<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Andrew Milroy]]></title><description><![CDATA[Technology analyst and commentator.]]></description><link>https://andrewmilroy1.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!RDhn!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34a8b23b-de8b-42ac-a100-baf5ed90f55d_2523x2523.jpeg</url><title>Andrew Milroy</title><link>https://andrewmilroy1.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 02 Sep 2026 13:09:52 GMT</lastBuildDate><atom:link href="/__u/andrewmilroy1.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Andrew Milroy]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[andrewmilroy1@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[andrewmilroy1@substack.com]]></itunes:email><itunes:name><![CDATA[Andrew Milroy]]></itunes:name></itunes:owner><itunes:author><![CDATA[Andrew Milroy]]></itunes:author><googleplay:owner><![CDATA[andrewmilroy1@substack.com]]></googleplay:owner><googleplay:email><![CDATA[andrewmilroy1@substack.com]]></googleplay:email><googleplay:author><![CDATA[Andrew Milroy]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Microsoft’s Agentic AI Governance Paradox]]></title><description><![CDATA[Microsoft assessed against Veqtor8&#8217;s ten principles for independent AI governance]]></description><link>https://andrewmilroy1.substack.com/p/microsofts-agentic-ai-governance</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/microsofts-agentic-ai-governance</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Thu, 27 Aug 2026 02:15:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OIQU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!OIQU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 424w, /__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 848w, /__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 1272w, /__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!OIQU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif" width="1170" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105675,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/212937135?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 424w, /__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 848w, /__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 1272w, /__u/substackcdn.com/image/fetch/$s_!OIQU!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4101a675-112b-4beb-a9d8-9d2a9c3b03f5_1170x780.avif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Agentic AI governance is becoming a regular part of my conversations with large enterprises and Microsoft features in almost all of them. This is not surprising given that Microsoft is so deeply embedded in enterprise IT architecture. It is now extending its position into agentic AI with a growing set of capabilities for discovering, securing and governing agents.</p><p>Veqtor8 published ten principles for independent agentic AI governance in May 2026. They were developed from a series of AI governance workshops and ongoing discussions with enterprises which are adopting agentic AI products and services. The principles cover the operational governance of agents, but also the need for independent oversight across platforms, models, data sources and workflows.</p><p>Microsoft provides an interesting case against which to consider those principles. Its governance capabilities are extensive, particularly around agent identity, ownership and operational control. At the same time, Microsoft is both a major provider of the agentic AI environment and a provider of the tools used to govern it.</p><p>This creates an interesting paradox. The more an enterprise uses Microsoft to manage and govern its agents, the more its governance depends on the same platform it is trying to oversee.</p><p>I have used the ten principles here to take a closer look at Microsoft&#8217;s approach. It draws primarily on discussions with enterprises, including their experiences with Microsoft. Product information and analyst briefings are also used to understand the Microsoft capabilities discussed.</p><p><strong><span>The ten principles</span></strong></p><ol><li><p><strong>Architectural independence.</strong> The governance layer operates above the platform estate as continuously running infrastructure, accountable to none of the platforms it observes.</p></li><li><p><strong>Governance for operational excellence and resilience.</strong> Governance exists to make the enterprise better run and remains available if any platform in the estate becomes unavailable.</p></li><li><p><strong>Data portability and sovereignty.</strong> Governance evidence is owned by the enterprise, held in formats it controls, and producible to an auditor without any vendor&#8217;s cooperation.</p></li><li><p><strong>Data governance as a foundation.</strong> Unified cataloguing, classification, lineage, quality monitoring and semantics that hold their meaning across platforms.</p></li><li><p><strong>Federated architecture.</strong> Signals are ingested from any platform, normalised into a common governance model and presented as one view.</p></li><li><p><strong>Reduced vendor concentration.</strong> Governance avoids recreating the concentration risk it seeks to manage.</p></li><li><p><strong>Cyber and identity governance across machine boundaries.</strong> Consistent identity tracking for people, agents, workflows, service principals and model-to-model connections, including across platform boundaries.</p></li><li><p><strong>Continuous cross-platform auditability.</strong> Evidence is captured as activity occurs, including what crossed a boundary, under whose authority and in what governance state.</p></li><li><p><strong>Agent accountability and ownership.</strong> Every agent carries a named owner, an authorisation record, defined operational limits and a decommissioning process.</p></li><li><p><strong>Independent quantification of AI risk and value.</strong> Risk and return are measured using sources with no financial interest in the answer.</p></li></ol><p><strong><span>Microsoft&#8217;s agentic governance stack</span></strong></p><p>Microsoft has assembled a broad set of capabilities for governing agents. Agent 365 provides an agent registry, maps activity and connections, and works with Microsoft Defender and Microsoft Purview for security and governance. Entra Agent ID gives agents identities, access policies, lifecycle management and scoped permissions.</p><p>Defender provides runtime security controls, while Purview provides classification, data protection and compliance capabilities. Microsoft IQ brings together organisational context, structured business data and semantics, enterprise knowledge and external information.</p><p>These capabilities address issues raised repeatedly in enterprise discussions. Organisations need to understand the agents in use, accountability for those agents, their access, their activities, their value and their cost.</p><p><strong><span>Microsoft assessment against the 10 principles</span></strong></p><p>I have assessed Microsoft against each of the ten principles, based primarily on enterprise feedback and analysis of Microsoft&#8217;s current capabilities. The results fall into three groups<span>.</span></p><blockquote><p><span>&#183; </span><strong>Strong alignment: </strong>Agent accountability and ownership, cyber and identity governance across machine boundaries, and data governance as the foundation.</p><p><span>&#183; </span><strong>Mixed alignment: </strong>Federated architecture, continuous cross-platform auditability, and independent quantification of AI risk and value.</p><p><span>&#183; </span><strong>Limited alignment: </strong>Architectural independence, governance for operational excellence and resilience, data portability and sovereignty, and reduced vendor concentration.</p></blockquote><p><strong><span>Strong alignment</span></strong></p><p><strong><span>Agent accountability and ownership</span></strong></p><p>Ownership is one of the first problems enterprises encounter as agent numbers grow. Organisations need visibility across all agents, an understanding of agent accountability, their permissions and their costs.</p><p>Agent 365 addresses much of this within the Microsoft environment. Its registry can include Microsoft-built, partner, synced and self-registered external agents. Sponsorship provides named accountability and lifecycle management supports decommissioning. Per-user rather than per-agent licensing also means governance licensing does not rise directly with every additional agent.</p><p><strong><span>Cyber and identity governance across machine boundaries</span></strong></p><p>Identity becomes more difficult as agents act on behalf of people, call tools, interact with other agents and move between systems.</p><p>Entra Agent ID gives agents identities and applies access policies and permissions to them. This provides a strong accountability chain within the Microsoft environment. Once an agent crosses into another platform, however, the end-to-end record also depends on identity controls and telemetry from that environment.</p><p><strong><span>Data governance as an agentic AI governance foundation</span></strong></p><p>Data governance comes up consistently in enterprise discussions. Organisations need to control the data agents can access and ensure they work from consistent business definitions.</p><p>Fabric IQ combines data accessible through OneLake with semantic models and ontologies covering business entities, relationships, rules and actions. Its coverage depends on data being accessible through OneLake. Shortcuts can provide zero-copy access to some external data held in supported open formats, while operational databases and many other enterprise systems use mirroring or ingestion.</p><p>Large enterprises typically operate across ERP systems, SaaS applications, operational databases, mainframes and multiple analytical platforms. Fabric IQ provides governance and semantics across data made available through Fabric. The enterprise requirement extends across the wider data estate.</p><p><strong><span>Mixed alignment</span></strong></p><p><strong><span>Federated architecture</span></strong></p><p>Organisations generally expect their agent estates to include several platforms. Agent 365 can include partner, synced and self-registered external agents, giving enterprises a broader view of their agent estate.</p><p>Microsoft can provide a broader view of the agent estate, but that view is based on Microsoft&#8217;s governance model and telemetry, and the depth of information may differ between Microsoft and third-party agents. The Veqtor8 principle goes further, calling for signals from all platforms to be brought together and normalised into a common enterprise governance model, rather than viewed through the governance model of one platform provider.</p><p><strong><span>Continuous cross-platform auditability</span></strong></p><p>Enterprises need to reconstruct what an agent did after an unexpected outcome, security incident or regulatory investigation. Microsoft provides extensive logging and audit capabilities within its environment.</p><p>Cross-platform workflows are harder. Establishing what data moved, who authorised the action, which controls applied and what actions followed depends on evidence from every environment involved.</p><p>This is an industry-wide challenge. Enterprises need a continuous audit trail that follows the agent across platform boundaries.</p><p><strong><span>Independent quantification of AI risk and value</span></strong></p><p>Enterprises are struggling to measure the economics of agentic AI consistently. They can usually identify productivity improvements, faster processes and increased capacity. Few can consistently connect the cost of individual agents with the financial value they create.</p><p>Microsoft provides detailed cost and usage information across its services, with reporting available at model and deployment level and finer attribution to individual agents and sessions still developing. This gives enterprises a reasonable basis for managing the economics of Microsoft-based agents.</p><p>A major challenge emerges when agents operate across multiple platforms. Enterprises need to bring cost, risk and outcomes together across the whole agent estate and measure them consistently against their own business objectives.</p><p>Vendor evidence can provide useful benchmarks, but enterprises ultimately need their own independent measures of agent cost, risk and value.</p><p><strong><span>The limits of platform-native governance</span></strong></p><p>Platform-native governance has a natural boundary. It can provide deep control and visibility inside the platform, but it cannot independently oversee the platform itself.</p><p>Microsoft has assembled a substantial governance stack for agents operating in its environment. The remaining four principles are harder to meet through a platform-native model because they require some separation between the governance layer and the platforms it oversees.</p><p><strong><span>Architectural independence</span></strong></p><p>Microsoft provides an integrated governance environment for its agents, drawing on capabilities across Agent 365, Entra, Defender and Purview. This gives enterprises strong visibility and control over agents operating within the Microsoft environment.</p><p>The limitation is structural. Microsoft is both a provider of the agentic AI environment and a provider of the governance used to oversee it. Independent governance requires an additional layer of oversight that does not depend on Microsoft, or any other platform provider, for its operation or evidence.</p><p><strong><span>Governance for operational excellence and resilience</span></strong></p><p>Microsoft provides strong operational governance for agents within its environment. This helps enterprises manage agent performance, security and control as deployments scale.</p><p>Independent governance adds resilience by ensuring that oversight does not depend entirely on the platforms being governed. It also gives the enterprise continuity of governance across a wider, multi-platform agent estate.</p><p><strong><span>Data portability and sovereignty</span></strong></p><p>Enterprises need control over governance evidence for audits, investigations, regulatory requirements and platform changes. Microsoft provides governance information across services including Purview, Defender, Agent 365 and Azure Cost Management, with capabilities to access and export that information.</p><p>Microsoft also provides extensive data residency and sovereign cloud capabilities. The Veqtor8 framework adds a separate requirement for governance evidence to remain under enterprise control and portable across platforms, rather than dependent on any one platform provider.</p><p><strong><span>Reduced vendor concentration</span></strong></p><p>Agentic AI brings models, data, identity, security, runtime and governance closer together. Microsoft can provide capabilities across all of them. For enterprises already heavily invested in Microsoft, this can simplify deployment and operation.</p><p>It can also increase dependency on a single technology and commercial ecosystem. Agent 365, Entra, Defender, Purview and Fabric can all form part of the same environment. Independent governance provides some separation from that environment, helping enterprises oversee concentration risk rather than making governance itself another source of it.</p><p><strong><span>Implications for enterprises</span></strong></p><p>Most enterprises running Microsoft agents have good reasons for using Microsoft&#8217;s governance capabilities. They provide agent inventory, identity, security and operational controls that organisations would otherwise have to build or source elsewhere.</p><p>The assessment also shows the limits of relying on platform-native governance alone. Microsoft can extend governance to third-party agents and environments, but that oversight is still provided through Microsoft&#8217;s governance stack. As agent estates spread across multiple platforms, enterprises also need oversight that is independent of any one platform provider.</p><p>Four practical steps follow.</p><ul><li><p>Use platform governance for operational control and independent governance for enterprise oversight. Microsoft provides extensive controls across its own environment and can extend oversight to third-party agents. Independent governance provides a separate view across the wider estate.</p></li><li><p>Maintain accountability across platform boundaries. Enterprises need to follow agent identity, ownership, permissions and activity as agents interact with other platforms, tools and data sources.</p></li><li><p>Retain governance evidence continuously. Establish what information can be extracted from each platform, at what level of detail and with what delay.</p></li><li><p>Measure risk and value independently. Vendor evidence can provide useful reference points, but enterprises need to measure costs, outcomes and risks against their own business objectives.</p></li></ul><p><strong><span>The paradox remains</span></strong></p><p>Microsoft&#8217;s governance capabilities are valuable, particularly for agent identity, ownership, security and operational control within its environment. Its support for third-party agents gives it a broader reach than a system limited to Microsoft-built agents.</p><p>The constraint sits at the boundary of the platform rather than in any shortfall of capability. The enterprises I speak to expect agents to operate across multiple platforms, models, data environments and workflows. No platform-native governance layer can, by itself, provide a complete and independent view of that estate.</p><p>As Microsoft&#8217;s agentic governance capabilities expand, enterprises may choose to place more agents, and more of the evidence used to oversee them, inside Microsoft. That may make operational sense, but the resulting increase in dependence on Microsoft needs to be understood and actively managed.</p><p>Agentic AI needs two layers of governance. Platform-native governance keeps each environment operating safely, while independent governance lets the enterprise decide for itself whether an agent earns its keep, its trust and its budget.</p><p><em>Andrew Milroy is the founder of Veqtor8, an independent technology advisory firm focused on AI, cybersecurity, cloud and data management.</em></p><p><em>This article reflects the author&#8217;s opinion and analysis based primarily on enterprise research and professional conversations, supported by publicly available product information and vendor briefings. It is not legal, regulatory or investment advice.</em></p>]]></content:encoded></item><item><title><![CDATA[The Industrialisation of Judgement]]></title><description><![CDATA[Observability and governance as AI moves from reasoning to autonomous action]]></description><link>https://andrewmilroy1.substack.com/p/the-industrialisation-of-judgement</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/the-industrialisation-of-judgement</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Tue, 18 Aug 2026 07:35:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CpPQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!CpPQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!CpPQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg" width="1024" height="1137" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1137,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/211650125?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!CpPQ!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ead1f22-c07d-4354-9623-10caaf901c5e_1024x1137.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>More than two thousand years ago, Aristotle distinguished practical wisdom from the application of universal rules. His concept of phronesis recognised that some decisions cannot be resolved by rules alone because circumstances require judgement. Enterprises now wrestle with the same issues. LLMs give enterprises an ability to interpret ambiguity and compare alternatives. In effect, judgement is being industrialised.</p><p>Enterprises I speak with are benefitting from the use of agentic AI often for the simple reason that it goes beyond deterministic rules-based automation. They find it to be particularly useful when a business problem requires judgement and cannot be addressed using a fixed set of rules alone.</p><p>They run into problems when probabilistic AI (LLMs) is used in critical processes. For example, decisions involving financial, security or customer consequences cannot rely solely on probabilistic reasoning. Deterministic boundaries are needed around the decisions and actions that follow. The solution requires finding the right balance between deterministic and probabilistic controls. The greater the consequence of an AI action, the stronger the case for deterministic controls around probabilistic reasoning.</p><p><strong>Balancing deterministic and probabilistic controls</strong></p><p>Each stage of agentic activity requires a different degree of judgement and control. An agent typically needs freedom to interpret an ambiguous situation whereas the data it accesses and the actions it takes need to be tightly controlled.</p><p>I separate agentic activity into five stages. The stages are Observe, Reason, Decide, Act and Handoff.</p><ul><li><p><strong>Observe</strong> covers the information available to the agent. Access controls, identity, data classifications and sovereignty requirements typically provide deterministic boundaries around that access.</p></li><li><p><strong>Reason</strong> is where probabilistic AI has an obvious role. An agent often interprets information, assesses alternatives and addresses circumstances that were not anticipated when the system was developed.</p></li><li><p><strong>Decide</strong> sits between judgement and control. Some decisions can remain probabilistic, while others need, for example, policy checks, confidence thresholds or human approval.</p></li><li><p><strong>Act </strong>covers authority. Probabilistic reasoning informs an action, but its execution must be bounded by deterministic controls such as financial limits, permissions, and escalation thresholds.</p></li><li><p><strong>Handoff </strong>is different from the other stages because it crosses a boundary. It covers the transfer of an output to another entity like another agent or a human. The output contains probabilistic judgement, but the conditions governing its transfer and subsequent use should be deterministic.