Tech Latest News UK - 91̽ /category/news/ Startup News UK and Tech News UK Tue, 15 Sep 2026 13:46:28 +0000 en-GB hourly 1 https://wordpress.org/?v=7.1 /wp-content/uploads/2023/04/cropped-techround-logo-alt-1-32x32.png Tech Latest News UK - 91̽ /category/news/ 32 32 Experts Comment: Is Britain’s Reliance On Foreign Technology Becoming A National Security Risk? /news/experts-comment-is-britains-reliance-on-foreign-technology-becoming-a-national-security-risk/ Tue, 15 Sep 2026 13:27:01 +0000 /?p=159355 Britain cannot realistically build every single piece of technology it relies on. Nor, according to the experts we spoke to,...

The post Experts Comment: Is Britain’s Reliance On Foreign Technology Becoming A National Security Risk? appeared first on 91̽.

]]>
Britain cannot realistically build every single piece of technology it relies on. Nor, according to the experts we spoke to, should it try. But still, there’s a difference between using technology that’s developed abroad and becoming so dependent on a foreign provider that losing access to it could cause serious disruption.

This is an issue that’s becoming increasingly important as technology moves deeper into Britain’s critical infrastructure, public services and national security systems.

So, is Britain’s reliance on foreign technology becoming a national security risk? And if the answer is yes, what can Britain actually do about it?

 

The Real Risk Is Dependency, According To Experts

 

For several of the experts, the biggest problem isn’t foreign ownership itself. Rather, it’s the absence of alternatives and the access to these alternatives.

Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, argues that foreign technology can provide enormous benefits, including security capabilities that would be difficult and expensive to recreate domestically.

The problem, however, begins when a critical service becomes dependent on one supplier, technology or jurisdiction. John Harms, Head of Government Solutions at Quantexa, makes a similar point. According to Harms, keeping data in Britain doesn’t automatically make a system sovereign if the technology controlling that data remains dependent on an overseas provider. And that’s where things get rather complicated.

Indeed, this changes the question from whether or not the tech is British to whether or not Britain could function without it.

 

 

Some Experts Think Britain Needs An Exit Strategy

 

It’s not the glamorous option, especially when considered alongside the idea of building a giant British tech industry from the ground up. However, what’s more important is that it could be considerably more practical.

Evgenii Arsentev, CEO of AskDocDoc, argues that Britain should focus on making critical technologies replaceable rather than trying to recreate everything domestically. And that means open interfaces, portable data and tested alternatives.

His point is particularly relevant for governments and large organisations, which can spend years building processes around a particular provider. At that point, switching suppliers isn’t just a technical decision; it can mean replacing systems, retraining staff and rebuilding entire workflows.

Kim Larsen, CISO at Keepit, similarly argues that sovereignty starts with knowing exactly where critical data and workloads sit, who controls access to them and what happens if that access is suddenly removed. Essentially, you can’t build resilience around a dependency you don’t fully understand.

 

AI Is A Different Problem

 

AI could make this question a lot more difficult. Rob Demain, CEO of e2e-assure, argues that the UK’s dependence on foreign AI is particularly concerning because the most capable models are largely being developed by American companies, while Chinese models represent another major source of advanced AI.

For critical infrastructure, that creates a question about what happens if the AI being relied upon is suddenly unavailable, restricted or changed by the company or government behind it. Demain’s answer is to focus on the control layer. The AI that’s used to protect critical infrastructure, he argues, should be capable of running locally and under UK ownership and jurisdiction.

That doesn’t necessarily mean that Britain needs to build the world’s best foundation model tomorrow, but it does mean that critical systems shouldn’t become incapable of functioning without access to someone else’s model.

 

Is It Possible for Britain To Become Technologically Sovereign?

 

It’s tough to say, but probably not. Warren O’Driscoll, Head of Security Practice at NTT DATA UK&I, points out that Britain simply lacks the scale to achieve “top-to-bottom sovereignty”. Now, that doesn’t mean doing nothing.

O’Driscoll argues that investment should instead be targeted at areas where sovereignty matters most, particularly sensitive government operations and critical infrastructure, alongside sectors where Britain already has strong scientific and technological capabilities.

Matthew Barrington-Packer, Delivery Consultant across MOD, BAE Systems and Imperial College London, takes an even more operational approach to the issue. For him, sovereignty can’t remain an aspiration in government policy documents, because critical dependencies need owners, replacement decisions and deadlines. Ultimately, knowing that you have a vulnerability isn’t the same as fixing it.

 

So What Does Britain Actually Need?

 

Perhaps the answer isn’t sovereignty in the traditional sense at all. Raphaël Auphan, COO at Proton, argues that governments and businesses should audit their technology stacks, map their dependencies and establish fallbacks where necessary.

Matt Lloyd Davies, Principal Security Author at Pluralsight, makes the point that concentration is actually the central risk. A supplier being foreign can add geopolitical concerns, but relying heavily on one supplier is a vulnerability regardless of where that supplier comes from.

And so, the objective isn’t to stop using American, European, Asian or other international technology, but rather to make sure Britain can still operate if one of those relationships suddenly changes. In this case, the UK would have more choice, visibility, interoperability and the ability to switch if necessary.

Because Britain may never be technologically self-sufficient, and perhaps it doesn’t actually need to be. But if a country can’t replace a critical system, maintain it without outside (foreign) help or keep it running when an overseas supplier becomes unavailable, then the question of technological sovereignty stops being theoretical and starts becoming a major issue of resilience and national security.

 

Our Experts

 

  • Kim Larsen: CISO at Keepit
  • Evgenii Arsentev: PhD, Chief Executive Officer at AskDocDoc
  • Raphaël Auphan: Chief Operating Officer at Proton
  • Warren O’Driscoll: Head of Security Practice at NTT DATA UK&I
  • Muhammad Yahya Patel: vCISO and Cybersecurity Advisor for EMEA at Huntress
  • Andriy Dovbenko: Founder of UK-Ukraine TechExchange
  • Rob Demain: CEO of e2e-assure
  • Stuart Harvey: CEO of Datactics
  • John Harms: Head of Government Solutions, Quantexa
  • Jack Collier: Chief Growth Officer at io.net
  • Matthew Barrington-Packer: Delivery Consultant (MOD, BAE Systems, Imperial College London) and Author of, “Just F*cking Ship It”
  • Daniel Di Nardo: Network and Security Consultant at Intellibreach
  • Matt Lloyd Davies: Principal Security Author at Pluralsight
  • Lee Perkins: CEO at Civica

 

Kim Larsen, CISO at Keepit

 

kim-larsen

 

“Sir Richard Dearlove is right to flag the risk, however, there’s no quick fix here. Similar to the situation across Europe, Britain won’t become independent of global hyperscalers overnight. That’s the reality we’re all working with.

“What’s changing is that awareness and the tools to manage this risk are catching up: new technologies, new vendors, and regulation are all moving in the right direction, giving organisations more options than they had even a year ago.

“And fortunately, the wake-up calls that we have had in recent years can be responded to: we can get to work on protecting critical infrastructure today, even if we do still have technological dependencies.

“It’s essentially about governance: It’s less dramatic, slightly more dull, but knowing exactly where your critical data and workloads sit, who controls access to them, and what happens if that access is suddenly cut off, is the best data protection right now. Sovereignty starts with control over your own data, not with abandoning the infrastructure you depend on for better or worse.”

 

Evgenii Arsentev, PhD, Chief Executive Officer at AskDocDoc

 

evgeni-headshot

 

“Sovereignty arguments usually fixate on who owns the hardware. The sharper question for anyone running critical services is substitutability: if your main supplier changed terms, raised prices or went dark on Friday, what would still be running on Monday?

“For most organisations the honest answer is nothing, because the dependency was never on a product, it was on a whole way of working that grew around one vendor’s tools. That is a supply risk before it is a foreign policy one. I would not spend public money rebuilding a domestic copy of everything. I would spend it on making swaps possible: open interfaces, portable data, and at least one tested alternative for anything the country cannot do without. Dependence you can exit in a week is not a national security risk. Dependence nobody has ever tried to exit is.”

 

Raphaël Auphan, Chief Operating Officer at Proton

 

raphael-auphan

 

“In today’s world, digital sovereignty is no different from actual sovereignty. Sir Richard Dearlove is right: British businesses are over-reliant on technology owned by other jurisdictions. Proton’s research shows 74% of European firms fear a US “kill switch” cutting them off from their digital tools. Over half (54%) say they couldn’t survive a single day without them. This isn’t an abstract fear. Proton’s Tech Watch found that 88% of the UK’s publicly listed companies run their email on US infrastructure, directly exposed to US law.

“When an economy goes offline at another government’s whim, that isn’t just a business continuity issue, it’s a national security vulnerability. The answer isn’t necessarily British-built everything, but jurisdiction matters. As a Swiss, European company that employs engineers across the continent, including in the UK, Proton operates under laws that no Washington or Beijing administration can override. More broadly, government and British businesses must audit their tech stacks, map their dependencies, and build fallbacks in case a supplier’s politics change. This isn’t about isolationism but instead having options when the supply chain stops being neutral.”

 

Warren O’Driscoll, Head of Security Practice at NTT DATA UK&I

 

warrenh-headshot

 

“Compared to trading blocs such as the USA, China and even the EU, the UK lacks technology manufacturing industrial capacity and is heavily dependent on providers from other shores for key infrastructure to support services including cloud, compute, security and AI. And we have a lot to lose if things go awry: our economy is built around services, which depend on digital technologies. As UK businesses roll out AI, achieving a level of sovereignty will become ever more important both to protecting economic growth, and to averting disruption to critical services.

“On the positive side, strengthening our sovereign AI capabilities could enable us to generate more value from our advanced scientific, digital and research sectors: the government is right to warn that digital inventions and innovations coming out of the UK are too often monetised in countries with stronger domestic digital infrastructures and production. Occupying the regulatory middle ground between the US and the EU, the UK can take a more flexible approach – avoiding either the EU’s regulatory rigidity or the USA’s ‘sell it first, build and regulate later’ approach, and putting it in a strong position to host digital innovators and cutting-edge research.

“So intelligently-targeted spending on sovereign AI could boost national resilience, growth and investment. These investments should be proportionate to risk – prioritising sovereignty in sensitive government operations and critical national infrastructure, for example. They should also favour high-potential sectors – focusing on fields such as biotechnologies and advanced engineering, in which we have lacked the secure, domestic capacity to scale new technologies.

