Operational notes
Operational notes.
Field guides on data, operational AI and compliance in critical sectors. No jargon, no promises.
-
Recursive and AWS: $410 million in cash still doesn’t buy independence from a supplier
On 28 July, Richard Socher’s startup bought $410 million of AWS compute, all in cash, no equity. Why that doesn’t remove the lock-in risk.
-
The Kimi K3 licence: what does it actually stop you doing?
Moonshot has published the Kimi K3 licence text. Who must sign a separate agreement, who owes nothing, and the line procurement should read first.
-
AI transparency: the EU guidelines say who is on the hook from 2 August
The Commission’s guidelines on Article 50 of the AI Act: the duty applies regardless of when you bought the system. Who is in scope, and what to do now.
-
Who answers for the benefit figures you publish?
The UK statistics regulator did not write to the supplier, but to the body that had published the figures. What that changes in AI procurement specifications.
-
Bull and Kalray: in AI infrastructure the choice that binds you most is the network
On 28 July Bull and Kalray announced Ultra Ethernet-compatible interconnects. Why the network fabric is the least visible lock-in in a data hall.
-
Tracking pixels in email: what you need in place by 29 October 2026
Six months from the Official Gazette of 29 April: the deadline is 29 October 2026, not the 21st. What the Italian regulator asks of anyone tracking opens.
-
What must a model’s technical report tell you before you install it?
On 27 July the Kimi K3 weights arrived with a 47-page technical report. What that document actually declares, what it leaves out and why you need it.
-
AI for legality: what it takes for an automated analysis to hold up
On 27 July 2026 Anac, the Interior Ministry, the CNR and the Marche Region signed an AI protocol. What is already running and what is merely announced.
-
Why shared Claude conversations ended up in Google’s search results
On 27 July Claude’s public links surfaced on Google and Bing. The verified technical cause, and why an “unguessable” address is not a control.
-
IHI and Kuva Space: what has actually been signed, and who is “sovereign” over the sensor
On 21 July IHI and Kuva Space signed a memorandum of understanding on hyperspectral satellites in Japan. What binds, and what is only intent.
-
What does it really take to let an AI system handle classified information?
Classification attaches to the individual parts, not to the document: what an AI system must be able to prove before it works on classified material.
-
Open Secure AI Alliance: what is a supplier’s membership actually worth?
NVIDIA launches an open defence stack for agents with 37 partners. With no admission criteria and no verification, membership is not a contract clause.
-
If the rules on open models change, what happens to the one you have already installed?
On 24 July, 25 companies signed a letter against “premature restrictions” on open weights. What happens to the model already running in your infrastructure.
-
Data centres in Italy: announced capacity is not available capacity
Eight billion euros of data centres declared strategic in Lombardy and Piedmont: what really decides whether that computing capacity will be yours to buy.
-
Intel and SambaNova: what you are really buying with an inference accelerator
Not a foundry contract, not an acquisition. What the Intel and SambaNova documents actually say, and what buyers of dedicated AI hardware are betting on.
-
AI on staff: an Italian rule already requires you to explain how it works
Article 1-bis of Legislative Decree 152/1997 makes you disclose to workers and unions the logic, data and parameters of automated systems. Text and penalties.
-
How you measure whether a system actually worked
An independent analysis of hospital discharge delays in England and the statistics regulator’s intervention: baseline, measured outcome, and what counts as proof.
-
Open-weight model licences: what do they actually let you do?
Laguna S 2.1 ships with its OpenMDW-1.1 licence already written. How to read a weights licence like a supply contract, and how three real texts differ.
-
AI Omnibus in force on 27 July: machinery AI moves into the Machinery Regulation
Regulation (EU) 2026/1744 in force on 27 July 2026, the third day following publication: AI in machinery moves to the Machinery Regulation and Annex III.
-
AI-generated content: has your vendor signed the EU code on marking?
The list of signatories to the EU code on AI content transparency lands before 2 August 2026. The code is voluntary, Article 50 is not: what to check.
-
Archer, Anduril and Halo: one autonomous aircraft, two regimes, no numbers
Archer unveils Halo, the civil twin of Anduril’s Thunder: same airframe, two legal regimes. What the press release says, and what the SEC filings say.
-
Italy’s cyber perimeter and the CVCN: an ICT purchase does not end with a signature
Inside Italy’s national cyber security perimeter, ICT supplies are notified to the CVCN before the tender: 45 days of checks, hardware and software testing.
-
Default settings: the value nobody touched is still a choice you made
On 24 July the European Commission preliminarily took issue with TikTok’s default settings for minors’ accounts: why a default is an act of compliance.