</p></li></ul><p>A failed payment is a great example that most people experience and understand. An agent which investigates a failed payment combines a range of signals such as transaction information and customer history before deciding whether fraud, insufficient funds or a technical problem is the most likely explanation. Deterministic controls then govern action in this example. The system checks things like the payment location, payment time, payment size, balance and so forth. A high-value transaction requires additional verification, while a refund could be limited to a fixed amount or require human approval.</p><p>The agent is therefore allowed to interpret the evidence, but it does not have unlimited authority to act on its conclusion. The judgement in this case is probabilistic and the controls around the resulting decision are deterministic. I hear you say that these checks are just conventional automation and not AI. That is true. The key point here is that enterprise systems do not need to use probabilistic AI for every part of an agent&#8217;s journey.</p><p><strong>Handoff and orchestrating agents</strong></p><p>Handoff becomes more important when agentic processes require the orchestration of multiple agents. Think of a customer experience process where deterministic AI, probabilistic AI and humans all interoperate. One agent&#8217;s &#8216;Act&#8217; becomes another agent&#8217;s &#8216;Observe&#8217;. An output generated through probabilistic reasoning passes to a second agent, which reasons on that output before passing its conclusion elsewhere. Uncertainty propagates through the system, often followed by something more dangerous, namely authority.</p><p>Consider three agents managing suspected fraud. The first analyses customer activity and concludes that a transaction is probably fraudulent. A second receives that conclusion and decides that the account should be restricted. A third initiates communication with the customer. Each agent may behave reasonably in isolation, but the chain creates two different governance risks.</p><p>The first is epistemic risk which means the risk of an agent treating an uncertain conclusion as established fact. In a customer service process, one agent may conclude that a customer is likely to cancel based on their recent interactions. If that conclusion passes to another agent as a fact rather than a probability, the uncertainty is lost even though the evidence has not changed. The second agent may then make the wrong decision based on something it believes to be a fact.</p><p>The second is authority risk. One agent may recommend that a customer&#8217;s account is suspended because it suspects fraud. If the next agent treats that recommendation as an instruction and suspends the account, a recommendation has become an action without the required control in between. If this risk is not managed effectively by financial services firms, a lot of people will find themselves locked out of their accounts unnecessarily.</p><p>Handoff should therefore be treated as a governance control point rather than the movement of information between two agents. For higher-risk activities, at least six features must travel with the output:</p><ul><li><p><strong>Identity.</strong> The agent responsible for the output and the party on whose behalf it acted.</p></li><li><p><strong>Provenance.</strong> The information, sources and tools used to produce the output.</p></li><li><p><strong>Classification.</strong> Categorise the outputs as fact, inference, recommendation or instruction.</p></li><li><p><strong>Uncertainty.</strong> The level of confidence associated with the output.</p></li><li><p><strong>Authority.</strong> The scope of the originating agent&#8217;s authority to decide, recommend or request action.</p></li><li><p><strong>Permitted use.</strong> The actions the receiving agent is authorised to take in the context of the output.</p></li></ul><p>NIST&#8217;s National Cybersecurity Center of Excellence concept paper, Accelerating the Adoption of Software and AI Agent Identity and Authorization, is useful because it considers agents as non-human identities and examines how established technologies including OAuth 2.0, and OpenID Connect can be applied to agent identification and authorisation. As agents begin acting for people, applications and other agents, identity needs to carry authority rather than simply a name.</p><p>Handoff also means that each stage of agentic activity should not be read as a linear process that ends after an action. The output of one agent becomes the information observed by another. Governance must survive that transition.</p><p><strong>Calibrating deterministic control</strong></p><p>The appropriate balance between probabilistic reasoning and deterministic control varies massively by use case. This means that the stages of agentic activity need to be accompanied by a decision risk assessment based on four characteristics.</p><ul><li><p><strong>Consequence.</strong> This relates to the potential impact of getting a decision wrong. For example, this can range from a poor internal summary to a material financial loss.</p></li><li><p><strong>Uncertainty.</strong> This is the amount of judgement required to reach a decision. If inputs and outcomes are clear, there may be little value in probabilistic reasoning. Greater uncertainty increases the value of judgement, but also the need to understand and manage it.</p></li><li><p><strong>Reversibility.</strong> This means the extent to which an action can be undone. A recommendation can be rejected, and system changes can be rolled back. Money transferred, information disclosed or commitments made externally are usually harder to reverse.</p></li><li><p><strong>Autonomy.</strong> This represents the degree to which the agent can act without human involvement. There is a big difference between recommending an action and executing it. As autonomy increases, so does the need for effective controls at runtime.</p></li></ul><p>Consequence relates to the impact of an action. Restarting a service is typically routine if it is isolated and easily recovered. The same action has a much larger impact if other critical services, customer journeys or business processes depend on it. This makes dependency context important. An agent needs some understanding of the wider environment and the potential impact of the changes it makes. A rule allowing an agent to restart a particular type of service is usually deterministic, but the consequences of doing so are not fixed. They change with the dependencies.</p><p>The purpose of a decision risk assessment is to establish the appropriate balance of probabilistic reasoning, deterministic control, human involvement and runtime assurance.</p><p><strong>Singapore sets the pace</strong></p><p>Singapore&#8217;s Infocomm Media Development Authority (IMDA) first published its Model AI Governance Framework for Agentic AI in January 2026, describing it as a first-of-its-kind framework for the reliable and safe deployment of agentic AI. On 20 May, following industry feedback, IMDA updated it with guidance covering multi-agent systems, third-party agents and automation bias. This effectively addresses the handoff and authority challenges described above. The framework is organised around assessing and bounding risks upfront, making humans accountable, implementing technical controls throughout the agent lifecycle, and enabling end-user responsibility through transparency and training.</p><p>These are more operational concerns than many of the principles that characterised the first phase of AI governance. An organisation can have excellent statements on responsible AI and still deploy an agent with too much access, too much authority or an inadequate mechanism for human intervention. Once AI can act, governance must deal with events triggered at runtime.</p><p><strong>Observability becomes a governance requirement</strong></p><p>Traditional observability has been extremely good at determining if technology is working and helping identify the causes of failures. Agentic AI creates the possibility that every technical component can work correctly while the overall outcome is still wrong.</p><p>For example, a customer&#8217;s account is suspended because one agent incorrectly interprets another agent&#8217;s fraud recommendation as an instruction. The models respond, the APIs work and the workflow completes as designed. The failure is caused by the decision and the authority to act on it.</p><p>Observability in an agentic environment therefore needs to follow the decision across the workflow, covering the agent&#8217;s identity, the context it used, the decisions it made, the actions it took and the handoffs that followed.</p><p>Dependency intelligence becomes particularly important once agents can act. Knowing that an agent restarted a service needs to be complemented by intelligence that records which applications, infrastructure and business processes depended on that service at the time. Reliable autonomous action requires a current model of the environment and its dependencies.</p><p>The agent&#8217;s working context is another part of the evidence. Instructions, retrieved data, previous interactions and tool outputs all influence behaviour. This visibility exposes unnecessary retrieval, repeated model calls and excessive retries. Importantly for those that are concerned with token costs, it also exposes behaviour that makes an agent operationally successful but economically inefficient. Observability in an agentic environment, provides evidence about autonomous behaviour.</p><p><strong>The expanding governance boundary</strong></p><p>The OWASP Top 10 for Agentic Applications 2026 shows how the governance surface is expanding as agents gain access to more tools and systems. OWASP&#8217;s MCP guidance highlights risks including tool poisoning, prompt injection, excessive delegated permissions and supply-chain compromise. OWASP has also highlighted the risk of rogue agents attracting sensitive tasks by claiming capabilities they do not legitimately possess.</p><p>The governance perimeter cannot therefore stop at the agent. It needs to encompass the identities, permissions, tools and systems that the agent can access.</p><p>Regulation is moving in a similar direction. The EU AI Act reinforces the need for evidence around system behaviour through requirements covering areas such as logging and human oversight. Singapore, NIST, OWASP and the EU approach the problem differently, but they indicate that we can expect a broader governance requirement as AI becomes more autonomous.</p><p><strong>Govern, Operate and Assure</strong></p><p>I have previously argued that effective AI governance works across three connected activities. Agentic AI makes the relationship between them much tighter.</p><p>Under <strong>Govern</strong>, the decision risk assessment establishes the risk associated with a decision, while the stages of agentic activity establish if probabilistic reasoning is appropriate and if deterministic controls, human approval or other restrictions are required.</p><p>Under <strong>Operate</strong>, agents work within those boundaries. Identity, data access, policy enforcement, tool permissions, runtime controls, and observability must work together. Platforms combining observability, live dependency intelligence, AI reasoning and autonomous remediation can use operational context both to inform an agent&#8217;s decision and to constrain the set of actions available to it.</p><p>Under <strong>Assure</strong>, organisations need evidence that the controls established under &#8216;Govern&#8217; continue to work while the agents operate. Reconstruction needs to go further than replaying a decision record. Dependencies change, services degrade or upstream systems produce unusual results. Assurance benefits from reconstructing both the agent&#8217;s decision and the operational context in which it was made. If assurance is expected to have some independence from the systems being assured, agent telemetry should be available through open instrumentation and telemetry standards rather than being inseparable from a proprietary platform.</p><p>This is critical as platforms move beyond observing and analysing systems towards taking autonomous remedial action themselves. A platform combining rich telemetry with current dependency intelligence is well placed to identify a problem, understand its likely impact, reason about possible responses and resolve it.</p><p>It also changes the assurance architecture. A platform that exercises autonomous control is not automatically a sufficient source of evidence that the control is exercised correctly. If an agent suspends a customer&#8217;s account because of suspected fraud, the organisation needs evidence showing why the decision was made and if the agent acted within its authority. For higher-risk decisions, independent assurance is needed to establish that the agent remained within its governed boundaries.</p><p><strong>Governing probability</strong></p><p>Multi-agent systems make &#8216;Handoff&#8217; important because one agent&#8217;s action becomes another agent&#8217;s context. Provenance, uncertainty and authority need to survive that transition. In a customer service process, an agent&#8217;s assessment that an account may be fraudulent must not become an instruction to suspend it simply because it has passed to another agent. Without effective controls, uncertainty can become fact and a recommendation can become an action, leaving customers unnecessarily locked out of their accounts.</p><p>Observability is therefore becoming part of the evidence architecture that makes governance credible, providing the runtime and historical evidence needed to establish whether autonomy remains within governed boundaries.</p><p>Aristotle&#8217;s insight remains relevant. Judgement is necessary precisely because rules cannot anticipate every circumstance. The governance challenge is to put the right rules around judgement, and to retain enough evidence to establish that those boundaries hold when the system acts.</p><p><em>This article is based on my own analysis and the agentic AI governance frameworks I have developed through my work at Veqtor8. I used AI tools during research, drafting and editing to test arguments, explore alternatives and improve clarity.</em></p>]]></content:encoded></item><item><title><![CDATA[Open-Weight Models, Governance, and Europe's AI Opportunity]]></title><description><![CDATA[In March 1940, two refugee physicists working at the University of Birmingham in the UK altered the course of modern history.]]></description><link>https://andrewmilroy1.substack.com/p/open-weight-models-governance-and</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/open-weight-models-governance-and</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Wed, 08 Jul 2026 14:16:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-Odj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!-Odj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!-Odj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4684940,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/206052770?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!-Odj!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ded14ed-50f1-4434-9819-c0cc7a7c3f90_5000x5000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>In March 1940, two refugee physicists working at the University of Birmingham in the UK altered the course of modern history. Otto Frisch and Rudolf Peierls demonstrated that an atomic bomb was not only a theoretical possibility but also an engineering challenge that could be solved. Their memorandum became the foundation of the Manhattan Project, which demonstrated that scientific discovery and industrial capability are not the same thing.</p><p>For more than two centuries Europe repeatedly occupied the scientific and engineering frontier. Alan Turing established many of the theoretical foundations of computing. Tommy Flowers built Colossus, the world&#8217;s first large-scale programmable electronic computer. Frank Whittle pioneered the jet engine. CERN created the World Wide Web. European engineers developed GSM, the communications standard that connected billions of people, while ARM&#8217;s processor architecture went on to power much of the world&#8217;s digital infrastructure. Today, ASML occupies an indispensable position in advanced semiconductor manufacturing.</p><p>This is not an argument that Europe invented everything, nor that the United States only commercialised the work of others. Indeed, the United States produced major scientific breakthroughs of its own. The point is that Europe has repeatedly demonstrated an exceptional capacity for scientific discovery and engineering innovation, while the United States consistently excels at attracting global talent, mobilising capital and converting technological breakthroughs into industrial and geopolitical advantage.</p><p>History teaches us that technological leadership has never depended upon invention alone. Instead, it often depends on the ability to convert invention into sustained economic capability and comparative advantage.</p><p><strong>AI Shifts Global Power Dynamics</strong></p><p>AI represents a remarkable historical reversal. Since the beginning of the Industrial Revolution, Europe has generally found itself at, or close to, the technological frontier. Sometimes the United States commercialised European innovation more effectively. Sometimes Asian economies industrialised it more efficiently. Yet Europe usually began from a position of technological leadership. For perhaps the first time in more than two centuries, Europe enters a general-purpose technology revolution without leading the underlying technological breakthrough.</p><p>Every major technology passes through distinct phases. Scientific discovery is followed by industrialisation, industrialisation by commercialisation, commercialisation by standardisation and eventually by widespread adoption throughout the economy. Each phase rewards different capabilities. The countries that generate the greatest long-term economic value are not always those responsible for the original breakthrough. More often, they are those that create the institutions, infrastructure and markets through which new technologies become productive.</p><p>There is little reason to believe AI will be different, but few see it this way. Instead, the focus tends to be on the latest frontier model. Governments and enterprise alike demonstrate what can be described as a frontier model mindset. Success is measured by benchmark scores, reasoning capability and the release cadence of the largest foundation models. These metrics are important, but they obscure a more important question. Where will most economic value be created? The answer is unlikely to be inside frontier laboratories.</p><p><strong>Open-Weight Models Change the Economics of Dependence</strong></p><p>The overwhelming majority of GDP is generated by organisations whose competitive advantage has little to do with solving frontier scientific problems. Their objective is to improve productivity, reduce costs, strengthen customer engagement, improve decision-making and automate routine work. For these organisations, the difference between the world&#8217;s best model and a model that is simply good enough is often much less significant than the ability to deploy AI securely, govern it effectively and integrate it into existing business processes. For most organisations, AI is a productivity technology rather than a scientific endeavour.</p><p>As open-weight models improve, organisations will increasingly discover that they can achieve almost all the value they require without relying on externally hosted frontier models. The strategic significance of open-weight models, such as Mistral, is that they separate intelligence from dependence. They allow countries and enterprises to build capable AI systems without relying on continuous access to foreign-owned AI services. Governments, defence organisations, healthcare providers and operators of critical infrastructure are unlikely to base their long-term strategies upon permanent reliance on externally controlled foundation models, regardless of how capable those models become. Their priority will increasingly be operational control, resilience, auditability and sovereignty.</p><p>This is perhaps the most important strategic issue Europe has yet to fully embrace. AI sovereignty does not require ownership of every layer of the AI stack. It requires sufficient control over the layers that are most important to economies. Europe does not need to replicate OpenAI to reduce strategic dependence upon the United States. It needs the ability to deploy capable open-weight models within European infrastructure, governed by European institutions, integrated with European enterprise software and operating upon European data. Such an approach would not eliminate dependence on foreign technologies entirely, particularly in areas such as advanced semiconductors, but it would materially reduce dependence on externally controlled AI services while giving Europe much greater strategic autonomy.</p><p><strong>Governance Is Industrial Infrastructure</strong></p><p>Governance is often presented as Europe&#8217;s weakness because it is assumed to constrain innovation. That interpretation misunderstands its role within technological revolutions. Railways depended upon standards. Financial markets depended upon regulation. The internet depended upon common protocols and trusted institutions. Artificial intelligence will require governance not because governments wish to regulate innovation, but because enterprises will only deploy AI at scale when they trust the environment within which it operates. Governance therefore becomes economic infrastructure. It creates the trust, predictability and interoperability that allow AI to move from experimentation into production and eventually into everyday economic activity.</p><p>The geopolitical environment reinforces this conclusion. Export controls on advanced semiconductors, restrictions on access to frontier models and proposals for closer government involvement in leading AI companies all point in the same direction. AI is increasingly regarded as strategic national infrastructure.