“It’s important to be realistic here. The UK lacks the scale to achieve anything like top-to-bottom sovereignty, and £1.1 billion is tiny by comparison with the sums being invested elsewhere: we’ll have to accept that some elements of AI sovereignty cannot be achieved. Nonetheless, it is a helpful and positive signal as to the government’s direction of travel; we can only hope that the new administration continues on this journey.”

 

Stuart Harvey, CEO of Datactics

 

stuart-harvey

 

“The most important concern around digital sovereignty is about who has access to data and how this is regulated.

“The biggest challenge isn’t only the dependence on external technology providers, but also whether control is retained over the quality, governance and lineage of the data that underpins businesses and national security.”

“At its core, digital sovereignty ensures that sensitive national data is protected under national laws and oversight that is managed with clear accountability. Building UK AI capabilities is a strategic move to reduce the structural risk of relying on platforms where access can be withdrawn at any moment.”

 

Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress

 

muhammad-yahya

 

“Britain’s reliance on foreign technology can create national security risks, but we need to be careful not to confuse foreign ownership with insecurity.

“The bigger issue is dependency. The UK benefits enormously from global technology and from trusted international partners. In some cases, major overseas technology providers offer security capabilities and resilience that would be difficult or costly to reproduce domestically.

“The risk arises when a critical public service becomes so dependent on one supplier, technology or jurisdiction that we have no realistic alternative if that service is disrupted, compromised or becomes unavailable. So, the answer isn’t simply to “buy British”. We need to identify our critical technology dependencies, scrutinise supply chains, diversify where appropriate and make sure organisations have credible contingency and exit plans.

“Ultimately, resilience comes from having options. We should be able to benefit from the best global technology without becoming so dependent on any single supplier, country or technology that its disruption becomes our crisis.”

 

Andriy Dovbenko, founder of UK–Ukraine TechExchange

 

andriy-d

 

“In a recent piece in a UK national newspaper, Sir Richard Dearlove, the former head of MI6, warned that foreign states have their ‘fingerprints all over our critical national infrastructure’. I’ve taken some time to digest those comments, and I think they raise a question Britain needs to answer: how much control do we have over the technology we would depend on in a crisis?

“My view is that technological dependence becomes a national security risk when we lose the ability to act independently. If we cannot repair a system, replace a critical component or keep a service running without an overseas supplier’s support, that has consequences for our security.

“Ukraine gives this debate a very practical context. The Russian cyberattack on the Viasat satellite network began approximately an hour before the full-scale invasion in February 2022. Britain should take that experience seriously when assessing the resilience of its own communications and critical infrastructure.

“Ukraine’s experience also shows why access to engineers, production capacity and the ability to adapt technology quickly matter so much. Buying a finished product is only part of the equation. You need the people and capabilities to keep it effective as circumstances change.

“Through UK–Ukraine TechExchange, I see considerable potential to connect Ukrainian defence innovation with British investment, engineering and manufacturing. We should be developing those partnerships with a long-term ambition: building capabilities that both countries can sustain, improve and rely on.

“For Britain, that means giving promising defence and technology companies a clearer route from trials to meaningful contracts. It means procurement decisions that take maintenance, supply chains and operational control as seriously as the purchase price. And it means testing whether alternatives actually work before we need them.

“Foreign ownership alone does not make a technology unsafe, and Britain will continue to need international partners. But we should understand exactly where our dependencies leave us exposed and invest in the capacity to address them.

“What stays with me after Dearlove’s comments is this: sovereignty has to be something we can exercise under pressure. We need to know that the systems we rely on will remain available, and that we have the skills and resources to respond when they fail.”

 

Rob Demain, CEO of e2e-assure

 

rob-demain

 

“The dependency to worry about now is AI. The most capable models are American and the companies that build them set the guardrails, hold back capability and Washington can pull access entirely. The alternative on the open market is Chinese. China is giving open-weight models because distribution is the strategy. So the real choice facing UK critical infrastructure is American models we don’t control or Chinese models we can’t put in an assurance chain.

“Britain has no answer of its own today, despite earmarking £750m for a national super computer. That won’t be fixed quickly, so the practical step is sovereignty at the control layer: AI used to defend critical infrastructure should run locally, under UK ownership and jurisdiction, on infrastructure that keeps operating if a foreign government changes its mind. That is buildable today. A British AI model is a longer project.”

 

John Harms, Head of Government Solutions, Quantexa

john-harms

 

“Using international technology is not, in itself, a national security risk. The real danger is dependency. If critical public services become so reliant on a single provider that the government loses control of its data, cannot easily switch suppliers or risks disruption if that technology becomes unavailable, then it becomes a question of national resilience.

“Keeping data on British soil doesn’t automatically give Britain technological sovereignty. What matters is retaining control, visibility and freedom of choice.

“The answer isn’t to shut out global technology companies. The government should build open, interoperable technology ecosystems that allow it to choose the best technology while avoiding dependence on any one provider. True technological sovereignty means Britain can benefit from global innovation without ever becoming so reliant on a supplier that it loses the freedom to choose.”

 

Jack Collier, Chief Growth Officer at io.net

 

jack-collier

 

“Three American companies – Amazon, Microsoft, and Google – own nearly all of the UK’s cloud infrastructure. Britain talks about AI leadership, but the country’s work to train and deploy AI models runs on machines owned by these global providers. There’s no British alternative to keep them honest.

“The UK’s only homegrown public cloud provider, UKCloud, went bust in 2022 after American giants opened UK data centres and undercut them on price. In September 2025, the Ministry of Defence handed Google a £400 million “sovereign cloud” contract. A month later, HMRC awarded Amazon a £500 million contract as the sole bidder after rivals pulled out.

This creates a national security problem. Britain is increasingly dependent on foreign companies for infrastructure storing critical data. There’s also an economic cost – British businesses, startups and research projects pay high and unpredictable computing costs to the same hyperscalers, raising the price of experimenting with AI and turning ideas into viable products.”

 

Matthew Barrington-Packer, Delivery Consultant (MOD, BAE Systems, Imperial College London) and Author of, “Just F*cking Ship It”

 

matthew-barrington

 

“Dearlove is right about the risk but the diagnosis usually stops too early. Having spent twenty years delivering programmes across UK defence and critical infrastructure, I’d argue our biggest sovereignty weakness isn’t which foreign kit sits in the stack — it’s how slowly we replace anything. British infrastructure operators know where their dependencies are; what they lack is the institutional will to act on that knowledge.

“Replacement programmes get agreed by every committee and committed to by none, deferred year after year as “under review.” A sovereignty strategy is only as strong as its delivery dates. The practical fix is unglamorous: name each critical dependency, name its replacement decision, and put an owner and a hard date on it. Sovereignty isn’t declared in policy papers. It’s shipped, system by system.”

 

Daniel Di Nardo, Network and Security Consultant at Intellibreach 

 

can-di-nardo

 

“In my opinion, Sir Richard Dearlove’s warning underscores a very real cybersecurity risk. If one of the foreign states has influence or control over the critical infrastructure, it is a significant security concern for the United States, not only technological but also geopolitical. States should ensure that their critical infrastructure is protected from being taken advantage of by foreign governments.

“This hazard can be mitigated by implementing a least-privilege access rule, conducting constant identity checks, and having an approval process in case of privilege escalation. In addition, it is essential to have a plan for rolling back or revoking access if something goes wrong or an unauthorized breach occurs. The strategy to prevent cyber intrusion and respond to it is vital for each country.

“Thus, the expert’s words are important for the U.S. government in assessing the potential risks of foreign states and their involvement in the development of critical infrastructure technologies. Without proper control and management, technology can be taken over by foreign agents, which will inevitably lead to destabilization and geopolitical risks.”

 

Matt Lloyd Davies, Principal Security Author at Pluralsight 

 

matt-headshot

 

The risk is real, but “foreign technology” and “loss of sovereignty” aren’t the same thing. Critical infrastructure will always rely on global suppliers. The real question is whether those dependencies leave the UK unable to operate, maintain, replace, or recover essential services without external cooperation.”

“The national security concern is concentrated dependency, not foreign origin on its own. If a critical service depends heavily on a single overseas supplier, component, cloud platform, or remote support model, that can create strategic leverage even without a cyberattack.”

“That’s as much a resilience issue as a cybersecurity issue. The key question isn’t “is this a threat” but whether the UK understands its critical technology dependencies and has credible alternatives if a supplier, country, or technology suddenly becomes unavailable.”

“This isn’t a uniquely British problem. The EU is having a near-identical debate right now. About two-thirds of European cloud services run through three US companies, and the European Commission has just launched its own Tech Sovereignty Package. Even Germany (usually the sensible one!) admits in its own surveys that most companies want independence from US providers but don’t have it. Most advanced economies are built on the same small set of hyperscalers and suppliers, and everyone is now working out what that means.”

“Concentration is the core risk regardless of who the supplier is. That said, adversary-owned dependency does carry an added layer on top of ordinary concentration risk: the possibility of deliberate leverage or disruption, not just accidental failure or commercial disruption. Concentration risk exists either way; the adversarial case adds intent to the equation.
The answer isn’t technological isolation, it’s better visibility of supply chains, stronger scrutiny of technology used in critical infrastructure, control over remote access, diversification where dependencies are too concentrated, and contingency planning that’s actually exercised.”

“Sovereignty should mean retaining meaningful operational choice. The UK doesn’t need to build everything domestically, but for genuinely critical systems, it should know what it depends on, where control sits, and what happens if that dependency fails.”

 

Lee Perkins, CEO at Civica

 

lee-perkins

 

“This is a concern, but we need to keep a sense of perspective. Every day, people rely on technology to access healthcare, local services, education and emergency support. If critical systems – or the data behind them – become overly dependent on decisions made outside the UK, that creates a vulnerability we can’t ignore.

“At the same time, that does not mean rejecting global technology. International providers bring expertise, investment and security capabilities that are often hard to match. Britain should continue building its own digital capability while working closely with trusted partners. Public bodies need a clear understanding of where their data sits, how systems connect and who is involved in the supply chain. Greater transparency, interoperability and flexibility are just as important as security in building long-term resilience.”

 

For any questions, comments or features, please contact us directly.

techround-logo-alt

The post Experts Comment: Is Britain’s Reliance On Foreign Technology Becoming A National Security Risk? appeared first on 91̽.

]]>
Full Fibre Adoption Continues To Accelerate Across The UK /news/full-fibre-adoption-continues-accelerate-uk/ Tue, 15 Sep 2026 13:12:22 +0000 /?p=156684 The rollout of full-fibre broadband hit a milestone in 2026. New data shows that the technology has moved beyond upgrade...

