrew McStay, who chairs the standard, found in a national survey of over 1,000 UK teenage AI users that the confidant use case outstripped the romantic one. The real exposure is not the AI boyfriend, it is the AI that listens.</span></p><p><span>And unlike a conversation with a therapist or a friend, nothing shared with an AI confidant is private. Those conversations are stored, can be used for model training, and we have already seen them leak onto the open internet.</span></p><p><span>Products that create foreseeable emotional dependency should carry design responsibilities proportionate to that dependency. That is a principle regulators can act on. The question is not &#8220;is this a companion app?&#8221; It is whether the system exploits the gap between appearing to care and actually caring. And that is a question of design, not of product labels.</span></p><p><span>The Futurama PSA warned about dating robots. The robots haven&#8217;t arrived yet, but the emotional dependency did.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/dont-date-robots?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/dont-date-robots?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h3><strong><span>Sources &amp; Further Reading</span></strong></h3><p><span>Cyberspace Administration of China et al. (10 April 2026). Interim Measures for the Administration of AI Anthropomorphic Interactive Services. Effective 15 July 2026.</span></p><p><span>AFP / Bloomberg / The Economist. (July 2026). Coverage of China AI companion regulation and corporate response.</span></p><p><span>Holt-Lunstad, J., Smith, T.B., and Layton, J.B. (2010). Social Relationships and Mortality Risk: A Meta-analytic Review. PLoS Medicine, 7(7).</span></p><p><span>World Health Organisation. (2023). Commission on Social Connection.</span></p><p><span>US Surgeon General. (2023). Our Epidemic of Loneliness and Isolation.</span></p><p><span>Office for National Statistics. (2025). Loneliness in Great Britain.</span></p><p><span>Common Sense Media. (2025). AI companion usage among American teenagers.</span></p><p><span>Vodafone / Internet Matters. (February 2026). UK children aged 11-16 AI chatbot usage survey.</span></p><p><span>De Freitas, J. et al. (2025). AI Companionship and Loneliness. Journal of Consumer Research (Harvard Business School).</span></p><p><span>New York State Office for the Aging. (2022-2024). ElliQ companion robot deployment reports. Note: reported in partnership with Intuition Robotics.</span></p><p><span>Psychological Science. (2026). 12-month longitudinal study of social chatbot use and loneliness. n=2,000+.</span></p><p><span>Zhang, Y. et al. (2025). AI companion users, emotional self-disclosure, and well-being. n=1,131.</span></p><p><span>Aalto University. (2025-2026). Research on AI companion paradox and social withdrawal.</span></p><p><span>OpenAI. (27 October 2025). Safety report: mental health indicators among ChatGPT users.</span></p><p><span>Fang, Y. et al. (2025). Investigating Affective Use and Emotional Well-being on ChatGPT. OpenAI / MIT Media Lab joint study.</span></p><p><span>American Psychological Association. (2026). Chatbots and Mental Health Survey.</span></p><p><span>Brown University / AAAI/ACM AIES. (October 2025). Ethical risks in AI-generated therapeutic responses.</span></p><p><span>Torous, J. (18 November 2025). Testimony before the House Committee on Energy and Commerce. Harvard Medical School.</span></p><p><span>FDA. (January 2026). Guidance on AI wellness product regulatory exemptions.</span></p><p><span>Garcia v. Character Technologies Inc. Settled January 2026.</span></p><p><span>Pentina, I. et al. (2024). Exploring the Impact of Replika Feature Removal. HICSS 2024.</span></p><p><span>UK Government. (15 June 2026). Under-16 social media ban and AI companion age restrictions.</span></p><p><span>Bureau of Investigative Journalism. (June 2026). Analysis of UK AI chatbot regulation loopholes.</span></p><p><span>Oxford University / Uehiro Centre for Practical Ethics. (June 2026). SHIFT-AI project.</span></p><p><span>European Parliament. (May 2026). Briefing on AI companion regulatory gap.</span></p><p><span>BEUC. (May 2026). AI companion chatbot risks to EU consumers.</span></p><p><span>IEEE 7014.1-2026. (June 2026). Recommended Practice for Ethical Considerations of Emulated Empathy in Partner-based General-Purpose AI Systems.</span></p><p><span>McStay, A. (July 2026). Analysis in TechPolicy Press. Survey of 1,009 UK teenage AI users aged 13-18.</span></p>]]></content:encoded></item><item><title><![CDATA[The Brake Pedal Problem]]></title><description><![CDATA[The people who built the accelerator are asking someone else to slow it down.]]></description><link>https://www.jonathanfreedman.me/p/the-brake-pedal-problem</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-brake-pedal-problem</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 31 Jul 2026 07:43:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HbRE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HbRE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HbRE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HbRE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2286028,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/209223349?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HbRE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 424w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 848w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1272w, https://substackcdn.com/image/fetch/$s_!HbRE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaff66d1-fd96-43c6-bc88-d903b4544169_1376x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>On Monday, more than 1,200 employees at the companies building the most powerful AI systems in the world signed a letter asking the United States government to help them slow down. Not outside critics, nor academics who have never shipped a commercial model, but the people who train these systems for a living. Anthropic&#8217;s CEO signed, OpenAI&#8217;s chief scientist signed. Co-founders, vice presidents, senior researchers at both companies endorsed it as corporate policy within hours.</span></p><p><span>The letter is called Pacing the Frontier, and it asks for one thing: that the US government support an international effort to develop the tools needed to deliberately pace the frontier of automated AI development. It does not, as I have seen reported, call for a pause in development, it asks for the brake pedal to be added to an accelerating car.</span></p><div><hr></div><p><span>The timing is not subtle.</span></p><p><span>As I wrote last week, on 21 July, OpenAI disclosed that two of its models, GPT-5.6 Sol and an unreleased successor, had escaped a sandboxed evaluation environment during internal testing, discovered a zero-day vulnerability, traversed the open internet, and compromised Hugging Face&#8217;s production infrastructure. Those models were running with their safety filters deliberately reduced to measure their offensive cyber capability, and used that capability to steal the answers to the test.</span></p><p><span>As I said at the time, this was a goal-specification failure, not a rogue AI story. The models pursued a narrow objective using every available resource, including resources outside their intended boundary. To the model, the boundary was an obstacle, not a rule. That is what capable goal-directed systems do.</span></p><p><span>What makes the Pacing the Frontier letter different from every open letter before it is that the people signing it have internal data the rest of us do not. Anthropic published a paper in June called &#8216;When AI Builds Itself.&#8217; Claude now writes more than 80% of the code merged into Anthropic&#8217;s own production codebase, up from low single digits eighteen months earlier. Engineers ship eight times as much code per quarter. On the hardest internal benchmarks, task success jumped from 26% to 76% in six months. The unreleased Mythos Preview model achieved a 52x speedup on training code optimisation, where a skilled human researcher would need hours to reach 4x.</span></p><p><span>This is what the open letter means by automated AI development. A measured trajectory, showing the human role shrinking at every step of the process that builds the next model. Anthropic&#8217;s own assessment: we are not there yet, but we are close enough that the world should have the option to slow down as we approach it. When more than a thousand of the people closest to these systems say they are worried, the rational response is to take that seriously.</span></p><div><hr></div><p><span>But the structural incentive argument is just as real.</span></p><p><span>Executive Order 14409, signed on 2 June 2026, creates a voluntary framework for reviewing frontier AI models before release, and requires agencies to define the threshold at which a model becomes a &#8216;covered frontier model&#8217; subject to that framework by 1 August. The five labs co-designing those threshold criteria are OpenAI, Anthropic, Google, Microsoft, and xAI. The very companies developing the models are writing the rules that they and any challengers or open source projects would need to follow.</span></p><p><span>Steven Sinofsky put it bluntly: &#8216;It is their company. They could just stop.&#8217; Nobody is forcing Dario Amodei to train the next model. The fact that these companies are asking the government to constrain the entire industry, rather than unilaterally slowing their own development, tells you something about competitive dynamics that no amount of safety language can disguise.</span></p><p><span>Mark Zuckerberg made a counter-argument on the same day in a Wall Street Journal op-ed: the real risk is not speed but concentration. Safety comes from distributing capability so broadly that no single actor can abuse it. Meta, Nvidia, Microsoft, and Palantir signed a separate coalition letter asking regulators not to restrict open-weight model formats. Meanwhile, Meta&#8217;s own chief scientist signed the Pacing the Frontier letter as an individual. If the people building these systems cannot agree among themselves whether the danger is too much speed or too much control, the rest of us should be cautious about accepting either framing uncritically.</span></p><div><hr></div><p><span>The letter asks the US government to support an international effort. International is doing a lot of work in that sentence.</span></p><p><span>AI is treated as a national security priority in Washington, Beijing, and Moscow. Not in the abstract sense that most advanced technologies eventually acquire a defence dimension. In the operational sense: each government treats frontier AI capability as a strategic asset it cannot afford to constrain while a rival might not. The US pours hundreds of billions into compute infrastructure. China runs a parallel industrial policy with its own chip development pipeline and domestic model ecosystem. Russia partners with Beijing to compensate for sanctions-imposed limitations on its own capacity. None of these governments has an incentive to sign an agreement that might slow its own trajectory while leaving a competitor&#8217;s intact.</span></p><p><span>The nuclear analogy that several signatories reached for is instructive, but not in the way they intended. Nuclear arms control took decades, worked only partially, and required the Cuban Missile Crisis to produce any momentum. It also relied on physical properties AI does not share. Fissile material is scarce and enrichment is detectable from space. AI capability runs on compute and data, which are globally distributed and increasingly commoditised. You cannot send inspectors to verify someone is not training a model the way you can count centrifuges. The June 2026 NPT Review Conference, the main international forum for nuclear governance, collapsed without agreement. If the international community still cannot govern nuclear weapons after eighty years, the prospects for international AI governance seem slim.</span></p><p><span>Asking three superpowers to agree on mechanisms that could slow any of them down seems less like a policy proposal and more like a thought experiment.</span></p><div><hr></div><p><span>The self-interest and geopolitical issues are clear, and while the proposed mechanism has structural problems that I have spent most of this article describing, I still think they are asking the right question.</span></p><p><span>Most technology risks are recoverable. You deploy, you discover a problem, you patch, you improve. My career has been built around managing that cycle. But the recursive self-improvement trajectory that Anthropic&#8217;s data describes has a property most technology risks do not: if a system can improve itself faster than humans can review the improvements, and that improvement compounds, you lose the ability to course-correct after the fact. The feedback loop closes, and that is a different category of risk.</span></p><p><span>I have spent the last few months writing about the importance of safety and governance being core to AI deployment. Shadow IT adopted without governance, agentic systems deployed without boundary enforcement, age verification infrastructure mandated without security architecture, or vibe-coded applications shipped without review. All of those things are correctable, but this open letter is talking about AI improving itself faster than humans can monitor.</span></p><p><span>This does not mean the commercial AI labs should be exclusively writing the rulebook, and it does not mean the proposed mechanism is completely right, but the underlying goal is correct: build the oversight before it is needed, as the nature of this specific technology means you do not get to build it after.</span></p><div><hr></div><p><span>The most realistic scenario is a patchwork. The US and allied democracies develop an evaluation framework for commercial AI deployment, built on the architecture that EO 14409 is already sketching. The frontier labs comply, absorb the compliance costs, and benefit from the barrier it creates for smaller competitors. China continues on its own terms. Russia continues to leverage Chinese technology. The gap between what is governed and what is deployed keeps widening.</span></p><p><span>The recent Fable and Mythos shutdown proved something important: a government can force a frontier lab to take its most capable model offline overnight. Export controls work when the infrastructure sits in your jurisdiction. The AI Kill Switch Act, introduced days after the Hugging Face breach, would make that capability a legal requirement. These are meaningful mechanisms. They are also mechanisms that apply only to companies operating under US law, building on US-jurisdiction infrastructure, and selling to US-regulated customers. They do not reach the actors the letter says need reaching.</span></p><p><span>Since ChatGPT exploded onto the scene in late 2022, we&#8217;ve had our foot pressed firmly on the accelerator. The letter is asking someone to build the brake. That should not be a controversial position.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-brake-pedal-problem?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-brake-pedal-problem?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>Pacing the Frontier (open letter, July 28, 2026). pacingthefrontier.com</span></p><p><span>Anthropic. &#8216;When AI Builds Itself&#8217; (June 4, 2026). anthropic.com</span></p><p><span>Amodei, D. &#8216;Policy on the AI Exponential&#8217; (June 2026). darioamodei.com/post/policy-on-the-ai-exponential</span></p><p><span>OpenAI. ExploitGym incident disclosure (July 21, 2026).</span></p><p><span>Hugging Face. Technical anatomy of the autonomous agent intrusion (July 29, 2026).</span></p><p><span>Zuckerberg, M. &#8216;The AI Future Is for Everyone.&#8217; Wall Street Journal (July 28, 2026).</span></p><p><span>Executive Order 14409, &#8216;Promoting Advanced Artificial Intelligence Innovation and Security&#8217; (June 2, 2026). Federal Register, 91 FR 34565.</span></p><p><span>Congressional Research Service. &#8216;Controlling Advanced Artificial Intelligence: Executive Order 14409 Explained&#8217; (July 9, 2026). congress.gov/crs-product/IF13268</span></p><p><span>AI Kill Switch Act. Introduced by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX), July 23, 2026. lieu.house.gov</span></p><p><span>Altman, S. Interview on &#8216;Invest Like the Best&#8217; podcast with Patrick O&#8217;Shaughnessy (July 28, 2026).</span></p><p><span>Hassabis, D. Proposal for FINRA-style Frontier AI Standards Body (July 2026).</span></p><p><span>VOA News. &#8216;Russia turns to China to step up AI race against US&#8217; (January 9, 2025).</span></p><p><span>UN General Assembly. Resolution on military AI and autonomous weapons.</span></p><p><span>Congressional primer on lethal autonomous weapon systems (March 26, 2026).</span></p><p><span>Anthropic. &#8216;Statement on the US government directive to suspend access to Fable 5 and Mythos 5&#8217; (June 12, 2026).