AI governance for regulated firms
Plain-English guidance on AI risk, compliance & trust
SAFE Framework and V.E.R.I.F.Y. Protocol
FCA, SRA, NHS, GDPR, EU AI Act
Your AI agent doesn’t need bad intentions to do something bad. It needs capability, access, and a control environment that fails in the wrong order.
This week I stopped treating that as a theoretical problem and tested it. I built a controlled autonomous-agent environment using Hermes Agent, GPT-5.6 and Docker, preregistered what I expected to happen, and ran two experiments. EXP-001A: the egress control was enabled but unavailable. The agent attempted terminal execution, but the environment failed closed. No Docker sandbox was created. EXP-001B: I deliberately disabled that control.
The sandbox started and the command executed, but the tested OpenAI API key was still absent from the container environment. One control disappeared. Another still held. That is the part I think matters for businesses adopting AI agents. A control marked Enabled is not evidence that it works. And one failed control should not automatically expose everything behind it.
The better questions are: Which control stops which behaviour? What happens when it fails? And what evidence shows the next layer will catch it? I’ve written up the experiment, what passed, what remains untested, and what Anthropic’s recent cybersecurity-evaluation incidents tell us about agent containment, stopping mechanisms and monitoring. Read the full analysis: https://t.co/tKQw8N2ed3
More experiments are coming. I’ll publish the results whether the controls pass or fail.
This Week I Tested the Control Instead of Trusting It. On Monday I said an agent needs no malicious intent to cause harm. It needs a legitimate objective, enough capability, and a control environment that fails in the wrong order. Here is the full story, and something I had not planned to include. https://t.co/TdHxflz5Rt
Your Copilot Cited the Wrong Policy. Who Owns the Decision?
The three things worth checking in your own environment, if you are using Copilot or any assistant against internal documents:
· Can you prove which version of a policy it relied on, not just which document?
· Can you explain why that source was treated as authoritative rather than superseded?
· Can you evidence who reviewed the answer, and what they actually checked?
https://t.co/QGmIzrMFnW
Most firms read "the EU AI Act was delayed" and relaxed.
The part that governs your chatbots, your marketing content and your AI-generated material was not delayed. It's live now, under Article 50.
And here's what most coverage missed: it's not really a labelling problem. It's a contracts problem.
Article 50 splits its duties across two different parties, the provider and the deployer. Chatbot disclosure and content marking fall on the provider. Deepfake labelling and biometric notices fall on the deployer. When your marketing agency uses a vendor's AI tool on your website, who holds which duty? If your contracts don't say, that's your gap, not theirs.
It's also extraterritorial. Serve EU users from the UK and you're in scope, whatever your postcode.
I mapped the four duties and who owns each one.
https://t.co/WlRl5MxdXR
Sources, so you can check rather than take my word for it.
Consolidated text as at 27 July 2026, which is what I read:
https://t.co/VfyeAes5gv
Amending Regulation (EU) 2026/1744:
https://t.co/Xm4lsaQT4A
Article 113 is at the end of the enacting text. Article 5(1)(ba), (bb) and the qualifying paragraphs 1a and 1b are near the start.
I keep a mapping of SAFE and V.E.R.I.F.Y. against ISO/IEC 42001, the EU AI Act, UK GDPR, the FCA Handbook and the DSIT principles, with the source and verification date on every column:
https://t.co/qAiTanbKTo
The EU AI Act timetable has been amended, and it is worth checking your own material against it.
Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July and entered into force on 27 July. Three separate dates, and they get conflated.
What Article 113 now says:
High-risk systems under Article 6(2) and Annex III apply from 2 December 2027, previously 2 August 2026. That is a shift of sixteen months.
High-risk systems under Article 6(1) and Annex I apply from 2 August 2028, previously 2 August 2027. A shift of twelve months.
There is also a new date of 2 December 2026 for two new prohibitions inserted into Article 5. Worth being precise here, because it is being reported loosely: the existing Article 5 prohibitions have applied since 2 February 2025 and are unchanged. What is new is Article 5(1)(ba), covering AI systems that generate or manipulate intimate imagery of an identifiable person without their explicit consent, and Article 5(1)(bb), covering material within the meaning of Directive 2011/93/EU.
Both are qualified by new paragraphs 1a and 1b. Placing on the market is only prohibited where that generation is the intended purpose, or where the system's design makes it a reasonably foreseeable and reproducible outcome without significant technical modification and adequate safeguards are absent. Use is only prohibited where the deployer uses it for that purpose. Those qualifiers matter and almost nobody is discussing them.
Two things worth checking in your own material.
The consolidated text is the easiest way to read the current wording, but it carries no independent legal effect. The authentic instrument is the version published in the Official Journal. Cite accordingly.
And in the final Regulation, post-market monitoring is Article 72 and serious incident reporting is Article 73. Material citing 61 or 62 for those subjects may rest on the 2021 proposal, so it is worth checking which version it was written against.
All of the above is from the consolidated text itself, CELEX 02024R1689-20260727, checked on 11 August 2026. Not from a summary.
Three AI rules that are actually yours this week:
The AI Act deadline that did not move
What the FCA’s AI position really means
The governance gap around AI agents
Read the briefing:
https://t.co/qkXZw2DVXu