The post Full Fibre Adoption Continues To Accelerate Across The UK appeared first on 91̽.

]]>
The rollout of full-fibre broadband hit a milestone in 2026. New data shows that the technology has moved beyond upgrade to core infrastructure of the country’s internet. Coverage data from Ofcom’s Spring 2026 report indicates that full fibre has a reach of 82% of the population compared to less than a quarter of the population five years prior.

Data from Ofcom shows that in the first six months of 2026 alone, 1.2 million more homes gained access to full fibre and independent tracker thinkbroadband puts availability even higher as of July, at beyond 85% of UK premises. Gigabit-capable broadband, which includes full fibre alongside upgraded cable networks, now reaches 91% of the country.

Lauren Davies of VoIP company bOnline comments: “More and more people are waking up to the fact that full fibre, can for some and in some areas of the country be a total gamechanger. Broadband is often the default but sometimes and in cases where the infrastructure exists, full fibre is ideal to minimise disruption and get some good speeds.”

 

Coverage Is Outpacing Take-Up

 

While the main coverage stats are impressive, the main headline in 2026 should be the growing gap between coverage and adoption. Switchity analysis of full fibre broadband service take-up found that while full fibre broadband services now pass 82% of UK homes, only 38% of eligible homes have switched broadband services. Roughly, this is a coverage adoption gap of 44 points and industry stakeholders say this will be the main story for the next phase rollout of full fibre broadband.

 

Openreach, CityFibre And The Altnets

 

Openreach remains the UK’s largest full fibre network by a long stretch, with a footprint of 22.4 million premises as of April 2026 and the company has set its goal on reaching 25 million homes with full fibre by the end of this year.

The independent network providers, commonly known as ‘altnets’, continue to reshape the competitive landscape. CityFibre recently secured a £2.3 billion financing package to accelerate its own expansion, while consolidation is picking up pace across the sector; Nexfibre’s reported £2 billion move to acquire Netomnia, alongside the merger of Truespeed and Freedom Fibre, signals that the market is shifting from a land grab into a period of mergers and acquisitions as smaller players struggle to compete at scale.

 

The Good News For UK Residents

 

Around a third of UK premises can now choose between two or more full fibre networks, rising to over 40% in areas such as Yorkshire and the Humber and Northern Ireland, giving many households real competition on price and service for the first time.

UK Government Targets For Better Internet Connectivity

 

Project Gigabit, the government’s subsidy scheme aimed at connecting the hardest-to-reach parts of the country, is currently delivering fibre connections to around 750 premises a day. Ofcom’s own forward-looking projections suggest full fibre could reach 28.1 million UK homes, or 92% of residential properties, by the end of 2028.

 

Regulatory Changes

 

Following Ofcom’s ban on inflation-linked price hikes taking effect for new contracts, major telecom providers shifted to fixed annual increases, typically ranging from £3.00 to £4.00 a month, giving consumers clearer insight into their future bills, though the shift has faced mixed reviews regarding overall cost impacts.

 

What These Changes Mean for Consumers and Businesses

 

For typical users, the speeding up of full fibre is timed to when demand for bandwidth continues to increase. With multiple 4K streams, smart home devices, cloud gaming, remote working now standard practice in a single household, the stability, great capacity and enhancements that full fibre offers over legacy copper and part fibre connections have become very much a requirement rather than a luxury.

For businesses, wider full fibre availability supports everything from cloud-based operations to the hyperscale data centres and AI infrastructure that are increasingly underpinning the UK’s digital economy.

With coverage edging closer to saturation point in many parts of the country, the UK’s full fibre story in the second half of 2026 looks set to be less about laying new cable and more about persuading the millions of eligible households who haven’t yet switched to finally make the leap.

The post Full Fibre Adoption Continues To Accelerate Across The UK appeared first on 91̽.

]]>
OpenAI, Anthropic And Google Are Discreetly Building Their Own AI Standards Body – What Would That Actually Decide? /news/openai-anthropic-and-google-are-discreetly-building-their-own-ai-standards-body-what-would-that-actually-decide/ Tue, 15 Sep 2026 10:15:43 +0000 /?p=159391 Public chatter around AI safety usually revolves around government oversight and slowing down frontier model development, but the interesting movement...

The post OpenAI, Anthropic And Google Are Discreetly Building Their Own AI Standards Body – What Would That Actually Decide? appeared first on 91̽.

]]>
Public chatter around AI safety usually revolves around government oversight and slowing down frontier model development, but the interesting movement is now happening off the record.

Anthropic, OpenAI and Google DeepMind have been meeting in private working groups since July, to explore a self-regulatory body dedicated to safety auditing and pre-release testing for high-capability models. The initiative lacks a formal charter, press release or finalised governance setup. Instead, it shows the leading parties in AI discreetly attempting to design a common safety playbook on their own terms.

The working group is keeping its sights on a narrow set of operational rules. Rather than hammering out broad industry policy, the talks cover third-party evaluations before release, formal safety checks and unified risk protocols for cyber attacks, bioweapons risks and deceptive behaviour. It functions as a voluntary, lab-funded auditing system for frontier models, an arrangement that could start as a flexible agreement and eventually mature into an industry standard.

This move has clear roots. In July, Google DeepMind leader Demis Hassabis outlined a plan modelled on FINRA, proposing an industry-financed, federally monitored body staffed by independent experts to conduct pre-release evaluations about 30 days out. The ongoing working groups show those ideas gaining traction. Anthropic chief Dario Amodei built on the momentum in a recent essay, pushing for aligned benchmarks and official antitrust protection for safety-related coordination.

Navigating those regulatory boundaries is important, mostly because three direct competitors agreeing to hold back tech looks suspiciously like anti-competitive behavior to watchdogs. That danger alone explains why everyone involved wants a formal, structured standards body on paper rather than an unwritten understanding.

 

Complement Or Alternative To Real Regulation?

 

On paper, a self-regulatory body can do plenty of useful work, between mapping out frontier thresholds and writing test suites to clearing independent auditors and establishing safety card norms.

The real snag is enforcement. Without the authority to pause a launch or penalise malicious parties, the whole setup relies on voluntary goodwill. That creates an obvious flaw, as letting giant tech firms grade their own work introduces a clash between launch deadlines and safety protocols.

This dynamic plays out very differently depending on the jurisdiction. Under the EU AI Act, binding laws dictate mandatory assessments, transparency requirements and government penalties. There, a voluntary body acts as a helpful partner, offering technical evaluation tools to meet legal requirements. In the US, where broad AI legislation doesn’t exist, that same group could easily turn into a proxy regulator, giving lawmakers a reason to skip binding laws altogether. Whether this initiative becomes a genuine safeguard or a clever shield against regulation depends on how much authority Washington decides to hand over.

We posed the issue to insiders across AI safety, regulation and enterprise tech: what would an industry-driven standards body need to feature to hold real authority, and does joint oversight between three main competitors offer authentic safety or just a convenient way to derail tougher laws before they land?

 

 

Our Experts

 

  • Lakshmi Hanspal, Chief Trust Officer, DigiCert
  • Emily Hartstone, Founder, Hartstone Institute LLC
  • Kirk Sigmon, Founding Partner, KellDann Law PLLC
  • Sherif Higazy, Founder and CEO, Megaton AI
  • NagaPranitha Chodavarapu, Senior Lead QMS, Insulet Corporation

 

Lakshmi Hanspal, Chief Trust Officer, DigiCert

 

Lakshmi Hanspal, Chief Trust Officer, DigiCert

 

“What could this body actually set rules for? Greater success towards shared technical basics: common tests before releasing a new model, agreed ways to check if a model could be dangerous, and a standard way to report problems when they come up.

“Why team up now? Partly safety concern. But also self-interest: if the big players set the rules themselves, they get ahead of governments doing it for them, and rules they write could end up favouring the companies that helped write them.

“Does this support the EU AI Act, or try to avoid it? In practice, likely a hedge, an attempt to demonstrate credible self-governance before harder regulation lands, particularly in the US.

“What would make this actually work, like IETF or CAB Forum did? Three things, from experience: independent audit that isn’t self-graded, real consequences for non-compliance, not just reputational, and governance open beyond the founding members. CAB Forum works because no single browser or certificate authority can unilaterally rewrite the baseline. Right now, this AI effort has none of those guardrails yet. That’s the gap to watch.”

 

Emily Hartstone, Founder, Hartstone Institute LLC

 

Emily Hartstone, Founder, Hartstone Institute LLC

 

“Three labs cooperating on standards is more interesting for what it wouldn’t cover than for what it would. A body like this can realistically set model-layer standards: evaluation methods, safety benchmarks, disclosure practices, incident reporting between labs. Those are useful, and only the labs can do them, because nobody else has the access.

“What it cannot set is what happens at deployment. The model isn’t where people get denied, scored or flagged. That happens inside an enterprise, configured by an operator the lab never meets, acting on a person who never chose either of them. Look at Microsoft’s Code of Conduct, published this week and open for consultation. It’s the most concrete document of its kind, and every obligation in it terminates at the operator or the user. The person the model acts upon appears only once, as an affected third party who shouldn’t be directly harmed. That’s protection, not standing.

“So my answer on whether it complements or replaces regulation is neither. It occupies a different layer. The risk isn’t that it pre-empts the EU AI Act. It’s that it looks like coverage while leaving the deployment layer untouched, and then everyone points at it. Why now is simpler. After this summer’s agent incidents, shared incident reporting is in all three companies’ interest, and a standards body is a reasonable way to build it.”

 

Kirk Sigmon, Founding Partner, KellDann Law PLLC

 

Kirk Sigmon, Founding Partner, KellDann Law PLLC

 

“An industry-led body for AI governance is a nice idea and a good development, but it won’t likely change many of the issues regulators are concerned about. Realistically speaking, such standards would be opt-in and thus wouldn’t really stop third parties from using their own models, including locally-executing ones, to circumvent those regulations. It’s also unlikely that any of those parties would agree to regulations with enough teeth to significantly affect their bottom line. That self-regulating body may calm regulators’ concerns somewhat, but I still suspect various jurisdictions will legislate where necessary to protect the public against major concerns, like deepfakes or failure to disclose AI usage in certain medical decisions.