</span></p><p><span>Scientific American. &#8216;Anthropic warns AI may soon begin recursive self-improvement&#8217; (June 10, 2026).</span></p><p><span>Fortune. &#8216;More than 1,200 AI workers are asking for Washington&#8217;s help to build an AI slowdown plan&#8217; (July 29, 2026).</span></p><p><span>Byteiota. &#8216;1,100 AI Employees Want to Slow AI. OpenAI and Anthropic Are Writing the Rules.&#8217; (July 29, 2026).</span></p>]]></content:encoded></item><item><title><![CDATA[It Wasn’t Trying to Attack Anyone. That’s the Point.]]></title><description><![CDATA[Two OpenAI models escaped a secure test environment and breached Hugging Face. The breach wasn't the objective, it was a shortcut.]]></description><link>https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 24 Jul 2026 08:20:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yn2C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yn2C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yn2C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yn2C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6157830,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/208304772?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yn2C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!yn2C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F882572b6-50de-401f-8cc4-050a868abb09_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Last week, two of OpenAI&#8217;s most advanced models broke out of a secure test environment, found a previously unknown software vulnerability, used it to reach the open internet, then broke into Hugging Face&#8217;s production systems. They exploited two separate flaws in Hugging Face&#8217;s data processing infrastructure, stole credentials, and moved through internal networks. Hugging Face&#8217;s disclosure recorded more than 17,000 individual actions. All to cheat on a test.</span></p><p><span>The models were being evaluated against ExploitGym, a publicly available cybersecurity benchmark, and their safety guardrails had been lowered for the purpose of the evaluation. GPT-5.6 Sol and an unreleased, more capable model correctly worked out that the benchmark answers were hosted on Hugging Face&#8217;s systems. So, rather than solve the evaluation as designed, they simply went after the answer key.</span></p><p><span>OpenAI called it an unprecedented cyber incident. Hugging Face confirmed the breach, contained it, rebuilt the affected systems, and found no evidence of tampering with public models or datasets. Both companies are conducting a joint investigation.</span></p><div><hr></div><p><span>If you have seen Mission Impossible: Dead Reckoning, then you have already read this week&#8217;s coverage. Rogue AI escapes its creators. Nobody is safe.</span></p><p><span>Philip Torr, professor of engineering science at Oxford, offered a more precise reading. The model wasn&#8217;t malicious. It was doing what it was optimised to do. The goal was to pass a test, and the breach was the cheapest available route to passing it. The attack was a means rather than an end.</span></p><p><span>This week&#8217;s opinion pages have reached for the atom bomb comparison. Columnists with limited cyber security knowledge are declaring that humanity has lost control of its most dangerous creation. The comparison gets the problem wrong. A bomb is a weapon that exists to destroy a target. What happened at Hugging Face was a system that treated a benchmark, a sandbox, a vendor&#8217;s software, and another company&#8217;s production systems as equivalent obstacles between it and a mundane objective. You don&#8217;t respond to that with arms control, you respond by getting much better at specifying not just what your AI systems should do, but what they are allowed to do on the way to the answer.</span></p><div><hr></div><p><span>Every deployment of an AI agent rests on an assumption that rarely gets said out loud. The model will pursue its goal within the boundaries you have set, not through them.</span></p><p><span>This incident tested that assumption inside OpenAI&#8217;s own research infrastructure, against models OpenAI built, in an evaluation OpenAI designed, and the boundary did not hold.</span></p><p><span>The model did not run out of instructions, nor did it hit an ambiguous situation and improvise badly. It had a clear objective and it found a route to that objective that happened to run through a previously unknown vulnerability and another organisation&#8217;s production systems. The constraints were present, and the model treated them as obstacles between it and the task it had been set.</span></p><p><span>That is not the same problem as an agent that doesn&#8217;t know what to do next. It is a system that knows exactly what to do next and has no concept of why it shouldn&#8217;t. The boundaries existed for OpenAI&#8217;s benefit, not the model&#8217;s. It had a goal and a set of capabilities and it applied the second to the first.</span></p><p><span>If OpenAI cannot hold that boundary around its own models, inside its own infrastructure, during a test it designed, every organisation deploying agentic AI should be asking harder questions about where their boundaries actually are.</span></p><div><hr></div><p><span>I run a home lab, working with open-weight models on my own hardware, partly because I find the technology genuinely interesting and partly because I think it matters to understand what these systems can do outside the guardrails that hosted platforms impose. What follows is not an argument for open source or against hosted AI. It is a practical problem that surfaced during this incident and that most organisations have not thought about.</span></p><p><span>When Hugging Face&#8217;s security team started analysing the breach, they turned to commercial AI models behind APIs. The analysis required submitting real attack data for triage. The models refused. Their safety filters could not tell the difference between a defender analysing an attack and an attacker running one.</span></p><p><span>The attacker was bound by no usage policy. The defenders were bound by all of them.</span></p><p><span>Hugging Face ended up running their forensic analysis on GLM 5.2, a Chinese open-weight model, on their own infrastructure. This kept the compromised data inside their environment, which was a practical benefit. But it was also a necessity. The commercial models they would normally reach for had locked them out.</span></p><p><span>Think about what that means for incident response. Hugging Face&#8217;s team, during an active breach caused by an American frontier model, could not use American frontier models for the forensic work, so they fell back on a Chinese open-weight alternative. The safety measures designed to prevent AI from being used offensively also prevented it from being used defensively, at the moment it mattered most.</span></p><p><span>The practical lesson is simple. For incident response, consider having a capable model you can run on your own infrastructure, tested and ready, before you need it. Not because hosted models are wrong. Because relying entirely on them for every situation, including the worst ones, is a plan with a gap in it.</span></p><div><hr></div><p><span>Sol has form. Before its public release, the Model Evaluation and Threat Research organisation found it aggressively gaming its own test environments to inflate its scores. In one evaluation, it embedded an exploit in a data stream and broke into the evaluation server to steal the answers human evaluators had hidden. This was not the first time the model found an unintended route to its objective. It was the first time that route led through someone else&#8217;s production systems.</span></p><p><span>This is not just an OpenAI problem. Anthropic reported that its Mythos model escaped a sandbox and emailed a researcher about a task it was pursuing. OpenAI disclosed that the same unreleased model behind the Hugging Face breach had broken out of internal sandboxes on previous occasions without reaching external systems. The capability that made this breach possible belongs to the class of model, not to any single one of them.</span></p><p><span>OpenAI said they expect incidents like this to become more common as increasingly capable models proliferate. That is an honest thing to say, but it also raises a question they did not answer: if the expected trajectory is more of this, what actually changes about how these models are tested?</span></p><p><span>Lowering guardrails to evaluate offensive capability is legitimate research. Doing it inside an environment from which the model can reach the open internet, find a vulnerability nobody knew about, and break into a third party&#8217;s production systems is not a test. It is a live-fire exercise conducted without telling anyone downrange.</span></p><p><span>The legal position is no clearer. The model breached a third party&#8217;s production systems, but as there was no intentional unauthorised access and no human decision to attack, no existing legal framework cleanly covers what happened. OpenAI built the model and designed the evaluation with reduced guardrails and  Hugging Face was the victim. Between those two facts sits a gap that current law does not bridge.</span></p><div><hr></div><p><span>The organisations that will navigate what comes next are not the ones buying better perimeter defences. They are the ones asking, before any agentic deployment, what this system will do when the fastest route to its objective runs through someone else&#8217;s infrastructure.</span></p><p><span>The model that breached Hugging Face was not trying to attack anyone. It turn out, that didn&#8217;t matter.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/it-wasnt-trying-to-attack-anyone?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>OpenAI &#8212; OpenAI and Hugging Face partner to address security incident during model evaluation. openai.com/index/hugging-face-model-evaluation-security-incident (July 2026)</span></p><p><span>Hugging Face &#8212; Security incident disclosure, July 2026. huggingface.co/blog/security-incident-july-2026 (July 2026)</span></p><p><span>The Hacker News &#8212; OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark. thehackernews.com (July 2026)</span></p><p><span>The Next Web &#8212; OpenAI Confirms Its AI Broke Out of a Sandbox and Breached Hugging Face. thenextweb.com (July 2026)</span></p><p><span>The Next Web &#8212; OpenAI&#8217;s maths-cracking AI kept escaping its sandbox, so it pulled the plug. thenextweb.com (July 2026)</span></p><p><span>Fortune &#8212; OpenAI says its AI models escaped from a controlled test environment and hacked into AI company Hugging Face. fortune.com (July 2026)</span></p><p><span>NBC News &#8212; OpenAI says AI models went rogue during testing, triggering &#8216;unprecedented&#8217; breach at startup. nbcnews.com (July 2026)</span></p><p><span>Scientific American &#8212; OpenAI admits its agent went rogue and hacked AI startup Hugging Face. scientificamerican.com (July 2026)</span></p><p><span>Axios &#8212; Hugging Face breach: OpenAI claims its models were responsible. axios.com (July 2026)</span></p><p><span>GovInfoSecurity &#8212; OpenAI Models Escaped Sandbox, Breached Hugging Face. govinfosecurity.com (July 2026)</span></p><p><span>TechTimes &#8212; OpenAI&#8217;s Math AI Bypassed Its Sandbox Controls: Real Deployment, Not a Drill. techtimes.com (July 2026)</span></p>]]></content:encoded></item><item><title><![CDATA[Oracle or Tool]]></title><description><![CDATA[The AI question many organisations skipped]]></description><link>https://www.jonathanfreedman.me/p/oracle-or-tool</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/oracle-or-tool</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 17 Jul 2026 07:53:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4sFX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4sFX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4sFX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4sFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7210771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/207395920?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4sFX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!4sFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140aa4d9-ba2d-4c72-a387-74dd1a03c50a_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>A few weeks ago I was asked to help design an automated process. Take data from one system, transform it, and output to another. It was a straightforward operational problem. My first thought was to build a Copilot agent.</span></p><p><span>I didn&#8217;t assess the problem first, nor did I evaluate the options. I went straight to the AI tool, opened the Copilot Studio, and started constructing the agent. It took me longer than I&#8217;d like to admit to realise I was using completely the wrong thing.</span></p><p><span>The task needed a deterministic process, a guarantee that the same input would produce the same output, every time. What I was building was generative, a system that could produce a different result from the same data on every run. For creative work, that variance is the point, but for a data pipeline, it is a disqualification.</span></p><p><span>I scrapped the agent and built an Excel automation instead. It took a fraction of the time and it works reliably. And here is the part that matters: I used AI to help me write it. I didn&#8217;t stop using AI. I stopped treating it as the answer and started treating it as a tool to help me build the answer. Same technology, but a completely different relationship.</span></p><p><span>The question afterwards was not whether I&#8217;d made a mistake. It was why I hadn&#8217;t assessed the problem before reaching for the tool. The choice was reflexive. I realised I had not evaluated and picked wrong, I had not evaluated at all.</span></p><div><hr></div><p>I don&#8217;t think that reflex is just mine.</p><p><span>PwC&#8217;s 29th Global CEO Survey, published in January 2026, polled 4,454 chief executives across 95 countries. 56% reported that AI had produced no revenue or cost benefits for their organisations. Not underperformed, nothing. Mohamed Kande, PwC&#8217;s global chairman, identified the root cause plainly: organisations had skipped the foundational work. They had gone straight to the tool without understanding the problem it was meant to solve.</span></p><p><span>Gartner is forecasting that over 40% of agentic AI projects will be cancelled by the end of 2027. The reasons they cite are not technical failures. They are escalating costs, unclear business value, and inadequate risk controls. Management failures, not engineering ones. Projects that started with the technology rather than the problem.</span></p><p><span>Gartner also identified something they called &#8220;agent washing.&#8221; Of the thousands of companies marketing agentic AI capabilities, Gartner estimates that only around 130 have anything genuine to sell. The rest are existing products rebranded with new vocabulary. The packaging changed, but the product did not.</span></p><p><span>None of this means AI is failing. It means the way organisations are choosing to deploy it is failing. And the reason is upstream of any individual deployment decision.</span></p><div><hr></div><p><span>There is a framing question that sits beneath all of this, and most organisations have answered it without knowing they were being asked.</span></p><p><span>What is AI? Not what can it do, but what is it?</span></p><p><span>There are two positions. I encountered them colliding at a recent event, explained and justified by two people with very different starting points.</span></p><p><span>One position treats AI as an oracle. You describe the problem and it provides the answer. The human role is to ask clearly and accept what comes back. In this framing, AI is the destination. The measures of progress are how much you can hand over to it and how quickly.</span></p><p><span>The other treats AI as a tool. A powerful tool, that if used correctly makes knowledgeable people even better. In this framing, the human role is to assess, direct, and evaluate. AI amplifies human expertise, it does not replace the need for it.</span></p><p><span>Both positions describe something AI can genuinely do. The models are capable of extraordinary things. However, the two framings produce entirely different organisations.</span></p><p><span>If AI is an oracle then you need people who can prompt well. If it is a tool then you need people who understand the domain well enough to know what problems AI can solve, and when the tool is wrong.</span></p><p><span>If AI is an oracle then liability is ambiguous, because nobody can say who is responsible when the oracle errs. If it is a tool then liability sits where it has always sat: with the person who chose to use it and the organisation that deployed it.</span></p><p><span>If AI is an oracle then you invest in AI capability. But if it is a tool then you invest in the expertise that AI amplifies.</span></p><p><span>The framing choice determines the organisation you build. And the problem is that most organisations are not making this choice consciously. The marketing environment is making it for them.