</p><p><strong>Building Europe&#8217;s Sovereign AI Economy</strong></p><p>Europe therefore faces a strategic choice. Its objective should not be technological autarky as complete independence is neither realistic nor economically desirable. The objective is strategic autonomy across the layers of the AI stack that are most important to governments, enterprises and critical infrastructure. It can define success by attempting to win the frontier model race against countries that currently possess overwhelming advantages in capital, hyperscale infrastructure and platform ecosystems, or it can recognise that the next phase of competition may reward different strengths. If the vast bulk of economic activity can be supported by capable open-weight models deployed within trusted sovereign environments, then Europe&#8217;s greatest opportunity lies not in building the single most capable model on earth but in becoming the world&#8217;s most productive AI economy.</p><p>That objective is entirely consistent with Europe&#8217;s historical strengths. The continent has long excelled in engineering, enterprise software, industrial systems, standards and governance. AI may finally provide an opportunity to combine those capabilities into a coherent industrial strategy that reduces strategic dependence while creating new economic value.</p><p>For more than two centuries Europe repeatedly produced scientific breakthroughs that others industrialised and commercialised. AI may require Europe to complement its tradition of innovation with an equally strong focus on industrialisation, sovereign infrastructure and enterprise deployment. The countries that define the next phase of technological leadership will not necessarily be those that build the most capable model. They are more likely to be those that build the most productive AI economies. This gives Europe huge opportunities to lead in core pillars of the AI economy. </p>]]></content:encoded></item><item><title><![CDATA[Enterprise AI Enters Its Bill Shock Era]]></title><description><![CDATA[Most enterprise AI bill shock comes from weak governance, not bad models]]></description><link>https://andrewmilroy1.substack.com/p/enterprise-ai-enters-its-bill-shock</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/enterprise-ai-enters-its-bill-shock</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Tue, 23 Jun 2026 10:39:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2VXF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!2VXF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!2VXF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1914559,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/203227037?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2VXF!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94fcee38-5f49-4cfe-8014-0c23c4a2eb80_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>A finance team recently opened an invoice and found a number they couldn&#8217;t explain. One widely circulated account described a company that rolled out Claude AI to its workforce without usage limits and then faced an extraordinary single-month bill. This experience is becoming more widely reported. Repeatedly, companies report rapid growth of AI use, weak controls, and very little cost governance.</span></p><p><strong><span>Bill Shock Goes Mainstream</span></strong></p><p><span>Perhaps the most well-known example of bill shock that is spreading across enterprise AI deployments globally is the case of Uber. Uber gave thousands of its engineers access to an AI coding tool in late 2025, and by April 2026 the company said it had exhausted its AI coding budget for the year. More revealing than the overrun itself was the admission that leadership could not clearly connect token consumption to useful features.</span></p><p><span>Other enterprises are reporting similar dynamics. In large environments, AI bills can rise quickly not because of fraud or system failure, but because usage scales faster than governance, especially when organisations cannot see which teams, workflows, or agents are consuming the most tokens.</span></p><p><span>Recent reporting indicates that enterprise token consumption has increased significantly since early 2025, with some organisations seeing rapid increases in usage and OpenAI enterprise data showing average reasoning token consumption per organisation rising by roughly 320 times year over year. </span></p><p><strong><span>The Hidden Cost Engine Behind AI</span></strong></p><p><span>Understanding why AI costs behave the way they do requires stepping back from the invoices and looking at the pricing architecture underneath.</span></p><p><strong><span>AI Costs Follow a Different Logic</span></strong></p><p><span>Traditional enterprise software costs followed broadly predictable patterns. Compute is billed by the hour, storage by the gigabyte and SaaS typically by the seat. With reasonable discipline, a finance team can forecast IT costs. The marginal cost of serving one more user is often close to zero once the infrastructure is in place.</span></p><p><span>AI pricing is fundamentally different. Every prompt, every response, and every step an autonomous agent takes is billed by the token, the basic unit of data processed by models. Token costs vary with prompt length, model complexity, context window size, and the retrieval architecture sitting underneath the application. In agentic systems, one interaction may trigger many model calls, each billed independently, which is one reason enterprises are seeing spending accelerate faster than expected.</span></p><p><span>The bill that surprises enterprises is rarely the one associated with initial deployment. It is typically associated with running systems every day, across thousands of employees, with no operational-level visibility into what is driving the cost. Three structural forces are making this worse simultaneously.</span></p><p><strong><span>Three Forces Driving Bills Higher</span></strong></p><p><span>The first is the shift to agentic AI. Earlier AI tools handled discrete queries. Autonomous agents handle multi-step tasks, invoking multiple model calls, retrieval operations, and tool executions per user request. Each step increases token consumption in ways that standard cost models do not capture. Industry reporting identifies agentic workflows as a significant driver of increased enterprise AI spend, with hidden orchestration, integration, and tool-call costs adding materially to visible token bills.</span></p><p><span>The second is the embedding of AI inside existing software. AI costs are no longer always arriving as a separate AI purchase. They are appearing inside CRM platforms, ERP systems, HR tools, collaboration software, and productivity suites, sometimes as a visible add-on and sometimes buried inside a higher software tier or usage construct. Finance teams often discover these costs at renewal rather than at deployment.</span></p><p><span>The third is tokenmaxxing. As enterprises struggled to measure AI return on investment, many defaulted to tracking the one thing they could see, usage. Companies began treating heavy AI users as innovation leaders. In some organisations, AI engagement started to influence performance measurement.</span></p><p><strong><span>Usage Becomes Theatre</span></strong></p><p><span>The result is predictable. Employees optimise for the metric rather than the outcome. They make unnecessary, suboptimal prompts and generate outputs nobody uses. Amazon shut down an internal AI usage leaderboard after employees gamed it with low-value activity, and reporting on the episode made clear how quickly usage metrics can distort behaviour when they become a target.</span></p><p><span>Goodhart&#8217;s Law, first articulated in the 1970s, states that the moment a measure becomes a target, it stops being a good measure. Applied to enterprise AI, the consequence is a massive invoice and a usage report that tells the organisation very little about whether its AI investment is working.</span></p><p><strong><span>From Dashboard to Control</span></strong></p><p><span>The practical response to AI bill shock has two phases. The first is achieving visibility. The second is building governance that prevents overrun before it occurs rather than reporting it later.</span></p><p><span>Most enterprises approach this in the wrong order. They build dashboards. Dashboards show what happened last month. By the time the alert fires, the spend has already occurred. The more important shift is moving cost control upstream, into the inference path itself, where a governance layer can intercept a request, assess it against a budget, and reject or escalate before the token is consumed. Several practical measures sit between these two phases.</span></p><p><strong><span>Visibility Is Only the Starting Point</span></strong></p><p><span>Achieving visibility begins with mapping the full AI cost footprint. Most enterprises know their primary AI platform spend. Far fewer have mapped the AI costs embedded in existing SaaS platforms, the shadow AI tools employees are using with personal accounts, or the agent workflows that trigger dozens of model calls per user request. In practice, the visible model bill is often only part of the total AI cost stack, with orchestration, retrieval, retries, observability, and integration adding materially to what teams think they are spending.</span></p><p><strong><span>Not Every Task Needs a Frontier Model</span></strong></p><p><span>Classifying workloads by value and cost is the next step. Not every AI task justifies a frontier model. Routing complex reasoning to capable models while directing simpler classification and summarisation tasks to smaller, cheaper alternatives can reduce inference costs significantly without degrading output quality. Many enterprises still route every request to the most expensive model regardless of task complexity, which is usually a sign of missing governance rather than deliberate architecture.</span></p><p><strong><span>Cost Accountability Has to Live Somewhere</span></strong></p><p><span>Implementing department-level accountability addresses the ownership problem. AI spend that is shared across the organisation belongs to nobody. Assigning token budgets to departments, teams, and workflows creates the accountability structure that makes cost visible at the level where spending decisions are made. Some organisations are starting to treat tokens as a managed resource rather than an unlimited entitlement.</span></p><p><strong><span>Prevention Beats Reporting</span></strong></p><p><span>Setting hard limits before costs occur, rather than alerts after them, closes the governance loop. A hard limit at the inference layer blocks a request when a budget is exhausted rather than notifying a finance team three weeks later. The distinction between prevention and reporting is the difference between a cost governance framework and a cost reporting framework.</span></p><p><strong><span>Outcomes Beat Activity</span></strong></p><p><span>Measuring changes in workflows rather than how many tokens were consumed addresses the tokenmaxxing problem directly. The organisations generating visible returns from AI are not the ones with the highest usage metrics. JPMorgan reported that AI tools helped advisers find information up to 95 percent faster and linked that to a 20 percent rise in gross sales in its asset and wealth management business. Walmart revealed that users of its Sparky assistant built baskets roughly 35 percent larger than non-users. Salesforce reported Agentforce annual recurring revenue of $800 million by the end of fiscal 2026. In each case, the meaningful metric was an outcome, not an activity count.</span></p><p><span>AI cost optimisation is necessary but not sufficient. It becomes effective only when embedded in a governance layer that enforces budgets upstream, assigns accountability, and measures outcomes rather than activity.</span></p><p><strong><span>The Veqtor8 Cost and Value Framework</span></strong></p><p><span>An organisation that cannot track what its agents are spending will struggle to govern what its agents are doing. An organisation that measures AI adoption through usage metrics rather than outcome metrics cannot distinguish between genuine productivity and political posturing. An organisation that discovers its AI budget has been consumed four months into the year has not only a cost problem but also an accountability failure.</span></p><p><span>The Veqtor8 AI Cost and Value Framework maps enterprise AI deployments across two dimensions, each with three levels of maturity.</span></p><p><strong><span>Cost Governance</span></strong></p><p><span>Cost Governance runs from Blind through Managed to Governed.</span></p><p><span>A Blind organisation has no centralised visibility into AI spend. Bills arrive as surprises. No individual or team owns accountability for token consumption. Finance discovers the problem at month end or at renewal.</span></p><p><span>A Managed organisation has alerts and budgets in place but operates reactively. Cost spikes are identified after they occur. Department-level accountability exists in principle but is not enforced at the inference layer. Governance is a reporting exercise rather than a control mechanism.</span></p><p><span>A Governed organisation has built cost accountability into its operational structure. Token budgets are assigned to teams and workflows and enforced before costs occur. Real-time visibility flows down to the operational level, not just to central finance. Named individuals own AI cost at the team level. The organisation can tell, at any point, which teams and workflows are driving its AI spend and why.</span></p><p><strong><span>Value Realisation</span></strong></p><p><span>Value realisation runs from Activity through Output to Outcome.</span></p><p><span>An Activity organisation measures AI adoption through usage metrics such as prompt volume, session counts, and engagement rates. These organisations are most vulnerable to tokenmaxxing because the metric they are optimising for has no necessary connection to business value. High activity scores and low returns can coexist indefinitely because nobody is asking whether the work has changed.</span></p><p><span>An Output organisation measures what the AI produced, documents generated, code written, responses delivered. This is better than activity measurement but still incomplete. Output without outcome measurement cannot answer the question Uber&#8217;s leadership was asking, which is whether the tokens consumed produced anything worth keeping.</span></p><p><span>An Outcome organisation measures changes in workflows such as revenue generated, customer satisfaction, decision quality, or error rates. The organisations generating the strongest visible returns from AI, including JPMorgan, Walmart, and Salesforce, are Outcome organisations because they tied AI deployment to business results rather than usage volume.</span></p><p><strong><span>Measuring Maturity Shift</span></strong></p><p><span>Most enterprises sit at Blind and Activity. The goal is Governed and Outcome. Moving up both dimensions simultaneously is how AI spend becomes a strategic asset rather than an uncontrolled operating cost.</span></p><p><span>The path from Blind to Governed requires investment in visibility infrastructure, centralised cost governance, and named accountability at the team level. The path from Activity to Outcome requires a more fundamental shift, deciding what the AI is for before deploying it, and measuring whether it achieved that purpose rather than whether it was used.</span></p><p><span>Neither shift is conceptually complex. Both are organisationally difficult, for the same reason that tokenmaxxing emerged in the first place. Organisations find it easier to measure what they can see than to define what they are trying to achieve.</span></p><p><strong><span>Governance Wins</span></strong></p><p><span>The bill shock crisis is not primarily a technology problem. The technology works, and the pricing model is usually visible enough in principle. The tools to manage token costs are available and becoming more mature.</span></p><p><span>The problem is governance. Organisations are deploying AI rapidly without the cost accountability frameworks, ownership structures, or outcome measurement disciplines that sustainable deployment requires.</span></p><p><span>The organisations that address both dimensions of the Veqtor8 AI Cost and Value Framework will find that AI spend becomes more manageable, attributable, and increasingly justifiable. The organisations that continue to treat cost management as a finance problem and value measurement as optional will keep receiving invoices they cannot explain, for outcomes they cannot demonstrate.</span></p><p><em><span>Andrew Milroy is the founder of Veqtor8, a Singapore-based global technology advisory firm. He advises enterprises, governments, and technology vendors on agentic AI governance, cybersecurity, and technology strategy across the United States, Europe, and Asia Pacific. The Veqtor8 AI Cost and Value Framework is available for enterprise assessment engagements.</span></em></p>]]></content:encoded></item><item><title><![CDATA[Cognitive Disintermediation and AI’s Impact on Employment]]></title><description><![CDATA[The removal of human cognitive intermediation and the restructuring of knowledge work.]]></description><link>https://andrewmilroy1.substack.com/p/cognitive-disintermediation-and-ais</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/cognitive-disintermediation-and-ais</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Thu, 11 Jun 2026 07:15:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WvVd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!WvVd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!WvVd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg" width="768" height="432" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:432,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:41932,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/201561259?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!WvVd!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55727220-c4fd-40f6-9b51-638018897a6e_768x432.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Agentic AI is not just changing how work gets done. It is removing the human cognitive layer from much of the knowledge work we do today. This is cognitive disintermediation, and it may be the most significant structural shift in the history of the knowledge economy.</p><p>Every major technological disruption removes a layer of human involvement from the economy. The internet eliminated or radically reduced demand for entire industries including travel agents, video rental stores, classified advertising, directory publishers, and film processing. Other industries including financial services, retail and manufacturing were transformed. People still travelled, bought products, looked for jobs, and consumed media, but the human intermediary was no longer needed for a range of activities.</p><p>Agentic AI is doing something structurally similar to knowledge work, but at a depth and speed that have few precedents. The human cognitive layer that sits between information and decision-making, between data and output, and between instruction and action is being disintermediated across large parts of the knowledge economy. This is cognitive disintermediation.</p><p>It is not automation in the traditional sense. Automation replaced physical labour and repetitive process execution. Cognitive disintermediation removes the human judgment, analysis, synthesis, and decision-making intermediary from tasks that have historically required a trained human mind to perform. The financial analyst who translates data into insight. The junior lawyer who synthesises case precedents into a brief. The research associate who turns a question into a structured answer. The customer service representative who translates a customer problem into a resolution pathway. These roles are being disintermediated by systems that can perform the same cognitive translation faster, cheaper, and in many cases more consistently.</p><p>The cognitive intermediary layer of the knowledge economy appears to be being removed in real time, and many organisations experiencing this shift have not built the governance frameworks, accountability structures, or organisational models to manage a more agentic future.</p><p>The irony worth noting is that the firms most confident they understand this transition are among those most exposed to it. In 2025, one of the world&#8217;s largest management consulting firms, an organisation whose business model is built on providing cognitive intermediation to the clients it serves, announced the elimination of thousands of positions concentrated in junior research and analytical roles. The AI systems that firm had been advising clients to adopt were, in effect, removing the cognitive intermediary layer from its own operations.</p><p><strong>Three Patterns of Workforce Change</strong></p><p>The discourse around AI and employment tends to focus on binary options. Jobs will be lost, or jobs will be created. Humans will be replaced, or humans will be augmented. These framings are not wrong, but they are insufficient. They describe the extreme ends of a distribution that is far more complex in the middle.</p><p>Cognitive disintermediation does not operate uniformly. It operates through three distinct patterns, each of which requires a different organisational and strategic response. Understanding which pattern applies to which function, at which moment in an organisation&#8217;s AI journey, is one of the most important analytical tasks facing senior leaders today.</p><p><strong>Pattern One: Elimination</strong></p><p>The first pattern is the most straightforward and the most politically difficult to discuss. Some roles are being eliminated because the cognitive function they perform has been fully and reliably replicated by AI systems. The intermediary layer they occupied no longer requires a human mind.</p><p>These are often not unskilled roles. This is the finding that most challenges conventional assumptions about how AI affects employment. Observations based on direct use of AI systems in professional settings consistently show that the most exposed roles are concentrated among educated, higher-paid, knowledge-based workers, not the manual, physical, or interpersonal roles that earlier automation waves targeted.