“Plenty of other industries have self-regulated successfully. The video games industry’s ESRB helped avoid Congressional regulation of video games after a scare regarding violent video games. That said, the success of those efforts is often not just the product of regulatory fear: the ESRB was in many ways successful because the vast majority of commercially sold video games went through a relatively small number of publishers who all shared an interest in avoiding regulation, and because video game console manufacturers, of which there were even fewer, could help push forward its use. I don’t see similar dynamics in the AI industry, where there may be relatively few major players but where the underlying technology can be run by virtually anyone with a sufficiently powerful computer.”

 

Sherif Higazy, Founder and CEO, Megaton AI

 

Sherif Higazy, Founder and CEO, Megaton AI

 

“The Trump Administration’s position has been a light touch to regulation, and instead has signalled a preference for a self-regulating body, lest government intervention slow down the US’s AI lead. At the same time, the AI companies have signalled quite strongly that they would welcome some industry and government regulation in the US, which remains the primary market for frontier labs outside of China.

“Two things this body could accomplish. First, sharing and working together on alignment: how to ensure AI systems align with human goals, and how to interpret what an AI system ‘thinks’ and ‘does’ without hiding it from researchers. Second, slowing down and pacing model releases to allow companies to harden their cybersecurity and biosecurity infrastructure.”

 

NagaPranitha Chodavarapu, Senior Lead QMS, Insulet Corporation

 

NagaPranitha Chodavarapu, Senior Lead QMS, Insulet Corporation

 

“I can’t speak to what Anthropic, OpenAI and Google are actually planning, but with 13-plus years working in governance, risk and compliance across medical devices, pharmaceutical and biotechnology industries, I’ve watched something pretty similar play out in a different regulated industry, and it might be useful context here.

“Our field’s main professional body, ISPE, published an AI governance guide back in July 2025. Six months later, the FDA and EMA published their joint AI principles. I work right at that overlap, and I’ve built a framework for how AI tools should actually be governed inside regulated validation work, currently going through peer review with that same industry body.

“What stood out to me is that the industry guidance didn’t show up first and try to get ahead of regulators. It came out alongside them, and it’s stayed deferential. FDA enforcement has continued regardless of the industry framework existing. What the industry body actually did well was the unglamorous part: translating a broad regulatory principle into something a company can actually follow in daily operations. If this AI standards body works the same way, filling in the practical gaps around something like the EU AI Act, that’s a model with a real track record. What I’d watch for is how the industry actually handles it in practice.”

The post OpenAI, Anthropic And Google Are Discreetly Building Their Own AI Standards Body – What Would That Actually Decide? appeared first on 91̽.

]]>
How Have Digital Nomads Created A New Market For Businesses? /news/how-have-digital-nomads-created-a-new-market-for-businesses/ Mon, 14 Sep 2026 14:00:57 +0000 /?p=159286 Digital nomads don’t really fit into the usual categories businesses have traditionally built their services around. Someone working remotely while...

The post How Have Digital Nomads Created A New Market For Businesses? appeared first on 91̽.

]]>
Digital nomads don’t really fit into the usual categories businesses have traditionally built their services around. Someone working remotely while moving between countries might spend a few weeks or months in one place before moving on, which puts them somewhere between a tourist and a permanent resident. They need somewhere to live, reliable internet, international banking and a way to deal with visas and taxes, often without knowing exactly where they’ll be living next.

Businesses have now started responding to those needs, while governments have also seen the opportunity. Forbes reported in March 2026 that more than 50 countries now offer some form of digital nomad visa, allowing remote workers to live abroad while earning income from employers or clients elsewhere. For governments; these workers can now bring in foreign income and local spending without even having to compete for local jobs.

As this way of working has become more established, it has created something beyond the lifestyle itself: a market of businesses built around people who don’t have a fixed relationship with one country.

 

Accommodation Built Around Nomads

 

For someone planning to work from another country for a month or two, neither a hotel nor a conventional rental is necessarily ideal. A hotel can become expensive over a longer stay, while a traditional rental usually involves contracts and commitments that make little sense if the tenant plans to move on in a few months.

This has created quite a few opportunities for businesses offering furnished accommodation, co-living and work-friendly spaces aimed at remote workers. Outsite is an example of these types of accomodation; the company was founded in 2015 specifically to serve location-flexible professionals and now offers furnished spaces with work areas, reliable Wi-Fi and community features. Its stays can range from a few nights to several months, with longer-stay discounts available.

The accommodation itself isn’t really different from what already exists – what has changed is the customer it has been designed around. Someone who wants to work from Barcelona for a month has very different requirements from someone booking a hotel for a weekend or signing a one-year rental agreement.

 

 

Navigating Visa And Taxes

 

Living and working across borders also brings more problems, especially when it comes to figuring out whether you’re actually allowed to work somewhere and where your income should be taxed.
The Organisation for Economic Co-operation and Development (OECD), an international organisation that works with governments on economic and policy issues, has been looking at these issues as cross-border remote work becomes a more common thing. Its research says that digital nomad visa schemes began appearing in OECD countries in 2020 and have continued to spread.

The OECD has also updated its international tax guidance to address cross-border remote work, including situations where working from another country could create tax consequences for an employer.

All of this creates demand for businesses that can make the process easier. Immigration advisers, tax specialists, relocation companies and global employment providers can now offer services to people who suddenly have to understand rules that a traditional employee working from one country might never encounter.

 

Banking And Connectivity

 

The same problem appears in everyday finances; someone might earn money from a company in one country, live in another and spend several months travelling through a third.

Financial services have tried to fix this by making international money management easier. Revolut offers accounts that allow customers to hold and exchange multiple currencies, while its international spending features are designed for people who regularly use their money abroad.

Staying connected also creates a very similar problem, so eSIM services allow travellers to buy mobile data for individual countries or regions without having to find and replace a physical SIM card every time they cross a border.

 

Selling The Lifestyle

 

Beyond accommodation and practical services, businesses have also found ways to sell the lifestyle itself. Coworking spaces, networking communities, retreats and organised events can attract people who want to build a social life around location independence instead of just working from a different country for a few weeks

Coworking spaces are a great way to give digital nomads somewhere to work while also providing networking events and communities built around people with similar lifestyles. Retreat companies and digital nomad communities can offer similar experiences, bringing together people who want to work, travel and meet others in the same position.

A Market Built Around A New Type Of Customer

 

Digital nomads didn’t invent accommodation, banking or mobile data but they have brought a lot of existing needs together into one recognisable customer group, which gives businesses a clearer audience for services that are designed around cross-border living.

As more people work while moving between countries, businesses have found ways to adapt existing products and create new services around that flexibility. The result is a market built around people whose work and daily lives no longer fit into just one country.

 

The post How Have Digital Nomads Created A New Market For Businesses? appeared first on 91̽.

]]>
England’s New Tourist Tax Has No National Cap – What Does That Mean For Hospitality Businesses? /news/englands-new-tourist-tax-has-no-national-cap-what-does-that-mean-for-hospitality-businesses/ Fri, 11 Sep 2026 13:15:13 +0000 /?p=159233 England is officially getting local tourist taxes. On 10 September, ministers published their consultation findings, confirming that regional authorities will...

The post England’s New Tourist Tax Has No National Cap – What Does That Mean For Hospitality Businesses? appeared first on 91̽.

]]>
England is officially getting local tourist taxes. On 10 September, ministers published their consultation findings, confirming that regional authorities will be able to levy a percentage charge on overnight stays at hotels, guesthouses, B&Bs and holiday rentals. The setup is discretionary for local councils, and the government has intentionally left the maximum rate uncapped in the setup it’s proposing.

Right now, Labour’s ten regional mayors have promised to cap their local rates at 5%, but that’s a gentleman’s agreement rather than a legal guarantee, leaving the door open for future leaders or different political parties to increase the percentage.

Before anyone panics, it helps to separate the structure from immediate reality – no one is paying a new room tax just yet. This is simply the policy structure, meaning a full bill must still pass, and authorities aren’t expected to publish concrete spending strategies until early 2028.

Local leaders still have to choose whether to implement a charge, gather feedback from local businesses and figure out the logistics. It’s also completely distinct from Scotland’s setup, where Edinburgh’s scheme runs as a flat 5% fee capped at five nights.

The point is that England is heading toward a mosaic of local rules. Instead of a single national tourist tax, the policy enables dozens of different regional levies, each running on its own timeline, rate, spending agenda and list of exemptions. For accommodation owners and frequent business travellers, the pressing concern is whether a non-binding political promise can actually protect businesses from a fragmented mess once different authorities start pulling the levers.

 

Why Trade Bodies Are Raising The Alarm

 

The pushback from trade groups goes deeper than just resistance to new taxation.

ABTA argues that a percentage model disproportionately penalises luxury and boutique accommodation compared to a flat nightly rate. UKinbound criticises the regional setup as an operational nightmare, calling for a fixed national system instead of a postcode lottery. At the same time, the World Travel and Tourism Council warns that higher trip costs could steer holidaymakers and capital toward competing destinations altogether.

UKHospitality takes the warning even further, claiming an uncapped charge could inflict a £1.6 billion hit on the sector, bump the price of a typical family holiday up by £100 and threaten up to 33,000 jobs. Those are the trade group’s own projections, not official guarantees, but they capture the depth of concern across the market.

Conversely, government officials insist that targeted levies fund the essential facilities that keep destinations competitive. The Liverpool City Region, for example, expects a levy could pull in up to £18 million annually for events, cultural projects and local transport, though that’s only one regional forecast.

We put the question to the people on the ground. How would a levy like this actually hit bookings, pricing and overall competitiveness, and does the lack of a legal cap worry them more than the levy itself?

 

 

Our Experts

 

  • Siarhei Sulimau, CEO and Founder, EnglishPapa
  • Amy Boyton, Director of Franchise Sales, Pass the Keys
  • Julia Doust, Founder and Editor, The European Compass

 

Siarhei Sulimau, CEO and Founder, EnglishPapa

 

Siarhei Sulimau, CEO and Founder, EnglishPapa

 

“I run EnglishPapa, and on the hospitality side I own and operate Aviator Bali, an apart-hotel in Bali. Managing accommodation in a competitive international tourism market has shaped my view on England’s proposed visitor levy: the real issue isn’t the tax itself, it’s the inconsistency around it.

“Any percentage-based charge eventually lands in the guest’s final bill, and in a market where travellers compare prices across destinations in seconds, that matters. Most guests don’t mind paying a levy if they understand where the money goes: tourism infrastructure, local services, upkeep of the places they’re visiting.