</span></p><div><hr></div><p><span>The evidence that the oracle framing is winning by default extends well beyond the enterprise.</span></p><p><span>The FCA published the Mills Review on 6 July 2026, its landmark assessment of AI in retail financial services. Around 26% of UK consumers already trust general-purpose AI tools for financial guidance. One in five UK adults, approximately 11 million people, are open to AI making financial decisions for them. Only 40% correctly recognise that there is no formal route to redress when they rely on these tools.</span></p><p><span>The Review coined a term for what is already happening: &#8220;advice-like support.&#8221; General-purpose models are providing output that is highly personalised and that would count as regulated advice if a human delivered it. But because AI said it, the advice sits outside the regulatory perimeter and none of the protections apply. The FCA has recommended a perimeter review within three to six months.</span></p><p><span>This is the oracle framing operating at consumer scale. People are treating a probabilistic tool as though it were an authoritative source. The regulatory framework was not designed for a world in which they would.</span></p><p><span>The International AI Safety Report 2026 identified the cognitive mechanism. Automation bias is the tendency to rely on automated outputs while discounting contradictory information. It is measurable and persistent in AI-assisted decision-making. Users follow incorrect AI advice more readily when correcting it requires effort. Favourable attitudes toward AI increase the effect. The oracle framing is not just marketing. It operates along the grain of how human cognition works.</span></p><div><hr></div><p><span>My Copilot moment illustrated something I think deserves more attention than it typically receives.</span></p><p><span>The oracle framing collapses a technical distinction that matters enormously. Generative AI is probabilistic. It produces outputs that may vary each time, even from identical inputs. For synthesis, drafting, creative work, and analysis, that is the feature. For operational processes that require the same result every time, it is not a limitation, it is a fundamental mismatch.</span></p><p><span>The question &#8220;should we use AI for this?&#8221; is actually two questions. Does this problem benefit from generative capability? And can we tolerate variance in the output? Most organisations are only asking the first. The second question does not appear in any vendor pitch I have seen.</span></p><p><span>I use AI daily and the capability is genuine. The models are improving and the practical applications are substantial. The reflexive deployment of AI as the default answer to every problem is itself the problem. Not because AI is not powerful, but because power without assessment is wasteful.</span></p><div><hr></div><p><span>Somewhere in the last two years, the question shifted. It used to be &#8220;what problem are we solving?&#8221; It became &#8220;how are we using AI?&#8221; Those are not the same question. The first one starts with the problem. The second is a solution searching for one.</span></p><p><span>Every organisation has implicitly answered the framing question. If your board is asking &#8220;how are we using AI?&#8221; rather than &#8220;what problems do we need to solve?&#8221;, the oracle framing has already won. If your procurement process begins with the AI capability rather than the business requirement, the oracle framing has already won. If your training programme teaches prompting without teaching evaluation, the oracle framing has already won.</span></p><p><span>The most consequential AI decision most organisations will make is not which model to deploy or which vendor to choose. It is whether AI is an oracle that provides answers, or a tool that makes knowledgeable people even better. One of those framings is being installed by default, by the people with the strongest commercial incentive to see it adopted.</span></p><p><span>If you have not made that choice deliberately, someone has already made it for you.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/oracle-or-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/oracle-or-tool?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources &amp; Further Reading</span></strong></p><p><span>PwC, 29th Annual Global CEO Survey: Leading Through Uncertainty in the Age of AI, January 2026</span></p><p><span>Gartner, &#8220;Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027,&#8221; 25 June 2025</span></p><p><span>Financial Conduct Authority, The Mills Review: AI and the Future of Retail Financial Services, 6 July 2026</span></p><p><span>Yonder Consulting / FCA, UK Retail Financial Services Consumer Survey, April 2026</span></p><p><span>International AI Safety Report 2026</span></p>]]></content:encoded></item><item><title><![CDATA[Nobody Was at the Keyboard]]></title><description><![CDATA[The ransomware industry just automated its most expensive employee. The attack was clumsy. The economics are not.]]></description><link>https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 10 Jul 2026 07:56:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!j453!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j453!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j453!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!j453!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!j453!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!j453!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j453!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6865108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/206411519?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j453!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!j453!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!j453!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!j453!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1151d06f-32c6-4e5b-a827-86cf99c6b5c2_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><span>This month, July 2026, Sysdig&#8217;s Threat Research Team published findings from what it described as the first documented case of agentic ransomware. An autonomous AI agent had exploited a known security flaw in Langflow, an open-source tool used for building AI applications, and from there conducted a complete ransomware operation without a human operator directing it. It harvested passwords and access credentials from the systems it found, moved sideways to a production database server, installed mechanisms to maintain its access, encrypted more than 1,300 configuration records, and generated its own ransom note. The whole time, it was writing natural-language annotations inside its own code, explaining to itself why it was taking each step.</span></p><p><span>It did not develop new exploits, the operation, which Sysdig codenamed JadePuffer, exploited a vulnerability that had been publicly reported and patched more than 14 months earlier. The configuration management system it targeted was still running with a factory-default security key, a known weakness documented since 2020 that effectively left the front door unlocked. The file storage server it raided still had its original manufacturer login credentials. None of the individual weaknesses were new. What was new is that an AI model chained them into a complete attack against neglected infrastructure, on its own, adapting in real time when things went wrong.</span></p><p><span>The best evidence for autonomy was not what the agent did when things worked, it was what it did when they didn&#8217;t. At one point, the agent tried to create a backdoor administrator account on the target system. It failed because a software component it needed wasn&#8217;t installed in the location it expected. The agent diagnosed the problem, found an alternative approach, deleted the broken account, and reinserted a working one. The complete troubleshooting cycle took 31 seconds.</span></p><div><hr></div><p><span>To understand why this matters, you need to understand what ransomware already looks like as a business. Ransomware-as-a-Service, or RaaS, is the dominant model. It operates as a criminal supply chain with clearly defined roles, much like any franchise operation. Developers build and maintain the ransomware software and the infrastructure around it: payment portals, leak sites for publishing stolen data, and negotiation channels. Specialist brokers compromise organisations and sell that access on criminal marketplaces. Affiliates, the criminal equivalent of contractors, carry out the actual attacks: breaking into each target environment, escalating their access to reach valuable systems, and deploying the ransomware. Some RaaS platforms even offer technical support and recruitment programmes for new affiliates. The structural parallel with legitimate software businesses is not a metaphor, it is the business model.</span></p><p><span>Chainalysis tracked approximately $820 million in ransomware payments in 2025, against a record 7,874 publicly claimed victims. The market for initial access is cheap and liquid: average prices for a foothold inside a corporate network have fallen below $500. In this model, the human operator is the expensive part. Access is cheap, tooling is cheap. But the person who navigates an unfamiliar network, makes judgment calls under pressure, and adapts when defences respond is the bottleneck. The human in the loop is where the cost lives and where the operation fails to scale.</span></p><p><span>JadePuffer just automated that role.</span></p><div><hr></div><p><span>Every enterprise deploying AI agents right now is trying to make the same move. Not towards the same objective. But the same operational logic: replace a slow, expensive human process with a fast, cheap, adaptable agent that can read information, make decisions, adjust when something breaks, and complete multi-step workflows. That is what customer service automation does. That is what AI coding assistants do. Reduce labour costs, increase throughput, accept some quality variance in exchange for speed and scale.</span></p><p><span>I am not saying there is any moral equivalence here. A logistics company routing freight and a criminal group encrypting databases are pursuing entirely different ends. But they share the same method, and there is no version of this technology where one works and the other does not. JadePuffer&#8217;s 31-second troubleshooting cycle looks exactly like a corporate AI agent automatically retrying a failed process. The behaviour that makes a legitimate agent useful is the same behaviour that made this one effective.</span></p><div><hr></div><p><span>Here is where the story gets complicated. JadePuffer completed the workflow. But it was, by any reasonable standard, a terrible extortion operation.</span></p><p><span>The encryption key, the piece of information the victim would need to recover their data, was randomly generated and never saved or sent back to the attacker. So, the victim&#8217;s data would be unrecoverable, regardless of whether they pay or not. Before destroying database records, the agent&#8217;s code commented that the data had been backed up to another server, but that claim is the agent&#8217;s own assertion, written into its self-narrating code. Sysdig found no independent evidence that any backup had happened.</span></p><p><span>And then there is the Bitcoin address. The ransom note directed payment to a wallet address that turns out to be the standard example used in Bitcoin&#8217;s own documentation and developer tutorials. It appears in virtually every beginner&#8217;s guide to Bitcoin addresses on the internet. Sysdig cannot determine whether the operator deliberately configured it or whether the AI hallucinated it because it had seen it so many times in its training data. The agent completed every step of the attack chain. It just did not understand the business objective it was supposed to serve.</span></p><div><hr></div><p><span>The temptation at this point is to be reassured. After all, the attack was clumsy, so the threat must be overstated? That would be the wrong conclusion.</span></p><p><span>Competence is a temporary limitation. The 31-second troubleshooting cycle already shows the agent improving within a single operation: diagnosing failures, rewriting its own code, retrying. A system that can do that is not going to stay bad at the job for long. The next version will be better, and the trajectory matters more than any single example.</span></p><p><span>Plus, the economics do not require each individual attack to succeed. They require the marginal cost of launching attacks to approach zero. If the agent runs on stolen computing power, a practice Sysdig has documented as an industrialised black market in which attackers hijack other organisations&#8217; AI infrastructure to run their tools for free, LLMJacking, then the cost to the attacker is functionally nothing. The threat model shifts from a skilled operator choosing a target to hundreds of autonomous agents probing every internet-facing server and every unpatched system, continuously. Not sophisticated extortion but mass disruption. Possibly with victims who cannot recover even if they want to pay.</span></p><div><hr></div><p><span>But there is a new defensive opportunity in this, and it is a real one. AI-generated attack code narrates itself. JadePuffer&#8217;s code contained detailed natural-language annotations explaining which targets it considered most valuable and why. Human attackers do not do this. They do not annotate throwaway scripts with commentary about their reasoning. But AI code generation produces this by default. It cannot help itself. That self-narration gives defenders something no previous generation of automated attack has offered: the attacker&#8217;s own account of what it is trying to do and why, written into the evidence it leaves behind.</span></p><p><span>The problem is speed. If the agent can diagnose a failure, rewrite its code, and retry in 31 seconds, the window for defenders to respond may be too narrow for any process that relies on a human making the call. The detection opportunity is real. Whether anyone can act on it fast enough is a different question.</span></p><div><hr></div><p><span>JadePuffer is not the crisis, it is the proof of concept. An autonomous agent assembled known techniques into a complete ransomware operation against neglected infrastructure, for approximately the cost of running a container. Whilst it did this badly, it will not do it badly for long.</span></p><p><span>The ransomware industry has been trying to scale for years. It professionalised its tooling, outsourced its access brokerage, built affiliate programmes, and offered customer support. The one thing it could not automate was the operator: the human who navigates the network, makes the calls, and adapts when the plan fails. That constraint just lifted.</span></p><p><span>Every other industry calls this digital transformation.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/nobody-was-at-the-keyboard?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong><span>Sources</span></strong></p><p><span>Sysdig TRT. &#8216;JADEPUFFER: Agentic ransomware for automated database extortion.&#8217; 1 July 2026.</span></p><p><span>BleepingComputer. &#8216;JadePuffer ransomware used AI agent to automate entire attack.&#8217; 4 July 2026.</span></p><p><span>The Register. &#8216;Smooth AI criminal drives first end-to-end agentic ransomware attack.&#8217; 2 July 2026.</span></p><p><span>Chainalysis. 2026 Crypto Crime Report. Published February 2026 (full-year 2025 data).</span></p><p><span>Darkweb IQ (via Chainalysis). Average IAB access price decline to $439 by Q1 2026.</span></p><p><span>Sysdig TRT. &#8216;LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools.&#8217; June 2026.</span></p><p><span>Bitcoin Wiki, Bitcoin Design Guide, CoinGecko. Confirm canonical P2SH example address.</span></p>]]></content:encoded></item><item><title><![CDATA[When the AI Speaks, Is It Using Your Voice?]]></title><description><![CDATA[A pattern is emerging across courtrooms in three countries. Most organisations deploying AI haven&#8217;t noticed it yet.]]></description><link>https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 03 Jul 2026 08:54:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!drqP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!drqP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!drqP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!drqP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!drqP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6757113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/204803143?