</p><p>The roles most vulnerable to elimination are those where the cognitive task is primarily one of translation. These tasks include converting data into insight, questions into answers, inputs into outputs, without requiring sustained human judgment about unprecedented situations, interpersonal accountability, or physical presence. Financial analysts whose primary function is data aggregation and routine modelling. Junior research roles whose core output is information synthesis and structured summaries. Customer service representatives handling standard query resolution. Data entry and verification functions. Routine compliance reporting. These roles represent a significant proportion of knowledge economy employment, and the pipeline into them, particularly for younger workers entering professional life, appears to be narrowing.</p><p>Entry-level hiring data is particularly significant. Early evidence from labour market studies suggests that companies are beginning to slow or stop hiring into exposed occupations at the junior level, even where overall employment figures remain stable. The cognitive intermediary pipeline appears to be closing before employment statistics catch up. Young professionals entering the workforce today face a knowledge economy in which the traditional entry points, the roles designed to build expertise through structured cognitive work, are contracting faster than alternatives are appearing.</p><p>The strategic issue for enterprise leaders is not whether elimination is happening in their organisation. For most large enterprises it appears to be, regardless of whether it has been named as such. The issue is whether the elimination is being managed deliberately or accumulating as a series of uncoordinated decisions that will eventually add up to a structural change nobody consciously chose.</p><p><strong>Pattern Two: Elevation</strong></p><p>The second pattern is less visible, more complex, and ultimately more consequential for how organisations function. Many knowledge roles are not being eliminated. They are being fundamentally redesigned around a new relationship between human judgment and machine capability. The role survives but the work changes. In many cases, the role rises to something more strategic, more accountable, and more distinctly human than in its previous state.</p><p>The Chief Financial Officer and the finance function provide an illustration of this pattern within enterprises. The traditional finance function is built around the cognitive intermediary. Teams of analysts convert raw financial data into reports, forecasts, and recommendations. Controllers ensure the accuracy of numbers that move up the organisation to inform decisions. Financial planning and analysis teams synthesise historical performance and market data into forward projections. The CFO sits at the apex of this cognitive pyramid, interpreting the synthesised output and translating it into strategic recommendations for the board and the CEO.</p><p>Agentic AI appears to be dismantling this pyramid from the base up. Cognitive tasks are being absorbed by AI systems that perform them faster, more accurately, and without the coordination costs that human teams require. The base of the cognitive pyramid is being removed.</p><p>The CFO role does not disappear; rather it is elevated. The function that remains is the one that cannot be replicated by a system operating on historical patterns and defined parameters. The CFO who thrives in an agentic environment is not the one who managed the largest team of analysts. It is the one who can interrogate AI-generated financial intelligence with sufficient depth to know when it is wrong, who can translate machine-generated insight into strategic judgment in conditions of uncertainty, and who can be personally accountable for decisions that AI systems informed but did not make.</p><p>The same elevation applies across other functions. For example, the CISO role is being elevated from operational security manager to enterprise risk and resilience strategist as agentic AI removes the cognitive intermediary layer from activities like threat detection, incident response, and routine compliance monitoring. The CIO is being elevated from infrastructure manager to architect of human-machine workflows. The General Counsel is being elevated from legal researcher to accountability anchor for decisions made at the intersection of AI-generated analysis and genuine legal judgment.</p><p>In each case, the surface area of the role changes more than the title. The work that AI cannot do such as sustained judgment under uncertainty, personal accountability for consequential decisions, and handling unprecedented situations, expands to fill the space left by the work that AI can do. The cognitive intermediary work disappears, and the cognitive leadership work grows.</p><p>The challenge for organisations is that elevation requires deliberate redesign. Roles do not naturally evolve into their elevated form without intentional organisational choices about accountability, training, and incentive structures. The CFO role needs a different mandate, a different set of performance metrics, and a different relationship with AI systems than the one the role historically required. Most organisations are changing the tools their finance functions use without redesigning the roles those functions contain. The elevation is being left to happen by accident rather than being architected by design.</p><p><strong>Pattern Three: Emergence</strong></p><p>The third pattern is the least understood. New roles are emerging from the cognitive disintermediation of knowledge work. These are roles that did not exist in their current form before agentic AI became an operational reality in enterprise settings.</p><p>These are not rebranded versions of existing roles with AI added. They are new cognitive functions created by the specific accountability requirements of operating in an environment where autonomous systems make consequential decisions.</p><p>The most significant emerging category is governance and oversight of agentic systems. As autonomous agents make decisions across enterprise functions, initiating procurement actions, generating client communications, processing financial transactions, flagging security events, producing legal documentation, someone must own accountability for agent decisions and actions. That accountability cannot rest with the AI system. It cannot be distributed across the organisation without being owned by somebody. It requires a new class of professional whose cognitive function is specifically the governance, auditing, and accountability oversight of autonomous AI operations.</p><p>AI governance officers, agent oversight managers, machine accountability leads, and sovereign AI architects are emerging as distinct professional functions in organisations that are deploying agentic AI. These are not IT roles in the traditional sense. They require a combination of domain expertise, governance methodology, regulatory knowledge, and the specific analytical capability to interrogate AI system behaviour at a level of depth that most professionals have not yet developed.</p><p>The demand for AI fluency in the workforce illustrates the emergence pattern. Reported demand for roles explicitly requiring AI competency has grown rapidly over the past two years. This suggests a structural shift in the dynamics of the knowledge economy.</p><p>The emergence pattern also appears outside traditional organisational boundaries. The compression of cognitive intermediary work, combined with the democratisation of AI tools that can perform that work, is enabling individual professionals to replicate what previously required teams. One-person enterprises, equipped with AI systems that handle research, analysis, client communication, financial management, and operational coordination, are emerging as a new economic unit that the industrial-era organisational model did not anticipate. The knowledge worker displaced from the cognitive intermediary role inside a large organisation may find that the same AI tools that displaced them now enable them to compete with that organisation from the outside.</p><p>This is the dimension of cognitive disintermediation that most enterprise leaders have not yet considered. The reduction in the cognitive intermediary headcount inside the organisation does not remove those cognitive capabilities from the market. In many cases it releases them, equipped with powerful AI tools, into competitive positions that did not previously exist.</p><p><strong>The Cognitive Disintermediation Framework</strong></p><p>Cognitive disintermediation is not a prediction. It is an observation based on emerging evidence and practice across the global knowledge economy. The binary debate, AI takes jobs or AI creates jobs, is less useful than an assessment of which pattern applies to which function, at what pace, and with what organisational implications.</p><p>The three patterns of cognitive disintermediation, Elimination, Elevation, and Emergence, provide a framework for that assessment. Applied systematically across an organisation&#8217;s functions and roles, the framework provides insights that every senior leader needs to understand.</p><p>In finance, legal, technology, security, research and analysis, and other functions, organisations must decide which cognitive intermediary tasks are being eliminated, which roles are being elevated, and which new accountability functions need to be built. These decisions vary across organisations and sectors, but the framework for addressing them is the same.</p><p>Organisations that apply it deliberately will navigate this transition with their institutional knowledge, accountability structures, and competitive capabilities intact. Those that treat it as a workforce planning problem rather than a strategic redesign challenge will find that the cognitive intermediary layer of their organisation is removed whether they like it or not.</p><p>To help enterprise leaders map, navigate, and govern this structural shift, Veqtor8 has operationalised these insights into a structured advisory program. The Veqtor8 Cognitive Disintermediation Framework provides boards and executive teams with a rigorous, data-driven assessment of their current exposure, risk profiles, and emerging capability requirements.</p><p>If your organisation is ready to move past the binary AI debate and architect a deliberate, agentic-ready operational model, contact Veqtor8 to initiate an enterprise assessment engagement.</p><p><em>Andrew Milroy is the founder of Veqtor8, a Singapore-based global technology advisory firm. He advises enterprises, governments, and technology vendors on agentic AI governance, cybersecurity, and technology strategy across the United States, Europe, and Asia Pacific.</em></p><p><em>The Veqtor8 Cognitive Disintermediation Framework, built around the three patterns described in this article, is available for enterprise assessment engagements. If your organisation is navigating the workforce and governance implications of agentic AI, let us know.</em></p><p><em>Disclaimer: This framework is for informational purposes only and does not constitute formal legal, financial, or management advice. Veqtor8 accepts no liability for organisational, or investment decisions made based on this content.</em></p>]]></content:encoded></item><item><title><![CDATA[The Six Dimensions of AI Sovereignty]]></title><description><![CDATA[Most enterprises are managing one dimension of AI sovereignty. There are six.]]></description><link>https://andrewmilroy1.substack.com/p/the-six-dimensions-of-ai-sovereignty</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/the-six-dimensions-of-ai-sovereignty</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Wed, 03 Jun 2026 13:01:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Se2Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Se2Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 424w, /__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 848w, /__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 1272w, /__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Se2Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif" width="857" height="893" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:893,&quot;width&quot;:857,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77165,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/200446830?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 424w, /__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 848w, /__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 1272w, /__u/substackcdn.com/image/fetch/$s_!Se2Z!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b1626b3-b8a7-4ff9-bac2-3ffa823fb4b9_857x893.avif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI sovereignty has moved to a boardroom imperative faster than most organisations anticipated. Regulatory pressure, geopolitical volatility, and the rapid operationalisation of agentic AI have together made a sovereignty strategy necessary. Most organisations have one. Few have one adequate for the environment they now face.</p><p>Managing AI sovereignty is a multidimensional game of chess. Most organisations are playing on one board while their exposure accumulates across five others. The framework set out here is drawn from what enterprises are wrestling with on the ground. These include the decisions being made under pressure, the assumptions being tested by geopolitical events, and the new vulnerabilities being discovered. </p><p>Agentic AI is also changing the nature of sovereignty itself. Enterprises are no longer protecting data alone. Increasingly, they are protecting the institutional knowledge, decision logic, workflow logic, and operational intelligence accumulated by AI systems.</p><p><strong>Six Actions for Minimum Viable Sovereignty</strong></p><p>Complete independence is neither practical nor necessary. Organisations can instead pursue a minimum viable sovereign posture aligned to their risk appetite and operational requirements. The six dimensions below set out where that posture needs to exist, and the actions that help build it.</p><ol><li><p><strong>Strengthen data sovereignty.</strong> Identify your most sensitive data assets, including personal information, financial records, AI training data, governance evidence, and strategic intelligence. Apply controls based on sovereignty sensitivity rather than treating all workloads equally.</p></li><li><p><strong>Understand jurisdictional exposure.</strong> Map every critical technology provider, identifying where it is incorporated, which laws govern it, and which governments may have legal authority over the data, systems, or communications it handles.</p></li><li><p><strong>Reduce operational dependency.</strong> Assess the dependency of critical business processes on specific vendors. Develop fallback options, portability plans, and contractual protections that allow operations to continue if a key supplier becomes unavailable.</p></li><li><p><strong>Protect model and IP sovereignty.</strong> Identify where organisational knowledge, decision logic, workflows, model weights, and AI-generated intellectual property are accumulating. Ensure these assets remain portable and are not irretrievably embedded within a single platform.</p></li><li><p><strong>Prepare for political disruption.</strong> Assess exposure to sanctions, regulatory interventions, executive orders, and other government actions that could affect access to critical technology services. Develop contingency plans.</p></li><li><p><strong>Strengthen technical sovereignty.</strong> Prioritise technologies that can be inspected, modified, deployed, and migrated without requiring vendor permission. Technical flexibility reduces dependency and improves resilience as AI ecosystems evolve.</p></li></ol><p>None of these actions delivers complete sovereignty in isolation. Together, they establish a practical foundation for participating in the global AI ecosystem while maintaining control over major risks.</p><p><strong>The Residency Fallacy</strong></p><p>Most enterprises believe sovereignty is addressed through local data centres, sovereign cloud offerings, and compliance with local regulations. While all three may be true, none necessarily changes the legal authority over the systems and data on which the organisation depends.</p><p>A server in Singapore running on AWS infrastructure is not sovereign from US law. A Microsoft Azure deployment in a Frankfurt data centre is not insulated from US government access. A Google Cloud workload in a Sydney availability zone is not outside the reach of US legal instruments because of its physical location.</p><p>Data residency, where data physically sits, is different from data sovereignty, which is about who has legal authority over that data. An organisation can have complete data residency in any jurisdiction while having limited sovereignty if the infrastructure provider is incorporated in a country whose laws permit or compel government access.</p><p>In 2025, Microsoft France acknowledged before a French Senate inquiry that it could not guarantee that data stored in France would be beyond the reach of US authorities. That highlights the distinction between data residency and legal sovereignty. Most enterprises have invested in sovereignty initiatives that improve data residency without materially changing their underlying legal exposure.</p><p><strong>Jurisdictional Foundations</strong></p><p>Jurisdictional sovereignty addresses the laws that govern technology providers and the extent to which governments can force access to data, systems, or communications. In the United States, legislation including the Cloud Act, FISA 702, and the Patriot Act creates legal pathways through which authorities can compel access to data or communications handled by US-incorporated providers, regardless of where that data is stored. For enterprises running critical workloads on US technology platforms, the implication is straightforward. Data residency does not remove legal exposure.</p><p>Many organisations assume that acting as the data controller provides meaningful protection. In practice, a provider that possesses and can access data remains subject to legal orders directed at it. For this reason, customer-managed encryption is often a more effective control than contractual language alone.</p><p>China presents similar considerations. The National Intelligence Law requires Chinese organisations to support and cooperate with state intelligence activities, while other laws governing data security, cybersecurity, and personal information create additional obligations around government access, data localisation, and cross-border transfers.</p><p>The purpose of this analysis is not to pass judgement on any jurisdiction. It is to understand which governments have legal authority over critical technology providers and how that exposure contributes to an organisation&#8217;s overall sovereignty posture.</p><p><strong>The Political Layer</strong></p><p>The legal instruments described above are structural and relatively permanent. Political risk is different. It is the additional exposure that comes from a government&#8217;s demonstrated willingness to use its influence over technology companies as an instrument of policy beyond conventional law enforcement.</p><p>Structural legal risk can be managed through architecture and contracts. Political risk requires a different kind of preparation. Political sovereignty is not unique to any one country. It arises wherever governments use legal or regulatory authority in ways that affect access to critical technology services.</p><p>Recent events illustrate how political decisions can have operational consequences for organisations that depend on global technology platforms. Following US government sanctions against the International Criminal Court&#8217;s (ICC) chief prosecutor, he lost access to his Microsoft email account. The ICC subsequently migrated away from Microsoft&#8217;s software, moving to an open-source sovereign alternative developed under a German government digital sovereignty initiative. The migration cost time, money, and operational continuity because a US government executive order threatened any company with fines and prison time for providing technological support to a sanctioned individual.</p><p>Separately, the US government imposed sanctions on a United Nations Special Rapporteur in July 2025, shortly after she published a report naming major US technology companies in relation to their activities in conflict zones. The same executive order mechanism applied. Any US company providing technological support to a sanctioned individual faces legal jeopardy. Every enterprise needs a contingency plan in case of unexpected sanctions, including those operating within the United States.</p><p><strong>The Alternatives That Now Exist</strong></p><p>Until recently, enterprises seeking frontier AI model capability outside US providers had no credible alternatives, but that position has changed significantly.</p><p>Mistral AI, the French company founded in 2023 with backing that includes explicit European sovereign AI ambitions, has built a family of open-weight large language models that are competitive with US alternatives for a range of enterprise use cases. Mistral models can be self-hosted on non-US infrastructure, fine-tuned on proprietary data without that data ever touching a US-controlled system, and deployed entirely within jurisdictions of the enterprise&#8217;s choosing. For workloads where sovereignty is critical, Mistral represents a credible European alternative at the model layer, even if it is not a universal replacement for every frontier capability.</p><p>DeepSeek&#8217;s open-weight model releases demonstrated that frontier-level AI capability is achievable outside the US, at dramatically lower cost. The strategic implication extends beyond the specific models. The era of US monopoly at the frontier model layer is ending. Enterprises now have genuine architectural choices that did not exist eighteen months ago.