Three long-running columns of close reading — how enterprises actually deploy AI, how it is being governed, and the reports worth an afternoon. Filed weekly, with receipts.
A close reading of how Fortune-500 companies actually wire generative AI into the business. Not press releases — architecture, vendor choice, where the money lands.
The new rules, in plain language. EU, UK, Singapore, US state-level. What changed, who has to act, by when, and what it means for a company that is not a hyperscaler.
The reports worth an afternoon, taken seriously at length — on AI, organisations, interaction, and the enterprise. One document per entry. We read the appendices so the argument holds.
Colorado turns decision explanations, human review and protections for minors into operational procedure, the EU’s cloud and AI study feeds lock-in and extraterritorial risk into CADA, the CAC holds publicly available personal information to a reasonable scope, NIST consults on NVD modernization, and Korea updates its CBPR certification standards.
A useful tool is not automatically production-ready. Scenario risk — not tool effectiveness — should decide whether AI runs on public cloud, enterprise SaaS, private or hybrid infrastructure, or sovereign AI, as UiPath moves agentic automation on-premises and SoftBank and Oracle turn sovereign AI into a packaged model-plus-cloud offering.
The EU refines GPAI post-market monitoring and copyright transparency, the UK’s AI Growth Lab brings legal AI under coordinated regulatory consultation, NIST joins the Genesis Mission on industrial agent security, the US keeps outbound AI investment restrictions in force, and Korea and Singapore both pull agents inside existing frameworks.
The EU’s Digital Omnibus pushes high-risk obligations back again, NIST launches a blind testing programme and a data-centre security analysis that extends AI governance to computing infrastructure, Korea eases the clinical evidence pathway for medical AI, and China pushes IPv6 into large-model deployment.
Alibaba.com’s Accio Work builds a seller operating agent and Made-in-China.com’s SourcingAI a buyer procurement agent. Read as deployment chains — data integration, context construction, orchestration, permission control, observability — they show platform budgets shifting from connection efficiency to the capabilities buyers and sellers cannot complete on their own.
The EU’s content-labelling obligations enter application, Singapore’s PDPC explains how the PDPA applies across the generative-AI lifecycle, the UK AI Security Institute finds every evaluated model overstepping task boundaries, the US expands its Genesis Mission research platform, and China eases obligations for small-scale handlers while updating outbound-data rules.
If you want both columns delivered together, four times a year, in one quiet email — leave an address. Otherwise just bookmark this page.