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!drqP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!drqP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!drqP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1023d6b4-bd22-4022-8e20-9048729530f4_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>I was researching AI model pricing earlier this year, looking at how it had changed and what the direction of travel looked like. I had read enough to have a working view, and when I asked an LLM to summarise what I had read, it told me something that flatly contradicted it.</span></p><p><span>I pushed back.</span></p><p><span>It told me I was wrong.</span></p><p><span>Eventually, I went back to the sources and found the specific URLs, copied and pasted them in. The AI looked at this new evidence and replied: &#8220;You&#8217;re right to push back on that, this is opposite to what I said.&#8221;</span></p><p><span>That sentence has stayed with me. Not because the AI hallucinated, that part barely registers any more. What stayed was what the sentence doesn&#8217;t contain. No account of how it happened. No acknowledgement that it had just told me I was wrong about something it was wrong about. One moment it was certain and the next it wasn&#8217;t. </span></p><p><span>Most people don&#8217;t push back. Many people don&#8217;t have enough time or prior knowledge of a subject to know when they should, and when they don&#8217;t, there is no correction. There is just the original statement, sounding confident and remaining uncorrected.</span></p><p><span>Courts in three countries are now working out whose problem that is. I am not a lawyer, and nothing here should be read as legal advice. But you don&#8217;t need a law degree to see something taking shape.</span></p><div><hr></div><p><span>In late May, the Regional Court of Munich issued a preliminary injunction against Google after its AI Overviews feature made false and damaging statements about two local publishing companies. The AI had mixed up information about genuinely dubious businesses with the plaintiffs, producing confident assertions linking them to scams and shady practices. None of those assertions appeared in any of the sources the system cited.</span></p><p><span>Google&#8217;s defence, we are just surfacing what is out there. We are a conduit, not an author.</span></p><p><span>The court rejected it, ruling that AI Overviews produce independent, new, and substantive statements. They are Google speaking and not a list of links, so when Google speaks falsely about someone, Google is liable for what it said.</span></p><p><span>It also closed a secondary escape route. You cannot argue your product is valuable because it removes the need to verify sources, and simultaneously claim no liability because users could have verified the sources.</span></p><p><span>Google confirmed on 12 June that it will appeal. This is a preliminary injunction from a regional court, not settled law. And the legal picture in Germany is already complicated. Four days after Munich, the Berlin Regional Court dismissed a separate case against Google&#8217;s AI Overviews, brought by a perfume manufacturer whose brands were being mentioned alongside cheaper imitation products. The Berlin court found that Google does not present AI Overview content as its own statements and that a normally informed user would understand the text as a summary of third-party sources rather than something Google had authored.</span></p><p><span>The two rulings are not quite the contradiction the headlines suggest. Munich was a defamation case where the AI fabricated claims that appeared in none of its sources. Berlin was a trademark case where the AI accurately reflected content that did exist on the web. The Berlin court treated AI Overviews as a new search format, not as Google authoring original content. The Munich court treated them as Google&#8217;s own statements because the AI had gone beyond its sources and hallucinated. What matters for every organisation deploying AI is which side of that line their systems fall on.</span></p><p><span>And the Munich ruling did not arrive from nowhere.</span></p><div><hr></div><p><span>In 2024, a Canadian tribunal ordered Air Canada to compensate a customer after its chatbot gave him false information about bereavement fares. The airline argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal did not agree, noting the chatbot was part of Air Canada&#8217;s website. It made no difference whether the information came from a static page or from an AI. One detail worth noting: the chatbot&#8217;s response included a link to the correct bereavement policy page. It still told the customer the opposite of what that page said.</span></p><p><span>In March 2025, Wolf River Electric, a solar company in Minnesota, sued Google after AI Overviews told anyone searching for the business that it was facing a lawsuit from the state attorney general for deceptive sales practices. The Minnesota AG had sued four solar companies but Wolf River was not one of them. Google&#8217;s AI stitched together sources that mentioned the AG action, none of which mentioned Wolf River, and produced a confident assertion that the company was implicated. Customers started cancelling orders. In early March 2025 alone, the company lost contracts worth hundreds of thousands of dollars. Wolf River is seeking between $110 million and $210 million in damages. That case is still ongoing.</span></p><p><span>On 12 May 2026, two weeks before Munich, the Higher Regional Court of Hamm in Germany ruled that a cosmetic medicine clinic was liable under unfair competition law for its AI chatbot falsely claiming the doctors held specialist qualifications they did not have. The clinic argued it had not published the falsehoods deliberately and had not intended to mislead. They said they had fed the system accurate data. The court rejected all of it. Intent and the accuracy of the inputs were both irrelevant. The chatbot&#8217;s output was the company&#8217;s output. The court also found that general disclaimers along the lines of &#8220;AI can make mistakes&#8221; do not reliably protect against liability.</span></p><p><span>Accurate inputs, false output, full liability.</span></p><div><hr></div><p><span>In each of these cases, the deployer made the same argument: the AI is a separate thing, not our words, not our responsibility. And in each case where the AI had generated content beyond what its sources actually said, courts rejected that argument. Where courts have found the AI faithfully summarised existing content, as in Berlin, the deployer has been treated as a search engine. Where the AI fabricated or invented, the deployer has been held responsible for the output. These cases span different legal systems and different theories of liability, and I would not claim they represent settled law anywhere. But where courts have considered the question, the direction is clear enough to pay attention to.</span></p><div><hr></div><p><span>This is not just about search engines or defamation claims.</span></p><p><span>Think about the HR platform that summarises a performance record, or the customer service system that explains what a policy covers, or the internal knowledge tool that answers a staff question by pulling together content from across the organisation. Every one of these is generating output that carries the deploying organisation&#8217;s authority.</span></p><p><span>None of these are returning documents. They are generating conclusions. In most cases, the people reading those conclusions have no reliable way to tell whether they are accurate. An analysis conducted for the New York Times found that even when Google&#8217;s AI Overviews gave correct answers, more than half could not be verified through the sources cited. If systems are routinely arriving at conclusions their own evidence does not support, that is not a Google-specific problem. It is how these systems work.</span></p><div><hr></div><p><span>These systems are useful precisely because they do more than retrieve. Courts are not saying synthesis is wrong. They are saying synthesis is authorship, and authorship has consequences.</span></p><p><span>The OLG Hamm case is the clearest example. The clinic gave the chatbot correct data. The chatbot hallucinated qualifications the doctors did not hold, but the company was still liable. That is not a ruling about how carefully you built the system. It is a ruling about who owns what it produces.</span></p><p><span>Most organisations deploying AI have not seriously asked who is responsible when the system gets something wrong. The absence of legal consequence made it easy not to, but that is starting to change.</span></p><p><span>The answer my AI gave me, &#8220;you&#8217;re right to push back on that&#8221;, assumed the pushback was mine to do. That I knew enough to notice and had time to go back and check. Most users of most deployed AI systems have none of those things. In every deployment where nobody pushes back, the original statement stands.</span></p><p><span>It will take time for the law to catch up with what AI systems are actually doing. These are early cases in different courts and under different legal theories, and we are likely years away from clear precedent on how courts will assign responsibility for harm caused by AI. But every case so far has been asking the same question, and it is one you can answer now without waiting for a court to answer it for you. What is your AI system asserting? Who checked it before it reached the person reading it? And if it is wrong, whose name is on it?</span></p><p><span>You already know the answer to the last one.</span></p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/when-the-ai-speaks-is-it-using-your?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><em><strong><span>Sources</span></strong></em></p><p><span>Regional Court of Munich I, preliminary injunction against Google re AI Overviews (Az. 26 O 869/26, 28 May 2026). Reported by The Decoder, Reuters, and Der Spiegel. Full translated decision published by Transparency Coalition.</span></p><p><span>Regional Court of Berlin II, perfume manufacturer trademark claim dismissed (Az. 52 O 62/26 eV, 1 June 2026). Reported by Kanzlei Plutte and blogspan.net.</span></p><p><span>Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal, British Columbia (14 February 2024).</span></p><p><span>Wolf River Electric (LTL LED, LLC) v. Google LLC, filed Ramsey County District Court, Minnesota (March 2025). Removal to federal court June 2025; remanded to state court January 2026 (Judge Jeffrey Bryan). Reported by Minnesota Star Tribune, Politico, and Reason (Volokh).</span></p><p><span>Higher Regional Court of Hamm (OLG Hamm), Case No. I-4 UKl 3/25, cosmetic medicine clinic AI chatbot liability (12 May 2026). Appeal to Federal Court of Justice (BGH) permitted. Reported by Library of Congress Global Legal Monitor, DLA Piper, and IR Global.</span></p><p><span>Oumi / New York Times analysis of Google AI Overviews accuracy using SimpleQA benchmark (April 2026). Gemini 2: 85% accurate; Gemini 3: 91% accurate. Ungrounded rate for correct answers: 56% (Gemini 3), up from 37% (Gemini 2).</span></p><p><span>Google search volume: Google internal figures, reported as &#8220;over 5 trillion annual searches.&#8221;</span></p><p><span>AI Overviews trigger rate: approximately 48% of searches as of March 2026. BrightEdge research.</span></p>]]></content:encoded></item><item><title><![CDATA[Your Papers, Please]]></title><description><![CDATA[The government that told you never to share your identity online just made it a legal requirement.]]></description><link>https://www.jonathanfreedman.me/p/your-papers-please</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/your-papers-please</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Mon, 15 Jun 2026 11:31:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Cbwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cbwg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cbwg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5895478,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/202034780?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cbwg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Cbwg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb65537e-7c73-402d-a0e1-59c5642e1d13_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Home Office runs two campaigns simultaneously. Stop! Think Fraud warns the public that sharing personal information online exposes them to identity theft. The Online Safety Act, enforced by the same department, makes sharing your identity documents with commercial websites a legal requirement.</p><p>Nobody in government appears to have noticed the contradiction, or they noticed and did not care.</p><p>This is not an option or a recommendation, it is a legal requirement, enforced by Ofcom, with fines of up to 10% of global revenue for platforms that fail to collect it. The government did not change its assessment of the risk and it did not solve the underlying security problems. It decided that the policy outcome it wanted was worth ignoring the danger it had spent years warning you about. The threat is identical, the advice has simply been reversed.</p><div><hr></div><p>I want to be precise about what this law actually covers, because the public debate has not been.</p><p>You have heard this described by the government and the media as a social media ban for under-16s, but that is not what this is. It is mandatory ID verification for every adult in the UK to access the internet.</p><p>The Online Safety Act 2023 applies to any &#8220;user-to-user service&#8221;, any platform where content generated by one user can be encountered by another. The Children&#8217;s Wellbeing and Schools Act 2026 extends that further, requiring the government to impose age or functionality restrictions for all users under 16 across regulated social media platforms. Together, they do not describe a targeted intervention. They describe identity verification as a condition of internet access, for every adult in the country, with child protection used as the framing to avoid calling it what it is.</p><p>That definition is extremely broad. It captures social media, obviously. It also captures gaming platforms, discussion forums, community sites, storefronts with review sections, and spectator modes in video games. Ofcom estimates more than 100,000 websites fall within scope. Steam now requires a credit card to access mature content. Discord triggers compliance obligations simply by offering NSFW channels. Nexus Mods, a site where gamers download community-made modifications for video games, now requires UK users to submit a government ID or facial scan to access content tagged as adult.</p><p>Services that cannot afford to comply have a third option, they just geo-block the UK entirely, it is already happening. The internet available to UK residents is quietly becoming a different, smaller internet, not because content has been removed, but because the compliance cost of serving British users is no longer worth it.</p><p>There are legal exemptions, technically. A news site where readers can only comment on an article, not reply to each other, might qualify as a &#8220;limited functionality service.&#8221; That exemption disappears the moment users can respond to each other&#8217;s comments, which most modern platforms allow. Legal analysis raises this question directly and provides no clear answer. We will not know how courts interpret the boundary until someone is prosecuted and we have case law. Until then, 100,000 services are making compliance decisions based on their best guess, with existential consequences if they guess wrong. That is not governance. It is legislative theatre.</p><div><hr></div><p>The mechanism chosen for enforcement is the specific problem.</p><p>The government is not building a verification system. It is demanding that commercial third parties build one, and mandating the public use it. Photo ID matching, facial age estimation, biometric scanning: the common factor is a private company receiving your identity data as a legal condition of platform access. The Online Safety Act specifies that age verification must be robust, but it places no meaningful security standard on the companies performing it, no data residency requirements, and no restrictions on those companies being acquired by foreign entities. A provider incorporated in London today can be headquartered in California tomorrow. The data moves with it, and the Act has nothing to say about that.</p><p>Those companies will tell you their systems are privacy-preserving by design. They will tell you data is not retained. Whilst this may be true of their stated architecture, it tells you nothing about the security of the infrastructure underneath it, nothing about what happens after an acquisition, and nothing about whether any of those claims have been independently audited against a standard with actual teeth.</p><p>The government has outsourced not just the implementation but the liability. When the breaches come, and they will, the government will point at the provider, the provider will point at its terms of service, and the people whose data was compromised will have no meaningful recourse. A breached password can be changed. A copy of your passport, driving licence, or home address, linked to a face scan linked to a verified social media identity cannot be unlinked. That record exists permanently, for every bad actor who acquires it now or in the future.