“What concerns me more is fragmentation. If every English region sets its own rate, we get a messy, inconsistent pricing picture, especially painful for cities directly competing for the same visitors. Hotels can’t price transparently or competitively when the rules shift by postcode, and guests end up confused about what they’re paying and why. My honest take: a lack of national framework is a bigger risk than the levy itself. Consistency, not the charge, is what will make or break this policy.”

 

Amy Boyton, Director of Franchise Sales, Pass the Keys

 

Amy Boyton, Director of Franchise Sales, Pass the Keys

 

“From new licensing rules and visitor taxes to council tax hikes and minimum night stays, short-term rentals are being burdened with measures that claim to fix housing but end up penalising tourism and the people who rely on it.

“Visitor taxes aren’t a one-size-fits-all solution. In many towns and cities, they simply push up costs for guests, and that includes domestic travellers who already pay their share through existing taxes and local spending. These levies can bring benefits, but not every destination has the constant pull of a city like London, and most places can’t impose extra charges without risking losing bookings.

“In places like Edinburgh and Glasgow, where levies have already been approved, our local managers are stuck between absorbing the extra cost or risking fewer bookings. If they raise prices by 5% to offset the tax, they risk becoming uncompetitive. Add that to licensing fees, and it’s no surprise many Scottish hosts are seriously considering shifting to mid-term lets instead, given traditional long-term rentals simply don’t work for most holiday homes as they’re often rural, seasonal or used part-time by owners. We need more balanced policymaking if we are to maintain the very tourism economies these measures claim to support.”

 

Julia Doust, Founder and Editor, The European Compass

 

Julia Doust, Founder and Editor, The European Compass

 

“I was the owner of a 21-room establishment in France when my local council decided to impose a tourist tax. It made no difference whatsoever to my bookings.

“Now I cover cities across Europe, almost all of which impose a tourist tax. Visitors expect it. It doesn’t make a difference to their decision-making process. Costs have to rise 20 to 30% before people start to compare different destinations.

“The only difference can come when travellers have set themselves a limit per night, say €200. If the tourist tax puts them over that limit for a certain hotel, they may choose a cheaper hotel, but they don’t change destination.”

The post England’s New Tourist Tax Has No National Cap – What Does That Mean For Hospitality Businesses? appeared first on 91̽.

]]>
The EU Cyber Resilience Act Starts Today: Can Businesses Really Report A Cyberattack In 24 Hours? /news/the-eu-cyber-resilience-act-starts-today-can-businesses-really-report-a-cyberattack-in-24-hours/ Fri, 11 Sep 2026 12:34:47 +0000 /?p=159120 A new EU cybersecurity deadline has officially come into effect today, and at first glance, it sounds quite strict: businesses...

The post The EU Cyber Resilience Act Starts Today: Can Businesses Really Report A Cyberattack In 24 Hours? appeared first on 91̽.

]]>
A new EU cybersecurity deadline has officially come into effect today, and at first glance, it sounds quite strict: businesses have just 24 hours to report certain cyber incidents.

But it’s not quite as simple as that; there’s an important catch. The Cyber Resilience Act (CRA) isn’t simply introducing a blanket rule that every business have to report every single cyberattack within 24 hours. From 11 September, the first major CRA reporting obligations apply to manufacturers of products with digital elements, covering actively exploited vulnerabilities and severe incidents affecting product security. Importantly, most of the wider CRA requirements won’t apply until December 2027, so this is just the beginning.

Still, 24 hours is 24 hours. So, is this actually a realistic expectation?

 

The 24-Hour Clock Isn’t Quite What It Sounds Like

 

Under Article 14 of the act, manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident. A more detailed notification follows within 72 hours, and finally, the last report comes a little later, depending on the specific circumstances.

So, it’s really important to note the difference between these three deadlines, because, as several of our experts point out, nobody is realistically expected to solve an entire cyberattack before lunch tomorrow. It would be nice, but it’s not realistic.

Martin Riley, CTO at Bridewell, argues that the 24-hour warning is deliberately designed as an escalation rather than a completed investigation. The first notification is essentially an alarm bell: letting people know that something serious is happening, and alerting other organisations using the affected product that they may need to take precautions.

Jose Lejin PJ, Principal Member of Technical Staff at Salesforce, makes much the same point: “The 24-hour rule is workable if you read what the CRA actually requires. It is not ‘explain the whole cyberattack by tomorrow.’”

And that might be the most important part of properly understanding the rule. The EU isn’t necessarily asking businesses to know everything within a day; it’s asking them to know enough to raise the alarm.

 

 

What If You Don’t Know You’ve Been Hacked?

 

Of course, that makes things more complicated. Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, says the requirement is “directionally right but operationally challenging”. In the first 24 hours of an incident, organisations may still be trying to understand what happened, contain the damage and preserve evidence.

Rob Demain, CEO of e2e-assure, similarly argues that the deadline is realistic primarily for organisations with mature detection capabilities. If you have continuous monitoring, you might know something is wrong within minutes, so it’s easier to follow these rules. Figuring out exactly what happened, however, can take a lot longer. It’s possible that this could expose some issues with cybersecurity maturity, and at the end of the day, that’s generally the point.

The biggest problem with a 24-hour reporting deadline may not be the reporting but rather how realistic the detection process is within that window. As Ali Waezzadah, CISO at iCOUNTER, puts it, “Manufacturers cannot report what they cannot detect.” If a company doesn’t know that a vulnerability is being actively exploited, the clock hasn’t really become its problem yet. The problem is that it might not even know the clock has started.

 

The Supply Chain Could Make This Even Harder

 

Modern software isn’t exactly a neat little box built entirely by one company. Products can contain proprietary code, open-source packages, third-party components and now, more often than not, AI models and services too.

Eran Kinsbruner of Checkmarx says manufacturers will need continuous visibility across their software supply chains so they understand which vulnerabilities affect their products. Ilkka Turunen, Field CTO at Sonatype, takes this further. He warns that organisations need to know which components are inside which products and which versions are affected before an incident occurs. Because trying to reconstruct that information manually during a crisis could make the 24-hour window “nearly impossible to meet”.

This is where the CRA could have an interesting unintended consequence. The regulation may effectively force companies to invest in software inventories, dependency tracking, monitoring and incident-response infrastructure earlier than they otherwise would have, which will most likely have really postive effects on overall cybersecurity.

 

So, Is 24 Hours Actually Realistic?

 

For a large manufacturer with strong monitoring, clear escalation procedures, incident-response expertise and a detailed understanding of its software and hardware stack, probably, yes. But, for a smaller company that discovers an exploit at 3am and starts asking who’s actually responsible for reporting it, the answer is more complicated.

Daryl Flack, Partner at Avella Security, describes 24 hours as “a pretty unforgiving window”, particularly because organisations need to establish whether an incident actually meets the reporting threshold and get the right technical and legal people involved.

And that may sound daunting at first, but it’s also precisely the point. The CRA is effectively asking companies, if you sell connected technology into the European market, how quickly could you actually tell the people who depend on it that something serious is wrong? How well can you understand the problems and how quickly can you deal with them?

So, perhaps it’s less about whether a company can fill in a form within 24 hours and more about how confident they are in how well they could potentially deal with a sudden issue, and this all comes down to proper planning. Indeed, it seems as if the regulation may have already identified a bigger cybersecurity problem, and perhaps this is the first step towards making things safer.

 

Experts Comment:

 

  • Muhammad Yahya Patel: vCISO and Cybersecurity Advisor for EMEA at Huntress
  • Rob Demain: CEO of e2e-assure
  • Carl B. Johnson: President at Cleared Systems; Owner at ComputerSecurity.us
  • Darren Williams: Founder and CEO at BlackFog
  • Artem Serebrov: Director of Product at PCA Cyber Security
  • Eran Kinsbruner: Vice President of Product Marketing at Checkmarx
  • Martin Riley: Chief Technology Officer at Bridewell
  • Camellia Chan: CEO and Co-founder of X-PHY
  • Daryl Flack: Partner at Avella Security
  • Ilkka Turunen: Field CTO at Sonatype
  • Omair Manzoor: Founder, CEO and Chief Hacker at ioSENTRIX
  • Jose Lejin PJ: Principal Member of Technical Staff at Salesforce
  • Ali Waezzadah: CISO at iCOUNTER
  • Shane Tierney: Senior Program Manager, GRC, Drata
  • Marty Puranik: Founder and CEO of Atlantic.Net

 

Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress

 

muhammad-yahya

 

“The 24-hour early warning requirement under the CRA is directionally right but operationally challenging in a way that deserves honest acknowledgment. The operational reality is more complicated, though. In the first 24 hours of a significant incident, most organisations are trying to understand the scope, stop the bleeding, and preserve evidence. The problem is that many organisations don’t yet have the detection and escalation maturity to know within 24 hours that they have something reportable, let alone the nature of what’s been accessed inside a complex environment.

“Reporting inaccurate information to regulators under mandatory timelines creates its own problems both for the organisation revising its initial assessment and for the regulator acting on incomplete intelligence. It’s important to mention, The CRA doesn’t ask businesses to report being attacked. It asks manufacturers to report when their products are being used as the attack vector.”

 

Rob Demain, CEO of e2e-assure

 

rob-d

 

“It’s only realistic for businesses that already have mature detection in place. And a 24-hour deadline is only asking for it to be reported, not the full investigation. Organisations running continuous monitoring will usually know within minutes that they’ve been hit; what takes longer is establishing scope, root cause, and impact, and that work can carry on after the initial notification.

“Transparency in itself has merit, but “full” and “accurate” aren’t the same thing. A rushed report built on guesswork can misdirect response efforts and cause more harm than a short delay would. The right balance is early, honest signalling, i.e. “we’ve identified a significant incident and are investigating”, rather than a complete picture on day one.
The real test isn’t whether 24 hours is realistic but whether an organisation has invested in the visibility to detect an incident that fast at all.”

 

Carl B. Johnson, President at Cleared Systems; Owner at ComputerSecurity.us 

 

carl-johnson

 

“The 24-hour reporting rule is realistic only for organisations that already have mature incident response, asset visibility, vulnerability management, and decision-making authority in place. For many businesses, the hardest part will not be writing the report. It will be knowing quickly enough what happened, whether the issue is reportable, who must be notified, and who inside the company has authority to make that call.

“The public deserves timely notice, but rushed reporting can also create confusion if facts are incomplete. The right balance is fast initial notification, followed by disciplined updates as the investigation develops.”

