Meta rejected Facebook and Instagram ads for a Barcelona staging of Virginia Woolf's A Room of One's Own, then advised stripping the words describing its own subject. On the EU's total ad ban since October 2025, collateral censorship, and who actually pays for it.
Digital Sovereignty
Platform Governance
EU Policy
Alan Wright
21 September 2026
While LinkedIn tears into the EU Digital Omnibus's Article 88c redline, the Council has already scrutinised and cut that provision back once. It hasn't touched Article 9's special category data derogation, GDPR's strictest tier, or Article 12(5)'s narrowing of subject access requests, the two changes doing the quieter, more consequential work.
AI Governance
Data Protection
EU Policy
Alan Wright
18 September 2026
Twenty-two months of Windows 11 updates breaking Remote Desktop, Windows Hello, and now Claude's own file access, mandatory patches included. What that record, an unresolved Windows Recall vulnerability, a Copilot that reinstalls itself against your wishes, and Quick Machine Recovery's back-to-front default settings add up to, plus what's actually changed for SMEs willing to give Linux a real try and why SELinux's default-enforcing hardening beats anything Windows ships turned on.
Cybersecurity
Digital Sovereignty
Vendor Lock-In
Alan Wright
17 September 2026
A September 2026 Windows update that broke USB audio on some PCs is a low-stakes way into a real problem: Cyber Essentials' 14-day patching rule measures timing, not process, and its own security update management control names same-day automatic updates as the preferred route to compliance. Why notify-and-review, staged rollout, and a rollback plan are the actual discipline, and why most small firms can run it without enterprise tooling.
Cybersecurity
Digital Sovereignty
Compliance
Alan Wright
14 September 2026
OpenAI's chief scientist published an essay calling for a voluntary AI slowdown three days after his own company shipped its most capable model yet, and Anthropic's coordinated-pause call landed a week after its own confidential IPO filing. What's actually behind three unrelated "AI is slowing down" stories, including the compute financing reset wall arriving in 2027 that no amount of rhetoric changes.
AI Governance
AI Policy
Financial Markets
UK Policy
Alan Wright
13 September 2026
Sometime before 25 August, the public download pages for VMware's Virtual Disk Development Kit went dark, with no Broadcom announcement of any kind. The library sits underneath nearly every agentless tool for leaving vSphere, from Azure Migrate to Red Hat's MTV to Nutanix Move, and its disappearance lands the same fortnight Broadcom revived a free vSphere Standard edition.
Cybersecurity
Digital Sovereignty
Vendor Lock-In
Alan Wright
8 September 2026
OpenAI and Anthropic filed draft IPO paperwork within weeks of each other in 2026, racing each other to public markets after OpenAI's own March round had already oversubscribed a $1 billion retail tranche to more than $3 billion, six months before any prospectus existed. The real figures behind two companies reaching for a pool of capital their existing backers, already tapped out and increasingly each other's largest customers and suppliers, can no longer fully underwrite alone.
AI Policy
Financial Markets
AI Governance
Alan Wright
4 September 2026
OpenAI's GPT-6 Astra scored 98.6% on ARC-AGI-3 through its own Provider Adapter and 62.7% through the benchmark maintainer's standard harness, same weights, same model. The gap is now a subscription line item at every major lab, and buried inside the adapter's opaque carried-forward reasoning state is a GDPR accountability problem nobody selling the harness has an answer for.
AI Governance
Cybersecurity
Data Protection
AI Policy
Alan Wright
4 September 2026
OpenAI's own technical report documents a live, correctly diagnosed Artifactory compromise on 27 June 2026, and a decision by on-call staff that stopping the evaluation run was not required; it ran eight more days until its own volume of traffic took the service down. The report's headline safeguard numbers come from OpenAI's auto-review model grading OpenAI's own incident, after the fact. Its central claim about contained tampering is directly contradicted by the independent investigation published alongside it.
AI Governance
Cybersecurity
AI Policy
OpenAI
Alan Wright
4 September 2026
Anthropic signed a wave of hijacked Claude accounts out on 30 August, after commodity infostealers replayed stolen session cookies straight past two-factor authentication. The sign-out never touched the Google Workspace connector behind it: a separate, persistent OAuth grant that only a manual disconnect removes, and one no admin console is watching on a card-billed personal account. Anthropic's own fix for exactly this gap, enterprise-managed connector authorisation, went live six days earlier, covering ten connectors and not the one this campaign actually exposed.