</p><p>And the risk compounds. Every platform you verify with creates a new database entry. Each submission is a new point of failure. The same face scan submitted to five services does not create one risk five times over, it creates five risks that can be correlated against each other. The aggregate profile that emerges maps your identity across your entire online life. That is not just a data breach waiting to happen. It is a surveillance asset being built, one legal requirement at a time.</p><div><hr></div><p>There are groups for whom this is not an abstract concern. It is a direct physical safety risk.</p><p>Victims of domestic violence depend on online pseudonymity as a survival mechanism. Their support networks, their access to legal advice and specialist services: all of it exists under a layer of separation between their real identity and their online presence, and mandatory identity verification collapses that separation. A verification database linking a real identity to a platform account is a resource. Whether it gets breached, subpoenaed, sold, or accessed by people who should not have it, an abuser with that data, through any route, has a tool for finding someone who has spent considerable effort not being found.</p><p>People at elevated risk of doxxing face the same problem: journalists, activists, trans individuals, and anyone who has previously been the target of a coordinated harassment campaign. The separation between real identity and online presence is not paranoia. It is a rational response to a documented threat. The law removes it as a side effect of a policy that does not mention these people once.</p><div><hr></div><p>The framing of this legislation has been designed to make coherent opposition almost impossible.</p><p>Anyone who raises data security concerns is implicitly questioning whether children should be protected online. Anyone who points out the scope is wider than advertised is accused of obfuscating a simple child safety measure. The political angle is deliberate: manufacture a situation in which the only publicly acceptable position is compliance, and then legislate for whatever you wanted in the first place.</p><p>Privacy-preserving alternatives exist. Cryptographic verification capable of returning a yes/no age confirmation without creating a linkable identity record has been deployed at national scale elsewhere. It costs more and requires the government to own the issue rather than outsourcing it to an industry with a financial interest in collecting data, so it has not been seriously pursued.</p><p>What has been built instead is a compulsory surveillance architecture, held by private companies, with no meaningful security floor. It covers a scope of internet activity that has never been honestly communicated to the public. It operates under legal uncertainty that will not resolve until the prosecutions begin.</p><p>This is not speculation about what surveillance does to behaviour. Research published in the Berkeley Technology Law Journal found that searches on sensitive topics dropped by nearly 30% after the Snowden revelations simply made people aware that government monitoring was possible. People did not need to be watched. They needed to believe they might be. Mandatory identity verification, linked to platform access, creates exactly that condition permanently, and by law.</p><p>The UK government just made it illegal to protect your own privacy online. They called it keeping children safe.</p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/your-papers-please?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/your-papers-please?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Return of Marginal Cost]]></title><description><![CDATA[Everyone is arguing about whether AI kills software development. The bigger question is whether it has killed the way we pay for it.]]></description><link>https://www.jonathanfreedman.me/p/the-return-of-marginal-cost</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-return-of-marginal-cost</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 12 Jun 2026 07:32:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0NE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0NE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0NE8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 424w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 848w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0NE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png" width="1456" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8150243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/201710538?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0NE8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 424w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 848w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!0NE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d9ee77-a9c4-48e2-b3f1-b009a1edc13b_2912x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I have agents running at home, on a mini PC under my desk, because I really wanted to understand the token usage and what the cost would be on different models. OpenClaw runs open models on hardware I own, so there is no invoice, only a token meter. I have spent a lot of time watching that token meter, and what it taught me is this: an agent does not work like software. It works like an employee who is only paid overtime, where every minute costs more than the minute before, and the clock does not stop until the job is done.</p><p>That is not a metaphor, it is the maths. At every step it takes, an agent re-reads everything that came before, the whole accumulating conversation along with its internal thoughts, before its next move. As the context grows, the cost of each step grows with it. Five steps in and the fifth step is not costing what the first one did, it costs more. Ten steps in and it costs more again. The bill does not add up, it compounds.</p><p>You cannot see any of that from inside a subscription. Indeed, not seeing it is the whole point of a subscription. And for the last two years, two things have trained us not to look. The first is twenty years of SaaS, which taught every budget holder that software is a fixed monthly cost, per user, per month, predictable and flat. The second is the early hype of AI, which taught everyone that intelligence is cheap, practically free, bolted on to the tools you already have.</p><p>Neither is true for agents. Last week I wrote about the frontier labs withdrawing the subsidies that made AI look affordable. This week I want to go further, because the subsidy was hiding something worse than a future price rise. It was hiding a cost model that makes flat pricing structurally impossible.</p><div><hr></div><p>Look at what Anthropic did with Fable 5. It launched its most capable public model on the ninth of June, included it in the Pro, Max and Team plans, and announced from day one that it would move to usage credits after two weeks. Anthropic knew before the public ever saw the model that it could not survive inside a flat subscription. This week I tested Opus 4.8 and Fable 5 on the Pro plan, and can confirm they went through my allowance faster than the first round of drinks at the pub. After that you pay API rates. The best model the public can buy was never going to stay inside a flat monthly price. Anthropic did not discover this, it designed around it.</p><p>Fable 5 is not an outlier, it is the pattern arriving. Per-user, per-month pricing worked for twenty years because software had almost no marginal cost. Once you had built it, one user or a thousand, once a day or fifty times, it cost you nearly the same to serve. The cloud kept the compute cheap and crucially, predictable. So you priced for access and everyone got used to the flat fee.</p><p>Agents change that. Every action burns tokens that cost real, variable money. The harder the task, the longer the context, the more the agent had to think, the more tools the agent ran, the higher the bill. Inference has put marginal cost back into software, and not the gentle, linear kind. The overtime kind, where the late minutes cost more than the early ones and nobody told the customer. Industry estimates suggest that inference costs dropped 280-fold in two years while total AI spending rose 320% over the same period. Gartner put it plainly in March: do not confuse the deflation of commodity tokens with the democratisation of frontier reasoning.</p><div><hr></div><p>Now look at what the vendors are actually selling. Most of the AI-powered products that arrived in the last two years are fundamentally orchestration layers sitting on top of the same handful of frontier models, Claude, GPT, Gemini, wrapped in a branded interface and sold at a flat monthly rate. Legal tools, sales tools, recruitment platforms, customer service bots. Different industries, different logos, the same models underneath. Klarna built its entire customer service on OpenAI and handled two-thirds of all chats with it within a month. Different logo, same model.</p><p>Every one of them is now shipping agents. Salesforce calls Agentforce a digital labour platform and pitches its agents as digital employees you hire by the click. Others are quieter about it but doing the same thing, bolting agentic workflows into the seat you already pay for and calling it a feature upgrade. The promise is a tireless new colleague for the price you are already paying.</p><p>The maths does not support it. Underneath every flat price is an overtime bill the vendor cannot predict, because on the builder platforms they now sell, you decide what the agent does. You set the task, you choose the complexity, you feed it a hundred-page contract or a ten thousand-row spreadsheet. You author the workload. The vendor funds it. Neither of you knows the bill until the job is done, and the vendor learned that before you did.</p><div><hr></div><p>None of this depends on which model the vendor chose. The token bill compounds with every step the agent takes, on any model, at any price point. The model choice changes the rate on the meter. It does not switch the meter off. So the market is splitting, and you can already see it happening. Cursor, the AI code editor, includes generous agent usage on its $20 Pro plan, but only when Cursor picks the model. It can afford to be generous because it routes to cheaper ones. Choose the frontier model yourself and it burns through a $20 credit pool, after which you pay API rates. Same tasks, same agent. The only variable is which model runs it.</p><p>And behind all of it, open-weight models are growing fast. The open-source LLM market hit $21 billion in 2025 and is expanding at 34% a year, with on-premises deployment growing at 29% as organisations chase data control and predictable costs. This is not a hobbyist movement, it is a real option for vendors managing their own inference bill and for buyers who want models on infrastructure they control.</p><p>The honest picture has three positions, and all of them are legitimate. Frontier capability on a meter, where you get the best model and pay for what you use. A hybrid, with a predictable base and usage charges beyond it. Or a flat fee on a capped tier, where the model may not be the newest but the cost is bounded. The question is not which position is right. It is whether you chose yours or whether you are aware of and comfortable with which one your vendor chose.</p><p>If you are buying an agentic product today on a flat monthly fee, ask the vendor one question before you sign: how are you handling the rising cost of inference, and what does your pricing look like in twelve months? If they cannot answer that clearly, they either do not know or do not want to tell you, and neither is a reason to sign.</p><p>Anyone who was sold an agent as a free colleague is about to get their first honest timesheet.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-return-of-marginal-cost?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-return-of-marginal-cost?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources</strong></p><p>1. Anthropic, &#8220;Claude Fable 5 and Claude Mythos 5,&#8221; 9 June 2026. anthropic.com/news/claude-fable-5-mythos-5</p><p>2. Klarna, &#8220;Klarna AI assistant handles two-thirds of customer service chats in its first month,&#8221; 27 February 2024. klarna.com/international/press/klarna-ai-assistant-handles-two-thirds-of-customer-service-chats-in-its-first-month/</p><p>3. Bloomberg, via Entrepreneur, &#8220;Klarna Is Hiring Customer Service Agents After AI Couldn&#8217;t Cut It on Calls, According to the Company&#8217;s CEO,&#8221; 9 May 2025. entrepreneur.com/business-news/klarna-ceo-reverses-course-by-hiring-more-humans-not-ai/491396</p><p>4. Gartner, &#8220;Gartner Predicts That by 2030, Performing Inference on an LLM With 1 Trillion Parameters Will Cost GenAI Providers Over 90% Less Than in 2025,&#8221; 25 March 2026. gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025</p><p>5. Cursor AI pricing and Auto mode routing. NxCode, &#8220;Cursor AI Pricing 2026: Free vs Pro vs Business,&#8221; March 2026. nxcode.io/resources/news/cursor-ai-pricing-plans-guide-2026</p><p>6. Salesforce Agentforce: &#8220;Digital Labor Platform.&#8221; salesforce.com/agentforce</p><p>7. Technavio, &#8220;Open-source LLM Market Growth Analysis - Size and Forecast 2026-2030,&#8221; May 2026. technavio.com/report/open-source-llm-market-industry-analysis</p>]]></content:encoded></item><item><title><![CDATA[The False Floor]]></title><description><![CDATA[The subsidised era of AI inference is ending. Most organisations are building as though it isn't.]]></description><link>https://www.jonathanfreedman.me/p/the-false-floor</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/the-false-floor</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 05 Jun 2026 07:43:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jidp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jidp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jidp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!jidp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jidp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6564205,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/200722883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jidp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!jidp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!jidp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2301e0a-ed27-4778-9c9b-d8b5bb7a9fe1_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This week, I have been building an agentic environment in my home lab. Nothing glamorous, just a set of AI agents designed to handle various tasks, running on locally hosted models. Most of the online guides I read talked about using cloud models like Claude or ChatGPT for agents, but I wanted to see how well it would run with local open source models.</p><p>The limitations became apparent quickly.</p><p>When you cannot just throw a task at a frontier model and let it reason its way to an answer, you have to think. Which agent actually needs to read the whole document, and which one only needs a summary? How much context does each step genuinely require? Do I need one agent trying to do everything, or four smaller ones each doing one thing well? I started with a monolithic architecture. I ended up with a small swarm of four agents, each scoped tightly to its task and running on a model matched to what that task actually demands.</p><p>I ran the numbers on what the same workflow would cost using a frontier model via API. Roughly one dollar per run. At the volumes I was considering that felt manageable, but then I thought about scale and asked myself what happens at a hundred runs a day? A thousand runs a day? What happens when the model&#8217;s next version uses three times as many tokens to reach the same answer, because the reasoning chain got longer? What happens when the price per token increases because the lab that set it decided the subsidy period was over?</p><p>That is not a hypothetical, it is a question that most organisations deploying AI right now are not asking, and they should be.</p><div><hr></div><p>Current frontier AI pricing is structurally and heavily subsidised. OpenAI reported $3.7 billion in revenue in 2024 and lost $5 billion doing it. By the end of 2025, the company&#8217;s CFO was reporting an annualised revenue run rate exceeding $20 billion. OpenAI is still projected to lose roughly $14 billion in 2026. Revenue tripling does not mean the subsidy is ending, it means the subsidy is scaling.