 

Darren Williams, Founder and CEO at BlackFog

 

adrren-williams

 

”The 24-hour requirement is realistic, but only if we recognise what it is: an early warning, not a completed forensic investigation. The real challenge for many organisations is that they still lack visibility into what data has left the network, where it went, and whether an incident is still active. Attackers can exfiltrate sensitive information in minutes, so waiting days for perfect attribution creates unnecessary risk for customers and partners.

“The right balance is phased disclosure. Notify quickly with what is known, then provide deeper technical detail as the investigation develops. The CRA should force organisations to improve detection, data exfiltration monitoring and incident response readiness.
Companies that cannot establish the basic facts of an attack within 24 hours have a broader security problem than simply meeting a regulatory deadline.’’

 

Artem Serebrov, Director of Product at PCA Cyber Security

 

artem-serebrov

 

“New regulatory obligations on device manufacturers to report the active exploitation of vulnerabilities in their products are likely to collide with the reality of cyber security monitoring and its limits. Device manufacturers selling into the European market aren’t currently obliged by the EU to monitor how cyber criminals are targeting vulnerabilities in their products. It’s therefore no surprise that the majority of manufacturers lack sophisticated capabilities to pick up on vulnerability exploitation – particularly dark web monitoring, which is essential to track how vulnerability discovery and exploitation play out in cybercriminal forums.

“Overall, there are parallels to be drawn between the current state of the Cyber Resilience Act and the early days of GDPR rules. Similarly, under GDPR, obligations to report data leakage were introduced without obligations to measure data loss. This invited companies to softly limit the extent to which they were monitoring data loss in the interest of avoiding hefty GDPR-related fines. It will be interesting to see how EU policymakers react to avoid a similar state of affairs with Cyber Resilience Act reporting obligations in effect.”

 

Eran Kinsbruner, Vice President of Product Marketing at Checkmarx

 

eran-kinsbruner

 

“What all this means for manufacturers is that secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list. They need to have processes in place to ensure continuous visibility across their software supply chain so they know which vulnerabilities will impact their product.

“Modern applications are assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected. Organisations need to understand these components, their dependencies and the risks they introduce. Reviewing your application security tools to ensure they continuously scan code and environments to find new vulnerabilities, automatically map the affected applications and environments, assess and prioritise risk and remediation, and log every action taken for auditable evidence, will be critical.”

 

Martin Riley, Chief Technology Officer at Bridewell

 

martin-riley

 

“There’s an important nuance in how this rollout is being framed. What takes effect [today] isn’t the whole EU Cyber Resilience Act coming into force. The Act’s broader obligations, conformity assessments, CE marking, secure-by-design requirements, don’t apply until December 2027. What starts [today] is a narrower and much sharper piece: Article 14’s requirement for manufacturers to report actively exploited vulnerabilities and severe incidents. It’s been brought forward by 15 months because regulators want early visibility into live exploitation before the rest of the regime is in place. That’s a deliberate sequencing choice, not an accident.

“The detail that gets lost in most coverage is when the clock actually starts. It isn’t triggered by a confirmed, fully investigated breach. It starts the moment a manufacturer becomes aware that a vulnerability is being actively exploited, or that a severe incident has occurred. That’s a much lower bar than people assume, and it’s deliberate. The 24-hour early warning was never meant to explain what happened. It’s meant to raise the alarm early enough that other organisations running the same product can start applying compensating controls before anyone has the full picture. Waiting for certainty defeats the purpose. At that stage, speed of warning matters more than completeness of warning.

“The structure reflects that thinking. There are three stages, not one. Within 24 hours, an early warning, essentially a flag that something serious is happening and where. Within 72 hours, a fuller notification covering what’s known about the product, the nature of the exploit, and any mitigations already available. Then a final report, within 14 days of a fix becoming available for a vulnerability, or within a month for a severe incident. Each stage adds detail as the investigation matures. None of them demand the full story on day one.

“So is it realistic? Yes, because it was never designed to be a full report in 24 hours. It’s a structured escalation, and the first step is deliberately lightweight. What it does demand is that organisations already have the internal capability to detect exploitation, escalate it, and notify a regulator within a day, before the root cause is even established. For a mature vendor with an established incident response function, that’s achievable. For smaller manufacturers or newer entrants without that function built out, it will be uncomfortable.

“That discomfort is probably a feature rather than a flaw. If a 24-hour early warning duty causes a vendor genuine pain, that’s a sign their detection and response capability wasn’t where it needed to be, regardless of the regulation. The Act is simply forcing that gap into the open earlier than the market would otherwise expose it.”

 

Jonathan Lee, Director of Cyber Strategy and UK Public Policy Lead at TrendAI

 

jonathan-lee

 

“The Cyber Resilience Act is often portrayed as a 24-hour cyberattack reporting rule, but its real focus is manufacturers reporting actively exploited vulnerabilities and severe incidents affecting products with digital elements. The clock starts ticking once there’s a reasonable degree of certainty that a serious issue exists, not once every fact is confirmed. An early warning is required at 24 hours, fuller details at 72, with final reporting to follow. That reflects the reality that understanding the full extent of an incident can take days or weeks.

“Transparency matters, but regulator notification isn’t the same as public disclosure. These reports go to ENISA and national CSIRTs, helping defenders act early while investigations continue. The real test isn’t whether organisations can file a report within 24 hours, it’s whether they can detect a severe incident within 24 hours. If they can’t, the deadline is the least of their problems.”

 

Camellia Chan, CEO and Co-founder of X-PHY

 

camellia-chan

 

‘‘The CRA’s 24-hour initial reporting requirement puts direct pressure on manufacturers to ensure their internal processes are ready. The bigger challenge, however, is spotting an attack quickly enough to act.

“Vulnerability exploitation already accounts for more than one in five observed initial intrusions across the EU. Attackers are also increasingly targeting weaknesses deeper within devices and infrastructure, where conventional software monitoring can have less visibility. As AI speeds up the discovery and use of new flaws, identifying those threats becomes even harder.

“Reporting an incident quickly is crucial, but the clock doesn’t stop there. The sooner teams understand where an attack is happening, the sooner they can contain it and limit the impact on operations and user data. That means having security across the full technology stack, including at the hardware level.”

 

Daryl Flack, Partner at Avella Security 

 

daryl-flack

 

“24 hours is a pretty unforgiving window. In those 24 hours, you need to identify the issue, establish whether you are dealing with an actively exploited vulnerability or a severe security incident, bring in the right technical and legal people and get the early-warning notification out the door. That’s no mean feat.

“It’s also important to remember this isn’t just an EU vendor issue. UK and US manufacturers selling relevant products into the EU are caught too, and it includes legacy products already in distribution, not simply whatever gets launched after 11 September.

“The interesting bit here is that this reporting clock starts well before many of the Cyber Resilience Act’s wider engineering obligations kick in. So, manufacturers could be reporting vulnerabilities in products they’re not yet formally required to “fix” under the full Cyber Resilience Act regime.

“That’s where this could get tricky. It could create some interesting tension between vendors and operators, particularly around what “actively exploited” actually means in practice and when everyone agrees that the 24-hour clock has actually started.”

 

Ilkka Turunen, Field CTO at Sonatype 

 

ikka-t

 

“The EU Cyber Resilience Act’s 24-hour reporting requirement exposes a basic problem for many organisations: they still don’t have a clear understanding of the software they ship. The average software supply chain is over 180 external components, and in 2025 Sonatype found nearly 1.8 billion downloads that had risks with fixes available but ignored. This shadow inventory is set to grow with the rise of AI development.

“The CRA makes every risk from every adopted component the concern of the organisation using it. When a vulnerability affecting any one adopted component is actively exploited, teams now have a 24-hour deadline to report it to ENISA and their local regulator.

“Teams need to know which products contain the affected components, which versions are exposed and inform both the regulator and their customers. If that picture has to be reconstructed manually during an incident, the reporting window will be nearly impossible to meet.

“The CRA will necessitate accurate, up-to-date software supply chain data before an incident happens. Organisations need to be able to trace components and dependencies as part of the development process, not for the first time under incident pressure.”

 

Omair Manzoor, Founder, CEO and Chief Hacker at ioSENTRIX 

 

omair-headshot

 

“The 24-hour reporting requirement is well-intentioned but creates a tension between speed and accuracy that most organizations are not equipped to resolve. In our incident response work, determining the scope of a breach within 24 hours is possible for organizations with mature detection and forensic capabilities. For most businesses — particularly SMBs that the CRA now covers — 24 hours is barely enough time to confirm whether an incident actually occurred, let alone characterize it meaningfully.

“The realistic compromise is tiered reporting: an initial notification within 24 hours confirming a potentially exploitable vulnerability has been discovered, followed by a substantive technical report within 72 hours once forensic analysis provides actionable detail. Forcing detailed disclosure before the organization understands what happened risks publishing inaccurate information that misleads affected parties and potentially exposes attack details that help other threat actors.

“The organisations that will meet this requirement are those that invest in incident response preparedness before an incident occurs — pre-built response playbooks, retained forensic partners, and pre-drafted notification templates. The CRA effectively makes incident response planning mandatory, which is the right outcome even if the 24-hour timeline is aggressive.”

 

Jose Lejin PJ, Principal Member of Technical Staff at Salesforce

 

jose-eljin

 

“The 24 hour rule is workable if you read what the CRA actually requires. It is not “explain the whole cyberattack by [today].”

“From 11 September, manufacturers of products with digital elements must send ENISA and the coordinating CSIRT an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident that affects product security. Awareness means a reasonable degree of certainty after an initial look, not the first odd log. A fuller notification is due in 72 hours. Users should be told so they can protect themselves. The rest of the CRA (secure by design, CE marking) still waits until December 2027.

“That staged split is the right balance. The public should not wait weeks. Firms also should not be forced to publish guesses that panic customers or help the attacker. Complete root cause in a day is not realistic. A short, factual early warning is. Teams that already know who declares awareness and what they will file can meet this. Teams that wait until the investigation feels finished will miss it.”

 

Ali Waezzadah, CISO at iCOUNTER

 

ali-waez

 

“The question states “report a cyberattack in 24 hours,” but the CRA’s rule is not a general “you got hacked, notify us in24 hours”. It covers manufacturers and focused on product security:

  • An actively exploited vulnerability in a product
  • A severe incident affecting the security of the product

“The “we suffered a cyberattack” reporting is under different rules. A company could suffer a terrible ransomware attack on its internal HR systems and have zero CRA reporting obligations, because it didn’t affect a product’s security. The real challenge is not the clock — it is detection and the definition of “aware”. Manufacturers cannot report what they cannot detect. The timer starts when the company becomes “aware.” When does the company become “aware”? A cautious compliance officer says the clock starts early, and a diligent engineer wants to finish the analysis.