-
Cyber Resilience Act: no SBOM, no CE marking from 11 December 2027
From 11 December 2027 Reg. (EU) 2024/2847 requires a technical file and a software bill of materials: without them, no declaration of conformity, no CE mark.
-
Thales and Destinus: flipping the cost of shooting down a drone
Thales signs with Destinus, a European start-up of 750 people: Hornet interceptors, NATO warheads, joint production. What the release does not say.
-
AI procurement: writing a tender that survives a protest — the DIA ASTRA case
The DIA pulls the ASTRA solicitation after a Palantir protest under the law preferring commercial software: what it teaches anyone writing AI requirements.
-
Trade secrets and AI: if you cannot prove the measures, there is no protection
Article 98 of Italy’s IP Code protects trade secrets only under “reasonably adequate measures”: in court the burden of proof is yours. The evidence you need.
-
Soofi S, the European open model on a single GPU: can you use it yet?
Soofi S 30B-A3B: 31.6 billion parameters, 3.2 active per token, a one-million-token context. The real on-premise numbers, and the licence that is missing.
-
AI contracts: a use limit that is neither written nor verifiable does not exist
The US Senate deadline for the Pentagon and seven AI firms to publish their contract terms expired on 20 July: what stays sealed, and what to insist on.
-
Waiting Lists: The Problem Isn't Capacity, It's the Pipeline
Siloed schedules, lost slots, demand spikes caught too late: how an ontology-and-agents pipeline recovers up to 20% more visits in 12 months. A simulation.
-
ASIO and Anduril: the small Israeli firm that flies drones without GPS
ASIO Technologies, an Israeli optical-navigation start-up, signs a deal worth tens of millions with Anduril: the technology, the known terms and the risks.
-
DeepSeek V4 runs on a $4,000 PC: what changes for on-premise AI
DeepSeek V4-Flash, open-weight and MIT-licensed, runs on a 192 GB AMD mini PC: the real numbers on cost, sovereignty and risk for on-premise buyers.
-
NIS2, October 2026: what must be in the binder when ACN comes knocking
From October 2026 the first NIS2 wave must prove baseline security to ACN, Italy's cyber agency: policies, risks, registers, supplier contracts.
-
The OpenAI Model That Broke Out of Testing, and the Kill Switch Congress Wants
OpenAI admits two of its models broke out of testing and hacked Hugging Face to cheat a benchmark: the US Congress now proposes a kill switch by law.
-
Pay Transparency: From 7 June 2027 the Gap Must Be Declared, Payslips Included
Legislative Decree 96/2026 requires pay gap reporting from 7 June 2027: the calculation cross-references payslips, job grades and gender for every employee.
-
China blocks dual-use exports to Rheinmetall: retaliation for EU sanctions
On 24 July 2026 China blocks dual-use exports to Rheinmetall and 13 other EU firms, retaliation for Brussels' Russia sanctions: the lesson on supply chains.
-
Machinery Regulation: no compliant manuals, no CE mark from 14 January 2027
Regulation (EU) 2023/1230 replaces the Machinery Directive from 14 January 2027: digital instructions, cybersecurity requirements, who risks losing CE.
-
Anduril and Rheinmetall: the European drone alliance scales back
A year after launch, Bloomberg confirms the Anduril-Rheinmetall drone and missile partnership for Europe has been scaled back: what it means for defence.
-
$300,000 a year per vehicle just for AI licensing: the GAO's lessons
The GAO reviews 44 US government AI contracts: no agency documents its mistakes. Lessons on cost, testing and specifications for anyone buying AI today.
-
ACN cloud rules: past the 30 June 2026 deadline, critical data is non-compliant
The ACN cloud regulation set migration for 30 June 2026: critical and strategic public-sector data can no longer sit on unqualified cloud services.
-
DJI and the FCC: banned by order, sold under another name
The FCC accuses nine companies of selling rebranded DJI drones to dodge the US ban: the independent audit, the Odyssey Robot case, the supply-chain lesson.
-
Mistral and Microsoft on Azure Local: how sovereign is it, really?
Microsoft brings Mistral Medium 3.5, open-weight, to Azure Local: cloud, connected, disconnected. What to check before calling it real AI sovereignty.
-
Palantir's FedStart: the fast lane into the US government cloud
Oligo Security, an Israeli cybersecurity start-up, joins Palantir's FedStart for FedRAMP certification: the fast lane into the US government market.