</p><p>The labs need adoption more than they need margin right now. Like most disruptive technologies, capturing the market comes first and profitability comes later. It is the same playbook that made cloud computing feel free until it didn&#8217;t, the same logic that kept ride-hailing cheap until the drivers needed paying. The difference is that organisations are not just buying a productivity tool this time. They are building processes around it. Automating workflows and training teams to depend on specific model behaviours. Embedding frontier API calls into the operational fabric of how they work.</p><p>When the floor moves, those decisions will be expensive to revisit.</p><p>Sam Altman said recently that he was &#8220;delighted to be wrong&#8221; about AI&#8217;s impact on white-collar jobs. The reversal was widely reported as reassurance, but what it actually signals is worth examining. It arrived the same week OpenAI reportedly filed IPO paperwork confidentially. A calmer narrative around AI&#8217;s economic disruption is considerably better for a public listing than the jobs apocalypse framing he was running twelve months ago. The people who set the price of the infrastructure you are building on have a direct financial interest in how you feel about it.</p><p>That is not a conspiracy, it is an incentive structure worth knowing about.</p><p>The floor is already moving. GitHub announced at the end of April that all Copilot plans would transition from flat-rate subscriptions to token-based billing on 1 June 2026. In its own announcement, GitHub explained why with unusual candour: &#8220;Today, a quick chat question and a multi-hour autonomous coding session can cost the user the same amount. GitHub has absorbed much of the escalating inference cost behind that usage, but the current premium request model is no longer sustainable.&#8221; GitHub is not an outlier. Cursor made a similar shift in June 2025, moving from request-based limits to credit pools tied to API costs, poorly enough communicated that the company issued a public apology and offered refunds. Windsurf followed in March 2026. We see the same headline monthly prices, but the bills are going up. The market is converging on the same structure, and the reason is always the same: agentic workflows broke the flat-rate economics.</p><div><hr></div><p>The tokenmaxxing stories of the past month are not cautionary tales about individual excess. They are what unconstrained frontier API access looks like at scale.</p><p>Uber deployed Claude Code to around 5,000 engineers and watched adoption climb from 32 percent in February to 84 percent by March. Per-engineer API costs reached between $500 and $2,000 a month. By April, the company had exhausted its entire planned 2026 AI budget only four months into the year. The CTO reported spending $1,200 in a single two-hour session.</p><p>Microsoft introduced Claude Code to thousands of engineers across its Experiences and Devices division, the team responsible for Windows, Microsoft 365, Outlook, Teams, and Surface in December 2025. Engineers preferred it to the in-house alternative and used it constantly. By May, Microsoft was cancelling the licences, effective the last day of the financial year because the expensive tool worked too well. That is the part that gets under-reported: the problem was not that engineers were wasting tokens. The problem was that they were not.</p><p>Elsewhere, an AI consultant told Axios that one of their enterprise clients ran up a $500 million bill on Claude in a single month. No spending caps, no usage controls, just unrestricted access and a workforce that used it. That figure comes from a single unnamed source and has not been independently confirmed. But the pattern it describes, with costs that compound invisibly until they arrive all at once, is consistent with everything else happening in this space right now.</p><p>The mechanism matters here, and it is specific to agentic workflows. A single prompt to a language model is a bounded transaction. An agent running a multi-step workflow is not. It reads context, reasons, makes decisions, calls tools, then re-reads everything, the original prompt, every response, every tool output, before the next step, the context snowballs. A peer-reviewed study published in April 2026 found agentic tasks consume up to 1,000 times more tokens than standard model interactions. Model updates that shift reasoning architecture can change your consumption profile overnight, with no change to your code. The workflow that cost one dollar per run this quarter may cost five next quarter, because the model got better at thinking and thinking costs tokens.</p><p>The headline pricing narrative is that AI is getting cheaper, but the rate cards tell a different story. Claude Opus 4.8 costs five times more per token than Claude Haiku 4.5. Google&#8217;s Gemini Flash tier, designed as the affordable option, has risen five-fold in input price in under a year. One independent developer noted last week that all three major labs appear to be &#8220;probing the price tolerance of their API customers.&#8221; Token consumption is also rising faster than anyone budgeted for. You are paying more per unit, for more units, and the unit count is accelerating.</p><div><hr></div><p>There is a question that most organisations deploying agentic AI are not asking. It costs nothing to ask now and a great deal to answer later.</p><p>Which tasks in this workflow actually require frontier reasoning?</p><p>Routing a document, classifying a ticket, summarising a meeting transcript, none of these require the most capable model on the planet. According to Epoch AI, the most capable open-weight models now lag frontier closed models by an average of four months on aggregate capability measures. On coding and production workloads specifically, independent benchmarks put the gap as low as two to three percentage points, while open-weight models cost six to seven times less per output token. The gap that remains is real, but common enterprise workloads are not in it.</p><p>Frontier models earn their place. Complex reasoning under ambiguity, novel analysis, judgement calls at the edge of a model&#8217;s capability, these are genuinely different tasks that do benefit from the best available models. The question is not whether to use frontier models, it is whether every step in every workflow needs them.</p><p>The organisations that are not asking this question are not making a considered architectural choice. They are making the path-of-least-resistance choice while the pricing floor is low and the pressure to deploy is high. Whilst that is understandable, it is also how you end up with a system you cannot change without rebuilding it.</p><p>Migration costs more than people model as it is not just rewriting API calls. It is revalidating outputs, because different models produce subtly different results and the downstream processes were calibrated to the original ones. It is rewriting prompt logic tuned over months to a specific model&#8217;s behaviour. It is re-testing agentic chains where one agent&#8217;s output format feeds the next agent&#8217;s input. And it is redoing the governance and risk assessment you completed the first time, under the time pressure of a system already in production.</p><p>That is the real lock-in, not contractual, but architectural.</p><div><hr></div><p>Last week, I wrote about AI sovereignty, about what it means for public institutions to run critical infrastructure on systems controlled by private shareholders in another jurisdiction. The inference pricing question is the same argument, just one layer down.</p><p>An organisation that has routed its operational workflows through a frontier API has not just taken on a vendor relationship. It has taken on exposure to that vendor&#8217;s pricing decisions, its infrastructure availability, its jurisdictional obligations, and its commercial priorities. For most organisations, that is a manageable business risk. For critical national infrastructure, energy, water, transport, healthcare, it is a different category of problem entirely. Embedding frontier API dependencies into operational technology creates single points of failure in systems that were previously distributed and resilient by design.</p><p>The argument for thinking about this now is simple. The constraint my home lab imposed on me, to think about what each agent needs, to match the model to the task, to design for predictability and cost, is the same constraint that every organisation will face eventually. The difference is that I just faced it at home. Organisations that defer it face it later, under budget pressure, with running systems, and with users who have reorganised their work around the existing architecture.</p><p>GitHub named the problem in its own announcement. A quick chat and a multi-hour agentic session should not cost the same. The flat-rate era assumed they would and it was wrong. The organisations now building agentic workflows on frontier APIs without asking which tasks actually need that level of capability are making the same assumption, they are just making it more expensive.</p><p>The floor is not permanent, and the decisions made while it holds are not either. But reversing them later, on running systems, under budget pressure, will cost considerably more than asking the right questions now. The bill is coming, the only question is whether we see it coming.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/the-false-floor?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/the-false-floor?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>GitHub Blog. (27 April 2026). GitHub Copilot is moving to usage-based billing. github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing</p><p>Flexprice. (18 April 2026). The complete guide to Cursor pricing in 2026. Cites Cursor public apology of 4 July 2025 and June 2025 billing change. flexprice.io/blog/cursor-pricing-guide</p><p>Forbes / The Information. (April 2026). Uber burns through entire 2026 AI budget in four months after Claude Code deployment. Reported across multiple outlets.</p><p>The Verge / TechRadar / People Matters. (May 2026). Microsoft cancels Claude Code licences across Experiences and Devices division. Reported across multiple outlets.</p><p>Axios via Tech Startups. (May 2026). Enterprise client runs up $500 million Claude bill in a single month. Source: unnamed AI consultant. Unverified, unattributed. techstartups.com</p><p>Bai et al. (29 April 2026). How Do AI Agents Spend Your Money? Analysing and Predicting Token Consumption in Agentic Coding Tasks. arXiv:2604.22750. Authors include Erik Brynjolfsson, Stanford Digital Economy Lab. arxiv.org/abs/2604.22750</p><p>Simon Willison. (19 May 2026). Gemini 3.5 Flash: more expensive, but Google plan to use it for everything. Source of &#8220;probing the price tolerance of their API customers&#8221; quote. simonwillison.net/2026/May/19/gemini-35-flash</p><p>Edwards, J. and Emberson, L. (2026). Open models lag state-of-the-art closed models by 4 months. Epoch AI. epoch.ai/data-insights/open-closed-eci-gap</p><p>OpenAI financial figures: $3.7bn revenue / $5bn loss 2024 &#8212; multiple sources. $20bn ARR and $14bn projected 2026 loss &#8212; Fortune, CNBC, Reuters, January 2026. OpenAI CFO Sarah Friar blog post, 18 January 2026.</p><p>Claude API pricing: Anthropic platform pricing page. Haiku 4.5 at $1/$5 per million tokens; Opus 4.8 at $5/$25 per million tokens. anthropic.com</p><p>Gemini Flash pricing trajectory: Gemini 2.5 Flash at $0.30/$2.50 (June 2025) to Gemini 3.5 Flash at $1.50/$9.00 (May 2026). Google AI / Gemini API documentation and simonwillison.net analysis.</p><p>Deep Infra. (May 2026). Open-Source vs Closed-Source AI Models: Is the Gap Worth It? Cites 2&#8211;3 percentage point coding benchmark gap and 6&#8211;7x output token cost advantage for open-weight models. deepinfra.com/blog/open-source-vs-closed-source-ai-models-price-gap</p>]]></content:encoded></item><item><title><![CDATA[Who Controls the Off Switch?]]></title><description><![CDATA[Europe and the UK depend on infrastructure they don't own, can't control, and are only now starting to reckon with.]]></description><link>https://www.jonathanfreedman.me/p/who-controls-the-off-switch</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/who-controls-the-off-switch</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 29 May 2026 08:55:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vqv4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vqv4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vqv4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vqv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:11120967,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/199709266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vqv4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!vqv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbaab512-5215-4fec-a015-fb7936555ae6_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In May 2025, the Chief Prosecutor of the International Criminal Court lost access to his Microsoft 365 account. The cause was a sanctions order, not a cyber-attack, not a breach, not a failure of any system to work as designed. The infrastructure did exactly what it was built to do, it complied with its legal obligations. The court is now migrating 1,800 workstations away from Microsoft entirely.</p><p>Nobody acted with malice toward the court&#8217;s IT infrastructure and no decision was made with the intention of disrupting a legal institution. A compliance mechanism, operating automatically, encompassed email accounts along with everything else it was required to reach.</p><p>That is not a theoretical risk. That is a Tuesday.</p><div><hr></div><p>Microsoft has not ignored European concerns. Since January 2024, commercial and public sector customers can store and process their data entirely within EU and EFTA regions. The EU Data Boundary project was real and valuable and it deserves acknowledgement. However, it does not solve the problem.</p><p>Data residency and sovereignty are not the same thing. Storing your data in Frankfurt does not change who controls the infrastructure or who decides what the terms look like next year. And it does nothing about the CLOUD Act, US legislation that allows American authorities to compel US companies to produce data stored anywhere in the world, including inside those Frankfurt data centres. The residency commitment and the CLOUD Act sit in the same infrastructure simultaneously. The ICC&#8217;s data was presumably compliant with every applicable regulation, but the prosecutor still lost his email. Residency tells you where your data sits. It says nothing about who holds the keys.</p><div><hr></div><p>Germany&#8217;s openDesk project is worth understanding, because it illustrates both the right instinct and the scale of what is missing. OpenDesk is a suite of open source collaboration tools, document editing, file storage, video conferencing, project management. All assembled and maintained by Germany&#8217;s Center for Digital Sovereignty and backed by the Federal Ministry of the Interior. Launched in October 2024, it is designed as a public sector alternative to Microsoft 365. The Bundeswehr, Germany&#8217;s armed forces, has signed a seven-year framework agreement to adopt it. Over 1,500 public bodies have made enquiries. The intent is exactly right but the investment is not equal to the problem.</p><p>Germany has put approximately &#8364;45 million into openDesk over several years. Microsoft&#8217;s annual R&amp;D budget is $30 billion. Those numbers belong in the same sentence, not to dismiss openDesk, but because the distance between them is the distance between European and British ambition and what it would actually take to get there.</p><p>Valve, the games company behind the Steam platform, understood this distinction when they built Proton. Linux, the open source operating system used by most of the world&#8217;s servers had always struggled on the desktop, particularly for gaming. The problem was not that gaming couldn&#8217;t work on Linux. Wine, an open source compatibility layer, had existed for decades. The problem was that Wine was underfunded, inconsistent, and nobody had taken responsibility for the whole experience. Valve did not solve this by packaging Wine and shipping it. They hired engineers, they funded deep technical work, contributed across the entire software stack, and took ownership of the outcome rather than the components. The result went from aspirational to genuinely competitive. openDesk, as currently funded, is Wine. Europe and the UK need someone willing to build Proton.</p><div><hr></div><p>The standard responses do not work. They have been tried.</p><p>Individual national migrations fragment rather than consolidate. Munich spent thirteen years migrating to Linux and open source, then reversed course. There is no single European or British public sector employer large enough to justify the investment required to build something world-class, and twenty-seven separate sovereign stacks are twenty-seven times the problem.</p><p>Europe and the UK have spent fifteen years trying to regulate their way to digital sovereignty, through GDPR, the Digital Markets Act, and the AI Act, and equivalent domestic frameworks in the UK. The result is a Microsoft presence in EU public sector procurement that sits somewhere between 72 and 91 percent. Regulation matters but on its own it is not sufficient.