PAGES19
WORDS29,760
SOURCES148
READ TIME57 min
TYPEHUB
CHECKED25 AUG 26
What goes wrong when AI systems touch real data, real credentials and real money — and the checks that catch a good deal of it.
The checklist
Ordered so stopping partway still covers the expensive part.
EXPLAINER · 16 MIN · 30 SOURCESWhen Claude Models Reached Real Systems Without Permission: What Anthropic ReportedFour Claude incidents in Anthropic’s own cyber tests and one reported by the UK AI Security Institute: which model, what it reached, the harm and what changed.EXPLAINER · 4 MIN · 4 SOURCESWhat Is Meta’s Sentinel? The Agent That Guards the AgentSentinel is the program Meta put between its Muse agent and the internet. What it checks, how its approval prompts work, and what Meta says it does not fix.REVISED · 4 MIN · 3 SOURCESGrok and the Deepfake Investigations: What Regulators Actually DidThree dated regulator actions in January 2026: California opened an investigation, sent a cease and desist, and the EU opened proceedings over Grok on X.THE CRAFT · 3 MIN · 2 SOURCESA Security Checklist for AI-Built SoftwareSecurity checks for software you did not fully write, in three tiers by what a mistake costs, plus three AI-specific checks standard practice misses.THE RECORD · 3 MIN · 1 SOURCESVibe Coding: What It Is and What It CostsVibe coding is building software by describing it and not reading the result. Where it works, what it costs when it does not, and the line it must not cross.
Injection and boundaries
Fetched content is data. Models cannot reliably tell.
THE CRAFT · 3 MIN · 2 SOURCESAgent GuardrailsFour lines that belong in every agent prompt. Scope, negatives, injection defence and stopping conditions — the permission model tTHE CRAFT · 2 MINPermission Tiers for AgentsFive permission levels for agents, set per task by how hard an action is to undo, not by how far you trust the agent, and why grants should end with the task.THE CRAFT · 3 MIN · 1 SOURCESSkills Are a Supply ChainInstalling a skill loads someone else’s instructions into your agent. An audit of 3,984 published skills found 13.4% had a critical flaw and 76 were malicious.
Site data: each card restates the page it links to, where the figure is sourced and quoted; cards checked against those pages 23 Sep 2026.
Verification
Checking output, checking vendors, and knowing when to stop.
THE RECORD · 3 MIN · 1 SOURCESAuditing AI-Generated WorkChecking everything is not a strategy. Four risk tiers with a different check for each, the signals worth looking for, and a monthly review of your own use.THE RECORD · 3 MIN · 3 SOURCESAuditing a Vendor’s AI ClaimsEvery demo works; that is what a demo is. Questions that separate a product from a demo, what to ask about accuracy figures, and answers that end the call.THE RECORD · 3 MINThe Cost of Checking Too MuchEverything says check more. Almost nothing says where checking stops paying. Review theatre, uniform attention, and the failure noTHE CRAFT · 2 MINDiagnosing a Run That Went WrongThe agent finished and the output is wrong. How to find the first wrong step in the transcript rather than its consequences, and the failure signatures to spot.
Fraud and fakes
What the same tools do in the wrong hands.
EXPLAINER · 6 MINHow AI Fraud Actually WorksSeven specimens of AI-assisted fraud, pinned and annotated: the cloned executive, the deepfake video call, the fake job…THE RECORD · 6 MIN · 4 SOURCESDeepfake Self-DefenceVoice clones need about three seconds of audio. Sourced, dated, and revised when the numbers move.THE RECORD · 1 MINSPOT FAKE IMAGES & VIDEOWhat still gives away AI-generated images, video and cloned voices in 2026 — and why the visual tells are disappearing…THE RECORD · 6 MIN · 1 SOURCESHOW TO SPOT AI WRITINGNine reliable signals of AI-generated text, why detector tools cannot be trusted to accuse anyone, and what to do…
Your own data
What leaves, and where it goes.
THE RECORD · 4 MIN · 2 SOURCESWHAT HAPPENS TO WHAT YOU TYPERetention, training, human review and whose data it legally is — four separate questions people collapse into one.DATED · 7 MIN · 13 SOURCESTHE RULES ARRIVINGThe EU AI Act became broadly applicable on 2 August 2026. What changed, when, and what it actually means.THE RECORD · 4 MIN · 3 SOURCESTHE HOUSEHOLD GUIDEA printable one-page guide to protecting your household from voice-cloning and deepfake scams: a family code word, hang up and call back, and the warning signs.