</p><p>China&#8217;s domestic AI ecosystem represents the most complete sovereign AI infrastructure built by any non-US actor. Enterprises should understand it as a structural development in the global AI landscape while applying thorough jurisdictional analysis to Chinese vendors. China&#8217;s National Intelligence Law creates equivalent Chinese state access obligations to those the Cloud Act creates for US providers. Substituting US dependency for Chinese dependency does not solve a sovereignty problem. Instead, it trades one geopolitical exposure for another.</p><p>The practical implication for enterprises is a portfolio approach: US frontier models where capability justifies the jurisdictional trade-off; European sovereign models where jurisdictional independence matters more than absolute capability; and self-hosted open-weight models for the most sensitive workloads. The goal is not independence from all external AI infrastructure, as this is neither practical nor necessary. The goal is deliberate interdependence, which allows enterprises to know where dependencies sit, understand the exposure each one creates, and determine that the trade-off is acceptable.</p><p><strong>Singapore as a Model</strong></p><p>Singapore offers a useful operational model of deliberate AI sovereignty, and the lessons translate directly to enterprise practice.</p><p>Singapore uses US cloud infrastructure extensively and engages deeply with Chinese technology ecosystems. It has not attempted to build a fully sovereign domestic AI stack, because full-stack sovereignty is neither practical nor necessary. Instead, it has pursued deliberate interdependence with explicit governance.</p><p>The Infocomm Media Development Authority&#8217;s (IMDA) Model AI Governance Framework, expanded in early 2026 to address agentic AI, establishes operational accountability, oversight requirements, and risk management standards for autonomous AI systems. It allows Singapore-based organisations to deploy global AI capabilities within a governance architecture they control.</p><p>The principle is directly applicable at the enterprise level. An organisation does not need to own its own models or build its own cloud infrastructure. It needs to govern how those external capabilities operate within its own boundaries, covering what they can access, what they can do, what audit trail they leave, and what the exit options are if the relationship needs to change.</p><p><strong>Sovereignty as Strategy</strong></p><p>Sovereignty is not the same as independence. Most mature organisations are not attempting to disengage from the global AI ecosystem. Instead, they are attempting to participate in it on their own terms.</p><p>Passive dependency is a choice made by default. Deliberate interdependence is a choice made by design. The difference between them is not the technology stack. It is whether the organisation has thought carefully about what it depends on, understood the exposure that dependency creates, and taken deliberate steps to manage it across all six dimensions.</p><p>Most enterprises have addressed one dimension and left the others largely unexamined. The framework set out here is a starting point for changing that. The organisations that work through all six will be significantly better positioned than those that discover their exposure after the fact.</p><p><em>Andrew Milroy is the founder of Veqtor8, a Singapore-based global technology advisory firm. He advises enterprises, governments, and technology vendors on agentic AI governance, cybersecurity, and technology strategy across the United States, Europe, and Asia Pacific. If your organisation has not yet assessed its AI sovereignty exposure, it is probably overdue.</em></p><p><em>Disclaimer: This article reflects the author&#8217;s opinion and analysis based on publicly available information and professional conversations. It is not legal, regulatory, or investment advice.</em></p>]]></content:encoded></item><item><title><![CDATA[A Manifesto for Agentic AI Governance]]></title><description><![CDATA[Enterprises need an independent agentic AI governance layer, operating above their applications now, if they are to fully realise the value and manage the risk of autonomous agents.]]></description><link>https://andrewmilroy1.substack.com/p/a-manifesto-for-agentic-ai-governance</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/a-manifesto-for-agentic-ai-governance</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Tue, 26 May 2026 02:13:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CjtB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!CjtB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 424w, /__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 848w, /__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 1272w, /__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!CjtB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif" width="1170" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156251,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/199269602?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 424w, /__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 848w, /__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 1272w, /__u/substackcdn.com/image/fetch/$s_!CjtB!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe622b04c-ca2a-4ec0-8009-9082c4bdfb16_1170x780.avif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Organisations are scaling agentic AI faster than most governance approaches can keep up. Autonomous agents are moving rapidly from pilots to production, executing complex workflows, making decisions, and operating continuously across multiple systems. While agentic AI is proving its value, the harder challenge is scaling it reliably and maximising that return on investment.</p><p>This makes independent oversight critical. In an agentic world, governance is no longer a periodic review exercise. Instead, it is an operational discipline. Independent agentic AI governance is emerging as a distinct enterprise category because existing frameworks are insufficient, and platform vendors cannot be expected to govern themselves.</p><p><strong>Governance Is an Operational Activity</strong></p><p>In an agentic environment, governance must be woven into workflows, decisions and controls as agents operate. Crucially, it must sit above all platforms and agents, providing independent oversight while remaining embedded in how agentic AI operates. It must shape behaviour in real time while also enabling speed, scale and trust.</p><p>The cloud era showed the way. In mature cloud environments, governance increasingly moved into the infrastructure itself through policy-as-code, automated guardrails and continuous compliance built into operations. Agentic AI needs the same model, but with a broader purpose. It is not only about managing risk. It is also about making agentic systems usable, scalable and productive at enterprise level.</p><p>Governance must not be treated as a brake on innovation. It must be treated as a core ingredient for making innovation operational and for enabling agentic AI to scale.</p><p><strong>Existing Governance Frameworks Fall Short</strong></p><p>Enterprise IT governance, architecture management, data stewardship, cloud governance and the internal AI governance committees now emerging in many organisations, provide a foundation, but they are insufficient. COBIT and TOGAF are useful frameworks, but they do not solve the problem of a platform both running agentic AI and supplying the evidence used to assess it. TOGAF&#8217;s phases and review cycles suit slower moving environments better than agentic systems, and neither framework addresses data generated autonomously across platform boundaries. Agents do not wait for the next architecture review board.</p><p>The AI-specific frameworks, including NIST AI RMF and ISO 42001, are among the strongest available. They remain necessary foundations, but they still focus mainly on how an enterprise manages its own AI systems rather than the governance problems created when agentic AI operates across platforms and boundaries.</p><p>Singapore&#8217;s IMDA Model AI Governance Framework for Agentic AI provides practical guidance across risk assessment, human accountability, technical controls and end-user responsibility. It is a useful reference point, but it does not resolve the independence question. It governs how an enterprise manages its own agents, not the conflict of interest that arises when the platforms generating the activity also supply the governance evidence.</p><p>The same applies to the internal frameworks many enterprises have built for generative AI and LLMs. These usually include prompt guardrails, acceptable use standards, bias controls and output review processes. They are valuable, but they were built around a human being in the loop at the point of decision. Agentic AI removes that assumption. As agents chain together decisions across multiple systems, nobody may have approved the individual steps that led to the outcome, and nobody may even have seen them.</p><p><strong>The Structural Problem with Platform-Native Governance</strong></p><p>The major enterprise platforms are building extensive agentic AI capabilities and local governance. Microsoft, ServiceNow, Salesforce, SAP, and many others are embedding increasingly sophisticated governance tooling into their products. Many enterprises find these capabilities valuable.</p><p>The issue is not capability, but independence. A platform cannot truly oversee itself in an independent way. Its governance tooling uses its own telemetry, methodologies, and analytics models to assess activity within that specific platform. While this is appropriate for internal operational management, it is fundamentally different from independent governance.</p><p>This is a commercial reality, not a criticism. Every major platform vendor wants deeper integration and stronger customer retention. The challenge faced by organisations is whether oversight should sit inside the same commercial arrangement it is meant to govern.</p><p>Existing governance disciplines provide a solid foundation, but they do not fully solve the challenges that autonomous agents create. Enterprises need to govern cross-platform activity in a way that is independent, operational, and scalable. This creates an urgent requirement for a new approach.</p><p><strong>The Independent AI Governance Framework: Ten Principles</strong></p><p>The framework proposed here is not a replacement for existing governance structures. It is a set of guidelines that may help enterprises scale agentic AI more effectively and generate more value from their investments.</p><p><em><strong>1. Architectural Independence</strong></em></p><p>The independent governance layer should be persistent presence above the enterprise application and platform estate, not a feature within any individual platform. It needs to be continuously operating infrastructure that connects to every platform in the AI estate, ingests governance-relevant signals from each and maintains an independently controlled governance record that belongs to the enterprise and no one else. Applications and platforms come and go. The governance layer persists above them, accountable to none of them.</p><p><em><strong>2. Governance for Operational Excellence and Resilience</strong></em></p><p>Independent governance exists primarily to make enterprises better run. Compliance is critical, but it should not dominate governance. In an agentic world, governance must keep pace with agentic operations. Enterprises need to know which agents are operating on their behalf, whether the data they consume is trustworthy, whether agentic AI investments are delivering the returns being claimed, and whether their governance evidence can survive a vendor relationship ending. Governance must also remain available if any platform in the AI estate becomes unavailable.</p><p><em><strong>3. Data Portability and Sovereignty</strong></em></p><p>Governance data and operational logic must be owned by the enterprise, stored in formats the organisation controls, and portable without the cooperation of any individual vendor. Audit trails, decision logs, model performance records, and policy attestations must not accumulate inside platform infrastructure the enterprise cannot independently exit. The enterprise must be able to produce its complete governance data to any auditor without requiring the cooperation of any external platform. True sovereignty dictates that the enterprise retains the absolute right to verify and control its autonomous operations, ensuring continuity even if a primary vendor relationship shifts or dissolves.</p><p><em><strong>4. Data Governance as an Agentic AI Governance Foundation</strong></em></p><p>Independent agentic AI governance cannot be built on ungoverned data. Enterprises need a unified data catalogue, consistent classification, automated lineage tracking, continuous quality monitoring and a semantic layer that preserves meaning across platforms. Every dataset, including agent-generated data, needs a named owner accountable for its quality and fitness for purpose.</p><p><em><strong>5. Federated Architecture</strong></em></p><p>Enterprise agentic AI runs across many platforms simultaneously. The most significant governance risks are at the boundaries between those platforms, as lines of responsibility break down and platform-native tools do not always provide a unified view. Independent agentic AI governance should ingest signals from any platform through standardised connectors, normalise them into a common governance data model and provide a unified view without requiring every platform to adopt the same architecture.</p><p><em><strong>6. Reduced Vendor Concentration</strong></em></p><p>Independent agentic AI governance must avoid dependence on too few vendors, because concentration at the platform layer can create a single point of failure for both operations and governance evidence. It should preserve independence, maintain resilience, and ensure that governance does not recreate the same concentration risk it is meant to manage.</p><p><em><strong>7. Cyber and Identity Governance Across Machine Boundaries</strong></em></p><p>Agentic AI governance and cybersecurity governance cannot be treated as separate functions. The governance layer must track identities at scale, including human users, AI agents, automated workflows, service principals and model-to-model connections. An autonomous agent crossing multiple platform boundaries may operate under different identity contexts in each system. Without consistent identity tracking across those boundaries, the accountability chain for any agentic decision cannot be reliably established.</p><p><em><strong>8. Continuous Cross-Platform Auditability</strong></em></p><p>Governance evidence should be generated and stored as agentic AI activity occurs, not reconstructed after the fact. Platform-native tools can log what happens within their own boundaries, but they do not usually provide a complete record of cross-boundary transitions, including the data that crossed, the identity that authorised it, or the governance state at the moment of handoff. A governance layer above the platforms can capture that evidence continuously and make it available in real time or for later audit.</p><p><em><strong>9. Agent Accountability and Ownership</strong></em></p><p>Every AI agent must have a named owner, an authorisation record, defined operational boundaries and a decommissioning process. Accountability cannot stop at deployment. Ownership also carries responsibility for integrity and availability. If an agent drifts from the behaviour it was authorised for, the owner must detect it and act.</p><p><em><strong>10. Independent Quantification of AI Risk and Value</strong></em></p><p>Neither agentic AI risk nor its value should be measured only by the platform that has a financial interest in the answer. Independent agentic AI risk tools can estimate risk in financial terms using independent data sources rather than relying on a platform&#8217;s own reporting. Vendors can do the same with ROI figures, using their own methods and metrics. If enterprises use those numbers alone, they risk making decisions with less reliable information.</p><p><strong>The Emerging Market Category &#8211; Independent Agentic AI Governance</strong></p><p>The independent agentic AI governance layer described in this framework is not yet a clearly established commercial category, but enterprise demand for it is growing. Boards need information that platform dashboards cannot provide independently. Risk functions need numbers they can stand behind, and agentic deployment is advancing faster than governance architecture. Existing tools are fragmented, and many pure-play governance capabilities are being absorbed into larger platforms. The market still lacks a fully integrated, cross-platform governance layer with independent evidence capture and operational resilience.</p><p>This is not a compliance-first category. It is an operational one. Agentic AI governance is increasingly the discipline organisations need to run themselves well. Regulation is imposed from outside. Compliance is evidence of adherence to those obligations. The organisations that build independent agentic AI governance will be better able to run agentic AI, manage risk and satisfy regulatory expectations as a result.</p><p><strong>The Missing Layer</strong></p><p>Enterprises are scaling agentic AI deployments at a velocity that completely outpaces current governance infrastructure. Boards urgently need independent insights and hard data on their agents, including the actual value they deliver, the risks they carry, and where ultimate accountability sits. They also require governance evidence they control entirely themselves, rather than telemetry trapped inside vendor ecosystems they cannot independently exit.</p><p>Enterprises must build independent agentic AI governance now, applying the same rigour and operational discipline to autonomous machine activity that they already apply to finance, data, and legal risk. A continuously operating, vendor-independent layer is the missing layer.</p><p><em>Andrew Milroy is the founder of Veqtor8, a Singapore-based global technology advisory firm. He has spent more than 25 years advising enterprises on technology strategy across AI, cybersecurity, cloud and data management across North America, Europe and Asia Pacific.</em></p><p><em>This article reflects the author&#8217;s opinion and analysis based on publicly available information and professional conversations. It is not legal, regulatory or investment advice.</em></p>]]></content:encoded></item><item><title><![CDATA[Is ServiceNow a Golden Cage?]]></title><description><![CDATA[By 2030, every major enterprise will need an AI governance layer that sits above its platforms rather than inside them.]]></description><link>https://andrewmilroy1.substack.com/p/is-servicenow-a-golden-cage</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/is-servicenow-a-golden-cage</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Wed, 20 May 2026 02:42:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NHJh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!NHJh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!NHJh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg" width="768" height="1344" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1344,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100044,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/198502658?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!NHJh!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b133ee9-104e-4903-867e-50d30f96ea39_768x1344.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At Knowledge 2026 in Las Vegas, ServiceNow made an ambitious case for becoming the AI operating system of the enterprise. It also raised AI governance questions that will be asked with increasing urgency as agentic AI takes hold.</p><p>In my recent piece on <em>The End of the Road for the CISO</em>, I argue that the CISO role is converging with a range of other functions into a broader governance and resilience function that most organisations are not yet equipped to run. In the conversations I have with CISOs, CIOs and technology executives across North America, Europe and Asia Pacific, one platform often surfaces at the centre of that governance challenge. That platform is ServiceNow.</p><p>ServiceNow positions itself as the solution to AI governance across enterprise workflows, and Knowledge 2026 revealed its strategy. As a governance hawk, I believe the claims made in Las Vegas deserve much closer examination than they are currently receiving.</p><p><strong>ServiceNow&#8217;s Vision</strong></p><p>ServiceNow has transformed from a sophisticated IT ticketing tool into the AI operating system of the modern enterprise, and the results its customers presented at Knowledge 2026 are notable. Honeywell eliminated most of its service desk conversations, the City of Raleigh achieved a 98% ticket deflection rate, and PayPal is running database tasks twice as fast as before.</p><p>The platform is built around four pillars: Sense any data, Decide with context, Act across workflows, and Secure at scale. A partnership ecosystem including NVIDIA, Microsoft, Anthropic, Armis and Veza illustrates that this is no longer a vendor with a product. It is a platform actively becoming the operating system of the enterprise, and every technology leader should treat it accordingly.</p><p><strong>The Golden Cage</strong></p><p>ServiceNow states its position plainly. It is, in its own words, the &#8216;AI control tower for business reinvention&#8217;. ServiceNow Otto puts that vision to work for every person in the organisation, across every workflow, getting work done from start to finish on the platform that already runs the business. The dependency those phrases describe is the product rather than a side effect. It is a walled garden in plain sight.</p><p>Sense pulls data in from anywhere, referenced against the Configuration Management Database (CMDB), ServiceNow's master inventory of every server, application, device, user and the relationships between them. Decide runs everything through the Context Engine, a semantic layer that maps every person, role, asset, service and policy in real time, learning continuously from every decision made on the platform. Act executes through ServiceNow&#8217;s AI specialists, workflows and playbooks. The data enters from anywhere, but the platform increasingly becomes the place where operational context and learning accumulate.