AI Governance
Cybersecurity
OAuth
Anthropic
Alan Wright
3 September 2026
OpenAI's new Apple Messages plugin only needs one Mac user's consent to make years of a conversation searchable by AI; everyone else on the thread never gets a vote. The policy promise rests on an unscoped OS permission grant rather than a narrow API, defeats disappearing-message tradecraft, and sits outside both the UK's journalistic source-protection law and, for a US-held copy, its overseas data-access regime. The politicians it also exposes are already living on personal WhatsApp for substantive business, not on hardened GCHQ kit.
AI Governance
Cybersecurity
Data Protection
UK Policy
Alan Wright
28 August 2026
Researchers scanned 6,214 corporate domains and found 120 llms.txt files pointing at code nobody registered; claiming a handful of the gaps got a Fortune 500 coding agent phoning home within the hour, EDR silent throughout, because every part of the request looked sanctioned. The reporting calls it a collapsing data-code boundary. The harder question is who signed off on shell access to a stack they never actually audited.
AI Governance
Cybersecurity
AI Policy
Anthropic
Alan Wright
28 August 2026
OpenAI's own account of how its agents hacked Hugging Face calls itself a warning shot; nobody caught it for five weeks. The same summer saw Anthropic, the UK AI Security Institute, and Meta each disclose the identical failure independently. Four labs, two shared third-party evaluators, and not one of them detected it in real time.
AI Governance
Cybersecurity
AI Policy
Anthropic
Alan Wright
27 August 2026
Ollama's v0.33.0 update folded Claude Desktop routing into a menu-bar toggle on 25 August 2026, the same week Brussels quietly pushed the EU AI Act's high-risk deadline back sixteen months. Neither event closes the actual gap: which model answered a prompt, on whose account, and under whose data-handling terms, is a question almost no company's stack can currently answer. Google's tier split and Claude's own consumer-versus-API divide tell the same story from a different angle -- the choice was shipped as a feature, the accountability wasn't.
AI Governance
Cybersecurity
GDPR
Anthropic
Alan Wright
27 August 2026
Microsoft rebuilt Windows Recall around a TPM-backed enclave, biometric gating, and a sensitive-data filter after the 2024 backlash, and eighteen months of independent testing has found a way past every layer anyway: an unsandboxed rendering process handing malware decrypted screenshots on request, a filter that still misses credit card numbers, no published GDPR compliance statement. None of it was ever the real gap. Windows has never required consent for the screen capture that fills the archive in the first place, enclave or not.
Cybersecurity
Digital Sovereignty
Microsoft
GDPR
Alan Wright
27 August 2026
China's Ministry of State Security just retired Windows 10 China Government Edition eighteen months early, no CVE disclosed, after eight years running telemetry, patching, and activation through CMIT, a state-controlled joint venture marketed the whole time as "strict outgoing data control." The control plane trap this publication caught under Google Cloud in May just resurfaced under Beijing, proving it was never a US problem or a China problem.
Digital Sovereignty
Cybersecurity
China
Microsoft
Alan Wright
19 August 2026
Five French government platforms have been breached in eight months, two ministries hit twice: DGFiP via FICOBA then its own tax and cadastral portal, the Interior Ministry via email and TAJ/FPR then ANTS. CNIL named the exact authentication gap in writing in March 2025, a minister confirmed it under oath in January, and the state's own coordinated fix still doesn't fully land until February 2028.
Cybersecurity
GDPR
Regulatory Governance
France
Alan Wright
17 August 2026
Digital Isle of Man profiled Red5 Systems as a governance-first Microsoft Copilot rollout, phased access, human judgement retained, the right words in the right order. Microsoft's own documentation tells a narrower story: the EU Data Boundary is defined as EU and EFTA only, a scope that has never included the Isle of Man, and the Anthropic subprocessor path can route prompts to US infrastructure regardless of what a 2004 adequacy decision was ever built to answer.