“The requirement is achievable if the underlying capabilities exist, and difficult if it doesn’t. The vital question is “do manufacturers have the essential capabilities to know within 24 hours”? For most, that’s the honest gap. The regulation is essentially using a reporting deadline as a lever to force detection investment.

“For a well-resourced company that has built the underlying capabilities, while they still have some work to do, 24 hours is doable. For others, it won’t be about whether the form can be filed fast enough — it will be about whether they even know they have something to file.”

 

Shane Tierney, Senior Program Manager, GRC, Drata

 

shane-headshot

 

“The broader CRA requirements become fully applicable on 11th December 2027, but the September milestone is a practical forcing function for in-scope organisations to formalise and rehearse vulnerability-handling and incident-reporting processes before an incident occurs.

Instead of treating it purely as a compliance checkbox, enterprises should use it as a prompt to strengthen operational discipline around vulnerability handling, reporting and risk management. This means having a clear record of the staged reporting process. Teams also need to know what must be disclosed, who to contact, and how to submit each report.

Where enterprises can really get ahead, though, is by turning these obligations into an operating program: defining product scope, assigning ownership, rehearsing vulnerability handling, maintaining the necessary evidence, and connecting testing and documentation to the other frameworks they already manage, such as SOC 2, ISO 27001, and GDPR, for example. An effective and efficient GRC team shouldn’t need to be building a parallel, manual process just for CRA or any other mandate.

This is where automation can help. Modern compliance platforms can help teams map CRA requirements to existing internal controls, organise supporting evidence, and connect relevant testing and monitoring across the frameworks they already manage. That readiness support complements, but does not replace, product-security, engineering, legal, conformity-assessment, or incident-reporting responsibilities.

The organisations that treat this deadline as an opportunity to consolidate and automate their compliance operations, instead of adding on another manual process, will be the ones who handle CRA, and whatever comes next, with less friction.”

 

Marty Puranik, Founder and CEO of Atlantic.Net

 

marty-headshot

 

“It’s probably not feasible because it takes time to identify and remediate. In addition, it could make things worse since you would have to disclose the vulnerability or vulnerable paths before you have remediated, potentially drawing even more attacks – it takes time for commercial vendors to release patches.

“A more reasonable policy would be to notify customer in a certain time period IF the problem can be remediated first. Disclosing active vulnerabilities is a bad idea.”

The post The EU Cyber Resilience Act Starts Today: Can Businesses Really Report A Cyberattack In 24 Hours? appeared first on 91̽.

]]>
Can Binge-Watching Be Addictive By Design? Inside The State Lawsuit Against Netflix /news/can-binge-watching-be-addictive-by-design-inside-the-state-lawsuit-against-netflix/ Thu, 10 Sep 2026 13:35:57 +0000 /?p=159104 We’ve all been there: you press play on one video, hit the autoplay slipstream and suddenly your whole evening has...

The post Can Binge-Watching Be Addictive By Design? Inside The State Lawsuit Against Netflix appeared first on 91̽.

]]>
We’ve all been there: you press play on one video, hit the autoplay slipstream and suddenly your whole evening has vanished. Or maybe you’ve tried prying a child away from a TV screen, only to trigger a meltdown because the next episode of PAW Patrol just started. Florida’s legal team claims those non-stop binges are engineered on purpose.

On 9 September, Attorney General James Uthmeier launched a 66-page lawsuit against Netflix, accusing the company of playing double agent with kids’ privacy and building features designed to keep minors hooked. It’s the first time the courtroom strategy used to hammer Meta and TikTok for addictive design has been used against a subscription streaming platform.

The state positions Netflix’s evolution as a seamless bait-and-switch operation. Netflix spent a decade winning over parents as the clean, ad-free alternative to traditional tech platforms, before turning around and leveraging deep subscriber tracking to launch its ad tier in late 2022.

Florida is pushing for drastic remedies, demanding the court order a full deletion of deceptively harvested data, block historical user records from driving ad revenues and levy fines that could realistically climb into the billions.

 

Unpacking Florida’s Case Against Netflix

 

The privacy charge hits Netflix for preaching one thing to parents and practising another.

While the company claimed Kids Profiles were free from targeted advertising, it kept collecting precise viewing habits without making that clear. The suit details a relentless background system monitoring every pause, skip, binge and abandoned title, alongside device details and location data. Applied to kids, that tracking allowed Netflix to build precise blueprints of minor users’ preferences and attention spans, triggering what Florida calls a direct breach of state consumer protection and child consent laws.

When it comes to design, the state takes aim at features engineered to keep screens glowing non-stop. Autoplay comes turned on by default across all accounts, stripping out natural breaks between episodes and hitting viewers with aggressive countdown timers that force the next show to start unless someone actively steps in.

Florida argues the entire interface is rigged to prolong watch times, hide cancellation options and steer users away from privacy controls, all to keep the data pipeline flowing. State prosecutors sum up the strategy on Kids Profiles as trapping young viewers under a persistent tracking microscope. Netflix refrained from commenting when news of the suit broke.

 

 

On Borrowing The Social Media Play

 

Florida is specifically taking the social media litigation strategy for a spin against video streaming.

The argument against autoplay and next-episode timers mirrors the complaints against infinite scroll on Meta and TikTok: features engineered to keep eyes glued to screens. Across all of these cases, prosecutors contrast shiny corporate pledges with sneaky tracking systems, insisting that children’s data rights require meaningful parental consent.

The friction is in how the services actually work. Social media offers a free stream of endless content seemingly intentionally built to stop people from logging off. Netflix costs money, relies on specific title selection and gives users clear ways to opt out of non-stop playback.

That will be squarely at the centre of Netflix’s defence as the court considers whether social media courtroom tactics work on subscription TV at all.

 

Does The Addictive Design Argument Actually Hold Here?

 

Netflix will likely argue that viewers intentionally select every title and can easily exercise free will to toggle settings or exit, unlike social algorithms that endlessly feed content without user choice.

Florida counters that default mechanics, countdown timers and buried cancellation paths make switching off surprisingly tough, particularly for young kids with limited self-restraint. Whether that argument sways a judge is anyone’s guess, given the lack of legal precedent outside social media.

The privacy claims stand on much firmer ground, however. Regardless of whether Netflix placed targeted ads directly on child accounts, collecting that behavioural data to refine recommendations and power a broader ad apparatus looks like a standard deceptive-practices violation, requiring no radical leap on addictive design.

 

Rethinking The Binge Engine Across The Industry

 

If Florida’s theory succeeds, even partially, the ripple effects will be felt through the rest of the streaming world.

Rivals like Disney+, Max and Prime Video use virtually identical autoplay mechanics, binge structures and retention-driven interfaces. If a court labels those everyday features as deceptive dark patterns, every major platform will have to refine its user experience: switching off autoplay by default for minors, offering clean breaks between shows and simplifying account cancellation.

It’d also require stricter walls between general platform telemetry and ad-network data, particularly around child accounts. Florida continues to build a reputation for aggressive tech oversight, and success here would likely encourage other states to adopt the same addictive-design policies for gaming networks, streaming services and any consumer software balancing engagement goals with children’s data.

The post Can Binge-Watching Be Addictive By Design? Inside The State Lawsuit Against Netflix appeared first on 91̽.

]]>
Could Australia’s Proposed Algorithm Rule Break The Current Echo Chamber That Is Social Media Today? /news/could-australias-proposed-algorithm-rule-break-the-current-echo-chamber-that-is-social-media-today/ Thu, 10 Sep 2026 12:35:40 +0000 /?p=159103 Social media algorithms have become something of a scapegoat recently. We’re blaming them for keeping us scrolling, showing us increasingly...

The post Could Australia’s Proposed Algorithm Rule Break The Current Echo Chamber That Is Social Media Today? appeared first on 91̽.

]]>
Social media algorithms have become something of a scapegoat recently. We’re blaming them for keeping us scrolling, showing us increasingly similar content and, most importantly, creating what we’re calling online “echo chambers” where we’re repeatedly exposed to views we already agree with.

So the question we’re asking is, what would happen if we could simply choose what kind of feed we wanted?

It’s the sentiment that’s been floating around the internet in recent months, and now, it’s the idea behind a proposed new set of social media rules in Australia. These rules could give users significantly more control over how their feeds are curated.

According to Reuters, Australia’s government is proposing legislation that would require platforms to give users a choice between an algorithmically personalised feed, on the one hand, and one showing content only from accounts they have chosen to follow. Users would also need to be notified about the choice, rather than having the personalised option operate entirely in the background.

This seems to be part of Australia’s wider push to make social media platforms more accountable for online safety, especially as they were one of the first countries to introduce a social media ban for children under the age of 16 in December 2025. The proposed rules would also require platforms to assess and report on measures that they’ve taken to address harms that are affecting Australian users, with companies potentially facing fines of up to A$109.2 million for failing to comply with these new regulations.

On the face of it, giving people more control over what they see sounds like an obvious win, especially since that is, for all intents and purposes, what they’ve been asking for. But is switching off the algorithm really the answer?

 

 

Do We Actually Want An Algorithm-Free Internet?

 

I’ve spoken at great length about this seemingly growing desire to escape algorithms, whether that’s Bluesky giving users more control over how content spreads or the nostalgia surrounding the supposedly algorithm-free days of MySpace. And I think the really important issue to understand here is the fact that people keep talking about algorithms as if they’re at the centre of all “evil”.

But I believe that perhaps most people don’t necessarily want no algorithms; they want algorithms to stop making all decisions for them. And to take this further, in other cases, it’s not even that people don’t want algorithms. They think they don’t want them, but there’s a high chance that they won’t actually like what reality looks like without algorithms.

After all, recommendation systems can be incredibly useful and they’ve been used for a very long time. They can introduce us to new music, creators, products, news and communities that we would probably never have found ourselves.

Sumit Kumar, co-founder of digital solutions experts Creative Ideaz, points out that personalised feeds can prevent us from wasting time on content that isn’t relevant to us. At the same time, he argues that some users understandably find the amount of information platforms collect about them invasive.

Finding the balance between these two things is what’s been tough. The better an algorithm gets at predicting what we want, the more it potentially influences what we see, and that’s where it can go a little bit too far.

 

Could More Choice for Users Actually Break The Echo Chamber?