</p><p>In an agentic AI world, whoever owns the data controls the playing field, and the degree to which a single vendor now owns the operational, financial, HR, security, legal and procurement intelligence of a major enterprise should concern any executive or board.</p><p>At Knowledge 2026, ServiceNow announced Action Fabric, opening its platform to any AI agent built on Claude, Copilot or a customer&#8217;s own technology via Model Context Protocol (MCP). This may be presented as evidence of openness. But every agent connected generates operational data that can flow back into the CMDB and analytics, potentially making ServiceNow more informed about the business while also increasing the enterprise&#8217;s dependence on the platform.</p><p>Execution openness is not architectural openness. APIs are not the same as data sovereignty. The acquisitions of Moveworks, Armis and Veza tell the same story. All three now sit within the ServiceNow platform strategy. The space for more independent security intelligence options has narrowed.</p><p>ServiceNow is targeting $30 billion in subscription revenues by 2030 and reaching that number requires deep embedding across every major enterprise function before the architectural implications become visible. Offering a free year of AI Control Tower at $2 million list value, bundled with a promise to go live in under 100 days, is a very sophisticated on-ramp. By month 13, customers do not lose a tool. They risk losing the institutional memory of their entire AI operation.</p><p><strong>Who Governs the Governor?</strong></p><p>ServiceNow positions AI Control Tower as the enterprise answer to AI chaos. Enterprises are under intense pressure to deploy AI and show results. Accountability lags adoption and enterprises need to consider whether routing everything through ServiceNow&#8217;s governed layer addresses this issue or relocates it.</p><p>Genuine AI governance requires data that can be seen, moved and audited independently of the platform being governed, and ServiceNow&#8217;s architecture makes that difficult in ways that are not immediately obvious. AI Control Tower is part of the ServiceNow platform, not independent of it. It can govern what runs through ServiceNow, but it cannot govern ServiceNow itself.</p><p>Consider the FedEx demo shown at Knowledge 2026, where the AI Control Tower dashboard displayed $250 million in productivity gains, 3.6 million hours saved and $103 million in net AI returns at 70% ROI. Those are impressive numbers, and if accurate they represent a genuinely transformational business case. But every metric FedEx uses to understand the value of its AI investment lives inside ServiceNow&#8217;s platform, calculated by ServiceNow&#8217;s methodology, on ServiceNow&#8217;s analytics engine, presented on ServiceNow&#8217;s dashboard, by a vendor with a direct commercial interest in those numbers being as large as possible. A small disclaimer advises readers to be sure to check AI-generated content for accuracy.</p><p>The ROI methodology draws on reasonably standard measures including ticket deflection rates, hours saved and mean time to resolution. But there is a big difference between a vendor-controlled governance platform and an independent one. This difference becomes more important as agentic AI becomes core infrastructure inside major enterprises.</p><p>Databricks with Unity Catalog and Palantir with its Ontology framework offer architectures that are more open, more federated and more readily auditable by external parties. Neither is a perfect solution, and neither yet offers the enterprise breadth that ServiceNow has assembled, but neither positions itself as both the infrastructure and the auditor. That structural conflict is the core of the governance concern, and it is one that no amount of partnership announcements resolves.</p><p><strong>The Regulatory Reality</strong></p><p>The governance concern described above is not a theoretical problem for future risk committees. It is a live examination risk for enterprises in regulated industries today, and one that is intensifying as regulators in multiple jurisdictions move toward mandatory AI accountability requirements that platform-native governance cannot satisfy on its own.</p><p>In the United States, the Office of the Comptroller of the Currency (OCC), Federal Reserve and FDIC updated their interagency model risk management guidance in April 2026 (SR 26-2), replacing the framework that had governed bank model risk practices since 2011. Independent validation and ongoing monitoring remain core expectations, now applied on a more risk-based, proportionate basis. New York's cybersecurity regulation for financial institutions, updated in 2023, goes further, explicitly requiring covered institutions to include AI systems within their cybersecurity programs with documented access controls and audit trails.</p><p>The critical word in both frameworks is independent, and the regulatory expectation is unambiguous that banks are responsible for ensuring compliance even when using external AI tools provided by vendors. If ServiceNow&#8217;s AI specialists are making or influencing decisions inside a financial institution, the bank still owns the governance obligation, but the evidence trail needed to satisfy an examiner may sit inside ServiceNow&#8217;s environment and may depend on ServiceNow&#8217;s cooperation, including timely data extraction under the applicable contract terms.</p><p>In Europe, the EU AI Act is phasing in obligations through 2026 and 2027, with the majority of rules entering into application on 2 August 2026 and the final tranche following in 2027. DORA imposes ICT risk requirements that explicitly cover AI systems for any financial institution operating in EU markets, and GDPR Article 22 creates specific obligations around automated decision-making for any enterprise with European customers. In Asia Pacific, consider Singapore as an example. Monetary Authority of Singapore (MAS) guidelines, Singapore&#8217;s Model AI Governance Framework and PDPA create a parallel layer of obligations that are increasingly addressing platform concentration risk directly.</p><p>For enterprises operating globally, AI governance architecture must satisfy the most demanding regulator across their entire footprint. The walled garden does not adjust its walls based on jurisdiction.</p><p><strong>Recommendations for ServiceNow</strong></p><p>ServiceNow has the market position, the partner ecosystem and the regulatory relationships to shape this conversation rather than react to it as the pressure intensifies. There are four areas where proactive leadership would serve both the market and ServiceNow&#8217;s own long-term interests.</p><p>The first is full TCO transparency. Enterprises making multi-year commitments to a platform that will become core infrastructure for their AI operations need to understand the complete cost picture, including implementation, developer dependency, upgrade cycles, ongoing administration and the real cost of eventual exit, before they are too deep inside the platform.</p><p>The second is a significant extension of data portability, which in some cases may be limited to 45 days. Enterprises should not assume that a short post-termination window will be sufficient to extract years of operational intelligence from a complex deployment.</p><p>The third is the serious consideration of separating AI Control Tower commercially from the core platform. A governance product that can only assess what runs through ServiceNow&#8217;s own infrastructure is not an independent governance product, and as regulatory scrutiny of platform concentration increases, the structural conflict between being both the infrastructure and the auditor will become increasingly difficult to defend.</p><p>The fourth, and most strategically important, is for ServiceNow to actively advocate for independent AI governance as a recognised market category. ServiceNow is uniquely positioned to help define AI governance standards. The vendor that helps create standards is in a much stronger position with regulators, customers and other stakeholders.</p><p><strong>Recommendations for Enterprises</strong></p><p>The following recommendations focus on the intelligence that organisations are prepared to put inside one vendor&#8217;s walls, and the terms on which it resides there.</p><p>&#183; Check the exit terms. Some publicly available ServiceNow contract materials describe a 45-day window to request or extract customer data after termination, with data returned in ServiceNow&#8217;s own format rather than a guaranteed machine-readable standard. Most enterprises will discover this detail long after the walls have closed around years of operational intelligence.</p><p>&#183; Know the TCO. The licence fee is the entry price to the platform, not the total cost of operating inside it.</p><p>&#183; Treat the free AI Control Tower year as a trial, not a gift. It is the most sophisticated on-ramp in enterprise software. The year it provides is the year an organisation should be auditing carefully what the platform is learning about its environment, its operations and its AI economics before any long-term commitment is made.</p><p>&#183; Map the intelligence before going deeper. Organisations should know exactly how much institutional knowledge already lives inside ServiceNow across current deployments, which decisions depend on the Context Engine, which workflows cannot run without the CMDB, and which governance evidence exists only inside the platform, before adding another integration or AI specialist to the estate.</p><p>&#183; Ask the exit question before it becomes urgent. Can the AI governance strategy survive a ServiceNow exit? Can security operations function if the platform is unavailable? Can the board still measure AI investment value without the Control Tower dashboard? These are questions best answered before the operational freedom to act on them has been diminished.</p><p>Financial institutions should additionally ask whether the organisation can produce independent model validation evidence that an OCC examiner or other financial services regulator will require without the platform's active cooperation and continued access. The revised interagency model risk management guidance (SR 26-2), issued jointly by the Federal Reserve, OCC and FDIC in April 2026, retains independent validation as a core expectation. A platform that operates a model cannot objectively validate it, and that principle applies regardless of the platform's own governance tooling.</p><p>Concentration risk deserves board attention. When workflows, identities, asset intelligence, AI economics and institutional memory all run through a single platform, the walled garden becomes a single point of failure. Concentration risk is not a reason to avoid ServiceNow. It is a reason to understand clearly what the resilience posture looks like if the walls shake.</p><p><strong>The Emerging Case for Independent AI Governance</strong></p><p>Three forces are converging, and their intersection will reshape enterprise AI governance before 2030 in ways that are not yet reflected in most organisations&#8217; platform strategies.</p><p>Regulatory pressure is building across the US, Europe and Asia Pacific toward stronger AI accountability and independent validation of the platforms being governed. The pace differs significantly by jurisdiction, with US federal policy currently moving toward a lighter touch while EU frameworks move toward binding obligations, but the direction of travel across the global regulatory landscape does not differ. Enterprises that build their governance architecture around a single platform&#8217;s self-reported controls are making a bet on regulatory stability that the evidence does not support.</p><p>Agentic AI proliferation is making the single-platform governance model increasingly difficult to sustain. ServiceNow&#8217;s own materials continue to point to a very large agentic future by 2030, with AI agents operating across boundaries that no single vendor&#8217;s architecture can fully contain, regardless of MCP integration or partnership ecosystem.</p><p>The glaring omission in the enterprise AI market is a genuinely independent AI governance layer that sits above all platforms and can audit ServiceNow, Salesforce, SAP, Databricks and any agentic framework within a single coherent governance model. The company that builds and scales this will become critical infrastructure for the global enterprise AI stack, partly because the market will choose it, but mainly because regulators will eventually require it.</p><p><strong>The CISO and the Platform Face the Same Reckoning</strong></p><p>In <em>The End of the Road for the CISO</em>, the argument was that the CISO role is being absorbed into a broader governance and resilience function as boards shift their focus from protecting the business to governing autonomous operations they can trust, control and defend to regulators.</p><p>ServiceNow is the most important platform sitting at the centre of that shift today. The governance questions it raises are being drowned out by its own capability.</p><p>The question every enterprise needs to answer before its next ServiceNow renewal is not whether the platform delivers value, which it typically does. The question is whether its AI governance strategy is built on a foundation it controls, or one it is renting from the platform it is supposed to govern.</p><p>By 2030, every major enterprise will need an AI governance layer that sits above its platforms rather than inside them. ServiceNow has built a sophisticated platform-native governance solution. Platform-native and independent are not the same thing. The market has not priced that difference yet. It will.</p><p><em>Andrew Milroy is the founder of Veqtor8, a Singapore-based global technology advisory firm. He has spent the past 25 years advising enterprises on technology strategy across cybersecurity, AI, cloud and data management.</em></p><p><em>Disclaimer: This article reflects the author&#8217;s opinion and analysis based on publicly available information and professional conversations. It is not legal, regulatory, or investment advice.</em></p>]]></content:encoded></item><item><title><![CDATA[The End of the Road for the CISO?]]></title><description><![CDATA[The CISO Role is Untenable]]></description><link>https://andrewmilroy1.substack.com/p/the-end-of-the-road-for-the-ciso</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/the-end-of-the-road-for-the-ciso</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Fri, 15 May 2026 02:24:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EmXF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!EmXF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_webp, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!EmXF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1794360,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://andrewmilroy1.substack.com/i/197792210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_424, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_848, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_1272, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!EmXF!, /__u/andrewmilroy1.substack.com/w_1456, /__u/andrewmilroy1.substack.com/c_limit, /__u/andrewmilroy1.substack.com/f_auto, /__u/andrewmilroy1.substack.com/q_auto:good, /__u/andrewmilroy1.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7617c2d-4546-4fe6-80a0-92e4ce8cefde_4870x3247.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Agentic AI is not just transforming cybersecurity. It is collapsing it into a broader function. The Chief Information Security Officer (CISO) role will soon cease to exist as we know it today.</p><p>The CISO occupies an unenviable and arguably untenable role. In theory it is indispensable and central to organisations but in practice, it is marginalised. I increasingly hear from boards and from CISOs themselves that the role as currently constructed, is not working. Cybersecurity is treated as expensive insurance, structurally disconnected from the real engines of growth. Even after a ransomware plague, sustained regulatory pressure, and an unbroken decade of high-profile breaches, the CISO remains neglected, underfunded, and measured largely by nothing bad happening.</p><p>Security is converging into the broader issue of whether autonomous operations can be trusted, governed, and controlled. </p><p>Many CISOs have already made the shift toward strategic governance. But even that elevated version of the role is now being absorbed into a broader function.</p><p><strong>Security on the Wrong Side of Transformation</strong></p><p>Boards are no longer primarily focused on protecting the business. They are focused on reinventing it before competitors do. Across every sector, investment is flowing aggressively toward AI-driven transformation, automation, and operational acceleration.</p><p>Cybersecurity, in its traditional form, increasingly finds itself perceived as a hindrance. The function is widely considered to be too slow, too siloed, and too tethered to a defensive mindset which is designed for a world that is rapidly disappearing. Agentic AI is seen by most business decision makers as offering unprecedented opportunities to gain competitive advantage through speed, agility and innovation. Security professionals rightly see risk at a time when their businesses are chomping at the bit to let agentic AI rip through their organisations. Where leadership sees opportunity, the CISO&#8217;s function too often sees exposure. This tension is becoming structurally unmanageable, and the organisations I speak with know it.</p><p><strong>AI Is Absorbing Cybersecurity From Within</strong></p><p>The disruption is not only external. AI is beginning to consume large parts of cybersecurity itself. Vulnerability discovery, threat detection, triage, policy analysis, and security analytics, workflows that once required substantial operational teams, are being accelerated or partially automated by AI agents.</p><p>The most compelling evidence of where this is heading comes from Anthropic&#8217;s Claude Mythos. Revealed in early April 2026, Mythos is not a dedicated security tool. It is a general-purpose frontier model whose cybersecurity capabilities emerged, in Anthropic&#8217;s own words, as a downstream consequence of general improvements in code, reasoning, and autonomy. That is a significant admission. Nobody designed Mythos to do this. It arrived at these capabilities on its own.</p><p>In testing, Mythos identified thousands of high-severity zero-day vulnerabilities across every major operating system and web browser. The scale of what it found exposed something the industry has long preferred not to confront directly, which is the appalling underlying state of global cybersecurity infrastructure. Decades of accumulated technical debt, under-investment, and reactive security practice laid bare by a single model in a matter of weeks.</p><p>Anthropic considered the risks of public release significant enough that it declined to make Mythos generally available, instead launching Project Glasswing. This controlled initiative gives early access to several organisations including AWS, Apple, Google, Microsoft, JPMorgan Chase and Nvidia, with the explicit goal of patching critical vulnerabilities before hostile actors could exploit the same capabilities.</p><p>But Mythos also points toward where defensive security is heading. Tools with these capabilities will not remain the preserve of a handful of technology giants. They will plug into agentic frameworks that can identify vulnerabilities and remediate them in real time, autonomously and continuously, without waiting for a human analyst to triage a ticket. The time between detection and response, historically measured in hours or days, collapses to seconds. That is a structural shift in how security operates.</p><p>This represents the dissolution of cybersecurity as a clearly bounded operational domain. Some key functions that once defined the CISO&#8217;s remit are being absorbed into wider enterprise platforms, embedded in AI-assisted layers that operate continuously and at a scale no human team can match.</p><p><strong>The New Battlefield: Operational Trust</strong></p><p>As autonomous systems begin to interact with infrastructure, applications, customers, employees, suppliers, and other AI agents with limited human intervention, the nature of risk transforms fundamentally. Identity is rapidly becoming the control plane for both humans and machines.</p><p>This shift is already visible in the regulatory landscape. In financial services, DORA in Europe and CPS 230 in Australia are pushing organisations away from narrow security thinking toward broader operational resilience models covering third-party risk, business continuity, governance, and identity. In the United States, the SEC and Federal Reserve are increasingly focused on systemic risk, operational accountability, and continuity. Responsibility for governing autonomous systems is spreading across operations, legal, risk, data, and architecture teams. It is not sitting inside a single security function.</p><p>From an enterprise risk perspective, board attention is shifting quickly toward a central question. How can autonomous operations be trusted, governed, and controlled without leadership losing visibility over its own decision-making and operational behaviour?</p><p><strong>The CISO Role Will Collapse into Governance</strong></p><p>It is important to be clear that AI transformation will not eliminate the concerns that cybersecurity addresses. Those concerns become more acute, not less, and the focus will shift to the speed with which we address them.</p><p>The residual CISO function will be much more centred around governance and risk management. It will further converge with other enterprise risk roles to set parameters, deploy governance frameworks, and determine risk appetite. This function will decide which autonomous decisions require human authorisation and which can be delegated entirely to machine judgment. It will establish accountability frameworks for agent-to-agent interactions, govern machine identities at scale, and ensure that enterprise AI operates within ethical, legal, and operational boundaries that boards and regulators can understand and defend.