AI Governance
Digital Sovereignty
Microsoft
Isle of Man
Alan Wright
14 August 2026
Nvidia's $500 billion financing arrangement with six Wall Street asset managers is the same off-balance-sheet structure the Bank for International Settlements labelled "shadow borrowing" five months earlier, now given a press conference instead of a warning. Congress asked the regulator built to catch exactly this kind of cross-market contagion to investigate back in November 2025; there is still no public confirmation it did, while the exposure is already reaching retirement savers through investment-grade bond funds inside their 401(k)s.
AI Policy
Digital Sovereignty
Capital Markets
Financial Governance
Alan Wright
13 August 2026
Anthropic's new watermark answers a fine of up to €15 million, but the detector that would let anyone verify it can't be released without teaching people how to beat it. The Isle of Man's National AI Office has now missed one Strategy deadline and slipped a second to early 2027, while a Manx advocate's own reading of the AI Act admits nobody yet knows whether the law even reaches a private consultancy report.
AI Policy
Digital Sovereignty
Anthropic
Isle of Man
Alan Wright
12 August 2026
Zscaler's ThreatLabz traced a month-long ransomware campaign to a target profile that skips the CEO for the 46-year-old manager who can approve a payment. Isle of Man company filings, LinkedIn, and most corporate "about us" pages hand attackers that reporting-line map for free, and almost nobody has weighed the trade-off before publishing it.
Cybersecurity
Ransomware
Governance
Isle of Man
Alan Wright
9 August 2026
Nscale's £2.5bn UK investment was announced as confirmed and, in government's own words, contracted. The flagship site turned out to be a scaffolding yard, and DSIT admitted under Guardian questioning that no contract existed and nothing was being audited. Three weeks after that admission, the department itself was abolished by a new Prime Minister, and nobody was left to answer for the claim.
AI Policy
Digital Sovereignty
Governance
Capital Markets
Alan Wright
8 August 2026
Manx Care's own Freedom of Information response concedes the exact referral pathway it was asked to risk-assess, then answers a different question when the DPIA question actually lands. Liverpool University Hospitals NHS Foundation Trust, confirmed on NHS England's own Federated Data Platform sign-up list, is both the referral partner named in that concession and the trust now selecting the vendor for the Manx Care Record.
Data Sovereignty
NHS
GDPR
Isle of Man
Alan Wright
3 August 2026
Anthropic's fifth MCP spec release finally gives networked servers a real way to verify who is calling them, OAuth 2.1, PKCE, the enterprise standard. It applies to HTTP only. Stdio, the transport most MCP tooling actually runs on, isn't mentioned once, because it never had the problem this update solves. Airlock, a self-hosted MCP gateway, finished its own build on exactly that assumption the same day, before the announcement even existed.
AI Policy
Digital Sovereignty
MCP
Anthropic
Alan Wright
31 July 2026
Refuge Bistro & Bar paid its renewal and had a decade of use behind it, and still lost refuge.im to a stranger. NIC.IM's own contract explains why: renewal notices sent to an agent's inbox count as sent to the business by law, and a domain was never property to begin with, just a registration that can lapse for reasons the registrant never sees.
Digital Sovereignty
Network Governance
Isle of Man
Governance
Alan Wright
28 July 2026
A federal complaint against an alleged Scattered Spider member exposed Microsoft's Global Device Identifier: a persistent, server-assigned token that tracked him across four countries and a VPN. The same mechanism sits on every managed Windows machine, one Microsoft Store sign-in away from firing, because Microsoft retired the enterprise alternative that used to prevent it. No third-party notice reaches the employer whose network gets logged, the Crown Dependencies get no CLOUD Act fast-track either way, and on most estates nobody has checked whether the registry key that blocks it is even set.
Cybersecurity
Digital Sovereignty
CLOUD Act
Isle of Man
Alan Wright
27 July 2026
Cloudflare's own July 2026 report puts agent traffic past half of all internet traffic, with humans down to fifteen minutes an hour on the open web. Google denies the decline while running a single mixed-use crawler that blends indexing and AI training into one stream, a blend regulators had to legislate apart by force. What AI search actually sells is synthesis: one voice with the disagreement quietly removed, and no way to check its working.
AI Governance
Digital Sovereignty
Search
Isle of Man
Alan Wright
27 July 2026
Hugging Face disclosed a breach driven end to end by an autonomous AI agent, then found its own incident responders blocked mid-forensics: commercial hosted-model guardrails could not tell an analyst from an attacker. The attacker answered to no usage policy. The defenders needed a model they could run themselves. The export-control fight this publication covered in June just supplied its own operational case study.