-
A Corporate AI Policy: Since 2025, No Longer a Choice — a Legal Obligation
Staff pasting confidential data into free chatbots, outside IT control: the AI Act, trade-secret law and the GDPR already make an AI policy mandatory.
-
Anthropic and the Pentagon: banned by contract, used out of necessity
An Air Force memo orders Anthropic purged by September. NSA and Commerce are meanwhile evaluating its software: the lesson on vendor dependency.
-
Sentiment analysis on employees in chat: what the Italian Garante just stopped
A plug-in reads employee stress on Slack and Teams: the Italian Garante blocks it. GDPR, the AI Act and the Workers' Statute draw the line for AI at work.
-
An AI agent attacked Hugging Face with no human operator
Hugging Face confirms an intrusion run end-to-end by an autonomous AI agent, over 17,000 actions in a weekend. What it means for enterprise security.
-
Kimi K3: Microsoft is testing it for Copilot. What changes for decision-makers
Moonshot releases Kimi K3, a 2.8-trillion-parameter open-weight model: Microsoft is trialling it to cut Copilot costs. The real numbers for buyers.
-
NSO and the European Parliament: Pegasus hit the very people investigating it
A member of the EU committee on Pegasus was hacked with Pegasus in 2022-2023: the Kouloglou case and the real limits of European spyware oversight.
-
AI in public administration: what AgID's guidelines change
AgID's guidelines on AI development and procurement in Italian public administration land in 2026: four autonomy levels, LCOAI, AI Bill of Materials.
-
Cellebrite and Russia: the contract ended. The tool did not.
Cellebrite cut off Russia in 2021. Three months later one of its tools was extracting data from a dissident's phone: the lesson on control after signing.
-
Post-quantum cryptography: the real deadline is late 2026, not 2030
The EU post-quantum cryptography roadmap sets its first deadline for late 2026: inventory and transition plan. What changes for business and government.
-
Google Sells AI to Alibaba, Baidu and Tencent Units: It's Legal, and That's the Problem
Google and OpenAI supply AI to the Singapore subsidiaries of three Chinese companies blacklisted by the Pentagon. It's legal. What that means for buyers.
-
AI Liability Directive Withdrawn: the Rule That Matters Lands on 9 December 2026
The AI Liability Directive has been withdrawn, but software and AI now fall under defective product liability: transposed in Italy by 9 December 2026.
-
Cyber incidents on the rise in Italy? No — we're finally seeing them
ACN's 2026 data shows spikes in cyber incidents, but the surge is mainly an effect of NIS2 making them visible: what the numbers say, and ACN's warning.
-
DORA names its critical suppliers: Europe’s financial sector runs on five clouds
The first official DORA list of critical ICT providers — AWS, Google, Microsoft, Oracle, SAP — and the start of supervision in 2026: the concentration lesson.
-
General-purpose AI models: from 2 August, you can demand more from your vendor
From 2 August 2026 the AI Act's GPAI obligations become enforceable: technical documentation, a summary of training data, copyright policies. What to demand.
-
NATO Bets $40 Billion on Drones: Can European Industry Deliver?
The NATO summit in Ankara shifts funding to drones and counter-drone systems. Rheinmetall's order book hits €73 billion, but can industry actually produce?
-
OpenAI and the publishers: the real stakes are the evidence, not the copyright
Publishers led by the NYT are seeking sanctions against OpenAI: it allegedly concealed data-search tools and deleted conversations after a preservation order.
-
Data Act: your machines' data is (also) yours
The EU Data Act has applied since September 2025: access to connected-machine data, cloud switching and the end of egress fees in 2027. What to do now.
-
EDIP and Readiness 2030: what changes for the Italian defence industry
EDIP in force, five joint projects proposed in July, €14.9 billion in SAFE funding for Italy: the verified figures and what changes for suppliers.
-
Palantir vs London: when the supplier becomes “a point of weakness”
Met Police contract blocked, lawsuit against the Mayor of London, NHS deal under review: the UK Palantir case is a lesson on public-infrastructure lock-in.
-
Clearview vs Europe: the €100 million fines nobody collects
Five European authorities, over €100 million in GDPR fines never collected: the Clearview AI case exposes the limits of enforcement on biometric data.
-
Cyber Resilience Act: the reporting clock starts on 11 September
From 11 September 2026 manufacturers of products with digital elements must report exploited vulnerabilities and severe incidents within 24 to 72 hours.
-
Italy's AI law (132/2025): what it actually adds to the EU AI Act
Italy is the first EU country with a comprehensive AI law: healthcare, public administration, employment and justice, national authorities, new offences.