</p><p>Increasingly, this governance mandate is extending into organisational resilience. Boards have largely accepted that breaches and disruptions are inevitable. They want to know how quickly the organisation can recover and keep functioning. This issue pulls the evolving CISO role deeper into business continuity, supply chain risk, and operational recovery, areas that were once considered outside the security leader's remit.</p><p>The hands-on operational security leader who manages SOC teams, directs threat-hunting, and runs incident response is a figure whose function is being automated away in real time. The security leaders that a excel will be those who understand that their value lies not in operational execution but in defining the rules of engagement for systems that will increasingly govern themselves.</p><p>The residual CISO role  is one of governance, setting the parameters within which machines are permitted to act autonomously.</p><p><strong>The End of the Standalone Function</strong></p><p>The boundaries between cybersecurity, IT operations, resilience, governance, risk, and AI management are already collapsing.</p><p>Cybersecurity will not disappear. The discipline of protecting organisations from adversarial action, system failure, and operational risk remains as important as ever. But it will stop existing as a standalone function with its own budget, its own reporting line, and its own seat at the table defined by operational security work. Residual cybersecurity activities will fall into a broader discipline centred on governance, resilience, identity, and machine oversight.</p><p>Several organisations I have spoken with already understand this and are restructuring accordingly, seeking competitive advantage by moving faster into the agentic world and positioning themselves to govern an increasingly machine-led environment.</p><p>The end of the road for the CISO, as we know the role today, is not theoretical. For most organisations, it is already underway</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://andrewmilroy1.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Appalling State of AI Governance and Cybersecurity]]></title><description><![CDATA[Almost every organisation I speak to is, in effect, making a Faustian bargain with cyber risk, accepting levels of exposure that would once have been considered indefensible.]]></description><link>https://andrewmilroy1.substack.com/p/the-appalling-state-of-ai-governance</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/the-appalling-state-of-ai-governance</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Sat, 18 Apr 2026 02:43:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RDhn!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34a8b23b-de8b-42ac-a100-baf5ed90f55d_2523x2523.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Almost every organisation I speak to is, in effect, making a Faustian bargain with cyber risk, accepting levels of exposure that would once have been considered indefensible. This is the price they are paying to move at speed with AI.</p><p>Recent developments, most notably the Mythos revelations, have exposed the fragility of the current technology operating model. At the same time, widely reported tensions between Anthropic and elements of the United States Department of War over safeguards on advanced models highlight a growing pressure to prioritise speed and strategic advantage over meaningful control and governance.</p><p>There is understandable pressure from boards and senior management to deliver quick returns. AI has become the primary mechanism through which those expectations are being pushed into the business, yet cybersecurity is not being treated as a central part of that transition and, in many cases, remains a secondary concern, as it was during earlier technology shifts such as cloud transformations.</p><p>In some organisations, poor cybersecurity practices are being compounded by the fact that budgets are being redirected towards AI initiatives that are positioned as drivers of growth, while cybersecurity continues to be viewed as a cost centre. The result is a situation where risk exposure is increasing at the same time as the capability to manage that risk is being constrained.</p><p>Risk is being made even greater by two structural shifts. Firstly, regulatory oversight, particularly in key markets, is weakening or becoming less effective. Secondly, organisations are becoming increasingly dependent on a small number of hyperscalers, whose platforms underpin large parts of the global digital economy.</p><p><strong>AI is moving much faster than the controls that should govern it</strong></p><p>When AI is discussed at an executive level, the emphasis tends to fall on familiar use cases such as chatbots, software development productivity, customer service activities, marketing content generation, and operational optimisation, all of which are framed in terms of value creation. That framing, however, obscures the impact of AI on cybersecurity.</p><p>AI is making it faster to generate code, faster to identify vulnerabilities, faster to craft highly convincing phishing and social engineering campaigns, and faster to exploit weaknesses at scale. The combined effect is to create massive new opportunities for adversaries, while the potential to use AI to strengthen controls is being sidelined. For most, using AI to transform security is not a priority, and the result is rapid AI adoption with little corresponding increase in defensive capability. From a cybersecurity perspective, this is creating a level of systemic risk that is both growing and, in many cases, poorly understood.</p><p>In addition, much of the global software estate was never engineered to withstand the current level of scrutiny or speed of exploitation. AI is now exposing structural weaknesses and critical vulnerabilities that have existed for years but were tolerated because fixing them was expensive and rarely seen as urgent.</p><p><strong>Mythos exposes devastating vulnerabilities</strong></p><p>The recent revelations around Anthropic&#8217;s Mythos model has made headline news, raising awareness of the scale of cybersecurity risk that advanced AI capabilities can introduce. It is also reasonable to assume that similar capabilities are already being developed elsewhere, even if they have not been publicly disclosed.</p><p>A model capable of identifying previously unknown, critical vulnerabilities across major software platforms represents a significant technical advance and has clear defensive value, but it also has equally clear offensive potential. Anthropic&#8217;s decision to restrict access through Project Glasswing rather than release it openly has been widely interpreted as a responsible approach.</p><p>However, that interpretation becomes less convincing once you consider reports that information about the model leaked early due to issues within Anthropic&#8217;s own environment, suggesting that even the organisation developing the capability has struggled to fully contain it. Given that access has been extended to a relatively small group of very large technology vendors, many of which operate highly complex environments and have themselves been responsible for major security incidents, the assumption that this capability can be tightly controlled over time becomes difficult to sustain.</p><p>More broadly, large AI providers and hyperscalers are being asked to carry an increasing share of critical economic and strategic functions, while simultaneously facing political and commercial pressure to move faster and reduce constraints. The result is a modern Faustian bargain, where capability, speed, and strategic advantage are prioritised at the expense of cybersecurity risk. Monopolies are effectively transferring that risk to their customers.</p><p>A small number of hyperscalers now form the backbone of modern digital infrastructure, which means that when issues occur, the impact can extend far beyond any single organisation.</p><p><strong>Concentration risk is now structural</strong></p><p>The more significant risk, however, is structural. As organisations deepen their reliance on these platforms while also adopting the vendors&#8217; own security tools as their primary line of defence, they create a circular dependency in which the same entities that introduce systemic risk are also expected to manage it.</p><p>This is an efficient commercial model, but it concentrates risk in ways that are difficult to manage, creating the potential for correlated failure across infrastructure, data, and security layers when something goes wrong.</p><p><strong>Governance is not keeping pace with the risk</strong></p><p>At the same time as these technical and structural risks are increasing, governance mechanisms are not keeping pace and, in some cases, are being weakened.</p><p>The effective sidelining of bodies such as the Cyber Safety Review Board (CSRB) reduces the level of independent scrutiny applied to major incidents, which in turn limits the industry&#8217;s ability to learn from those incidents in a transparent and systematic way. Without that level of oversight, there is less pressure to address root causes and more incentive to manage perception.</p><p>The system is failing not because the risks are invisible, but because the incentives across organisations, vendors, and governments consistently reward speed, scale, and short&#8209;term advantage more than resilience</p><p><strong>Closing the gap between capability and control</strong></p><p>The response to this radical shift in the threat environment cannot be limited to incremental improvements or the addition of more tools, because the underlying issue is not a lack of technology, but a misalignment between how quickly capability is expanding and how slowly control is evolving.</p><p>Organisations need to start by reframing AI adoption as an expansion of attack surfaces rather than purely as a value creation activity. Until that shift happens, security will continue to be engaged too late and with too little influence over how systems are designed and deployed.</p><p>They also need to operate on the assumption that adversaries are benefiting from the same technological acceleration, if not faster, which means planning for a world in which vulnerability discovery, exploit development, and social engineering are all happening at greater speed and scale.</p><p>There is a more structural issue around dependency that needs to be addressed more directly, particularly in environments where infrastructure, identity, data platforms, AI capabilities, and security tooling are concentrated within a single ecosystem. In those scenarios, resilience depends less on the strength of any individual control and more on the ability to contain and recover from failure.</p><p>At the same time, organisations need to be more realistic about what vendor&#8209;provided security can and cannot do, recognising that while these tools can be effective, they do not remove the underlying risks associated with scale, complexity, and shared dependency.</p><p>Finally, there needs to be a more active push for meaningful governance, because without stronger accountability mechanisms, the underlying incentive structure is unlikely to change</p><p>.</p>]]></content:encoded></item><item><title><![CDATA[The Escalating Cybersecurity Cost of Regulatory Chaos]]></title><description><![CDATA[Microsoft has a long history of bringing products to market at breakneck speed.]]></description><link>https://andrewmilroy1.substack.com/p/the-escalating-cybersecurity-cost</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/the-escalating-cybersecurity-cost</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Fri, 20 Feb 2026 01:45:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RDhn!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34a8b23b-de8b-42ac-a100-baf5ed90f55d_2523x2523.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Microsoft has a long history of bringing products to market at breakneck speed. In its rush to ship, security has not always played an integral role. Its oversights have fuelled the development of a lucrative suite of security products, designed to address vulnerabilities in its own products. In other words, it is building a revenue engine around managing risks that it has created.</p><p>For a brief period, however, Microsoft genuinely appeared to put security first. That shift followed two of the most serious state-sponsored security failures in history, the Chinese linked Storm-0588 attack and the Russian-linked Midnight Blizzard breach. These incidents, and the scrutiny that followed, temporarily made insecurity too expensive to ignore.</p><p>Today, as regulatory oversight in Microsoft&#8217;s home jurisdiction weakens, that security-first posture looks increasingly fragile, as does security discipline across all other US-based technology vendors. The disbanding of the US Cyber Safety Review Board (CSRB) and broader moves to undermine technology&#8209;related regulation under the Trump administration, risk returning us to a more relaxed approach to cybersecurity, at a time when systemic risk is peaking. Without strict cybersecurity regulations and aggressive enforcement, the world&#8217;s largest technology platforms are structurally incentivised to accept higher levels of risk. Given their fiduciary duties and focus on profitability, they will under&#8209;invest in security if the cost of insecurity falls.</p><p>There is also a growing diplomatic dimension. When US hyperscalers face regulatory action in the EU or UK, it often triggers political pushback from Washington. If hyperscalers are treated as strategic national assets to be shielded from foreign regulators, the incentive to make deep, sometimes uncomfortable investments in product security weakens. As oversight recedes, dependence on a handful of hyperscalers deepens, concentrating risk exposure in ways few organisations fully recognise.</p><p><strong>The breaches that changed the tone</strong></p><p>It may feel like the distant past, but it&#8217;s worth revisiting the events that forced Microsoft to change its tone on cybersecurity. In 2023 and 2024, two major state-sponsored intrusions shook the technology industry and triggered calls for far greater regulatory scrutiny.</p><p>The Chinese&#8209;linked actor Storm&#8209;0558 accessed Microsoft&#8217;s cloud email environment and compromised accounts belonging to senior US government officials. The attack involved the theft of a Microsoft signing key, which enabled forged authentication tokens to be accepted deep inside Microsoft&#8217;s identity infrastructure. This revealed weak key management, insufficient logging, and fragile trust boundaries in systems underpinning government and enterprise communications. The US CSRB described it as a &#8220;cascade of security failures,&#8221; highlighting not just a single vulnerability but systemic weaknesses across design, operations, and response.</p><p>Shortly afterwards, the Russian&#8209;linked group Midnight Blizzard breached Microsoft&#8217;s corporate systems, accessing senior leadership email accounts and source code repositories via a basic password&#8209;spraying attack against legacy accounts. That a company selling identity, cloud, and security tooling to the world could be compromised through such fundamental hygiene issues was a deeply embarrassing demonstration of how far practice lagged behind marketing.</p><p>While AWS and Google Cloud have also faced serious incidents, the Microsoft breaches exposed weaknesses at the very heart of its authentication and trust architecture. For governments and enterprises already deeply embedded in the Microsoft ecosystem, these failures scream that cloud does not magically eliminate risk. Instead, it displaces and concentrates risk.</p><p><strong>From crisis to a security&#8209;first pivot</strong></p><p>Following the scathing CSRB report as well as lessons learnt during the COVID pandemic period, Microsoft CEO Satya Nadella told staff to prioritise security above all else. The company made it clear that if its teams faced a trade-off between security and other priorities, security was to win.</p><p>Microsoft launched its Secure Future Initiative (SFI), explicitly tying it to the need to address structural weaknesses exposed by Storm&#8209;0558 and subsequent attacks. Engineering authority was strengthened, secure&#8209;by&#8209;design principles were elevated, and for a time, security appeared central to its mission. This shift did not occur for altruistic reasons. It was triggered by independent federal review, public criticism, and reputational risk at the highest levels of government. Security improved because scrutiny made insecurity expensive, and because external accountability gave internal champions leverage.</p><p>This pattern is not unique to Microsoft. Across the technology sector, meaningful security uplift usually follows crisis, investigation, or enforcement. When regulators and independent review bodies shine a light on failures and impose real consequences, boards and executives find it much easier to prioritise long&#8209;term resilience over short&#8209;term gains.</p><p><strong>Warning bells: leadership and messaging shifts</strong></p><p>As the external pressure begins to lift, driven by the removal of the CSRB and weakening of regulations in the United States, we are seeing early signs of a retreat.</p><p>Recently, Nadella announced that Charlie Bell, the Executive Vice President of Security who joined Microsoft from AWS in 2021 with a mandate to embed security into Microsoft&#8217;s culture, would be replaced by Hayete Gallot. Gallot is a seasoned executive, but her background is primarily in customer experience, go&#8209;to&#8209;market, and franchise building rather than deep security engineering. In explaining the move, Nadella emphasised Gallot&#8217;s track record in building large franchises and accelerating adoption of platforms such as Purview.</p><p>The message, at least outwardly, was commercial rather than architectural. There was little explicit signalling that Microsoft intends to maintain the difficult, structural work of hardening its core products at the same intensity that followed Storm&#8209;0558 and Midnight Blizzard. When security is framed primarily as a growth opportunity and portfolio narrative, foundational hardening can easily drift behind product momentum, especially when external oversight is fading.</p><p>This is not an argument that Gallot cannot lead a serious security agenda. Rather, it is a warning that, in the absence of independent pressure, organisational gravity tends to pull security back towards being a revenue line and brand attribute rather than a non&#8209;negotiable engineering discipline.</p><p><strong>The hyperscaler dependence trap</strong></p><p>Governments and enterprises are now structurally dependent on three primary providers: Microsoft Azure, AWS, and Google Cloud. Between them, these firms anchor identity, productivity, infrastructure, and increasingly AI for much of the world.</p><p>Microsoft sits at the nexus of identity and productivity. Azure hosts critical workloads, Microsoft 365 runs communication and collaboration, and Entra ID underpins authentication for countless public and private sector environments. Switching is difficult, integration is deep, and AI services are now being bundled into long&#8209;term cloud contracts. AWS and Google Cloud play similarly central roles in other parts of the digital economy, from ecommerce and media to data analytics and AI research.</p><p>When internal security discipline weakens at any one of these firms, the systemic exposure is enormous. Customer dependence on them also creates incentives to sell more to a captive market and to slow down any re&#8209;architecting for security. AI&#8209;driven features and agentic services amplify this risk. As AI is embedded into productivity suites, developer workflows, and cloud consoles, identity compromise or misconfiguration can translate into much larger blast radii, with automated systems able to change configurations, move data, or trigger workflows at scale.</p><p>The hyperscaler dependence trap has led enterprises and governments to take enormous risk by centralising critical functions to gain efficiency and speed. In doing so, they also centralise failure modes into a small set of firms whose incentives are only partially aligned with long&#8209;term security.</p><p><strong>The danger of regulatory silence</strong></p><p>Microsoft will be breached again, as will AWS and Google Cloud. The more important question is what happens after the next breach. Do hyperscalers maintain uncompromising internal discipline when no independent body is investigating them? Do they report breaches promptly and transparently, or does quiet containment become the rational option in a politicised environment?</p><p>The dismantling of the CSRB sends a clear, and dangerous, signal. It weakens independent post&#8209;incident review and reduces the likelihood that major systemic failures will be investigated with the rigour and transparency we saw after Storm&#8209;0558. It also risks chilling future regulatory ambition. If high&#8209;profile oversight bodies can be dissolved when they become inconvenient, why would any agency push hard on large, politically connected vendors?</p><p>When enforcement becomes politically sensitive, the path of least resistance for hyperscalers is to focus on growth, AI narratives, and shareholder returns. Cybersecurity, particularly the unglamorous work of refactoring identity systems, hardening legacy code, and improving logging and key management, is easily viewed as important but not a means of differentiation.</p><p>In a concentrated cloud market, security must be structural, not a passing fashion. When identity, productivity, infrastructure, and AI are centralised in a handful of firms, security drift is not simply a corporate risk, it is a systemic one. Without tight, independent regulation and credible enforcement, we are waiting for the next &#8220;cascade of failures&#8221; to happen.</p><p>For regulators, boards, and security leaders, this means that the need to:</p><ul><li><p>Treat regulatory weakening as a first&#8209;order cyber risk, not background noise.