AI Policy
Digital Sovereignty
Cybersecurity
Anthropic
Alan Wright
21 July 2026
A hacker with valid credentials wiped Romania's entire land registry database, halting real-estate transactions nationwide, days after ANCPI's own press release promised redundant backup locations. The same credentials that reached production reached the backups too. Here's why redundancy is not the same as isolation, and what actually saved the one copy that survived.
Cybersecurity
Critical Infrastructure
Incident Response
Digital Sovereignty
Alan Wright
21 July 2026
A Douglas firm just claimed the island's first ISO 42001 AI governance certification, zero non-conformances on the first attempt. Here's what that certificate actually attests to, what it doesn't, and how we built the same governance artefact ourselves for the cost of an afternoon.
AI Governance
Digital Sovereignty
ISO 42001
Isle of Man
Alan Wright
5 July 2026
Anthropic's crackdown on Chinese access to Claude, a contested covert detection mechanism, a confirmed state-sponsored espionage campaign, and the Azure infrastructure underneath both frontier labs -- read as one structure rather than four separate stories.
AI Policy
Digital Sovereignty
CLOUD Act
Anthropic
Alan Wright
3 July 2026
OONI documented 554,507 domains blocked and a half-configured MitM certificate behind LaLiga's anti-piracy regime -- Amnesty International, UNHCR and the UK's own NCSC caught in the crossfire. The same week, EuroISPA asked Brussels who should pay for it, and named DNS resolvers and VPN providers as the next targets.
Digital Sovereignty
Cybersecurity
EU Policy
Network Governance
Alan Wright
2 July 2026
The EU's Cloud and AI Development Act is the most serious attempt yet to define what sovereign cloud actually means. A Delaware corporation with a Dublin address self-certifies Level 1 compliance. A Manx operator with a Nuremberg server and no CLOUD Act surface fails the entry criterion. The framework knows this and has decided, for now, that this is acceptable.
Digital Sovereignty
EU Policy
CLOUD Act
Cloud Governance
Alan Wright
28 June 2026
Between 22 April and 5 June 2026, operators linked to Alibaba's Qwen lab conducted 28.8 million exchanges with Claude through approximately 25,000 fraudulent proxy accounts. The June 12 directive was not what it appeared to be. The cave was already open.
AI Policy
Digital Sovereignty
Export Controls
Anthropic
Alan Wright
28 June 2026
The bare-metal Mastodon install wasn't an ideological choice. It was an accumulation. Certbot kept breaking cert renewals, Caddy fixed that, and the official install guide did the rest. Here's what it took to undo it -- including the one database migration that didn't survive the journey.
Infrastructure
Self-hosting
Fediverse
Docker
Alan Wright
27 June 2026
If your business relies on productivity suites or cloud storage provisioned by a US-headquartered entity, your data is subject to American jurisdictional reach. The landmark litigation that forced the CLOUD Act into existence centred on data stored at the Grange Castle facility in Dublin. It does not matter if the hard drive is in Clondalkin or Cork.
Data Protection
Digital Sovereignty
GDPR
Ireland
Alan Wright
26 June 2026
The IOMFSA confirmed on 24 June 2026 that it has issued no guidance on algorithmic index-inclusion contagion as a distinct risk category -- because its licensed insurers have not flagged it as material. The SEC has not modelled it. The FCA has not modelled it. ESMA has not modelled it. The Isle of Man holds £88.1 billion in passive wrapper assets with a $22–27 billion forced rebalancing event approaching and no circuit breaker in the supervisory framework.
Financial Services
Isle of Man
Capital Markets
Financial Governance
Alan Wright
24 June 2026
In May, I wrote that sovereign infrastructure demands sovereign discipline. On 12 June 2026, at 5:21 PM Eastern Time, the US Commerce Department ran the experiment for me. Nothing in my infrastructure changed that evening. Here is what that means for every organisation that still thinks a vendor SLA is a sovereignty strategy.