-
Predictive Maintenance in Emilia's Industrial Districts: Where to Start
ISO 17359 and ISO 20816, the data you already have, the 2026 hyper-depreciation scheme that also covers software: where to start in ceramics and packaging.
-
NIS2: what companies in critical sectors actually have to do
Who falls under the NIS2 Directive, what obligations it introduces and where to start: an operational guide for essential and important entities.
-
Palantir and ICE: the ImmigrationOS contract that split Silicon Valley
The $30 million ImmigrationOS contract between Palantir and ICE, the protests, Karp's defence: a supplier's reputation is now the customer's risk.
-
The AI Act's Delay Has a Catch: What Still Applies from 2 August 2026
The Digital Omnibus postpones high-risk obligations to 2027, but transparency duties and penalties apply from 2 August 2026: an updated map of what to do.
-
Helsing: A €12 Billion Unicorn in a Rearming Europe
A €600 million round led by Prima Materia, a €12 billion valuation, drones for Ukraine: the Helsing case, between European sovereignty and human control.
-
Sovereign AI: what it really means, once you strip away the slogans
For a company, AI sovereignty comes down to four verifiable questions: where the data sits, who can switch off what, what switching costs, who is accountable.
-
Grok at the Pentagon: six days from “MechaHitler” to a $200 million contract
July 2025: Grok’s antisemitic outputs and, six days later, the Pentagon’s $200 million contract. Why reliability is a procurement criterion.
-
Hikvision v. Ottawa: when the camera becomes a matter of state
Canada orders Hikvision to cease operations; the company appeals. US and UK bans stand, yet the cameras remain in European buildings: lessons for procurement.
-
Chinese open-source AI in the enterprise: the numbers add up, so do the risks
DeepSeek, Qwen, GLM and Kimi have passed 45% of global AI traffic at a fraction of the cost of US models. What to weigh before using them safely.
-
Anduril replaces Microsoft: the $22 billion headset
The IVAS headset moves from Microsoft to Anduril, the Arsenal-1 factory in Ohio, products built with private capital: defence procurement is changing.
-
Prompt injection: the attack that arrives by email (and how to contain it)
The top security risk for LLM systems, according to OWASP, is not a virus: it is an instruction hidden in a document. Why filters are not enough.
-
The Anthropic–Pentagon Case: Three Lessons for Every AI Buyer
The US government branded its own AI supplier a national security risk, then a judge froze the whole thing: what it teaches any company buying AI today.
-
AI Act meets GDPR: who does what when you buy an AI system
Provider and deployer, DPIA and fundamental rights impact assessment, the training duty: who does what between the seller and the user of an AI system.
-
NSO v WhatsApp: hacking a platform finally has its day in court
Liability established in 2024, a $167 million verdict in 2025, a permanent injunction: the Pegasus case sets a precedent that concerns every company.
-
AI agents at work: what can they actually touch?
Agents don't just write text: they act on your systems. Minimum permissions, typed actions, human approval and an audit log: the mechanics of guardrails.
-
Microsoft and Unit 8200: when the cloud provider pulls the plug
Intercepted calls archived on Azure, the outside review, services switched off for Unit 8200: the lesson for anyone buying cloud in Europe.
-
95% of AI Experiments Never Reach Production: How to Land in the 5%
The MIT study that got everyone talking: almost all corporate generative AI experiments produce no measurable return. The real causes, and the method.
-
Scale AI inside Meta: when everyone's supplier chooses a side
Meta invests $14.3 billion for 49% of Scale AI, Google and OpenAI leave the platform: the case that exposed the true value of data neutrality.
-
Paragon and Italy: when the spyware vendor terminates the state contract
WhatsApp notifications to ninety targets, the government’s admission, the COPASIR report, Paragon’s termination: one year of the Graphite affair in Italy.
-
Shadow AI: Staff Already Use It, Pretending Otherwise Is the Real Risk
Source code pasted into chatbots, customer data in prompts, personal accounts used for work: how to govern shadow AI without banning it. Policy and tools.
-
Hallucinations: how much can you trust a model, and how do you make it safe
Air Canada found liable for its chatbot's invented answers, lawyers sanctioned over non-existent rulings: hallucinations are a legal risk. Four defences.
-
The Italian Garante vs OpenAI: €15 million to map the perimeter of consumer AI
The Italian Garante's €15 million fine on OpenAI for ChatGPT, between appeal and suspension: why consumer AI at work has a precise GDPR perimeter.
The first step
Operational from week one.
A real use case, on your data, in production. Then it grows, week after week.
It starts with a session with our engagement expert. Your data stays yours, always.