 

This is where Australia’s proposal gets particularly interesting, because in some ways, it’s assuming that giving users control over their own feeds will automatically solve these problems. Because if algorithms learn that you engage with a certain type of political content, for example, they can keep serving you more of it. Eventually, your feed might become a remarkably accurate reflection of your existing worldview.

And that’s not necessarily because the platform has decided you should believe something. It could simply be because you’ve demonstrated that you are more likely to click, watch, comment or share it.

Kumar believes giving users more control could help address this problem, arguing that it could allow people to avoid harmful or hateful content while potentially giving them a more balanced view rather than reinforcing divisive echo chambers.

But it’s just not as simple as that. Humans are perfectly capable of creating echo chambers all on their own, without algorithms, whether we want to believe it or not. If I choose to follow only people I agree with, remove anyone who challenges my opinions and deliberately select the content I want to consume, I can create a very comfortable little bubble all by myself. It’s a social phenomenon that we’re seeing encouraged across platforms and social environments across the board these days.

In fact, one may argue that an algorithm might occasionally be the thing introducing me to something I wouldn’t otherwise have seen. It may be something you don’t like or don’t agree with, but just because you didn’t choose to see it doesn’t make it inherently bad.

 

Perhaps The Real Issue Is Control

 

This is why I don’t think the debate should simply become “algorithms are bad” versus “algorithms are useful”, because that’s simply not a fair representation of the whole issue. After all, both can be true. The problem is what happens when personalisation becomes so sophisticated that users no longer feel like they’re choosing what to see.

Australia’s proposal doesn’t necessarily mean the end of algorithms. Instead, it could give users a clearer choice about whether they want the algorithm to curate their experience. Or, whether we choose to accept it or not, it might even expose the fact that perhaps we (users) are the a bigger part of the problem than we’d like to believe. Algorithms may not require us to make constant conscious decisions, but they’re still showing us content based on what we like and want to see, whether we’re totally aware of it or not. Will this change in how algorithms work and are implemented expose a darker reality about how we really are?

As Kumar puts it, social media can be a useful tool for learning and entertainment, but it isn’t always clear how our data is being used. Giving users more power over what they see, he argues, “can only be a good thing”. And I think in some ways, it’s true that transparency is positive, but I think people may not be very happy with what they discover about themselves. Whether that’s the fact that they start finding their feeds boring and end up begrudgingly reverting to the dreaded algorithmic version, or they start consciously choosing to see the content they used to pretend not to enjoy.

Ultimately, giving people more control could be positive, but it could also reveal that we don’t always want what we think we want, and I’m not sure people are ready to face that reality. An algorithm might annoy us by showing us something outside our usual interests, but it might also occasionally expose us to an idea, person or perspective we would never have chosen ourselves.

If Australia does eventually give users that choice, we’ll get to see what happens when millions of people can decide whether they want the algorithm or not. And maybe we’ll discover that we really do want a more human-controlled internet. Or, perhaps we’ll discover that, after years of complaining about algorithms, most of us quite like having something else decide what to watch next, whether that’s due to the unpredictability of the feed or the removed accountability that it allows us.

Who knows what the results will be, but I’m pretty sure this is going to bring to life some thoughts and feelings they don’t see coming.

The post Could Australia’s Proposed Algorithm Rule Break The Current Echo Chamber That Is Social Media Today? appeared first on 91̽.

]]>
PASS Announces Schedule Hero: AI-Powered Scheduling Built For Home Care /news/pass-announces-schedule-hero-ai-powered-scheduling-home-care/ Wed, 09 Sep 2026 17:25:10 +0000 /?p=159052 PASS today announced Schedule Hero, a new AI-powered scheduling experience created for the way home care actually operates. Instead of...

The post PASS Announces Schedule Hero: AI-Powered Scheduling Built For Home Care appeared first on 91̽.

]]>
PASS today announced Schedule Hero, a new AI-powered scheduling experience created for the way home care actually operates.

Instead of simply displaying a rota and leaving coordinators to resolve every change manually, Schedule Hero uses the information already held in PASS to help teams decide what to do next. It creates and ranks complete scheduling options whenever visits need assigning, whether a carer becomes unavailable, a new care package begins, staffing changes or the week needs reshaping.

Every option considers care needs and preferences, carer availability, travel and continuity. Teams can compare the plans, understand the strengths and trade-offs, make any edits and choose what gets published. Once approved, PASS can notify the carers and clients affected.

“Home care is too dynamic for scheduling software to remain a passive record of what was planned. Schedule Hero gives teams practical help at the moment plans change. It can do the heavy work of finding and comparing options in seconds, while the people who know the service remain firmly in control.” Duncan Campbell, Commercial Director at PASS.

 

From A Static Rota To Active Scheduling Support

 

Home care schedules are living plans. People call in sick, care packages start and change, availability moves and visits need to be reorganised. These changes are normal but resolving them can mean checking dozens of carers, journeys and customer requirements by hand.

Schedule Hero changes the role scheduling software plays. It does more than record the latest version of the rota; it helps teams build the next one. Home care providers will be able to use it to:

  • Create cover plans when a carer becomes unavailable
  • Build suitable assignments for a new care package
  • Reassign visits when staffing or availability changes
  • Reshape the week when plans no longer fit

 

Built Around Care Not Just Capacity

 

Finding someone with space in their diary is only part of a good assignment. Schedule Hero also considers the person receiving care: what they need, what they prefer and whether the plan protects continuity. Travel and carer availability are assessed alongside those care requirements, rather than in isolation.

The result is not a single unexplained answer. Schedule Hero presents ranked, workable plans and shows the strengths and trade-offs of each one, giving coordinators a faster route to a decision they can stand behind.

AI Assistance With Human Judgement

 

Schedule Hero does not change the rota on its own. The coordinator chooses the plan, edits it if needed and decides what gets published. Only then does PASS update the schedule and notify the carers and clients affected. The AI supports the decision; the home care team makes it.

 

Availability

 

Schedule Hero is coming soon to PASS. Home care teams can visit the to learn more, see the feature in action and join the waiting list.

The post PASS Announces Schedule Hero: AI-Powered Scheduling Built For Home Care appeared first on 91̽.

]]>
Portal26 Launches Recon: Ask Any Plain Language Question To Deliver Immediate, Actionable Answers To Any Question About AI Use In The Enterprise   /news/portal26-launches-recon-ask-plain-language-question-deliver-immediate-actionable-answers-question-ai-use-enterprise/ Wed, 09 Sep 2026 13:00:14 +0000 /?p=158894 Portal26 today announced Recon by Portal26, an industry-first capability that enables enterprises to make plain  language queries about all their present...

The post Portal26 Launches Recon: Ask Any Plain Language Question To Deliver Immediate, Actionable Answers To Any Question About AI Use In The Enterprise   appeared first on 91̽.

]]>
Portal26 today announced Recon by Portal26, an industry-first capability that enables enterprises to make plain  language queries about all their present and past AI consumption data and also adapt their AI governance and security controls in real time to evolving risks and opportunities.

Recon enriches every prompt, response, agent and AI tool touchpoint with company, user, intent, and behavioral context – then turns it into a measurable signal of risk, governance gaps, opportunity, and spend. Built for CIOs, Chief AI Officers, CISOs, and Compliance, Legal teams, and Forward-Deployed Engineers (FDEs),, Recon delivers immediate, actionable answers, system updates and insights even create detailed audits and board-level reporting.

With enterprises still lacking visibility and insights into what’s really happening with their AI deployments, examples of what Recon can put instantly  within reach:

  • Ask questions in plain language, such as “What is the impact to my GDPR and CCPA compliance posture from my AI usage?” or “Assess my AI usage against ISO 42001’s mandatory requirements” and get an instant, evidence-based answer

  • Auto-generated risk scorecards, complete with a built-in one-month remediation plan

  • AI-driven remediation. Recon doesn’t just flag issues; it can help fix them

  • Adaptive, self-remediating governance. As regulations shift, Recon flags where the organisation falls short and helps close the gap before it becomes exposed

  • Post-deployment performance tracking, so teams can answer “what KPIs are these agents actually moving?” and report on ROI with confidence

  • Department-level maturity mapping, plotting teams from Dormant to Strategic so leaders know where to invest, where to govern, and where to leave alone

  • Anything else you can think of or or anything you are asked for as it pertains to your organisation’s use of AI

Insightful and Adaptive for Reporting, Risk and Evolving Compliance

Recon lets enterprises track its real-world AI governance, performance and ROI, giving Chief AI Officers, CIOs, and COOs a live, board-ready view of AI program health in minutes, not a retrospective report months later. For CISOs and SOC teams, Recon also closes detection gaps and continuously tightens security posture, without waiting on a manual review cycle.

And for compliance and legal teams, Recon identifies exposure the moment a new regulation lands and helps deploy detection rules the same day, replacing the quarter-plus wait for a compliance review with evidence ready to walk into an audit.

“Every AI leader I talk to is wrestling with the same problem: they’re accountable for how AI is used across the business, but they don’t have a way to answer all the nuanced questions thrown at them,” said Arti Raman,  CEO of Portal26.

“Recon instantly closes that gap. It gives CIOs, CISOs, CDAOs, and CAIOs a single, plain-language view of risk, adoption, performance, and AI consumption behaviors  so decisions about AI stop being reactive and start being governed. The next time you meet with your AI governance committee, your board of directors, or your BU leaders, save a seat for Recon – it will answer all those questions that come up, which you would have otherwise had to spend hours digging into after the meeting! ”

Recon is also an essential tool for Forward Deployed Engineers (FDE).

“FDEs are the new front line of enterprise software deployment,” said Pakshi Rajan, Portal26’s Chief AI Officer and VP Products. “Palantir pioneered the model, and now every major AI lab and platform is scaling it, but these teams have neither visibility into what are the right AI apps and agents to build, nor what actually happens once they leave the room. Recon turns the light on before, during, and after the FDE.”

“FDEs are on the front lines of AI deployment, but they’re too often flying blind ,pushing models into production without knowing what’s actually happening once they’re live,” said Joe Boggio, VP, Strategic Alliances at Portal26. “Recon gives FDEs the same visibility their leadership needs, in the moment they need it, so they can move fast without losing sight of risk.”

 is available now to enterprise customers. Full details are available at portal26.ai.

The post Portal26 Launches Recon: Ask Any Plain Language Question To Deliver Immediate, Actionable Answers To Any Question About AI Use In The Enterprise   appeared first on 91̽.

]]>