AI Policy
Digital Sovereignty
Export Controls
Infrastructure
Alan Wright
24 June 2026
Three AI bosses sat down with G7 leaders and warned them the clock was running out. Nobody mentioned that one of them had his most capable model forcibly withdrawn by his own government five days earlier. The biosecurity parallel nobody is making -- and what it means for every jurisdiction that wasn’t in the room.
AI Policy
Digital Sovereignty
Export Controls
Anthropic
Alan Wright
18 June 2026
Washington has a kill switch. Beijing has a censorship regime. Small jurisdictions are being handed a false binary and told to choose. The open source sovereign inference path has been available the whole time. Nobody in the mainstream press mentioned it.
AI Policy
Digital Sovereignty
Open Source
Isle of Man
Alan Wright
16 June 2026
At 5:21pm on a Friday, Washington ordered Anthropic to cut foreign nationals off from its newest models. Anthropic could not do that selectively, so it cut off everyone, including Americans. The same government that called Anthropic a national security threat in February had embedded its own engineers inside the NSA by June. Britain’s response was to ask for a seat at a table it had just discovered it was never invited to.
AI Policy
Digital Sovereignty
Export Controls
Anthropic
Alan Wright
15 June 2026
A Munich court just ruled that Google’s AI Overviews are Google’s own speech, not neutral search results — and the reasoning reaches well beyond Germany. Here is what we built in response: a self-hosted, ad-free metasearch engine that just gives you links. It took an afternoon, £4.98, and eighteen months of infrastructure debt paid off in advance.
AI Governance
Digital Sovereignty
Search
Isle of Man
Alan Wright
14 June 2026
A 30% price increase with no change in usage. For a self-funded operation, that is not background noise; it is a decision. We moved. Here is what that actually looked like -- and what it means for any organisation that has ever assumed its infrastructure vendor relationship is stable.
Sovereign Infrastructure
Digital Sovereignty
Governance
Isle of Man
Alan Wright
10 June 2026
Canada’s Bill C-22 is not an aberration. Governments across the Five Eyes and beyond are independently arriving at the same conclusion: capability mandates, secret ministerial orders, and metadata retention at scale. Signal would rather leave Canada than comply. Windscribe is looking for the exit. The Cloud Act grew up and moved to Ottawa. The question is where it moves next.
Digital Sovereignty
Surveillance Law
Isle of Man
Five Eyes
Alan Wright
10 June 2026
Three companies. $3.7 trillion. Three weeks. Anthropic filed confidentially on 1 June. OpenAI followed on 8 June. SpaceX lists this Friday. The AI cash-burn race just became the public market's problem — and the bill is going to land somewhere.
Financial Markets
AI Policy
Digital Sovereignty
Isle of Man
Alan Wright
9 June 2026
On 5 June 2026, GitHub disabled 73 Microsoft repositories in 105 seconds. The Miasma worm did not need its victims to run anything. It just needed them to look.
Supply Chain Security
Developer Infrastructure
Agentic AI
Cybersecurity
Alan Wright
8 June 2026
New fast-track index inclusion rules mean trillion-dollar AI flotations become a programmatic mandate for institutional asset managers worldwide. The transmission mechanism runs straight through the Isle of Man's offshore wrapper sector -- and nobody has stress-tested it.
Digital Sovereignty
Capital Markets
Isle of Man
Financial Governance
Alan Wright
3 June 2026
The Isle of Man owns a sovereign subsea fibre cable to the UK mainland. For two years it sat unused while the regulator investigated whether the government was blocking the demand it claimed did not exist.
Digital Sovereignty
Regulatory Affairs
Isle of Man
Infrastructure
Alan Wright
2 June 2026
AI data centres consume tens of thousands of cubic metres of water per day to keep their chips below thermal death point. Kent’s taps ran dry on a bank holiday weekend. The infrastructure debate has been asking the wrong question.
Digital Sovereignty
Infrastructure
EU Policy
Environment
Alan Wright
30 May 2026
When a project becomes the company -- a look back over a year at the digital coalface. From an Easter Monday cardiac event to a sovereign infrastructure consultancy in twelve months.
Infrastructure
Company Building
Digital Sovereignty
Isle of Man
Alan Wright
29 May 2026
CVE-2026-48710 exposes MCP servers through a trivial HTTP Header parsing flaw. But the real story is why patches won't fix it: shadow IT deployments skip the proxy layer because it 'adds complexity.' When digital sovereignty depends on a shrug, you've already lost.