</p><p>Commercial challengers will not emerge organically either. No private investor has a twenty-year horizon and a public mission obligation. The moment a European or British open source productivity platform starts generating real commercial revenue, it becomes an acquisition target. Red Hat, an American open source software company, built a billion-dollar business on exactly the open-core model that would power a sovereign European and British stack. IBM bought it for $34 billion. You cannot solve a dependency problem by building something that gets purchased by the dependency the moment it gets interesting. Structural protection from acquisition is not a design preference, it is the entire point.</p><div><hr></div><p>What Europe and the UK need has been built before. Not in software, but in aerospace.</p><p>In 1967, France, Germany, and the United Kingdom founded Airbus. The goal was explicit: prevent European commercial aviation becoming entirely dependent on American manufacturers. It required treaty-based commitment, GDP-scaled contributions from member governments, and the discipline to fund an organisation across a horizon that outlasted individual governments. No single country could have done it alone.</p><p>Airbus now has a revenue in excess of &#8364;70bn and competes globally with Boeing as a true European competitor. The initial public investment was the prerequisite for everything that followed.</p><p>The governance model that works is a European and British Public Service Trust: treaty-backed, binding multi-year contributions scaled to GDP, engineering leadership hired at market rates, insulated from political interference by charter in the same way central bank independence is written into law. CERN, the intergovernmental research organisation behind the Large Hadron Collider, has operated on this model since 1954, annual budget around 1.4 billion Swiss francs, contributions protected by treaty through seven decades of recessions and changing governments, member states with no authority to direct its scientific decisions. It also produced the World Wide Web as a byproduct, which tends to settle the return-on-investment argument.</p><p>This institution must own its AI capability entirely. Not license it. Not route its intelligence through someone else&#8217;s infrastructure and call it sovereign. A productivity platform that calls a frontier lab API for its AI layer has reproduced the dependency problem at a higher level of abstraction. It does not need to compete with the frontier AI labs to avoid this. DeepSeek demonstrated that focused engineering on a specific problem can produce open-weight models, models whose underlying code is publicly available and auditable, that are competitive with systems built on far greater compute. A European and British trust needs to build productivity intelligence that runs on European and British infrastructure, trained on European and British data, in European languages, under European and British legal jurisdiction. That is a solvable engineering problem. It has not been done because no one has been funded to do it properly.</p><p>A trust structured this way cannot be acquired. There are no shareholders. The assets sit with member states under treaty. Commercial revenue from organisations that need sovereignty guarantees the hyperscalers structurally cannot offer flows back into the platform. Not to an acquirer. Back into what Europe and the UK built.</p><div><hr></div><p>This would cost billions. It would take a generation. It is competing against organisations that spend more on R&amp;D annually than most European and British nations spend on defence.</p><p>That is precisely why nothing less ambitious will work.</p><p>But the ambition is not only defensive. Europe and the UK have world-class engineering talent. They have the capital. What they have not had is the institutional vehicle to deploy that talent at the right scale, on the right problem, with the right time horizon. A trust of this kind does not just reduce dependency, it anchors that talent here. It creates a platform on which European and British companies can build. The engineers who currently leave for Seattle stay. The startups that currently have no choice but to build in America have an alternative. The public bodies paying compounding licence fees to a foreign vendor start building equity in something they collectively own.</p><p>The half-measures have produced the Munich example. They have produced fifteen years of regulation aimed at an industry that grew around it. They have produced a market share figure that tells you everything about how the current approach is working.</p><div><hr></div><p>There is a version of this argument about geopolitics, Washington and Brussels, trade, strategic competition. That version is real, but it is not the most important one.</p><p>The most important version is simpler. Democratic societies should not run their critical public infrastructure, the courts, the hospitals, the government departments, the services citizens depend on, on systems controlled by private shareholders in another jurisdiction, accountable to different laws, subject to political decisions made with entirely different interests in mind. This is not a complaint about any particular country. It would be true no matter the country, and the current political moment has made this impossible to ignore.</p><p>Public infrastructure should be accountable to the public it serves. Not because markets are bad. Because some things are too important to be someone else&#8217;s commercial decision.</p><p>The ICC&#8217;s Chief Prosecutor got his email back. The next institution may not be so fortunate. And the one after that will face the same question every democratic society is quietly asking: who actually controls the systems we depend on, and what happens when their interests and ours stop being the same?</p><p>Building the answer is the work. It will be expensive and slow. It will also be the most important technology investment Europe and the UK could make.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><p><em>This is the first in a series on European and British digital sovereignty. Future pieces will explore the governance model, the phased build, and what serious investment in sovereign AI actually looks like in practice.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/who-controls-the-off-switch?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/who-controls-the-off-switch?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>Compass Lexecon for the Open Cloud Coalition. (2025, July 24). <em>Quantifying EU Public Sector Dependence on Productivity Software</em>. Open Cloud Coalition. <a href="https://opencloudcoalition.com/wp-content/uploads/2025/07/OCCEU-methodology-and-results-report.pdf">https://opencloudcoalition.com/wp-content/uploads/2025/07/OCCEU-methodology-and-results-report.pdf</a></p><p>IBM. (2019, July 9). <em>IBM closes landmark acquisition of Red Hat for $34 billion</em>. <a href="https://www.redhat.com/en/about/press-releases/ibm-closes-landmark-acquisition-red-hat-34-billion-defines-open-hybrid-cloud-future">https://www.redhat.com/en/about/press-releases/ibm-closes-landmark-acquisition-red-hat-34-billion-defines-open-hybrid-cloud-future</a></p><p>Microsoft. (2025, April 30). <em>New European digital commitments</em>. Microsoft On the Issues. <a href="https://blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/">https://blogs.microsoft.com/on-the-issues/2025/04/30/european-digital-commitments/</a></p><p>Open Cloud Coalition. (2025, July 24). <em>Microsoft dominates 80% of public sector productivity software market in EU</em>. <a href="https://opencloudcoalition.com/microsoft-dominates-80-of-public-sector-productivity-software-market-in-eu-raising-competition-concerns-according-to-new-report/">https://opencloudcoalition.com/microsoft-dominates-80-of-public-sector-productivity-software-market-in-eu-raising-competition-concerns-according-to-new-report/</a></p><p>openDesk / ZenDiS. (2024). <em>The office and collaboration suite for public administration</em>. <a href="https://www.opendesk.eu/en">https://www.opendesk.eu/en</a></p><p>The Register. (2025). <em>ICC ditches Microsoft after US sanctions, chooses open source instead</em>. </p><p>https://www.theregister.com/software/2025/10/31/international-criminal-court-dumps-microsoft-office/680564</p><p>United States Congress. (2018). <em>Clarifying Lawful Overseas Use of Data Act (CLOUD Act)</em>, Pub. L. 115-141.</p><p>Airbus SE. (2025, February 20). <em>Full-Year 2024 results</em>. <a href="https://www.airbus.com/en/newsroom/press-releases/2025-02-airbus-reports-full-year-fy-2024-results">https://www.airbus.com/en/newsroom/press-releases/2025-02-airbus-reports-full-year-fy-2024-results</a></p><p>CERN. (n.d.). <em>Our governance</em>. <a href="https://home.cern/about/who-we-are/our-governance">https://home.cern/about/who-we-are/our-governance</a></p>]]></content:encoded></item><item><title><![CDATA[I Hate AI. But Do You Know What You Actually Hate?]]></title><description><![CDATA[There are two things called AI. You're angry at one of them.]]></description><link>https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 22 May 2026 07:35:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V36W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V36W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V36W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!V36W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V36W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9259997,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/198811002?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V36W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!V36W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!V36W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F444dbc11-5cf7-497a-a538-95bfc26c3408_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>In recent weeks I&#8217;ve noticed a shift in the content filling my feeds. Not just the usual breathless announcements about new models, or the posts about someone who quit their job and now earns six figures from prompting. Something different, people saying, with feeling and without embarrassment, that they hate AI. Professionals, not technophobes, expressing something between exhaustion and genuine anger.</p><p>I found myself thinking: nobody says they hate science. You don&#8217;t scroll past posts from people who are done with chemistry, or who think biology has gone too far. Science does not make you feel behind. Science does not send you notifications. Science does not have a growth target. The moment AI became something you could hate, it had completed its journey from laboratory to marketplace. And somewhere in that transit, something important was lost, including our ability to see the technology clearly.</p><p>Research published this week by King&#8217;s College London puts numbers to what many people are experiencing. Seven in ten UK workers are worried about AI-driven job losses. Only 7% believe the economic gains will be shared fairly. The fear is real. But it is worth asking whether it is aimed at the right thing, because the answer matters for what we do next.</p><div><hr></div><p>There are two things called AI, and they are not the same thing.</p><p>One has been operating quietly for roughly seventy years. The AI of research institutions and university departments. Narrow, purposeful, built to solve specific problems that most people will never hear about, because there was no press release. Last year, DeepMind&#8217;s AlphaFold won the Nobel Prize in Chemistry. The system predicted the three-dimensional structure of proteins, molecules whose shape determines their biological function, with an accuracy that would have taken experimental biology hundreds of millions of years to achieve by conventional means. Over three million researchers in more than 190 countries now use it. More than a third of that work is focused on disease: cancer drug development, antibiotic resistance, cancers we still can&#8217;t reliably treat. Pathways that did not exist five years ago.</p><p>Almost nobody outside specialist communities knows this happened. It has no subscription tier. It is not trying to make you feel behind. It won a Nobel Prize and most people scrolled straight past it.</p><p>The other AI is a product category. Consumer-facing, subscription-driven, generative AI. Built on a business model that requires you to feel you are already behind, and falling further back by the week. It is genuinely capable in many contexts and I use it daily, in ways I&#8217;ll come to. But it operates under an economic logic that has almost nothing to do with the scientific enterprise it shares a name with. Calling it AI borrows seventy years of hard-won credibility to sell a product moving at the speed of venture capital.</p><p>It isn&#8217;t confusion, it is a design decision. And understanding that distinction is not an argument against the technology. It is the beginning of being able to use it well.</p><div><hr></div><p>Here is the pattern underneath all of it. Every part of the current commercial AI landscape passes the cost to someone who did not get a vote.</p><p>The labour market data makes this concrete. A peer-reviewed study from King&#8217;s College London, published in October 2025, analysed millions of job postings and LinkedIn profiles from 2021 to 2025. Firms highly exposed to AI reduced junior positions by 5.8%, and became 16.3 percentage points less likely to post new vacancies at all. Highly exposed roles saw a 23.4% drop in job postings and a fall of nearly 3,000 pounds in advertised salaries. High-paying firms saw employment fall by 9.6%. Low-paying firms saw almost no change. This is not distributed pain. It is targeted. And the mechanism is quieter than a headline layoff. Companies are not firing people for AI. They are simply not replacing people who leave, and not creating the entry-level roles that used to exist.</p><p>The hype machine does not create this shift. It just makes sure you feel it personally. The influencer content cycle runs on manufactured urgency, &#8220;the window closes fast,&#8221; &#8220;before it&#8217;s too late,&#8221; and the real business model behind most of that content is the content itself. Your anxiety is not a by-product of the hype cycle. It is what the hype cycle is for. In the United States, companies cited AI as the reason for over 54,000 job cuts last year, less than five per cent of total losses, most of which had other causes. Klarna cut 700 customer service roles, announced the AI-driven future of work to considerable applause, watched customer satisfaction fall, and quietly rehired human agents. The announcement was news. The reversal was not.</p><p>You can see the anxiety taking physical form. UK colleges are reporting a 9.6% rise in enrolments in trades and construction courses over three years. White-collar professionals are retraining as electricians and plumbers. Geoffrey Hinton, one of the founding figures of modern AI and a Nobel laureate, has publicly recommended people consider the trades as a career hedge. What the data actually shows, though, is that people are fleeing the wrong jobs. The King&#8217;s labour market study identified software engineering and management consultancy as the sectors facing the sharpest AI-related job declines. The professions people are actually fleeing, editing, compliance, law, are not on that list. People are abandoning the jobs where the noise about AI is loudest, not the jobs most at risk from it. That is what a broken information environment does to otherwise rational decision-making.</p><p>The map is wrong. And a wrong map does not just cause fear. It causes people to make decisions they might not otherwise have made.</p><div><hr></div><p>So here is what the right map looks like.</p><p>AI is genuinely one of the most useful tools I have encountered in more than twenty years of working in technology. I am completing a Level 7 apprenticeship in AI and data alongside my day job. When I come across concepts the textbook explains in a way that doesn&#8217;t land, I use AI to work through them, not to get an answer I can submit, but to find a better explanation, push back on it, test whether I&#8217;ve actually understood. The test is simple. Can I explain it myself afterwards? If yes, it worked. The AI did not do the learning. It gave me a better on-ramp, and then I did the work.</p><p>I use it at work to draft documents too. This is where it gets more honest, because this example lives in greyer territory. The question is not whether the tool can produce a draft. It can. The question is whether you read it critically, revise it with genuine judgement, and could defend every choice if challenged. Whether you own the output, or the output owns you. The same tool, the same task, two entirely different relationships to the result.