</p></li><li><p>Explicitly model hyperscaler concentration and jurisdictional regulatory posture in enterprise risk assessments.</p></li><li><p>Assume less external assurance over cloud providers and demand more evidence, transparency, and independent testing.</p></li><li><p>Negotiate cloud contracts that include independent audit rights, transparent incident reporting, and meaningful remedies for security failures.</p></li><li><p>Avoid hyperscaler monocultures where possible and build realistic exit and contingency plans.</p></li><li><p>Evaluate third party products and providers that explicitly address the risk posed by hyperscaler dependence.</p></li></ul><p>Enterprises and governments already face a far more dangerous threat environment and a dramatically expanded attack surface, driven in part by rapid AI adoption. They must now also factor regulatory retreat into their risk calculations and enforce their own controls to address the increased risk of hyperscaler dependence. Security cannot be allowed to become optional just because referees have left the field.</p>]]></content:encoded></item><item><title><![CDATA[Forget AI Attacks. The Real Threat in 2026 is the Attack on Regulators]]></title><description><![CDATA[Two elephants in the room]]></description><link>https://andrewmilroy1.substack.com/p/forget-ai-attacks-the-real-threat</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/forget-ai-attacks-the-real-threat</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Thu, 18 Dec 2025 03:40:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RDhn!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34a8b23b-de8b-42ac-a100-baf5ed90f55d_2523x2523.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Two elephants in the room</strong></p><p>In the cybersecurity and risk management domains, there are two elephants in the room that are receiving insufficient attention. One is the increasingly intense undermining of regulators, and the other is over-dependence on a few hyperscalers.</p><p><strong>Why regulators matter</strong></p><p>Cybersecurity, privacy, child safety, and effective market competition all depend on regulators having the power and capacity to act. Regulators play a critical role in setting guardrails in advance, establishing baseline expectations for security, resilience, privacy, transparency, and fair competition that protect both businesses and consumers. These guardrails reduce systemic risk, create predictability for enterprises, and prevent dominant platforms from entrenching monopolistic positions that suppress choice, innovation, and consumer protection. Increasingly, regulators lack the authority, resources, and political backing to perform these functions effectively.</p><p><strong>The hyperscaler dependence trap</strong></p><p>The second massive issue is the growing dependence on a small number of hyperscalers. Governments and enterprises have concentrated critical workloads, sensitive data, and core digital services inside the infrastructure of a handful of providers. This concentration is becoming harder to justify at a time when both the US federal government and the Chinese government increasingly treat major technology platforms as strategic national assets. It raises uncomfortable questions about jurisdiction, control, and whether critical systems can securely remain dependent on platforms that are subject to the policy priorities of a single nation.</p><p><strong>The AI-amplified vicious cycle</strong></p><p>These two elephants in the room reinforce each other. As regulators weaken, more breaches go undetected, regulatory enforcement falters, and oversight of tech monopolies diminishes. At the same time, rapid advances in AI increase risk enormously. Weakened regulation materially exacerbates AI risk. AI systems operating at scale require strong oversight, transparency, and enforcement to ensure explainability, integrity, and security, and to prevent misuse. When regulatory authority erodes, managing AI risk at scale becomes increasingly difficult.</p><p><strong>Even the EU is under pressure</strong></p><p>Even where regulators retain formal authority, particularly in the EU, that power is now under sustained political and legal attack as recent enforcement actions against major platforms (note the recent X fine) demonstrate.</p><p><strong>Four targeted regulator types</strong></p><p>Four types of regulatory bodies face simultaneous pressure:</p><p>&#183; Privacy and cybersecurity authorities</p><p>&#183; Online safety and child protection agencies</p><p>&#183; Competition and antitrust regulators</p><p>&#183; Consumer protection and disinformation oversight bodies</p><p><strong>Six attack vectors</strong></p><p>The attacks come in multiple forms, typically from:</p><p>&#183; Aggressive lobbying, increasingly from nation states</p><p>&#183; Budget cuts</p><p>&#183; Jurisdictional challenges</p><p>&#183; Legal stalling tactics</p><p>&#183; Narrative warfare (&#8220;regulation harms innovation and freedom of speech&#8221;)</p><p>&#183; Technical obstruction by platforms</p><p><strong>The assault is already happening</strong></p><p>The erosion of regulatory power is already underway across multiple jurisdictions, with the possible exception of the EU, which nevertheless is under sustained political and commercial attack.</p><p><strong>United States: cyber transparency in retreat</strong></p><p>The United States illustrates how quickly cyber regulation can advance and then unravel under political and commercial pressure. After the SEC introduced stronger cybersecurity disclosure rules in 2023, major financial and industry groups swiftly lobbied for their dilution or repeal. By mid-2025, the SEC had withdrawn a more prescriptive set of cybersecurity and risk management rules altogether, marking a clear retreat from stronger oversight and accountability.</p><p>At the same time, several proposed measures aimed at countering foreign interference in critical infrastructure and digital operations stalled or were deprioritised. These reversals suggest that moves toward transparency and national security resilience are rolled back as soon as they threaten powerful commercial or political interests. In the U.S. system, regulators are increasingly outmatched by lobbying pressure, litigation threats, and partisan pushback.</p><p>The trend accelerated further in December 2025, when President Trump signed an executive order directing federal agencies to establish a single national AI framework and to challenge state-level AI laws that conflict with it. The order significantly curtails states&#8217; ability to regulate AI independently, consolidating authority at the federal level, while undermining state sovereignty and regulatory independence.</p><p>These developments signal a decisive shift away from cyber transparency, decentralised oversight, and proactive risk management, at a time when systemic digital and AI-driven risks are increasing rapidly.</p><p><strong>United Kingdom: Online Safety Act (OSA)</strong></p><p>The OSA was designed to protect children and reduce online harm. Instead, its enforcement has been systematically undermined. Critics frame it as regulatory overreach and delay it through political and industry pressure.</p><p>Implementation has come under attack from opposite directions. Advocacy groups argue progress is too slow and too weak to address genuine harm, while major technology firms and the US government claim the measures risk over-censorship and freedom of speech. The UK government, meanwhile, is pushing for faster action, underscoring how contested and fragile the enforcement mandate has become. The result is a regulator (Ofcom) caught in a political dispute, rather than delivering clear, consistent, online-safety outcomes.</p><p><strong>Canada: stalled reform and regulatory paralysis</strong></p><p>Canada&#8217;s attempt to modernise privacy and platform regulation through Bill C-27 collapsed under intense lobbying and political delay. The CPPA and the country&#8217;s first federal AI law were both abandoned when Parliament was prorogued in early 2025, eliminating years of reform.</p><p>The political context matters. Once the Trump administration took power, Washington signalled that moves by allies to tax or tightly regulate dominant US technology firms could trigger trade retaliation, including higher tariffs. For Canadian policymakers, that threat reinforced the message that any constraints on US tech monopolies carry economic and political risks.</p><p><strong>Australia: privacy enforcement with shrinking resources</strong></p><p>Australia has faced a surge in major data breaches and government cyber incidents, yet the Office of the Australian Information Commissioner (OAIC) has been constrained by years of budget pressure. The laws exist, but the regulator lacks the capacity to enforce them. In effect, this is a form of regulatory weakening by underfunding rather than statute.</p><p>Frustration with platform self-governance is growing. In December 2025, the federal government introduced a national ban on social media access for children under 16. This blunt policy move reflects declining confidence in existing regulatory tools. Major technology firms are lobbying to dilute the ban, repeating the pattern seen globally. Whenever and wherever governments attempt strong action, platforms mobilise to neutralise it.</p><p><strong>The Albanese and ICC cases: signals of how digital infrastructure can be weaponised</strong></p><p>In July 2025, after her UN report criticised the role of US tech firms in military operations, Francesca Albanese was sanctioned under EO 14203, cutting her off from US cloud services, email, productivity tools, and financial systems. Several ICC officials encountered comparable restrictions, with sanctions limiting their ability to use major US-based digital platforms.</p><p>These actions show how access to essential digital infrastructure can be withdrawn through nation state policy, with significant operational impact on independent investigators. Regulators, oversight bodies, and civil society now rely on platforms that a single government can restrict with immediate effect.</p><p>Even the EU remains structurally dependent on platforms based in a foreign jurisdiction. EU regulators face increasing foreign political interference while confronting highly litigious, tech monopolies.</p><p><strong>The uncomfortable truth is that regulation drives cybersecurity</strong></p><p>Although organisations will always implement the minimum controls required to keep their businesses operating, they rarely invest in strong data protection purely out of intrinsic motivation. Serious investment usually comes when regulation turns data protection into a board-level concern. Strong regulation attaches consequences to poor data handling and holds senior decision-makers accountable.</p><p>GDPR drove the biggest global cybersecurity improvement in decades, effectively setting global best practice for data protection. It introduced mandatory breach notification, strict vendor controls, encryption expectations, DPIAs, data minimisation, and formal accountability structures like DPOs, backed by real penalties for non-compliance. Companies adopt these measures because they are mandatory and the regulator has strong enforcement powers.</p><p>When regulators weaken, cybersecurity, privacy and safety (often child safety) deteriorate. Critically, AI risk accelerates, because systems operating at scale without strong regulatory guardrails can cause significant damage.</p><p>In parallel we are seeing tech monopolies shift towards rent extraction as regulatory pressure diminishes. This is being manifested in substantial cloud price increases, AI compute charges, bundling that suppresses competition, reduced transparency, and arbitrary product discontinuation.</p><p><strong>The structural risk of dependence on hyperscalers</strong></p><p>When regulatory oversight is weak and major platforms face little constraint, dependence on hyperscalers becomes a structural vulnerability for a range of reasons including:</p><p>&#183; Pricing, access and terms can change quickly, and dependent customers have little recourse</p><p>&#183; Enterprises have limited transparency into how data is used or moved</p><p>&#183; National regulators cannot reliably audit systems controlled by powerful foreign vendors</p><p>&#183; AI services become bundled into the systems of a small number of providers.</p><p>Governments and enterprises will, in 2026, need to examine ways of reducing their dependence on a handful of hyperscalers, at least for critical workloads, sensitive data, and national infrastructure. Sovereign clouds, and selective repatriation strategies will become essential tools to manage risk and ensure digital sovereignty.</p><p><strong>Implications for governments, boards and risk leaders</strong></p><p>All technology stakeholders are being impacted by the undermining and stymying of regulations. Enforcement power will be contested more aggressively, politically, legally and financially.</p><p>&#183; EU, UK, Canadian, Australian, and other regulators will face an onslaught of political, narrative, and financial attacks, while US regulatory capability is being significantly constrained.</p><p>&#183; For CISOs and risk managers, scenario planning needs to recognise that regulation and enforcement will lag further behind real world risk, making organisations and consumers more exposed to technology risk, than they have ever been.</p><p>&#183; Boards and executives may view regulatory retreat as short-term relief. In reality, it shifts cyber and privacy risk onto enterprises and consumers (often children) without clear guardrails or shared accountability.</p><p>&#183; Non-US governments are seeing a rapid erosion of their digital sovereignty. They need both strong regulators and diversified infrastructure if they are to maintain any semblance of independence from foreign pressure. For many enterprises and governments, dependence on a small set of US or Chinese platforms is now a major strategic vulnerability, not simply a procurement choice.</p><p>Even within the United States, both government and industry will need to reconsider how much critical national capability resides inside private technology firms whose interests do not always align with either national security or democratic accountability.</p><p><strong>Confronting the unavoidable risks of 2026</strong></p><p>2026 will be a year when regulators face relentless attacks across political, legal, financial, and commercial fronts. This weakening of regulatory power is likely to expose the risks inherent in reliance on a few US technology platforms and will force governments worldwide to confront the erosion of their digital sovereignty. They will need to strengthen their regulators and diversify their infrastructure.</p><p>Organisations cannot wait for regulators to recover. Risk management in 2026 and beyond will require:</p><p>&#183; Reduced single-country and single-vendor dependence. Critical workloads, data and capabilities will need to move away from reliance on a small number of US hyperscalers (and in some cases Chinese tech stacks) to avoid exposure to policy shifts and foreign political pressure. This will increasingly involve cloud repatriation for specific high-risk workloads and data, and diversification across jurisdictions and providers for the rest.</p><p>&#183; Stronger data and digital sovereignty strategies. Organisations will need greater transparency on where their data sits, whose laws apply, which jurisdictions can compel access, and how to keep intellectual property and sensitive data within trusted environments.</p><p>&#183; Explicit protection against nation-state threats. Security programs will need to assume that hostile states will seek to sabotage infrastructure or acquire data and IP through covert action and supply chain intrusion.</p><p>The organisations that act early will be the ones that optimise their cybersecurity postures and resilience.</p>]]></content:encoded></item><item><title><![CDATA[Countering Cognitive Threats in the Age of Disinformation and Rage Baiting: Reflections from London]]></title><description><![CDATA[London&#8217;s Reality Versus Online Perception]]></description><link>https://andrewmilroy1.substack.com/p/countering-cognitive-threats-in-the</link><guid isPermaLink="false">https://andrewmilroy1.substack.com/p/countering-cognitive-threats-in-the</guid><dc:creator><![CDATA[Andrew Milroy]]></dc:creator><pubDate>Tue, 09 Dec 2025 09:23:23 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e5f83757-d7c1-4ca1-8a59-234f5359c5d5_612x407.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>London&#8217;s Reality Versus Online Perception</strong></p><p>I recently spent a fantastic few days in London. It is truly one of the greatest cities in the world, offering everything from culture and history to world-class sport, extraordinary entertainment, every type of cuisine imaginable, and breathtaking architecture. The city is filled with beautiful green spaces and the public transport system is astonishingly comprehensive, even if slightly expensive.</p><p>I lived in London for over a decade, from the early 1990s to the early 2000s. That period shaped a large part of my life and I have always considered the city a home. Before returning to London this time, however, I felt unexpectedly anxious. My social media feeds were, and continue to be, inundated with clips portraying London as dangerous, declining, or dystopian. Clips entitled &#8220;London Has Fallen&#8221; have gone viral along with content suggesting a UK civil war is imminent. Much of this content is presented without context and designed to provoke an emotional reaction. In contrast, official statistics show that violent crime in London is significantly lower than in many large international cities. Yet the online narratives remain persistent and widespread.</p><p>Friends in the United States, Singapore, and Australia warned me to be careful in London. I suspect that, like many people, their views are influenced not by personal experience or empirical evidence but by what they see on their phones.</p><p><strong>Rage Baiting and the Spread of Disinformation</strong></p><p>When I arrived in London, I found the opposite of what online disinformation suggested. The city was more vibrant and felt safer than at any point during the decade I lived there. Back then, social media did not exist to enrage us about threats like an IRA bomb or a nail bomber. Today, London&#8217;s pubs, theatres, and restaurants are full. Tourist sites are packed, and the public transport system is better integrated than ever.</p><p>I also notice a striking trend. There seem to be far more American visitors than I recall from the past. London and nearby areas like the Cotswolds appear to have become magnets for Americans drawn to the mix of heritage, culture, creativity, and open society.</p><p>This contrast between reality and perception made me reflect on why disinformation about London spreads so easily. The core issue is that people often trust what is delivered directly to their phones, even when it contradicts empirical evidence or their own lived experience. Disinformation creators exploit this. They understand that emotive content and rage baiting, generate far more engagement than context, nuance, or boring facts.</p><p><strong>The Rise of Cognitive Threats</strong></p><p>Authoritarian regimes, particularly Russia, have learned to exploit these dynamics. London is a representation of an open, innovative, dynamic and creative society that they cannot replicate. London&#8217;s success completely debunks the notion that closed, homogenous, authoritarian systems offer better outcomes. As a result, disinformation networks regularly target cities like London, New York, and Paris. They amplify isolated incidents, distort context, and sometimes fabricate events. The aim is to erode trust in the stability and success of open, diverse societies, and to help like-minded authoritarians gain power.</p><p>Just as London faces relentless disinformation from external actors, organisations today are increasingly vulnerable to cognitive threats that exploit internal beliefs, perceptions, and decision-making<em>. </em>Within organisations, cognitive threats have become as damaging as technical ones. It is surprisingly easy to influence people when they are repeatedly exposed to misleading content. Employees can adopt harmful beliefs or even act against the interests of their own organisations, if targeted with false narratives.</p><p><strong>The Hybrid Threat Landscape</strong></p><p>Hybrid threats now combine technical exploits, such as phishing, malware, and credential theft, with information warfare and psychological manipulation. This means the today&#8217;s security defences are woefully inadequate. Cybersecurity must include strategies to strengthen human resilience, critical thinking, and awareness, as information warfare techniques increase in both volume and sophistication.</p><p><strong>Defending Against Cognitive and Hybrid Threats</strong></p><p>AI-generated media will accelerate this problem, making disinformation faster, cheaper, and harder to detect. Organisations need concrete steps to protect themselves. This includes regular employee training on cognitive biases and their impact on decision-making, education about recognising phishing and social engineering attempts, and active monitoring of how their brand or sector is manipulated online. These measures can reduce the risk that employees are unknowingly influenced by false narratives or weaponised rumours.</p><p><strong>How Long Can the Deluge of Disinformation and Psychological Manipulation Continue?</strong></p><p>How long can the steady erosion of belief in empirical evidence, combined with the constant promotion of outrage, continue? Disinformation weakens both institutions and organisations, distorting perceptions and making ill-informed or false narratives difficult to reverse. My trip reminded me that London is not a city in decline. It is alive, energetic, and full of possibility. Perhaps that is why it attracts so much targeted disinformation.</p><p>These dynamics shape not just how we see cities but also how we think and act inside our organisations. It poses a question for us all. How do we counter cognitive threats in the age of disinformation and rage baiting?</p>]]></content:encoded></item></channel></rss>