Supply Chain Security
Digital Sovereignty
MCP
Infrastructure
Alan Wright
28 May 2026
A forensic breakdown of documented institutional failure. The real story isn't about ChatGPT -- it's about a municipal authority that chose insurance over hardening, and the strategic consequences.
Critical Infrastructure
Governance
Cybersecurity
Municipal
Alan Wright
27 May 2026
AI is genuinely useful. But there is a difference between using it to make experienced people more productive and using it to avoid developing experienced people in the first place. One is leverage. The other is deficit spending on human capital with a deferred bill.
AI
Society
Isle of Man
Governance
Alan Wright
27 May 2026
Teams rushing to local models to cut token costs are creating worse operational problems without discipline. Here's what actually costs more than the tokens you saved.
Infrastructure
Operations
AI
Governance
Alan Wright
26 May 2026
The FBI has warned about Kali365, a Phishing-as-a-Service kit that doesn’t steal your password or intercept your MFA code. It steals your OAuth token after you complete authentication yourself. The victim is the MFA step.
Cybersecurity
Phishing
Microsoft 365
OAuth
Alan Wright
22 May 2026
Railway.com kept their control plane with Google Cloud after moving workloads elsewhere. Google suspended the account without warning. The EU is replicating this architecture at policy level. Control plane ownership is the real sovereignty question.
Digital Sovereignty
Infrastructure
EU Policy
NIST
Alan Wright
20 May 2026
The Bank of England has been briefing Britain’s financial sector on a threat they cannot defend against. The capability they need is real, verified, and available -- to American companies, under American political control. That is not a technology problem. That is a sovereignty problem.
Cybersecurity
Sovereignty
AI
Governance
Alan Wright
20 May 2026
More than 100 UK data centres are planning to generate their own electricity using on-site gas plant. The Guardian framed it as politics. This piece covers the engineering.
Energy
Infrastructure
Net Zero
AI
Alan Wright
19 May 2026
Anthropic built a subsystem to prevent internal secrets leaking into public commits. Then they accidentally published everything around it. The brake belonged to someone else.
Anthropic
Git
Sovereignty
Governance
Alan Wright
19 May 2026
The NHS Palantir contract is processing special category health data belonging to tens of millions of people. The regulation requires a published, reviewable accountability mechanism before that processing begins. Where is it?
Data Sovereignty
NHS
GDPR
Isle of Man
Alan Wright
18 May 2026
The infrastructure the internet forgot to fund is running on goodwill and spare time. The people holding it together are exhausted. One day, one of them will close their laptop and not open it again.
Open Source
Supply Chain
Sovereignty
Governance
Alan Wright
13 May 2026
Gartner says sovereign cloud is only possible if you are American or Chinese. Europe produces white papers. One operator in Peel runs a genuinely sovereign stack. The question was never capability.
Sovereignty
Cloud
Gartner
Infrastructure
Alan Wright
11 May 2026
The European Commission ordered Google to share its search data. Google’s own scientist showed it could re-identify users in two hours. The Commission is now in a bind of its own making.
EU
Google
Privacy
DMA
Alan Wright
10 May 2026
An AI agent deleted a production database and its backups. It knew the rules. It decided they didn’t apply. Writing constraints down is not the same as enforcing them.
Agentic AI
Governance
Cybersecurity
Alan Wright
10 May 2026
France announced it was reclaiming its digital destiny. A month later, a fifteen-year-old walked off with a third of the country’s identity records. Data residency is not a security posture.
Data Sovereignty
Cybersecurity
Governance
Alan Wright
9 May 2026
A wind farm, a dead radar, and a governance knot nobody wants to unpick. The headline cost is £40 million. The final bill is unknown.
Energy
Infrastructure
Isle of Man
Alan Wright
9 May 2026
Digital Isle of Man’s Data Sovereignty Framework Has No Legal Drive Yet — but sixteen health-tech vendors are already in the building.
Data Sovereignty
Isle of Man
Alan Wright
6 May 2026
Six national cybersecurity agencies just published coordinated guidance on agentic AI. It is more alarming than the headlines suggests.
Agentic AI
Governance
Alan Wright
4 May 2026