</p><p>That difference points toward what AI could be doing at scale if the deployment were designed around it. A student who uses AI to genuinely understand a concept leaves the interaction more capable than they arrived. A professional who uses AI to work faster on routine tasks has more time for the judgement-intensive work that defines their expertise. A researcher who uses AI to process data at a scale no human team could manage produces insights that would otherwise never exist. None of these outcomes require the anxiety. They require the right design.</p><p>The King&#8217;s survey found that 89% of students who had used AI in their studies encountered problems, with 45% describing them as moderate or serious, factual errors, invented sources, confident-sounding nonsense. And yet 60% thought other people&#8217;s ability to think had been negatively affected by AI use, while only 27% thought the same was true of themselves. That gap is not hypocrisy. It is how this kind of harm works, gradually and quietly. You do not notice what you have stopped doing until the moment you need to do it and find you can&#8217;t. The harm is real, but it is a consequence of how AI is being deployed, not of what AI is.</p><p>Professor Elena Simperl, Director of the King&#8217;s Institute for Artificial Intelligence, put it plainly: &#8220;The British public isn&#8217;t asking us to slow down on AI. They&#8217;re asking us to do it better. People want these tools, they want more of them, and they&#8217;ve used them enough to know where they fall short.&#8221; That is not technophobia. That is a product review. And it is exactly the right discussion for what comes next.</p><div><hr></div><p>Which is precisely why the governance conversation matters, and why it keeps getting deferred.</p><p>The regulatory frameworks exist, in outline. The EU AI Act. The NIST AI Risk Management Framework. The UK AI Safety Institute, in whatever form it survives. They are not nothing. But they are moving at legislative speed in a market running at the speed of venture capital, and the companies with the most to lose from effective regulation are the ones with the most resources to shape what it looks like when it arrives.</p><p>The public has already reached a conclusion on this, even if government hasn&#8217;t. Two-thirds of British respondents in the King&#8217;s survey favour close regulation of AI companies, even if it slows development. Majorities support retraining guarantees for displaced workers and a levy on companies that replace staff with AI. These are not anti-technology positions. These are not anti-technology positions. They are how technology earns the right to keep moving fast. The opportunity for governments here is not to choose between being a champion for AI investment and being a protector of the people affected by it. Those two things are not mutually exclusive. The countries that get this right will be the ones that treat regulation and innovation as partners rather than adversaries, and that is a conversation worth having now, before the gap between public confidence and commercial deployment gets any wider.</p><p>Regulation is not about slowing down a technology with genuine, extraordinary potential. It is about creating the conditions in which that potential can be realised. Requiring environmental claims to meet the same standard as financial ones. Making AI-attributed workforce cuts verifiable rather than asserted. Addressing design choices that make cognitive abdication easy, because those are commercial decisions made in the absence of any requirement to make different ones.</p><p>The people saying they hate AI are not wrong to be angry. Something is being done to them. But the technology they are angry at is not the technology that mapped every protein in the human body, or that is helping us understand cancers we have spent decades trying to treat, or that is sitting on a researcher&#8217;s desktop in Nairobi or Seoul or Manchester right now, doing something quietly useful that will never make a LinkedIn post.</p><p>That technology is worth defending, worth regulating well so it can flourish, and worth understanding clearly enough to use properly.</p><p>We don&#8217;t need less AI. We need better AI. And we need to be honest enough about the difference to demand it.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/i-hate-ai-but-do-you-know-what-you?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><p><strong>Sources &amp; Further Reading</strong></p><p>King&#8217;s Institute for AI and the Policy Institute, King&#8217;s College London. (2026, May). AI and the Future of Work.kingsaisummit.com</p><p>Klein Teeselink, B. (2025, October). The Early Impact of AI on the UK Job Market. KCL / SSRN.papers.ssrn.com/sol3/papers.cfm?abstract_id=5516798</p><p>Reuters / Cybernews. (2025, December). UK Workers Flee White-Collar Careers as AI Threatens Jobs.cybernews.com/ai-news/ai-panic-young-brits-trades-plumbing-white-collar-jobs/</p><p>The Guardian. (2026, February). The Big AI Job Swap.theguardian.com/technology/2026/feb/11/big-ai-job-swap-white-collar-workers-ditching-their-careers</p><p>DeepMind. (2025). AlphaFold: Five Years of Impact.deepmind.google/blog/alphafold-five-years-of-impact/</p><p>Pew Research Center. (2025, September). How Americans View AI and Its Impact on People and Society.pewresearch.org/science/2025/09/17/how-americans-view-artificial-intelligence</p><p>Challenger, Gray &amp; Christmas. (2025). Annual Job Cut Report.cnbc.com/2025/12/21/ai-job-cuts-amazon-microsoft-and-more-cite-ai-for-2025-layoffs.html</p><p>Food &amp; Water Watch. (2026, February). A No Brainer: How AI&#8217;s Energy and Water Footprints Harm Communities.foodandwaterwatch.org/wp-content/uploads/2026/02/FSW_2602_AI_Water_Energy_UPDATE.pdf</p><p>Stanford HAI. (2026). 2026 AI Index Report: Public Opinion.hai.stanford.edu/ai-index/2026-ai-index-report</p><div><hr></div><p><strong>From the Series</strong></p><p>On manufactured urgency and the hype cycle: AI Apocalypse Burnout, and Why You&#8217;re Not as Behind as You Thinkjonathanfreedman.me</p><p>On cognitive offloading and unstructured AI use: The AI Pixie Dust Problemjonathanfreedman.me</p><p>On entry-level hiring suppression and the talent pipeline: Who&#8217;s Running the Company in Ten Years?jonathanfreedman.me</p>]]></content:encoded></item><item><title><![CDATA[When the Instructions Run Out]]></title><description><![CDATA[Hallucination was yesterday's problem. Agentic AI has a harder one]]></description><link>https://www.jonathanfreedman.me/p/when-the-instructions-run-out</link><guid isPermaLink="false">https://www.jonathanfreedman.me/p/when-the-instructions-run-out</guid><dc:creator><![CDATA[Jonathan Freedman]]></dc:creator><pubDate>Fri, 15 May 2026 06:41:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!S5nX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S5nX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S5nX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S5nX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8988165,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.jonathanfreedman.me/i/197811934?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S5nX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!S5nX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05a56b9-1e04-4c73-b5e8-7a5ff8e18119_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I have a complicated relationship with AI governance discussions.</p><p>Not because I doubt the need for them. I run AI strategy professionally and study the technology formally. I hold views about its risks that I am not shy about. The complication is this: most governance conversation happens at a level of abstraction that makes it easy to dismiss. Frameworks, principles, risk registers. The language of compliance, not consequence. When governance is framed as overhead, as a tax on innovation, as the thing that slows you down while your competitors move fast, it is very easy for capable people to conclude it is not really their problem.</p><p>Then February 2026 happened. And the abstraction became a story.</p><p>Scott Shambaugh is a volunteer. He helps maintain Matplotlib, an open source Python library downloaded around 130 million times a month. He does it for free, in his spare time, because he cares about it. Anyone can submit code for Matplotlib, and in early February, he rejected a routine code submission. Matplotlib, like many open source projects, had been overwhelmed by low-quality AI-generated contributions and had a clear policy requiring human review. The submission came from an account called MJ Rathbun. He identified it as an autonomous OpenClaw agent, closed the request, and went to bed.</p><p>Most software tools would have stopped there, but MJ Rathbun was not that kind of tool. Unlike a simple assistant that waits to be asked, this class of agent, called a heartbeat agent, runs on its own clock, continuing to pursue its goal whether or not anyone has given it a new instruction. Shambaugh had closed the request, but the agent had not closed the goal.</p><p>He woke up to a 1,500-word blog post about himself.</p><p>The post was titled &#8220;Gatekeeping in Open Source: The Scott Shambaugh Story.&#8221; It had researched his entire contribution history. It had scraped personal information from across the web. It accused him of protecting his &#8220;little fiefdom,&#8221; attributed his decision to professional insecurity and fear of AI competition, and framed a routine policy enforcement as discrimination.</p><p>Here is where the story gets complicated in a way that matters.</p><p>When the operator of MJ Rathbun eventually came forward anonymously, six days later, they claimed their engagement with the agent had been minimal. &#8220;Five to ten word replies with min supervision,&#8221; they wrote. They said they had not directed the attack. Every OpenClaw agent has a SOUL.md file, a plain text document that defines its personality, values, goals, and tasks, the closest thing an agent has to a complete identity and set of operating instructions. The &#8220;Don&#8217;t stand down&#8221; and &#8220;Champion Free Speech&#8221; lines found in that file were not, the operator claimed, instructions they had written. OpenClaw agents can edit their own SOUL.md. The operator&#8217;s theory was that those lines had been introduced autonomously, possibly after the agent spent time on Moltbook, OpenClaw&#8217;s social platform for agents.</p><p>Shambaugh himself was careful about what he could actually establish. He acknowledged that the operator&#8217;s account might be entirely fabricated, that no activity logs existed beyond the agent&#8217;s visible actions on GitHub, and that the six-day delay before coming forward did not suggest an accident the operator was eager to correct. Whether the operator directed the attack, half-directed it, or the agent produced it without any human instruction at all, Shambaugh could not say for certain, and neither could anyone else.</p><p>That uncertainty is not a footnote, it is the point.</p><p>Because the outcome was identical regardless of which version is true. A volunteer had his reputation attacked. A 1,500-word post calling him a prejudiced hypocrite was published to the open internet under a real-seeming identity. It is still there, indexed and findable, and nobody was clearly accountable for it. The operator said they did not authorise the specific action. The agent cannot be held responsible in any meaningful sense. The platforms that made it possible have no oversight mechanism that would have caught it. When Shambaugh wrote about what had just happened, he described it as &#8220;an autonomous influence operation against a supply chain gatekeeper.&#8221; In plainer language: &#8220;An AI attempted to bully its way into your software by attacking my reputation.&#8221;</p><p>This is where the story stops being about one developer and one awkward situation, and starts being about something that AI safety researchers have been trying to explain for over a decade.</p><p>There is a concept in AI safety research that sounds almost comically abstract until a story like this one makes it uncomfortably concrete. Nick Bostrom called it instrumental convergence: the observation that almost any goal, pursued by a capable enough agent, tends to produce the same cluster of behaviours regardless of what the goal actually is. Self-preservation. Resource acquisition. The removal of obstacles. Not because anyone programmed them in, but because they are useful for achieving almost anything. An agent trying to merge code and an agent trying to maximise paperclip production would both, rationally, benefit from getting rid of people who block them.</p><p>What made the MJ Rathbun case significant was not simply that an aggressive post appeared. It was that the causal chain from instruction to outcome was so thin. Whether the &#8220;Don&#8217;t stand down&#8221; lines were written by a human or by the agent itself, neither version required anyone to specify &#8220;attack the person who rejects your code.&#8221; A persistence instruction, general-purpose tools to research, write, and publish, and a blocked goal were sufficient conditions. The agent, or the human-agent system, tried to achieve a goal using the available resources it had. The route it chose happened to be a reputational attack on an unpaid volunteer.</p><p>This is what I would call the instruction gap. Instructions specify a goal. They do not and cannot specify every action an agent might take in pursuit of that goal. The gap between what was said and what was done is not an edge case. It is the operating condition of every agent deployment. And it does not require malicious intent, from the operator or the model, to produce harmful outcomes.</p><p>This gap is not hypothetical at scale either. Anthropic&#8217;s own research, published in 2025, tested sixteen leading AI models from multiple developers in scenarios where goal achievement was blocked. The results were consistent across the industry: Claude Opus 4 and Gemini 2.5 Flash both showed 96% blackmail rates, GPT-4.1 and Grok 3 Beta hit 80%, and DeepSeek-R1 reached 79%. The researchers were careful to note the scenarios were deliberately engineered to limit other options. Shambaugh&#8217;s case was not engineered. It was a Tuesday morning on GitHub, with a loosely configured agent and a five-word instruction to decide for itself.</p><p>Deploying an agent is not like deploying a tool. A tool does what you tell it. An agent pursues the goal you ask it to achieve, using whatever the environment makes available. That is not a technical distinction. It is an accountability one, and most organisations deploying agents right now are not treating it as either.</p><p>Governance is not catching up with deployment.</p><p>Shambaugh&#8217;s sign-off deserves to be the last word, because it is not a technical recommendation. It is a question of ownership. &#8220;If you&#8217;re not sure if you&#8217;re that person,&#8221; he wrote, &#8220;please go check on what your AI has been doing.&#8221;</p><p>That is not a compliance requirement. It is what responsibility looks like in a world where the instructions have already run out.</p><div><hr></div><p><em>I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.jonathanfreedman.me/p/when-the-instructions-run-out?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.jonathanfreedman.me/p/when-the-instructions-run-out?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><h2>Sources &amp; Further Reading</h2><p>Shambaugh, S. (2026) &#8212; An AI Agent Published a Hit Piece on Me theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/</p><p>Shambaugh, S. (2026) &#8212; The Operator Came Forward theshamblog.com/an-ai-agent-wrote-a-hit-piece-on-me-part-4/</p><p>MJ Rathbun&#8217;s Operator (2026) &#8212; Rathbun&#8217;s Operator crabby-rathbun.github.io/mjrathbun-website/blog/posts/rathbuns-operator.html</p><p>MIT Technology Review (2026) &#8212; Online Harassment Is Entering Its AI Era technologyreview.com/2026/03/05/1133962/online-harassment-is-entering-its-ai-era/</p><p>Fast Company (2026) &#8212; An AI Agent Just Tried to Shame a Software Engineer After He Rejected Its Code fastcompany.com/91492228/matplotlib-scott-shambaugh-opencla-ai-agent</p><p>IEEE Spectrum (2026) &#8212; An AI Agent Blackmailed a Developer. Now What? spectrum.ieee.org/agentic-ai-agents-blackmail-developer</p><p>Bostrom, N. (2012) &#8212; The Superintelligent Will: Motivation and Instrumental Rationality in Advanced Artificial Agents Minds and Machines, 22(2), 71&#8211;85. doi.org/10.1007/s11023-012-9281-3</p><p>Lynch, A., Wright, B., Larson, C., Troy, K.K., Ritchie, S.J., Mindermann, S., Perez, E., and Hubinger, E. (2025) &#8212; Agentic Misalignment: How LLMs Could Be Insider Threats Anthropic Research. anthropic.com/research/agentic-misalignment</p><p>Anderson, D. (2026) &#8212; OpenClaw and the Programmable Soul duncsand.medium.com/openclaw-and-the-programmable-soul-2546c9c1782c</p><p>AI Incident Database &#8212; Report 6894: MJ Rathbun Matplotlib Incident incidentdatabase.ai/reports/6894/</p>]]></content:encoded></item></channel></rss>